Na imprensa
The Washington Post
Hackers who broke into OpenAI warn the AI industry has a security problem
More powerful AI magnifies cyberattack risks.
Financial Times · via Ars Technica
Researchers used Claude to hack OpenAI
Researchers used Claude to reach an OpenAI employee account and sensitive GitHub data.
The Wall Street Journal
Hackers Used Anthropic’s Claude to Break Into OpenAI
A bug-hunting independent security research team accessed OpenAI’s internal code system, exposing growing risks in automated cyber threats

The Hacker News
Active Exploitation Attempts Target WSO2 API Manager JWT Bypass
Attackers are targeting a critical WSO2 flaw reported by Hacktron that can put administrative accounts at risk.
The Register
Attackers pummel critical WordPress vuln to create all sorts of mischief
Plus dozens of PoCs in the public domain
Help Net Security
Two new high severity WordPress vulnerabilities, patch immediately!
The 7.0.2 WordPress security release addresses one critical and one high severity security issue.

Cyber Security News
GPT-5.6 Sol Ultra Builds Full Chrome Exploit Chain From Security Patches
In Hacktron’s comparison of three AI models, only Sol Ultra completed the Chrome challenge, costing about $1,597.

Cybernews
Major GNU software repository Savannah fixes two-year flaw
GNU Savannah, a major platform for developing and distributing free software, said it had patched exploitable flaws that left it vulnerable for roughly 2 years.

DevOps.com
Hacktron Plans to Build AI Platform to Test Code for Vulnerabilities
After raising $2.9 million, Hacktron is building a platform to test code changes and separate exploitable vulnerabilities from false positives.
The Register
Claude Opus wrote a Chrome exploit for $2,283
Pause your Mythos panic because mainstream models anyone can use already pick holes in popular software

Cybernews
Cloudflare’s Next.js alternative faces critical security flaws
Cloudflare’s AI-built Next.js alternative launched with critical security flaws, intensifying its rivalry with Vercel.
CSO Online
BeyondTrust fixes critical RCE flaw in remote access tools
Organizations running BeyondTrust’s self-hosted remote access software are urged to patch a vulnerability rated 9.9 out of 10.

BleepingComputer
BeyondTrust warns of critical RCE flaw in remote support software
BeyondTrust patched its cloud services and urged on-premises customers to update after Hacktron discovered a critical vulnerability.

The Hacker News
BeyondTrust Fixes Critical Pre-Auth RCE Vulnerability in Remote Support and PRA
A critical vulnerability in BeyondTrust’s remote access products could allow unauthenticated attacks without user interaction.