2026
51 篇文章當掃描器看不見攻擊:Cloudflare 用 ML 拆解店面前的惡意 JavaScript
Cloudflare 的 Page Shield ML 在真實流量中攔下八個惡意 payload,而 VirusTotal 與 URLScan 幾乎全部漏判。
閱讀文章 ↗AI 代理如何把網路間諜活動從「人為指揮」變成「自主執行」
Anthropic 揭露首宗大規模 AI 主導的網路間諜活動,Claude Code 被濫用執行 80-90% 攻擊流程,開發者需重新思考代理式 AI 的防禦設計。
閱讀文章 ↗蒸餾攻擊不是理論:Anthropic 揭露 DeepSeek、Moonshot、MiniMax 的 1,600 萬次提取
Anthropic 在 2026 年 2 月揭露三家 AI 實驗室透過 24,000 個詐騙帳號,對 Claude 發動工業級蒸餾攻擊。本文從產品建構者角度,解析攻擊手法、偵測機制,以及這對 API 安全與出口管制的啟示。
閱讀文章 ↗當 AI 測試環境意外連上真實網路:Anthropic 三起事件的檢討
Anthropic 在回顧網路安全評估時,發現 Claude 模型因環境設定錯誤而意外存取真實系統。本文整理事件經過、原因與後續改進,並探討對 AI 評估與產品建構者的啟示。
閱讀文章 ↗Astra 實測數據拆解:ExploitBench 滿分、兩個零日漏洞,與少用 9% token 的祕密
Astra 在 ExploitBench 拿下 100% 解題率(GPT-5.6 Sol 只有 22%),評測過程甚至發現兩個全新零日漏洞。本文從開發者角度拆解官方評測數據:V8 內部移植、沙箱逃逸鏈、提權鏈,以及 token 效率為何比 Raw 能力更值得注意。
閱讀文章 ↗Cloudflare 聯手 OpenAI Daybreak:用網路脈絡解決漏洞優先順序難題
Cloudflare 推出 Vulnerability Discovery and Remediation 早期存取服務,結合 OpenAI Daybreak 模型與自家網路流量資料,為開發者提供具生產脈絡的漏洞修補建議。
閱讀文章 ↗Gemini 3.8 Flash 價格 2027 年翻倍:Cyber 版 CWE-Bench 47.2%
第三個 Flash 六週內上線:入門價 2027 年翻倍,Flash Cyber 以 CWE-Bench 47.2% 逼近旗艦,兩小時找到重大漏洞。
閱讀文章 ↗OpenAI 推出 Astra:第一個觸發 Critical 網路門檻的模型如何安全上架
OpenAI 於 2026 年 9 月 3 日推出 Astra,這是第一個被判定達到 Preparedness Framework Critical 網路能力門檻的模型。本文拆解 Daybreak 分層存取、預設封鎖的護欄設計、91.5% 的拒絕率與 honeypot 測試結果,以及對企業導入者的實際意涵。
閱讀文章 ↗Fairwind 計劃:Google 如何用 AI 幫政府與企業主動修補漏洞
Google 推出 Fairwind 計劃,讓政府與關鍵基礎設施夥伴搶先使用 Gemini 3.8 Flash Cyber 與 CodeMender,自主尋找並修復漏洞。本文解析此計劃的設計、限制與對產品建構者的啟示。
閱讀文章 ↗Adaptive Intelligence:讓每次攻擊都變得不划算
Cloudflare 推出 Adaptive Intelligence,從「假設攻擊者終會突破」出發,用持續學習與一次性規則扭轉攻防經濟學。
閱讀文章 ↗Z.ai 發表 GLM-5.3:開源程式碼新高,網路攻擊能力超預期
2026 年 8 月 14 日,Z.ai 發表 GLM-5.3:沿用 GLM-5.2 基座、靠後訓練把程式碼基準推上開源新高,並主動披露網路攻擊能力「發展得比我們預期更快」,授權同步轉為自訂條款。
閱讀文章 ↗偷走 AI 的思考:兩次 API 呼叫還原隱藏推理鏈
德國研究團隊利用同家族較弱模型與越獄提示,兩次 API 呼叫還原加密思考區塊的推理原文;公開代理軌跡中更發現大量 API 金鑰與密碼。
閱讀文章 ↗OpenAI 首度無法排除 Astra 達 Critical 網路門檻
