MACHINE LEARNING
AI
Prompt injection, deepfakes, model theft, the EU AI Act, security and policy at the frontier.
Where artificial intelligence meets the threat model: prompt injection, agentic and MCP attack surfaces, deepfake-driven social engineering, shadow AI, and the governance rules catching up with all of it. Start with the prompt-injection defender’s playbook, the MCP attack surface and the first AI agent to run a ransomware attack.
Start here
- Prompt injection: the defender’s playbook
- MCP security: the attack surface mapped
- JadePuffer: the first AI agent to run a ransomware attack
- Deepfake vishing: voice-clone fraud explained
- What the EU AI Act requires from US companies
Latest AI security coverage
- 36,769 exposed AI endpoints, only 2% ask for a loginMysterium VPN counted 36,769 self-hosted AI endpoints reachable on the public internet. Only 2.02% return an authentication challenge, and that is a floor.
- What is slopsquatting? AI package hallucinations, explainedSlopsquatting is a supply-chain attack that weaponises the package names AI coding assistants invent. How it works, what the research measured, the real 2026 incidents, and how to defend an AI-assisted pipeline.
- “Delve” is dead: AI writing tells expire in 18 monthsThe word delve fell 94% from its 2024 peak while dash use doubled. We measured 21,442 arXiv abstracts: AI writing tells expire in about 18 months.
- Vibe coding is shipping vulnerabilities at scale in 2026AI-generated code is fast and insecure. Veracode found 45% of samples carry OWASP Top 10 flaws, roughly a fifth of AI-suggested packages are hallucinated, and vibe-coded apps are already leaking real data.
- Prompt injection left the lab in 2026. It is in the wild nowPrompt injection stopped being a lab demo in 2026. A one-click Claude Desktop flaw, AI browsers leaking credentials, and agents tricked into crypto payments show the attack is now operational, not theoretical.
- Shadow AI is the new stealer-log jackpot in 2026Shadow AI is now a top insider threat: 45% of staff use AI on corporate devices, most via personal accounts. When those sessions land in stealer logs, attackers inherit the AI and everything typed into it.
- macOS.Gaslight: malware that prompt-injects your SOCSentinelLABS found macOS.Gaslight, a DPRK-linked Rust backdoor that embeds 38 fake system messages to make AI malware-triage agents abort. It is the first implant built to attack the analyst’s LLM, not the sandbox.
- JadePuffer: the first AI agent to run a ransomware attackSysdig documented JADEPUFFER, the first ransomware attack whose technical execution was run end to end by an AI agent. A human handler still picked the target, built the infrastructure, and supplied credentials.
- Agentic AI threats: how MCP becomes an attack chainAgentic AI moves the threat from what a model says to what it does. We map how MCP turns goal hijacking, tool misuse, and privilege abuse into a working attack chain, and the controls that contain it.
- MCP security in 2026: the attack surface mappedA technical map of the Model Context Protocol attack surface in 2026: tool poisoning, line jumping, rug pulls, tool-chaining exfiltration, token sprawl, and the RCE flaws that turned MCP servers into entry points.
- Build a secure MCP server in 2026: a hardening guideA practitioner’s hardening guide for MCP servers in 2026: OAuth 2.1 auth, least-privilege tool scopes, sandboxing, egress control, and the tool-definition pinning that blocks poisoning and rug pulls.
- Deepfake vishing 2026: voice-clone fraud explainedDeepfake vishing uses AI-cloned voices to defeat phone-based trust. Here is how voice-clone fraud works in 2026, what it costs, and how to stop it.
- Fable 5 and Mythos 5: the US-only gate threat actors will beatWashington cut Fable 5 and Mythos 5 for every foreigner. Meanwhile 34,814 stolen Claude sessions and 74,114 ChatGPT cookies already sit in infostealer logs. A citizenship gate is just KYC, and KYC loses.
- Prompt injection: the 2026 LLM defender’s playbookPrompt injection is now the dominant attack vector against LLM-powered applications, and most teams shipping AI features don’t have a defensive playbook. We map the attack taxonomy, walk through real exploit patterns, and lay out the controls that actually contain the blast radius.
- MCP for WordPress: set up an MCP server in 2026A step-by-step tutorial for wiring an MCP server into a WordPress site (using the AI Engine MCP adapter) so Claude, Cursor, or any MCP-compatible client can read posts, run admin tasks, and edit content. With auth, scope, and security hardening you actually need.
