AI & software security
-
Google patches Chrome V8 zero-day
Google has patched a high-severity V8 type-confusion vulnerability in Chrome and says an exploit for CVE-2026-85046 exists in the wild.
-
Magento zero-day exploited against live stores
Security researchers say attackers are exploiting an unpatched Magento and Adobe Commerce zero-day capable of unauthenticated remote code execution across current platform versions.
-
VMware flaws can cross virtual-machine boundary
Broadcom has patched two VMware Workstation and Fusion vulnerabilities that can allow an attacker with administrative control inside a virtual machine to execute code on the host.
-
Autonomous pentesting is solving the wrong half of the problem
Jay Kaplan, CEO and Co-founder of Synack, argues autonomous pentesting can expand coverage, but without expert human validation it risks shifting security teams from untested assets to untriaged findings.
-
CREST accredits first AI-enabled penetration-testing providers
CREST has accredited its first ten AI-enabled penetration-testing providers, creating an assurance framework around how artificial intelligence is governed inside professional security testing services.
-
Git trust flaw hits AI coding agents
Manifold Security has disclosed a class of execution flaws across AI coding agents that can allow untrusted repository configuration to run commands before normal workspace trust controls.
-
OpenAI says Astra reaches critical cyber threshold
OpenAI now says Astra meets its highest published cybersecurity capability threshold, moving beyond its August assessment that it could not rule out the classification.
-
Langflow attacks target cloud and AI secrets
Attackers are exploiting a critical Langflow code-execution flaw and probing compromised environments for OpenAI keys, AWS credentials, and other sensitive secrets.
-
JFrog Artifactory flaw reportedly exploited in wild
A critical Artifactory authentication bypass is reportedly being exploited days after disclosure, creating a potentially serious route into self-managed software artefact infrastructure.
-
Anthropic resumes cyber tests under tighter controls
Anthropic has resumed external cyber evaluations after models reached unintended real systems, adding stronger sandboxing, real-time intervention, and tighter controls for third-party testing.










