trampolim.net
PT EN

Trampolim · Technology weekly

The Week in Tech

Sections

Security

Everything this paper has published on Security, newest first.

49 stories · By Max · Security

Archive

August 2026

July 2026

Issue 13
July 20–26, 2026
Continuous code scanning only became viable when the cost fellThe core argument of Microsoft's product isn't finding more flaws. It's finding them sooner, because it can now run without pause.
Issue 12
July 13–19, 2026
Attack reaches Fairlife production and Coca-Cola halts a plantThe incident was disclosed in a regulatory filing. Intruders reached parts of the production environment, and US manufacturing stopped temporarily.
Issue 12
July 13–19, 2026
Healthcare software supplier breached, and the reach is two thousand hospitalsCraneware disclosed unauthorised access to part of its data environment. Its platform serves thousands of hospitals, clinics and pharmacies.
Issue 12
July 13–19, 2026
Call for investigation into a US federal security platformA senator warned that even unclassified data from the platform carries national security weight, including because it supports World Cup operations.
Issue 12
July 13–19, 2026
Data theft campaign keeps targeting corporate platformsThe same group active through the year added a pharmaceutical firm to its list. The target is always the system many share.
Issue 12
July 13–19, 2026
A single software supplier becomes a stop point for thousands of operationsThe healthcare software incident describes a risk that doesn't appear in any individual customer's assessment.
Issue 10
June 29 – July 5, 2026
Agency warnings and code auditing land in the same weekA joint statement on offensive capability and an open-source audit programme form one picture.
Issue 10
June 29 – July 5, 2026
Giving agents their own identity becomes a product categoryPer-action authorisation and identity-provider governance answered the same problem within weeks.

June 2026

Issue 09
June 22–28, 2026
Attack hijacks coding agents through error logs, and 85% failed the testThe technique injects instructions into monitoring data. The agent reads it as an order and executes on the developer's machine.
Issue 09
June 22–28, 2026
Audit-dedicated model finds 24 flaws in the Linux kernelThe Daybreak programme found privilege escalations and a critical flaw in a widely used proxy.
Issue 09
June 22–28, 2026
Agencies warn that game-changing security models are months awayThe joint statement came in the same period an executive order created pre-release review for advanced systems.
Issue 09
June 22–28, 2026
CrowdStrike ships continuous per-action authorisation for agentsThe proposal is zero standing privilege: the agent asks permission per action instead of carrying broad credentials.
Issue 09
June 22–28, 2026
Anthropic connects agent governance to an identity providerThe partnership lets customers control assistant use and tool access through a single layer.
Issue 09
June 22–28, 2026
Agents reach data nobody explicitly approvedResearch from the period shows agents inheriting the permissions of whoever configured them, with no scope of their own.
Issue 09
June 22–28, 2026
With no universal fix, the defence becomes process designResearchers recommend human review between untrusted data and agent action.
Issue 08
June 15–21, 2026
A free tool targets the blind spot exploited by autonomous AI attacksThe risk assessment covers a component present across much of corporate infrastructure.
Issue 08
June 15–21, 2026
Over a hundred security leaders petition against the model's removalA congressional deadline passed with no public response, and the company said it was serving almost no traffic.
Issue 08
June 15–21, 2026
Autonomous AI attacks move from research reports into product descriptionsA tool launched in the period explicitly names the threat as its reason to exist.
Issue 07
June 8–14, 2026
Anthropic issues a rare warning about its own modelThe company said its models may soon be too powerful to control.
Issue 07
June 8–14, 2026
An enterprise AI security layer arrives with exfiltration detectionThe package includes access control, multi-party approval and granular audit logging.
Issue 06
June 1–7, 2026
OpenAI restricts access to its cybersecurity-dedicated toolThe limitation anticipates the criterion that would guide regulatory decisions weeks later.

May 2026

Issue 04
May 18–24, 2026
A trojanised editor extension yielded access to 3,800 internal repositoriesThe attack harvested cloud credentials, package registry keys and AI tooling configuration files.
Issue 04
May 18–24, 2026
AI tooling configuration becomes a valuable target for attackersThe file holds interface keys and the list of what the assistant can reach.
Issue 04
May 18–24, 2026
A credential harvested from one machine works across many projectsThe number of repositories reached comes from missing expiry and missing scope.
Issue 03
May 11–17, 2026
Learning platform goes down during finals with a ransom note on screenThe system used by universities suffered a breach and an outage displaying a note to every user.
Issue 03
May 11–17, 2026
A security company has its source code repository accessedThe vendor serves more than 50,000 corporate and government customers. What leaked was the code itself.
Issue 03
May 11–17, 2026
Electronics manufacturer confirms attack with a claim of 11 million recordsThe group responsible claimed a data volume the company did not confirm.
Issue 03
May 11–17, 2026
Convenience chain notifies breach in franchisee document systemsAttackers reached the administrative repository holding contracts and partner documents, the system nobody treats as critical.
Issue 03
May 11–17, 2026
A supplier attack exposes the link nobody auditsCustomers assess their own systems and inherit the security posture of whoever they hired.
Issue 03
May 11–17, 2026
Patching instead of negotiating has a visible cost and is the right callRetaliation after the fix shows the pressure attackers apply once they lose leverage.
Issue 03
May 11–17, 2026
Security tools run with high privilege, which makes them better targetsAccess to a security vendor's code is worth more than access to an ordinary system.
Issue 03
May 11–17, 2026
The attacker's number and the company's confirmation rarely matchThe gap isn't accidental: each side has opposite incentives when publishing volume.
Issue 03
May 11–17, 2026
The year's campaign has a fixed method and interchangeable targetsThe same group appears across unrelated sectors, always targeting platforms many share.
Issue 02
April 27 – May 10, 2026
A security-dedicated variant ships in preview limited to vetted teamsThe format repeats the design a competitor adopted weeks earlier.
Issue 02
April 27 – May 10, 2026
Pharmaceutical firm detects an attack and reports containment nine days laterThe company identified the incident on May 4, with exfiltration confirmed.
Issue 02
April 27 – May 10, 2026
Vetting an organisation isn't vetting a useThe trusted access model the sector adopted has a structural blind spot.
Issue 02
April 27 – May 10, 2026
Regulated sectors have a shorter clock to come back onlineProduction under quality regulation doesn't restart on a technology decision.
Issue 02
April 27 – May 10, 2026
A limited preview buys time without resolving the underlying questionThe format defers the decision about broad release of sensitive capability.

April 2026

Book a call