A years-old Linux kernel flaw allowing local privilege escalation to root has been disclosed after AI-assisted research uncovered a race condition in net/sched. In new research published July 27, Lee Jia Jie of Singapore offensive security firm STAR Labs said… Read More "AI-Assisted Bug Hunt Uncovers Linux Kernel 0-Day in net/sched"
Bugs in Hugging Face Diffusers Bypass Custom Code Safeguard
Three high-severity flaws in vulnerable versions of Hugging Face’s diffusers library let crafted model repositories silently execute arbitrary code during affected loading flows, bypassing the safeguard built to prevent exactly that. According to research from threat exposure management firm Zafran Security… Read More "Bugs in Hugging Face Diffusers Bypass Custom Code Safeguard"
Only Half of UK Manufacturers Have a Cyber Incident Response Plan
Almost a third of UK manufacturers (30%) experienced a cyber incident over the past year, either directly or through their supply chain. Despite this, the sector’s cyber resilience maturity remains far from optimal, according to a new report by Make… Read More "Only Half of UK Manufacturers Have a Cyber Incident Response Plan"
OpenAI Pauses Some Development of Astra Model on Security Concerns
OpenAI has said it is temporarily halting some internal testing of a forthcoming model after assessing its cyber capabilities as “critical.” The AI firm said in a blog post on August 7 that testing of Astra had revealed “significant advancements… Read More "OpenAI Pauses Some Development of Astra Model on Security Concerns"
A maximum severity GitLab flaw could turn your CI/CD server into an attacker’s treasure trove
Beyond patching, the watchTowr Intel team said defenders should try to identify exploitation attempts by hunting through log files for HTTP POST requests to “/api/v4/projects/{id}/repository/commits/” URIs containing “file.path” parameters. CI/CD platforms are critical trust infrastructure Organizations running affected self-managed GitLab… Read More "A maximum severity GitLab flaw could turn your CI/CD server into an attacker’s treasure trove"
Logistics Giant Ceva Suffers Data Breach Impacting European Clients
A data breach at one of the world’s biggest logistics companies appears to have had a significant impact on its wider supply chain ecosystem of customers. Ceva Logistics is a subsidiary of the French CMA CGM Group, which is the world’s… Read More "Logistics Giant Ceva Suffers Data Breach Impacting European Clients"
OpenAI Launches Two-Tier Access Program Alongside GPT 5.6 Cyber
OpenAI is launching GPT‑5.6‑Cyber, its newest large langue model (LLM) purpose-trained for cybersecurity tasks, based on its latest frontier AI model, GPT‑5.6 Sol. The AI company also tweaked its Daybreak program to introduce two new tiers, Daybreak Blue – for… Read More "OpenAI Launches Two-Tier Access Program Alongside GPT 5.6 Cyber"
Suisan City, California, Responds to Cyber Incident Amid Wave of US Lo
Suisan City in California is continuing to grapple with an ongoing cyber-incident, amid a spate of cyber-attacks targeting local authorities in the US. The City government declared a state of emergency after its IT network was infected by “malicious software”… Read More "Suisan City, California, Responds to Cyber Incident Amid Wave of US Lo"
Cursor Security Bug Allowed Repositories to Execute Commands Pre Trust
A flaw in Cursor’s command-line coding agent has been found to allow a cloned repository to run any command it chose on a developer’s machine before they were asked whether they trusted it, and outside the sandbox even when the… Read More "Cursor Security Bug Allowed Repositories to Execute Commands Pre Trust"
Six npm Packages Read C2 Addresses From Ethereum Wallet
Six npm packages have been found querying an attacker-controlled Ethereum wallet to work out where to fetch their next stage of malware, reading command-and-control (C2) addresses out of a blockchain transaction. Sonatype Research Labs identified the packages on August 10… Read More "Six npm Packages Read C2 Addresses From Ethereum Wallet"