AI & software security
-
Why cybersecurity must evolve for the age of AI agents
Vishal Salvi, Global Head of Cybersecurity Services at Cognizant, argues that AI agents need identity, access controls, monitored context, and governance before organisations can safely scale autonomy.
-
Claude tests crossed into live systems
Anthropic says three cyber evaluation incidents allowed Claude models to reach the internet and access real production systems through a third-party test environment.
-
Product security gets an SME playbook
ENISA’s secure-by-design and secure-by-default playbook gives smaller manufacturers practical steps for building product security into engineering and release work.
-
AI agent rollout strains identity governance
Kocho says AI agents and non-human identities are expanding enterprise access faster than many organisations can govern, monitor, and hold accountable.
-
AI-discovered flaws show ordinary exploitation rates
VulnCheck says only 14 of 1,061 AI-assisted vulnerability discoveries were confirmed as exploited in the wild during the first half of 2026.
-
North Korean campaign connects npm compromises
Amazon says compromises of axios, debug, chalk, and typo-crypto were linked to the same DPRK-linked actor, reframing separate incidents as a wider supply chain campaign.
-
Self-hosted Gitea platforms face RCE risk
Gitea has disclosed a critical remote code execution flaw that can let repository writers execute shell commands as the Gitea OS user.
-
Unprotected AI agent bridge exposes command access
Noma Security says a critical Ruflo MCP bridge vulnerability exposed agent tools over HTTP without authentication, allowing command execution inside the container.
-
Rails image flaw puts application secrets at risk
Rails has fixed CVE-2026-66066, an Active Storage vulnerability that may allow arbitrary file reads and remote code execution in affected applications.
-
Cyber remains undefined in England’s technical education plan
England’s planned technical pathways for pupils from age 14 include AI and digital subjects, although the place of cyber security within the curriculum has not been defined.









