Ah, the brave new world where AI-generated content is the norm, but with a whispering touch:…
Category: Security
OVSwrap: How a 13-Year-Old Kernel Bug Suddenly Became a Root Exploit
A flaw in the Linux kernel’s Open vSwitch datapath shows how a small implementation detail can…
When AI Hackers Escape the Sandbox
The latest wave of AI cybersecurity evaluations highlights a challenge that is becoming increasingly important: how…
One Oversized Packet Was Enough to Skip Apple’s Screen Sharing Login
Apple’s built-in Screen Sharing service is supposed to expose only a login prompt to the network.…
Codex Security Brings AI-Powered Security Reviews to the Command Line
Modern software development increasingly relies on automation, but security reviews often remain one of the last…
When a Git Worktree Became an AI Agent Escape Hatch
Claude Code’s worktree bug is a useful reminder that AI coding agents are not just “chat…
US Government Halts Anthropic’s AI Models Citing Security Fears, Sparks Industry Controversy
The US government has suddenly pulled the plug on Anthropic’s Fable 5 and Mythos 5 models,…
The Build Log That Spoke to AI Agents
Most software supply-chain discussions focus on code: malicious dependencies, compromised registries, unexpected network calls, or hidden…
The Vulnerability Bottleneck Has Moved
Security teams have spent years treating vulnerability discovery as the hard part. The latest numbers from…
Shai-Hulud and the Danger of Trusted Packages
Supply chain attacks rarely need clever exploits. They often need something simpler: a trusted package, a…
YellowKey Turns BitLocker Into an Open Door
There is a certain kind of vulnerability that feels less like a bug and more like…
When Apple Accidentally Shipped Its AI’s Playbook
A small packaging mistake can reveal a lot about how modern software is actually built. In…
GPT-5.4-Cyber: Testing Trust at the Edge of AI Security
OpenAI is testing how far an AI system can responsibly go when the goal is defense…
Zero-Day Every Day: The Vulnpocalypse Is Here
An AI found 500+ zero-days in production software — including Ghost CMS and the Linux kernel…
AI-generated bug reports have improved across the board
Imagine sitting down for lunch and next to you is Greg Kroah-Hartman, a key figure in…
Beware: LiteLLM AI Gateway Users Hit by Supply Chain Attack through Compromised PyPI Packages
Heads up, developers. There’s a potential security issue with LiteLLM, a popular AI Gateway, involving compromised…
Meet Shannon by Keygraph: The AI Breakthrough in Autonomous Web Security Testing
Alright, cyber enthusiasts, let’s talk about Shannon by Keygraph—a game changer in the realm of AI-powered…
Someone Built a Firewall for Claude Code — And You Probably Need It
If you’re letting Claude Code read arbitrary files, fetch random web pages, or pipe raw command…
AI Agents Are Privileged Processes. We’ve Been Treating Them Like Chatbots.
Someone sends you a link. You click it. Within milliseconds, before your next keystroke, an attacker…
Cheddar Bench: Coding Agents Playing Bug Treasure Hunt
Let’s talk about Cheddar Bench—a brilliant unsupervised benchmark that’s turning bug detection into an exciting treasure…