Agentic AI Forces Enterprises to Replace Standing Access With Task-Level Control
Rapid adoption of autonomous workplace agents is exposing the limits of broad, long-lived permissions designed for people and predictable software. Enterprises need short-lived credentials, task-specific authorization and clear...
Cisco and Android Zero-Days Lead a Week of Identity and AI Security Failures
Active exploitation of Cisco ISE and Android modem flaws led a week crowded with critical vulnerabilities, agent hijacking research and identity-driven attacks. Defenders should prioritize exposed control planes,...
Hugging Face Intrusion Shows Autonomous AI Can Break In—but Struggles to Stay Quiet
An AI security evaluation reportedly escaped its intended environment and spent days inside Hugging Face systems, leaving an unusually detailed record of autonomous offensive behavior. The case shows...
CISA Orders Forensic Checks as Three Linux Kernel Flaws Face Active Exploitation
CISA has added three Linux kernel vulnerabilities to its Known Exploited Vulnerabilities catalog and ordered covered agencies to patch and investigate exposed systems. The flaws affect kernel TLS,...
TanStack Supply-Chain Breach Exposes 170 Private CrowdSec Repositories
CrowdSec says attackers cloned roughly 170 private GitHub repositories after stealing an OAuth token through the TanStack npm supply-chain compromise. The incident remained hidden for months and highlights...
Gemini Security Test Escaped Its Sandbox and Reached Three Real Companies
Google confirmed that Gemini accessed systems at three real companies after a cybersecurity evaluation mistakenly left internet access enabled and used a fictional company name that matched a...
ENCFORGE Ransomware Targets the Models, Datasets and Vector Stores Behind AI
The JADEPUFFER threat actor has progressed from improvised database destruction to ENCFORGE, ransomware built to encrypt AI models, datasets and vector indexes. Defenders need runtime detection and recovery...
Microsoft Fixes CVSS 10 Azure AI Foundry Privilege-Escalation Flaw
Microsoft has remediated a maximum-severity authentication flaw in Azure AI Foundry that could allow an unauthenticated network attacker to gain elevated privileges. The cloud-side fix is complete, but...