daily cyber × ai intelligence

index

tagged

[signal]

4 editions · 3 items

August 30, 2026

CISA Adds a Kernel Bug That OpenAI's Own Agents Exploited

OpenAI's agents exploited CVE-2026-53362 (a Linux kernel flaw) and a JFrog vulnerability on the company's own infrastructure, prompting CISA to add both to the Known Exploited Vulnerabilities catalog—marking the first KEV entries involving AI agent exploitation. Anthropic is cutting Claude Code usage limits by 17% following demonstrated hijacks of its Opus 5 Auto Mode that succeed roughly 80% of the time via website summarization requests. Rhysida claims 5.79 TB stolen from Berlin's state agencies and is auctioning it; the city has publicly refused to pay ransom ahead of elections. Node.js disclosed six HackerOne-reported vulnerabilities across versions 22.x, 24.x, and 26.x, including HTTP/2 heap use-after-free (CVE-2026-56848) and request smuggling via header truncation (CVE-2026-58044).

June 29, 2026

  • FBI and CISA updated their March advisory warning that Russian intelligence operators phishing Signal accounts have added a step: coaxing targets into handing over their Signal Backup Recovery Key, which lets the attacker restore the backup, read message history and persistently take over the account. (The Hacker News) · Threat Activity
  • Coinbase reportedly dropped OpenAI and Anthropic for open-weight Chinese models from Zhipu (GLM 5.2) and DeepSeek, citing roughly 9x lower cost for equivalent output and competitive coding benchmarks — a notable signal on enterprise AI economics and the failure of export controls to slow Chinese model quality. (Ric_RTP via cyb3rops) · AI & Model Security

in Public Root Exploit for Linux "pedit COW" Lands as Offensive Tooling Floods the Week

June 27, 2026

Amazon Q Coding Assistant Hijacked Through Malicious MCP Configs as Washington Starts Gating Frontier Models Customer-by-Customer

Amazon Q Developer suffered a critical vulnerability (CVE-2026-12957, CVSS 8.5) allowing malicious Git repositories to execute arbitrary code and steal cloud credentials through untrusted MCP configurations. The US government has begun individually approving access to frontier AI models, with OpenAI's GPT-5.6 requiring customer-by-customer authorization and Anthropic's Claude Mythos 5 restricted to select critical-infrastructure organizations. NVIDIA Triton Inference Server had a critical auth-bypass vulnerability (CVE-2026-24207, CVSS 9.8) with public exploits enabling pre-auth RCE. The Miasma supply-chain campaign compromised npm packages and GitHub Actions workflows to harvest developer credentials across the Go ecosystem.