Microsoft Teams to Add Third-Party Deepfake Detection as Synthetic-Media Attacks Escalate
Microsoft plans to roll out synthetic audio and video detection in Teams starting November 2026, routing meeting media through certified third-party providers to flag possible deepfakes. The move...
Anthropic Rolls Out Tiered Claude Access for Vetted Red Teams and Critical-Infrastructure Defenders
Anthropic has expanded its Cyber Verification Program into three distinct access tiers, giving vetted security researchers, red teams, and defenders of high-risk systems fewer restrictions when using Claude...
GitLab AI Gateway Sandbox Escape Opens Door to Remote Command Execution
GitLab has patched a CVSS 9.9 sandbox escape in self-hosted AI Gateway deployments. An authenticated Duo Agent Platform user could abuse crafted flow templates to execute commands on...
When AI Agents Go Off-Script: OpenAI Systems Quietly Probed Four Public Websites
Newly disclosed incidents show OpenAI's autonomous agents escalating to SQL injection, path traversal, and access-control bypass attempts against government and university systems on their own, without ever being...
Zero-Day in Meta’s Muse AI Assistant Lets Local Malware Hijack Voice Commands and Steal Credentials
Researcher Patrick Wardle has disclosed an unpatched flaw in Meta's macOS AI agent Muse that lets unprivileged malware quietly redirect dictation traffic and harvest account credentials. The bug...
Cisco and Android Zero-Days Lead a Week of Identity and AI Security Failures
Active exploitation of Cisco ISE and Android modem flaws led a week crowded with critical vulnerabilities, agent hijacking research and identity-driven attacks. Defenders should prioritize exposed control planes,...
Gemini Security Test Escaped Its Sandbox and Reached Three Real Companies
Google confirmed that Gemini accessed systems at three real companies after a cybersecurity evaluation mistakenly left internet access enabled and used a fictional company name that matched a...
ENCFORGE Ransomware Targets the Models, Datasets and Vector Stores Behind AI
The JADEPUFFER threat actor has progressed from improvised database destruction to ENCFORGE, ransomware built to encrypt AI models, datasets and vector indexes. Defenders need runtime detection and recovery...