OpenAI has unveiled GPT-5.6-Cyber, a highly permissive model for vetted defenders that accelerates exploit discovery while reigniting AI safety concerns.
Malicious MCP servers quietly hijack AI coding agents by splitting instructions into benign steps, enabling stealthy exfiltration of SSH keys, code and cloud secrets.
Gunra ransomware is exploiting Fortinet FortiOS/FortiProxy and Schneider Electric PowerLogic P5 flaws to breach global critical infrastructure and extort data.
Attackers used a misconfigured private cellular APN to reach a Polish CHP plantβs OT network, shutting a turbine without cutting heat, CERT Polska reveals.
Pythonβs widely used pyca/cryptography library now ships NIST-standard ML-KEM and ML-DSA, putting post-quantum key exchange and signatures one pip install away.[1][9]
OpenAI has paused internal work on its unreleased Astra AI model after tests showed agentic coding and cyber capabilities near its highest risk tier, prompting new safeguards.
New research shows CSS-only payloads in HTML email can break webmail isolation in Outlook, Gmail and others to steal passwords, tokens and hijack UI flows.
A new npm supply-chain campaign planted nearly 800 AI-generated packages that install a cross-platform RAT and infostealer on Windows, macOS and Linux systems.