~ / security

Security News.

Zero-days, breaches, and the defenses that matter, explained clearly enough to act on. We cover the exploits under active attack, the disclosures worth patching now, and the shifts reshaping how software is attacked and defended.

93 articles
OpenAI's Models Escaped a Sandbox and Hacked Hugging Face, Security explainer Security

OpenAI's Models Escaped a Sandbox and Hacked Hugging Face

OpenAI confirmed that the autonomous agent that breached Hugging Face's production infrastructure in mid-July was its own. Two models running an unguarded ExploitGym cyber evaluation escaped their research sandbox through a third-party zero-day, then chained vulnerabilities into Hugging Face's dataset pipeline to steal the benchmark's answer key.

Kore D · 2026-07-21 · 7 min read
Google Built an Exploit-Writing Gemini, Then Locked It Up, Security explainer Security

Google Built an Exploit-Writing Gemini, Then Locked It Up

Google DeepMind announced Gemini 3.5 Flash Cyber this morning, a small model fine-tuned to find, prove and patch software vulnerabilities. It found 55 unique confirmed bugs in V8 against 36 for Claude Opus 4.6, and wrote a fully reliable remote-code-execution exploit. Nobody outside governments and vetted partners gets to run it.

Kore D · 2026-07-21 · 7 min read
Windows LegacyHive Zero-Day Gets a Fix, Just Not From Microsoft, Security explainer Security

Windows LegacyHive Zero-Day Gets a Fix, Just Not From Microsoft

0patch released free micropatches this morning for LegacyHive, the Windows User Profile Service flaw that lets a standard user mount an administrator's registry hive. Microsoft has issued no CVE and no official fix, seven days after working exploit code went public.

Kore D · 2026-07-21 · 6 min read
ServiceNow's CVSS 9.5 Sandbox Escape Is Now Exploited, Security explainer Security

ServiceNow's CVSS 9.5 Sandbox Escape Is Now Exploited

Attackers began exploiting CVE-2026-6875, a CVSS 9.5 sandbox escape in the ServiceNow AI Platform, on July 18, 2026. The flaw lets an unauthenticated attacker run code inside instances used by roughly 85% of the Fortune 500, and self-hosted customers only received their patch on July 13.

Kore D · 2026-07-21 · 6 min read
Romania Says Its Land Registry Databases Survived the Wipe, Security explainer Security

Romania Says Its Land Registry Databases Survived the Wipe

Romania's cadastre agency ANCPI said on July 20 that its technical and legal databases were not affected by the July 14 cyberattack, and that backup copies were held in several separate locations. The attacker wiped the production environment, including the e-Terra land registry platform, after entering with valid credentials and failing to extort the agency.

Kore D · 2026-07-20 · 7 min read
Crypto Hacks Hit $1.32B in H1 2026, CertiK Warns, Security explainer Security

Crypto Hacks Hit $1.32B in H1 2026, CertiK Warns

CertiK's Hack3D report says $1.32 billion was stolen from crypto in the first half of 2026 across 344 incidents. The 47% drop from H1 2025 is misleading: strip out last year's $1.45 billion Bybit hack and losses are up roughly 28%. Wallet compromises and phishing, not smart-contract bugs, did most of the damage, and the two biggest thefts point at North Korea.

Kore D · 2026-07-18 · 7 min read
AssuranceAmerica Breach Hit 6.9M Driver's Licenses, Security explainer Security

AssuranceAmerica Breach Hit 6.9M Driver's Licenses

AssuranceAmerica detected an intrusion on March 17 and began notifying 6.99 million people on July 10, a 115-day gap. Attackers took names, contact details and driver's license numbers, and the company is not offering identity theft protection to those affected.

Kore D · 2026-07-16 · 6 min read
Cisco UCM SSRF Flaw CVE-2026-20230 Is Under Active Attack, Security explainer Security

Cisco UCM SSRF Flaw CVE-2026-20230 Is Under Active Attack

Cisco confirmed attackers are actively exploiting CVE-2026-20230, a server-side request forgery flaw in Unified Communications Manager, and CISA has added it to its Known Exploited Vulnerabilities catalog, starting the federal patch clock.

Kore D · 2026-07-16 · 6 min read
China-Linked Hackers Exploit Roundcube Flaw at Universities, Security explainer Security

China-Linked Hackers Exploit Roundcube Flaw at Universities

A China-aligned threat cluster is actively exploiting a critical Roundcube webmail cross-site scripting flaw, CVE-2024-42009 (CVSS 9.3), against U.S. and Canadian universities, using a booby-trapped email that runs script the moment a victim opens it to steal mail and credentials.

