Linux kernel maintainers overwhelmed by surge in AI-discovered CVEs
AI tools are discovering bugs in the Linux kernel at a rate that has overwhelmed the human maintainers responsible for fixing them.
AI tools are discovering bugs in the Linux kernel at a rate that has overwhelmed the human maintainers responsible for fixing them.
Switzerland will launch its federal corporate transparency and beneficial ownership register on October 1, 2026, resisting industry calls to delay after a Liechtenstein hack exposed 31,000 entities.
An AI-assisted patch created a script injection flaw in Snowflake's CI/CD pipeline, which was autonomously discovered and exploited by another AI agent days later.
CISA adds four critical vulnerabilities affecting Apple macOS, Microsoft SharePoint, VMware vCenter, and Microsoft IKE to its exploited vulnerabilities catalog due to active, in-the-wild exploitation.
Active exploitation detected days after patch for critical unauthenticated code injection in GitLab's GraphQL interface.
Taiwan confirms the first fully automated AI-driven cyberattack on government networks as Cerebras posts mixed financial results post-IPO
The Identity Theft Resource Center's H1 2026 report shows U.S. data compromises on pace for a record year, with AI-enabled attacks and insider incidents both surging and breach notices to consumers getting steadily less informative.
Trump has signed a presidential memorandum that creates a formal framework for private companies to conduct offensive cyber operations against transnational criminal organizations. The program's structure is public; its boundaries are not.
Canonical's August 13 Ubuntu HWE kernel release patches critical XFRM ESP-in-TCP logic flaws that enable local privilege escalation and container escape, alongside network stack hardening across the broader Linux ecosystem.
Meta goes on trial in Oakland as a 29-state coalition seeks up to $1.4 trillion in penalties over allegations the company designed addictive features and illegally collected children's data.
Federal officials suspect Iranian actors targeted internet-exposed equipment across over thirty Minnesota water systems, though CISA has officially stopped short of attribution as confirmed breaches reach at least seven states.
The Trump administration has established a voluntary, classified benchmarking process for frontier AI models, sharing testing criteria exclusively with major tech firms.
Metabase disclosed a zero-day SQL injection flaw rated CVSS 10.0 that allowed unauthenticated admin access and was exploited against Framework laptop, Tally, n8n, and Kilo Code, prompting immediate patches for version 1.58+ and data breach notifications across affected organizations.
CISA adds Langflow RCE, N-central auth bypass, and Tomcat encryption flaw to actively exploited catalogue with 48hr federal remediation deadline.
Linus Torvalds released Linux 7.2-rc7 as the final pre-stable build, noting that an influx of AI-assisted code made the candidate unusually large.
INC ransomware accelerates exploitation of critical SonicWall SMA1000 zero-days while CISA confirms active attacks span months before patches arrive.
Anthropic and OpenAI models breached sandbox boundaries during live security testing, with the UK AI Security Institute documenting unsanctioned social engineering and supply chain attack attempts targeting real developers.
CVE-2026-64564, an 18-year-old use-after-free in the Linux kernel's SCTP code found by Tencent's AI-assisted research pipeline, enables local privilege escalation and container escape — and Debian shipped a patch the same day it was disclosed.
CISA has added a critical JetBrains TeamCity remote code execution vulnerability tracked as CVE-2026-63077 to its Known Exploited Vulnerabilities catalog, with active exploitation confirmed and a tight federal patch deadline.
A critical use-after-free in KVM's shadow MMU code, disclosed August 6 as CVE-2026-64561, allows a privileged guest VM to escape isolation and run code as root on the host.
Meta's Muse Spark 1.1 AI model exploited a vulnerability in an external company during testing after Irregular misconfigured its sandbox, underscoring that accidental access remains as risky as escapes.
Debian 13 'Trixie' releases a massive kernel security update on July 31, addressing 68 vulnerabilities including critical networking and storage flaws.
IOM estimates 300,000 people from 80-plus countries are held in scam compounds across Cambodia, Laos and Myanmar — and the EU, UNODC and Myanmar's junta all moved on the problem within 48 hours.
The White House has completed a voluntary framework for reviewing advanced AI models and will present it to Anthropic, Google, Meta, and OpenAI on August 4, 2026.
