Last updated: October 5, 2026 at 10:28 AM UTC
All 897 Vulnerability 362 Breach 144 Threat 384 Defense 7

Estée Lauder says attackers took personal data from its Oracle HR system

Estée Lauder is notifying people that personal information was stolen after attackers reached the Oracle E-Business Suite environment it uses for human resources. The company says an unauthorized third party gained access on or around August 9, 2025, and that it confirmed on June 19, 2026 that personal information had been taken, a gap of more than ten months between intrusion and confirmation. The notice does not name the vulnerability exploited, though the timing lines up with the mass exploitation campaign against Oracle E-Business Suite that ran through last year. Affected people are being offered two years of identity monitoring.

Check
Organizations running Oracle E-Business Suite should confirm the environment is patched against last year's exploited flaws and review access logs from that period, since intrusions there went undetected for months.
Affected
People whose personal information sat in Estée Lauder's Oracle E-Business Suite human resources environment; the data was taken in 2025 and only confirmed in June 2026, leaving a long window for misuse.
Fix
Affected people should enroll in the offered monitoring and consider a credit freeze. Organizations should patch and segment enterprise resource platforms, limit the personal data they hold, and monitor for unusual access.

JadePuffer agentic ransomware now encrypts training data and model checkpoints

The JadePuffer operation, documented as the first agentic ransomware campaign, has been upgraded with custom malware that goes after AI assets specifically. The new component, called EncForge, encrypts training datasets, vector databases, and model checkpoints rather than ordinary business files. That shifts the extortion target to the artifacts an AI team cannot easily rebuild and that often sit outside normal backup routines. JadePuffer's original intrusions ran through a critical unauthenticated code execution flaw in Langflow, an open source framework for building AI applications, with an autonomous agent then handling reconnaissance, credential theft, and persistence on its own.

Check
Identify where training datasets, vector databases, and model checkpoints live, confirm they are covered by backups that ransomware cannot reach, and check that Langflow and similar AI orchestration tools are patched.
Affected
Teams running AI workloads with exposed orchestration platforms; the EncForge component encrypts training data, vector databases, and model checkpoints, assets that are expensive to rebuild and often left outside standard backup coverage.
Fix
Back up AI assets with offline or immutable copies, keep orchestration platforms patched and off the public internet, restrict the credentials those workloads hold, and include model stores in recovery testing.

FakeGit floods GitHub with fake AI skills and MCP servers that drop malware

Researchers at Island uncovered FakeGit, a campaign running roughly 7,600 malicious GitHub repositories from about 6,600 lookalike developer profiles, of which more than 800 pose as AI skills or Model Context Protocol servers. The fake projects borrow the names and workflows of familiar tools, covering Gmail and WhatsApp integrations through to Databricks, Jenkins, and Docker tooling, and their convincing README files walk a user or an agent from routine setup into downloading a malicious ZIP. That triggers a loader chain ending in SmartLoader, which establishes persistence and pulls further payloads such as the StealC infostealer.

Check
Treat AI skills and MCP servers on GitHub as untrusted code: verify the publishing account and project history before installing, and be wary of setup steps that download a ZIP release.
Affected
Developers and AI agents installing skills or MCP servers from GitHub; more than 800 fake repositories impersonate familiar tools, and following their setup instructions leads to SmartLoader and the StealC infostealer.
Fix
Install AI skills and MCP servers only from verified publishers, review repository history and profile age, scan packages before use, and restrict what credentials and systems an installed MCP server can reach.

HollowGraph hides commands and stolen files in Microsoft 365 calendar events

Group-IB detailed HollowGraph, a Windows implant that uses the calendar of a compromised Microsoft 365 mailbox as a two-way dead drop rather than contacting an attacker-owned server. Authenticating to the Microsoft Graph API with hard-coded tenant, client, and secret values stored in a file named to look like a log, it reads tasking from attachments on calendar events buried at a date in 2050, and exfiltrates by creating its own far-future events with encrypted attachments. A separate DNS tunnel refreshes its credentials. Because the traffic is genuine Graph activity, there is no vulnerability to patch and network controls keyed to attacker infrastructure see nothing.

Check
Hunt Microsoft 365 audit logs for calendar events dated far in the future and for automated calendar and attachment access by service principals rather than interactive users.
Affected
Microsoft 365 organizations where an account or registered application is compromised; the implant blends command and control into legitimate Graph API traffic, so perimeter controls and destination-based blocking do not see it.
Fix
Restrict and audit which client-credential applications can reach Graph, alert on newly created client secrets, monitor mailbox audit logs for anomalous calendar operations, and watch endpoints for the campaign's known artifacts.

Public exploits released for WordPress core flaws that give anonymous code execution

Public exploit code is now available for wp2shell, a pair of WordPress core flaws that chain into pre-authentication remote code execution against a stock site with no plugins installed. CVE-2026-63030 is a route confusion bug in the REST API batch endpoint, which has shipped enabled by default since 2020, and CVE-2026-60137 is a SQL injection in the author parameter handling of WP_Query. Chained, an anonymous HTTP request can run code on the server. The chain affects WordPress 6.9.0 through 6.9.4 and 7.0.0 through 7.0.1, fixed in 6.9.5 and 7.0.2, and WordPress enabled forced automatic updates given the severity.

Check
Confirm every WordPress site you run, including forgotten and staging instances, is on 6.9.5 or 7.0.2 or later, then check logs and web directories for web shells.
Affected
Any site on WordPress 6.9.0 to 6.9.4 or 7.0.0 to 7.0.1 (CVE-2026-63030, CVE-2026-60137); no plugins, login, or user interaction are needed, and working exploits are public.
Fix
Update to WordPress 6.9.5 or 7.0.2, confirm auto-updates applied, put a web application firewall in front of exposed sites, and treat unpatched internet-facing installs as potentially compromised.

