Browsing Category
Security
137 posts
Cybersecurity news, software supply chain risk, privacy threats, and practical security guidance.
Gemini 3.5 Flash Makes Computer Use a Mainstream Agent Tool
Google has moved computer use into Gemini 3.5 Flash, letting developers build agents that can see screens and act across browser, mobile, and desktop environments. The useful question is how teams design the execution loop, safety gates, and sandbox around it.
Clean GitHub Repos Can Still Trap AI Coding Agents
Mozilla’s 0DIN showed how an AI coding agent can be led from a normal-looking GitHub setup flow into running a DNS-fetched reverse shell. The proof of concept is a warning for teams letting agents install, initialize, and debug unfamiliar projects on developer machines.
Open-Weight AI Cyber Gap Narrows to Months, AISI Finds
The UK AI Security Institute says GLM-5.2 and DeepSeek V4-Pro now trail leading closed AI models on cyber tasks by roughly four to seven months. For defenders, that shrinking gap turns open-weight model policy into an operational security issue, not a distant AI governance debate.
Cisco Unified CM Exploit Gives Voice Servers a June 28 Patch Deadline
CISA gave federal agencies until June 28 to fix CVE-2026-20230, a Cisco Unified Communications Manager SSRF flaw that can write files and lead to root access when WebDialer is enabled. Enterprise teams should treat it as a voice-infrastructure exposure check, not just another Cisco patch.
Meta’s Virtue AI Hires Move Agent Security Into the Model Lab
Meta Superintelligence Labs is hiring Virtue AI co-founders Bo Li, Dawn Song, Sanmi Koyejo and other team members. The move brings automated red teaming, runtime guardrails, and agent-action security closer to Meta’s frontier AI work as labs race to make agents safer before they reach billions of users.
Mythos Limits Are Already Pushing AI Cyber Tools Toward Alternatives
Anthropic’s Mythos 5 is returning only for approved U.S. cyber defenders while Fable 5 remains restricted. In the same week, Sakana AI and 360 Security showed why AI cyber capability is becoming a provider-risk and sovereignty problem, not just a model benchmark race.
ElevenLabs SynthID Rollout Makes AI Voice Watermarking a Public Test
ElevenLabs has started adding Google DeepMind’s SynthID watermark to free text-to-speech generations and plans to expand it across all audio products in July. The move gives listeners a public detector for ElevenLabs-generated audio, but watermarking still has limits that matter for deepfake investigations and platform policy.
GitHub Code Quality Goes Paid July 20: What Teams Should Audit Now
GitHub Code Quality becomes a paid product on July 20, adding a $10-per-active-committer license, GitHub AI Credits for AI-powered checks, and GitHub Actions minutes for CodeQL scans. Teams using the free preview should audit enabled repositories, active committers, Actions usage, AI review behavior, and merge-blocking rules before billing starts.
PTC Windchill Exploits Put Manufacturing PLM Systems on Patch Clock
CISA added CVE-2026-12569, a critical PTC Windchill and FlexPLM remote code execution flaw, to its Known Exploited Vulnerabilities catalog with a June 28 deadline. The bug is being used to deploy JSP web shells against product lifecycle management systems that often sit deep inside manufacturing and engineering workflows.
Windows 10 Security Updates Now Run Through October 2027
Microsoft has extended consumer Windows 10 Extended Security Updates through October 12, 2027. Here is what the extra year covers, who qualifies, how enrollment works, and why it is still not full Windows 10 support.