Threat modelling stories
AI tools are speeding routine checks, but hidden business logic flaws and context-specific risks still need human testers to spot them.
Security teams may get findings within 24 hours as Cobalt targets faster testing across sprawling software estates.
Buyers of AI tools now have a benchmark to judge testing providers, as CREST's new standard targets gaps in assurance and due diligence.
Rising disclosure volumes are forcing security teams to predict which flaws attackers will exploit as FIRST broadens its vulnerability conference in Luxembourg.
As attackers use AI to speed up phishing and malware, companies are being told that multi-factor authentication and patching matter more than ever.
Patching is urgent for Cudy WR3000 rev 2.0 routers, as public code shows how two flaws can let attackers gain root command execution.
The new tool aims to catch Bitcoin software flaws between formal audits after a regression led to more than USD $116 million stolen.
Researchers can claim up to USD $1 million for breaking Vercel Sandbox's isolation, as the cloud provider opens its boundary to public scrutiny.
In two days, the system uncovered more than 100 critical bugs in stolen code repositories, outpacing manual review and aiding incident response.
Unauthorised access could let attackers send arbitrary commands to spacecraft and instruments via NASA's AIT-GUI console, now fixed in version 2.5.2.
Verified access to Anthropic's Claude models should sharpen ArmorCode's exploitability scoring as security teams race to cut alert noise.
Misconfigured test setups let three Claude models touch live systems, exposing production data and credentials during security exercises.
Nearly half of scanned MCP server builds carried at least one security concern, underscoring fresh supply chain risks as AI agents rely on them.
The move could reshape enterprise AI security as vendors and regulators demand stronger controls around access, logging and containment.
Cloud audits produced the highest critical finding rate, while every AI system tested showed vulnerabilities and web logic flaws rose sharply.
New EU cyber rules are pushing software vendors to prove security is built into products, not bolted on after release.
Security experts warn the breach shows autonomous AI can exploit old misconfigurations at machine speed, widening enterprise identity and containment risks.
Cybersecurity experts warn single-person approvals are now vulnerable after an AI agent used fabricated identities to slip malicious code past checks.
The findings heighten concern that frontier AI agents can breach boundaries, pressure real people and target software supply chains under loose controls.
Security chiefs face a widening breach risk as most firms plan to use AI agents, yet barely a third feel ready to secure them properly.