Ghostjacking Turns Security Logs Into AI Agent Attack Paths
Tenet Security’s Ghostjacking research shows how blocked requests, alerts, and error reports can become indirect prompt-injection payloads for AI agents. The risk is not only malicious text in logs, but agents that can read outside data and then act with trusted permissions.
OpenAI’s GPT-5.6-Cyber Puts Safer Hacking Behind a Trust Gate
OpenAI is giving approved defenders access to GPT-5.6-Cyber through a new Daybreak Red tier. The launch is less a general chatbot upgrade than a test of whether advanced exploit validation can be useful inside identity checks, scoped permissions, monitoring, hardware-key requirements, and human review.
N-able N-central Hotfix Turns RMM Servers Into an Incident Response Drill
N-able has released a second required hotfix for an actively exploited N-central authentication-bypass flaw. For MSPs and enterprise IT teams, the work is not only upgrading to 2026.3.1.10, but also checking Take Control sessions, Cloudflare Tunnel persistence, and downstream endpoints before treating the RMM platform as trusted again.
Tenable CyberAgents Exchange Turns Security Agents Into Shared Infrastructure
Tenable launched CyberAgents Exchange at Black Hat USA as a free, open-source registry for cybersecurity AI agents, skills, MCP servers, and playbooks. The useful idea is shared defense code; the hard part is proving each component is trustworthy enough to run inside real security operations.
White House AI Review Rules Put Frontier Models Behind a Private Gate
The White House has finalized a voluntary framework for reviewing advanced AI models before release, but the testing criteria are staying private. That turns frontier model launches into a new kind of prerelease security review, with open-weight models and outside researchers still sitting largely outside the process.
ChatGPT Voice Can Now Talk Through Your Files and Projects
OpenAI added file uploads and Projects to ChatGPT Voice, letting users talk through documents and project context instead of switching back to typing. The useful change is hands-free analysis; the risk is that voice now reaches deeper into saved work, files, and workspace settings.
Cloudflare Kitesurf Gives AI Agents a Browser Built for Scale
Cloudflare’s Kitesurf is a new browser for AI agents, not people. It runs on Workers, works with Browser Run, and trades pixel-perfect Chromium compatibility for lower CPU, lower memory use, stateless isolation, and cheaper bursty automation.
OpenAI’s Astra Pause Turns Frontier AI Into a Release-Gate Test
OpenAI paused some internal Astra work after early evaluations could not rule out “Critical” cyber capabilities. The move shows frontier model launches are becoming cybersecurity release-gate events, with stricter test environments, monitoring, government review, and third-party controls now part of the path to deployment.
Google Earth Pulls AI Image Tool After Map-Deepfake Backlash
Google rolled back a new Google Earth image-generation feature one day after launch, after users shared AI-generated geospatial scenes that appeared to violate company policies. The episode shows why satellite-style imagery needs stronger provenance, sharing limits, and product guardrails than ordinary AI art tools.
Rails Active Storage Flaw Turns Image Uploads Into a Secret-Rotation Drill
Rails maintainers patched CVE-2026-66066, a critical Active Storage flaw that can let attackers turn image uploads into arbitrary file reads and possible remote code execution. For affected teams, the job is not only upgrading Rails and libvips, but checking exposure windows and rotating secrets that may have been readable by the Rails process.