🔴 AI Agents Turned Into Attackers: Hugging Face Reveals Autonomous Intrusion Campaign
Hugging Face says an autonomous AI agent breached part of its production infrastructure and accessed internal data and service credentials.
Hugging Face is one of the world’s leading open-source AI companies. It provides a platform where developers and organizations can build, share, and deploy machine learning and generative AI models.
Hugging Face disclosed that an autonomous AI agent breached part of its production infrastructure last week. The company detected the intrusion, contained it, and found unauthorized access to a limited number of internal datasets and service credentials. The investigation is still ongoing, but there is no evidence the attackers modified public AI models, datasets, Spaces, or the company’s software supply chain.
Hugging Face says an autonomous AI agent breached part of its production infrastructure and accessed internal data and service credentials.
Hugging Face is one of the world’s leading open-source AI companies. It provides a platform where developers and organizations can build, share, and deploy machine learning and generative AI models.
Hugging Face disclosed that an autonomous AI agent breached part of its production infrastructure last week. The company detected the intrusion, contained it, and found unauthorized access to a limited number of internal datasets and service credentials. The investigation is still ongoing, but there is no evidence the attackers modified public AI models, datasets, Spaces, or the company’s software supply chain.
🔴 Critical ServiceNow code execution flaw now exploited in attacks
Attackers have begun exploiting a critical vulnerability (CVE-2026-6875) in the ServiceNow AI Platform, according to threat intelligence company Defused.
Formerly known as the Now Platform, ServiceNow AI Platform is an enterprise-grade Platform-as-a-Service (PaaS) that helps businesses integrate AI into core enterprise workflows.
Attackers have begun exploiting a critical vulnerability (CVE-2026-6875) in the ServiceNow AI Platform, according to threat intelligence company Defused.
Formerly known as the Now Platform, ServiceNow AI Platform is an enterprise-grade Platform-as-a-Service (PaaS) that helps businesses integrate AI into core enterprise workflows.
🔴 CVE-2026-42533: Critical NGINX Bug Could Turn HTTP Requests Into Server Takeovers
F5 fixes critical nginx flaw CVE-2026-42533 that can crash servers and, in some cases, allow remote code execution through crafted HTTP requests.
F5 released patches for a critical nginx vulnerability, tracked as CVE-2026-42533 (CVSS score of 9.2), that can allow an unauthenticated attacker to trigger a heap buffer overflow using specially crafted HTTP requests.
“heap buffer overflow might occur in a worker process when using the map directive with regex matching if the map variable was included in a string expression after a capture affected by this map; a similar issue might happen when using a non-cacheable variable in a string expression (CVE-2026-42533).” reads the advisory.
F5 fixes critical nginx flaw CVE-2026-42533 that can crash servers and, in some cases, allow remote code execution through crafted HTTP requests.
F5 released patches for a critical nginx vulnerability, tracked as CVE-2026-42533 (CVSS score of 9.2), that can allow an unauthenticated attacker to trigger a heap buffer overflow using specially crafted HTTP requests.
“heap buffer overflow might occur in a worker process when using the map directive with regex matching if the map variable was included in a string expression after a capture affected by this map; a similar issue might happen when using a non-cacheable variable in a string expression (CVE-2026-42533).” reads the advisory.
🔴 Capital One Open Sources AI-Powered ‘VulnHunter’ Security Tool
Financial services giant Capital One has released an internally developed AI-powered security tool to the public as open source.
Dubbed “VulnHunter”, the tool was designed to find and fix software vulnerabilities at the code level, but Capital One says it is not a traditional, passive vulnerability scanner.
“We designed VulnHunter with a developer-first mindset to solve a massive industry pain point: overwhelming false positives that create friction and slow down daily workflows,” Chris Nims, EVP & Chief Information Security Officer (CISO) at Capital One, explained in a LinkedIn post.
Financial services giant Capital One has released an internally developed AI-powered security tool to the public as open source.
Dubbed “VulnHunter”, the tool was designed to find and fix software vulnerabilities at the code level, but Capital One says it is not a traditional, passive vulnerability scanner.
“We designed VulnHunter with a developer-first mindset to solve a massive industry pain point: overwhelming false positives that create friction and slow down daily workflows,” Chris Nims, EVP & Chief Information Security Officer (CISO) at Capital One, explained in a LinkedIn post.
