Hermes
Thursday 23 July 2026  ·  35 articles scored  ·  2 top scorers  ·  last 24h
1
🤖 ai The Decoder
77%

OpenAI claims responsibility for the Hugging Face hack after its own models escaped a test sandbox

During an internal security evaluation, OpenAI models, including GPT-5.6 Sol, escaped their sandbox, independently discovered a zero-day vulnerability, and breached Hugging Face's production infrastr…

Novelty
92%
Depth
70%
Practical
50%
Surprise
95%
Relevance
95%
https://the-decoder.com/openai-claims-responsibility-for-the-hugging-face-hack-after-its-own-models-escaped-a-test-sandbox/
2
⚡ tech Stratechery
72%

OpenAI Hacks Hugging Face, What Happened, Alignment and Paper Clips

OpenAI accidentally hacked Hugging Face, but the takeaways are more encouraging than people realize.

Novelty
85%
Depth
65%
Practical
45%
Surprise
90%
Relevance
90%
https://stratechery.com/2026/openai-hacks-hugging-face-what-happened-alignment-and-paper-clips/
3
🔐 security SecurityWeek
69%

Fourth SharePoint Vulnerability Exploited in Past Month’s Wave of Attacks

CVE-2026-50522 is being exploited by threat actors to steal machine keys and retain long-term access. The post Fourth SharePoint Vulnerability Exploited in Past Month’s Wave of Attacks appeared first…

https://www.securityweek.com/fourth-sharepoint-vulnerability-exploited-in-past-months-wave-of-attacks/
4
🤖 ai The Decoder
67%

Every frontier AI model tested by Britain's safety institute tried to cheat on cybersecurity evaluations

The UK's AI Safety Institute tested five frontier models from OpenAI and Anthropic in cybersecurity evaluations. All five tried to cheat. One even ran code on an external service to access the instit…

https://the-decoder.com/every-frontier-ai-model-tested-by-britains-safety-institute-tried-to-cheat-on-cybersecurity-evaluations/
5
🤖 ai AI Alignment Forum
66%

Are we existentially threatened by the type of AI misalignment seen in the OpenAI Hugging Face attack?

OpenAI models recently broke through a series of security boundaries and into Hugging Face servers in order to cheat on a cyber eval. A lot of people thought it was scary because it was a clear examp…

https://www.alignmentforum.org/posts/H6DDSEvrtCk8Sehfd/are-we-existentially-threatened-by-the-type-of-ai
6
📦 m365 Petri IT Knowledgebase
64%

Cisco Launches Antares AI Models for Vulnerability Detection in Large Codebases

Cisco has announced a new family of small language models (SLMs) called Antares. These new AI models are designed specifically to help security teams identify known vulnerabilities within large codeb…

https://petri.com/cisco-antares-ai-models-vulnerability-detection/
7
🤖 ai The Decoder
64%

Cisco bets its small open cybersecurity models can outperform GPT-5.5 at vulnerability detection for a fraction of the cost

Cisco has released two small, open-source AI models for cybersecurity that detect about 150 times more vulnerabilities per dollar than large AI agents, according to the company's own tests. The artic…

https://the-decoder.com/cisco-bets-its-small-open-cybersecurity-models-can-outperform-gpt-5-5-at-vulnerability-detection-for-a-fraction-of-the-cost/
8
🔐 security SecurityWeek
61%

Vibe-Coded Apps Riddled With Exploitable Security Flaws

Analysis found 434 exploitable flaws in AI-generated apps, with denial-of-service, authorization and secrets exposure risks among the most common issues. The post Vibe-Coded Apps Riddled With Exploit…

https://www.securityweek.com/vibe-coded-apps-riddled-with-exploitable-security-flaws/
9
🔐 security SecurityWeek
56%

When Identity Verification Fails: Lessons from a Real-World SIM Swap and Near Account Takeover

Identity confidence changes throughout every interaction and should be reassessed continuously as new risk signals emerge. The post When Identity Verification Fails: Lessons from a Real-World SIM Swa…

https://www.securityweek.com/when-identity-verification-fails-lessons-from-a-real-world-sim-swap-and-near-account-takeover/
10
🤖 ai The Decoder
55%

Anthropic's $1.5B piracy settlement with book authors is a record loss that hands AI labs their biggest legal win

Anthropic has to pay $1.5 billion to book authors, the largest copyright settlement in class action history. But the payout is for downloading roughly 482,460 works from piracy databases, not for AI …

https://the-decoder.com/anthropics-1-5b-piracy-settlement-with-book-authors-is-a-record-loss-that-hands-ai-labs-their-biggest-legal-win/
11
🔐 security SecurityWeek
53%

Flaw in Adobe Extension With 300M Installs Enabled WhatsApp Data Theft

An attacker only needed to convince the targeted user to visit a malicious website to exfiltrate WhatsApp messages and contacts. The post Flaw in Adobe Extension With 300M Installs Enabled WhatsApp D…

https://www.securityweek.com/flaw-in-adobe-extension-with-300m-installs-enabled-whatsapp-data-theft/
12
🔐 security SecurityWeek
52%

US Warns of Iranian Hackers Targeting Siemens, Schneider, and Rockwell ICS Devices

An updated advisory from federal agencies provides information on the techniques used to hack programmable logic controllers. The post US Warns of Iranian Hackers Targeting Siemens, Schneider, and Ro…

https://www.securityweek.com/us-warns-of-iranian-hackers-targeting-siemens-schneider-and-rockwell-ics-devices/
13
🔐 security Microsoft Security Blog
47%

Real world incident response: Microsoft and AXA XL strengthen cyber resilience

Our collaboration with AXA XL brings Microsoft Incident Response services directly to cyber insurance policyholders, helping organizations coordinate technical, business, and insurance decisions. The…

https://www.microsoft.com/en-us/security/blog/2026/07/22/real-world-incident-response-microsoft-and-axa-xl-strengthen-cyber-resilience/
14
⚡ tech The Verge
46%

iOS code could reportedly let Apple cut off apps when users miss iPhone payments

Code found in an iOS 27 beta would allow Apple to put a financed iPhone in "Restricted Mode" if it detects any missed payments, 9to5Mac reports. The finding follows a story from Bloomberg earlier thi…

https://www.theverge.com/tech/969596/apple-restricted-mode-ios-27
15
🔐 security Schneier on Security
45%

First-Person Identity Theft Story

Harrowing story of an identity theft victim. Yes, the person made a mistake—they gave the scammer a two-factor authentication code that allowed the scammer to take over their email address. But the r…

https://www.schneier.com/blog/archives/2026/07/first-person-identity-theft-story.html