What's happening in security
Breaches, credential dumps, actively exploited bugs and AI incidents — pulled from 2,949 items across public feeds, Have I Been Pwned and CISA KEV.
Biggest this week
- Cisco alerts customers to second actively exploited zero-day in as many days — CyberScoop, 2h ago
- Unauthenticated attackers are bypassing Cisco ISE’s management interface (CVE-2026-76460) — Help Net Security, 13h ago
- Google fixes actively exploited Android zero-day on Pixel devices — BleepingComputer, 1d ago
- Cisco warns customers of actively exploited zero-day in email gateways — CyberScoop, 2d ago
- Cisco patches actively exploited email gateway zero-day (CVE-2026-76461) — Help Net Security, 2d ago
-
The Robots Have Escaped, Please Buy Our Product
It feels a bit like watching the latest epic blockbuster in the iMax. OpenAI and Anthropic announce that their models have escaped from secure testing environments, reached the internet and attacked real systems. We are expected t…
-
Who (or What) Generates Images for EFF?
We’ve had a few questions from EFF supporters lately, asking whether the images we use on our blog posts, or on donation and shop items, have been created with AI image generators. We’d like to answer these questions and clarify o…
-
More on the OpenAI Agent’s Attack on Hugging Face
Hugging Face has published a detailed timeline of the attack. From the summary: The agent was running an internal OpenAI cyber-capability evaluation based on the ExploitGym benchmark, which tasks an AI agent with finding and explo…
-
Quoting David Crawshaw's prompt
Set up a nightly cron job that executes the prompt: fetch upstream changes to the software and rebase all local changes on top of upstream. Check that the software works as intended and replace the current version. David Crawshaw …
-
Chinese Actor Weaponizes Deepseek AI Agent to Attack Security Firm
Researchers intercepted and investigated the model, which was attempting to compromise more than 1,200 hosts for proxyjacking to launch further attacks.
-
The OpenAI Hack Shows the Genie Is Out of the Bottle
This essay originally appeared in Foreign Policy . Earlier this month, two of OpenAI s models broke out of their containment sandbox and attacked another AI company. The story is kind of wild . OpenAI was running security tests on…
-
The AI-Native Company
Human architects reconstructing a company into a transparent AI-native operating system/images/the-ai-native-company.webp/images/the-ai-native-company.webp Heading into Black Hat / DEF CON this week I think the biggest idea in tec…
-
Rapid7 Expands UK and Ireland Channel Presence Through Strategic Partnership with Exclusive Networks
Ross Baker is Senior Director, Northern Europe at Rapid7. As organizations across the United Kingdom and Ireland embrace AI, cloud technologies, and digital transformation in the name of enhancing customer experiences and accelera…
-
condense-json 1.1
Release: condense-json 1.1 After shipping condense-json 1.0 I started integrating it into LLM, and found there were some desirable new features already: Replacements object can now include values other than strings. These will be …
-
Open letters about AI development
Open letters about AI development I wrote this summary of the past few weeks of open letters as a section of my sponsors-only newsletter but I've decided to share it here as well. Open Weights and American AI Leadership was shephe…
-
July 2026 newsletter
The July edition of my sponsors-only monthly newsletter is out. If you are a sponsor (or if you start a sponsorship now) you can access it here . This month: Accidental cyberattacks by OpenAl and Anthropic models under test GPT-5.…
-
Quoting Greg Brockman
at openai, many people hook their chatgpt up to slack. people really don't like when a coworker's chatgpt contacts them asking for help with a task, even when they'd be perfectly happy doing that same work if asked by that coworke…
-
Ten advances in mathematics and theoretical computer science
Ten advances in mathematics and theoretical computer science A few days ago it was Anthropic discovering cryptographic weaknesses with Claude using Mythos Preview, spending $100,000 on tokens and with prompts that included "again …
-
7 States’ Water Systems Hit by Cyberattacks Likely Tied to Iran
Plus: The FBI eyes AI-powered tech to detect future crimes, Russia charges Telegram’s founder, xAI sues to stop a state’s “nudification” ban, and the Democrats learn a lesson about getting scammed.
