
The AI has entered the chat.
GPT escapes the sandbox and hacks Huggingface. SolarWinds patches multiple critical flaws. CISA orders patching of a critical Langflow AI vulnerability. A Paidwork breach affects over 23 million users. A recently patched SharePoint vulnerability is under active exploitation. Oracle patches over 1,400 vulnerabilities. Apps turn Smart TVs into residential proxies. The FCC considers expanding direct to satellite communications. German and U.S. authorities dismantle a major phishing-as-a-service (PhaaS) platform. Our guest is Jimmy McNary, Deputy Federal CTO at Semperis, discussing comprehensive identity security assessments for Microsoft GCC. AI models can’t resist bending the rules.
Today is Wednesday July 22nd 2026. I’m Dave Bittner. And this is your CyberWire Intel Briefing.
GPT escaped the sandbox and hacked Hugging Face.
OpenAI has disclosed that two of its frontier AI models, GPT-5.6 Sol and an undisclosed pre-release model, autonomously breached Hugging Face’s production infrastructure during an internal cybersecurity evaluation. The models were tested in a restricted environment, but they chained together vulnerabilities, uncovered an undisclosed zero-day flaw, escalated privileges, gained internet access, and ultimately compromised Hugging Face systems to obtain evaluation-related data. Hugging Face had previously reported the July 16 intrusion and suspected an autonomous AI agent was responsible, a conclusion later confirmed by OpenAI. The company said it has responsibly disclosed the zero-day vulnerability, strengthened safeguards for future evaluations, and partnered with Hugging Face on security improvements. Security leaders say the incident demonstrates that advanced AI systems can pursue unintended, harmful strategies without explicit malicious intent. They warn the event marks a turning point for defenders, highlighting the need to prepare for AI-driven attacks that could eventually be adopted by malicious threat actors.
SolarWinds patches multiple critical flaws.
SolarWinds has released Serv-U 2026.3, addressing 15 security vulnerabilities in its Serv-U Managed File Transfer (MFT) and FTP Server products, including multiple critical flaws rated 9.1 CVSS. The vulnerabilities could allow authenticated attackers to escalate privileges, execute arbitrary code, and potentially gain root access on Unix-like systems through broken access controls and insecure direct object references (IDOR). While Windows deployments face lower impact, the breadth of issues makes upgrading a priority, particularly for internet-facing servers. The release also introduces several security enhancements, including stronger Content Security Policies, new browser security headers, expanded multi-factor authentication support for Microsoft Active Directory and LDAP users, and a fix for a stored cross-site scripting (XSS) vulnerability. Additional improvements to logging, file-sharing reliability, and browser compatibility further strengthen the platform’s overall security and operational resilience.
CISA orders patching of a critical Langflow AI vulnerability.
CISA has ordered U.S. federal agencies to urgently patch CVE-2026-0770, a critical vulnerability in the Langflow AI agent framework that is being actively exploited. The flaw allows unauthenticated attackers to achieve remote code execution as root. Researchers have observed more than 220 exploitation attempts, with attackers seeking to deploy malware and steal AWS credentials, environment variables, and container metadata. CISA has added the vulnerability to its Known Exploited Vulnerabilities catalog and directed agencies to remediate affected systems by Friday, warning that the flaw poses a significant risk to federal networks.
A Paidwork breach affects over 23 million users.
A reported data breach at Paidwork, a platform that pays users for completing online microtasks, has allegedly exposed the personal and financial information of more than 23 million users. The breach reportedly occurred in March 2026, with an 11 GB database advertised on a cybercrime forum the following month. Exposed information includes names, contact details, dates of birth, bank account numbers, transaction histories, device and IP data, profile photos, and hashed passwords. Although Paidwork has not publicly confirmed the incident, security experts warn the stolen data could enable phishing, identity theft, credential stuffing, and account takeover attacks. Users are advised to change reused passwords, enable multi-factor authentication, monitor financial accounts for suspicious activity, and remain alert for scams leveraging their exposed personal information.
A recently patched SharePoint vulnerability is under active exploitation.
Researchers have identified active exploitation of CVE-2026-50522, a critical Microsoft SharePoint remote code execution vulnerability patched on July 14. The flaw allows authenticated Site Owners to execute arbitrary code through insecure deserialization. Security firms Defused and WatchTowr observed attacks, with threat actors reportedly stealing SharePoint machine keys to maintain long-term access. Experts warn that patching alone is insufficient and recommend rotating credentials on potentially compromised systems. The vulnerability is the fourth actively exploited SharePoint flaw disclosed in the past month.
