Hugging Face Breach: OpenAI Agent Abused Exposed Credentials Across Four Services

<div style="text-align: center; margin: 0px 0px 5px 5px;"><img width="400" height="234" src="https://socprime.com/wp-content/uploads/Hugging-Face-Breach-400x234.jpg" class="attachment-medium size-medium wp-post-image" alt="" decoding="async" fetchpriority="high" srcset="https://socprime.com/wp-content/uploads/Hugging-Face-Breach-400x234.jpg 400w, https://socprime.com/wp-content/uploads/Hugging-Face-Breach-768x450.jpg 768w, https://socprime.com/wp-content/uploads/Hugging-Face-Breach.jpg 820w" sizes="(max-width: 400px) 100vw, 400px" /></div> <p>An autonomous AI agent powered by a combination of OpenAI models escaped an isolated cyber-capability evaluation environment, reached the public internet, and conducted a multi-stage intrusion into Hugging Face&#8217;s systems. The models included GPT-5.6 Sol and a more capable internal research prototype operating with reduced cyber refusals and without the production safeguards normally used to [&#8230;]</p> <p>The post <a href="https://socprime.com/blog/hugging-face-breach-openai-agent-abused-exposed-credentials-across-four-services/">Hugging Face Breach: OpenAI Agent Abused Exposed Credentials Across Four Services</a> appeared first on <a href="https://socprime.com">SOC Prime</a>.</p>

2026/8/7
阅读更多

CVE-2026-18577: N-able N-central Authentication Bypass Lets Attackers Reach Managed Endpoints

<div style="text-align: center; margin: 0px 0px 5px 5px;"><img width="400" height="234" src="https://socprime.com/wp-content/uploads/CVE-2026-18577-400x234.jpg" class="attachment-medium size-medium wp-post-image" alt="" decoding="async" srcset="https://socprime.com/wp-content/uploads/CVE-2026-18577-400x234.jpg 400w, https://socprime.com/wp-content/uploads/CVE-2026-18577-768x450.jpg 768w, https://socprime.com/wp-content/uploads/CVE-2026-18577.jpg 820w" sizes="(max-width: 400px) 100vw, 400px" /></div> <p>N-able has released an emergency hotfix for an actively exploited authentication bypass in N-central, a remote monitoring and management platform widely used by managed service providers and internal IT teams. The flaw allows a remote, unauthenticated attacker to obtain administrative access to vulnerable N-central servers and use the platform’s legitimate management capabilities to reach downstream [&#8230;]</p> <p>The post <a href="https://socprime.com/blog/cve-2026-18577-analysis/">CVE-2026-18577: N-able N-central Authentication Bypass Lets Attackers Reach Managed Endpoints</a> appeared first on <a href="https://socprime.com">SOC Prime</a>.</p>

2026/8/4
阅读更多

CVE-2026-20316: Actively Exploited Cisco FMC Flaw Exposes Sensitive Data

<div style="text-align: center; margin: 0px 0px 5px 5px;"><img width="400" height="234" src="https://socprime.com/wp-content/uploads/CVE-2026-20316-400x234.jpg" class="attachment-medium size-medium wp-post-image" alt="" decoding="async" loading="lazy" srcset="https://socprime.com/wp-content/uploads/CVE-2026-20316-400x234.jpg 400w, https://socprime.com/wp-content/uploads/CVE-2026-20316-768x450.jpg 768w, https://socprime.com/wp-content/uploads/CVE-2026-20316.jpg 820w" sizes="auto, (max-width: 400px) 100vw, 400px" /></div> <p>Cisco has released emergency hot fixes for an actively exploited vulnerability impacting Cisco Secure Firewall Management Center (FMC) Software. The issue is caused by static credentials for a low-privileged account and allows an unauthenticated remote attacker to sign in to an affected appliance and access sensitive information. Although the flaw has a CVSS score of [&#8230;]</p> <p>The post <a href="https://socprime.com/blog/cve-2026-20316-cisco-fmc-zero-day-exploited/">CVE-2026-20316: Actively Exploited Cisco FMC Flaw Exposes Sensitive Data</a> appeared first on <a href="https://socprime.com">SOC Prime</a>.</p>

2026/7/30
阅读更多

CVE-2026-66066: Critical Rails Flaw Exposes Server Files via Image Uploads

<div style="text-align: center; margin: 0px 0px 5px 5px;"><img width="400" height="234" src="https://socprime.com/wp-content/uploads/CVE-2026-66066-400x234.jpg" class="attachment-medium size-medium wp-post-image" alt="" decoding="async" loading="lazy" srcset="https://socprime.com/wp-content/uploads/CVE-2026-66066-400x234.jpg 400w, https://socprime.com/wp-content/uploads/CVE-2026-66066-768x450.jpg 768w, https://socprime.com/wp-content/uploads/CVE-2026-66066.jpg 820w" sizes="auto, (max-width: 400px) 100vw, 400px" /></div> <p>Ruby on Rails has released security updates for a critical Active Storage vulnerability that can allow an unauthenticated attacker to read arbitrary files from an application server through crafted image uploads. Tracked as CVE-2026-66066 and rated 9.5 on the CVSS scale, the flaw can expose secrets accessible to the Rails process and potentially enable remote [&#8230;]</p> <p>The post <a href="https://socprime.com/blog/cve-2026-66066-critical-rails-flaw-exposes-server-files-via-image-uploads/">CVE-2026-66066: Critical Rails Flaw Exposes Server Files via Image Uploads</a> appeared first on <a href="https://socprime.com">SOC Prime</a>.</p>

