Duncan Riley
Latest from Duncan Riley
Pentera Labs warns vulnerable demo apps are being actively exploited in the wild
Vulnerable training and demo applications exposed to the public internet are being actively exploited and used as entry points for full cloud account compromise at major enterprises, including Fortune 500 companies. That’s according to a new report out today from Pentera Labs, the research arm of Pentera Security Ltd. The report, When the Lab Door Stays Open, ...
Nightfall expands data protection with AI Browser Security for browsers, endpoints and SaaS
Cloud data protection startup Nightfall today announced the launch of its AI Browser Security solution, a new solution designed to stop real-time data theft through artificial intelligence tools, AI-powered browsers and modern web workflows that legacy data loss prevention solutions cannot see or control. The solution seeks to assist with the issue that has arisen as employees ...
AI inference startup Baseten hits $5B valuation in $300M round backed by Nvidia
Artificial intelligence inference startup Baseten Labs Inc. has raised $300 million in new funding on a $5 billion valuation. The round was co-led by Institutional Venture Partners LP and CapitalG LP, Google LLC’s independent growth fund, with Nvidia Corp. reportedly also participating with a $150 million investment. Founded in 2019, Baseten is an AI infrastructure ...
Court filings raise questions over DOGE access to Social Security Administration data
Questions about data governance and privacy safeguards at the U.S. Social Security Administration have resurfaced following new court filings that allege employees tied to the Department of Government Efficiency accessed sensitive agency systems. Accusations that DOGE employees may have illegally accessed or copied SSA data first emerged in August when a senior official filed a ...
Ethernovia raises more than $90M to advance Ethernet packet processors for automotive and edge AI
Semiconductor startup Ethernovia Inc. revealed today that it has raised more than $90 million in new funding to accelerate development and production of its next-generation packet processor family, expand software and systems capabilities, and support customer engagements across automotive, robotics and industrial markets. Founded in 2018, Ethernovia is focused on transforming how data moves within ...
Global 2000 companies lag on domain security despite rising cyber risks
Despite gradual improvements, many of the world’s largest companies remain exposed to domain-based cyber risks as attackers increasingly exploit weaknesses outside the traditional corporate firewall. That’s according to Corporation Service Co.‘s Domain Security Report 2026, released today. It examines the domain security posture of Forbes Global 2000 companies and compares them with the world’s top 100 ...
HackerOne launches Good Faith AI Research Safe Harbor to protect responsible AI testing
Offensive security solutions firm HackerOne Inc. today announced the launch of the Good Faith AI Research Safe Harbor, a new industry framework that establishes clear authorization and legal protections for researchers testing artificial intelligence systems in good faith. The framework seeks to address the issue whereby, as AI systems scale rapidly across critical products and services, legal ...
Anthropic’s official Git MCP server hit by chained flaws that enable file access and code execution
Anthropic PBC’s official Git Model Context Protocol server has several security vulnerabilities that can lead to arbitrary file access and, in some scenarios, full remote code execution triggered entirely through prompt injection. That’s according to a new report out today from artificial intelligence security startup Cyata Security Ltd. The flaws affect mcp-server-git, the reference implementation of Anthropic’s ...
Sophos introduces Workspace Protection to simplify hybrid and remote work security
Cybersecurity firm Sophos Ltd today announced the launch of Workspace Protection, a new service that expands its portfolio with an accessible and affordable alternative to heavyweight and cost-intensive secure access service edge solutions for securing hybrid and remote work. Built around the Sophos Protected Browser, the new service allows organizations to protect applications, data, users and guests ...
Indirect prompt injection in Google Gemini enabled unauthorized access to meeting data
A new report out today from cybersecurity company Miggo Security Ltd. details a now-mitigated vulnerability in Google LLC’s artificial intelligence ecosystem that allowed for a natural-language prompt injection potentially to bypass calendar privacy controls and exfiltrate sensitive meeting data via Google Gemini. The issue arose from Gemini’s deep integration with Google Calendar, which allows the AI ...









