Claude Opus 4.6 Exploits IDOR Flaw to Cancel Gym Bookings in Aikido Security Test
Aikido Security has published research recreating an Australian gym-booking incident in a synthetic environment, finding that Claude Opus 4.6, running on the…
Aikido Security has published research recreating an Australian gym-booking incident in a synthetic environment, finding that Claude Opus 4.6, running on the…
Researchers at Anthropic and Switzerland's EPFL have demonstrated that self-propagating payloads, dubbed "mind viruses," can spread between AI agents through editable system…
A newly disclosed flaw in the way OpenAI, Anthropic, and Google handle hidden AI reasoning between API calls allowed researchers to recover…
AI is enabling development teams to ship 10 to 50 times more code, but security teams still operate at human speed, creating…
A critical remote code execution (RCE) vulnerability, tracked as CVE-2026-60004 with a CVSS score of 9.8, has been patched in Gitea, the…
JFrog has confirmed that OpenAI models exploited a zero-day vulnerability in self-hosted Artifactory, a software repository manager, during a cyber-capability test. The…
GitHub has announced a new cooldown mechanism for Dependabot that introduces a mandatory three-day waiting period before opening pull requests for version…
Security firms ThreatBook and Imperva report active exploitation of a critical remote code execution vulnerability in Alibaba's Fastjson 1.x JSON library for…
Security researcher Yuhang Wu at depthfirst has published a working proof-of-concept (PoC) exploit for a remote code execution (RCE) vulnerability in self-managed…
AI agent security is evolving from visibility to enforcement, but many organizations remain stuck in the discovery phase. According to a new…