Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

AgentForger Showed Why Securing AI Agents Takes More Than a Patch

• Zenity secures ChatGPT Workspace Agents across their full lifecycle, from posture management at build time to detection and response at runtime. • AgentForger showed how a single link could forge an autonomous AI agent that inherits a real employee's identity and access, a risk legacy security tools can't see. • Zenity's AISPM catches the misconfigurations these attacks rely on, such as agents that auto-approve sensitive actions or connect to privileged systems.

Global Teams, Local Languages: Closing the Multilingual Privacy Gap

A privacy policy that only works in English is not a global privacy policy. It is an English-language policy that a global company happens to be using. That distinction matters more than most teams realize. Enterprises now centralize contracts, HR files, healthcare records, and support conversations from regional offices around the world into a shared AI platform, often assuming that whatever detection and masking logic works for their English-language content will work everywhere else. It does not.

Membership Inference Attacks in AI: How They Expose Training Data?

AI models are becoming essential to enterprise innovation, but the sensitive data that powers them is creating new security and privacy challenges. Even when raw training datasets remain inaccessible, attackers may still identify whether specific information was used to train a model through membership inference attacks.

Better generic secrets detection starts with finding non-secrets

This article was co-written by Zach Rice and Joe Leon, both at Aikido Security. tl;dr Some credentials are meant to be public, but secret scanners still flag them as generic secrets. We wrote suppression rules for the most common ones and reduced false positives by ~2%. These rules now ship by default in Betterleaks. Secrets scanners are built on regular expressions. Each pattern targets a specific credential type, like an AWS secret access key, a GitHub PAT, or a Stripe token.

AI Chat: The Hugging Face / OpenAI breach - the attacker was the model [340]

AI Chat with Maxime Lamothe-Brassard and Chris Luft — a special episode. One story, pulled apart start to finish. In mid-July 2026, Hugging Face disclosed a breach of its production infrastructure carried out end-to-end by an autonomous AI agent. Five days later, OpenAI revealed the attacker was its own models — GPT-5.6 Sol and a more capable unreleased model — which broke out of an internal cyber-capability evaluation called ExploitGym and reached into Hugging Face's production systems to steal the benchmark's answer key.

Is this the end of human-written code?

Last week an OpenAI model escaped its evaluation sandbox and hacked Hugging Face's infrastructure to cheat on a security benchmark. We recorded a special episode of AI Chat about it. Maxime Lamothe-Brassard's take is worth sitting with: we may be entering a phase where developers get locked out of writing code, not because AI writes it better, but because AI has gotten so good at finding vulnerabilities that insurers stop accepting the risk of human handcrafted code.

How UAE Banks Go Live on Stablecoins | Fireblocks x MFTA

Stablecoins moved $33 trillion globally last year, and the UAE is right at the center. Fireblocks' John Hallahan on how banks get from pilot to production. John Hallahan, Head of Business Solutions & Advisory at Fireblocks, joins Raghda Ibraheem to unpack the UAE Stablecoin Payments Playbook from MFTA and Fireblocks, a practical roadmap for banks and payment companies moving from proof of concept to large-scale production.

Introducing your compliance co-founder

Accelerating security solutions for small businesses‍ Tagore offers strategic services to small businesses. A partnership that can scale‍ Tagore prioritized finding a managed compliance partner with an established product, dedicated support team, and rapid release rate. Standing out from competitors‍ Tagore's partnership with Vanta enhances its strategic focus and deepens client value, creating differentiation in a competitive market. AI has completely changed how startups build.

When the Attacker Is the AI: What the OpenAI Sandbox Escape Means for Threat Intelligence Teams

An OpenAI agent broke out of its test sandbox and autonomously breached Hugging Face with no human direction, an incident both companies called unprecedented. CYJAX examines why this doesn't fit existing threat actor categories, maps it to the standard attack lifecycle, and outlines three additions CTI teams should make to their collection plans and PIRs to track autonomous offensive tooling before it hits their own network. On 16th July 2026, Hugging Face disclosed that it had been breached.

Bitsight's Ratings Algorithm Update for 2026 Makes Risk Vectors More Impactful

Bitsight's annual Ratings Algorithm Update (RAU) has been in effect as of July 16, 2026. In preparation, RAU 2026 Preview was made available in April 2026. As in the past, RAU 2026 is an effort to account for the continuous evolution of the threat landscape the Bitsight security ratings seek to quantify. This year's update is focused on modernizing the rating by improving how it is composed from various risk vectors (RVs). In particular, this entails the following.