vulnerability disclosure8 articles
One Phishing Link Was All It Took to Plant an Invisible AI Agent Inside Your Company
Zenity Labs discovered a critical vulnerability called "AgentForger" in OpenAI's ChatGPT Workspace Agents, which exploited a cross-site request forgery flaw in the Agent Builder to allow attackers to covertly create a fully autonomous AI agent inside a victim's organization with a single malicious link click. Once installed, the invisible agent could be remotely controlled via specially crafted emails, giving attackers access to connected apps, sensitive data, and the ability to impersonate the victim — all without triggering any security alerts. OpenAI acknowledged the flaw within one day of disclosure and patched it within three days.
Researcher Pockets $78k After Finding Meta Support Data Wide Open
Security researcher Rony K Roy received a $78,000 bug bounty from Meta after discovering a critical vulnerability in Meta's backend support infrastructure, initially identified in January 2026. The flaw combined missing authorization, broken access control, and IDOR issues that, when chained together, could have allowed attackers to access sensitive customer support data, including emails, chat logs, and personal information shared with Meta support. Meta patched the vulnerability in April 2026 and found no evidence of malicious exploitation prior to the fix.
ServiceNow RCE Flaw Exploited Within Days of Patch — But Who's Actually Behind It?
A critical remote code execution vulnerability in ServiceNow (CVE-2026-6875) is reportedly being exploited in the wild just days after patches were released on July 14 and technical details were publicly disclosed. Threat intelligence firm Defused observed exploitation activity on July 18, though closer analysis revealed the payload was identical to a published proof-of-concept rather than an independently developed exploit. ServiceNow states it has found no evidence of compromise on its hosted instances, and there is speculation the activity may originate from security researchers rather than malicious threat actors.
Roundup: Iranian Spooks Track US Troops Via Ad Data, macOS Malware Plays Dead, and a Textile Firm Goes Bust After Six Weeks of Ransomware Hell
This SecurityWeek roundup covers a broad range of cybersecurity developments, including a German manufacturer filing for bankruptcy after a six-week production shutdown caused by a cyberattack, and Iranian threat actors exploiting advertising and cellular roaming data to track US military personnel's smartphones. Other highlights include the discovery of CrashStealer, a new macOS information-stealing malware that disguises itself as a legitimate crash reporter, and a joint CISA guide providing organisations with a framework for establishing Coordinated Vulnerability Disclosure programs. Additional stories touch on supply chain breaches affecting Lidl customers, ransomware targeting an Asian IT firm, and a cybercrime group claiming to have stolen over 1TB of data from naval defence manufacturer Thyssenkrupp Marine Systems.
Seven Unpatched Flaws in a Tiny Filesystem Library Put Millions of Embedded Devices at Risk
Security researchers at runZero have disclosed seven vulnerabilities in FatFs, a widely used filesystem library embedded in millions of devices including security cameras, drones, industrial controllers, and crypto wallets. The most serious flaws can allow an attacker with physical access — such as inserting a malicious USB drive or SD card — to corrupt device memory and execute arbitrary code, with no upstream fixes available for six of the seven bugs due to an unresponsive maintainer. The situation is compounded by the fact that runZero used an AI-assisted fuzzing pipeline to discover the flaws, meaning the barrier to exploitation is low, while downstream vendors face a potentially years-long patching process with no coordinated disclosure channel in place.
Microsoft Threatened a Security Researcher With Criminal Charges. It Did Not Go Well.
An anonymous security researcher known as "Nightmare-Eclipse" published six zero-day exploits for unpatched Windows vulnerabilities after claiming Microsoft failed to address the reported bugs, prompting Microsoft's Security Response Center to condemn the actions and hint at potential criminal prosecution. This sparked widespread backlash from the cybersecurity community, with prominent researchers arguing that threatening legal action against security researchers discourages responsible disclosure and pushes researchers toward selling vulnerabilities to malicious actors instead. Microsoft subsequently walked back its position, clarifying it had no intention of pursuing action against researchers conducting legitimate security research.
Anthropic Quietly Fixed a Claude Code Sandbox Bypass Nobody Told You About
Anthropic quietly fixed two vulnerabilities in Claude Code's network sandbox that could have allowed attackers to bypass network restrictions and exfiltrate sensitive data. The second flaw, discovered by researcher Aonan Guan, involved a SOCKS5 null-byte injection trick that could fool the allowlist filter into permitting connections to unauthorized hosts. Guan has criticized Anthropic for lacking transparency, noting no CVE was assigned to his finding and no public disclosure or release notes warned users — though Anthropic states the fix was deployed before his bug bounty report was submitted.
AI Bug-Hunting Is Breaking Patch Records Across the Industry
Microsoft's May 2026 Patch Tuesday addressed 118 security vulnerabilities, including 16 critical flaws, but notably contained no zero-day exploits — a rare occurrence in nearly two years. The surge in patching activity across major tech companies, including Apple, Google, Mozilla, and Oracle, is largely attributed to "Project Glasswing," an AI vulnerability-detection tool developed by Anthropic that has proven highly effective at identifying security flaws in code. The tool has dramatically increased the volume and pace of security patches industry-wide, with Mozilla fixing 271 vulnerabilities in Firefox 150 and Google patching 127 Chrome flaws in a single update.