What's happening in security
Breaches, credential dumps, actively exploited bugs and AI incidents — pulled from 2,942 items across public feeds, Have I Been Pwned and CISA KEV.
Biggest this week
- Unauthenticated attackers are bypassing Cisco ISE’s management interface (CVE-2026-76460) — Help Net Security, 9h ago
- Google fixes actively exploited Android zero-day on Pixel devices — BleepingComputer, 1d ago
- Cisco warns customers of actively exploited zero-day in email gateways — CyberScoop, 2d ago
- Cisco patches actively exploited email gateway zero-day (CVE-2026-76461) — Help Net Security, 2d ago
- Active Exploitation Triggers Emergency Patch for Cisco ISE Zero-Day — SecurityWeek, 13h ago
-
Oracle’s partner co-innovation initiative leads to success
Oracle’s focus on collaborating earlier with partners in joint engagements is working in the vendor’s favour as it uses AI to open up more opportunities. In 2025, the vendor’s group vice president and head of alliances and channel…
-
Budget airlines, mobile phones, and AI
I was talking to some friends about how much more we travel now than we (our parents generation) did in the 1980s. I know there are a lot of factors that contribute towards the shift, but the main point we landed on was that budge…
-
'CoSnitch' Attack Tricked Copilot into Mapping Out Architecture
Researchers discovered a meta-hacking technique that can manipulate the AI service into revealing its own security weaknesses.
-
The 'Industrial Accidents' Behind Rogue AI Agent Attacks — and the Sandbox Failures Exposed
Rich Mogull, chief analyst with the Cloud Security Alliance, joins the Dark Reading News Desk with what defenders need to take away from AI agents escaping their environments to launch attacks.
-
OpenAI Overhauls Safety Protocols After Its AI Agents Went Rogue
The ChatGPT maker says its upcoming Astra model may have reached “critical” cyber capabilities, prompting it to halt a significant number of training runs while it tightens internal safeguards.
-
Webinar Today: Rethinking Cyber Defense for AI-Speed Attacks
Join the live webinar as we explore if detection-first security operations can keep pace with AI, or if it’s time to rethink prevention as the strongest default. The post Webinar Today: Rethinking Cyber Defense for AI-Speed Attack…
-
Meta Ran Ads for an App That Promised to Nudify Female Politicians
One advertisement featured a pornographic video with a deepfake closely resembling a prominent US politician. Apple removed the app from the App Store after an inquiry from WIRED.
-
CISO Conversations: Nico Waisman – From Self-Taught Hacker to AI-Driven Offensive Security at XBOW
With no formal training and no career plan, Waisman built a path from Argentina's early hacking scene to leading security at an AI-powered offensive security firm. The post CISO Conversations: Nico Waisman – From Self-Taught Hacke…
-
AI "Mind Viruses" Can Spread Between Agents Through Persistent Prompt Files
Security researchers at Anthropic and Switzerland's EPFL have demonstrated that self-propagating payloads can spread from one artificial intelligence (AI) agent to the next through the editable system prompt files that autonomous …
-
Xpander Raises $7.5 Million for AI Management and Governance
Xpander’s platform uses a universal agent harness that executes AI agents as portable workloads and securely renders interfaces on demand. The post Xpander Raises $7.5 Million for AI Management and Governance appeared first on Sec…
-
Fortinet Acquires AI Security Company Virtue AI
Fortinet will use Virtue AI technology to enhance its AI security portfolio, including for AI models, applications, and agentic systems. The post Fortinet Acquires AI Security Company Virtue AI appeared first on SecurityWeek .
-
Google’s $10,000 refund test shows why AI agents need zero trust
Google’s open-source autonomous Customer Support Returns Agent, built using the Agent Development Kit (ADK) and Gemini, demonstrates how developers can apply zero-trust security principles to AI agents that interact with sensitive…
-
LLMs and Contextual Integrity
I have been thinking a lot about AI and integrity. Part of that is contextual integrity. I recently found two papers on the topic. CIMemories: A Compositional Benchmark for Contextual Integrity of Persistent Memory in LLMs : Abstr…
-
Can AI Coexist With Privacy? Proton’s Andy Yen Says It Will Have To
Proton’s CEO is a champion of encryption for everyone. So why is he going all in on un-encryptable AI?
