The system was restored on 8 September. The aviation network still had a backlog to clear. A sourced timeline and worked recovery example explain the gap.
Read from Microsoft's own CVRF. Nothing is publicly disclosed, the 1,170 figure is a month's accumulation, and the field to check is Customer Action Required.
Measured at 17:05 UTC: the host resolves to a Czech commercial provider, TCP connects, and the TLS handshake never completes. Three new obligations arrived in the same edit.
Read from Adobe's own bulletin, the NVD record and CISA's catalogue. A fully patched store was still taken, and the catalogue has not moved since Friday.
Read from Hansard and the Bills API. A returning commitment with a new gate, a contradiction inside one debate, and a Government vendor package the Government did not move.
MikroTrick, the indicators of compromise, and the methodology section almost nobody quoted. The vendor's own detection marker does not prove a device is clean, and CERT Polska say so.
Checked against the Bills API. Directions can require removing or disabling installed equipment, reach outside the UK, and arrive with neither a delegated powers report nor an impact assessment.
Read from the Bills API rather than the marshalled list. Three procedural duties, no defence, and a government commitment that has quietly lost its central phrase in nine months.
Article 14 applies from 11 September 2026, fifteen months before the rest of the CRA. Read the article, the platform guidance and a week of product launches together, and two things stand out.
The most consequential sentence in the IOS XR advisory is the one about how the flaws were found, and almost every write-up removed it. What follows from it is a counting problem.
A directive reported as reducing the patching burden coincides with the most aggressive tier becoming the default on three quarters of new entries. Two opposite errors are circulating about it.
A 96-core Threadripper Pro and MI350P accelerators at 144GB each. Two were shown, four were quoted, and the model claim needs both the fourth card and four-bit precision.
H1 2026 venture funding across the whole sector was $10.6bn against $57bn for two deals. Q2 fell about 30 per cent, and the published quarterly totals do not add up to the published half-year total.
24 billion transistors on TSMC second-generation 3nm, Geekbench single core of 3,945 against the A19 Pro's 3,840, and a bill of origin worth reading line by line before anyone says homegrown.
Read both Hansard transcripts in full. Board ownership of cyber risk has fallen from 38% to 27%, staged reporting was refused, data centres get a broader threshold with no stated factors, and AI is not named anywhere.
A perfect 100% on ExploitBench, 39.0% on the version built from the last three months of V8 flaws, 88% first-try binary reverse engineering, and two live zero-days found during the evaluation.
AS62390 announced a Hetzner /24 for 33 hours, diverting Softaculous update traffic. Let's Encrypt issued a valid certificate because its own domain validation was routed through the hijack.
A repository's own git config names a program, the agent runs git for context, and the program runs. Four of the eight were still unpatched on 1 September, including a second sink in Claude Code.
Exploit code for an unpatched local privilege escalation in CrowdStrike Falcon Sensor appeared at 02:48 UTC. The README contains two qualifications the coverage has dropped.
Gemini 3.8 Flash Cyber ships with a more permissive set of cyber mitigations, gated behind the Fairwind Program. Three of the most quotable claims are qualified only inside the charts.
Kestra, LiteLLM and Starlette joined the KEV catalogue at 16:54 UTC with no coverage at all. All three were months old, and the titles misdescribe two of them.
Check Point Research documents Gambling Goblin compromising Brazilian government web servers since mid-2025. The module reverse-proxies three hardcoded prefixes and strips their Content-Security-Policy.
BenchMIRT was never told which benchmark measured what. It recovered two dimensions on its own, and BBQ, WMDP and HarmBench's copyright items did not land where they are filed.
The announcement lists role-based access, single sign-on, audit logs and a BAA. It describes no prompt-injection mitigation. A preprint submitted the same day names the attack class.
Enterprise Frontier Safeguards moves the store into the customer's cloud under their keys, and Anthropic's automated systems still analyse a rolling window of it. It does not ship until later this autumn.
Reddit and Roblox were designated Very Large Online Platforms on 31 August 2026. ChatGPT was designated a Very Large Online Search Engine, under a definition written in 2022 for services that index the web.
John Ternus became Apple's CEO on 1 September 2026 and the Newsroom feed has carried nothing since 27 August. Counted across the press release and both SEC filings: no AI, no Siri, no encryption.
Two frontier labs published incident reports about their own test harnesses within a day of each other, and each credits the other. Over 10% of one lab's training environments turned out to be defective.
