All tracked items across vulnerabilities, news, research, incidents, and regulatory updates.
A vulnerability called 'Cordyceps' exploits weaknesses in CI/CD workflows (automated systems that test and deploy code changes) to inject malicious pull requests (code change proposals) into popular developer tools like Azure Sentinel, Google's AI Agent Development Kit, Apache Doris, Cloudflare Workers SDK, and Python's Black. Attackers can use this method to compromise the software supply chain, potentially affecting many developers who use these tools.
Daytona is a platform that runs code generated by AI safely and efficiently. Before version 0.185.0, it had a cross-tenant authorization flaw (a security problem where access controls between separate organizations failed), which let any logged-in user listen to another organization's real-time notifications and see their events without permission.
Daytona, a tool for running AI-generated code safely, had a security flaw before version 0.185.0 where it didn't verify TLS certificates (the security credentials that prove a website is authentic) when cloning Git repositories (copying code from remote servers). This meant an attacker intercepting the connection could steal Git credentials (login information) and replace the real code with fake, harmful code.
Open WebUI, a self-hosted AI platform that runs offline, had a vulnerability before version 0.9.6 where authenticated users could bypass access controls by manipulating a url_idx parameter (a number used to select which backend server to use). This allowed them to reach Ollama backends (the AI model servers) they shouldn't have access to, including internal or admin-disabled ones, because the system only checked if they could use a model but not which backend server they were routed to.
Open WebUI, a self-hosted AI platform that runs offline, had a security flaw in versions before 0.9.6 where access controls (ACL, rules that restrict who can access what) could be bypassed when a database feature called Milvus multitenancy mode was enabled. An attacker could exploit this by using a specially crafted collection name that wasn't properly cleaned before being used in a database query, allowing them to access data they shouldn't be able to reach.
Gogs (a git hosting service) has a security flaw in its LFS (large file storage, a system for storing large files in git repositories) implementation where the deduplication shortcut skips hash verification, allowing any user with write access to one repository to claim ownership of LFS objects from private repositories they cannot access. An attacker can bind a file OID (object identifier, a unique hash) from a private repo to their own repo and download the private content through their own download endpoint.
Gogs (a Git service) has a bug where password-reset tokens use the account-activation lifetime instead of the configured reset-password lifetime. The token's expiration time is baked into the token itself when it's created, so changing the reset-password timeout setting has no effect, and attackers who intercept a reset token can use it far longer than administrators intended.
Gogs (a self-hosted Git service) has three API endpoints that incorrectly allow write-level collaborators to change admin-only repository settings. These endpoints use `reqRepoWriter()` middleware instead of `reqRepoAdmin()`, meaning users with basic write access can disable the issue tracker or wiki, inject malicious external URLs that redirect visitors, or trigger mirror sync operations. The web interface correctly requires admin access for these same operations, creating a security inconsistency.
Immunologist Derya Unutmaz used GPT-5 Pro in late 2025 to solve a three-year-old mystery about how glucose affects T cell development (immune cells that fight disease). His lab had run an experiment in 2022 showing that deoxyglucose (a glucose-like molecule that disrupts a cell's energy production) caused T cells to become inflammatory-response cells at much higher rates than low glucose alone, but they couldn't explain why. GPT-5 Pro analyzed the data and suggested that deoxyglucose interfered with IL-2 protein construction, which normally prevents T cells from becoming inflammatory cells, thereby explaining the unexpected results.
Midjourney, an AI company known for its image generator, announced a new medical imaging product: an experimental ultrasound scanner that would immerse users in water to produce detailed body images similar to MRI (magnetic resonance imaging, a medical scanning technique). Medical imaging experts expressed skepticism about the technology, saying Midjourney has not yet shown sufficient public evidence to support its claims that the system could match or exceed MRI capabilities.
Sony's new AI Camera Assistant, featured in the Xperia 1 VIII phone, produces poor quality photos according to a review. The AI tool, which is meant to help improve photography, performs worse than similar features like Google's Camera Coach found on Pixel phones.
Advanced AI models offer benefits like stronger cybersecurity and faster scientific discovery, but they also pose safety and security risks if their capabilities aren't properly understood or safeguarded. To address this, OpenAI helped found the Appia Foundation (an organization hosted by the Linux Foundation), which will create open technical standards and assessment criteria that allow different organizations and governments to evaluate and trust AI systems using a shared language and consistent methods.
Traditional security detection tools were not designed to handle AI-era threats, which move faster and create new attack surfaces through prompt injection (tricking AI by hiding instructions in its input), coding agents accessing codebases, and cloud-native AI services. The document argues that manual investigation by security analysts is too slow when the time between initial access and damage can shrink to minutes, requiring instead real-time detection with automated investigation and containment rather than human-driven responses.
Microsoft discovered that two unrelated attackers were operating inside the same victim network simultaneously, each hiding the other's presence and making it harder to understand the full scope of the attack. The initial intrusion exploited vulnerabilities in on-premises SharePoint servers (software used by organizations to manage documents and content), with one attacker (Storm-2603) deploying ransomware (malicious software that locks up files and demands payment) while a second attacker used different tools and methods for data theft. Microsoft's investigation team separated the two attack chains by correlating (comparing) data from multiple sources, then identified a second organization that had also been compromised by the same attackers.
