Hi, what are you looking for?
Learn more about protecting against unmonitored use of generative AI (Shadow AI) in business units and building and enforcing AI governance frameworks.
The funding round was led by Balderton Capital, with additional support from Crosspoint Capital and previous investors General Catalyst and Ten Eleven Ventures.
France-based startup Edamame says its runtime verification platform uses host telemetry and AI analysis to detect coding-agent “intent drift,” secret theft and supply-chain attacks...
CISOs are now facing machine-speed attacks and asking, “How do I agent?” The industry must provide remediation at scale.
New AI Threat Defense platform combines capabilities from Mandiant, Wiz and Gemini to help customers fight AI with AI.
Now in its third year, the AI Risk Summit is the leading conference that brings together CISOs, security leaders, AI researchers, developers, policymakers, and...
Malicious repositories and disguised symlinks can trick AI coding agents into silently installing attacker-controlled MCP servers capable of stealing secrets, compromising CI pipelines, and...
The AI giant says the new plugin, which helps developers find vulnerabilities as they write code, has been used extensively internally.
Notable integrations include CrowdStrike, Palo Alto Networks, Microsoft, Okta, Zscaler, Netskope, Cloudflare, Fortinet, and Wiz.
Many findings have been confirmed to be critical or high-severity vulnerabilities and the number will continue to increase.
More than 200 vulnerabilities patched in recent Chrome releases are marked as ‘reported by Google’.
Digital.ai’s latest threat report warns that agentic AI has erased the distinction between emerging and primary targets, enabling attackers to strike mobile apps within...
1Password says AI coding agents should never hold persistent secrets, introducing a just-in-time credential model for OpenAI Codex designed to keep credentials out of...
The researcher who found it says the vulnerability could have been chained with a prompt injection to exfiltrate data.
As enterprises rush AI projects into production, security teams are increasingly being forced into reactive mode.
Four vulnerabilities in OpenClaw can be chained together to steal credentials, escape the sandbox, and plant persistent backdoors.
Participants demonstrated exploits for Windows, Linux, VMware, Nvidia, and AI products.
Other noteworthy stories that might have slipped under the radar: Nvidia cloud gaming data breach, Android 17 security upgrades, FBI warning after ShinyHunters hacks...
Two employee devices were compromised in the attack, and credential material was stolen from OpenAI code repositories.
Independent benchmarking finds Mythos highly effective for source code audits, reverse engineering, and native-code analysis, though its exploit validation and reasoning capabilities remain inconsistent.
The goal of the guidance, which outlines minimum elements, is to help organizations enhance transparency in AI systems and supply chains.