Skip to content
10M+
sites analysed
1046
insights published
25
frameworks tracked
8
regional editions
Recent intelligence All 1046 insights →
Security & Trust

June 2026: Six CVSS 9.8 Vulnerabilities. 1.14 Million WordPress Sites.

The AI-First Web

Claude bypassed limits on real sites; Anthropic cut web access for its tests

The AI-First Web

Meta's Muse agent limits what attackers can take, not what Meta can see

Security & Trust

In tests, AI-run decoy servers kept attack bots busy far longer than scripts

Security & Trust

A fake security workflow now mines whole git histories for credentials

The AI-First Web

Postman and AWS say missing context, more than missing tools, broke its AI agent

Innovation & Growth

Cloudflare's cheaper AI decision model can read less text per request

Security & Trust

Oratomic says 10,000 qubits could threaten encryption, not millions

Innovation & Growth

Bun 1.4.3 adds a type-check gate and enforces a flag it once ignored

Innovation & Growth

One AP News article set 618 cookies before the consent banner was answered

Security & Trust

GitHub Enterprise's secret scanner trusted the secrets it was checking

Security & Trust

A Snorkel AI researcher says big models stumble on finance data through poor discipline

Security & Trust

A Sentry engineer saw coding agents dodge lint rules and inflate coverage

Business Efficiency

AI agent harnesses are old workflow engines with the plan written later

Business Efficiency

A twice-a-year pen test leaves long gaps while code ships nonstop

Business Efficiency

AssemblyAI could not fix its bought support bot fast enough; it solved about 10%

Innovation & Growth

AI-built knowledge for coding agents should trace every fact to code or telemetry

Innovation & Growth

A small finance model trained for under $500 in compute beat its 235B sibling

Innovation & Growth

Turn the corrections you keep repeating to a coding agent into automatic checks

The AI-First Web

Anthropic's AI finds suspected bugs faster than its staff can check them

The AI-First Web

One missed swim-class rule shows the risk of AI errand agents

The AI-First Web

A copy trained on a hidden-flaw AI's answers confessed the flaw more often

Security & Trust

iRhythm says patient data was stolen from business apps, not clinical systems

Security & Trust

iVerify finds DarkSword iPhone variant that steals keychain and wallet data

Security & Trust

Attackers exploit AhsayCBS backup flaws; Huntress says 10.3.4 is affected

Security & Trust

WorkOS put app security in the platform so non-engineers can ship internal apps

Security & Trust

PraisonAI's localhost-only safeguard can be bypassed by a forged Host header

Security & Trust

Some malware now carries notes written for the AI tools that analyze it

Security & Trust

Apiiro: a 17,610-repo GitHub malware fleet was re-aimed, not rebuilt

Security & Trust

Malware aimed at Ukraine was reworked repeatedly, from July 2024 to April 2026

Security & Trust

Report: Oracle Health's old Cerner server breach may affect nearly 20 million

The AI-First Web

An AI model filed a false homicide tip, and its maker found out 2 months later

The AI-First Web

Only 3.6% of 857 releases from nine Chinese AI labs had safety results

The AI-First Web

AI refusal is a statistical habit, not a lock. Plan your controls around that

The AI-First Web

Engineers' skill shifts from writing workflows to constraining agent plans

The AI-First Web

AWS says its agent payments cap spending outside the AI model's control

The AI-First Web

Google's new Gemini work agent gets its own email and its own audit trail

The AI-First Web

Anthropic's Haiku 5.5 cuts short-prompt prices 90%, making agents cheaper

The AI-First Web

ChatGPT can now build its own interface for an answer, OpenAI says

The AI-First Web

Exposed LMCache servers can be taken over with one message; no fix yet

The AI-First Web

Google's EmbeddingGemma 2 puts video and audio search on the device

Business Efficiency

281 Free VPN Apps, 2.4 Billion Installs, One Shared Incentive Problem

Business Efficiency

Joomla Ships 644 Commits Per Year. It Still Carries 1,313 CVEs.

Business Efficiency

UpdraftPlus Auth Bypass: The WordPress Backup Plugin on 3 Million Sites Just Became the Attack Vector. Zero Authentication. An All-Zero Encryption Key. Actively Exploited.

Business Efficiency

WordPress Backup Plugins Require Admin Access

Business Efficiency

Kirki Plugin: 500,000 WordPress Sites Exposed to Admin Account Takeover via Password Reset