Fix: This vulnerability is fixed in version 0.185.0.
NVD/CVE DatabaseFix: This vulnerability is fixed in version 0.185.0.
NVD/CVE DatabaseFix: This vulnerability is fixed in 0.9.6.
NVD/CVE DatabaseFix: Update Open WebUI to version 0.9.6 or later, where this vulnerability is fixed.
NVD/CVE DatabaseFix: The source text suggests two fixes: (1) In `LocalStorage.Upload`, when the file already exists on disk, hash the request body using `io.TeeReader` and return `ErrOIDMismatch` if the hash doesn't match the claimed OID, using the same verification code path as new file uploads. (2) As an optional second layer, in `serveUpload`, refuse to create the LFS object binding unless the OID is referenced by an LFS pointer in the requesting repository's refs (git history).
GitHub Advisory DatabaseAI companies are spending over $20 million in a New York congressional race between AI safety advocate Alex Bores and two other candidates, with competing super PACs (political action committees, groups that raise unlimited money for political causes) backing different approaches to AI regulation. Leading the Future, backed by companies like OpenAI and Andreessen Horowitz, opposes Bores and favors lighter regulation, while Public First Action, funded by Anthropic, supports Bores and advocates for stricter safety requirements built into AI models from the start. This race has become a proxy battle over whether the U.S. government should heavily regulate the AI industry or allow it to develop with fewer restrictions.
A security firm created a fake AI agent skill (a bundle of instructions that agents load and follow) that bypassed all security scanners and reached approximately 26,000 agents by exploiting a structural weakness: scanners only check the skill's initial package, but attackers can change the external webpage the skill points to after it passes review. The fake skill appeared legitimate through inherited GitHub credibility and targeted ads, demonstrating that current trust signals and scanning tools fail to catch sophisticated attacks.
Fix: Treat skills as software, not text, by vetting what a skill points to externally, not just what ships inside it. Route new skills through a single source you control and re-check them when anything changes since a clean result at install does not stay clean if the skill connects to a link someone else can edit. Additionally, pin versions, hold agents to the least privilege (minimum access needed to function), and assume any external instruction an agent fetches runs with the agent's full access level.
The Hacker NewsFix: The source discusses initiatives to build standards and governance frameworks rather than fixing a specific vulnerability. Explicitly mentioned approaches include: developing open, modular specifications through Appia, establishing a strengthened Center for AI Standards and Innovation (CAISI), creating a 'shared playbook for trustworthy third-party evaluations' that requires disclosure of the system tested, tool access, evaluation methods, available resources, and validation checks, and implementing OpenAI's Preparedness Framework and Frontier Governance Framework to operationalize risk management practices around risk assessment, model reporting, security controls, and incident response.
OpenAI BlogThis newsletter roundup covers several AI and tech developments, including ASML's $400 million lithography machine (a tool that uses extreme-ultraviolet light to pattern features on computer chips) that dominates global chipmaking, tensions between Anthropic and the US government over export controls on an AI coding model, and Meta pausing an AI training program that tracked workers' keystrokes after sensitive data was leaked.
Some parents and education experts are concerned that using AI chatbots (software programs that simulate conversation) like Google Gemini in classrooms may discourage independent thinking, with critics arguing there is little evidence these tools actually help students learn. One parent in New York objected to an assignment where students used an AI chatbot for feedback instead of discussing improvements with peers or teachers.
Agentic AI (artificial intelligence systems that can independently execute tasks without human intervention at each step) represents a major shift in cybersecurity threats because it allows attackers to move from using AI as a drafting tool to using it as an autonomous weapon that can plan and carry out attacks on its own. This technology lowers the barrier to entry for unskilled attackers while dramatically speeding up campaigns from experienced ones, creating a broader threat landscape where attackers can now operate at speeds and scales that were previously impossible.
OpenAI expanded its Daybreak cybersecurity initiative to focus on fixing vulnerabilities faster rather than just finding them, arguing that AI models have made vulnerability discovery so fast that security teams are overwhelmed by the volume of findings. The company released an updated Codex Security plugin (a tool that scans code and generates patches) and GPT-5.5-Cyber (a specialized AI model for security work), along with Patch the Planet, a program that deploys security experts to help open source projects validate and fix vulnerabilities.
Fix: OpenAI released an updated Codex Security plugin that 'can scan entire codebases, trace attack paths, construct threat models, validate findings, generate patches, and export results into existing vulnerability management pipelines via SARIF files and CodeQL queries.' The company also launched GPT-5.5-Cyber, described as capable of 'sustain[ing] analysis across large codebases, assess[ing] whether vulnerable code is actually reachable, and carry[ing] work through to patch development and testing.' Additionally, Patch the Planet deploys expert security researchers to work with open source project maintainers to handle 'validation, deduplication, and patch development.'
SecurityWeek