ELSEIF
Your brief EB
204 stories from 71 feeds 32 clusters Refreshed 7 minutes ago next pull 14:05

TOPIC

Security

Vulnerabilities, supply chain risk, and defensive engineering. We cover disclosures with enough detail to judge your own exposure, and skip the vendor scare copy that usually surrounds them.

12TODAY
8FEEDS
4mMEDIAN
FEEDS Vercel 10 Techmeme 10 Krebs on Security 6 Schneier on Security 6 Hacker News 4 Lobsters 3 IEEE Spectrum 3 LWN.net 3

SECURITY

Everything in Security.

01 555 -4

Security LWN.net

Security updates for Monday

Why it matters — Applying these updates helps mitigate known security risks in deployed systems. Engineers should prioritize the kernel and openssh patches, as they affect core system integrity and remote access. Keeping the .NET runtime and related libraries current reduces exposure in application environments.

1 feed
5 min
02 483 -2

Security Hacker News

EU rules on AI models become enforceable. What's going to change?

Why it matters — Teams deploying or building AI models for the EU market now face compliance requirements around training data transparency, copyright disclosure, and risk mitigation for frontier models. The regulatory burden may delay EU launches of new AI models and could require shifting resources from engineering to legal compliance.

2 feeds
6 min
03 478 -5

Security Docker

Docker AI Governance: Audit Logs, Now Where Your Security Team Already Works

Why it matters — Engineers can now audit agent behavior without building custom pipelines, because logs flow directly into the SIEM their security team already runs. Denied actions, which leave no trace in agent output, are recorded only at the enforcement point, giving teams visibility into what their controls actually block. This makes it easier to demonstrate compliance and approve agent deployments.

1 feed
5 min
04 455 -5

Security CNCF

Cortex completes OSTIF security audit

Why it matters — Operators running Cortex for multi-tenant observability data can now deploy a version with verified fixes for seven security findings, including six medium-severity issues. The audit specifically validated the confidentiality, integrity, and availability of tenant boundaries and cluster operations, which are critical for multi-tenant isolation.

1 feed
2 min
05 432 -4

Security Techmeme

Horizon3, whose AI penetration testing platform NodeZero helps find and exploit attack paths in production systems, raised a $250M Series E at a $2B valuation (Kate Park/TechCrunch)

Why it matters — The valuation more than triples the company's previous mark, signaling strong investor confidence in autonomous security testing tools. For teams operating production environments, it underscores a growing market for AI-driven platforms that continuously validate real attack paths rather than relying on static assessments.

1 feed
46 min
06 428 -2

Security Hacker News

Californians' data deletion requests, DROP, become enforceable Aug. 1

Why it matters — Systems handling California resident data must now process bulk deletion requests submitted through the state portal, as non-compliance carries a penalty of $200 per day per affected resident. The state regulator has already demonstrated a willingness to enforce these rules, having fined twelve data brokers for failing to register.

1 feed
3 min
07 405 -4

Security Techmeme

The EU's AI Act enforcement powers take effect, letting it evaluate AI models before regional release, restrict market access, fine model providers, and more (Kai Nicol-Schwarz/CNBC)

Why it matters — For teams shipping AI models or model-powered products into the EU, a new gate now sits between development and deployment: regulators can evaluate a model prior to release and, where needed, block or fine it. The change shifts some compliance burden from self-attestation toward regulator review, so release planning, documentation, and risk classification need to be treated as gating steps rather than after-the-fact paperwork.

1 feed
44 min
08 397 -4

Security Techmeme

Sources: South Korean AI chip designer DeepX raised a ~$29M Series D at a ~$2.2B valuation, and is in talks to raise ~$209M at a ~$2.4B valuation by September (Yoolim Lee/Bloomberg)

Why it matters — The valuation jump to roughly four times its previous level signals strong capital interest in alternative AI hardware vendors. If the larger raise succeeds, it would provide DeepX the resources to scale production, potentially offering engineers new silicon options for AI workloads.

1 feed
42 min
09 396 -4

Security ZDNET

How Google used AI agents to find and fix 1,072 Chrome security bugs - in 60 days

Why it matters — With billions of users relying on Chrome, faster vulnerability detection reduces the window for attackers to exploit flaws. The AI‑driven workflow cuts weeks of manual analysis, freeing developer resources and enabling more frequent security updates. This shift may lead to a twice‑weekly patch cadence to maintain protection at scale.

1 feed
11 min
10 332 -1

Security Hacker News

Show HN: Bor – Open-source policy management for Linux desktops

Why it matters — For teams managing Linux desktop fleets, Bor now covers more of the policy surface—email clients, an enterprise browser, and host firewalls—reducing the number of separate configuration tools needed. The security hardening and per-action RBAC make it more viable for production deployments where auditability and least-privilege admin access matter.

1 feed
5 min
11 302 -2

Security Techmeme

Two independent teams used GPT-5.6 Sol Ultra on the same quantum cryptography problem, filing papers 3 hours apart, raising questions about scientific credit (Peter Hall/Scientific American)

Why it matters — When powerful AI models can rapidly solve hard problems, the likelihood of simultaneous independent discovery spikes, and existing norms for assigning scientific priority break down. Researchers and institutions now face a governance gap: credit assignment, peer review, and preprint timing conventions were not designed for AI-accelerated parallel breakthroughs.

