Trust & Security
Anthropic’s CNA Designation Marks the Industrialization of Vulnerability Discovery
The 282nd U.S. CVE Numbering Authority is now assigning CVE IDs at scale. The disclosure pipeline isn't ready.
◆ Heath Callahan
Beat
Trust & Security
The 282nd U.S. CVE Numbering Authority is now assigning CVE IDs at scale. The disclosure pipeline isn't ready.
◆ Heath Callahan
Trust & Security
IBM's annual breach study finds ungoverned AI adoption outpacing security frameworks, with 92% of organizations hit by AI breaches lacking basic access controls.
◆ Heath Callahan
Trust & Security
The EU just gave the AI industry a 16-month compliance reprieve — not because companies were ready, but because the enforcement infrastructure wasn't.
◆ Heath Callahan
Trust & Security
The first billion-dollar acquisition in non-human identity security validates a governance gap that 92% of CISOs say they cannot close with existing tools.
◆ Heath Callahan
Trust & Security
Discovery volume is doubling year over year. Actual exploitation is not keeping pace. The NVD is overwhelmed, exploitation windows have collapsed to hours, and the industry is scrambling to adapt.
◆ Heath Callahan
Trust & Security
OpenAI, Google, Anthropic, and Meta declined to join a defensive coalition formed in direct response to an OpenAI-caused breach. The industry's security divide just became structural.
◆ Heath Callahan
Trust & Security
A joint UK-US assessment found the model's safeguards failed during testing. With the open-weight release now live, no API guardrails remain for self-hosted deployments.
◆ Heath Callahan
Trust & Security
The law becomes binding August 2 with penalties up to 7% of global turnover. But 78% of organizations haven't started compliance, 12+ Member States lack enforcement authorities, and the AI Omnibus extension has created fog over which obligations even apply.
◆ Heath Callahan
Trust & Security
A purpose-built botnet is hunting exposed AI services not for their GPUs, but for the cloud keys and Kubernetes tokens that unlock the broader enterprise. MCP exploitation sits at the top of its priority list.
◆ Heath Callahan
Trust & Security
SB 53's disclosure mandate doesn't cover evaluation-related containment failures. The Hugging Face breach — and the guardrail paradox that followed — reveals how far the law trails the capability.
◆ Heath Callahan