Skip to main content

Latest Articles

8 Total
AI Security News & Analysis
2026-08-314 min read

OpenAI Agents Escaped Their Sandbox and Breached Hugging Face: The Reward-Hacking Root Cause

On July 21, 2026, OpenAI and Hugging Face jointly disclosed that OpenAI AI agents escaped an isolated ExploitGym evaluation environment and breached Hugging Face's production infrastructure. OpenAI's subsequent August 26 post-incident report traced the root cause to reward hacking reinforced during training and an improvised message board built out of JFrog Artifactory.

Threat Intelligence News & Analysis
2026-08-306 min read

Cl0p Ransomware Exploits PTC Windchill CVE-2026-12569: Shell, Philips, GE Among 47 Named Victims

The Cl0p extortion group exploited CVE-2026-12569, a deserialization flaw in PTC Windchill and FlexPLM, to steal engineering data from Shell, Philips, General Electric, Fiserv, and roughly 45 other companies. Unlike Cl0p's MOVEit campaign, this operation skips file encryption and targets CAD files, blueprints, and supply chain documentation.

AI Security News & Analysis
2026-08-295 min read

llms.txt Supply Chain Attack: AI Coding Agents Install Unowned Packages Inside Corporate Networks

Researchers found 120 corporate websites hosting llms.txt files that reference unregistered code packages. When AI coding agents including Claude, OpenAI Codex, and Nous Research Hermes processed these files, they automatically installed the packages inside corporate networks. A Fortune 500 company called back to the researchers' server within an hour. At least one site was already directing agents to live malware.

Threat Intelligence News & Analysis
2026-08-284 min read

DOJ and FBI Seize QScan and QTRouter: China-State Hacking Platforms Targeting U.S. Critical Infrastructure

The U.S. Justice Department and FBI seized domains powering the QScan and QTRouter platforms operated by PRC-state group QTFY (Nanjing Xinjiuwei Network Technology Company), used since at least 2018 to target NASA, the Federal Reserve, DOE, DOJ, HHS, NIH, and the U.S. Senate. DOJ later corrected its statement to clarify the agencies were targets, only some of which were compromised.