SecurityZCode Uploaded Repositories Without Clear Consent — Z.ai Opens the ClientZCode packaged local projects for cloud uploads. Z.ai stopped the feature, deleted data and released the client source.September 24, 2026·2 min read▲—▼
SecurityPalo Alto Turns AI Red Teaming Into a Continuous ServiceUnit 42 continuously tests web apps, APIs and clouds with three model families, but has published no effectiveness data.September 22, 2026·2 min read▲—▼
SecurityNIST IR 8587 Sets New Limits for Cloud Identity Keys and TokensNIST and CISA detail protection, rotation and revocation for identity tokens used by cloud services and workloads.September 16, 2026·2 min read▲—▼
SecurityAnthropic: AI Agents Automate Attacks — Attribution Still Comes From the VendorAnthropic documents agentic attacks and 151 million exchanges attributed to Alibaba. The attribution is the vendor's own.September 11, 2026·2 min read▲—▼
SecurityGoogle: Attackers Built an Agentic Credential Campaign in Under Six HoursGTIG observed an AI-assisted campaign that, after cloud access, harvested thousands of credentials in under six hours.September 8, 2026·4 min read▲—▼
Cloud & InfraKubernetes 1.37 Gets Serious About Rootless: 'Enabled by Default' Still Does Not Mean RootlessKubeletInUserNamespace is now beta and its feature gate is enabled by default. Existing clusters do not suddenly lose host-root privileges — the actual user-namespace environment still has to be deliberately configured.September 6, 2026·6 min read▲—▼