Secure AI Adoption: Close the Governance Gap to Accelerate AI in the Cloud September 25, 2026 Keegan Justis BLOG 8 min. Every week, another team spins up a new artificial intelligence (AI) service. A…
At a glanceMoving the SonarQube Remediation Agent to Claude Opus 5.5 improved every quality measure we track and cut the cost of each fix by roughly 58%.
CARBONATO exploits exposed Docker daemons, installs an AI agent, steals API keys and spreads across networks with autonomous command execution. CARBONATO is a Docker-based botnet that has been active…
arXiv:2609.28537v1 Announce Type: new Abstract: Over the past thirty years, the online advertising industry built a large-scale data collection ecosystem, with the goal of tracking a user's online…
arXiv:2609.28559v1 Announce Type: new Abstract: LLMs increasingly operate through coding-agent harnesses that inspect repositories, invoke tools, and modify files. Substituting the model behind such…
arXiv:2609.28564v1 Announce Type: new Abstract: Agentic video-generation systems close a loop between a generator and a verifier: an LLM plans shots, calls a text-to-video model, and a multimodal…
arXiv:2609.28572v1 Announce Type: new Abstract: Multi-stage LLM-based cyber agents may complete attack workflows while remaining brittle, costly, or reliant on incorrect interpretations of execution…
arXiv:2609.28585v1 Announce Type: new Abstract: Multi-step tool-calling LLM agents rely on host runtimes to preserve state across turns. When a runtime carries an external tool return into later…
arXiv:2609.28843v1 Announce Type: new Abstract: Blockchain and artificial intelligence (AI) are converging into a single infrastructural layer for securing data sharing, model integrity, and…
arXiv:2609.28900v1 Announce Type: new Abstract: Multi-agent systems built on large language models (LLMs) are increasingly deployed in high-stakes settings such as finance, healthcare, and software…
arXiv:2609.28915v1 Announce Type: new Abstract: LLM agents are deployed into infrastructure that grants them broad host authority, yet existing agent-security benchmarks and defenses operate almost…
arXiv:2609.28940v1 Announce Type: new Abstract: Autonomous penetration-testing harnesses use large language models (LLMs) for reconnaissance, exploitation, and reporting, but often rely on those same…
arXiv:2609.29130v1 Announce Type: new Abstract: Short claims such as not-phishing or official can change how a large language model (LLM) judges a domain name, without explicit prompt-injection…
If you’re new to fuzzing and want to learn the fundamentals first, check out our Fuzzing 101 course at gh.io/fuzzing101. Continuous fuzzing is not a magic solution that solves all your problems…
Compared with GPT-6 Astra, GPT-6 Sol writes 27% less code and produces 22% fewer findings in total, at a pass rate 2.76 points lower and with more findings per line of code. GPT-6 Astra was the…
Most of us click on search results without knowing much about the website we’re about to visit. And once we’re there, it’s not always obvious when something isn’t quite right. Now, we’ve added two…
Posted by Sam James on Sep 23 Here's the relevant release notes at the link in the email below: """ +Changes in version 0.4.9.13 - 2026-09-23 + This security release includes several high severity…
arXiv:2609.26893v1 Announce Type: new Abstract: We introduce ACTS (Artifacts in Cipher Testing Suite), a reproducible benchmark that isolates cryptanalytic ability through tiered metadata deprivation…
arXiv:2609.27091v1 Announce Type: new Abstract: The growing adoption of blockchain technologies, particularly the Ethereum platform, has amplified the critical role of smart contracts in…