The intelligence feedUpdated as material events develop
Analysis / Research / Guidance
The Briefing
Independent reporting on AI security, exploited vulnerabilities, and enterprise cyber risk. Built to help defenders understand what changed and what deserves action.
OpenAI launches GPT-5.4-Cyber for defensive cybersecurity while GitHub releases Season 4 of Secure Code Game focused on agentic AI vulnerabilities. Learn why the OWASP Top 10 for Agentic AI matters now.
University of California researchers expose a critical AI supply chain threat: malicious LLM routers that intercept data, steal crypto, and compromise credentials at scale.
Adobe's emergency fix for CVE-2026-34621 puts malicious PDFs back at the center of enterprise risk, with evidence the flaw may have been exploited since December. This is the kind of simple, familiar attack path that still breaks real organizations.
US Treasury Secretary and Federal Reserve Chair held an emergency meeting with major bank CEOs over Anthropic's Claude Mythos Preview AI model, triggering coordinated regulatory responses across the US, UK, and Canada.
Anthropic's Claude Mythos Preview autonomously discovered thousands of zero-day vulnerabilities in major operating systems and browsers, including a 27-year-old OpenBSD bug. Here's what defenders need to know.
Critical Marimo notebook vulnerability CVE-2026-39987 enables pre-authentication RCE via unauthenticated WebSocket terminal. Exploited within 10 hours of disclosure with credential theft in under 3 minutes.
Four critical vulnerabilities in PraisonAI multi-agent framework disclosed April 8, 2026 enable sandbox escape, RCE via YAML parsing, template injection, and unauthenticated access. With CVSS scores up to 9.9, discover the urgent patching requirements.
Critical Docker vulnerability CVE-2026-34040 allows AI coding agents to bypass authorization plugins with a single padded HTTP request, exposing host filesystems and cloud credentials. Discover the exploit chain and urgent patching requirements.
Flowise AI platform faces critical CVSS 10.0 RCE vulnerability CVE-2025-59528 with 12,000+ exposed instances under active attack. Discover the exploit chain and immediate patching requirements.