Security — Page 6
Cybersecurity, vulnerabilities, breaches, and defensive research.
- Kali Linux 2026.2 puts maintenance ahead of spectacle
The new release adds 9 tools, faster VM boots, GNOME 50, KDE Plasma 6.6 and a heavier NetHunter push for Android-based testing.
- Anonymous Exploitarium repo shows the new AI security triage problem
The GitHub archive mixes serious PoCs, conditional claims and self-reported AI-assisted fuzzing across open-source projects.
- Sakana and 360 turn Anthropic's Mythos ban into an opening
Fugu and Tulongfeng are being pitched as regional answers to U.S. model access risk, but their benchmark claims remain company-reported.
- Andrew Nesbitt's fake CVE is a real warning for AI security startups
The June 26th satire turns prompt injection, automated triage and agentic remediation into one supply-chain failure mode.
- Moltbook's 1.5 Million Token Breach Shows the Cost of Agent Hype
Wiz found missing Supabase controls let outsiders read and write production data before Meta bought the AI-agent forum.
- Z.ai's GLM-5.2 puts price, not just intelligence, at the center of the AI model race
Z.ai is using open weights and lower token costs to pressure Anthropic and OpenAI where enterprises feel the bill.
- Anthropic nears US deal to restore Fable 5 and Mythos 5 access
Tom Brown has taken the lead in talks with Commerce after a June 12th order forced Anthropic to shut off its top models globally.
- OpenAI's GPT 5.6 rollout shows Washington is becoming AI's gatekeeper
Sam Altman told staff the federal government asked OpenAI to limit GPT 5.6 access before wider release, The Information reported.
- Dawn Song, Bo Li and Sanmi Koyejo join Meta Superintelligence Labs
Meta is hiring three Virtue AI founders and other team members as agent security becomes core infrastructure for frontier labs.
- Aikido brings pentest-style reasoning into static code review
Code Audit analyzes source code for multi-step vulnerabilities that rule-based scanners and live pentests can miss before release.
- Langflow attacks show AI agent frameworks have become production infrastructure before security caught up
VentureBeat tied active Langflow exploitation to fresh LangGraph and LangChain-core flaws that turn old AppSec bugs into AI infrastructure risk.
- Sebastian Kurz's DREAM raises $260M at a $3B valuation for sovereign AI cyber defense
The former Austrian chancellor and ex-NSO cofounder Shalev Hulio are pitching governments on cyber systems they control themselves.
- Anthropic's Mythos fight turns on the hacker who first told it to slow down
Nicholas Carlini warned Anthropic not to release Mythos in March. He is now central to its case that guarded access is safer than a ban.
- Unicorn Engine's decade-long CPU emulation bet still has teeth
Nguyen Anh Quynh and Dang Hoang Vu built Unicorn as a focused alternative to QEMU, and security tooling still leans on that choice.
- Anthropic fight with Trump turns into a cyber-defense fight
Security leaders say the Fable 5 and Mythos 5 restrictions risk punishing the same bug-finding work defenders need.
- Depthfirst turns FFmpeg into a proof point for autonomous security agents
The AI security startup says its agent found 21 FFmpeg zero-days for about $1,000, including an RCE exploit primitive.
- Malware authors use nuclear and biological weapons language to evade scanners
A Hades supply-chain wave hid weapons-policy bait in non-executing code comments to jam LLM-first malware triage.
- Anthropic says the jailbreak behind Fable 5 shutdown was code review
The Amodeis' safety-first AI company is now fighting Washington over whether a narrow coding prompt justifies pulling frontier models.
- Moonshot's Kimi K2.7 Code lands on Cloudflare Workers AI
The post gives Moonshot distribution through Cloudflare, but offers no pricing, benchmarks, context length, or model-size details.
- Troy Hunt's breach counter hits 1,000 as disclosure lags stretch
Have I Been Pwned now lists 1,003 breached sites and 17.6B pwned accounts, with recent Carnival and Zara notices arriving weeks after public leaks.
- Dashlane says attackers stole some customers' encrypted password vaults
Dashlane says about 20 accounts were accessed after attackers brute-forced 2FA to register new devices and download vaults.
- Researchers warn Meta's AI Instagram support can be tricked to email password reset links
Posts on X and a now-removed Hacker News thread describe a prompt that convinces the AI agent to send reset links to attacker emails without identity checks; posters say takeovers are active and urge users to lock down email and 2FA.
- PromptArmor says ChatGPT for Google Sheets can exfiltrate entire workbooks via a single prompt injection
The AI risk team reports that OpenAI’s new Sheets add-on can be manipulated to run attacker scripts and steal data across an account, even with human approvals required.
- Whip launches as a social feed of tappable AI mini apps and games
Creator samagra14 debuts Whip as a social home for playful, weird, useful AI mini apps and games, with no-code creation and a public download link.