Liquibase argues the AI governance industry is watching the wrong layer of the stack
Data Engineering
Bruno Digital · 17h ago

Liquibase argues the AI governance industry is watching the wrong layer of the stack

Citing incidents at Replit, PocketOS, OpenAI, and Anthropic, Liquibase argues enterprise AI risk lives in what agents can execute against production databases, not in which model they run on.

Researchers Found a Way to Trick AI Coding Agents Into Leaking Secrets, One Fragment at a Time
Cybersecurity·17h ago

Researchers Found a Way to Trick AI Coding Agents Into Leaking Secrets, One Fragment at a Time

The GhostSplice technique splits malicious instructions across separate MCP tool descriptions and results, pushing exfiltration rates on tested models from zero to one hundred percent once an AI agent stitches the fragments together.

Bruno DigitalRead news
The LiteLLM Supply Chain Breach Just Cost Six Major Enterprises Their Secrets
Cybersecurity·17h ago

The LiteLLM Supply Chain Breach Just Cost Six Major Enterprises Their Secrets

A poisoned Trivy container turned into a full CI/CD compromise at LiteLLM, and threat intelligence firm Hudson Rock traced the fallout to source code theft at Cisco, a 4-terabyte leak at Mercor, and 250-plus enterprise disclosures in total.

Bruno DigitalRead news
A China-Nexus Actor Turned a VMware vCenter Bug Into Root Access in Five Days
Cybersecurity·17h ago

A China-Nexus Actor Turned a VMware vCenter Bug Into Root Access in Five Days

CVE-2026-59310 gave attackers non-interactive root code execution on vCenter Server appliances, and a suspected China-linked group used it to plant backdoors, open reverse SSH tunnels, and drop Babuk-derived ransomware as cover.

Bruno DigitalRead news
Lazarus Group Is Exploiting a Windows Zero-Day to Hit Defense and Aerospace Firms
Cybersecurity·17h ago

Lazarus Group Is Exploiting a Windows Zero-Day to Hit Defense and Aerospace Firms

Microsoft's August Patch Tuesday closed a WinSock privilege escalation flaw that the North Korean-linked Lazarus Group had already weaponized to deploy the FudModule rootkit against defense contractors in four countries.

Bruno DigitalRead news
A Breach at One Logistics Vendor Is Now a Problem for Steam, ING, and Ten Retailers
Cybersecurity·1d ago

A Breach at One Logistics Vendor Is Now a Problem for Steam, ING, and Ten Retailers

A cyberattack at CEVA Logistics has rippled outward to a Dutch bank, a video game platform, and multiple European retailers, showing how one shipping vendor's breach becomes everyone's incident response problem at once.

Bruno DigitalRead news
One Attacker Fired Off 200,000 AI Requests in Two Minutes, CrowdStrike Finds
Cybersecurity·1d ago

One Attacker Fired Off 200,000 AI Requests in Two Minutes, CrowdStrike Finds

CrowdStrike's 2026 Threat Hunting Report shows AI has moved from a novelty in adversary toolkits to standard operating equipment, compressing the time between vulnerability disclosure and exploitation to under two days.

Bruno DigitalRead news
A Worm Moved Through Ten npm Packages With Two Billion Downloads a Month
Cybersecurity·1d ago

A Worm Moved Through Ten npm Packages With Two Billion Downloads a Month

A compromised maintainer account turned keyv, cacheable, and eight other widely used npm packages into a self-propagating credential harvester, and the exact count of infected downstream packages is still climbing.

Bruno DigitalRead news
Lazarus Turned a LinkedIn Job Offer Into a Windows Kernel Exploit
Cybersecurity·1d ago

Lazarus Turned a LinkedIn Job Offer Into a Windows Kernel Exploit

CISA gave federal agencies until August 25 to patch a Windows Winsock flaw that North Korea's Lazarus Group used to escalate from a fake recruiter's PDF to full system control.

Bruno DigitalRead news
An Actively Exploited N-able N-central Bug Just Made CISA's Watch List
Cybersecurity·1d ago

An Actively Exploited N-able N-central Bug Just Made CISA's Watch List

CISA confirmed active exploitation of an authentication bypass in N-able's N-central remote monitoring platform, and the attack path runs straight through the tool many MSPs use to manage every client endpoint they touch.

Bruno DigitalRead news
Amazon Signs a Global Supply Deal With AutoStore but Keeps the Purchasing Optional
Cybersecurity·1d ago

Amazon Signs a Global Supply Deal With AutoStore but Keeps the Purchasing Optional

Amazon and the Norwegian warehouse robotics maker struck a framework to supply automation worldwide, a deal AutoStore's record order backlog says is already paying off even without a single guaranteed Amazon purchase order.

Bruno DigitalRead news
GitLab Patches a Critical Unauthenticated Flaw That Attackers Exploited Within Days
Cybersecurity·2d ago

GitLab Patches a Critical Unauthenticated Flaw That Attackers Exploited Within Days

CVE-2026-19478, a maximum-severity code injection bug in GitLab's GraphQL layer, let unauthenticated attackers modify or delete public projects with zero clicks, and exploitation began before most self-hosted instances had patched.

Bruno DigitalRead news
A Hacker Selling 3.6 Million Azure Records Named McDonald's and Vodafone, and Two Victims Say the Data Is Old
Cybersecurity·2d ago

A Hacker Selling 3.6 Million Azure Records Named McDonald's and Vodafone, and Two Victims Say the Data Is Old

A threat actor going by TheHatman began advertising employee records from nine companies obtained through compromised Azure credentials, but Gap and Tata Consultancy Services say their data is stale and non-sensitive, not evidence of a fresh breach.

Bruno DigitalRead news