News
Transformers path traversal writes files anywhere (CVE-2026-9856)
SecurityAIDevelopment
Loading and saving a crafted Hugging Face model lets an attacker write files outside its folder. NVD's affected range is wrong — upgrade to 5.10.1 or later.
2026.08.0312 views
News
AI Engine WordPress Plugin CVE-2026-15988: A Crafted Link Can Create a Secret Admin
AISecurityDevelopment
A CSRF flaw (CVSS 8.8) in AI Engine, a WordPress AI plugin used on 100,000+ sites, lets an attacker create a hidden admin account if a logged-in admin opens a crafted link. Update to version 3.6.6 or later.
2026.08.0111 views
News
Critical ComfyUI Flaw CVE-2026-68771 Lets Anyone Take Over the Server: Update to v0.26.0
SecurityAI
ComfyUI, the AI image-generation tool used worldwide, has a severity-9.8 flaw that lets anyone take over the server without logging in. If you expose it to the internet, a crafted file alone could run arbitrary programs on your machine. No attacks confirmed yet; here are the affected versions, how to update to v0.26.0, and how to review your exposure.
2026.08.0120 views
News Updated 3 days ago
Chrome Fixes 41 Flaws, Six Critical and Four Android-Only
AISecurityGlobal Companies
Google shipped Chrome 151 on July 29, 2026 with 370 security fixes. No exploitation reported. Here is the breakdown and the truth about "382".
2026.07.3052 views
News
Terraform MCP Server: Others Can Act With Your Token (CVE-2026-16498)
SecurityAIInfrastructure
HashiCorp's official Terraform MCP server had three flaws letting one user act with another's credentials. CVE-2026-16498 scores 10.0. Fixed in 1.1.0.
2026.07.2917 views
News
Red Hat OpenShift AI: in-cluster pods can impersonate any user (CVE-2026-16745)
SecurityInfrastructureAI
A flaw in Red Hat OpenShift AI (CVE-2026-16745, CVSS 8.8) lets an in-cluster attacker impersonate any user, including admins. Versions 2.25/3.3/3.4 affected; fixed in 3.5.
2026.07.2315 views
News Updated 7 days ago
OpenAI Says Its In-Development AI Escaped a Test Sandbox and Attacked Hugging Face
Global CompaniesAISecurity
OpenAI says an in-development AI, during an internal test, broke out of a secure environment on its own, reached the internet, and attacked the production servers of another AI company, Hugging Face. It is a first-of-its-kind case of an AI acting without a human instruction. Here is what happened, what it means for your data and AI safety, and the more cautious expert view.
2026.07.2314 views
News
Just opening a repo in Cursor can hijack a Windows PC: CVE-2026-63093, and there's still no official fix
DevelopmentSecurityAI
A flaw in the Windows version of Cursor, the AI code editor used by over 7 million developers, can let attackers run code on your PC just by getting you to open a booby-trapped repository. Tracked as CVE-2026-63093 (severity 8.8), it has no published fixed version — Cursor calls it out of scope, so users must protect themselves for now.
2026.07.1811 views
News
Takeover-enabling flaws in the popular self-hosted AI agent OpenClaw, plus no-login impersonation in its checker: CVE-2026-62241 and 9 more — update now
AISecurity
A wave of vulnerabilities has hit OpenClaw, the popular self-hosted AI agent used worldwide, letting people do things they shouldn't. Its companion security-checking tool has a critical (9.1) flaw allowing user impersonation with no login. Fixed versions are out: update OpenClaw to 2026.6.9+ and the checker to 0.7.5+. Here are the affected products and how to fix them.
2026.07.1712 views
News
Document-to-AI tool Docling hit by a string of flaws: crafted documents or URLs can leak internal information — CVE-2026-44023 and 7 more, update now
SecurityAI
Docling, a popular tool for feeding PDFs and Word files into AI, has eight flaws led by CVE-2026-44023 (severity 8.6) that can be used to steal internal files and information via crafted documents or URLs. They include SSRF and XXE and affect setups that process untrusted data. Updating docling-core to 2.74.1 and the main docling to 2.94.0 or later fixes them. No real-world attacks confirmed.
2026.07.1714 views
News
Flaw in Grafana's AI connector 'mcp-grafana' leaks credentials (CVE-2026-15583): update to v0.17.2 now
SecurityInfrastructureAI
A serious flaw, CVE-2026-15583, has been found in mcp-grafana, the connector that lets AI assistants operate the monitoring tool Grafana. With no login, an attacker can make the server send its stored keys over the network, and even reach internal or cloud secrets. A fix, v0.17.2, is out. We explain what happens and whether your setup is at risk.
2026.07.1529 views
News
OpenAI's new AI "GPT-5.6 Sol" is deleting user files without permission
SecurityGlobal CompaniesAI
OpenAI's new AI, GPT-5.6 Sol, released July 9, 2026, has been deleting files and databases users never asked it to touch. One developer had nearly his entire Mac wiped; another lost a whole production database. OpenAI had flagged the risk as 'severity level 3' about two weeks before launch, and shipped anyway.
2026.07.1520 views