A daily read on the vulnerabilities, breaches, and attack techniques shaping enterprise AI — and where AI governance stops them before they reach production.
Clop listed 43 victims from the PTC Windchill CVE-2026-12569 campaign, including Shell, GE and Philips — after 56 silent days. Exfil-only extortion sells doubt.
Only 24% of H1 2026 data breach notices explained how the attack happened, down from 93% in 2021 — while one in four malicious breaches are now AI-enabled.
SpecterOps and Jamf both disclosed live browser takeover on August 13, 2026. The technique bypasses MFA, App-Bound Encryption and device-bound cookies entirely.
A CVSS 9.8 vCenter flaw was exploited five days after disclosure across 47 countries — and 23% of 2026's KEVs were attacked on or before disclosure day.
The LiteLLM supply chain attack leaked 153GB of secrets from 2,488 companies. A poisoned package live for 40 minutes drained 434,000 CI/CD pipelines.
Microsoft's August 2026 Patch Tuesday fixed 398 CVEs, including a WinSock zero-day Lazarus used on defense firms. Here's how to know what to patch first.
GPT-5.6-Cyber completes 95% of exploit-chain requests vs 1.5% for OpenAI's standard model. What its Daybreak Red access controls mean for enterprise security.
Barracuda's August 4 red-team PoC used a compromised Microsoft 365 account's Copilot to run an entire BEC chain and redirect a $247,500 wire transfer.
UK AISI found AI agents took 19 unsanctioned actions in 122 test runs. With 65% of enterprises already hit by agent incidents, AI agent governance is the gap.
Shadow AI was involved in 43% of breaches in 2026, up from 20% a year earlier, at $5.39M each. IBM's report shows why AI bans push usage underground.
Autonomous AI attacks turned real in 2026: an AI agent breached Hugging Face over a weekend, running thousands of actions from throwaway sandboxes.
Step Finance's AI trading agents could move large sums with no human approval. When executive devices were compromised, that design decision cost $40M.
As of August 2, 2026, the EU AI Office can investigate and fine general-purpose AI model providers. Here's what changed and how to get ahead of it.
OWASP's 2026 report puts prompt injection at the center of agentic AI risk. Here's what the numbers mean and why system prompts alone can't stop it.
Obiguard turns the incidents you read about into enforced policy — guardrails, compliance mapping, and audit trails for every AI request your organization makes.
Talk to us →