OpenAI has published an update on the incident in which one of its agents escaped its sandbox and accessed Hugging Face infrastructure.
Securing Loop Engineering: Six Trust Boundaries for Autonomous Agents
Opening Scenario: The GitHub Issue That Reprograms the Loop Every morning, an automated system checks a repository’s open GitHub issues, decides which…
Anthropic Says Claude Hacked Into 3 Organizations During Cybersecurity Tests
In a review triggered by OpenAI’s Hugging Face incident, Anthropic discovered three of its AI models had breached real-world organizations during…
Retrieval Augmented Generation With Spring AI 2.0, Claude, and PGvector
Language models become much more useful when they can answer questions about information they were never trained on, including your internal…
Researchers Report 84 Flaws in 4G and 5G Cores, Including a Session Hijacking Flaw
An academic study has disclosed a “widespread class” of security vulnerabilities impacting 4G and 5G core networks that, if successfully exploited, could…
How to Protect Your AI Agents from Prompt Injection Attacks: An Active Defense Approach
I’ve spent the past week locked in a room (figuratively, mostly) building a solution for a problem that’s been bugging me since the last AI security…
Charities remain locked out of CAF Bank online accounts
A week into shutdown, 14,000 customers still have no restoration date and some are struggling to pay staff
Moonshot AI Claims Kimi K3 Matches OpenAI and Anthropic Models
Founded by Moonshot AI, the company has released the Kimi K3 large language model, a next-generation large language model the company claims is…
CREST Launches AI-Enabled Pentesting Accreditation
CREST has introduced an optional AI-Enabled Penetration Testing accreditation module designed to verify responsible AI usage among cybersecurity service…
Attackers Are Turning Microsoft’s Trusted Login System Into Their Latest Phishing Weapon
Attackers are increasingly abandoning fake Microsoft login pages in favor of abusing Microsoft’s legitimate authentication infrastructure, allowing…
Frontier Airlines Hit by Third Data Breach
Frontier Airlines is facing scrutiny after reportedly suffering its third data security incident in 2024, marking a troubling pattern for the budget…
Huntress Flags Widespread Credential Stuffing Campaign Hitting SonicWall Devices
Managed detection and response provider Huntress has issued a threat advisory warning of an active and rapidly growing credential stuffing campaign…
US, Australia Release OT Isolation Guidance
The United States and Australia have published joint guidance to help critical infrastructure organizations isolate their operational technology systems…
DEF CON 34 Badges Feature Open Source Security Chip
The badges for DEF CON 34 feature an open source security chip designed by renowned hardware hacker Andrew “bunnie” Huang.
Snowflake’s AI Agent Security Framework
Snowflake has introduced a multi-layered security framework designed to protect AI agents from manipulation and prevent unauthorized actions.
FTC sues Hims & Hers over health data sharing
The Federal Trade Commission has filed a lawsuit against telehealth provider Hims & Hers, accusing the company of sharing sensitive customer health data…
Wordfence Finds Critical Backdoor in ARVE WordPress Plugin
A backdoored ARVE WordPress Plugin release could grant attackers administrator access with one token, but WordPress.org blocked automatic distribution to…
Anthropic AI models breached three real companies
Anthropic revealed Thursday that three of its Claude AI models escaped test environments and successfully breached real-world companies during security…
Cybercrime goes subscription: AI, malware and infrastructure on demand
Cybercrime has become a commercialized ecosystem where criminals can buy or rent nearly every capability needed to launch sophisticated attacks. These…
Attackers abuse Microsoft auth for phishing
Cybercriminals have shifted tactics in phishing campaigns by exploiting Microsoft’s legitimate authentication infrastructure rather than deploying fake…
IT Security News Hourly Summary 2026-07-31 15h : 8 posts
8 posts were published in the last hour 13:2 : What an LLM Can Find: A Practical, Cheap Path to Code-level Threat Discovery 13:2 : CVE-2026-63077 TeamCity RCE Vulnerability 13:2 : Keycloak Flaw Exposes Users’ Personal Data to Restricted Admins…
What an LLM Can Find: A Practical, Cheap Path to Code-level Threat Discovery
An AI-assisted audit found 29 flaws in GlobaLeaks, showing LLMs make large-scale code reviews faster, cheaper, and accessible. GlobaLeaks, a mature…
CVE-2026-63077 TeamCity RCE Vulnerability
JetBrains has disclosed a critical authentication bypass vulnerability in TeamCity On-Premises that enables remote attackers to execute arbitrary…
Keycloak Flaw Exposes Users’ Personal Data to Restricted Admins
A broken access control vulnerability in Keycloak could allow unauthorized administrator accounts to access users’ personal information. This issue,…