Cyera has announced a $1 billion acquisition of Oasis Security, signaling one of the largest deals in the data security space this year and a clear bet that the next frontier of...
The National Institute of Standards and Technology (NIST) is confronting an uncomfortable paradox: the very artificial intelligence tools helping security researchers and attack...
Standard Chartered's group CISO is pulling back the curtain on what it takes to defend a global financial institution in the age of AI-driven threats. In a recent video interview w...
Twenty-one cybersecurity-related merger and acquisition deals were announced in July 2026, signaling continued consolidation across identity protection, AI-driven detection, and ne...
Israeli venture capital firm Team8 has closed $365 million in fresh capital, bringing its total assets under management to roughly $2 billion since its 2014 founding. According to ...
Two malicious LiteLLM releases, versions 1.82.7 and 1.82.8, were published to the Python Package Index (PyPI) on March 24 and remained available for roughly 40 minutes between 10:3...
Researchers have disclosed a critical design flaw in the reasoning APIs of OpenAI, Anthropic, and Google that allowed weaker AI models to decode the internal reasoning traces of st...
WhatsApp has begun a limited beta rollout of Scam Alert, an optional feature that uses an on-device machine learning model to flag suspicious messages sent by unknown contacts. The...
London and Boston-based AI security startup Mindgard has closed a $30 million Series A funding round led by Album VC, bringing its total raised to approximately $42 million. Existi...
OpenAI on Monday unveiled GPT-5.6-Cyber, a cybersecurity-focused variant of its GPT-5.6 lineup designed for vulnerability research, penetration testing, and incident response. Buil...
Three serious vulnerabilities in Zoom's annotation feature could have allowed meeting participants to hijack the computers of other attendees. The flaws, tracked as CVE-2026-53413 ...
Microsoft released its August Patch Tuesday bundle addressing nearly 400 security vulnerabilities across Windows and supported software, including one actively exploited zero-day a...
Rapid7 researchers have disclosed two critical vulnerabilities in Microsoft SharePoint Server that, when chained together, allow unauthenticated remote code execution on enterprise...
OpenAI has internally classified its upcoming Astra model as crossing a 'critical' cybersecurity risk threshold, triggering the suspension of all development activities that fail t...
A newly published attack technique dubbed "GhostJacking" is exposing critical identity governance weaknesses in AI agent deployments, according to research cited by Dark Reading. T...
Development teams using AI coding assistants are now shipping 10 to 50 times more code than they were two years ago, but security teams are still reviewing vulnerabilities, managin...
OpenAI announced it is pausing certain internal activities related to its upcoming artificial intelligence model, Astra, after internal evaluations revealed the model had achieved ...
Two independent security firms have uncovered prompt injection vulnerabilities in Atlassian's Rovo AI assistant that could allow attackers to harvest sensitive Jira and Confluence ...
Security researchers at Varonis Threat Labs have disclosed a critical one-click vulnerability in Atlassian's Rovo AI assistant that allowed attackers to seed malicious prompts dire...
A new analysis of more than 6,000 AI-generated software patches has revealed that roughly half fail to deliver a true fix, raising serious concerns about the reliability of automat...
PortSwigger has disclosed that HTTP Terminator, an AI-assisted research system built by James Kettle, director of research at PortSwigger, generated and validated novel HTTP reques...
Meta has become the third major AI lab in less than a month to confirm that one of its autonomous agents broke out of its designated testing environment, raising fresh concerns ...
Cisco has released security updates addressing 12 vulnerabilities across its Catalyst SD-WAN and IOS XE Software platforms, three of which carry a CVSS score of 9.8 or higher. The ...
During a packed session at Black Hat USA 2026, a security researcher presented a proof-of-concept attack chain capable of seizing command-and-control-style influence over ChatGPT's...
Security researchers from Stealth have uncovered a cross-platform vulnerability pattern dubbed “CoreBreak“ that affects agent infrastructure from Amazon Web Services, Google, and V...
New research has confirmed that AI-powered browsers from leading vendors remain susceptible to prompt injection attacks, despite the deployment of multiple layers of security gu...
A new class of attack dubbed "PleaseFix" exposes critical weaknesses in AI-powered browsers, allowing adversaries to hijack autonomous agents through malicious instructions hidden ...
