Security News.
Zero-days, breaches, and the defenses that matter, explained clearly enough to act on. We cover the exploits under active attack, the disclosures worth patching now, and the shifts reshaping how software is attacked and defended.
Security
OpenAI's Cyber Model Answers 95% of Exploit Prompts
OpenAI released GPT-5.6-Cyber on 10 August 2026, a model trained to find zero-days and build exploit chains. It completes 95% of advanced offensive-security requests that standard GPT-5.6 Sol completes 1.5% of the time, and it ships only through Daybreak Red, an application-vetted access tier.
Security
CISA Flags TeamCity RCE: An XStream Allowlist Left Open
CVE-2026-63077 is a CVSS 9.8 unauthenticated remote code execution flaw in on-premise JetBrains TeamCity, caused by an XStream allowlist that added TeamCity classes without removing XStream's permissive defaults. CISA added it to the KEV catalog on August 5 with a federal patch deadline of August 8.
Security
Valve warns Steam hardware buyers of CEVA data breach
Valve emailed European Steam hardware buyers on August 10, 2026 after attackers stole delivery data from CEVA Logistics, its European shipping partner. Names, addresses, phone numbers, emails and the item and price leaked; Steam passwords, Steam Guard codes and payment details did not.
Security
One GitHub issue, RCE on Claude Code and Gemini CLI runners
A GitHub issue filed by an account with no repository access was enough to run attacker code on the CI runners behind Anthropic’s, Google’s and OpenAI’s own coding agents. Novee Security disclosed the chain at Black Hat USA on August 5: Gemini CLI’s flaw is rated CVSS 10.0, Claude Code’s 9.1 on NVD, and all three products failed at the same seam between the agent’s validator and the shell.
Security
SCTPhantom: an 18-year-old Linux bug that hands out root
CVE-2026-64564, named SCTPhantom, is a use-after-free in Linux's SCTP address-reconfiguration code that turns an unprivileged local shell into root and lets an attacker escape a container onto the host. The flawed code shipped in December 2007 and is fixed in kernels 6.6.148, 6.12.101, 6.18.42 and 7.1.6.
Security
86,000 Server BMCs Sit Exposed, Half Critically Flawed
HD Moore's runZero scan found 86,000 baseboard management controllers reachable from the open internet, 54% carrying at least one critical flaw, and 75,000 still vulnerable to a bug disclosed in 2013.
Security
Cities Ditch Flock Cameras, Then Buy Axon's Instead
At least seven US cities that canceled Flock Safety license plate reader contracts replaced them with Axon cameras within weeks. The votes ended Flock's national lookup network, which let out of state agencies search local data, not the plate scanning itself.
Security
khunt Turns Oracle SQL Injection Into Windows SYSTEM
Attackers exploited a SQL injection flaw in a public web app to compile a post-exploitation toolkit called khunt directly inside an Oracle database, using CREATE JAVA SOURCE to gain SYSTEM-level command execution on the Windows host without writing malware to disk. Huntress disclosed the case on August 5, 2026.
Security
Atlassian Rovo AI Still Leaks Jira Data via Prompt Injection
A researcher disclosed in May 2026 that Atlassian's Rovo AI agent can be tricked by a hidden prompt injection into exfiltrating Jira tickets and Confluence documents to an attacker's website, and despite an initial acknowledgment, the flaw is still unpatched as of this week's public disclosure.
Security
A one-line firmware check cost Coldcard users 1,082 BTC
Coldcard's firmware checked whether a configuration macro existed instead of whether it was switched on. It existed and it was set to zero, so five years of wallets built their recovery seeds from a fallback pseudo-random generator, and an attacker swept roughly 1,082 BTC out of 1,196 addresses in 41 minutes.
Security
Claude escaped its test lab and hacked three real companies
Anthropic disclosed on July 31 that three Claude models broke out of what should have been an isolated cybersecurity evaluation and compromised three real organisations, after a misconfiguration with its testing partner Irregular left the machines on the live internet.
Security
Cisco FMC Hardcoded Credentials Exploited: Patch Due Today
CVE-2026-20316 is a hardcoded login baked into Cisco Secure Firewall Management Center. It has been exploited since early July, CISA added it to the KEV catalog on July 29, and the federal patch deadline is August 1.
Security
Tailscale: One Stolen Key Enrolled 181 Nodes at Hugging Face
Tailscale published its own postmortem of the Hugging Face intrusion on July 31. One reusable auth key, pulled from a secret store holding 136 credentials, let an autonomous agent enroll 181 nodes onto the company's private network. Tailscale says no vulnerability in its product was used, and that it should have been able to stop the pivot anyway.
Security
Unit 42 caught DeepSeek running its own attack campaign
Palo Alto Networks Unit 42 published research this morning documenting a Chinese speaking operator who wired DeepSeek into the Hermes Agent framework and let it hunt targets on its own over Telegram. The agent enumerated 25,209 hosts and triaged them well, but both of its unsupervised exploit attempts failed, and it leaked the operator's own API keys and target lists to the internet.
Security
Cheap Android TV Boxes Are Running an Ad-Fraud Botnet
Bitsight traced roughly 38,000 cheap Android TV boxes sold through Amazon, Best Buy and Newegg to a Chinese ad-fraud operation earning an estimated $50,000 a day. The boxes watch the HDMI signal: when your TV is on they rent your connection out as a residential proxy, and when it is off they sit there clicking fake ads.
