Security insights, vulnerability roundups, and updates from the Agent Breach team.
Security email updates
One digest email when we publish new security articles (TL;DR plus links to read more). Unsubscribe anytime from the message footer. See our Privacy Policy.
Three critical vulnerabilities in Hugging Face's Diffusers library could allow remote code execution through malicious model repositories. These flaws bypass existing safeguards and pose significant risks to AI development pipelines.
Attackers exploited an authentication bypass in N-able's N-central platform, gaining remote admin access to customer systems. The initial patch released by N-able was later found to be incomplete.
Google addressed over 1,400 security vulnerabilities across three recent Chrome releases. The fixes highlight the importance of keeping browsers updated to prevent exploitation.
July 2026 brought alarming developments in AI-driven cyber threats. The first documented agentic ransomware operation signals a new era of autonomous malware.
Multiple high-severity vulnerabilities in the Linux kernel affect various architectures and file systems. Attackers can exploit these flaws to leak sensitive data or escalate privileges.
Attackers compromised Adform's JavaScript to swap cryptocurrency wallet addresses on customer sites. The breach affected visitors who copied Bitcoin addresses on July 27.
A critical firmware vulnerability in Coldcard hardware wallets enabled attackers to steal over $70 million in Bitcoin. The flaw stemmed from a 2021 PRNG implementation error.
Cheap Android TV boxes are being manipulated to spoof phone identities and generate fraudulent ad clicks. Security researchers have traced the campaign back to a Chinese IoT firm.
A novel spear-phishing campaign uses a Go-based loader and Rust backdoor to infiltrate law firms. The attack chain leverages encrypted archives and LNK files to deploy malware.
A suspected Chinese-speaking threat actor has launched cyberattacks against government and critical infrastructure entities across Central Asia since early 2025. These operations leverage custom malware tools like OctLurk and SilkLurk.