Hermes
Wednesday 5 August 2026  ·  75 articles scored  ·  3 top scorers  ·  last 24h
1
🔐 security Microsoft Security Blog
75%

ChainDrop supply chain compromise: Anatomy of a self-propagating worm

A credential-stealing worm hidden in more than 400 compromised npm packages automatically spread across software ecosystems by republishing malicious updates. This analysis details the attack chain, …

Novelty
80%
Depth
75%
Practical
70%
Surprise
70%
Relevance
80%
https://www.microsoft.com/en-us/security/blog/2026/08/04/chaindrop-supply-chain-compromise-anatomy-self-propagating-worm/
2
🔐 security Schneier on Security
72%

The OpenAI Hack Shows the Genie Is Out of the Bottle

This essay originally appeared in Foreign Policy. Earlier this month, two of OpenAI’s models broke out of their containment sandbox and attacked another AI company. The story is kind of wild. OpenAI …

Novelty
80%
Depth
75%
Practical
50%
Surprise
80%
Relevance
85%
https://www.schneier.com/blog/archives/2026/08/the-openai-hack-shows-the-genie-is-out-of-the-bottle.html
3
🔐 security SecurityWeek
70%

Gemini Agent-to-Agent Attack Method Exposed Secrets, Enabled Pull Request Tampering

A crafted prompt to a low-privilege Google ADK agent could be used to pass a malicious hand-off comment to a privileged agent. The post Gemini Agent-to-Agent Attack Method Exposed Secrets, Enabled Pu…

Novelty
80%
Depth
60%
Practical
60%
Surprise
75%
Relevance
85%
https://www.securityweek.com/gemini-agent-to-agent-attack-exposed-secrets-enabled-pull-request-tampering/
4
🔐 security Schneier on Security
70%

More on the OpenAI Agent’s Attack on Hugging Face

Hugging Face has published a detailed timeline of the attack. From the summary: The agent was running an internal OpenAI cyber-capability evaluation based on the ExploitGym benchmark, which tasks an …

https://www.schneier.com/blog/archives/2026/08/more-on-the-openai-agents-attack-on-hugging-face.html
5
🤖 ai AI Alignment Forum
69%

Concrete Evaluations to Investigate the OpenAI Model That Hacked Hugging Face

[Tweet Thread] This post is written in our personal capacity. Three-Minute Executive Summary An OpenAI model/multi-agent system bypassed its sandbox and launched a cyberattack on Hugging Face in orde…

https://www.alignmentforum.org/posts/aCdhjy7Rps3BEhiSj/concrete-evaluations-to-investigate-the-openai-model-that
6
🤖 ai The Decoder
67%

IBM finds 92% of companies hit by AI security breaches lacked basic access controls

According to IBM, 92 percent of companies that experienced an AI security incident had inadequate access controls for their AI systems. The model itself was rarely the problem. The article IBM finds …

https://the-decoder.com/ibm-finds-92-of-companies-hit-by-ai-security-breaches-lacked-basic-access-controls/
7
🔐 security SecurityWeek
66%

Weaponized Email AI Assistants Could Help Attackers Hijack Accounts

Researchers demonstrate how attackers could abuse built-in email chatbots to evade detection, impersonate trusted employees, compromise executive accounts, and facilitate financial fraud. The post We…

https://www.securityweek.com/weaponized-email-ai-assistants-could-help-attackers-hijack-accounts/
8
🤖 ai The Decoder
66%

Two teams solved the same quantum crypto problem using GPT-5.6 just three hours apart

Two research teams independently solved the same open quantum cryptography problem using OpenAI's GPT-5.6 Sol Ultra, submitting their papers just three hours apart. "If someone mentions an open probl…

https://the-decoder.com/two-teams-solved-the-same-quantum-crypto-problem-using-gpt-5-6-just-three-hours-apart/
9
📦 m365 Petri IT Knowledgebase
65%

Stop Treating Entra Connect Like Middleware

Entra Connect is well known as the application responsible for synchronizing on-premises Active Directory (AD) identities to the Entra Cloud. This service is not only integral to an environment’s ope…

https://petri.com/stop-treating-entra-connect-like-middleware/
10
🔐 security SecurityWeek
64%

Rethinking AI Security: Why CASB and DLP Need an Interaction-Aware Layer

Build your strategy around answering these questions to ensure employees use AI productively while keeping sensitive data, IP, and agent behavior within the boundaries set for safe AI use. The post R…

https://www.securityweek.com/rethinking-ai-security-why-casb-and-dlp-need-an-interaction-aware-layer/
11
🤖 ai Import AI
63%

Import AI 467: Self-sustaining AI viruses; pacing AI progress; confusion about AI and creativity

Welcome to Import AI, a newsletter about AI research. Import AI runs on arXiv, cappuccinos, and feedback from readers. If you’d like to support this, please subscribe. Subscribe now Self-sustaining a…

https://jack-clark.net/2026/08/03/import-ai-467-self-sustaining-ai-viruses-pacing-ai-progress-confusion-about-ai-and-creativity/
12
📦 m365 Petri IT Knowledgebase
63%

Microsoft Sentinel Adds Detections-As-Code, Table Insights, and New Data Connectors

Microsoft’s July 2026 update for Sentinel introduces new capabilities to streamline detections-as-code workflows for commercial customers. The release also improves data lake visibility and expands d…

https://petri.com/microsoft-sentinel-detections-as-code-table-insights/
13
🔐 security Schneier on Security
62%

Some Claude Chats Are Searchable on Google

And it’s personal information (alternate link): The exposed data includes an AI-powered therapy app that someone appears to have vibe-coded, notes on meetings, and a dashboard someone made apparently…

https://www.schneier.com/blog/archives/2026/08/some-claude-chats-are-searchable-on-google.html
14
⚡ tech Stratechery
61%

Microsoft Earnings, Microsoft vs. Meta, The Efficiency Payoff

Microsoft's earnings were compelling because they showed a clarity of strategy, lower costs, and a tangibility of application. The reason why is scarier.

https://stratechery.com/2026/microsoft-earnings-microsoft-vs-meta-the-efficiency-payoff/
15
🔐 security Microsoft Security Blog
60%

Advance Zero Trust for AI: New tools and guidance to secure AI agents and DevSecOps

Microsoft expands its Zero Trust for AI strategy to enhance security for AI and DevSecOps environments with new tools and guidance. The post Advance Zero Trust for AI: New tools and guidance to secur…

https://www.microsoft.com/en-us/security/blog/2026/08/04/advance-zero-trust-for-ai-new-tools-and-guidance-to-secure-ai-agents-and-devsecops/