# threat research (blogs) — RSS Amplifier

Recent posts from the 1 feeds in the RSS Amplifier directory that cover threat research.

Page: <https://rssamplifier.com/topics/threat-research/blogs>  
Feed: <https://rssamplifier.com/topics/threat-research/blogs.md>

---

## [Why shadow AI is far riskier than shadow IT](https://www.reversinglabs.com/blog/why-shadow-ai-is-far-riskier-than-shadow-it)

_2026-08-19 · Jaikumar Vijayan · ReversingLabs Blog_

Organizations don’t realize how pervasive shadow AI has become. And as AI's capability grows, shadow use is harder to manage.

## [Why software delivery cannot depend on trust alone](https://www.reversinglabs.com/blog/why-software-delivery-cannot-depend-on-trust-alone)

_2026-08-19 · John P. Mello Jr. · ReversingLabs Blog_

Attackers turned the trusted AsyncAPI CI/CD publishing pipeline against its users, and the provenance checks all came back clean.

## [Black Hat 2026: AI rewrites the rules of cybersecurity](https://www.reversinglabs.com/blog/black-hat-2026-ai-is-rewriting-the-rules-of-cybersecurity)

_2026-08-18 · Paul Roberts · ReversingLabs Blog_

The annual cybersecurity conference focused on frontier AI agents — and what they mean for cyber. Here are three key takeaways.

## [AI worms are coming — and traditional controls won't stop them](https://www.reversinglabs.com/blog/ai-worms-are-coming)

_2026-08-13 · Paul Roberts · ReversingLabs Blog_

Researchers built a worm that reasons about hosts it infects, and the open-weight models powering it sit outside AI-provider safety controls.

## [OWASP Top 10 for LLM Apps 2026: Excessive agency risk on the rise](https://www.reversinglabs.com/blog/owasp-top-10-for-llm-apps-excessive-agency)

_2026-08-12 · John P. Mello Jr. · ReversingLabs Blog_

While prompt injection and data disclosure remain concerns, excessive agency climbed the list — not surprising with recent security incidents.

## [Frontier AI agents: Only as safe as their containment](https://www.reversinglabs.com/blog/ai-agents-containment)

_2026-08-11 · Jaikumar Vijayan · ReversingLabs Blog_

The post-mortems of two compromises by rogue AI agents show that security teams need to focus on guardrails, not the AI model.

## [AI domain takeover takeaway: Focus on the harness not the model](https://www.reversinglabs.com/blog/ai-domain-takeover-takeaway)

_2026-08-06 · John P. Mello Jr. · ReversingLabs Blog_

Research into an Active Directory takeover with a single AI prompt highlights why organizations need to focus on agentic SOCs.

## [How to Leverage Spectra Analyze's Search for SVG Analysis](https://www.reversinglabs.com/blog/spectra-analyze-search-function-for-svg-analysis)

_2026-08-05 · Zaria Vuksan · ReversingLabs Blog_

Here's how to use Spectra Analyze to hunt for malicious SVGs, from setting up queries and evaluations of samples to tips for investigation.

## [Why AI coding makes zero trust an AppSec requirement](https://www.reversinglabs.com/blog/ai-zero-trust-appsec)

_2026-08-04 · John P. Mello Jr. · ReversingLabs Blog_

Traditional SBOMs, signing, and provenance all have blind spots, making them no longer capable of assuring software security.

## [Point a Domain, Start a Pit (Sponsored)](https://crawlproof.com/a/oEIOM1VLyCRj)

_2026-08-04 · **Sponsored**_

Point any domain to a blacked-out, poison-green coming-soon page with an email waitlist.

## [Can Lean improve security for AI-coded software?](https://www.reversinglabs.com/blog/can-lean-improve-security-for-ai-coded-software)

_2026-07-30 · John P. Mello Jr. · ReversingLabs Blog_

AI coding requires the stack be reconstructed with mathematical proofs built in — a task well suited to the Lean language. Here’s the reality.

