This website uses cookies
Read our Privacy policy and Terms of use for more information.
Mar 27, 2026
CVE-2026-33017 gives unauthenticated attackers full remote code execution on any exposed Langflow AI pipeline with a single HTTP request. CISA confirmed active exploitation and added it to its Known Exploited Vulnerabilities catalog on March 25 — eight days after Sysdig observed the first attacks in the wild. Patch to version 1.9.0. Do it today.
Mar 26, 2026
Forty-seven per cent of security leaders — per Cybersecurity Insiders’ 2026 CISO AI Risk Report — have already seen AI agents behave unexpectedly this year. The response that works isn’t to slow deployment down — it’s to build the governance rails that make fast deployment safe.
Mar 25, 2026
A confirmed Sev-1 at Meta. A 1.5 million token credential dump from an OpenClaw platform. 135,000 exposed agent instances. Five new reports this week put numbers — and breach reports — to a risk that is already past the theory stage.
Mar 24, 2026
When attackers compromise a device management platform, they don’t need malware — they use your own tooling. The Stryker attack is the most disruptive state-linked wiper campaign of 2026, and a direct case study in what happens when privileged access to management infrastructure goes unguarded.
Mar 23, 2026
An autonomous AI agent breached McKinsey’s internal chatbot in under two hours. A popular agent platform’s marketplace is distributing malware. Core AI infrastructure has critical unpatched flaws. This week’s theme: the tools organisations use to deploy AI are themselves under attack.
Mar 20, 2026
Most developers now use AI to write or augment code — and for good reason. But the tooling that makes teams faster also introduces security blind spots that traditional workflows were not built for.
Mar 19, 2026
Customer call records, source code, FBI background checks, and financial data exfiltrated from one of Canada’s largest BPO providers. The $65 million ransom demand was rejected.
Mar 17, 2026
The Hardened Newsletter — A daily guide to security in the AI-driven enterprise