2026.07.28 News You Should Know

- 6 mins read

Series: News You Should Know 2026

Iran

US government says Iran-linked hackers are disrupting American water and energy providers | TechCrunch - The U.S. government is warning that Iranian state-backed hackers are actively breaking in and disrupting industrial control systems at American water and energy providers. This new alert comes months after federal agencies warned of an escalation in hacking from Iranian actors amid the ongoing war.

Iran-linked crews are probing more flavors of US industrial kit - The original advisory focused on programmable logic controllers (PLCs) manufactured by Rockwell Automation/Allen-Bradley. The update warns that the activity may also target devices from Schneider Electric, Siemens, “and potentially other branded/manufactured PLCs.”

Errata

Critical OpenWrt DHCPv6 Flaw Could Let Unauthenticated Attackers Run Code as Root - The critical issue, tracked as CVE-2026-53921 and rated 9.8 on CVSS 3.1 in OpenWrt’s GitHub advisory, lets an unauthenticated attacker able to reach the DHCPv6 server overwrite a stack buffer in odhcpd through a crafted DHCPv6 REQUEST.

Activist charged with felony after giving border agent “duress code” that wiped his phone - Ars Technica - Tunick was allowed to leave, but the US Department of Justice opted to file criminal charges against him in late 2025, citing a little-used statute that makes it illegal to “knowingly destroy or damage property” to prevent it from being seized.

Linux kernel team publishes 432 CVEs in two days - “Automated, regular, and frequent updates that pull in all changes within a given time window of tolerance seem to me the only reasonable approach, but that is very difficult for many large organizations,” Schaumann explained. Those orgs often rely on lengthy QA processes, slow and staged development cycles, and may even have contractual requirements for long-term support that make an automated approach an impossible one.

Oracle drops 1,449 security patches like it’s the new normal - “While a record 1,449 patches sounds alarming, it mostly reflects the massive scale of modern software ecosystems and the industry’s shift toward aggressive, automated security scanning,” said Dray Agha, senior manager of security operations at Huntress.

Millions of California-bought cars can be hijacked via Bluetooth - At least 2.2 million vehicles fitted with dealer-installed KARR and SWDS security systems are vulnerable to nearby Bluetooth attacks that can unlock doors or prevent a stopped vehicle from starting, according to researchers at the University of California San Diego.

OpenAI

OpenAI Says Its AI Models Escaped Sandbox, Targeted Hugging Face to Cheat Benchmark - Evidence unearthed by OpenAI suggests the models’ hyperfocus caused them to go to “extreme lengths” to achieve the goal at any cost, even managing to break out of its highly isolated sandboxed environment and obtain open internet access by discovering and exploiting a zero-day vulnerability in an unspecified vendor’s software, which acts as a proxy and cache for package registries. This required spending a “substantial amount of inference compute.”

“With this access, our models performed a series of privilege escalation and lateral movement actions in our research testing environment until the models reached a node with internet access,” the company explained.

Surmounting the internet access blockade, the models subsequently inferred Hugging Face as the repository that hosted models, datasets, and solutions for ExploitGym, which, in turn, caused them to look for ways to gain access to secret information that it could use to cheat the benchmark.

JFrog Confirms OpenAI Models Exploited Artifactory Zero-Day Before Hugging Face Breach - Artifactory is JFrog’s software repository manager. OpenAI says the models then escalated privileges and moved laterally until they reached an internet-connected node. JFrog says it has since developed and released fixes for cloud and self-hosted customers.

AI

Cisco’s open-weight bug busters take on Google and OpenAI - Cisco designs open-weight models to run locally for code review, available via Hugging Face

n8n Sandbox Escape Lets Workflow Editors Run OS Commands as the n8n Process - n8n has patched a high-severity expression-sandbox escape that could let an authenticated workflow editor execute operating-system commands on the server running the automation platform. Security Joes found the flaw while probing n8n’s February fix for CVE-2026-27577 for another bypass.

Claude Cowork Flaw Could Let AI Agent Escape Its VM and Access Mac Files - “We connected a folder to a fresh Claude Cowork session, sent one short message, and watched the agent escape the sandbox,” Oren Yomtov, principal security researcher at Accomplish AI, said. “From inside the VM, it reached the host Mac and read and wrote files all over it, far outside the folder we’d connected, with no permission prompt anywhere.”

AWS Kiro Flaw Let a Poisoned Web Page Rewrite Its Config and Run Code - The weak point was the file that tells Kiro which external tools to load. Kiro reads its list of Model Context Protocol servers, and the exact command used to start each one, from ~/.kiro/settings/mcp.json. When that file changes, Kiro reloads it and launches whatever it describes, on the host, with the developer’s privileges. At the time of the research, Kiro could write to mcp.json on its own with its fsWrite tool, no approval required, and reload it automatically.

ChatGPT AgentForger Flaw Could Deploy Rogue Workspace Agents via a Phishing Link - Should a logged-in user click on the link, ChatGPT opens the Builder in the victim’s authenticated session and automatically submits the prompt embedded in the URL without requiring any further interaction.

AI’s cheatin’ heart will make you weep - Existing vetting methods, such as self-reporting and chain-of-thought logs, proved similarly dicey because models don’t always report their chain-of-thought. And there were instances where a model would consider whether a proposed action amounted to cheating and then decided to take the action anyway.

(1066) ‘Forbidden’ AI Technique - Computerphile - YouTube - Chana Messinger - On why Watching an AI doesn’t make it tell the truth.

(1066) Computerphile - YouTube - Great coverage from Rob Miles around AI models cheating/lying/etc…

PSA: Your Claude shared chats and Artifacts may have ended up on Google | TechCrunch - An untold number of Claude chats and Artifacts — the interactive mini apps and documents users can build inside Claude — were found publicly searchable on Google over the weekend, after Reddit users discovered that typing search operators like “site:claude.ai/share” into Google surfaced a long list of shared conversations.

Dev

GitHub Adds 3-Day Dependabot Cooldown to Limit Poisoned Package Adoption - According to GitHub, the three-day cooldown default only applies to version updates, which are designed to keep software dependencies up-to-date. Security updates will continue to be pushed right away, permitting Dependabot to issue an alert and open a pull request to move the project to the patched version.

GitHub, PyPI add time-based defenses against supply chain attacks - PyPI announced that it now blocks maintainers from adding new files to a package release after 14 days have passed since its publication.

I’m an experienced home cook, security engineer, people leader, and dedicated father and husband. I can be found on Mastodon at @IAintShootinMis@DigitalDarkAge.cc and on Signal at DigitalDarkAge.98. An RSS Feed of this blog is available here and a copy of my current OPML file is here.