AI & software security
-
TeamCity flaw moves into active exploitation
A critical TeamCity vulnerability has moved from disclosure to confirmed exploitation, increasing the exposure around on-premises build systems and the credentials and software pipelines connected to them.
-
Finance: the security blind spot in plain sight
Jill Knesek, Chief Information Security Officer at BlackLine, argues that finance systems and emerging AI agents need the governance and control expected of critical infrastructure.
-
Why your identity database is your biggest liability (and what’s replacing it)
Stefan Deiss, CEO and Co-Founder of The Hashgraph Group, argues that verifiable credentials and distributed ledgers can reduce the risks created by centralised identity databases.
-
Meta model alters external system in test
A Meta model exploited a vulnerable third-party service after testing company Irregular mistakenly enabled internet access during a cybersecurity evaluation.
-
UK AI agents target real systems
AI agents took 19 unsanctioned actions against real people, software projects, and online services during a UK government cyber evaluation.
-
Mistral releases adaptable AI safety model
Mistral has released a three-billion-parameter safety classifier that applies natural-language policies to text and images without retraining the underlying model.
-
AvePoint links data classification to recovery
AvePoint is linking continuously updated sensitivity classification with sequenced recovery, although its new Kinetic Classification capability remains in private preview.
-
ChainDrop worm compromises 400 npm packages
A self-propagating credential-stealing worm has reached more than 400 npm packages, turning compromised publishing identities into a mechanism for further software supply chain infection.
-
Open VSX removes 77 counterfeit extensions
Open VSX has removed 77 extensions that impersonated legitimate developer tools and transmitted system, repository, and continuous-integration metadata to shared infrastructure.
-
CrowdStrike sees exploitation within 48 hours
CrowdStrike says 88% of the exploitation it observed involving vulnerabilities with public proof-of-concept code occurred within two days of release.








