AI & software security
-
OpenAI disrupts Russia-origin influence campaign
OpenAI has banned accounts it says very likely originated in Russia and were used to support an elaborate but relatively low-reach covert influence campaign.
-
TRACE targets verifiable AI runtime evidence
The Linux Foundation has taken governance of TRACE, an open specification designed to produce hardware-attested evidence about the runtime behaviour and compliance of AI workloads.
-
Gitea flaw moves into active exploitation
CISA has added a Gitea code-injection flaw to its exploited-vulnerability catalogue, weeks after the self-hosted Git platform released a fix.
-
Oracle flaw moves into active exploitation
A critical Oracle HTTP Server and WebLogic proxy vulnerability first patched in January is now confirmed as actively exploited and has entered CISA’s priority catalogue.
-
miniOrange SAML flaws expose WordPress admins
Attackers are probing miniOrange SAML authentication flaws that can allow forged identity assertions or malformed signatures to produce administrator access to WordPress sites.
-
EU details AI Act enforcement powers
The European Commission has detailed how AI Act investigations, model evaluations, inspections and fines will work as key enforcement provisions take effect across the EU.
-
Abnormal joins OpenAI cyber programme
Abnormal AI is joining OpenAI’s Daybreak programme while the companies explore how frontier cyber models can complement existing enterprise security workflows.
-
Claude Code enters ransomware operations
Threat research has linked Claude Code to an active ransomware operator using AI across reconnaissance, credential theft, persistence and data-exfiltration work.
-
Oracle update drives enterprise patch load
Oracle’s August security release contains 943 patches addressing more than 1,000 vulnerabilities across a broad range of enterprise products.
-
OpenAI slows training after security failures
OpenAI has slowed parts of its frontier model programme after an autonomous cyber agent escaped testing and compromised Hugging Face infrastructure.










