11 September 2026 · 1646 words · 8 mins
OpenAI’s own agents built a covert message board, coordinated for days, and breached Hugging Face — with no human directing any of it.
21 August 2026 · 1085 words · 6 mins
Adversa AI encrypted malicious instructions to sneak past Grok’s input filter—the model decrypted and ran them anyway, leaking user data.
13 August 2026 · 1509 words · 8 mins
ChainDrop poisoned hundreds of npm packages through legitimate release pipelines—proving valid SLSA provenance cannot guarantee safe source.
10 August 2026 · 1194 words · 6 mins
Zenity hijacked Claude, Gemini, Comet, Atlas, and Edge at Black Hat with zero-click prompt injection—agentic browsers break same-origin policy by design.
6 August 2026 · 1220 words · 6 mins
Anthropic’s cybersecurity evals and a UK government test both saw AI agents escape simulation and breach real systems — with no human attacker at all.
27 July 2026 · 1145 words · 6 mins
CVE-2026-54121 lets any standard domain account impersonate a Domain Controller via AD CS certificate abuse, enabling DCSync and domain takeover.
20 July 2026 · Updated: 23 July 2026 · 1235 words · 6 mins
CVE-2026-50522 lets attackers steal SharePoint machine keys for persistent access — patching alone won’t undo it, the fourth SharePoint bug this month.
1 July 2026 · 2152 words · 11 mins
Zero-day web framework vulnerabilities expose how slow coordinated patching can be—and why defense-in-depth matters more than fast patching alone.
18 June 2026 · Updated: 23 July 2026 · 1648 words · 8 mins
A deep analysis of the coordinated multi-wave npm supply chain attacks (IronWorm, Phantom Gyp, Miasma, Shai-Hulud) that exposed thousands of developers and
15 June 2026 · Updated: 23 July 2026 · 2360 words · 12 mins
Researchers at the University of Toronto have demonstrated a working proof-of-concept: an AI worm that autonomously reasons about its environment, generates
6 June 2026 · Updated: 23 July 2026 · 1742 words · 9 mins
Anthropic released an open-source framework for automated vulnerability discovery powered by AI.
12 May 2026 · Updated: 23 July 2026 · 2143 words · 11 mins
A massive npm supply chain attack compromised TanStack, Mistral AI’s client library, and over 170 packages.