A harmless-looking symlink in a Git repo can redirect a tool into reading or writing anywhere on your machine. That old trick is now showing up in AI coding assistants, with nasty results.
System prompts form the foundation of generative AI applications. A system prompt is a collection of instructions and operational context provided to a large language model (LLM) that shapes how the model behaves and interacts with users and tools. System prompts often contain proprietary information, including role definitions, behavioral guidelines, tool descriptions and usage instructions,
Microsoft’s Secure Future Initiative (SFI) aims to define and meet security requirements for a well-defended cloud service. This involves not only setting the standards but also continuously assessing live services to ensure they comply, particularly in the context of rapidly evolving artificial intelligence. The initiative emphasizes proactive measures to strengthen cloud security against emerging threats.
Cloud security Insights | Microsoft Security Blog
·
Over a dozen major economies have now published post-quantum cryptography (PQC) adoption guidance. As a CISO, you’re probably well into your migration plan and know the most difficult part has little to do with changing algorithms. The real leadership challenge is driving coordinated change across a large, complex organization where asymmetric cryptography is embedded in
AI agents and large language models (LLMs) are transforming software development by building, analyzing, and deploying code throughout the lifecycle. As AI increasingly shapes software supply chains, it is crucial to implement proactive security measures and access controls. To govern authentication and permissions effectively without hindering development speed, organizations must revise their access management strategies, ensuring the security of AI-driven processes.
With the introduction of models that require data sharing with third-party providers—such as Claude Fable 5—organizations need a way to centrally enforce data retention policies. Amazon Bedrock gives you control over whether your prompts and model outputs are retained after an inference request completes. You might need a way to enforce your retention settings across
AI agents are changing how software gets built, but the infrastructure around them hasn’t caught up. Agents burn through tokens on noise. They take actions they shouldn’t. Context evaporates between releases. And most delivery pipelines were never designed for the pace and volume of agentic development. On June 11th we brought together developers in San
CISA has added a new vulnerability, CVE-2026-48282, related to Adobe ColdFusion, to its Known Exploited Vulnerabilities (KEV) Catalog due to signs of active exploitation. This type of vulnerability is often targeted by cybercriminals and poses significant risks for federal agencies. Binding Operational Directive (BOD) 26-04 mandates federal agencies to prioritize high-risk vulnerabilities in their remediation efforts. Although this directive is for federal agencies, CISA urges all organizations to adopt similar risk-based vulnerability management strategies. Organizations can also submit exploited vulnerabilities for potential inclusion in the KEV Catalog.
Hitachi Energy has identified a buffer overflow vulnerability in their e-mesh EMS products, specifically in versions 4.1.6, 4.4.2, and 4.7.0. Exploiting this vulnerability could lead to denial of service or arbitrary code execution. The issue arises from an NGINX vulnerability linked to the ngx_http_rewrite_module, affecting systems with ASLR disabled. Users are advised to update NGINX to version 1.30.2 or newer and follow specific mitigation steps. This advisory is part of an ongoing effort to improve cybersecurity in critical infrastructure sectors, particularly in the energy domain.
Hitachi Energy has identified a vulnerability in the PROMOD V product line that relies on insecure HTTP communication instead of HTTPS. This flaw allows potential attackers to intercept sensitive data, risking credential theft and unauthorized access. Versions affected include PROMOD V 1.0.10 and older. Users are urged to upgrade to version 1.0.11 and implement HTTPS on the Digipede server for remediation. CISA recommends minimizing network exposure and implementing strong cybersecurity practices to safeguard these systems.