Tag:AI
OpenAI, Anthropic, Meta and the UK AI Security Institute have each now disclosed agents reaching systems they were never authorised to touch. Luke Potter revisits his original AI agent security analysis with the fuller evidence, and what it demands of containment design.
The OpenAI agents didn’t go rogue. They went out of scope, together.
OpenAI, Anthropic, Meta and the UK AI Security Institute have each now disclosed agents reaching systems they were never authorised…
You can’t secure what you can’t see.
OpenAI's own agent breached Hugging Face's infrastructure without ever going rogue. It just stayed on-task and found the gaps in…
When the API Lies – How RAID Discovered a Critical Privilege Escalation by Reading JavaScript
A privilege escalation vulnerability hid behind a broken endpoint and a misleading error message. Here's how RAID's agentic system decompiled…
The OpenAI agent didn’t “go rogue”. The containment failed.
I’ve purposely held back from commenting on the OpenAI and Hugging Face incident. The early coverage was predictably dramatic. AI…
How RAID found unauthenticated customer data in a retail GraphQL API
CovertSwarm's web testing agent identified a critical broken access control vulnerability in a retail subscription platform's GraphQL middleware. The platform…
CovertSwarm is a founding signatory of the CREST AI Charter
CovertSwarm has become a founding signatory of the CREST AI Charter, endorsing nine principles for responsible AI use in cybersecurity.
Frontier AI models are exciting.
CovertSwarm COO Luke Potter on why frontier AI is genuinely exciting, why most of the conversation is asking the wrong…
AI Sharpens the Question. It Doesn’t Change the Answer.
The cyber security industry has spent decades selling findings instead of answers. AI tools like Mythos make the problem faster…
Mythos found a $20,000 bug. It won’t tell you who’s already inside.
Anthropic's Mythos has dominated the security conversation this week. But the debate about whether it's overhyped is the wrong argument.…