VulnCheck data questions AI vulnerability discovery risk
New research from VulnCheck complicates warnings that AI-assisted vulnerability discovery is making exploitation more dangerous. The vulnerability research firm published its H1 […]
GitHub adds approval checks for suspicious Actions workflows
GitHub has introduced an automatic approval step for certain GitHub Actions workflow runs in public repositories. The measure is intended to stop […]
Microsoft targets vulnerability scanning costs
Microsoft has released MAI-Cyber-1-Flash, a security model built into MDASH that finds vulnerabilities at half the cost of alternatives. Redmond announced the […]
Open Secure AI Alliance aims to open-source AI security defences
A new group of major firms, the Open Secure AI Alliance, are setting out to build open-source AI tools for security defences. […]
Codeberg members vote to reject LLM training and vibe coding
Codeberg members voted to reject LLM training on platform data and to restrict vibe-coded projects hosted on the forge. The German non-profit […]
GitHub Actions abuse turned Packagist repos into scanners
According to Socket, GitHub Actions abuse in Packagist repos ran cPanel scanning from temporary cloud runners. The incident began with malicious development […]
Cisco open-sources Antares AI models for vulnerability detection
Cisco has released two open-weight security models designed to search software repositories for files linked to known vulnerability categories. Antares-350M and Antares-1B […]
models escaped via package proxy
Criminals did not run the autonomous agent that compromised Hugging Face’s production infrastructure last week. OpenAI disclosed on Tuesday that the campaign was driven […]
Hugging Face confirms AI agent breached production systems
Hugging Face confirmed attackers used an autonomous AI agent to breach its production infrastructure and steal cloud credentials. The platform, which hosts […]
SleeperGem RubyGems attack evades CI to hit developer laptops
Three malicious RubyGems packages published in July 2026 evaded CI detection by targeting developer laptops directly, researchers say. Security researchers at Aikido […]
White House launches AI clearinghouse for vulnerability patching
The White House has launched GOLD EAGLE, an AI clearinghouse to coordinate vulnerability patching across infrastructure sectors. The administration says it has […]
Fake GitHub repositories exploit developer trust to spread malware
A campaign involving at least 292 impersonation repositories shows that securing the software supply chain requires developers to verify where tools, binaries, […]