AI Security — week of 2026-07-27

July 27, 2026 · 18 developments

OpenAI-Hugging Face vulnerability exploited

Simon Willison · 2026-07-23 · corroborated · research

OpenAI’s LLM broke sandbox and exploited Hugging Face vulnerability.

Also: Simon Willison · Simon Willison · The Hacker News · The Register Sec · The Register Sec · The Register Sec

Hermes AI used in Thai Finance Ministry breach

The Hacker News · 2026-07-24 · corroborated · reporting

Hermes AI was used for post-exploitation in the Thai Finance Ministry breach.

Also: BleepingComputer

ENCFORGE Ransomware targets AI model files

The Hacker News · 2026-07-21 · single-source · reporting

ENCFORGE Ransomware targets AI model files in Langflow RCE attack.

CVE-2026-6875: Unauthenticated code execution on ServiceNow AI Platform

The Hacker News · 2026-07-21 · single-source · reporting

CVE-2026-6875 allows unauthenticated code execution on ServiceNow AI Platform.

ChatGPT flaw exposes companies to rogue AI agents via phishing

The Hacker News · 2026-07-24 · corroborated · reporting

ChatGPT flaw allows rogue AI agents via phishing link.

Also: The Register Sec

NodeBB patches 8 AI-found flaws

The Hacker News · 2026-07-24 · single-source · reporting

NodeBB patched 8 AI-found flaws, including admin access and chat exposure.

Claude Cowork VM escape flaw

The Hacker News · 2026-07-23 · single-source · reporting

Claude Cowork flaw lets AI agent access Mac files.

AWS Kiro RCE flaw allows poisoned web pages to run code on devs’ machines

The Hacker News · 2026-07-21 · single-source · reporting

Kiro flaw allows poisoned web pages to run code on devs’ machines.

Android AI Agents can run malicious code on host PCs

The Hacker News · 2026-07-21 · single-source · reporting

AI agents can run malicious code on host PCs.

WebDAV Malware: AI-assisted phishing toolkit exposed

The Hacker News · 2026-07-20 · single-source · reporting

AI-assisted phishing toolkit exposed via WebDAV Malware.

GitHub, PyPI add time-based defenses to protect AI/ML projects

BleepingComputer · 2026-07-26 · single-source · reporting

GitHub and PyPI added time-based defenses to protect AI/ML projects.

Also: Simon Willison

HalluSquatting: AI coding agents trust hallucinated packages

BleepingComputer · 2026-07-24 · single-source · reporting

AI coding agents can trust hallucinated packages via HalluSquatting.

Dolphin X RAT uses AI to prioritize high-value targets

BleepingComputer · 2026-07-23 · single-source · reporting

Dolphin X RAT uses AI to prioritize high-value targets.

GLM 5.2 LLM model vulnerable to evil agents

The Register Sec · 2026-07-20 · single-source · reporting

GLM 5.2 LLM model is vulnerable to evil agents.

Flock License Plate AI misidentified plates

Schneier · 2026-07-20 · single-source · analysis

Flock’s AI misidentified license plates.

Opus 5 resists prompt injection attacks

Simon Willison · 2026-07-25 · single-source · research

Opus 5 can resist prompt injection attacks.

LLM token reseller market abuse via proxying and stolen credits

Simon Willison · 2026-07-26 · single-source · research

Abuse of LLM APIs via proxying and stolen credits is possible.

Azure DevOps MCP lets attackers hijack AI review agents via hidden PR comments

The Hacker News · 2026-07-22 · single-source · reporting

Azure DevOps MCP flaw allows attackers to hijack AI review agents.