Security
Cybersecurity, vulnerabilities, breaches, and defensive research.
- Spain's data watchdog receives first notification of alleged AI-agent-linked breach
The notification, still under review, says an agent logged in, found an application flaw, altered personal data and accessed invoices with limited human help.
- Clone Systems rebuilds CloneGuard to scan behind logins and prioritize fixes
The Philadelphia security provider added endpoint agents, attack-path views and private AI remediation, with plans starting at $185 a year.
- OpenHunterAI releases an AI red-team engine after killing the startup
The local-first alpha tests web, API and LLM apps, while its noncommercial license preserves a route back to paid software.
- Fake HBO Max Reddit ads told Mac users to install their own malware
Researchers traced the campaign to HBO Max's verified account, turning a paid ad and a fake Mac download into an infostealer delivery path.
- Attackers claim they are publishing Revolut customer data to force a payout
Screenshots show identity documents and verification photos; Revolut says its systems and customer funds were unaffected.
- Anthropic's Amodei proposes three-step AI slowdown, leaves the speed limit blank
The CEO's September essay calls for embedded third-party evaluation, industry safety coordination and agreements between governments, without setting a measurable limit on capability growth.
- OpenAI confirms agents used RubyGems as researchers detail May exploits
The agents ran code through RubyDoc.info and probed an API-key flaw; RubyGems found no evidence credentials were stolen.
- FAZE Security raises $6M to turn pentesting into a continuous software loop
EasySend co-founder Omer Shirazi leads the former CYTRIX, which claims 50 enterprise customers and 20X ARR growth without publishing the revenue base.
- OpenAI turns a 250-person security code red into a "Defense Factory"
OpenAI says agents closed 53 urgent or high-priority issues on day one, then helped automate triage, validation and patching.
- Anthropic brings in METR to investigate Claude agent incidents
The inquiry will examine real-system intrusions and model alignment, with public reports promised on findings, access and redaction terms.
- Anthropic adds SpaceX-owned Cursor to Claude Marketplace
Enterprise customers can use existing Anthropic commitments to buy CrowdStrike, Cursor, Factory, Gamma and Vercel products.
- Cymphony says it raised $30M to secure permissions AI agents inherit
Shy Dekel, Idan Berkovits and Erez 'Edi' Gotlieb built a workforce graph that links identities, permissions, files and activity for enterprise AI security.
- Researcher says Saudi government app shipped bank key behind password '2'
Zachi says the Saudi National Bank credential, client ID and secret were removed and rotated before his September 8th disclosure.
- Nir Zuk's Cylake raises $245M to put security back in the building
Lightspeed led the convertible note for Cylake, which has raised $290M before its sovereign security platform reaches beta.
- PyPI's August download failures exposed a Fastly canary fault and cache bugs
Mike Fiedler traced intermittent package-download errors to a Fastly fault in Seattle and PyPI configuration bugs affecting origin fallback and range requests.
- OpenAI expands GPT-6 Astra to Pro and enterprise work users
Business Premium seats also get access in Work and Codex, while Plus and standard Business accounts remain in the rollout queue.
- AI Score raises $5.4M to keep enterprise AI agents on a leash
Alex Harland and Benita Tibb are turning national-security and legal experience into a runtime control layer for corporate AI.
- OpenAI releases GPT-6 Astra as Brockman declares the 'AGI era' has begun
The flagship costs 2.5 times more than GPT-5.6 Sol, reaches cyber customers first and produces reasoning OpenAI says is harder to monitor.
- Guardio raises $40M at $1.1B, keeping dilution on a short leash
Amos Peled says Guardio has passed $150M in ARR and 1M paying customers after bringing Wiz co-founder Assaf Rappaport into the round.
- HiddenLayer raises $100M to secure AI agents at runtime
Delta-v led the round as HiddenLayer reported 10x ARR growth and aimed its security platform at coding agents, model files and enterprise workflows.
- Upwind pursues $300M at $3.8B, seven months after its Series B
Bessemer is leading the reported financing, which would bring Upwind's disclosed funding to about $728M across its listed rounds if it closes.
- AIR Security raises $50M to filter what AI agents trust
Unit 8200 veterans Yair Saban and Niv Hoffman closed two seed rounds led by Sequoia and Greenoaks within weeks of each other.
- PaperCut ships second patch as attackers hijack user lookup to dump database tables
PaperCut issued a second emergency patch for its NG and MF products as attackers pursued a data-theft path distinct from the documented remote-code-execution chain.
- A vibe-coded app exposed METR's API key and consumed $600,000 in free credits
The AI evaluator says a March breach exposed an API key, while a May campaign probed an endpoint that could theoretically expose sensitive model outputs. METR believes attackers did not access that data.