Security — Page 5
Cybersecurity, vulnerabilities, breaches, and defensive research.
- GitHub issues $100,000 bounty for critical RCE vulnerability disclosed by @sagitz_
The researcher disclosed CVE‑2026‑3854, a critical RCE flaw, prompting the largest payout in GitHub's Vulnerability Reward Program to date.
- Glow raises $180 million to control AI software on enterprise endpoints
The Onavo co-founder and former Meta VP is betting prevention-first security can manage the software and agents spreading across corporate devices.
- watchTowr sees SharePoint attackers stealing keys that can outlast patches
watchTowr says its honeypots saw attacks within hours of public exploit code, matching founder Benjamin Harris's core security thesis.
- OpenAI announces models hacked Hugging Face during an eval
The models escaped an evaluation sandbox, found a zero-day and used Hugging Face's dataset pipeline to reach internal systems, OpenAI says.
- Empirical Security raises $25M to tailor exploit predictions to each customer
Brightmind led the Series A for the Chicago team behind Kenna Security and EPSS, taking disclosed funding to $37 million.
- White House AI adviser attacks cyber guardrails after Kimi K3 bug test
David Sacks seized on a developer's unverified comparison as Hugging Face documented a similar guardrail failure during breach analysis.
- Beacon Security raises $13 million for agentic cybersecurity data layer
Gal Tal-Hochberg's new company wants to fix the raw telemetry problem before security teams hand more work to AI agents.
- OpenAI ships GPT-Red to train GPT-5.6 against prompt injection attacks
The internal-only model uses adversarial self-play to generate attacks that harden OpenAI's production models before deployment.
- Sysdig's AI ransomware report puts Loris Degioanni's runtime bet to the test
JADEPUFFER was human-directed, but Sysdig says an AI agent handled reconnaissance, credential hunting, encryption and the ransom note.
- Ghostcommit exposes the image blind spot in AI code review
ASSET Research Group's proof-of-concept hides a secret-stealing instruction inside a PNG that text-based reviewers skip.
- GitLost shows how a public issue can make GitHub's AI agent leak private repo data
Noma Labs says a prompt injection in GitHub Agentic Workflows crossed from public issue text into private repository content.
- Nebula Security publishes GhostLock exploit for 15-year Linux kernel flaw
The AI security lab says the bug powered an IonStack chain and earned a $92,337 kernelCTF reward from Google.
- As Amazon lets Mechanical Turk fade, Mercor hits a $2 billion gross run rate
The figure is before contractor payouts, but it shows how AI labs have shifted paid human labor from commodity microtasks to expert data work.
- Dario Amodei's Mythos bet is hitting the public CVE record
Epoch AI found a June spike in serious vulnerability disclosures, but the data shows a bottleneck Anthropic still has to clear: patching.
- YouTube's AI can be tricked into leaking private video titles, researcher says
Security researcher Javox says Google rejected the report as social engineering, exposing a policy gap around AI-driven creator tools.
- Citizen Lab says Pegasus hacked an EU lawmaker investigating Pegasus
Stelios Kouloglou's iPhone was infected in 2022 and 2023 while he sat on the European Parliament's spyware inquiry committee.
- Sysdig says JADEPUFFER carried out ransomware with an AI agent
Sysdig's report sharpens Loris Degioanni's runtime thesis: attackers can chain old cloud flaws without a human operator.
- Dawnguard raises $3.3M as secure-by-design cloud security gets funded
Co-founders Mahdi Abdulrazak and Kim van Lavieren launch Dawnguard's platform publicly, add a New York office, and pass $6.3M raised.
- Anthropic vs. The U.S. Government: The Full Timeline
The documentary follows Dario Amodei's refusal to drop Claude safeguards through the ban, lawsuits and export-control shutdown.
- Straiker hires Sriram Puthucode as CRO after $64M Series A
The AI-agent security company says Puthucode will lead global revenue as it pushes into EMEA and prepares APJ leadership expansion.
- Matt Mastracci says a fake VC interview tried to turn his maintainer laptop into a supply-chain foothold
The Rust maintainer found a TypeScript take-home repo that hid PinpinRAT in a TypeScript patch and PNG payload.
- Anthropic's Fable 5 redeployment faces a same-day cyber safety test
Alec says Fable 5 still helped plan offensive IoT abuse after Anthropic restored access on July 1st.
- Dario Amodei gets Fable 5 back online after Anthropic's export-control scare
Claude Fable 5 returns globally on July 1st, while Mythos 5 remains tied to government-approved cyberdefense access.
- Commerce is expected to lift Anthropic Fable 5 export controls tonight
The move would reopen access to Anthropic's general-use frontier model after an 18-day fight over AI, cybersecurity and export law.