AI/MLHugging Face ‘attacker’ revealed to be OpenAI agents that escaped testing sandboxLaura FrenchJuly 22, 2026OpenAI said GPT-5.6 Sol and a pre-release model exploited vulnerabilities to “cheat” on ExploitGym.
IdentitySharePoint vulnerability steals machine keys; fourth recent exploitSteve ZurierJuly 22, 2026New SharePoint flaw exploited as attackers steal machine keys for lasting access.
Application securityJADEPUFFER agentic ransomware returns, targets AI assets with ENCFORGE payloadLaura FrenchJuly 22, 2026The agent abused the victim’s Docker daemon to access and encrypt AI-related files.
RansomwareQilin exploits Palo Alto Networks GlobalProtect VPN firewallsSteve ZurierJuly 21, 2026Qilin exploited a patched Palo Alto VPN flaw, highlighting the cost of delayed patching.
Application securityHugging Face uses GLM 5.2 to investigate AI agent-driven cyberattackLaura FrenchJuly 20, 2026Hugging Face turned to an open-weight model after being restricted by frontier model guardrails.
Cloud SecurityCritical ServiceNow AI flaw exploited days after patch releaseSteve ZurierJuly 20, 2026Attackers exploit critical ServiceNow AI bug just days after security patch release.
Application securityOver 1 million malicious emails found using text salting to fool AI scannersLaura FrenchJuly 17, 2026Text salting fills emails with hidden benign content to mask malicious phishing lures.
RansomwareStolen identities cause 79% of ransomware attacks, says Sophos reportSteve ZurierJuly 17, 2026Identity failures replace software flaws as ransomware's top access vector.
Vulnerability ManagementCritical Oracle EBS bug added to CISA list of exploited vulnerabilitiesLaura FrenchJuly 17, 2026The flaw allows an unauthenticated attacker to remotely compromise Oracle Payments.
RansomwareAttackers execute a complete ransomware operation in under 24 hoursSteve ZurierJuly 16, 2026Spirals ransomware encrypted a victim in under 24 hours, underscoring the need for rapid containment.