AI Security — Page 2
164 articles in this category

Burp AT Puts Agentic AI Inside Burp Suite Pentests
PortSwigger's Burp AT public beta gives pentesters AI agents that chase leads through Burp's own tooling, with per-task control over what runs unattended.

XM Cyber Open-Sources Three Exposure Hunting Tools
XM Cyber released three open-source tools on July 29 that hunt macOS XPC privilege escalation paths and overprivileged Oracle Cloud identities.

Microsoft Project Perception Puts AI Agents on Defense
Microsoft unveiled Project Perception on July 27, an agentic security platform with red, blue and green AI agents plus the MAI-Cyber-1-Flash model.

Open Secure AI Alliance Unites 40+ Firms on Defense
NVIDIA, Microsoft, IBM and 40+ others launched the Open Secure AI Alliance on July 27, pooling five open-source projects to defend AI agents.

Druva AI Resilience Adds Backup for Claude Code Work
Druva launched AI Resilience on July 21, adding backup, rollback, and governance for Claude Code projects and Microsoft Copilot activity logs.

Snowpick Open-Source Scanner Checks ServiceNow Exposure
Bishop Fox released Snowpick, a free Go tool that tests your own ServiceNow portal for unauthenticated data exposure across 26 table checks.

Google Threat Intelligence Ships Agentic AI Defense
Google Threat Intelligence moved its agentic AI to general availability, automating threat hunting, triage, and malware analysis with cited results.

Next.js Ships First Pre-Announced Security Update
Next.js patched 9 CVEs in v16.2.11 and v15.5.21 — its first pre-announced monthly security release, giving teams time to plan upgrades before disclosure.

Google Selfie Video Sign-In Rescues Locked-Out Accounts
Google's new selfie video verification gives locked-out users a face-based recovery path, with liveness checks, encryption, and full user control.

AI Agent Sandbox Design: 4 Lessons From New Research
Pillar Security's seven disclosures across Cursor, Codex CLI and Gemini CLI reveal four sandbox failure modes AI agent builders can design against.

Microsoft Dusseldorf Brings Open-Source OAST to Your Servers
Microsoft open-sourced Dusseldorf, a self-hosted OAST platform catching 4 blind bug classes while keeping callback data on your own servers.

7-Zip 26.02 Patches an Archive Decoder Flaw via ZDI
7-Zip 26.02 fixes a heap overflow in the XZ decoder, found by researcher Landon Peng and coordinated through ZDI as advisory ZDI-26-444. Update manually.

VulnHunter Open-Sources Capital One's AI Bug Hunting
Capital One released VulnHunter under Apache 2.0 — an agentic security tool that traces exploit paths and tries to disprove its own findings first.

Prompt Injection Becomes a Defense With Context Bombs
Tracebit's 'context bombs' plant text in cloud decoys that trip an AI attacker's own guardrails — cutting attack success from 91% to 15%.

GPT-Red: OpenAI's AI Red-Teamer Cuts Injection Fails
OpenAI built GPT-Red, an automated red-teaming model, then used it to harden GPT-5.6 Sol to 6x fewer prompt-injection failures than GPT-5.5.

SingGuard-NSFA Brings Open Guardrails to AI Agents
Ant Group open-sourced SingGuard-NSFA under Apache 2.0 — four guardrail models covering 185 threat scenarios across 133 languages, free to download.

AgentMon 3 Gives AI Agents Self-Refining Guardrails
Codenotary's AgentMon 3, out July 7, learns each org's normal AI-agent behavior and auto-tunes runtime policies, cutting manual upkeep up to 80%.

Sophos Fusion Unifies Security Tools With Agentic AI
Sophos launched Fusion on July 15 — an AI-native platform that unifies endpoint, SIEM, identity, and network tools with shared threat intel.

Microsoft Secure Future Initiative Hits New Milestones
Microsoft's July 2026 Secure Future Initiative report: phishing-resistant MFA on 99.97% of accounts, 732K+ resources locked down, and AI-driven defense.

CodeQL 2.26 Adds Free AI Prompt-Injection Detection
CodeQL 2.26.0 adds a free js/system-prompt-injection query in code scanning, with new sinks for the OpenAI, Anthropic, and Google GenAI SDKs.

Rustinel Is a Fast Open-Source EDR Built in Rust
Rustinel, launched July 8, is an open-source endpoint detection tool in Rust that unifies Windows and Linux monitoring into one clean codebase.

CVE Lite CLI Scans npm Projects Right in Your Terminal
CVE Lite CLI, now an OWASP Incubator project, checks JavaScript lockfiles against the OSV database and suggests one-line fixes for npm, pnpm, Yarn, and Bun.

Cloudflare Adds IPsec Downgrade Protection for Post-Quantum Tunnels
Cloudflare shipped beta IPsec downgrade protection that makes both VPN peers sign the full handshake, blocking attackers from quietly weakening a tunnel's encryption.

New Open-Source Tools Help Blue Teams Defend AI Agents
A fresh wave of open-source security tools gives blue teams free, community-built defense for the AI agent era, protecting the newest attack surface.
