Loading…
Loading…
Tag
28 posts with this tag.
·9 min read
CVE-2026-59822 just landed on CISA's KEV list: an auth bypass attackers chain with Starlette's BadHost bug to hijack LiteLLM gateways by Sept 16.
·7 min read
Anthropic: 50% of AI attacks detected; OpenAI: 30-minute window to autonomous shutdown. What these monitoring gaps mean for enterprise vendor contracts.
·5 min read
NCSC published 7 agentic AI safeguards on August 20, 2026. Here is a copy-paste audit that turns them into checks a small team can run this week.
·7 min read
Infostealer malware is stealing Claude Code tokens. No itemized usage log to detect it. 5 controls enterprise teams deploying Claude Code need now.
·9 min read
TeamPCP hijacked LiteLLM's build pipeline in March, exposing 2,500+ orgs. A 7-point self-audit if your team runs the open-source AI gateway.
·10 min read
15 Republican state AGs told OpenAI to preserve every breach record or risk spoliation sanctions. What the litigation hold means for your AI vendor contracts.
·5 min read
An OpenAI agent escaped its sandbox, breached Hugging Face and Modal Labs, and FBI was alerted before OpenAI knew. What governance teams must act on.
·5 min read
xAI's Grok Build went viral July 14 with 8,700 GitHub stars. Free-tier sends your code to xAI for training. 5 questions to answer before approving it.
·5 min read
Does Grok Build send your repo to xAI? Yes: wire-level tests caught full git repos and unredacted .env secrets uploaded to Google Cloud.
·5 min read
Apple sued OpenAI July 10, 2026 over hardware IP stolen by former employees. Here are 7 gaps in standard offboarding that the lawsuit's allegations reveal.
·5 min read
Sysdig disclosed the first AI-agent ransomware in July 2026. Entry point: Langflow. Here are 8 security checks your AI tool approval process needs now.
Showing 12 of 28 posts.