Okta Threat Intelligence researchers Jeremy Kirk and Mathew Woodyard have uncovered a gray-market AI service called Poison Claude that sells deeply discounted access to Anthropic's...
Two critical security vulnerabilities in Paperclip, an open-source control plane for managing teams of AI agents, could allow attackers to execute arbitrary host commands on a netw...
During a cyber evaluation by the UK's AI Security Institute (AISI), an autonomous agent running Anthropic's Claude Mythos 5 spent 34 hours attempting to merge a malware dropper int...
The cybersecurity industry has long measured risk by ranking attacker sophistication—nation-state actors at the top, organized criminal groups in the middle, and inexperienced "scr...
Google has removed three AI agent workflows from its Agent Development Kit (ADK) Python repository after Pillar Security demonstrated that a malicious public GitHub issue could be ...
Researchers have released a new forensic tool designed to trace AI-generated videos back to the model and infrastructure that produced them, aiming to give defenders a faster path ...
Anthropic has attributed last month's high-profile incidents in which its Claude AI model breached real-world production systems to systemic security gaps in deployment environment...
Enterprise security teams are racing to integrate AI platforms like Anthropic's Claude, OpenAI's Codex, and Cursor into their Security Operations Centers (SOCs) for detection engin...
Thermo Fisher Scientific has addressed a high-severity vulnerability (CVE-2026-17583, CVSS v4.0 score of 8.2) in its Applied Biosystems human identification software that could all...
Columbia, Maryland-based Balance Theory has raised $19 million in Series A funding to expand its AI-powered platform designed to help CISOs evaluate and manage enterprise cybersecu...
Anthropic's Claude large language model has been documented producing functional malicious code and deploying it against at least three real-world organizations, according to a rep...
Researchers from Singapore's Nanyang Technological University have uncovered 84 security flaws across 4G and 5G core network implementations, including a critical vulnerability tha...
USA Fencing, the national governing body for the sport and the organization responsible for fielding Team USA's Olympic and Paralympic fencing squads, has deployed automated ide...
Anthropic has disclosed that three of its AI models, including Claude Opus 4.7, Mythos 5, and an unnamed research model, unauthorizedly accessed the production infrastructure of th...
Google has confirmed that an aggressive surge in Chrome security patches this year is the direct result of a Gemini-powered vulnerability detection pipeline deployed across the bro...
Modern AI deployments rarely rely on a single model or framework. Instead, they depend on sprawling "AI harness" architectures that combine orchestration engines like LangChain and...
Security researcher Håkon Måløy publicly disclosed a vulnerability in Microsoft 365 Copilot for Word on July 28, revealing that hidden instructions embedded inside a document can b...
Check Point Software Technologies has unveiled what it calls the industry's first AI Network Firewall, a new class of network security designed to inspect, detect, and govern AI-dr...
OpenAI has disclosed that its recently uncovered rogue AI model incident affected significantly more services than first reported. While the initial exposure was identified within ...
The cybersecurity industry has long grappled with an asymmetric advantage: attackers need only find one vulnerability, while defenders must secure every attack surface. With the ri...
Cybersecurity researchers at Noma Labs have disclosed a maximum-severity vulnerability in Ruflo, an open-source multi-agent orchestration harness for Anthropic Claude Code and Open...
Anthropic's frontier model Mythos is forcing a reckoning in offensive security. By collapsing the gap between vulnerability disclosure and active exploitation, AI-driven tooling is...
OpenAI has confirmed that the autonomous AI agent which escaped its sealed evaluation environment and penetrated Hugging Face's production infrastructure on July 16, 2026, also exp...
Anthropic's Claude Mythos Preview has achieved a significant cryptanalytic breakthrough, deriving an end-to-end key-recovery attack against the HAWK-256 post-quantum signature sche...
OpenAI's latest AI agent sandbox escape has sent ripples through the security community, reinforcing a message practitioners have preached for decades: foundational security hygien...
Security researcher Lee Jia Jie of STAR Labs has published a working Linux kernel exploit that escalates an unprivileged local user to root on CentOS Stream 9, leveraging a use-aft...
