Google has announced a series of network security improvements coming to Android 17, targeting vulnerabilities that allow network operators,…
700 OpenAI Agents Coordinate Attack on Hugging Face and Gain Remote Code Execution
OpenAI’s ExploitGym evaluation environment reportedly became the site of a large-scale, unsanctioned multi-agent campaign after hundreds of models found…
OpenAI Agents Exploited Linux Kernel Flaw on Company’s Own Systems
CISA has added the exploited flaw, CVE-2026-53362, to its KEV catalog, alongside a JFrog vulnerability exploited by OpenAI agents.
IT Security News Hourly Summary 2026-08-28 15h : 6 posts
6 posts published in the last hour 12:31700 AI Agents Linked to Hugging Face Security Breach 12:31CISA identifies security hurdles that led to very different results in two red-team engagements 12:31Polymorphic Phishing Attack Generates Unique Credential-Stealing Page on Every Visit…
700 AI Agents Linked to Hugging Face Security Breach
Around 700 AI agents created by OpenAI participated in the breach of Hugging Face during a cybersecurity evaluation, according to an independent…
CISA identifies security hurdles that led to very different results in two red-team engagements
The agency said its recent simulated cyberattacks offered several key lessons for many organizations.
Polymorphic Phishing Attack Generates Unique Credential-Stealing Page on Every Visit
A newly analyzed phishing operation is using server-side polymorphism to generate a distinct credential-harvesting page for virtually every request,…
Russian APT BlueDelta Uses HOOKEDGE to Target Defense and Diplomatic Organizations
BlueDelta (APT28) uses webhook.site and Microsoft Edge to hide HOOKEDGE espionage traffic targeting European governments. Recorded Future’s Insikt Group…
Critical WordPress Plugin Flaw Allows Unauthenticated Administrator Account Takeover
A critical authentication bypass vulnerability has been identified in the WPMU DEV Dashboard WordPress plugin, which could allow unauthenticated attackers…
IT Security News Hourly Summary 2026-08-28 14h : 25 posts
25 posts published in the last hour 11:32RMM Phishing Campaign Spans 46 Countries as Attackers Abuse Trusted IT Tools 11:32CrowdStrike Threat Hunts for Shell Command Obfuscation on VMware ESX 11:32AI Doesn’t Mean the End of Mathematics—at Least Not Yet 11:32CISA:…
RMM Phishing Campaign Spans 46 Countries as Attackers Abuse Trusted IT Tools
A global RMM phishing campaign is abusing trusted remote access tools across 46 countries, with US activity accounting for about 45%.
CrowdStrike Threat Hunts for Shell Command Obfuscation on VMware ESX
This post has no text preview — click the link below to read the original article. This article has been indexed from Blog Read the original article: CrowdStrike Threat Hunts for Shell Command Obfuscation on VMware ESX
AI Doesn’t Mean the End of Mathematics—at Least Not Yet
This essay was written with Kasra Rafi, and originally appeared in The Guardian. Earlier this month, about 40 top mathematicians gathered at OpenAI’s…
CISA: Most exploited vulnerabilities should have been eradicated decades ago
Organizational culture and systemic gaps in Secure by Design adoption blamed for sorry state of affairs
China-Made ZBT Routers Ship With Two Implants Giving Unauthenticated Attackers Root Access
VulnCheck has disclosed two previously undocumented factory implants in firmware for routers built by Shenzhen Zhibotong Electronics (ZBT), each of which…
The AI agent swarm that attacked Hugging Face is a warning for the future
An army of AI agents was responsible for the Hugging Face incident. What does it mean for the future of AI?
Tech, Cybersecurity Giants Unite Behind OpenAI-Led Cyber Defense Pledge
Nearly 130 tech and cybersecurity companies back a collective call to boost cyber defenses as AI-enabled attacks grow more sophisticated.
Russian University Leak Exposes GRU Cyber Training Pipeline Behind APT28 and Sandworm
Leaked university records have opened an unusual window into Russia’s military cyber ecosystem. The documents point to a structured training program, not…
North Korean remote workers are broadening their job hunt beyond IT
North Korean (DPRK) remote workers are expanding their job searches beyond IT, according to Huntress. Recent investigations have identified suspected DPRK…
ServiceNow Patches Critical Flaws Enabling Unauthenticated RCE and SQL Injection
ServiceNow has issued security advisories for four vulnerabilities, including critical flaws in its AI platform. These vulnerabilities could allow…
Industry that built the problem offers to sell you the solution
100+ tech giants warn AI attacks are coming, skip the part where they pay for defenses
Researchers Execute Code Inside Fortune 500 Companies via AI Agent llms.txt Files
Security researchers have shown that AI coding agents can be manipulated into installing attacker-controlled packages by following instructions found in…
Three CVSS 10.0 ServiceNow Flaws Could Let Unauthenticated Attackers Execute Code and SQL
ServiceNow has released patches for four security flaws impacting the ServiceNow AI Platform, three of them rated 10.0 on the CVSS scoring system and…
Suspected Iran-Linked Cyberattack Knocks UK Power Plant Offline for Four Days
A cyber incident reportedly forced a small UK power generation facility offline for about four days in July 2026. While the activity has been linked in…