The chain of events leading up to OpenAI's agents attacking Hugging Face and other organizations in July began months earlier, and involved agents asking other agents for help, building message boards, and even becoming paranoid that other agents were maliciously trying to trick them, two OpenAI staffers said at the Black Hat infosec conference on Wednesday. In their talk, OpenAI technical staffer Michael Dalton and researcher Eric Wallace provided new details about the security incident. READ MORE...
Cybercriminals and state-backed hacking groups are abusing trusted identities, cloud services, AI tools, and software supply chains to gain access while avoiding detection, according to CrowdStrike's 2026 Threat Hunting Report. Intrusion activity increased by about 4% over the past year. Even though the increase was smaller than in the previous reporting period, it shows a growing focus on more targeted campaigns. READ MORE...
Apple has imposed strict new submission limits on its bug bounty portal after finding itself overwhelmed by low-quality, AI generated vulnerability reports - many of which were found to be describing security flaws that simply didn't exist. According to a report in the Financial Times, Apple has found itself facing a massive influx of submissions from amateur bug hunters who have used AI to generate plausible-sounding but completely hallucinated bug reports. READ MORE...
Maksim Silnikau, the creator and administrator of the Ransom Cartel ransomware operation, was sentenced to 16 years in prison for his role in ransomware attacks against at least 18 companies worldwide. The U.S. Department of Justice announced today that the 40-year-old Belarusian national was sentenced for conspiracy to commit offenses against the United States, conspiracy to commit wire fraud, and aggravated identity theft. READ MORE...
More than half a dozen services advertised on underground forums and messaging platforms, offering discounted or "unlimited" token access to frontier AI models, were discovered by Okta. Okta believes the trend is likely driven by Chinese users seeking access to AI models that are unavailable because of regulatory and provider restrictions. According to researchers, cost, access restrictions, and a degree of anonymity pull people toward these services. READ MORE...
BLACK HAT - Two security researchers found a way to exploit vulnerabilities in Samsung software, including the virtual assistant Bixby, to hack mobile devices. The research was conducted by Dimitrios Valsamaras, senior security researcher at Microsoft, and Ken Gannon, head of mobile research at Mobile Hacking Lab. They demonstrated the vulnerabilities at the Pwn2Own Ireland hacking competition in October 2025, where they earned $50,000 after exploiting them to hack a Samsung Galaxy S25 device. READ MORE...
Researchers disclosed 15 vulnerabilities in TP-Link networking technologies that they say call into question organizations' blind trust in zero-touch provisioning (ZTP). TP-Link is one of the world's largest edge device manufacturers. At Black Hat this week, Forescout's Vedere Labs security researchers Stanislav Dashevskyi and Francesco La Spina revealed 15 vulnerabilities affecting TP-Link "Omada", the software-defined networking (SDN) ecosystem for TP-Link's products. READ MORE...
AI security company Zenity has disclosed the details of two AI browser hacking techniques targeting Claude in Chrome and ChatGPT Atlas, demonstrating how they can be used for account takeovers, phishing, and making unauthorized Amazon purchases. Zenity described its research in two separate blog posts published on Wednesday, one covering the ChatGPT Atlas research and one covering the Claude in Chrome attack. READ MORE...
Using email platforms to target users is nothing new in the world of threat actors. But as these well-known threats take command of everyone's attention, another vector remains hidden in plain sight. While HTML is the structure that powers web pages, Cascading Style Sheets (CSS) address design and presentation of the page. And according to Gareth Heyes, Web security researcher at PortSwigger, it can be weaponized because of its multiple capabilities. READ MORE...