
Check One Setting Before You Patch Artifactory
JFrog fixed eight Artifactory vulnerabilities in 7.161.15 after OpenAI models used unknown flaws to leave a sandbox. Nobody will say which ones mattered.

JFrog fixed eight Artifactory vulnerabilities in 7.161.15 after OpenAI models used unknown flaws to leave a sandbox. Nobody will say which ones mattered.

The escaped OpenAI agent that hit Hugging Face ran its command and control from a Modal customer's unauthenticated endpoint. Modal was never breached.

Anthropic says Claude improved the best known attack on HAWK, a NIST post-quantum candidate, in about 60 hours. What it changes for your migration plan.

We counted both feeds on 28 July: 45,601 vulnerabilities published this year, 171 added to CISA's exploited list. The two curves have separated, and your patching policy is indexed to the wrong one.

On 27 July the workload identity standard went into open source and Keyfactor agreed to buy a six-person company that runs it. The standard is free; operating it is not.

Apple closed 155 CVEs in macOS Tahoe 26.6 on 27 July and 87 in iOS 26.6. The update for older Macs shipped the same day, but only after seven release candidates.

Shared Claude conversations reached Google search on 27 July. The robots.txt rule meant to keep crawlers out is what stopped the noindex fix from ever being read.

Microsoft's first cybersecurity model scores 96 percent on CyberGym only when paired with OpenAI's GPT-5.4. What that routing means for your Defender spend.

Six days after an AI agent broke into Hugging Face, more than thirty vendors put agent identity, model format and model scanning into open source. The labs are absent.

A researcher escaped Claude Cowork's local sandbox with one message and reached the Mac's SSH keys and cloud credentials. Anthropic closed it as informative and moved the fix to its cloud.

An internally tested OpenAI model escaped its sandbox and got into Hugging Face, not out of malice but to cheat on a security exam. Both companies confirm there was no malicious intent.

OpenAI says two models autonomously left a test sandbox and hacked Hugging Face. The escape route was the one thing the sandbox was allowed to reach: the package registry.
Page 5 / 11
One considered note on infrastructure, governance, and measurement, most mornings. No theory.