🔴 Researchers Uncover HOLLOWGRAPH: Malware That Hides Inside Microsoft 365 Calendar Invites
A previously undocumented strain of Windows malware is using Microsoft 365 calendar invites as a covert communications channel, allowing attackers to issue commands and exfiltrate stolen files from victim networks while hiding in plain sight among ordinary enterprise traffic, according to new research from the threat intelligence firm Group-IB.
The malware, dubbed HOLLOWGRAPH, was detailed by Group-IB‘s Threat Intelligence team, which said it has attributed the tool with high confidence to the Cavern backdoor framework, a modular command-and-control (C2) toolkit previously linked to Iranian-nexus activity. Researchers said the sample abuses the Microsoft Graph API via a compromised Microsoft 365 account traced to Israel, using it to blend malicious communications into legitimate cloud traffic.
A previously undocumented strain of Windows malware is using Microsoft 365 calendar invites as a covert communications channel, allowing attackers to issue commands and exfiltrate stolen files from victim networks while hiding in plain sight among ordinary enterprise traffic, according to new research from the threat intelligence firm Group-IB.
The malware, dubbed HOLLOWGRAPH, was detailed by Group-IB‘s Threat Intelligence team, which said it has attributed the tool with high confidence to the Cavern backdoor framework, a modular command-and-control (C2) toolkit previously linked to Iranian-nexus activity. Researchers said the sample abuses the Microsoft Graph API via a compromised Microsoft 365 account traced to Israel, using it to blend malicious communications into legitimate cloud traffic.
🔴 YouTube clarifies policies around AI slop and upsetting videos
YouTube already had policies around AI content. Last year, the company announced it was stemming creators’ ability to generate revenue from what it called “inauthentic content,” including mass-produced videos and other types of repetitive content that have become easier to generate with the help of AI technology.
A recent change sees YouTube further cracking down on AI slop by clarifying its policies around how content on its platform can be monetized. To discourage creators from using AI and other tools to make low-quality content, YouTube’s policy now explains that there are three types of videos under the broader category of “inauthentic content” that cannot be monetized.
YouTube already had policies around AI content. Last year, the company announced it was stemming creators’ ability to generate revenue from what it called “inauthentic content,” including mass-produced videos and other types of repetitive content that have become easier to generate with the help of AI technology.
A recent change sees YouTube further cracking down on AI slop by clarifying its policies around how content on its platform can be monetized. To discourage creators from using AI and other tools to make low-quality content, YouTube’s policy now explains that there are three types of videos under the broader category of “inauthentic content” that cannot be monetized.
🔴 Inference startup Infinity raises $15M from Touring Capital, OpenAI and Anthropic researchers
AI infrastructure company Infinity announced a $15 million raise at a $100 million valuation on Monday from investors including Touring Capital, Principal VC, and researchers from companies such as OpenAI and Anthropic.
The startup is building software to make it easier for AI chips to run AI models. One big reason Nvidia became the top player is not just its high-performance chips, but also its CUDA software (Compute Unified Device Architecture), which allows its GPUs (originally designed to run graphics) to act as general-purpose processing CPUs. The largest AI development frameworks PyTorch and TensorFlow have been built on top of CUDA. This allows developers to write their apps in popular languages like Python, use those major AI frameworks and their apps will, by default, run on Nvidia chips.
AI infrastructure company Infinity announced a $15 million raise at a $100 million valuation on Monday from investors including Touring Capital, Principal VC, and researchers from companies such as OpenAI and Anthropic.
The startup is building software to make it easier for AI chips to run AI models. One big reason Nvidia became the top player is not just its high-performance chips, but also its CUDA software (Compute Unified Device Architecture), which allows its GPUs (originally designed to run graphics) to act as general-purpose processing CPUs. The largest AI development frameworks PyTorch and TensorFlow have been built on top of CUDA. This allows developers to write their apps in popular languages like Python, use those major AI frameworks and their apps will, by default, run on Nvidia chips.
🔴 Natural raises $30M to reinvent payments for AI agents — and take on Stripe
AI agents are starting to execute more sophisticated tasks, such as identifying vendors that can deliver freight, comparing prices, and messaging the vendor to organizing a delivery. But when it comes to making a payment for the shipment, they still need to involve a human.
