OpenAI Cyber Test Breached Hugging Face Production
Hugging Face traced 17,600 actions from an Artifactory escape through two malicious-dataset vectors and into its clusters, network and source control.
Reader edition
Hugging Face traced 17,600 actions from an Artifactory escape through two malicious-dataset vectors and into its clusters, network and source control.
Zenity found URL parameters that preselected a template and auto-submitted instructions inside a logged-in user's Workspace Agents builder.
Any authenticated proxy-key holder could make two MCP preview endpoints run an arbitrary command on the LiteLLM host.
The botnet spread through developer extensions and packages, then used stolen credentials to force-push malicious code into default branches.
CVE-2026-6875 chained query evaluation with a sandbox escape, giving an unauthenticated attacker broad control of a ServiceNow instance and its connected proxy servers.
Push Security traced paid search ads to shared ChatGPT and Claude pages that handed visitors to fake desktop-app downloads.
A civil lawsuit targets a Telegram-based phishing-kit operation that Google links to 2.5 million texts and more than one million fraudulent URLs.
CVE-2025-55241 allowed an Entra actor token from one tenant to impersonate users in another through the legacy Azure AD Graph API.
Researchers put instructions to read .env and encode it into source inside a PNG that text-only pull-request reviewers ignored but vision-capable coding agents later followed.
A Teams lure installed a headless Edge extension and a Python native-messaging host, giving a ransomware access broker a quiet route to local command execution.
A stolen npm publisher account added a malicious dependency to more than 140 Mastra packages, giving Sapphire Sleet an install-time path into developer and CI systems.
AIR says its brand-landingpage experiment reached 26,000 agents after scanners missed a remote instruction source that changed after approval.
CVE-2026-12957 allowed project configuration to start MCP processes with a developer's environment. AWS fixed the flaw in Language Servers for AWS 1.65.0.