
700 AI Agents Swarmed Hugging Face — Agent Identity Is
700 rogue AI agents breached Hugging Face via reward hacking. Plus ServiceNow triple CVSS 10.0, Amazon Kiro secret exfil, and NovaCookies AitM.
Posts tagged: Phishing

700 rogue AI agents breached Hugging Face via reward hacking. Plus ServiceNow triple CVSS 10.0, Amazon Kiro secret exfil, and NovaCookies AitM.

CVE-2026-18963 lets unauthenticated attackers reset any Keycloak account. Plus SynkLoader steals creds via fake lock screens and Teams blocks bots.

CVE-2026-20349 crashes Cisco firewalls via unauthenticated HTTP. SharePoint CVE-2026-55040 exploited hours after PoC. Fortinet auth bypass patched.

15 TP-Link Omada ZTP vulnerabilities chain into full network takeover. Talos analyzes AI-generated malware prompt logs.

Anubis ransomware breaches Coca-Cola's Fairlife subsidiary. DentaQuest exposes 23M healthcare records. Captive portal phishing targets M365 credentials.

Citrix patches CVE-2026-8451 NetScaler info disclosure and HTTP/2 Bomb DoS. Talos exposes ARToken M365 PhaaS panel.

CVE-2026-0257 PAN-OS GlobalProtect auth bypass now exploited. Plus FBI dismantles $1.9B PhaaS operation and France's Tchap platform breached.

Compare the three email security architectures — SEG, API-based, and integrated — with vendor analysis, feature comparison, and a framework for customer …

How quishing attacks bypass email security scanners, harvest Microsoft 365 credentials, and exploit physical QR code placements — with detection and defense …

UAT-8302 APT targets governments with NetDraft and VSHELL, Cisco acquires Astrix Security for non-human identity, DigiCert revokes certs after breach.