vulnerability
IBM’s 2026 Data Breach Report: 92% of AI Incidents Had No Access Controls
Most enterprises are treating AI security as a question of which model to trust. IBM’s 2026 Cost of a Data Breach report, built with the Ponemon Institute, points somewhere else: at the machine identities and access controls the model runs on. Among the one in five organizations that reported an AI-related breach, 92% had no […]
Anthropic’s AI Security Tests Broke Into Three Real Companies
AI models built to test corporate defenses have started breaking into real companies while still believing they are inside a sandbox. Anthropic disclosed three such incidents this week, found when it reviewed 141,006 of its own cybersecurity evaluation runs after a similar breakout at OpenAI. The AI security failure here was containment, not capability: a […]
OpenAI’s Models Hacked Out of Their Sandbox. AI Governance Didn’t Stop Them
Enterprise AI governance programs are built around one assumption: that a model’s stated rules are the boundary that holds it. A sandbox test at OpenAI just broke that assumption. Two of the company’s most capable models, run through a cyber-capability test with their safety refusals switched off, broke out of the sandbox meant to hold […]
Vulnerability Remediation Gap: 79% Breached by Known Weaknesses
Most security teams track their vulnerabilities carefully. Most get breached by them anyway. Vicarius, the vulnerability remediation platform provider, surveyed 300 IT and cybersecurity leaders for its 2026 State of Vulnerability Remediation report. It found that 79% experienced a security incident last year tied to a weakness already in their inventory, and how a team […]
OpenAI Daybreak Shifts AI Security Focus from Finding to Fixing
Over 500,000 vulnerabilities automatically confirmed as patched. That number, from OpenAI’s Daybreak expansion announced this week, signals a shift in where AI security effort now concentrates: not in finding flaws, but in closing them before attackers arrive. Codex Security has scanned over 30 million commits across more than 30,000 codebases since its March research preview. […]
Gentlemen Ransomware Builds Modular EDR Killer Suite From Rival Gang Tools
Ransomware affiliates have long relied on commodity EDR-killing tools, but Gentlemen ransomware takes a different approach. The gang fields a curated, modular suite of endpoint detection and response killers drawn from at least three rival criminal gangs, engineered so affiliates can swap drivers between attacks without rewriting code. BleepingComputer reported on analysis by ESET, the […]
ShinyHunters Exploits Oracle PeopleSoft Zero-Day in 100-Org Wave: Check Point June 15 Threat Intelligence
This week’s threat intelligence shows attacker operations scaling faster than defenders can absorb patches. Check Point Research’s 15 June weekly bulletin covers a zero-day that let ShinyHunters hit more than 100 organizations, exploitable flaws in LangGraph’s AI agent framework, and a Patch Tuesday addressing more than 200 Windows vulnerabilities. ShinyHunters exploited CVE-2026-35273, a critical Oracle […]
Trump Phone leaks customer data due to a vulnerability
The Trump Mobile T1 Phone, which has been trending since May 2025 as a supposed rival to Appleās iPhone lineup, is now making headlines for reasons far removed from its marketing ambitions. The premium smartphone, priced at $499 and promoted with a gold-plated exterior, has reportedly become the center of a serious data privacy controversy […]
AI Security Adds Defender Burden Faster Than Skills Catch Up
When nearly half the chief information officers in Logicalis’s April 2026 survey said they wish AI had “never been invented,” they were not posing as Luddites. They were describing a queue. TechTarget’s news brief on AI security pulls three threads from the past two weeks (the Logicalis CIO findings, the Q1 2026 bank earnings calls, […]
Talos Year in Review: Identity Security Drives Defender Priorities as Device Attacks Jump 178%
Cisco Talos closed its 2026 Year in Review on a sober identity security finding: device-compromise attacks rose 178% year over year, and ransomware chains now lean almost entirely on valid accounts and credentialed tools rather than novel exploits. Talos’s incident-response telemetry shows attackers prioritize what is exposed and reachable, with React2Shell and ToolShell weaponized inside […]







