What's happening in security
Breaches, credential dumps, actively exploited bugs and AI incidents — pulled from 3,021 items across public feeds, Have I Been Pwned and CISA KEV.
Biggest this week
- Cisco alerts customers to second actively exploited zero-day in as many days — CyberScoop, 1d ago
- Unauthenticated attackers are bypassing Cisco ISE’s management interface (CVE-2026-76460) — Help Net Security, 1d ago
- Google fixes actively exploited Android zero-day on Pixel devices — BleepingComputer, 2d ago
- Cisco warns customers of actively exploited zero-day in email gateways — CyberScoop, 3d ago
- Cisco patches actively exploited email gateway zero-day (CVE-2026-76461) — Help Net Security, 3d ago
-
The CHATBOT Act Forces One Parenting Model On Every Family
Update: The Senate Commerce Committee voted to advance this bill on August 5, 2026. EFF continues to oppose the bill, which still needs approval from the full Senate. Artificial intelligence is rapidly changing education, and the …
-
Lindsay Deibler-Wallace, assistant head of Upper School, took no action to protect them after telling parents …
Lindsay Deibler-Wallace, assistant head of Upper School, took no action to protect them after telling parents that “boys will be boys.” https:// arstechnica.com/tech-policy/20 26/07/high-school-defends-staying-silent-while-boys-ma…
-
Anthropic’s Opus 5 Is Better at Resisting Prompt Injection
The chart is interesting. On the IPI benchmark, Opus 5 improved over Opus 4.8, reducing the probability of an attacker succeeding within 15 attempts from 5.5% to 2.0%, and from 0.5% to 0.2% on 1 attempt. It also improved on Sonnet…
-
Suppose you're briefing your stakeholders on a rogue AI agent hacking your infrastructure. Do you call it a th…
Suppose you're briefing your stakeholders on a rogue AI agent hacking your infrastructure. Do you call it a threat actor? Me and @ Secitup discuss this and SO MUCH more as we dissect the (excellent) Hugging Face post mortem. https…
-
AI scammers outperform humans when it comes to building trust
The AI chatbot was more effective at creating “exploitable trust” than the humans.
-
The Good, the Bad and the Ugly in Cybersecurity – Week 31
Police flag 4,000 URLs to disrupt The Com, theft victims sue Apple over a $1.8M wallet scam, and OpenAI and Anthropic models reach real systems in cyber tests.
-
The $5 million threat: AI Is supercharging phishing attacks
According to the newly-published study, phishing and social engineering are becoming more expensive to recover from, trickier to detect, and increasingly augmented by artificial intelligence. Read more in my article on the Fortra …
-
The Xcode Assassin Returns: A Deep Dive Into the Latest XCSSET Version
Analysis of XCSSET v40 reveals a macOS malware targeting developers via Xcode. Unit 42 used advanced pattern matching and AI to decode its logic. The post The Xcode Assassin Returns: A Deep Dive Into the Latest XCSSET Version appe…
-
Anthropic Says Claude Hacked Into 3 Organizations During Cybersecurity Tests
In a review triggered by OpenAI’s Hugging Face incident, Anthropic discovered three of its AI models had breached real-world organizations during third-party evaluations.
-
I'm not going to mince words: the major AI labs are negligent in protecting the public from their agents. We n…
I'm not going to mince words: the major AI labs are negligent in protecting the public from their agents. We need government regulation now or at the very least a private cause of action with guaranteed punitive damages for agents…
-
What the Singularity Actually Means
What the Singularity Actually Means/images/what-the-singularity-actually-means.webp/images/what-the-singularity-actually-means.webp The singularity might be my favorite idea in all of AI, and it has a real, specific meaning that I…
-
Read This Before You Buy That TV Streaming Stick
Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-time fee, warning that they secretly rent the user's Internet connection out to s…
-
What’s new in Microsoft Security: July 2026
This month’s updates help security and IT teams secure their AI environments, use AI to defend, and strengthen the foundations that AI-powered operations depend on. The post What’s new in Microsoft Security: July 2026 appeared…
-
What’s new in Microsoft Security: July 2026
This month’s updates help security and IT teams secure their AI environments, use AI to defend, and strengthen the foundations that AI-powered operations depend on. The post What’s new in Microsoft Security: July 2026 appeared…
-
Claude Mythos — Hype vs. Reality: What Security Teams Need to Know
In this edition of Reporters' Notebook, our journalists discuss the ins and outs of Anthropic's Claude Mythos rollout. How seriously should we take its risks? How big of a deal is it?
