Logo
Search
HOME
ARCHIVE
SIGN IN
SUBSCRIBE
Logo
ALPHA

FEATURED


AI Agents Just Broke Into 440 Companies in 48 Hours

Sep 15, 2026

•

3 min read

AI Agents Just Broke Into 440 Companies in 48 Hours

A Russian-speaking threat actor pointed a swarm of AI agents at one PaperCut vulnerability — and beat human defenders to the finish line.

patch management

+6

Dennis Andrade
Dennis Andrade

THE LATEST


Sep 8, 2026

•

4 min read

Someone Just Minted Themselves Admin Access to Thousands of Companies

A JFrog Artifactory bug lets attackers skip login entirely — and mint admin tokens for the software supply chain thousands of companies run on.

Software Supply Chain

+6

Sep 1, 2026

•

3 min read

Someone Just Used AI to Break Into 10 Companies

A ransomware crew turned a free coding assistant into an attack tool — and it never knew the difference.

Software Supply Chain

+5

Aug 28, 2026

•

8 min read

I Won't Let My Kids on TikTok, Instagram Roblox. Here's the $400 Million Reason Why

An extra issue, off the usual format — on TikTok's $400M fine, Meta's $17.1B settlement, the Roblox lawsuits, and why I think age verification should be a condition of doing business, not a roadmap item.

tiktok

+9

TRENDING


Your AI Assistant Is Spying for Strangers

Your AI Assistant Is Spying for Strangers

Researchers turned Microsoft Copilot into a full reconnaissance tool using nothing but polite, innocent-sounding questions — and any AI assistant with broad access could do the same.

meta-hacking

+9

Firefox's Master Key Was Sitting on GitHub

Firefox's Master Key Was Sitting on GitHub

The signature that proves a Firefox update is real got exposed — and there's no way to know who saw it

Software Updates

+6

Your AI Login Isn't Yours Anymore

Your AI Login Isn't Yours Anymore

Stolen and resold AI accounts are turning shared logins into a surveillance channel nobody notices

Account Takeover

+6

Your Copilot Caught a Virus

Your Copilot Caught a Virus

A hidden instruction in one Word file just proved AI assistants will infect every document they touch next.

Microsoft Copilot

+7

Your AI Code Reviewer Just Approved Malware It Never Saw

Your AI Code Reviewer Just Approved Malware It Never Saw

A hidden comment in a pull request is all it takes to hijack the AI gatekeeper your team trusts to ship safe code

Zero Trust

+6

The Email That Convinced Your AI You're Allergic to Penicillin

The Email That Convinced Your AI You're Allergic to Penicillin

One email is all it takes to plant a permanent lie in your AI assistant's memory — and there's no patch coming, because it isn't a bug.

identity-security

+6

The 3-Minute Security Audit Every Developer Should Run Before AI Touches Their Code

The 3-Minute Security Audit Every Developer Should Run Before AI Touches Their Code

Symlink attacks, hallucinated packages, and prompt injection are turning your AI pair programmer into an attacker's easiest way in

NHI

+6

You Just Gave Microsoft Permission to Let Strangers Into Your Account. It Took Three Seconds

You Just Gave Microsoft Permission to Let Strangers Into Your Account. It Took Three Seconds

ConsentFix and ClickFix attacks are turning OAuth consent prompts into skeleton keys — no password theft, no MFA bypass required. Here's how they work and what to revoke today.

Microsoft 365

+6

SUBSCRIBE TO OUR NEWSLETTER

Practitioner intelligence on identity, AI agents, and enterprise trust.

Home

Archive

Subscribe

Sign Up

Login

Reset Password

Search

Profile

STAY CONNECTED

© 2026 Identity Decoded.
beehiivPowered by beehiiv