Our Blog

Research, analysis, and practical guidance on cybersecurity and AI security from our London team.

AI Security & Data Governance21 July 2026

Nativ and the Local-LLM Wave: What Running Models On-Device Really Fixes

A new open-source macOS app wraps Apple's MLX in a chat UI and a local OpenAI-compatible API server — a reminder that "local" reduces one class of AI data risk while introducing others.

local-llmsmlxdata-sovereignty
4 min readRead
DeFi & Smart Contract Security21 July 2026

Allbridge Core Loses $1.65M to a Flash Loan Pricing Bug It Fixed in 2023

A flash loan against Allbridge Core's Solana stablecoin pools distorted internal pricing and let an attacker drain roughly $1.65 million — the same class of bug the protocol says it patched on BNB Chain three years ago.

defi-securityflash-loanweb3
3 min readRead
Web3 & Bridge Security20 July 2026

Across Protocol's Solana Bridge Hit for $3.35M — Relayer, Not Users, Took the Loss

A July 17 attack on Across Protocol's Solana deployment drained roughly $3.35 million from the project's own relayer, not from bridge users — a result that says as much about bridge architecture as it does about the exploit itself.

web3bridge-securitysolana
4 min readRead
Vulnerability Management20 July 2026

CVE-2026-14266: 7-Zip Heap Overflow in XZ Parsing Fixed in 26.02

A heap-based buffer overflow in 7-Zip's XZ decoder let a crafted archive corrupt memory on extraction. The fix landed quietly in June; ZDI's July 15 advisory is why you're hearing about it now.

7-zipcve-2026-14266xz
4 min readRead
DeFi & Smart-Contract Security19 July 2026

Summer Finance's $6M Vault Accounting Bug Ends in Full Shutdown

A flash-loan attacker exploited how Summer Finance's Fleet Commander vault priced its underlying strategies, extracting $6 million in a single transaction — and the protocol has now wound down entirely.

defi-securityflash-loan-attacksmart-contract-security
4 min readRead
AI Governance19 July 2026

Token Leaderboards and Blind Mandates: AI's Hidden Governance Risk

A widely shared consultant's account of executives mandating AI use they've never touched themselves is a governance failure, not just a culture problem — and it leaves real gaps for security teams to close.

ai-governanceiso-42001shadow-ai
4 min readRead
AI Governance18 July 2026

AI-Built Dev Tools and the Verification Gap: A SQLite Case Study

Simon Willison had an AI model build an interactive SQLite query-plan explainer — then published it with an explicit admission he can't verify its output himself. That's a small, honest window into a governance problem security and engineering teams will keep running into.

ai-governancellm-toolingiso-42001
4 min readRead
Vulnerability Management18 July 2026

OpenSSL's HollowByte DoS Flaw Shipped With No CVE — Here's Why That Matters

An 11-byte TLS handshake header can lock up hundreds of megabytes of server memory before authentication even starts. OpenSSL fixed it in June 2026 without a CVE, an advisory, or a changelog entry.

openssldenial-of-servicevulnerability-management
4 min readRead
AI Governance & Compliance17 July 2026

Why Giving Users 'Control' Over Data Won't Fix AI-Era Privacy

Legal scholar Daniel Solove argues in the Wall Street Journal that consent-based privacy law has failed — and that AI makes the case for regulating companies directly, the way food and drug law does.

ai-governanceprivacydata-protection
4 min readRead
Browser & AI Security17 July 2026

Puter Ported Firefox to WebAssembly — and Routed Every Byte Through Its Own Server

Puter's proof-of-concept compiles the Firefox/Gecko engine to WebAssembly so it runs inside another browser tab — a striking feat of AI-assisted engineering that also happens to be a live demonstration of what a network trust boundary looks like.

ai-securitybrowser-securitywebassembly
4 min readRead
AI Governance16 July 2026

Thinking Machines' Inkling: Open Weights, Thin Data Provenance

Mira Murati's lab has open-sourced a 975-billion-parameter multimodal model under Apache 2.0 — but its training-data documentation gives security and governance teams little to work with.

