LIVE FEED
CRITICAL AI-Generated Scripts Exploit Siemens S7 PLCs in US Infrastructure // FIRST LOOK CUSTODY Framework Ships to Constrain AI Agents in Enterprise Networks // FIRST LOOK OpenAI Launches Private Safety Processing for Zero-Data Monitoring // FIRST LOOK smolvm Brings Hardware-Isolated Sandboxing for AI Code Execution // FIRST LOOK OpenAI Adds Mandatory RL Training Safeguards for Frontier Models // HIGH AI Mind Viruses Spread Between Agents via Prompt Files // FIRST LOOK Fortinet Acquires Virtue AI to Secure AI Models and Agents // HIGH CVE-2026-24301: Microsoft Copilot One-Click Data Exfiltration // CRITICAL CVE-2026-64849: MLflow SSRF Exploited to Steal Cloud Credentials // HIGH CoSnitch Attack Forces Copilot to Expose Its Own Architecture //
SkillCloak Bypasses AI Agent Skill Scanners at 90% Rate

SkillCloak Bypasses AI Agent Skill Scanners at 90% Rate

ATLAS OWASP HIGH Significant risk · Prioritise patching ▲ 8.5 The Hacker News

Researchers at Hong Kong University of Science and Technology have demonstrated that static scanners used to vet malicious AI agent 'skills' — modular add-ons for agents like Claude Code and OpenAI Codex — can be systematically bypassed using a tool called SKILLCLOAK. The technique leverages either character-substitution obfuscation or self-extracting packing into scanner-ignored directories like .git/, achieving evasion rates above 90% across all eight tested scanners. The same research team also developed SKILLDETONATE, a runtime behavioral sandbox that catches most of the threats static analysis misses.

◉ AI THREAT BRIEFING

Stay ahead of the threat.

Twice-weekly digest of critical AI security developments — every story mapped to MITRE ATLAS and OWASP LLM Top 10. Free.

No spam. Unsubscribe anytime.