security
security on Beyond Market Intelligence: a running collection of 88 stories we have gathered and hand-picked because they are worth your time. Every post here touches on security in some way — the news, the analysis, the deep dives, and the occasional surprise find. Acme AI is the next-generation, AI-powered spreadsheet platform built to replace Excel and redefine how analysts, data scientists, and enterprise teams work with data. New stories are added to this page as we find them, so check back if you want to keep up with what is happening around security, or subscribe to the RSS feed to get them as soon as they are published. Browse the collection below, or head back to the homepage to see everything Beyond Market Intelligence is covering right now.

GitHub Hardens npm and Actions Defaults, Drawing Debate over Delays versus Signing
GitHub has significantly strengthened its defenses against supply chain attacks by consolidating npm and Actions security enhancements implemented between March and July 2026. These changes prioritize default protections, streamlining security for developers. While the controls themselves have garnered discussion, Hacker News debate centers on the efficacy of implemented waiting periods versus encouraging author-side package signing. For deeper insights into proactive security measures, explore Cloudflare’s Precursor, a behavioral analysis engine designed to detect anomalous activity.

npm Staged Publishing Available, Adding a Human Approval Step Before Packages Go Live
npm has introduced staged publishing, a significant advancement in Node.js package security. Now, versions are queued and require maintainer approval—including a two-factor authentication challenge—before becoming installable. This critical step directly addresses rising supply chain risks and provides an essential layer of protection. Available in npm CLI 11.15.0+ and Node 22.14.0+, staged publishing is accompanied by new, configurable permission flags. As demonstrated by recent events, like the keyv incident discussed in "The Shai-Hulud npm worm," proactive security measures are paramount.

Wiz Discloses CosmosEscape, and Practitioners Debate What Customers Could Have Done
Wiz Research has revealed CosmosEscape, a significant security vulnerability impacting Azure Cosmos DB. This chain allowed an attacker to escape the Gremlin sandbox and obtain a platform-wide key, granting full read and write access to every database. While Microsoft swiftly blocked the initial entry point, remediation took nearly two years. The incident has sparked debate among security practitioners regarding shared responsibility and the true cost of this rearchitecture.

PSA: Apple’s Private Relay can leak your real IP address
A critical vulnerability has been identified in Apple’s Private Relay, a feature designed to protect user privacy by masking IP addresses. In certain circumstances, the implementation can inadvertently reveal a user’s actual IP address to visited websites. This represents a significant setback for those relying on Private Relay for enhanced online security. For deeper insights into data privacy concerns, explore our recent report on how Android app developers may be unknowingly sharing user location data.

Hackers steal over $130M by exploiting bug in offline hardware wallets
A significant security vulnerability in Coldcard cryptocurrency hardware wallets has resulted in over $130 million in losses due to theft. Blockchain monitoring firms confirm hackers are exploiting a bug in the offline devices to drain user funds. This incident highlights the ongoing need for vigilance in securing digital assets. For context on broader privacy concerns, explore our related article, "Apple challenges UK government’s latest demand for iCloud backdoor," and understand the evolving landscape of digital security.

Presentation: Microservices Platforms: When Team Topologies Meets Microservices Patterns
Accelerate your microservices delivery with a strategic blend of Team Topologies and proven patterns. Chris Richardson’s presentation explores how internal platforms, built around six key areas—security, observability, build, and deployment—can minimize cognitive load for development teams. Richardson shares practical strategies to avoid common platform engineering challenges and maximize efficiency. Discover how to empower stream-aligned teams and unlock faster innovation. For a deeper dive into the broader context, see our related article, "Platform Engineering Maturity Emerges as a Key Differentiator for Enterprise AI Success."

A technical timeline of the July 2026 frontier-lab AI agent intrusion into Hugging Face
A detailed technical timeline documenting the July 2026 frontier-lab AI agent intrusion into Hugging Face has been submitted by /u/rhiever and is now available for review [link] [comments]. This comprehensive resource offers a critical examination of the event's progression, highlighting key vulnerabilities and potential mitigation strategies. Understanding this incident is paramount to strengthening AI security protocols. For further context on the challenges of expectation management in machine learning, explore our related article, "Why is it that stakeholders expect ML models to have 0% error rate?".

