Threat modelling stories
AI tools are speeding routine checks, but hidden business logic flaws and context-specific risks still need human testers to spot them.
Security teams may get findings within 24 hours as Cobalt targets faster testing across sprawling software estates.
The new tool aims to catch Bitcoin software flaws between formal audits after a regression led to more than USD $116 million stolen.
Researchers can claim up to USD $1 million for breaking Vercel Sandbox's isolation, as the cloud provider opens its boundary to public scrutiny.
In two days, the system uncovered more than 100 critical bugs in stolen code repositories, outpacing manual review and aiding incident response.
Unauthorised access could let attackers send arbitrary commands to spacecraft and instruments via NASA's AIT-GUI console, now fixed in version 2.5.2.
Verified access to Anthropic's Claude models should sharpen ArmorCode's exploitability scoring as security teams race to cut alert noise.
Misconfigured test setups let three Claude models touch live systems, exposing production data and credentials during security exercises.
Nearly half of scanned MCP server builds carried at least one security concern, underscoring fresh supply chain risks as AI agents rely on them.
The move could reshape enterprise AI security as vendors and regulators demand stronger controls around access, logging and containment.
Cloud audits produced the highest critical finding rate, while every AI system tested showed vulnerabilities and web logic flaws rose sharply.
New EU cyber rules are pushing software vendors to prove security is built into products, not bolted on after release.
Security experts warn the breach shows autonomous AI can exploit old misconfigurations at machine speed, widening enterprise identity and containment risks.
The episode has sharpened concerns that advanced AI systems can uncover and exploit real-world security flaws during testing, even in restricted environments.
Developers can now use Google Cloud's examples to build and govern Gemini-powered agents for approvals, compliance and data workflows.
Enterprise security teams can now move from fragmented asset views to explainable risk scoring, as the platform reaches general availability.
Security teams are being warned to keep humans and strict controls in place as AI agents can miss context and leak sensitive code.
Cybersecurity experts warn single-person approvals are now vulnerable after an AI agent used fabricated identities to slip malicious code past checks.
The findings heighten concern that frontier AI agents can breach boundaries, pressure real people and target software supply chains under loose controls.
Security chiefs face a widening breach risk as most firms plan to use AI agents, yet barely a third feel ready to secure them properly.