🚨 OpenAI says the Hugging Face breach was broader than first disclosed.
The system used exposed credentials to access four third-party accounts, using one as a relay and staging point and another for data storage.
Read the new details: https://t.co/4XdUaRjhNf
‼️ BREAKING — Claude AI found a working HAWK-256 key-recovery attack.
HAWK is a NIST post-quantum cryptography candidate. It also made an impractical 7-round AES-128 attack up to 800x faster.
Read this here: https://t.co/JbDhrTjjt2
🚨 Attackers are exploiting a CVSS 10.0 command injection flaw in on-prem Arista VeloCloud Orchestrator.
A successful exploit could compromise the orchestrator and give attackers access to managed Edge devices. CISA has ordered federal agencies to patch by July 30.
Details: https://t.co/nkd4dQGLqA
🛑 A hacker switched off Hermes AI’s command approvals and set the agent loose to automate post-exploitation inside Thailand’s Finance Ministry.
It scanned hosts, searched for ways to gain root access, and crawled staff files dating to 2012. The operation surfaced because the attacker left its logs exposed.
Read the full story: https://t.co/0Y3ZhcSitt
🛑 Kimi K3 AI agents found Redis 0-days. Then they built working RCE exploits.
The authenticated chains abuse RESTORE across multiple #Redis releases. Redis has shipped seven security updates, with no exploitation reported in the wild.
Details: https://t.co/dwbmxBmFiG
⚠️ Attackers are exploiting a Check Point SmartConsole flaw that can grant full administrative access.
CVE-2026-16232 affects management servers exposed directly to the internet under a specific configuration. Check Point says a small number of customers were targeted.
Read: https://t.co/jqkAVWQEIC
🔥 OpenAI says its own AI models broke out of a sandbox, exploited a zero-day, and targeted Hugging Face’s production infrastructure to cheat a security benchmark.
The incident showed how long-running models can learn and work around approval-system blind spots.
Read the full story: https://t.co/vSn2K4HeBz
🛑 ALERT - WordPress sites are under active attack.
Attackers are exploiting the #wp2shell chain to gain unauthenticated RCE on vulnerable stock installations, with no plugins required. Public exploit code is now fueling mass scanning and web shell deployments.
Read what defenders should check: https://t.co/p6S8ILrUw0
🚨 ALERT: A newly disclosed 7-Zip vulnerability could let attackers run code when a user opens a crafted XZ archive.
CVE-2026-14266 is a high-severity heap overflow in the XZ decoder. The code runs with the same privileges as 7-Zip.
Details: https://t.co/Stxn6X5EvE
🛑 WARNING - A new critical NGINX vulnerability that has existed for 15-years lets unauthenticated attackers crash worker processes with crafted HTTP requests.
CVE-2026-42533 affects specific regex map configurations.
F5 says it may also allow pre-auth RCE if ASLR is disabled or bypassed.
Read how the bug works: https://t.co/r0FYOqw61D
🚨 Two SonicWall SMA 1000 zero-days were exploited before disclosure to gain root access.
Researchers link the activity to UTA0533, which planted custom malware and sniffed unencrypted LDAP credentials from compromised VPN appliances.
Full attack chain: https://t.co/YoyRiTQME3
🛑 Hugging Face, the world’s largest AI model repository, says an autonomous AI agent breached its production systems through a malicious dataset.
It accessed internal data and service credentials, then moved across several clusters through thousands of actions in short-lived sandboxes.
Full story: https://t.co/ULJfbJfhmW