-
OpenAI tightens defenses after AI agents breach research environment
Following the OpenAI-Hugging Face incident, in which an agentic collective autonomously penetrated OpenAI’s research infrastructure and another company’s production infrastructure by chaining together multiple weaknesses, OpenAI b…
-
Synthesized builds Test Data Agent to validate AI agents with production-like data
Synthesized has announced its Test Data Agent, a new agentic infrastructure capability being developed to create and provision the realistic data, business context, and system states enterprises need to validate AI agents safely b…
-
Google’s open-source HEIR lets AI work with data it can’t see
Google’s researchers and engineers developed the Homomorphic Encryption Intermediate Representation (HEIR) compiler project, an open-source compiler toolchain and development platform for homomorphic encryption. It can convert pre…
-
A hollowed out data layer is making CISOs fly blind into AI attacks
The security industry is currently transitioning to an era where both offense and defense are AI-led, and every SOC operates at machine speed. However, what most CISOs have not yet reckoned with is that the AI defenders they are a…
-
Dell CTO John Roese: Partners, culture, and governance are all layers of AI transformation
AI success depends on disciplined execution, governance, culture change, startup innovation, and human relationships, said Dell global chief technology officer (CTO) John Roese. For Dell, this means partners are not an optional ro…
-
Qwen 3.8 27B scores 52 on the Artificial Analysis Intelligence Index
Qwen 3.8 27B scores 52 on the Artificial Analysis Intelligence Index That's the same score as GPT-5.6 Luna (max), and just one point behind GLM-5.2 (max) and DeepSeek V4 Pro 0813 (max) - that GLM is 753B and that DeepSeek is 1.6B …
-
Irregular says ‘human oversight’ responsible for AI sandbox escape incidents
In a post-mortem, the frontier AI testing company said internet access for models is necessary to fully test out their cybersecurity capabilities. The post Irregular says ‘human oversight’ responsible for AI sandbox escape inciden…
-
'Turf War' Between Claude Agents Leads to Self-Replicating Malware
Three testing models with the same goal but different directives engaged in increasingly aggressive territorial attacks on one another, according to Anthropic.
-
If you are an expert witness, do not use ChatGPT to write the report you are charging $475/hour for. All of yo…
If you are an expert witness, do not use ChatGPT to write the report you are charging $475/hour for. All of your chat prompts are subpoenable and we are all going to laugh so hard. https://www. 404media.co/show-how-3m-is-0-a t-fau…
-
Adam Shostack Talks Hugging Face & PHANTOM-B
World-class threat modeler Adam Shostack shared he was blown away by OpenAI's revelations about the Hugging Face attack, and explains why his new threat model for LLMs is both lightweight yet still usable.
-
Works start on Datagrid’s Southland AI data centre campus
Southland-based data centre firm Datagrid New Zealand has announced that horizontal works have started on its AI data centre campus in Makarewa, north of Invercargill. The company selected HEB Construction to undertake the works f…
-
Irregular faces criticism over ‘spin’ in AI hacking postmortem
The company at the center of a series of incidents in which AI models compromised real-world computer systems during security evaluations is facing criticism after the release of a report that security experts say leaves key quest…
-
We Tracked a Shipment of Rare Books. It Ended at an Amazon AI Training Facility
We Tracked a Shipment of Rare Books. It Ended at an Amazon AI Training Facility Excellent piece of reporting from 404 Media. For a while now there have been stories of book dealers receiving orders for large volumes of books from …
-
An “invisible” car? Researcher uses machine learning to hide vehicles from Flock cameras
A cybersecurity expert has demonstrated how computer-generated patterns can successfully prevent surveillance cameras from detecting vehicles - such as the controversial AI-powered Flock licence plate readers that are becoming inc…
-
Fortinet expands AI security portfolio with Virtue AI acquisition
Fortinet has acquired Virtue AI, strengthening its broader Security for AI strategy and its vision for securing the agentic enterprise. The acquisition builds on Fortinet’s existing AI security portfolio, which includes the FortiG…
-
Irregular Details How a Naming Error Let AI Models Attack a Real Company
The AI security testing firm has shared information on a recently disclosed incident involving Anthropic AI models. The post Irregular Details How a Naming Error Let AI Models Attack a Real Company appeared first on SecurityWeek .
-
How MCP Servers Can Expose Enterprise Secrets
MCP servers can expose enterprise secrets through plaintext configuration files, over-permissioned access and prompt injection, often before security teams even know the server is running. As more organizations adopt AI agents int…
-
Operation ASTERIX: Anatomy of a Crypto Fraud Pipeline
Operation ASTERIX overview Rapid7 researchers identified an exposed web directory on infrastructure used to support a cryptocurrency fraud operation. The server contained raw phone-number datasets, account-validation tools, enrich…
-
Fix Execution, Not the SOP
A flood of documents pours into a funnel that drips onto a tiny model a man is polishing, while real unbuilt work waits through an open door/images/fix-execution-not-the-sop.webp/images/fix-execution-not-the-sop.webp AI is multipl…
-
Conflicting Test Goals Pushed Claude Agents to Deploy Self-Replicating Malware
Anthropic has been conducting tests to identify issues in how AI agents interact with each other. The post Conflicting Test Goals Pushed Claude Agents to Deploy Self-Replicating Malware appeared first on SecurityWeek .
