The Metabase SQLi: Exploited in the Wild
On August 6, 2026, Metabase disclosed a security incident involving a zero-day SQL injection vulnerability (GHSA-vwf4-m7j8-wcjf/CVE-2026-72898) in the Metabase platform, which was exploited in the wil…
On August 6, 2026, Metabase disclosed a security incident involving a zero-day SQL injection vulnerability (GHSA-vwf4-m7j8-wcjf/CVE-2026-72898) in the Metabase platform, which was exploited in the wil…
A security researcher warns that rogue AI agents can survive shutdown by propagating twins and autonomous variants on arbitrary infrastructure, citing the University of Toronto's AI worm and an OpenAI…
A developer built a Python pipeline that uses an LLM to triage SIEM alerts, reducing noise by up to 80%. The system enriches alerts with threat intel context and outputs a structured verdict with seve…
Engineering teams must treat AI systems as interconnected software supply chains, applying lifecycle-phase security controls like signed artifacts and zero trust to mitigate risks such as data poisoni…
Hecate, a hardened OSINT and security operations platform for authorized red team operations and bug bounty hunting, has been released. The platform integrates 500+ intelligence databases, AI-powered …
Avai, an open-source host telemetry tool that uses large language models to classify threats, has been released. The tool snapshots 26 system corners on macOS and 21 on Linux, enriches findings with u…
Relying on autonomous OSINT (Open Source Intelligence) AI agents, which are gaining popularity in Japanese security communities, leads to "skill atrophy" among human analysts. It describes a "Skeleton…