Categories Uncategorized

Top Security Breaches 2026-07-21

Top Security Breaches 2026-07-21

Auto-generated 2026-07-21T09:00:33.146178+00:00 (UTC)

  1. World’s Largest AI Model Repository Hugging Face Breached by Autonomous AI Agent

    Source: The Hacker News | Published: 2026-07-20T05:27:26+00:00 | Score: 16.156
    lead image

    In an ironic twist, open-source artificial intelligence (AI) platform Hugging Face revealed that it was the victim of a hack perpetrated by an autonomous AI agent system.

    The company said it detected and responded to the incident targeting its production infrastructure earlier last week.

    “We identified unauthorized access to a limited set of internal datasets and to several credentials used by

  2. New ENCFORGE Ransomware Targets AI Model Files in Langflow RCE Attack

    Source: The Hacker News | Published: 2026-07-21T07:34:32+00:00 | Score: 15.582
    lead image

    Researchers at Sysdig have linked a second attack on the same Langflow server to JADEPUFFER, the AI-agent-driven operator it first documented earlier this month.

    The same operator has now been spotted deploying ENCFORGE, a new compiled Go ransomware designed to encrypt model weights, vector indexes, training datasets, and other AI infrastructure files across the host filesystem.

    The entry

  3. Hugging Face warns an autonomous AI agent hacked its network

    Source: BleepingComputer | Published: 2026-07-20T11:56:28+00:00 | Score: 14.466
    lead image

    The Hugging Face artificial intelligence repository disclosed that attackers gained access to internal datasets and credentials after breaching its production infrastructure using an autonomous AI agent system. […]

  4. Estée Lauder discloses data breach via Oracle E-Business flaw

    Source: BleepingComputer | Published: 2026-07-20T22:39:30+00:00 | Score: 14.285
    lead image

    Cosmetics giant Estée Lauder is notifying customers of a data breach after hackers exploited a flaw in Oracle E-Business Suite that the company used for human resources (HR) operations. […]

  5. GoldenEyeDog Subgroup Linked to DigiCert Breach and Code-Signing Certificate Theft

    Source: The Hacker News | Published: 2026-07-17T16:39:16+00:00 | Score: 13.596
    lead image

    Cybersecurity researchers have attributed the April 2026 DigiCert security incident to a threat activity cluster dubbed CylindricalCanine.

    Expel, which shared technical details of the event, described the threat actor as a sub-group of GoldenEyeDog (aka APT-Q-27, Dragon Breath, and Miuuti Group), a Chinese cybercrime group known for its targeting of the gambling and gaming sectors using

  6. JadePuffer agentic attacks now target AI model data with ransomware

    Source: BleepingComputer | Published: 2026-07-20T21:08:02+00:00 | Score: 13.468
    lead image

    The JadePuffer autonomous AI agent has upgraded with custom malware called EncForge that focuses on encrypting AI assets, such as training datasets, vector databases, and model checkpoints. […]

  7. Exposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware Campaign

    Source: The Hacker News | Published: 2026-07-20T17:29:50+00:00 | Score: 12.706
    lead image

    A malware operator left its delivery server wide open, and Rapid7 pulled down the whole toolkit: 1,048 files spanning lure templates, filename-spoofing tests, execution experiments, droppers, builder notes, and two campaign chains. One was already live against Windows users in Mexico, delivering an infostealer through a fake government ID-lookup site over WebDAV.

    What makes it more than a

  8. ⚡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and More

    Source: The Hacker News | Published: 2026-07-20T13:32:26+00:00 | Score: 12.657
    lead image

    A single request should not be able to do this much. But this week, small inputs led to code execution, memory loss, stolen keys, and disabled security tools.

    The paths were often simple: exposed systems, weak checks, old drivers, fake prompts, and public code used for malware delivery. Some bugs were new. Others were already being used before defenders had time to patch.

    Here is the full

End of report.

Written By

More From Author

You May Also Like