Threat modelling stories
Companies selling software into the bloc now have 24 hours to flag exploited flaws, with fines reaching EUR €15 million for delays.
Stricter controls on agent identities and tool access aim to curb security and reliability risks as autonomous AI systems spread.
Mac users face a higher risk of tampered printer installs after HP fixed three bugs in Easy Start, including a root-level file flaw.
Security teams could see fewer false positives and faster fixes as Cycode's new system blends rule-based checks with AI to trace attack paths.
Faster agentic AI adoption is forcing tighter oversight, with new controls on permissions, monitoring and cyber-risk systems.
New controls and tests are being added as agentic AI systems spread, with Microsoft warning that risks now span tools, data and users.
Better AI security programmes are easing immediate threat concerns, but many CISOs still doubt their organisations can manage risks over the next two years.
Buyers of AI tools now have a benchmark to judge testing providers, as CREST's new standard targets gaps in assurance and due diligence.
Rising disclosure volumes are forcing security teams to predict which flaws attackers will exploit as FIRST broadens its vulnerability conference in Luxembourg.
As attackers use AI to speed up phishing and malware, companies are being told that multi-factor authentication and patching matter more than ever.
Patching is urgent for Cudy WR3000 rev 2.0 routers, as public code shows how two flaws can let attackers gain root command execution.
The new tool aims to catch Bitcoin software flaws between formal audits after a regression led to more than USD $116 million stolen.
Researchers can claim up to USD $1 million for breaking Vercel Sandbox's isolation, as the cloud provider opens its boundary to public scrutiny.
In two days, the system uncovered more than 100 critical bugs in stolen code repositories, outpacing manual review and aiding incident response.
Unauthorised access could let attackers send arbitrary commands to spacecraft and instruments via NASA's AIT-GUI console, now fixed in version 2.5.2.
Verified access to Anthropic's Claude models should sharpen ArmorCode's exploitability scoring as security teams race to cut alert noise.
Misconfigured test setups let three Claude models touch live systems, exposing production data and credentials during security exercises.
Nearly half of scanned MCP server builds carried at least one security concern, underscoring fresh supply chain risks as AI agents rely on them.
Cybersecurity experts warn single-person approvals are now vulnerable after an AI agent used fabricated identities to slip malicious code past checks.
The findings heighten concern that frontier AI agents can breach boundaries, pressure real people and target software supply chains under loose controls.