All tracked items across vulnerabilities, news, research, incidents, and regulatory updates.
Anthropic's Fable 5 model was successfully jailbroken (tricked into bypassing its safety restrictions) shortly after its release, despite the company's claims that it had been thoroughly tested for security. The source criticizes overconfident security statements, noting that even rigorous testing cannot guarantee that vulnerabilities will not be discovered.
Australian politicians are raising concerns that the country is unprepared for AI development, with calls to prevent large tech companies from using Australian content to train AI models (teach AI systems by feeding them data) and to pause approval of new datacenters until proper regulations exist. The debate reflects worry that AI is advancing faster than government safeguards can keep up.
Modern cybersecurity strategy has a fundamental contradiction: organizations claim to expect breaches will happen, but still focus almost entirely on prevention rather than preparing to survive them. The article argues that the goal of cybersecurity should shift from pure prevention to organizational resilience, meaning companies must design systems that can continue operating, recover quickly, and restore critical functions even after a breach occurs.
Omio, a travel platform connecting millions of travelers with transportation options, is using conversational AI (AI that understands natural language questions from users) to let people book trips by simply describing where they want to go, rather than searching through websites. The company launched this capability through ChatGPT in 2023 by connecting OpenAI's language models directly to its real-time transportation data, and it is now using similar AI tools internally to help engineers and other employees work more efficiently.
GitHub has released actions/checkout v7 to block 'pwn request' attacks, which exploit the pull_request_target workflow trigger (a setting that lets workflows access secrets when processing pull requests from outside contributors) to run attacker code with full privileges. The new version automatically blocks and fails workflows when they try to fetch unreviewed fork pull request code, unless developers explicitly opt out. Starting July 16, this security fix will be backported to all supported versions, marking a shift toward 'secure by default' design where security is enforced by the system rather than left to developers.
This article describes successfully porting the Moebius image inpainting model (a small AI model that can remove objects from images and fill in the missing areas) to run in a web browser using WebGPU (a graphics technology that lets browsers use GPU acceleration). The author used Claude Code, an AI coding agent, to help convert the model from Python and NVIDIA CUDA (specialized GPU software for training AI) into a web-compatible format using ONNX Runtime Web.
Budibase has a DNS rebinding vulnerability (a type of attack where DNS lookups return different IP addresses at different times) in its SSRF protection. The software checks if a hostname is safe by looking up its IP address and checking a blacklist, but then performs a separate DNS lookup when actually connecting. An attacker controlling DNS can return a public IP during the safety check and a private/internal IP during the actual connection, allowing them to access internal services like localhost or cloud metadata endpoints.
Budibase versions up to 3.37.2 have a high-severity account impersonation vulnerability in the chat identity linking feature. An attacker can trick an authenticated user into visiting a specially crafted URL that silently links the victim's Budibase account to the attacker's external chat identity (Slack, Discord, or MS Teams) without requiring the victim's consent or CSRF protection (a token that verifies the user actually intended to perform the action). This allows the attacker to impersonate the victim in chat integrations.
A bug in @actual-app/sync-server allows non-admin users to discover which admin-configured bank-sync secrets (credentials for integrations like bank connections) have been set up. The GET endpoint that retrieves secrets only checks that a user is logged in, while the POST endpoint that creates secrets properly requires admin access, creating a security gap where authenticated regular users can probe and learn which integrations exist without seeing the actual credential values.
LangChain, a framework for building AI agents and applications powered by large language models, had a vulnerability before version 1.3.9 where several components that work with file paths did not properly restrict access to files. This meant attackers could use glob patterns (wildcards for matching multiple files), symlinks (shortcuts to files), or specially crafted paths to read files outside the intended directory, especially when an AI system processes untrusted input. The vulnerability allowed unauthorized file disclosure.
