📡 Tech & Security Digest — 2026-07-30
Curated from Hacker News, security blogs, and tech publications.
Ars Technica
- We now have a better understanding how OpenAI hacked into Hugging Face — 10 days passed from OpenAI models exploiting JFrog Artifactory 0-day to release of a patch. …
- Anthropic is finding bugs faster than Microsoft can fix them — Microsoft is on a mad dash behind the scenes to patch exploits before hackers find them. …
BleepingComputer
- Russian hackers exploit Exchange OWA zero-day for long-term mailbox access — The Russian state-sponsored hacking group Laundry Bear, also known as Void Blizzard, is exploiting an Exchange Outlook Web Access vulnerability in ema…
- Cisco warns of FMC static credential flaw exploited in zero-day attacks — Cisco is warning that a high-severity Secure Firewall Management Center (FMC) static credential vulnerability, tracked as CVE-2026-20316, was actively…
- Hackers disrupt over 30 Minnesota water utilities in coordinated OT attack — The Minnesota IT Services (MNIT) agency activated its cybersecurity incident response capabilities across the entire state after hackers targeted more…
- OpenAI models used Artifactory zero-days to escape to the internet — JFrog has confirmed that OpenAI models exploited zero-day vulnerabilities in self-hosted Artifactory servers to help escape an isolated testing enviro…
- OpenAI agent used exposed credentials at 4 services in Hugging Face breach — In a new update, OpenAI says its AI models also used publicly exposed credentials to compromise accounts on four third-party services during the recen…
Hacker News
- Disrupting supply chain attacks on NPM and GitHub Actions (87 pts)
- Turning a dumb AC unit smart (without losing my security deposit) (158 pts)
- GPT-5.6 vs. Claude Fable 5 for Physical AI, which performs best? (95 pts)
Krebs on Security
- Microsoft Patches a Record 570 Security Flaws — Microsoft Corp. today released software updates to plug at least 570 security holes in its Windows operating systems and other software, almost triple…
- Felons, Fraudsters Flog Offensive Cybersecurity Startup — A cybersecurity startup dangling millions of dollars to acquire zero-day security vulnerabilities in popular software is run by a pair of far-right co…
- Who Runs the Ransomware Group ‘The Gentlemen?’ — A cybercrime group known as The Gentlemen has emerged as the second most active ransomware gang by victim count, rapidly attracting a talented pool of…
The Hacker News
- Russian Hackers Exploit Microsoft OWA Flaw to Keep Mailbox Access After Credential Rotation — The Russian threat actors recently linked to the exploitation of a now-patched vulnerability in Zimbra have been observed exploiting another vulnerabi…
- Public PoC Released for Exploited Check Point SmartConsole Authentication Bypass — Cybersecurity researchers have shared additional technical details about a recently patched critical security flaw impacting Check Point Security Mana…
- Attackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw — A maximum-severity security flaw impacting on-premises versions of Arista VeloCloud Orchestrator (VCO) has come under active exploitation in the wild….
- Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available — Security firms ThreatBook and Imperva say attackers are targeting a critical flaw in Fastjson, Alibaba’s JSON library for Java. In affected Spring Boo…
- Cisco FMC Zero-Day Actively Exploited, Static Credentials Could Expose Sensitive Data — The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a newly disclosed security flaw impacting Cisco Secure Firewall Ma…
- Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory — Cybersecurity researchers have flagged a maximum-severity security flaw in Ruflo, an open-source agent meta-harness for Anthropic Claude Code and Open…
- JFrog Confirms OpenAI Models Exploited Artifactory Zero-Day Before Hugging Face Breach — JFrog has confirmed that OpenAI models exploited a zero-day in self-hosted Artifactory while trying to reach the open internet from a sealed evaluatio…
- OpenAI Agent Used Exposed Credentials Across Four Services During Hugging Face Breach — OpenAI on Tuesday revealed the rogue artificial intelligence (AI) agent that escaped its sealed evaluation environment and broke into Hugging Face’s p…
- ChatGPT AgentForger Flaw Could Deploy Rogue Workspace Agents via a Phishing Link — Cybersecurity researchers have disclosed a critical vulnerability in OpenAI’s ChatGPT Workspace Agents that could have allowed a single phishing link …
- Mythos Asks the Right Question. It Doesn’t Answer It. — AI is compressing exploit timelines. The real question isn’t whether your vulnerability management playbook needs to change, it’s which part of it you…