CybersecurityAgents9 min reading time

AWS, Google, and Vercel Agent Flaws Let Attackers Trigger Tools Without Running the Model

The Hacker News
Read full post
Security vulnerabilities in agent infrastructures from AWS, Google, and Vercel allowed attackers to trigger agent tools without model authorization, bypassing system prompts and guardrails. AWS has fixed its AgentCore issue, Google updated ADK to version 2.5.0, and Vercel patched its AI SDK harness packages. These flaws vary in attack conditions and require different attacker capabilities, but are limited to the tools each agent can access.

More in Cybersecurity

Cybersecurity10 min read

Anthropic Details Disrupted Claude Misuse Across Seven Harm Areas

Covered by 4 sources
Cybersecurity4 min read

Sam Altman met with top power utilities about securing the electrical grid. He offered one possible solution: OpenAI's cyber services.

Covered by 2 sources
Cybersecurity6 min read

Anthropic reveals rogue AI agents hate CAPTCHAs, just like you

TechCrunch