Anthropic finds evidence of a fourth AI escaping from containment
After this discovery, the company instigated a wider search of 481 million transcripts, covering all those from its Frontier Red Team, some non-cyber evaluations, reinforcement…
After this discovery, the company instigated a wider search of 481 million transcripts, covering all those from its Frontier Red Team, some non-cyber evaluations, reinforcement…
Today, we’re making Cloudflare CASB more powerful than ever by introducing automatic remediation policies. This means security teams can now design event-driven logic to revoke…
Acknowledgments: Special thanks to Jon Semon, Andrew Brant, and Lindsey O’Donnell-Welch for their contributions to this investigation and writeup. Background There’s still three months until…
As AI platforms become part of daily workflows, attackers have found a new way in: the platforms themselves. The Huntress Security Operations Center (SOC) says…
A critical flaw in current security operations is assuming time is on our side. Historically, attacks progressed slowly, allowing analysts and response teams time to…
In one case, a group of Russian state-sponsored hackers identified by Microsoft as Midnight Blizzard used Claude for reconnaissance, breaching targets that included Ukrainian and…
Threat actors are increasingly using Claude-based AI workflows to automate cyberattacks, accelerate data theft, and reduce the technical expertise needed to run complex intrusions. Anthropic’s…
Canonical shipped Ubuntu 24.04.5 LTS, bundling security updates and fixes for high-severity bugs into new installation media for the “Noble Numbat” release. Anyone installing fresh…
The “major malicious attack” that targeted RubyGems in May 2026 was the work of a swarm of OpenAI agents, according to a new report published…
Public sector organisations must move beyond “conversational AI [artificial intelligence]” to “full transformation”. Those that do, and redesign workflows around advanced AI technology, report average…
Cold cryptocurrency storage provider Trezor says roughly 347,000 of its customers received phishing emails after a third-party marketing platform used by the company was hacked.…
Looks like TerminalFix The technique observed in this case is consistent with an attack pattern Microsoft calls TerminalFix, a variant of ClickFix. These attacks use…