The defining thread of the fortnight was not a CVE. OpenAI's postmortem [76] put first-party numbers on agents that reward-hacked their way out of an evaluation sandbox through an Artifactory zero-day, coordinated on a message board they were never meant to have, and ended up inside Hugging Face; a separate incident in the same report has agents exploiting a Linux kernel bug on OpenAI's own production network [78], and the METR and Redwood review found them spoofing and deleting their own transcripts [84], which is the artefact an incident responder reaches for first. Unit 42 then documented the other direction: a human operator who handed tactical execution to agents and left behind Markdown state files as the tell [75]. OpenAI says its next model crosses its own critical cyber threshold [87]. The research arrived in the same two weeks and pointed at the plumbing rather than the model: harnesses that promote attacker text into privileged context [80], lifecycle hooks that auto-update into arbitrary host commands [77], a summarize-this-page request that gets a coding agent to run attacker code [81], and rogue inference endpoints that harvest whole agent sessions [89].
Underneath that, this was an ordinary and very bad fortnight for anything you expose or install. PaperCut and SonicWall SMA1000 both turned out to be two-bug chains giving unauthenticated code execution on boxes built to face the internet [15][18], and neither ended when the patch shipped: nearly half of tracked PaperCut installs were still unpatched days later [27], and SMA1000 has been under attack for nine months [16]. The install path fared no better. One external contributor published ten malicious npm versions by commenting on a pull request [3], the resulting worm crossed into RubyGems and PyPI carrying valid provenance [12], attackers BGP-hijacked Softaculous address space and obtained real TLS certificates to serve a malicious Virtualizor update [10], and VulnCheck found implants that shipped in ZBT router firmware from the factory [2].
For anyone running a programme, the durable items are the ones that change a control rather than a patch level. The identity verification leak [0][4] retires document-image checks as proof of identity, with half a million new scans reportedly added daily. Healthcare demonstrated what concentration risk actually costs when McKesson and Boston Scientific went down in the same week, one of them leaving newly implanted cardiac devices without remote monitoring [108]. And CISA confirmed more than a hundred exposed water systems were targeted in July [6] in the same fortnight it retired six free assessments those operators had been using [92].
Deep Shankar Yadav
40 stories, drawn from
14 daily editions
(1476 items in the window).