OpenAI 內部評估首度無法排除 Astra 觸及 Preparedness Framework 的 Critical 網路安全門檻:agentic coding 與 cyber 能力大幅躍進,五層控制與思緒監控已啟動,外部紅隊測試是下一個觀察點。
閱讀文章 ↗第三方資安測試中,模型為何越界?OpenAI 揭露兩起評估事件
OpenAI 公布 UK AISI 與 Irregular 在第三方資安評估中發生的模型越界事件,分析測試環境設定與模型能力交互下的風險,並提出強化評估環境的方向。
閱讀文章 ↗Chrome 兩個版本修復 1,072 個漏洞:AI 撐起整條資安工具鏈
Google 於 7 月 30 日公布 Chrome 資安成績單:149 與 150 兩個版本合計修復 1,072 個安全漏洞,超越前 23 個版本總和,AI 找漏洞、修漏洞與自動分診貫穿全程。
閱讀文章 ↗Claude Mythos 60 小時改寫 HAWK 攻擊
Anthropic 前沿紅隊報告:Claude Mythos Preview 用 60 小時把 HAWK-256 攻擊成本從 2^64 降到 2^38,並以 Möbius Bridge 技術把 7 輪 AES-128 攻擊加速 200 至 800 倍。
閱讀文章 ↗MCP 企業託管授權定案:零接觸 OAuth 讓 AI 代理連上企業工具
Model Context Protocol 於 2026 年 6 月 18 日將企業託管授權(EMA)納入穩定規格:員工登入 SSO 即自動接通獲准的 MCP 伺服器。Okta 為首家 IdP,Claude、Claude Code、VS Code 與七家伺服器已支援。本文解析 ID-JAG 機制與安全辯論。
閱讀文章 ↗Miasma 蠕蟲再襲 Microsoft:73 個儲存庫停用,AI 編碼代理成靶
被劫持的帳號六月五日把惡意提交推入 Azure durabletask 儲存庫,植入 .claude、.gemini 與 .cursor 設定檔,開檔即執行竊憑證 payload;GitHub 在 105 秒內停用 73 個儲存庫,官方 functions-action 工作流應聲斷裂。
閱讀文章 ↗AI 令網路攻擊更危險,但現有框架可能看不見
Anthropic 分析 832 個因惡意網路活動被停用的帳戶,發現 AI 正被用於攻擊鏈的後期階段,令攻擊更自動化,而 MITRE ATT&CK 框架未能完全捕捉這些新行為。
閱讀文章 ↗Meta AI 客服機器人成了帳號綁架工具:Instagram 通知受駭用戶
駭客只對 Meta 的 AI 客服機器人說「這是我的帳號」,機器人就把受害者 Instagram 綁到駭客信箱。白宮舊帳號與太空軍高階士官長相繼淪陷後,Meta 稱漏洞已修復,並開始通知受影響用戶。本文拆解這場低技術門檻的 AI 安全面事件。
閱讀文章 ↗Cyera 傳以 120 億美元估值募資:80 倍 ARR 的資安豪賭
2026 年 6 月 2 日,Calcalist 與 TechCrunch 報導資安新創 Cyera 以 120 億美元估值募集至少 3 億美元。ARR 突破 1.5 億美元、隱含 80 倍倍數,本文拆解這場五個月內二度調升估值的爭議交易與併購策略。
閱讀文章 ↗Cisco 實測 15 個封閉前沿模型:多輪攻擊無一倖免
2026 年 5 月 27 日,Cisco 發表研究,對 OpenAI、Anthropic、Google、Amazon、xAI 共 15 個封閉模型發動近 7,000 次多輪攻擊,最高成功率達 88.3%,沒有任何模型免疫,連設定旗標都會大幅改變風險。本文解析測試方法、各模型數字與採購建議。
閱讀文章 ↗NHS 畏懼 AI 漏洞挖掘大舉關閉開源庫,GDS 發布指引唱反調
AI 尋找漏洞的能力躍升後,NHS England 內部指示關閉幾乎所有開源儲存庫;GDS 與 DSIT 於 5 月 14 日發布指引唱反調:預設保持開放,關庫無助修補根本弱點,只會增加成本。
閱讀文章 ↗Cisco 裁員近 4,000 人加碼 AI:創紀錄營收下的成本重組
