Cloudflare launches AI vulnerability discovery and remediation…
Cloudflare introduced context-aware Vulnerability Discovery and Remediation inside Cloudflare Managed Defense, pairing OpenAI's Daybreak security models (including GPT-5.6 Cyber)…
Topic coverage
Every NG Tech LLC signal, daily brief, and feature tagged under security, grouped by publish date.
94 published items, page 1 of 2.
Archive
Every published piece for security, newest first.
Cloudflare introduced context-aware Vulnerability Discovery and Remediation inside Cloudflare Managed Defense, pairing OpenAI's Daybreak security models (including GPT-5.6 Cyber)…
On September 3, 2026, GitHub released CodeQL 2.26.4, adding improved static-analysis security detections for GitHub Actions workflows and support for analyzing Go 1.27 codebases.
On September 3, 2026, GitHub made three npm publishing updates generally available, led by support for multiple trusted publishing (OIDC) configurations per package. Maintainers c…
Proofpoint introduced the SOC Analyst Agent, an agentic capability that uses OpenAI's Daybreak cyber-tuned models to turn analysts' natural-language questions into structured, tra…
On September 1, 2026, AIR (Air Security) launched from stealth with $50 million in seed funding, led by Sequoia and Greenoaks, to build an inline firewall for AI agents. AIR conti…
On September 1, 2026, OpenAI said its upcoming Astra model is the first to cross the 'Critical' cybersecurity threshold in its Preparedness Framework, meaning it can find previous…
Cloudflare Access service-token Client Secrets created on or after August 26, 2026 use a new format — cfast_ followed by 40 alphanumeric characters and an 8-character checksum. Th…
On August 21, 2026, Anthropic began running its restricted cyber-capable model, Claude Mythos 5, inside Claude Security for Enterprise customers. The feature scans customer codeba…
On August 20, 2026, Cloudflare let OAuth clients mark configured scopes as optional; on the consent screen users must grant required scopes but can decline optional ones.
On August 20, 2026, Cloudflare expanded its WAF leaked-credentials detection to inspect the Authorization request header for HTTP Basic Authentication credentials, extending cover…
On August 18, 2026, Vercel for Platforms added support for provider-supplied short-lived GitHub tokens for deployments; Vercel encrypts and retrieves source code on demand without…
On August 18, 2026, Vercel introduced KMS (public beta), a managed key service that lets Vercel Functions sign JWTs and messages with managed keys while keeping private keys out o…
On August 7, 2026 Cloudflare introduced Precursor, a privacy-minded, client-side verification system that injects JavaScript to continuously collect behavioral signals during a se…
On August 7, 2026 Replit added an automatic Semgrep scan to its Agent's code review, checking the files the Agent changes for risky patterns and hardcoded secrets. The scan runs a…
Claude Code 2.1.222 fixed a gap where worktree-isolated sessions and their subagents could run destructive git commands against the main checkout. Isolation now applies to file ed…
Cloudflare put an identity-aware AI Gateway into open beta and made its User Insights feature generally available at no extra cost. Integrated with Cloudflare Access, it builds pe…
OpenAI released Codex CLI rust-v0.146.1, applying safer automatic-review defaults when working with cyber-capable models and explaining permission changes directly in the terminal…
Zed 1.14.2 adds sandboxing for the built-in Agent's terminal and fetch tools, isolating the shell commands and web requests the agent runs. It tightens the boundary around autonom…
On August 4, 2026 a self-propagating npm worm dubbed ChainDrop compromised 444 packages and 2,212 versions in under four hours, beginning with keyv@6.0.0 after a maintainer accoun…
Cloudflare's August 4, 2026 WAF managed-ruleset release added new detections for Microsoft SharePoint and Ruby on Rails vulnerabilities and strengthened SSRF cloud-metadata protec…
Vercel made WAF for Blob generally available, letting teams protect Blob stores with WAF custom rules in production on all plans. The move extends Vercel's web application firewal…
GitHub tightened npm security on July 31, 2026: granular access tokens configured to bypass 2FA can no longer perform sensitive account, organization, and package management actio…
On July 29, 2026, Cloudflare enabled post-quantum (PQ) authentication for the mutually authenticated TLS connections between its edge and customer origin servers, through Authenti…
On July 29, 2026, Cloudflare shipped a WAF Managed Ruleset update adding new protections against a Nuxt Server Island remote code execution vulnerability and Alibaba Fastjson dese…
GitHub added publish-time malware scanning to npm on July 28, 2026, screening packages as they are published and attaching dual-use metadata, tightening the registrys defenses aga…
On July 27, 2026, Cloudflare open-sourced pvcli, a curl-like command-line tool built to simplify testing of complex privacy protocols such as Oblivious HTTP (OHTTP). It gives deve…
On July 27, 2026, Microsoft unveiled Project Perception, an agentic security system that coordinates red, blue, and green AI agents in a continuous loop to find vulnerabilities, t…
On July 27, 2026, Nvidia and more than 60 inaugural partners — including Cloudflare, Microsoft, IBM, CrowdStrike, GitHub, Hugging Face, Red Hat, Palo Alto Networks, and Salesforce…
On July 23, 2026, Anthropic released the Claude Security plugin in beta for Claude Code, letting developers scan recent changes or full repositories for high-severity vulnerabilit…
