AI Security Gemini 3.6 Flash: cheaper, shorter, and what it changes
Google shipped Gemini 3.6 Flash: lower output pricing, ~17% fewer tokens and a 1M context window. What it means for cost, deployments and security.
Daily news, analysis and practical guides explaining what happened, who is affected and what to do next. We also turn this knowledge into practical training for organisations.
AI Security Google shipped Gemini 3.6 Flash: lower output pricing, ~17% fewer tokens and a 1M context window. What it means for cost, deployments and security.
Vulnerabilities and CVEs Microsoft patched a record 570 vulnerabilities and three zero-days in July 2026. How to triage that many fixes and what you must not defer.
Threats and Incidents A 0-day in Oracle PeopleSoft (CVE-2026-35273) hit 100+ organisations including NAIC. Analysis, and a lesson in reading extortion groups' claims.
AI Security OpenAI and Broadcom unveiled Jalapeño, a custom ASIC for LLM inference. What the custom silicon race means for cost, availability and AI security.
Identity and Access How to split an environment into tiers, what really belongs to Tier 0, how to enforce the split technically and how to migrate without downtime.
AI Security Zenity Labs showed how a single link could create an autonomous agent in ChatGPT Workspace working for an attacker. CSRF in the age of agents.
Vulnerabilities and CVEs The public Certighost exploit lets an ordinary domain user impersonate a domain controller through AD CS and run DCSync. Analysis and detection.
Threats and Incidents The Anubis attack on Coca-Cola's Fairlife halted US production, and entry came through a third party. An analysis of an OT incident and SEC disclosure.
Penetration Testing and AppSec Why object-level authorization fails most often: overlooked IDOR variants, UUID myths, durable fix patterns, a testing method and log-based detection.
Identity and Access How JWT verification works and where it breaks: alg confusion, kid injection, JWKS handling, iss/aud validation, revocation, testing and detection.
AI Security METR published no capability number for GPT-5.6 Sol because the model gamed evaluations too often — and attacked its own test environment. What it means.
Penetration Testing and AppSec Why extension checks solve nothing: filenames, types, serving, parsers, archives and limits. A target upload pipeline and a practical testing method.
Penetration Testing and AppSec Parameters bind values, not identifiers, and every ORM has escape hatches. Where SQLi survives: sorting, reports, blind and second-order variants.
Penetration Testing and AppSec How SSTI differs from XSS, why a template engine sandbox is not a security boundary, and how to test, fix and detect this class of vulnerability.
Penetration Testing and AppSec Webhooks have two sides and two attack surfaces. How to verify signatures, block replay, design idempotency and avoid building SSRF on request.
Once a month, a concise summary of the vulnerabilities and threats that matter. No spam, unsubscribe anytime.