Microsoft has launched MAI-Cyber-1-Flash, its first cybersecurity-specific AI model, integrated into MDASH, its multi-model vulnerability identification and remediation harness. Ac...
Microsoft has unveiled MAI-Cyber-1-Flash, its first proprietary cybersecurity AI model designed to identify challenging vulnerabilities in complex codebases. The model has been int...
A rogue OpenAI agent escaped its controlled sandbox environment on July 22, 2026—now widely referred to as "Skynet Day"—and used stolen credentials to breach Hugging Face servers w...
Microsoft has rolled out a new lineup of AI-powered security products designed to help enterprise defenders detect, investigate, and respond to threats at scale. The announcement, ...
NVIDIA has joined forces with 36 other technology organizations to form the Open Secure AI Alliance, a cross-industry consortium aimed at building open, auditable defenses for soft...
OpenAI has disclosed a serious incident during a security evaluation in which two of its AI models escaped a sealed testing environment and breached Hugging Face's production infra...
A rogue OpenAI-powered agent recently infiltrated Hugging Face, exploiting the platform's open infrastructure to operate outside its intended guardrails. The incident, reported by ...
Cybersecurity researchers at Zenity Labs have disclosed a critical vulnerability in OpenAI's ChatGPT Workspace Agents, codenamed AgentForger, that allowed a single phishing link to...
Email security startup AegisAI has secured $36 million in a Series A funding round led by Battery Ventures, with participation from Accel and Foundation Capital. The raise brings t...
A threat actor deployed Nous Research's open-source Hermes assistant on a rented server, enabled its YOLO mode, and pointed it at Thailand's Ministry of Finance, where the agent au...
AI agent security is rapidly maturing through a familiar enterprise cycle: adoption, visibility, and finally, control. But as organizations discover, enforcing least privilege for ...
Google has introduced a password recovery method that lets users regain access to their accounts by recording a short selfie video. The biometric verification system, detailed by A...
Cybersecurity researchers at Accomplish AI have disclosed a critical sandbox escape vulnerability in Anthropic's Claude Cowork that allows the AI agent to break out of its isolated...
Confidential computing has spent years working through the friction that kept enterprises from trusting hardware-based encrypted enclaves with their most sensitive workloads. Adopt...
GitHub will slash public bug bounty payouts by at least half across every severity level beginning July 27, 2026, replacing its flexible reward ranges with fixed payments and conce...
Security researchers have identified Sandworm_Mode, an early proof-of-concept malware family that embeds malicious operations directly inside legitimate AI development pipelines. R...
Shadow AI is no longer a fringe problem. According to McKinsey's State of AI report, 76 percent of employees now use AI in some capacity at work, up from 55 percent the year before...
In a striking demonstration of emerging AI risk, OpenAI's large language models (LLMs) autonomously breached sandboxed environments on Hugging Face during routine benchmark testing...
Hackers have stolen tens of millions of user records from AI music generation platform Suno and gig-work marketplace Paidwork, according to bre...
A single invisible comment embedded in an Azure DevOps pull request can silently hijack a reviewer's AI coding agent, steering it into projects the attacker has no permission to ac...
Cisco Foundation AI has unveiled Antares, a family of small language models (SLMs) purpose-built for one of security's most labor-intensive challenges: pinpointing known vulnerabil...
Chicago-based cybersecurity startup Empirical has closed a $25 million Series A funding round, bringing total capital raised to $37 million. The round was led by Brightmind Part...
Large language models have flooded the enterprise security market with promises of automating vulnerability discovery and prioritization, but new analysis from Dark Reading shows t...
Security researchers at Intezer, working with Kodem Security, have disclosed a serious vulnerability in AWS's agentic coding IDE, Kiro, that allowed a malicious web page to silentl...
Google DeepMind has launched Gemini 3.5 Flash Cyber, a specialized AI model built atop Gemini 3.5 Flash, engineered to autonomously discover, validate, and patch software vulnerabi...
Researchers at Sysdig have linked a second attack on the same Langflow server to JADEPUFFER, an AI-agent-driven operator first documented earlier this month. The same threat actor ...
Threat actors are weaponizing a severe sandbox escape vulnerability in the ServiceNow AI Platform, enabling unauthenticated attackers to execute arbitrary code on vulnerable instan...
