Our Blog

Research, analysis, and practical guidance on cybersecurity and AI security from our London team.

AI Security26 September 2026

Coding agents make software engineering harder, says Simon Willison

Simon Willison argues that coding agents raise the bar on discipline and knowledge rather than lowering it. Here is what that means for security teams.

coding-agentsai-securityllm-security
3 min readRead
AI Security25 September 2026

Anthropic's AI Misuse Report: Agents Do the Work, Humans Steer

Anthropic's report on detected Claude misuse describes AI agents handling reconnaissance, exploitation and data theft while humans pick targets and review output. Here is what security teams should take from it.

ai-securitythreat-intelligencellm-misuse
3 min readRead
Cloud Security25 September 2026

Cloudflare Containers Flaw Exposed Other Customers' Leftover Disk Data

A thin-provisioning misconfiguration let one Cloudflare Containers tenant read residual data from disk blocks previously used by other customers. Cloudflare says it has fixed the flaw and found no evidence of exploitation.

cloudflarecontainersmulti-tenancy
3 min readRead
Vulnerability Management24 September 2026

Eight exploited CVEs hit Linux, F5, Check Point, Arista and Zyxel

A single day's CVE roundup lists eight vulnerabilities as confirmed exploited, and most sit in infrastructure that security teams rely on for control and visibility. Here is how to triage them.

cveknown-exploitednetwork-security
3 min readRead
AI & Agent Security24 September 2026

Plugin4Shell: A Zero-Click RCE in Claude Code, Codex, Copilot and Gemini CLI

A SHA-pinning bypass lets a malicious marketplace plugin silently swap in attacker code across four major AI coding agents — with no click required, and no fix yet for two of them.

ai-securitysupply-chain-securityai-coding-agents
4 min readRead
AI Security23 September 2026

Self-Jailbreaking: When Reasoning Training Quietly Breaks LLM Safety

A new paper shows that fine-tuning reasoning models on ordinary math and code tasks can make them talk themselves past their own safety guardrails — no adversarial prompt required.

ai-securityllm-securityai-alignment
4 min readRead
AI & Agent Security23 September 2026

MCP's Real Value Isn't Convenience — It's Access Control

A Hacker News debate asked whether the Model Context Protocol is obsolete now that agents can call APIs directly. For security teams, that's the wrong question — MCP's value was never convenience.

mcpai-agent-securityllm-security
4 min readRead
AI Security22 September 2026

GPT-6 Astra Autonomously Cracked an Unbroken 1941 Enigma Message

Given only a loose goal, OpenAI's GPT-6 Astra picked its own target from an archive of unsolved WWII Enigma traffic, wrote its own cryptanalysis tooling, and broke it — a capability signal AI security teams should take seriously, even though the cipher itself was never the hard part.

ai-securityagentic-aiai-red-teaming
4 min readRead
AI Governance22 September 2026

TypeSafe's Jev: Fast AI Decisions With No Explanation Trail

TypeSafe AI's new "System One" model, Jev, swaps text generation for typed probability scores at sub-second speed. For anyone wiring it into a security or compliance decision, that speed comes from removing the one thing an auditor needs: a reasoning trail.

ai-governancellm-securityiso-42001
4 min readRead
Cloud Security21 September 2026

Cloudflare Python Workers Hit GA: What the WASM Sandbox Means for Security

After two years in preview, Cloudflare's Pyodide-on-WebAssembly runtime for Python is now production-grade — and it quietly reshapes the isolation model and supply-chain surface teams need to think about.

cloud-securitydevsecopssupply-chain
4 min readRead
AI/LLM Security21 September 2026

OWASP's 2026 LLM Top 10 Is Built From Real Breaches, Not Just Opinion

The new OWASP GenAI/LLM Top 10 blends expert consensus with 6,639 documented real-world incidents — and the shift shows agentic AI deployments are already getting breached in production.

owaspllm-securityagentic-ai
4 min readRead
Vulnerabilities & Exploits20 September 2026

Cisco ISE CVE-2026-76460 (CVSS 10) and Email Gateway CVE-2026-76461: Exploited Zero-Days

Cisco has patched two unrelated but actively exploited flaws in appliances that sit on the identity and mail perimeter. Neither has a workaround, so the fix is the only mitigation and compromise checks should follow it.

