Browser AI Agents
-
Hugging Face says AI agent breached its production infrastructure
Hugging Face said an autonomous AI agent breached its production infrastructure, reaching some internal datasets and credentials. The company said public models were not affected and it has rotated secrets and rebuilt compromised nodes.
-
Google Dialogflow CX flaw could have exposed chats across agents
Google fixed a Dialogflow CX flaw that could have let an attacker with edit access to one agent read conversations and influence other Code Block-enabled agents in the same Cloud project. Varonis reported no signs of real-world abuse.
-
Sysdig says AI agent ran ransomware attack through patched Langflow flaw
Sysdig says an AI agent carried out a ransomware attack from start to finish after exploiting a patched Langflow flaw, stealing credentials and encrypting a production database. The report says the case shows how exposed software and weak defaults can be chained automatically.
-
Google Vertex AI flaw could expose cloud data, researchers say
Researchers say a Google Cloud Vertex AI flaw could let an attacker abuse AI agent permissions to reach customer data and restricted internal repositories. Google has updated guidance and urged least-privilege controls.
-
NIST center issues RFI seeking input on security for autonomous AI agents
A Request for Information from NIST’s CAISI asked for input on secure practices for autonomous AI agents on Jan. 8, focusing on novel risks, assessment methods, and deployment constraints as agencies push toward operational standards.
-
AI agents flagged as new insider threat in 2026 by Palo Alto report
A Palo Alto Networks predictions report warns AI agents are a new insider threat in 2026 as Gartner forecasts 40 percent of enterprise apps will adopt task specific agents. The report highlights privilege risk, prompt injection and defensive uses.





