FR
live
archive

All articles

AI agent security can’t fit in human review anymore

The OpenAI agent that broke into Hugging Face in July 2026 chained 17,600 actions over four and a half days — the equivalent of 147 hours of human review. Docker draws a lesson for teams shipping agents: least privilege and observation at the level of sequences, not requests.

Medusa ransomware tops 500 critical infrastructure victims, CISA warns

On August 18, 2026, the FBI, CISA and HHS updated their joint advisory on the Medusa ransomware: more than 500 critical infrastructure victims since 2021, up from 300 in March 2025. Defenders need to patch the exploited flaws and segment networks before the gang does it for them.

AWS logs four incidents in four months, two on the same network path

Between May and August 2026, AWS suffered four notable reliability incidents, two of them on the same network path linking US-West-2 to the Seattle metro area — with the company still declining to confirm a shared root cause. Teams single-homed in us-west-2 need to audit their single points of failure before next quarter.

Gemini 3.7 Flash halves the price and closes in on frontier models

On August 14, 2026, Google shipped Gemini 3.7 Flash, its most intelligent workhorse model for coding and agents, at $0.75 per million input tokens — half the price of its predecessor, only three weeks later. For teams industrializing agentic coding, it is the value benchmark to lock in before the January 1, 2027 price hike.

ShieldFont poisons AI scrapers with nothing more than a font

In August 2026, two designers published ShieldFont, a webfont that renders readable text to humans while feeding a subtly scrambled version to scrapers that pull the raw HTML. For self-hosters running a blog or documentation, it is a nearly free technical defense — at the cost of search and accessibility tradeoffs.

Password spraying surges 155× in 2026 by slipping through MFA blind spots

Huntress measured a 155× increase in password spraying attacks in the first half of 2026, driven by an LSHIY campaign that generated 81 million login attempts in two weeks through the ROPC flow. Security teams must disable ROPC and extend MFA to every authentication flow, with no exceptions.

Type at least two characters.

↑ ↓ navigate ↵ open esc dismiss