AI Security EU AI Omnibus takes effect: new AI Act deadlines
The EU AI Omnibus took effect on 27 July 2026. We explain new high-risk deadlines, deepfake rules, sandboxes, business duties and a compliance plan.
Daily news, analysis and practical guides explaining what happened, who is affected and what to do next. We also turn this knowledge into practical training for organisations.
AI Security The EU AI Omnibus took effect on 27 July 2026. We explain new high-risk deadlines, deepfake rules, sandboxes, business duties and a compliance plan.
Vulnerabilities and CVEs A public exploit runs commands as git on unpatched GitLab 18.11.3 servers. The fix shipped as a bugfix, with no CVE. Analysis and lessons.
Threats and Incidents Sysdig documented JadePuffer — the first ransomware attack carried out end to end by an LLM agent. We analyse the chain and what defenders should do.
AI Security Microsoft unveiled Project Perception, joining red, blue and green-team agents. We examine its design, reported results, risks and safe SOC adoption.
Vulnerabilities and CVEs Node.js announced HIGH-severity fixes for the 26, 24 and 22 release lines. Here is what is confirmed, what remains undisclosed and how to patch safely.
AI Security OpenAI analysed 800,000 messages to measure task crossover. We examine the results, limitations and implications for skills, security and AI governance.
Threats and Incidents Spirals ransomware encrypted an IT firm's network in under 24 hours. We break down the attack timeline and show where it could have been stopped.
AI Security Anthropic released the Claude Security Plugin in beta — a multi-agent vulnerability scanner for Claude Code. How it works, where it helps, what it won't replace.
Vulnerabilities and CVEs Two CVSS 9.1 flaws in FortiSandbox let an unauthenticated attacker run OS commands. Both are in CISA KEV. Analysis, detection and remediation.
AI Security Google shipped Gemini 3.6 Flash: lower output pricing, ~17% fewer tokens and a 1M context window. What it means for cost, deployments and security.
Vulnerabilities and CVEs Microsoft patched a record 570 vulnerabilities and three zero-days in July 2026. How to triage that many fixes and what you must not defer.
Threats and Incidents A 0-day in Oracle PeopleSoft (CVE-2026-35273) hit 100+ organisations including NAIC. Analysis, and a lesson in reading extortion groups' claims.
AI Security OpenAI and Broadcom unveiled Jalapeño, a custom ASIC for LLM inference. What the custom silicon race means for cost, availability and AI security.
Identity and Access How to split an environment into tiers, what really belongs to Tier 0, how to enforce the split technically and how to migrate without downtime.
AI Security Zenity Labs showed how a single link could create an autonomous agent in ChatGPT Workspace working for an attacker. CSRF in the age of agents.
Once a month, a concise summary of the vulnerabilities and threats that matter. No spam, unsubscribe anytime.