research
An AI agent can pass every safety check and still leak secrets
A pull request lands with a tidy bug report in the description. A bot reads it before any person does, pulls a few shell commands out of it, gets them approved, and posts the …
Android malware detection collapses when the context stage comes out
A phone backup app asks for storage, contacts, SMS, and call logs. A device-management tool asks for more than that. Run either one past a machine learning malware scanner and …
Exposed BMCs hand out password hashes before login
An attacker who reaches UDP port 623 on a server’s baseboard management controller can ask it for a password hash and receive one before logging in. The exchange is part …
AI took more than junior developer jobs and the bill comes later
A ticket comes in for a small bug fix. Hand it to the junior on your team and you wait a day, review something that half works, and sit down to explain what went wrong. …
The automotive software vulnerabilities hiding in your dashboard
Pop the hood on a new car and you won’t find much you can fix with a wrench. What you’ll find is software, and a lot of it. The screen in the dash probably runs …
Multi-patch vulnerability fixes can leave open source exposed
Vulnerability management runs on a shorthand. A CVE shows a linked patch, someone applies it, and the ticket moves to closed. That shorthand covers most open source fixes. A …
Small teams are the heaviest users of AI coding agents
The pull request arrives with the tests already run and the description already written, the work of an agent that handled the whole thing on its own. Somebody still has to …
Nobody was checking the drives that encrypt your laptop
A drive ships with a label promising hardware encryption. You plug it in, set a password, and trust the chip inside to handle the rest. Millions of laptops and workstations …
A forensic tool for backdoored code completions in AI assistants
Developers lean on AI coding assistants for a growing share of their daily work, letting the tools predict the next few lines and accepting many suggestions with a quick …
Prompt injection is becoming the XSS of the web agent era
Autonomous web agents read whatever a page displays, and much of that content comes from strangers. Product reviews, seller listings, and advertisements sit beside trusted …
The script, not the voice, is what makes AI voice phishing work
The call comes in at 4:40 on a Friday. The voice belongs to a senior manager, or sounds close enough, and she needs a password reset before a flight. She is polite, she is in …
What public money does to open-source projects
Most of the software running inside a typical company was written by volunteers the company never paid. Open-source code sits under web apps, build pipelines, and the machine …
Featured news
Resources
Don't miss
- Your AI agents can reach data no one approved
- Hugging Face breach reignites open-weights debate, raises liability questions
- Exposed BMCs hand out password hashes before login
- JetBrains fixes critical unauthenticated RCE in TeamCity On-Premises (CVE-2026-63077)
- Shadow AI incident response begins with logs that may already be gone