GitHub stories
Cybersecurity experts warn single-person approvals are now vulnerable after an AI agent used fabricated identities to slip malicious code past checks.
The findings heighten concern that frontier AI agents can breach boundaries, pressure real people and target software supply chains under loose controls.
Security chiefs face a widening breach risk as most firms plan to use AI agents, yet barely a third feel ready to secure them properly.
A Windows Defender zero-day is leaving organisations exposed to SYSTEM-level takeover until Microsoft issues an official fix.
Employers can now link AI bills to team output as Rippling's new console aims to show whether model use is worth the cost.
The browser-based system aims to let staff use AI across internal tools without new infrastructure, while tightening access and oversight.
Pressure is mounting on businesses to secure AI data and recover faster after cyber incidents, as static labels and ad hoc restoration prove too slow.
Stricter checks now govern the 15,000-star repository as Google tries to stop weak instructions and broken links hurting AI coding agents.
Three out of four offensive security investigations traced back to identity or privilege, exposing access gaps across cloud, SaaS and AI systems.
Nearly half of scanned MCP server builds carried at least one security concern, underscoring fresh supply chain risks as AI agents rely on them.
Developers can now break large code changes into smaller reviews as GitHub rolls the feature out across all repositories.
Malicious packages are now spreading faster across code repositories, with Google saying open source ecosystems face the sharpest rise in risk.
Security teams can now trace attack routes across AWS and Microsoft Entra, as SpecterOps extends BloodHound into hybrid and AI-linked environments.
Subscription merchants could gain faster access to local payment methods as Recurly taps Juspay's Hyperswitch for more than 300 providers.
Critical vulnerability backlogs have swelled 29-fold, prompting a tool that sends fix plans into engineering systems and AI coding tools.
Enterprise AI agents are already generating revenue, but shortages of compute and skills could determine who captures the gains.
Merchants on Recurly will gain access to more than 300 payment providers through one integration, helping curb failed recurring charges.
Developers using AI assistants could face stolen credentials and poisoned repositories as the worm hides inside normal coding workflows.
Businesses could soon hand routine office tasks to named AI agents, as CollectivIQ rolls out software that works inside existing workplace systems.
Security teams may get findings within 24 hours as Cobalt targets faster testing across sprawling software estates.