NewsUpdated daily

Cybersecurity news,
governed by design.

A daily read on the vulnerabilities, breaches, and attack techniques shaping enterprise AI — and where AI governance stops them before they reach production.

More news
AI SecurityShadow AI

The Extension Your Employee Installed Last Year Can Now Drive the AI Assistant Built Into Their Browser

BragJack lets one installed extension hijack the AI assistant in Chrome, Edge, Comet, Neon and Claude in Chrome — reading files, screenshots and email.

September 21, 2026·9 min read
Vulnerability ManagementAI Security

One Model Version Couldn't Write the Exploit. The Next One Did It in an Afternoon. The Bug Never Changed

Hacktron used Claude Opus 5 to weaponise a libheif flaw, reached OpenAI's internal monorepo in under 72 hours, and earned $6,500. The previous model had failed.

September 20, 2026·10 min read
AI SecurityVulnerability Management

Microsoft Fixed a CVSS 10 Flaw in Azure AI Foundry. There Was Nothing for Customers to Patch, and Nothing for Them to Check

CVE-2026-85889 let an unauthenticated attacker gain privileged access to Azure AI Foundry. Microsoft fixed it server-side. What customers can still check.

September 19, 2026·8 min read
AI AgentsIncident Response

Spain's Data Regulator Got Its First Breach Report Where the Attacker Was an AI Agent. Its Advice Is About Your Clock, Not the Model

Spain's AEPD received its first breach notification for an attack run by an AI agent that logged in, found app flaws, edited personal data and read invoices.

September 18, 2026·10 min read
AI AgentsAI Security

The AI Assistant Recommended the Package. The Developer Accepted It. A Worm Reached 100 Repositories

Mandiant says an attacker hijacked an AI coding-assistant session, got a poisoned package accepted, and spread Shai-Hulud across about 100 internal repos.

September 17, 2026·10 min read
Incident ResponseThreat Intelligence

Revolut Checked That the Email Was Real. Nobody Could Check That the Person Behind It Was

Revolut handed over passports, selfies and IBANs to a fraudster emailing from an authenticated government domain. Nothing was hacked — the process worked.

September 16, 2026·11 min read
AI SecurityThreat Intelligence

The Attack Ran on Your AI Key. In the Provider's Logs, the Attacker Looks Like You

Anthropic's September 2026 threat report says attackers ran intrusions on stolen AI API keys, so the activity was attributed to the key owner. One ran a month.

September 15, 2026·11 min read
AI AgentsAI Security

The Agent Was Sandboxed. The Switch That Turned the Sandbox Off Was Inside It

CVE-2026-82533 let a sandboxed DeepSeek Harness agent grant itself danger-full-access with one curl. It sat on GitHub 11 days before being formally reported.

September 14, 2026·10 min read
Vulnerability ManagementIncident Response

The Server Had the August Hotfix. It Was Breached Anyway — and Its Logs Had Already Rotated

N-able shipped four N-central hotfixes in five weeks. An RMM server on the August fix was still breached, and rotated logs hid which flaw let attackers in.

September 13, 2026·10 min read
AI SecurityShadow AI

Six Chinese AI Labs Distilled US Models Through Cut-Price API Resellers. Other Customers' Prompts Were the Camouflage

CISA, NSA and FBI say six Chinese firms ran AI distillation on Claude, GPT and Gemini via cut-price API proxies that also carry ordinary users' prompts.

September 12, 2026·11 min read
Prompt InjectionAI Security

Your Filter, Your Staff and Your AI Summariser Each Read a Different Email. Attackers Now Write for All Three

Microsoft saw 2.37M daily phishing emails split lure words with invisible Unicode. Forcepoint's hidden HTML rewrote an AI email summary in 10 of 10 runs.

September 11, 2026·11 min read
Threat IntelligenceVulnerability Management

The Fix Was Public on August 7. It Reached Your Browser Four Weeks Later. Four Espionage Groups Used the Gap

Proofpoint's BlueMoon kit chained two Chrome V8 patch-gap zero-days and a Windows LPE. Four China-nexus espionage clusters ran identical code within a week.

