An autonomous AI agent uncovered 21 previously unknown vulnerabilities in FFmpeg, a ubiquitous media library embedded across countless apps and devices—highlighting both the growing role of AI in vulnerability research and the systemic risk in common media stacks. In the same week, Google released Chrome 149 with patches for 429 security issues, the most ever in a single browser update. Security teams should prioritize patching FFmpeg dependencies and fast-track Chrome updates across fleets.
Source: TheHackerNews
CISA Adds Actively Exploited SolarWinds Serv-U DoS Bug to KEV
CISA added CVE-2026-28318, a high-severity denial-of-service flaw in SolarWinds Serv-U file transfer software, to its Known Exploited Vulnerabilities catalog, citing evidence of active exploitation. Inclusion in KEV signals immediate patching priority for federal agencies and a strong warning to all organizations relying on Serv-U to mitigate service disruption risk.
Source: TheHackerNews
New “Pink Extortion” Group Uses Vishing to Breach Microsoft 365 and Exfiltrate Cloud Data
Researchers warn of a threat actor dubbed Pink Extortion that uses voice phishing to socially engineer help desks and bypass MFA, then raids Microsoft 365 environments for sensitive files. The group reportedly leverages stolen data for extortion, underscoring the need for hardened help-desk procedures, phishing-resistant MFA (e.g., FIDO2), and conditional access monitoring.
Source: HackRead
Claude Opus Helps Uncover Four-Year-Old Flaw in Zcash Privacy Pool
Security researcher Taylor Hornby, aided by Claude Opus 4.8, identified a critical vulnerability in Zcash’s Orchard pool that could have enabled undetectable creation of counterfeit coins. The bug went unnoticed for years, raising tough questions about the assurance of complex privacy systems and the accelerating role of AI in cryptographic reviews; it’s unclear if the flaw was ever exploited in the wild.
Source: Security Affairs
OpenAI Rolls Out ChatGPT “Lockdown Mode” to Thwart Prompt-Injection Data Exfiltration
OpenAI introduced a new Lockdown Mode for ChatGPT that restricts tools capable of exfiltrating data, aiming to reduce risks from prompt-injection attacks. Available to logged-in users across Free, Go, Plus, and Pro tiers, the feature targets individuals and organizations handling sensitive information, though it does not eliminate all injection pathways.
Source: TheHackerNews
Research: Consumer Apps Turn Smart TVs and Phones into Residential Proxies for AI Web Scraping
A researcher reverse-engineered Bright Data’s embedded iOS SDK and found it can convert consumer devices—including always-on smart TVs—into exit nodes for web-scraping traffic sold to AI customers. The practice raises privacy, bandwidth, and corporate policy concerns, especially for organizations with BYOD or unmanaged IoT on corporate or home-office networks.
Source: TheHackerNews
Report: Anthropic Engineers Embedded at NSA to Support Offensive Use of “Mythos” AI
According to reports, Anthropic has deployed around six engineers inside the NSA to help the agency operationalize Mythos, its restricted AI model with advanced cybersecurity capabilities. The move spotlights the rapid convergence of private AI vendors with national security missions and renews debates over oversight, transparency, and the boundaries of offensive cyber-AI use.
Source: Security Affairs
You May Also Be Interested In...
Oxford Uni student data pwned again—this time via career platform breach
The Clock Is Already Ticking: Why Post-Quantum Cryptography Can’t Wait
Belgian banks must reimburse phishing victims as soon as they report a loss, judge says