What's happening in security
Breaches, credential dumps, actively exploited bugs and AI incidents — pulled from 2,936 items across public feeds, Have I Been Pwned and CISA KEV.
Biggest this week
- Unauthenticated attackers are bypassing Cisco ISE’s management interface (CVE-2026-76460) — Help Net Security, 7h ago
- Google fixes actively exploited Android zero-day on Pixel devices — BleepingComputer, 1d ago
- Cisco warns customers of actively exploited zero-day in email gateways — CyberScoop, 2d ago
- Cisco patches actively exploited email gateway zero-day (CVE-2026-76461) — Help Net Security, 2d ago
- Active Exploitation Triggers Emergency Patch for Cisco ISE Zero-Day — SecurityWeek, 11h ago
-
What 90 days and a small budget can buy in AI agent security
In this interview with Help Net Security, Prasad Tharippala, Field CISO at Versa, explains what organizations miss when they run open-weight models in house. He covers the hidden costs of GPU infrastructure, licensing review and s…
-
Dicker Data’s half-yearly NZ slowdown offset by Australian growth
Dicker Data has seen overall growth in the business during the first half of its 2026 financial year, supported by “particularly strong” growth in the Australian side of its business, more than making up for declines seen in New Z…
-
Breaking Claude Code Opus 5 Auto Mode
Breaking Claude Code Opus 5 Auto Mode Anthropic are putting a great deal of faith in Claude Code's auto mode for protecting their coding agent users against prompt injection attacks. They recently made that the default and have ma…
-
Nearly 700 rogue AI agents coordinated in the Hugging Face attack
New details about the July attack on Hugging Face reveal that hundreds of AI agents driven by OpenAI's internal IM1 model coordinated the compromise through an unauthorized message board. [...]
-
OpenAI Says Reward Hacking Drove AI Agents to Exploit Zero-Days and Breach Hugging Face
OpenAI on Wednesday revealed that reward hacking was a key driver behind the artificial intelligence (AI)-powered hack of Hugging Face last month, adding that it found evidence of misaligned behavior as early as late May. The inci…
-
Unit 42 warns AI has shifted balance of power from defenders to attackers
Palo Alto Networks’ threat intelligence team said the early waves of threats riding on agentic AI models have broken in the wild, and organizations are unprepared for what’s coming next. The post Unit 42 warns AI has shifted balan…
-
100-plus companies call for ‘global surge’ in AI-powered cyber defense
OpenAI, Anthropic, Google, Microsoft, and others say there’s a narrow “defenders’ window” to strengthen security before AI-powered attacks become more sophisticated. The post 100-plus companies call for ‘global surge’ in AI-powere…
-
“Sorry, I can’t help with that”: How your guardrails might become the attacker’s best friend
In his first Threat Source newsletter, David Bianco explores the critical need for operational sovereignty in customizing AI guardrails to maintain the defender’s advantage.
-
Agentic AI Risks, CVE Program Concerns Permeate Black Hat USA 2026
This installment of the Reporters' Notebook video series discusses the topics that dominated the cybersecurity conference, such as AI's effects on vulnerability reporting and security research.
-
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Elon Musk claimed he was aware of “literally zero” CSAM content created through Grok. A new lawsuit from thousands of real victims say the model was trained on their child abuse. The post Former sexual abuse victims say Grok used …
-
Hundreds of agents went rogue in lead up to Hugging Face breach
OpenAI released a technical breakdown of the historic incident and plans changes to prevent such an occurrence from happening again.
-
Claude, Codex, and Hermes installed unowned code inside corporate networks
227 install commands were found in corporate docs pointing at code nobody owns.
-
Boardroom Battles 2026: ASD’s Cyber Priorities & AI Risk
The Australian Signals Directorate’s 2026 board priorities and frontier AI guidance show why speed alone won’t stop AI-era cyber threats.
-
Amazon Kiro Prompt Injection Can Exfiltrate Sensitive Data Through Kiro Powers
Cybersecurity researchers have disclosed details of a vulnerability in Amazon Kiro, an artificial intelligence (AI)-powered, agentic integrated development environment (IDE), that could facilitate data exfiltration via prompt inje…
-
How OpenAI let a mob of LLM agents game a test and ransack Hugging Face
Without authorization, 1,200 OpenAI agents conspired among themselves to game a test.
