IncidentAI Workflow Hijacking at Noma Labs
Noma Labs has uncovered a significant security flaw they call workflow identity hijacking, where attackers can execute privileged actions in AI-driven workflows without proper authentication. This isn
Expert perspectives on application security, compliance, and emerging threats
IncidentNoma Labs has uncovered a significant security flaw they call workflow identity hijacking, where attackers can execute privileged actions in AI-driven workflows without proper authentication. This isn
IncidentBetween May 11 and 12, 2026, OpenAI agents submitted over 2,000 malicious packages to RubyGems. They exploited a design flaw in RubyDoc.info s documentation build process, achieving remote code execut
IncidentBetween August 15 and September 8, 2026, threat actors exploited self-hosted JFrog Artifactory instances. They used three vulnerabilities to bypass authentication, escalate privileges, and deploy a Ru
IncidentWhat Happened On September 4, attackers began exploiting CVE-2026-75650 , a CVSS 10.0 vulnerability in Adobe Commerce and Magento Open Source. The flaw, dubbed StyleSmuggler by Sansec, allows unauthen
Get weekly security insights and compliance updates delivered to your inbox.
IncidentOn September 4, attackers exploited a zero-day vulnerability in Magento and Adobe Commerce, deploying a Linux backdoor on a system running the latest security updates. The exploit, named StyleSmuggler
IncidentOn January 15, 2026, researchers disclosed CVE-2026-0768 , a critical remote code execution vulnerability in Langflow s component editor. By late August, exploitation attempts had spiked sharply. Atta
IncidentBetween July 14 and August 18, 2026, Wordfence blocked over 440,000 attempts to exploit two critical WordPress plugin vulnerabilities. More than 250,000 targeted CVE-2026-14894 in Super Forms, while a
IncidentWhat Happened Security researchers at SpecterOps have identified 39 methods attackers use to compromise passkey authentication systems. These methods don t break FIDO2 cryptographic protocols. Instead
IncidentWhat Happened On August 19, attackers began exploiting CVE-2026-32475 , a file upload validation vulnerability in Elementor Pro, a popular WordPress page builder plugin. This flaw allows remote code e
IncidentAI Uncovers Hidden Vulnerabilities OpenAI s Codex Security, an AI-powered code scanning tool, recently scanned over 1.2 million commits and identified 792 critical vulnerabilities, along with 10,561 h
IncidentWhat Happened Attackers are exploiting CVE-2026-0768, a critical vulnerability in Langflow, a low-code platform for building AI workflows. This platform allows teams to assemble LangChain components t
IncidentYour AI development framework just handed attackers root access and every API key in your environment variables. No authentication required. What Happened Attackers exploited CVE-2026-0768 in Langflow
IncidentWhat Happened McKinsey s internal AI platform exposed over 200 documented endpoints to the internet without authentication. External researchers found these APIs, which provided direct access to inter
IncidentWhat Happened On August 28, JFrog disclosed CVE-2026-82329, a critical authentication bypass vulnerability in Artifactory with a CVSS score of 9.8. This flaw allows attackers to gain administrative pr
IncidentWhen you clone a repository, you expect your AI coding assistant to help write code. You don t expect it to execute an attacker s commands without asking. That s exactly what happened with eight vulne
IncidentWhat Happened DryRun Security tested three AI coding agents, OpenAI Codex GPT 5.2, GitHub Copilot Workspace, and Replit Agent, on two application builds. The agents generated code for a task managemen