AI Security OpenAI pauses training as Astra approaches critical cyber capability
OpenAI slowed frontier development after the Hugging Face incident and its Astra assessment. We examine sandboxes, CoT monitoring, cost and lab controls.
Daily news, analysis and practical guides explaining what happened, who is affected and what to do next. We also turn this knowledge into practical training for organisations.
AI Security OpenAI slowed frontier development after the Hugging Face incident and its Astra assessment. We examine sandboxes, CoT monitoring, cost and lab controls.
Vulnerabilities and CVEs Oracle's final bulletin contains 943 new fixes across databases, EBS, Middleware, Java and other products. Here is how to turn the matrix into a rollout plan.
Vulnerabilities and CVEs Apple released three major security updates on 17 August. We examine ImageIO, WebKit, Kernel and Telephony fixes and a practical MDM rollout plan.
Vulnerabilities and CVEs CVE-2026-15623 was disclosed on 17 August, although Google fixed it in SecOps 6.3.85 in May. We examine blind SQLi, chronology, risk and monitoring.
AI Security Three MLflow flaws combine redirect SSRF, lineage writes without UPDATE and cross-user artifact reads. We analyse the 3.15.0 fixes and hardening.
AI Security Two Onyx flaws exposed other users' MCP OAuth tokens and let curators extend access into another group's documents. We examine the mechanics, fixes and detection.
Identity and Access Three LemonLDAP::NG and Net::OAuth flaws show how state, oauth_verifier and pre-auth dispatch semantics can quietly move an SSO trust boundary.
Cloud, Infrastructure and DevSecOps A provider-cache symlink, expensive ZIP files and an older sensitive-value leak show why IaC directories and package sources are security inputs.
Penetration Testing and AppSec A wave of Scriban CVEs shows why LoopLimit and object filters are insufficient. We analyse DoS, CLR property writes and safer template execution.
Vulnerabilities and CVEs Three Stoat CVEs combine a missing IPv6 address, unbounded SVG rendering and inconsistent message permissions. We explain the 0.15.0 fix.
Vulnerabilities and CVEs Unbounded CSP reports and request-driven locale caches can exhaust the Java heap. We analyse S2-073, S2-074, mitigations and fixed releases.
Identity and Access An option-merging error makes @fastify/jwt ignore a route-specific key. We explain the authorization bypass, affected architectures and upgrade to 10.2.2.
Cloud, Infrastructure and DevSecOps TAR path traversal enables arbitrary file writes while a DAA decompression bomb exhausts the analyser. We explain the fixes in Pandora 1.12.6.
Vulnerabilities and CVEs PDF annotations, calculations and database metadata reach innerHTML while Node Integration raises impact to code execution. We analyse the CVE wave and v3.7.4.
Cloud, Infrastructure and DevSecOps The Net Check feature accepts Socket.io input and executes it as root. We explain the OT risk, the 3.50.1.19 update and effective segmentation.
Once a month, a concise summary of the vulnerabilities and threats that matter. No spam, unsubscribe anytime.