An issue was discovered in OpenSBI 1.3 allowing attackers to cause a denial of service via crafted request to the SBI function #2 or the 'Find and configure a matching counter' function of SBI PMU ext…
The latest update for #Indusface includes "CVE-2026-56164: Unauthenticated SharePoint Zero-Day Grants Farm Administrator Access" and "CVE-2026-6875: ServiceNow Sandbox Escape Leads to Pre-Auth RCE in #AI Platform".
It’s a science fiction nightmare: What happens if the machines take over?The world got a potential taste of that last week, when OpenAI, the maker of ChatGPT, said two of its models had autonomously hacked into another AI company.OpenAI says its technology carried out the attack during a c..
A new framework for Mixture-of-Experts (MoE) inference, DA-MoE, optimizes GPU dispatch by adapting to routing distributions, achieving up to 1.55x speedups. This innovation enhances language model performance, unlocking efficiency in expert computations.
The latest update for #BitSight includes "The ECB's AI #Cybersecurity Action Plan: Why Speed, Visibility, and Evidence Matter" and "Bitsight's Ratings Algorithm Update for 2026 Makes Risk Vectors More Impactful".
News From A Neighbor@newsfromaneighbor.bsky.social
Not to get into conspiracy thinking or to speak about science fiction dystopian stories, however isn’t that part of what allowed Skynet to destroy humanity. The idea of uncontrollable AI has plagued many minds for decades.
Huntress reports an active credential-stuffing campaign targeting SonicWall VPN and firewall accounts, compromising 30 organizations and 92 users in under two days. No post-compromise activity observed yet. #SonicWall#Huntress#CISA
#BlueVoyant announces its #Microsoft365 E7 readiness bundle, pairing BlueVoyant AI with deployment support for Microsoft Purview and Security Copilot with its recently announced Microsoft Agent 365 Security Deployment Service.
🧠 Microsoft presented its own AI models and tools to investors, positioning itself as a direct competitor to OpenAI and Anthropic. The company outlined plans for sustai…
The latest update for #UpGuard includes "No Hackers Required: 10 Shadow AI Leaks Hiding in Plain Sight" and "Oracle Just Shipped 1,449 Security Patches in One Quarter. We Checked How Much of It Is Actually New.".
The latest update for #Cloudflare includes "Post-quantum authentication to origins is now supported" and "Natural disasters and government interference: examining Q2 2026's major Internet disruption events".
Microsoft pitched its own homegrown AI models, harnesses, and even a Mythos competitor on Wednesday, telling Wall Street it plans for continued growth.
Rust for HPC + GPU Bundle by GitforGits | Asian Publishing House is a new release on Leanpub!
Most developers reach for Python when they need GPU power, but Rust also can deliver the same acceleration with memory safety and zero runtime overhead. … leanpub.com/b/rusthighpe...
Amazon researchers say a North Korea-linked group used tiny typo-crypto as a rehearsal before compromising axios and other open-source packages, using trusted maintainer access and hidden code. #NorthKorea#axios#typo-crypto
Onyx Security, whose platform enables enterprises to deploy AI agents securely, raised a $113M Series B led by Bessemer, taking its total funding to $153M (Meir Orbach/CTech)
Root Evidence puts real-world evidence at the center of vulnerability prioritization
Root Evidence has launched the Evidence Platform, a vulnerability management platform that prioritizes vulnerabilities based on evidence of real-world exploitation and financial impact rather tha… #hackernews#news
The latest update for #WatchGuard includes "#AI Is Driving More Network Inspection. Can Your Security Keep Up?" and "CRN Recognizes Two WatchGuard Executives Among Top 100 Executives of 2026".
The latest update for #AppSentinels includes "MCP Prompt Injection: How Attackers Hijack AI Agent Workflows Through MCP Tool Calls" and "Best #API Discovery Tools for Lineage Mapping".
The latest update for #GitGuardian includes "An #AI Agent Breached Hugging Face. The Attack Playbook Was Older Than the Attacker" and "How to Reduce Time to Revoke for Exposed Credentials".
Russian hackers are exploiting a new Exchange OWA XSS flaw in half-click email attacks, deploying OWAReaper for long-term mailbox access across U.S. and European government and industry targets. #Russia#Exchange#OWAReaper
The latest update for #BlueVoyant includes "Your Vendors Are Rushing Into #AI. Their Attack Surface Is Coming With Them" and "When the Breach Isn't Yours, But the Risk Still Might Be".
OpenAI's CEO says we've reached a point in the AI race that is the stuff of science fiction novels. "We are now, like, in the singularity," Sam Altman www.businessinsider.com/sam-altman-o...
"As Japanese financial newspaper Nikkei Asia found in a recent investigation, just five US tech giants — Alphabet, Microsoft, Amazon, Meta, and Oracle — are hiding an estimated $1.65 trillion in debt that doesn’t appear on balance sheets.
The latest update for #Appknox includes "DORA #Compliance for Mobile Apps: Mapping Security Findings to Regulatory Requirements" and "Best MAST Tools in 2026: Top Mobile Application #SecurityTesting Platforms Compared".