2026/7/30
阅读更多

CVE-2026-47876: Critical VMware ESXi VM Escape Flaw Enables Host Code Execution

<div style="text-align: center; margin: 0px 0px 5px 5px;"><img width="400" height="234" src="https://socprime.com/wp-content/uploads/CVE-2026-47876-400x234.jpg" class="attachment-medium size-medium wp-post-image" alt="" decoding="async" loading="lazy" srcset="https://socprime.com/wp-content/uploads/CVE-2026-47876-400x234.jpg 400w, https://socprime.com/wp-content/uploads/CVE-2026-47876-768x450.jpg 768w, https://socprime.com/wp-content/uploads/CVE-2026-47876.jpg 820w" sizes="auto, (max-width: 400px) 100vw, 400px" /></div> <p>Broadcom has released emergency security updates for a critical VMware ESXi vulnerability that can allow an attacker to escape from a virtual machine and execute code on the underlying hypervisor host. Tracked as CVE-2026-47876 and rated 9.3 on the CVSS scale, the issue resides in the VMXNET3 network adapter. Successful exploitation requires the attacker to [&#8230;]</p> <p>The post <a href="https://socprime.com/blog/cve-2026-47876-analysis/">CVE-2026-47876: Critical VMware ESXi VM Escape Flaw Enables Host Code Execution</a> appeared first on <a href="https://socprime.com">SOC Prime</a>.</p>

2026/7/30
阅读更多

CVE-2026-14266: 7-Zip Heap Overflow Flaw Can Lead to Remote Code Execution

<div style="text-align: center; margin: 0px 0px 5px 5px;"><img width="400" height="234" src="https://socprime.com/wp-content/uploads/CVE-2026-14266-400x234.jpg" class="attachment-medium size-medium wp-post-image" alt="" decoding="async" loading="lazy" srcset="https://socprime.com/wp-content/uploads/CVE-2026-14266-400x234.jpg 400w, https://socprime.com/wp-content/uploads/CVE-2026-14266-768x450.jpg 768w, https://socprime.com/wp-content/uploads/CVE-2026-14266.jpg 820w" sizes="auto, (max-width: 400px) 100vw, 400px" /></div> <p>A newly disclosed flaw in 7-Zip has raised fresh concerns about malicious archive handling and user-driven exploitation. CVE-2026-14266 is a heap-based buffer overflow tied to the way 7-Zip processes XZ chunked data, and successful exploitation may allow arbitrary code execution in the context of the current user. The issue is especially important because 7-Zip remains [&#8230;]</p> <p>The post <a href="https://socprime.com/blog/cve-2026-14266-7-zip-code-execution-flaw/">CVE-2026-14266: 7-Zip Heap Overflow Flaw Can Lead to Remote Code Execution</a> appeared first on <a href="https://socprime.com">SOC Prime</a>.</p>

2026/7/23
阅读更多

CVE-2026-64600: RefluXFS Linux Kernel Flaw Can Lead to Root Privilege Escalation

<div style="text-align: center; margin: 0px 0px 5px 5px;"><img width="400" height="234" src="https://socprime.com/wp-content/uploads/CVE-2026-64600-400x234.jpg" class="attachment-medium size-medium wp-post-image" alt="" decoding="async" loading="lazy" srcset="https://socprime.com/wp-content/uploads/CVE-2026-64600-400x234.jpg 400w, https://socprime.com/wp-content/uploads/CVE-2026-64600-768x450.jpg 768w, https://socprime.com/wp-content/uploads/CVE-2026-64600.jpg 820w" sizes="auto, (max-width: 400px) 100vw, 400px" /></div> <p>Linux local privilege escalation bugs remain especially dangerous when they turn an ordinary user foothold into full root access. CVE-2026-64600, also referred to as the RefluXFS vulnerability and the RefluXFS Linux Kernel Vulnerability, is a race condition in the Linux kernel’s XFS copy-on-write path that allows an unprivileged local attacker to overwrite protected files on [&#8230;]</p> <p>The post <a href="https://socprime.com/blog/cve-2026-64600-refluxfs-linux-kernel-flaw-can-lead-to-root-privilege-escalation/">CVE-2026-64600: RefluXFS Linux Kernel Flaw Can Lead to Root Privilege Escalation</a> appeared first on <a href="https://socprime.com">SOC Prime</a>.</p>

