AI-generated reports push GNOME to shorten its disclosure window

Volunteer maintainers of open source projects now receive a steady flow of security vulnerability reports produced with AI tools. Many arrive with no mention that a language model helped write them. The volume has grown enough that GNOME is revising th… Continue reading AI-generated reports push GNOME to shorten its disclosure window

The Windows 10 hangover is becoming a security problem

Windows 11 now runs on 78.8% of Windows devices after Microsoft ended support for Windows 10 on 14 October 2025, according to Lansweeper. Windows 10 still accounts for 16.9% of devices and no longer receives security updates, leaving newly discovered v… Continue reading The Windows 10 hangover is becoming a security problem

Meet Dusseldorf, Microsoft’s open-source out-of-band security platform

Out-of-band vulnerabilities surface when an application quietly reaches out to an external system during an attack, and capturing that traffic calls for infrastructure that many researchers assemble on their own. A new open-source project from Microsof… Continue reading Meet Dusseldorf, Microsoft’s open-source out-of-band security platform

Product showcase: ZoneAlarm Mobile Security adds customizable content filtering to mobile security

ZoneAlarm Mobile Security is a security app from Check Point designed to protect mobile devices against phishing, malicious websites, unsafe networks, and fraudulent links. It is available for iPhone, iPad, Android, and can run on Apple silicon Macs th… Continue reading Product showcase: ZoneAlarm Mobile Security adds customizable content filtering to mobile security

Nearly half of open-source AI projects never reach production

Open models are moving into production across more organizations, and the work of securing those deployments increasingly extends beyond the model weights. Mozilla’s The State of Open Source AI 2026 identifies deployment, governance and operational too… Continue reading Nearly half of open-source AI projects never reach production

Week in review: High severity WordPress vulnerabilities, fake OAuth IDs bypass sign-in logs

Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Two new high severity WordPress vulnerabilities, patch immediately! The 7.0.2 WordPress security release addresses one critical and one high severity secu… Continue reading Week in review: High severity WordPress vulnerabilities, fake OAuth IDs bypass sign-in logs

Claude can now sign into websites with 1Password without exposing your credentials

1Password has introduced 1Password for Claude, a beta integration that lets Anthropic’s AI assistant complete browser tasks requiring authentication without accessing users’ passwords or other secrets. The integration is available to paid C… Continue reading Claude can now sign into websites with 1Password without exposing your credentials

Prompt injection is becoming the XSS of the web agent era

Autonomous web agents read whatever a page displays, and much of that content comes from strangers. Product reviews, seller listings, and advertisements sit beside trusted site menus on a single page. An agent that reads all of that text as instruction… Continue reading Prompt injection is becoming the XSS of the web agent era

A hard drive reliability check on 341,263 drives, from 4TB to past 20TB

Large cloud storage operators track their hard drives every day, recording which units keep running and which ones drop off the racks. Backblaze does this at scale, and its Q1 2026 report covers a fleet built for continuous use. The analysis covered 34… Continue reading A hard drive reliability check on 341,263 drives, from 4TB to past 20TB