Artificial Intelligence (AI)
Three Hugging Face Diffusers CVEs Bypass Custom-Code Safeguard
From safeguard to bypass — the diffusers CVEs land this week, and any machine that loads an untrusted model repository is the exposed surface.
Artificial Intelligence (AI)
From safeguard to bypass — the diffusers CVEs land this week, and any machine that loads an untrusted model repository is the exposed surface.
Nation-State Cyber Threats
New backdoor, familiar actor — the Iran-linked group tracked as Nimbus Manticore has a fresh toolset, and Kaspersky's write-up of NightLedger lands this week.
Vulnerabilities
Twenty-four thousand hash leaks underneath the OS — the BMC exposure map lands this week, and the fix is not a patch but a posture change.
Artificial Intelligence (AI)
Ten days after Hugging Face — the second autonomous-agent cyber event lands this week.
Vulnerabilities
From advisory to active ransomware — the PTC Windchill flaw is on the wire this week, and reporting now ties the exploitation to a Cl0p-style extortion campaign.
Data Breaches
From May intrusion to July disclosure — one of 2026's largest healthcare breaches lands this week.
Data Breaches
Confirmed at the parent, claimed by Anubis — Fairlife lands on the leak wire this week.
Vulnerabilities
From advisory to public proof-of-concept — the critical AD CS "Certighost" domain-takeover flaw (CVE-2026-54121) goes public this week, with the fix already shipped in Microsoft's July 2026 update.
Vulnerabilities
Patch first, patch fast — a public vBulletin exploit lands this week.
Artificial Intelligence (AI)
From incident to alliance in ten days — the AI-defender industry reorganizes this week.
Vulnerabilities
The EDR update that broke the EDR — Microsoft Defender for Endpoint for Linux misfires this week, disabling protection on some hosts and stalling on hardened RHEL.
Vulnerabilities
From CVE fix to fresh bypass: roughly five months after patching CVE-2026-27577, n8n has closed the same class of expression-sandbox escape again — this time reportedly with no CVE of its own, only a security advisory.