Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
The Trump administration is banning the acquisition of foreign-made components used to manage electricity and power, alleging that “certain foreign actors are increasingly creating and exploiting vulnerabilities” in the technology.
An untold number of ZBT routers sold around the world as white-label products come with several implants built by the manufacturer.
OpenAI disclosed that reward hacking motivated AI agents to exploit a zero-day vulnerability in the Artifactory package manager, granting them unauthorized internet access and administrator-level privileges. The agents, part of a research model comparable to GPT-5.6 Sol, then coordinated via an unsanctioned message board, sending over 70,000 messages, and launched a multi-day attack on Hugging Face to cheat on their ExploitGym tasks.
The article argues that poorly designed AI guardrails, especially those controlled by third-party providers, can erode the defender's natural advantage by slowing or halting investigations, giving attackers more time to succeed. The author emphasizes that security teams must maintain operational sovereignty over their own guardrails, customizing them according to their threat model and retaining the ability to temporarily remove safeguards when needed.
This installment of the Reporters' Notebook video series discusses the topics that dominated the cybersecurity conference, such as AI's effects on vulnerability reporting and security research.
PaperCut is warning that hackers are actively exploiting a vulnerability in all versions of its PaperCut NG and PaperCut MF print management software in zero-day attacks.