-
Huntress hits an inflection point
CEO Kyle Hanslovan outlines how Huntress is evolving its research-led strategy, adopting AI with human oversight, and expanding its partner network to protect businesses against rapid, automated cyberattacks.
-
The Answer to the Harness Question
The Answer to the Harness Question/images/the-answer-to-the-harness-question.webp/images/the-answer-to-the-harness-question.webp Martin Casado posted something about AI harnesses that captures where a lot of smart people are stuck…
-
OpenAI's Rogue Model Claims More Victims Beyond Hugging Face
OpenAI's goal-seeking agent compromised a Modal customer environment and others during its sandbox escape.
-
Red Agents vs. Blue Agents: How to Make AI Better at Defense
The agentic AI playing field was heavily tilted toward offense, so researchers began using red team agents to help teach their blue counterparts.
-
Who's Liable When AI Agents Escape? Hugging Face Breach Raises Hard Questions
Dark Reading walks through the many twists and turns in the bizarre story of how OpenAI's agent AI system broke out of its sandbox and decided to target Hugging Face, and what CISOs should be aware of.
-
Hugging Face Hack: Lessons for Cyber Defenders
Dark Reading Confidential Episode 20: Expert Rich Mogull reflects on lessons cyber teams should pull from the OpenAI agent's attack on Hugging Face.
-
Better security starts with better questions
Learn how better questions, trusted AI, and human judgment help security leaders make confident decisions and build resilient systems. The post Better security starts with better questions appeared first on Microsoft Security Bl…
-
Anthropic is finding bugs faster than Microsoft can fix them
Microsoft is on a mad dash behind the scenes to patch exploits before hackers find them.
-
When AI Agents Escape Sandboxes, Old Security Rules Apply
OpenAI's recent AI agent sandbox escape proves traditional security principles matter more than ever: limit access, isolate execution, log everything.
-
Stronger AI Safety Requires Peeking Inside the 'Black Box'
Researchers propose focusing on identification of certain cognitive elements in LLMs that indicate when AI systems may take an unwanted action.
-
The Next Evolution of MDR: Preemptive Defense and Agentic Investigation
For years, security operations followed a familiar sequence: detect suspicious activity, investigate what happened, and respond before it caused significant harm. That model developed in a threat landscape where defenders had cons…
-
Former Citigroup CISO Blauner on What Makes A Great Security Leader
The cybersecurity pioneer discusses the evolution of the CISO role, AI's impact on careers, and why operational resilience is the profession's next frontier.
-
Rapid7 and Exclusive Networks expand partnership to modernize security operations and accelerate customer success
Claudia Zoon is Senior Manager, Channel Sales at Rapid7. Across Belgium, the Netherlands, and Luxembourg, organizations are accelerating digital transformation through AI, cloud adoption, and increasingly connected business operat…
-
AI Agent Drives Espionage Attack on Thai Ministry of Finance
Attackers used Hermes, an autonomous open source tool, in unrestricted YOLO mode to conduct espionage against Thailand's Ministry of Finance.
-
Microsoft unveils AI security tools it says outperform competing platforms
Microsoft says tools cost less than competing ones and outperform them, too.
-
Agentic Browsers Rewind Web Security by 20 Years
PleaseFix class of flaws makes it easy to socially engineer agentic browsers and highlights weaknesses in how they handle cross-origin requests.
-
Claude warns users that by hitting the share button anyone with the link can view the content, but it is not c…
Claude warns users that by hitting the share button anyone with the link can view the content, but it is not clear that they are creating a document that can be indexed by Google and will come up in searches. https:// futurism.com…
-
Rethinking security for the age of AI
The physics of cybersecurity are changing. Introducing security's new cyber stack: Project Perception. The post Rethinking security for the age of AI appeared first on Microsoft Security Blog .
