AI & software security
-
Plug and Play trust enables SYSTEM attacks
Researchers have demonstrated attack chains that make Windows install signed vendor software for emulated devices, creating routes to SYSTEM privileges through trusted Plug and Play behaviour.
-
Mindgard raises $30m for AI security expansion
UK-rooted AI security company Mindgard has raised $30 million to expand a platform built around adversarial testing of models, agents, and AI applications.
-
LiteLLM exposure estimate tops 2,500 organisations
CloudSEK estimates that the LiteLLM supply chain compromise potentially exposed more than 2,500 organisations and 434,000 CI/CD pipelines, while stressing that exposure does not establish compromise.
-
Mozilla revokes exposed Firefox signing key
Mozilla has revoked and replaced a GPG subkey used for some Firefox and Thunderbird release artefacts after an unencrypted copy was committed to a private GitHub repository.
-
Poisoned feed compromises BdThemes WordPress plugins
Attackers compromised infrastructure serving a remote data feed used by seven BdThemes WordPress plugins, allowing malicious code to run inside administrators’ browsers without altering plugin files in the official repository.
-
Windows zero-day hits European defence targets
Microsoft has patched a Windows privilege-escalation zero-day that Check Point says was exploited in a Lazarus-linked campaign targeting defence, aerospace, and aviation organisations, including victims in Europe.
-
SAP patches critical Commerce Cloud flaw
SAP’s August security release fixes a maximum-severity authorisation flaw in Commerce Cloud alongside critical vulnerabilities affecting manufacturing and core enterprise platforms.
-
GitHub broadens Dependabot malware alerts
GitHub has expanded Dependabot’s malicious-package coverage beyond npm, allowing dependencies across most supported ecosystems to be matched against a wider pool of known malware advisories.
-
Poisoned logs can redirect privileged AI agents
DEF CON research shows how attacker-controlled information inside trusted operational systems can influence AI agents that have permission to change cloud and security environments.
-
OpenAI widens controlled cyber-model access
OpenAI has launched GPT‑5.6‑Cyber through an expanded Daybreak programme, giving approved researchers access to a model deliberately trained to answer substantially more advanced dual-use cyber requests.








