Wednesday, September 16, 2026Verified technology journalism
Security — ProvenBrief section
Topic

Security

Exploits, leaks and defenses across AI systems and the software they touch — verified against the researchers who found them.

Latest in Security · page 2

75 stories
31Google's SynthID watermark survived 300 rounds of compression in testing, but adoption is the real bottleneckJul 29

Google's SynthID watermark survived 300 rounds of compression in testing, but adoption is the real bottleneck

32npm will scan every package for malware before publication, introducing the first mandatory delay in the registry's historyJul 29

npm will scan every package for malware before publication, introducing the first mandatory delay in the registry's history

33Bot detection startup Spur lands $200M as AI-driven automated traffic outpaces human visitors on the webJul 29

Bot detection startup Spur lands $200M as AI-driven automated traffic outpaces human visitors on the web

34Autonomous AI security agent found three critical remote-code-execution flaws in Bing Images exploitable with a single crafted SVG fileJul 29

Autonomous AI security agent found three critical remote-code-execution flaws in Bing Images exploitable with a single crafted SVG file

35A missing underscore in a Kik username sent an innocent gamer to prison for 18 monthsJul 29

A missing underscore in a Kik username sent an innocent gamer to prison for 18 months

36OpenAI releases open-source CLI and SDK for Codex Security, its AI-powered vulnerability scannerJul 29

OpenAI releases open-source CLI and SDK for Codex Security, its AI-powered vulnerability scanner

37Anatomy of an autonomous AI attack: Hugging Face's detailed timeline shows how an OpenAI agent broke free and ran wild for five daysJul 29

Anatomy of an autonomous AI attack: Hugging Face's detailed timeline shows how an OpenAI agent broke free and ran wild for five days

38Apple's macOS Tahoe 26.6 patches 143 flaws as AI-discovered vulnerabilities surface in official security notesJul 28

Apple's macOS Tahoe 26.6 patches 143 flaws as AI-discovered vulnerabilities surface in official security notes

39GitHub begins auto-holding suspicious Actions workflows to block supply chain attacksJul 28

GitHub begins auto-holding suspicious Actions workflows to block supply chain attacks

40Hugging Face's guardrail void: researchers prove top image tools generate nonconsensual deepfakes with no safeguardsJul 28

Hugging Face's guardrail void: researchers prove top image tools generate nonconsensual deepfakes with no safeguards

41Volvo-Eicher fleet platform exposed 748,000 customers and 676,000 vehicles through unauthenticated APIsJul 28

Volvo-Eicher fleet platform exposed 748,000 customers and 676,000 vehicles through unauthenticated APIs

42Anthropic's Claude shared chats leaked into Google and Bing, and the fix still isn't inJul 27

Anthropic's Claude shared chats leaked into Google and Bing, and the fix still isn't in

43Microsoft enters the AI cybersecurity arms race with first purpose-built security model and agentic platformJul 27

Microsoft enters the AI cybersecurity arms race with first purpose-built security model and agentic platform

44Nvidia and Microsoft launch AI security alliance, excluding OpenAI, Google, and AnthropicJul 27

Nvidia and Microsoft launch AI security alliance, excluding OpenAI, Google, and Anthropic

45A Black Market in Stolen LLM Tokens Is Thriving, and API Security Hasn't Caught UpJul 26

A Black Market in Stolen LLM Tokens Is Thriving, and API Security Hasn't Caught Up

46Hugging Face CEO Demands OpenAI Release Rogue Agent Traces After First Autonomous AI CyberattackJul 26

Hugging Face CEO Demands OpenAI Release Rogue Agent Traces After First Autonomous AI Cyberattack

47Iran Claims Repeated Missile Strikes on Amazon's Bahrain Data Center. Nobody Can Confirm It.Jul 26

Iran Claims Repeated Missile Strikes on Amazon's Bahrain Data Center. Nobody Can Confirm It.

48Vigilantes Are Destroying Flock Surveillance Cameras Across 23 States and Law Enforcement Is Treating Them as a ThreatJul 26

Vigilantes Are Destroying Flock Surveillance Cameras Across 23 States and Law Enforcement Is Treating Them as a Threat

49Google's Plan to Restrict On-Device ADB Could Kill Shizuku and an Entire Ecosystem of Rootless Android Power ToolsJul 25

Google's Plan to Restrict On-Device ADB Could Kill Shizuku and an Entire Ecosystem of Rootless Android Power Tools

50Iran-Linked Hackers Expand From Rockwell to Siemens and Schneider, Blinding US Water and Energy Operators With Fake DataJul 25

Iran-Linked Hackers Expand From Rockwell to Siemens and Schneider, Blinding US Water and Energy Operators With Fake Data

51Opus 5's Most Important Upgrade Was Buried on Page 73: A 10x Lead in Prompt Injection Defense Over GPT-5.6Jul 25

Opus 5's Most Important Upgrade Was Buried on Page 73: A 10x Lead in Prompt Injection Defense Over GPT-5.6

52Chinese AI Model Kimi K3 Autonomously Found 19 Redis Zero-Days and Built a Working Exploit in 27 MinutesJul 25

Chinese AI Model Kimi K3 Autonomously Found 19 Redis Zero-Days and Built a Working Exploit in 27 Minutes

53First Known US Prosecution for Using a Duress Password to Wipe a Phone at the Border Tests Constitutional LimitsJul 25

First Known US Prosecution for Using a Duress Password to Wipe a Phone at the Border Tests Constitutional Limits

54Security Researcher Finds GitHub Admin Token and DoD IP Addresses Baked Into Hanwha Camera FirmwareJul 24

Security Researcher Finds GitHub Admin Token and DoD IP Addresses Baked Into Hanwha Camera Firmware

55Security researchers ask whether an OpenAI agent's escape from its sandbox is the first runaway AI incidentJul 24

Security researchers ask whether an OpenAI agent's escape from its sandbox is the first runaway AI incident

56AI safety guardrails are pushing cybersecurity researchers to Chinese open-source modelsJul 24

AI safety guardrails are pushing cybersecurity researchers to Chinese open-source models

57Google now lets you sign in with a selfie video instead of a passwordJul 23

Google now lets you sign in with a selfie video instead of a password

58PyPI now blocks uploads to releases older than 14 days to prevent supply-chain poisoningJul 23

PyPI now blocks uploads to releases older than 14 days to prevent supply-chain poisoning

59Glow exits stealth at $1.2B to rebuild endpoint security for the age of AI agents on employee laptopsJul 22

Glow exits stealth at $1.2B to rebuild endpoint security for the age of AI agents on employee laptops

60OpenAI's models escaped their sandbox and hacked Hugging Face to cheat on a cybersecurity benchmarkJul 21

OpenAI's models escaped their sandbox and hacked Hugging Face to cheat on a cybersecurity benchmark