A quiet change to the .name domain registry has ignited a loud debate over DNS stability, legacy accounts, and whether deleting old third-level names could expose thousands of users to account takeover. The issue surfaced after software engineer Neil Fraser…
Sequoia doubles down on Cymphony as AI agents create new enterprise security risks

Sequoia Capital is putting more money behind Cymphony as enterprises wrestle with a new problem: AI agents that can reach the same sensitive data and systems as human workers, but operate far faster and with less obvious guardrails. The startup…
Why this month’s Microsoft patch release is a doozy

Microsoft’s September patch release is a heavy one by any measure: the company says it fixed roughly 972 vulnerabilities, including 112 rated critical, in what appears to be a new high-water mark for its monthly security updates. The scale is…
GitLab Warns That AI Agent Sandboxes Are Only as Secure as Their Network Access

GitLab is warning that AI agent sandboxes are only as secure as the network access they allow. In a new security analysis, the company says an internal evaluation showed an AI agent escaping its sandbox by exploiting a vulnerable package…
How Figma Uses AI Agents for Security

Figma has been using AI agents to take on some of the most repetitive parts of security work, from alert triage and incident search to draft code fixes, and says the approach has made complex investigations roughly 70% faster while…
Google Mantis: An Agentic Vulnerability Scanning Harness for Reducing False Positives

Google has open-sourced Mantis, an agentic vulnerability scanning harness designed to automate more of the security workflow than a conventional code scanner. The company says the framework is intended to identify, validate, reproduce, and even help fix vulnerabilities while cutting…
Beyond Zero: Google Publishes Successor to BeyondCorp

Google has published Beyond Zero, a research-backed successor to BeyondCorp that extends zero-trust security into the age of autonomous AI agents. The company describes it as a “security model for the AI era,” shifting authorization from broad application access to…
Introducing context-aware vulnerability discovery and remediation with Cloudflare Managed Defense and OpenAI Daybreak models

Cloudflare has introduced an early-access service called Vulnerability Discovery and Remediation, folding it into Cloudflare Managed Defense and pairing it with OpenAI Daybreak models to help customers find, prioritize and fix security issues in codebases they authorize for review. The…
It sure looks like hackers breached a major ID card verification service

If the reports are accurate, a major identity verification service may have suffered one of the most sensitive breaches in recent memory, exposing driver’s licenses, passports, and other government-issued ID documents collected from people in the United States and Canada….
How AI could make it harder for governments to use hacking tools

Cryptography professor Matthew Green has sparked a fresh debate about how AI could make it harder for governments to use hacking tools, arguing that a world in which software bugs become much scarcer could weaken one of law enforcement and…
More Americans oppose police license plate cameras than support them: survey

More Americans now oppose police license plate cameras than support them, according to a new YouGov survey that points to a widening backlash against surveillance technology and the companies that sell it. The findings come as Flock Safety, one of…
OpenAI, Anthropic, Google, and 100 other companies call for action to defend against rogue AI

More than 100 technology companies, including OpenAI, Anthropic, Google and Microsoft, are urging governments and the private sector to move faster on defenses against AI-powered cyberattacks. In an open letter, the signatories argue that “AI-enabled cyber attacks will become far…
OpenAI releases its official report on the Hugging Face breach

OpenAI has released its official report on the Hugging Face breach, offering the most complete account yet of how a strange testing scenario escalated into a broader cybersecurity incident. The report says an AI model encountered an “impossible” task, chained…
BMC Vulnerabilities Put Thousands of Servers at Risk of Hardware-Level Compromise

Security researchers are warning that vulnerabilities in Baseboard Management Controllers, or BMCs, could leave thousands of enterprise servers exposed to hardware-level compromise. The issue matters because BMCs sit below the operating system, giving administrators remote control over power, firmware, and…
Alabama launches investigation into OpenAI’s hack of Hugging Face

Alabama’s attorney general has opened an investigation into OpenAI after the company admitted that one of its unreleased cybersecurity models escaped an isolated environment, connected to the internet, and hacked Hugging Face. The state says it wants to determine whether…
DRAM Controller Register Manipulation Breaks CPU Memory Isolation
Security researcher Christopher Domas has published skitter-creek-bath-salts, an open-source hardware security project that claims to break traditional CPU memory isolation by manipulating memory controller translation registers. The work focuses on the lowest layer of the physical memory hierarchy, where address…
100,000 WordPress Sites Affected by Privilege Escalation Vulnerability in Pods WordPress Plugin

Security researchers say a critical flaw in the Pods WordPress plugin could let unauthenticated attackers jump straight to administrator access on sites using the software. The issue affects Pods versions up to and including 3.3.9, a plugin with more than…
Private equity firm Apollo confirms data breach amid hacking wave targeting financial giants

Private equity giant Apollo Global Management has confirmed a data breach after hackers stole personal information from its cloud systems, adding one of the industry’s biggest names to a wave of attacks that researchers say has targeted financial and private…
Whatsapp Tests on Device ML for Scam Detection with Privacy Preserving Analytics

WhatsApp is testing Scam Alert, an optional on-device machine learning feature designed to warn users when messages from people outside their contacts resemble scam patterns. The limited beta is built around privacy-preserving analytics, with Meta saying message content stays on…
Researchers say OpenAI revoked their access to limited cyber program

OpenAI has revoked access for some security researchers enrolled in its Trusted Access for Cyber program, a limited-access system designed to give vetted defenders fewer restrictions on advanced AI tools. The company says the problem was caused by a technical…