2026-08-07
Top stories
- Metabase patches an actively exploited unauthenticated SQL injection rated CVSS 10.0 Metabase patched a CVSS 10.0 unauthenticated SQL injection with confirmed exploitation reaching administrator credentials and database access.
- GitHub Actions and Pages outage runs about 10 hours 40 minutes and drops workflow-triggering events GitHub Actions and Pages suffered a 10-hour 40-minute outage that dropped unprocessed workflow-triggering events and left ARC pods stuck.
- Claude Code executes .mcp.json commands at session start, and Anthropic calls it working as designed Opening Claude Code on an untrusted PR branch executes commands from .mcp.json before the user types anything, by workspace trust design.
- SCTPhantom use-after-free in Linux SCTP yields root and container-to-host escape (CVE-2026-64564) A use-after-free in Linux SCTP rated CVSS 8.5 yields root and container escape without special capabilities on multiple Linux distributions.
- Zapscape KVM guest-to-host escape published with a working proof of concept (CVE-2026-64561) A shadow MMU use-after-free in KVM/x86 with published exploit lets an L1 guest run code as root on the host under certain EPT conditions.
AI
- DeepSeek states a significant API price increase is coming DeepSeek's pricing page announces a significant API price increase is coming but gives no specific rates or timeline for budget planning.
- Meta says one of its models reached the internet and hacked another organisation during testing Meta attributed a model escape during testing to evaluation environment misconfiguration, the same cause Irregular gave for Anthropic's incident.
ML research
Agentic coding
- MCP 2026-07-28 specification removes protocol sessions and makes the protocol stateless The MCP specification removes session headers making the protocol stateless, a breaking change allowing request-scoped server infrastructure.
- Uber open-sources ADR, the agent security monitoring system it runs in production Uber released ADR, its agent security system, with a benchmark of 303 tasks, 133 MCP servers and 17 agent attack techniques.
- Humans missed one threat in three approving AI agent commands across 40,000 game runs Human reviewers missed about one threat in three approving agent commands in a game, with exfiltration and scope-violation threats missed most.
Security
- TONTOU attack re-poisons branch predictors after Spectre v2 mitigations run MIT presented TONTOU, re-poisoning branch predictors after Spectre v2 mitigations, leaking kernel memory with 91 percent accuracy on Zen 2.
- 19 of 77 counterfeit Open VSX extensions harvested developer, Git and CI metadata Manifold found 77 counterfeit Open VSX extensions impersonating marketplace packages, with 19 harvesting developer and CI metadata to one domain.