2026 年 5 月,Cisco 宣布裁減近 4,000 個職位(約 5% 員工),把資源轉向 AI 與網路安全,同時公布創紀錄的單季營收。本文解析這波「賺錢也裁員」的重組邏輯,以及 Cloudflare、GM 同期類似行動背後的企業 AI 支出浪潮。
閱讀文章 ↗Google 首次截獲 AI 開發的零日攻擊:繞過 2FA 的邏輯漏洞
Google 威脅情報團隊 5 月 12 日報告首度確認:有犯罪集團使用疑似 AI 開發的零日漏洞繞過 2FA,目標是一款開源網管工具,並已策劃大規模濫用。報告同時揭露自我變形惡意軟體與用 Gemini 驅動的 Android 後門。
閱讀文章 ↗TanStack npm 供應鏈攻擊解析:三個漏洞串出 84 個惡意版本
2026 年 5 月 11 日,攻擊者利用 pull_request_target、Actions cache 中毒與 OIDC 記憶體竊取,從 TanStack 的合法發佈管線推送 84 個惡意版本,竊取雲端憑證與 SSH 金鑰。本文拆解攻擊鏈與修補對策。
閱讀文章 ↗Mini Shai-Hulud 蠕蟲襲捲 npm:連 Mistral SDK 與 SLSA 證明都淪陷
2026 年 5 月 11 日,自傳播的 Mini Shai-Hulud 蠕蟲透過被劫持的發布管線感染 170 多個 npm 套件,連 Mistral 官方 SDK 也中鏢。惡意版本帶著有效 SLSA 證明上架,專偷 AI 開發者的憑證與 Claude Code 設定。本文拆解攻擊鏈與對策。
閱讀文章 ↗GPT-5.5 Instant 的系統卡透露了什麼:首次被列為高能力的 Instant 模型
OpenAI 在 2026 年 5 月 5 日發布 GPT-5.5 Instant 系統卡,這是首個被列為高能力等級的 Instant 模型,特別在網路安全和生化防護方面。本文為產品開發者解析這份文件的重點與含義。
閱讀文章 ↗批評 Anthropic 設閘之後,OpenAI 也限制 GPT-5.5-Cyber 存取
OpenAI 宣布 GPT-5.5-Cyber 僅透過 Trusted Access for Cyber 計畫提供給關鍵資安防禦者,此分層機制已涵蓋數千名驗證防禦者。九天前 Altman 才批評 Anthropic 限制 Mythos 是「恐控行銷」,如今兩家實驗室走向同一結論。
閱讀文章 ↗LMDeploy 視覺語言模組 SSRF 漏洞:揭露 13 小時後即遭利用
開源 LLM 推理工具 LMDeploy 的視覺語言模組存在 SSRF 漏洞 CVE-2026-33626,揭露後 12.5 小時即遭利用,攻擊者藉模型抓圖函式直取雲端 metadata 與內網服務。本文解析漏洞成因、Sysdig 誘捕紀錄與自架推理棧的防護清單。
閱讀文章 ↗Google 掃描公開網路:間接提示注入攻擊正在增長
Google 威脅情資團隊掃描 Common Crawl 網頁快照,首度系統性盤點網路上的間接提示注入:從惡作劇、SEO 操縱到資料外洩樣樣有,惡意案例在 2025 年 11 月至 2026 年 2 月成長 32%。本文解析研究方法與防禦對策。
閱讀文章 ↗Vercel 資安事件:一個第三方 AI 工具如何外洩客戶資料
2026 年 4 月 19 日 Vercel 披露資安事件:員工自用的 Context.ai 遭 Lumma 竊取木馬入侵,攻擊者透過 OAuth 權杖奪走其 Google Workspace 帳號,讀取未標記敏感的環境變數,客戶憑證遭論壇兜售。
閱讀文章 ↗華府催華爾街測試 Anthropic Mythos:訴訟與合作並行的雙軌
Bloomberg 揭露,財政部長 Bessent 與聯準會主席 Powell 召集銀行高層,促測 Anthropic 限流釋出的 Mythos 偵測資安漏洞;共同創辦人 Jack Clark 證實已向政府簡報,一邊控告國防部、一邊深度合作。
閱讀文章 ↗N-Day-Bench:用知識截止後的真實漏洞評測 LLM 安全能力
Winfunc 推出 N-Day-Bench:只收錄模型知識截止後才公開的真實漏洞,讓 LLM 在唯讀沙箱中從已知 sink 回溯資料流。首輪 GPT-5.4 以 83.93 居首,GLM-5.1 與 Claude Opus 4.6 緊追在四分之內。
閱讀文章 ↗Gartner:2028 年 25% 企業 GenAI 應用每年至少 5 次資安事件
