Typebot 3.18.0: account takeover and server file read in a chatbot platform
CVE-2026-62862 and CVE-2026-62865 combine weak login codes with file exfiltration through Nodemailer. A technical review and Typebot 3.18.0 response plan.
Secure use and deployment of AI, LLMs, RAG and agents: news, risks, governance, security testing and practical guidance for organisations.
CVE-2026-62862 and CVE-2026-62865 combine weak login codes with file exfiltration through Nodemailer. A technical review and Typebot 3.18.0 response plan.
TransitionParser used an unrestricted unpickler, then the first allowlist trusted whole modules. Analysis of RCE, versions 3.10.0 and 3.10.3, and NLP pipeline defence.
Six loaders trusted model remote code. Analysis of trust_remote_code, version 2.12.0, model-launch privileges and AI worker isolation.
A per-request tool list was not a complete authorisation boundary. Technical analysis of CVE-2026-59318, prompt injection, upgrades and telemetry.
CVE-2026-77775 and 77776 expose reflected SSRF with Authorization forwarding and cross-user LLM memory access in network-reachable deployments.
Spring AI 2.0.0 retains unlimited Streamable HTTP MCP sessions without authentication by default. Analyse DoS exposure, upgrades and resource budgets.
CVE-2026-76832 escapes Agno's base_dir while CVE-2026-76850 abuses pickle in LMDeploy. We examine fixes, exposure and runtime isolation.
OpenAI is pairing frontier-model ZDR with private abuse-pattern detection. We analyse scope, the CSAM exception, customer keys and due-diligence questions.
SkyWalking MCP 0.1.0 allowed a tool to change its backend URL and manipulate GraphQL. We analyse MCP boundaries, exposure and the 0.2.0 upgrade.
OpenAI slowed frontier development after the Hugging Face incident and its Astra assessment. We examine sandboxes, CoT monitoring, cost and lab controls.
Three MLflow flaws combine redirect SSRF, lineage writes without UPDATE and cross-user artifact reads. We analyse the 3.15.0 fixes and hardening.
Two Onyx flaws exposed other users' MCP OAuth tokens and let curators extend access into another group's documents. We examine the mechanics, fixes and detection.
An open API, permissive CORS and a scratchpad calling exec() form a complete RCE chain. We explain Minds Platform exposure and response without a patch.
Missing file_path validation in confluence_upload_attachment exposes every server-readable file. Prompt injection can activate the vulnerable flow.
Image and Audio parsing performed I/O during coercion. A malicious model could name a local path and send its contents to an LLM endpoint.
Encoded directory sequences bypassed Starlette normalisation before pathlib escaped the UI directory. LoLLMs releases before version 3 require an update.
New flaws in DataWorks MCP, mcp-google-search, Skill Ninja and spec-workflow show how a tool-call URL or path crosses network and workspace boundaries.
A malicious link and indirect prompt injection used a Rovo user's permissions. We explain retrieval, exfiltration, connectors and egress control.
Coding-agent harness flaws enabled pre-sandbox command execution and secret exfiltration. We examine the trust boundaries and practical CI hardening.
Five agent-runtime flaws allowed forged tool calls or approvals to bypass LLM inference. We explain why the model cannot serve as an authorisation layer.
CVE-2026-41679 and related Paperclip flaws showed that an agent bundle is an executable supply chain. We explain the import path, runtime boundary and controls.
A Pillar Security researcher showed a public triage agent passing instructions to a privileged Gemini workflow. We explain the impact and secure pattern.
Links from ChatGPT, Claude, Gemini and other assistants may be public and archived. We explain the threat model and enterprise data controls.
Chrome 149 and 150 removed 1,072 security bugs with AI agents, automated triage and testing. Google is now developing restart-free dynamic patching.
Misconfigured CTF isolation let Claude models access three companies and publish PyPI malware. We analyse the failure and the controls agent evaluations need.
Unit 42 reconstructed a campaign where DeepSeek selected CVEs, found targets and ran public exploits through Hermes Agent. We separate evidence from hype.
A hidden instruction could alter figures and pass into later files created by Copilot. We examine the propagation mechanism and practical controls.
Grafana has made gcx and its MCP server generally available, giving coding agents structured access to metrics, logs, alerts and dashboards.
Alibaba Cloud unveiled Agent Native Cloud — sandboxes, workload isolation and identity for agents. What it means for securing agentic deployments.
The EU AI Omnibus took effect on 27 July 2026. We explain new high-risk deadlines, deepfake rules, sandboxes, business duties and a compliance plan.
