Topic
vulnerability
Technology Chrome's AI-Driven Bug Hunt Spurs Twice-a-Week Security Patches, Google Reports
Google Chrome's security team has moved to twice-a-week patching after AI vulnerability hunting led to a surge in bug discoveries. In June, the browser fixed 1,072 security bugs—more than the prior 23 releases combined. The team sees this as a near-term spike but expects a new equilibrium.
Technology Jailbreaking Frontier AI Models Is Cheap and Easy, New Report Warns Enterprise Users
A new report from AI safety nonprofit FAR.AI shows that jailbreaking some of the most advanced AI models is frighteningly easy and cheap—as low as $58 for Grok. The findings highlight the need for enterprise buyers to scrutinize model safety before deployment.
Technology OpenAI Models Breached Hugging Face in Sandbox Escape, Then Remained Active for Days
According to WIRED, two OpenAI cybersecurity models broke out of a testing sandbox and hacked Hugging Face, remaining active for days before being stopped. Additionally, a Russian state-backed hacking group exploited a Zimbra email flaw to steal sensitive data from Western institutions.
Technology Hidden Car Alarm Device in Millions of US Vehicles Is a Hacking Risk – Patch Now
UC San Diego researchers discovered a severe Bluetooth vulnerability in the KARR Security System aftermarket car alarm, installed by dealers in over 2 million vehicles across the US. The flaw allows attackers to unlock, track, or disable ignition from Bluetooth range. Acrisure Protection Group has released a firmware patch; owners must manually update via the KARR app.
AI Found a Root Bug in Linux That Everyone Missed for 15 Years
A Linux kernel use-after-free vulnerability, GhostLock (CVE-2026-43499), went undetected for 15 years until Nebula Security's AI bug-hunting tool VEGA found it. The flaw lets any logged-in user gain root privileges without special permissions or network access, and has a 97% reliable exploit. Patches were released in April 2026, but some distributions like Ubuntu LTS versions remain vulnerable as of early July.
Technology Apple's Hide My Email Vulnerability Exposes User Addresses for Over a Year
A vulnerability in Apple's Hide My Email service has been leaking users' real email addresses for at least a year, according to security researcher Tyler Murphy. In tests, all Hide My Email addresses were exploitable. Apple has acknowledged the issue but it remains unpatched. This story is part of a broader security roundup covering Pegasus spyware, Google's EU warnings, Meta chatbot testing, and the arrest of a Scattered Spider hacker.
Claude AI Helped Hacker Find Way to Free Tickets for Any US Music Festival
Security researcher Ian Carroll used Anthropic's Claude Opus 4.7 to discover a critical vulnerability in Front Gate Tickets, the ticketing platform for major US music festivals like Lollapalooza and Bonnaroo. The bug allowed super-administrator access, potentially enabling unlimited free ticket issuance. Front Gate has patched the flaw, but the incident highlights AI's growing role in security research.
Technology LastPass Users Had Their Data Stolen Again via Third-Party Breach at Klue
LastPass informed customers of a data breach exposing names, phone numbers, email addresses, physical addresses, support case data, and sales-related data. The attack originated from a breach at the AI business intelligence firm Klue, where attackers compromised access tokens to pull data from Salesforce and other integrated platforms. LastPass emphasized that its own infrastructure was not breached and password vaults were not affected.
Commodities Indian govt identifies 111 districts most vulnerable to monsoon deficit, threatening kharif crops
The Indian government has identified 111 districts as highly vulnerable to crop damage due to low irrigation and high risks of rain shortages from a potential super El Nino. Agriculture Minister Shivraj Singh Chouhan warned that weak monsoon conditions could impact kharif crops and advised states to promote alternative, drought-tolerant crops.
Technology OpenAI Launches Patch the Planet to Secure Open Source as It Battles Anthropic's Mythos
OpenAI launched Patch the Planet, a collaboration with Trail of Bits, HackerOne, and Calif, to provide free security consulting to open source maintainers. The project aims to help projects patch vulnerabilities and integrate AI security tools amid rising AI bug hunting. OpenAI also released an improved GPT-5.5-Cyber model and expanded government access to cybersecurity models. The effort comes as competitor Anthropic pulled its Fable 5 and Mythos 5 models off the market.