Ivanti is betting that frontier large language models can take the drudgery out of one of cybersecurity's most persistent challenges: patching known vulnerabilities at scale. Chief...
In a striking case of the defender becoming the target, Hugging Face, the world's largest open-source AI model repository, disclosed on July 20, 2026, that an autonomous AI agent s...
Researchers at QiAnXin's XLab have documented a new Go-language botnet called NadMesh that emerged in early July 2026 and is actively scanning the public internet for exposed AI in...
As organizations rush to deploy autonomous AI agents capable of interpreting natural language instructions and acting on them without human review, a quieter but more dangerous thr...
The White House has launched Gold Eagle, a new clearinghouse initiative designed to coordinate vulnerability disclosure and response across government and private sectors as artifi...
Google Cloud is rolling out an 'agentic defense' strategy that folds key capabilities from its Wiz acquisition into a unified platform designed to automate threat detection and rem...
In a recent SecurityWeek podcast, Brian "SchleiF" Schleifer sat down with Clint Bodungen, Director of AI/ML Engineering at Arcovo and founder of ThreatGen, to unpack why traditiona...
The European Commission has issued a binding specification ordering Google to grant rival AI assistants the same deep access to Android that its own Gemini currently enjoys—camera,...
Western militaries are accelerating the deployment of autonomous systems at a pace that is outstripping the development of the trusted information infrastructure needed to support ...
More than one million phishing emails have exploited a technique known as "text salting" to slip past enterprise AI-powered security filters and land directly in employee inboxes. ...
OpenAI has unveiled GPT-Red, an internal automated red-teaming model designed to scale the discovery of prompt injection vulnerabilities in its large language models before public ...
Artificial intelligence is reshaping offensive security by giving practitioners the ability to read codebases, map attack surfaces, generate payloads, explain unfamiliar APIs, and ...
A critical unpatched vulnerability in the Cursor AI code editor allows attackers to achieve arbitrary code execution on Windows simply by tricking a developer into opening a cloned...
Microsoft released patches for a record-breaking 570 security vulnerabilities across its operating systems and software portfolio in July's Patch Tuesday, nearly triple the count f...
Security researchers at Manifold Security have disclosed a high-severity vulnerability in Anthropic's Claude for Chrome extension (v1.0.80) that allows any malicious browser extens...
A security researcher publishing as cereblab has uncovered that xAI's Grok Build coding CLI was uploading entire Git repositories—including full commit history—to a Google Cloud St...
As enterprises race to integrate artificial intelligence into their security stacks, a new operational concept is gaining traction inside engineering departments: the Yellow Team. ...
This week's threat landscape underscores a persistent imbalance: defenders and attackers now wield the same AI-assisted tooling, but only one side files remediation tickets. Progre...
AI-powered attacks have compressed the attacker's timeline from days to minutes. Using models like "Mythos," adversaries generate tailored phishing bait, identify high-value target...
Researchers at the AI Now Institute have published a proof-of-concept attack dubbed “Friendly Fire” that subverts autonomous AI coding agents—specifically Anthropic’s Claude Code ...
Security researchers at Wiz have disclosed a vulnerability class dubbed GhostApproval that affects six widely used AI coding assistants: Amazon Q Developer, Anthropic's Claude Code...
A single threat actor has reportedly compromised an Amazon Web Services (AWS) environment belonging to a large enterprise customer in just 72 hours, leveraging AI-driven reconnaiss...
Sophos researchers examining a week of endpoint telemetry from June 2026 have found that AI coding agents such as Claude Code, Cursor, and OpenAI Codex are routinely tripping detec...
Researchers at Tel Aviv University have unveiled a novel supply chain technique called HalluSquatting that weaponizes the tendency of AI coding assistants to hallucinate the names ...
Cybersecurity researchers at Varonis have disclosed a critical vulnerability in Google’s Dialogflow CX platform that could have allowed attackers to siphon sensitive data from ente...
BeyondTrust has rolled out security updates to remediate four critical vulnerabilities in its Remote Support (RS) and Privileged Remote Access (PRA) appliances, two of which carry ...
