Cursor, Codex, Gemini CLI, Antigravity hit by sandbox escapes
Researchers escaped the sandboxes in Cursor, Codex, Gemini CLI and Antigravity by having the AI agent write files that trusted host tools later run. Multiple CVEs, patches, and Google downgrading two Antigravity findings.
In November 2025, AI music generation tool Suno suffered a data breach that later came to light in July the following year. The data contained over 55M unique email addresses. Phone numbers were also present where they had been used as the sign-up method. Although representing a small portion of the corpus, the breach also included tens of thousands of Stripe records relating to purchases, containing names, physical addresses, purchase amounts and partial credit card data including the card type, expiry date and last 4 digits. The company advised that "Suno does not have access to customers' full credit card numbers in Stripe".
x64dbg usage log: start debugging and modify a program
Explore the comprehensive guide by fairycn on how to master x64dbg on Windows 11, from installation to advanced debugging techniques, ensuring effective program modifications and insightful CPU disassembly analysis.
This Windows Box is incredibly intriguing, featuring challenging passages and an unstable machine. Despite these difficulties, it’s an enjoyable experience with numerous exploits available.
Telegram is the richest open source intel surface online. Here is how to work it in 2026, from forwarding chains to sock puppets, without getting burned.
New HollowGraph malware uses Microsoft Graph for stealthy C2 comms
A malicious component dubbed HollowGraph uses the calendar feature in compromised Microsoft 365 mailboxes as a command-and-control channel to receive attacker commands and exfiltrate stolen data.
Hackers are exploiting recently patched WordPress bugs, putting millions of websites at risk
Two critical security flaws in WordPress’ software have given hackers the chance to remotely take over tens of millions of websites, according to an estimate by a cybersecurity researcher.
Attacco ad Hugging Face: gli Agent AI diventano parte attiva della catena offensiva, come proteggersi
La scorsa settimana un agente di AI autonomo ha violato parte dell'infrastruttura di produzione di Hugging Face. L’azienda di AI open source ha rilevato l’intrusione, contenendola e riscontrando accessi non autorizzati ad alcuni set di dati interni e credenziali di servizio. Ecco perché gli Agent AI amplificano la superficie di attacco
Il phishing cambia le regole? Il NIST ridisegna la governance delle identità digitali
La revisione delle linee guida NIST SP 800-63-4 segna un cambio di paradigma nella gestione delle identità digitali. Autenticazione resistente al phishing, verifica continua del rischio e Zero Trust ridisegnano un modello destinato a influenzare anche la NIS2 e il mercato europeo
Choosing an AI SOC platform requires understanding how it will perform in your own environment, not just during an evaluation. Prophet Security shares a practical framework for assessing AI SOC solutions, including how to validate accuracy, operating models, long-term reliability, and production readiness.
Hugging Face discloses breach linked to autonomous AI agent
The Hugging Face artificial intelligence repository disclosed that attackers gained access to internal datasets and credentials after breaching its production infrastructure using an autonomous AI agent system.
Risks, Vulnerabilities And Response: Threat Intelligence is Quietly Becoming The Connected Layer in Security
Cyberthreat Intelligence is not a feed bolted on the side, it is the operational impetus behind strengthened security. And that change in role has earned the market its first dedicated industry evaluation.
Microsoft confirms Windows Server Update Services sync delays
Microsoft is working to fix a known issue affecting Windows Server Update Services (WSUS) servers, which has caused synchronization problems for more than a week.
Videosorveglianza e diritto di accesso: il caso Lidl ridefinisce la gestione delle richieste GDPR
Il provvedimento con cui il Garante Privacy ha sanzionato Lidl mostra come moduli, canali interni e procedure non possano ostacolare l'esercizio dei diritti previsti dal GDPR. Un caso che offre indicazioni operative su organizzazione, videosorveglianza e gestione delle richieste di accesso
Windows KB5121767 OOB update fixes shutdowns on some Dell PCs
Microsoft has released emergency updates to fix a known issue causing some Dell PCs to shut down after installing the July 2026 Windows 11 security updates.