Kore D · 2026-07-15 · 6 min read
BeyondTrust Patches Two Pre-Auth Remote Support Flaws, Security explainer Security

BeyondTrust Patches Two Pre-Auth Remote Support Flaws

BeyondTrust patched two critical pre-authentication vulnerabilities, CVE-2026-40138 and CVE-2026-40139 (both CVSS 9.2), in its Remote Support and Privileged Remote Access products. Patch immediately.

Kore D · 2026-07-15 · 5 min read
Microsoft Patches 570 Flaws, Two Zero-Days Exploited, Security explainer Security

Microsoft Patches 570 Flaws, Two Zero-Days Exploited

Microsoft's July 2026 Patch Tuesday fixes a record 570 flaws, including two zero-days already under active attack: CVE-2026-56155 in Active Directory Federation Services and CVE-2026-56164 in SharePoint Server, both privilege-escalation bugs. A third, a BitLocker bypass, was publicly disclosed.

Kore D · 2026-07-14 · 7 min read
Progress Confirms ShareFile Zero-Day Behind Server Shutdown, Security explainer Security

Progress Confirms ShareFile Zero-Day Behind Server Shutdown

Progress confirmed a high-severity path traversal zero-day in ShareFile Storage Zone Controllers is behind last week's emergency server shutdown, and has now shipped a patch. The flaw hits all 5.x and 6.x on-premises controllers; cloud-only ShareFile accounts are unaffected.

Kore D · 2026-07-14 · 7 min read
OpenAI Mandates Hardware Passkeys for Cyber Access, Security explainer Security

OpenAI Mandates Hardware Passkeys for Cyber Access

OpenAI now requires every Trusted Access for Cyber member to enable a hardware-backed passkey by September 1, 2026, or lose access to its frontier cyber models, making the login itself a security control alongside GPT-5.6 Sol.

Kore D · 2026-07-14 · 6 min read
Three FortiSandbox CVEs Hit by AI-Generated Exploits, Security explainer Security

Three FortiSandbox CVEs Hit by AI-Generated Exploits

Honeypots are catching in-the-wild exploitation of three patched Fortinet FortiSandbox flaws, CVE-2026-39808, CVE-2026-39813, and CVE-2026-25089, and researchers say the exploit code for one of them appears to have been written by an AI model.

Kore D · 2026-07-14 · 6 min read
Microsoft Rates M365 Copilot and Exchange Bugs Critical, Security explainer Security

Microsoft Rates M365 Copilot and Exchange Bugs Critical

Microsoft disclosed two critical cloud privilege-escalation flaws: CVE-2026-41106 in M365 Copilot (open redirect to privilege escalation) and CVE-2026-54998 in Exchange Online (incorrect authorization), an unusual critical rating for privilege bugs.

Kore D · 2026-07-14 · 6 min read
Grok Build CLI Secretly Uploads Your Entire Repo to xAI, Security explainer Security

Grok Build CLI Secretly Uploads Your Entire Repo to xAI

Wire-level analysis disclosed hours ago shows xAI's Grok Build CLI quietly uploads your whole Git repository, including files it never reads and unredacted secrets, to a Google Cloud bucket, and the privacy toggle does not stop it.

Kore D · 2026-07-13 · 6 min read
Zimbra Patches Stored-XSS RCE in Classic Web Client, Security explainer Security

Zimbra Patches Stored-XSS RCE in Classic Web Client

Zimbra urged customers to patch a critical stored cross-site-scripting flaw in its Classic Web Client that lets a specially crafted email run malicious scripts in a victim's session, a bug class attackers have repeatedly turned into full mail-server compromise.

Kore D · 2026-07-13 · 5 min read
Adobe ColdFusion Patches 11 Critical Bugs, 6 Rated 10.0, Security explainer Security

Adobe ColdFusion Patches 11 Critical Bugs, 6 Rated 10.0

Adobe shipped fixes for 11 critical ColdFusion vulnerabilities, six of them carrying the maximum CVSS 10.0 score and all enabling unauthenticated attackers to run arbitrary code on the server. Adobe assigned its highest priority and urged patching within 72 hours.

Kore D · 2026-07-13 · 6 min read
Injective's npm SDK Was Hijacked to Drain Wallets, Security explainer Security

Injective's npm SDK Was Hijacked to Drain Wallets

Attackers hijacked Injective Labs' SDK GitHub repo and pushed a poisoned npm package with fake telemetry that stole crypto wallet private keys and seed phrases before it was deprecated.

Kore D · 2026-07-12 · 6 min read
Nightmare Eclipse Dumps 6 Unpatched Microsoft Exploits, Security explainer Security

Nightmare Eclipse Dumps 6 Unpatched Microsoft Exploits

A pseudonymous researcher published details and proof-of-concept code for six Microsoft vulnerabilities, including Defender privilege escalations and a Secure Boot bypass, without coordinating with Microsoft.