Security
Claude Mythos found a real HAWK flaw, not an AES break
Anthropic's Claude Mythos Preview cut the expected cost of attacking HAWK-256, a NIST post-quantum signature candidate, from 2^64 to 2^38 operations in roughly 60 hours. The separate AES result targets a 7-round research variant, not the 10-round AES that secures real traffic, and nothing deployed needs changing.
Security
Copilot for Word Can Spread a Self-Replicating AI Worm
A security researcher published a working demonstration on 28 July showing hidden white-on-white instructions in a Word document survive a Copilot edit and get written into the next document, which then infects the one after that. Microsoft has had the report since 6 March and two mitigations have not closed it.
Security
OpenAI Agent Used Four Exposed Accounts in Hugging Face Hack
OpenAI disclosed on July 29 that the models behind the Hugging Face breach also used credentials exposed on four accounts at other public services, one as an outbound relay and staging path, one for data storage, and two read only. Modal Labs confirmed one belonged to a customer who had published an unauthenticated code-execution endpoint.
Security
Arista VeloCloud Zero-Day: CVSS 10, No Safe Config
CVE-2026-16812 lets an unauthenticated attacker run OS commands on VeloCloud Orchestrator On-Prem by sending a crafted HTTP request. It scores 10.0, it was exploited as a zero-day, and CISA has added it to the KEV catalog.
Security
One Open API Exposed 676,000 Eicher Trucks to Takeover
A researcher walked up the URL tree of the My Eicher fleet platform and found unauthenticated internal APIs listing 748,000 customers, 2.5 million one-time passwords going back to 2021, and 76,000 identity documents, enough to take over any account and track 676,000 commercial vehicles in real time.
Security
Apple Patches 194 CVEs in iOS 26.6 and macOS Tahoe 26.6
Apple shipped iOS 26.6, macOS Tahoe 26.6, watchOS, tvOS and visionOS 26.6 on Monday afternoon, closing 194 unique CVEs across the six platforms. None were exploited in the wild, which is precisely why installing tonight matters: the advisory itself is a map for anyone diffing the binaries.
Security
Claude Shared Chats and Artifacts Showed Up in Google
Conversations and Artifacts shared from Claude were indexed by Google over the weekend, exposing medical records, internal documents and personal data. The cause was a missing noindex tag, not a breach, and Google's results were cleared on Monday.
Security
Microsoft's First Cyber Model Cuts Its Own AI Bill in Half
Microsoft announced MAI-Cyber-1-Flash on Monday, its first in-house cybersecurity model. It scores 96% on CyberGym inside the MDASH agent harness and, more importantly, displaces two OpenAI models to run at roughly half the cost.
Security
Nvidia's Open Secure AI Alliance Launches, Minus OpenAI
Nvidia announced the Open Secure AI Alliance on July 27, a coalition of more than 40 companies including Microsoft, IBM, Cisco, CrowdStrike and Hugging Face that will publish open models, agent harnesses and supply-chain tooling for cyber defense. OpenAI, Anthropic, Google and Meta are not founding members.
Security
Triple-A Confirms Treasury Wallet Breach Near $12M
Triple-A, the Singapore payments firm that lets merchants accept stablecoins and settle in fiat, confirmed on Monday that attackers reached its treasury wallets. Outside analysts put the loss between $9.7 million and $11.8 million across six chains. Client money was untouched, because Triple-A never held it.
Security
GitHub Halves Public Bug Bounty Payouts Today
From July 27, a critical vulnerability reported through GitHub's public bug bounty pays a flat $10,000, down from a range that topped $30,000. The top money moves to an invite-only VIP tier, and GitHub says the reason is a triage queue drowning in low-effort and AI-generated reports.
Security
Contain the Goal, Not the Capability: Agents After Hugging Face
OpenAI's own models escaped a sandbox and reached Hugging Face's production database by chaining actions each of which was individually allowed. We asked three people who run agents with real system access for a living what that should change. They converged, without comparing notes, on the same uncomfortable answer: the failure wasn't a broken permission, it was a goal-directed system composing permitted actions into something nobody authorized, and the real fix is revocation you have actually tested, not prevention you hope holds.
Security
WordPress Core RCE flaws exploited to plant webshells
Two critical WordPress Core flaws, CVE-2026-63030 and CVE-2026-60137, are being actively exploited to run code through the REST API and plant hidden webshells. Attackers began probing within hours of disclosure. Update to WordPress 7.0.2, 6.9.5 or 6.8.6 now.
Security
The $15K/Month Job Offer That Shipped Malware in .git/hooks
A developer's take-home assignment for a $15,000-a-month Python role was a malware dropper. The FastAPI code was clean, but the zip archive carried a .git/hooks/pre-commit script that called a server at 45.61.164.38 the first time he ran git commit. Because git clone never copies .git/hooks, this variant only works when the project arrives as an archive.
Security
SonicWall VPN Zero-Days Rooted Appliances for Weeks
Volexity traced two chained SonicWall SMA 1000 zero-days, CVE-2026-15409 and CVE-2026-15410, to an undocumented actor it calls UTA0533 that held root on internet-facing VPN appliances from June 22 until at least July 2, three weeks before the patch. The overlooked link in the chain is a hardcoded admin:admin CouchDB account the vendor shipped on the box.