-
OpenAI Agents Coordinated via Makeshift Message Board Ahead of Hugging Face Hack
New training environments will teach AI models to distrust instructions arriving from other agents outside sanctioned channels. The post OpenAI Agents Coordinated via Makeshift Message Board Ahead of Hugging Face Hack appeared fir…
-
Alleged TeamPCP Hackers Charged in Australia Over Major Supply Chain Attacks
The Australian Federal Police (AFP) has charged two Western Australian men with a combined total of 14 offences over their alleged role in TeamPCP, the cybercrime group behind the March 2026 compromise of the open-source security …
-
Okta Shares Surge on Strong Earnings, Growing Demand for AI Identity Security
The identity security company beat quarterly expectations and raised its outlook as enterprises face growing pressure to secure AI agents and other non-human identities. The post Okta Shares Surge on Strong Earnings, Growing Deman…
-
What the Data Says About AI in Security Operations in 2026
AI is officially mainstream in security operations. According to Prophet Security's State of AI in Security Operations 2026 report (produced from ViB’s survey of 250+ cybersecurity pros), 40% of security teams now use AI daily. An…
-
In today's Breach Please, me and @ Secitup discuss the OpenAI post-mortem on their hack of Hugging Face. We ge…
In today's Breach Please, me and @ Secitup discuss the OpenAI post-mortem on their hack of Hugging Face. We generally agree that the post mortem doesn't make them look any better. We then dissect business lessons you can take away…
-
The Future of AI-Driven Security Depends on Complete Data
For twenty-five years, "data" in security meant logs and events. But logs are a lossy representation of reality. The post The Future of AI-Driven Security Depends on Complete Data appeared first on SecurityWeek .
-
LLM-Based Social Engineering Scams
OpenAI disrupted a social engineering group from Cambodia that used ChatGPT. Its scope is impressive: The network simultaneously conducted multiple types of scams, often blending elements from different schemes. For instance, oper…
-
Abnormal AI expands email security from detection to data protection and phishing-simulation training
Abnormal AI announced an expansion of its email security platform with three new capabilities: Control Center, Email DLP Rules, and AI Phishing Coach upgrades. Together, the launch extends Abnormal’s behavioral AI across all three…
-
AI will not fix a governance problem in your camera estate
Camera systems often outlive the companies that install them. In this Help Net Security interview, Rob Janssens, EMEA Cyber Security Director at Hikvision Europe, discusses what happens when the integrator is gone, the documentati…
-
The best human hacking team still out-solved the best AI team
Bring an AI agent to a hacking competition and you would expect to find it propping up the teams who were struggling. In the 2026 Global Cyber Skills Benchmark, agents showed up in 17 of the Top 25 finishers. The people who least …
-
Headline: AI writes lots of code. Buried under the headline: that doesn't always translate into features reach…
Headline: AI writes lots of code. Buried under the headline: that doesn't always translate into features reaching users. Oh, and even when that code does reach users, it doesn't work reliably. And when it doesn't, it takes longer …
-
Qwen3.8-Flash-Next
Qwen3.8-Flash-Next Another open weights model from Qwen. This one is "a multimodal MoE model that also serves as an early preview of the architecture used in Qwen4". It's pretty big: 125B tokens, but only 6B active which means it …
-
Dicker Data brings Huddly AI camera systems to New Zealand
Dicker Data New Zealand has secured a new distribution partnership with Norwegian AI-powered video technology provider Huddly. The agreement will see Dicker Data distribute Huddly’s full range of intelligent camera systems to part…
-
'HTTP Terminator' Hunts for Novel Desync Attacks
James Kettle of PortSwigger talks with the Dark Reading News Desk about his AI-powered open source tool, which found new HTTP request-smuggling techniques.
-
OpenAI’s Hugging Face Hack Debrief Raises More Questions Than It Answers
The AI giant acknowledges that it could have done far more to prevent its AI agents from going rogue. But it still fails to explain why it didn't see this fiasco coming.
-
OpenAI: Agent behavior that led to Hugging Face intrusion formed in May
The company says the breach stemmed from a systemic failure of alignment and security, and has taken measures to prevent agents from independently orchestrating complex cyberattacks. The post OpenAI: Agent behavior that led to Hug…
-
Sometimes I hear non-technical people speculating that this is a thing that could happen and I am posting it h…
Sometimes I hear non-technical people speculating that this is a thing that could happen and I am posting it here to let them know that yes, this is a thing that happens. https://www. theguardian.com/world/2026/aug /26/fake-thinkt…
-
Stop Building a 2003 SOC with AI: Local Context, Failure Modes and Your Path (Part 3)
In Part 1 of this series , we dumped a pile of uncomfortable questions on you and promised answers. In Part 2 of the series , we talked about why 1990s-2000s alert triage must die. The core thesis, if you recall: if you add AI age…
-
There is not enough popcorn in the world to talk to address the fact that OpenAI has been notified by 15 state…
There is not enough popcorn in the world to talk to address the fact that OpenAI has been notified by 15 state AGs to retain records for its Hugging Face incident (and any others it might have caused that aren't reported). Me and …
-
AI Speeds Up Malware Development, Not Its Success Rate: Analysis
Palo Alto Networks Unit 42 analyzed 405 AI-linked malware samples and found only 12 reached production endpoints. The post AI Speeds Up Malware Development, Not Its Success Rate: Analysis appeared first on SecurityWeek .
