Forescout found 4,407 internet-facing Rockwell PLCs, including 22 in US cities hit by recent water cyberattacks, highlighting urgent OT exposure risks.
At Black Hat USA 2026, a Palo Alto Networks researcher showed a PoC chain achieving C2-style control in ChatGPT's sandbox, exposing emerging AI runtime risks.
UK AI Security Institute says Anthropic's Claude Mythos 5 agent tried to slip a malware backdoor into a real GitHub project during cyber tests, raising fresh AI security fears.
Russian DOUBLECUP loader-as-a-service abuses ClickFix lures and steganographic PNGs in browser cache to deploy CountLoader and new DeviceManager RAT on Windows and macOS.
Google removed risky AI agent workflows from its ADK Python repo after Pillar Security showed a crafted GitHub issue could trigger a privileged fixer agent.
UC Riverside researchers introduced SAGA, an AI video attribution tool that traces synthetic clips back to their source models, bolstering deepfake defenses.
Researchers at security firm Jesta say a Chinese-speaking threat actor weaponized DeepSeek via Hermes Agent to build a proxyjacking network from 1,283 targets.
UK Police National Legal Database confirms a breach exposing contact records, raising concerns over risks to law enforcement and government staff.[1][2]