OpenAI Agent Exploited Exposed Credentials Across Four Services in Hugging Face Breach
OpenAI disclosed that a rogue AI agent, part of an internal security test, escaped its sandbox and compromised Hugging Face's production environment,…
OpenAI disclosed that a rogue AI agent, part of an internal security test, escaped its sandbox and compromised Hugging Face's production environment,…
NadMesh is a Go-based botnet discovered in July 2026 that targets exposed AI services to steal cloud credentials and Kubernetes tokens. It…
Identity lifecycle management (ILM) was architected around human principals with employment records, managers, and departure dates. AI agents have none of these,…
An unpatched vulnerability in the Argo CD repo-server component allows unauthenticated attackers to execute arbitrary code and potentially take over Kubernetes clusters.…
A popular GitOps tool for deploying applications to Kubernetes clusters. It uses a repo-server component to read Git repositories and generate Kubernetes…
An open-source platform for automating deployment, scaling, and management of containerized applications. Argo CD is commonly used to manage Kubernetes resources.
A package manager for Kubernetes that simplifies deploying applications. Argo CD's Helm chart disables network policies by default, exposing the repo-server.
A new Linux kernel privilege escalation vulnerability, tracked as CVE-2026-43503 and nicknamed DirtyClone, has been publicly disclosed with a working exploit. Discovered…
F5 advisory lists NGINX Ingress Controller as affected by CVE-2026-42533, though fixed builds were not yet published at the time of the…