The security intelligence platform for AI teams
AI security threats move fast and get buried under hype and noise. Built by an Information Systems Security researcher to help security teams and developers stay ahead of vulnerabilities, privacy incidents, safety research, and policy developments.
OpenAI Launches Codex Security AI Agent for Vulnerability Detection: OpenAI deployed Codex Security, an AI-powered agent that scans code repositories for vulnerabilities; during beta testing it identified 792 critical and 10,561 high-severity issues across 1.2 million commits with false positive rates dropping over 50%.
Critical SSRF Vulnerability in PinchTab Browser Control Server: CVE-2026-30834 is a high-severity Server-Side Request Forgery flaw in PinchTab (pre-0.7.7), an HTTP server that gives AI agents Chrome browser control; the /download endpoint allowed arbitrary requests to internal network services and potential exfiltration of sensitive data.
Anthropic and Pentagon at Odds Over AI Weaponization Safeguards: Anthropic refused to remove safety restrictions on Claude AI for military use, specifically blocking domestic mass surveillance and autonomous weapons capabilities; the Pentagon designated Anthropic a supply chain risk in response, while Anthropic vowed legal challenge, raising critical questions about AI governance in defense applications.
Anthropic's Claude Model Discovers 22 Firefox Security Flaws: Anthropic identified 22 previously unknown vulnerabilities in Firefox (14 high-severity) using Claude Opus 4.6 during a two-week security partnership with Mozilla, demonstrating AI agents' effectiveness at discovering complex security issues in mature codebases.
OpenAI robotics lead Caitlin Kalinowski resigned in protest of the company's Pentagon agreement, citing concerns about rushed governance and insufficient safeguards against domestic surveillance and autonomous weapons. OpenAI responded by stating its agreement includes red lines against domestic surveillance and autonomous weapons, supported by both contract language and technical safeguards, while committing to continued engagement with stakeholders on these issues.