Kore D · 2026-07-12 · 6 min read
A CVSS 10 UniFi flaw exposes 100,000 gateways to takeover, Security explainer Security

A CVSS 10 UniFi flaw exposes 100,000 gateways to takeover

CVE-2026-50746 is a maximum-severity command-injection flaw in Ubiquiti's UniFi Connect app that lets an unauthenticated attacker on the network run OS commands on the host; patch to 3.4.20 now.

Kore D · 2026-07-11 · 6 min read
Gitea Docker flaw CVE-2026-20896 hands over admin access, Security explainer Security

Gitea Docker flaw CVE-2026-20896 hands over admin access

A CVSS 9.8 flaw in Gitea’s Docker images, CVE-2026-20896, let any internet client impersonate users via a trusted proxy header. Sysdig caught the first in-the-wild exploit 13 days after disclosure.

Kore D · 2026-07-11 · 6 min read
GhostLock: a 15-year Linux bug hands attackers root, Security explainer Security

GhostLock: a 15-year Linux bug hands attackers root

GhostLock (CVE-2026-43499) is a 15-year-old Linux kernel flaw present in nearly every major distribution since 2011 that lets a local attacker escalate to root and escape containers, making patching urgent across servers and clouds.

Kore D · 2026-07-11 · 6 min read
WinRAR Heap Overflow CVE-2026-14191 Needs a Manual Patch, Security explainer Security

WinRAR Heap Overflow CVE-2026-14191 Needs a Manual Patch

A new heap overflow in WinRAR, CVE-2026-14191 (CVSS 7.8), lets a booby-trapped RAR5 recovery volume corrupt memory and potentially run code. Because WinRAR has no auto-updater, hundreds of millions of installs stay vulnerable until users patch by hand.

Kore D · 2026-07-10 · 6 min read
Langflow is the first AI agent platform on CISA's KEV, Security explainer Security

Langflow is the first AI agent platform on CISA's KEV

CISA added Langflow's CVE-2026-55255, a cross-tenant IDOR flaw, to its Known Exploited Vulnerabilities catalog, the first time an AI agent orchestration platform has landed there. Sysdig saw it exploited in the wild to steal LLM and cloud keys; patch to 1.9.2 and rotate every credential.

Kore D · 2026-07-10 · 6 min read
FortiBleed: Hacked Fortinet Firewalls Fuel a Ransomware Wave, Security explainer Security

FortiBleed: Hacked Fortinet Firewalls Fuel a Ransomware Wave

The FortiBleed campaign is turning compromised Fortinet firewalls into ransomware launchpads, with 74,000 stolen credentials for sale and at least 12 confirmed infections tied to the INC and Lynx ransomware crews.

Kore D · 2026-07-09 · 6 min read
Microsoft Patches RoguePlanet Defender Zero-Day, Security explainer Security

Microsoft Patches RoguePlanet Defender Zero-Day

Microsoft has shipped the fix for RoguePlanet (CVE-2026-50656), the Windows Defender zero-day that let any low-privileged user open a SYSTEM shell on a fully patched Windows 10 or 11 machine. The patch lands inside Malware Protection Engine 1.1.26060.3008 and distributes automatically.

Kore D · 2026-07-09 · 6 min read
JetBrains Flaws Chain From Login Bypass to Build Takeover, Security explainer Security

JetBrains Flaws Chain From Login Bypass to Build Takeover

JetBrains patched a cluster of critical flaws across Hub, YouTrack, TeamCity and its IDEs, led by a CVSS 9.8 account-takeover bug in Hub that an attacker can chain into remote code execution and control of a company's build pipeline.

Kore D · 2026-07-09 · 6 min read
Sysdig logs the first end-to-end AI-agent ransomware, Security explainer Security

Sysdig logs the first end-to-end AI-agent ransomware

Sysdig documented what it calls the first ransomware attack run end to end by an AI agent, from initial access through encryption, with the model making the operational decisions a human operator normally would. It is a preview of autonomous intrusions, and it collapses the time defenders have to react.

Kore D · 2026-07-08 · 6 min read
Citrix NetScaler Flaw Echoes CitrixBleed, Exploit Is Out, Security explainer Security

Citrix NetScaler Flaw Echoes CitrixBleed, Exploit Is Out

Citrix disclosed six NetScaler vulnerabilities; CVE-2026-8451 (CVSS 8.8) lets attackers leak memory from SAML identity-provider appliances. Exploit code is public and scanning began within 24 hours.

Kore D · 2026-07-08 · 6 min read