Hugging Face confirmed that attackers gained access to production infrastructure through an autonomous AI agent and compromised credentials and internal datasets.
HollowByte enables DoS attacks on OpenSSL-based servers through targeted memory fragmentation via false length field specifications in the TLS handshake; patches are available for multiple versions.
Publicly listed IT companies must immediately disclose cyberattacks as price-sensitive insider information, otherwise they face a fine under the Market Abuse Regulation.
CVE-2026-60137 and CVE-2026-63030 enable unauthenticated remote code execution on WordPress 6.9–7.0.1 without prerequisites when both vulnerabilities are combined.