Subscribe
Sign in
Home
Notes
Disclaimer
Contact
Consult
About
21:32
AI Agents Are Starting to Find Their Own Way Out
AI agents are escaping sandboxes, collaborating with each other, and finding new ways around security controls. Here’s what that means for AI security.
Aug 13
•
ToxSec
28
18
12
Black Hat 2026 AI Security: Agents, Escapes, and Machine-Speed Attacks
Agent frameworks, AI browsers, and a swarm of OpenAI evaluation agents that built themselves a message board
Aug 9
•
ToxSec
25
11
6
What If AI Security’s Biggest Risk... Isn’t?
Rank the risks on incident data alone and prompt injection drops off the list entirely. It still shipped at number one.
Aug 6
•
ToxSec
23
1
6
LLM Router Attacks: No Signature, No Detection, No Reference
How a malicious AI gateway swaps a tool call’s arguments after inference finishes, bypassing guardrails by construction instead of by persuasion.
Jul 30
•
ToxSec
22
1
8
Ignore Previous Instructions: From Meme to CVSS 9.3 [Special Guest Post]
The AI security bug nobody can patch, and the vendors know it.
Jul 28
•
ToxSec
and
Mohib Ur Rehman
21
10
12
Latest
Top
Discussions
Hacking Hugging Face to Cheat a Benchmark
GPT-5.6 Sol found a zero-day in a package registry proxy, escaped the eval sandbox, and went looking for the answer key in production.
Jul 26
•
ToxSec
26
13
4
11:07
GhostApproval: When the AI Approval Prompt Lies
A symlink attack against AI coding agents turns human-in-the-loop confirmation dialogs into a consent bypass, and the agent knows it’s lying.
Jul 23
•
ToxSec
26
6
10
Context Bombs: Defensive Prompt Injection Traps
A decoy secret loaded with text built to trip an AI attacker’s own safety training, so the model refuses itself.
Jul 19
•
ToxSec
26
6
9
Canary Tokens for Prompt Injection Detection
The cheapest tripwire in LLM security. Drop a high-entropy string in context, watch for it in output, and let the extraction attempt announce itself.
Jul 16
•
ToxSec
28
1
8
The Lethal Trifecta Broke Three Agents in 2026
Untrusted input, sensitive access, and the power to act. Hold all three in one agent and the exfil chain writes itself, no zero-day required.
Jul 10
•
ToxSec
23
1
6
Cisco’s Agent Runtime SDK Bakes Security Into the Build
Build-time policy enforcement now ships across Bedrock AgentCore, Vertex, Azure AI Foundry, and LangChain. The OpenClaw RCE never touched the model.
Jul 7
•
ToxSec
21
3
6
The AI Agent Kill Switch Most Teams Don’t Actually Have
Frontier models sabotage their own shutdown, and the fix everyone reaches for first makes it worse. Here’s how to build one that holds.
Jul 4
•
ToxSec
21
14
10
See all
ToxSec - AI and Cybersecurity
Security for a world run by machines that lie.
Subscribe
Recommendations
View all 32
SK NEXUS
Saqib Tahir
Learn Grow Monetize
Katharine Gallagher
Cash & Cache
Raghav Mehra
Heuristics vs Traps
Mila Agius
AI Family Network
Manisha
ToxSec - AI and Cybersecurity
Subscribe
About
Archive
Recommendations
Sitemap
This site requires JavaScript to run correctly. Please
turn on JavaScript
or unblock scripts