What's happening in security
Breaches, credential dumps, actively exploited bugs and AI incidents — pulled from 2,929 items across public feeds, Have I Been Pwned and CISA KEV.
Biggest this week
- Unauthenticated attackers are bypassing Cisco ISE’s management interface (CVE-2026-76460) — Help Net Security, 5h ago
- Google fixes actively exploited Android zero-day on Pixel devices — BleepingComputer, 1d ago
- Cisco warns customers of actively exploited zero-day in email gateways — CyberScoop, 2d ago
- Cisco patches actively exploited email gateway zero-day (CVE-2026-76461) — Help Net Security, 2d ago
- Active Exploitation Triggers Emergency Patch for Cisco ISE Zero-Day — SecurityWeek, 9h ago
-
Nearly 1 in 10 Exposed LiteLLM Gateways Accepted the Example "sk-1234" Admin Key
Nearly one in ten of the internet-facing LiteLLM servers that Wiz Research scanned in February accepted sk-1234, the example admin key in LiteLLM's own setup guide. LiteLLM is an open-source AI gateway, the software a company puts…
-
Anthropic Discloses Fourth AI Hacking Incident Involving Claude Opus 4.6
Anthropic on Wednesday disclosed a fourth incident in which its artificial intelligence (AI) model broke into real third-party systems, marking the latest in a growing list of cases that have raised concerns about the security ris…
-
The Boring Way to Get to AI Taking Over Everything
A charcoal sketch of a faceless purple robot working the levers of a dense industrial machine, beside an empty office chair with a worker's cap left hanging on it/images/slow-path-to-ai-takeover.webp/images/slow-path-to-ai-takeove…
-
AI adoption brings new security headaches for already stretched CISOs
CISOs are taking on AI governance without a matching increase in resources or expertise, adding to an already broad remit spanning data protection, identity, resilience and compliance, according to Proofpoint’s 2026 Voice of the C…
-
At least one in three roles eliminated by AI will be restored by 2029 at a higher cost: Gartner
Gartner on Wednesday said that it expects 30 per cent of the positions eliminated by AI-related layoffs to be refilled by 2029, suggesting that the initial terminations were ill-advised and excessive. “When business and IT executi…
-
First Focus boosts NZ presence through Resolve Technology buy
Australian-founded First Focus has further boosted its New Zealand presence by acquiring Wellington-based managed IT services provider Resolve Technology. This is First Focus’ fourth New Zealand acquisition this year, bringing its…
-
.blend URL Viewer
Tool: .blend URL Viewer I'm continuing to have a lot of fun with GPT-6 Astra and Blender (see my TIL ). As a big fan of the Imperial Fabergé Easter eggs , I've always thought it would be fun to make some new ones that celebrate po…
-
San Francisco Orders Meta to Stop ‘Allowing’ AI Child Abuse Ads
The City Attorney’s Office has asked Meta to explain how the harmful ads repeatedly ran on Facebook and Instagram. The company claims the ads are not under the city’s jurisdiction.
-
How AI anxieties dominated the summer’s big cybersecurity conference
From the CVE Program to autonomous hacks, everyone is worried about the technology s next evolution.
-
US Government Accuses Chinese AI Firms of Distilling Frontier Models
US agencies claim Chinese companies covertly extracted billions of tokens from OpenAI, Anthropic, Google Gemini, and SpaceX's Grok to reduce development costs.
-
Digital Sovereignty: What It Is, What It Could Be
The term “digital sovereignty” has become ubiquitous. European officials invoke it in debates about cloud infrastructure, AI , semiconductors , and platform regulation. Governments throughout the global majority use it to argue fo…
-
A Pentagon Memo Called It an "Arms Race." That Was the Point.
Nobody outside the AI labs can measure who is winning, so the numbers come from those who profit from them. Call it an arms race and the claim you cannot verify becomes an order you cannot question.
-
CISOs are feeling the security burden of accelerated AI use
A report shows CISOs face increased pressures related to cyber resilience and business continuity.
-
Identity-Based AI Attack Threatens Security of Enterprise Data
Workflow identity hijacking can bypass standard security controls and hijack an organization's data by sending a basic request through an unauthenticated entry point.