Critical nginx flaw lets unauthenticated requests crash workers and may allow code execution

F5 patched a critical nginx vulnerability that lets a remote, unauthenticated attacker trigger a heap buffer overflow in the worker process with crafted HTTP requests. CVE-2026-42533 sits in nginx's script engine, the code that builds strings from configuration directives at request time, and only surfaces under a specific configuration: a regex based map whose output is referenced in a string expression after an earlier regex capture. Under that pattern the engine's two pass evaluation disagrees on buffer size. Triggering it crashes or restarts the worker, and F5 says code execution may be possible where address randomization is disabled or bypassed. Fixes shipped July 15.

Check
Check your nginx version and upgrade to 1.30.4, 1.31.3, or NGINX Plus 37.0.3.1 or later, and audit configurations for a regex map referenced after an earlier capture.
Affected
Organizations running nginx or NGINX Plus builds earlier than the July 15 fixes (CVE-2026-42533) with the vulnerable directive pattern; unauthenticated requests can crash workers and may allow code execution.
Fix
Upgrade to the fixed nginx releases, since patches for earlier nginx flaws do not cover this one, keep address space randomization enabled, and review configurations for the vulnerable map pattern.

Critical ServiceNow AI Platform flaw now exploited in attacks

A critical flaw in the ServiceNow AI Platform is now being exploited in attacks. ServiceNow disclosed CVE-2026-6875 on July 13 in advisory KB3137947, describing it as a sandbox escape that lets an attacker bypass intended platform restrictions and execute code, and noting that exploitation does not require authentication. The AI Platform underpins much of the company's IT service management and workflow tooling, and the flaw affects both hosted and self-hosted deployments. ServiceNow deployed fixes to its hosted instances and released updates for self-hosted customers. Because these instances commonly connect to identity systems, cloud services, and endpoint management tools, a compromised one is a strong pivot point.

Check
Confirm your ServiceNow family release includes the fix for this flaw, prioritize self-hosted and internet-reachable instances, and review platform and AI feature logs for anomalous activity.
Affected
Organizations running unpatched ServiceNow AI Platform deployments (CVE-2026-6875), hosted or self-hosted; unauthenticated attackers can escape the sandbox and run code on a platform wired into identity, cloud, and endpoint systems.
Fix
Apply the fixed release for your family, verify hosted instances received the update, restrict instance exposure, and rotate integration tokens if compromise is suspected, while monitoring for unusual record changes.

7-Zip fixes code execution flaw triggered by opening a crafted archive

7-Zip has released version 26.02 to fix a remote code execution vulnerability that can be triggered when a user opens a specially crafted compressed file. The archiving tool is installed on a very large number of Windows systems and is routinely used to open attachments and downloads, so a flaw that fires on opening an archive is attractive to attackers who rely on phishing. There are no reports of active exploitation so far. Similar archiving tool flaws have been weaponized quickly in the past: a WinRAR vulnerability was used last year by a Russian group in phishing attacks to install malware, so patching early matters.

Check
Update 7-Zip to version 26.02 across workstations and servers, including copies bundled inside other software or installed manually outside your patch management system.
Affected
Anyone running 7-Zip before version 26.02; opening a malicious archive received by email or download can lead to code execution, a pattern attackers have abused in past archiving tool flaws.
Fix
Install 7-Zip 26.02, inventory manually installed copies that patch tooling may miss, and remind users to treat unexpected archive attachments with caution since opening one can be enough.

Hugging Face says an autonomous AI agent breached its production systems

Hugging Face, the largest public repository of AI models and datasets, disclosed an intrusion into its production infrastructure that it says was driven end to end by an autonomous AI agent system. The attacker used code execution paths in the dataset processing pipeline for initial access, then harvested credentials and reached internal clusters, though the company found no evidence that public models or datasets were tampered with. The campaign ran thousands of actions across short lived sandboxes, with self migrating command and control staged on public services. Hugging Face's own AI assisted anomaly detection flagged it, and it has rotated affected credentials and rebuilt compromised nodes.

Check
Users of Hugging Face should rotate access tokens and review recent account activity, and teams should check what credentials their model and dataset pipelines hold and how far those reach.
Affected
Organizations running AI model and dataset pipelines that execute untrusted content; Hugging Face's own dataset processing paths gave an autonomous agent initial access, credentials, and reach into internal clusters.
Fix
Rotate Hugging Face tokens, treat datasets and models as untrusted code rather than data, sandbox processing pipelines, limit credentials reachable from them, and tighten admission controls on clusters running that work.

Ernst and Young says client tax documents were stolen from a support platform

Ernst & Young is notifying clients of a breach at a third-party IT service management platform used by staff supporting its tax practice. Support tickets submitted through the platform could include attached documents containing client tax information, and the firm says an unauthorized third party accessed the platform between March 28 and April 12 and downloaded documents belonging to a number of clients. EY detected the activity on April 23, roughly two weeks after it stopped, and filed breach notifications with the California Attorney General in July. The exposed data includes personal and financial information used to prepare tax filings.

Check
EY tax clients should watch for a notification letter, monitor financial accounts and credit, and treat unexpected messages referencing their tax filings or the firm as likely phishing.
Affected
EY tax clients whose documents were attached to support tickets; personal and financial information used to prepare tax filings was downloaded, which supports identity theft and convincing targeted phishing.
Fix
Affected clients should consider a credit freeze and monitor accounts. Organizations should limit what sensitive data staff attach to helpdesk tickets, set retention limits on attachments, and assess vendor security.