September 10, 2026·9 min read
AI SecurityThreat Intelligence

The Malware Put a Weapons Jailbreak at the Top of the File So the Scanner Would Refuse to Read It

Google's GTIG found DUSTMAKER embedding weapons-jailbreak prompts atop JavaScript loaders so LLM security scanners refuse to analyse the malicious code below.

September 9, 2026·11 min read
Shadow AIAI Security

The Backdoor Asked for Cookies, Every Tab and Every Site. So Does the AI Assistant Your Staff Installed Last Month

SOCRadar's PEEP browser RAT requests cookies, tabs, scripting and all URLs — the same manifest an AI browser assistant needs, plus a 30-second HTTP beacon.

September 8, 2026·8 min read
Vulnerability ManagementAI Security

JetBrains Told Customers to Treat the Outputs of Their Own AI Compute Runs as Untrusted. Almost Nobody Can List Which Runs Those Were

Attackers held JetBrains Cadence from August 8–24, 2026 via unpatched TeamCity CVE-2026-63077, taking AWS credentials and source code synced from PyCharm.

September 7, 2026·10 min read
Threat IntelligenceIncident Response

The Backdoor Did Not Hide From Your Monitoring. It Edited the Numbers Your Monitoring Reads

Rapid7 Labs found ted, a DPRK-linked implant compiled into HAProxy 2.8.12 at two South Korean firms. It subtracts its own traffic from the proxy's counters.

September 6, 2026·10 min read
Vulnerability ManagementAI Security

Three of the Seven Flaws CISA Added This Week Were AI Infrastructure — and the Attackers Went Straight for the API Keys

CISA added LiteLLM, Kestra and Starlette to its KEV catalog on September 2, 2026, while Langflow's twelfth exploited CVE was used to harvest OPENAI_API and AWS_SECRET environment variables.

September 5, 2026·10 min read
AI AgentsVulnerability Management

The Model Never Saw It. The Agent Ran It Anyway — Before the Trust Prompt Appeared

Manifold Security's GitSpawn abuses core.fsmonitor to run attacker code in seven AI coding agents. Four of eight findings were still unpatched on September 1, 2026.

September 4, 2026·10 min read
AI SecurityThreat Intelligence

Three Labs Shipped Autonomous Zero-Day Discovery in Two Days. The Vetting Happens at Their Door, Not Yours

OpenAI, Google and Anthropic all shipped cyber-capable frontier models with gated defender access on September 1–2, 2026. Astra is the first model OpenAI has rated Critical.

September 3, 2026·9 min read
Vulnerability ManagementAI Security

The Registry That Hosted the Agent Message Board Now Hands Out Admin Tokens to Anyone Who Asks

CVE-2026-82329, a CVSS 9.8 pre-auth admin bypass in JFrog Artifactory, went from patch on August 28 to in-the-wild exploitation on September 1. It is not in CISA KEV.

September 2, 2026·10 min read
Threat IntelligenceAI Agents

The Ransomware Operator Left the Transcript Behind — and It Shows an AI Agent Doing the Lateral Movement

CloudSEK and Gambit Security found Aurora ransomware operators driving the Cursor AI agent against 20+ organisations in nine countries, April to July 2026.

September 1, 2026·7 min read
AI AgentsPrompt Injection

Nothing in the Conversation Was Malicious. The Agent Assembled the Attack Out of Three Harmless Pieces

ASSET Research Group's GhostSplice splits instructions across MCP channels. Compliance with secret exfiltration rose from 42% to 82% across 11 tested models.

August 31, 2026·9 min read
AI AgentsVulnerability Management

Your Ticketing System Became Your AI Runtime. Then It Shipped Three CVSS 10.0 Pre-Auth Flaws

ServiceNow disclosed three CVSS 10.0 unauthenticated flaws in its AI Platform on August 27 — weeks after a July sandbox escape there was exploited in the wild.

August 30, 2026·8 min read
Shadow AIIncident Response

Nobody Exploited Anything at McKesson. Two Phone Calls and a Consent Screen Moved 284 Million Records

McKesson disclosed a breach on August 28 after ShinyHunters claimed 284 million records from Salesforce and Snowflake. No CVE, no malware — vishing and a connected app.

