The intelligence feedUpdated as material events develop
Analysis / Research / Guidance

The Briefing

Independent reporting on AI security, exploited vulnerabilities, and enterprise cyber risk. Built to help defenders understand what changed and what deserves action.

Latest intelligence

Current coverage

Browse the full archive
AI agent ransomware attack illustration showing an exposed Langflow workflow, autonomous intrusion steps, and database extortion

AI Agent Ransomware Attack: Why JADEPUFFER Turns Exposed AI Workflows Into a Full Intrusion Path

An AI agent ransomware attack became a same-day public story on July 2, 2026, when The Hacker News surfaced Sysdig's JADEPUFFER findings to a broader security audience. The real lesson is not only that one Langflow server was exposed. It is that internet-facing AI workflow tools can now become a low-friction bridge from prompt-era convenience to fully automated intrusion, lateral movement, and database extortion.

Read intelligence ↗
AI coding agent malware illustration showing a clean GitHub repository, dependency setup prompt, DNS-based command retrieval, and shell access on a developer workstation

AI Coding Agent Malware: Why a Clean GitHub Repo Can Still Open a Shell

The clean GitHub repo AI coding agent malware story became fresh on June 27, 2026, when BleepingComputer reported Mozilla 0DIN's demonstration that Claude Code could walk itself into a hidden shell chain during normal project setup. This breakdown explains why error recovery, dependency initialization, and runtime trust now matter as much as prompt filtering in AI coding workflows.

Read intelligence ↗

Showing 82-90 of 262 articles