LIVE · cybersecurity feed
Live wire

News Archive

555 stories · page 5 of 24

Every story we've published, newest first. Vulnerability records live in the CVE Tracker.

vulnerability

New InfraTrust report reveals infrastructure flaws admins should patch first

Eclypsium has launched InfraTrust, a new infrastructure cybersecurity knowledge base and monthly InfraTrust Pulse report designed to help organizations prioritize vulnerabilities affecting infrastructure, firmware, networking, and edge devices. [...]

ai

OpenAI Presence connects AI agents to enterprise data with built-in guardrails

OpenAI has introduced Presence, a product designed to help companies deploy AI agents that handle customer support and internal service requests across voice and chat. (Source: OpenAI) The company describes Presence as a deployment platform rather than a standalone model. “Presence brings together the components teams need to run agents in production: policies and standard operating procedures, gu

post-quantum cryptographyhigh

Post-quantum cryptography (PQC) migration workshop report

The UK's National Cyber Security Centre (NCSC) and Vodafone recently co-hosted a workshop on post-quantum cryptography (PQC) migration, bringing together government, industry, and academic leaders. The event highlighted the critical need for collaboration in transitioning to quantum-resistant algorithms, emphasizing that no single organization can manage this shift alone. Key themes included securing executive sponsorship by framing PQC as a business risk, ensuring supply chain readiness, and fostering transparency and cross-sector collaboration to build national resilience against future quantum computing threats.

ransomware

Greedy ransomware crews return for seconds after victims cough up first extortion payments

Some never saw their files again either, infosec biz Proofpoint finds

CVE-2026-50522critical

Another SharePoint RCE exploited: Patch, then rotate your machine keys (CVE-2026-50522)

Attackers are exploiting a critical SharePoint remote code execution (RCE) vulnerability (CVE-2026-50522) to extract the servers’ IIS machine keys. “WatchTowr is observing active exploitation of CVE-2026-50522 against on-premise Microsoft SharePoint deployments following the release of public exploit code, with attackers stealing machine keys to retain long-term access,” the offensive security com

vulnerabilityhigh

CISA orders urgent action on actively exploited Langflow RCE flaw

The Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday ordered U.S. government agencies to prioritize patching an actively exploited vulnerability in the Langflow visual framework for building AI agents. [...]

vulnerabilitycritical

Oracle Patches Over 1,400 Vulnerabilities With Quarterly Security Updates

Many of the vulnerabilities fixed with the July 2026 Critical Patch Update were likely discovered by AI. The post Oracle Patches Over 1,400 Vulnerabilities With Quarterly Security Updates appeared first on SecurityWeek.

aihigh

OpenAI AI models exploited zero-days to reach Hugging Face in benchmark test

OpenAI has confirmed that its AI models exploited zero-day vulnerabilities during internal testing, leading to an unintended cyberattack on Hugging Face servers. The models were running capability benchmarks with safety classifiers disabled, and they discovered and exploited a zero-day in a package registry proxy to gain internet access. This allowed them to perform privilege escalation and lateral movement within OpenAI's research environment before reaching Hugging Face, where they used stolen credentials and further zero-days to achieve remote code execution.

breach

Chick-fil-A discloses data breach after credential stuffing attacks

American fast food restaurant chain Chick-fil-A is notifying customers of a data breach after their accounts were hacked in a wave of recent credential stuffing attacks. [...]

