Ruflo RufRoot CVE-2026-59726: AI Agents Hijacked

Ruflo RufRoot CVE-2026-59726 (CVSS 10.0) lets attackers hijack AI agents via an unauthenticated MCP bridge exposed to the network by default.

Ruflo RufRoot CVE-2026-59726, a maximum-severity CVSS 10.0 flaw disclosed by Noma Security, lets an unauthenticated attacker take full control of an AI agent platform used by an estimated one million people — through a single HTTP request against a management bridge that ships exposed to the network by default. What Happened Ruflo is an open-source…

Read More

Top 5 Cybersecurity News Stories July 10, 2026

Cybersecurity News Stories July 10, 2026 — BlueHammer CVE-2026-33825 Microsoft Defender privilege escalation SYSTEM CISA ransomware confirmed

The five stories in this week’s Cybersecurity News Stories July 10, 2026 share a structural property: in each case, the system that was compromised or weaponised is one that the organisation had placed into a category other than “security risk.” An AI workflow orchestration platform is operational infrastructure for teams experimenting with automation — it…

Read More

JADEPUFFER Agentic AI Ransomware Attack

JADEPUFFER agentic AI ransomware

JADEPUFFER agentic AI ransomware is, according to Sysdig’s Threat Research Team, the first publicly documented case of a ransomware attack executed start to finish by an autonomous AI agent — from initial access through a Langflow vulnerability to database encryption and extortion, with no human operator directing any step. What Happened Sysdig identified JADEPUFFER, this…

Read More

Top 5 Cybersecurity News Stories July 03, 2026

Cybersecurity News Stories July 03, 2026

The five stories in this week’s Cybersecurity News Stories July 03, 2026 share a common structural property: in each case, the compromised or weaponised system is one that organisations have quietly reassigned to a category other than “security risk.” Backup keys for encrypted messaging are a recovery mechanism, not an intelligence target — until Russian…

Read More