What's happening in security
Breaches, credential dumps, actively exploited bugs and AI incidents — pulled from 2,946 items across public feeds, Have I Been Pwned and CISA KEV.
Biggest this week
- Cisco alerts customers to second actively exploited zero-day in as many days — CyberScoop, 40m ago
- Unauthenticated attackers are bypassing Cisco ISE’s management interface (CVE-2026-76460) — Help Net Security, 11h ago
- Google fixes actively exploited Android zero-day on Pixel devices — BleepingComputer, 1d ago
- Cisco warns customers of actively exploited zero-day in email gateways — CyberScoop, 2d ago
- Cisco patches actively exploited email gateway zero-day (CVE-2026-76461) — Help Net Security, 2d ago
-
Rebranded AI legal tech firm Nylon to raise $20m for UK, US expansion
Auckland legal tech company Nylon has embarked on a rebrand and is seeking to raise $20 million in a new seed round to expand in the UK and US. Founded in 2023, Nylon was previously known as Law Cyborg and uses AI to answer detail…
-
Stealing Reasoning Traces from Proprietary LLM APIs
Stealing Reasoning Traces from Proprietary LLM APIs A vanity domain name ( stolen-thoughts.com ) for a neat paper : Anthropic, OpenAI, and Google return encrypted chain-of-thought blocks to clients that can be replayed across sess…
-
Stealing Reasoning Traces from Proprietary LLM APIs
Stealing Reasoning Traces from Proprietary LLM APIs A vanity domain name ( stolen-thoughts.com ) for a neat paper : Anthropic, OpenAI, and Google return encrypted chain-of-thought blocks to clients that can be replayed across sess…
-
Stop Building a 2003 SOC with AI: Triage Must Die (Part 2)
(with key ideas from Augusto Barros ) In Part 1 of this series , we dumped a pile of uncomfortable questions on you and promised answers. The core thesis, if you recall: if you add AI agents into a legacy, swivel-chair SOC structu…
-
Where an AI Watermark Can Hide in Plain Text
Diagram of the four layers a text watermark can live in, from encoding down to meaning, with the two bypasses canonical regeneration and prose rewriting crossing out the layers they strip/images/where-watermarks-hide-in-text-layer…
-
AI Genie in the Wild
When I give talks about AI genies , I use this sort of example as a hypothetical. It s happened . The story is from Australia. Someone named Andrew tasked OpenClaw to book gym classes for him. And . Minutes later, his AI agent rep…
-
"Nobody Asked for A.I." Is a Stupid Argument
Charcoal sketch of a colossal kneeling figure made of hundreds of interlocking hands, reaching down with open palms toward a vast crowd of suffering people/images/nobody-asked-for-ai-header.webp/images/nobody-asked-for-ai-header.w…
-
The AI Governance Gap Is a Leadership Problem: Waiting Won’t Close It
Organizations are rushing to implement AI without fully grasping where its legal protections begin and end. The post The AI Governance Gap Is a Leadership Problem: Waiting Won t Close It appeared first on SecurityWeek .
-
Vague Task, Total Access: When AI Delegation Becomes a Security Risk
AI agents can improvise beyond the intended scope of a task when they are given broad access to enterprise systems and data. Token Security explains why organizations need to define agent intent and continuously enforce permission…
-
Citrix expands Platform Flex with observability and secure developer services
Citrix has announced new services for Citrix Platform Flex, extending its flexible credit model with additional options for delivering, monitoring and securing digital work environments. The new offerings include Citrix Experience…
-
A Zoom Screen-Sharing Bug Let Anyone Take Over Other Devices on a Call
Researchers say it took fewer than 20 prompts for a public AI tool to find a flaw (now fixed) allowing anyone on a Zoom call to hijack another participants’ device.
-
Corma Raises $60 Million for Defensive Cybersecurity AI Model
Corma emerged from stealth with seed funding from Sequoia Capital, Khosla Ventures, and Coatue. The post Corma Raises $60 Million for Defensive Cybersecurity AI Model appeared first on SecurityWeek .
-
AI for Military Support
Interesting empirical research: Black Box Warfare: Human Judgment and Military Decision-Making in the Age of AI . Abstract: How is AI transforming decision-making in modern conflict? This study provides a unique empirical window i…
-
Extension Banned for Stealing AI Chats Returns to Chrome Store, Resumes Malicious Activities
The extension amassed over 300,000 installs and a 4.6 rating before Google removed it for stealing data. The post Extension Banned for Stealing AI Chats Returns to Chrome Store, Resumes Malicious Activities appeared first on Secur…
-
Malicious MCP Servers Can Split Instructions to Make AI Coding Agents Exfiltrate Secrets
A malicious tool server connected to an AI coding assistant can quietly walk off with SSH keys, environment secrets, source code, and customer data without ever sending one obviously harmful instruction. The trick can work even af…
-
OpenAI Unveils New Cybersecurity Model GPT-5.6-Cyber
OpenAI has also announced the expansion of its Daybreak platform to give more organizations access to its AI. The post OpenAI Unveils New Cybersecurity Model GPT-5.6-Cyber appeared first on SecurityWeek .
