AI Security
Cybersecurity innovations, AI-powered threat detection, responsible disclosure, and the defenders shaping the digital frontier.
164 articles

WhatsApp Passkeys Go Multi-Device for 1 Billion Users
WhatsApp now supports multiple passkeys per account, upgrades its six-digit PIN to a full password, and adds caller context on Android.

Microsoft Teams Blocks External Meeting Bots by Policy
A new Microsoft Teams admin policy automatically blocks identified external meeting bots, with general availability due by late September 2026.

Fortinet Buys Virtue AI to Red-Team Your AI Agents
Fortinet acquired Virtue AI on August 17, adding agentic red-teaming across 50 sandboxed environments and 1,000 risk categories to its security fabric.

Mandiant AI Agents Found 100 Critical Flaws in 2 Days
Google's Mandiant published its AVDH blueprint after the agent pipeline verified 100+ critical vulnerabilities in 48 hours and produced 12 assigned CVEs.

Stealthium Watches the GPU Layer Most Tools Miss
Stealthium launched a security control plane for GPUs and AI accelerators, turning kernel traces and VRAM telemetry into detections for neo-cloud workloads.

OpenAI Model Security Adds Sandboxes and 30-Min Alerts
OpenAI published a new internal security bar: hard sandboxing, activation classifiers on sampled tokens, and a 30-minute alert-or-pause rule.

AI Agent Memory Files: One Prompt Blocks the Spread
Anthropic and EPFL found payloads spread between AI agents via editable memory files, and a one-paragraph prompt warning cut the spread to near zero.

Windows 11 Drops WMIC, a Longtime Malware Favorite
Microsoft has removed the WMIC command-line tool from Windows 11 24H2 and 25H2, closing a living-off-the-land binary abused by ransomware for years.

Hazmat Locks AI Coding Agents Out of Your SSH Keys
Hazmat is a free open-source tool that runs AI coding agents under a separate user with a kernel sandbox and firewall, keeping SSH keys out of reach.

Google Cloud Maps Post-Quantum Crypto Readiness by 2029
Google Cloud published a phased post-quantum roadmap targeting full readiness by 2029, with quantum-safe key exchange already live on API endpoints.

OT Vulnerability Triage Drops From Weeks to Minutes
Fortress and Industrial Defender integrated asset intelligence with AI vulnerability correlation, cutting OT vulnerability-to-asset triage to minutes.

GLM-5.3 Posts an 84.5% CyberGym Cyber Defense Score
Z.ai's GLM-5.3 lifts CyberGym from 77.2% to 84.5% on post-training alone, and the team is holding weights back two weeks for safety hardening.

Signal Automates Encryption Checks With Key Transparency
Signal's Automatic Key Verification uses a key transparency log audited by Cloudflare and Trail of Bits to confirm chats without meeting in person.

OpenAI Daybreak Splits Into Blue and Red Defender Tiers
OpenAI restructured Daybreak into Blue and Red tiers on August 10 and added GPT-5.6-Cyber, a purpose-trained model gated to vetted security partners.

CrowdStrike Offers $100K to Red-Team Rogue AI Agents
CrowdStrike and AWS opened a $100,000 AI security challenge running August 31 to September 29, teaching defenders prompt injection and agent hijacking.

Chainloop Signs Every Artifact Your CI Pipeline Builds
Chainloop is an open-source evidence store that collects, signs, and policy-checks CI output across 17 formats including CycloneDX and SPDX SBOMs.

Linux Kernel SCTP Fix Lands in All Stable Branches
An 18-year-old SCTP use-after-free went from private report to patched across every supported Linux stable branch in a little over three weeks flat.

HTTP Terminator Hunts Request Smuggling Bugs With AI
PortSwigger open-sourced HTTP Terminator, an AI research system that generated 30,000 desync vectors and surfaced a now-patched Apache zero-day.

Securing AI Coding Agents in CI: A Hardening Guide
Black Hat 2026 showed a single GitHub issue could reach CI secrets. Here are seven hardening steps for AI coding agents, plus the patched version numbers.

Shieldstral Runs Multimodal Safety on One 16GB GPU
Mistral's Shieldstral is a 3B open-weight safety classifier covering 12 languages and images, taking plain-language policies at inference on a 16GB GPU.

OWASP Subtractive Security Scores What You Remove
OWASP launched a Subtractive Security Top 10 with nine platform lists and a Path Erasure Rate metric that counts attack paths deleted, not alerts raised.

Chrome's Gemini Bug Hunter Found a 13-Year-Old Flaw
Google's Gemini-based scanner surfaced a Chrome sandbox escape hidden for 13 years, and AI triage now helps the team ship two security releases a week.

NVIDIA SkillSpector Scans AI Agent Skills for Risk
NVIDIA's open-source SkillSpector checks AI agent skills for 64 vulnerability patterns before install, scoring risk 0-100 and exporting SARIF for CI.

CISA C4 Framework Scores Open Source Project Trust
CISA's new 35-page open source security guide introduces the C4 Framework — Code, Community, Controls, Continuity — plus SBOM and open AI model practices.
