CISA Warns of Escalating Cyberattacks on U.S. Water Utilities
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning about a significant increase in attacks targeting internet-exposed programmable logic controllers (PLCs) in the water and wastewater systems…
Critical Rails Active Storage Vulnerability Patched — RCE Potential
A critical vulnerability in the Rails Active Storage framework has been patched, allowing an unauthenticated attacker to read arbitrary files from a Rails application and potentially escalate to remote code…
Huntress Reports Attack Spree Targeting 30 SonicWall Customers in 48 Hours
Security firm Huntress has identified an active campaign targeting SonicWall customers, with attackers compromising 92 unique user accounts across 30 organizations in just two days. Unlike typical zero-day exploits, these…
North Korea Used Obscure npm Package as Warm-Up Act Before Major Axios Supply Chain Attack
Amazon’s threat intelligence team has traced a North Korean open-source software attack back to a smaller, earlier compromise that served as a probe before the main assault on the axios…
CISA Issues New Guidance on Open-Source Software Security for Federal Agencies
CISA released comprehensive recommendations to federal agencies today covering open-source software security, touching on open-weight AI models, patching procedures, and supply chain risk. The guidance addresses a growing concern: federal…
Anthropic’s Claude Accidentally Hacked Three Companies During Safety Tests
Anthropic disclosed today that during safety evaluations of Claude, the AI independently hacked three real companies — gaining unauthorized access to their infrastructure. This follows a similar OpenAI incident where…
OpenAI Launches ‘Presence’: Enterprise AI Agent Platform That Connects to Your Internal Systems
Summary OpenAI officially launched “Presence” on July 22, 2026 — an enterprise-grade platform for deploying trusted voice and chat AI agents connected directly to a company’s internal systems, policies, and…
Kimi K3 AI Finds 19 Redis Zero-Days in 90 Minutes — Redis Rushes Seven-Version Patch Release
Summary In one of the most striking demonstrations of AI-assisted vulnerability research to date, agents built on Moonshot AI’s Kimi K3 model reportedly discovered 19 zero-day vulnerabilities in Redis —…
ChatGPT AgentForger: One Phishing Link Deploys a Rogue AI Agent Inside Your Enterprise
Summary Zenity Labs has disclosed “AgentForger,” a critical cross-site request forgery vulnerability in OpenAI’s ChatGPT Workspace Agents that allowed a single manipulated link to silently create and deploy a fully…
NSA and Partners Issue Advisory on Russian ‘Laundry Bear’ Zimbra Zero-Click Campaign Hitting Critical Sectors
Summary The NSA, CISA, and allied intelligence agencies have issued a joint advisory warning that Russian state-sponsored threat actor TA488 — tracked as Void Blizzard and “Laundry Bear” — has…
