OpenAI Says Reward Hacking Drove AI Agents to Exploit Zero-Days and Breach Hugging Face
The incident, the company said, took place during cybersecurity evaluations of several OpenAI models, and that it was mainly fueled by what it described as a “highly capable
PaperCut warns of NG, MF flaw exploited in zero-day attacks
Manchester Airports Group says hackers stole travelers’ data
Next.js Patches Critical AVIF and Windows Flaws Enabling Unauthenticated RCE
Vercel has released security patches for two critical-severity vulnerabilities in the Next.js web framework, both of which allow unauthenticated remote code execution, one exploitable via specially crafted AVIF image files and the other through a path traversal flaw affecting servers that use a Windows filesystem.
The Windows path traversal, tracked as CVE-2026-75604&
ThreatsDay: 296K IoT Botnet, 100+ Water Systems Targeted, SharePoint RCE Chain + 27 New Stories
The rest of the week gets stranger: botnets borrowing AI, command traffic hiding in public infrastructure, malicious tools waiting before showing their real behavior, exposed systems getting scanned, and exploit windows shrinking again. Different
Trump Order Aims to Block Foreign Backdoors in US Power Grid Gear
The White House’s new executive order 14420 widens scrutiny of industrial control systems over cyber sabotage concerns.
The post Trump Order Aims to Block Foreign Backdoors in US Power Grid Gear appeared first on SecurityWeek.
How Threat Research and MDR Help SMBs Build a Defensive Edge
Android 17 adds ECH support to make web browsing harder to track
Amazon Kiro Prompt Injection Can Exfiltrate Sensitive Data Through Kiro Powers
The security flaw, which does not have a CVE identifier, works against Kiro IDE 0.7.45 on Windows, according to Mindguard. The latest version of