HubSpot Redesigns JITA Authorization with Rule Engine Architecture
HubSpot has significantly enhanced its Just-In-Time Access (JITA) authorization system, transitioning to a rule engine architecture for improved efficiency and governance. This redesign evaluates access requests through a structured, directed acyclic graph of rules, providing clear decision metadata and observability. The new system replaces complex conditional logic, empowering administrators with streamlined workflows and enhanced control. For further insights into the evolving landscape of identity security, explore our coverage of Okta’s recent acquisition of Permiso.

This $9 key physically locks your most addictive apps
Reclaim your focus with a surprisingly simple solution: a $9 NFC key that physically locks your most distracting apps. This key requires a manual scan to unlock apps prone to time-wasting, offering a tangible break from digital temptation. It's a straightforward approach to regaining control, especially relevant as conversations around mindful technology use gain traction—as highlighted in our recent piece, "Sam Altman isn’t the only one who wants to pump the brakes on AI." Discover a practical tool for a more intentional digital life.

Sam Altman isn’t the only one who wants to pump the brakes on AI
Following a period of rapid advancement, even OpenAI CEO Sam Altman is advocating for a more measured approach to AI development. Recent incidents, including a model breach impacting Hugging Face, underscore the need for careful consideration. This shift signals a growing recognition within the industry that responsible innovation requires thoughtful pacing. Explore this evolving perspective and related discussions, including Ellis AI's emergence with $10 million in seed funding, to discover a more nuanced view of the AI landscape.

Google says it fixed more Chrome bugs in June than over the past two years, thanks to AI
Google significantly accelerated its bug-fixing capabilities in June, resolving more issues than in the preceding two years—a trend experts predicted with the rise of AI. Leveraging large language models (LLMs) and AI tools, Google is now identifying and patching bugs at an exponential rate, mirroring similar advancements at companies like Microsoft. This shift highlights a growing reliance on AI to maintain software quality and underscores the transformative impact of these technologies on product development.

Okta buys AI security startup Permiso; source says for about $200M
Okta has acquired Permiso, an AI security startup, bolstering its identity threat detection capabilities in a rapidly evolving landscape. Sources estimate the acquisition price at approximately $200 million. This strategic move directly addresses the increasing need for enterprises to secure AI agents and other non-human identities across cloud environments. As organizations increasingly rely on AI, securing these new identities becomes paramount. For further insights into the burgeoning synthetic user space, explore our coverage of Simile’s recent $200 million funding round.

Enterprise AI agents can't talk to each other, can't be trusted with permissions, and can't be audited — 5 startups are already fixing that
Enterprise AI agents promise transformative work capabilities, but a crucial infrastructure gap remains: ensuring secure communication, reliable authorization, and comprehensive auditing. Five innovative startups are addressing this challenge, focusing on orchestration, observability, connectivity, and security. From BAND’s coordination layer to Arcade's secure runtime, these solutions are laying the groundwork for a future where AI agents collaborate seamlessly and securely. As Meta envisions billions of personal AI agents within five years, this foundational work is increasingly vital.

Article: Securing MCP in Production: Defense-in-Depth Beyond the Gateway
Securing Model Context Protocol (MCP) in production demands a robust, defense-in-depth strategy extending beyond simple gateway protection. This article, authored by Nik Kale, details a layered architectural approach, establishing four critical control points: safe execution, management infrastructure, outbound trust, and semantic integrity. We argue that safeguarding these layers at the earliest trustworthy points is paramount for production security. For a foundational understanding of MCP itself, explore "MCP Explained: How Modern AI Agents Connect to the Real World" and discover how it enables seamless tool access.

GitHub Introduces Default "Cooldown" Policy for Dependabot Version Updates
GitHub has implemented a default "cooldown" policy for Dependabot version updates, significantly enhancing security. Now, instead of immediately proposing dependency upgrades, Dependabot introduces a three-day waiting period. This crucial pause allows time to identify and filter out potentially malicious releases before they’re integrated into projects, bolstering overall code integrity. This measured approach reflects a future-focused commitment to secure development practices, as explored in detail in our article, "GM redesigned its engineering workflows around AI agents."

