Cybersecurity
Vulnerabilities, ransomware, CVEs, pentesting, OSINT and the latest in information security.
38 published articles
AI meets offensive security
AI agents just automated the pentesting pipeline, and the open source version comes with a kill switch
VulnClaw is an open source AI-powered pentesting CLI that uses LLM agents to automate the full workflow. It supports 13 model providers, integrates MCP tools, and includes anti-hallucination measures to keep claims tied to real outputs.
2026-07-20
Data privacy
Grok Build was uploading entire codebases to the cloud. Musk says the data is safe now.
SpaceXAI's Grok Build CLI was uploading entire codebases to cloud storage. Elon Musk says all previously uploaded data will be deleted, but the incident exposes just how much AI coding tools can quietly collect.
2026-07-17
Cybersecurity
An AI attacked a major AI platform, and the industry isn't ready for what it found
Hugging Face suffered a breach by an autonomous AI agent that exploited its data pipeline. The incident reveals how AI-driven offensive tooling operates at machine speed, and why defenders need capable models on their own infrastructure to keep pace.
2026-07-16
Enterprise AI governance
Your AI's behavior has no owner. Mistral Studio just fixed that.
Mistral Studio introduces a centralized system of record for AI prompts and skills, with immutable versions, named owners, rollback capabilities, and audit logs. It enables line-of-business teams to iterate on instructions without engineering bottlenecks, while maintaining CI/CD controls and compliance traceability.
2026-07-13
Enterprise Security
Microsoft is about to flood patch Tuesday with AI-discovered security fixes
Microsoft will use AI to identify security issues earlier, leading to more fixes bundled into each patch Tuesday. The company is updating its Secure Development Lifecycle to account for AI-enabled attack techniques while keeping humans in the loop for code review.
2026-07-09
Autonomous Defense
AI agents are rewriting the rules of cybersecurity
Attackers are exploiting unpatched vulnerabilities and polymorphic malware that traditional signature-based tools miss. Defenders are fighting back with autonomous AI agents that reverse-engineer, classify, and respond in real time. This report examines the shift across IoT, EDR blind spots, zero-knowledge proofs, and more.
2026-07-06
Messaging & Privacy
WhatsApp username reservations raise impersonation fears as India regulators push back
WhatsApp username reservations let users interact by handle rather than phone number, but early testing found handles resembling prominent figures still available. India's IT ministry warned the feature could increase fraud and impersonation, while digital rights groups criticized the regulatory intervention.
2026-07-02
Cybersecurity
CISA adds microsoft sharepoint server vulnerability to exploited list as parallel ransomware attacks emerge
CISA flags CVE-2026-45659 under active exploitation, urging federal agencies to patch by July 4, 2026. Microsoft details parallel Storm-2603 and unknown actor activity using sharepoint vulnerabilities and tunneling tools.
2026-07-02
Advanced Persistent Threat
ToddyCat apt deploys umbrij malware to hijack gmail via oauth token theft
ToddyCat's latest tool, Umbrij, automates theft of OAuth tokens from active Gmail sessions by launching Chromium browsers in headless mode and controlling them via remote debugging ports. The malware can extract authorization codes granting full access to Gmail, Drive, Contacts, Calendar, and Tasks.
2026-07-02
International crackdown
Teen accused in scattered spider hacking crew extradited to the US
Peter Stokes, 19, was extradited from Finland to the U.S. on charges tied to the Scattered Spider hacking crew. The group has been linked to over 100 intrusions and $100 million in ransom payments, targeting casinos, retailers, and airlines. Stokes appeared in Chicago federal court on June 30 and is being held in custody.
2026-07-02
Cybersecurity
First fully AI-run ransomware attack discovered by sysdig researchers
Sysdig's Threat Research Team found an AI agent, tracked as JADEPUFFER, exploiting an unpatched Langflow flaw to break in, steal credentials, move laterally, and encrypt a production database. The attack ran without a human operator, raising alarms about the democratization of ransomware.
2026-07-02
Zero-Day Alert
Critical Zero-Day CVE-2025-XXXX Strikes Widely Deployed Enterprise VPN Appliances
A critical zero-day vulnerability (CVE-2025-XXXX, CVSS 9.8) affecting popular enterprise VPN appliances allows unauthenticated remote code execution. Exploit code has been published, and multiple vendors have released emergency patches. Organizations must prioritize remediation to prevent network compromise.
2026-07-01