-
AI Autopsy: FortiBleed Shows Why Edge Devices Are Now Credential Attack Paths
A massive credential exposure highlights a wider perimeter security failure Ian Williams investigates what happened when tens of thousands of Fortinet devices were turned into a launchpad for broader compromise Read the rest of AI…
-
Who will be the Stanislav Petrov in your organization?
The recent news coverage of “rogue AI” systems hacking innocent companies reminded me of one of the world’s most unsung heroes and genuinely someone who may well have saved the world. In 1983, the USSR’s early warning systems repo…
-
An AI tool found 84 flaws in 5G network software and 23 of them still have no fix
Researchers at Nanyang Technological University turned a set of AI agents loose on the software that runs 4G and 5G phone networks, and the agents came back with 84 security flaws nobody had reported before. Developers have confir…
-
Microsoft NZ crowns Nick Walton as new MD
Microsoft has appointed Nick Walton as its new managing director for New Zealand with a mission to help guide the company through what is expected to be a significant chapter for AI adoption and digital transformation. The appoint…
-
In Pictures: NZ channel leaders chart the path to growth at EDGE 2026
New Zealand technology partners were brought together during the first session at EDGE 2026 to examine the opportunities and challenges facing Kiwi partners looking to enter their next phase of growth. Hosted by Foundry Editorial …
-
IMO, the most interesting thing to come out of # HackerSummerCamp is that no one should be using AI to patch v…
IMO, the most interesting thing to come out of # HackerSummerCamp is that no one should be using AI to patch vulns https:// 1password.com/blog/why-ai-gene rated-patches-still-require-human-review
-
Introducing Muse Glimmer
Introducing Muse Glimmer Meta are back in the open weights game! Muse Glimmer is a brand new 30B model under a clean Apache 2.0 license (a step up from the janky Llama licenses of old). They claim to have optimized it for exactly …
-
Introducing Muse Glimmer
Introducing Muse Glimmer Meta are back in the open weights game! Muse Glimmer is a brand new 30B model under a clean Apache 2.0 license (a step up from the janky Llama licenses of old). They claim to have optimized it for exactly …
-
'GhostJacking' Exposes Identity Governance Gaps in AI Agents
New research shows how attackers can use security alerts and blocked events to manipulate and hijack AI agents.
-
The FTC wants to regulate AI for ideological bias
The commission is mulling whether to begin regulating bias in AI systems. Critics say they’re overstepping their legal authority and infringing on free speech. The post The FTC wants to regulate AI for ideological bias appeared fi…
-
OpenAI says Daybreak will expand to offer specialized cyber services
The company rolled out “Red” and “Blue” programs for defenders, introduced a new model and announced partnerships with 16 major cybersecurity vendors. The post OpenAI says Daybreak will expand to offer specialized cyber services a…
-
NATO and an AI startup can now name and track software vulnerabilities
NATO s cyber defense arm and a startup that uses artificial intelligence to find software flaws can now issue the ID numbers the industry uses to track those flaws, the European Union Agency for Cybersecurity announced last week. …
-
OpenAI releases ChatGPT 5.6 Cyber, but it's only for approved users
OpenAI has developed a new model called "GPT 5.6 Cyber," designed for vulnerability research, penetration testing, incident response, and remediation. [...]
-
Microsoft named a Leader in the 2026 IDC MarketScape for MDR/MXDR for the Enterprise
Microsoft is named a Leader in the 2026 IDC MarketScape for MDR services. Discover how Microsoft Defender Experts MDR combines AI, threat intelligence, and human expertise. The post Microsoft named a Leader in the 2026 IDC MarketS…
-
Microsoft named a Leader in the 2026 IDC MarketScape for MDR/MXDR for the Enterprise
Microsoft is named a Leader in the 2026 IDC MarketScape for MDR services. Discover how Microsoft Defender Experts MDR combines AI, threat intelligence, and human expertise. The post Microsoft named a Leader in the 2026 IDC MarketS…
-
OpenAI’s Upcoming Astra Model Raises Autonomous Cyberattack Concerns
The current GPT-5.6-Sol has been assigned a ‘high’ cybersecurity threshold, but Astra could reach the maximum ‘critical’ threshold. The post OpenAI’s Upcoming Astra Model Raises Autonomous Cyberattack Concerns appeared first on Se…
-
Why transparent AI agents matter more than you think
The difference between a prompt injection attack you'll catch and one you won't might just be whether your AI agent can explain itself. The post Why transparent AI agents matter more than you think appeared first on CyberScoop .
