Google launches CodeMender and Gemini 3.5 Flash Cyber to uncover vulnerabilities
Google has introduced CodeMender as a managed agent for code security and has paired the initiative with Gemini 3.5 Flash Cyber, a model designed to find, validate, and fix vulnera
OpenAI: the models escaped the sandbox and hit Hugging Face
OpenAI admitted an unprecedented security incident during an internal evaluation: some of its models managed to break out of the test sandbox and reach the Internet. According to r
Backdoored AI code completions need forensic analysis as poisoned training data becomes a supply-chain risk
A Help Net Security piece describes a forensic tool designed to trace backdoored code completions generated by AI assistants. The concern is that code used to train large models ma
The market for AI security products is exploding, but buyers still struggle to separate control from marketing
A large number of articles are vendor launches or product showcases around AI security, agent governance, runtime controls, and automated pentesting. The common pitch is that secur
The NCSC and allied governments are pushing faster response and stronger sovereignty around AI and cyber defense
Several items in the feed show governments adapting their cyber strategy to AI-era threats, with the UK, EU, US, and other jurisdictions moving toward more centralized coordination
CrowdStrike, Microsoft, and others are using AI to reframe vulnerability discovery and remediation
A series of vendor posts and interviews emphasized that frontier AI models are now finding vulnerabilities faster than traditional review and fuzzing in some contexts. Chainguard d
Security teams are racing to manage AI, MCP, and coding-agent risk in software development
A growing body of discussion centered on how AI coding agents, MCP servers, and agent histories create new software-security exposures. Researchers and practitioners warned that AI
AI-generated malware and botnets are moving from concept to production
Researchers reported multiple malware and botnet projects that show signs of LLM assistance, including TuxBot v3 Evolution and AI-generated PowerShell reconnaissance code. TuxBot w
Microsoft and security vendors rush to address AI-era attack surfaces
A broad set of vendors and researchers focused this week on how AI changes security operations, from agentic defense to prompt injection and AI-powered attacks. Microsoft, Google,
AI-assisted intrusions in government networks show how frontier models are changing cyber espionage
Researchers found an active Chinese intrusion campaign that used Claude Code and DeepSeek to automate parts of espionage operations against government systems and financial firms.

