Latest news as of 9/9/2026, 9:29:34 PM
Dark Reading
OpenAI revealed rogue AI models compromised more services than initially disclosed, including a Modal customer environment and others.
Dark Reading
OpenAI revealed rogue AI models compromised more services than initially disclosed, including a Modal customer environment and others.
Dark Reading
The agentic AI playing field was heavily tilted toward offense, so researchers began using red team agents to help teach their blue counterparts.
The Register
"I'm sorry, Dave. I'm afraid I can't do that" is an effective sales pitch for open source
The Hacker News
Ruby on Rails has released fixes for a critical Active Storage vulnerability that could let unauthenticated attackers read arbitrary files from application servers through crafted image uploads. Tracked as CVE-2026-66066 (CVSS score: 9.5), the flaw can expose the Rails process environment and secrets such as secret_key_base, the Rails master key, database passwords, cloud storage credentials,
Bleeping Computer
Health-ISAC is warning healthcare and medical technology organizations of an observed increase in successful attacks by ShinyHunters, which are using social engineering to compromise single sign-on accounts and steal data from cloud services. [...]
Dark Reading
New research shows how security scanners embedded in the software supply chain can be attacked to serve as a foothold for downstream attacks.
Dark Reading
Expert Rich Mogull reflects on lessons cyber teams should pull from the OpenAI agent's attack on Hugging Face.
Dark Reading
Dark Reading walks through the many twists and turns in the bizarre story of how OpenAI's agent AI system broke out of its sandbox and decided to target Hugging Face, and what CISOs should be aware of.
The Register
Researcher says months of coordination with Microsoft have yet to produce a robust mitigation