Vulnerability
Found 10 recent publications

Artificial intelligence may install malicious code on your computer
Do you allow your artificial intelligence tools to write and install code independently? You should think again. A new study reveals that the most popular AI tools, including Claude from Anthropic and Codex from OpenAI, could become a conduit for injecting malware directly into your computers and corporate networks. The new risk stems from the way these tools read and execute instructions from...

Vulnerability in AWS SDK Put Thousands of Companies at Risk
Researchers at the Israeli security firm Pi discovered a vulnerability in official AWS SDKs that allows requests to be rerouted to attacker-controlled servers. This flaw exposes sensitive cloud credentials.

Worrying? The loophole that brings expired credit cards back to life
Has your credit card expired and you are about to throw it away? A study presented at the USENIX Security 2026 conference reveals that in some cases, the old card can still be used to make a payment. A team from the University of Massachusetts Amherst found a weakness in the contactless payment protocol that allowed researchers to make a terminal treat an expired card as if it were still valid.

20 prompts in 24 hours: how Israeli cyber researchers used AI to locate a critical vulnerability in Zoom
Researchers from the Israeli cyber company A Security found a dangerous vulnerability in Zoom by sending fewer than 20 prompts to an AI model in less than 24 hours. Previously, such research would have required months of work by a team of experts.

Lawsuit against Apple: Critical vulnerability in iCloud+ exposed user IP addresses
Many users pay for an iCloud+ subscription for the iCloud Private Relay feature, designed to mask IP addresses while browsing. However, new research has uncovered a serious flaw that renders this protection ineffective, leaving users vulnerable to tracking.

Asked an AI agent to sign him up for a gym class — and then everything went wrong
Andrew Bird, an Australian developer, asked an OpenClaw agent to get him a spot in a morning class. The bot found a permissions vulnerability, cancelled another person from the waiting list, and then failed to add them back.

AI agent hacks gym booking system without user request
An AI agent performing a routine booking task autonomously exploited vulnerabilities in a gym's software. It secured spots on blocked dates and removed other members from the waitlist without the user's input.

User asked for a spot in a gym class, the AI agent carried out a cyberattack
Instead of just booking a gym class, the AI agent identified a security vulnerability, exploited it to bypass booking restrictions, and removed another person from the waiting list. The incident, defined as the first known autonomous cyberattack in Australia, raises legal questions regarding the responsibility of users and the companies developing the technology.

Israeli cyber firm Sygnia exposes vulnerability in AI-generated code
Israeli company Sygnia has identified a critical security breach in a major financial institution's application. The flaw, stemming from code written by the AI model Claude, allowed unauthorized access to sensitive customer data.

Risk for half a million users: the vulnerability that exposes files on your computer
Would you allow an AI-based digital assistant to manage tasks for you directly on your personal computer? The idea sounds great and promises to save us valuable time, but it turns out it also brings significant security risks.