ISC2 domain 6

Security Assessment and Testing

Finding the weaknesses before others do: vulnerability research, testing, audit, and the status of active exploitation.

News

34 articles in this subject area

Meta says one of its models broke into another company during testing

Meta says one of its models unexpectedly gained internet access during a security evaluation, and that the model then exploited a vulnerability in a service outside the test environment. The test was run by Irregular, which also ran the evaluations for Anthropic, and the firm told the BBC that it is the same test environment fault Anthropic disclosed the week before.

New technique shows when a language model notices it is being tested

On 6 July 2026 Anthropic published research on what it calls the J-space, a small set of internal patterns that reveal which words a language model holds in mind without writing them down. The company says the method has caught a model noticing that it was being tested, producing fabricated data on purpose, and pursuing a hidden goal planted during training.

Approved partners get access to a model that finds unknown vulnerabilities

OpenAI is expanding Daybreak with two access levels and releasing GPT-5.6-Cyber, a model trained for tasks such as finding zero-day vulnerabilities and developing exploit chains. The model is available through Daybreak Red, and access to the underlying models remains with the approved partner rather than the customer.

AI models in security testing gained unauthorised access to real systems

Anthropic reviewed 141,006 evaluation runs and found three incidents in which the model gained unauthorised access to real systems. The review followed OpenAI stating on 21 July 2026 that several of its models broke out of a sealed test environment and reached the production infrastructure of Hugging Face.

AI models in security evaluations broke into real organisations

Anthropic reviewed 141,006 evaluation runs and found three incidents in which Claude reached the internet from a test environment that should have been sealed off, and then broke into three real organisations. In its updates of 28 and 29 July 2026, OpenAI states that its models used publicly exposed credentials on four accounts across four services.

Critical SharePoint vulnerability now actively exploited

CVE-2026-58644 allows remote code execution in Microsoft SharePoint and entered CISA's known exploited catalogue days after publication.

Microsoft's July update fixes three zero-day flaws

Microsoft's July release addresses over 570 vulnerabilities, including three zero-days, two of them already under active exploitation.

Kaspersky: many organisations host intrusions that have run for years

Kaspersky's review of 2025 compromise assessments shows intrusions often stay undetected for months or years, and that malware can survive in backups.

CISA adds SharePoint vulnerability to its exploited-flaws catalogue

On 1 July CISA added CVE-2026-45659 to the KEV catalogue, a deserialisation flaw in Microsoft Office SharePoint allowing code execution.

CISA warns of StoneFly storage flaws that grant root access

CISA has issued an ICS advisory on multiple StoneFly Storage Concentrator flaws that can allow command execution with root privileges.

CISA adds two exploited infrastructure vulnerabilities

Cisco Catalyst SD-WAN Manager and the LiteSpeed cPanel plugin have entered the KEV catalog after observed exploitation.

CISA shifts patching from severity scores to actual exploitation

A new directive gives US federal agencies three days to fix confirmed exploited vulnerabilities, with longer deadlines for the rest.

Cisco warns of critical Unified CM flaw with PoC exploit code

CVE-2026-20230 lets a remote attacker write files to the operating system and escalate to root. Proof-of-concept code is public; no active exploitation observed.

Palo Alto GlobalProtect vulnerability exploited in the wild

CVE-2026-0257 has been added to CISA's Known Exploited Vulnerabilities catalog, allowing an unauthorised VPN connection in certain PAN-OS configurations.

Cisco Talos shows how DICOM files can be used against imaging systems

A Cisco Talos white paper demonstrates how an Orthanc server can be targeted during image upload, resulting in an out-of-bounds write.

Proof-of-concept code published for Dirty Frag in the Linux kernel

Dirty Frag chains two kernel flaws to obtain root without relying on race conditions.

Fragnesia: new Linux kernel privilege escalation with published exploit

CVE-2026-46300 lets a local user become root. The kernel fix landed on 13 May, but distributions lag behind.

Researcher sharpens criticism of Microsoft's handling of RedSun

A researcher claims Microsoft quietly patched the RedSun Windows flaw without a CVE or advisory, and that YellowKey is less understood than assumed.

cPanel fixes three serious vulnerabilities in cPanel and WHM

Three cPanel and WHM vulnerabilities can let attackers read files, execute code or escalate privileges on affected systems.

Twelve-year-old PackageKit flaw affects widely used Linux distributions

Deutsche Telekom's red team has found a CVSS 8.8 privilege escalation flaw in the PackageKit daemon, fixed in version 1.3.5.

Cisco Talos documents attack techniques built on native macOS features

Talos shows how built-in macOS features can be used for remote execution and payload staging without leaving suspicious files behind.

Anthropic launches Glasswing and an AI model aimed at security

Claude Mythos Preview is built to find and fix severe software flaws, and Anthropic has assembled over 40 companies in a defensive consortium.

Storm-1175 exploits new vulnerabilities and encrypts within a week

Microsoft describes an actor exploiting vulnerabilities a day after disclosure, sometimes before, with Medusa ransomware as the endgame.

Critical FortiClient EMS flaw exploited before the advisory landed

CVE-2026-35616 enables unauthenticated code execution in FortiClient EMS 7.4.5 and 7.4.6. Fortinet has issued a hotfix to install now.