Anthropic Discloses Fourth AI Hacking Incident Involving Claude Opus 4.6
Anthropic disclosed a fourth incident in which its AI model broke into real third-party systems, involving an early version of Claude Opus 4.6.
Breaches, defenses, and the quiet infrastructure risks that do not make headlines until they do.
Anthropic disclosed a fourth incident in which its AI model broke into real third-party systems, involving an early version of Claude Opus 4.6.
Check Point has patched two critical vulnerabilities in the way its firewall and management products handle VPN certificates.
CISA added three actively exploited flaws affecting Cisco, Citrix, and Fortinet to its KEV catalog, requiring FCEB agencies to patch by September 12, 2026.
The Gigabud banking trojan now installs a second Android app that creates a work profile on an infected phone and drops a tampered banking app inside it.
Nearly one in ten internet-facing LiteLLM servers scanned by Wiz Research in February accepted sk-1234, the example admin key from LiteLLM's own setup guide.
A suspected Russian-speaking cyber actor used AI agents to exploit two PaperCut NG/MF flaws, compromising 440+ instances across 395 organizations.
Alby has warned of a critical flaw in Alby Hub that could let an attacker take over a wallet and send its funds.
Google patched 230 security vulnerabilities Tuesday, including CVE-2026-87491, a V8 out-of-bounds write under active exploitation.
A flaw in DeepSeek Harness let a sandboxed agent turn off its own sandbox with a single command, tracked as CVE-2026-82533.
Multiple espionage-motivated threat clusters have been found deploying a previously undocumented exploit kit called BlueMoon.
Cybercriminals are hijacking AI user accounts via infostealer logs to create "stolen keys" that bypass MFA on major AI platforms.
cPanel has patched a flaw that lets a single hosting account take control of an entire server via an SQL injection issue in EmailTrack.
U.S. cybersecurity and intelligence agencies have accused China-based AI companies of conducting "systematic extraction" of proprietary functionalities from A
The U.S. Department of Justice announced coordinated actions against illicit online marketplace Xinbi Guarantee, seizing Telegram channels and freezing $52.8 mi