First Recon AI has released its AI Security Runtime, a new platform designed to help organizations manage and secure their use of artificial intelligence. The system monitors all AI interactions, enforces policies before data is processed by models, and creates auditable records of AI decisions, enabling faster AI adoption with robust governance.

First Recon AI has publicly launched its AI Security Runtime, a platform designed to govern and secure the use of artificial intelligence within enterprises. The system aims to provide organizations with the ability to manage AI interactions, enforce policies, and generate auditable records of AI activity.
The runtime inspects all AI interactions, whether between humans and models, agents and tools, or agents and other agents. It applies security policies before data reaches an AI model and logs every decision made, creating evidence that can be used for compliance and auditing purposes. This is intended to address the growing challenge enterprises face as AI adoption outpaces the ability of traditional security tools, which were designed for file and network security, to manage AI-specific risks.
First Recon AI's platform operates across various AI touchpoints, including applications, gateways, APIs, agents, and endpoints. It is designed to detect sensitive data, potential threats, and policy violations in real time. The system enforces decisions by allowing, redacting, holding, or blocking data before it is processed by an AI model. All decisions are recorded as sealed, metadata-only evidence, intended to be compatible with SIEM systems and compliance frameworks like NIST, GDPR, and the EU AI Act.
At the heart of the AI Security Runtime is a proprietary Semantic Security Engine. This engine analyzes the meaning, intent, and context of AI interactions, moving beyond simple pattern matching. It utilizes a Security Context Graph to link interactions, user identities, and data sources, which the company states improves detection accuracy over time.
The company highlights that many existing AI risk solutions focus on a single control point, such as a gateway. First Recon AI's approach integrates multiple security layers, including device-level security, semantic data security, shadow AI discovery, agent security, and cost controls, all managed under a unified policy.
First Recon AI CEO Kentaro Kawamori stated that enterprises are seeking provable control over AI, a capability that current tools often fail to provide. He explained that the AI Security Runtime was developed to enable companies to deploy AI more aggressively while maintaining control and meeting emerging AI compliance requirements with concrete evidence.
The AI Security Runtime is available in two forms. The First Recon AI endpoint agent is designed for organizations requiring stringent control and enforcement, managing AI use on macOS and Windows devices, including unauthorized AI tools, and preventing sensitive data exfiltration. Additionally, the First Recon AI application offers a secure AI workspace for chat and agent use, accessible via web browser or desktop, serving as a governed alternative to unsanctioned AI tools. Both offerings aim to provide comprehensive coverage from the device to the AI model, with a single policy interface applicable to major AI providers such as OpenAI, Anthropic, Google, and Meta.
First Recon AI has also announced a partnership with Conscia Group, a European cybersecurity and managed IT services provider. Conscia Group's CTO Henrik Møll noted that their clients, who manage critical infrastructure, require demonstrable AI control for regulatory purposes. He indicated that First Recon AI's approach to governing AI interactions and generating audit trails meets these demands.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

OpenAI has announced a $1 billion commitment to provide subsidized access to its Daybreak AI cybersecurity tools for under-resourced critical infrastructure defenders. The initiative, named Daybreak for Frontline Defenders, will offer AI models, training, and technical support over the next six months, prioritizing water and wastewater utilities, electric grid operators, and local government entities. This move aims to equip organizations with limited budgets and staff against increasingly sophisticated cyber threats.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed