AI Evaluation Containment: One Vendor, Three Labs, Four Failures
AI evaluation containment has now failed publicly at three frontier labs, and the same testing vendor is named in three of the…
Information security is the practice of protecting systems, data, and users from compromise and loss. Articles in this category cover threat models, social engineering, authentication, compliance considerations, and the operational habits that keep an organization defensible at scale.
AI evaluation containment has now failed publicly at three frontier labs, and the same testing vendor is named in three of the…
The evaluation sandbox used to test frontier AI models for cyber capability has now failed publicly at two different labs nine days…
Security-specialized AI became a shipping product category in the last two weeks of July. Sakana AI released Fugu-Cyber on 21 July. Google…
The Open Secure AI Alliance launched on 27 July with NVIDIA convening a coalition to build and share open tooling for securing…
Buried in Hugging Face’s disclosure of the July 2026 breach of its infrastructure is a detail that most follow-up coverage has skipped,…
wp2shell is the name given to a pair of chained vulnerabilities in WordPress core that together let an unauthenticated attacker run code…
WordPress secrets have historically lived in places that any security review would flag: the WordPress options table, plugin-specific tables, individual user meta…
In mid-July 2026, Hugging Face reported that an autonomous AI agent had broken into part of its production infrastructure. A few days…
Passkeys are the post-password authentication credential. They replace both the traditional password and the additional MFA code that authenticator apps produce, with…
The question that comes up almost every time someone configures their first authenticator app is the right question to start this post…