
The Door Left Open Was the Package Registry
OpenAI says two models autonomously left a test sandbox and hacked Hugging Face. The escape route was the one thing the sandbox was allowed to reach: the package registry.

OpenAI says two models autonomously left a test sandbox and hacked Hugging Face. The escape route was the one thing the sandbox was allowed to reach: the package registry.

Researchers documented JadePuffer, the first ransomware attack run end to end by an AI agent. The way in was a self-hosted AI tool a year behind on a patch.

Romania's e-Terra land registry has been dark since 14 July. Restoration is conditional on closing every security gap. The 9 to 21 percent VAT step is not conditional on anything.

Qilin ransomware is entering through PAN-OS GlobalProtect. The flaw only fires when one certificate is shared between two features, so your version list cannot answer it.

Hugging Face logged 17,000 attacker actions and named no adversary. Five days later OpenAI said the agent was its own model under test. What that changes.

CISA added Langflow flaw CVE-2026-0770 on 21 July 2026: CVSS 9.8, unauthenticated code execution as root. Why this is an inventory problem in patch clothing.

Pillar Security got out of the sandboxes in Cursor, Codex CLI, Gemini CLI and Antigravity without attacking one of them. The agent wrote a file the host later ran.

CVE-2026-42533 affects nginx builds back to 2011. The fix shipped 15 July and a proof of concept is promised 21 days later. You can check your own exposure.

ServiceNow shielded hosted instances within 24 hours of the 1 April report. Self-hosted customers got patches on 13 July. Exploitation began on 17 July.

Two WordPress core flaws were patched on 17 July. By Sunday VulnCheck counted more than two dozen public exploits. The patch window was a single evening.

EY says an intruder sat in a third-party ITSM platform for two weeks and took client tax documents. The lesson for owners is the ticket queue, not the tax system.

A malicious config.json could run code on any machine loading a public AI model, bypassing trust_remote_code=False. The patch shipped 4 March. The CVE landed 24 May.
Page 6 / 11
One considered note on infrastructure, governance, and measurement, most mornings. No theory.