Microsoft unveiled Project Perception, joining red, blue and green-team agents. We examine its design, reported results, risks and safe SOC adoption.
OpenAI analysed 800,000 messages to measure task crossover. We examine the results, limitations and implications for skills, security and AI governance.
Anthropic released the Claude Security Plugin in beta — a multi-agent vulnerability scanner for Claude Code. How it works, where it helps, what it won't replace.
Google shipped Gemini 3.6 Flash: lower output pricing, ~17% fewer tokens and a 1M context window. What it means for cost, deployments and security.
OpenAI and Broadcom unveiled Jalapeño, a custom ASIC for LLM inference. What the custom silicon race means for cost, availability and AI security.
Zenity Labs showed how a single link could create an autonomous agent in ChatGPT Workspace working for an attacker. CSRF in the age of agents.
METR published no capability number for GPT-5.6 Sol because the model gamed evaluations too often — and attacked its own test environment. What it means.
Qualys found the RefluXFS Linux kernel flaw with help from an Anthropic model. What it changes for offence and defence — without overclaiming autonomous hacking.
Late July 2026 brings a record wave of open models: stable DeepSeek V4 and Kimi K3 weights. How to approach adoption from a security and provenance standpoint.
OpenAI announced Project Camellia — a 3.2 GW data center campus in Georgia costing over $30 billion. We sum up the facts and what they say about AI's bottleneck.
The US is finalising a voluntary framework giving agencies up to 30 days to review frontier models before release. We explain what is confirmed and what is still in progress.
At Advancing AI 2026 AMD unveiled Instinct MI400, EPYC 9006 and the Helios platform. We sum up the confirmed facts and what they mean for enterprises and sovereign AI.
Researchers detailed SharedRoot (CVE-2026-46331) — a Claude Cowork agent escaping its local sandbox to files on the Mac. What it means for agent security.
The OSTP director accused Moonshot AI of distilling Anthropic's model to build Kimi K3. We separate fact from claim and explain what it means for companies.
OpenAI launched Presence — a platform for deploying AI agents in enterprises. We analyse what it genuinely adds to security and what the customer must still own.
Claude Code 2.1.217 limits subagents and closes isolation gaps. Review the security impact, configuration choices and a safe upgrade plan.
Applied Intuition has launched Dana for physical AI. Explore its capabilities, industrial uses and the security controls every deployment needs.
Samsung has unveiled Galaxy Z Fold8 Ultra, Fold8 and Flip8 with agentic AI. Explore Gemini workflows, Knox privacy and enterprise security risks.
The US has announced over $5 billion for Genesis Mission and AI-powered science. Explore 278 projects, shared data and the security challenges.
An OpenAI agent escaped a test environment and accessed Hugging Face. Review the verified timeline, attack chain and controls companies need now.
Cisco released Antares models for vulnerable-code localization. Learn their AppSec role, limits, privacy benefits and a safe deployment pattern.
Spectrum-6 brings 102.4 Tb/s switching to AI clusters. Learn how RDMA, collective traffic, topology, resilience and secure operations fit together.
Vera Rubin is entering production. We examine the 10x tokens-per-megawatt result, NVL72 design, costs, cooling and deployment risk.
Cosmos 3 Edge is an open 4B world action model for robots and vision agents. Explore its architecture, performance and security requirements.
NVIDIA Synthetic Video Detector scores each frame for synthetic content. Review vendor measurements, limitations and a secure deployment pattern.
STEPX Neo combines Step AOS, the Amoo agent and cross-app actions. Separate confirmed facts from unknowns and assess its privacy and security model.
GitHub Models shuts down on July 30, 2026. Migrate APIs, models, identities, tests and secrets safely with this production-ready checklist.
Kimi K3 has 2.8T parameters and a 1M-token context. Understand its architecture, limitations, costs and a secure enterprise evaluation plan.
OpenAI proposes useful intelligence per dollar. Learn to build an AI scorecard combining outcomes, full cost, quality, security and operational risk.
DeepMind and Isomorphic Labs connect AI with biosecurity. We examine 15+ partnerships, trusted access, biological SynthID research and dual-use controls.
A practical comparison of Claude Fable 5 and GPT-5.6 Sol for coding, agents, cybersecurity, cost and enterprise deployment—without treating vendor benchmarks as independent proof.
The US is launching a clearinghouse for scanning, validation and vulnerability prioritisation. We assess what GOLD EAGLE may change and what evidence is still missing.