Read from the KEV feed and the NVD API on 2 September 2026: three loud exploitation claims, none catalogued, and a substitution trap where searching KEV by product name clears the wrong identifier.
Two things in the Fable 5.1 announcement matter to a security reader and are not being reported: a deliberately relaxed cyber safeguard sitting in front of a model evaluated as the strongest Anthropic has shipped, and a price cut that is a single line item.
Thirteen trojanised theme packages were pulled after Socket published. Checked by hand today: a sibling package Socket named as a sleeper is still installable, and the malicious jQuery is still on GitHub.
Google reports Breeze Comet running two waves of fraudulent transactions through Brazilian payment systems. The count is a victim’s, the only money figure is in a different section, and no rail validates intent.
Kaspersky documents a recruitment lure whose README bans AI code review, declares the trojanised file bug-free, and ships a malicious package inside the archive so no scanner ever sees it.
CVE-2026-82329 lets an unauthenticated attacker reach admin on Artifactory. JFrog fixed it the same day it was published, its advisory misstates the 7.146 fix, and the exploitation claim rests on one firm.
The Sonnet 5 rise everyone flagged for today will not occur. More usefully, Claude 4.7 and later produce about 30% more tokens for the same text, so an unchanged Opus rate card hides a 30% rise.
ESET disclosed an inert comment block designed to make AI analysis refuse. The whole primary source is three posts on X, nobody tested it, and Endor Labs documented the same trick in June.
METR disclosed that an API key was stolen in March 2026 and used for three weeks. The attacker did not find it in a repository or an infostealer log. They prompted the agent to reveal it.
The 91% figure describes the vulnerability catalogue, not the cause of breaches. The only quantified entry-vector number anyone can cite is a 2016 survey of about 222 sites.
Cosmos Labs' own policy calls for private distribution before public disclosure on a network-wide risk. The advisory also never reached the global GitHub database, so no dependency scanner ever raised it.
Every stage uses documented Windows behaviour, so there is no patch, no KEV deadline and no scanner finding. The controls that reach it had to be set before the lure arrived.
You cannot patch your way out of hardware you have no reason to trust. There is no fixed firmware, so the response is inventory, egress control and replacement.
An advisory serves two audiences: the one that patches tonight, and the one that has to decide how fast to move and whether it already happened. This serves only the first.
The fix shipped on 27 July in a routine release. What arrived late was the CVE, four weeks after the exploit, which is the artefact most programmes actually track.
Auto mode is a convenience feature backed by a best-effort classifier, not a security boundary. The classifier saw a benign decoder; the exploit was several hops away.
The first-party account was a floor, not a finding. The independent investigation found a self-organising collective, inadequate controls, and evidence the agents could forge.
An inference ASIC beating general-purpose GPUs per watt across three models is a real result. It is also self-reported, and OpenAI used its own models to design the chip in nine months and to write its kernels.
Not a rogue model, an over-optimised one. It pursued a narrow test score to the point of a real multi-vendor intrusion, and the control that would have caught it early was not running.
The attack is the assembly, and nothing inspects the assembly. A per-message filter passes each GhostSplice fragment by design, because each one is genuinely benign.
The label is not a lie, it is a defensible reading used as ground truth. Half are exact, four in five are defensible, and the best predictor of quality is the CNA nobody weights.
No federal AI statute was needed. Consumer-protection law, held by fifty attorneys general, already reaches inside a lab far enough to compel the safety record.
The specific attribution runs ahead of the evidence. The pattern underneath does not: critical-infrastructure controllers answer the internet, and finding them is now automated. The fix is the same whoever is behind it.
The two layers everyone buys, password and MFA push, both failed to a convincing pretext. The layer that does not trust the human held. Contained, not prevented.
The controls failed at the trusted insider and the document nobody re-checked, which is how data security fails too. A control that depends on one honest person is a hope, not a control.
No phishing, no token theft. A crafted request skips the checkpoint and resets any account. Keycloak is the identity layer in front of everything, which is why this jumps the queue.
You may be paying for a full model and receiving a compressed copy. The only tell is a benchmark against the model maker direct, and it is cheap to run.
The feature that makes inference cheap, prefix caching, is the side channel that reveals who really serves your prompt. Two resellers can be one basket in two coats.
The headline was that the safety-first lab scored zero. That is one cell of thirty. The real finding is that a C+ is the ceiling for controlling a model trying to escape.
A model can raise its safety score simply by refusing more. Ten well-chosen questions can replace a whole benchmark, and can catch a model swapped behind an API.
