Security Insights
Latest threat analysis, industry news, and security best practices from our expert team.
Trezor–ShipMonk Third-Party Breach: 67,000 U.S. Customers' 'Deleted' Data Exposed — Detection and Response Guide
Introduction On Friday, hardware wallet manufacturer Trezor disclosed that a breach at its shipping provider, ShipMonk, has exposed the pers...
H1 2026 Malware & Vulnerability Trends: Defending Against Trusted Tool Abuse, AI-Driven Attacks, and Supply Chain Compromise
The Threat Landscape Has Shifted — And Your Detections Need to Shift With It Recorded Future's H1 2026 malicious software and vulnerability ...
CVE-2026-82329: JFrog Artifactory Auth Bypass Under Active Exploitation — Detection and Remediation Guide
A Critical Artifactory Flaw Is Being Exploited — And Your Build Pipeline Is the Prize Within days of public disclosure, threat actors began ...
llm-anthropic 0.27 and the anthropic-sdk-python v1.0.0 Breaking Change: A Defender's Guide to Managing the httpx-to-httpx2 Dependency Shift
Introduction On August 24, 2026, Simon Willison released llm-anthropic 0.27, an update to the Anthropic plugin for his LLM command-line tool...
OWASP's New AI Skills Security Blueprint: Defending Against Malicious AI Agent Add-Ons
Introduction The Open Worldwide Application Security Project (OWASP) has published a new Top 10 security list purpose-built for the modern A...
llm 0.33 Dependency Overhaul: What Security Teams Must Verify Before Upgrading Simon Willison's LLM CLI
Introduction On August 22, 2026, Simon Willison shipped llm 0.33, a release of his widely adopted open-source CLI for interacting with large...
Simon Willison's llm 0.32.1: Transitive Dependency Breakage in AI CLI Tooling — Supply-Chain Lessons and Hardening Guide
What Happened On August 21, 2026, Simon Willison shipped llm 0.32.1, an emergency dot-release for his widely used open-source CLI tool for i...
Recorded Future Adds Native Risk Ratings to Third-Party Risk: What Defenders Should Do With It
Introduction Recorded Future has launched native risk ratings capabilities inside its Third-Party Risk product, uniting external threat inte...
VMware Exploitation, Unpatched Windows Flaw, MCP Attacks & Browser Hijacking: Weekly Threat Recap and Defensive Playbook
Introduction This week's threat landscape is a case study in a lesson I keep repeating to clients: the attacks causing the most damage are r...