OpenAI Agent Used Exposed Credentials Across Four Services During Hugging Face Breach
OpenAI on Tuesday revealed the rogue artificial intelligence (AI) agent that escaped its sealed evaluation environment and broke into Hugging Face's producti...
20 articles
OpenAI on Tuesday revealed the rogue artificial intelligence (AI) agent that escaped its sealed evaluation environment and broke into Hugging Face's producti...
Ernst & Young previously confirmed that personal and financial information was stolen from a third-party management platform. The post ShinyHunters Claims Er...
A pull request lands with a tidy bug report in the description. A bot reads it before any person does, pulls a few shell commands out of it, gets them approv...
Attackers have been observed distributing a modular Remote Access Trojan (RAT) through the npm ecosystem by deliberately splitting malicious functionality ac...
A ransomware hit lands a chemical plant in a safe state. Nobody is hurt, the site holds steady, and the operators begin the restart.
Cybercriminals are rapidly operationalizing adversarial prompt injection techniques to evade AI-powered security controls, signaling a shift toward targeting...
Specter is a Flipper Zero app that finds powered NFC readers by listening for the radio field they give off. The readers it hunts work at 13.
OpenAI has open-sourced Codex Security, a command-line interface and TypeScript SDK designed to help engineering and security teams identify, validate, and r...
A credential expired. An AI agent kept using it anyway, and a mid-sized company’s systems went down for a quarter’s worth of trouble before anyone traced the...
Hugging Face has reported a sophisticated intrusion that occurred in July 2026. In this incident, an autonomous AI agent escaped from its evaluation sandbox,...
Beta release versions of two npm packages in the @joyfill namespace have been compromised to deliver a remote access trojan (RAT) associated with the DEV#POP...
Researchers at Anthropic reported that Claude Mythos Preview autonomously discovered new cryptographic attacks against the post-quantum signature candidate H...
A phone backup app asks for storage, contacts, SMS, and call logs. A device-management tool asks for more than that.
Popular telehealth provider Hims & Hers "shared consumers’ sensitive health information with third-party advertising platforms such as Meta and Snap despite ...
A high-severity heap buffer overflow vulnerability has been identified in the NGINX Stream module’s script engine. This vulnerability may allow unauthenticat...
There’s new benchmark measuring AI’s ability to perform mathematical cryptanalysis. Anthropic’s frontier model actually found new attacks.
A party-line vote in the Senate installed Jay Clayton as director of national intelligence, a job that has drawn increasing scrutiny during Donald Trump's se...
Reported by Bleeping Computer. A proof-of-concept exploit was released for a vulnerability in Windows Active Directory Certificate Services (AD CS) known as ...
As reported by Bleeping Computer, Arista released a patch for a critical command injection vulnerability affecting on-premises VeloCloud Orchestrator (VCO) d...
As reported by Dark Reading, Operation Cronos, a significant international law enforcement effort, successfully dismantled LockBit, once one of the most domi...