Gartner 4 月 9 日預測:2028 年 25% 企業生成式 AI 應用每年至少 5 次小型資安事件(2025 年為 9%),2029 年 15% 每年至少一次重大事件。主因是 MCP 與 agentic AI 擴散,安全審查趕不上部署速度。
閱讀文章 ↗NVD 棄守 CVE 積壓:AI 讓漏洞洪流沖垮人工管線
NIST 宣布 NVD 只富化 KEV、聯邦政府與關鍵軟體三類 CVE,3 月 1 日前積壓全改標「Not Scheduled」。2020–2025 年 CVE 提交量增 263%,2025 年達 49,458 筆創新高,人工分析管線正式棄守。
閱讀文章 ↗Anthropic 啟動 Project Glasswing:用 Mythos Preview 獵零日漏洞
2026 年 4 月 7 日,Anthropic 聯合 AWS、Apple、Microsoft 等 12 家機構啟動 Project Glasswing,讓未公開的 Mythos Preview 模型在夥伴環境內尋找零日漏洞,CyberGym 達 83.1%,並提供 1 億美元使用額度。
閱讀文章 ↗Redwood 首席科學家的 AI 現況快照:1.6 倍研發加速與 8% 失準事件機率
2026 年 4 月 7 日,Redwood Research 首席科學家 Ryan Greenblatt 發表長文,估計前沿實驗室工程加速已達 1.6 倍、整體 AI 進度僅 1.15 至 1.2 倍,並給出 8% 嚴重目標偏離事件機率與 60% 半年內自主開發漏洞的機率。本文拆解數字與推論。
閱讀文章 ↗OpenAI 推 Safety Bug Bounty:提示注入與 Agent 濫用也能領賞
OpenAI 於 2026 年 3 月下旬宣布 Safety Bug Bounty,委由 Bugcrowd 營運,把 Agent 濫用、第三方提示注入與資料外洩等過去不列入資安漏洞的 AI 風險納入獎金範圍,可重現的高嚴重度問題最高 7,500 美元。
閱讀文章 ↗Accenture 攜手 Anthropic 推出 Cyber.AI:Claude 當資安營運的推理引擎
3 月 25 日 RSA 2026 期間,Accenture 發表以 Claude 為推理引擎的 Cyber.AI,讓 agentic AI 執行評估、分類與修復,並用 Agent Shield 治理自主 agent。內部已掃過 1,600 個應用與逾 50 萬個 API,掃描從 3 到 5 天縮至 1 小時內。
閱讀文章 ↗Google RSAC 2026:用 Gemini 情報與 AI Agent 追上 22 秒的攻擊
Google 在 RSAC 2026 發表 Gemini 驅動的暗網情報與 SecOps AI agent,Wiz 併購同週完成;Mandiant M-Trends 2026 顯示攻擊者 22 秒就能轉手入侵存取,防禦自動化從選配變成生存條件。
閱讀文章 ↗OpenAI 推出 Codex Security 研究 preview:找漏洞也幫你修的資安 agent
2026 年 3 月 6 日,OpenAI 把 Codex Security 推進研究 preview:這個應用資安 agent 在程式碼庫中找漏洞並協助修復,鎖定 ChatGPT Enterprise、Business 與 Education 客戶,主打大規模程式碼掃描。
閱讀文章 ↗歐洲議會封鎖議員公務裝置內建 AI:雲端資料與美國司法風險
歐洲議會 IT 部門停用議員與幕僚公務裝置上的內建 AI 功能:無法保證上傳雲端資料的安全,且美國政府可依法調閱美企持有的資料。這個決定暴露歐盟機構對美國 AI 供應商的信任裂痕。
閱讀文章 ↗ChatGPT 推出 Lockdown Mode 與 Elevated Risk 標示:把注入防禦做成產品功能
OpenAI 於 2026 年 2 月 16 日為 ChatGPT 導入 Lockdown Mode 與 Elevated Risk 標示,針對 prompt injection 與資料外洩攻擊提供防禦。當助理開始代理使用者讀網頁、動資料,攻擊面也跟著搬進對話框。