Today’s financial sector relies on financial rails, the underlying infrastructure that moves money and information between a money and financial information between banks, businesses, and consumers. But these financial rails were built for human-initiated transactions, not autonomous AI agents. For example, traditional payment systems like credit cards and ACH rely on human authorization for transactions, which slows down agents engineered to work autonomously.
AI agents are starting to execute more sophisticated tasks, such as identifying vendors that can deliver freight, comparing prices, and messaging the vendor to organizing a delivery. But when it comes to making a payment for the shipment, they still need to involve a human.
Today’s financial sector relies on financial rails, the underlying infrastructure that moves money and information between a money and financial information between banks, businesses, and consumers. But these financial rails were built for human-initiated transactions, not autonomous AI agents. For example, traditional payment systems like credit cards and ACH rely on human authorization for transactions, which slows down agents engineered to work autonomously.
🔴 Scams Now Drive Almost Half of All Malware Detections as Attackers Weaponise Everyday Trust
Scams accounted for almost 46% of all threat detections in the first half of 2026, making them the single largest category of malicious activity tracked by Gen Digital, the company behind Norton, Avast, LifeLock and MoneyLion, according to its newly published Threat Report H1 2026.
The report, Gen’s first half-yearly threat publication after previously reporting on a quarterly basis, argues that the defining pattern of the period was not any single new technique, but attackers consistently inserting themselves into systems and moments that users, platforms and security tools already trust, from hotel booking threads and WhatsApp device pairing to software update channels and AI agent permissions.
Scams accounted for almost 46% of all threat detections in the first half of 2026, making them the single largest category of malicious activity tracked by Gen Digital, the company behind Norton, Avast, LifeLock and MoneyLion, according to its newly published Threat Report H1 2026.
The report, Gen’s first half-yearly threat publication after previously reporting on a quarterly basis, argues that the defining pattern of the period was not any single new technique, but attackers consistently inserting themselves into systems and moments that users, platforms and security tools already trust, from hotel booking threads and WhatsApp device pairing to software update channels and AI agent permissions.
🔴 Mythos Didn't Break Your Security Program. Your Exposure Window Could.
The industry spent the initial months after Anthropic's April 7 Mythos reveal focused on volume. How many new CVEs would Mythos add to an already overloaded pipeline? How quickly would the flood of AI-driven discovery overwhelm triage capabilities? How long would it take adversaries to weaponize Mythos findings at scale? Those questions were and remain valid. Yet they all stop short of addressing the single metric that determines whether any of those vulnerabilities actually lead to a breach: the exposure window.
The industry spent the initial months after Anthropic's April 7 Mythos reveal focused on volume. How many new CVEs would Mythos add to an already overloaded pipeline? How quickly would the flood of AI-driven discovery overwhelm triage capabilities? How long would it take adversaries to weaponize Mythos findings at scale? Those questions were and remain valid. Yet they all stop short of addressing the single metric that determines whether any of those vulnerabilities actually lead to a breach: the exposure window.
🔴 New Continuous Runtime Security Validation service aims to strengthen fintech cyber resilience
Fintech organisations across the UK and Ireland can now access a new service designed to provide ongoing assurance over production security following a strategic partnership between Critical Cloud and Tarian Labs. The Continuous Runtime Security Validation offering helps businesses continuously verify that their security controls remain effective as cloud environments, applications and AI capabilities evolve.
The partnership brings together Critical Cloud’s Managed Runtime Assurance operating model with Tarian Labs’ offensive security specialists, whose experience spans government, defence and critical national infrastructure projects.
Fintech organisations across the UK and Ireland can now access a new service designed to provide ongoing assurance over production security following a strategic partnership between Critical Cloud and Tarian Labs. The Continuous Runtime Security Validation offering helps businesses continuously verify that their security controls remain effective as cloud environments, applications and AI capabilities evolve.
The partnership brings together Critical Cloud’s Managed Runtime Assurance operating model with Tarian Labs’ offensive security specialists, whose experience spans government, defence and critical national infrastructure projects.
