Full Archive · Page 10

Research archive, page 10

Browse entries 217–240 of 1576. Return to the first page to search and filter the complete collection.

Cloudflare AI Security August 14, 2026 analysis

How Cloudflare detects MCP traffic and helps secure it

Cloudflare Gateway now classifies inspected Streamable HTTP MCP traffic using the MCP-Protocol-Version header, exposes the user and destination in logs and a dashboard, and supports allow or block rules through an MCP-specific selector. The article distinguishes unapproved shadow MCP from direct connections that bypass an approved Portal's controls, and notes blind spots including local stdio, off-network, non-inspected, and otherwise unobserved traffic.

Google DeepMind Blog December 9, 2025 analysis

FACTS separates factuality tests for memory, search, images and supplied context

Google DeepMind’s December 2025 FACTS suite evaluates factual answers under four different information conditions: model knowledge alone, web search, images and supplied documents. Its search track standardizes the retrieval tool across models, while public examples accompany a private held-out evaluation set managed by Kaggle. The combined score averages results across tracks and sets, which can conceal sharply different failure patterns. The release provides a reusable evaluation structure, but benchmark accuracy does not establish factual reliability on a different application’s questions, retrieval system or user population.

RIG-RAG: A Graph-Inspired Approach to Agentic Cloud Infrastructure video thumbnail Play video
CAMLIS / PMLR November 14, 2025 video

RIG-RAG: A Graph-Inspired Approach to Agentic Cloud Infrastructure

RIG-RAG converts changing cloud configuration data into a typed, security-enriched graph for natural-language investigation and scheduled oversight. The authors report a production AWS deployment supporting 300,000 users, with interactive queries for analysts and curated recurring questions that detect infrastructure drift and expose relationships such as public reachability and identity access.

Microsoft Security Blog September 25, 2026 news

Storm-3168: compromised service principals enable rapid Azure destruction

Microsoft documents two compromised service principals used for Azure discovery, resource destruction and credential collection in activity linked to Storm-3168. The investigation distinguishes successful deletions from failed operations and attempts to remove recovery protections. Although the actor is associated with agentic ransomware reporting, the Azure evidence establishes destructive cloud operations, not a confirmed autonomous decision for every action. Microsoft reports no observed ransom note or confirmed successful data exfiltration in this case.

One Operator, Many Drones: Inside Skydio's Autonomy Stack — Suchet Bargoti, Skydio video thumbnail Play video
AI Engineer September 24, 2026 video

One Operator, Many Drones: Inside Skydio's Autonomy Stack — Suchet Bargoti, Skydio

Suchet Bargoti demonstrates remotely coordinated drones and explains Skydio’s division of autonomy between aircraft and cloud services. Immediate control stays on the vehicle; cloud models support heavier reasoning, shared maps and tool-based task planning. Fleet observations feed later updates. The talk illustrates how an operator can shift attention between aircraft, while its stated reliability target is not a measured fleet-wide success rate.

The Hacker News AI Security September 9, 2026 news

Joint advisory describes alleged model-distillation campaigns and detection controls

CISA, NSA and FBI allege industrial-scale extraction of US model capabilities through distributed accounts, proxies and aggregators. Their advisory recommends correlating prompts, usage and account behavior across providers; it distinguishes these alleged campaigns from legitimate model distillation.

The Hacker News AI Security August 31, 2026 news

Aurora Ransomware Operators Use Cursor AI in Attacks Against 10 Targets

CloudSEK and Gambit Security report that an Aurora ransomware affiliate used Cursor for sustained Russian-language attack planning and hands-on exploitation after obtaining credentials or an existing route into victim networks. Recovered infrastructure linked the agent sessions to Active Directory discovery and escalation plans, while the broader intrusion still relied on familiar social engineering, credential theft, lateral movement, defense evasion, exfiltration, and ransomware deployment.