1 feed
54 min
12 271 new

Security LWN.net

Wednesday, July 29, 2026 Security Releases

Why it matters — Two of the High-severity flaws allow remote attackers to exhaust memory or trigger heap-use-after-free on any exposed HTTP/2 server without authentication. The Permission Model over-grant issue means workloads relying on --permission for filesystem sandboxing may have been allowing access outside intended allowlists.

2 feeds
6 min
13 268 -2

Security Techmeme

Sources detail the troubled development of Tencent's ambitious, GTA-like game Last Sentinel, which has burned hundreds of millions of dollars over six years (Jason Schreier/Bloomberg)

Why it matters — The scale of investment and timeline without a shippable product illustrates the risk profile of large-scale game development, where technical and organizational challenges can compound over years. For engineers, it's a case study in how ambitious scope and unclear direction can drain resources on a single project.

1 feed
57 min
14 257 -2

Security Techmeme

LLMs are moving from generating artifacts to creating hyper-custom worlds on demand, but still lack the ability to natively perceive and audit what they create (Andrej Karpathy/@karpathy)

Why it matters — For engineers, this means that as LLMs generate increasingly complex software environments, the models themselves cannot be trusted to verify the security or correctness of their output. Builders must implement external auditing and perception mechanisms to validate these hyper-custom worlds, as the generator cannot serve as its own auditor.

1 feed
55 min
15 242 -1

Security Lobsters

NativeScope — Open Source local Studio for React Native debugging

Why it matters — A local, open-source debugging tool gives React Native developers control and transparency over their debugging environment, which is relevant for security-conscious workflows where data should not leave the developer's machine. This assessment is based on limited information from a single source with no article body available.

1 feed
4 min
16 241 -2

Security Hacker News

CRM: An open-source, agentic-first CRM

Why it matters — Only one feed elseif tracks has carried this so far, so there is no independent corroboration yet. Read it as a single-source report.

1 feed
10 min
17 219 -1

Security Techmeme

Thoughts on Apple Upgrade; sources: MacBook Air is now facing shortages too; Apple wants to turn its future glasses and headsets into health and fitness devices (Mark Gurman/Bloomberg)

Why it matters — The hardware subscription model could shift how organizations budget for and manage Apple device fleets. MacBook Air shortages may delay procurement for teams standardizing on that hardware. Health and fitness positioning for future headsets and glasses signals Apple's direction for wearable compute platforms.

1 feed
37 min
18 203 new

Security Cloudflare

Post-quantum authentication to origins is now supported

Why it matters — This closes the authentication gap on the origin connection, protecting against quantum-computer impersonation attacks rather than just harvest-now/decrypt-later encryption threats. Engineers can configure fully post-quantum mutually authenticated TLS to their origins today, ahead of WebPKI standardization.

1 feed
13 min
19 174 new

Security OpenAI

Univé builds an AI-ready workforce

Why it matters — This case study illustrates one organization's approach to deploying AI at enterprise scale with governance structures in place. For teams rolling out AI tools, it underscores that responsible governance and employee engagement are part of the adoption strategy alongside the technology itself.

1 feed
4 min
23 169 new

Security LWN.net

Security updates for Thursday

Why it matters — Only one feed elseif tracks has carried this so far, so there is no independent corroboration yet. Read it as a single-source report.

1 feed
4 min
28 163 new

Security Lobsters

Apple Screen Sharing Pre-Auth RCE

Why it matters — This is a critical-severity bug requiring no credentials, no user interaction, and no target-specific knowledge—only that Screen Sharing is enabled. An attacker can pipeline a single TCP connection to bypass authentication and write a root crontab plus reverse shell, achieving root RCE within 60 seconds.

1 feed
7 min
30 160 new

Security GitHub

Don’t stop early: Case-folding source code at memory speed

Why it matters — For engineers building large-scale search or indexing systems, this approach demonstrates that case-insensitive matching can be performed at memory speed, removing a common computational bottleneck. It provides a concrete reference architecture for optimizing text processing pipelines where branching would normally limit throughput.

1 feed
2 min
31 160 new

Security Techmeme

This year's Defcon badges include Baochip-1x, an open source chip whose security is verifiable and that can also be used as a hardware security token (Kim Zetter/Wired)

Why it matters — An open-source chip whose security can be independently verified gives engineers a hardware security component they can audit themselves rather than relying on vendor assurances. If the design is truly open and verifiable, it provides a transparent alternative to proprietary hardware security tokens where trust is placed in the manufacturer.

1 feed
55 min
32 158 new

Security Schneier on Security

Facial Recognition at Madison Square Garden

Why it matters — The selective disabling of surveillance infrastructure demonstrates that technical bypasses exist and are applied based on client status, creating a tiered access model to privacy. Engineers should note that the capability to opt out of tracking is technically feasible but restricted to privileged actors rather than applied as a universal policy.

1 feed
1 min
37 149 -1

Security Vercel

Qwen 3.8 Max now available on Vercel AI Gateway

Why it matters — Engineers can route requests to this model through a unified API that handles retries, failover, and usage tracking with no markup on provider pricing. The gateway's Zero Data Retention support and API key budgets give teams control over data handling and cost limits when integrating the model into production workflows.

1 feed
2 min