
AI is finding vulnerabilities faster than anyone can patch them. Now what?
Project Glasswing and Claude Mythos Preview reveal a surge in zero-days. Learn why reactive patching fails and how secure-by-default supply chains keep you safe.
2432 articles

Project Glasswing and Claude Mythos Preview reveal a surge in zero-days. Learn why reactive patching fails and how secure-by-default supply chains keep you safe.

AI can find vulnerabilities at scale, but enterprise security now depends on control, validation, and governance that can keep up.

Is Grype a single point of failure? Learn how Chainguard uses layered defenses, source builds, and multiple data sources to ensure trusted CVE detection.

Google has announced the public availability of Device Bound Session Credentials (DBSC) for Windows users on Chrome 146, with macOS support coming soon. This initiative aims to combat session theft, which typically occurs when malware extracts session cookies from browsers. DBSC works by cryptographically binding authentication sessions to specific devices using secure hardware modules, ensuring that exfiltrated cookies quickly expire and become unusable. The protocol is designed to prioritize user privacy, preventing cross-site tracking. Google collaborated with the web community on DBSC’s development and plans to enhance its capabilities for enterprise environments and broader device support in the future.

Open source attacks are rising. Chainguard Libraries rebuilds packages from verified source to block malware—now free until June 30, 2026.

Five supply chain attacks in 12 days exposed a broken trust model. Learn why scanning and hardening fail, and why trusting the source is the only fix.

Chainguard is deprecating SecDB in favor of OSV, delivering more accurate, granular vulnerability data and better visibility for modern software supply chains.

AI is accelerating code and attacks. Learn why patching alone can’t keep up, and why securing the software supply chain starts with trusted inputs.

Announcing Snyk Container Registry Sync GA for automated image management and runtime intelligence. Scale container security effortlessly for the fast-paced AI era.

Modern supply chain attacks target CI, dev machines, and dependencies. Learn how building from source helps prevent malware and reduce risk.

Adam Gavish from Google’s GenAI Security Team discusses indirect prompt injection (IPI) as a growing threat to AI applications like Workspace with Gemini. Attackers can manipulate AI behavior by embedding malicious instructions within data sources, sometimes without user input. Google employs a multi-faceted strategy to enhance defenses against IPI, including proactive attack discovery, red-teaming simulations, a vulnerability rewards program, and synthetic data generation. They focus on improving LLMs to better identify harmful commands while ensuring operational efficiency. Ongoing defense refinement involves updating configurations, retraining models, and extensive testing to validate improvements. Google’s commitment to AI security emphasizes a robust, agile response to evolving threats, aiming to provide a safe user experience in AI-first environments.

The LiteLLM compromise showed AI risk extends beyond dependencies. Use Evo AI-SPM to map your full AI blast radius, securing connected models, tools, and agent workflows.1