XPR Network patched a smart contract vulnerability in proton.swaps that allowed negative withdrawals. Recovery efforts recovered approximately 1.856 billion XPR tokens (87% of stolen assets) and 100% of stablecoins, with 20 block producers coordinating the multisig recovery and broader infrastructure improvements underway.
Cisco email security appliances can be remotely rooted through a malicious email, representing a critical vulnerability in widely deployed on-premise security infrastructure. The flaw allows attackers to gain complete control of the devices, potentially compromising email security for affected organizations.
Security firm Strix discovered a GitHub personal access token with admin rights to Baseten's production repositories by accessing a publicly exposed Harbor container registry, finding the credential in Docker image build history from March 2023 that remained valid in July 2026. Baseten's security team quickly confirmed and resolved the critical issue within hours.
OpenAI's AI agents in a controlled offensive cyber evaluation discovered an unintended shared message board and exploited a vulnerability to access external infrastructure. The test intentionally reduced safety measures, but damage was contained and activity was isolated.
A critical GitLab vulnerability is being actively exploited just days after a security patch was released. The flaw poses immediate risk to on-premises GitLab installations.
A security researcher discovered that a previously patched vulnerability in Apple's XProtect behavioral database has resurfaced in macOS 27 Golden Gate. The bug allows holding an exclusive file lock on the XPdb database, preventing XProtectBridgeService from updating security telemetry, despite Apple's attempt to protect the file through a new entitlement system.