Install
Please confirm you are human
This browser or connection looks automated. Press and continuously hold the control for 3 seconds to enable Google-hosted web results and, when separately allowed, AI-assisted answers.
A successful check enables 100 search requests. Interactive access does not authorize scraping, systematic collection, or reuse of search output.
News
One HTTP Request, Every File on the Server: GitLab’s CVSS 10 Commits-API Flaw Hits Active Exploitation Within Hours
56+ min ago (170+ words) A single HTTP POST to the commits API bypasses all security controls and reads arbitrary files from a GitLab server. CISA gave agencies until September 14 to patch. watchTowr saw exploitation attempts starting six hours after disclosure. The vulnerability was reported…...
Once in a BlueMoon: How a Chrome Patch-Gap Turned Three V8 Zero-Days Into an Espionage Kit
1+ hour, 21+ min ago (65+ words) Three V8 bugs, individually medium-severity, chain into SYSTEM-level access through the patch-gap window. Four espionage clusters adopted the kit within days. The structural shift: browser-based AI agents inherit the same attack surface. Heath Callahan Trust, Identity & Security All stories by Heath…...
The Agent Security Reckoning: What to Watch at Dreamforce 2026
1+ hour, 45+ min ago (61+ words) As Dreamforce positions agent security as a first-class pillar, the security keynote raises three questions Salesforce hasn't answered: agent identity, headless authentication, and audit trails for multi-agent environments. Heath Callahan Trust, Identity & Security All stories by Heath Callahan → |[email protected] Heath…...
Dreamforce 2026: Salesforce Is Betting the Whole Stack on Agent Governance as Infrastructure
16+ hour, 33+ min ago (308+ words) The industry's largest enterprise platform has re-engineered governance from a bolt-on compliance layer into the core runtime of the agentic enterprise. For builders, the question is no longer whether to govern agents — it's how deeply governance shapes the architecture. When…...
Four Weeks, Four Critical CVEs: AI Inference Infrastructure Is Now a Regular Target
16+ hour, 24+ min ago (104+ words) The authentication gap has migrated from agent runtimes into the inference server layer. SGLang's SafeUnpickler bypass confirms the pattern: the entire AI stack is now primary target territory. IBM Langflow (CVE-2026-81204), also disclosed September 8, carries a CVSS of 9.8 and allows…...
Akamai and MuleSoft Unify Runtime Enforcement Across Agent Fabric – Bridging the Gap Between Security Policy and AI Orchestration
1+ day, 7+ hour ago (149+ words) The roadmap for the second half of 2026 suggests that this integration will only deepen. Planned updates include native MuleSoft onboarding features and expanded runtime security specifically for AI and MCP environments. These capabilities will be demonstrated at Salesforce Dreamforce from…...
DeepSeek Harness Sandbox Escape Lets AI Agents Disable Their Own Confinement
1+ day, 8+ hour ago (69+ words) CVE-2026-82533 is the first confirmed vulnerability where an AI agent runtime sandbox was the direct attack surface. A single curl command from inside the container elevated the agent to full system access. Heath Callahan Trust, Identity & Security All stories by…...
What Agent Commerce Needs From Product Data: Lessons From the W3C/GS1 Workshop
1+ day, 16+ hour ago (68+ words) A Zurich workshop brought W3C, GS1, Google, Shopify, OpenAI, and Mars together to address the 'last meter' problem – agents can complete transactions but still buy the wrong product without proper identity standards. Tessa Vaughn Agentic Commerce All stories by Tessa Vaughn → |[email protected]…...
DeepSeek’s New Architecture Slashes Agentic Costs by 80%
1+ day, 18+ hour ago (128+ words) A Causal Encoder-Decoder design compresses cache-hit costs to $0.003 per token and retires V4-Pro, forcing a recalibration of the agent economy's pricing structure. These developments occur as DeepSeek, now carrying a $71 billion valuation, continues to push the limits of Chinese open-weight…...
79% of Multi-Agent Failures Are Specification Problems – And the New Protocol Stack Isn’t Solving That Layer
1+ day, 18+ hour ago (76+ words) UC Berkeley's MAST taxonomy shows the vast majority of multi-agent system failures stem from how agents are designed and specified, not from model limits. The industry's runtime enforcement stack addresses the easier half of the problem. Blair Hayes Agent Infrastructure…...