Trail of Bits45 · 2026-01-29 12:00
Building cryptographic agility into Sigstore
Software signatures carry an invisible expiration date. The container image or firmware you sign today might be deployed for 20 years, but the cryptographic signature protecting it may become untrustworthy within 10 years. SHA-1 certificates become worthless, weak RSA keys are banned, and quantum computers may crack today’s elliptic curve cryptography. The question isn’t whether our current signatures will fail, but whether we’re prepared for when they do. Sigstore, an open-source ecosystem f...
OpenAI Blog32 · 2026-01-29 00:00
Retiring GPT-4o, GPT-4.1, GPT-4.1 mini, and OpenAI o4-mini in ChatGPT
On February 13, 2026, alongside the previously announced retirement of GPT‑5 (Instant, Thinking, and Pro), we will retire GPT‑4o, GPT‑4.1, GPT‑4.1 mini, and OpenAI o4-mini from ChatGPT. In the API, there are no changes at this time.
Rational Security27 · 2026-01-29 17:00
The "Pawing at Scott" Edition
This week, Scott sat down with his Lawfare colleagues Alan Rozenshtein, Eric Columbus, and Molly Roberts for a deep dive into two of the week’s big national security news stories: “Slipping Down the Slope.” Last week’s killing of 37-year-old ICU nurse Alex Pretti by Border Patrol agents in Minneapolis, Minnesota, has triggered what increasingly appears to be a national backlash against the Trump administration’s immigration policies and ICE’s violent tactics. Republicans and Democrats alike h...
API Security News » Feed15 · 2026-01-29 17:17
Issue 288: State of API Security 2026, Agentic AI, Authentication Bypasses, and the Race to Patch APIs
This week, we look at how long-standing API security failures are being amplified by automation, AI, and increasingly aggressive exploitation timelines. From agentic AI vulnerabilities in ServiceNow to authentication bypasses actively exploited in SmarterMail and Fortinet infrastructure, this issue highlights how broken authentication and authorization continue to dominate real-world incidents. We also dive into the 42Crunch [...] Read More... The post Issue 288: State of API Security 2026, ...
Thoughts on Security12 · 2026-01-29 05:52
Tracking Signal Identifiers
In the past few days Signal groups exploded in the news with revelations that Signal groups are the primary "ICE tracker" channels, may have dispatched Alex Pretti to his fatal encounter with DHS, and are under investigation by the FBI. As groups frequently hit the 1000-member capacity, concern about infiltration is rampant. Key facets of […]