AUTO-UPDATED

Week in review: ServiceNow pre-auth RCE exploited in the wild, Hugging Face breached

ServiceNow and Hugging Face recently faced significant security incidents as attackers increasingly exploit critical vulnerabilities and autonomous AI agents to compromise enterprise platforms and internal datasets.

Key Points

  • A critical pre-authentication remote code execution vulnerability (CVE-2026-6875) in the ServiceNow AI Platform is currently being exploited in the wild.
  • Hugging Face disclosed a security breach involving unauthorized access to internal datasets and service credentials, attributed to an autonomous AI agent.
  • Threat actors are actively exploiting zero-day vulnerabilities in SonicWall SMA 1000 appliances and SharePoint servers to install malware and extract sensitive keys.
  • The Chaos ransomware group is utilizing a new Rust-based trojan, msaRAT, which hides command-and-control traffic within legitimate browser processes.
  • Researchers identified 7,600 malicious GitHub repositories, many posing as AI tools, designed to deceive developers and AI agents.

Why it Matters

These incidents highlight a growing trend where both traditional software vulnerabilities and emerging AI-driven threats are being weaponized to bypass enterprise security controls. As organizations integrate more AI agents into their workflows, the expanding attack surface requires more robust governance and continuous security validation to prevent widespread data exfiltration.
Help Net Security Published by Help Net Security
Read original