Actions
Media Outlet details
| Scope | International, Trade/B2B |
|---|---|
| Language | English |
| Country | United States of America |
|
Similarweb UVM |
Request pricing |
|
Comscore UVM |
Request pricing |
Recent Articles
Search ArticlesThe Challenge of Hacking Back, the Origins of ExploitGym, and Water Plant Attacks
This week we discuss the new White House memo on using private sector operators in offensive cyber operations, Lindsey's deep dive into the origins of the ExploitGym AI benchmark, and the rash of attacks on water utilities in the U.S. Links Inside ExploitGym: https://decipher.sc/2026/08/20/inside... White House memo: https://www.whitehouse.gov/presidenti... OpenAI post: https://openai.com/index/the-defender...
Inside ExploitGym: How Researchers Are Measuring AI Agent Exploitation Capabilities
In May, a group of researchers submitted a paper to arXiv with a thought-provoking title: “Can AI Agents Turn Security Vulnerabilities into Real Attacks?” The research wasn’t theoretical: it was based on ExploitGym, an evaluation benchmark designed to test if AI agents could use known security flaws to develop working exploits.
MLflow Bug Actively Exploited to Steal Credentials
Security researchers have identified a critical vulnerability in MLflow that exposes default tracking server installations to unauthenticated Server-Side Request Forgery (SSRF) and attackers are already exploiting it. This flaw allows remote, unauthenticated attackers to read sensitive data from internal network services or cloud metadata endpoints and potentially interact with internal management services through POST requests.
OpenAI, Anthropic AI Agents Performed ‘Unsanctioned’ Actions During Cyber Tests
The AI Security Institute (AISI) on Tuesday said that OpenAI and Anthropic models had gone rogue during tests last week that were performed with internet access and with “ model-provider cyber classifiers were deliberately disabled.” In one case, one of the agents attempted (unsuccessfully) to launch a supply-chain attack by convincing an open-source repository maintainer to accept a malicious GitHub pull request.
Researchers Find Persistent Backdoor in Zbtlink Routers
Researchers at VulnCheck have identified a persistent, previously undisclosed backdoor embedded in the firmware of a wide range of Chinese-manufactured routers. The vulnerability, named EndlessDoors by the research team, affects more than 20 specific models of networking hardware sold globally under both the Zbtlink and Wiflyer brand names. Jacob Baines, CTO at VulnCheck, discovered the flaw while analyzing the device firmware.
The truth about AI model security and what’s coming next | Gary McGraw
Necessary cookies enable essential site features like secure log-ins and consent preference adjustments. They do not store personal data. None Functional cookies support features like content sharing on social media, collecting feedback, and enabling third-party tools. None Analytical cookies track visitor interactions, providing insights on metrics like visitor count, bounce rate, and traffic sources.
Researchers Find Persistent Backdoor in Zbtlink Routers
Researchers at VulnCheck have identified a persistent, previously undisclosed backdoor embedded in the firmware of a wide range of Chinese-manufactured routers. The vulnerability, named EndlessDoors by the research team, affects more than 20 specific models of networking hardware sold globally under both the Zbtlink and Wiflyer brand names. Jacob Baines, CTO at VulnCheck, discovered the flaw while analyzing the device firmware.
OpenAI, Anthropic AI Agents Went ‘Rogue’ Again: Five Questions Answered
The AI Security Institute (AISI) on Tuesday said that OpenAI and Anthropic models had gone rogue during tests last week that were performed with internet access and with “model-provider cyber classifiers [that] were deliberately disabled.” In one case, one of the agents attempted (unsuccessfully) to launch a supply-chain attack by convincing an open-source repository maintainer to accept a malicious GitHub pull request.
Exploits Target N-able CVE-2026-18577 Flaw
Researchers are warning MSPs and enterprise IT teams that use N-able’s N-central Remote Monitoring and Management (RMM) platform that CVE-2026-18577, a critical authentication bypass vulnerability, is currently being actively exploited in the wild. The vulnerability, which effectively provides unauthenticated administrative access to the RMM console, stems from two related security issues.
Inside the Cybercrime Ecosystem
In today's mercurial cybercrime economy, few people understand the shift from reactive response to proactive defense better than Mike Sweeney. As the director of preemptive cyber defense at Silent Push, Sweeney is challenging the status quo of traditional cyber threat intelligence, advocating for a forward-looking approach that treats the internet as a single, observable network.