Your AI agents can reach data no one approved
A credential expired. An AI agent kept using it anyway, and a mid-sized company’s systems went down for a quarter’s worth of trouble before anyone traced the …
Android malware detection collapses when the context stage comes out
A phone backup app asks for storage, contacts, SMS, and call logs. A device-management tool asks for more than that. Run either one past a machine learning malware scanner and …
Hugging Face breach reignites open-weights debate, raises liability questions
The first publicly documented cyberattack run end-to-end by an autonomous AI was an OpenAI benchmark test that escaped its sandbox and breached Hugging Face. In an incident …
BlackCloak extends deepfake protection to the executive’s trusted circle
Deepfakes have made one of our oldest assumptions unreliable: that you can trust a familiar face or voice. While the industry focuses mainly on building “in-line detection …
Bugcrowd introduces Savant Pathseeker for agentic penetration testing with exploit validation
Bugcrowd unveils Savant Pathseeker, the first solution in its Agentic Offensive Testing line. Savant Pathseeker gives security teams the speed and scale to test every external …
Prescient Security adds attack surface management to Cait, broadens AI-assisted pentesting
Prescient Security has announced a series of capability expansions to Cait (Cacilian AI), its continuous AI-assisted penetration testing service. The updates which will roll …
Cyberhaven launches Flow to secure data across human and AI workflows
Cyberhaven has introduced Cyberhaven Flow, an AI-native data security platform built to protect data across human and AI workflows. Flow connects lineage, identity, and …
Intel 471 expands Verity471 with AI agent and MCP support for threat intelligence
Intel 471 has announced two new AI capabilities in the Verity471 platform, MCP471 and Agent471. As attackers use AI to lower the barrier to scale, security teams must use …
SpecterOps brings AWS attack path management and AI to hybrid identity security
SpecterOps has announced new capabilities built to give defenders a dynamic understanding of how adversaries traverse their hybrid environment and the ability to proactively …
Team Cymru unveils Pure Signal Command for AI-powered threat intelligence and incident response
Team Cymru has announced Pure Signal Command, the connected operating environment for analysts, security teams, applications, and AI agents to access and act on Team Cymru’s …
Exposed BMCs hand out password hashes before login
An attacker who reaches UDP port 623 on a server’s baseboard management controller can ask it for a password hash and receive one before logging in. The exchange is part …
JetBrains fixes critical unauthenticated RCE in TeamCity On-Premises (CVE-2026-63077)
JetBrains has fixed a critical vulnerability (CVE-2026-63077) affecting TeamCity On-Premises and is urging admins to upgrade self-hosted servers as soon as possible. …
Featured news
Resources
Don't miss
- Bots with good manners are better at fooling people on social media
- Zero-click RCE vulnerability hit four major AI coding agents, two remain unpatched
- CISA wants critical infrastructure orgs and smaller security teams to start using cyber decoys
- Unauthenticated attackers are bypassing Cisco ISE’s management interface (CVE-2026-76460)
- Scammers leave AI fingerprints all over fake antivirus renewal page