AI-assisted attacks shrink the Gulf's patch window from days to hours
The United Arab Emirates reports about 800,000 attack attempts a day. Cloudflare released zero-trust controls for internal agents, while Canonical backed a 3-year C-to-Rust study.
Artificial Intelligence··Evening
The interval between attack and patch is narrowing
The United Arab Emirates Cyber Security Council reports about 800,000 attack attempts a day since February, 4 times the prewar level. The council says AI is being used to write phishing messages, search software for weaknesses and produce malicious programs quickly. Ram Narayanan, Check Point's Middle East country manager, says the interval between disclosure of a vulnerability and attempts to exploit it has fallen from days to hours in some cases. Council head Mohamed Al Kuwaiti said in April that the attacks came from about 20 countries and more than 40 organisations. The country began a programme in May aimed at building its own AI defences.[1]
Cloudflare keeps agents in isolated copies
Cloudflare released Cloudflare OS, the layer it developed for employees to build applications grounded in company knowledge, under an Apache-2.0 licence. Each employee receives an isolated copy instead of using a shared service. Under the Gatekeepers security framework, agents begin in a zero-trust state without ambient permissions. The system masks sensitive database columns, applies role-based rate limits and asks for human approval before destructive operations. Each application copy runs in isolated V8 environments managed by Cloudflare's open-source workerd runtime. The code is available in Cloudflare's GitHub repository.[2]
Canonical will test rewriting C in Rust
Canonical and UK Research and Innovation are co-funding a 3-year doctoral project at the University of Bristol. It will study whether large language models can split C programs containing hundreds of thousands of lines into smaller parts and rewrite them as behaviourally correct, maintainable Rust. The proposal explicitly names two tools: snap-confine and AppArmor. Canonical's Jon Seager says traditional translators can preserve C structure too literally, leaving code that compiles as Rust but still relies on unsafe operations. Seager is leading the project with Professor Meng Wang and Dr Cristina David at Bristol. There are not yet any measured results.[3]