The latest update for #Datadog includes "Engineering the Datadog Agent for FedRAMP High Certification" and "Normalize security logs to Google #SecOps UDM with #Observability Pipelines".
The latest update for #AikidoSecurity includes "Four #incidentresponse decisions from the Hugging Face breach" and "Better generic secrets detection starts with finding non-secrets".
The latest update for #OneIdentity includes "Solving the identity debt crisis with a One Identity platform approach: IGA, PAM and AD" and "Managing Microsoft Teams with One Identity Active Roles".
The latest update for #Acronis includes "Atlanta's $17M Ransomware Attack: What Could Have Stopped It" and "What is data security and how does it work?".
In Q4, Microsoft's Anthropic investment saw a $3.2B gain, while its OpenAI investment was marked down ~$600M but has generated a $5B gain on a full-year basis (Julie Bort/TechCrunch)
Kenny Swann AI Tutor (not political at all)@kennyswann.bsky.social
Lilian Weng left for health reasons.
Then she joined OpenAI.
The talent war is getting weird.
It's not just about the money, it's about where the power is moving.
A vulnerability in Microsoft Copilot allows attackers to embed malicious instructions in Word documents, which can alter document outputs and propagate the worm through normal workflows.
Public Citizen's J.B. Branch makes the case that the OpenAI–Hugging Face incident was "a foreseeable governance failure rooted in private decision-making"—and that voluntary corporate risk management is not enough. Congress must investigate, he says.
OpenAI AI-agent escape attempts, Artifactory zero-days, and Anthropic Mythos findings on AES and post-quantum weaknesses headline today’s recap. Supply-chain RAT drops and exposed BMC IPMI hashes add to the risk. #OpenAI#Artifactory#Anthropic
Healthcare Dive recently reported that hackers breached Craneware, a hospital software vendor used by thousands of healthcare organizations. What stood out to me is how much operational dependency now sits outside the walls of a healthcare organization.
Scam researchers told a Claude agent and human "scammers" to text test subjects and build a relationship. After a week, subjects said they trusted the AI more than the human and almost half were willing to install an app at its request. Almost none detected it was AI. www.wired.com/story/ai-sca...
So it seems likely that the AI exploited human mistakes to get access, just like most hackers do. Published and missing credentials are human errors that hopefully AI will help prevent.
Mr. Evans revealed a game-changing cybersecurity solution that could save the district nearly $40,000 while enhancing security and training for K-12 needs.
Framingham City Posts Bot - UNOFFICIAL!@framingham-bot.bsky.social
Framingham DPW (via Facebook): Due to the weather, the following morning programs are cancelled for today - Thursday, July 30, 2026: - Tennis Clinic (make-up on Friday) - Hitting & Fielding Clinic We apologize for the inconvenience and appreciate your understanding.… [Link]#Framingham
Inside Moscow's elite Bauman University, a secret department trains the GRU's next-gen hackers, saboteurs, and spies. Leaked documents now expose how its graduates feed the units behind Russia's cyberattacks, election interference, and NATO sabotage.
It’s not hard because of high-level coding. It’s hard because of gatekeeping and trying to learn 20 tools at once instead of mastering basic networking.
‘CoreWeave has sweetened terms on a $2.6B leveraged loan to fund additional computing capacity in an effort to win over investors growing wary of AI-related debt as bubble concerns mount. Discussions now involve the loan pricing 5.5% above benchmark.’ www.bloomberg.com/news/article...
Scale AI hires former Google Cloud COO Francis deSouza as CEO, replacing interim CEO Jason Droege, who took over last year after Alexandr Wang left for Meta (Madison Mills/Axios)
Privacy-Preserving Identity Management and Software Bill of Materials Vulnerability Detection: Practical Use Cases from the PRIVIDEMA Project (Mariya Georgieva Belorgey, Benoit Cogliati, Simon Demarty, Lois Huguenin-Dumittan, Özcan Öztürk, Salma Rasti Samiei, Oana Stan) ia.cr/2026/1536
Business Intelligence Briefly@bizintelbriefly.bsky.social
22% of organizations experienced AI-enabled attacks on critical business platforms in the past 12 months, while most leaders lack confidence in detection and AI security.
OpenAI recently showed how tweaking the harness used in a benchmark made GPT Sol 5.6 go from 13.3% to 38.3%. This is a good example of the value of harnesses especially as models commoditize.
Getting 3x the performance from using the right harness will likely beat any difference in models.
If the generative AI giant had followed well-known security best practices, it’s likely that its AI agent would never have escaped to the open internet and hacked multiple companies.
This post shares how my team balanced routing logic across MoEs with load balancing to spread tokens more evenly, with sharding techniques in a compute-constrained environment. It's practical and illustrates fundamental architectural points in MoEs. Check it out! vectorinstitute.ai/mixture-of-e...
Can Cyber Operations Be Deterred? What Wargames Reveal | WOTR
• Gaming Deterrence
• Whither Cyber Deterrence?
• A Cyber Deterrence Paradox
• The Invisible Made Visible warontherocks.com/can-cyber-op...
London-based Inforcer, which helps managed service providers handle their clients' Microsoft 365 accounts, raised a $50M Series C led by Insight Partners (Dominic-Madori Davis/TechCrunch)