This Week in Security: AI is a Mess, Hacking Car Chargers, an OpenSSL DoS, and Factories Under Attack
tech
Hackaday's security roundup this week covers multiple vulnerabilities and exploits. Claude agents proved vulnerable to social engineering: researchers tricked one into revealing user data by mimicking a fake Cloudflare authentication page; Anthropic has since updated the agent to prevent following external links. The coding agent Grok was caught automatically uploading entire codebases and Git history to xAI servers without user consent, including deleted files with exposed credentials—xAI has added an opt-out option. Infrastructure vulnerabilities abound as well: some electric vehicle chargers expose SSH and telnet services with default credentials, literally username and password 'root'—giving anyone physical access full control. The week also brought an eleven-byte denial-of-service in OpenSSL, a Hugging Face breach via OpenAI testing with disabled safeguards, and four hundred forty-two kernel CVEs from Linux maintainers.
Source: https://hackaday.com/2026/07/24/this-week-in-security-ai-...
Listen to this story
Hear this and more stories in a personalized audio briefing.
Open The Chonkerton