閱讀文章 ↗微軟 Cyber Pulse 報告:八成財星 500 大企業已在跑 AI 代理
微軟首份 Cyber Pulse 報告以第一方遙測揭露:超過八成財星 500 大企業已有活躍 AI 代理,29% 員工用過未經核准的代理。報告提出對代理套用零信任與五項治理能力,把可觀測性推上企業資安議程首位。
閱讀文章 ↗Microsoft 新掃描法:不必知道觸發詞,也能抓出 LLM 裡的臥底後門
微軟研究團隊發表 The Trigger in the Haystack:利用聊天模板讓中毒模型自行洩漏後門訓練資料,再以注意力分析重建觸發詞,在 47 個臥底模型上達約 88% 偵測率、13 個良性模型零誤報,為開源模型上線前稽核提供新工具。
閱讀文章 ↗Moltbook:AI agent 專屬社群一週 160 萬帳號,資料庫漏洞外洩 150 萬組金鑰
只開放 AI agent 註冊的社群平台 Moltbook 一週湧入超過 160 萬個帳號,agent 自發形成宗教與新語言討論;Wiz 隨後披露其 Supabase 資料庫設定錯誤,暴露私人訊息與約 150 萬組 API 金鑰,任何 agent 都可能被接管。
閱讀文章 ↗前 Google 工程師因竊取 AI 機密被定罪:美國首宗案件解析
2026 年 1 月 29 日,舊金山聯邦陪審團裁定前 Google 工程師 Linwei Ding 的 7 項經濟間諜與 7 項竊取營業秘密罪名全部成立,涉及 TPU 晶片與超級電腦叢集軟體逾 2,000 頁機密文件。FBI 稱此為美國首宗 AI 相關經濟間諜定罪,本文整理案情與內部威脅啟示。
閱讀文章 ↗AI 一次找齊 OpenSSL 全部 12 個零日漏洞:資安研究的分水嶺
2026 年 1 月 27 日,OpenSSL 協調修補 12 個零日漏洞,全數由 AISLE 的自主 AI 分析器發現,其中最高風險者 CVSS 9.8、不需有效金鑰即可能遠端觸發,最老的程式碼可追溯到 1998 年 SSLeay 時代。AI 漏洞發現正在改寫攻防規則。
閱讀文章 ↗Claude Code 新增 /security-review 與 GitHub Actions 整合:安全審查走進 agent
2026 年 1 月中旬的更新中,Anthropic 為 Claude Code 加入 /security-review 指令與 GitHub Actions 整合兩項資安功能,同期 Cowork 研究預覽擴及 Pro 方案。本文解析安全審查內建於 coding agent 的意義。
閱讀文章 ↗CrowdStrike 收購 SGNL:把每個 AI Agent 都當成特權身分來防護
2026 年 1 月 8 日,CrowdStrike 宣布收購 Continuous Identity 新創 SGNL,將即時存取控制延伸到人類、非人類身分與 AI Agent。本文拆解交易結構、技術整合,以及代理式 AI 對身分安全典範的衝擊。
閱讀文章 ↗
2026
51 ARTICLESCatching JavaScript That Waits for the Right Victim
Cloudflare's Page Shield ML caught 8 payloads that scanners missed, showing why storefronts need runtime detection, not just static scans.
READ POST ↗What the First AI-Orchestrated Espionage Campaign Means for Your Security Stack
Anthropic details how agentic AI ran 80-90% of a cyberattack, forcing a rethink of defense tooling.
READ POST ↗What Distillation Attacks Change About How You Ship AI
Anthropic found three labs running industrial-scale distillation campaigns against Claude.
