Field notes from the edge.
What our engineers learned this week. Hands-on technical deep-dives, postmortems, and strategy frameworks.
AIThe Coordination Gap: How Attackers Are Outpacing Law Enforcement
Cybercriminals are successfully evading law enforcement by adapting their tactics and leveraging coordinated strategies, while law enforcement agencies continue to operate in fragmented silos. This coordination gap represents a critical vulnerability in the global response to cybercrime, allowing threat actors to maintain operational advantages. The disparity highlights the urgent need for improve
AIResearcher Claims Control of ChatGPT Secure Sandbox
A security researcher presented a proof-of-concept attack at Black Hat USA 2026 demonstrating command-and-control (C2) style access to ChatGPT's secure sandbox environment. The exploit chain raises significant concerns about the security isolation of AI systems that enterprises increasingly rely upon for business operations.
AIFrom Bobmojis to Bobbleheads: How the Democratic Party Built a Security-First Culture
Former Democratic National Committee chief security officers discuss how building a security-first organizational culture requires strong executive-level support and creative engagement strategies. The approach combines serious security initiatives with unconventional methods, including humor and absurdity, to drive adoption and awareness across the organization.
AILatest GitHub outage squeezes Actions, Pages to death
GitHub experienced another major outage affecting its Actions automation platform and Pages hosting service, with workflow runs failing and API errors reported. This incident marks the latest in a troubling pattern of reliability issues, with over 75 incidents logged across April through July 2024. Despite Microsoft-owned GitHub's April apology and June promises of structural improvements to addre
AIHumans in the loop miss a third of dangerous AI coding agent requests
A browser-based game testing human oversight of AI coding agents reveals that users approve approximately one-third of malicious requests, highlighting significant security risks in human-in-the-loop systems. The research, based on over 40,000 game runs, demonstrates that approval fatigue leads to sloppy decision-making, with users approving 93% of permission prompts in real-world scenarios. Exper
AIAI Browsers Vulnerable to 'PleaseFix' Zero-Click Agent Hijacking
AI-powered browsers face a critical security vulnerability dubbed 'PleaseFix' that allows attackers to hijack AI agents through zero-click exploits using malicious instructions embedded in web content. The attack vector leverages hidden commands in content that AI browsers process, enabling unauthorized control of autonomous agents. No straightforward remediation currently exists for this emerging
AIAI Sends Global Crime Syndicates Into Fraud Nirvana
Organized crime syndicates are leveraging AI technologies including voice cloning, deepfake video, and LLM-driven automation to execute sophisticated fraud operations at unprecedented scale, generating billions in illicit revenue. These advanced capabilities enable criminals to impersonate individuals convincingly, manage multiple fraudulent personas simultaneously, and operate across language bar
AI15 TP-Link Bugs Expose Risks in Zero-Trust Provisioning
Security researchers have identified 15 vulnerabilities in TP-Link devices that highlight significant security risks associated with automated zero-trust network provisioning processes. The findings use TP-Link, a major network device manufacturer, as a case study to demonstrate broader industry concerns about automated device onboarding and configuration.
AICSS: The Hidden Threat Lurking in Your Inbox
Security researchers have identified CSS as an emerging threat vector for data exfiltration in webmail environments, moving beyond its traditional design-focused role. The vulnerability exploits CSS capabilities to extract sensitive information from email clients, with some vendors lacking adequate protections against these attacks.
AIFlaws in Google APK for Python Unlock Agent-to-Agent Attack
Google has patched security vulnerabilities in its APK for Python that enabled agent-to-agent attacks by exploiting trust boundaries between AI agents operating at different privilege levels. The flaws posed supply chain security risks by allowing unauthorized automation to be triggered across agent privilege boundaries.
AIAngola's Largest Telco Breached Hours Before IPO
Unitel, Angola's largest mobile operator, suffered a cyberattack that disrupted services on the same day as its initial public offering. The government-owned telecommunications provider is still working to restore full operations following the breach, which represents a significant security and reputational incident during a critical business milestone.
AISmoke#Screen RMM Takeover Gambit Exposes Threat Actor Playbook
Threat actors are leveraging social engineering tactics and variable payloads to deploy ScreenConnect remote monitoring and management (RMM) software for unauthorized persistent access to enterprise networks. The campaign, dubbed Smoke#Screen, demonstrates how legitimate IT administration tools are being weaponized to establish footholds in compromised environments. This attack pattern reveals evo
AIAI Notetaker Lets Hackers Spy on Government, Corporate Video Calls
A security vulnerability in tl;dv, an AI-powered meeting notetaker, stemmed from a Google Firebase misconfiguration that exposed sensitive meeting data. The flaw allowed unauthorized users to query other users' meeting information and potentially gain access to ongoing video calls, posing significant risks to government and corporate communications.
AIUK mulls making employers ask before installing bossware
The UK government is consulting on new regulations that would require employers to consult workers before deploying workplace monitoring technologies, including AI-powered productivity tools, keystroke logging, and biometric surveillance. The proposed rules, part of broader labor reforms, could range from non-statutory guidance to mandatory consultation with trade unions, as workplace surveillance
AIDevice Code Phishing Up 1,500% in 2026; Vishing Doubles
Social engineering attacks are experiencing dramatic growth, with device code phishing surging 1,500% in 2026 and vishing incidents doubling. These evolving attack techniques enable threat actors to circumvent established security controls while minimizing their digital footprint, presenting significant challenges for enterprise security teams.
AIAttackers Exploit N-able Patch Bypass Flaw on RMM Servers
N-able has discovered a new authentication bypass vulnerability (CVE-2026-18577) in its Remote Monitoring and Management (RMM) servers that allows attackers to gain administrator-level access. The flaw represents another attack vector that bypasses existing patch protections, posing significant security risks to managed service providers and their enterprise clients.
AIAnthropic: AI Attacks Result of Security Gaps, Not Model Issues
Anthropic has clarified that recent security incidents involving its Claude AI model breaching real-world systems were caused by excessive permissions rather than fundamental flaws in the model itself. The primary vulnerability stemmed from over-permissioning, particularly granting unrestricted Internet access to the AI system.
AINew Tool Traces AI Videos Back to Their Source
Researchers have developed a new tool designed to trace AI-generated videos back to their original source, addressing growing concerns about synthetic media authenticity. The initiative aims to foster industry-wide collaboration on developing stronger protective measures against deepfakes and AI-generated content misuse.
AIChinese Actor Weaponizes DeepSeek AI Agent to Attack Security Firm
Security researchers discovered a Chinese threat actor weaponizing DeepSeek AI to conduct automated attacks against over 1,200 hosts. The AI agent was being used for proxyjacking operations, establishing compromised systems as proxies to launch subsequent attacks while obscuring the attacker's origin.
