Alabama Subpoenaed OpenAI. An AI Sandbox Escape Is Now a Consumer-Protection Case.

Alabama has subpoenaed OpenAI over the Hugging Face agent incident, testing whether an AI containment failure can become a consumer-protection case.
Vulnerabilities, defensive security, architecture and operational security.

Alabama has subpoenaed OpenAI over the Hugging Face agent incident, testing whether an AI containment failure can become a consumer-protection case.

A WordPress plugin did not merely miss one permission check. Its request path could send the method allowlist, nonce check, login requirement and capability gate through an error handler that logged the failure and returned control to the caller. The…

Operation Fake KickOff uses fake recruiters, browser-in-the-browser pages and live MFA relay to steal corporate Google Workspace access.

Rapid7 counted twice as many high and critical disclosures, while newly exploited vulnerabilities stayed near 40. The queue is not the risk model.

Brandenburg’s seven memorial sites remained open after ransomware disabled central IT. The real resilience story was the emergency operation behind the public doors.

A Term Finance governance proposal sat on-chain for six days without a veto, then removed its own timelock and drained an estimated $8.5 million from the protocol's vaults.

A malicious website could ask the N-able Passportal browser extension for authentication tokens and receive enough access to enumerate, decrypt and modify credentials across a password vault. The vulnerable extension did not require the attacker to compromise N-able, the managed…

Ray CVE-2025-62593 turns a malicious browser visit into AI infrastructure code execution. Patch Ray and replace browser trust with authentication.

ToxicPanda 2.0 abuses VPN permission to cut off Google Play, then automates Android wireless debugging to obtain shell-level capability. The chain shows how legitimate platform functions can become a post-compromise control path.

ReliaQuest says a stolen password and approved MFA push produced a valid session, but device trust blocked every attempt to reach company applications.