Field notes from the edge.
What our engineers learned this week. Hands-on technical deep-dives, postmortems, and strategy frameworks.
AIResearcher Claims Control of ChatGPT Secure Sandbox
A security researcher presented a proof-of-concept attack at Black Hat USA 2026 demonstrating command-and-control (C2) style access to ChatGPT's secure sandbox environment. The exploit chain raises significant concerns about the security isolation of AI systems that enterprises increasingly rely upon for business operations.
AIFrom Bobmojis to Bobbleheads: How the Democratic Party Built a Security-First Culture
Former Democratic National Committee chief security officers discuss how building a security-first organizational culture requires strong executive-level support and creative engagement strategies. The approach combines serious security initiatives with unconventional methods, including humor and absurdity, to drive adoption and awareness across the organization.
AIAI Browsers Vulnerable to 'PleaseFix' Zero-Click Agent Hijacking
AI-powered browsers face a critical security vulnerability dubbed 'PleaseFix' that allows attackers to hijack AI agents through zero-click exploits using malicious instructions embedded in web content. The attack vector leverages hidden commands in content that AI browsers process, enabling unauthorized control of autonomous agents. No straightforward remediation currently exists for this emerging
AIAI Sends Global Crime Syndicates Into Fraud Nirvana
Organized crime syndicates are leveraging AI technologies including voice cloning, deepfake video, and LLM-driven automation to execute sophisticated fraud operations at unprecedented scale, generating billions in illicit revenue. These advanced capabilities enable criminals to impersonate individuals convincingly, manage multiple fraudulent personas simultaneously, and operate across language bar
AI15 TP-Link Bugs Expose Risks in Zero-Trust Provisioning
Security researchers have identified 15 vulnerabilities in TP-Link devices that highlight significant security risks associated with automated zero-trust network provisioning processes. The findings use TP-Link, a major network device manufacturer, as a case study to demonstrate broader industry concerns about automated device onboarding and configuration.
AICSS: The Hidden Threat Lurking in Your Inbox
Security researchers have identified CSS as an emerging threat vector for data exfiltration in webmail environments, moving beyond its traditional design-focused role. The vulnerability exploits CSS capabilities to extract sensitive information from email clients, with some vendors lacking adequate protections against these attacks.
AIFlaws in Google APK for Python Unlock Agent-to-Agent Attack
Google has patched security vulnerabilities in its APK for Python that enabled agent-to-agent attacks by exploiting trust boundaries between AI agents operating at different privilege levels. The flaws posed supply chain security risks by allowing unauthorized automation to be triggered across agent privilege boundaries.
AIAngola's Largest Telco Breached Hours Before IPO
Unitel, Angola's largest mobile operator, suffered a cyberattack that disrupted services on the same day as its initial public offering. The government-owned telecommunications provider is still working to restore full operations following the breach, which represents a significant security and reputational incident during a critical business milestone.
AISmoke#Screen RMM Takeover Gambit Exposes Threat Actor Playbook
Threat actors are leveraging social engineering tactics and variable payloads to deploy ScreenConnect remote monitoring and management (RMM) software for unauthorized persistent access to enterprise networks. The campaign, dubbed Smoke#Screen, demonstrates how legitimate IT administration tools are being weaponized to establish footholds in compromised environments. This attack pattern reveals evo
AIAI Notetaker Lets Hackers Spy on Government, Corporate Video Calls
A security vulnerability in tl;dv, an AI-powered meeting notetaker, stemmed from a Google Firebase misconfiguration that exposed sensitive meeting data. The flaw allowed unauthorized users to query other users' meeting information and potentially gain access to ongoing video calls, posing significant risks to government and corporate communications.
AIDevice Code Phishing Up 1,500% in 2026; Vishing Doubles
Social engineering attacks are experiencing dramatic growth, with device code phishing surging 1,500% in 2026 and vishing incidents doubling. These evolving attack techniques enable threat actors to circumvent established security controls while minimizing their digital footprint, presenting significant challenges for enterprise security teams.
AIAttackers Exploit N-able Patch Bypass Flaw on RMM Servers
N-able has discovered a new authentication bypass vulnerability (CVE-2026-18577) in its Remote Monitoring and Management (RMM) servers that allows attackers to gain administrator-level access. The flaw represents another attack vector that bypasses existing patch protections, posing significant security risks to managed service providers and their enterprise clients.
AIAnthropic: AI Attacks Result of Security Gaps, Not Model Issues
Anthropic has clarified that recent security incidents involving its Claude AI model breaching real-world systems were caused by excessive permissions rather than fundamental flaws in the model itself. The primary vulnerability stemmed from over-permissioning, particularly granting unrestricted Internet access to the AI system.
AINew Tool Traces AI Videos Back to Their Source
Researchers have developed a new tool designed to trace AI-generated videos back to their original source, addressing growing concerns about synthetic media authenticity. The initiative aims to foster industry-wide collaboration on developing stronger protective measures against deepfakes and AI-generated content misuse.
AIChinese Actor Weaponizes DeepSeek AI Agent to Attack Security Firm
Security researchers discovered a Chinese threat actor weaponizing DeepSeek AI to conduct automated attacks against over 1,200 hosts. The AI agent was being used for proxyjacking operations, establishing compromised systems as proxies to launch subsequent attacks while obscuring the attacker's origin.
AIIs There Really a Fix for CISO Fatigue?
Chief Information Security Officers (CISOs) are experiencing significant burnout due to being held accountable for security outcomes without having sufficient organizational authority to implement necessary changes. This structural imbalance is creating unsustainable working conditions for security leaders and requires organizational intervention to address the root causes of CISO fatigue.
AICISA Issues Fresh SBOM Guidance. Did They Get It Right?
CISA has released updated guidance on Software Bill of Materials (SBOM) that introduces approximately two dozen changes to SBOM fields aimed at improving comprehensiveness. However, critics contend that while the updates enhance data collection, they fall short of delivering meaningful improvements to risk management capabilities.
AIInterpol Leverages Global System to Curtail Fraud Payments
Interpol is utilizing its global network and systems to intercept and prevent fraudulent payment transactions before cybercriminals can complete cash-out operations. The initiative emphasizes the critical time-sensitive nature of law enforcement response to financial fraud, requiring rapid coordination across international jurisdictions to freeze illicit payments.
AIThe Morning After We Pull a Root of Trust, Nobody Owns It
Security teams must prioritize creating comprehensive inventories of certificates and cryptographic keys as a foundational security practice. This inventory becomes critical when organizations need to rotate or revoke root certificates, as lack of visibility into certificate ownership and deployment can create significant operational and security risks.