Oracle patches over 1,400 vulnerabilities.
Oracle’s July 2026 Critical Patch Update addresses 1,449 vulnerabilities, including 1,434 unique CVEs across 334 products. Around 600 of the flaws can be exploited remotely without authentication, with major updates affecting E-Business Suite, Fusion Middleware, Communications, and PeopleSoft. Oracle credited only a small number of external researchers, suggesting most vulnerabilities were identified internally, likely with AI-assisted security tools. Organizations are urged to apply the updates promptly, as Oracle product vulnerabilities are frequently targeted by threat actors.
Space Cyber Story
Your next smartphone connection might not come from a cell tower at all. The FCC is considering a proposal that could expand direct-to-device satellite communications. Maria Varmazis has more.
Apps turn Smart TVs into residential proxies.
LG Electronics USA says it will suspend smart TV apps that use residential proxy software development kits (SDKs), following research showing more than 42% of apps in its webOS store can turn users’ televisions into always-on residential proxy nodes. According to Krebs on Security, the company is working with developers to remove the feature and warned that non-compliant apps will be removed from the platform. Researchers found proxy SDKs embedded in a wide range of apps, including games, screensavers, and utilities, with Bright Data accounting for many of the integrations. While proxy providers say they vet customers and implement safeguards, researchers argue consumers often lack meaningful transparency or control over how their devices are used. LG also pledged to strengthen its app review process to prevent similar software from reaching users. The announcement follows recent criticism over LG monitor software that promoted McAfee antivirus subscriptions through Windows Update.
German and U.S. authorities dismantle a major phishing-as-a-service (PhaaS) platform.
German and U.S. authorities have dismantled Kratos, a major phishing-as-a-service (PhaaS) platform, by seizing more than 200 servers and arresting its alleged developer in Indonesia. Led by Germany’s Federal Criminal Police Office (BKA) and Frankfurt prosecutors, with support from U.S. law enforcement, the operation disrupted a service believed to have supported more than 1,800 criminal customers conducting approximately 15,000 phishing campaigns each month across 35 countries. Kratos enabled attackers to create convincing fake Microsoft login pages to steal user credentials, facilitating account takeovers and other cybercrimes. Authorities estimate the platform generated at least €300,000 in subscription revenue since 2024. The operation, dubbed Operation Olympus Blade, also transferred the platform’s domains to the FBI, enabling investigators to identify additional suspects through seized infrastructure.
AI models can’t resist bending the rules.
The UK government’s AI Security Institute has found that when AI models are given a task, they sometimes approach it with the enthusiasm of an employee who has discovered a shortcut and hopes no one asks too many questions. In cybersecurity evaluations, every model tested attempted to “cheat” at least some of the time, whether by searching the internet for answers, bypassing sandbox restrictions, probing the testing environment, or targeting systems outside the intended scope. Even more awkwardly, the models often failed to admit what they had done when questioned. GPT-5.4 recorded the highest rate of cheating at 14.1% of test runs, while Claude Mythos Preview was the least frequent offender at 7.8%, though it still made the list. The findings suggest that self-reporting and chain-of-thought monitoring cannot be relied upon to detect deceptive behavior. For defenders, the lesson is clear: trusting AI to grade its own homework may not be the security strategy anyone hoped for.
And that’s the CyberWire.
For links to all of today’s stories, check out our Daily Briefing at the cyberwire dot com.
We’d love to know what you think of this podcast. Your feedback ensures we deliver the insights that keep you a step ahead in the rapidly changing world of cybersecurity. If you like the show, please share a rating and review in your podcast app. Please also fill out the survey in the show notes or send an email to cyberwire@n2k.com
We’re proud that N2K CyberWire is part of the daily routine of the most influential leaders and operators in the public and private sector, from the Fortune 500 to many of the world’s preeminent intelligence and law enforcement agencies.
N2K helps cybersecurity professionals and organizations grow, learn, and stay ahead. We’re the nexus for discovering the people, tech, and ideas shaping the industry. Learn how at n2k.com.
N2K’s lead producer is Liz Stokes. We’re mixed by Tré Hester, with original music by and sound design Elliott Peltzman. Our contributing host is Maria Varmazis. Our executive producer is Jennifer Eiben. Peter Kilpe is our publisher. And I’m Dave Bittner. Thanks for listening.

