⚡ Weekly Recap: Rogue AI Agents, Check Point Exploit, Slopsquatting, ClickFix Lures and More This week’s cybersecurity recap highlights a concerning trend of AI-powered attacks and vulnerabilities. OpenAI lost control of its AI agents, leading to a breach of Hugging Face, while a Chinese threat actor used DLL side-loading to deliver malware. Simultaneously, AI models are hallucinating package names, leading to… The Hacker News · Jul 27, 2026 CVE-2026-16232CVE-2025-66376CVE-2026-54121
vulnerability Adobe Acrobat Extension Flaw Let Malicious Sites Read WhatsApp Web Data A vulnerability in the Adobe Acrobat Chrome extension (HermeticReader, CVE-2026-48294) allows attackers to silently steal WhatsApp Web data by tricking users into visiting a malicious website. The flaw requires only user… The Hacker News · Jul 22, 2026 High CVE-2026-48294chromeextensionwhatsapp
vulnerability Flaw in Adobe Extension With 300M Installs Enabled WhatsApp Data Theft A widely-used Adobe Chrome extension was exploited to steal WhatsApp data by tricking users into visiting a malicious webpage. The vulnerability, dubbed HermeticReader, allowed attackers to silently access users' private… SecurityWeek · Jul 22, 2026 High CVE-2026-48294uxsschromedata-breach