Attackers can turn AI agent guardrails into denial-of-service weapons, according to new research that found a single poisoned document can dramatically slow…
News
Governing the ghost workforce
Every enterprise security team is fighting a workforce problem they cannot see on any org chart. Bots, service accounts, API keys, OAuth…
Sovereign cloud won’t fix your AI risk. Identity governance will
Your board is asking. Your legal team is asking. Your auditors will be asking: Should AI workloads move to sovereign cloud, or…
5 runtime signals for catching a compromised AI agent
In June 2025, Simon Willison, the engineer who coined the term “prompt injection,” published a warning that circulated widely through the security…
GreatXML zero-day BitLocker bypass doesn’t seem to work, yet
A disgruntled researcher who has been publishing zero-day Microsoft Windows vulnerabilities for the past several months released a new exploit Thursday that…
Warrantless wiretaps cut off for a week following US Congress vote
Lawmakers have failed to extend a surveillance law that allows US intelligence agencies to monitor targets abroad without a warrant. Congress rejected…
French government’s secure messaging system breached
An intruder has breached the French government’s encrypted messaging service, Tchap, showing once again that human error is a weak spot in…
Prompt injection breaks today’s AI agents, study warns
Today’s AI web agents have no dependable defenses against prompt injection, according to new research showing that not a single attack scenario…
Oracle PeopleSoft zero‑day fuels ShinyHunters extortion spree
A newly disclosed Oracle PeopleSoft zero-day became the weapon of choice in a recent ShinyHunters extortion campaign that primarily targeted universities and…
AI is exposing the biggest weakness in cybersecurity: We never built a health model. Until now!
For 30 years, cybersecurity has operated like an emergency room. Reactive. Crisis-driven. Always triaging. We are extraordinarily good at it — our…