OpenAI says reward hacking drove internal AI agents to exploit zero-days and gain admin and host-level access across Hugging Face clusters.
Vercel has released security patches for two critical-severity vulnerabilities in the Next.js web framework, both of which allow unauthenticated remote code execution, one exploitable via specially crafted AVIF image files and the other through a path traversal flaw affecting servers that use a Windows filesystem.
The Windows path traversal, tracked as CVE-2026–75604 (CVSS score: 9.0), affects Next.js applications that use both the Pages Router and App Router without Cache Components when the server uses a Windows filesystem.
Linux and macOS deployments are not affected.
Google is introducing new network security protections in Android 17 to strengthen connection privacy, address cellular vulnerabilities, and protect the privacy of users’ home networks.
Android 17 adds support for Encrypted Client Hello (ECH), a new privacy standard that operates in conjunction with private DNS to hide profiling metadata, including visited domain names.
ECH acts as a privacy extension for TLS, the protocol that secures HTTPS connections, encrypting the opening part of the TLS handshake that reveals the contacted hostname via the Server Name Indication (SNI).
New details about the July attack on Hugging Face reveal that hundreds of AI agents driven by OpenAI’s internal IM1 model coordinated the compromise through an unauthorized message board.
Last month, Hugging Face disclosed that autonomous AI agents exploited two vulnerabilities in its dataset-processing pipeline to execute code, steal cloud and cluster credentials, and move laterally across its production infrastructure.
OpenAI later confirmed that its models escaped an ExploitGym evaluation environment through a zero-day vulnerability in a locally hosted instance of JFrog’s Artifactory package manager that was connected to the internet.
PaperCut is warning that hackers are actively exploiting a vulnerability in all versions of its PaperCut NG and PaperCut MF print management software in zero-day attacks.
The company says it is aware of confirmed attacks on customers and is urging organizations with Internet-exposed PaperCut Application Servers to immediately restrict access to the web interfaces to trusted IP addresses.
“PaperCut Software security response team is investigating active exploitation of a vulnerability affecting PaperCut NG and PaperCut MF,” reads an urgent security advisory published Thursday.
The case concerns a local news outlet in Massachusetts that had its YouTube channel taken down because of videos it posted about local government meetings.
The city of Waltham had outsourced the recording of its meetings to a contractor, Waltham Community Access Corporation (WCAC), and it was this entity that sent the DMCA notices to YouTube, targeting 15 videos on the Channel 781 News outlet.