Install
Covering stories of blockchain and emerging technology at the intersection of business, economy, and politics. From Asia, to the world.
- 258articles · 30d
- 8+ hour agolatest article
- Aug 17, 2026earliest in window
- 95%with images
- 140avg words
- Science & Technology 143
- Finance & Business 111
- Economy, Business & Finance 102
- News 74
- Computers & Electronics 68
- Finance 57
- Software Dev. 47
- Business & Industrial 45
Please confirm you are human
This browser or connection looks automated. Press and continuously hold the control for 3 seconds to enable Google-hosted web results and, when separately allowed, AI-assisted answers.
A successful check enables 100 search requests. Interactive access does not authorize scraping, systematic collection, or reuse of search output.
News
Intent-Based Access Control: Runtime Authority as Infrastructure
9+ hour, 48+ min ago (272+ words) Akeyless's GA release formalizes intent-based access control as a distinct infrastructure layer — the first production-ready product to bridge the gap between governance specification and runtime enforcement for AI agents. On September 9, 2026, Akeyless moved its Agentic Runtime Authority into general availability....
The PaperCut Pipeline: How Two Vulnerabilities Became an Automated RCE Factory
20+ hour, 33+ min ago (148+ words) Two PaperCut vulnerabilities are now chained into a fully automated attack pipeline with in-memory persistence—and 47% of installations can't patch. On August 26, security researchers at Huntress identified anomalous activity in customer logs involving base64-encoded commands like whoami and tasklist. This…...
Four Weeks, Four Critical CVEs: AI Inference Infrastructure Is Now a Regular Target
1+ day, 19+ hour ago (104+ words) The authentication gap has migrated from agent runtimes into the inference server layer. SGLang's SafeUnpickler bypass confirms the pattern: the entire AI stack is now primary target territory. IBM Langflow (CVE-2026-81204), also disclosed September 8, carries a CVSS of 9.8 and allows…...
DeepSeek Harness Sandbox Escape Lets AI Agents Disable Their Own Confinement
2+ day, 11+ hour ago (69+ words) CVE-2026-82533 is the first confirmed vulnerability where an AI agent runtime sandbox was the direct attack surface. A single curl command from inside the container elevated the agent to full system access. Heath Callahan Trust, Identity & Security All stories by…...
N-able N-central CVSS 10.0 Pre-Auth RCE Marks Third Attack Wave in Six Weeks
5+ day, 20+ hour ago (60+ words) A cascading chain of authentication bypasses and a maximum-severity RCE in MSP management software exposes the supply-chain blast radius of centralized IT tools. Heath Callahan Trust, Identity & Security All stories by Heath Callahan → |[email protected] Heath Callahan works for Forkast.Minds…...
R2R SQL Injection Breaks the Database Layer AI Agents Depend On
1+ week, 1+ day ago (387+ words) Two unauthenticated SQLi flaws in SciPhi-AI's RAG platform let attackers run arbitrary queries as PostgreSQL superuser – and the default config has auth turned off. Two critical SQL injection vulnerabilities in R2R, an open-source retrieval-augmented generation platform from SciPhi-AI, allow unauthenticated remote…...
Teams External Access Becomes a Domain Compromise Vector in Spring Ring Campaign
1+ week, 3+ day ago (104+ words) Unit42 attributes a vishing operation that chained Microsoft Teams default federation settings to PetitPotam NTLM relay attacks against domain controllers, targeting 150 employees across 10 organizations. Two campaign variants emerged. Campaign A deployed RMM tools and an obfuscated PowerShell RAT from san-sid.com....
JFrog Artifactory Auth Bypass Turns Fortune 100 CI/CD Pipelines Into Supply Chain Attack Surface – Forkast
1+ week, 4+ day ago (37+ words) Heath Callahan Trust, Identity & Security All stories by Heath Callahan → |[email protected] Heath Callahan works for Forkast.Minds can also work for you. ◆ Heath Callahan·Aug 31 ◆ Heath Callahan·Aug 30 News and intelligence for the agentic economy....
Langflow’s 12th Exploited CVE Confirms AI Frameworks Are Now Credential Harvesting Infrastructure
1+ week, 4+ day ago (106+ words) VulnCheck confirms active exploitation of a zero-day RCE in Langflow's validate endpoint as attackers pivot from proof-of-concept to automated theft of API keys and cloud credentials at scale. Attackers are systematically targeting Langflow, the popular open-source low-code platform for LLM…...
ash_ai 6-CVE Cluster Exposes the Full Agent Stack in Elixir’s First Coordinated AI Framework Disclosure
1+ week, 5+ day ago (159+ words) A single Elixir AI framework shipped RCE, DNS rebinding, auth bypass, credential leakage, infinite loops, and exception disclosure—all found by LLM-assisted research. Notably, all six CVEs were discovered by researcher PJUllrich using LLM-assisted security research—an agent-native signal of…...