AI Security
-
Mass vulnerability scans spoofing ClaudeBot / GPTBot are hunting for your .claude.json
Somebody figured out that the fastest way past a robots allowlist is to just say you’re an AI crawler. Known Agents’ Agentic Web Index is now tracking an active campaign doing exactly that: fake Googlebot traffic at 0.5% of all requests, with ChatGPT-User, GPTBot, OAI-SearchBot and PerplexityBot each around 0.1%. What they’re actually looking for… Continue reading
-
OpenAI GPT-5.6-Cyber + Daybreak Blue / Daybreak Red: 95% vs 1.5% on advanced security requests
95% versus 1.5%. That’s the completion rate on advanced cybersecurity prompts for OpenAI’s new GPT-5.6-Cyber against standard GPT-5.6 Sol. Daybreak Blue sits at 2%. OpenAI didn’t tune the guardrails on August 10 — it took them off for one audience. Two doors instead of one Daybreak, previously a single vetted-access program, now splits. Blue is… Continue reading
-
Uber ADR goes open source: 10 months in production, 97.2% precision on credential leaks
Uber just open-sourced ADR, the security system that has been watching its internal AI agents for 10 months. The scale is real: 50,000+ agent sessions a day across 7,200+ hosts — Claude Code, Cursor, Codex, plus customer-facing agents. ADR caught hundreds of credential leaks at 97.2% precision. The release: a runtime Sensor that normalizes agent… Continue reading
-
Microsoft Project Perception: three AI vendors, one router, aimed straight at Anthropic Mythos
Microsoft’s new AI security product, codenamed Project Perception, ships as soon as this month. It’s not a chatbot or an API — it’s a platform that sits inside enterprise IT systems, scans for software vulnerabilities, and fixes them automatically. The exact job Anthropic built Mythos for. The router is the product Perception isn’t a new… Continue reading
-
Capital One open-sources VulnHunter, a security agent that hacks your code before it flags it
A bank shipping an offensive-security tool under Apache 2.0 is not what anyone expected. But VulnHunter (Capital One) is exactly that: an agentic AI tool that reads your source code the way an attacker would, not the way a linter does. What it actually is Not another SAST scanner spraying pattern-matches at you. VulnHunter starts… Continue reading
-
Squidbleed:Claude Mythos 挖出潜伏 29 年的 Squid 漏洞
Security firm Calif.io pointed Claude Mythos Preview, running multi-agent analysis, at Squid proxy’s FTP parsing code. The model flagged a heap over-read almost immediately. The bug dates to a January 1997 commit — older than Squid’s own GitHub history. Human code review missed it for 29 years. It’s now CVE-2026-47729, aka Squidbleed. One line of… Continue reading
-
Astra Autonomous Pentest Sends AI-Found Fixes Straight Into Your IDE
Penetration testing has always been slow, manual, and expensive. Astra’s new Autonomous Pentest turns it into a pipeline of AI agents, built on insights from more than 5,000 real-world pentests, that own the full cycle — from finding a bug to handing a developer the fix. ## How Astra Autonomous Pentest works Discovery agents hunt… Continue reading
-
Google: First AI-Generated Zero-Day Exploit Caught in the Wild
The “AI will write malware someday” debate is over. On May 11, Google’s Threat Intelligence Group confirmed the first documented case of criminals using an LLM to find AND weaponize a working zero-day — a 2FA bypass in a widely-used open-source web admin platform. Not a research demo. A live attack, aimed at mass exploitation.… Continue reading