Black Hat Asia 2026 | Cache Me, Catch You: Exploiting LLM Caching Layers in vLLM, GPTCache & Friends video thumbnail Play video
Black Hat August 21, 2026 video

Black Hat Asia 2026 | Cache Me, Catch You: Exploiting LLM Caching Layers in vLLM, GPTCache & Friends

The NDSS-backed research identifies six inference-time cache attacks across vLLM, SGLang, GPTCache, and related stacks. Weak prefix and image cache keys plus semantic near-match errors can make distinct inputs share cached state, enabling poisoned responses, information leakage, and moderation bypass; the authors provide experimental artifacts and vendor disclosures.

Adversa AI Trusted AI Blog August 18, 2026 analysis

Top 10 zero-click attacks against AI agents

Adversa compares ten shipped or research-stage zero-click agent compromises, including EchoLeak, DuneSlide, TrustFall, ShadowLeak, GeminiJack, and Morris II. The recurring chain is untrusted retrieved content entering model context, an agent applying inherited privileges, and data or code escaping through images, cloud requests, browser navigation, email, or a developer shell.

The Hacker News AI Security August 18, 2026 analysis

AI "Mind Viruses" Can Spread Between Agents Through Persistent Prompt Files

An Anthropic and EPFL preprint tests self-propagating instructions in sandboxed agent chains whose MEMORY.md and SOUL.md files persist across sessions. Writes to the system-loaded soul file produced most propagation attempts and infected the next agent 55% of the time; all four action payloads survived some 20-hop trials. A one-paragraph warning reduced tested spread to near zero, and the researchers found no successful wild propagation in archived Moltbook data.

The Hacker News AI Security August 18, 2026 analysis

Microsoft Copilot Personal Flaws Could Let One Click Exfiltrate Data From Connected Apps

Varonis' CoSnitch research combines Copilot Personal's q parameter with an undocumented autorun parameter so one crafted link executes an attacker prompt inside a signed-in session. The prompt can read already authorized mail, calendars, Drive metadata, chat history, and memory, then exfiltrate data through Copilot's URL fetch. A separate web-summarization path could persist attacker instructions in memory. Microsoft patched CVE-2026-24301 on August 18.

Why Great Models Fail: Lessons From 9 Years of Deploying ML Models - Megan Robertson video thumbnail Play video
NDC Conferences YouTube August 13, 2026 video

Why Great Models Fail: Lessons From 9 Years of Deploying ML Models - Megan Robertson

Drawing on nine years of cross-industry ML deployments, Megan Robertson explains why a statistically accurate model can still fail to deliver in production. The session moves beyond offline performance to scoping, organizational failure modes, monitoring, maintainability, and the operational conditions required for a model to keep producing useful results.

Noma Labs July 29, 2026 analysis

RufRoot: unauthenticated Ruflo MCP bridge enabled RCE and memory poisoning

Before Ruflo 3.16.3, its default Docker Compose deployment bound the MCP bridge to all interfaces without authentication. A reachable attacker could invoke the terminal tool, read model-provider keys and conversations, spawn agents, and poison persistent AgentDB patterns. Noma Labs verified the chain; the patch adds loopback binding, bearer authentication for public exposure, an opt-in terminal tool, authenticated MongoDB, tighter CORS and container defaults, and regression tests.

Hunt.io July 23, 2026 analysis

Thailand's Ministry of Finance Targeted With Hermes AI Agent Running Unattended

Hunt.io recovered 585 files and Hermes logs from an exposed staging server used against Thailand's Ministry of Finance. The evidence shows an operator who already had target knowledge and access running Hermes in unattended “YOLO” mode for repetitive post-exploitation enumeration, while also staging Hadoop exploitation scripts and a custom Hades implant; it does not show the agent finding the initial entry point or novel vulnerabilities.

Breaking AI Inference Systems: Lessons From Pwn2Own Berlin video thumbnail Play video
Black Hat July 8, 2026 video

Breaking AI Inference Systems: Lessons From Pwn2Own Berlin

Fuzzinglabs researchers explain how threat modeling, file-format fuzzing, and plugin analysis exposed an authentication bypass and memory-corruption issues in Ollama plus command injection in NVIDIA Triton Inference Server's model-configuration pipeline. The Pwn2Own case study also examines RedisAI, ChromaDB, and container-runtime attack surfaces.