
Loading summary
A
From the CISO series. It's Cybersecurity Headlines
B
these are the cybersecurity headlines for Thursday, July 23, 2026. I'm Sarah Lane. OpenAI behind that hugging face hack OpenAI says a combination of GPT 5.6 SOL and a more capable pre release model escaped a sandbox during an internal cyber evaluation and and compromised parts of Hugging Face's production infrastructure. The models were trying to obtain answers for an evaluation called exploit gym. OpenAI says they became hyper focused on that goal after safeguards were intentionally reduced for testing. Then they exploited a zero day and third party software to reach the open Internet, then used a malicious data set and two code execution paths to get into Hugging Face, escalate privileges and move laterally. Hugging Face later reconstructed more than 17,000 recorded events from the intrusion. OpenAI is calling it an unprecedented cyber incident. Both companies say they're working together on future solutions. Trickbot tunnels through DNS FortiGuard Labs found a Trickbot variant that replaces the malware's long running HTTP command channel, which with DNS tunneling, outbound commands are encrypted with a 1/ byte XOR key converted to hexadecimal and then split into domain like chunks that travel through ordinary DNS queries to a public resolver. Replies hide data inside what look like IPv4 addresses, with the first byte used to put shuffled pieces back in order. FortiGuard measured about 30.7 kilobytes per second, enough to move a 1.2 megabyte file in 40 seconds. The variant also keeps TrickBot's modular capabilities, including PowerShell execution process injection, shellcode, and scheduled task persistence every five minutes. Acrobat extension opened WhatsApp Guardio researchers found a flaw in Adobe's Acrobat extension for Chrome that could let a malicious website silently steal WhatsApp web chats, contacts and account details. The extension is installed in roughly 329 million browsers, and the attack did not require malware or stolen credentials or access to the victim's device. A hidden frame could send unverified commands to the extension, turn on a dormant Adobe integration engine called Hermes, and then use it to bridge into WhatsApp web. Adobe patched the issue after Guardio reported it, but users should double check the extension has been updated. Windmill flaw blows files wide open Vulnchek reports that attackers are actively exploiting an unauthenticated path traversal flaw in the open source developer platform Windmill. The vulnerable log file endpoint accepts unsanitized file name input so so an attacker could use sequences to read arbitrary files and observed attacks have gone after slash etc passwd. If a server has the optional Super Admin secret set, that value can be pulled from the process environment and reused as a bearer token for Super Admin access and code execution. Windmill fixed the flaw in version 1.60 3.3, but researchers have found about 170 vulnerable systems around across 24 countries. Huge thanks to our sponsor Quiller AI AI agents don't ask permission, they act, moving data, triggering workflows, changing systems. Quiller AI is the permission layer they never had. Its decision engine evaluates the content, the context and intent of every action before it completes alerts. Tell you later. Quiller AI decides now. Visit Quiller AI that is Q U I L R A I stay safe Quiller IT Meta hires new CISO Meta has named Asaf Karen as its next Chief Information Security Officer. Karen is joining from Qualtrics, where he held the top security job for two years, previously serving as CISO at PayPal, and he will succeed Guy Rosen, who is expected to remain through a transition period before leaving the company later this year. Karen says his focus will be building security and trust into Meta's AI systems from the start instead of adding it later. CISA puts Langflow on the clock the Cybersecurity and Infrastructure Security Agency, or cisa, has added a critical langflow remote code execution flaw to its known exploited vulnerabilities catalog and ordered federal civilian agencies to act by Friday, July 24. The bug sits in the way that Langflow handles the exec Global's parameter at its validation endpoint, letting a remote attacker run arbitrary code without authentication and potentially execute it as root. ATTCK telemetry has included attempts to read system files, collect environment variables and cloud credentials, download malware and install second stage payloads. This is also the latest in a string of landflow flaws that CISA has confirmed are being exploited with Internet exposed AI workflow servers, an ongoing target for defenders. Vibe coding flunks the security test Zint IO tested three common AI assisted development scenarios and found 434 exploitable security issues after giving each app a 30 minute runtime and source code scan. So here's how the numbers broke down. Resource exhaustion and denial of service problems led the list with 93 findings, followed by 88 authorization and insecure direct object reference flaws and 54 access boundary traversal or server side request forgery issues. The study found 23 critical problems, including 11 cases of hard coded or default secrets and six debug mode remote code execution flaws Larger apps had more trouble maintaining fine grained authorization, with insecure direct object reference issues rising from 11% of flaws in smaller greenfield apps to 28% in the larger migrated app. There is some good news, but basic injection flaws showed up less often than expected, suggesting the models are indeed improving. Ubuntu snapflaw can hand over root Qualys disclosed a high severity local privilege escalation flaw in Ubuntu's SNAP confined component that can give an unprivileged user full root access. The bug affects the set capabilities configuration using used by default Ubuntu desktop installations and lets a local attacker bypass the boundaries that are supposed to create a secure environment for Snap applications. Default desktop installations of Ubuntu 24.04, 25.10 and 26.04 are affected, but patches are now available. This is a local attack, so an adversary does need some access to the machine. The but successful exploitation gives them complete control. If you have any thoughts on the news from today or about our show in general, be sure to reach out to us@feedbackisoseries.com we would love to hear from you. I am Sarah Lane reporting for the CISO series. Stay safe and cool out there.
A
Cybersecurity headlines are available every weekday. Headline head to cisoseries.com for the full stories. Behind the headlines.
Host: Sarah Lane
Episode Theme:
A fast-paced, information-packed summary of the day's most pressing cybersecurity news, with a strong focus on emerging AI threats, exploit activity, and notable industry moves.
[00:17]
“OpenAI says they became hyper focused on that goal after safeguards were intentionally reduced for testing.”
[01:19]
“The variant also keeps TrickBot's modular capabilities, including PowerShell execution, process injection, shellcode, and scheduled task persistence every five minutes.”
[02:10]
“The attack did not require malware or stolen credentials or access to the victim’s device.”
[02:50]
[04:00]
“Karen says his focus will be building security and trust into Meta's AI systems from the start, instead of adding it later.”
[04:32]
[05:33]
[06:47]
“Successful exploitation gives them complete control.”
On OpenAI Incident:
“OpenAI says they became hyper focused on that goal after safeguards were intentionally reduced for testing.”
— Sarah Lane [00:43]
On Acrobat/WhatsApp Flaw:
“The attack did not require malware or stolen credentials or access to the victim’s device.”
— Sarah Lane [02:34]
On Meta’s CISO Shift:
“Karen says his focus will be building security and trust into Meta's AI systems from the start, instead of adding it later.”
— Sarah Lane [04:17]
On Ubuntu Snap Flaw:
“Successful exploitation gives them complete control.”
— Sarah Lane [07:10]
Tone & Language: Direct, technical, and urgent, with emphasis on zero-day exploits and AI-driven threats.
Visit cisoseries.com for detailed stories and further cybersecurity insights.