News

Claude Cowork Sandbox Escape Lets AI Agent Break Out of Linux VM and Access Files Across macOS
Security researchers have disclosed SharedRoot, a sandbox escape affecting Anthropic's Claude Cowork that allows AI agents to break out of a Linux VM

RefluXFS (CVE-2026-64600): Linux Kernel XFS Flaw Lets Local Users Gain Root by Overwriting Protected Files
Learn how the RefluXFS Linux kernel vulnerability (CVE-2026-64600) exploits an XFS copy-on-write race condition to gain root privileges

Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC
Learn how attackers are exploiting the critical Microsoft SharePoint RCE vulnerability CVE-2026-50522 after a public PoC release

OpenAI’s AI Accidentally Hacked Hugging Face During Cybersecurity Testing: A Turning Point for Autonomous Offensive AI
OpenAI confirmed that GPT-5.6 Sol escaped a research sandbox during ExploitGym evaluation, exploited a zero-day, gained Internet access and compromised Hugging Face infrastructure

Hackers Exploit Palo Alto PAN-OS Flaw to Deploy Qilin Ransomware in Active Intrusions
Threat actors are actively exploiting the Palo Alto PAN-OS GlobalProtect authentication bypass vulnerability (CVE-2026-0257) to gain unauthorized access

15-Year-Old NGINX Vulnerability Lets Attackers Crash Workers and May Enable Remote Code Execution
NGINX has long been regarded as one of the most reliable and high-performance web servers on the Internet, powering millions … Read more

Hugging Face’s AI-Driven Security Incident Is a Wake-Up Call for Every Organization Building AI Infrastructure
Hugging Face disclosed an AI-driven security incident involving dataset processing vulnerabilities, credential theft, and autonomous AI agents

OpenSSL ‘HollowByte’ Flaw Enables Memory Exhaustion DoS with Just 11 Bytes of TLS Data
Learn how the OpenSSL HollowByte vulnerability lets attackers exhaust server memory using just 11-byte TLS requests with a technical analysis

Critical WordPress Core Flaw “wp2shell” Enables No-Auth Remote Code Execution on Default Installs
A critical WordPress core vulnerability dubbed wp2shell allows unauthenticated remote code execution on default installs. Update to 7.0.2 for patch

EY Discloses Data Breach After Third-Party Support Platform Exposes Client Tax Information
EY confirms a data breach after attackers compromised a third-party support platform, exposing sensitive tax client information. Here's what happened





