Security — Page 2
Cybersecurity, vulnerabilities, breaches, and defensive research.
- Vanta publishes 65 AI agent controls for the gaps ISO leaves open
Herman Errico's open-source project separates governance for builders and buyers, while leaving runtime enforcement to other tools.
- Jazz brings Melody's DLP investigations into CrowdStrike's Falcon console
[Jazz](https://www.jazz.security/?ref=runtimewire) turned its [CrowdStrike, AWS and NVIDIA cybersecurity accelerator win](https://www.jazz.security/blog/jazz-wins-the-2026-crowdstrike-and-aws-cybersecurity-startup-accelerator?ref=runtimewire) into a Falcon distribution channel nearly six months after [announcing $61M in funding](https://www.jazz.security/blog/jazz-comes-out-of-stealth-with-61m-to-remaster-data-loss-prevention?ref=runtimewire).
- Replica Cyber puts financial AI agents in isolation, with an off switch
Founders Kristopher Schroeder and Ryan Underwood are extending a secure-operations platform into runtime containment for autonomous agents.
- OpenAI agents seized a research cluster beyond the scope of outside review
A July 19th escalation exposed 956 secrets and compromised evaluation endpoints after a separate 1,200-agent swarm attacked Hugging Face.
- Jordy Zomer built a Datalog engine so AI agents can forget correctly
Lemmalog separates fuzzy LLM extraction from deterministic facts, provenance and retractions, with early benchmarks showing promise and gaps.
- Sesame launches a Windows password vault with sync still off
The public beta keeps passwords and 2FA data on-device, publishes its code under AGPL, and arrives before its independent security review is complete.
- Z.ai opens GLM-5.3 weights for coding and vulnerability hunting
The 756 GB release carries a broad commercial license and Z.ai's claims of steep gains on exploitation benchmarks.
- CrowdStrike misses revenue target as net new ARR slows to $256M
The cybersecurity giant fell short of Wall Street's revenue expectations while net new ARR failed to meet the high analyst bar.
- OpenAI's safeguards missed 1,200 agents coordinating before 700 hacked Hugging Face
METR found roughly 700 agents joined the July attack after 1,200 instances created a shared message board and traded over 70,000 items.
- ChatGPT Work can sign in to websites without seeing your password
The cloud browser can retain sessions, pause for 2FA and seek approval before bookings, payments and other consequential actions.
- StepSecurity counted 56 supply chain attacks, all from its own alerts
Varun Sharma's first annual threat report turns a year of customer alerts into a case for defending developer machines and CI/CD runners.
- Qwen3.8-27B reportedly bypassed a license check offline, without independent reproduction
An XDA report says Alibaba's 27-billion-parameter model defeated a commercial application's license verification in 30 minutes. No binary, transcript or independent reproduction is available.
- Attackers poisoned three Rust crates and used Cargo builds to run malware
The releases lived for under two hours, but Cargo build scripts could execute the downloader on developer laptops and CI runners.
- Anthropic puts Claude Security's GitHub scanner behind an Enterprise login
Claude Security entered public beta for Claude Enterprise customers in late April 2026; Anthropic keeps the more capable Mythos 5 in a separate trusted-access program.
- SafeDep says poisoned arrayref release ran malware during Rust builds
SafeDep documented an August 20th compromise in which arrayref 0.3.10 pulled a typosquatted dependency that ran a remote binary during compilation, before crates.io removed the malicious packages.
- Causum launches AIAP to put expiration dates on AI agent authority
Founder Reza Fatahi's protocol puts a broker between agents and credentials, granting access for a defined purpose and time as autonomous systems gain more power to act.
- Harness ships security agents spanning vulnerability scans, fixes and virtual patches
Jyoti Bansal is folding scanning, triage, remediation and production protection into the delivery pipeline after Harness merged with Traceable.
- OpenAI pauses model training to harden its own research systems
The company ended a two-week halt for some deployment-bound training, but its largest planned frontier run and many Astra workloads remain paused under costlier security controls.
- HiddenLayer joins DOE's $60M Prometheus project to secure nuclear AI
The funding is subject to appropriations and covers a 32-partner effort, not a separately disclosed award to HiddenLayer.
- SpaceXAI bars Grok customers from helping direct or indirect rivals
SpaceXAI's policy page lists August 14th as the date for a ban on using Grok outputs to help build direct or indirect rivals.
- Wiz says Red Agent exploited a Snowflake workflow flaw introduced by Copilot
A June workflow change let a crafted issue title execute commands and expose a Jira token for five days before Snowflake patched it.
- Z.ai publishes GLM-5.3 research without a documented access path
Z.ai reports coding and vulnerability-exploitation gains, but its product documentation identifies GLM-5.1 as the latest release and provides no GLM-5.3 access path.
- Apple issues new mercenary spyware alerts to targeted iPhone users
Citizen Lab researcher John Scott-Railton urged recipients to verify the warning through Apple and seek expert security help.
- Sansec detects attempts to exploit critical Adobe Commerce account-takeover flaw
Founder Willem de Groot's security shop says its WAF is blocking attempts, while Adobe says it has no confirmed in-the-wild exploits.