Your Browser Should Not Be an Authentication Boundary for AI Infrastructure

Ray CVE-2025-62593 turns a malicious browser visit into AI infrastructure code execution. Patch Ray and replace browser trust with authentication.
Artificial intelligence, local AI, agents, tooling and AI security.

Ray CVE-2025-62593 turns a malicious browser visit into AI infrastructure code execution. Patch Ray and replace browser trust with authentication.

A Grok proof of concept turned encrypted content from an untrusted webpage into trusted runtime instructions, then used an outbound request to expose private session data.

An AirTag led journalists to an Amazon operation that reportedly cuts apart printed books for AI training. Purchasing a copy may establish ownership of the object. It does not settle what technology companies owe authors, readers and the cultural record.

Cisco Talos found UAT-10147 using agentic AI to scale exploitation and post-compromise work across a target list containing approximately 170,000 web-server URLs.

WordPress fixed a pre-auth reflected XSS that can be chained to server-side code execution when a logged-in administrator is drawn into the attack. The chain is contextual, but the update is urgent.

Attackers are exploiting MLflow CVE-2026-64849 to turn exposed AI engineering services into a route to cloud metadata, internal systems and workload identity.

Microsoft Paint and Photos embed server-issued identifiers into locally generated AI images, joining remote moderation, pixel watermarking and C2PA provenance.

Apple has moved fixes from next-generation betas into current systems. AI is shrinking the time enterprises have to test, approve and deploy patches.

The most important cybersecurity feature in a new AI model may not be how well it performs. It may be who can run it. Chinese AI company Z.ai says its GLM-5.3 model achieved 84.5% on CyberGym, slightly above Anthropic Mythos…

Google found an agentic attack framework managing more than 23,800 harvested secrets. In a separate operation, another framework built and launched a credential campaign in under six hours.