Threat modelling stories
A free account could have let attackers alter Zapier-maintained packages and hijack logged-in users' browser sessions, researchers said.
Millions of downloads were exposed to silent code execution as a flaw in Hugging Face Transformers let malicious models run on load.
Microsoft patched a CVE-2025-59199 flaw in October after researchers showed a single click could let low-integrity code escape Windows 11's sandbox.
Broader Claude access should help MIND sharpen data discovery and loss prevention for customers, after it joined Anthropic's cyber scheme.
Members are backing tougher open source security as OpenSSF expands guidance on regulation, Python coding and AI-driven vulnerability tools.
The findings suggest AI-assisted bug hunting is edging closer to practical exploitation, raising the stakes for software teams racing to patch flaws.
Security teams under pressure to prove real exploitability can now test live production systems for attack paths rather than theoretical flaws.
The public test could bolster or undermine claims that VEIL can anonymise sensitive AI data without letting outsiders recover the original records.
JupiterOne rolls out AI attack surface and vulnerability tools to help security teams map links, prioritise flaws and cut through alert overload.
Organisations using AI in software development will get training on secure coding and governance as vulnerabilities and data risks mount.
Vetted security teams will get fewer refusals on authorised tasks as OpenAI tightens access around its most permissive cyber model.
A flaw in a widely watched Microsoft repository could have let attackers run code and steal secrets through GitHub Actions, Tenable said.
Banks could face undetected ledger and pricing changes as autonomous AI attacks exploit poorly governed databases, Liquibase warns.
Patching delays now carry greater risk as Google says AI is helping attackers scale intrusions, speed up breaches and automate operations.
Reporters face rising risks from phishing, spyware and device compromise as Bitdefender urges tighter source protection and account security.
Customers gain broader visibility into AI risks as Wiz adds cloud, edge and coding-tool coverage, with Red Agent now in public preview.
The framework is designed to expose hidden risks in production AI systems that can be missed by conventional one-off tests.
Belgian software SMEs risk losing B2B contracts as new EU rules expose weak threat modelling and scant security training, a PXL study says.
Organisations using AI-assisted development can now get specialist secure coding training as KnowBe4 expands its library for technical teams.
Researchers can now train on live attack traffic after a new open-source dataset adds 100 million labelled security records from production systems.