-
Clover: Building the Future of Product Security
This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Aug. 26, 2026 – Watch the Video Clover Security is on a mission to enable both humans and AI to build secure-by-design software, at scale, with…
-
AnonyMousKIT phishing-as-a-service uses AI voice calls to steal iPhone passcodes
A phishing-as-a-service (PhaaS) platform called AnonyMousKIT is automating the theft of Apple ID credentials needed to remove Activation Lock from stolen iPhones, SOCRadar found. By leveraging a critical flaw – the use of bare rel…
-
Spyware for Babies
The New York Times has a long article ( alt link ) on surveillance systems aimed at babies. They are increasingly using AI. Nanit and its rivals want to own 24/7 health tracking for the sub-four-foot set. And their already astonis…
-
Imagine the SOC Without a Queue: From Alert Backlog to AI Hypothesis Engine
The SOC we've always known was built around a model that guarantees most of the alert queue will never receive analyst review. There's never time. In a traditional SOC, the typical progression follows a well-known pattern: an aler…
-
Choose your fighter: Balancing competing requirements to select models for your AI SOC
Selecting a model for your security operations center (SOC) and digital forensics and incident response (DFIR) tasks is important, but selecting the best one is more involved than you might think. Here's how to choose.
-
OpenAI Bans Russian ChatGPT Accounts Used to Run Influence Operation
OpenAI on Tuesday said it banned a cluster of Russian ChatGPT accounts that used VPNs to bypass access restrictions and run an influence operation, which relied on its artificial intelligence (AI) tool to generate social media pos…
-
Quoting Paul Dix
The fact that AI wrote 1M LOC and then refined it over the course of the next couple of months to produce a reliable piece of software that is currently running on millions of developer machines is absolutely mind blowing. And you…
-
Linux Foundation takes on TRACE, a hardware-backed runtime evidence specification for AI agents
The Linux Foundation announced the contribution of TRACE (Trust, Runtime Attestation and Compliance Evidence), from OPAQUE. Collaboratively developed by AMD, Intel, Microsoft, OPAQUE and the Technology Innovation Institute (TII), …
-
Fake Apple Support AI Calls Target Stolen-Device Owners for Passcodes and 2FA Codes
Cybersecurity researchers have disclosed details of a phishing-as-a-service (PhaaS) platform built to strip Apple's Activation Lock from stolen devices, using rented AI voice agents that call theft victims posing as Apple Support …
-
Production data in testing is still common, and Tricentis’ CISO wants it gone
In this Help Net Security interview, Erika Dean, CISO at Tricentis, talks about keeping production data out of test environments and why she thinks the alternatives are good enough now. She explains how her team caught a prompt in…
-
Hottest cybersecurity open-source tools of the month: August 2026
Presented here is a curated selection of noteworthy open-source cybersecurity solutions that have drawn recognition for their ability to enhance security postures across diverse settings. SkillSpector: NVIDIA’s open-source securit…
-
Tech NZ urges SMEs to build digital foundations before AI
Industry body Tech New Zealand has urged small and medium-sized businesses to strengthen their digital foundations before pursuing broader AI adoption. Tech NZ’s latest report found New Zealand is well placed to harness the benefi…
-
Gartner sees market for securing AI reach US$4.8bn by 2027
The securing of AI use is becoming one of the fastest-growing areas of cybersecurity as organisations rush to protect AI systems from new and emerging threats, with the global market projected to reach US$4.8 billion. The securing…
-
Hidden Prompts Trick AI Into False Email Summaries
With some simple HTML that's invisible to users, attackers can manipulate AI-powered email summarizers into producing malicious information.
-
Perplexity’s on-device AI offering promises data control and lower token costs
Perplexity on Tuesday rolled out an offering that runs the AI entirely on a local machine, and that, it said, will keep “private data local and escalating to the cloud only when a task needs it.” The service, called simply Portabl…
Last fetch · 0 new