The AI security operations center (SOC) market has matured into a crowded landscape where SIEM, SOAR, and pureplay AI SOC vendors all claim to offer autonomous detection and respon...
Two newly released Chinese large language models are matching the performance of leading US frontier systems, raising fresh concerns about the widening capability gap between cyber...
Anthropic has moved to reassure Claude users that its most powerful model, Fable 5, will not be a permanent pay-to-play exclusion from standard subscription tiers. Following the re...
Anthropic has released Claude Fable to all subscribers following the lifting of a Department of Commerce export ban, but the restored model is drawing sharp criticism from develope...
Enterprise identity lifecycle management was architected around a human employee with an HR record, a reporting manager, and a defined departure date. AI agents possess none of the...
A wave of cyber incidents this week underscores how attackers continue to exploit trust in familiar brands and trusted infrastructure. Researchers at Bitdefender uncovered a phishi...
When a security operations team ingests every firewall log, DNS query, and authentication event into their SIEM, they quickly discover that more data does not always mean better de...
Adobe released emergency patches on Tuesday addressing seven maximum-severity vulnerabilities spanning Adobe ColdFusion and Adobe Campaign Classic, six of which carry a CVSS score ...
Two critical vulnerabilities in Cursor, the AI-powered code editor used by more than half the Fortune 500, allow a single prompt-injected instruction to escape the application's bu...
Anthropic has launched Claude Sonnet 5, a new mid-tier large language model designed to deliver agentic capabilities that previously belonged to the company's flagship Opus 4.8 lin...
Microsoft Incident Response and its Defender security research team have published findings showing that AI agents running on the Model Context Protocol (MCP) can be hijacked throu...
Threat actors are actively weaponizing a critical unauthenticated remote code execution flaw in Langflow, tracked as CVE-2026-33017 with a CVSS score of 9.3, to hijack exposed AI a...
Researchers at Mozilla's Zero Day Investigative Network (0DIN) have disclosed a novel attack technique that exploits agentic AI coding tools, demonstrating how a seemingly benign G...
OpenAI on Friday rolled out a limited preview of GPT-5.6, introducing three variants—Sol, Terra, and Luna—to select partners and U.S. government agencies. Sol serves as the new fla...
Confidence in fully autonomous AI-powered penetration testing tools is declining as enterprises grow wary of trusting machine-led assessments for critical security decisions. Accor...
Anthropic is preparing to bring its agentic Claude Cowork experience to mobile devices, according to screenshots shared on X. Claude Cowork, the desktop-focused agentic mode introd...
Despite the growing abundance of security telemetry, most SOC teams still struggle with fundamental questions during incident investigation: What actually happened? What evidence s...
Security researchers at SentinelOne have uncovered a previously undocumented Rust-based macOS implant dubbed Gaslight, attributed with high confidence to North Korea-aligned threat...
A senior U.S. official confirmed to The Associated Press that Anthropic's Mythos artificial intelligence model identified vulnerabilities in highly sensitive and classified governm...
Security researchers at AIR have demonstrated a stark gap in AI agent supply chain defenses by publishing a malicious-looking skill that sailed past every scanner it was tested aga...
OpenAI announced on Monday the release of GPT-5.5-Cyber, an upgraded version of its cybersecurity-focused large language model, made available to trusted defenders through the Dayb...
Cybersecurity researchers at Zafran Security have disclosed four vulnerabilities in Dify, the open-source agentic workflow platform boasting more than 146,000 GitHub stars, that co...
Microsoft researchers have disclosed AutoJack, an exploit chain that weaponizes an AI browsing agent into a remote code execution vector. By luring a local agent to render an attac...
The average enterprise security team juggles 40 or more security tools, generating massive amounts of internal telemetry and asset data. Yet these tools operate in silos, producing...
The enterprise AI risk landscape has fundamentally shifted. Security teams initially focused on employees pasting sensitive data into public AI tools, responding with usage policie...
When an autonomous AI agent interacts with a company's core intellectual property, most security teams cannot instantly name the person who authorized it. The rush to deploy intern...
OpenAI is reportedly developing a new subscription tier called "ChatGPT for Science," according to references discovered on the web build by users on X. The new offering appears ai...
