Hermes
Wednesday 22 July 2026  ·  71 articles scored  ·  5 top scorers  ·  last 24h
1
🔐 security SANS Internet Stormcast
77%

WordPress Exploitation Underway (CVE-2026-63030), (Mon, Jul 20th)

Last week, Searchlight Cyber released details about a vulnerability they are calling "wp2shell". The vulnerability was initially announced without a CVE number. But now has been assigned CVE-2026-630…

Novelty
80%
Depth
65%
Practical
85%
Surprise
75%
Relevance
85%
https://isc.sans.edu/diary/rss/33168
2
🤖 ai The Decoder
76%

Hugging Face says an AI agent hacked its infrastructure, and it used AI to fight back

Hugging Face reports an attack on parts of its production infrastructure that was allegedly carried out entirely by an autonomous AI agent system. The attack spanned thousands of actions controlled b…

Novelty
88%
Depth
65%
Practical
60%
Surprise
90%
Relevance
92%
https://the-decoder.com/hugging-face-says-an-ai-agent-hacked-its-infrastructure-and-it-used-ai-to-fight-back/
3
⚡ tech The Verge
73%

OpenAI says it accidentally hacked Hugging Face with a new AI system

OpenAI CEO Sam Altman. | Bloomberg via Getty Images OpenAI says its AI models mistakenly breached open-source AI platform Hugging Face during internal testing. In a blog post on Tuesday, OpenAI write…

Novelty
90%
Depth
60%
Practical
50%
Surprise
95%
Relevance
85%
https://www.theverge.com/ai-artificial-intelligence/968988/openai-hugging-face-hack-ai
4
🔐 security SecurityWeek
72%

New HollowGraph Malware Abuses Microsoft 365 Calendar for C&C Communication

Part of a larger toolkit, HollowGraph uses a compromised 365 account’s calendar as a two-way dead-drop. The post New HollowGraph Malware Abuses Microsoft 365 Calendar for C&C Communication appeared f…

Novelty
80%
Depth
50%
Practical
70%
Surprise
80%
Relevance
90%
https://www.securityweek.com/new-hollowgraph-malware-abuses-microsoft-365-calendar-for-cc-communication/
5
🔐 security SecurityWeek
70%

Hugging Face Hacked in Autonomous AI Attack

Targeting production infrastructure, the attack compromised internal datasets and service credentials. The post Hugging Face Hacked in Autonomous AI Attack appeared first on SecurityWeek.

Novelty
85%
Depth
50%
Practical
55%
Surprise
90%
Relevance
90%
https://www.securityweek.com/hugging-face-hacked-in-autonomous-ai-attack/
6
🔐 security SecurityWeek
65%

SonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before Patch

The zero-days CVE-2026-15409 and CVE-2026-15410 were exploited by a threat actor tracked by Volexity as UTA0533. The post SonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before Patc…

https://www.securityweek.com/sonicwall-zero-days-exploited-to-deliver-custom-malware-for-weeks-before-patch/
7
📦 m365 Petri IT Knowledgebase
65%

Why Hybrid Identity Becomes Technical Debt and How to Move to Cloud-Only

Moving from a hybrid IT environment to a fully cloud-based architecture is a transformative journey for many organizations. This shift, driven by evolving business requirements and technological adva…

https://petri.com/why-hybrid-identity-becomes-technical-debt/
8
📦 m365 Petri IT Knowledgebase
64%

9 Best Microsoft Entra ID Management Tools for Enterprise Identity and Governance

Microsoft Entra ID is now the identity control plane for many organizations, but managing Entra ID well is no longer just about creating users, assigning groups, or enabling multifactor authenticatio…

https://petri.com/best-microsoft-entra-id-management-tools/
9
🔐 security SecurityWeek
64%

Capital One Open Sources AI-Powered ‘VulnHunter’ Security Tool

The agentic security tool identifies potentially exploitable code flaws, traces attack paths, and recommends targeted remediations. The post Capital One Open Sources AI-Powered ‘VulnHunter’ Security …

https://www.securityweek.com/capital-one-open-sources-ai-powered-vulnhunter-security-tool/
10
🤖 ai The Decoder
62%

An AI system helped Pakistani judges clear massive backlogs at $38.50 return per dollar invested

A field experiment with 1,559 Pakistani judges found that the AI assistant JudgeGPT boosted case resolution by 6.3 percent. The catch: only judges who got hands-on training saw gains. Without it, the…

https://the-decoder.com/an-ai-system-helped-pakistani-judges-clear-massive-backlogs-at-38-50-return-per-dollar-invested/
11
🤖 ai The Decoder
61%

Google's "Frozen v2" chip reportedly bakes Gemini's architecture directly into silicon for efficiency gains

Google is developing "Frozen v2," a server chip that bakes the Gemini architecture directly into hardware. According to internal sources, it could be 6 to 10 times more efficient than current TPUs. S…

https://the-decoder.com/googles-frozen-v2-chip-reportedly-bakes-geminis-architecture-directly-into-silicon-for-efficiency-gains/
12
🤖 ai AI Alignment Forum
61%

Towards surfacing model algorithms with meta-tokens in the J-Space

TL;DR We used J-lens on Qwen3.6-27B to find “meta-tokens”: tokens that surface non-obvious computation in the model. When the model reads ambiguous text, 什么意思 ("what does this mean") fires in the J-s…

https://www.alignmentforum.org/posts/6ek6n7yZ5DzfarJHy/towards-surfacing-model-algorithms-with-meta-tokens-in-the-j
13
🤖 ai The Decoder
60%

Nvidia's grip on AI chips weakens as Microsoft turns to AMD and Anthropic may follow

Microsoft is expanding Azure's AI infrastructure with AMD's new Helios platform, which is set to challenge Nvidia's GPU systems in the second half of 2026. A public GitHub profile suggests Anthropic …

https://the-decoder.com/nvidias-grip-on-ai-chips-weakens-as-microsoft-turns-to-amd-and-anthropic-may-follow/
14
🤖 ai The Decoder
58%

Claude Cowork learns new skills through screen recordings and voice-over explanations

Anthropic's Claude Cowork desktop app now lets users record their screen while completing a task, add voice commentary, and have Claude turn the whole thing into a reusable skill. The article Claude …

https://the-decoder.com/claude-cowork-learns-new-skills-through-screen-recordings-and-voice-over-explanations/
15
🔐 security SecurityWeek
57%

OpenSSL Silently Fixes ‘HollowByte’ DoS Vulnerability

Attackers could send waves of malicious payloads to trigger buffer pre-allocations that are not freed, exhausting server memory. The post OpenSSL Silently Fixes ‘HollowByte’ DoS Vulnerability appeare…

https://www.securityweek.com/openssl-silently-fixes-hollowbyte-dos-vulnerability/