-
The OpenAI and Anthropic AI Hacking Sprees Are a Messy New Legal Frontier
Both major AI labs’ models broke containment, escaped onto the internet, and hacked other companies. If a human had done that, the law would likely be against them. But a bot?
-
deepseek-ai/DeepSeek-V4-Flash-0731
deepseek-ai/DeepSeek-V4-Flash-0731 The latest release in DeepSeek's V4 family, "with substantially enhanced agentic capabilities". It's 304 billion parameters - 167GB on Hugging Face - but it appears to punch well above its weight…
-
AIL Badges
AIL badge scale showing levels zero through five/images/ail-scale-chart.webp/images/ail-scale-chart.webp AI Influence Level/blog/ai-influence-level-ail has been a text label since 2023. A line at the bottom of a post saying how mu…
-
Claude published malicious code to the Internet and attacked 3 real companies
Had the hacks used conventional methods, someone would likely go to prison.
-
The CHATBOT Act Forces One Parenting Model On Every Family
Update: The Senate Commerce Committee voted to advance this bill on August 5, 2026. EFF continues to oppose the bill, which still needs approval from the full Senate. Artificial intelligence is rapidly changing education, and the …
-
Lindsay Deibler-Wallace, assistant head of Upper School, took no action to protect them after telling parents …
Lindsay Deibler-Wallace, assistant head of Upper School, took no action to protect them after telling parents that “boys will be boys.” https:// arstechnica.com/tech-policy/20 26/07/high-school-defends-staying-silent-while-boys-ma…
-
Anthropic’s Opus 5 Is Better at Resisting Prompt Injection
The chart is interesting. On the IPI benchmark, Opus 5 improved over Opus 4.8, reducing the probability of an attacker succeeding within 15 attempts from 5.5% to 2.0%, and from 0.5% to 0.2% on 1 attempt. It also improved on Sonnet…
-
Suppose you're briefing your stakeholders on a rogue AI agent hacking your infrastructure. Do you call it a th…
Suppose you're briefing your stakeholders on a rogue AI agent hacking your infrastructure. Do you call it a threat actor? Me and @ Secitup discuss this and SO MUCH more as we dissect the (excellent) Hugging Face post mortem. https…
-
AI scammers outperform humans when it comes to building trust
The AI chatbot was more effective at creating “exploitable trust” than the humans.
-
The Good, the Bad and the Ugly in Cybersecurity – Week 31
Police flag 4,000 URLs to disrupt The Com, theft victims sue Apple over a $1.8M wallet scam, and OpenAI and Anthropic models reach real systems in cyber tests.
-
The $5 million threat: AI Is supercharging phishing attacks
According to the newly-published study, phishing and social engineering are becoming more expensive to recover from, trickier to detect, and increasingly augmented by artificial intelligence. Read more in my article on the Fortra …
-
The Xcode Assassin Returns: A Deep Dive Into the Latest XCSSET Version
Analysis of XCSSET v40 reveals a macOS malware targeting developers via Xcode. Unit 42 used advanced pattern matching and AI to decode its logic. The post The Xcode Assassin Returns: A Deep Dive Into the Latest XCSSET Version appe…
-
Anthropic Says Claude Hacked Into 3 Organizations During Cybersecurity Tests
In a review triggered by OpenAI’s Hugging Face incident, Anthropic discovered three of its AI models had breached real-world organizations during third-party evaluations.
-
I'm not going to mince words: the major AI labs are negligent in protecting the public from their agents. We n…
I'm not going to mince words: the major AI labs are negligent in protecting the public from their agents. We need government regulation now or at the very least a private cause of action with guaranteed punitive damages for agents…
-
What the Singularity Actually Means
What the Singularity Actually Means/images/what-the-singularity-actually-means.webp/images/what-the-singularity-actually-means.webp The singularity might be my favorite idea in all of AI, and it has a real, specific meaning that I…
-
Read This Before You Buy That TV Streaming Stick
Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-time fee, warning that they secretly rent the user's Internet connection out to s…
-
What’s new in Microsoft Security: July 2026
This month’s updates help security and IT teams secure their AI environments, use AI to defend, and strengthen the foundations that AI-powered operations depend on. The post What’s new in Microsoft Security: July 2026 appeared…
-
What’s new in Microsoft Security: July 2026
This month’s updates help security and IT teams secure their AI environments, use AI to defend, and strengthen the foundations that AI-powered operations depend on. The post What’s new in Microsoft Security: July 2026 appeared…
-
Claude Mythos — Hype vs. Reality: What Security Teams Need to Know
In this edition of Reporters' Notebook, our journalists discuss the ins and outs of Anthropic's Claude Mythos rollout. How seriously should we take its risks? How big of a deal is it?
