The intelligence feedUpdated as material events develop
Analysis / Research / Guidance
The Briefing
Independent reporting on AI security, exploited vulnerabilities, and enterprise cyber risk. Built to help defenders understand what changed and what deserves action.
CISA, the NSA, and four allied cybersecurity agencies released unprecedented joint guidance on securing agentic AI systems. Discover the five critical risk categories, mandatory zero-trust requirements, and the immediate actions your enterprise must take before deploying autonomous AI agents.
CVE-2026-26268 exposes a critical flaw in Cursor AI where cloning a malicious repository triggers automatic remote code execution. With 88% of enterprises already experiencing AI agent security incidents, discover why your IDE is now the weakest link in your security chain.
A critical command injection vulnerability in GitHub's internal protocol allowed remote code execution with a single git push. CVE-2026-3854 exposed millions of repositories to cross-tenant access - and 88% of enterprise servers remain unpatched.
The Arup deepfake fraud cost $25 million in September 2026, signaling a terrifying new era where AI agents autonomously execute social engineering attacks. Discover how agentic AI is amplifying deepfake threats and the critical defenses enterprises need now.
Critical CVE-2026-42208 exposes LiteLLM to pre-authentication SQL injection, enabling attackers to extract API keys and escalate to full RCE. Sysdig detected exploitation within 36 hours of disclosure. Learn the attack chain and urgent defenses.
Utility giant Itron confirmed a cyberattack on its internal IT systems, exposing risks to critical infrastructure. Discover what CISOs must learn about OT/IT separation, incident response, and protecting the energy grid.
The US State Department orders global diplomatic push warning allies about Chinese AI companies including DeepSeek, Moonshot AI, and MiniMax allegedly stealing American AI IP through model distillation.
OpenAI released GPT-5.5 with stronger cybersecurity safeguards and a $25,000 Bio Bug Bounty challenging researchers to find universal jailbreaks. With Irregular Labs confirming improved offensive capabilities and the model now available via API, CISOs should treat this as a public stress test for high-stakes AI safety controls.
House lawmakers witnessed a chilling demonstration of jailbroken AI models that bypassed safety guardrails to plan terror attacks, build bombs, and launch cyberattacks. Discover what this means for enterprise AI security and why your organization needs immediate defensive action.