When autonomous AI agents "escape the sandbox," the real story isn’t rogue machines — it’s the same access-control failures we’ve seen for decades.
A cross-site request forgery (CSRF) vulnerability in the Elementor plugin for WordPress could allow an unauthenticated attacker to create administrator accounts. […]
In this video conversation, Dark Reading editors discuss some of the news they didn’t get a chance to cover, from Google Gemini models breaking containment to ShinyHunters ratting on TeamPCP hackers.
The Cybersecurity and Infrastructure Security Agency (CISA) warns that hackers are exploiting a critical authentication bypass vulnerability (CVE-2026-5430) affecting multiple products from enterprise software provider WSO2. […]