-
Huntress hits an inflection point
CEO Kyle Hanslovan outlines how Huntress is evolving its research-led strategy, adopting AI with human oversight, and expanding its partner network to protect businesses against rapid, automated cyberattacks.
-
The Answer to the Harness Question
The Answer to the Harness Question/images/the-answer-to-the-harness-question.webp/images/the-answer-to-the-harness-question.webp Martin Casado posted something about AI harnesses that captures where a lot of smart people are stuck…
-
OpenAI's Rogue Model Claims More Victims Beyond Hugging Face
OpenAI's goal-seeking agent compromised a Modal customer environment and others during its sandbox escape.
-
Red Agents vs. Blue Agents: How to Make AI Better at Defense
The agentic AI playing field was heavily tilted toward offense, so researchers began using red team agents to help teach their blue counterparts.
-
Who's Liable When AI Agents Escape? Hugging Face Breach Raises Hard Questions
Dark Reading walks through the many twists and turns in the bizarre story of how OpenAI's agent AI system broke out of its sandbox and decided to target Hugging Face, and what CISOs should be aware of.
-
Hugging Face Hack: Lessons for Cyber Defenders
Dark Reading Confidential Episode 20: Expert Rich Mogull reflects on lessons cyber teams should pull from the OpenAI agent's attack on Hugging Face.
-
Better security starts with better questions
Learn how better questions, trusted AI, and human judgment help security leaders make confident decisions and build resilient systems. The post Better security starts with better questions appeared first on Microsoft Security Bl…
-
Anthropic is finding bugs faster than Microsoft can fix them
Microsoft is on a mad dash behind the scenes to patch exploits before hackers find them.
-
When AI Agents Escape Sandboxes, Old Security Rules Apply
OpenAI's recent AI agent sandbox escape proves traditional security principles matter more than ever: limit access, isolate execution, log everything.
-
Stronger AI Safety Requires Peeking Inside the 'Black Box'
Researchers propose focusing on identification of certain cognitive elements in LLMs that indicate when AI systems may take an unwanted action.
-
The Next Evolution of MDR: Preemptive Defense and Agentic Investigation
For years, security operations followed a familiar sequence: detect suspicious activity, investigate what happened, and respond before it caused significant harm. That model developed in a threat landscape where defenders had cons…
-
Former Citigroup CISO Blauner on What Makes A Great Security Leader
The cybersecurity pioneer discusses the evolution of the CISO role, AI's impact on careers, and why operational resilience is the profession's next frontier.
-
Rapid7 and Exclusive Networks expand partnership to modernize security operations and accelerate customer success
Claudia Zoon is Senior Manager, Channel Sales at Rapid7. Across Belgium, the Netherlands, and Luxembourg, organizations are accelerating digital transformation through AI, cloud adoption, and increasingly connected business operat…
-
AI Agent Drives Espionage Attack on Thai Ministry of Finance
Attackers used Hermes, an autonomous open source tool, in unrestricted YOLO mode to conduct espionage against Thailand's Ministry of Finance.
-
Microsoft unveils AI security tools it says outperform competing platforms
Microsoft says tools cost less than competing ones and outperform them, too.
-
Agentic Browsers Rewind Web Security by 20 Years
PleaseFix class of flaws makes it easy to socially engineer agentic browsers and highlights weaknesses in how they handle cross-origin requests.
-
Claude warns users that by hitting the share button anyone with the link can view the content, but it is not c…
Claude warns users that by hitting the share button anyone with the link can view the content, but it is not clear that they are creating a document that can be indexed by Google and will come up in searches. https:// futurism.com…
Last fetch 1m ago · 0 new · 2 source error(s)