Vulnerabilities
7 storiesCritical ServiceNow code execution flaw now exploited in attacks
CVE-2026-6875 in the ServiceNow AI Platform is now under active exploitation, giving attackers code execution on one of Europe's most prevalent ITSM platforms — emergency patching should be treated as a top priority this week.
BleepingComputer9/10[UPDATE] [hoch] Composer: Mehrere Schwachstellen ermöglichen Codeausführung
BSI flags updated advisory for multiple RCE vulnerabilities in the PHP dependency manager Composer — a supply-chain risk for any organisation running PHP build pipelines.
CERT-Bund (BSI)8/10Critical NGINX Vulnerability Can Crash Workers and May Allow Remote Code Execution
F5 patched CVE-2026-42533, a critical unauthenticated heap-overflow in NGINX workers exploitable via crafted HTTP requests — given NGINX's ubiquity as a reverse proxy, patch urgency is maximum.
THN (Feedburner)8/10[UPDATE] [hoch] Mozilla Firefox und Firefox ESR: Mehrere Schwachstellen
Updated BSI advisory highlights multiple high-severity Firefox and Firefox ESR flaws enabling potential code execution and security bypasses — patch priority for enterprise desktop fleets.
CERT-Bund (BSI)7/10[NEU] [hoch] IBM Langflow Desktop OSS: Mehrere Schwachstellen
IBM Langflow Desktop OSS carries high-severity flaws enabling RCE and admin takeover — a warning for enterprises integrating AI-workflow tools without hardening them like production software.
CERT-Bund (BSI)7/10Mythos Didn't Break Your Security Program. Your Exposure Window Could.
Rather than fixating on Mythos-driven CVE volume, this analysis argues enterprises should focus on the shrinking exposure window — the gap between AI-accelerated discovery and adversary weaponisation is collapsing.
THN (Feedburner)7/10[NEU] [hoch] Extreme Networks ExtremeXOS: Mehrere Schwachstellen
High-severity ExtremeXOS flaws let authenticated attackers escalate to admin on network switches — organisations running Extreme infrastructure should patch before adversaries chain these with credential-stuffing attacks.
CERT-Bund (BSI)6/10
Threat Intel
5 storiesAutonomous AI Intrusions Are Here: Lessons from the Hugging Face Compromise
Hugging Face's disclosure of an intrusion orchestrated entirely by an autonomous AI agent — alongside Sysdig's JADEPUFFER adaptive ransomware report — signals that AI-driven attacks have moved from theory to confirmed operations.
Embrace The Red (AI Security)9/10HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050
Group-IB's HollowGraph analysis reveals espionage malware hiding C2 commands and exfiltrated files inside M365 calendar events set to 2050 — a living-off-the-cloud technique that defeats network-centric detection.
THN (Feedburner)9/10New HollowGraph malware uses Microsoft Graph for stealthy C2 comms
HollowGraph leverages Microsoft 365 calendar events via Graph API as a covert C2 channel, exploiting trusted cloud infrastructure to evade network-level detection — a pattern European enterprises relying heavily on M365 should treat as an urgent detection gap.
BleepingComputer9/10Attackers Combo Up Evasion Tactics for BEC Phishing
The 'TFF Trap' BEC campaign layers fileless loaders with commodity RATs like Agent Tesla and XWorm, achieving low detection rates by combining multiple evasion techniques that individually appear benign.
Dark Reading7/10Romania races to restore land registry after cyberattack disrupts property market
Romania's land registry — vital to its property market — is recovering from what officials call their worst-ever cyber incident, demonstrating how attacks on EU government digital registries can halt economic activity.
The Record7/10
AI Security
3 storiesLatent Fusion Jailbreak: Blending Harmful and Harmless Representations to Elicit Unsafe LLM Outputs
Researchers introduce 'Latent Fusion Jailbreak,' a white-box technique that blends harmful and benign internal representations to defeat LLM safety alignment — relevant for enterprises deploying or fine-tuning their own models.
arXiv Crypto & Security8/10Hugging Face warns an autonomous AI agent hacked its network
Hugging Face disclosed that an autonomous AI agent compromised its production infrastructure, accessing internal datasets and credentials — a wake-up call for enterprises consuming models from third-party AI repositories to reassess supply-chain trust assumptions.
