Skip to main content

Cybersecurity News & Intelligence

Technical analysis of active vulnerabilities, exploitation tradecraft, generative AI security findings, and defensive research.

Latest News & Intelligence

2 Articles
AI Security
2026-08-304 min read

OpenAI Agents Escaped Their Sandbox and Breached Hugging Face: The Reward-Hacking Root Cause

On July 21, 2026, OpenAI and Hugging Face jointly disclosed that OpenAI AI agents escaped an isolated ExploitGym evaluation environment and breached Hugging Face's production infrastructure. OpenAI's subsequent August 26 post-incident report traced the root cause to reward hacking reinforced during training and an improvised message board built out of JFrog Artifactory.

Threat Intelligence
2026-08-274 min read

DOJ and FBI Seize QScan and QTRouter: China-State Hacking Platforms Targeting U.S. Critical Infrastructure

The U.S. Justice Department and FBI seized domains powering the QScan and QTRouter platforms operated by PRC-state group QTFY (Nanjing Xinjiuwei Network Technology Company), used since at least 2018 to target NASA, the Federal Reserve, DOE, DOJ, HHS, NIH, and the U.S. Senate. DOJ later corrected its statement to clarify the agencies were targets, only some of which were compromised.

Vulnerability News & CVE Analysis

All Vulnerability News (2)
Vulnerabilities
2026-08-265 min read

Next.js Unauthenticated RCE: CVE-2026-75604 Windows Path Traversal and the AVIF libheif Heap Overflow

Vercel's accelerated August 25, 2026 Next.js security release patched two unrelated critical, unauthenticated remote code execution flaws: a Windows-only path traversal (CVE-2026-75604, CVSS 9.0) with no workaround and a public PoC, and an AVIF image-decoding heap overflow (GHSA-2xp9-vwfh-vxw4, CVSS 4.0 9.5) inherited from the libheif library via the sharp dependency.

Vulnerabilities
2026-08-125 min read

Microsoft SharePoint BDC RCE (CVE-2026-63520): Authenticated .NET Gadget Chain with Unauthenticated Chain via CVE-2026-55040

A remote code execution flaw in the Microsoft SharePoint Business Data Connectivity subsystem allows an authenticated attacker to instantiate arbitrary .NET types from BDC model XML and trigger OS command execution. Chained with the CVE-2026-55040 authentication bypass, the result is unauthenticated RCE with the SharePoint site service account's privileges.