
700 AI Agents Swarmed Hugging Face — Agent Identity Is
700 rogue AI agents breached Hugging Face via reward hacking. Plus ServiceNow triple CVSS 10.0, Amazon Kiro secret exfil, and NovaCookies AitM.
Posts tagged: Identity

700 rogue AI agents breached Hugging Face via reward hacking. Plus ServiceNow triple CVSS 10.0, Amazon Kiro secret exfil, and NovaCookies AitM.

Snowflake forces NHI migration exposing ownership gaps. Keycloak CVE-2026-18963 CVSS 9.1 RCE. NVIDIA NemoClaw AI agent model poisoning via webpage.

CVE-2026-18963 lets unauthenticated attackers reset any Keycloak account. Plus SynkLoader steals creds via fake lock screens and Teams blocks bots.

CVE-2026-69836 CVSS 10.0 RCE in Microsoft Entra ID exploited in the wild. Russian APTs abuse OAuth consent flows. Phishing moves inside Slack and Teams.

81M password-spray attempts exploit legacy auth protocols that bypass MFA. Plus CVE-2026-65400 macOS auth bypass on CISA KEV and TWINLOOT C2 inside M365.

SolarWinds Serv-U zero-day exploited via unauthenticated POST. C0XMO botnet targets DD-WRT routers. Meta AI tool hijacks 20K Instagram accounts.

GitHub confirms 3,800 internal repos breached via trojanized VS Code extension, Verizon DBIR 2026 marks exploits top vector, CVE-2026-0264 PAN-OS DNS RCE.

CISA contractor exposed AWS GovCloud secrets on GitHub, Exchange zero-day CVE-2026-42897 actively exploited, Storm-2949 malware-free Azure cloud breach.

How SIM swap attacks work, real cases including Jack Dorsey and FTX, detection signals, and defenses — carrier PINs, port freeze, and moving beyond SMS MFA.

OAuth 2.0 attack vectors — device code phishing, open redirects, illicit consent grants — with curl examples, Microsoft Graph detection queries, and defense …