Skip to content Skip to sidebar Skip to footer
Illustration for the Kimbodo News & Research briefing “How Supply‑Chain Worms and Token‑Jacking Steal AI Compute — and Practical Defenses for Your Production AI Stack” (AI Security & Cybersecurity).

How Supply‑Chain Worms and Token‑Jacking Steal AI Compute — and Practical Defenses for Your Production AI Stack

What Happened Recent incident analyses highlight two converging attack trends against AI and cloud development ecosystems: self‑propagating supply‑chain malware that harvests CI/CD credentials, and targeted theft of developer API keys to monetize AI compute. ChainDrop is an npm supply‑chain worm that infects packages and installers, extracts secrets from compromised GitHub Actions runners to…

Read More

Illustration for the Kimbodo News & Research briefing “AI Security & Cybersecurity — August 5, 2026” (AI Security & Cybersecurity).

AI Security & Cybersecurity — August 5, 2026

What Happened Recent defensive research and incident investigations expose three converging trends that matter for cloud, AI and developer security: CNAPP is being reframed as the unified control plane for cloud and AI risk, with risk‑based, multicloud attack‑path analysis and signal correlation across posture, runtime, identity, data, application and AI (Microsoft Defender for…

Read More

Illustration for the Kimbodo News & Research briefing “How to Stop Industrialized Zero‑Day Discovery and C2 Evasion: Practical Zero‑Trust + DevSecOps for AI Systems” (AI Security & Cybersecurity).

How to Stop Industrialized Zero‑Day Discovery and C2 Evasion: Practical Zero‑Trust + DevSecOps for AI Systems

What Happened Four recent findings change the security calculus for AI-driven systems and enterprise infrastructure. Expanded Zero Trust for AI: Microsoft released an AI‑focused Zero Trust Assessment and a DevSecOps Workshop that extends Zero Trust to AI, Security Operations and Infrastructure, adds 15 control groups (91 tasks) and introduces the AI Memory framework…

Read More

Illustration for the Kimbodo News & Research briefing “Prevent "Pass the Passkey" Account Takeovers — Harden Your WebAuthn/FIDO Implementations” (AI Security & Cybersecurity).

Prevent “Pass the Passkey” Account Takeovers — Harden Your WebAuthn/FIDO Implementations

What Happened Unit 42 disclosed a class of account takeover issues called "Pass the Passkey" that arise when relying parties fail to validate the WebAuthn/FIDO "User Verified" (UV) indicator on authentication assertions. When servers ignore the UV flag, passkey authentication can be reduced to a possession-only factor: attackers who obtain or replay credentials (for example…

Read More

Illustration for the Kimbodo News & Research briefing “How Travel Wi‑Fi Phishing and Developer Supply‑Chain Malware Are Being Weaponized — and What Businesses Should Do Now” (AI Security & Cybersecurity).

How Travel Wi‑Fi Phishing and Developer Supply‑Chain Malware Are Being Weaponized — and What Businesses Should Do Now

What Happened Targeted travel phishing and captive‑portal attacks A campaign tracked as CaptiveCrunch (Storm‑2945 / Midnight Blizzard) has been using AI‑augmented techniques to compromise corporate travelers through manipulated hospitality/shared Wi‑Fi. Attackers deploy captive‑portal DNS/HTTP manipulation and fake browser/OS prompts to push victims into device‑code/OAuth phishing flows and AitM credential pages. The objective is persistent access…

Read More

Illustration for the Kimbodo News & Research briefing “How to Harden Cloud and AI Systems Against Agentized, Model‑Driven and Application‑Level Attacks” (AI Security & Cybersecurity).

How to Harden Cloud and AI Systems Against Agentized, Model‑Driven and Application‑Level Attacks

What Happened Three concurrent trends have crystallized in recent industry work that change enterprise risk models: Platform vendors are operationalizing multi‑agent security workflows and expanding AI‑native protections across identity, data and runtime. Microsoft announced Project Perception — a coordinated red/blue/green multi‑agent system plus enterprise telemetry to run continuous end‑to‑end security workflows — and…

Read More

Illustration for the Kimbodo News & Research briefing “Ask Better Questions to Secure AI: Practical Defense-in-Depth for Production AI Systems” (AI Security & Cybersecurity).

Ask Better Questions to Secure AI: Practical Defense-in-Depth for Production AI Systems

What Happened Industry security research and vendor reports have converged on a simple conclusion: securing AI is a systems problem, not a one-off checklist. Modern guidance emphasizes starting with clear questions about what assets and outcomes matter, then layering controls across people, processes, technology, data and governance so intelligence turns into action rather than false…

Read More

How AI Agents Scale Vulnerability Discovery — Practical Defenses and an Implementation Blueprint

What Happened Security research groups and vendors have converged on a new reality: large language models (LLMs) and specialized agent workflows materially amplify both offensive and defensive vulnerability discovery. Independent projects show LLM-driven workflows can reproduce historic bugs, find new high‑severity issues, and produce actionable PoCs at scale when paired with tailored infrastructure. A concrete…

Read More

Illustration for the Kimbodo News & Research briefing “Why Businesses Must Treat Models as First-Class Attack Surfaces — and How to Build an AI Cyber Stack That Actually Works” (AI Security & Cybersecurity).

Why Businesses Must Treat Models as First-Class Attack Surfaces — and How to Build an AI Cyber Stack That Actually Works

What Happened Microsoft announced Project Perception, a purpose-built Cyber Stack for "the changed physics" of cybersecurity: a closed-loop, agentic Red/Blue/Green system that continuously perceives, reasons and acts across identities, endpoints, applications, data, clouds and AI systems while preserving human control. The design uses a frontier + specialized multi-model architecture with a shared, token-efficient security context…

Read More

Why Modern Email and Webmail Attacks Evade Classic Controls — and What Enterprises Should Deploy Now

What Happened Two recent, concrete threat observations illustrate where adversaries are focusing and how they are adapting around defensive actions. Email and collaboration abuse: Microsoft telemetry shows sustained, high-volume phishing and BEC activity driven by API/scripted campaigns, nested-EML/OAuth redirect chains that drop installers, large automated BEC blasts, Teams-based vishing, and continued credential-phishing dominance…

Read More

Preventing AI Model Theft, Poisoning and API Abuse: Practical Defenses for Enterprise Systems

What Happened Security teams and independent research groups have converged on a clear pattern: production AI systems are facing the same classes of threats as traditional software, plus a set of model-specific attacks. Public and commercial defenders — including Project Zero, Trail of Bits, Unit 42, HiddenLayer, Lakera, OWASP AI and MITRE ATLAS — have…

Read More

AI Security & Cybersecurity — July 17, 2026

Executive Summary Short summary: Multiple coordinated incidents and research reports in July 2026 show attackers exploiting software supply chains, agentic/AI contexts, living‑off‑the‑land techniques, in‑memory payloads and OT zero‑days to gain persistent, high‑privilege access. Defenders are responding with guidance on least‑privilege for AI agents, EDR/XDR detection, supply‑chain hygiene, and incident hunting/playbook updates. Key actionable mitigations include…

Read More