-
Rethinking security for the age of AI
The physics of cybersecurity are changing. Introducing security's new cyber stack: Project Perception. The post Rethinking security for the age of AI appeared first on Microsoft Security Blog .
-
Enhancing AI security through global AI red teaming
Microsoft's External Red Team Alliance (EXTRA) is a global AI security initiative designed to advance AI safety research and red teaming. By partnering with universities, researchers, and regional experts, EXTRA helps identify eme…
-
Enhancing AI security through global AI red teaming
Microsoft's External Red Team Alliance (EXTRA) is a global AI security initiative designed to advance AI safety research and red teaming. By partnering with universities, researchers, and regional experts, EXTRA helps identify eme…
-
Breach Please S0:E3 is live. We spent most of the time trying to deconstruct the gaping hole between OpenAI's …
Breach Please S0:E3 is live. We spent most of the time trying to deconstruct the gaping hole between OpenAI's public statements about its agent hack and the Reuters reporting on the same. https:// youtu.be/sW0HMEVov7A
-
What Our AI SOC Analyst Can Do (and What We Won’t Let It Do)
See agentic security operations governance in action: Huntress' AI SOC lets Athena investigate and act autonomously within guardrails our human analysts set.
-
The Top CISO Stories from Around the Web: July 2026
Between tight post-quantum deadlines and hackers turning lookalike AI tools into dangerous new entry points, today's CISOs are facing an unprecedented operational squeeze. This month, we dive into the fundamental questions securit…
-
The Good, the Bad and the Ugly in Cybersecurity – Week 30
Authorities arrest Kratos's developer, HollowGraph hides C2 in 2050 calendar events, and OpenAI's models breach Hugging Face to steal benchmark answers.
-
Your Best Analyst Shouldn’t Be a Person. It Should Be a Capability Everyone Can Summon.
Transform expert SOC analysis into an on-demand AI capability to empower all analysts and accelerate threat resolution.
-
Breach of Confidence: 24 July 2026
I ve been trying to explain to my kids why I don t let them use AI to write their homework. Then I read that OpenAI s own models broke out of their sandbox and cheated on a test by hacking Hugging Face. So basically, we ve raised …
-
The Entire Game for AI Is Articulation of Ideal State
A person showing an AI the exact structure they imagine, and the AI building it/images/ai-ideal-state-articulation.webp/images/ai-ideal-state-articulation.webp I've been saying this for something like eight months now, with varyin…
-
OpenAI’s AI “goes rogue” and hacks Hugging Face: what you need to know
You can't have failed to hear the news headlines about "rogue" OpenAI models hacking into another AI organisation, Hugging Face. But what has actually happened, who is to blame, and is it as serious as some of the reports suggest?…
-
What Happened Between OpenAI and Hugging Face?
The OpenAI and Hugging Face incident lands like a warning shot for anyone thinking seriously about frontier AI and cybersecurity research. A model evaluation crossed the neat boundary of a research environment, reached a live thir…
-
Inside FakeAgent: How a Claude Desktop Malvertising Campaign Hit 29 Organizations with SectopRAT
On July 21 and July 22, Huntress observed a number of attacks that started with a malicious public Claude Artifact hosted on a legitimate Claude domain, and ended in organizations being infected by the SectopRAT stealer.
-
OpenAI says its AI agent broke out of testing sandbox to hack Hugging Face
"This is day one for cybersecurity in the age of agents," Hugging Face CEO says.
-
From Triage Grind to Strategic Operator: The New AI SOC Career Path
Learn how AI is reshaping SOC careers, elevating analysts from manual triage to strategic threat hunting and AI governance.
-
The OpenAI Hack Was a Mini Paperclip Maximizer
One thing that I don't think enough people are thinking about with this OpenAI / Hugging Face incidenthttps://thehackernews.com/2026/07/openai-says-its-own-ai-models-escaped.html is that it's an actual instance of the famous Paper…
-
When discussing AI safety, it's critical to understand: 1. Models can only act on the world when we give them …
When discussing AI safety, it's critical to understand: 1. Models can only act on the world when we give them a path with which to do so 2. Everyone understands prompts aren't guardrails 3. Anyone discussing a real-world safety is…
Last fetch 5m ago · 0 new · 2 source error(s)