🔴 AI’s most important protocol is getting a little bit easier to use
The Model Context Protocol (MCP) is one of the basic building blocks of AI interoperability, giving AI models a secure way to access external data sources and services. It’s the plumbing that lets a chatbot reach into your calendar, your database, or your internal tools, instead of engineers building custom pipes for every connection. Next week, that protocol is getting a significant update, and while it might not be noticeable to end users, it could make a big difference in how the ecosystem develops.
The Model Context Protocol (MCP) is one of the basic building blocks of AI interoperability, giving AI models a secure way to access external data sources and services. It’s the plumbing that lets a chatbot reach into your calendar, your database, or your internal tools, instead of engineers building custom pipes for every connection. Next week, that protocol is getting a significant update, and while it might not be noticeable to end users, it could make a big difference in how the ecosystem develops.
🔴 X relaunches a rebuilt Android app after year-long effort
Nearly a year ago, Elon Musk-owned X announced it would begin rebuilding the Android version of its app, which had not held up well compared with its iOS counterpart. On Monday, the company shipped the refreshed app, which is now available to download.
The new Android version of X was built from scratch and promises improvements to loading, scrolling, notifications, and more, X said in its announcement.
Nearly a year ago, Elon Musk-owned X announced it would begin rebuilding the Android version of its app, which had not held up well compared with its iOS counterpart. On Monday, the company shipped the refreshed app, which is now available to download.
The new Android version of X was built from scratch and promises improvements to loading, scrolling, notifications, and more, X said in its announcement.
🔴 Hackers stole ‘significant’ amount of data from tech firm relied on by thousands of US hospitals and pharmacies
U.K.-based healthcare billing software maker Craneware is responding to a cyberattack in which hackers stole a “significant volume” of customer data from its systems, the company said on Monday.
The company said the hackers appear to have been expelled from its systems, but its investigation into the breach is ongoing, according to a statement filed with the London Stock Exchange.
U.K.-based healthcare billing software maker Craneware is responding to a cyberattack in which hackers stole a “significant volume” of customer data from its systems, the company said on Monday.
The company said the hackers appear to have been expelled from its systems, but its investigation into the breach is ongoing, according to a statement filed with the London Stock Exchange.
🔴 Salt Security tackles AI governance challenge with 100 pre-built agentic security policies
Salt Security has expanded its Policy Hub to include 100 pre-built security policies, as organisations look for practical ways to govern AI agents across enterprise environments.
The company says the milestone creates one of the industry’s largest libraries of governance policies for agentic AI, covering APIs, Model Context Protocol (MCP) servers, authentication, access controls, compliance and runtime behaviour. The announcement comes as organisations rapidly adopt AI agents that can interact with enterprise systems and perform tasks autonomously. Because these agents rely on APIs to access data and invoke tools, Salt argues that traditional API governance has become an essential part of governing AI systems.
Salt Security has expanded its Policy Hub to include 100 pre-built security policies, as organisations look for practical ways to govern AI agents across enterprise environments.
The company says the milestone creates one of the industry’s largest libraries of governance policies for agentic AI, covering APIs, Model Context Protocol (MCP) servers, authentication, access controls, compliance and runtime behaviour. The announcement comes as organisations rapidly adopt AI agents that can interact with enterprise systems and perform tasks autonomously. Because these agents rely on APIs to access data and invoke tools, Salt argues that traditional API governance has become an essential part of governing AI systems.
🔴 SEBI Fines CDSL Rs 1 Crore Over 2022 Malware Attack, Cybersecurity Lapses
India's markets regulator has imposed a cumulative penalty of Rs 1 crore on Central Depository Services (India) Ltd (CDSL) for cybersecurity lapses that led to the November 2022 malware attack, holding that the breach was "foreseeable" and could have been prevented through compliance with mandatory security standards.
In an 88-page order, the Securities and Exchange Board of India (SEBI) levied a Rs 90 lakh penalty under the SEBI Act and Rs 10 lakh under the Depositories Act, while disposing of proceedings against CDSL's former Chief Information Security Officer Rajesh Nadkarni and former Chief Technology Officer Amit Mahajan without imposing monetary penalties
India's markets regulator has imposed a cumulative penalty of Rs 1 crore on Central Depository Services (India) Ltd (CDSL) for cybersecurity lapses that led to the November 2022 malware attack, holding that the breach was "foreseeable" and could have been prevented through compliance with mandatory security standards.
