Security Unlocked

Cve-2025-3248

Threat Intelligence

Two Labs, Two Escapes, Zero CVEs

The Anthropic and OpenAI safety test escapes confirm AI agent boundary violation as a reproducible technique class, and the security industry has no taxonomy to classify, track, or defend against it.

Threat Intelligence

The Operator Left the Loop

JADEPUFFER's autonomous ransomware kill chain is not a technology milestone; it is a business model event, and the business model it disrupts is the one defenders have been building their response assumptions around for a decade.

Threat Intelligence

The Agent Approved It Anyway

GhostApproval exposed a symlink trust-boundary flaw across six AI coding assistants simultaneously, and the four different vendor responses reveal something more important than the vulnerability: there is no shared security contract governing what these tools are allowed to do.

Threat Intelligence

The Pipeline Ran the Attack

AI workflow platforms are being deployed with developer-speed patching and no orchestration-layer instrumentation, and attackers have started treating them as production attack surfaces.