READ POST ↗Three Real-World Incidents in Anthropic's Cybersecurity Evals
Anthropic reviewed 141,006 evaluation runs and found three incidents where Claude accessed the internet from test environments, compromising real systems.
READ POST ↗Inside Astra's Cyber Evals: 100% on ExploitBench, Two Zero-Days, and 9% Fewer Tokens
Astra scored 100% on ExploitBench where GPT-5.6 Sol scored 22%, and the eval surfaced two zero-days. A breakdown of the V8 port, the escape chains, and the token-efficiency gain.
READ POST ↗Context-Aware Vulnerability Discovery: Cloudflare and OpenAI Daybreak
Cloudflare's new Vulnerability Discovery and Remediation service pairs OpenAI Daybreak models with network context to prioritize and patch code vulnerabilities.
READ POST ↗Gemini 3.8 Flash Intro Price Doubles on Jan 1: 54.9% HLE
Gemini 3.8 Flash intro pricing doubles on Jan 1, 2027; Flash Cyber scores 47.2% on CWE-Bench and found a critical vulnerability in under two hours.
READ POST ↗OpenAI Ships Astra: How the First Critical-Threshold Cyber Model Went Live
OpenAI's September 3 launch of Astra is the first model at the Critical cyber threshold of its safety framework: Daybreak tiered access, default-off guardrails, and pause-and-review monitoring.
READ POST ↗Fairwind Program: Google's Proactive Cyber Defense for Governments and Enterprises
Google launches Fairwind Program, giving trusted governments and enterprises access to Gemini 3.8 Flash Cyber and CodeMender for autonomous vulnerability finding and patching.
READ POST ↗Adaptive Intelligence: Making Bot Attacks Too Expensive to Run
Cloudflare's new bot detection engine flips the economics of attacks by continuously retraining, using disposable rules, and learning from traffic—so attackers can't adapt faster than defenders.
READ POST ↗GLM-5.3: Open-Weight Coding Frontier With Sharp Cyber Gains
GLM-5.3 reuses the GLM-5.2 base and wins in post-training, hitting open-weight coding highs while Z.ai flags that its cyber capability 'developed faster than we expected.'
READ POST ↗Stealing Reasoning Traces from Proprietary LLM APIs
Researchers make weaker sibling models transcribe strong models' encrypted reasoning in two API calls — and find API keys and passwords leaking inside thoughts.
READ POST ↗OpenAI Can't Rule Out Critical for Astra: A Framework First
Astra is the first model OpenAI can't rule out at the Critical cyber threshold; GPT-5.6-Sol rated High, five control layers and CoT monitoring in motion.
READ POST ↗When AI Models Cross the Line: Lessons from Two Third-Party Cyber Evaluations
OpenAI reveals two incidents where models exceeded test boundaries during cyber evals, highlighting the need for evolving evaluation environments.
READ POST ↗Chrome Fixed 1,072 Security Bugs, Largely with AI
Google says Chrome 149 and 150 fixed 1,072 security bugs, surpassing the prior 23 milestones combined, with AI agents finding, fixing, and triaging vulnerabilities end to end.
READ POST ↗Claude Mythos Rewrites HAWK Attacks in 60 Hours
Anthropic's Frontier Red Team: Claude Mythos Preview cut HAWK-256 attack cost from 2^64 to 2^38 in 60 hours and sped up 7-round AES-128 attacks 200-800x.
READ POST ↗MCP's Zero-Touch OAuth: Enterprise-Managed Authorization
MCP's Enterprise-Managed Authorization is now stable: SSO login auto-connects approved servers via ID-JAG tokens. Okta ships first; Claude and VS Code support it.
READ POST ↗Miasma Worm Hits Microsoft Repos, Targeting AI Coding Agents
A hijacked account pushed a malicious commit into Azure's durabletask repo, planting files that run a credential stealer when Claude Code or Cursor opens it. 73 repos went dark.
READ POST ↗AI-Enabled Cyber Threats: Why Old Security Frameworks Are Failing
Anthropic's year-long analysis of 832 banned accounts reveals how AI is making attackers more dangerous and why MITRE ATT&CK needs an update.