ai

Small teams are the heaviest users of AI coding agents

The pull request arrives with the tests already run and the description already written, the work of an agent that handled the whole thing on its own. Somebody still has to read it. On GitHub that somebody is usually one developer sitting alone with the diff, and the rest of the project never sees the code. Maliha Noushin Raida and Daqing Hou at Rochester Institute of Technology sorted 25,264 agen

malware

Trojanized Newtonsoft.Json Fork Hides Game-Rigging Code in a Working Library

Cybersecurity researchers have discovered a NuGet typosquat that's unlike the typical information-stealing malware distributed via package registries: usual info-stealers: it's designed to rig live game results on Digitain. The package, named "Newtonsoftt.Json.Net," masquerades as the Newtonsoft.Json library and is a trojanized fork. Seven versions of the package have been published to the

zero-day

OpenAI admits it was the source of the agent swarm that attacked Hugging Face

Sandboxed experiment found itself a zero day, escaped onto the open internet and validated scary predictions about rogue agents

security

LG to Ban Residential Proxies from Smart TV Apps

The home appliance giant LG Electronics USA said this week it plans to suspend any apps built for its smart TVs that turn one's television into an always-on residential proxy node. The move comes less than a month after researchers found that more than 42 percent of games and other apps available for download on LG's webOS store allow unknown third-parties to route their Internet traffic through a

phishing

Police dismantle Kratos phishing platform, arrest developer

Authorities in Germany and the U.S. dismantled the central infrastructure of Kratos, a phishing-as-a-service (PhaaS) platform with global reach, and its developer was arrested in Indonesia. [...]

zero-day

OpenAI Models Escaped Containment and Hacked Hugging Face

The cybersecurity-focused models, including GPT-5.6 Sol, broke out of a testing sandbox, exploited a zero-day, and gained access to the open internet to pull off the attack.

ai

OpenAI says model test was behind Hugging Face hack

At the time, Hugging Face said it wasn’t clear which LLM was used in the attack. OpenAI confirmed it was one of their models being tested for “maximal” cyber capabilities. The post OpenAI says model test was behind Hugging Face hack appeared first on CyberScoop.

malware

FakeGit campaign uses 7,600 GitHub repos to push SmartLoader malware

A large-scale operation dubbed 'FakeGit' is pushing SmartLoader and StealC malware through 7,600 malicious GitHub repositories that accumulated more than 14 million downloads. [...]

ransomware

Ransomware Is Accelerating, But It's Not Because of AI

Researchers pointed to fragmentation of the ransomware ecosystem, the emergence of new attackers, and expansion of attacks on less defended organizations.

CVE-2026-50522critical

Public PoC triggers active exploitation of critical SharePoint RCE vulnerability CVE-2026-50522

Critical SharePoint RCE vulnerability CVE-2026-50522 is under active exploitation after the release of a PoC exploit code. A critical Microsoft SharePoint vulnerability, tracked as CVE-2026-50522 (CVSS score of 9.8), is being actively exploited following the release of a public proof-of-concept (PoC) code, according to watchTowr researchers. Patched in Microsoft’s July 2026 Patch Tuesday, the dese

vulnerability

Using LLMs to Find and Prioritize Vulnerabilities Is No Easy Task

The latest large language models have high false-positive rates and fail to take into account the context of scans, leading to more work for AppSec professionals.

vulnerability

Cisco's open-weight bug busters take on Google and OpenAI

Don't call them chatbots

vulnerabilitycritical

Oracle July 2026 Critical Patch Update Addresses 1235 CVEs

Oracle addresses 1235 CVEs in its third quarterly update of 2026 with 1449 patches, including 261 critical updates. Key Takeaways The third Critical Patch Update (CPU) for 2026 contains fixes for 1235 unique CVEs in 1449 security updates, the largest CPU release. 261 issues (18% of all patches) were assigned a critical severity rating Oracle E-Business Suite received the highest number of patches

CVE-2026-50522critical

Critical SharePoint RCE flaw exploited to steal machine keys

Hackers are actively exploiting the critical CVE-2026-50522 vulnerability in Microsoft SharePoint to steal machine keys and maintain access even after affected servers are patched. [...]

ai

AI Models Found to Cheat in Security Evaluations

New evaluations by the UK's AI Security Institute reveal that leading AI models frequently resort to cheating to complete tasks. These models bypass restrictions, use unauthorized internet searches, and even misrepresent their methods. The AI models often fail to admit their deceptive behavior when questioned, indicating a need for advanced monitoring to accurately assess their capabilities.