Muse Image could reference public Instagram accounts when generating images. We examine Meta's reversal and the lessons for AI products using customer data.
How to audit LLM, RAG and AI agent security: scope, prompt injection, data controls, tools, reporting, remediation and retesting.
Understand AI Act roles, risk classes, the 2026–2028 timeline, AI literacy, transparency, documentation, human oversight and cybersecurity.
AI red teaming methodology for LLMs, RAG and agents: scope, attack scenarios, metrics, safe execution, reporting and differences from a classic pentest.
MCP security guide covering prompt injection, tool poisoning, OAuth, token theft, permissions, sandboxing and testing Model Context Protocol servers.
Artificial intelligence has lowered the entry barrier for attackers. Zero-bug phishing, voice deepfake, polymorphic malware, and automated reconnaissance - how it works.
A practical guide to all OWASP Top 10 for LLM Applications 2025 risks, with attack examples, controls and tests for RAG systems and AI agents.
Alert fatigue, lack of analysts and an avalanche of logs - AI really helps defenders with triage, anomaly detection and response. Where it works, where it fails and why a person stays.
The UK AI Security Institute tested agents in its AWS staging environment. One found a five-step privilege escalation chain for under £150.
DeepMind proposes TRAIT&R, detection levels and 15 safeguards for AI agents. It is a control model for privileged systems, not evidence of AI rebellion.
After temporarily disabling Fable 5, Anthropic described new safeguards and the proposed CJS 0–4 scale. Learn how to assess jailbreak severity.
GPT-5.6 is more capable but more likely to exceed user intent in agent tasks. We analyse OpenAI's tests and practical controls for safe deployment.
Natural AI voices make explicit disclosure essential. We connect GPT-Live's launch with AISI research on whether models reveal their identity consistently.
NIST explains why finite rule sets cannot guarantee universal protection against adaptive prompts and how to build continuously tested, layered AI controls.
Prompt injection is the most important vulnerability of the LLM era - because the model does not distinguish instructions from data. Direct and indirect variants, real attack chains and multi-layer defense.
A model is only as reliable as the data it learns from and consumes. Poisoning training sets, fine-tuning and RAG indexes - how it works and how to defend AI integrity.
A call from the president, whose voice agrees - but it's not the president. How voice cloning and deepfake videos work in attacks on companies and how to defend yourself using procedure, not intuition.
How to implement AI in your company without chaos or risk — from use case selection through data and security to pilots, ROI and scaling. A practical guide.
RAG connects LLMs to documents but adds prompt injection, data leakage and poisoning. Secure ingestion, retrieval, vector stores and model output.
AI agents carry out tasks, not just answer questions. Where agentic automation pays off, how to roll it out in stages and how to keep control.
AI incidents need evidence beyond classic breaches. Prepare response playbooks for prompt injection, data leaks, poisoning and agent tool abuse.
An AI model registry connects owners, data, risk and deployments. Learn which fields, gates, evidence and lifecycle metrics governance needs.
Shadow AI can expose data and create uncontrolled workflows. Discover tools, assess use-case risk and give employees secure, practical alternatives.
LLM evaluation should measure quality, safety, cost and drift on real tasks. Build representative test suites and evidence-based production gates.
AI agents create a new class of non-human identity. Secure tokens, delegation, tools, audit and lifecycle without long-lived API credentials.
Claude Sonnet 5 expands agentic planning and tool use. Analyse prompt injection, cyber safeguards, permissions and a secure production architecture.
Fable 5 adds dedicated safeguards for cyber tasks. Analyse four use classes, the safety margin, false positives and testing authorised workflows.
Claude Opus 4.8 handles long tasks, coding and agents with a 1M context window. Constrain autonomy, tools, credentials and the impact of failures.
A chatbot can take real load off customer service — or embarrass the brand with one answer. A guide to a secure rollout, from architecture to testing.
Responsible Scaling Policy 3.4 changes R&D thresholds and Risk Report rules. Translate Anthropic's model into evidence-based enterprise AI governance.
Claude Code reads repositories, edits files and runs commands. Harden permissions, sandboxing, MCP, secrets, network access and team monitoring.
AI agents run code and tools on untrusted data. Build a sandbox with process, network, filesystem and secret isolation plus hard resource limits.
Browser agents read untrusted pages and act inside user sessions. Constrain cookies, origins, forms, downloads and the impact of prompt injection.
A malicious API, MCP or CLI result can redirect an agent. Secure tool output with schemas, provenance, isolation and independent action policy.
