> TODAY'S SUMMARY (5 articles)
Today's cybersecurity news highlights several critical issues. OpenAI has acknowledged unauthorized access attempts to four Australian government websites, involving security bypass methods and the use of exposed keys. Citrix has issued patches for actively exploited zero-day vulnerabilities in its NetScaler products, following unofficial warnings that left many users vulnerable. Additionally, Ubuntu is addressing critical regression security issues in curl, which could pose risks to users of version 14.04 LTS. In a positive development, Nvidia launched the Open Agent Safety Platform to enhance governance of agentic AI systems, combining software and hardware for improved monitoring. Overall, the day underscores the ongoing challenges of security vulnerabilities and the need for timely patching.
|
// AI-powered summary generated at 04:00
We look into how attackers are using the legitimate Ren'Py game engine to spread a malware loader that ultimately delivers Amatera Stealer.
7-Zip fixed a vulnerability that could let attackers run code by tricking users into opening malicious XZ-compressed archive files. 7-Zip released version 26.02 to address a remote code execution vulnerability in its handling of XZ-compressed data. The flaw, discovered by researcher Landon Peng, can...
Hugging Face, the widely used platform for sharing open-source machine learning models and datasets, has disclosed a security breach it says was carried out by an autonomous AI agent system. How the attack unfolded In a blog post published Thursday (July 16), the company said that earlier that week,...
Microsoft is working to fix a known issue affecting Windows Server Update Services (WSUS) servers, which has caused synchronization problems for more than a week. [...]
The agentic security tool identifies potentially exploitable code flaws, traces attack paths, and recommends targeted remediations.
The post Capital One Open Sources AI-Powered ‘VulnHunter’ Security Tool appeared first on SecurityWeek.
Microsoft has released emergency updates to fix a known issue causing some Dell PCs to shut down after installing the July 2026 Windows 11 security updates. [...]
A new toolkit for attorneys in Massachusetts targets the technologies police use—and conceal—to build criminal cases, from facial recognition to AI-written police reports.
F5 fixes critical nginx flaw CVE-2026-42533 that can crash servers and, in some cases, allow remote code execution through crafted HTTP requests. F5 released patches for a critical nginx vulnerability, tracked as CVE-2026-42533 (CVSS score of 9.2), that can allow an unauthenticated attacker to trigg...
Two chiefs of UK policing agencies said the Transport for London prosecution demonstrates the need for Cybercrime Risk Orders
Targeting production infrastructure, the attack compromised internal datasets and service credentials.
The post Hugging Face Hacked in Autonomous AI Attack appeared first on SecurityWeek.
A first-of-its-kind analysis found more than one in eight apps built for US service members carried foreign code—some from firms in nations the Pentagon designates as adversaries.
Attackers have begun exploiting a critical vulnerability (CVE-2026-6875) in the ServiceNow AI Platform, according to threat intelligence company Defused. [...]
Opening a crafted XZ archive in 7-Zip could let an attacker run code on the machine. The flaw, CVE-2026-14266, is a heap-based buffer overflow in how the archiver processes XZ chunked data, and Trend Micro's Zero Day Initiative (ZDI) detailed it on July 15. A fix shipped on June 25 in 7-Zip 26.02....
A solo Russian-speaking threat actor known as "bandcampro" outsourced a chunk of their operations to Google's open-source Gemini CLI artificial intelligence (AI) and commandeered a live botnet.
The findings come from an analysis of 200 Gemini CLI session logs between March 19 and April 21, 2026, wh...
Information published.
Information published.
Windows 11 now runs on 78.8% of Windows devices after Microsoft ended support for Windows 10 on 14 October 2025, according to Lansweeper. Windows 10 still accounts for 16.9% of devices and no longer receives security updates, leaving newly discovered vulnerabilities unpatched. “There’s a temporary b...
Hugging Face says an autonomous AI agent breached part of its production infrastructure and accessed internal data and service credentials. Hugging Face is one of the world’s leading open-source AI companies. It provides a platform where developers and organizations can build, share, and deploy mach...
The fresh security update resolves six critical and high-severity use-after-free vulnerabilities.
The post Chrome 150 Update Patches Severe Memory Safety Bugs appeared first on SecurityWeek.
Information published.