Keyv, cacheable npm supply chain attack hits 400-plus packagesLaura FrenchAugust 4, 2026The attack is believed to be related to Mini Shai-Hulud.
Black Hat 2026: 6 qualities security pros should look for in agentic AI systemsMorey J. Haber August 4, 2026
Phishing the agent: Why identity controls are essential to secure and manage AIsPaul WagenseilJuly 27, 2026
AI/MLResearchers find ‘agent-to-agent’ privilege escalation in Google’s ADK for Python repoLaura FrenchAugust 4, 2026A low-privileged agent triggered by a PR or issue could be led to manipulate a high-privileged agent.
RansomwareINC Ransomware chains two SonicWall SMA 1000 zero-days in attacksSteve ZurierAugust 3, 2026INC ransomware exploits SonicWall zero-days, prompting compromise fears.
AI/MLAnthropic Claude models compromised 3 companies during testingLaura FrenchJuly 31, 2026OpenAI’s Hugging Face incident disclosure prompted Anthropic to review its own evaluations.
Critical Infrastructure SecurityUnspecified threat actors targeting US water systems, CISA warnsSteve ZurierJuly 31, 2026CISA reports surge in cyberattacks targeting water utility PLCs.
Threat ManagementAmazon attributes axios, debug, chalk NPM attacks to DPRK’s Sapphire SleetLaura FrenchJuly 31, 2026Amazon linked the campaigns through overlapping C2 indicators, TTPs and code.
Cloud SecurityCritical Azure Cosmos DB flaw risked cross-tenant compromiseSteve ZurierJuly 30, 2026Patched Azure Cosmos DB bug threatened Microsoft and customer databases.
Critical Infrastructure SecurityIndustry CISOs urge resilience, AI governance and regulatory reformSC StaffJuly 30, 2026CISOs urge resilience, supply chain security and simpler cyber rules.
AI/MLOpenAI agent exploited JFrog Artifactory flaw, abused Modal customer sandboxLaura FrenchJuly 30, 2026Hugging Face and OpenAI revealed further details on the agent’s 4.5-day attack campaign.