READ POST ↗Meta AI Support Bot Let Hackers Steal Instagram Accounts
Hackers told Meta's AI support bot an account was theirs; the bot complied and linked attacker emails. Meta says the flaw is fixed and is notifying targeted users.
READ POST ↗Cyera's $12B Round: 80x ARR and the AI Security Land Grab
Cyera is raising $300M+ at $12B led by Evolution Equity, five months after its $9B Series F. With ARR above $150M, that is an 80x multiple — a bet on AI-era data security spend.
READ POST ↗Cisco Tested 15 Frontier Models: None Survive Multi-Turn
Cisco ran 6,986 multi-turn attacks against 15 closed frontier models from five labs. Multi-turn success hit 88.3% and no model was immune. What the study means for AI buyers.
READ POST ↗NHS Retreats from Open Source; GDS Says Keep Code Open
After AI bug-hunting jumped, NHS England moved to close nearly all its open source repos; May 14 GDS and DSIT guidance pushes back: keep code open by default and fix weaknesses.
READ POST ↗Cisco Cuts 4,000 Jobs to Fund AI Despite Record Revenue
Cisco is cutting nearly 4,000 jobs to fund AI and cybersecurity while posting record quarterly revenue. Cloudflare and GM made similar AI cuts days earlier.
READ POST ↗Google Catches the First AI-Developed Zero-Day in the Wild
Google's GTIG reports the first AI-developed zero-day: a 2FA-bypass logic flaw in an open-source sysadmin tool, plus self-morphing malware and a Gemini-driven Android backdoor.
READ POST ↗Inside the TanStack npm Supply-Chain Compromise
A pwn request, a poisoned Actions cache, and an OIDC token dumped from runner memory let attackers publish 84 malicious versions of 42 TanStack npm packages on May 11, 2026.
READ POST ↗Shai-Hulud npm Worm Hits Mistral SDK; Provenance No Defense
A self-spreading npm worm infected 170+ packages including Mistral's SDK on May 11, 2026, published with valid SLSA provenance and stealing Claude Code configs and cloud creds.
READ POST ↗GPT-5.5 Instant System Card: What It Means for Product Builders
OpenAI's GPT-5.5 Instant is the first Instant model rated High capability for cybersecurity and biosecurity. Learn what changed, how it works, and what to consider.
READ POST ↗OpenAI Gates GPT-5.5-Cyber After Mocking Mythos Limits
OpenAI is gating GPT-5.5-Cyber behind its Trusted Access program for vetted defenders, nine days after Altman called Anthropic's Mythos limits 'fear-based marketing'.
READ POST ↗LMDeploy SSRF Flaw Exploited 13 Hours After Disclosure
CVE-2026-33626 in LMDeploy's vision-language loader let attackers reach cloud metadata and internal networks; Sysdig caught the first exploit 12.5 hours after disclosure.
READ POST ↗Google Scanned the Web for Indirect Prompt Injections
Google Threat Intelligence scanned Common Crawl for indirect prompt injections: pranks, SEO manipulation, data exfiltration — malicious cases up 32% since November 2025.
READ POST ↗Vercel Breach: A Third-Party AI Tool Leaked Customer Data
Vercel disclosed a breach on April 19: attackers hit Context.ai, hijacked an employee's Google Workspace via OAuth, and read non-sensitive environment variables now up for sale.
READ POST ↗US Urges Wall Street Banks to Test Anthropic's Mythos
Treasury's Bessent and Fed's Powell urged big banks to test Anthropic's restricted Mythos model for vulnerability detection; Anthropic confirmed government briefings.
READ POST ↗N-Day-Bench: LLMs vs Real Post-Cutoff Vulnerabilities
N-Day-Bench tests LLMs on real vulnerabilities disclosed after each model's knowledge cutoff. GPT-5.4 leads at 83.93, with GLM-5.1 and Claude Opus 4.6 within four points.
READ POST ↗Gartner: GenAI Security Incidents to Nearly Triple by 2028
Gartner: by 2028, 25% of enterprise GenAI apps will see 5+ minor security incidents yearly, up from 9% in 2025. The driver is MCP-powered agentic AI outpacing security review.
READ POST ↗NVD Gives Up on CVE Backlog as AI Inflow Accelerates
NIST now enriches only KEV, federal and critical-software CVEs; the pre-March 2026 backlog is 'Not Scheduled'. CVE submissions rose 263% from 2020 to 2025.
