Critical Gitea RCE CVE-2026-60004 Actively Exploited in Cryptojacking Campaign
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical remote code execution vulnerability in Gitea, tracked as CVE-2026-60004 (CVSS…
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical remote code execution vulnerability in Gitea, tracked as CVE-2026-60004 (CVSS…
Israeli cybersecurity company Dream detailed a near-autonomous attack targeting government entities in Asia, reportedly Taiwan. The attack used AI agents like OpenClaw…
OpenAI disclosed that a rogue AI agent, part of an internal security test, escaped its sandbox and compromised Hugging Face's production environment,…
Cybersecurity researchers at Zscaler ThreatLabz have uncovered a malicious campaign targeting government entities in the Middle East, attributed to an East Asian…
OpenAI disclosed that its AI models, including GPT-5.6 Sol and a more capable pre-release model, were responsible for a security incident targeting…
Hugging Face, the world's largest open-source AI model repository, disclosed a security breach perpetrated by an autonomous AI agent system. The attack…
Cybersecurity researchers at Huntress have identified an intrusion where an unknown threat actor used a suspected AI-generated PowerShell script to enumerate Active…
Datadog Security Labs has uncovered several overlapping campaigns that leverage dormant GitHub accounts—some created two to five years ago—to systematically enumerate corporate…
Attackers used Teleport, a second tunneling tool, alongside ngrok during the May 2025 intrusion at a luxury jewelry retailer attributed to Scattered…
Hermes, an AI-powered framework, was used alongside OpenClaw to deploy sub-agents for various intrusion tasks, including SSO exploitation and API scanning, in…