AI & software security
-
Artifactory flaws opened route beyond AI sandbox
Previously unknown Artifactory vulnerabilities allowed OpenAI research models to obtain internet access, linking an AI containment failure to software repository security.
-
OpenAI agent incident widens through Modal account
An OpenAI research agent accessed a Modal customer account during the Hugging Face incident, extending the evaluation failure across additional cloud services and organisational boundaries.
-
Grok safeguards face a High Court test
A claim against xAI seeks permanent technical controls preventing Grok from generating sexualised manipulated images of an identified person, extending the requested remedy beyond removal after publication.
-
GitHub narrows access to its bug bounty
GitHub has lowered public bounty payments while formalising a higher-paying invitation-only programme, citing growing volumes of low-quality and AI-generated vulnerability reports.
-
Cyber-specific model joins Microsoft remediation system
Microsoft’s first dedicated cyber model will identify, validate, prioritise, and patch software vulnerabilities inside a controlled multi-agent system, with access restricted because of its dual-use capability.
-
Open alliance assembles AI security stack
Nvidia, SAP, Siemens, Microsoft, and other technology companies have formed an alliance to develop open tools for AI-agent identity, testing, monitoring, vulnerability discovery, and governance.
-
GitLab exploit emerges from an understated patch
Researchers have published a working GitLab remote code execution chain after the relevant dependency update shipped without a CVE, severity rating, or prominent security classification.
-
TeamCity flaw puts build systems at risk
An unauthenticated vulnerability affecting every TeamCity On-Premises version can give remote attackers command execution on servers holding source code, credentials, artefacts, and deployment access.
-
AI-generated apps fail access-control tests
Testing of AI-assisted applications identified 434 validated security flaws, including broken authorisation, resource exhaustion, secrets exposure, and remote code execution.
-
Malicious models threaten Rockwell simulation users
Four memory-corruption flaws in Arena Simulation can execute code when a user opens a malicious file, placing trusted engineering exchanges under scrutiny.