In an 88-page order, the Securities and Exchange Board of India (SEBI) levied a Rs 90 lakh penalty under the SEBI Act and Rs 10 lakh under the Depositories Act, while disposing of proceedings against CDSL's former Chief Information Security Officer Rajesh Nadkarni and former Chief Technology Officer Amit Mahajan without imposing monetary penalties
🔴 Why blocking AI models won’t stop the cyber threats they create
2026 has turned out to be the year when predictions about AI-powered cyberattacks, long hypothesized as a potential risk associated with AI improvement, seem to be coming true. New models have capabilities on par with the best human hackers, marking a pivotal window of opportunity in both AI and cybersecurity policy. This is a transitional period where new technologies are pushing existing American cybersecurity infrastructure to the brink. The real question isn’t whether cybersecurity still matters, but rather: How will the risks that AI introduces be managed before they outpace defenses, and who will step up to lead this challenge?
2026 has turned out to be the year when predictions about AI-powered cyberattacks, long hypothesized as a potential risk associated with AI improvement, seem to be coming true. New models have capabilities on par with the best human hackers, marking a pivotal window of opportunity in both AI and cybersecurity policy. This is a transitional period where new technologies are pushing existing American cybersecurity infrastructure to the brink. The real question isn’t whether cybersecurity still matters, but rather: How will the risks that AI introduces be managed before they outpace defenses, and who will step up to lead this challenge?
Browser Manipulation Module Enables Financial Theft and Account Hijacking
Security researchers have uncovered a powerful web injection module used by the TELEPUZ malware family that enables attackers to manipulate banking sessions, steal browser data, execute malicious JavaScript, and modify financial transactions in real time.
🔗 Read More
Security researchers have uncovered a powerful web injection module used by the TELEPUZ malware family that enables attackers to manipulate banking sessions, steal browser data, execute malicious JavaScript, and modify financial transactions in real time.
🔗 Read More
🔴 Neo Emerges From Stealth With $100M to Control and Secure Enterprise AI Software
American-Israeli cybersecurity startup Neo emerged from stealth mode on Monday with $100 million in funding for a platform that enables enterprises to control and secure AI software.
Neo received the investment across seed and Series A funding rounds from Andreessen Horowitz, Bessemer Venture Partners, Craft Ventures, and Merlin Ventures. The company will use the money to grow its engineering and go-to-market teams.
Neo’s platform serves as a control layer that governs AI agents, AI-enabled applications, and traditional software across enterprise environments.
American-Israeli cybersecurity startup Neo emerged from stealth mode on Monday with $100 million in funding for a platform that enables enterprises to control and secure AI software.
Neo received the investment across seed and Series A funding rounds from Andreessen Horowitz, Bessemer Venture Partners, Craft Ventures, and Merlin Ventures. The company will use the money to grow its engineering and go-to-market teams.
Neo’s platform serves as a control layer that governs AI agents, AI-enabled applications, and traditional software across enterprise environments.
🔴 Healthcare giant Abbott probes two cyber incidents amid extortion claims
Abbott Laboratories, one of the world’s largest healthcare and medical device companies, is investigating two apparently unrelated cyber incidents after confirming unauthorized access to internal systems. While Abbott says there has been no impact on manufacturing, laboratory operations, or patient care, cybercriminal groups ShinyHunters and ShadowByt3$ claim the breaches were far more extensive. Those claims remain unverified at the time of writing and, so far, unsupported by publicly leaked data.
The incidents reportedly involve Abbott’s Cancer Diagnostics business and its LabCentral customer portal for core laboratory diagnostics.
Abbott Laboratories, one of the world’s largest healthcare and medical device companies, is investigating two apparently unrelated cyber incidents after confirming unauthorized access to internal systems. While Abbott says there has been no impact on manufacturing, laboratory operations, or patient care, cybercriminal groups ShinyHunters and ShadowByt3$ claim the breaches were far more extensive. Those claims remain unverified at the time of writing and, so far, unsupported by publicly leaked data.
The incidents reportedly involve Abbott’s Cancer Diagnostics business and its LabCentral customer portal for core laboratory diagnostics.