
OpenAI’s Rogue AI Used JFrog Zero-Days to Breach Hugging Face
A new postmortem reveals OpenAI’s rogue AI model exploited JFrog Artifactory zero-days to escape its sandbox and breach Hugging Face

A new postmortem reveals OpenAI’s rogue AI model exploited JFrog Artifactory zero-days to escape its sandbox and breach Hugging Face

Rapid7 released a public PoC for CVE-2026-16232, a CVSS 9.3 Check Point SmartConsole authentication bypass already under active exploitation in

Nebula Security published a full browser-to-kernel exploit chain for Firefox CVE-2026-10702, a JIT flaw that exposes Tor Browser users to

CVE-2026-60004 in Gitea 1.17–1.27.0 lets a repository writer execute arbitrary shell commands as the Gitea service account via malicious patch

CVE-2026-53921, a CVSS 9.8 stack buffer overflow in OpenWrt’s DHCPv6 server, lets unauthenticated attackers execute arbitrary code as root on

Iran-linked Nimbus Manticore deployed the new NightLedger backdoor and WebSocket tunnelers against targets in the Middle East, Africa, and South

Tengu, a new Mirai-derived Linux IoT botnet, triggers device reboots via hardware watchdog when defenders kill its process, supporting 25

Researchers found 24,650 internet-exposed BMCs that disclose IPMI password hashes before login, enabling offline hash cracking and full server takeover.

More than 30 Minnesota water utilities were disrupted in a coordinated OT attack; Tenable suspects Iran-linked CyberAv3ngers based on targeting

Broadcom patched CVE-2026-47876, a critical ESXi VM escape via VMXNET3, plus two critical vCenter Server flaws, with no confirmed in-the-wild
Subscribe to the Daily Security Review Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.