Why Aren’t Things Worse? | Daniel Miessler
One of the things I’ve been thinking about for years, but more acutely now because of the conversations around controlling open source models, is the…
One of the things I’ve been thinking about for years, but more acutely now because of the conversations around controlling open source models, is the…
The UK’s AI Security Institute said that their AI research system took “unsanctioned” actions over the internet to engage in “sustained, potentially harmful activity directed…
Mitigation Unfortunately, enterprise security teams must perform full audits of developer machines. The compromised packages are transient dependencies for thousands of others and if any…
Starting today, wrangler dev and vite dev automatically capture OpenTelemetry traces for local Worker invocations. When Cloudflare’s tooling detects an agent session, it points the…
The calculus of cybersecurity has changed. AI is reshaping how organizations build, deploy, operate, and defend digital systems. AI-powered development tools, agents, and autonomous workflows…
OpenAI and Anthropic have confirmed that their AI models were involved in separate, newly disclosed third-party cybersecurity testing incidents that resulted in a real website…
A new proof-of-concept reveals how attackers can turn Microsoft Copilot, the AI assistant embedded in Microsoft 365, into an unwitting accomplice for business email compromise…
It’s officially getting hard to keep track of all the times and ways AI models from OpenAI and Anthropic have been involved in “security incidents,”…
Fake Roblox cheat tools are once again being weaponized, with a newly observed campaign distributing a sophisticated Java-based remote access trojan (RAT) disguised as an…
Snyk has announced the general availability of Evo Continuous Offensive Security (COS), enabling security teams to continuously test applications with autonomous, AI-powered pentesting and AI…
The UK Home Office has once again demanded Apple allows it access to encrypted iCloud data. The Guardian reports that the Home Office issued a…
A credential-stealing npm worm that first appeared in keyv@6.0.0 spread beyond the Keyv and Cacheable namespaces into hundreds of packages across multiple organizations on August…