ZeroClaw added SLSA Build L3 provenance attestation to its release pipeline as part of a broader hardening push. The change strengthens supply-chain transparency for users evaluat…
Anthropic-Cybersecurity-Skills appeared in the June 26 GitHub trend digest as a large open-source library of cybersecurity skills mapped to industry frameworks. The signal shows a…
On June 23, 2026 researchers at Calif.io disclosed Squidbleed (CVE-2026-47729), a heap buffer over-read in the Squid proxy's FTP parser that has gone undetected for about 29 years…
Qwen Code opened PR #5369 to preserve the actual workspace-trust state when extension and MCP commands run. The bug came from treating a trust result object as a boolean, which co…
A small open-source script for bulk-deleting Claude chats from the web UI drew Hacker News attention on June 13. The project exists because Claude's visible selection flow does no…
Cloudflare added custom topics to AI prompt protection, extending predefined detections for PII, source code, and jailbreak attempts with organization-specific concepts. Teams can…
OpenClaw shipped v2026.6.5 with QQBot reasoning-content sanitization and broader MCP tool-result coercion. The release addresses a trust boundary issue: agent reasoning or tool sc…
Anthropic’s red team published research on how large language models can accelerate and automate N-day exploit development, focusing on already-disclosed vulnerabilities that rema…
A command-injection flaw in the widely used LiteLLM AI gateway (CVE-2026-42271) lets its MCP test endpoints run arbitrary commands, and Horizon3.ai showed it chains with a Starlet…
Astra Autonomous Pentest led the June 6 Product Hunt AI lineup with an agentic security pitch: AI agents that find, validate, and fix vulnerabilities. The launch reflects demand f…
Anthropic expanded Project Glasswing from an initial partner group to roughly 200 total organizations, targeting power, water, healthcare, communications, hardware, and other upst…
Vercel Blob now supports OIDC authentication and makes it the default for newly connected projects. Vercel-issued short-lived tokens replace long-lived `BLOB_READ_WRITE_TOKEN` cre…
DCP launched on Product Hunt with a positioning centered on encrypted permissions, key handling, and approval flows for autonomous agents. The product pitches itself as a non-cust…
OpenClaw's June release line now spans security boundary hardening and a June 15 v2026.6.8-beta.1 update focused on Telegram and WhatsApp delivery reliability. The updated record…
Anthropic's first public Project Glasswing update says Claude Mythos Preview and roughly 50 partners have already found more than 10,000 high- or critical-severity vulnerabilities…
1Password and OpenAI introduced a Codex integration that routes credential access through the 1Password Environments MCP Server instead of exposing raw secret values in prompts, r…
OpenAI says it is adopting Google’s SynthID watermarking technology for AI images and pairing it with a verification tool. The move adds a concrete provenance layer to generated i…
Keygraph's Shannon Lite is surfacing as an open-source AI pentester for web applications and APIs that combines source-code analysis with exploit execution. The project emphasizes…
Vercel launched Protected Source Maps so browser `.map` files return 404 to the public while staying available to authenticated team members. The feature is enabled by default for…
OpenAI disclosed that two employee devices were affected in the TanStack npm supply chain attack and said limited credential material was exfiltrated from a subset of internal sou…
Whisper launched an MCP-based AI context layer for security and infrastructure investigations, exposing live BGP, DNS, WHOIS, GeoIP, and threat-intelligence relationships from Whi…
Vercel updated the Sandbox firewall to support forwarding selected HTTP requests to a proxy under customer control, along with matchers and credentials brokering for the requests…
Fabraix launched publicly as an adversarial verification platform for AI agents, pairing black-box stress testing with runtime defense. The product is built around finding functio…
Anthropic published new alignment research saying current Claude models from Haiku 4.5 onward no longer show the blackmail-style agentic misalignment behaviors highlighted in prio…
Anthropic introduced natural language autoencoders, a research approach that translates Claude's internal activations into human-readable text. The company positions it as an inte…
OpenAI began rolling out Trusted Contact, an optional ChatGPT setting that lets adults nominate a person who may be notified if trained reviewers determine a serious self-harm ris…
Vercel published a coordinated May 2026 security release for Next.js, covering 13 advisories across denial of service, middleware and proxy bypass, SSRF, cache poisoning, and XSS.…
Braintrust confirmed a breach in one of its AWS environments and told customers to rotate sensitive API keys on May 6. For an AI evaluation and experimentation platform, the incid…
Vercel open-sourced deepsec, a security harness that uses coding agents to scan large repositories for hard-to-find vulnerabilities on infrastructure the user controls. The projec…
ZeroClaw merged a security-policy fix that distinguishes git -C from git -c in its shell controls. The change addresses an over-broad policy behavior that could block legitimate G…
Tinfoil launched on Product Hunt with a privacy-focused AI chat and API pitch centered on keeping conversations private. The product enters a market where data handling and traini…
noirdoc launched an open-source Claude Code plugin and companion API proxy that pseudonymize names, emails, IBANs, and other sensitive fields before model calls are made. The prod…
QwenPaw v1.1.5.post1 ships a security-sensitive update that rejects absolute static file paths to prevent path traversal, while also moving Feishu tool approvals to interactive ca…
Anthropic published an election safeguards update describing how Claude is trained and monitored to handle political and election-related prompts. The company shared fresh evaluat…
Vercel's April 2026 security bulletin says the incident originated with a compromise of Context.ai, a third-party AI tool used by a Vercel employee. According to the bulletin, the…
OpenAI opened applications for a GPT-5.5 Bio Bug Bounty that asks vetted researchers to find a universal jailbreak that can beat a five-question biology safety challenge in Codex…
OpenAI released Privacy Filter, an open-weight model for detecting and redacting personally identifiable information in text. The model is positioned as local, high-throughput pri…
GitHub added a workflow that lets teams assign Dependabot alerts to coding agents including Copilot, Claude, and Codex so the agent can analyze the vulnerability and open a draft…