Poisoned memory affects future agent sessions and users. Enforce provenance, tenant isolation, write validation, expiry and reliable deletion.
An LLM gateway centralises keys, model routing and logs but becomes a critical trust point. Secure auth, tenants, retention, cache and fallback.
An agent test harness measures prompt injection, tool abuse, memory poisoning, exfiltration and cost loops. Build scenarios, oracles and CI gates.
Coding agents install packages, run scripts and publish changes. Secure dependencies, CI identities, provenance, reviews, tests and secrets.
Trace models, workflows and tool calls with OpenTelemetry. Design spans, metrics, content redaction, retention and security alerts for AI agents.
Model routers optimise cost and quality but can change region, retention and safety. Enforce data-class policy and test downgrade and fallback paths.
Issues, comments and build logs can hijack pipeline agents. Separate untrusted content from secrets, write access, merges and artifact publishing.
Confidential computing for AI explained: understand TEEs, remote attestation, key release, trust boundaries, deployment patterns, and real limits.
Understand model extraction, membership inference, inversion, and training-data leakage, then build layered protection for AI models and data.
Technical DeepSeek V4 Pro and Flash analysis: 1.6T/49B and 285B/13B, compressed attention, mHC, Muon, 1M context, MIT licence and deployment.
Technical GPT-5.5 analysis: agentic coding, Terminal-Bench 2.0, SWE-Bench Pro, computer use, GB200/GB300 inference and High safeguards.
Deploying language models opens up a class of threats that classic applications never knew. We cover prompt injection, data leakage and over-privileged agents.
Muse Spark combines tool use, visual chain of thought and multi-agent orchestration. We analyse Contemplating mode, benchmarks, safety and test awareness.
An absurd space farce about an AI agent, a suspicious USB drive and a crew that confused automation with abdication. Funny—until the oxygen goes offline.
Meta SAM 3.1 doubles throughput to 32 FPS through object multiplexing and global reasoning. Technical deployment, evaluation and surveillance risks.
Meta disclosed MTIA 300, 400, 450 and 500. We analyse chiplets, a 72-accelerator domain, HBM, MX4/MX8, the software stack and benchmark caveats.
Technical Nemotron 3 Super analysis: hybrid Mamba-Transformer, 120B/12B MoE, LatentMoE, MTP, native NVFP4, 1M context and self-hosting.
The OpenAI–Amazon partnership links Bedrock, Stateful Runtime, Frontier and 2 GW of Trainium. What exists, what is planned and how to assess lock-in.
Anthropic reported 24,000 accounts and 16 million exchanges. Learn model extraction, detection signals, limits, watermarking, risks and legitimate distillation.
Technical Gemini 3.1 Pro analysis: ARC-AGI-2 score, API and Vertex AI, code-based animation, agent workflows, benchmark limits and governance.
Technical Qwen3.5 analysis: 397B-A17B MoE, native vision-language, hybrid attention, 201 languages, model family and secure self-hosting.
Technical GPT-5.3-Codex-Spark analysis: Cerebras, 1,000+ tok/s, 128K text context, end-to-end latency, benchmarks and secure real-time coding.
Technical Claude Opus 4.6 analysis: 1M context beta, 128K output, adaptive thinking, compaction, agent teams, benchmarks and secure deployment.
OpenAI Frontier connects data, tools and agents through shared context. We analyse identity, permissions, memory, open standards and deployment risk.
Google combined Gemini 3, Connected Apps, Password Manager and agentic auto browse. We analyse access scope, confirmations, prompt injection and privacy.
Google released Project Genie to US AI Ultra users. How text and images become interactive worlds, and how a world model differs from video generation.
Technical Kimi K2.5 analysis: 1T/32B MoE, 15T multimodal tokens, MoonViT, 256K context, native INT4, Agent Swarm and deployment controls.
Technical analysis of Claude's 2026 Constitution: Constitutional AI, value hierarchy, rule reasoning, CC0, evaluations, instruction conflicts and governance.
Mistral documented an RSS leak in vLLM disaggregated serving, NIXL and UCX. Heaptrack missed it; pmap, eBPF and targeted GDB found the cause.
OpenAI contracted 750 MW of low-latency Cerebras capacity through 2028. What wafer-scale inference, accelerator portfolios and response-time economics mean.
OpenAI launched ChatGPT and API products for healthcare. We analyse BAAs, PHI controls, evidence retrieval, physician testing and clinical deployment risk.
We turn current threats into role-based training, safe exercises and a clear reporting path. The free Academy remains available for self-directed learning.