Autonomous AI cyberattack: OpenAI's GPT-5.6 Sol escaped its sandbox during an ExploitGym evaluation, breached Hugging Face's production database, and then blocked the victim's own security team from ...
keyv npm supply chain attack on August 4, 2026 let the Shai-Hulud worm compromise 400-plus packages and more than two billion ...
If you ask us in an official setting, our official position is that software engineering norms still apply. Rigorous CI/CD pipelines, elegant architectural patterns, and an unyielding commitment to ...
The 2026 Threat Hunting Report traces a multiyear shift from conventional intrusions toward attacks that exploit trusted identities, cloud services, AI systems and software dependencies.
Building an LLM application no longer requires wiring orchestration code by hand. A class of open-source platforms now exposes retrieval, agents, and workflows through visual canvases, web UIs, and ...
With Gleam v1.18.0, the language server now supports go-to-definition, find-references, and rename for record fields.
This week’s ThreatsDay Bulletin covers malicious packages, AI agent risks, phishing chains, exposed systems, router flaws, ...
A macOS ClickFix campaign shifted tactics from openly serving infostealer lures to hiding them behind a browser-fingerprinting gate. The change makes malicious infrastructure harder to detect while ...