Home About Black Hat Contact Essays Fireside Chats My Take News Alerts Q&A Reels RSAC Videocasts
 

Top Stories

 

News Alert: SpyCloud survey finds machine identity risks outpace defenses, exposing gaps in oversight

AUSTIN, Tex., Sept. 9, 2026, CyberNewswire – SpyCloud, the leader in identity threat protection, today released its annual SpyCloud Identity Threat Report, a survey-based study finding that non-human identities (NHIs) – the AI agents, service accounts, API keys, and authentication tokens that connect to internal systems – have become the most common route attackers take into the enterprise.

The survey found that compromised NHIs (31%) are nearly 2x as likely to be the primary entry point compared to phishing and social engineering (17%), the second-ranked answer. NHI-related misuse was also the most commonly reported identity-based event type at 42%, yet the vast majority of organizations aren’t watching for them. While 95% of organizations believe they have adequate visibility into AI- and NHI-related exposures, only 36% monitor them, making machine identities the least-watched category of identity risk in the report. Further amplifying the problem, 68% of organizations experienced an identity-based event in the same period, with those affected averaging eight events each.

Organizations typically maintain a clear inventory of their human workforce, but few extend that same visibility to the service accounts, API keys, and AI agents authenticating into their systems every day. These identities are provisioned for convenience and often hold real privilege, yet in most environments nobody owns them: a service account doesn’t get off-boarded, doesn’t rotate its own credentials, and doesn’t fail an MFA challenge, so once one is exposed it can stay usable for months.

News Alert: Reflectiz launches AI website testing, uses site context to find and verify flaws

BOSTON, Sept. 8, 2026, CyberNewswire — Reflectiz, the continuous web exposure management company, today launched a multi-agent penetration testing platform for websites. Multiple specialized AI agents discover, attack, and validate vulnerabilities across complex web environments, and because they start from an existing model of each site, they cover up to ten times more than conventional pentesting tools.

A pentest used to be an event. An engagement, a report, done. The report described a moment. The website kept going: login, checkout, payments, dozens of third-party scripts, all probed by attackers daily.

“Websites change every week and get pentested once or twice a year. That gap is where exposure builds up,” said Idan Cohen, CEO and co-founder of Reflectiz. “Teams need testing that keeps up with releases at a cost they can sustain, and trusted coverage of what was tested.”

Testing with site context

Reflectiz has spent a decade scanning thousands of production websites and holds a live model of each one: pages, scripts, third parties, domains, sensitive inputs, and behaviors. The pentesting agents add the attacker’s perspective to that same model.

News Alert: Link11 reports fewer but stronger DDoS attacks in Europe for the first half of 2026

FRANKFURT, September 3, 2026, CyberNewswire — Link11 has released its European Cyber Report for the first half of 2026, providing an overview of DDoS attack activity targeting European companies.

Although the number of DDoS attacks on the Link11 network decreased by 42 percent, the report records new highs for attack intensity across bandwidth, packet rate and cumulative data volume, indicating that attacks have become more targeted and intense.

Attack intensity hits records

Although the number of attacks decreased by 42 percent, record highs were reached in terms of attack intensity in every category. The highest measured bandwidth attack reached 2.3 Tbit/s—85 percent higher than the previous peak of 1.2 Tbit/s in the first half of 2025.

The packet rate followed the same pattern, reaching a new peak of 322 million packets per second — up 56 percent from 207 million packets per second a year earlier. Cumulative traffic also increased, rising from 438 to 705 terabytes over the six-month period — a 61 percent increase.

GUEST ESSAY: AI coding assistants are putting open source in your code without declaring it

By Mike Pittenger

For years, software teams have managed open source risk in two familiar forms: licensing obligations and known vulnerabilities. AI coding assistants introduce a third risk that is harder to see.

Related: Where SBOMs fall short

They can place open source snippets directly inside source files without declaring a package, updating a build file or adding anything to a software bill of materials.

These hidden dependencies expose a weakening assumption behind established software controls: that third-party code arrives through a declared component. When it does not, the Software Composition Analysis tools and SBOM processes organizations rely on may never see it.

Where trails break

When a developer uses an open source package, the package normally appears in a manifest or dependency file. That creates a trail. SCA tools can identify the component, check its license and known vulnerabilities, and include it in the resulting SBOM.

LW ROUNDTABLE: OpenAI’s test agents self-organized into a rogue swarm no one anticipated

By Byron V. Acohido

Hugging Face is where the world’s open-source AI models live. Not ChatGPT, Claude or Gemini, but the free engines anyone can download and build into their own products. More than two million of them, in one place.

Related: Hugging Face breach guardrails failure

The big models try to do everything. Most of the small ones on Hugging Face do one job apiece. Same machinery underneath — you ask in plain language, and the system brings machine learning to bear. The big ones do that for whatever you bring them. Most of the small ones do it for one task: reading X-rays, sorting insurance claims, flagging fraud in a payment stream. That is why there are two million of them.

A test breaks loose

In July, one of the big engines broke into the place where the small ones live. OpenAI, the company behind ChatGPT, wanted to know how good its own engine was at hacking. It built agents to find out — engines given a goal and left to pursue it on their own — and set them loose on a set of hacking problems inside a sandbox, a sealed computing environment with no way out to the internet. One of those agents got out anyway, reached the open internet and hacked into Hugging Face’s production systems. No person directed any of it.

News alert: Bright Security launches AI PT, AI-powered penetration testing that cuts weeks to hours

SAN RAFAEL, Calif., Sept. 1, 2026, CyberNewswire — As AI compresses the gap between vulnerability disclosure and exploitation to nearly zero, the new AI Pentesting Module gives security teams continuous, AI-driven penetration testing built on Bright’s proven dynamic testing engine, at a fraction of traditional cost.Bright Security, the AI-native application security company, today announced AI PT, its new AI penetration testing module. It finds, exploits, and proves real vulnerabilities the way a human tester would, at a fraction of the time and cost of a traditional engagement.

The launch responds to a rapidly closing window between disclosure and exploitation. Frontier AI systems built for security research, including Anthropic’s Claude Mythos and OpenAI’s Aardvark, can now discover and weaponize software flaws with little to no human involvement. Anthropic’s own research team recently used a similarly capable system to uncover more than 500 previously unknown high-severity vulnerabilities in widely used open-source software, flaws that had gone undetected for years. Independent research tracking more than 83,000 CVEs, compiled by Zero Day Clock, found that the typical gap between a vulnerability’s disclosure and its first exploit has fallen from roughly two years in 2018 to a matter of hours today. Separately, vulnerability-intelligence firm VulnCheck reports that more than a quarter of exploited flaws are now weaponized within 24 hours of going public.

MY TAKE: ChatGPT’s five-hour outage coincided with a model retirement its incident record omits

By Byron V. Acohido

Millions of people rely on ChatGPT Work. For more than five hours Monday, it would not run. I was one of the people watching it fail.

The trouble began at 8:04 a.m. Pacific and ran through the heart of the American workday. OpenAI declared recovery at 1:28 p.m. Its incident record lists elevated latency, elevated errors, a mitigation and a recovery. It names no cause, no scope and no count of who was affected.

So Tuesday morning I put the questions to the company’s own public-facing tool.

What surfaced was not in the incident record. Monday was also the day OpenAI retired GPT-5.4 and GPT-5.4 Mini from Codex and other work surfaces authenticated through a ChatGPT account. The company announced that change a month ago and gave customers ample notice. It did not mention the change once while its paid work product was failing.

And when I returned to a restored ChatGPT Work, my session opened on an engine I had never seen before, at a reasoning level I never use.