Security news.
Today's security brief highlights critical vulnerabilities and active exploitation, including a zero-day in ServiceNow and widespread exploitation of WordPress and SonicWall flaws. AI continues to feature prominently, with Hugging Face breached by an autonomous AI agent and Russian intelligence using AI to hack IP cameras for military espionage.
Critical ServiceNow flaw (CVE-2026-6875) exploited in attacks
A critical code execution vulnerability in the ServiceNow AI Platform is now actively exploited, allowing attackers to run code.
Hugging Face breached by autonomous AI agent
The AI model repository Hugging Face disclosed a breach where an autonomous AI agent system gained unauthorized access to internal datasets and credentials.
WP2Shell WordPress vulnerabilities exploited in the wild
Critical remote code execution flaws (CVE-2026-60137, CVE-2026-63030) in WordPress Core, dubbed "wp2shell", are being actively exploited following public disclosure.
Russian intelligence hacks IP cameras to spy on NATO and Ukraine logistics
A Russian intelligence service is systematically hijacking internet-connected security cameras across Europe and Ukraine to monitor military transport routes and troop movements.
7-Zip vulnerability (CVE-2026-14266) allows code execution via XZ archives
A heap-based buffer overflow in 7-Zip's handling of XZ chunked data could allow an attacker to execute code by convincing a user to open a crafted XZ archive; a fix is available in 7-Zip 26.02.
Critical NGINX vulnerability (CVE-2026-42533) allows crash and potential RCE
F5 has patched a critical NGINX flaw that enables a remote, unauthenticated attacker to trigger a heap buffer overflow with crafted HTTP requests, potentially leading to worker process crashes or remote code execution.
OpenSSL silently fixes 'HollowByte' DoS vulnerability
A denial-of-service vulnerability in OpenSSL, dubbed 'HollowByte', allowed attackers to exhaust server memory through un-freed buffer pre-allocations triggered by malicious payloads.
Ernst & Young data breach affects personal and financial information
Hackers stole names, addresses, Social Security numbers, and credit/debit card numbers from Ernst & Young via a compromised third-party management platform.