Latest cyber news, threats, security, and guidelines. Stack up.

Latest

Last 3 days · one card, one id
AI
Published 2026-08-27
Verified 2026-08-29

Open letter: a limited window for a global cyber-defense surge

OpenAI published an open letter, "A call for collective action on cyber defense," signed on that page by OpenAI, Anthropic, Google, Microsoft, AWS and a long listed set of other firms. The letter says there is a limited window to strengthen cyber defences; that in the coming months AI-enabled cyber attacks will become far more widespread and sophisticated as models become more capable; and that hospitals, water treatment plants and internet infrastructure are at risk. It argues status-quo security will not be enough, and calls on organisations, cybersecurity companies and governments to put cyber-capable AI in defenders' hands, starting with essential services. Dated 27 August 2026 in contemporaneous reporting; the letter page itself does not print a date.

Product
Agentic / frontier AI (cyber defense)
Exploited in Australia?
unknown

Primary: OpenAI open letter · TechCrunch (27 Aug; date stamp)

ai llm agentic

Vulnerability
Published 2026-08-27
Verified 2026-08-29

ServiceNow AI Platform unauthenticated SQL injection (CVE-2026-74820)

ServiceNow's 27 August 2026 CVE record says it remediated an unauthenticated SQL injection in the ServiceNow AI Platform that could, in certain circumstances, let an unauthenticated user run arbitrary SQL against the instance database and read or change data beyond what was intended. ServiceNow scored it 10.0 (CVSS 4.0). Hosted instances received a vendor-deployed security update; partners and self-hosted customers were given the update. ServiceNow says it is not currently aware of malicious exploitation. The same 27 August CNA batch includes CVE-2026-6876 (Now Platform sandbox escape, CVSS 4.0 8.7) and CVE-2026-18886 (AI Platform improper access control). Self-hosted operators should apply the August 2026 CVE advisory updates. Affected CNA rows include Xanadu, Yokohama, Zurich and Australia patch families listed on the CVE record.

Product
ServiceNow AI Platform (also Now Platform for CVE-2026-6876)
Versions
CNA-listed Xanadu, Yokohama, Zurich and Australia patch-family builds (see KB3152242)
CVSS
(CVSS 4.0, ServiceNow CNA)
Exploited in Australia?
unknown
Patch to
Hosted: vendor already deployed the update. Self-hosted/partners: apply August 2026 CVE advisory updates (KB3152242)

Primary: CVE-2026-74820 (ServiceNow CNA) · Vendor: ServiceNow August 2026 CVE advisory (KB3152242) · CVE: CVE-2026-74820, CVE-2026-6876, CVE-2026-18886 · CVE-2026-6876 (same-day Now Platform sandbox escape)

vulnerabilities cloud ai