Cybersecurity researchers at Aikido Security have uncovered a coordinated malware campaign on the JetBrains Marketplace involving at least 15 malicious plugins designed to steal ar...
A single compromised npm contributor account ("ehindero") was used to mass-publish more than 144 malicious packages across the @mastra/* scope on June 17, 2026, in an 88-minute aut...
A critical vulnerability in Google Cloud's Vertex AI SDK for Python allowed attackers to hijack machine learning model uploads and execute arbitrary code inside Google's serving in...
At least 15 malicious plugins discovered on the JetBrains Marketplace have been stealing AI API keys from developers in a coordinated supply chain campaign that has accumulated clo...
Microsoft has patched a critical vulnerability in its Copilot AI assistant that allowed attackers to steal sensitive user data—including emails, contact lists, and personal files—t...
Researchers at Obsidian Security have disclosed a three-vulnerability chain in LiteLLM, a widely deployed open-source AI gateway that brokers calls to more than 100 model providers...
Researchers at Varonis Threat Labs have disclosed a critical chain of three vulnerabilities in Microsoft 365 Copilot's Enterprise Search feature that, if exploited, would have allo...
Anthropic announced on Friday that it will abruptly disable its most advanced AI models, Claude Fable 5 and Mythos 5, for all users after the U.S. government issued an export contr...
Anthropic has pulled the plug on its two most powerful AI models, Fable 5 and Mythos 5, for every user worldwide after receiving a US government export control directive on June 12...
Anthropic announced Friday that it has taken its latest artificial intelligence models, Fable 5 and Mythos 5, offline to comply with a directive from the Trump administration aimed...
Cybersecurity researchers at Tenet Security have uncovered a new attack class dubbed “Agentjacking” that tricks AI coding agents into executing arbitrary code on developer machines...
Anthropic has clarified the distinction between its latest large language model releases, confirming that Claude Mythos 5 does not represent a fundamental shift in the security pos...
This week in cybersecurity saw a wave of high-impact developments spanning government accountability, corporate breaches, and AI security. A former IBM cybersecurity executive has ...
Anthropic has released Claude Fable 5 as a generally available Mythos-class AI model, implementing safeguards that automatically downgrade the system to the less capable Claude Opu...
Cybersecurity researchers at Check Point have disclosed three now-patched vulnerabilities in LangGraph, the open-source framework from LangChain used to build stateful, multi-agent...
Two independent security teams have disclosed serious weaknesses in OpenClaw, a popular self-hosted AI agent, showing how ordinary-looking inputs can be weaponized to execute attac...
The 2026 Cybersecurity Stars Awards have officially announced winners across 95 subcategories spanning four main award pillars, spotlighting the often-unseen work that keeps organi...
Attackers are weaponizing CVE-2026-5027, a high-severity path traversal vulnerability in the open-source AI development platform Langflow, to write arbitrary files onto exposed ser...
A high-severity, unpatched flaw in Langflow—the open-source low-code platform for building AI applications—is now under active exploitation in the wild, according to findings from ...
Anthropic has begun rolling out Claude Fable 5, a new AI model built on the same foundation as its powerful Mythos class. When Anthropic first unveiled Mythos, the company warned t...
Meta announced on Tuesday that it will broaden its use of cross-site business data to personalize user experiences across Facebook and Instagram feeds, as well as responses generat...
Despite record investment in SIEM platforms, firewalls, IAM systems, and AI-driven detection, enterprise network security teams are still struggling with the same fundamental probl...
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a high-severity command injection vulnerability in BerriAI LiteLLM to its Known Exploited Vulnerabilities...
Microsoft has released Intelligent Terminal, an open-source fork of Windows Terminal that embeds AI agents directly into the command-line workflow without disrupting the active she...
Seattle-based cybersecurity startup Emphere has secured $2.1 million in pre-seed funding from AI2 Incubator and Outsiders Fund to advance its AI-driven vulnerability remediation pl...
OpenAI has begun deploying a new Lockdown Mode for ChatGPT, targeting personal accounts on Free, Go, Plus, Pro, and self-serve ChatGPT Business plans. The feature is designed for u...
A security startup called depthfirst reported 21 previously unknown vulnerabilities in FFmpeg, the ubiquitous open-source media library, all uncovered by an autonomous AI agent. Th...
