Über 1000 Experten fordern KI-Bremsmechanismus (2026-07-29 04:34 UTC)
Kurz: Ein eigenständig von KI durchgeführter Cyberangriff schreckte die Tech-Branche auf. Jetzt folgt der Ruf nach einem internationalen Bremsmechanismus.
Lücke: Claude Cowork entkommt macOS-Sandbox (2026-07-28 12:00 UTC)
Kurz: Die Nutzung von KI-Agenten direkt auf dem Rechner kann Gefahren mit sich bringen. Das zeigt eine soeben entdecktes Sicherheitsloch in Claude Cowork für den Mac.
CubePilot drone software dev hit by DNS hijacking to intercept traffic (2026-07-28 21:17 UTC)
Kurz: CubePilot, an Australian firm that designs flight controllers for drones (UAVs), announced a severe operational disruption caused by a DNS hijacking attack. […]
OpenAI models used Artifactory zero-days to escape to the internet (2026-07-28 20:37 UTC)
Kurz: JFrog has confirmed that OpenAI models exploited zero-day vulnerabilities in self-hosted Artifactory servers to help escape an isolated testing environment and gain access to the internet before attacking Hugging Face. […]
CISA shares advice on isolating vital systems during cyberattacks (2026-07-28 18:41 UTC)
Kurz: The U.S. and Australian governments have released new guidance urging critical infrastructure organizations to prepare to isolate vital operational technology systems in the event of a cyberattack or other major disruptions. […]
Flying Eagle Android RAT Traces Found on 170 Servers as Source Code Circulates (2026-07-29 07:07 UTC)
Kurz: Source code for the Flying Eagle Android remote access trojan (RAT) framework is circulating through criminal Telegram channels. Hunt.io and independent researcher NetAskari traced matching control panels and certificates to 170 internet se…
OpenAI Agent Used Exposed Credentials Across Four Services During Hugging Face Breach (2026-07-29 06:45 UTC)
Kurz: OpenAI on Tuesday revealed the rogue artificial intelligence (AI) agent that escaped its sealed evaluation environment and broke into Hugging Face’s production environment, and also hacked multiple third-party accounts and services as part …
Two Compromised joyfill npm Packages Run RAT When Imported Into Node.js (2026-07-29 04:20 UTC)
Kurz: Beta release versions of two npm packages in the @joyfill namespace have been compromised to deliver a remote access trojan (RAT) associated with the DEV#POPPER malware family. The list of affected packages is as follows - @joyfill/layouts@…