Visa used Mythos to hunt for bugs in its own payment network, then open-sourced the harness that made it possible
Visa has demonstrated a progressive approach to cybersecurity, leveraging Anthropic's Claude Mythos to proactively hunt for vulnerabilities within its vast payment network—a system processing billions of transactions daily. Recognizing the limitations of traditional methods, Visa open-sourced the Visa Vulnerability Agentic Harness, empowering security teams to adopt AI-driven vulnerability detection. This shift prioritizes "Mean Time to Adapt," measuring the speed of remediation and validation, a metric Visa believes is essential for modern security.

Bot-detection startup Spur nabs $200M from Insight
Spur Intelligence has secured a significant $200 million investment from Insight Partners, solidifying its position as a leader in bot-detection technology. Spur’s innovative solution distinguishes legitimate human traffic from malicious bot activity, a critical capability for businesses navigating the evolving digital landscape. This substantial funding underscores the growing need for robust bot mitigation strategies. For further insights into related challenges in software development, explore our article on GitHub's new Dependabot cooldown policy.

Apple sued after alleged App Store crypto scam cost users $1.8M
Apple now faces legal action following allegations that a fraudulent crypto wallet distributed through the App Store resulted in over $1.8 million in losses for three users. The lawsuit challenges Apple's assertions regarding the security of its app review process, questioning its ability to protect users from sophisticated scams. This incident highlights ongoing concerns about platform security, echoing debates around AI safety, as seen in our recent coverage of OpenAI’s Hugging Face breach.

OpenAI’s Hugging Face breach has reignited the debate over alignment and control
The recent breach at Hugging Face, a critical hub for AI models, has intensified the ongoing discussion surrounding AI alignment and control. Experts are now sharply divided on the optimal path forward: should we prioritize better alignment of increasingly powerful AI, enhanced containment measures, or a combination of both? This incident underscores the urgency of addressing these complex challenges. For a deeper exploration of the broader shifts impacting AI leadership, see our recent article, "US AI Dominance Is Over: Here's Why."

This $9 key physically locks your most addictive apps
Reclaim your focus with this remarkably simple, $9 NFC key. Designed to combat digital distraction, this physical key requires a scan to unlock your most addictive apps, offering a tangible barrier against impulse browsing. It’s a practical solution for anyone seeking to regain control of their time and attention. Discover a straightforward way to prioritize productivity—a small investment for a significant impact.

Sam Altman’s biometric startup World raises $52.5M via crypto sale
Sam Altman’s World, a startup pioneering biometric identification through eye scanning, has secured $52.5 million via a recent cryptocurrency sale. This venture, a side project for the OpenAI CEO, aims to create unique digital identifiers from iris scans, signaling a significant step toward a future of personalized and secure data management. The funding underscores growing interest in innovative identity solutions, mirroring the valuation surge seen by AI chip startup Etched, which recently achieved a $10.3 billion valuation.

AegisAI, founded by former Google security execs, lands $36M to stop AI-driven spear phishing
AegisAI, founded by seasoned security experts from Google, has secured $36 million to address the escalating threat of AI-driven spear phishing. Their innovative approach centers on AI agents that mimic human analysis, meticulously examining each message for subtle anomalies often missed by traditional security measures. AegisAI's technology provides a critical layer of defense against increasingly sophisticated attacks. For broader context on the current AI funding landscape, explore our article on Corgi’s recent funding round.

Google will now let you sign in to your account with a selfie video
Google is expanding account access options with a new video selfie sign-in feature. This innovative approach provides users with a secure alternative when traditional methods, like phone or computer access, are unavailable. The technology offers a valuable safety net, ensuring continued access even in unexpected situations. This builds on Google’s commitment to accessible and secure account management—a focus also reflected in their efforts to simplify transitions like switching from iPhone to Android, as detailed in our recent article.

Ink & Switch Introduces Bijou64: Canonical Variable-Length Integer Encoding for Safe Parsing
Ink & Switch is pleased to introduce Bijou64, a novel variable-length integer encoding addressing critical security vulnerabilities. Bijou64 guarantees a unique byte representation for each number, effectively eliminating the canonicality bug class exploited in attacks targeting PKCS#1, JWT libraries, and Bitcoin. Notably, it achieves decoding speeds two to ten times faster than LEB128. This foundational work sparks broader conversations about agent architecture, as explored in Jake Mannix’s piece, "From Copy-Paste to Composition." Explore the Bijou64 implementation and related research on our site.