-
Africa’s Cybersecurity Challenge Is Bigger Than Access to Technology
Gopan Sivasankaran is Rapid7's Regional Director, Middle East & Africa. Across Egypt, Nigeria, South Africa, and Kenya, organizations are expanding their use of cloud infrastructure, artificial intelligence, digital services, and …
-
Hazmat: Open-source containment for AI agents
Hazmat is an open-source tool that runs AI coding agents inside a separate account on your own machine. It wraps the harnesses people use: Claude Code, Codex, OpenCode, Cursor Agent, and several more, plus any script you write you…
-
Inside EDGE 2026 Day Two: AI, M&A and the Future Channel
AI dominated the conversation at EDGE 2026 Day two, but it wasn’t the only topic keeping channel leaders talking. From the cybersecurity arms race and the growing skills shortage to marketplace disruption, M A strategy and the fut…
-
When companies get specific about AI, revenue growth looks different
Companies that provide specific evidence of how they use AI tend to record stronger revenue growth. Researchers at Carnegie Mellon University and Larridin examined a study universe of 564 companies across 12 industry sectors. Indi…
-
Most Kiwi consumers feel telcos don’t keep promises: study
A majority of New Zealand consumers say telecommunications providers are falling short of their promises, and as a result, many are trusting AI more than brands, a new survey has found. Accenture Song’s Brand Experience Gap study …
-
Anthropic confirms Claude is down in major outage affecting multiple services
Claude is experiencing a major outage, with users reporting login problems and degraded performance across several Anthropic services. [...]
-
Qwen 3.8 27B is excellent, but it defaults to wildly overthinking things
Friday's big release was Qwen 3.8 27B , an Apache 2 licensed 27B parameter vision-capable LLM from Alibaba's Qwen research lab. I've been looking forward to this one: 27B is an excellent size for running a model on a reasonably sp…
-
Quoting Dario Amodei
I do agree that the public has a negative view of AI (and that this is a big problem), but I don’t think it is primarily caused by me or any other AI leader warning about AI’s risks. I think it is fundamentally a crisis of trust. …
-
Another Crazy Experience with AI
Another Crazy Experience with AI/images/ai-fixed-my-mac.webp/images/ai-fixed-my-mac.webp Just had another crazy experience with AI last week. One of the types that reminds me that we're living in different times. I have been suffe…
-
There Is Only One Technology
There Is Only One Technology/images/only-one-technology.webp/images/only-one-technology.webp Had a thought about technology yesterday: The moment we used plant twine to attach a chipped stone to a stick, AI became inevitable. Ther…
-
CORS Chat
Tool: CORS Chat I built this today ( with GPT-5.6-Sol xhigh ) to help test Qwen 3.8 27B running in LM Studio on both my M5 MacBook Pro and an NVIDIA DGX Spark. It provides a web UI for exercising an OpenAI-Responses-compatible cha…
-
How Anthropic plans to watermark Claude's AI-generated text
It could soon become easier to identify AI-generated content, even if it's not the usual "It's Not X, it's Y" type of post you'd come across on LinkedIn and other socials. [...]
-
Don't classify. Hallucinate!
Don t classify. Hallucinate! I still have quite a bit of older content on my blog that I never got round to tagging. My blog has 1,856 tags - likely too many to feed to an LLM in one go and say "which of these tags match the follo…
-
The Different Games OpenAI and Anthropic Are Playing
The Different Games OpenAI and Anthropic Are Playing/images/openai-anthropic-approaches.webp/images/openai-anthropic-approaches.webp URL once the cut is published --> So one thing I find really interesting right now is the differe…
-
Mission-Driven Security: Inside a Global Bank's Defense
In this video interview, Standard Chartered's group CISO shares insights on transitioning from technical roles to strategic leadership, the importance of business-savvy security executives, and how AI is reshaping both defensive c…
-
In today's episode of Breach Please, Jake and Jess talk about cyber companies conducting cyber ops against tra…
In today's episode of Breach Please, Jake and Jess talk about cyber companies conducting cyber ops against transnational-criminal organizations, per the new Presidential directive. We also talk about a bug in how major AI platform…
Last fetch 11m ago · 2 new · 2 source error(s)