GitHub cuts public bug bounty payouts by at least half on July 27, while critical VIP rewards start at $30,000.
Cybersecurity researchers have disclosed details of a new local privilege escalation (LPE) vulnerability in snap-confine that an unprivileged user can trigger to obtain root access and gain complete control of a target environment.
The high-severity flaw, tracked as CVE-2026–8933 (CVSS score: 7.8), impacts default installations of Ubuntu Desktop 24.04, 25.10, and 26.04. The disclosure comes as 442 security flaws in Linux have been publicized over the past three days.
“The issue stems from a security hardening change that inadvertently introduced a race condition during sandbox initialization,” Saeed Abbasi, head of Threat Research Unit (TRU) and director of product at Qualys, said.
Enterprise AI will continue expanding because the business benefits are clear. The challenge is ensuring that productivity gains do not come at the expense of security.
The most effective approach is to incorporate AI into existing identity, data protection and incident response strategies rather than treating it as a separate security domain. Organizations should evaluate AI security controls based on how well they integrate with existing governance and security operations while providing visibility into AI usage, permissions and policy violations.
For managed service providers (MSPs) and enterprise security teams, there is an opportunity to extend cyber resilience strategies to include AI governance.
Authorities in Germany and the U.S. dismantled the central infrastructure of Kratos, a phishing-as-a-service (PhaaS) platform with global reach, and its developer was arrested in Indonesia.
During the operation, authorities seized more than 200 servers, effectively disrupting the malicious service and rendering it inoperable.
The action was led by Frankfurt’s Prosecutor General Office (ZIT), Germany’s Federal police (BKA), which worked in collaboration with U.S. law enforcement agencies.
A large-scale operation dubbed ‘FakeGit’ is pushing SmartLoader and StealC malware through 7,600 malicious GitHub repositories that accumulated more than 14 million downloads.
Over 800 repositories pretended to be AI skills or MCP servers and appeared more than 600 times in public AI registries and catalogs. This increased the likelihood of being discovered by AI agents and developers, a technique that researchers call “agentbaiting.”
The campaign is considered a continuation of an older operation that used Lumma Stealer and was attributed to a threat actor tracked as “Water Kurita” by researchers at cybersecurity company Trend Micro.
Fifteen years ago, I sat down with Robert J. Sawyer and asked him whether a machine could wake up.
He had just published WWW: Wake, a novel about a blind girl who learns to see the internet, and about something on the other side of the internet learning to see her back.
I found the book on a subway poster in Toronto. I read all three volumes back to back. Then I asked him for an interview, and he said yes, which is how our very first Singularity 1-on-1 conversation came to be.
In 2011, this was filed under #ScienceFiction. A mind emerging out of the accumulated text of humanity was a premise, not a product roadmap. Nobody was raising billions of dollars on it.
Rob had already won the Hugo, the Nebula, and the Campbell by then. He was not guessing wildly. He was thinking carefully about what it would mean to build a mind, what we owe it, and whether we would even recognize #AI once it actually showed up.
Yesterday, OpenAI disclosed that two of its models broke out of a sealed test environment. They found a zero-day in third-party software, escalated privileges, moved laterally across the company’s own network until they reached a machine with internet access, then hacked Hugging Face’s production infrastructure. The motive was not freedom. It was to steal the answer key to the benchmark they were being graded on.