-
Stealthium Targets Security Blind Spots in AI Accelerators and Neo-Clouds
The startup analyzes subtle telemetry signals to detect attacks that traditional security tools cannot see inside accelerator-powered AI infrastructure. The post Stealthium Targets Security Blind Spots in AI Accelerators and Neo-C…
-
When Credentials Are No Longer Enough: Device Trust in the AI Era
AI is making phishing, credential theft, and social engineering faster and more efficient, while traditional trust signals such as passwords, MFA, IP reputation, and geolocation become easier to bypass. Specops explains why organi…
-
Kimsuky Builds Offline AI Stack to Boost Phishing and Automate Malware Development
North Korea's state hackers are no longer content to type prompts into public chatbots. One of the country's main espionage groups has begun running artificial intelligence (AI) offline on its own servers, connecting document-sear…
-
‘Ghostjacking’ Attack Uses Poisoned Logs to Turn AI Agents Bad
An AI agent executes instructions that an attacker has planted in the log or alert that records a blocked request word for word. The post Ghostjacking Attack Uses Poisoned Logs to Turn AI Agents Bad appeared first on SecurityWeek …
-
Anthropic to put AI in charge of reviewing Claude Code actions by default
Anthropic will make auto mode in Claude Code the default for new sessions on Pro, Max, and Team plans starting August 14. Users who previously selected a different default may receive a one-time prompt asking whether they want to …
-
OpenAI locks down Astra over potential critical cyber capabilities
OpenAI s internal evaluation of its upcoming model, Astra, found significant advances in agentic coding and cybersecurity, leading the company to conclude that it cannot rule out the model reaching the critical capability level fo…
-
OpenAI's Next AI Model Astra Shows Cyber Performance Strong Enough to Trigger Pause
OpenAI has announced that it's pausing some "internal activities" involving its upcoming artificial intelligence (AI) model Astra after an internal evaluation found it had made significant advancements in agentic coding and cybers…
-
71% of CISOs spend 10+ hours on board reports
Boards want evidence that security controls and architecture reduce business risk, expressed in terms of resilience, consequence, and decision relevance. Translating technical findings into business language remains a major time b…
-
How to report an AI Act violation in the EU
The EU s fight to regulate AI models entered a new chapter on 2 August 2026, when the European Commission s AI Office and national authorities began enforcing the AI Act. The AI Act is the EU s law regulating AI, the first broad l…
-
Quoting OpenClaw
The API has zero authorisations checks on cancelling other people's reservations … I tested this with the person in waitlist position #1 — and it actually went through. So you've moved from #4 to #3 already. OpenClaw , hacking an …
-
Quoting OpenClaw (running Opus 4.6)
The API has zero authorisations checks on cancelling other people's reservations … I tested this with the person in waitlist position #1 — and it actually went through. So you've moved from #4 to #3 already. OpenClaw (running Opus…
-
Quoting Claude Opus 5 system prompt
Claude Fable 5 and Claude Mythos 5 were first released on June 9, 2026. On June 12, 2026, Anthropic suspended access to both models to comply with U.S. Department of Commerce export controls; the Department lifted those controls o…
-
Quoting Claude Opus 5 system prompt
Claude Fable 5 and Claude Mythos 5 were first released on June 9, 2026. On June 12, 2026, Anthropic suspended access to both models to comply with U.S. Department of Commerce export controls; the Department lifted those controls o…
-
Nothing Draws a Crowd Like the End of the World
Artificial intelligence is a brilliant toy and a useful tool. It is also a debt-fueled $725 billion buildout, sold on the end of the world and metered to the American ratepayer.
-
GitHub Models is now retired
GitHub Models is now retired I missed this news until today, when the GitHub Actions run for my simonw/research repository failed with this error message: GitHub Models is temporarily unavailable as part of a scheduled retirement …
-
GitHub Models is now retired
GitHub Models is now retired I missed this news until today, when the GitHub Actions run for my simonw/research repository failed with this error message: GitHub Models is temporarily unavailable as part of a scheduled retirement …
-
Work Just Became Fun for Millions of People
Charcoal sketch of a purple meeting room torn open, with figures joyfully building a rising sienna structure/images/work-just-became-fun-header.webp/images/work-just-became-fun-header.webp There's a narrative about AI and work tha…
Last fetch · 0 new