Week ending 30 July 2026

42 daily briefs published · 175 stories tracked · compiled 30 July 2026

Highlight of the week

The OpenAI rogue-agent breach was the week's clear centre of gravity: six independent outlets, eleven findings and six appearances in our own daily briefs, with scope expanding beyond Hugging Face to Modal and other platforms. It was flagged high severity and it kept growing across 28 and 29 July, which is the pattern that matters. A single agent identity misused reaches every platform that trusted it, and the perimeter is a token rather than a network.

Read alongside AgentForger CSRF (one phishing link deploys a rogue ChatGPT Workspace agent) and Ruflo/RufRoot, a patch-resistant unauthenticated RCE in an AI agent harness, the week's message is that agent platforms are now production infrastructure being attacked as such.

Standout trends

Agent platforms as the new attack surface

Beyond the OpenAI breach, Claude Cowork VM escape let an agent read host Mac files, sandbox bypasses in Cursor, Codex and Gemini CLI traced back to plain text config files, and n8n patched an expression-sandbox escape reaching OS commands. Shadow AI agents multiplying across enterprise platforms and dormant non-human identities creating hidden cloud paths describe the governance gap underneath all of it.

AI turning up on the offensive side

NodeBB patched eight high-severity flaws found by AI pentest agents in six hours. Claude was reported deriving a key-recovery attack on post-quantum HAWK-256, Dolphin X RAT claims AI victim scoring, and a Claude jailbreak is being sold as attack-as-a-service. The Hermes agent story, reported twice this week, has an agent conducting the intrusion itself.

Working exploit code arriving in the open

Public proof-of-concept landed for Certighost AD CS, the already-exploited Check Point SmartConsole bypass, GitLab RCE after concealed disclosure, vBulletin, and a Linux kernel use-after-free for local root. Nightmare Eclipse dumped eight working Microsoft zero-days in a disclosure feud.

Network and security appliances under sustained pressure

Arista drew a 48-hour CISA patch deadline. Check Point SmartConsole and Fortinet FortiOS both entered KEV, FortiBleed harvested credentials from tens of thousands of devices, Cisco FMC static credentials are being exploited, and MikroTik, OpenWrt DHCPv6 and hotel Wi-Fi gateways round it out.

Build systems as the softest route in

TeamCity's CVSS 9.8 auth bypass allows pre-release code tampering, Gitea RCE via planted Git hooks, compromised @joyfill npm packages, weaponised GitHub Actions runners, AppSec scanners shown as a foothold, and CubePilot hit by DNS hijacking. GitHub's three-day Dependabot cooldown is the defensive response.

Worth watching

Old code keeps paying: a 2002-era BMC flaw, nine-year-old RefluXFS, and 200,000 IoT devices held via RC4 flaws from 2013. Also watch OT, after the coordinated attack on 30+ Minnesota water systems.

By the numbers


← All weekly reports