GuidesVerification Layers for AI-Generated Code
You ve got an AI agent writing production code. It passes the linter and looks clean. Then it ships a dependency that phones home to an expired domain, or it refactors an authentication check into a d
Expert perspectives on application security, compliance, and emerging threats
GuidesYou ve got an AI agent writing production code. It passes the linter and looks clean. Then it ships a dependency that phones home to an expired domain, or it refactors an authentication check into a d
GuidesThe Question at Hand Your security team is evaluating AI agents for threat detection, incident response, or vulnerability analysis. The vendor pitch sounds promising, but here s what they won t tell y
IncidentImproved Security in AI Models Anthropic has released data showing that Opus 5 significantly improves resistance to prompt injection attacks. On the IPI benchmark, Opus 5 reduced the probability of a
IncidentWhat Happened On July 27, security researcher Kevin Beaumont discovered that Adform s JavaScript tracking script had been compromised to steal cryptocurrency. The malicious code monitored users clipbo
Get weekly security insights and compliance updates delivered to your inbox.
IncidentWhat Happened In November 2025, security firm Wiz discovered a critical vulnerability in Azure Cosmos DB. This flaw could have allowed attackers to access the master key for any Cosmos DB instance. Th
GeneralWhat Changed On July 29, a coordinated attack compromised Arch User Repository (AUR) packages through the orphan adoption system. It began with openconnect-sso and expanded to over 200 packages before
IncidentWhat Happened On July 27, JetBrains disclosed CVE-2026-63077, a critical authentication bypass vulnerability in TeamCity On-Premises that allows remote code execution. This flaw affects all versions o
IncidentAn attacker sends a single HTTP request to your AI orchestration platform. Within seconds, they have shell access to your production environment, can read your database, and manipulate the memory of e
IncidentWhat Happened On October 21, 2024, attackers compromised two of npm s most widely used packages: debug (with over 200 million monthly downloads) and chalk (with over 100 million monthly downloads). Th
IncidentWhat happened Oracle s July 2026 Critical Patch Update (CPU) includes 1,449 security fixes across 1,235 unique CVEs. Nine vulnerabilities in Oracle Fusion Middleware have a CVSS score of 10.0, allowin
GeneralOnly two out of hundreds of platform engineers feel confident in their security systems for AI-written code. This statistic from PlatformCon London highlights a critical issue: your team is deploying
IncidentAn AI-powered fraud detection system at a financial services organization became the entry point for a supply chain attack. Attackers exploited trust relationships between the system s components, exp
IncidentA single POST request, no credentials required, and an attacker owns your AI orchestration layer. That s what CVE-2026-59726 exposed in Ruflo, an AI orchestration platform used to coordinate multi-age
IncidentWhat Happened A security scanning tool, integrated into a software development pipeline, became a vector for downstream compromise. Positioned as a protective control in the CI/CD workflow, the scanne
IncidentAn unauthenticated attacker uploads a specially crafted image to your Rails application. Thirty seconds later, they re reading your .env file, extracting database credentials, API keys, and every secr
IncidentWhat Happened A remote code execution vulnerability in Gitea allowed any user with repository write access to execute arbitrary shell commands on the host server. Tracked as CVE-2026-60004 with a CVSS