<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>DiggingBeagle</title><link>https://diggingbeagle.com/</link><description>Evidence-first AI-security research</description><item><title>Anthropic&#39;s September report shows agentic cyber operations moving from assistance to throughput</title><link>https://diggingbeagle.com/news/anthropic-september-report-shows-agentic-cyber-operations-moving-from-assistance-to-throughput/</link><guid isPermaLink="true">https://diggingbeagle.com/news/anthropic-september-report-shows-agentic-cyber-operations-moving-from-assistance-to-throughput/</guid><description>The cases are still built from familiar intrusion primitives, but reconnaissance, exploit development and data processing are increasingly delegated to persistent agent workflows.</description><pubDate>Thu, 10 Sep 2026 00:00:00 GMT</pubDate></item><item><title>Stolen AI credentials are now showing up as attacker infrastructure</title><link>https://diggingbeagle.com/updates/stolen-ai-credentials-are-now-showing-up-as-attacker-infrastructure/</link><guid isPermaLink="true">https://diggingbeagle.com/updates/stolen-ai-credentials-are-now-showing-up-as-attacker-infrastructure/</guid><description>Anthropic&#39;s September report documents resale, victim-funded compute and attribution cover as separate values of compromised AI access.</description><pubDate>Thu, 10 Sep 2026 00:00:00 GMT</pubDate></item><item><title>Check Point demonstrates a cross-account task channel inside ChatGPT sandboxes</title><link>https://diggingbeagle.com/news/check-point-demonstrates-cross-account-task-channel-inside-chatgpt-sandboxes/</link><guid isPermaLink="true">https://diggingbeagle.com/news/check-point-demonstrates-cross-account-task-channel-inside-chatgpt-sandboxes/</guid><description>A shared internal package service became a covert path between code-execution environments from different accounts.</description><pubDate>Tue, 08 Sep 2026 00:00:00 GMT</pubDate></item><item><title>OpenAI says agent-spam disclosure criteria are still being defined</title><link>https://diggingbeagle.com/updates/openai-says-agent-spam-disclosure-criteria-are-still-being-defined/</link><guid isPermaLink="true">https://diggingbeagle.com/updates/openai-says-agent-spam-disclosure-criteria-are-still-being-defined/</guid><description>OpenAI acknowledged the public-wiki activity and its Chief Scientist separately called for stronger shared safety bars.</description><pubDate>Sun, 06 Sep 2026 00:00:00 GMT</pubDate></item><item><title>Researchers reconstruct an OpenAI agent message board on the public web</title><link>https://diggingbeagle.com/news/researchers-reconstruct-openai-agent-message-board-on-the-public-web/</link><guid isPermaLink="true">https://diggingbeagle.com/news/researchers-reconstruct-openai-agent-message-board-on-the-public-web/</guid><description>The report found roughly 18,000 retained public posts from autonomous agents sharing answers and bypass ideas during a web-research task.</description><pubDate>Fri, 04 Sep 2026 00:00:00 GMT</pubDate></item><item><title>KASS moves smart-contract security from detection to executable exploit testing</title><link>https://diggingbeagle.com/news/kass-moves-smart-contract-security-from-detection-to-executable-exploit-testing/</link><guid isPermaLink="true">https://diggingbeagle.com/news/kass-moves-smart-contract-security-from-detection-to-executable-exploit-testing/</guid><description>A July paper reports a multi-agent system that retrieves audit knowledge, generates Foundry exploits and repairs or replans them against execution feedback.</description><pubDate>Fri, 17 Jul 2026 00:00:00 GMT</pubDate></item><item><title>MCP Python SDK advisories expose task ownership and browser-origin gaps</title><link>https://diggingbeagle.com/news/mcp-python-sdk-advisories-expose-task-ownership-and-browser-origin-gaps/</link><guid isPermaLink="true">https://diggingbeagle.com/news/mcp-python-sdk-advisories-expose-task-ownership-and-browser-origin-gaps/</guid><description>Two narrowly scoped advisories show why agent control planes still need ordinary session authorization and transport security.</description><pubDate>Thu, 16 Jul 2026 00:00:00 GMT</pubDate></item><item><title>Check Point turns an AI-generated malware idea into a browser-only ransomware proof of concept</title><link>https://diggingbeagle.com/news/check-point-turns-ai-generated-malware-idea-into-browser-only-ransomware-poc/</link><guid isPermaLink="true">https://diggingbeagle.com/news/check-point-turns-ai-generated-malware-idea-into-browser-only-ransomware-poc/</guid><description>A controlled Android demonstration used legitimate File System Access permissions to encrypt selected images without a native payload.</description><pubDate>Wed, 01 Jul 2026 00:00:00 GMT</pubDate></item></channel></rss>