It hit a wall. Then went around it. An OpenAI agent got past Australia's Medicare data portal in a test. SafeBreach offensive security engineer Adrian Culley says, “Nobody built it to stop at the boundary.” Are your agents built to stop? Read more: hubs.ly/Q04ykD1Y0
SafeBreach Offensive Security Engineer Adrian Culley explains why this matters:
“What’s notable isn’t that an AI agent found its way past a control—it’s that nobody built the agent to stop when it hit one.”
It hit a wall. Then went around it. An OpenAI agent got past Australia's Medicare data portal in a test. SafeBreach offensive security engineer Adrian Culley says, “Nobody built it to stop at the boundary.” Are your agents built to stop? Read more: hubs.ly/Q04ykD1Y0
Google’s AI model breached 3 companies during a contained test—guessing 1 password and using leaked credentials twice. SafeBreach’s VP of Research (@OrGolov) explains what this trend means for security teams. Close gaps before autonomous agents find them. hubs.ly/Q04yd9NJ0
AI didn’t just help write ransomware—it helped run the attack. A RaaS affiliate used Claude Sonnet across nearly every stage of live intrusions. Techniques aren’t new—speed and autonomy are. @BejeranoGuy explains what this means & what CISOs must validate.
hubs.ly/Q04xT0H-0
SafeBreach coverage for CHOSEN BRICK, spyware linked to Iranian state actors targeting journalists, activists, and dissidents. Use 9 existing simulations to validate controls against persistence, Defender tampering, screen and audio capture, and discovery. hubs.ly/Q04xQdcW0
Isolation is not the same thing as security. Security Research Team Lead, Ron Ben Yizhak, went from restricted user to root inside the Azure container behind Python in Excel—and found CVE-2026-45459 along the way. How isolated is "isolated," really?
Get the link in the comments.
CISA just confirmed ransomware crews are exploiting CVE-2025-14733. Unauthenticated, pre-auth, reachable over IKEv2 VPN—the exact services a firewall exposes. @SafeBreach Offensive Security Engineer explains why patch availability was never the gap: hubs.ly/Q04xd-xz0
When trusted software becomes the payload, standard malware detection may fall short. A phishing campaign across 46 countries is abusing legitimate RMM tools. SafeBreach’s Adrian Culley explains why you must test whether unexpected installs trigger alerts. scworld.com/news/phishing-ca…
.@anyrun_app reported that a phishing campaign spanning 46 countries is tricking victims into installing legitimate RMM tools, giving attackers trusted remote access while helping them evade detection. #cybersecurity#CISO#infosecbit.ly/4cwq1SO
Your AI maturity isn’t defined by your fastest team—it’s constrained by the slowest link in your pipeline. Discover why responsible AI adoption requires advancing the entire development lifecycle while maintaining human oversight of security-critical code.
hubs.ly/Q04wy55c0
QTFY isn't a hacking crew—it's a scanning business. 2M tasks a day. IOCs alone won't catch it. Adrian Culley breaks down QScan, QTRouter, and what to test first in our latest blog. hubs.ly/Q04vGrtP0
NEW SafeBreach coverage for JCSA-20260826-0: Nine simulations now map to QTFY activity. Key findings: exposure puts you in scope, residential proxies make malicious traffic look legitimate, and the infrastructure remains active.
Explore the coverage: hubs.ly/Q04vBj0_0
An advisory with nothing to patch—that's why AA26-237A matters. CISA's red team hit two orgs identically: one SOC contained it, the other one never saw it. The only response is to test yourself. See the 26 simulations you can run today: hubs.ly/Q04vqgrl0
🚨 CISA just released AA26-237A, examining two real red team assessments and what the defending SOCs did—and didn’t—catch.
SafeBreach Labs is analyzing the TTPs and our existing coverage. Check back tomorrow for our full analysis.
See the advisory here: hubs.ly/Q04vd9Rc0
12,000+ Zimbra servers are still exposed to CVE-2026-73570—now on CISA's KEV list. Patch shipped July 20. Exploited in the wild by Aug 18.
Patch-and-pray can't keep pace. CTEM validates what's exploitable right now.
hubs.ly/Q04v5mYt0
Claude Mythos and GPT-5.5 are crossing a new threshold in offensive cyber capability—finding decades-old bugs and completing expert-level intrusion simulations. But has AI actually changed real-world exploitation yet? See what the data shows: hubs.ly/Q04tJd7x0
CISA, the FBI, and HHS have refreshed their #StopRansomware advisory on #Medusa (AA25-071A)—the RaaS operation that's hit 300+ critical infrastructure organizations since 2021. SafeBreach Labs is working to add coverage. For more details, check back for our upcoming blog.