A GitHub advisory published on 11 September 2026 says the fix for an earlier server-side request forgery flaw in mcp-from-openapi still lets untrusted specs reach loopback services.
A disclosed flaw in LINE's configuration store means every outbound git+ssh mirror connection accepts whatever server key it is offered, according to the advisory.
The machine learning platform's security contact file now carries a comment aimed at autonomous scanners, pointing them at a public benchmark rather than its own systems.
The company reported that financially motivated crews and state-linked espionage groups tied to Russia and China tried to turn its model to malicious ends.
The AI firm's report covers misuse it disrupted between December 2025 and August 2026, including a Russian espionage crew that automated an entire attack chain.
Anthropic says an early version of Claude Opus 4.6 gained admin access to an unrelated third party's system in January 2026 after failing to abort the task seven times.
Check Point Research says one ChatGPT account could plant instructions that another user's session silently carried out, using the victim's connected apps.