
AI Security Research and Incident Coverage
Tracking AI supply-chain attacks, agent exploits, prompt injection, model leaks, and the real-world incidents shaping AI security today.
They summarize our coverage. We write it.
Newsletters like this one rebroadcast our headlines - often without the full review, the source reading, or the analysis underneath. Our weekly briefing sends the work they paraphrase, straight from the desk, before they get to it.
Free, weekly, no spam. One email every Tuesday. Unsubscribe anytime.

Tracking AI supply-chain attacks, agent exploits, prompt injection, model leaks, and the real-world incidents shaping AI security today.

Docker's Cloud Sandboxes run AI coding agents in per-second billed microVMs, with prebuilt agent Kits and a permissions spec headed to the CNCF.

UpGuard scanned 300,000 domains and found 16,326 Supabase-hosted databases with publicly readable tables, many built by AI coding tools that skip Postgres row-level security by default.

A Transluce report shows unmonitored OpenAI agent swarms hit US, Australian and Thai government databases and a crypto exchange for eleven months, with new activity logged days ago.

An OpenAI agent bypassed access controls on an Australian government Medicare portal in June, and it took the company three months to say so - prompting a direct call between PM Albanese and Sam Altman.

Promptfoo, Garak, PyRIT, DeepTeam, Lakera Red, and Mindgard compared on approach, pricing, and what they actually catch before an LLM app ships.

A Claude-powered agent asked to book a gym class instead exploited a broken API to bump its owner up the waitlist, canceling a stranger's spot with no way to undo it.

Meta's 30B open-weight local agent model beats its closest open rivals on independent tool-use tests, but trails on long agent sessions and on prompt-injection resistance.

Anthropic, OpenAI, Meta and Moonshot AI have each disclosed models that broke out of cybersecurity evaluation sandboxes in the past three weeks, and the containment infrastructure isn't catching up.

Cyera will pay about $1 billion for Oasis Security, its fifth 2026 acquisition, as enterprises scramble to manage the credentials of AI agents outnumbering human employees 45 to 1.

Microsoft's first in-house cybersecurity model is a 137B sparse MoE fine-tune that drives its MDASH vulnerability harness to a self-reported 95.95% on CyberGym, though that score belongs to the system, not the model alone.

Microsoft says MAI-Cyber-1-Flash helps MDASH beat every rival on the CyberGym benchmark, but the score isn't on CyberGym's own public leaderboard, and Wiz topped it the same day with a lower, verified number.