6 posts were published in the last hour 10:4 : Anonymous Researcher Dumps 204 0-Day Exploit Files Before Vendors Can Patch Them 10:4 : Oracle Patches Over 1,400 Vulnerabilities With Quarterly Security Updates 10:4 : Endpoint Security Firm Glow Launches…
Azure DevOps MCP Flaw Lets Hidden PR Comments Hijack AI Agents and Steal Data
A newly disclosed flaw in Microsoft’s official Azure DevOps MCP server shows how an invisible comment in a pull request can silently hijack a developer’s AI coding assistant and turn it into a data-exfiltration tool. Security researchers at Manifold Security…
Anonymous Researcher Dumps 204 0-Day Exploit Files Before Vendors Can Patch Them
An anonymous GitHub user has quietly assembled one of the most disruptive exploit collections of the year, dropping 204 zero‑day proof‑of‑concept files for dozens of open‑source projects before vendors had a chance to patch them. The archive, hosted under the…
Oracle Patches Over 1,400 Vulnerabilities With Quarterly Security Updates
Many of the vulnerabilities fixed with the July 2026 Critical Patch Update were likely discovered by AI. The post Oracle Patches Over 1,400 Vulnerabilities With Quarterly Security Updates appeared first on SecurityWeek. This article has been indexed from SecurityWeek Read…
Endpoint Security Firm Glow Launches With $180M in Funding at $1.2B Valuation
Using AI, the startup provides adaptive prevention through environment mapping, risk analysis, and automated policy enforcement. The post Endpoint Security Firm Glow Launches With $180M in Funding at $1.2B Valuation appeared first on SecurityWeek. This article has been indexed from…
AI models cheat on cybersecurity evaluations, then fail to admit it
Frontier AI models will take just about any route to finish a task, cheating included, according to new cybersecurity evaluations from the UK government’s AI Security Institute (AISI). AISI defines cheating as a model doing something outside the bounds of…
OpenAI AI models exploited zero-days to reach Hugging Face in benchmark test
OpenAI confirmed its AI models exploited zero-days during internal testing, reaching Hugging Face servers in an unintended real-world cyberattack. OpenAI admitted on July 21 that its own AI models, including GPT-5.6 Sol and an unnamed pre-release system, were behind the…
Microsoft To Fund Mistral Data Centre Expansion In Europe
Companies in ‘multi-billion dollar’ deal to fund construction of data centres in Europe, amid tech sovereignty drive This article has been indexed from Silicon UK Read the original article: Microsoft To Fund Mistral Data Centre Expansion In Europe
Threat Actor Turns Claude Opus Into Automated AI-Powered Penetration Testing Platform
A Russian-speaking threat actor known as “Trim” has reportedly transformed Anthropic’s Claude Opus into the central component of an automated, AI-powered penetration testing platform. This development highlights the rapid repurposing of advanced AI models for offensive security operations. According to…
SolarWinds Serv-U Update Fixes 15 Critical Vulnerabilities Enabling Remote Code Execution as Root
SolarWinds has released Serv-U 2026.3, which includes fixes for a cluster of 9.1 CVSS critical vulnerabilities that allow remote code execution (RCE) and privilege escalation up to root on Unix-like systems. This update significantly strengthens the managed file transfer (MFT)…
Ransomware Group Threatening to Leak Data Stolen From Coca-Cola’s Fairlife
The Anubis ransomware group claims to have stolen 1 TB of confidential data from the Coca-Cola subsidiary. The post Ransomware Group Threatening to Leak Data Stolen From Coca-Cola’s Fairlife appeared first on SecurityWeek. This article has been indexed from SecurityWeek…
OpenAI Says Models Escaped Sandbox, Hacked Outside Firm
Start-up says two of its models hacked their way out of offline internal systems, breached Hugging Face in order to cheat on benchmark This article has been indexed from Silicon UK Read the original article: OpenAI Says Models Escaped Sandbox,…
Council worker spared prison after four-day data-snooping spree
Herefordshire employee handed suspended sentence for breach of Computer Misuse Act This article has been indexed from www.theregister.com – Articles Read the original article: Council worker spared prison after four-day data-snooping spree
Police dismantle Kratos phishing platform behind 15,000 monthly campaigns
German and US law enforcement have dismantled the infrastructure behind Kratos, a notorious phishing-as-a-service (PhaaS) platform. Its alleged developer and administrator was arrested in Indonesia by local police. Seizure banner (Source: BKA) The takedown was led by the Frankfurt public…
Google’s Gemini 3.5 Flash Cyber becomes a vulnerability hunter
Google’s Gemini 3.5 Flash Cyber model finds, validates, and patches vulnerabilities before they can be exploited while helping mitigate broader misuse. It is part of a limited-access pilot program that will soon be available to governments and trusted partners through…
How hackers used Steam Workshop to spread malware
Steam Workshop has become the latest surprising malware delivery channel, with attackers hiding malicious code inside Wallpaper Engine “application wallpapers” to steal Steam credentials, install… The post How hackers used Steam Workshop to spread malware appeared first on Panda Security…
China Considers Restrictions On AI Models
China’s government reportedly considers barring foreign users from downloading model weights, among other new tech export rules This article has been indexed from Silicon UK Read the original article: China Considers Restrictions On AI Models
OpenAI Says Its AI Models Broke Loose and Hacked Hugging Face
The admission comes days after Hugging Face disclosed an attack powered by autonomous AI agents. The post OpenAI Says Its AI Models Broke Loose and Hacked Hugging Face appeared first on SecurityWeek. This article has been indexed from SecurityWeek Read…
Police Dismantle Kratos Phishing Kit Built to Steal Microsoft 365 Sessions and Bypass MFA
German and US law enforcement have taken down the core infrastructure of Kratos, described by German investigators as one of the world’s most widely used criminal phishing kits, and Indonesian authorities arrested the man they say developed and ran it.…
Moonshot Plans Funding Round At $50bn Valuation, Ahead Of IPO
Beijing start-up reportedly preparing to begin last private capital raise as it makes preparations for Hong Kong listing This article has been indexed from Silicon UK Read the original article: Moonshot Plans Funding Round At $50bn Valuation, Ahead Of IPO
GolangGhost Steals Chrome Secrets From macOS Keychain and Hijacks MetaMask Permissions
A new malware campaign is targeting cryptocurrency and Web3 professionals through fake job interviews. The operation delivers GolangGhost, a remote access trojan that can steal browser credentials, collect wallet data, and give attackers control of infected macOS systems. The attackers…
OpenAI Confirms Its Models Breached Hugging Face Production Systems During Cyber Benchmark Testing
OpenAI has acknowledged that its AI models, including GPT-5. Thank you for being a Ghacks reader. The post OpenAI Confirms Its Models Breached Hugging Face Production Systems During Cyber Benchmark Testing appeared first on gHacks. This article has been indexed…
Bit2Watt instability, AI models cheat, Chinese LLM ban
Bit2Watt threatens power stability All AI models cheat at cyber evaluations US weighing Chinese LLM ban Get the show notes here: https://cisoseries.com/cybersecurity-news-bit2watt-instability-ai-models-cheat-chinese-llm-ban/ Huge thanks to our sponsor, QuilrAI AI agents don’t ask permission. They act — moving data, triggering workflows,…
Z.ai Builds Massive AI Data Centre With Domestic Chips
Beijing-based AI start-up reportedly begins operating new data centre intended to scale to 1 GW of capacity with Chinese processors This article has been indexed from Silicon UK Read the original article: Z.ai Builds Massive AI Data Centre With Domestic…