ShinyHunters Pivots to OAuth Token Abuse for Persistent Salesforce Access
Summary Microsoft issued a warning on July 14, 2026, that ShinyHunters — the prolific threat group behind multiple massive 2026 breaches — has pivoted from direct credential theft to OAuth…
OpenAI Launches GPT-Live: Full-Duplex Voice AI That Listens, Speaks, and Reasons Simultaneously
Summary OpenAI introduced GPT-Live on July 13, 2026 — a new generation of voice AI built on a full-duplex architecture that allows the model to listen, speak, and reason at…
Critical ServiceNow AI Platform Flaw Enables Unauthenticated Remote Code Execution
Summary A critical vulnerability in the ServiceNow AI Platform was disclosed on July 14, 2026, enabling unauthenticated remote code execution against affected instances. The flaw affects the AI Platform component,…
DHS Network Breach: FEMA Analysts Dismissed Intrusion Alerts Twice Before Backdoors Were Found
Summary The Department of Homeland Security suffered a significant network intrusion in which attackers gained access to the Homeland Security Information Network (HSIN), installed hidden backdoors, and exfiltrated credential data…
NSA, CISA, and 12 Nations Warn: FSB Center 16 Actively Exploiting Routers Against Critical Infrastructure
Summary The NSA, CISA, FBI, and 12 allied nations issued a sweeping joint advisory on July 13, 2026, warning that Russia’s Federal Security Service (FSB) Center 16 is actively exploiting…
Ghostcommit: A Novel Attack Exfiltrates Secrets via AI-Assisted Development Workflows
Summary On July 11, 2026, researchers disclosed Ghostcommit, a novel attack technique that exploits a blind spot in AI-assisted software development workflows. The attack exfiltrates sensitive .env file contents by…
OpenAI and Anthropic Both File Confidential IPO Paperwork — The AI Safety Lab Era Goes Public
The two most prominent AI safety labs are simultaneously preparing to go public. OpenAI confidentially filed a draft S-1 registration statement with the SEC on June 8, 2026, at a…
ShinyHunters Weekend Rampage: 25M Conduent Government Records and 275M Canvas Student Profiles Exposed
Two massive data breaches emerged over the weekend, collectively affecting tens of millions of people across healthcare, education, and government services. Conduent breach — 25 million+ records exposed: Conduent, the…
BioShocking and AutoJack: Prompt Injection and RCE Now Reality for AI Browser Attack Chains
Two major research disclosures this weekend reveal that AI-powered browsers have become a serious attack surface for prompt injection and remote code execution — and that operators don’t need to…
Google Search Officially Ends the Blue Link Era — Gemini 3.5 Flash Now Powers All Results
On July 10, 2026, Google officially ended the 25-year era of “ten blue links.” Search results across the platform have now been fully replaced with AI-generated summaries powered by Gemini…