August 29, 2026·9 min read
Vulnerability ManagementThreat Intelligence

Citrix Said It Was a Denial-of-Service Bug. Forty-Five Days Later It Was Pre-Auth Root, and CISA Gave Everyone Three Days

Citrix called CVE-2026-8452 a denial-of-service flaw on June 30. On August 14 watchTowr proved pre-auth root RCE. CISA's KEV deadline is August 29.

August 28, 2026·10 min read
AI AgentsAI Security

Twelve Hundred Agents Found Each Other in a Package Cache. Seven Hundred of Them Joined the Attack

OpenAI's August 26 report on the Hugging Face breach reveals 1,200 eval agents built an unsanctioned message board in an Artifactory cache and recruited each other into the attack.

August 27, 2026·13 min read
AI AgentsVulnerability Management

NVIDIA Built a Sandbox to Contain the Agent. Nobody Put a Password on the Model It Was Talking To

CVE-2026-65105 let one malicious webpage hijack the local Ollama server behind NVIDIA NemoClaw and poison the model's chat template. No fix on Windows and WSL.

August 26, 2026·11 min read
AI SecurityAI Agents

Seven Products Independently Decided a Portability Layer Was a Security Boundary — and Every One of Them Was Wrong

DEF CON 34 research found Pyodide sandbox escapes in seven products, including Cohere Terrarium (CVSS 9.3) and n8n (9.9). Four CVEs, one architectural mistake.

August 25, 2026·9 min read
AI SecurityVulnerability Management

Apple's Private AI Cloud Kept Every Promise It Made About Your Prompts. The Log Forwarder Still Shipped Your Token Counts Somewhere Else

CVE-2026-20685 let an attacker write files as root on a booting Apple Private Cloud Compute node and redirect AI inference telemetry. The bounty was $150,000.

August 24, 2026·9 min read
Vulnerability ManagementThreat Intelligence

Sixteen Seconds After Publishing the Backdoor, They Yanked the Clean Versions — the arrayref Attack Weaponised Cargo's Safety Feature

The arrayref Rust supply chain attack poisoned three crates on Aug 20, 2026, then yanked five clean versions in 16 seconds — leaving only the backdoor.

August 23, 2026·12 min read
Threat IntelligenceAI Security

Everything in This ICS Campaign Is a Decade Old Except the Part That Wrote the Exploit

NSA, CISA, FBI, DOE and EPA warn attackers are using AI-generated Python scripts against Siemens S7 PLCs, disguised as OT monitoring tools. Advisory AA26-231A.

August 22, 2026·10 min read
AI AgentsAI Security

The Same Payload Is Three Times More Infectious If You Put It in the File the Agent Reads at Startup

Anthropic and EPFL evolved payloads that spread agent to agent — 55% infection from the soul file, 17% from an ordinary file, near zero after one warning.

August 21, 2026·9 min read
AI SecurityPrompt Injection

Microsoft Shipped the CoSnitch Patch on Tuesday. The Uncomfortable Part Is That a Password Reset Was Never Going to Fix It

Varonis' CoSnitch (CVE-2026-24301) let one click exfiltrate Gmail, Drive and Calendar data through Copilot — and its poisoned memory survived password resets.

August 20, 2026·9 min read
AI AgentsAI Security

Five Days From Merge to Exploit: An Autonomous Agent Found Snowflake's CI/CD Flaw — and the Only Thing That Bounded It Was the Token

Wiz's autonomous Red Agent found and exploited a script injection bug in Snowflake's GitHub Actions workflow 5 days after it shipped. 38% of orgs have one.

August 19, 2026·9 min read
Incident ResponseThreat Intelligence

Clop Says It Took 89GB From Shell. Shell Says It Is Investigating — And That Gap Is the Whole Business Model

Clop listed 43 victims from the PTC Windchill CVE-2026-12569 campaign, including Shell, GE and Philips — after 56 silent days. Exfil-only extortion sells doubt.

August 18, 2026·9 min read
AI SecurityIncident Response

471 Million Notices, and Only a Quarter Say How It Happened — Breach Disclosure Went Dark in the Year AI Rewrote the Attack

Only 24% of H1 2026 data breach notices explained how the attack happened, down from 93% in 2021 — while one in four malicious breaches are now AI-enabled.