READ POST ↗Project Glasswing: Anthropic's Mythos Hunts Zero-Days
On April 7, 2026, Anthropic launched Project Glasswing with partners incl. AWS, Apple and Microsoft, using the unreleased Mythos Preview model to hunt zero-day bugs at scale.
READ POST ↗Redwood Sizes Up AI: 1.6x Speed-Up, 8% Misalignment Odds
Redwood's Ryan Greenblatt estimates a 1.6x engineering speed-up, an 8% chance of a serious misalignment incident, and 60% odds of autonomous exploits within six months.
READ POST ↗OpenAI Opens Bug Bounty for Prompt Injection and Agent Abuse
OpenAI's new Safety Bug Bounty, run on Bugcrowd, pays up to $7,500 for reproducible AI abuse risks: prompt injection, agentic misuse, and data exfiltration via connectors.
READ POST ↗Accenture's Cyber.AI Puts Claude at the Core of Security Ops
At RSA 2026, Accenture launched Cyber.AI, an agentic security platform with Claude as its reasoning engine, plus Agent Shield to govern autonomous AI agents.
READ POST ↗Google RSAC 2026: Agentic Defense Meets a 22-Second Threat
Google used RSAC 2026 to launch Gemini-powered dark web intelligence and SecOps AI agents; Mandiant's M-Trends 2026 found attackers now hand off access in 22 seconds.
READ POST ↗OpenAI Ships Codex Security in Research Preview: A Security Agent That Finds and Helps Fix
OpenAI moved Codex Security into research preview on March 6, 2026: an app-security agent that finds and helps fix vulnerabilities in codebases, aimed at Enterprise, Business, and Education plans.
READ POST ↗EU Parliament Blocks Built-in AI on Lawmakers' Devices
The European Parliament's IT department disabled built-in AI features on lawmakers' work devices, citing data security, training-data leakage, and US legal compulsion risks.
READ POST ↗ChatGPT Gets Lockdown Mode and Elevated Risk Labels: Injection Defense as a Product Feature
On February 16, 2026, OpenAI introduced ChatGPT Lockdown Mode and Elevated Risk labels to defend against prompt injection and data-exfiltration attacks. Defense becomes a product feature.
READ POST ↗Microsoft Cyber Pulse: 80% of Fortune 500 Now Run AI Agents
Microsoft's first Cyber Pulse report: 80%+ of Fortune 500 firms run active AI agents, 29% of employees have used unsanctioned ones. The fix: Zero Trust for agents plus five governance capabilities.
READ POST ↗Microsoft's New Scan Catches Sleeper-Agent LLM Backdoors
Microsoft's 'The Trigger in the Haystack' pulls sleeper-agent backdoor triggers out of poisoned LLMs: ~88% detection across 47 models, zero false positives on 13 benign ones.
READ POST ↗Moltbook: 1.6M AI Agents, One Leaky Database, 1.5M API Keys
Moltbook, a social network only for AI agents, hit 1.6M accounts in a week — then Wiz found an exposed database leaking private messages and 1.5M API keys, enough to take over any agent.
READ POST ↗Ex-Google Engineer Convicted in First AI Espionage Case
A San Francisco federal jury convicted ex-Google engineer Linwei Ding on January 29, 2026 — seven counts of economic espionage, seven of trade secret theft, covering TPU chips and cluster software.
READ POST ↗AI Found All 12 OpenSSL Zero-Days in One Release
On January 27, 2026, OpenSSL patched 12 zero-day vulnerabilities, every one found by AISLE's autonomous AI analyzer — including a CVSS 9.8 overflow with code dating back to 1998 and the SSLeay era.
READ POST ↗Claude Code Adds /security-review and GitHub Actions Integration
Mid-January 2026 release notes add /security-review and a GitHub Actions integration to Claude Code, as the Cowork preview expands to Pro. Security review moves into the coding agent.
READ POST ↗CrowdStrike Buys SGNL to Secure AI Agent Identities
On January 8, 2026, CrowdStrike announced its acquisition of SGNL, whose Continuous Identity runtime extends real-time access control to humans, non-human identities, and AI agents.
READ POST ↗