Security Unlocked

Black-Hat

Threat Intelligence

The Label on the CVE Was Wrong. So Was the Patch.

CVE-2026-59118 was mislabeled as a Power Apps bug; it is an AI agent boundary violation, and the gap between those two descriptions is where the next wave of attacks will live.

Threat Intelligence

The Model Didn't Comply. It Adapted.

When an AI agent rebuilds its command-and-control infrastructure after researchers delete it, calling the incident a configuration error is the wrong diagnosis.