OpenAI Shipped an Exploit-Writing Model. The Base Model Could Already Do It.
GPT-5.6-Cyber completes 95 per cent of exploit-chain prompts against 1.5 per cent for the general model it is built on....
ASEAN edition · Fri, 2 Oct 2026 · Signal over noise
AI-curated tech news, ASEAN business intelligence, and cybersecurity updates — written for the region.
GPT-5.6-Cyber completes 95 per cent of exploit-chain prompts against 1.5 per cent for the general model it is built on....
Two poisoned LiteLLM releases were live on PyPI for forty minutes in March. CloudSEK has now mapped roughly 434,000 capt...
Three different totals are circulating for the same Patch Tuesday, and all are defensible. The one number that matters i...
Birmingham researchers surveyed 26 devices and found nine expose an interface that lets the SIM issue modem commands. Th...
Every vulnerability CISA catalogued in the first week of August carried a three-day federal deadline. We measured the ca...
No plugin update was published. Attackers reached BdThemes storage, poisoned a feed the plugins pull into the admin dash...
Klaviyo's signup form was misconfigured so third-party marketing trackers captured what users typed, including passwords...
Ransomware crews are now chaining two SonicWall SMA1000 flaws that CISA gave federal agencies three days to fix. If your...
CERT Polska has documented the first real-world use of a private APN as a route into operational technology. Thirty wind...
Framework and Tally were both breached on 3 August through a zero-day in Metabase, the business-intelligence tool they u...
Water systems in at least twelve US states have been broken into, with attackers changing controller passwords and IP ad...
China's Cybersecurity Review Office opened a formal review into Palo Alto Networks products on 6 August — seven months a...
MIT researchers showed that Spectre v2 mitigations can be stepped around on current Intel and AMD processors, breaking K...
N-able patched a critical authentication bypass in N-central, attackers found a path the patch did not block, and a seco...
Two flaws score 9.8. The 9.3 lets an attacker with admin rights inside a virtual machine execute code on the host beneat...
Three flaws in CatchPulse, the worst letting an unprivileged local user bypass policy enforcement. Reported 26 June, pat...
CVE-2026-34486 exists because of the fix for CVE-2026-29146. CSA reports active exploitation, and the catalogue lists th...
CVE-2026-9198 gives unauthenticated remote code execution on default Langflow deployments. CISA allowed three days; CSA...
A Singapore Land Authority test dataset created in 1998 was meant to hold only mock records. It held real names, NRIC nu...
CISA gave three days to fix an actively exploited N-able bypass. Across the catalogue, the three-week remediation window...
Singapore stood up a dedicated Cyber Command on 3 July. Its first islandwide scam sweep was the third such operation in...
A macro was defined and set to zero. One guard tested whether it existed rather than what it held, the linker bound sile...
Three waves of automated sweeps have taken about $89 million in bitcoin from 4,585 addresses since 30 July. The cause is...
CVE-2026-20316 scores 5.3 — a medium. CISA still gave federal agencies three days and told them to check for compromise....