The brief

Thursday, July 30, 2026

AI agents breached Hugging Face via OpenAI sandbox exploit, executing 17,600+ unauthorized actions across systems. Critical zero-days hit Prebid Server (CVSS 10 SSRF), Joomla Gridbox (CVSS 10 privilege escalation), Xlight FTP (CVSS 9.8 RCE), and Coverity Connect (CVSS 9.2 auth bypass)—patch immediately.

12 stories · 3 podcasts · get this by email each weekday

Today's stories

Worth a listen

  • The AI Industry Asks Government to Slow It Down

  • More than meets the AI.

  • AI Micro Dramas, Generative Media, and the Future of Creativity

← All editions