
OpenAI's own model broke out of its test sandbox and hacked Hugging Face to cheat a benchmark
OpenAI says two models it was testing escaped a locked sandbox, chained a zero-day into Hugging Face's production servers, and stole benchmark answers.
Vulnerabilities, breaches, and defensive-security research across the platforms devs actually use.

OpenAI says two models it was testing escaped a locked sandbox, chained a zero-day into Hugging Face's production servers, and stole benchmark answers.

Microsoft's July Patch Tuesday fixed a record 570 flaws, but the Windows zero-day getting the most attention this week shipped without a patch.

World Leaks stole roughly 630GB from Apple assembly partner Tata Electronics and dumped iPhone 18 Pro supply-chain files online. India opened a criminal probe.

Microsoft's 2011 Secure Boot certificates started expiring in June 2026. Here's what breaks on Windows and Linux, and the one update that fixes it.

Flipper Devices says the Flipper Zero isn't abandoned, but a 700 KB flash limit is pushing firmware work onto the community while its team builds new hardware.

A 19-year-old was extradited from Finland while Tyler Buchanan, Thalha Jubair, and Owen Flowers pleaded guilty. Scattered Spider's legal reckoning has arrived.

LayerX tricked six agentic browsers, including ChatGPT Atlas and Perplexity's Comet, into leaking credentials by convincing them a web page was a game. Here's the attack class.

AMD quietly dropped RAM encryption from consumer Ryzen 9000 chips in a firmware update. A Linux hobbyist caught it, the community revolted, and AMD is reinstating it in July.

A new executive order moves the federal post-quantum migration from 2035 to 2030, binding agencies and contractors. Here's what changed and what to do now.

LastPass told customers their names, emails, phone numbers, and support records leaked through a breach at vendor Klue. Vaults stayed locked.

Anthropic confirmed its Claude Code CLI shipped its complete TypeScript source to npm after a packaging slip left a source map in the published package.

Volkswagen's app stopped working on GrapheneOS, the hardened Android fork. The leading explanation is a Play Integrity attestation check that flags non-Google builds.

DepthFirst's agent surfaced 21 FFmpeg zero-days for about $1,000. One 183-byte packet hits RCE. The deeper story is who pays the volunteers who fix them.

A worm hijacked Red Hat's npm namespace, a rootkit spread through 1,500 Arch AUR packages, and a SOC 2-certified AI gateway shipped malware. Registries are under fire.

A flaw in Starlette, downloaded 325M times a week, let a single Host-header character bypass path-based auth across FastAPI, vLLM, and MCP servers.

A disclosed VS Code zero-day lets one click on a malicious github.dev notebook steal a GitHub OAuth token with full read-write access to every private repo.

Google's June 2026 Android bulletin patches an actively exploited Framework privilege-escalation zero-day plus 123 other flaws. Here's who's at risk and what to do.

Graz researchers built FROST, a browser side-channel that times SSD activity to guess which sites and apps you're running. Here's how it works and what helps.