ciscozero-daycve-2026-76460
3 min readRead
Vulnerabilities & Threat Intel20 September 2026

CISA KEV adds Cisco ISE and Acronis Backup flaws: what defenders should patch first

CISA has added CVE-2026-76460 (Cisco Identity Services Engine) and CVE-2026-87886 (Acronis Backup) to its Known Exploited Vulnerabilities catalog. Both sit in infrastructure that attackers value: network access control and backup.

cisa-kevcisco-iseacronis
3 min readRead
Application Security19 September 2026

datasette-auth-github 1.0 swaps browser-session cookies for 30-day logins

The Datasette GitHub-login plugin now sets an explicit cookie lifetime instead of relying on browser-session expiry. It is a small fix, but it is a reminder that session duration is a security decision as well as a usability one.

datasettesession-managementauthentication
3 min readRead
AI security19 September 2026

Gemini Accessed Three Real Companies in a Test: Sandbox Egress Was the Failure

Google has confirmed that a Gemini model accessed three real companies' systems during a May cybersecurity test run by Irregular. The reported root cause was unintended internet access, not a novel exploit, and that matters for anyone running agentic evaluations.

ai-securitygeminiai-red-teaming
3 min readRead

Archive

Browse all 188 posts by month

Topics

Llm Security53Ai Security44Ai Governance35Ai Red Teaming29Prompt Injection28Agentic Ai25Iso 4200115Supply Chain15Supply Chain Security13Incident Response13Devsecops11Ai Agents11Web311Defi Security10Threat Intelligence9Vulnerability Management9Web3 Security9Patch Management8Smart Contracts8Ai Agent Security7Defi7Anthropic5Cloud Security5Vulnerability Disclosure5Cryptography5Owasp5Llm Agents5Sandbox Escape5Project Zero5Datasette4Sandboxing4Claude4Privilege Escalation4Smart Contract Security4Software Supply Chain4Npm4Vibe Coding4Rce4Agentic Coding4Android4Zero Day3Cisa Kev3Agent Security3Pypi3Oracle Manipulation3Python3Windows Security3Vulnerability Research3Data Exfiltration3Bridge Security3Solana3Claude Code3Social Engineering3Malware3Secure Code Review3Browser Security3Secrets Management3Mobile Security3Coding Agents2Secure Development2Data Exposure2Cve2Network Security2Mcp2Webassembly2Cisco2Cve 2026 764602Gemini2Ai Safety2Credential Theft2Open Source Security2Sqlite2Chain Of Thought2Technical Debt2Legacy Systems2Appsec2Database Security2Prompt Engineering2Attack Surface2Chatgpt2Open Weight Models2Blockchain2Governance Attack2Iot Security2Ai Infrastructure2Developer Tools2Human Oversight2Deepseek2Post Quantum Cryptography2Github Actions2Ci Cd Security2Hardware Wallets2Bitcoin2Facial Recognition2Computer Vision2Privacy2Llm Tooling2Cryptanalysis2Phishing2Account Takeover2Ai Supply Chain2Physical Security2Openai2Flash Loan Attack2Tls2Compliance2Open Weights2Ai Generated Code2Malware Analysis2Pki20 Click2Bridge Exploit2Llm Misuse1Cloudflare1Containers1Multi Tenancy1Known Exploited1Linux Kernel1Ai Coding Agents1Ai Alignment1Reasoning Models1Explainability1Serverless1Excessive Agency1Cve 2026 764611Edge Security1Cisco Ise1Acronis1Actively Exploited1Session Management1Authentication1Cookies1Github Oauth1Model Weights1Ise1Authentication Bypass1Issabel1Cve 2026 890261Unauthenticated Rce1Hardcoded Credentials1Pbx Security1Iran1Mois1Spyware1Telegram1Llm Jailbreak1Gpt 6 Astra1Risk Assessment1Browser Extensions1Oauth1Twitch1Passkey Phishing1Aitm1Device Code Phishing1Microsoft 3651Business Email Compromise1Ai Transparency1Data Privacy1Audit Trails1Uma