Australia's AI opportunity starts with data
Elastic, a Founding Partner at Australia's first Parliamentary AI Industry Showcase, highlights that data, not just models, is the key to deploying safe, effective, and trusted AI.
September 17 , 2026CYBER SECURITY • SEPTEMBER 2026
Devops• Linux • Observability
Anthropic says Claude Mythos Preview helped derive an end-to-end key-recovery attack against HAWK-256 and a 200- to 800-fold speedup for an attack on seven-round AES-128. The HAWK attack exploits a previously unused symmetry in the lattice behind the signature scheme. Anthropic's released implementation gives an expected end-to-end runtime of about three hours and 42 minutes on a 96-core server
Læs artiklen →| Produkt | CVE'er | Kritisk | Handling |
|---|---|---|---|
| arista:velocloud_orchestrator | CVE-2026-16812 | 1 | Patch nu (7 dage) |
| linux:linux_kernel | CVE-2026-63795 | 0 | 30 dage |
| mozilla:firefox | CVE-2026-16367 | 0 | 30 dage |
| mozilla:thunderbird | CVE-2026-16367 | 0 | 30 dage |
| oracle:data_integrator | CVE-2026-47056 | 0 | 30 dage |
| oracle:coherence | CVE-2026-60217 | 0 | 30 dage |
| oracle:access_manager | CVE-2026-60358 | 0 | 30 dage |
| oracle:unified_directory | CVE-2026-60360 | 0 | 30 dage |
| oracle:http_server | CVE-2026-60365 | 0 | 30 dage |
| oracle:weblogic_server_proxy_plug-in | CVE-2026-60365 | 0 | 30 dage |
| Unknown / see vendor | CVE-2026-44359 CVE-2026-46412 | 0 | 30 dage |
Elastic, a Founding Partner at Australia's first Parliamentary AI Industry Showcase, highlights that data, not just models, is the key to deploying safe, effective, and trusted AI.
September 17 , 2026Kubernetes v1.37 brings important storage security features: emptyDir permission modes and bind mount options. They help application programmers and security professionals implement rigorous security policies, for example, prohibiting deletion of files across containers or execution of arbitrary binaries from writable volumes, directly in Kubernetes without any complicated circumvention. Linux storage and permission fundamentalsBefore diving into the new Kubernetes features, let us briefly review the low-level Linux security mechanisms that make them possible. Bind mount flagsWhen Linux mounts or remounts a directory, Virtual File System (VFS) flags control what actions are permitted on that filesystem: noexec: Do not permit direct execution of any binaries on the mounted filesystem. nosuid: Do not allow set-user-identifier or set-group-identifier bits to take effect
September 16 , 2026A critical security flaw in Issabel Framework, a web-based framework for the open-source unified communications PBX software, has come under active exploitation. The vulnerability in question is CVE-2026-89026 (CVSS v3.1 score: 9.8/CVSS v4.0 score: 9.3), which can allow an unauthenticated remote attacker to execute arbitrary operating system (OS) commands by taking advantage of a hard-coded
September 16 , 2026Enterprises in Russia have emerged as the target of three threat activity clusters tracked as NightEagle, Hacking Cat, and Toy Ghouls, according to multiple reports from Kaspersky. The cybersecurity vendor said it has identified attacks mounted by NightEagle (aka APT-Q-95), a threat actor known to be active since at least 2023, that involve new techniques for persistence and lateral movement.
September 16 , 2026Security researchers at Forever Security have shown that one ordinary browser extension could take control of the AI assistants built into five Chromium-based products: Gemini Live in Chrome, Perplexity Comet, Microsoft Edge, Opera Neon and the Claude in Chrome extension. Once the extension was installed, it could access each product's built-in AI with a single click. On Comet, Edge,
September 16 , 2026Mandiant says an attacker hijacked an active AI coding-assistant session at an unnamed software-as-a-service provider and later spread Shai-Hulud across about 100 internal code repositories. Before the repository spread, the assistant recommended software that the attacker had poisoned, and the recommendation was accepted. The worm stole repository secrets and source code for the
September 16 , 2026Parallels Desktop for Mac has a flaw that lets an ordinary local account run code as root, the highest level of access on a Mac, software company JFrog said this week. The attack needs code already running on the machine as a normal user, so it does not work over the network. JFrog says the fix is in Parallels Desktop 27, a version that Intel Macs cannot install. Yuval Moravchick, who leads
September 16 , 2026N0va is targeting organizations across North America and Europe with phishing campaigns that impersonate trusted services and abuse legitimate authentication flows. Successful attacks can give threat actors access to valid accounts without relying on obvious malware activity. From there, a single compromised identity can open the door to sensitive data, business systems, and additional cloud
September 16 , 2026Google has disclosed that a high-severity security flaw in its Pixel Cellular Modem has come under exploitation in the wild. The vulnerability, tracked as CVE-2026-58704 (CVSS score: 8.0), is a privilege escalation flaw. "In Cellular Modem, there is a possible permission bypass due to a logic error in the code," according to a description of the bug in the NIST National Vulnerability Database
September 16 , 2026A leaked credential shows up in a criminal marketplace, or a vulnerability gets a disclosure advisory, and either one can be weaponized against a real target before most security teams have triaged the alert. Attackers are combining that kind of intelligence with AI-assisted exploitation to accelerate the path from exposure to breach faster than most security programs are built to react.
September 16 , 2026Why is this running? Trace any process, port, container, or file back to what started it - CLI + TUI.
Free, local tool to track AI coding token usage and cost across 37 tools and agents (Claude Code, Cursor, Codex, Gemini and more), by model, project, and task. npx codeburn
End-to-end, code-first tutorials for building production-grade GenAI agents. From prototype to enterprise deployment.
Build your own AI SRE agents. The open source toolkit for the AI era.
Self-hosted TypeScript agent runtime with durable approvals and verifiable run records. Own it, approve it, audit it.
Open source, composable payments platform | PCI compliant | SaaS and Self-host options | Enables connectivity to multiple payment, payout, fraud, vault and tokenization providers | Uplifts authorization with intelligent routing and revenue recovery | Reduce payment processing costs with cost observability | Reduces payment ops with reconciliation
🪢 Open source agent evals & observability: Trace, evaluate, and improve LLM applications with one open platform.
Python SDK for Agent AI Observability, Monitoring and Evaluation Framework. Includes features like agent, llm and tools tracing, debugging multi-agentic system, self-hosted dashboard and advanced analytics with timeline and execution graph view
AI Agent Engineering Platform built on an Open Source TypeScript AI Agent Framework
An opinionated GoLang framework for accelerated microservice development. Built in support for databases and observability.