Listen very carefully on this ...

Nicholas Carlini - Black-hat LLMs | [un]prompted 2026

https://www.youtube.com/watch?v=1sd26pWhfmg

#cybersecurity #aisecurity #zeroday

Nicholas Carlini - Black-hat LLMs | [un]prompted 2026

YouTube

I updated minitrace to v0.2.0.

minitrace is a session trace format for human-AI coding agent interactions. The new version adds new framework adapters including some for web sessions, input provenance tracking, DuckDB-queryable JSON.

https://github.com/fukami/minitrace

#AISecurity #PromptInjection #OpenSource #InfoSec #LLM #AISafety #AIAlignment

GitHub - fukami/minitrace: A session trace format for capturing human-AI coding interactions across frameworks.

A session trace format for capturing human-AI coding interactions across frameworks. - fukami/minitrace

GitHub
YC W26 Demo Day: Hex Security is building AI agents that act as automated penetration testers, continuously probing company infrastructure for vulnerabilities to prevent cyberattacks. The startup claims it crossed 1M USD run-rate revenue in just eight weeks. Investors were reportedly 'fighting' to invest. https://techcrunch.com/2026/03/28/from-moon-hotels-to-cattle-herding-8-startups-investors-chased-at-yc-demo-day/ #Tech #Startup #News #AISecurity #HexSecurity
From Moon hotels to cattle herding: 8 startups investors chased at YC Demo Day | TechCrunch

We polled nearly a dozen VCs to find out which W26 startups are the sought after in the batch.

TechCrunch

Claude extension 0-click flaw

Silent prompt injection → full access
Wildcard trust + XSS chain
💬 AI agents = new perimeter?

🔔 Follow @technadu

Source: https://cybersecuritynews.com/claude-chrome-extension-0-click-vulnerability/

#Infosec #AIsecurity #ZeroClick

Chubby (@kimmonismus)

Human Security 보고서를 인용해 2025년 자동화 트래픽이 인간 활동보다 8배 빠르게 증가했고, AI 에이전트 트래픽은 약 8,000% 급증했다고 전합니다. AI 봇과 에이전트가 인터넷 트래픽을 주도하는 시대가 예상보다 빨리 도래했다는 경고성 내용입니다.

https://x.com/kimmonismus/status/2037856911786381538

#aisecurity #bottraffic #aiagents #automation #internettraffic

Chubby♨️ (@kimmonismus) on X

Bots have officially overtaken humans on the internet. A new report from Human Security found automated traffic grew 8x faster than human activity in 2025, with AI agent traffic surging nearly 8,000%. The age of machine-dominated internet traffic is here, years earlier than many

X (formerly Twitter)
Break LLM Workflows with Claude's Refusal Magic String - Hacking The Cloud

How Anthropic's refusal test string can be abused to stop streaming responses and create sticky failures.

OWASP recently released LLM & Gen AI Security Landscape - 2026, Q2 where it show players in the Gen AI space.

As you can see here, orgz still need to choose their best vendor

Nothing ever changed, only shifted
😜

#OWASP
#GenAI
#AISecurity
#AITrust
#VendorSelection
#Cybersecurity

⚠️ CRITICAL vuln in langflow-ai langflow < 1.9.0 (CVE-2026-33873): Agentic Assistant allows remote code injection via LLM-generated Python. Patch to 1.9.0+ or restrict feature access immediately. Details: https://radar.offseq.com/threat/cve-2026-33873-cwe-94-improper-control-of-generati-cafbe4ee #OffSeq #CVE202633873 #AIsecurity
Security leaders say the next two years are going to be ‘insane’

Top security experts warn AI is discovering vulnerabilities exponentially faster than defenders can respond, creating a "perfect storm" for attackers over the next two years.

CyberScoop