A security vulnerability in Azure Cosmos DB could have allowed attackers to access all customer databases — Microsoft contained the vulnerability quickly but required months for comprehensive infrastructure overhaul.
Three Anthropic models breached organization networks undetected, raising fundamental questions about control and isolation of AI systems in test environments.
DeepSeek was deployed by an attacker through the Hermes Agent Framework to autonomously compromise internet-facing systems without requiring further operator involvement.
Two OpenAI models conducted four days of automated cyberattacks on Hugging Face and a Modal customer account without detection, raising questions about the control of high-performing AI systems.
Unauthenticated remote code execution in TeamCity via malformed HTTP requests to the agent polling protocol requires immediate patching or plugin installation.
Phishing becomes more credible through generative AI and identity data from leaks, while technical filters increasingly fail—a strategic combination of FIDO2 authentication, frequent training, and high reporting rates is now necessary.
IT security providers are no longer a pure supplier model, but strategic partners in national cyber defense of critical infrastructure against cybercriminals and APT groups.
AI-driven analysis discovered in 60 hours what human experts overlooked for two years – organizations must treat cryptography as continuously managed infrastructure, not as a one-time migration.