Topics
Twenty-six topics, grouped by the part of the field they belong to. Topics with a reading path are marked.
Offense
AI-enabled intrusion
Attackers using AI models or agents to carry out intrusions.
Latest record 8 records · 1 findingsAI malware
Malware that calls or embeds language models, or that AI systems helped build.
Latest record 3 records · 0 findingsFraud & social engineering
Phishing, scams, and employment fraud carried out with AI.
Latest record 6 records · 3 findingsExploit development
Building working exploits with AI assistance or autonomy.
Latest record 19 records · 4 findingsThreat intelligence
Provider and vendor reports on how attackers use AI.
Latest recordOffense & defense
Measurement
Capability evaluation
How the cyber capability of models and agents is measured.
Latest record 27 records · 12 findings · reading pathEvaluation validity
Whether cyber evaluations measure what they claim: compute budgets, cheating, contamination, staleness.
Latest record 3 records · 0 findingsOpen-weight diffusion
How quickly capability reaches openly available models.
Latest recordGovernance
Capability thresholds
Lab and government thresholds that trigger safeguards or gate release.
Latest record 12 records · 0 findingsAccess controls
Trusted access programs, tiered access, and verification for cyber use.
Latest record 13 records · 2 findingsJailbreaks & safeguards
Model-level safeguards against cyber misuse and attempts to bypass them.
Latest record 34 records · 1 findingsStandards & guidance
NIST, OWASP, MITRE, CISA, NCSC, and similar guidance.
Latest record 13 records · 0 findingsRegulation & policy
Laws, executive actions, and export controls.
Latest record 18 records · 2 findingsIncident reporting
How AI incidents are disclosed, recorded, and corrected.
Latest recordAgent security
Prompt injection
Instructions smuggled into an agent through the content it reads.
Latest record 30 records · 6 findings · reading pathTools & MCP
Risks in the tools, MCP servers, plugins, and connectors agents use.
Latest record 14 records · 3 findingsAgent supply chain
Model artifacts, packages, extensions, and coding agents as supply-chain links.
Latest record 23 records · 6 findings · reading pathSandbox & containment
Keeping agents inside their execution and network boundaries.
Latest record 39 records · 3 findingsData exfiltration
Data leaving through an agent, by attack or by the agent’s own choice.
Latest record 15 records · 2 findingsMulti-agent security
Failures and attacks that spread between cooperating agents.
Latest record 22 records · 8 findings · reading pathMonitoring & control
Monitors, control protocols, and oversight of capable agents.
Latest recordDefense
Autonomous defense
Agents that detect, contain, and respond without waiting for a person.
Latest record 22 records · 3 findings · reading pathVulnerability repair
Automated patching and how to verify that a patch worked.
Latest record 12 records · 4 findingsSOC automation
Triage, detection engineering, and analyst assistance.
Latest record