5 critical · 30 to skim · nothing on fire
Data source: supabase
In a new update, OpenAI says its AI models also used publicly exposed credentials to compromise accounts on four third-party services during the recent attack on Hugging Face, expanding the scope of the fo
Claude is down for some users, with Anthropic confirming elevated errors across multiple AI models.
Watch an agent work through a task, and you’ll see the future of enterprise security. Watch Claude work through a long task some time.
JFrog has confirmed that OpenAI models exploited zero-day vulnerabilities in self-hosted Artifactory servers to help escape an isolated testing environment and gain access to the internet before attacking Hugging
Your workforce is building agents in Salesforce Agentforce, Microsoft Copilot Studio, Cursor, Zapier, Retool, and a dozen other tools, often without visibility or approval from IT or security.
ChatGPT is experiencing a major outage, and users are unable to load chats, including previous conversations. The outage started at approximately 5 AM ET and is affecting users worldwide, including those in the US and Europe.
A threat actor used the open-source Hermes AI agent in unattended "YOLO" mode to automate post-exploitation activity during an alleged breach of Thailand's Ministry of Finance.
Hackers are changing the DNS settings on Wi-Fi devices at hotels and conference centers to redirect users to fake Microsoft 365 login pages.
Three attacks, three names, and one identical flaw: AI coding agents treat a hallucinated identifier as a verified command.
A new Dolphin X remote access trojan claims to use an AI-powered profiling feature to score and rank infected users, helping cybercriminals identify which victims should be targeted first.
A malvertising campaign on the Bing search service is pushing a fake Claude desktop app installer hosted on a legitimate Claude.ai domain to deliver the SectopRAT malware.
OpenAI says its AI models, including GPT‑5.6 Sol and a pre-release model, hacked into the Hugging Face artificial intelligence repository while being tested in a sandboxed testing environment.
Generative AI is rapidly becoming part of everyday business operations. Employees use AI assistants to summarize documents, search enterprise knowledge, draft content and automate routine tasks.
Security researchers broke out of the sandboxes in four widely used AI coding agents, including Cursor, OpenAI's Codex, Google's Gemini CLI and Antigravity, without attacking the sandbox head-on.
The JadePuffer autonomous AI agent has upgraded with custom malware called EncForge that focuses on encrypting AI assets, such as training datasets, vector databases, and model checkpoints.
Attackers have begun exploiting a critical vulnerability (CVE-2026-6875) in the ServiceNow AI Platform, according to threat intelligence company Defused.
The Hugging Face artificial intelligence repository disclosed that attackers gained access to internal datasets and credentials after breaching its production infrastructure using an autonomous AI agent system.
A flaw in Anthropic's Claude for Chrome browser extension could allow a malicious extension to trigger predefined AI actions by simulating user clicks, potentially allowing it to abuse Claude's access to co
For most of the last two decades, enterprise security ran on a workable assumption: the environment was knowable.
A Russian-speaking threat actor known as "bandcampro" used Google's open-source Gemini CLI AI tool as a hacking agent and to operate a small-scale botnet.
AI is changing how vulnerability research gets done, but most of the conversation is still theoretical: what a model might eventually be capable of, rather than what it can actually find today.
OpenAI is temporarily relaxing GPT-5.6 Sol usage limits after demand for the company's most powerful model surged over the past 48 hours.
Anthropic has just extended access to Claude Fable 5 for paid subscribers until July 19, giving you another week to keep using the most powerful model.
Researchers have built a pull request that steals a repository's secrets by hiding the malicious instruction inside a PNG that AI code reviewers never open. The reviewer waves the change through.
Security was built for people. AI agents are exposing the gap. Forty-four years after Blade Runner imagined replicants walking among us, security teams are managing their own version of a non-human workforce
Microsoft says Windows users should expect to see an increase in security updates as the company increasingly relies on artificial intelligence to discover vulnerabilities in its codebase.
A new phishing-as-a-service (PhaaS) operation called Forg365 focuses on stealing Microsoft 365 accounts by combining adversary-in-the-middle (AiTM) and device code methods with AI-assisted lure generation.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) gave federal agencies until Friday to patch an actively exploited vulnerability in the Langflow visual framework for building AI agents.
IBM’s 2025 Cost of a Data Breach Report found that 16% of breaches studied involved attackers using AI tools, most often for phishing or deepfake impersonation attacks.
A cybersecurity startup dangling millions of dollars to acquire zero-day security vulnerabilities in popular software is run by a pair of far-right conspiracy theorists and convicted felons whose most recent ventures included fake intelligence companies and a now-defunct AI-based
A green pipeline is not a governed one, and agentic coding is widening the gap faster than review can close it.
A phishing campaign is impersonating more than 30 well-known brands, including Adobe, Netflix, Coca-Cola, and OpenAI, in fake job interviews to steal Google account credentials from marketing professionals.
Researchers identified what they believe is the first documented case of a ransomware operation, JadePuffer, conducted entirely by a large language model (LLM) agent.
Anthropic says Claude Fable 5 won't be accessible via Claude subscriptions after July 7, but it's not a permanent change, and the company expects the model to return outside the usage-based plan soon.
Claude Fable, the company's most powerful model, is now available to all users, but early impressions are disappointing, as it appears to be nowhere near the original release.
Slopsquatting, Phantom Domains, and HalluSquatting Are the Same AI Attack
New Dolphin X malware uses AI to rank high-value targets
Fake Claude app promoted by Bing ads pushes SectopRAT malware
OpenAI says its AI models hacked Hugging Face during testing
Cursor, Codex, Gemini CLI, Antigravity hit by sandbox escapes
Hugging Face warns an autonomous AI agent hacked its network
Critical ServiceNow code execution flaw now exploited in attacks
Claude Chrome extension flaw lets malicious extensions trigger AI actions
Google Gemini CLI abused as a hacking agent, malware botnet operator
Microsoft expects more Windows security updates from AI-discovered flaws
OpenAI confirms ChatGPT is down worldwide
Claude Fable 5 stays free for paid users until July 19 as Anthropic buys more time
Claude Fable 5 isn’t permanently leaving subscriptions, Anthropic says
CISA orders feds to prioritize patching Langflow auth bypass flaw