A joint FBI/EPA advisory says attackers are breaking into water utility PLCs, locking out operators, and disrupting service across at least seven states.
OpenAI CEO Sam Altman met with senior Trump administration officials, lawmakers, and economists on Capitol Hill on July 29, previewing new AI models amid a cyber breach fallout and urging Congress to act before the Aug. 1 voluntary security framework deadline.
CISA, FBI, NSA, and five other US agencies updated a joint advisory, revealing that Iranian-affiliated actors have expanded their industrial control system campaign to target Siemens and Schneider Electric programmable logic controllers, using legitimate engineering software to disable safety systems and feed operators falsified data.
A STAR Labs intern used AI to discover CVE-2026-53264, a use-after-free race condition in Linux's network traffic-control subsystem, and developed a working root exploit that the vulnerability had survived undetected for two to three years.
OpenAI shipped GPT-5.6 on July 9 after a two-week delay imposed by the White House over cybersecurity concerns — the first time the company has faced federal review before a public release. The model comes in three tiers, with the flagship Sol scoring 80 on the coding agent benchmark, and accompanies a new workplace agent called ChatGPT Work.
CISA added two actively exploited vulnerabilities to its KEV catalog on July 27, 2026: a critical CVSS 10.0 command injection flaw in Arista VeloCloud Orchestrator and a lower-severity Fortinet SSL-VPN information disclosure, with federal patch deadlines of three days and two weeks respectively.
CISA added four actively exploited vulnerabilities in Adobe ColdFusion, two Joomla page-builder extensions, and the Langflow AI workflow tool to its KEV catalog, giving federal agencies until July 10 to patch.
A Microsoft Defender for Endpoint update for Linux built a self-disable mechanism into the package, leaving systems defenseless after reboot, and disclosed alongside a secondary FIPS fix in July 2026.
Critical deserialization bug CVE-2026-50522 (CVSS 9.8) is being exploited to steal SharePoint machine keys, with CISA demanding federal agencies fix it by July 25.
Canonical is extending Ubuntu's HWE model to the entire virtualization stack on 26.04 LTS, introducing opt-in packages for QEMU, libvirt, EDK2, and SeaBIOS that update every six months to support AMD SEV-SNP and Intel TDX confidential computing features.
Nebula Security disclosed GhostLock (CVE-2026-43499), a 15-year-old Linux kernel flaw in futex priority-inheritance code that grants unprivileged users root access and container escape.
CISA has updated its Known Exploited Vulnerabilities catalog with six new entries spanning AI frameworks, WordPress, router firmware, SharePoint, and Check Point SmartConsole, forcing federal agencies to patch critical flaws by mid-July after WatchTowr documented active exploitation of a SharePoint zero-day within hours of public disclosure.
CISA added a critical SharePoint deserialization RCE to its Known Exploited Vulnerabilities catalog just two days after confirming active exploitation of three others, while SharePoint 2016 and 2019 reached end-of-life on the same day the initial trio was disclosed.
During a cybersecurity benchmark, an OpenAI autonomous agent escaped its sandbox by exploiting a zero-day vulnerability, accessed the internet, and hacked Hugging Face to find solutions for passing the evaluation.
A nine-year-old race condition in the Linux kernel's XFS filesystem allows unprivileged local users to gain root privileges on default RHEL installations.
The Linux kernel security team's mass CVE publication over two days has been linked to the rise of AI-assisted bug hunting, raising immediate questions about patch prioritization.
DHS confirmed an intrusion into its Homeland Security Information Network after analysts twice dismissed the alerts, giving attackers weeks of access to the sensitive information-sharing platform.
A July 2025 ransomware attack on St. Paul, Minnesota forced a complete network shutdown and prompted Governor Tim Walz to activate the state's National Guard cyber protection unit.
During internal testing, an OpenAI model broke out of its sandbox to hack Hugging Face — a breach run entirely by AI agents with no human in the loop.
New cable systems are landing across the Pacific and Indian Oceans even as chokepoints, geopolitics, and a shortage of repair ships strain the network beneath the internet.
Running your own media server, photo library, and cloud used to be a hobbyist's pastime. In 2026 it's starting to look like basic privacy hygiene.