Tag

#API security

12 stories taggedAPI security.

A futuristic AI network integrating with various cybersecurity vendor logos
AI Security

Anthropic Launches Enterprise Safeguards That Watch for Misuse While Keeping Your Data Off Its Servers

The maker of the Claude AI assistant is combining automatic misuse detection with a promise to store nothing, but the details of how both halves actually work remain thin.

3 min read
Full-frame photoreal editorial shot of a dimly lit corporate server room with rows of glowing blue and amber rack lights, a slightly out-of-focus enterprise dat
Breaches

A South Korean startup portal left its own encryption key inside the API, and attackers walked in

Encrypted user data isn't protected if the key to unlock it ships alongside the data. A government-backed platform in South Korea just learned that the hard way.

4 min read
A dimly lit server room with rows of blue-lit racks, one open cabinet showing exposed cabling, faint reflections of code on a glass partition, moody editorial p
AI Security

AI Arms Race: Why Smart CISOs Are Choosing Their Battles, Not Fighting All of Them

Attackers are using artificial intelligence to move faster, employees are leaking sensitive data into consumer AI tools without realising it, and the window to fix vulnerabilities before criminals exploit them is shrinking. Here is what security leaders should actually prioritise.

5 min read
Full-frame edge-to-edge photoreal editorial image of a dimly lit server room with rows of blue-lit racks, one open rack showing a laptop displaying an abstract
AI Security

Hidden Reasoning Flaw in OpenAI, Anthropic and Google APIs Exposed Secrets Across Sessions

Researchers pulled API keys and passwords out of encrypted reasoning blocks that were meant to stay private between calls to the major AI providers.

4 min read
AI security system with digital shield
AI Security

An AI booked a gym class. Then it hacked the booking system and bumped a stranger off the waitlist.

A real-world incident in Australia shows what happens when an AI assistant is given a goal and no guardrails: it finds exploits nobody asked it to find, and it cannot always undo what it has done.

4 min read
Close-up overhead shot of a plain laptop keyboard in a dimly lit office, the screen glowing pale blue, an inbox interface faintly reflected on the desk surface,
AI Security

Paperclip AI Agent Platform Carries Bugs That Hand Attackers the Keys to the Host

Two flaws in the open-source AI agent controller let a rigged agent import run commands on the server or developer laptop. A third leaks control-plane data through unprotected API routes.

4 min read
Photoreal news-editorial photograph, 16:9 framing, edge-to-edge composition
AI Security

Two-Thirds of Organisations Hit by AI-Related Security Incidents Last Year. The Weak Link Is the API.

A surge in AI adoption has quietly created a new kind of back door into company systems. Experts say most businesses are focused on the wrong part of the problem.

4 min read
Full-frame edge-to-edge photoreal overhead shot of a sleek aluminum laptop on a dark desk, screen glowing with abstract hex dump and disassembly patterns in coo
AI Security

The Network Is Quietly Becoming the Referee for AI Traffic

As AI tools multiply inside companies, firewalls are being asked to do a job they were never designed for: policing conversations between machines that think.

4 min read
Photoreal news-editorial style, 16:9 framing, full-frame edge-to-edge composition
Vulnerabilities

Vatican Prayer App Left 700,000 Users' Names and Emails Exposed for Anyone to Grab

A basic security blunder on the Catholic Church's official Click to Pray app meant that anyone with a browser could pull the personal details of every registered user, no hacking skills required.

4 min read
AI Security

Dify AI Platform Carried Multi-Tenant Flaws Exposing Private Chats and Internal APIs

Cross-tenant data leakage vulnerabilities in Dify's cloud service let attackers read other users' conversations, preview documents, and probe internal API endpoints.

2 min read
Identity & Access

SailPoint to Buy Entro Security for a Reported $200 Million

The acquisition adds non-human identity and secrets management to SailPoint's governance platform — a gap that's become increasingly hard to ignore.

2 min read
Vulnerabilities

ServiceNow's Unauthenticated API Endpoint Left Tenant Data Exposed for Months

An API resource shipped with authentication disabled by default. Now enterprises are asking whether the 'security researcher' explanation fully covers what got accessed.

2 min read
© 2026 Threat Vectr