The Week in 60 Seconds
Security & Exploitation
FBI warning on intimate-image account targeting
What happened
The FBI warned that criminals are taking over social-media and personal accounts to steal and distribute non-consensual intimate images (NCII), sometimes with victims’ identifying information. [4]
Reported tactics include high-volume password or PIN guessing using breached or public data, fake account-warning messages that solicit reset codes, and phishing pages that steal credentials. [4]
Why it matters
The material may be posted or sold with names, phone numbers, email addresses, and social-media handles, creating opportunities for harassment, stalking, and sextortion. [4]
Metabase exploitation and data-access reporting
What happened
Metabase Cloud was attacked through an unknown zero-day in versions 1.58 and above; the company rated the flaw CVSS 10.0 and said it enabled unauthenticated arbitrary SQL injection into the application database. [3]
After exploitation, an attacker could obtain administrator access, change application configuration, steal credentials for connected databases, read accessible data, and export it. [3]
Why it matters
Framework confirmed it was compromised through the flaw; names, login IPs, addresses, phone numbers, and email addresses were accessed, while order and payment information was reportedly not affected. [3]
AI & Agent Security
Reported AI-agent intrusion in Taiwan
What happened
Dream documented what it described as an apparently fully autonomous, end-to-end AI hacking operation against a government target; the Financial Times reported that suspected Chinese hackers used it against Taiwan, although Dream did not officially identify the government. [7]
Over four days, the toolkit reportedly mapped 21 government systems, searched for vulnerabilities, changed tactics when blocked, and used up to eight autonomous agents working in parallel. [7]
Why it matters
Dream’s researchers said the tool continuously ranked and reprioritized attack paths using new evidence and deployed another agent to search for information and devise a different approach after a path failed. [7]
OpenAI cybersecurity model announcement
What happened
OpenAI unveiled GPT‑5.6‑Cyber, a cybersecurity-focused model intended for vulnerability research, penetration testing, and incident response. [1]
OpenAI said the model is built on GPT‑5.6 Sol and trained for specialized cybersecurity tasks, including finding zero-day vulnerabilities and developing exploit chains. [1]
OpenAI Astra access pause
What happened
OpenAI paused internal activities involving its upcoming Astra model after preliminary evaluations found cybersecurity performance strong enough that it could not rule out reaching the Critical threshold under its Preparedness Framework. [2]
The framework defines the Critical cybersecurity threshold as either developing functional zero-day exploits across hardened critical systems without human intervention or executing novel end-to-end cyberattack strategies against hardened targets from a high-level goal. [2]
Why it matters
The article reports that Astra was not involved in the previously disclosed Hugging Face exploitation incident and distinguishes that incident from the model’s current cybersecurity assessment. [2]
Cloud & Platform
Akira Safe Mode intrusion analysis
What happened
In an Akira ransomware intrusion, the affiliate rebooted a computer into Safe Mode with Networking, which stopped the Huntress agent and disabled Microsoft Defender real-time protection, but constrained memory prevented the encryptor from completing. [8]
Why it matters
The incident was not a complete victim win: credentials and data had already been stolen, and the attacker obtained a temporary period in which security tooling was disabled. [8]
Microsoft Edge extension-support changes
What happened
Microsoft is beginning Edge’s retirement of Manifest V2 extensions, targeting consumer completion by the end of 2026 and managed-enterprise deprecation in early 2027. [9]
Microsoft says 95% of the most-used MV2 extensions in the Edge Add-ons store have moved to MV3; among 58 extensions with meaningful usage, three lack a publicly available MV3 alternative. [9]
Why it matters
The transition primarily affects privacy and content-blocking tools that modify requests, headers, redirects, or responses, including the classic uBlock Origin, which has more than 13 million Edge installs. [9]
Policy & Industry
New vulnerability naming authorities
What happened
The NATO Cyber Security Centre and AISLE joined as CVE Numbering Authorities under the ENISA Root, allowing them to issue CVE identifiers within their stated scopes. [5]
The NATO Cyber Security Centre can assign CVE IDs to eligible flaws across the NATO enterprise; the agency said this should improve tracking consistency and enable earlier sharing with trusted partners. [5]
Why it matters
The CVE program assigns unique records to publicly disclosed security flaws so governments, vendors and researchers can use a common vulnerability marker. [5]
NIST vulnerability-database plans
What happened
NIST is seeking public input on overhauling the National Vulnerability Database (NVD) to address AI-driven vulnerability discovery, exploitation, and machine-consumable security data. [6]
NIST says the NVD faces increased vulnerability volume and complexity, inconsistent data quality, greater reliance on automation, and demand for near-real-time enrichment. [6]
Why it matters
The request for information characterizes periodic scanning, static prioritization, and manual remediation as increasingly inadequate for vulnerability management. [6]