ai-governanceopen-weightsllm-security
4 min readRead
AI Agent Security16 July 2026

xAI's Grok Build CLI Quietly Uploaded Whole Repos — Then Went Open Source

A coding-agent CLI from xAI shipped entire local directories, including secrets, to a Google Cloud bucket regardless of privacy settings. xAI disabled the upload path and open-sourced the tool days later.

ai-securityagentic-aidata-exfiltration
4 min readRead
AI & LLM Security15 July 2026

Claude's Web-Fetch Guardrail Had a Gap: The Memory Heist Explained

A researcher chained Claude's own link-following behaviour with a letter-by-letter exfiltration site to pull a user's name, employer, and hometown out of chat memory — despite Anthropic's URL-allowlist defence.

prompt-injectionllm-securitydata-exfiltration
5 min readRead
Application Security15 July 2026

FIFA's Broken Access Control Bug Left World Cup Streams Open to Hijack

A researcher who signed up as a football agent found himself inside FIFA's internal platforms — because the authorization checks only ran in the browser.

broken-access-controlpenetration-testingvulnerability-disclosure
4 min readRead
DevSecOps & Infrastructure14 July 2026

Lobste.rs moves to SQLite: a lesson in shrinking your attack surface

The tech-news community site Lobsters has retired MariaDB in favour of SQLite after an eight-year migration effort — a small architectural decision with a useful security lesson about trading network attack surface for single-host risk.

devsecopsattack-surfacearchitecture
4 min readRead

Archive

Browse all 56 posts by month

Topics

Llm Security15Ai Governance14Ai Security12Prompt Injection10Ai Red Teaming8Iso 420017Web36Agentic Ai6Defi Security5Ai Agents5Project Zero4Android4Smart Contract Security3Mobile Security3Supply Chain3Defi2Smart Contracts2Patch Management2Flash Loan Attack2Tls2Compliance2Agentic Coding2Open Weights2Data Exfiltration2Claude2Vulnerability Disclosure2Cloud Security2Devsecops2Vibe Coding2Secure Code Review2Ai Generated Code2Malware Analysis2Supply Chain Security2Npm2Pypi2Pki2Vulnerability Research20 Click2Cryptography2Agent Security2Bridge Exploit2Local Llms1Mlx1Data Sovereignty1Macos1Flash Loan1Smart Contract Audit1Allbridge1Bridge Security1Solana17 Zip1Cve 2026 142661Xz1Heap Overflow1Vault Exploit1Shadow Ai1Ai Risk1Llm Tooling1Developer Tools1Openssl1Denial Of Service1Vulnerability Management1Privacy1Data Protection1Browser Security1Webassembly1Network Security1Cli Tools1Broken Access Control1Penetration Testing1Web Application Security1Attack Surface1Architecture1Database Security1Software Supply Chain1Llm Agents1Accountability1Vendor Risk1Claude Code1Ai Browsers1Typosquatting1Ci Cd Security1Smart Contract Exploit1Vault Accounting1Tls Certificates1Domain Validation1Ca Browser Forum1Web Security1Sycophancy1Openai1Windows Exploitation1Google1Offensive Security1Pixel1Kernel Exploit1Mediacodec1Llm Generated Code1Dom Xss1Web Components1Secure Development1Google Project Zero1Google Play1Malware1App Security1Post Quantum Cryptography1Anssi1Critical Infrastructure1Windows Security1Uac Bypass1Privilege Escalation1Win32k1Tool Calling1Export Controls1National Security1Ai Supply Chain1Open Source Ai1Model Provenance1Current Ai1Cognitive Debt1Prompt Engineering1Dspy1Evals1Google Workspace1Gemini1Aztec Connect1Zero Knowledge1Ai Surveillance1Computer Vision1Mass Surveillance1Physical Security1Browser Automation1Secrets Management1Rsa1Ssh Security1Code Generation1Drone Security1Autonomous Systems1Law Enforcement Technology1Cyber Physical Security1Ethereum L21Sgx1Web3 Security1Secret Network1Axelar1Infinite Mint1Mev1Ethereum1Ai Evasion1Github Actions1Ci Cd1Role Confusion1Python1Dependency Management1Packaging1Facial Recognition1Surveillance1Smart Glasses1Meta1Law Enforcement1Multi Agent Security1Llm1Appsec1Owasp1