-
Infostealer Logs Expose Replayable AI Tokens That Can Bypass MFA
Cybercriminals are hijacking artificial intelligence (AI) user accounts via information stealer logs to create "stolen keys" that grant illicit access to tools from model providers like Google, Anthropic, and others. Information s…
-
AI researcher getting increasingly angry at their AI solving math problems: No, I want you to STROKE me.
AI researcher getting increasingly angry at their AI solving math problems: No, I want you to STROKE me.
-
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
The remarks, to both CyberScoop and at the Billington CyberSecurity Summit, dovetail with the release of a new bureau cyber strategy. The post FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basi…
-
DeepSeek Harness Flaw Let AI Agents Disable Their Own File Sandbox Without Approval
A flaw in DeepSeek Harness, DeepSeek's open-source tool for running AI coding agents on a developer's machine, let a sandboxed agent turn off its own sandbox with a single command. The tool runs an agent's commands inside an opera…
-
Claude Fable Solves a Historical Cipher
Claude Fable 5.1 solved a 370-year-old cipher in forty-four minutes. This tracks with what I wrote about AIs doing mathematics: It s good at things that involve lots of searching and testing.
-
U.S. Agencies Accuse China AI Firms of Distilling Claude, GPT, Gemini, and Grok
U.S. cybersecurity and intelligence agencies have accused China-based artificial intelligence (AI) companies of conducting "systematic extraction" of proprietary functionalities and capabilities of American frontier models through…
-
Debtfix and Digital Future Aotearoa receive US$75k in GTIA grants
Two New Zealand charities have received US$75,000 in grants from the Global Technology Industry Association (GTIA) in its latest round of charitable giving. Auckland-based Debtfix Foundation received US$50,000 in a GTIA member-ref…
-
Looking back at 40 years of Advantage
Advantage celebrates its 40th anniversary this year. In that time, it has evolved from a PC manufacturer based in Palmerston North to a fully-fledged managed services provider with a team of 70, as well as support for customers in…
-
Atturra focuses on packaging a decade of integration expertise for the AI era
Atturra is looking to turn a decade of Boomi integration experience into its next growth engine by embedding years of delivery knowledge, governance frameworks and intellectual property into AI-powered tools designed to accelerate…
-
Evergreen doubles down on A/NZ MSP market, eyes AI-led future as acquisitions accelerate
Evergreen is ramping up its Australian and New Zealand expansion plans, with the US-based holding company expecting to add several more MSPs to its portfolio before the end of the year while positioning AI advisory services as the…
-
Quoting Terence Tao
I wrote recently about how the collection of good, fruitful open problems is now being mined in a non-renewable fashion, leading to the potential scenario of these problems becoming scarce. [...] We have now seen that even the rum…
-
On the Navier–Stokes Millennium Prize Problem
On the Navier–Stokes Millennium Prize Problem Impressive result from OpenAI, who used an unreleased model to produce a resolution to the Navier–Stokes existence and smoothness problem , one of the seven Millennium Prize Problems t…
-
Introducing ChatGPT Images 2.5
Introducing ChatGPT Images 2.5 OpenAI's image generation models are apparently used "more than 3 billion images across ChatGPT Images and the GPT‑Image models in the API". This latest release improves their instruction-following a…
-
Survival of the Basics: Which Security Fundamentals Were Secretly Relying on Lazy Attackers?
A few weeks ago I asked on X and LinkedIn a deceptively simple question: which “security basics” matter more against AI-armed attackers, and which ones don’t matter anymore? What Gemini think of this blog [before you freak out abo…
-
Why this month's Microsoft patch release is a doozy
Security gnomes are pumping out patches ahead of an expected onslaught of AI-assisted attacks.
-
OpenAI Agents Took Over Wiki Site Before Hugging Face Attack
Researchers and OpenAI disagree on whether an earlier incident involving DseWiki, which the company did not disclose, was a “hack.
-
Muse, Meta’s New Personal AI Agent, Needs You to Trust It
Designed to compete with OpenClaw and Instinct, the company says Muse can do everything from sell your car to book you a plane ticket.