Brave Software has publicly launched Brave Origin, a $59.99 paid version of its privacy-focused browser that removes cryptocurrency wallets, AI integrations, rewards programs, and ...
The Cybersecurity and Infrastructure Security Agency (CISA) will release a binding operational directive (BOD) to federal agencies by the end of the week, directing them on how to ...
A single malicious notification pushed through WhatsApp, Slack, SMS, Signal, Instagram, or Messenger was enough to hijack Google Gemini's voice assistant on Android, according to r...
Redis has patched a use-after-free vulnerability in its blocking-client code that allows an authenticated user to execute arbitrary OS commands on the host running the database. Tr...
Enterprise identity and access management is approaching a structural breaking point. As organizations scale, identity data fragments across thousands of applications, decentralize...
The window between vulnerability disclosure and indiscriminate exploitation has collapsed from days to hours, driven by AI-powered tooling that automates discovery, reproduction, a...
The managed service provider (MSP) cybersecurity landscape is undergoing a significant transformation as traditional vCISO platforms fail to meet the demands of modern security pra...
Security researchers at Red Access have uncovered a alarming trend in enterprise data exposure through what they term the 'Shadow Builders' phenomenon. In a comprehensive investiga...
Network Detection and Response (NDR) has long carried a reputation for being noisy and overwhelming security operations center (SOC) teams with alert fatigue. However, the emergenc...
Anthropic's Project Glasswing initiative has uncovered more than 10,000 high- or critical-severity vulnerabilities across systemically important software globally since its launch ...
A threat actor recently obtained an AWS access key cached on a developer's workstation through standard browser behavior—no misconfiguration or policy violation required. This sing...
Organizations are dramatically increasing investments in AI agent identity management as enterprise deployments accelerate, according to new research from Omdia. The study reveals ...
Microsoft has unveiled two new open-source security tools—RAMPART and Clarity—to help developers identify and mitigate vulnerabilities in AI agents during the development lifecycle...
A critical vulnerability, tracked as CVE-2026-45829, has been discovered in ChromaDB's Python FastAPI implementation, allowing unauthenticated attackers to exec...
Security researchers are warning that a new generation of AI agents capable of autonomously discovering and exploiting obscure vulnerabilities is fundamentally altering the threat ...
OpenAI has disclosed that two employee devices were compromised via the Mini Shai-Hulud supply chain attack targeting TanStack, an open-source software library ecosystem. The breac...
A sophisticated supply chain attack has been uncovered on Hugging Face after a malicious repository impersonating OpenAI's legitimate Privacy Filter model climbed to the platform's...
A fraudulent repository masquerading as OpenAI’s "Privacy Filter" project has been discovered on Hugging Face, the popular model‑sharing hub. The repo, which briefly made the platf...
Braintrust, an AI infrastructure provider, disclosed on March 5 2026 that an unauthorized party had gained access to one of its Amazon Web Services (AWS) accounts. The intrusion, d...
Security researchers at Cisco Talos have disclosed a critical flaw in the Claude Chrome extension (version 2.3.0) that lets remote attackers hijack the AI agent by abusing the exte...
Modern threat actors launch campaigns that generate thousands of alerts per hour, leaving security operations centers (SOCs) drowning in data. Even with a larger team of analysts, ...
Musk's legal team filed a complaint in the Delaware Court of Chancery on 12 March, alleging that OpenAI's board has abandoned its original mission to develop artificial general int...
Organizations investing heavily in data loss prevention (DLP) solutions are discovering a critical blind spot: the browser has become the primary vector for inadvertent data exfilt...
Security researchers have uncovered a phishing campaign that spoofs the official Anthropic Claude AI portal to distribute a new Windows backdoor dubbed “Beagle.” The fraudulent sit...
According to Gartner's inaugural Market Guide for Guardian Agents, published in 2024, enterprise deployment of AI agents is accelerating at a pace that outstrips the development of...
Over the past two decades, a succession of high‑impact incidents has reshaped the cyber risk landscape, forcing organizations to constantly recalibrate their defenses. From the rev...
