📡 Tech & Security Digest — 2026-07-29
Curated from Hacker News, security blogs, and tech publications.
Ars Technica
- We now have a better understanding how OpenAI hacked into Hugging Face — 10 days passed from OpenAI models exploiting JFrog Artifactory 0-day to release of a patch. …
BleepingComputer
- Arista patches VeloCloud Orchestrator zero-day exploited in attacks — Arista has patched a maximum-severity command injection vulnerability in on-premises VeloCloud Orchestrator deployments that is being actively exploit…
- Hackers target US firms in FastJson RCE zero-day attacks — Hackers are actively exploiting a vulnerability in the FastJson open-source Java library, allowing remote code execution without user interaction or e…
- OpenAI models used Artifactory zero-days to escape to the internet — JFrog has confirmed that OpenAI models exploited zero-day vulnerabilities in self-hosted Artifactory servers to help escape an isolated testing enviro…
- New Certighost PoC exploit lets attackers hijack Windows domains — A proof-of-concept exploit for “Certighost,” a Windows Active Directory Certificate Services vulnerability, has been released that can allow authentic…
- Coca-Cola confirms data theft in Fairlife ransomware attack — The Coca-Cola Company has confirmed that hackers stole data from its dairy subsidiary, Fairlife, during a ransomware attack earlier this month. […]…
Hacker News
- Google’s Beyond Zero: Enterprise Security for the AI Era (149 pts)
- Codex Security (485 pts)
- About the security content of macOS Tahoe 26.6 (203 pts)
Krebs on Security
- Microsoft Patches a Record 570 Security Flaws — Microsoft Corp. today released software updates to plug at least 570 security holes in its Windows operating systems and other software, almost triple…
- Felons, Fraudsters Flog Offensive Cybersecurity Startup — A cybersecurity startup dangling millions of dollars to acquire zero-day security vulnerabilities in popular software is run by a pair of far-right co…
- Who Runs the Ransomware Group ‘The Gentlemen?’ — A cybercrime group known as The Gentlemen has emerged as the second most active ransomware gang by victim count, rapidly attracting a talented pool of…
The Hacker News
- Attackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw — A maximum-severity security flaw impacting on-premises versions of Arista VeloCloud Orchestrator (VCO) has come under active exploitation in the wild….
- Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available — Security firms ThreatBook and Imperva say attackers are targeting a critical flaw in Fastjson, Alibaba’s JSON library for Java. In affected Spring Boo…
- Check Point Patches Exploited SmartConsole Flaw Allowing Full Admin Access — Check Point has released security updates to address multiple vulnerabilities impacting Security Management and Multi-Domain Management (MDSM) product…
- JFrog Confirms OpenAI Models Exploited Artifactory Zero-Day Before Hugging Face Breach — JFrog has confirmed that OpenAI models exploited a zero-day in self-hosted Artifactory while trying to reach the open internet from a sealed evaluatio…
- ChatGPT AgentForger Flaw Could Deploy Rogue Workspace Agents via a Phishing Link — Cybersecurity researchers have disclosed a critical vulnerability in OpenAI’s ChatGPT Workspace Agents that could have allowed a single phishing link …
- NodeBB Patches Eight AI-Found Flaws Exposing Admin Access and Private Chats — Eight security flaws in NodeBB went public on Wednesday, along with the code to exploit them. Aikido Security rates all eight as high severity and say…
- Critical TeamCity Flaw Could Let Attackers Run OS Commands Without Logging In — JetBrains is urging customers of on-premise versions of TeamCity to update to the latest version following the discovery of a critical security issue …
- Kimi K3 Agents Found Redis Zero-Days and Built RCE Exploit, Researchers Say — Redis shipped seven security releases on July 23 after researchers published authenticated RCE PoCs for stock Redis 6.2.22, 7.4.9, 8.6.4, and 8.8.0.
…
- Ubuntu snap-confine Flaw Could Give Local Users Root on Default Desktop Installs — Cybersecurity researchers have disclosed details of a new local privilege escalation (LPE) vulnerability in snap-confine that an unprivileged user can…
- n8n Sandbox Escape Lets Workflow Editors Run OS Commands as the n8n Process — n8n has patched a high-severity expression-sandbox escape that could let an authenticated workflow editor execute operating-system commands on the ser…