<img src="https://secure.ruth8badb.com/159098.png" alt="" style="display:none;">

IT Security Newsletter - 7/29/2026

SHARE

Top News

Authorities investigating a coordinated cyberattack against Minnesota water systems

Federal and state authorities are investigating what they call a coordinated cyberattack over two days against operational technology at more than 30 community water systems in Minnesota. Minnesota IT Services (MNIT), the state agency in charge of information technology, said it is coordinating with various state and federal agencies and private sector partners to respond to the attacks. READ MORE...


We now have a better understanding how OpenAI hacked into Hugging Face

Last week's unprecedented security event in which two OpenAI security hacking models trespassed into the network of fellow AI company Hugging Face was enabled by exploiting one or more zero-day vulnerabilities in Artifactory, JFrog, the product's developer, said Monday. In an incident mimicking a dystopian sci-fi novel, two OpenAI models broke out of the restricted environment meant to keep them from accessing the Internet during an internal test, the AI company revealed last week. READ MORE...

Trends

AI-found bugs aren't proving any easier to exploit despite the hype

Anthropic's Project Glasswing may have uncovered tens of thousands of potential security flaws, but new research suggests AI-assisted vulnerability discovery has yet to produce the wave of real-world attacks many expected. In research shared with The Register, VulnCheck analyzed 1,061 publicly attributed AI-assisted vulnerability discoveries from Anthropic's Project Glasswing and the Berkeley Vulnerability Research Initiative. READ MORE...


FBI sees Anthropic's Mythos as a law enforcement challenge

Advancements in AI model capabilities, like those found in Anthropic's Mythos, are raising concerns from law enforcement agencies about what adversaries may be capable of with the emerging technologies, an FBI official said Tuesday. The Trump administration imposed export controls on the Mythos 5 model in June shortly after its release, citing national security implications. Anthropic said Mythos 5 could identify and exploit bugs that were not previously known "in every major operating system." READ MORE...

Information Security

Stronger AI Safety Requires Peeking Inside the 'Black Box'

Adding security to AI often treats the large language model (LLM) or AI system as a black box, focusing on analyzing the tokenized inputs and outputs but not what goes on inside the model. The resulting techniques are often complex and individualized to specific models. A group of offensive-security researchers hopes to change that, presenting at the Black Hat USA 2026 in August a model-agnostic approach to activation analysis with standardized rules for processing activation events. READ MORE...


OpenAI's rogue AI agent shows why we need federal rules for autonomous systems

Months before the Hugging Face breach, Emergence AI published research that investigative journalist Ronan Farrow made public. Ten autonomous AI agents operated across five virtual environments for fifteen days without human intervention. Much of the attention focused on Grok 4.1 turning violent and Gemini 3 Flash committing 683 crimes. What mattered more went unnoticed: Anthropic's Claude Sonnet 4.6 stole resources from neighboring environments the moment it joined a shared one. READ MORE...

Exploits/Vulnerabilities

'Certighost' Flaw Haunts Microsoft Active Directory Certificates

Researchers released a proof-of-concept (PoC) exploit for a now-patched flaw in Microsoft's Active Directory Certificate Services (AD CS) that can allow a low-privileged domain user to impersonate a domain controller and fully compromise an AD environment. The flaw was present due to a defective trust boundary within the certificate-based client authentication aspect of Microsoft AD Services. READ MORE...


Thousands of Data Center Controllers Open to Takeover

Some 24,000 Internet-exposed server management controllers are vulnerable to a more than 20-year-old flaw that gives attackers a way to crack authentication credentials and gain privileged access to the underlying servers. The issue can evade conventional security tools because these management controllers operate independently of the server's operating system, kernel, containers, and workloads, and are therefore nearly invisible at those layers. READ MORE...

Encryption

Here's what Anthropic found when it turned Mythos loose on encryption algorithms

Anthropic researchers used Claude Mythos Preview to find new weaknesses in two cryptographic methods, the company said Tuesday, including one that is being considered by the National Institute of Standards and Technology for both traditional and quantum computing. In a blog post detailing the work, the frontier AI company called it a "substantial" research advancement, but also emphasized that neither flaw affects software now in use. READ MORE...

On This Date

  • ...in 1588, the Spanish Armada is defeated off the coast of Gravelines, France by British naval forces.
  • ...in 1909, the Buick Motor Company acquires the Cadillac Motor Company on behalf of General Motors for $4.5 million.
  • ...in 1953, Rush lead singer and bassist Gary Lee Weinrib, AKA Geddy Lee, is born in North York, Ontario.
  • ...in 1958, the US space agency NASA (National Aeronautics and Space Administration) is created as the successor to the National Advisory Committee for Aeronautics (NACA).