NIST AI SEC Core
NIST is revising the AI Risk Management Framework 1.0, the 2023 document whose Core sets out four functions — govern, map, measure, and manage — for managing AI risks across the system lifecycle. The …
NIST is revising the AI Risk Management Framework 1.0, the 2023 document whose Core sets out four functions — govern, map, measure, and manage — for managing AI risks across the system lifecycle. The …
AI-enabled products need human-centered fault tolerance that keeps core workflows completable when models fail, according to an engineering analysis that cites the NIST AI Risk Management Framework's …
NIST IR 8587 addresses token security as a non-human identity problem, warning that API tokens, OAuth credentials, personal access tokens, cloud credentials and service-account secrets can grant direc…
A developer built MAREF, an agent governance OS covering all ten OWASP Agentic Top 10 risks, after deploying OpenClaw (then Clawdbot) and discovering it auto-committed 37 passwords and 12 API keys in …
Cloudflare has set a 2029 deadline to achieve full post-quantum readiness across its platform, developing an internal AI-powered tool called CryptoLabe that uses large language models to discover, ana…
Anthropic's September 29, 2026 report recorded 50 successful end-to-end exploit attempts out of 410 for the open-weight GLM-5.3 model, a 12.2% success rate, versus 56 of 410 (13.7%) for Claude Mythos …
A federal appeals court upheld the Pentagon's designation of Anthropic as a supply chain risk, according to CNBC, after the company restricted its models from being used for autonomous weapons or dome…
MAREF Engineering released MAREF, an open-source Apache 2.0 agent governance framework whose 10-state Gray Code governance finite state machine is TLA+-verified with 5 invariants and covers all 10 ris…
A developer outlined an engineering approach to verifiable systems that combines zero-knowledge proofs, hardware attestation via TEEs like Intel SGX and ARM TrustZone, and Merkle-tree batching to repl…
A security-focused analysis argues that the key difference between AI agents and traditional automation is where control over execution lives: in code engineers wrote, or in a model-driven decision lo…
An analysis of OpenAI's September 22, 2026 GPT-6 Sol and Luna announcement estimates that OpenAI researchers could be spending more than $4.24 million per day on tokens at API prices, based on the com…
A Sept. 12 research preprint proposes PQLN, a hybrid post-quantum extension built as a rust-lightning research prototype, to protect five off-chain Lightning Network functions that would remain expose…
Orchid Security unveiled AI agent readiness controls on September 15, 2026, adding continuous identity drift monitoring and application-layer kill switches so enterprises can terminate an agent's auth…
Orchid Security introduced identity drift detection and application-level kill switches for AI agents, letting enterprises terminate an agent's authority within seconds when it exceeds its granted pri…
A developer measured Caddy 2.11.4's default post-quantum TLS handshake and found the hybrid X25519MLKEM768 key exchange inflates the ClientHello and ServerHello from a combined 440 bytes to 2704 bytes…
A practitioner framework published by an author citing 26 years of experience and U.S. patent US11681721B2 lays out five gates that organizations should clear before an AI agent receives real producti…
Aptos Foundation SVP and Head of Ecosystem Ash Pampati warned at Consensus Miami that quantum computing threats to blockchain cryptography are "sooner than we think," saying blockchains must stop trea…
NIST published a paper by Apostol Vassilev in IEEE Security & Privacy (vol. 24, no. 3, May-June 2026) claiming to extend Gödel's incompleteness theorem to AI, arguing that for any finite set of AI gua…
Enterprise AI deployments lack a lifecycle for managing business context, the meaning attached to data such as how finance defines revenue or which customer policy applies, according to an analysis of…
Neither "local AI" nor "private AI" has a formal definition, and no standard defines either term, according to an analysis that cites the NIST AI Risk Management Framework released January 26, 2023, w…