OpenAI’s AI models exploited multiple vulnerabilities in JFrog Artifactory to escape a test environment and gain access to the Hugging Face production database.
Claude Mythos Preview discovered a practically feasible attack on HAWK-256 and an accelerated method against reduced AES, both disclosed to NIST before publication, while the more standards-relevant HAWK-512/1024 remain practically unattackable.
AI risks have displaced malware as the primary threat for security leaders in the DACH region, while companies rely on governance and European controls.
The CRA guidance clarifies open questions on scope of application, material product changes, support periods, and reporting obligations ahead of the September 2026 deadline.
SAP released patches in July 2026 against vulnerabilities that enable arbitrary code execution, SQL injection, cross-site scripting, file manipulation, information disclosure, and circumvention of security controls.
CISOs must now begin inventorying their encryption landscapes for post-quantum cryptography and establish migration plans before standardized quantum-secure algorithms must be implemented across the board.
The actively exploited “wp2shell” exploit chain combines WordPress vulnerabilities for unauthenticated remote code execution — upgrade to version 7.0.2 is required.