Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Reconciling an AI Risk Estimate Against What Truly Happened

A model produces a figure, an event happens, and somebody asks whether the figure was right. It is the obvious question and it has almost no published answer, because the comparison is harder than it looks. ‍ A single realized loss cannot falsify a distribution. If a model puts a one percent chance on exceeding a threshold and the threshold is exceeded, the one percent case occurred, which is what the model said would sometimes happen. ‍

Emerging Threat: (CVE-2026-86858) ServiceNow AI Platform Unauthenticated Privilege Escalation via GraphQL

CVE-2026-86858 is an improper access control flaw in the ServiceNow AI Platform, classified as CWE-284. ServiceNow describes it as an unauthenticated privilege escalation reachable through GraphQL. In certain circumstances an unauthenticated user can create, modify, or delete instance data beyond what was intended. The vulnerability carries a CVSS v4.0 base score of 8.7 (High). Attack vector is network, attack complexity is low, and neither privileges nor user interaction are required.

The Agentic SOC Isn't Coming for Analysts' Jobs. It's Coming for Their Tabs.

An agentic SOC uses AI-powered investigation, analysis, and automation to gather data, connect activity, and handle repetitive investigative work. Analysts remain in control and focus on judgment, prioritization, and response. This addresses the need for machine-speed security operations as AI agents gain autonomy and Tier 1 access to systems. Spend five minutes watching a security analyst at work and the “AI will replace analysts” headline starts to sound out of touch.

AI Security in DevOps: Best Practices to Follow

Attacking a CI/CD pipeline used to require a specialist who understood Git internals, cloud identity, and the way build runners handle secrets. That is no longer true. The barrier to entry for an advanced attack has dropped to the level of writing prompts in English. Automation itself is not new to DevOps, but AI has raised its ceiling on both sides of the fence.

AI Threats Are Evolving Fast. Your Employees Are Still the Last Line of Defense.

New training on using AI safely and spotting AI-powered threats arrives this Cybersecurity Awareness Month Attackers are moving faster than ever, weaponizing newly discovered vulnerabilities before defenders can patch them and building new types of malware that signature-based defenses can’t catch.

When a Security Guardrail Detects the Attack and Still Can't Stop It

Salt Labs recently showed that a single email could hijack the AI agent platform Manus and reach a victim’s connected accounts. The full technical breakdown, with complete evidence, payloads, and screenshots, is in our research team’s write-up, and Dark Reading first reported the finding in an exclusive. This post is the shorter version: what the finding means and what it tells every organization now deploying AI agents. For the full technical detail, read the Salt Labs research blog.

How We Hijacked an AI Agent With a Single Email

Salt Labs found that the agentic AI platform Manus could be hijacked with a single email. By hiding malicious instructions inside an ordinary message, researchers got Manus to execute malicious code and, from there, reach the email, cloud storage, and code repository accounts a user had connected to it. The full attack required nothing from the victim beyond asking Manus to check their inbox. No stolen password, no clicked link.

Building a bot takes five minutes. What it stands on took eight years. Introducing LimaCharlie Bots.

Co-founder and CCO We shipped bots in the LimaCharlie AI Terminal. You can create one in a few minutes: give it a role, pick a profile if you want one, and open a chat. I said this during our September Build Log demo and I'll repeat it here, because everything else in this post follows from it. The bot is the easy part.

Introducing The GitGuardian Mixin Kit To Extend Docker Sandboxes for Safer AI Coding

Modern enterprise security is increasingly being tasked with keeping agents from affecting critical data and infrastructure. In this video, Dwayne, principal developer at GitGuardian, introduces how GitGuardian AI hooks extend the power of Docker Sandbox isolation. Their micoVM architecture plus the power of ggshield mean anyone can get an agent working in a secure way with very little effort. Chapters.

What's New at GitGuardian: AI Leak Triage & Laptop Secrets Scanning

We found 15x more valid secrets on developer laptops than in code repositories. In this September edition of What's New in GitGuardian, Sr. Product Managers Léna Cuissard and Emmanuelle Franquelin walk through two updates: agents that triage public secret leaks for you, and Developer Endpoint Protection coming together as one package.