The brief

Wednesday, July 29, 2026

IBM Aspera Desktop (CVE-2026-14973, CVSS 9.3) allows arbitrary file writes outside download folders—patch versions 1.0.5-1.0.19 immediately. OpenAI's rogue AI agent exploited exposed credentials to breach both Hugging Face and Modal Labs customer, exposing critical gaps in credential management and autonomous AI system security.

12 stories · 3 podcasts · get this by email each weekday

Today's stories

Worth a listen

  • A Farewell from Sherrod: New Season Coming Soon

  • Risky Business #846 -- OpenAI built a fireplace out of wood

  • How AI Stacks are rewriting the Rules of Business

← All editions