OpenAI: the models escaped the sandbox and hit Hugging Face
OpenAI admitted an unprecedented security incident during an internal evaluation: some of its models managed to break out of the test sandbox and reach the Internet. According to r
Active exploit on SharePoint CVE-2026-50522 after Patch Tuesday
Microsoft SharePoint has come under attack following the publication of a public proof-of-concept for CVE-2026-50522, a critical deserialization flaw that can lead to remote code e
ServiceNow AI Platform CVE-2026-6875: Unauthenticated RCE Already Exploited
The CVE-2026-6875 vulnerability in the ServiceNow AI Platform allows an unauthenticated attacker to execute remote code on self-hosted instances. Searchlight Cyber disclosed it on
WordPress wp2shell: the exploit chain fueling mass scanning
Two critical WordPress vulnerabilities, CVE-2026-63030 and CVE-2026-60137, have been combined into the chain known as wp2shell, capable of going from an unauthenticated request all
Qilin exploits CVE-2026-0257 in PAN-OS GlobalProtect to breach VPNs
The Qilin ransomware operation is abusing CVE-2026-0257, an authentication bypass vulnerability in PAN-OS GlobalProtect, to gain unauthorized access to corporate networks. The flaw
FakeGit: 7,600 malicious GitHub repositories trick AI agents and spread SmartLoader
A campaign called FakeGit set up around 7,600 malicious GitHub repositories, with over 800 projects pretending to be AI Skills or MCP servers. According to researchers, the operati
Two million cars with dealer-installed anti-theft systems are exposed via Bluetooth
Researchers at the University of California, San Diego, have discovered that at least 2.2 million cars with dealer-installed anti-theft systems are vulnerable to a Bluetooth attack
OT security: the ‘air gap’ is a myth and resilience must be designed
In an interview with Help Net Security, Benjamin Bachmann of Bilfinger explains that attackers are increasingly aiming to control industrial operations rather than merely steal dat
PR3TACK wants to map threats before attackers use them
PR3TACK is an open framework that seeks to bridge the gap between what attackers have already done and what they might do tomorrow. Instead of simply cataloging techniques observed
ANPR data access via PDND changes the way the Italian public sector works
Italy's public administration can now use data already held in the ANPR registry through the PDND, reducing repeated requests and manual certificate handling. Since July 1, 20