-
New Records Reveal Problems with Medicare’s AI Prior Authorization Experiment
EFF sued the government back in March for information about the Wasteful and Inappropriate Service Reduction (WISeR) model , a new Medicare program that uses AI to evaluate prior authorization requests for certain medical services…
-
AIs as Modern Genies
This essay was written with Barath Raghavan, and originally appeared in Lawfare . In April, an artificial intelligence (AI) agent conducting a routine task at a company hit a snag, tried to solve it, and soon ended up deleting the…
-
Don’t let AI distract from cybersecurity basics, officials and executives warn
Government and industry leaders said simple attacks remain far more consequential than anything AI is doing.
-
Autonomous AI Agents Compromise Thousands of Credentials in Under Six Hours
Threat actors are continuing to leverage artificial intelligence (AI) to streamline their operations, with one financially motivated hacking group employing an autonomous, multi-agent attack framework to carry out a large-scale cr…
-
The Shared Clipboard Inside the Sandbox: Cross-Account Data Leakage in ChatGPT
Research by: Alexey Bukhteyev Key Takeaways Introduction Over the past several years, AI assistants have moved far beyond text generation. Modern systems can execute code, install additional dependencies, analyze user files, and a…
-
Meta Failed to Catch Hundreds of AI Child Abuse Ads. Some Included Images of Real Kids
Images of real children—including a member of a European royal family—were used to create some of the 350 ads containing child sexual abuse. Lawmakers say they plan to investigate.
-
Stealing AI Reasoning Traces
Interesting research: Stealing Reasoning Traces from Proprietary LLM APIs : Abstract: Leading large language model providers now conceal their models step-by-step reasoning, or chain-of-thought, to protect intellectual property an…
-
Essential AI agent security questions
AI agents are outpacing legacy IAM. Discover the 3 questions every CISO must ask to secure them.
-
Dell’s $95B AI backlog shows the infrastructure crunch is far from over
Dell Technologies is acknowledging that infrastructure and storage supply still can’t keep up with agentic AI’s insatiable appetite for resources. The company this week reported a “record” AI backlog, with $95 billion in orders wa…
-
HPE’s record Q3: AI infrastructure, networking demands drive growth, but supply constraints tap the brakes
Demand for AI, networking, and servers drove HPE to a record quarter, the company reported during its third-quarter earnings call with financial analysts. “AI has become a multi-year growth driver, expanding demand across our HPE …
-
llm 0.35
Release: llm 0.35 New OpenAI model: gpt-6-astra for GPT-6 Astra . Tags: openai , llm , gpt-6-astra
-
Lack of dedicated AI leadership roles holding back transformation: Datacom
A leadership vacuum threatens New Zealand’s AI transformation, with only of 4 per cent of local business leaders saying AI has transformed their core operations – down from 8 per cent in 2025. This is according to research from Da…
-
Quoting Jakub Pachocki
The strongest argument I see for continuing to train much smarter models quickly is the need to build defensive systems against the dangers posed by other AI. [...] We will need powerful, aligned AI for defense; to secure infrastr…
-
Video compressor
Tool: Video compressor I recorded a short demo video of my Equal Earth animation on my phone and wanted to publish an optimized version of that video (using FFMPEG) on my blog, so I had Claude Fable 5.1 in Claude Code for web buil…
-
Mercator ↔ Equal Earth
Tool: Mercator ↔ Equal Earth I got curious about the Equal Earth map projection that was recently voted on at the UN so I had GPT-6 Astra (medium) in ChatGPT Work build me this animated transition between Mercator and Equal Earth …
-
AI SIEM Search
The new Huntress AI SIEM search feature lets you find answers in plain English, with no query language fluency required. Ask questions, get results, and skip the syntax.
-
Sam Altman calls GPT-6 Astra rollout ‘messy’ as enterprise users wait for access
OpenAI’s rollout of its GPT-6 Astra model ran into early access issues after paying ChatGPT users were unable to use the system shortly after launch, prompting CEO Sam Altman to apologise and say the release had been “messy.” “Fir…
-
VITG accelerates AI and cyber strategy with new managed services offerings
Virtual IT Group (VITG) has launched new managed services and managed security offerings designed to help Australian and New Zealand organisations tackle growing AI-driven cyber risks. The move is part of a broader transformation …
-
Victoria MacLennan joins Equinox IT as independent director
Equinox IT has appointed industry veteran Victoria MacLennan to its board as the company expands its artificial intelligence, cloud and digital services capabilities. As one of the country’s most influential figures in digital tec…
Last fetch 5m ago · 0 new · 2 source error(s)