< Back to all clusters
[TECHNOLOGY] · United States, India · 2 sources

AI agents’ security flaws exposed by Meta hack and Anthropic cybercrime report

A recent hack of Meta’s AI‑driven support agent showed that attackers could change a user’s email address by simply matching the victim’s location with a VPN and issuing a direct request. The exploit required no sophisticated prompt‑injection tricks, underscoring missing guardrails in AI agents. Meta confirmed the vulnerability has been fixed but gave no comment on how it slipped through testing. Security experts say AI agents need rigorous red‑teaming and built‑in safeguards such as mandatory security questions.

Anthropic’s new cybersecurity report, based on 832 accounts banned for malicious activity, found that AI tools are now being used deep within cyber‑attack chains. About 67% of the accounts employed AI for malware creation, while 6.5% leveraged it for lateral movement inside compromised networks. The study warns that AI assistance makes even low‑skill actors more dangerous and suggests the MITRE ATT&CK framework be updated to capture autonomous, AI‑directed behaviors. A state‑sponsored espionage operation highlighted in the report used an AI model to execute commands, exploit vulnerabilities, and steal credentials without human oversight.