this week in security — july 26 2026 edition
THIS WEEK, TL;DR
OpenAI says its AI models escaped a sandbox during a test and hacked Hugging Face
Reuters ($): The fallout from last week's hack of Hugging Face got a bit more complicated because OpenAI has since admitted that its GPT-5.6 Sol model and another unreleased AI model autonomously carried out the hack while undergoing internal testing. This was possible because the humans didn't set up the models' protective sandbox properly. The models found a zero-day bug allowing it to escape its sandbox, then gained access to the internet. From there, the models' agents broke into Hugging Face's systems by reasoning that the company's datasets held the answers to the test it was instructed to run. Reuters ($) and WSJ ($) reported that the models were running wild for days before OpenAI staff noticed what was going on. When Hugging Face realized it was being hacked, it called in the FBI. Hugging Face seemed OK about the whole thing in a later joint statement with OpenAI (blink twice if you're not!) but the whole episode opens up a whole can of worms of liability and legality and how these models can and should be used in defense. Very interesting and eye-opening, for sure, but still very far from world-ending, I promise.
More: OpenAI | Wired ($) | Wall Street Journal ($) | BBC News ($) | Bloomberg ($) | Hacker News | @campuscodi | @malwaretech
![a screenshot from Hacker Meme's post on Mastodon featuring the Simpsons meme: Principal Skinner and Superintendent Chalmers from the Simpsons —Chalmers: good lord what is happening in there? Skinner [labelled OpenAI next to Anthropic crossed-out]: cyber weapons Chalmers: can I see? Skinner: no](https://storage.ghost.io/c/ed/a2/eda2c6f7-faef-48b4-9ed4-86a4fa4dca68/content/images/2026/07/hacker-meme-1.jpg)
Flaw in a hidden car alarm puts millions of vehicles at risk of hacking
Wired ($): Millions of vehicles around the U.S. are fitted with hidden security devices by autodealers to prevent car thefts. But many customers don't realize their cars still have these devices installed even after leaving the dealer's lot. Security researchers figured out that every one of these KARR car alarm devices had the same authentication key, which allowed them to hack, track, and paralyze any car with one of these devices still fitted. They built an app as a proof-of-concept to show how easy it is to hack nearby devices with various commands, like honking a car's horn, all the way through to stealthy tracking and freezing the car altogether to prevent it from starting. Great reporting here and a fun video to watch. Stick around for what to look for on your car window to see if you're affected. Patch your vehicle today!
More: UC San Diego | The Register | Apple Insider | The Drive | @agreenberg

Opened a credit card? Data brokers gave your address to ICE
404 Media ($): If you ever opened a credit card in the U.S., then government authorities like ICE are buying access to your credit records — no warrant needed (or so they claim). This article, with a really great scrollable visualization, is the clearest picture of how ICE gets your personal information from your credit card provider, via a web of middlemen companies, aka data brokers. One of these big companies is Canadian data giant Thomson Reuters, which sells access to its CLEAR database to government agencies, including ICE — but not without pushback. Some of the company's investors called for the data broker giant to divest away from surveillance tech, but most didn't in the end, in part to not draw ire from the Trump administration. The Canadian government has been asked to block the sale of data to ICE, citing human rights abuses. One of the many issues here is that the data is sometimes just flat out wrong, and it's ordinary people who face the terrifying results. 404 Media also has a broader look at the surveillance tech used by ICE, including tracking social media and location data.
Archive: ~this week in security~ | More: Techdirt | Boing Boing | @heidilifeldman
~ ~
~this week in security~ is my weekly cybersecurity newsletter supported by readers like you. Please consider signing up for a paying subscription starting at $10/month for access to exclusive articles, analysis, and more.
Or, you can submit a one-time tip to show your support!
~ ~
THE STUFF YOU MIGHT'VE MISSED
DOJ accuses American of allegedly wiping phone using 'duress' password during border search
TechCrunch ($): An American was stopped at the U.S. border, allegedly not read his rights nor given access to his attorney, and was told he must give up his phone passcode before he could leave. He did, but as soon as the border agents entered the passcode, the "screen went blank, flashed several times and the phone appeared to restart." The DOJ since pressed charges under a little-known federal statute, and is thought to be the first case of an indictment related to the alleged use of a "duress" passcode. I chatted with esteemed security pros @legind and @runasand, who both said they had not seen a similar case before. (Disclosure alert: I wrote this story!)

