GitHub revamps bug bounty program with new VIP tier, payout changes

GitHub is changing its bug bounty program to reward higher-quality vulnerability reports and reduce low-effort submissions, including AI-generated reports. The changes will take effect on July 27, 2026. Reports submitted before that date will be honore… Continue reading GitHub revamps bug bounty program with new VIP tier, payout changes

Google’s Gemini 3.5 Flash Cyber becomes a vulnerability hunter

Google’s Gemini 3.5 Flash Cyber model finds, validates, and patches vulnerabilities before they can be exploited while helping mitigate broader misuse. It is part of a limited-access pilot program that will soon be available to governments and trusted … Continue reading Google’s Gemini 3.5 Flash Cyber becomes a vulnerability hunter

Security teams keep finding critical flaws after scheduled testing ends

Enterprise environments change between scheduled security assessments, leaving organizations with periods where new vulnerabilities can go undetected. Synack’s State of Continuous Security Validation report found that 95% of surveyed organization… Continue reading Security teams keep finding critical flaws after scheduled testing ends

AI can’t fix cybersecurity’s hiring problem

Organizations are redefining cybersecurity roles through workforce frameworks and placing greater emphasis on verified skills as AI and new regulatory requirements change hiring. The SANS 2026 Cybersecurity Workforce Survey found demand for specialists… Continue reading AI can’t fix cybersecurity’s hiring problem

Cloud operations become the next big role for agentic AI

Companies are using agentic AI to manage growing application environments, automate routine tasks, and support decisions. Business and IT leaders increasingly see the technology as part of cloud application management, according to Unisys’ AI &#0… Continue reading Cloud operations become the next big role for agentic AI

AWS wants GuardDuty to automate the first steps of threat investigations

Amazon GuardDuty investigation agent is now in public preview. The feature provides AI-powered investigations of GuardDuty findings, AWS accounts and AWS organizations, helping security teams reduce investigation time. During the public preview, the in… Continue reading AWS wants GuardDuty to automate the first steps of threat investigations

Open-source maintainers still work underfunded as sponsorship crosses $100 million

A maintainer patches a library late at night that ships inside thousands of products, and no invoice follows. Sebastián Ramírez and Caleb Porzio spent years in that position. Ramírez, known as tiangolo, builds tools that other Python projects depend on… Continue reading Open-source maintainers still work underfunded as sponsorship crosses $100 million

Nobody was checking the drives that encrypt your laptop

A drive ships with a label promising hardware encryption. You plug it in, set a password, and trust the chip inside to handle the rest. Millions of laptops and workstations run this way, on solid-state drives built to the TCG Opal2 standard. Milan Brož… Continue reading Nobody was checking the drives that encrypt your laptop