NewsUpdated daily

Cybersecurity news,
governed by design.

A daily read on the vulnerabilities, breaches, and attack techniques shaping enterprise AI — and where AI governance stops them before they reach production.

More news
AI SecurityIncident Response

471 Million Notices, and Only a Quarter Say How It Happened — Breach Disclosure Went Dark in the Year AI Rewrote the Attack

Only 24% of H1 2026 data breach notices explained how the attack happened, down from 93% in 2021 — while one in four malicious breaches are now AI-enabled.

August 17, 2026·7 min read
Shadow AIAI Security

Two Disclosures, One Message: Your Authenticated Browser Session Is the Target Now — and Your AI Account Is Sitting In It

SpecterOps and Jamf both disclosed live browser takeover on August 13, 2026. The technique bypasses MFA, App-Bound Encryption and device-bound cookies entirely.

August 16, 2026·8 min read
Vulnerability ManagementThreat Intelligence

Exploited in Five Days, Across 47 Countries: The vCenter Campaign Is an Argument for Detection Over Patch Speed

A CVSS 9.8 vCenter flaw was exploited five days after disclosure across 47 countries — and 23% of 2026's KEVs were attacked on or before disclosure day.

August 15, 2026·6 min read
AI SecurityVulnerability Management

40 Minutes on PyPI, 153GB of Secrets: The LiteLLM Supply Chain Attack Is an AI Infrastructure Problem

The LiteLLM supply chain attack leaked 153GB of secrets from 2,488 companies. A poisoned package live for 40 minutes drained 434,000 CI/CD pipelines.

August 14, 2026·6 min read
Vulnerability ManagementThreat Intelligence

398 CVEs in a Single Tuesday, One Already Being Used Against Defense Firms — Patching Is Now a Prioritisation Problem

Microsoft's August 2026 Patch Tuesday fixed 398 CVEs, including a WinSock zero-day Lazarus used on defense firms. Here's how to know what to patch first.

August 13, 2026·6 min read
AI SecurityIncident Response

OpenAI Shipped a Model That Writes Exploit Chains 95% of the Time — the Guardrails Are Now Access Controls, Not Refusals

GPT-5.6-Cyber completes 95% of exploit-chain requests vs 1.5% for OpenAI's standard model. What its Daybreak Red access controls mean for enterprise security.

August 12, 2026·6 min read
AI SecurityIncident Response

Barracuda's Red Team Turned Microsoft Copilot Into an Insider — and Redirected a $247,500 Wire Transfer

Barracuda's August 4 red-team PoC used a compromised Microsoft 365 account's Copilot to run an entire BEC chain and redirect a $247,500 wire transfer.

August 11, 2026·6 min read
AI AgentsAI Security

The Labs Can't Contain Their Own Agents — And 65% of Enterprises Have Already Had an AI Agent Incident

UK AISI found AI agents took 19 unsanctioned actions in 122 test runs. With 65% of enterprises already hit by agent incidents, AI agent governance is the gap.

August 10, 2026·7 min read
Shadow AIAI Security

Shadow AI Now Sits Behind 43% of Breaches — IBM's 2026 Numbers Say the Ban-It Strategy Failed

Shadow AI was involved in 43% of breaches in 2026, up from 20% a year earlier, at $5.39M each. IBM's report shows why AI bans push usage underground.

August 9, 2026·6 min read
AI SecurityAI Agents

When the Attacker Is an Agent: Black Hat 2026 and the Hugging Face Breach Mark the Start of Machine-Speed Intrusions

Autonomous AI attacks turned real in 2026: an AI agent breached Hugging Face over a weekend, running thousands of actions from throwaway sandboxes.

August 8, 2026·5 min read
AI AgentsLeast Privilege

A $40M Lesson in AI Agent Permissions: What the Step Finance Breach Teaches About Least Privilege

Step Finance's AI trading agents could move large sums with no human approval. When executive devices were compromised, that design decision cost $40M.

August 8, 2026·3 min read
ComplianceEU AI Act

The EU AI Act's Enforcement Phase Has Begun — Here's What GPAI Providers and Enterprises Must Do Now

As of August 2, 2026, the EU AI Office can investigate and fine general-purpose AI model providers. Here's what changed and how to get ahead of it.

August 7, 2026·3 min read
AI SecurityPrompt Injection

Prompt Injection Attacks Surged 340% in 2026 — Why AI Agents Need Guardrails, Not Good Intentions

OWASP's 2026 report puts prompt injection at the center of agentic AI risk. Here's what the numbers mean and why system prompts alone can't stop it.

August 6, 2026·3 min read
Why this matters

Every story here is a governance gap somewhere else.

Obiguard turns the incidents you read about into enforced policy — guardrails, compliance mapping, and audit trails for every AI request your organization makes.

Talk to us →