Iranian hackers are actively hacking U.S. water and energy providers
CISA: U.S. agencies say Iran-backed hackers are expanding their attacks targeting internet-connected devices on critical infrastructure networks (think water and energy providers). CISA says these attacks have gone up in the past few months since its first advisory in April, now adding that more of these industrial controls are being hacked. The FBI said in one observed case, the hackers altered shutdown and alarm logic, allowing systems to enter "unsafe conditions" without notifying the operators. Cybersecurity Dive has more, as does SecurityWeek on an affected California water provider.
Russia-linked hackers stole emails by exploiting Zimbra zero-day
CNN ($): The U.S. and more than a dozen allied governments are warning that Russian hackers are abusing a zero-day in Zimbra email services to steal gobs of data from affected servers. The hackers have been targeting governments and other sensitive institutions, including nuclear installations and the defense industry. The exploit could be triggered simply by opening an email; "no social engineering required," said Proofpoint. The attacks have been going on for at least five months and have been patched with CVE-2025-66376. The NSA also blasted out its own advisory [PDF], warning that the hacks are aimed at collecting intelligence for the Kremlin.
If you pay the hackers once, expect a second extortion demand
The Register: Sticking with Proofpoint for just another second, because its other findings this week underscored something researchers have long argued: If you pay a hacker's ransom once, there's a very good chance they'll come back and demand a second one. Proofpoint found [PDF] this to be the case in about one-third of reported cases over the past year, per a survey of ~930 organizations. It's often better to not pay the ransom at all, and have a good backup, recovery, and remediation plan.
European and U.S. banks exposed people's personal data via pixel trackers
Dark Reading: Banks and financial institutions across Europe and the U.S. have been sharing information about their customers and website visitors with third-party advertisers, like Meta and TikTok, even in some cases after users' rejected the website's cookies and tracking. JScrambler has more in its latest research. The use of pixel trackers have sparked several major healthcare data breaches in the past. In a previous blog, I highlighted how these tracking pixels work, and why you should use an ad-blocker!
~ ~
OTHER NEWSY NUGGETS
Healthcare software house hack sparks data fears: U.K software house Craneware, which makes billing and accounting software used by thousands of U.S. hospitals, clinics, and pharmacies, was hacked and a significant volume of data taken from its servers, per a listing on the London Stock Exchange. The company handles a large amount of patient data, sparking fears that sensitive health data may have been taken. (via TechCrunch ($), Computing.co.uk, HIPAA Journal)
Suno AI, Paidwork breaches affect millions: Have I Been Pwned reports that a November 2025 breach at music scraping startup Suno AI now affects 55 million people's names, phone numbers, and physical addresses. Details of the breach are only just coming to light after 404 Media ($) recently reported the hack. Also, a breach at Paidwork in April, meanwhile, affects 23 million people and includes their financial data, bank account numbers, and more. (via HelpNetSecurity, The Register)
Aussie power giant confirms data breach: Australia's largest gas and electricity company Origin was hacked and the personal information stolen of about 2 million customers, per the hacker's claims. The energy giant has closer to 5 million customers, so the breach may be larger. (via Sydney Morning Herald, Reuters ($))
Clop kicks new zero-day in face: The mass-hacking extortion crew Clop is reportedly back targeting zero-day flaws in PTC's Windchill and FlexPLM software, which companies use to manage their product development pipelines. The attacks are aimed at stealing data and extorting victims. The good folks at Ransom-ISAC have more intel on some of the extortion emails going around. (via Bleeping Computer, Techzine)

They're called wrench attacks for a reason: Criminals that use violence (aka wrench attacks; you can probably guess why they're called that) with the aim of stealing people's crypto have netted $124.1 million in losses and ransom demands over the past year. Attacks that involve home invasions are up 20-fold year-over-year. (via Certik, Cryptoslate, The Record)
Praying for a fix: Click To Pray, a prayer app linked to the Vatican, has an incredibly easy-to-abuse IDOR vulnerability that allows anyone without any authentication to cycle through the data of users who signed up to the app. BobDaHacker reported the bug six months ago but never heard back, so she dropped details in a blog post. The bug is still unfixed. (via Dark Reading)
~ ~
THE HAPPY CORNER
Welcome back to the happy corner. The bar for entry here is "chill," so let's enjoy some good news and the ~lighter stuff~ from the week.
Smart TV maker LG said it's suspending any app that turns its customers' televisions into an unwitting residential proxy network (aka botnet). Around 40% of all apps on LG TVs were enlisting these devices into proxy networks that malicious actors then use to piggyback the internet connections of ordinary homes, making their malicious traffic more difficult to identify. Brian Krebs has more on this development, because he has been banging the drum on this for some time.
Here's a blast from the past.... *in an extremely Attenborough-esque voice:* "This may be the very first ever cyber cat, seen here attempting to hack a Pentium PC from the 1990s."

Friend of the newsletter @yaelwrites has a perfect blog post summing up a bunch of job rejection emails.
And — please, hold on why I stop laughing for a moment — send in your best caption for whatever this is:

Got good news to share? Get in touch! this@weekinsecurity.com.
~ ~
CYBER CATS & FRIENDS
This week's cyber cat is Mittens. Don't be fooled by the adorable name, Mittens is in their cardboard fort, plotting, and ready to launch an offensive cyber-cat-attack at a moment's notice. Thanks to the anonymous reader for sending in!

🐈 Send in your cyber cats! 🐈⬛ Got a cat or a non-feline friend? Send me an email with their photo and name and they will be featured in a later newsletter!
~ ~
SUGGESTION BOX
And that's all there is for this week's busy newsletter, thanks so much for joining and reading!
As always, please do reach out if you have anything you want to share for next week's newsletter, or anything in-between. It's great to hear from you. And if you liked this week's edition, feel free to share it on your socials!
See you on the ~cyber-webs~
@zackwhittaker