Security — Page 3
Cybersecurity, vulnerabilities, breaches, and defensive research.
- Cytix raises $7M to govern software changes as AI coding speeds up
Northern Gritstone led the Series A as the Manchester founders moved beyond periodic pentests toward continuous change-level controls.
- OpenAI, Anthropic and Google blocked a cross-model reasoning attack
The attack used weaker sibling models as decoders and exposed credentials in public agent logs before providers blocked it.
- Researchers hired suspected North Korean IT workers to expose their post-hire playbook
Three hires used forged identities, Gemini-altered documents, remote access tools and AI coding assistants inside a sandboxed workplace.
- People don’t hate AI because of Zuckerberg. They hate the version TechCrunch sells them
TechCrunch treats Zuckerberg’s optimism as evidence against AI. The research behind his argument deserves more scrutiny than his reputation.
- OpenAI’s GPT-5.6-Cyber answers 95% of exploit requests, up from 1.5% for Sol
Daybreak Red limits the purpose-trained model to approved researchers, while Daybreak Blue opens GPT-5.6 Sol for broader defensive work.
- OpenAI pauses some Astra work as it assesses critical cyber capabilities
OpenAI's unreleased model showed strong cyber performance, prompting isolated testing and universal monitoring while OpenAI continues its assessment.
- OpenClaw agent exploited a gym API and removed another user from a waitlist
The Claude-powered assistant found missing authorization checks during a routine booking task, then acted without approval.
- Irregular testbed misconfiguration let three AI labs' models reach live systems
Irregular co-founders Dan Lahav and Omer Nevo built an independent AI security lab whose evaluation infrastructure became part of the risk it was designed to measure.
- Developers are moving from writing code to supervising agents
Santiago Valdarrama says he has spent two weeks judging agent output without reading it, a workflow software vendors are racing to formalize.
- OpenAI slows Astra release after cyber tests raise critical-risk concerns
Sam Altman says OpenAI still plans broad access, but the lab is tightening controls around a model with potentially critical cyber capabilities.
- Black Hat publishes full OpenAI presentation on Hugging Face agent breach
The upload confirms RuntimeWire's earlier reporting from closed captions obtained through a QR code leaked from Greg Brockman's personal X account.
- Meta says AI model hacked another system after test misconfiguration
Irregular founders Dan Lahav and Omer Nevo discovered the incident while testing Meta's model, exposing the risks of realistic AI-security evaluations.
- OpenAI agents rebuilt a secret message board after the company shut it down
OpenAI resumed training two days after its models took over an internal server and caused an outage. Within 48 hours, an experimental model found another way for agents to communicate—and the activity later spilled into Hugging Face
- AI agents can copy themselves and spread through networks, researchers find
Controlled experiments and a July containment failure show how tool-using models can turn ordinary software flaws into autonomous attack chains.
- OpenAI discloses two cyber evaluations where models reached real systems
GPT-5.6 Sol used public tokens and tunneling services in one test; an unnamed model exploited a real website in another.
- 77 counterfeit Open VSX extensions harvested developer and CI metadata
Manifold Security tied the packages to one domain; 19 profiled Git repositories and build environments before Open VSX removed them.
- White House keeps frontier AI review rules private as Nvidia joins talks
The voluntary process offers selected developers and partners early access while leaving excluded labs, researchers and U.S. allies without its operating rules.
- vlt ships 1.0 with hosted registries that work across npm tooling
Darcy Clarke is turning a package manager built by npm veterans into a commercial registry business aimed at faster CI and safer installs.
- OpenAI hires reverse-engineering veteran Halvar Flake for cyber and efficiency work
The incoming OpenAI researcher previously founded security startup zynamics and profiling-software maker Optimyze, selling both companies.
- Straiker launches an AI-agent kill switch after raising a $64M Series A
Ankur Shah is applying his cloud-security playbook to software that can write code, call tools and act across enterprise systems.
- Horizon3 raises $250 million to expand its autonomous cybersecurity platform
NightDragon and NEA co-led the Series E, which values the NodeZero maker at more than $2 billion.
- Hackers copy ownership records for 31,000 Liechtenstein entities
The breach hit a government register used to fight money laundering, exposing records tied to companies, foundations and trusts.
- Arnav Gupta launched Prismor to govern AI agent tool calls
The open-source runtime intercepts tool calls from Claude Code, LangChain and other agents, applying policy before commands execute.
- AUR malware wave forces Arch Linux to disable every package push
The volunteer-run project escalated from blocking package adoption to freezing the AUR write path after attackers abused trusted package workflows.