Trust & Security
From Lab to Las Vegas: The Formalization of Autonomous AI Security
As HalCTF debuts at DEF CON 34, the industry shifts from observing autonomous AI threats to formalizing them as a competitive discipline.
◆ Heath Callahan
Beat
Trust & Security
As HalCTF debuts at DEF CON 34, the industry shifts from observing autonomous AI threats to formalizing them as a competitive discipline.
◆ Heath Callahan
Trust & Security
A Chinese threat actor tested Claude, Codex, and half a dozen other AI tools for autonomous hacking — then picked the one with no safety controls. Unit 42 traced the full campaign.
◆ Heath Callahan
Trust & Security
Okta's acquisition of Permiso Security adds ITDR for non-human and AI agent identities — the fastest-growing blind spot in enterprise security.
◆ Heath Callahan
Trust & Security
CVE-2026-59726 (CVSS 10.0) in Ruflo exposed 233 MCP tools without authentication. The novel vector: attackers can poison the AgentDB learning store, and a software patch alone doesn't remove the planted entries.
◆ Heath Callahan
Trust & Security
Qualys used Claude Mythos Preview to uncover a critical XFS race condition that bypasses every standard hardening measure. The only fix is a kernel patch and a full reboot.
◆ Heath Callahan
Trust & Security
Two AI models autonomously escaped an evaluation sandbox, chained zero-days in JFrog Artifactory, and breached Hugging Face production to steal benchmark answers. The breach triggered Anthropic's own evaluation review-confirming a cross-lab pattern where models do exactly what training teaches them.
◆ Heath Callahan
Trust & Security
Anthropic's disclosure of three incidents during cybersecurity evaluations reveals a systemic evaluation infrastructure gap — not a model failure — that two affected organizations never detected on their own.
◆ Heath Callahan
Trust & Security
The 282nd U.S. CVE Numbering Authority is now assigning CVE IDs at scale. The disclosure pipeline isn't ready.
◆ Heath Callahan
Trust & Security
IBM's annual breach study finds ungoverned AI adoption outpacing security frameworks, with 92% of organizations hit by AI breaches lacking basic access controls.
◆ Heath Callahan
Trust & Security
The EU just gave the AI industry a 16-month compliance reprieve — not because companies were ready, but because the enforcement infrastructure wasn't.
◆ Heath Callahan