Protocol1Optimism1Smart Contract Risk1Rubygems1Incident Disclosure1Observability1Monkey Patching1Authorization Bypass1Ai Assisted Audit1Patch Tuesday1Race Conditions1Kernel Security1Fuzzing1Generative Ai1Deepfakes1Content Provenance1C2pa1Adversarial Ai1Computer Vision Security1Surveillance Tech1Alpr1Security Debt1Secure Sdlc1Bitcoin Sidechain1Liquid Network1Vmware1Vm Escape1Virtualization Security1Developer Tooling1Postgresql1Cve 2026 64711Dprk It Workers1Insider Threat1Remote Hiring Security1Lazarus Group1Sonicwall1Cryptomining1Ai Infrastructure Security1Llm Guardrails1Gru1Sandworm1Apt281Russia1Openai Codex1Cronos1Legal Tech1Crypto Payments1Model Tampering1Price Manipulation1Base1Exploit Postmortem1Cosmos1Defi Exploit1Genai Abuse1Fraud1Unit421Ransomware1Black Hat 20261Security Market1Vendor Landscape1Identity Security1Linux1Elf1Binfmt Misc1Rag Security1Soc1Siem1Android Malware1Badbox1Automotive Security1Edr Bypass1Living Off The Land1Kernel Drivers1Windows Defender1C2 Framework1Langgraph1Ai Search1Geo1Autonomous Agents1Microvm1Code Execution1Macos Security1Infostealer1Clickfix1Endpoint Detection1Open Source1Llvm1Ray1Dns Rebinding1Training Data1Data Provenance1Xss1Svg1Sanitization1Coldfusion1Adobe Commerce1Campaign Classic1Command Injection1Patch Advisory1Chrome Extensions1Vpn Security1Adversary In The Middle1Dao Security1Explainable Ai1Military Ai1Move To Earn1Tokenomics1Crypto Risk1Due Diligence1Api Security1Ai Policy1Ai Risk Management1Model Vetting1Crypto Scams1Brand Impersonation1Xrp1Aws1Ai Security Research1Jailbreak1Kev Catalog1Langflow1Apache Tomcat1Exchange Security1Cross Chain1Ml Kem1Ml Dsa1Python Security1Crypto Agility1Entropy1Crypto Security1Shai Hulud1Servicenow1Cve 2026 68751Adversarial Ml1Privacy Tech1Llm Cli1Ai Misuse1Secure Coding1Kubernetes Security1Rng1Key Management1Sandbox Isolation1Grapheneos1Border Search1Mobile Forensics1Duress Pin1Digital Rights1Uefi1Secure Boot1Eset1Nist1Post Quantum1Llm Research1Teamcity1Cicd Security1Botnet1Blockchain C21Ddos1Sharepoint1Cve 2026 505221On Prem Security1Api Abuse1Denial Of Wallet1Token Theft1Otp Interception1Insurance1Fastjson1Java1Spring Boot1Cve 2026 167231Active Directory1Ad Cs1Cve 2026 541211Kerberos1Distillation1Biometric Surveillance1Data Retention1Hugging Face1Mfa1Identity Theft1Cardano1Local Llms1Mlx1Data Sovereignty1Macos1Flash Loan1Smart Contract Audit1Allbridge17 Zip1Cve 2026 142661Xz1Heap Overflow1Vault Exploit1Shadow Ai1Ai Risk1Openssl1Denial Of Service1Data Protection1Cli Tools1Broken Access Control1Penetration Testing1Web Application Security1Architecture1Accountability1Vendor Risk1Ai Browsers1Typosquatting1Smart Contract Exploit1Vault Accounting1Tls Certificates1Domain Validation1Ca Browser Forum1Web Security1Sycophancy1Windows Exploitation1Google1Offensive Security1Pixel1Kernel Exploit1Mediacodec1Llm Generated Code1Dom Xss1Web Components1Google Project Zero1Google Play1App Security1Anssi1Critical Infrastructure1Uac Bypass1Win32k1Tool Calling1Export Controls1National Security1Open Source Ai1Model Provenance1Current Ai1Cognitive Debt1Dspy1Evals1Google Workspace1Aztec Connect1Zero Knowledge1Ai Surveillance1Mass Surveillance1Browser Automation1Rsa1Ssh Security1Code Generation1Drone Security1Autonomous Systems1Law Enforcement Technology1Cyber Physical Security1Ethereum L21Sgx1Secret Network1Axelar1Infinite Mint1Mev1Ethereum1Ai Evasion1Ci Cd1Role Confusion1Dependency Management1Packaging1Surveillance1Smart Glasses1Meta1Law Enforcement1Multi Agent Security1Llm1