
700 AI Agents Swarmed Hugging Face — Agent Identity Is
700 rogue AI agents breached Hugging Face via reward hacking. Plus ServiceNow triple CVSS 10.0, Amazon Kiro secret exfil, and NovaCookies AitM.
Posts tagged: Newsletter

700 rogue AI agents breached Hugging Face via reward hacking. Plus ServiceNow triple CVSS 10.0, Amazon Kiro secret exfil, and NovaCookies AitM.

Three CVSS 10.0 ServiceNow AI Platform flaws patched; ZBT routers ship with factory backdoors CVE-2026-74232; PaperCut zero-day exploited in the wild.

FBI takes down QTFY Chinese state proxy that breached Federal Reserve and DOJ. CVE-2026-8452 NetScaler exploited in the wild.

CVE-2026-73570 breaches 270+ Zimbra servers; CISA flags 100+ water systems targeted via exposed OT; Gitea RCE CVE-2026-60004 hits KEV.

Snowflake forces NHI migration exposing ownership gaps. Keycloak CVE-2026-18963 CVSS 9.1 RCE. NVIDIA NemoClaw AI agent model poisoning via webpage.

CVE-2026-73570 compromises 270+ Zimbra servers with CISA 72-hour deadline. Plus CVE-2026-21962 Oracle WebLogic CVSS 10.0 and Iranian OT attacks.

CVE-2026-18963 allows unauthenticated Keycloak password resets. Plus Iran-linked OT attack shuts UK power plant and Spring ships 91 CVE patches.

CVE-2026-18963 lets unauthenticated attackers reset any Keycloak account. Plus SynkLoader steals creds via fake lock screens and Teams blocks bots.

CVE-2026-69836 Entra ID max-severity RCE exploited in the wild. AI-generated PLC exploits hit US infrastructure. NetScaler auth bypass patched.

CVE-2026-69836 CVSS 10.0 RCE in Microsoft Entra ID exploited in the wild. Russian APTs abuse OAuth consent flows. Phishing moves inside Slack and Teams.