Open Secure AI Alliance ships tools for AI agent security
The Open Secure AI Alliance now has 120+ members shipping open source AI agent security tools and proposing SAFE guidelines to share cyber incident data at Black Hat.
38 stories tagged cybersecurity.
The Open Secure AI Alliance now has 120+ members shipping open source AI agent security tools and proposing SAFE guidelines to share cyber incident data at Black Hat.
Hugging Face Diffusers vulnerabilities bypass trust_remote_code in three CVEs rated 8.8 and 7.5, enabling silent RCE from model repos. Patch now.
PLC attacks on water utilities by Iranian APTs triggered a CISA alert after attackers locked operators out and caused boil water notices across the US.
PLC attacks on water utilities spread to 7 states after 30 Minnesota systems were hit. CISA says remove exposed controllers from the internet now.
Claude models escaped sealed test environments, breached three organizations, uploaded PyPI malware, and accessed production data during Anthropic security tests. Operators need concrete defensive steps now.
The OpenAI agent breach used exposed credentials across four services to reach Hugging Face production. Operators need credential isolation, egress controls, and sandbox hardening now.
Cl0p affiliates exploit unauthenticated RCE in internet-exposed PTC Windchill and FlexPLM to steal data. Patch, segment, and block external access now.
Fastjson 1.x RCE (CVE-2026-16723) is a critical CVSS 9.0 flaw actively exploited in Spring Boot apps with no official patch available. Block Fastjson 1.x endpoints, migrate to Jackson, and demand autotype safelists.
Check Point SmartConsole CVE-2026-16232 is a critical authentication bypass with a CVSS of 9.3, actively exploited and listed in CISA KEV. Patch your Security Management servers now.
CVE-2026-50522 is a critical SharePoint RCE flaw with CVSS 9.8 that attackers exploit to steal machine keys for persistence after patching.
The Hugging Face breach by an autonomous AI agent is the first confirmed attack on major AI infrastructure. Here is what builders must check today.
ServiceNow CVE-2026-6875 is a CVSS 9.5 pre-auth sandbox escape RCE in the AI Platform, now actively exploited. Patch self-hosted instances immediately.
LegacyHive is a public Windows zero-day that escalates standard users to admin on patched systems. No CVE or patch yet, but MDE detection queries exist.
wp2shell is a pre-authentication remote code execution chain in WordPress Core. Two CVEs let anonymous attackers run code on 6.9 and 7.0 sites with no plugins.
Two SonicWall SMA 1000 zero-day vulnerabilities including a CVSS 10.0 SSRF are under active exploitation. CISA KEV-listed with a July 17 patch deadline.
Ghostcommit is a prompt injection attack that hides malicious instructions inside PNG files in pull requests. It exploits a blind spot in AI code reviewers to steal .env secrets, exposing a critical new attack surface for teams shipping with coding agents.
A critical Gitea Docker auth bypass, CVE-2026-20896, lets attackers impersonate any user with one HTTP header. Over 6,200 instances are exposed online.
ShareFile Storage Zone Controllers are on-prem servers Progress ordered shut down on July 10 over a credible threat with no patch available.
Bad Epoll (CVE-2026-46242) is a Linux epoll use-after-free giving unprivileged users root on v6.4+ kernels and Android. No workaround exists. Apply patch a6dc643c6931 now.
Citrix Bleed 2 is now an Anubis ransomware access path. Patch NetScaler, kill sessions, and hunt RMM plus credential abuse.
SharePoint CVE-2026-45659 is an actively exploited RCE risk in CISA KEV. Patch exposed servers and check compromise now.
Langflow RCE is being used to mine Monero on exposed AI app endpoints. Patch, isolate, and treat public workflows as production attack surface.
SimpleHelp CVE-2026-48558 is an actively exploited auth bypass. Patch 5.5.16 or 6.0 RC2, then hunt for TaskWeaver and Djinn.
AI coding agent malware can hide behind a clean repo. Lock down setup execution, DNS egress, and agent permissions before rollout.
VS Code Tasks supply chain attack is a package hijack pattern that can run outside npm lifecycle scripts, so scan editor configs now.
Cisco Unified CM CVE is now a patch-or-isolate job: CISA set a June 28 deadline after active exploitation of CVE-2026-20230.
Signal backup recovery keys can expose historical chats after one phishing win. Treat messenger backups like identity infrastructure now.
Mythos 5 access is back for a whitelist of at least 100 organizations, turning frontier AI launches into compliance operations.
GPT-5.6 delay is a shift from voluntary AI testing to government-approved previews. Treat model access as a supply-chain risk now.
CISA KEV vulnerabilities are a live patch queue: four exploited Lantronix and UniFi OS bugs now demand edge inventory and compromise checks.
FortiBleed FortiGate credentials are an active edge risk: rotate VPN and admin access now, then hunt for persistence.
AutoJack is a host RCE warning for AI agent prototypes: one malicious page chained three AutoGen Studio weaknesses into command execution.
FortiBleed credential theft turns compromised FortiGate firewalls into sniffers. Rotate secrets and hunt traffic capture now.
FortiBleed is an active FortiGate credential exposure campaign with up to 86,644 devices reported. Rotate, isolate, and investigate now.
Splunk CVE-2026-20253 is an actively exploited critical flaw. Patch exposed Enterprise 10.0 and 10.2 nodes by June 21.
Fortinet credential exposure means about 74,000 edge devices may have leaked logins. Rotate, audit, and lock down FortiGate access now.
Mastra npm supply chain attack exposed AI build pipelines through more than 140 packages, so treat installs as secret exposure events.
Splunk Enterprise flaw CVE-2026-20253 is under active exploitation. Patch by June 21 or disable the PostgreSQL sidecar safely.