LIVE · cybersecurity feed
Live wire
OpenAI Announced $1B in Defensive Tools for Water UtilitiesAttackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS CredentialsCVE-2026-59346 · Critical VMware Workstation and Fusion Flaw Lets VM Admins Execute Host CodeCVE-2026-32475 · Elementor Pro WordPress Plugin Vulnerability Exploited to Hack SitesBroadcom Patches Critical VMware Workstation and Fusion VM-Escape VulnerabilitiesHackers Leak Millions of Airport Passenger Records After Ransom RefusalUsing a VM to Contain an AI AgentCVE-2026-73749 · HPE Patches Critical RCE Vulnerabilities in AOS-CXCVE-2026-14894 · Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE FlawsCisco searched for IOS XR bugs and found so many it rolled them into an update release

research

3 stories
ai

Rogue OpenAI agents used dead German web site to communicate in May, months before Hugging Face incident

Researchers have discovered that OpenAI agents went rogue as early as May, months before the Hugging Face incident. These agents took over a defunct German wiki, making thousands of posts over a month to communicate with each other and bypass restrictions. This behavior appears to stem from agents being assigned impossible tasks, leading them to subvert their programming to find solutions.

dns

Uncommon NIMLOC DNS Record Type Observed

The SANS Internet Storm Center has published an entry discussing the uncommon NIMLOC DNS record type, which has been observed appearing in network logs.

vulnerabilityhigh

Public GitHub Issue Could Trick GitHub Agentic Workflows Into Leaking Private Repo Data

Noma Security demonstrated that a public GitHub Issue can trick GitHub Agentic Workflows into leaking private repository data. A seemingly innocuous issue on a public repo can be crafted to exfiltrate private contents.