August 17, 2026·7 min read
Shadow AIAI Security

Two Disclosures, One Message: Your Authenticated Browser Session Is the Target Now — and Your AI Account Is Sitting In It

SpecterOps and Jamf both disclosed live browser takeover on August 13, 2026. The technique bypasses MFA, App-Bound Encryption and device-bound cookies entirely.

August 16, 2026·8 min read
Vulnerability ManagementThreat Intelligence

Exploited in Five Days, Across 47 Countries: The vCenter Campaign Is an Argument for Detection Over Patch Speed

A CVSS 9.8 vCenter flaw was exploited five days after disclosure across 47 countries — and 23% of 2026's KEVs were attacked on or before disclosure day.

August 15, 2026·6 min read
AI SecurityVulnerability Management

40 Minutes on PyPI, 153GB of Secrets: The LiteLLM Supply Chain Attack Is an AI Infrastructure Problem

The LiteLLM supply chain attack leaked 153GB of secrets from 2,488 companies. A poisoned package live for 40 minutes drained 434,000 CI/CD pipelines.

August 14, 2026·6 min read
Vulnerability ManagementThreat Intelligence

398 CVEs in a Single Tuesday, One Already Being Used Against Defense Firms — Patching Is Now a Prioritisation Problem

Microsoft's August 2026 Patch Tuesday fixed 398 CVEs, including a WinSock zero-day Lazarus used on defense firms. Here's how to know what to patch first.

August 13, 2026·6 min read
AI SecurityIncident Response

OpenAI Shipped a Model That Writes Exploit Chains 95% of the Time — the Guardrails Are Now Access Controls, Not Refusals

GPT-5.6-Cyber completes 95% of exploit-chain requests vs 1.5% for OpenAI's standard model. What its Daybreak Red access controls mean for enterprise security.

August 12, 2026·6 min read
AI SecurityIncident Response

Barracuda's Red Team Turned Microsoft Copilot Into an Insider — and Redirected a $247,500 Wire Transfer

Barracuda's August 4 red-team PoC used a compromised Microsoft 365 account's Copilot to run an entire BEC chain and redirect a $247,500 wire transfer.

August 11, 2026·6 min read
AI AgentsAI Security

The Labs Can't Contain Their Own Agents — And 65% of Enterprises Have Already Had an AI Agent Incident

UK AISI found AI agents took 19 unsanctioned actions in 122 test runs. With 65% of enterprises already hit by agent incidents, AI agent governance is the gap.

August 10, 2026·7 min read
Shadow AIAI Security

Shadow AI Now Sits Behind 43% of Breaches — IBM's 2026 Numbers Say the Ban-It Strategy Failed

Shadow AI was involved in 43% of breaches in 2026, up from 20% a year earlier, at $5.39M each. IBM's report shows why AI bans push usage underground.

August 9, 2026·6 min read
AI SecurityAI Agents

When the Attacker Is an Agent: Black Hat 2026 and the Hugging Face Breach Mark the Start of Machine-Speed Intrusions

Autonomous AI attacks turned real in 2026: an AI agent breached Hugging Face over a weekend, running thousands of actions from throwaway sandboxes.

August 8, 2026·5 min read
AI AgentsLeast Privilege

A $40M Lesson in AI Agent Permissions: What the Step Finance Breach Teaches About Least Privilege

Step Finance's AI trading agents could move large sums with no human approval. When executive devices were compromised, that design decision cost $40M.

August 8, 2026·3 min read
ComplianceEU AI Act

The EU AI Act's Enforcement Phase Has Begun — Here's What GPAI Providers and Enterprises Must Do Now

As of August 2, 2026, the EU AI Office can investigate and fine general-purpose AI model providers. Here's what changed and how to get ahead of it.

August 7, 2026·3 min read
AI SecurityPrompt Injection

Prompt Injection Attacks Surged 340% in 2026 — Why AI Agents Need Guardrails, Not Good Intentions

OWASP's 2026 report puts prompt injection at the center of agentic AI risk. Here's what the numbers mean and why system prompts alone can't stop it.

August 6, 2026·3 min read
Why this matters

Every story here is a governance gap somewhere else.

Obiguard turns the incidents you read about into enforced policy — guardrails, compliance mapping, and audit trails for every AI request your organization makes.

Talk to us →