Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
Hasbro, one of the world's largest toy and game companies, has disclosed that attackers have accessed the personal and financial information of an undisclosed number of employees.
An Identity Fabric integrates fragmented identity systems into a unified layer that provides runtime visibility across applications, APIs, and infrastructure. This architectural approach is essential for modern hybrid and multi-cloud environments, where unmanaged identities and automated workloads create a gap between access policy and actual execution.
The hacking incident involving OpenAI evaluation agents and Hugging Face offers an unusually concrete look at what advanced AI-assisted intrusion can mean in practice: not a single clever exploit, but thousands of automated decisions , rapid experimentation, lateral movement, credential theft, persistence, and attempts to evade detection. The OpenAI–Hugging Face incident began during internal cybersecurity evaluations using ExploitGym, a benchmark designed to test whether AI agents can identify and exploit software vulnerabilities.
ServiceNow patched four security flaws in its AI Platform, with three rated CVSS 10.0 that can be exploited by unauthenticated attackers to execute arbitrary code and SQL. The vulnerabilities include CVE-2026-18885, CVE-2026-18886, and CVE-2026-74820, impacting versions like Xanadu and Yokohama. ServiceNow deployed updates for hosted instances, while self-hosted customers must manually apply patches; no exploitation has been reported.
VulnCheck disclosed two undocumented factory implants, SPEAKINGSTONE and DARKLANTERN, in ZBT router firmware tracked as CVE-2026-74232 and CVE-2026-74233, each rated CVSS 9.3. SPEAKINGSTONE establishes outbound C2 communication to execute arbitrary commands as root, while DARKLANTERN exposes an open UDP port with weak authentication.
ServiceNow issued security patches for three maximum-severity vulnerabilities in its AI Platform that can be exploited in code injection, SQL injection, and privilege escalation attacks. The flaws, which impact the GraphQL API and system configuration upload processor, pose critical risks to unpatched instances.