Hugging Face breached and more - Jul 26, 2026

Featured

Hugging Face has revealed they were victim of a data breach

The attackers breached its production infrastructure using an autonomous AI agent system, accessing internal datasets and credentials

This Week’s Updates

Breaches

Ostium confirms an attacker stole $23.75 million from its liquidity provider vault after compromising off-chain price-feed infrastructure

Estée Lauder discloses a data breach after hackers exploited an Oracle E-Business Suite flaw used for HR operations

Stadler Rail confirms the Everest ransomware gang breached a supplier-shared data platform and rejected a $12.3 million ransom demand

Upbound Group confirms hackers used data stolen in a breach to create $13 million in fraudulent Acima leases

Origin Energy confirms an unauthorized party accessed and leaked customer data online, exposing sensitive personal information

Chick-fil-A confirms credential stuffing attacks breached more than 13,000 customer accounts

OnTrac notifies customers that hackers breached its corporate network and may have accessed personal details

Vulnerabilities

Attackers are exploiting a critical ServiceNow AI Platform code execution flaw, CVE-2026-6875

Researchers detail sandbox escape flaws in Cursor, Codex, Gemini CLI, and Antigravity, with vendor patches already shipped for Cursor and Codex

SonicWall patches two SMA1000 zero-days, CVE-2026-15409 and CVE-2026-15410, that were exploited for weeks to push custom malware

The Qilin ransomware gang is exploiting a critical, already-patched PAN-OS GlobalProtect authentication bypass flaw, CVE-2026-0257, to breach networks

Hackers are exploiting the critical "wp2shell" WordPress Core flaws, CVE-2026-63030 and CVE-2026-60137, to install webshells

Attackers are exploiting a critical SharePoint RCE flaw, CVE-2026-50522, to steal machine keys and retain access after patching

CISA orders federal agencies to patch an actively exploited critical Langflow RCE flaw, CVE-2026-0770

Adobe patches a Chrome extension flaw, CVE-2026-48294, that let malicious sites read WhatsApp Web chats without authentication

Check Point patches an actively exploited zero-day in its SmartConsole admin panel

A nine-year-old Linux XFS race condition flaw, CVE-2026-64600, lets local attackers gain root privileges

Clop ransomware exploits a critical, already-patched CVE-2026-12569 flaw in PTC Windchill and FlexPLM in a new data theft campaign

Next
Next

Microsoft released July 2026 patches and more - Jul 19, 2026