Weeks apart, at two unrelated companies, Escape's AI pentesting agent found the same stored XSS. Both had shipped a ...
Key Takeaways SOC 2 does not explicitly name penetration testing as mandatory, but auditors expect one in practice for any company handling sensitive data at scale. HIPAA does not name penetration ...
The AI Security Institute has a new report of AI systems engaging in “unsanctioned behavior”—what I have been calling “genie behavior—while being tested on their cybersecurity capabilities. The ...
Aug 21, 2026 - Jeremy Snyder - If you were at RSA Conference last year, you probably remember the goats. Or the puppies. Or the miniature petting zoos. It was a year of "over-the-top" spectacle. A bit ...
Flashpoint’s monthly analysis of insider threat recruitment, illicit access advertising, and threat actor activity targeting ...
ChainDrop hijacked 444 npm packages and 2B monthly downloads via a Claude Code hook. AI agents have collapsed the gap between ...
Meet Satyam Gupta. Satyam is a Software Engineer at Swimlane who spends most of his day building backend services, chasing ...
After announcing our channel partner program last month, we are excited to now be working with eleven incredible partners, ...
WebAuthn Level 3 was proposed for W3C Recommendation in July 2026. Encryption key derivation, cross-domain credentials, and automatic list syncing are now first-class. Here is what changed.
OpenAI announced Wednesday that it is testing a new security protocol designed to protect enterprise privacy without ...
Frontier AI’s ability to find vast numbers of previously unknown vulnerabilities has created a timing problem for defenders.
Generative AI has eliminated typos in phishing. Discover how attackers weaponize LLMs for perfect tone matching, and how ...