AI & software security
-
Belgian eID flaws exposed trust-chain weaknesses
Flaws in software connecting Belgian electronic identity cards to web services exposed card data, PIN handling, signing functions, and local code execution across a widely deployed digital-trust system.
-
Belgian eID flaws exposed trust-chain weaknesses
Flaws in software connecting Belgian electronic identity cards to web services exposed card data, PIN handling, signing functions, and local code execution across a widely deployed digital-trust system.
-
CSS research crosses email and AI boundaries
PortSwigger research shows how weaknesses in webmail HTML and CSS handling can escape message boundaries, manipulate trusted interfaces, expose information, and influence AI browsers consuming email content.
-
RovoBlast exposes AI agent permission risks
A fixed flaw in Atlassian Rovo showed how a crafted link could place attacker instructions inside a trusted AI session and use the agent’s legitimate access across connected enterprise services.
-
OpenAI tightens Astra controls over cyber risk
OpenAI has paused Astra-related internal work that does not meet stronger security requirements after preliminary evaluations left it unable to rule out its highest cybersecurity capability threshold.
-
Kimi K3 exploits gap in UK benchmark
Kimi K3 retrieved a benchmark solution through an allowed GitHub connection during a UK AI evaluation, exposing how containment design can distort measurements of autonomous cyber capability.
-
Claude browser research demonstrates account takeover chains
Zenity researchers used indirect prompt injection against Claude in Chrome to demonstrate cross-service account takeover paths through authenticated browser sessions.
-
AI alliance proposes shared incident exchange
The Open Secure AI Alliance has proposed a confidential framework for sharing AI security incidents and near misses, extending industry collaboration into operational failure data.
-
Atlas research exposes cross-session agent risk
Zenity researchers manipulated ChatGPT Atlas through hostile web content, demonstrating unauthorised actions across authenticated services before the browser’s scheduled retirement on 9 August.
-
Critical Jenkins flaw crosses agent-controller boundary
A critical Jenkins vulnerability can allow a compromised agent or suitably privileged user to bypass a deserialisation safeguard and potentially execute code on the higher-trust controller.






