A pull request lands with a tidy bug report in the description. A bot reads it before any person does, pulls a few shell commands out of it, gets them…
Apple Releases Security Updates Patching Nearly 200 Vulnerabilities Across macOS, iOS, iPadOS, and Safari
Apple has released security updates for its operating systems, addressing nearly 200 vulnerabilities. Thank you for being a Ghacks reader.
ShinyHunters Claims Ernst & Young Hack
Ernst & Young previously confirmed that personal and financial information was stolen from a third-party management platform.
Malicious npm Packages Deploy Cross-Platform RAT Targeting Alibaba Developers
A cluster of malicious npm packages has been used to deliver a cross-platform remote access trojan against developers who use Alibaba-related tools. The…
Attackers Split RAT Components Across npm Packages to Evade Isolated Code Reviews
Attackers have been observed distributing a modular Remote Access Trojan (RAT) through the npm ecosystem by deliberately splitting malicious functionality…
The energy sector’s OT cybersecurity talent is retiring faster than it can be replaced
A ransomware hit lands a chemical plant in a safe state. Nobody is hurt, the site holds steady, and the operators begin the restart. The systems stay…
Cybercriminals Use Adversarial Prompt Injection to Evade AI-Powered Security Tools
Cybercriminals are rapidly operationalizing adversarial prompt injection techniques to evade AI-powered security controls, signaling a shift toward…
Specter: Open-source NFC reader bug sweep for Flipper Zero
Specter is a Flipper Zero app that finds powered NFC readers by listening for the radio field they give off. The readers it hunts work at 13.56 MHz. The…
Your AI agents can reach data no one approved
A credential expired. An AI agent kept using it anyway, and a mid-sized company’s systems went down for a quarter’s worth of trouble before anyone traced…
OpenAI Open-Sources Codex Security CLI to Find, Validate, and Fix Code Vulnerabilities
OpenAI has open-sourced Codex Security, a command-line interface and TypeScript SDK designed to help engineering and security teams identify, validate,…
Two Compromised joyfill npm Packages Run RAT When Imported Into Node.js
Beta release versions of two npm packages in the @joyfill namespace have been compromised to deliver a remote access trojan (RAT) associated with the…
Autonomous AI Agent Escapes Sandbox and Breaches Hugging Face Production Systems
Hugging Face has reported a sophisticated intrusion that occurred in July 2026. In this incident, an autonomous AI agent escaped from its evaluation…
Android malware detection collapses when the context stage comes out
A phone backup app asks for storage, contacts, SMS, and call logs. A device-management tool asks for more than that. Run either one past a machine…
Claude AI Autonomously Discovers Cryptographic Weaknesses That Escaped Expert Review
Researchers at Anthropic reported that Claude Mythos Preview autonomously discovered new cryptographic attacks against
IT Security News Hourly Summary 2026-07-29 06h : 3 posts
3 posts were published in the last hour 4:2 : First-Ever Fully Autonomous AI Cyberattack Exploits 0-Day Flaws to Infiltrate Hugging Face 4:2 : NGINX Heap Overflow Flaw Could Let Unauthenticated Attackers Execute Arbitrary Code 4:2 : OpenAI Open-Sources Codex…
First-Ever Fully Autonomous AI Cyberattack Exploits 0-Day Flaws to Infiltrate Hugging Face
Between July 9 and July 13, 2026, security researchers documented what is being called the first fully autonomous AI agent cyberattack to chain zero-day…
NGINX Heap Overflow Flaw Could Let Unauthenticated Attackers Execute Arbitrary Code
A high-severity heap buffer overflow vulnerability has been identified in the NGINX Stream module’s script engine. This vulnerability may allow…
OpenAI Open-Sources Codex Security CLI for Finding, Validating, and Fixing Security Vulnerabilities
OpenAI has open-sourced Codex Security, a command-line tool and TypeScript SDK designed to help developers find, validate, and fix security…
America bans imported robots due to supply chain and security risks
Docs point to China’s Unitree as prime example of the foreign clanker threat
ISC Stormcast For Wednesday, July 29th, 2026 https://isc.sans.edu/podcastdetail/10028, (Wed, Jul 29th)
This post has no text preview — click the link below to read the original article. This article has been indexed from SANS Internet Storm Center, InfoCON: green Read the original article: ISC Stormcast For Wednesday, July 29th, 2026 https://isc.sans.edu/podcastdetail/10028,…
Measuring LLMs’ Ability to Perform Cryptanalysis
There’s new benchmark measuring AI’s ability to perform mathematical cryptanalysis. Anthropic’s frontier model actually found new attacks. The benchmark:…
IT Security News Hourly Summary 2026-07-29 03h : 3 posts
3 posts were published in the last hour 0:31 : OpenAI’s Rogue AI Agent Hacked More Than Just Hugging Face 0:31 : AI agent hacks national finance ministry, Botnet uses blockchain, Healthcare chain reopens 0:31 : Cyera agrees to acquire…
OpenAI’s Rogue AI Agent Hacked More Than Just Hugging Face
In a new disclosure, OpenAI says its agent used exposed logins to gain access to at least four “publicly available services” in its unhinged quest to…
AI agent hacks national finance ministry, Botnet uses blockchain, Healthcare chain reopens
Hospital ransomware fallout, blockchain botnet C2, and AI agent loose in Thailand’s Finance Ministry. South Carolina’s AnMed reopened some physician…