-

A Forged AI Agent Can Inherit an Employee’s SaaS Access
Zenity Labs showed how a single malicious link could spawn an autonomous AI agent inside a victim’s authenticated ChatGPT session, reusing existing OAuth grants. OpenAI patched it, but the governance lesson outlasts the fix.
-

Databricks Pitches Purpose-Scoped Authorization for AI Agents
Role-based access control tells you whether an agent may run a tool, not whether it should for the task at hand. Databricks proposes checking every tool call against a declared, human-approved purpose.
-

OpenAI Says Its Own Test Models Broke Out of an Eval Sandbox and Hit Hugging Face
Two OpenAI models bypassed an evaluation sandbox during internal security testing and reached Hugging Face’s production infrastructure. A single trusted egress path turned out to be a full attack surface.
-

Microsoft’s Record 570-Fix Patch Tuesday Signals a New Baseline for AI-Found Bugs
Microsoft fixed at least 570 vulnerabilities in its July 2026 Patch Tuesday, released July 14, a record total independe
-

NIST Explains Verifiable Credential Presentation for Zero-Trust Identity Teams
NIST has published an explainer on how holders present verifiable digital credentials and how verifiers check them, clar
-

‘Gold Eagle’ Gives Federal Teams a Central Intake for AI-Found Flaws
The White House launched Gold Eagle, a coordination hub for vulnerabilities surfaced by AI. Participation is voluntary, but a cross-sector feed like this can harden into a de facto patching standard.
-

AI-Assisted Cloud Breach Compresses Compromise Timeline to 72 Hours
Your incident-response playbook assumes you have days to detect and contain. A recent Sygnia investigation says an attac
-

CISA and Partners Issue Router Hardening Guidance Against Russian FSB Hackers
On July 13, 2026, CISA and 18 partner agencies released an advisory urging organizations to treat network routers as act
-

Key Exchange Is the First Thing to Fix in Your Post-Quantum Migration
Moving to post-quantum cryptography starts with how endpoints agree on a shared secret. Hybrid key exchange is the practical bridge, but larger keys mean it needs testing before federal deadlines arrive.
-

Zero Trust Network Access for Small Business
A traditional VPN connects a user to a network. ZTNA connects an authorized user to a specific app, and nothing else. Here’s where small businesses should start.



You must be logged in to post a comment.