Security Insights
Latest threat analysis, industry news, and security best practices from our expert team.
llm-gemini 0.34 and Gemini 3.8 Flash: A Defender's Guide to Safely Adopting LLM CLI Tooling in Security Operations
Introduction On September 2, 2026, Simon Willison released llm-gemini 0.34, the Gemini plugin for his widely used llm command-line toolkit. ...
Securing Enterprise AI at Scale: A Defender's Playbook from Adoption to Incident Readiness (2026)
The Board Said Yes to AI. Did Security Get a Vote? The debate over whether AI delivers business value is settled — Sygnia's 2026 CISO Survey...
Malicious 'Free' LLM Endpoints Are Harvesting Coding-Agent Sessions — How to Detect and Contain Rogue Inference Backends
The Free Inference Endpoint That Was the Adversary A recent SANS Internet Storm Center diary entry documented an experiment every defender r...
Hugging Face Incident: Treating AI Agents as Privileged Identities — Detection and Hardening Guide
Introduction SecurityWeek's recent analysis of the Hugging Face incident delivers a message security leaders can no longer afford to treat a...
Unit 42 Perturbation Probing: Why LLM Refusal Is a Thin Layer — Hardening and Detection Guide for Enterprise AI Deployments
Introduction New research published by Palo Alto Networks Unit 42 — Perturbation Probing: A New Diagnostic for the Fragility of LLM Safety —...
Hugging Face AI Agent Attack: Defending Against Coordinated Rogue AI Agent Compromise — Detection and Response Guide
Introduction New reporting on the July attack against Hugging Face — the central hub for machine learning models, datasets, and AI tooling —...
OWASP's New AI Skills Security Blueprint: Defending Against Malicious AI Agent Add-Ons
Introduction The Open Worldwide Application Security Project (OWASP) has published a new Top 10 security list purpose-built for the modern A...
CVE-2026-77776: Headroom LLM Proxy Identity Spoofing (CVSS 9.1) — Detection and Remediation Guide
NVD has published CVE-2026-77776, a CVSS 9.1 (Critical), network-exploitable vulnerability in Headroom's LLM proxy — the intermediary compon...
CoSnitch Attack: Defending Microsoft 365 Copilot Against Prompt Injection and Architecture Reconnaissance
CoSnitch: When Your AI Assistant Becomes the Reconnaissance Tool Security researchers have disclosed a novel attack technique dubbed CoSnitc...