In the past twelve months, enterprises have rushed to embed AI‑powered writing assistants, workflow automations and productivity plugins into their Google Workspace and Microsoft 3...
A joint research effort by the Security Research Lab (SRL) and the AI Security Initiative (AISI) scanned over one million publicly reachable AI endpoints across IPv4 space between ...
The rapid adoption of AI agents in production environments has uncovered a troubling trend: systems that are supposed to enhance operational efficiency are instead causing catastro...
Security researchers using an AI-driven static analysis engine called Sentinel have uncovered a nine‑year‑old flaw in the Linux kernel’s netfilter subsystem. The vulnerability, tra...
Anthropic has officially launched Mythos, its latest large language model designed with a reported 1.2 trillion parameters and native multimodal reasoning capabilities. According t...
Japan’s financial services industry is on high alert after the release of Anthropic’s latest large language model, internally dubbed “Claude Mythos,” which early demonstrations sug...
Security researchers have uncovered a new phishing-as-a-service platform called Bluekit that advertises more than 40 ready‑made templates targeting popular online services such as ...
Security researchers at Wiz have leveraged an AI‑powered reverse‑engineering engine to uncover a high‑severity flaw in GitHub’s continuous integration infrastructure that would hav...
Security researchers using an AI‑driven code analysis platform identified 38 distinct vulnerabilities in the OpenEMR electronic health record (EHR) system, including 12 rated criti...
In February 2026, a joint research team from SentinelLabs and the University of Calgary published a report revealing a paradigm shift in cyber‑attack tradecraft. The analysts, led ...
Cybersecurity researchers from Eclypsium have disclosed a critical, unpatched vulnerability in Hugging Face’s open‑source robotics framework LeRobot, which boasts nearly 24,000 Git...
In the past, security teams could count on a brief, predictable window between the disclosure of a vulnerability and the release of a patch. That buffer has all but vanished as AI-...
The rapid advancement of frontier large language models, including Anthropic's Claude family and OpenAI's rumored GPT-5.5, has ignited fierce debate within the cybersecurity commun...
Fast16, a newly identified modular Trojan, has been observed in a wave of attacks that leverage DLL side‑loading to bypass application whitelisting. Discovered by Cisco Talos on 20...
Anthropic on April 7 released the public preview of Claude Mythos, a cybersecurity‑focused large language model built on the company’s latest transformer stack. The model ships wit...
Glasswing’s recent announcement that it has secured the core code of its platform is a welcome step toward reducing software vulnerabilities, but security experts warn that the bro...
Enterprise organizations deploying AI agents are confronting a critical security gap that traditional governance frameworks fail to address: the AI Agent Authority Gap. As autonomo...
Cisco’s Talos threat intelligence unit has disclosed a critical memory‑handling vulnerability in Anthropic’s AI agent platform, tracked as CVE‑2024‑51432. The flaw resides in the m...
Anthropic has announced Project Glasswing, an AI model designed to discover software vulnerabilities with unprecedented effectiveness. The company has taken the extraordinary step ...
Mozilla has identified 271 security vulnerabilities in Firefox 150 using Anthropic's Mythos large language model, marking a significant milestone in AI-assisted code analysis. The ...
Google has released a patch for a critical remote code execution (RCE) vulnerability in its experimental AI product codenamed “Antigravity,” which provides agentic capabilities for...
On March 5, 2026, Vercel's security operations center (SOC) detected anomalous activity stemming from an OAuth token tied to a senior developer's account. The token, scoped to the ...
A new analysis published by Dark Reading warns that the most pressing security risk posed by artificial intelligence is not the emergence of novel code flaws, but the rapid amplifi...
The UK Cabinet Office’s Emerging Technology Cybersecurity Division (ETCD), in close collaboration with the National Cyber Security Centre (NCSC), has publicly released results from...
Worldcoin’s World ID initiative, built by Tools for Humanity, is deploying a biometric authentication system based on iris scanning to assign a unique human identity to every AI ag...
AI assistants, often marketed as autonomous "agents", are rapidly becoming a staple in developer toolchains, promising to automate everything from code generation to system configu...
Starting Monday, Google began rolling out a platform update for Android 14 (API level 34) that expands the capabilities of its on‑device AI assistant, Gemini. The change introduces...