Security & Cyber
LIVEVulnerabilities, threat intelligence, and security advisories
Turn specs into evals for any agent with ASSERT
Transform AI Model Specs into Evaluations with ASSERT
Reconstructing AI activity in investigations
Enhancing AI Investigations with Microsoft 365 Copilot and Azure AI
AI brands as bait: How threat actors are using the AI hype in social engineering
HIGHAI Hype Exploited in Social Engineering Attacks
Securing CI/CD in an agentic world: Claude Code Github action case
HIGHMicrosoft Uncovers Prompt Injection Vulnerability in Claude Code GitHub Action
Updating the taxonomy of failure modes in agentic AI systems: What a year of red teaming taught us
HIGHRed Teaming Reveals New AI Failure Modes and Mitigations
CRITICAL: Preinstall to persistence: Inside the Red Hat npm Miasma credential-stealing campaign
CRITRed Hat npm Miasma Attack: Credential Theft in CI/CD Environments
Microsoft Build 2026: Securing code, agents, and models across the development lifecycle
Microsoft Enhances AI Security with MDASH at Build 2026
Malicious npm packages abuse dependency confusion to profile developer environments
HIGHDependency Confusion Exploited by Malicious npm Packages in Developer Environments
Microsoft is named a Leader in the 2026 Gartner® Magic Quadrant™ for Endpoint Protection
Microsoft Secures Leadership in 2026 Gartner Magic Quadrant for Endpoint Protection
Typosquatted npm packages used to steal cloud and CI/CD secrets
HIGHTyposquatted npm Packages Threaten Cloud and CI/CD Security
CRITICAL: The Gentlemen ransomware: Dissecting a self-propagating Go encryptor
CRITThe Gentlemen Ransomware: A New Self-Propagating Threat Unveiled
From poisoned search results to GPU mining: A cryptojacking campaign abusing ScreenConnect and Microsoft .NET utilities
HIGHCryptojacking Campaign Exploits ScreenConnect and .NET Utilities via SEO Poisoning