Daybreak looks to rival Anthropic’s Mythos as a high-severity vulnerability detection tool, while also securing software from the start.
…
Unnamed attackers stole data on an undisclosed number of Best Western customers, meaning phishing emails could be on the way.
…
Threat actors were spotted by GTIG using AI to find a zero-day vulnerability that could have been used in a mass exploitation attack.
…
The maker of the Canvas school software said it “reached an agreement” with the hackers, but provided no guarantees that the hackers would not release the data or keep their word.

Instructure, the company behind the Canvas learning management platform, says it has “reached an agreement” with hackers that breached its systems last week to prevent stolen data from being leaked online. The ShinyHunters hacking group claimed responsibility for the attack before Canvas was briefly taken offline. The group threatened to publish 3.5 terabytes of student […]
Instructure CEO confirmed the company paid ShinyHunters to delete the stolen files.
Hackers are targeting enterprises with a jpeg file, establishing persistence and elevating privileges.

OpenAI is launching Daybreak, an AI initiative focused on detecting and patching vulnerabilities before attackers find them. Daybreak uses the Codex Security AI agent that launched in March to create a threat model based on an organization’s code and focus on possible attack paths, validate likely vulnerabilities, and then automate the detection of the higher […]
The breach is limited to GeForce NOW users in just one country, and no passwords were stolen.
A maintainer wants a first-aid kit for the Linux kernel and a proposal is currently being reviewed.