❌

Normal view

Wikimedia Says OpenAI Agents Tried to Compromise Etherpad and Use Wiki Tools as Proxies

6 October 2026 at 11:26
The Wikimedia Foundation, which hosts Wikipedia, has confirmed that it has discovered activity by rogue OpenAI agents on its platforms, including unsuccessful efforts to compromise Etherpad, a public note-taking tool, and edit Wikipedia pages. "The unauthorized bot activities included edits to our wikis, some unsuccessful attempts to exploit a public note-taking tool we host, and heavy traffic,

Welcome to the Jungle: What We Found Inside 15,465 Public MCP Servers

6 October 2026 at 11:02
In 2024, MCP (Model Context Protocol) set out to become the USB-C of AI: one standard for connecting models, agents, and IDEs to tools and data. The protocol delivered. Thousands of developers built servers, and enterprises plugged them into agent workflows. The ecosystem around it fell short. Earlier this year, our team at OX Security,Β  traced critical vulnerabilities in Anthropic's MCP

Google Pauses OSS Product Bug Bounty Rewards After Surge in Invalid Automated Reports

6 October 2026 at 09:21
Google has stopped accepting product vulnerability reports through its bug bounty program for its open-source software. The change, in effect since October 1, means researchers can no longer submit security flaws in the code of projects such as Go, Angular, and Protocol Buffers there for a reward. Reports about supply chain compromises are still accepted, and reports filed before October 1 are

Critical Atlassian Flaw Lets Unauthenticated Attackers Read Known Files Across 8 Products

6 October 2026 at 06:58
A critical flaw in 8 Atlassian Data Center products, which customers host themselves, allows an attacker with no login access to read specific files in each product's web application root directory. The attacker must already know a file's exact name and path and cannot list what the directory holds. AtlassianΒ disclosed the flaw, CVE-2026-21589, on October 5, rated it 9.3 out of 10, and

FBI Removes Accenture Contractor After Patch Failure Led to ShinyHunters Breach

6 October 2026 at 06:56
The U.S. Federal Bureau of Investigation (FBI) has removed an Accenture contractor for their alleged role in a ShinyHunters-breach that led to the theft of personal details of thousands of bureau employees. That's according to a report from Reuters, citing two sources familiar with the matter. "To date, our review has determined that the incident occurred as the result of a security failure ​

Denmark Says Attackers Accessed CPR Data for 8.8 Million People via Company Account

6 October 2026 at 06:00
Unauthorized parties have gained access to the names, addresses, and personal identification numbers of about 8.8 million people, living and dead, in Denmark's national population register, the country's digitalization ministryΒ said on October 5. They used a private Danish company's lawful right to look up records in the Central Person Register (CPR). The ministry has told people never to

ClickFix Smuggles Payloads Through Browser Cache to Bypass Windows Run Limits

6 October 2026 at 05:22
A new type of ClickFix attack is using compromised websites to trick users into executing a malicious payload cached in a web browser's cache. "Instead of downloading and executing remote payloads like the typical attack pattern, in this attack, the websites pre-fetch a script payload into the browser cache disguised as a PNG file," the Microsoft Threat Intelligence team said in a post on X.

❌