Corrections

Every material change to an item after it was published: a wrong date, a figure the primary source did not support, a claim tied to the wrong event. Sourcing upgrades that change nothing a reader relied on are not listed.

4 corrections

Google says its agentic vulnerability-discovery system found 100-plus critical flaws in two days

Date corrected from Aug 19 to Aug 18, the date of Google's own post, and a press figure for the number of pipeline stages replaced with the primary's description. Source moved from Help Net Security to Mandiant/GTIG.

CISA flags active exploitation of a critical Ray AI-framework flaw, giving federal agencies three days to patch

A sentence tying this CVE to Oligo Security's ShadowRay 2.0 campaign was removed. ShadowRay 2.0 exploits a different, older Ray flaw (CVE-2023-48022); the sources do not link the two. Source moved from press to the NIST NVD record.

OpenAI says it cannot rule out a 'Critical' cyber capability in its unreleased Astra model and is holding back internal work

Date corrected from Aug 10 to Aug 7, the date of OpenAI's own post, and the headline and summary softened to match it: the primary describes pausing internal Astra work that does not meet strengthened security controls, not a public release delay. Source moved from Axios to OpenAI.

OpenAI launches Daybreak, gating a cyber-tuned GPT-5.6-Cyber model to vetted security partners

Re-checked against OpenAI's own post. A press-only partner count and list, and a characterisation that partners received findings rather than the models, were removed as unsupported by the primary, which names three partners receiving model access.