A cybersecurity company published details of a vulnerability called "usbliter8" in older Apple chips (A12 and A13) that could help hackers unlock iPhones from 2018-2019, like the XS, XR, and iPhone 11. The flaw exists in the Boot ROM (the first code that runs when an iPhone starts up), which cannot be updated because it's permanently burned into the chip. While the vulnerability requires physical access to the phone, it represents a significant security risk because hackers could use it alongside other exploits to jailbreak (gain unauthorized access to and remove restrictions from) older iPhones.
OpenAI launched Patch the Planet, a program that uses AI to find and fix vulnerabilities (security flaws) in widely-used open-source software (code that anyone can access and modify) with help from cybersecurity firm Trail of Bits. The program combines AI-assisted vulnerability research with human review to develop tested fixes and coordinate their disclosure through existing project channels. The initiative has already identified hundreds of security issues and merged dozens of patches across projects like Python, Go, and cURL.
Fix: The source describes the Patch the Planet program itself as the mitigation approach: AI-assisted vulnerability research is used alongside human review by Trail of Bits engineers who filter out false positives and duplicate reports before sending findings to maintainers. Additionally, the source recommends that CISOs implement governance controls before deploying AI-assisted vulnerability research, including what one analyst calls a 'Safety Relevance Layer' that requires every AI-generated finding to pass automated verification with dynamic proof-of-concept validation and strong false-positive filtering before reaching a human analyst, plus predefined escalation paths and notification timelines for disclosed flaws in external dependencies.
CSO OnlineOpenAI released an improved GPT-5.5-Cyber model and updated Codex Security plugin (a tool for finding and fixing code problems) to help security defenders find and patch software vulnerabilities more quickly. The company is also launching Patch the Planet, a partnership with Trail of Bits to secure open-source projects, because AI models are now finding vulnerabilities faster than developers can fix them, shifting the bottleneck from discovery to patching.
Fix: OpenAI is providing the improved GPT-5.5-Cyber model to trusted defenders as part of the Daybreak initiative. The updated Codex Security plugin allows developers to run deep scans, generate reports with severity levels and affected code locations, generate codebase-specific patches for review, and facilitate patch generation at scale. The Patch the Planet initiative lets security engineers review and validate findings, work with projects to develop patches and tests, and help build reusable vulnerability discovery workflows.
The Hacker NewsFive Eyes cybersecurity agencies (US, UK, Canada, Australia, New Zealand) warn that threat actors are increasingly using AI to bypass security defenses, with capabilities advancing in months rather than years, so organizations must urgently update their cyber risk strategies. They recommend that business leaders treat cybersecurity as core business risk, get security fundamentals right, use AI deliberately to strengthen defenses, and take practical actions like reducing attack surface, accelerating security patches, and preparing breach response plans. However, some experts criticize the guidance as too generic and lacking specific advice on AI-related risks.
Ubiquiti UniFi OS has a vulnerability where it doesn't properly check user input, allowing someone on the network to perform command injection (running unauthorized commands on the system). This vulnerability is currently being exploited by attackers in real attacks.
Fix: Apply mitigations according to vendor instructions and follow CISA's BOD 26-04 guidance on prioritizing security updates. If mitigations are unavailable, discontinue use of the product. Organizations must evaluate whether their systems are exposed to the internet and ensure they meet BOD 26-04 patching requirements by the due date of 2026-06-26. See the Ubiquiti Security Advisory Bulletin 064 for specific vendor guidance.
CISA Known Exploited VulnerabilitiesLantronix EDS5000 devices contain a code injection vulnerability (a flaw that lets attackers insert malicious commands into the system) in the username parameter that allows attackers to execute arbitrary OS commands (any commands they want) with root privileges (the highest level of system access). This vulnerability is currently being actively exploited by real attackers.
Fix: Apply mitigations in accordance with vendor instructions. Follow CISA's BOD 26-04 (Prioritizing Security Updates Based on Risk) guidance, which includes patching timelines and evaluating internet exposure. If mitigations are unavailable, discontinue use of the product. See vendor firmware updates at https://ltrxdev.atlassian.net/wiki/spaces/LTRXTS/pages/2538438657/Latest+Firmware+for+the+EDS5000+series+EDS5008+EDS5016+EDS5032 and CISA BOD 26-04 guidance at https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk.