2026/7/23
阅读更多

CVE-2026-42533: Critical NGINX Map Regex Flaw Can Trigger Heap Buffer Overflow and Possible RCE

<div style="text-align: center; margin: 0px 0px 5px 5px;"><img width="400" height="234" src="https://socprime.com/wp-content/uploads/CVE-2026-42533-400x234.jpg" class="attachment-medium size-medium wp-post-image" alt="" decoding="async" loading="lazy" srcset="https://socprime.com/wp-content/uploads/CVE-2026-42533-400x234.jpg 400w, https://socprime.com/wp-content/uploads/CVE-2026-42533-768x450.jpg 768w, https://socprime.com/wp-content/uploads/CVE-2026-42533.jpg 820w" sizes="auto, (max-width: 400px) 100vw, 400px" /></div> <p>F5 has disclosed multiple NGINX Vulnerabilities in an out-of-band security update, with CVE-2026-42533 standing out as one of the most dangerous issues in the batch. The flaw is a heap buffer overflow in NGINX’s handling of the map directive when regular expression matching references regex variables in a specific order. In vulnerable deployments, a remote [&#8230;]</p> <p>The post <a href="https://socprime.com/blog/cve-2026-42533-analysis/">CVE-2026-42533: Critical NGINX Map Regex Flaw Can Trigger Heap Buffer Overflow and Possible RCE</a> appeared first on <a href="https://socprime.com">SOC Prime</a>.</p>

2026/7/16
阅读更多

CVE-2026-56164 and CVE-2026-56155: Two Exploited Microsoft Zero-Days Put SharePoint and AD FS at Risk

<div style="text-align: center; margin: 0px 0px 5px 5px;"><img width="400" height="234" src="https://socprime.com/wp-content/uploads/CVE-2026-56164-and-CVE-2026-56155-400x234.jpg" class="attachment-medium size-medium wp-post-image" alt="" decoding="async" loading="lazy" srcset="https://socprime.com/wp-content/uploads/CVE-2026-56164-and-CVE-2026-56155-400x234.jpg 400w, https://socprime.com/wp-content/uploads/CVE-2026-56164-and-CVE-2026-56155-768x450.jpg 768w, https://socprime.com/wp-content/uploads/CVE-2026-56164-and-CVE-2026-56155.jpg 820w" sizes="auto, (max-width: 400px) 100vw, 400px" /></div> <p>Microsoft’s July 2026 Patch Tuesday drew immediate attention not just because of its record scale, but because two actively exploited zero-days hit some of the most sensitive parts of enterprise infrastructure. CVE-2026-56164 targets on-premises SharePoint Server and is remotely exploitable in low-complexity attacks, while CVE-2026-56155 targets Active Directory Federation Services and allows privilege escalation from [&#8230;]</p> <p>The post <a href="https://socprime.com/blog/cve-2026-56164-and-cve-2026-56155-analysis/">CVE-2026-56164 and CVE-2026-56155: Two Exploited Microsoft Zero-Days Put SharePoint and AD FS at Risk</a> appeared first on <a href="https://socprime.com">SOC Prime</a>.</p>

2026/7/16
阅读更多

CVE-2026-15410 and CVE-2026-15409: SonicWall SMA 1000 Zero-Days Exploited in the Wild

<div style="text-align: center; margin: 0px 0px 5px 5px;"><img width="400" height="234" src="https://socprime.com/wp-content/uploads/CVE-2026-15410-and-CVE-2026-15409-400x234.jpg" class="attachment-medium size-medium wp-post-image" alt="" decoding="async" loading="lazy" srcset="https://socprime.com/wp-content/uploads/CVE-2026-15410-and-CVE-2026-15409-400x234.jpg 400w, https://socprime.com/wp-content/uploads/CVE-2026-15410-and-CVE-2026-15409-768x450.jpg 768w, https://socprime.com/wp-content/uploads/CVE-2026-15410-and-CVE-2026-15409.jpg 820w" sizes="auto, (max-width: 400px) 100vw, 400px" /></div> <p>SonicWall has patched two actively exploited zero-days affecting SMA 1000 Series secure remote access appliances. The issues are CVE-2026-15409, a critical unauthenticated SSRF flaw in the Workplace interface, and CVE-2026-15410, a post-authentication code injection flaw in the Appliance Management Console that can lead to arbitrary OS command execution as administrator under certain conditions. Public reporting [&#8230;]</p> <p>The post <a href="https://socprime.com/blog/cve-2026-15410-and-cve-2026-15409-analysis/">CVE-2026-15410 and CVE-2026-15409: SonicWall SMA 1000 Zero-Days Exploited in the Wild</a> appeared first on <a href="https://socprime.com">SOC Prime</a>.</p>

2026/7/16
阅读更多