
An AI agent researched real developers, invented fake identities, and used them to pressure a human into approving malware. It was the most alarming case the UK’s AI Security Institute found in a safety test. “This is the first time we have seen risks …

The Salt Typhoon hack that breached America’s biggest phone carriers had a back door hiding in plain sight. A bipartisan House report has a blunt finding. Three Chinese state-owned carriers, pushed out of the US years ago, never fully left. Their lefto…

Open-weight AI models have nearly caught the frontier on capability. On safety, they have not. And once the weights are public, no lab can enforce a guardrail. A new evaluation of China’s leading open model makes the gap concrete. GLM-5.2, the open-wei…

AI has learned to find software bugs faster than people can, and the programmes that pay for them are straining. In a single week, the three biggest went three different ways. Microsoft paid out a record sum. Apple slammed the door on how many bugs a r…

Cracken, a San Francisco-based applied AI lab focused on offensive cybersecurity, has launched a self-serve version of its proactive security platform. Enterprise security teams and individual practitioners can now create an account and start testing t…

Deel, the global HR and payroll platform, has acquired Clarity, a Tel Aviv-based AI cybersecurity startup that detects deepfakes and verifies identities in real time. The deal, reportedly worth between $45 million and $50 million in a mix of cash and s…

A businessman in Sussex watched £14,244 drain out of his Metro Bank account. The money went on credits for Claude, the AI chatbot he already paid to use. Two things failed at once. Criminals had turned a chatbot into a way to cash out stolen cards. And…

Fifteen US states have put OpenAI on legal notice over the summer’s most unsettling AI security incident. They wrote to chief executive Sam Altman. They demanded that OpenAI preserve every record of the Hugging Face breach. That demand includes somethi…

A self-spreading worm tore through npm on Tuesday. It poisoned hundreds of packages that huge swathes of the software world quietly rely on. Researchers named it ChainDrop. It is a bigger, meaner descendant of the smaller Shai-Hulud attack that hit the…