AI & software security
-
Ransomware groups target software supply chains
Sophos researchers say Vect and TeamPCP have linked supply chain credential theft with ransomware deployment, putting developer ecosystems in the extortion path.
-
MPs warn UK risks AI dependency
The Science, Innovation and Technology Committee says the UK lacks a coherent strategy for technology sovereignty as AI becomes central to global competition.
-
FCA warns AI could amplify cyber risk
The Mills Review says AI could reshape retail financial services by 2030 while increasing fraud, cyber security, consumer harm, and concentration risks.
-
EU weighs AI cyber strategy
MEPs are pressing the Commission on AI and cybersecurity proposals as Brussels considers how NIS2, ENISA powers, certification, and ICT supply chain rules should evolve.
-
Ransomware groups link supply chain theft
Sophos says Vect and TeamPCP have created an operational pipeline from open-source supply chain compromise to ransomware deployment.
-
JadePuffer makes agentic ransomware concrete
Sysdig says JadePuffer used an LLM-driven agent to conduct database extortion after exploiting Langflow and chaining routine techniques at speed.
-
Bank warns on agentic AI risk
Sarah Breeden has warned that agentic AI could reshape cyber, payments, and market resilience, forcing financial institutions to revisit accountability and recovery.
-
Cursor flaws expose AI coding risk
Cato AI Labs says two critical Cursor IDE vulnerabilities show how prompt injection can escape an agent sandbox and reach developer workstations.
-
Apple patch cadence compresses under AI
Apple has released some security fixes ahead of broader updates, acknowledging that AI may shorten the time between disclosure and exploitation.
-
AutoJack breaks localhost trust in AI agents
Microsoft’s AutoJack research shows how a malicious web page rendered by an AI browsing agent can reach local control planes.








