#mitre-atlas
15 posts

When AI Crossed from Assistant to Operator: Check Point's 2026 Verdict and the Week That Proved It
A deep research analysis of how AI cyber attacks have crossed the critical threshold from assisting attackers to running operations autonomously, anchored by Check Point's 2026 AI Security Report and a record week of autonomous exploits

Weekly AI Cybersecurity News Roundup — July 14–20, 2026
White House launches AI and cybersecurity coordination group, SANS warns of AI governance gap as adoption surges to 78%, Check Point report reveals AI now drives cyber attacks not just assists them, CISA adds two new KEV entries, novel agent data injection attack makes AI agents misclick, and ChatGPT single-prompt full cyber attack chain demonstrated.

AI-Generated Zero-Day Exploits: When Autonomous Agents Become the Weapon
A deep research analysis of how AI agents are now autonomously discovering and weaponizing zero-day vulnerabilities — from Google's confirmation of the first AI-created zero-day to PROMPTSPY's Gemini-powered Android backdoor and the supply chain attacks targeting AI infrastructure.

Giskard Review: Open-Source LLM + ML Security Testing, Tested
Giskard is the only open-source AI testing framework that covers both LLM security and traditional ML model quality in a single Python library. We test its autonomous red teaming agents, RAGET toolkit, 40+ vulnerability probes, and how it fits into a modern AI security stack alongside Garak and Promptfoo.

Weekly AI Cybersecurity News Roundup — July 7–13, 2026
EU launches sweeping AI cybersecurity action plan with Grand Challenge, CISA adds Langflow as first-ever AI agent platform to KEV catalog, Ghostcommit attack hides prompt injection in PNG images to steal code secrets, Accenture confirms 35GB data breach, DHS HSIN network breached, and Anthropic sues Abnormal AI over slash-mark logo trademark dispute.

Agentic AI Security in 2026: Why One in Eight Breaches Now Involves Autonomous Agents
A comprehensive deep research analysis of the agentic AI security landscape — from prompt injection and memory poisoning to the OWASP Top 10 for Agentic Applications and the defense architectures that can actually protect autonomous agent deployments.

Securing AI Agents in Production: Tool Access, Identity, and Monitoring
A practical guide to securing production AI agent deployments — covering least-privilege tool access, identity management, human-in-the-loop controls, and runtime monitoring for SaaS teams building with agentic AI.

Weekly AI Cybersecurity News Roundup — June 29–July 6, 2026
First fully autonomous AI ransomware campaign targets Langflow instances, Microsoft Defender now discovers 25+ AI agent types, CrowdStrike launches Continuous Identity for AI agents, Trump AI Executive Order reshapes federal vulnerability reporting, and the AI cyber attack explosion reaches new intensity with under-one-hour autonomous post-exploitation agents.

AI Supply Chain Security in 2026: The Hidden Link That Controls Your Model Pipeline
A comprehensive deep research analysis of AI supply chain security — from PyTorch dependency poisoning and Hugging Face model backdoors to NIST AI 600-1 provenance requirements, ML-BOM mandates, and the defense controls that actually work for production AI pipelines.

Weekly AI Cybersecurity News Roundup — June 22–29, 2026
CISA issues BOD 26-04 with critical patching mandates, Sophos uncovers AI-powered malware lab using Claude Opus for EDR evasion, Check Point VPN zero-day exploited since May, Cisco SD-WAN gets second zero-day patch in two weeks, and Verizon DBIR reveals employees using AI on corporate devices — many via personal accounts.

AI Model Extraction: How Attackers Steal $3M Models for $200 in API Queries
A comprehensive deep research analysis of AI model extraction attacks — from Tramèr et al.'s foundational 2016 work to 2026's distributed multi-client bypasses, CerberusAI framework, entangled watermarks, and the emerging cold-copy threat from Bleeding Llama (CVE-2026-7482).

Garak Review: NVIDIA's Open-Source LLM Vulnerability Scanner, Tested
Garak (8.2k GitHub stars, Apache 2.0) is NVIDIA's open-source LLM vulnerability scanner with 50+ probe modules for prompt injection, jailbreaks, encoding bypasses, and data leakage. We test it against real model endpoints, break down the CLI workflow, compare it to PyRIT and Promptfoo, and tell you whether it deserves a spot in your AI security stack.

Weekly AI Cybersecurity News Roundup — June 15–22, 2026
Anthropic forced to shut down Fable 5 and Mythos 5 models, SearchLeak vulnerability turns M365 Copilot into a one-click data exfiltration weapon, LiteLLM gateway RCE added to CISA KEV, Infinite Campus breach exposes school staff records, and FortiBleed campaign cracks Fortinet admin credentials.

The Industrialization of Web Bots: How Automated Exploit Kits, Credential Stuffing, and AI-Driven Botnets Reshape Cyberattacks in 2026
Botnet operators now exploit vulnerabilities within hours of disclosure, exploit payloads bundled into single frameworks, credential stuffing drives a major share of breaches, and Layer 7 DDoS surges year-over-year. Here's how automated web bots operate — and how to defend against them.

LLM Prompt Injection: The #1 AI Security Threat in 2026
A comprehensive deep research analysis of the prompt injection landscape — from academic taxonomies and real-world CVEs (EchoLeak, Copilot RCE) to enterprise defense strategies and the emerging agent hijacking threat model.