- What is MCP? A 2026 guide to Model Context ProtocolModel Context Protocol (MCP) is the emerging open standard for connecting AI assistants to tools, data, and live systems. This guide explains how MCP servers work, the architecture behind them, and how to build your first one, with security caveats security teams need to know.
- Detecting AI-generated phishing in 2026: a header-forensics, classifier, and DKIM workflowA 2026 workflow for telling AI-generated phishing apart from real correspondence, combining email-header forensics, public LLM-detection classifiers, and DKIM/SPF replay analysis.
- How to host Llama 3 70B locally with Ollama and Open WebUI: a 2026 tutorialA practitioner’s tutorial for running Llama 3 70B locally with Ollama, Open WebUI, and the right hardware. Privacy-sensitive AI work without sending a byte to OpenAI or Anthropic.
- How to red-team your own LLM app: tutorial with Garak, PyRIT, and PromptfooA 2026 tutorial for running structured prompt-injection and jailbreak red-team tests against your own LLM application using NVIDIA Garak, Microsoft PyRIT, and Promptfoo. Open-source, repeatable, CI-friendly.
- What the EU AI Act actually requires from US companies in 2026The EU AI Act’s enforcement window is open in 2026. Here’s what US companies actually need to do, ranked by risk tier and deadline, in plain English.
- How attackers are using AI agents to automate reconnaissance in 2026A practitioner’s look at how threat actors are wiring open-source LLMs and agent frameworks into their reconnaissance pipelines, what that means for defender visibility, and the detection signals that still work.
- Prompt injection attacks: a 2026 field manualA practitioner’s field manual on prompt injection in 2026: the four attack patterns that work against production LLM apps, the controls that actually mitigate them, and the test cases your red team should be running this quarter.
- How shadow AI is leaking your company’s secrets, and how to find itShadow AI (the AI tools your employees use without IT’s blessing) is the 2026 version of shadow IT, and it’s leaking proprietary code, customer data, and internal strategy at a pace most security teams aren’t measuring.
- The economics of AI agent jailbreaks: who profits when an LLM goes off-railsEvery successful jailbreak prompt has a price. A look at the underground market for AI agent bypasses in 2026: who builds them, who buys them, and how the profit motive shapes the threat landscape.
Every AI article
Every article we have published in this section, newest first.
- 36,769 exposed AI endpoints, only 2% ask for a login
- What is slopsquatting? AI package hallucinations, explained
- “Delve” is dead: AI writing tells expire in 18 months
- Vibe coding is shipping vulnerabilities at scale in 2026
- Prompt injection left the lab in 2026. It is in the wild now
- Shadow AI is the new stealer-log jackpot in 2026
- macOS.Gaslight: malware that prompt-injects your SOC
- JadePuffer: the first AI agent to run a ransomware attack
- Agentic AI threats: how MCP becomes an attack chain
- MCP security in 2026: the attack surface mapped
- Build a secure MCP server in 2026: a hardening guide
- Deepfake vishing 2026: voice-clone fraud explained
- Fable 5 and Mythos 5: the US-only gate threat actors will beat
- Prompt injection: the 2026 LLM defender’s playbook
- MCP for WordPress: set up an MCP server in 2026
- What is MCP? A 2026 guide to Model Context Protocol
- Detecting AI-generated phishing in 2026: a header-forensics, classifier, and DKIM workflow
- How to host Llama 3 70B locally with Ollama and Open WebUI: a 2026 tutorial
- How to red-team your own LLM app: tutorial with Garak, PyRIT, and Promptfoo
- What the EU AI Act actually requires from US companies in 2026
- How attackers are using AI agents to automate reconnaissance in 2026
- Prompt injection attacks: a 2026 field manual
- How shadow AI is leaking your company’s secrets, and how to find it
- The economics of AI agent jailbreaks: who profits when an LLM goes off-rails
- Local AI vs cloud AI: the real security trade-offs in 2026
- AI in the SOC: where it’s actually working in 2026
- Learning OpenClaw: exposing dangerous defaults
- The EU AI Act: what it actually requires
- AI red teaming: how to stress-test your AI systems
- Open-source models vs closed APIs: a security comparison
- Model theft and IP: what happens when your AI gets stolen
- Adversarial examples: tricking ML models with imperceptible changes
- The AI bill of materials: why you need to know what’s in your models
- How large language models are reshaping phishing
- Deepfakes and voice cloning: the state of synthetic media threats
- AI in cybersecurity: hype vs reality in 2026
- Prompt injection: the OWASP top risk for LLM applications























