Microsoft MDASH preview ties 100 agents to Defender validation
Microsoft expanded MDASH preview at Build 2026 with 100+ agents, Defender integration, and vulnerability validation claims.
Vulnerabilities, prompt injection, model safeguards, and containment design.
Microsoft expanded MDASH preview at Build 2026 with 100+ agents, Defender integration, and vulnerability validation claims.
Claude Code 2.1.161 redacts MCP secrets, while 2.1.160 adds approval prompts before edits to shell, Git, and build-tool configuration.
A SOUPS 2026 paper observed that AI coding assistants push security from upfront requirements into after-the-fact review.
Anthropic expanded Project Glasswing to about 150 new organizations. The hard part is shifting from Claude Mythos findings to validated disclosures, patches, and deployments.
The White House AI security order ties CISA guidance, a Treasury-led vulnerability clearinghouse, classified cyber benchmarks, and pre-release frontier model access into 30-day and 60-day deadlines.
Adafruit published a Flux.ai demand letter dispute. The real builder question is how AI PCB tools prove provenance, data boundaries, and human review.
PromptArmor disclosed an indirect prompt injection chain in ChatGPT for Google Sheets. OpenAI responded by removing Apps Script generation.
NVIDIA added DOCA Vault, Argus, and Flow security controls to BlueField-4 STX, moving AI agent data policy into storage and DPU paths.
PromptArmor disclosed a ChatGPT for Google Sheets exfiltration path, and OpenAI removed Apps Script code generation.
Anthropic Project Glasswing says Claude Mythos Preview and partners can find vulnerabilities faster than teams can validate, disclose, and patch them.
CSA analyzed the Mini Shai-Hulud and Megalodon supply-chain campaigns, showing how npm attacks now reach AI coding settings and CI/CD authority.
Cursor and Endor Labs formalized a hooks-based security partnership for agentic coding, blocking package installs, MCP use, and risky commands inside the IDE loop.