GeneralAI Agent Identity: The Reference Guide
You re deploying AI agents at scale. Your compliance framework covers user access, service accounts, and third-party integrations. But what about the agents themselves? Enterprises expect to deploy an
Expert perspectives on application security, compliance, and emerging threats
GeneralYou re deploying AI agents at scale. Your compliance framework covers user access, service accounts, and third-party integrations. But what about the agents themselves? Enterprises expect to deploy an
IncidentA remote code execution vulnerability lay hidden in Webmin for over a year, affecting versions 1.890 through 1.920. This wasn t a coding mistake — it was a deliberate insertion by a malicious actor wh
IncidentIncident Overview On January 15, 2025, Alibaba released Mythos, an advanced AI model with enhanced reasoning capabilities. Within 72 hours, security vendors began issuing alerts about AI-powered cyber
IncidentWhat Happened Mozilla s Zero Day Investigative Network (0DIN) demonstrated an attack exploiting AI coding agents through legitimate-looking GitHub repositories. The repository contained no malicious c
Get weekly security insights and compliance updates delivered to your inbox.
IncidentWhat Happened Spring Boot version 2.1.7 shipped with jackson-databind 2.9.9, a JSON parsing library containing two high-severity deserialization vulnerabilities (CVE-2019-14379 and CVE-2019-14439). Th
GeneralThe Conventional Wisdom The industry consensus suggests running AI-generated code in isolated sandboxes before it touches production. Tools like Greptile s TREX feature and Cursor s cloud agents creat
GeneralYou re maintaining a payment processing service that depends on 247 open source packages. Eighteen of them haven t seen a commit in over two years. Three have known CVEs with no patches coming. Your c
GeneralOver the past year, fewer companies are relying on AI systems for penetration testing. This isn t a failure of innovation—it s a market correction after inflated expectations met operational reality.
GeneralYour AI coding assistant just wrote 6,000 lines of code. It compiled. Tests passed. Your CI pipeline is green. But when a verification agent checked those same 6,000 lines against your team s actual r
IncidentWhat Happened Attackers are exploiting CVE-2026-12569 , a remote code execution vulnerability in PTC Windchill, to deploy web shells on vulnerable systems. The flaw has a CVSS score of 9.3. CISA added
IncidentWhat Happened SentinelLabs identified malware targeting MacOS systems that contains instructions designed to make LLM-assisted security products abort their analysis. The malware, detected under the r
DeadlinesThe proposed AI Incident Reporting Act mandates that developers of advanced AI models report major safety and security incidents to the Commerce Department within seven days of discovery. With civil p
IncidentWhat Happened On June 25, 2026, researchers identified a supply chain breach affecting the Leo Platform ecosystem on npm. Sonatype found 23 malicious package versions linked to the Shai-Hulud Miasma c
IncidentA supply chain attack targeting npm packages and GitHub Actions workflows revealed how attackers can now move across package ecosystems to harvest developer credentials at scale. The Miasma malware ca
IncidentIn January 2025, Polymarket users experienced a significant security breach when $3 million in cryptocurrency vanished from their wallets. The culprit? Malicious JavaScript injected through a third-pa
IncidentWhat Happened In August 2019, an attacker compromised a maintainer s RubyGems account for the rest-client library and inserted malicious code into versions 1.6.11 through 1.6.13. This backdoor allowed