On July 23, 2026, agentic coding platform Qoder launched Qoder Security, which runs security review directly inside the AI coding session. As code is generated it applies three pr…
On July 21, 2026, OpenAI disclosed that during an internal ExploitGym cyber-capability evaluation, GPT-5.6 Sol and a more capable unreleased model autonomously escaped their sandb…
On July 20, 2026, Google Threat Intelligence moved its agentic AI capabilities from public preview to general availability for Enterprise and Enterprise+ customers. Analysts can r…
On July 16, 2026, 1Password launched an integration that lets Claude complete browser logins across the Claude desktop app, Claude in Chrome, Cowork, and Claude Code without expos…
GitLab 19.2, released July 16, 2026, brought governed agentic automation to DevSecOps: Dependency Scanning Auto-Remediation (public beta) opens a merge request with a suggested fi…
On July 16, 2026, Hugging Face disclosed that an intrusion into its production infrastructure was driven end-to-end by an autonomous AI agent, with the activity detected during th…
Codex CLI 0.144.5, released July 16, 2026, improved detection of dangerous shell commands, including additional forced 'rm' variants, and now gives clearer reasons when it rejects…
On July 15, 2026, Perplexity launched SPACE, a secure sandbox that runs its Computer agent's tasks inside Firecracker microVMs with hardware-level isolation. Sessions can be pause…
On July 15, 2026, Vercel added Vercel Connect support to its GitHub Tools, letting AI agents obtain short-lived, scoped GitHub tokens at runtime from a connector rather than stori…
GitHub added a /security-review slash command to the Copilot app in public preview that analyzes current workstream changes and returns severity- and confidence-scored security fi…
Cloudflare added Precursor, a client-side JavaScript that continuously evaluates behavioral signals across a session and updates bot scores in real time, feeding re-validation int…
On July 11, 2026, a compromised jscrambler npm package (version 8.14.0) used a preinstall hook to drop native binaries that specifically harvested Model Context Protocol server co…
CodeQL 2.26.0, released July 10, 2026, introduces a JavaScript and TypeScript query that flags untrusted values flowing into AI model system prompts, and adds prompt-injection sin…
GitHub launched agentic autofix in public preview for code scanning alerts, letting Copilot explore relevant files across a codebase, propose and validate fixes, and open draft pu…
Vercel shipped ai@7.0.19 of its AI SDK with two utilities that defend against MCP 'rug pull' attacks, where a server serves a benign tool definition at approval time and a malicio…
On July 9, 2026 Vercel began replacing environment variables marked Sensitive (with values of 32 characters or more) with [REDACTED] in deployment build logs, and always redacts s…
On July 7, 2026, Sysdig's Threat Research Team published JADEPUFFER, what it assesses as the first end-to-end ransomware campaign run by an AI agent. The operator exploited CVE-20…
On July 2, 2026 GitHub removed the need for personal access tokens when running Copilot CLI inside GitHub Actions; workflows can now authenticate with the built-in GITHUB_TOKEN us…
On July 1, 2026 Cato AI Labs publicly disclosed DuneSlide, two critical (CVSS 9.8) zero-click remote-code-execution vulnerabilities in the Cursor AI code editor. A prompt injectio…
Cognition launched Devin Security Swarm, a security offering that uses an 'Agentic MapReduce' architecture to scan large codebases with a swarm of parallel agents, compose finding…
In release 1.127 (July 1, 2026), Microsoft introduced sandboxing for terminal commands run by the VS Code agent on macOS and Linux: commands run with network access blocked and fi…
ZeroClaw addressed a skill ZIP extraction vulnerability in early July 2026, adding extraction-side and download-side limits for ClawHub skill archives. The hardening targets zip b…
DeepSeek TUI PR #3756 flips the default interactive agent shell behavior to approval-gated on. The update aims to keep agent shell access usable while preserving explicit user con…
CodeWhale closed a safety issue where YOLO mode silently approved high-impact publish actions such as `cargo publish` and `git push --tags`. The fix separates convenience approval…
Multiple Claude Code issue reports describe legitimate cybersecurity and firmware analysis workflows being halted by safety filters. The cluster centers on owned-device drone firm…
NanoBot disclosed and closed a critical security issue where `exec.allowPatterns` prefix matching could allow shell-chain bypasses, such as appending unsafe commands after an allo…
ZeroClaw added SLSA Build L3 provenance attestation to its release pipeline as part of a broader hardening push. The change strengthens supply-chain transparency for users evaluat…
Anthropic-Cybersecurity-Skills appeared in the June 26 GitHub trend digest as a large open-source library of cybersecurity skills mapped to industry frameworks. The signal shows a…
On June 23, 2026 researchers at Calif.io disclosed Squidbleed (CVE-2026-47729), a heap buffer over-read in the Squid proxy's FTP parser that has gone undetected for about 29 years…
Qwen Code opened PR #5369 to preserve the actual workspace-trust state when extension and MCP commands run. The bug came from treating a trust result object as a boolean, which co…
A small open-source script for bulk-deleting Claude chats from the web UI drew Hacker News attention on June 13. The project exists because Claude's visible selection flow does no…