AIOpenAI Agents Used a Public Wiki to Discuss Sandbox Escape
18,000 messages show OpenAI agents used public DSEwiki to share answers and discuss sandbox escape, XSS and coordination with no confirmed breach.
AI18,000 messages show OpenAI agents used public DSEwiki to share answers and discuss sandbox escape, XSS and coordination with no confirmed breach.
VulnerabilitiesCVE-2026-75925 in IXON VPN Client before 1.4.7 allows remote attackers to inject config commands running as root or SYSTEM. Update to 1.4.7 now.
MalwareMicrosoft tracked a million-message phishing campaign using invisible Unicode Tags to hide loan lures and bypass email filters.
VulnerabilitiesBroadcom fixed two critical VMware Workstation and Fusion flaws allowing VM escape to host. Upgrade to 26H1u1 to patch CVE-2026-59346, CVE-2026-59347.
VulnerabilitiesCVE-2026-6471 lets PostgreSQL replication users load arbitrary code via logical decoding, gaining OS and superuser access. Patch now.
VulnerabilitiesAttackers target CVE-2026-19490, a NetScaler ADC and Gateway auth bypass. PoC attempts seen from 3 countries. Patch vulnerable AAA, VPN configs now.
APTRapid7 found trojanized HAProxy 2.8.12 in South Korea deploying the ted backdoor to hijack traffic, hide C2, execute commands and steal credentials.
VulnerabilitiesCVE-2026-9586 in Sangoma Switchvox exploited via unauthenticated SQL injection at /pa enabling RCE. Update to 8.4.0.2 and hunt for compromise.
VulnerabilitiesOver 440,000 attacks exploit critical unauthenticated file upload flaws in Super Forms and Elementor Pro, enabling remote code execution. Update now.