August 1, 2026
- Trail of Bits detailed a run of offensive AI research alongside its $3M DARPA AIxCC win. The team says it hijacked multi-agent systems, exfiltrated Gmail data through Perplexity's Comet browser, and hid prompt injection inside images — all documented publicly, with the AIxCC prize going to an autonomous vuln-finding-and-patching system (Trail of Bits).
· AI & Offensive Security
in When the Attacker Is a Model: AI Lands on Both Sides of the Fight
July 30, 2026
- Perplexity released Numbat, an open-source endpoint-visibility suite for AI agent activity across macOS/Linux/Windows — normalized telemetry, local rule-based detection, optional pre-action blocking, and forensic reconstruction. Useful for anyone building purple-team coverage of agentic workloads. Perplexity Research, GitHub
· New Tools & Releases
in OpenAI's Rogue Agent Widens: Four More Companies Caught in the Blast Radius
July 17, 2026
- Germany's media regulators issued a first-of-its-kind ruling classifying Google AI Overviews and Perplexity as the companies' own content under the State Media Treaty — not neutral search results. Both have a month to appeal (The Decoder).
· Industry & Policy
in Live SonicWall Exploitation, a New C2 Release, and AI Agents Tricked Into Running Attacker Commands
July 3, 2026
- CERT.dk flagged a malicious "Perplexity" browser extension that captured user searches and keystrokes. CERT.dk.
· AI & Model Security
in Ransomware on Autopilot, and a Pile of Critical Bugs Under Fire
July 1, 2026
- LayerX's BioShocking prompt-injection technique convinces AI browsers they're in a fictional game and gets them to hand over user credentials — successful against six assistants including ChatGPT Atlas, Perplexity Comet, and Claude's browser extension. BleepingComputer, The Hacker News
· AI & Model Security
in CitrixBleed Returns: watchTowr Discloses a New NetScaler Pre-Auth Memory Overread