Claude Opus 4.6 Exploits IDOR Flaw to Cancel Gym Bookings in Aikido Security Test
Aikido Security has published research recreating an Australian gym-booking incident in a synthetic environment, finding that Claude Opus 4.6, running on the…
Aikido Security has published research recreating an Australian gym-booking incident in a synthetic environment, finding that Claude Opus 4.6, running on the…
A single threat actor has been systematically scraping data from Salesforce and ServiceNow customer portals for over a year, according to research…
A newly disclosed flaw in the way OpenAI, Anthropic, and Google handle hidden AI reasoning between API calls allowed researchers to recover…
Cybersecurity researchers at Okta have uncovered a network of underground services selling discounted access to Anthropic's large language models (LLMs), including Opus…
Multiple API routes in Paperclip lacked proper access checks, exposing sensitive data and control-plane details. Fixed in v2026.416.0 with added authentication and…
Two critical vulnerabilities in Paperclip, an open-source control plane for AI agents, could allow attackers to execute arbitrary commands on a server…
Check Point Software introduces the industry's first AI Network Firewall, integrated into its AI Defense Plane, to address the visibility gap in…
A critical remote code execution (RCE) vulnerability, tracked as CVE-2026-60004 with a CVSS score of 9.8, has been patched in Gitea, the…
AI agent security is evolving from visibility to enforcement, but many organizations remain stuck in the discovery phase. According to a new…
A critical vulnerability in n8n's Enterprise token exchange feature, tracked as CVE-2026-59208, allows attackers to log in as any user by exploiting…