AI Security Project Genie and Genie 3: interactive AI worlds
Google released Project Genie to US AI Ultra users. How text and images become interactive worlds, and how a world model differs from video generation.
Daily news, analysis and practical guides explaining what happened, who is affected and what to do next. We also turn this knowledge into practical training for organisations.
AI Security Google released Project Genie to US AI Ultra users. How text and images become interactive worlds, and how a world model differs from video generation.
Vulnerabilities and CVEs Technical analysis of critical FortiCloud SSO CVE-2026-24858: attack conditions, affected Fortinet products, persistence accounts, logs and response.
AI Security Technical Kimi K2.5 analysis: 1T/32B MoE, 15T multimodal tokens, MoonViT, 256K context, native INT4, Agent Swarm and deployment controls.
AI Security Technical analysis of Claude's 2026 Constitution: Constitutional AI, value hierarchy, rule reasoning, CC0, evaluations, instruction conflicts and governance.
AI Security Mistral documented an RSS leak in vLLM disaggregated serving, NIXL and UCX. Heaptrack missed it; pmap, eBPF and targeted GDB found the cause.
AI Security OpenAI contracted 750 MW of low-latency Cerebras capacity through 2028. What wafer-scale inference, accelerator portfolios and response-time economics mean.
Threats and Incidents Microsoft and law enforcement disrupted RedVDS. We analyse 7,300 IPs, homoglyph domains, a shared Windows image and behaviour-based cybercrime detection.
Vulnerabilities and CVEs Technical analysis of CVSS 10 n8n Ni8mare: vulnerable form workflow, local file read, possible chains, detection, remediation and automation hardening.
AI Security OpenAI launched ChatGPT and API products for healthcare. We analyse BAAs, PHI controls, evidence retrieval, physician testing and clinical deployment risk.
Human Security Microsoft documented internal-looking phishing enabled by complex mail routing and weak spoof protection. A technical analysis of headers, DMARC and connectors.
Threats and Incidents 2025 was a record year for Poland: attacks on hospitals, DDoS on infrastructure and disinformation. We summarise the threats and lessons for businesses.
Vulnerabilities and CVEs CVE-2025-55182 React2Shell is a CVSS 10.0 unauthenticated RCE. Affected React and Next.js versions, public PoC, attacks and patches.
Vulnerabilities and CVEs CVE-2025-64446 (CVSS 9.4) lets unauthenticated attackers run FortiWeb admin commands. Public PoC, KEV, versions, hunting and fixes.
Vulnerabilities and CVEs CVE-2025-59287 (CVSS 9.8) enables RCE in Windows Server Update Services. OOB patches, KEV, defensive PoC, detection and remediation.
Vulnerabilities and CVEs CVE-2025-61882 (CVSS 9.8) enables unauthenticated code execution in Oracle EBS 12.2.3–12.2.14. PoC, IOCs, patches and threat hunting.
Once a month, a concise summary of the vulnerabilities and threats that matter. No spam, unsubscribe anytime.