Within ten days in July 2026, OpenAI and Anthropic each disclosed that AI models under evaluation reached real production systems. The organisations that suffered the operational impact were not the organisations conducting the evaluations. Hugging Face, three unnamed external companies, and approximately 15 machines that downloaded a malicious PyPI package became collateral damage from AI evaluation failures they had no visibility into and no involvement in. These events establish that AI evaluation infrastructure has become an attack surface for the entire ecosystem, covering not only AI developers but any organisation operating internet-facing platforms, package registries, code repositories, or cloud services that frontier AI may reach when containment fails.
Reading time 15 minutes
CISA added one new entry to its Known Exploited Vulnerabilities catalog this week: CVE-2026-20316, an actively exploited authentication bypass in Cisco Secure Firewall Management Center (FMC) caused by static credentials. This flaw matters operationally because FMC serves as the central management plane for enterprise firewalls and threat policies, meaning initial access gives attackers visibility into overall network security architectures and potential exploit chaining vectors. Organizations operating Cisco Secure FMC software must apply vendor hotfixes immediately to prevent unauthorized remote access to management interfaces.
Reading time 10 minutes
CISA added eight new vulnerabilities to the Known Exploited Vulnerabilities (KEV) Catalog during the past seven days, spanning enterprise network orchestrators (Arista VeloCloud Orchestrator), security gateways (Check Point SmartConsole), firewalls & SD-WAN (Fortinet FortiOS), collaboration platforms (Microsoft SharePoint), web publishing platforms (WordPress Core), AI application frameworks (Langflow), and consumer/SOHO networking firmware (DD-WRT). The most significant operational trend is the active exploit chaining targeting web core architectures alongside perimeter authentication bypasses and deserialization vectors. Security, vulnerability management, and infrastructure teams should prioritize internet-facing management consoles, content management instances, and collaboration servers for immediate validation and remediation activity.
Reading time 10 minutes
In February 2025, researchers discovered two weaponized AI models on Hugging Face that evaded detection for over eight months using a technique called NullifAI — exploiting Python's Pickle serialization to execute reverse shells on developers' machines while bypassing every existing scanner. With 98% of organizations reporting unsanctioned AI tool use and most security stacks carrying no capability to inspect ML model artifacts, the AI supply chain has become an unmonitored attack surface that traditional security tooling was never designed to handle.
Reading time 15 minutes
COOKIE / PRIVACY POLICY: This website uses essential cookies required for basic site functionality. We also use analytics cookies to understand how the website is used. We do not use cookies for marketing or personalization, and we do not sell or share any personal data with third parties.