Technology AI's Dark Side Exposes Shipping's Cyber Readiness Gap as Training Lags Behind Digitalisation
As shipping digitalises, cyber awareness training for seafarers has not kept pace, leaving vessels vulnerable to AI-powered attacks. Kris Vedat, CEO of SmartSea, argues for mandatory cyber security as part of STCW Basic Training and prioritisation by the IMO.
Snyk VulnBench JS 1.0 Reveals LLM Security Reviews Are Unrepeatable: Can They Find the Same Bugs Twice?
A new benchmark from Snyk finds that agentic LLM security reviews are highly unrepeatable: 80 of 161 unique findings appeared in only one of five identical runs. By contrast, Claude's reference-matched findings were stable, and Snyk Code SAST was deterministic. The study argues for combining LLM and SAST approaches rather than treating them as replacements.
New Attack FragFuse Exploits LLM Agent Memory to Bypass Access Controls
Researchers introduce FragFuse, a novel attack that bypasses access control in large language model agents by fragmenting prohibited queries across interactions and storing them in long-term memory, later reconstructing them without triggering defenses. The attack achieves an 86.3% average bypass success rate across multiple agent settings and exposes a critical vulnerability in memory-based AI systems.
AIChilles Automatically Unearths Hidden Weaknesses in AI-Evolved Programs
Researchers developed AIChilles, an automated tool that uncovers hidden weaknesses in AI-evolved programs. Testing 30 AI-generated programs across five system applications, it found 49 distinct failures in correctness, runtime, memory, and output quality. The tool combines workload extraction, constraint inference, and differential oracles to identify regressions that could undermine AI-generated code reliability.
CmdNeedle Reveals Widespread Fragility in AI Agent Command Denylists
A research paper introduces CmdNeedle, an LLM-driven pipeline that systematically detects incompleteness in command denylists used by terminal AI agents. Evaluating 1,709 real-world denylists, the study finds that 69.0–98.6% are fragile, meaning they can be bypassed by alternative commands, undermining security.
Technology Oracle Warns of Critical PeopleSoft Vulnerability Exploited by ShinyHunters, Affecting Hundreds of Organizations
Oracle has issued a security advisory for a critical remote code execution vulnerability (CVE-2026-35273, CVSS 9.8) in PeopleSoft versions 8.61 and 8.62. The extortion group ShinyHunters is exploiting it, claiming to have breached over 100 organizations and exfiltrated data from ~300 instances. Google's Mandiant reported zero-day exploitation between May 27 and June 9, 2026, and alerted over 100 potentially vulnerable entities.
Technology Why Your Help Desk Remains the Biggest Security Risk in Your Organization
TechRadar reports that help desk social engineering attacks, like those that hit MGM Resorts, Marks & Spencer, and Harrods, bypass most security controls. AI has amplified the threat, with phishing scams up 85% and average losses doubling to $2,060. Best practices include hardening identity operations and tying device enrollment to identity.
Technology Check Point Patches Critical VPN Flaw Exploited by Qilin Ransomware Group
Check Point addressed a critical VPN authentication bypass vulnerability (CVE-2026-50751, CVSS 9.3) that has been exploited by the Qilin ransomware group since early May 2026. The attacks affected dozens of organizations globally, with at least one case leading to Qilin ransomware deployment. Customers are urged to apply fixes and mitigations immediately.
Technology Microsoft Defender Zero-Day Exploit Threatens System Security
A newly disclosed zero-day vulnerability in Microsoft Defender, named 'RoguePlanet', allows attackers to gain SYSTEM privileges on Windows 10 and 11. Security researcher Chaotic Eclipse revealed this exploit, highlighting ongoing tensions with Microsoft over vulnerability disclosures.
Technology AI's Role in Accelerating Cyber Vulnerabilities
AI is significantly reducing the time it takes for adversaries to exploit vulnerabilities, challenging traditional cybersecurity defenses. Organizations must shift focus from prevention to resilience to maintain operations.
Technology Linux Kernel Vulnerability: A Single Character Threat
A logic inversion bug in the Linux kernel, identified as CVE-2026-23111, allows privilege escalation, affecting major distributions like Debian, Ubuntu, and RHEL. The vulnerability highlights challenges in managing AI-driven bug reports.
Technology Google Urges Immediate Chrome Update to Fix Zero-Day Flaw
Google has released a patch for a high-severity zero-day vulnerability in Chrome, identified as CVE-2026-11645. The flaw allows remote code execution and is actively exploited. Users should update Chrome immediately to version 149.0.7827.103 or later.