World’s Largest AI Model Repository Hugging Face Breached by Autonomous AI Agent

20/07/2026 0 Comments 0 tags

In an ironic twist, open-source artificial intelligence (AI) platform Hugging Face revealed that it was the victim of a hack perpetrated by an autonomous AI agent system. The company said

Critical NGINX Vulnerability Can Crash Workers and May Allow Remote Code Execution

20/07/2026 0 Comments 0 tags

F5 has shipped fixes for a critical nginx flaw that lets a remote, unauthenticated attacker trigger a heap buffer overflow in the worker process with crafted HTTP requests. CVE-2026-42533 was

SonicWall SMA Zero-Days Exploited Before Disclosure to Gain Root Access

19/07/2026 0 Comments 0 tags

A previously undocumented threat actor has been attributed to the exploitation of recently disclosed SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances as zero-days prior their public disclosure since

UAC-0145 Uses ClickFix CAPTCHAs to Infect Ukrainian Devices wih Malware

19/07/2026 0 Comments 0 tags

Russian state-sponsored threat actors have been observed leveraging the infamous ClickFix strategy to trick Ukrainian targets into infecting their own machines with data-stealing malware. According to the Computer Emergency Response

New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code

17/07/2026 0 Comments 0 tags

An anonymous HTTP request can run code on a WordPress site. The bug is in core, so a bare install with zero plugins is exploitable. Every 6.9 and 7.0 site

OpenSSL HollowByte Flaw Could Freeze Server Memory with 11-Byte TLS Requests

17/07/2026 0 Comments 0 tags

Eleven bytes will make an unpatched OpenSSL server set aside up to 131 KB of memory for a message that never arrives. On the glibc systems Okta tested, that memory

Seven Malicious Vite npm Packages Use Blockchain C2 to Deliver a RAT

17/07/2026 0 Comments 0 tags

Cybersecurity researchers have discovered a cluster of seven malicious npm packages targeting the Vite frontend tooling ecosystem as part of a software supply chain attack. The malicious package campaign, codenamed

GoldenEyeDog Subgroup Linked to DigiCert Breach and Code-Signing Certificate Theft

17/07/2026 0 Comments 0 tags

Cybersecurity researchers have attributed the April 2026 DigiCert security incident to a threat activity cluster dubbed CylindricalCanine. Expel, which shared technical details of the event, described the threat actor as

New NadMesh Botnet Hunts Exposed AI Services for Cloud Keys and Kubernetes Tokens

17/07/2026 0 Comments 0 tags

A Go botnet called NadMesh turned up in early July hunting exposed AI services, and the operator’s own dashboard claims 3,811 unique AWS keys. A Shodan harvester keeps the scan

Fake Coding Tests Deliver OtterCookie-Aligned Malware Hidden in SVG Flag Images

17/07/2026 0 Comments 0 tags

North Korean threat actors linked to the Contagious Interview campaign have been observed employing steganography in SVG image files to conceal malicious payloads as part of a campaign using fake