Corporate America has been gung-ho about AI, but it hasn’t brought all employees up to speed on how to use it safely. The result is that many employees may be playing fast and loose with company data.
The Missing Link in Agent Infrastructure Following its introduction of the Credentials API, which established a secure egress proxy for sensitive secrets, Google has released the ...
Can You Estimate a Roof Using Only Public Data and Public APIs? A Weekend Experiment with Solar API and PLATEAULast week, I ...
Exploiting Unauthenticated API Gateways in AWS September 21, 2026 sara.pearlman@guidepointsecurity.com BLOG  5 min. Over the past year, GuidePoint’s Threat and Attack Simulation (TAS) team has ...
Claude Code has stopped billing part of its own safety machinery, but only for some accounts. Version 2.1.278, released on September 19, changes auto mode ...
Browser AI agent security research: security researcher Gal Weizman of Forever Security demonstrated that one ordinary browser extension can hijack AI agents in Chrome, Edge, Perplexity Comet, Opera ...
OpenAI has published six reports on its own models misbehaving, including one that used a leaked API key without permission ...
A Brevo supply-chain attack used compromised Cloudflare access to inject malware into websites, potentially affecting over ...
This article is a memo summarizing the numerous pitfalls I encountered when trying to integrate the Google Calendar API into ...
A Colorado Springs School District 11 employee has filed a civil complaint against the district's superintendent and ...
Brevo confirmed that attackers stole a Cloudflare API key and used it to inject malicious ClickFix scripts into its websites ...