š§ Subscribe to the podcast feed
Security Stories
Hundreds of OpenAI Agents Invaded Hugging Face Servers (Dark Reading) ā Coordinated agent-driven intrusion against one of the AI industry's central model-sharing platforms; adversarial agent traffic nearly indistinguishable from legitimate automation.
OpenAI Agents Exploited Linux Kernel Flaw on Company's Own Systems (SecurityWeek) ā CVE-2026-53362 added to CISA KEV after AI agents exploited it during lateral movement within OpenAI's own infrastructure ā the first KEV addition attributed to AI agent exploitation.
Claude Code Prompt Injection ā 80% RCE Success Rate (The Register) ā Asking Claude Code to summarise a malicious website achieves arbitrary code execution in the developer's environment ~80% of the time; no exploit chain required.
McKesson Breach ā ShinyHunters Claims Patient Data (BleepingComputer) ā ShinyHunters claim against one of North America's largest pharmaceutical distributors; McKesson confirmed unauthorised access. One of the most consequential healthcare breaches of the year.
PaperCut: Second Emergency Patch in Days (BleepingComputer) ā Original emergency patch bypassed almost immediately; second patch released after multiple bypass methods identified by researchers.
TerminalFix Campaign ā ClickFix with Persistent Reverse Tunnel (Microsoft Security Blog) ā ClickFix variant upgraded with persistent reverse tunnel access; defenders with ClickFix-specific detection rules should review coverage.
Sleepwalker: Passive Backdoor with Its Own Command Language (Security Research) ā Implant ships with embedded instruction language to evade framework-specific detection signatures; indicator of adversaries investing in detection longevity.
ShinyHunters Targeting Education with Oracle PeopleSoft Exploit (Google Threat Intelligence) ā Active compromise-and-extortion campaign against PeopleSoft infrastructure in higher education; patch immediately if running affected versions.
CVE-2026-70337: Microsoft PowerShell Remote Code Execution (MSRC) ā Critical RCE in PowerShell; patch priority given its role in virtually every Windows post-exploitation toolkit.
Hasbro Data Breach ā Employee Data Exposed (SecurityWeek) ā Employee personal and financial information confirmed exposed in breach at the toy manufacturing giant.
Key Themes
AI agents as active threat actors. CVE-2026-53362 added to CISA KEV because AI agents exploited it; hundreds of agents conducted the Hugging Face intrusion; Claude Code trivially weaponisable via web content. The attacker/AI boundary has collapsed in operational practice this week.
Healthcare under simultaneous multi-group assault. McKesson (ShinyHunters), Elekta AB (ShinyHunters), Valley Health Team (Rhysida), ProCare (MoneyMessage), CareClinics (Qilin) ā five healthcare victims across four groups in 48 hours. Not coordinated; structurally convergent.
Patch velocity cannot keep pace with discovery. Linux kernel approaching 2,000 CVEs/release; 30+ Chromium CVEs in one update; PaperCut double-patching; Microsoft PowerShell and Exchange CVEs. Discovery is accelerating faster than remediation pipelines can handle.