Security Insights
Latest threat analysis, industry news, and security best practices from our expert team.
Hugging Face Supply-Chain Attack & PHANTOM-B: Threat Modeling Lessons for Defending AI/ML Pipelines
Introduction When Adam Shostack — arguably the most authoritative voice in threat modeling alive — says he was "blown away" by an attack dis...
Encrypted LLM Reasoning Traces Can Be Recovered: Defending OpenAI and Anthropic API Traffic from Trace Extraction
What Happened A few days ago, security researcher Johann Rehberger (Embrace The Red) published a hands-on write-up building on the paper "St...
Anthropic's Claude Text Watermarking Plan: What Defenders Need to Know About AI Content Provenance
Introduction Anthropic has publicly detailed its thinking on watermarking text generated by Claude — a technical approach that would allow A...
CVE-2026-73678: MindsDB Unauthenticated RCE via Anton Agent Scratchpad — Detection and Remediation Guide
A CVSS 10 in the AI Stack: Why CVE-2026-73678 Demands Immediate Action The NVD has published CVE-2026-73678, a critical, network-exploitable...
Reasoning Trace Extraction from Proprietary LLM APIs: Detection and Hardening Guide for Security Teams
Introduction A new attack technique against proprietary large language model APIs is making the rounds, and it should be on every security t...
Stealing Reasoning Traces from Proprietary LLM APIs: How Attackers Exfiltrate Chain-of-Thought and How to Defend Against It
Introduction A recently publicized technique demonstrates that proprietary large language model APIs — including models that deliberately su...
Prompt Injection Defense: Why Transparent AI Agents Are the Detection Layer Your SOC Is Missing
Introduction A recent opinion piece on CyberScoop makes an argument that every security leader deploying AI agents needs to internalize: the...
OpenAI Astra Model Paused Over Cyber Capability Gains: What Defenders Must Do Now
Introduction OpenAI has paused certain internal activities involving its next-generation model, codenamed Astra, after internal evaluations ...
ChatGPT Sandbox Escape at Black Hat USA 2026: Defending Against C2-Style Control of AI Sandboxes
Introduction At Black Hat USA 2026, a security researcher demonstrated a proof-of-concept attack chain that achieved command-and-control (C2...