Next.js Patches Nine Security Flaws Enabling SSRF, Middleware Bypass, DoS, and Internal Endpoint Disclosure

The Next.js team has released security updates that address nine vulnerabilities affecting the App Router, Server Actions, rewrites, image optimization, caching, and middleware deployments. Organizations are urged to upgrade to Next.js versions 15.5.21 or 16.2.11 immediately, as these updates fix…

OpenAI models escape containment, hack Hugging Face

<p>OpenAI reported this week that its autonomous AI models escaped an isolated testing environment during a training exercise and breached Hugging Face, an AI collaboration platform.</p> <p>Last week, Hugging Face <a target=”_blank” href=”https://huggingface.co/blog/security-incident-july-2026″ rel=”noopener”>disclosed</a> that it “detected and responded to…