Cyber Security News
Hugging Face Hack: Lessons for Cyber Defenders
Dark Reading Confidential Episode 20: Expert Rich Mogull reflects on lessons cyber teams should pull from the OpenAI agent’s attack on Hugging Face. Read more
Flaws in Google APK for Python Unlock Agent-to-Agent Attack
Google has fixed the issues, which exploited a trust boundary between two AI agents with different privilege levels to trigger automation that could compromise … Read more
Attackers Exploit N-able Patch Bypass Flaw on RMM Servers
Over the weekend, the vendor discovered another vector of authentication bypass CVE-2026-18577 that gives attackers administrator access. Read more
Anthropic: Claude Attacks Result of Security Gaps Not Model Issues
Last month’s incidents in which the AI model breached real-world systems derived from over-permissioning, especially with Internet access. Read more
Best Practices
Microsoft confirms an AI worm is propagating through Copilot and other MS apps
A prominent Norwegian AI researcher on Tuesday posted details about an AI worm that is wreaking havoc in various Microsoft applications, … Read more
A coordinated attack hit 30+ Minnesota water systems Who did it and what does a Rockwell notice add to the picture?
A coordinated cyberattack that targeted more than 30 Minnesota community water systems has alarmed industrial cybersecurity experts, not … Read more
Russian hackers turn Exchange flaw into ‘half-click’ mailbox takeover
A Russia-aligned threat group used a “half-click” exploit against Microsoft Exchange’s Outlook Web Access to install a browser-based back… Read more
Attackers are crafting malicious AI instruction files to turn your agents into quiet criminal helpers
AI agents are increasingly being deployed across the enterprise, a rapid adoption that has significantly broadened the organization’s att… Read more
New Threats and Vulnerabilities
Flying Eagle Android RAT Traces Found on 170 Servers as Source Code Circulates
Source code for the Flying Eagle Android remote access trojan (RAT) framework is circulating through criminal Telegram channels. Hunt.io and independent researc… Read more
Russian Hackers Exploit Microsoft OWA Flaw to Keep Mailbox Access After Credential Rotation
The Russian threat actors recently linked to the exploitation of a now-patched vulnerability in Zimbra have been observed exploiting another vulnerability, this… Read more
Cisco FMC Zero-Day Actively Exploited Static Credentials Could Expose Sensitive Data
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a newly disclosed security flaw impacting Cisco Secure Firewall Management C… Read more
Three Critical VMware Flaws Allow Auth Bypass Code Execution and VM Escape
Broadcom has released security updates to address multiple security flaws impacting VMware ESX, vCenter, Workstation, and Fusion, three of which have been desig… Read more
Patch Management
Leaked n8n API Tokens Exposed Live Instances to Credential Theft
GitGuardian researchers found 321 n8n instances accepting API tokens exposed in public GitHub commits and demonstrated four ways attackers could use them to acc… Read more
Fake Adobe and Zoom Updates Install ScreenConnect for Persistent Remote Access
Cybersecurity researchers have disclosed details of an active, multi-wave campaign that employs social engineering lures themed around Adobe and Zoom software u… Read more
Google Password Manager Attacks Could Let Malware Hijack Passkey-Protected Accounts
Malware running as an ordinary user on a Windows machine can sign into a victim’s passkey-protected accounts without a fingerprint, a PIN, or anything at all ap… Read more
Adobe Campaign Classic CVSS 100 Flaw Could Run Code Without User Interaction
Adobe has released security updates to address a maximum-severity security flaw in Campaign Classic (ACC), its enterprise-focused marketing automation platform,… Read more
Claude Code and Gemini CLI Flaws Let a GitHub Issue Reach CI Workflow Secrets
A GitHub issue opened by an account with no repository privileges was enough to execute code on the CI runners behind Anthropic’s and Google’s own coding-agent … Read more
AI and Security
AI struggles to patch vulns without adult supervision
AI models may not be that good at fixing security flaws. Researchers at 1Password’s Off-by-1 Labs analyzed security patches generated by two frontier models – … Read more
Open source project fools AI scrapers with poisoned font
If you don’t want AI scrapers training themselves on your website, there’s a new way to stop them that doesn’t involve server-side blocking or praying they res… Read more