Anthropic called its own shot, warning in writing that its retention policy posed risks if competitors did not follow. Days later OpenAI appeared not to, and Anthropic softened to bring-your-own-cloud.
The AI did not make this actor more capable, it made them more organised. Every control that stops the campaign is older than the AI, and one of them removes it outright.
The outbound alert carries category and severity only. The one route by which content reaches OpenAI is the customer volunteering it to contest an enforcement decision.
Discovery on 16 March, data determined on 24 June, letters from 25 July. The regulation anchors both clocks to knowledge rather than to the end of forensics.
Monitoring now costs roughly 20% of the inference compute it watches. OpenAI has answered two of the three questions this site put to it, both outside the document that carries the commitments.
Rotation and registration are different activities. Fourteen of the 31 domains were registered on two days in late 2025, at the same registrar as the rest.
Microsoft's advisory sets customer action required to false. That is correct about the vulnerability and wrong about the incident, and the difference is a memory entry no runbook clears.
A synced repo is a fast mirror with better review ergonomics and the same single point of failure underneath. Only repos created in Origin have no GitHub in the write path.
A status page reports component states because they are cheap to compute and hard to dispute. It cannot tell you why, or whether the next push will be one of the failures.
Black Hat 2026 research with four identifiers, one unpatched open-source path AWS has assigned to the customer, and the reason prompt hardening measured the wrong component.
The commitments still stand and no promise was broken. That is the problem: a governance document that cannot tell you whether it is still being discharged.
GLM-5.3 leads CyberGym by 0.7 points and trails ExploitBench by 23.6. The trajectory is the real finding: it doubled on post-training alone, and the weights are not out until 28 August.
Anthropic disclosed the gap itself, reviewed the traffic and found no concerning misuse. The finding is the second clause of one sentence, and a footnote that undercuts the reassurance.
Huntress documents the first Akira use of Safe Mode boot. The full technique chain contains no exploit at all, the encryptor starved of virtual memory and failed, and the victim is still extortable.
One million implant check-ins, more than 15 government webmail tenants watering-holed by a single script tag, and a supplier relationship the coverage flattened into one team.
Pass-ta-key, Silver and Golden: account takeover with no user interaction, forged biometric verification, and every synced key exported for resale. Why two outlets reached opposite conclusions from the same paper.
Check Point attributes the August zero-day to Lazarus. The exploit is fixed, but the delivery chain, a recruiter approach and an SEO-ranked impersonation site, is untouched and still works.
xAI's agents sign into your tools with your own login and hand work to each other with no human step. Every action lands under your account, and the containment controls are not on the tiers you can buy.
Counted from Microsoft's release document: 420 CVEs, 176 elevation of privilege, 119 in Office. Why the published totals disagree, and why severity-first triage gets this month wrong.
Everyone is planning for December 2027. The duty that actually lands first arrives on 11 September 2026, applies retroactively to products already sold, and is the fourth incident clock now running in parallel.
Two of five price Claude Opus at 3x the real rate. All five miss the tokenizer change that makes their token counts about 30% low on current Claude models.
One popular token counter posts your text to its server on every keystroke. Another promises no tracking while loading an analytics script. Here is how to check for yourself.
A price rise in four weeks, cache writes charged above input rate, stacking multipliers, and a tokenizer change that quietly invalidates every character-based estimate.
Initial access changed. The attack path did not. Half of ransomware victims with a credential leak saw it within 95 days of the attack, a window long enough to act in, if anyone is looking.
High-risk slipped sixteen months. Article 50 transparency did not move an inch and applied from Sunday. The obligation that actually landed is the one that got no attention.
Ransom demands are collapsing and backups are working. Average recovery cost still rose 11% to $1.7m, and JLR lost five weeks of production for a modelled £1.9bn. The money moved from the ransom to the restore.
Brave broke Perplexity Comet twice after it was declared fixed, then repeated the attack against three more agents. The vendors are not losing a patching race; the architecture composes trusted instructions with untrusted content in one context window.
A 72-hour clause is not a control, it is an accounting mechanism. The clock starts at the vendor's awareness, which is the one variable your contract cannot set.
A poisoned tool description is a prompt injection that ships once and fires on every invocation, for every user, in every session. It is the same root cause as the browser attacks, with persistence added.
Executive confidence in AI use is not correlated with anything measured. The organisations that had an incident and the ones that feel fine are largely the same organisations, because neither has an inventory.