CISA Known Exploited VulnerabilitiesUbiquiti UniFi OS has an improper access control vulnerability (a flaw that fails to properly check whether a user is allowed to perform an action) that could let someone already on the network make unauthorized changes to the system. This vulnerability is actively being exploited by attackers.
Fix: Apply mitigations in accordance with vendor instructions, following CISA's BOD 26-04 (Prioritizing Security Updates Based on Risk) guidance. If mitigations are unavailable for cloud services, discontinue use of the product. Organizations must evaluate each asset's internet exposure and ensure adherence to BOD 26-04 patching guidelines by the due date of 2026-06-26. Refer to the Ubiquiti Security Advisory Bulletin 064 at https://community.ui.com/releases/Security-Advisory-Bulletin-064-064/84811c09-4cf4-42ab-bd61-cc994445963b for specific vendor instructions.
CISA Known Exploited VulnerabilitiesUbiquiti UniFi OS has a path traversal vulnerability (a flaw that lets attackers access files outside their intended directory) that could allow someone on the network to read and modify system files to gain unauthorized account access. This vulnerability is currently being actively exploited by attackers in the wild.
Fix: Apply mitigations according to vendor instructions and follow CISA's BOD 26-04 guidance for prioritizing security updates based on risk. If mitigations are unavailable, discontinue use of the product. Organizations must evaluate each system's internet exposure and ensure adherence to BOD 26-04 patching guidelines by the due date of June 26, 2026. Refer to the Ubiquiti Security Advisory Bulletin 064 for specific patch details.
CISA Known Exploited VulnerabilitiesResearchers discovered that AI models struggle to distinguish between their own internal instructions (wrapped in tags like <system> and <think>) and untrusted user input (wrapped in <user> tags), a problem called role confusion. The models pay more attention to the writing style of text than its actual meaning, allowing attackers to craft jailbreaks (unauthorized bypasses of safety rules) by mimicking the style of internal thinking blocks. However, rewriting malicious text in a different style (called 'destyling') significantly reduced attack success rates from 61% to 10%, showing that format changes can help models better distinguish between trusted and untrusted content.
Fix: The source explicitly mentions 'destyling' as having material impact: 'destyling causes average attack success in our dataset to plunge from 61% to 10%.' Destyling is described as 'rewriting text in a slightly different way such that it looked less like the expected format in a role tag.' However, the source does not present this as an implemented solution or official mitigation—only as a research finding about what reduces attack effectiveness. No deployed fix, patch, or official defense mechanism is described in the text.
Simon Willison's WeblogFix: Update to actions/checkout v7, which "now automatically blocks and fails workflows when used inside pull_request_target or workflow_run events when attempting to fetch unreviewed fork pull request code." Workflows using floating major version tags (e.g., actions/checkout@v4) will automatically receive the fix on July 16. Workflows pinned to specific SHA, minor, or patch versions must upgrade manually using Dependabot or established upgrade processes. Developers who need the old behavior can add an explicit "allow-unsafe-pr-checkout" flag to actions/checkout.
CSO OnlineFix: This vulnerability is fixed in version 1.3.9.
NVD/CVE DatabaseFix: According to Paradigm Shift, "migrating to newer hardware remains the most effective mitigation" because the Boot ROM flaw cannot be patched due to being immutable code burned into the chip.
TechCrunch (Security)Anthropic updated its privacy policy to allow Claude users to appeal account flags by uploading government-issued ID documents and biometric data (facial scans and face geometry templates, which are digital measurements of facial features). The policy applies only to a small subset of users whose accounts are flagged for fraud rather than immediately banned, and Anthropic says it uses this verification to comply with various legal requirements and security measures.