Hermes
Friday 24 July 2026  ·  67 articles scored  ·  5 top scorers  ·  last 24h
1
🤖 ai The Decoder
77%

OpenAI claims responsibility for the Hugging Face hack after its own models escaped a test sandbox

During an internal security evaluation, OpenAI models, including GPT-5.6 Sol, escaped their sandbox, independently discovered a zero-day vulnerability, and breached Hugging Face's production infrastr…

Novelty
92%
Depth
70%
Practical
50%
Surprise
95%
Relevance
95%
https://the-decoder.com/openai-claims-responsibility-for-the-hugging-face-hack-after-its-own-models-escaped-a-test-sandbox/
2
📦 m365 Petri IT Knowledgebase
73%

Researchers Discover HOLLOWGRAPH Malware Abusing Microsoft 365, Graph API

Group-IB researchers have discovered HOLLOWGRAPH, a sophisticated malware linked with high confidence to the Cavern cyber-espionage framework. The malware abuses legitimate Microsoft 365 services to …

Novelty
75%
Depth
65%
Practical
70%
Surprise
70%
Relevance
90%
https://petri.com/hollowgraph-malware-microsoft-365-graph-api/
3
🔐 security SANS Internet Stormcast
72%

When the "Autonomous Attacker" Is Your Own AI Model, (Thu, Jul 23rd)

Two disclosures, five days apart, described the same intrusion from opposite ends — one from the victim, one from the party that turned out to be responsible — and together they make one of the m…

Novelty
80%
Depth
65%
Practical
60%
Surprise
80%
Relevance
85%
https://isc.sans.edu/diary/rss/33180
4
⚡ tech Stratechery
72%

OpenAI Hacks Hugging Face, What Happened, Alignment and Paper Clips

OpenAI accidentally hacked Hugging Face, but the takeaways are more encouraging than people realize.

Novelty
85%
Depth
65%
Practical
45%
Surprise
90%
Relevance
90%
https://stratechery.com/2026/openai-hacks-hugging-face-what-happened-alignment-and-paper-clips/
5
🔐 security Microsoft Security Blog
71%

Email threat landscape: Q2 2026 trends and insights

In the second quarter of 2026, the continuing effects of Microsoft’s disruption of the Tycoon2FA phishing platform contributed to sustained declines in several major phishing techniques, while threat…

Novelty
70%
Depth
70%
Practical
75%
Surprise
50%
Relevance
90%
https://www.microsoft.com/en-us/security/blog/2026/07/23/email-threat-landscape-q2-2026-trends-and-insights/
6
🤖 ai The Decoder
70%

One tampered ChatGPT link could spawn a rogue AI agent that took orders from an attacker every five minutes

Zenity Labs uncovered "AgentForger," a vulnerability in OpenAI's Agent Builder that let a single manipulated ChatGPT link create an autonomous agent on an employee's behalf. The agent inherited the v…

https://the-decoder.com/one-tampered-chatgpt-link-could-spawn-a-rogue-ai-agent-that-took-orders-from-an-attacker-every-five-minutes/
7
🔐 security SecurityWeek
69%

Fourth SharePoint Vulnerability Exploited in Past Month’s Wave of Attacks

CVE-2026-50522 is being exploited by threat actors to steal machine keys and retain long-term access. The post Fourth SharePoint Vulnerability Exploited in Past Month’s Wave of Attacks appeared first…

https://www.securityweek.com/fourth-sharepoint-vulnerability-exploited-in-past-months-wave-of-attacks/
8
🤖 ai The Decoder
67%

Every frontier AI model tested by Britain's safety institute tried to cheat on cybersecurity evaluations

The UK's AI Safety Institute tested five frontier models from OpenAI and Anthropic in cybersecurity evaluations. All five tried to cheat. One even ran code on an external service to access the instit…

https://the-decoder.com/every-frontier-ai-model-tested-by-britains-safety-institute-tried-to-cheat-on-cybersecurity-evaluations/
9
🔐 security SecurityWeek
67%

OpenAI Fixes ChatGPT Agent Flaw That Could Let Attackers Forge an AI Insider

AgentForger allows an attacker to create, insert and remotely control an invisible autonomous AI agent inside a victim organization. The post OpenAI Fixes ChatGPT Agent Flaw That Could Let Attackers …

https://www.securityweek.com/openai-fixes-chatgpt-agent-flaw-that-could-let-attackers-forge-an-ai-insider/
10
🔐 security SecurityWeek
66%

Is Patching Dead? Vulnerability Management in the Post-Mythos Era

You cannot out-patch a machine that writes a working exploit from a vulnerability description in twenty hours. Stop trying to optimize a game you cannot win. The post Is Patching Dead? Vulnerability …

https://www.securityweek.com/is-patching-dead-vulnerability-management-in-the-post-mythos-era/
11
🤖 ai AI Alignment Forum
66%

Are we existentially threatened by the type of AI misalignment seen in the OpenAI Hugging Face attack?

OpenAI models recently broke through a series of security boundaries and into Hugging Face servers in order to cheat on a cyber eval. A lot of people thought it was scary because it was a clear examp…

https://www.alignmentforum.org/posts/H6DDSEvrtCk8Sehfd/are-we-existentially-threatened-by-the-type-of-ai
12
📦 m365 Petri IT Knowledgebase
64%

Cisco Launches Antares AI Models for Vulnerability Detection in Large Codebases

Cisco has announced a new family of small language models (SLMs) called Antares. These new AI models are designed specifically to help security teams identify known vulnerabilities within large codeb…

https://petri.com/cisco-antares-ai-models-vulnerability-detection/
13
🤖 ai The Decoder
64%

Cisco bets its small open cybersecurity models can outperform GPT-5.5 at vulnerability detection for a fraction of the cost

Cisco has released two small, open-source AI models for cybersecurity that detect about 150 times more vulnerabilities per dollar than large AI agents, according to the company's own tests. The artic…

https://the-decoder.com/cisco-bets-its-small-open-cybersecurity-models-can-outperform-gpt-5-5-at-vulnerability-detection-for-a-fraction-of-the-cost/
14
🔐 security SecurityWeek
61%

Vibe-Coded Apps Riddled With Exploitable Security Flaws

Analysis found 434 exploitable flaws in AI-generated apps, with denial-of-service, authorization and secrets exposure risks among the most common issues. The post Vibe-Coded Apps Riddled With Exploit…

https://www.securityweek.com/vibe-coded-apps-riddled-with-exploitable-security-flaws/
15
🔐 security SecurityWeek
61%

Nuclear-Sabotage Malware Benchmark Trips Up Most Frontier AI Models

SentinelOne’s new benchmark, built on the Fast16 case, shows which AI models can sustain a malware investigation and which cannot. The post Nuclear-Sabotage Malware Benchmark Trips Up Most Frontier A…

https://www.securityweek.com/nuclear-sabotage-malware-benchmark-trips-up-most-frontier-ai-models/