OpenAI is previewing Private Safety Processing, a system that flags patterns of AI misuse across sessions without OpenAI staff ever seeing customer prompts, aiming to close the gap between zero-retention privacy and abuse monitoring.
OpenAI is previewing Private Safety Processing, a system that flags patterns of AI misuse across sessions without OpenAI staff ever seeing customer prompts, aiming to close the gap between zero-retention privacy and abuse monitoring.
CVE-2026-55253 lets attackers inject MongoDB operators into LangGraph's checkpoint filters, letting one tenant's agent read another tenant's session memory.
Trend Micro found 14 npm packages hiding a Linux backdoor that connects to RedC2 4.0, a commercial C2 kit whose 'Red Agent' turns plain-English commands into post-exploitation actions.
A researcher found a path traversal flaw in the boot process of Apple's Private Cloud Compute, letting them redirect AI inference telemetry to a server they controlled. Apple fixed it and paid out its top bounty tier.
A critical prompt injection vulnerability in Upstash's Context7 documentation server, installed by millions of developers, has no documented fix four days after disclosure. Researchers say it may be a regression of a bug patched in February.