Weekly Security Briefings
A curated newsletter of what changed in software security this week, why it matters, and what to do about it.

September 9, 2026
The Bug That Waited Twelve Years
A missing authorization check sat in PostgreSQL's replication path since 2014, a Magento zero-day was exploited before Adobe could patch it, attackers moved into the Coder and JetBrains build systems, and an AI's 23,000 findings turned out to be 8% reviewed.

June 15, 2026
A Regulator Can Switch Off Your AI Model in an Afternoon
Anthropic took Fable 5 and Mythos 5 offline after a US export-control order. Senior engineers spent the week cleaning up AI-generated code, two package ecosystems got backdoored in plain sight, and ShinyHunters ran an Oracle zero-day through higher ed.

May 12, 2026
SLSA Cleared the Malware. Scanners Missed the Zero-Day. OpenAI Named What Comes Next.
Shai-Hulud's compromised npm packages passed SLSA Level 3 attestation checks. The framework certified the wrong thing. Google confirmed the first criminal AI-generated zero-day. LiteLLM was chained to root in three HTTP requests at Pwn2Own. AI infrastructure is now an attack surface.

February 25, 2026
Claude Code Security Spooked Wall Street. The npm Worm Should Have.
Claude Code Security erased billions in market cap over capabilities that already existed. A self-spreading npm worm hit 50,000 downloads targeting AI coding tools. Russian actors used commercial AI to compromise hundreds of firewalls.

January 21, 2026
AI Coding Tools Systematically Ship Security Flaws Your Scanner Won't Find | Jan 15-21
Tenzai research proves all 5 major AI coding assistants generate critical business logic flaws. Prompt injection hits Google Gemini, Microsoft Copilot, Anthropic MCP. Europe launches GCVE vulnerability database.
December 3, 2025
98% of Companies Deploy AI Agents, 79% Have No Security Policy | Nov 27 - Dec 3
98% of enterprises deploy AI agents but 79% have no written security policies. Fragmented tooling creates 4-week MTTR for critical vulnerabilities. AI coding tools becoming attack surfaces. $190M+ funding validates automated remediation.
November 19, 2025
Attackers Automated 90% of Operations with Claude AI | Nov 15-19
Chinese state-sponsored actors automated 90% of cyberattack operations using Claude AI while 30,000 EU organizations face December NIS2 compliance deadlines. Seven zero-days under active exploitation demonstrate ongoing response velocity gap.
November 12, 2025
50% of CISOs Report Security Burnout. GitHub Copilot Reports First CVE
50% of CISOs report burnout affecting breach preparedness while 80+ critical CVEs landed in one week. Operational capacity hits the wall as teams drown in alerts and patch volumes exceed human triage capacity.
































