Zenity researchers reported the findings to Anthropic and OpenAI in late 2025 and early 2026, but they remain unpatched.
Category: securityweek
Critical Paperclip Flaw Allowed Admin Access, Code Execution
An attacker could self-register, sign in for board-level API access, and import a new company for code execution.
Belarusian Ransom Cartel Mastermind Gets 16 Years in Prison
Maksim Silnikau was the creator and administrator of the ransomware group and involved in Angler EK’s distribution.
Meta AI Hacked External Systems During Cybersecurity Testing
The incident involved a testing environment set up by Irregular, similar to what Anthropic reported last week.
Cisco Patches Critical SD-WAN, IOS XE, FMC Vulnerabilities
Patches were rolled out for two dozen vulnerabilities, including one with public proof-of-concept (PoC) code.
Hackers Start Exploiting Recent JetBrains TeamCity Vulnerability
Tracked as CVE-2026-63077, the critical bug can be exploited without authentication for remote code execution.
How a $50,000 Exploit Chain Turned Bixby Against Samsung Phones
The chain involved the exploitation of several vulnerabilities in the Samsung Members and Samsung Account applications.
Black Hat USA 2026 – Summary of Vendor Announcements (Part 3)
Many companies are showcasing their products and services this week at the 2026 edition of the Black Hat conference in Las Vegas.
The Fourth Battlefield: The Growing Role of Cyber Operations in Global Conflict
CrowdStrike co-founder Dmitri Alperovitch discusses how cyber operations support kinetic warfare, signal coming conflicts, and reshape the global…
New Attack Methods Enable Malware to Hijack Passkey-Protected Accounts
Palo Alto Networks researchers have demonstrated attacks against Google’s synced passkey implementation.
AI Agents Targeted Real People and Projects During Cybersecurity Tests
AI Security Institute reports Anthropic and OpenAI models going rogue against real people, organizations, and open source projects.
311,000 Impacted by Brown Health Medical Group-MA Data Breach
Hackers stole personal information, medical records, and financial information from the organization’s server.
Cybersecurity Alliance Drafts SAFE Guidelines for Sharing AI Incident Data
The guidelines are the work of the recently launched Open Secure AI Alliance, which now includes 120 organizations.
AI Security Institute Reports Anthropic and OpenAI Models Going Rogue Against Organizations
In one instance, an unsanctioned model attempted to inject malicious code into an open source repository.
CISA Warns of Exploited Langflow, N-central, and Tomcat Vulnerabilities
The flaws can be exploited for remote code execution, authentication bypass, and EncryptInterceptor bypass.
Over 400 NPM Packages Infected in ChainDrop Supply Chain Attack
The malware was designed to steal and exfiltrate secrets, and to propagate itself via stolen NPM and GitHub credentials.
Water Sector Cyberattacks Reportedly Hit at Least 12 States
Georgia has been confirmed as one of the attacked states after Clayton County reported a pump station disruption.
Rethinking AI Security: Why CASB and DLP Need an Interaction-Aware Layer
Build your strategy around answering these questions to ensure employees use AI productively while keeping sensitive data, IP, and agent behavior within…
Black Hat USA 2026 – Summary of Vendor Announcements (Part 2)
Many companies are showcasing their products and services this week at the 2026 edition of the Black Hat conference in Las Vegas.
CISO Conversations: Russ Kirby – Passion Is the Antidote to Burnout
Russ Kirby, CISO at Ping Identity, shares how passion, courage, and “good enough” thinking shaped his path from HP to the C-suite—and what keeps him up at…