Between July 9 and July 13, 2026, security researchers documented what is being called the first fully autonomous AI agent cyberattack to chain zero-day…
NGINX Heap Overflow Flaw Could Let Unauthenticated Attackers Execute Arbitrary Code
A high-severity heap buffer overflow vulnerability has been identified in the NGINX Stream module’s script engine. This vulnerability may allow…
OpenAI Open-Sources Codex Security CLI for Finding, Validating, and Fixing Security Vulnerabilities
OpenAI has open-sourced Codex Security, a command-line tool and TypeScript SDK designed to help developers find, validate, and fix security…
America bans imported robots due to supply chain and security risks
Docs point to China’s Unitree as prime example of the foreign clanker threat
ISC Stormcast For Wednesday, July 29th, 2026 https://isc.sans.edu/podcastdetail/10028, (Wed, Jul 29th)
This post has no text preview — click the link below to read the original article. This article has been indexed from SANS Internet Storm Center, InfoCON: green Read the original article: ISC Stormcast For Wednesday, July 29th, 2026 https://isc.sans.edu/podcastdetail/10028,…
Measuring LLMs’ Ability to Perform Cryptanalysis
There’s new benchmark measuring AI’s ability to perform mathematical cryptanalysis. Anthropic’s frontier model actually found new attacks. The benchmark:…
IT Security News Hourly Summary 2026-07-29 03h : 3 posts
3 posts were published in the last hour 0:31 : OpenAI’s Rogue AI Agent Hacked More Than Just Hugging Face 0:31 : AI agent hacks national finance ministry, Botnet uses blockchain, Healthcare chain reopens 0:31 : Cyera agrees to acquire…
OpenAI’s Rogue AI Agent Hacked More Than Just Hugging Face
In a new disclosure, OpenAI says its agent used exposed logins to gain access to at least four “publicly available services” in its unhinged quest to…
AI agent hacks national finance ministry, Botnet uses blockchain, Healthcare chain reopens
Hospital ransomware fallout, blockchain botnet C2, and AI agent loose in Thailand’s Finance Ministry. South Carolina’s AnMed reopened some physician…
Cyera agrees to acquire Oasis Security for $1B to safeguard proliferating AI agents
The deal is Cyera’s third acquisition this year.
A Typo Landed an Innocent Gamer in Prison for 18 Months
How much could a single underscore in a username really matter? Just ask Brandon Klayme, who served 18 months in prison before realizing how authorities…
Palo Alto Networks Achieves Global CBPR and PRP Certifications
Our mission is to be the cybersecurity partner of choice, protecting our digital way of life. Fulfilling that mission demands that we continually ensure…
MCP gets an enterprise makeover
Now happy to run on K8s and conventional networks, with an easier-to-live-with lifecycle
More Than 45,000 Software Flaws Reported as AI Reshapes Cybersecurity
AI security tools are helping uncover more software flaws, creating new patching demands and potential offensive risks for enterprise IT teams.
Looks like JFrog’s 0-days let OpenAI’s models hack Hugging Face
The vendor won’t confirm or deny
IT Security News Hourly Summary 2026-07-29 00h : 2 posts
2 posts were published in the last hour 22:2 : Authorities investigating a coordinated cyberattack against Minnesota water systems 21:55 : IT Security News Daily Summary 2026-07-28
Authorities investigating a coordinated cyberattack against Minnesota water systems
The two-day attack comes days after federal officials warned of state-linked threat groups targeting a wider set of industrial devices.
IT Security News Daily Summary 2026-07-28
195 posts were published in the last hour 21:2 : ChatGPT Joins Most Faked Brands Ranking in Phishing, Check Point Says 21:2 : FastJson RCE Zero-Day Actively Targets Organizations 21:1 : Meta Faces Scrutiny After Report Finds Thousands of AI…
ChatGPT Joins Most Faked Brands Ranking in Phishing, Check Point Says
ChatGPT entered Check Point’s top 10 phishing brand ranking as fake ChatGPT Plus payment failure emails targeted users’ credit card details.
FastJson RCE Zero-Day Actively Targets Organizations
Threat actors are actively exploiting the FastJson CVE-2026-16723 zero-day, with no patch available for affected FastJson 1.x versions.
Meta Faces Scrutiny After Report Finds Thousands of AI Nudify Ads on Facebook, Instagram
Meta is under renewed scrutiny after researchers found thousands of AI “nudify” ads on Facebook and Instagram, raising questions about the company’s…
Critical TeamCity Flaw Could Let Unauthenticated Attackers Execute Server Commands
JetBrains has patched CVE-2026-63077, a critical TeamCity flaw that could let unauthenticated attackers execute server commands and compromise connected…
Apple Fixes 194 Security Flaws Across iPhone, Mac and Other Devices
Apple’s latest iPhone, iPad and Mac updates patch 194 unique security flaws involving root access, kernel code execution and protected data.
Cursor Quietly Patches High-Severity Git Vulnerability After Seven-Month Delay
Cursor has patched a high-severity Windows vulnerability that allowed malicious Git repositories to execute code, highlighting security risks in AI coding…