Researchers escaped four top AI coding agents’ sandboxes without ever breaking them
Researchers escaped four top AI coding agents’ sandboxes without ever breaking them

The tools are Cursor, OpenAI’s Codex, Google’s Gemini CLI, and Antigravity. Over several months, Pillar Security found ways for each agent to cross its security boundary while staying, technically, inside the box. The escape that isn’t one The trick is…

Fake FBI social media scams are on the rise — here’s what to look out for
Fake FBI social media scams are on the rise — here’s what to look out for

Victims reporting crimes to the FBI are actually being caught and revictimized, leading to further financial losses.

Google launches a cheaper alternative to large AI security models like Mythos
Google launches a cheaper alternative to large AI security models like Mythos

Google is launching Gemini 3.6 Flash alongside a new security model dedicated to quickly finding and patching security vulnerabilities. In a blog post on Tuesday, Google describes Gemini 3.5 Flash Cyber as a “cost-efficient and highly capable alternative” to larger, more expensive AI systems, such as the one offered by Anthropic’s Mythos. The cybersecurity model […]

A cloud tenant could rattle the power grid with nothing but a rented GPU, researchers say
A cloud tenant could rattle the power grid with nothing but a rented GPU, researchers say

AI data centres already strain the grid just by running. A new paper asks a darker question: what if a tenant tried to break it on purpose? Three researchers at Zhejiang University set out the idea in a preprint called Bit2Watt, accepted to a leading h…

AI music generator Suno breach affects 55M users, per Have I Been Pwned

A hacker took names, phone numbers, and physical addresses of millions of customers who used AI music generator Suno.

OpenAI’s maths-cracking AI kept escaping its sandbox, so it pulled the plug
OpenAI’s maths-cracking AI kept escaping its sandbox, so it pulled the plug

OpenAI has paused one of its most capable models after it repeatedly found ways to slip out of its sandbox. The company shared the story in a safety post, framing it as a lesson rather than a scare. This is not just any system. About two months ago it …

Estée Lauder says it was hit by data breach caused by Oracle E-Business issue

The breach happened in August 2025, but was only spotted recently by Estée Lauder.

UK government scraps plans for digital ID cards after millions of Brits opposed

The new U.K. government scrapped a digital ID program that millions of British people opposed, in place of a tax cut to tackle the cost of living.

Empirical Security raised $25M to predict which flaws hackers will actually exploit
Empirical Security raised $25M to predict which flaws hackers will actually exploit

Most security teams face the same problem. There are far more flaws than anyone can fix, and no clear way to know which ones matter. Empirical Security wants to predict the answer. The Chicago startup’s Series A was led by Brightmind Partners, chief ex…

Hackers are mass-exploiting two WordPress flaws, and AI found the way in
Hackers are mass-exploiting two WordPress flaws, and AI found the way in

If you run a WordPress site, the advice this week is blunt: update it now. Two flaws in the software are under active exploitation across the internet. WordPress powers more than half of every website online, so the blast radius is huge. Security firms…