Dispatches. Practitioner-first cybersecurity coverage.
Independent reporting on AI security, SOC automation, identity, data and the adversarial edge. Every piece is rewritten in-house and credits every source — never a press-release copy.
Archive
Page 2 of 6-
There Is No 'Security Meter' for AI — Schneier Makes the Case for Assurance
In a recent essay, Bruce Schneier argues that benchmarks cannot tell you whether an AI system is secure, because they miss the emergent, systemic behavior that actually matters. His prescription borrows from three decades of software security: build mature assurance processes instead of chasing a single score.
-
ShinyHunters Turn an Unpatched PeopleSoft Flaw Into a University Data Heist
A pre-authentication remote code execution bug in Oracle PeopleSoft, CVE-2026-35273, was exploited as a zero-day for two weeks before a patch existed. The extortion crew Mandiant tracks as UNC6240 used it to breach universities, with one UK institution losing the records of roughly 455,000 people.
-
Google Discloses First Confirmed AI-Authored Zero-Day, a 2FA Bypass Used for Mass Exploitation
Google's threat intel team says an unknown actor used a large language model to find and weaponise a zero-day 2FA bypass in a web admin tool. The Python exploit shipped with hallucinated CVSS scores and educational docstrings — the smoking gun that an LLM, not a human, wrote it.
-
On-Prem Exchange Hit: CVE-2026-42897 Lets a Crafted Email Run Code in OWA
Microsoft confirms active exploitation of an XSS spoofing flaw in on-prem Exchange Server. A crafted email opened in Outlook Web Access is enough to execute attacker-supplied JavaScript in the victim's browser context, and CISA has set a federal KEV deadline for May 29.
-
UK AI Security Institute Finds GPT-5.5 Matches Claude Mythos at Vulnerability Discovery
A new evaluation from the UK's AI Security Institute concludes that OpenAI's generally-available GPT-5.5 performs on par with Anthropic's restricted Claude Mythos at finding software vulnerabilities — and that a smaller model with the right prompting scaffolding gets close enough to matter.
-
An 18-Year-Old NGINX Bug Reopens One of the Internet's Most-Reached Code Paths
A heap buffer overflow in NGINX's rewrite module, undisclosed since 2008, can be triggered by a single crafted HTTP request and reaches unauthenticated RCE on hosts running with ASLR disabled. F5 has shipped patches for Open Source, Plus, and every derivative.
-
Cisco SD-WAN Controllers Hit by 10.0 Auth Bypass — Active Exploitation Confirmed
A maximum-severity authentication bypass in Cisco Catalyst SD-WAN Controller (CVE-2026-20182, CVSS 10.0) lets unauthenticated attackers gain administrative control over the SD-WAN fabric via UDP 12346. Cisco has confirmed limited in-the-wild exploitation; the vulnerable component has now produced two 10.0-rated bypasses in three years.
-
OpenAI's Daybreak Hands Defenders a Frontier Vulnerability Model
OpenAI launched Daybreak, a defensive cyber initiative pairing three GPT-5.5 variants with Codex Security to give vendors access to AI vulnerability discovery, threat modeling, and patch validation. The release confirms that frontier labs now treat vuln-finding capability as gated infrastructure rather than a public product.
-
Anthropic's Mythos and the Asymmetry Problem in AI Vulnerability Discovery
Anthropic held back its Claude Mythos Preview from public release because it finds software vulnerabilities at a rate defenders cannot match in their patch cycles. Bruce Schneier argues the deeper concern isn't software at all — it's every other rule-based system AI can now mine for exploits.