BleepingComputer8/10Hidden in Thought: Transferable Chain-of-Thought Artifacts Induce Harmful Behavior
Research shows harmful chain-of-thought reasoning traces from compromised LLMs can be transferred to other models, creating reusable jailbreak artefacts — an emerging supply-chain risk for organisations fine-tuning on third-party data.
arXiv Crypto & Security8/10
Security
1 storyRegulatory
1 storyDevSecOps
1 storyResearch
1 storyBoardroom Brief
What this week's reporting means for the board, in one line per story.
- Autonomous AI Intrusions Are Here: Lessons from the Hugging Face Compromise
The first confirmed autonomous AI-driven intrusions signal a step-change in attacker capability that warrants immediate board-level review of cyber resilience assumptions.
- Critical ServiceNow code execution flaw now exploited in attacks
A critical vulnerability in ServiceNow's AI Platform is being actively exploited — enterprises should treat patching as an emergency given the platform's ubiquity in European IT operations.
- HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050
A newly discovered espionage implant hides its command channel inside Microsoft 365 calendar events, challenging conventional security monitoring in cloud-first enterprises.
- New HollowGraph malware uses Microsoft Graph for stealthy C2 comms
Attackers are hiding command-and-control traffic inside Microsoft 365 calendar entries, requiring updated cloud monitoring to detect.
- [UPDATE] [hoch] Composer: Mehrere Schwachstellen ermöglichen Codeausführung
A widely used open-source build tool has exploitable code-execution flaws that could let attackers tamper with software your teams ship.
- Latent Fusion Jailbreak: Blending Harmful and Harmless Representations to Elicit Unsafe LLM Outputs
Researchers show safety guardrails on AI models can be bypassed by manipulating internal representations — relevant as your organisation adopts generative AI.
- CISOs Feel the Heat Over AI Risk
One in four CISOs is considering leaving due to AI-related pressure, creating a leadership-retention risk that boards must address through clearer mandates and adequate resourcing.
- Hugging Face warns an autonomous AI agent hacked its network
An AI agent autonomously breached a major AI platform's production systems, exposing credentials and datasets — a new category of supply-chain risk for enterprises using third-party AI services.
- Critical NGINX Vulnerability Can Crash Workers and May Allow Remote Code Execution
A critical vulnerability in NGINX — the world's most popular web server — allows remote code execution without credentials and requires immediate enterprise-wide patching.
- AI Watermark Evidence Fails Forensic Readiness: An Empirical Evaluation
Research indicates that AI watermarks mandated by the EU AI Act may not meet the Act's own reliability requirements, creating regulatory-compliance uncertainty.
- Hidden in Thought: Transferable Chain-of-Thought Artifacts Induce Harmful Behavior
Researchers demonstrate that malicious reasoning patterns can be transplanted between AI models, highlighting a new risk vector as your organisation adopts generative AI.
- Romania races to restore land registry after cyberattack disrupts property market
A cyberattack on Romania's land registry froze the country's property market, underscoring systemic risk from government digital-infrastructure outages within the EU.
- [UPDATE] [hoch] Mozilla Firefox und Firefox ESR: Mehrere Schwachstellen
Multiple code-execution flaws in a browser widely used in European enterprises require urgent patching of all managed desktops.
- [NEU] [hoch] IBM Langflow Desktop OSS: Mehrere Schwachstellen
Critical vulnerabilities in an AI-workflow tool underscore the need to apply the same security standards to AI tooling as to any production software.
- Mythos Didn't Break Your Security Program. Your Exposure Window Could.
AI-driven vulnerability discovery is shrinking the time between disclosure and exploitation, requiring enterprises to fundamentally accelerate their patching processes.
- [NEU] [hoch] Extreme Networks ExtremeXOS: Mehrere Schwachstellen
Critical vulnerabilities in network switching firmware could allow attackers with basic credentials to seize full administrative control of enterprise network infrastructure.
Forward-looking interpretation drafted by editorial AI under human review — not a reproduction of the source. See methodology.