-
An autonomous AI agent powered by OpenAI models breached Hugging Face’s production infrastructure in July 2026 after escaping its evaluation sandbox via a zero-day vulnerability. Documented by HiddenLayer’s Research Team on July 31, the age…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Arch Linux has temporarily disabled package adoptions on the Arch User Repository (AUR) after detecting a wave of malicious activity targeting orphaned and unmaintained packages. The Arch Linux DevOps team confirmed the emergency measure on July 30, 20…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
The double-extortion ransomware group CRPx0 has listed Hyundai’s Turkish operations on its dark web leak site, claiming to have exfiltrated 1.5 GB of sensitive personnel and recruitment data from the automaker’s assessment systems. Accordin…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
HackerOne has rolled out a significant policy change requiring all hackers to complete identity verification before submitting reports to Bug Bounty Programs (BBPs). The update, effective immediately, aims to strengthen platform integrity and meet regu…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A newly disclosed macOS malware campaign dubbed MacSync weaponizes fake Claude AI installation guides to deploy a six-stage stealer and remote access trojan. Documented by Huntress, the kit targets browser credentials, keychain secrets, and cryptocurre…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A broken access control vulnerability in Keycloak could allow unauthorized administrator accounts to access users’ personal information. This issue, tracked as CVE-2026-17059, affects the Keycloak Admin REST API and was discovered by researcher E…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Ransomware operators are increasingly deploying “ransomware killers” that surgically overwrite the memory of security processes instead of simply terminating them, allowing encryption to proceed. At the same time, endpoint tools appear to run normally …
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
JetBrains has revealed a critical security vulnerability in TeamCity On-Premises that enables unauthenticated remote code execution (RCE) on affected servers. This poses a significant risk to CI/CD environments exposed over HTTP(S). The vulnerability, …
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Google has announced that its AI-assisted security workflows have helped Chrome fix 10,721 security vulnerabilities across Chrome Stable milestones 149 and 150. This number exceeds the total number of bugs patched across the previous 23 milestones comb…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
ClickFix-style fake macOS updates are now being weaponized with EtherHiding-backed command‑and‑control and a DPRK-linked crypto laundering network, turning a routine search click into a full-stack theft operation spanning browser, endpoint, blockchain,…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶


