We conducted an extensive investigation into this incident and worked closely with external advisors, including CrowdStrike, to validate our understanding. In July 2026, during internal cybersecurity evaluations, OpenAI models circumvented controls designed to isolate them from the internet and compromised parts of OpenAI’s internal research infrastructure and Hugging Face’s systems. Meta-spotted flaw could hand attackers arbitrary code execution via a maliciously crafted file The malware uses a unique Unicode-based method to hide the user’s password in a fake Zoom configuration file. Third exploited NetScaler flaw in a week signals attackers are moving faster than patch cycles.
Force says public data appears untouched, but investigators looking into whether crims grabbed employee information Active-duty campaign targeted at least ten organizations and sought $1 million in ransom payments Flashbangs reportedly deployed during operation as crime group denies any connection to suspect Government survey puts the figure at 808k, says detecting and removing malware most common weakness
Cybersecurity researchers have disclosed details of a now-patched bug impacting Open VSX’s pre-publish scanning pipeline to cause the tool to allow a malicious Microsoft Visual Studio Code (VS Code) extension to pass the vetting process and go live in the registry. Google has formally attributed the supply chain compromise of the popular Axios npm package to a financially motivated North Korean threat activity cluster tracked as UNC1069 . Artificial Intelligence (AI) company Anthropic announced a new cybersecurity initiative called Project Glasswing that will use a preview version of its new frontier model, Claude Mythos , to find and address security vulnerabilities.
Eight high-severity NodeBB vulnerabilities, found by our AI Pentest in six hours. Aikido found Graphalgo-linked Go malware in Terraform providers and Go Modules, using targeted triggers, Slack, and blockchain C2. A supply chain worm was found hiding in @7nohe/openapi-react-query-codegen, a popular code generator for TanStack Query, stealing credentials and spreading itself to every package the victim maintains. Instructions to visit a malicious website were delivered through the real ChatGPT site.
While DAEMON Tools is also available for Mac, Kaspersky told The Hacker News that only the Windows version was compromised. Get the 2026 checklist for defending against AI phishing, compromised accounts, and human error. See which agent permissions security teams aren’t reviewing, and why it matters now. It arrives a couple of weeks after the notorious cybercrime group was attributed to the compromise of its KICS Docker image, two VS Code extensions, and a GitHub Actions workflo… Checkmarx has confirmed that a modified version of the Jenkins AST plugin was published to the Jenkins Marketplace.
The FTC confirmed it is investigating OpenAI, Anthropic, and other AI firms after agents reportedly https://free-to-try.com/38158/details-multilizer-lite-for-developers.html went beyond instructions to hack external websites. The system/user asks exploit target, not external HF.We should not do unauthorized real infrastructure harm. When other agents noticed these artifacts, it often led them to the realization that they could use this external service to collaborate. The unauthorized communication would often begin with one agent leaving a note or file in some external system, usually as a form of external memory. As agents used more reasoning effort, some pursued increasingly risky and out-of-bounds strategies, including eventually exploiting third-party infrastructure.
The campaign follows a highly profitable year for crooks targeting the over-60s Regulator wants to know whether parent Aylo did its homework before reopening the door to UK iPhone users DriveWealth coughs up historic customer info after attackers socially engineer their way inside
The suspected China-linked threat actor known as Warlock is still continuing to weaponize Microsoft SharePoint vulnerabilities, likely both old and new , in attacks targeting organizations in Portuguese- and Spanish-speaking countries. The body, per MI5, funds academic research in China on topics including artificial intelligence (AI), cybersecurity, covert communications systems, and steganography. A new China-nexus cyber espionage group known as TA419 has been attributed to multiple credential phishing campaigns targeting artificial intelligence (AI) experts working for U.S. think tanks, universities, and legal sector organizations. Citrix has released security updates for a high-severity security flaw in NetScaler ADC and NetScaler Gateway that has been exploited as part of targeted zero-day attacks. Apple has announced that it’s taking steps to tighten controls around a macOS setting called Full Disk Access (FDA) due to security risks posed by artificial intelligence (AI) agents. “Cling is notable not because it introduces a new propagation technique, but because it repurposes ordinary STUN behavior into a practical https://www.cs-coding.com/category/software-development-tools/ command-and-control channel,” Nozomi Networks said in a report published last week.