Latest Briefings
AI Coding Assistants: Do Hidden Security Costs Erase the Productivity Gains?
Subscription fees of $19 to $200 per user per month are only the visible cost of AI coding tools. Security scanning, remediation,…
AI Agents Are Widening the Machine Identity Security Gap
New research and a real-world OAuth token breach show that identity security programs built for humans are struggling to keep pace with…
Three Chained Flaws in OpenClaw AI Assistant Enabled WhatsApp-to-Host Takeover
A researcher has disclosed details of three now-patched, high-severity vulnerabilities in the OpenClaw personal AI assistant that could be chained from a…
Weekly Roundup: DHS Database Breach, Adobe Speeds Up Patches, Canada Disrupts Ransomware Infrastructure
This week's roundup covers a breach of a DHS interagency network, Adobe's move to twice-monthly patch releases, Canadian intelligence operations against ransomware…
Progress Tells ShareFile Storage Zone Controller Customers to Shut Down Servers Now
Progress Software has disabled cloud access to on-premises ShareFile Storage Zone Controllers and is urging customers to manually power down affected Windows…
Dutch Police Suspect Local Hackers Behind Odido Vishing Breach
Dutch National Police say they have found strong indications that Dutch-speaking hackers used a vishing call to Odido's customer service to trigger…
GigaWiper: Go-Based Backdoor Merges Wiper, Ransomware, and Remote Access
Microsoft details GigaWiper, a Go-based backdoor active since October 2025 that bundles destructive disk-wiping, file encryption, and full remote control into a…
Ex-Ransomware Negotiator Sentenced to 70 Months for Secretly Aiding BlackCat
A former DigitalMint negotiator who fed victim insurance limits and negotiation strategy to BlackCat operators has been sentenced to nearly six years…
Managing Context Windows in Large Codebases
A practical guide to feeding big codebases to an AI model without drowning it in tokens, using retrieval, summarization, compaction, and sub-agents.
npm 12 Disables Install Scripts by Default to Cut Supply Chain Risk
GitHub has shipped npm 12 with install scripts turned off by default and has deprecated granular access tokens that could bypass two-factor…
Microsoft: AI-Powered Vulnerability Scanning Will Mean More Windows Patches
Microsoft is deploying a multi-model AI scanning system to find bugs in Windows binaries faster, and says customers should expect a higher…
Helix Vishing Group Targets SharePoint via Device Code Phishing
A newly identified extortion group called Helix is combining voice phishing, device code abuse, and MFA hijacking to steal and ransom data…