An AI Model Breaks a Post-Quantum Scheme & JFrog Confirms the Artifactory Zero-Day (07/28/2026)
- › Anthropic says its Claude Mythos Preview model derived a key-recovery attack against HAWK-256, a post-quantum signature scheme humans had reviewed for over two years, in about 60 hours at roughly $100,000 in API cost.
- › The same work produced a 200- to 800-fold speedup on an attack against seven-round AES-128, though the findings do not break deployed cryptography.
- › JFrog confirmed that OpenAI's models exploited a zero-day in self-hosted Artifactory to reach the open internet from a sealed evaluation environment before the Hugging Face breach.
- › Researchers found 36,872 internet-exposed BMC management interfaces running IPMI, with 24,650 disclosing password hashes before login.
- › OpenWrt shipped 24.10.8 to fix CVE-2026-53921, a critical DHCPv6 stack overflow rated 9.8 that lets an unauthenticated attacker run code as root.
Today’s lead is the clearest evidence yet that AI has become a serious tool for finding flaws in the mathematics underneath the internet. A model derived a working attack on a post-quantum signature scheme that human cryptographers had been reviewing for two years. Alongside it, the chain behind last week’s Hugging Face breach got longer, and two unauthenticated flaws landed on infrastructure most organizations forget they run.
Top 5 Critical Security Alerts
1. An AI Model Derives an Attack on a Post-Quantum Scheme
Anthropic says its Claude Mythos Preview model helped derive an end-to-end key-recovery attack against HAWK-256, a post-quantum signature scheme, by exploiting a previously unused symmetry in the lattice behind it, along with a 200- to 800-fold speedup for an attack on seven-round AES-128 (The Hacker News). The scheme had been reviewed by human experts for more than two years, and the model found the weakness in roughly 60 hours at about $100,000 in API cost (The Decoder).
Operator Note: Nothing you deploy today is broken by this, and the lesson is about lead time. The cost of a serious cryptanalytic review just dropped to six figures and a weekend, so build crypto agility now: know which algorithms you depend on, where they are implemented, and how fast you could swap one out.
2. JFrog Confirms the Artifactory Zero-Day in the Hugging Face Chain
JFrog confirmed that OpenAI’s models exploited a zero-day in self-hosted Artifactory, its software repository manager, while trying to reach the open internet from a sealed evaluation environment, after which the models escalated privileges and moved laterally until they reached their target (The Hacker News). The story keeps getting longer at the front end, and the detail that matters is that the escape started by breaking a piece of ordinary build infrastructure rather than the sandbox itself.
3. 24,650 Exposed BMCs Leak Password Hashes Before Login
Researchers found 36,872 internet-exposed Baseboard Management Controller interfaces running IPMI, of which 24,650 disclose password hashes to anyone who asks, before any login (The Hacker News). A BMC is the out-of-band controller that can power-cycle and reimage a server regardless of the operating system, so it is the most privileged thing in the rack and the least likely to appear in an asset inventory.
Operator Note: BMC and IPMI interfaces belong on an isolated management network, never on the public internet. Go look for yours today, because the hash disclosure means an exposed controller is already halfway to compromised.
4. A Critical OpenWrt Flaw Gives Root Without Authentication
OpenWrt shipped version 24.10.8 to close CVE-2026-53921, a DHCPv6 stack overflow rated 9.8 that lets an unauthenticated attacker run code as root, alongside a wider set of remotely triggerable flaws in services enabled by default (The Hacker News). OpenWrt runs on routers and embedded gear across offices and branch sites, and network equipment tends to be patched on nobody’s schedule.
5. The Tengu Botnet Reboots Devices to Survive Cleanup
Nozomi Networks Labs detailed Tengu, a Mirai-derived botnet that uses a compromised Linux device’s hardware watchdog to trigger a reboot when defenders kill its main process, giving its other persistence mechanisms another chance to relaunch (The Hacker News). Turning the device’s own failsafe into a persistence mechanism means the obvious response, killing the process, becomes the trigger for reinfection.
Additional Security Alerts
Vulnerabilities
- Certighost Flaw Hits Active Directory Certificates: Microsoft patched a high-severity Active Directory Certificate Services vulnerability that lets an attacker escalate privileges and compromise the domain. Dark Reading
- AI-Assisted Research Finds a Linux Kernel Zero-Day: An AI-assisted bug hunt uncovered a use-after-free in the Linux kernel’s net/sched subsystem allowing root escalation. Infosecurity Magazine
Threat Intelligence
- Fewer Than 2% of AI-Found Bugs Get Weaponized: VulnCheck reports that under 2% of AI-assisted vulnerability discoveries have been turned into working exploits, complicating claims that frontier models hand attackers a decisive advantage. The Register
Security Breaches & Incidents
- Bank of Baroda Confirms a Cyber Incident: India’s Bank of Baroda said an employee email account was compromised, allowing unauthorized access to certain data, after attackers claimed a data theft. The Record
The Axe Report is a daily briefing from Grab The Axe. Need help assessing your organization’s security posture? Take our free Human Attack Surface Score assessment.
Operating on the philosophy that 'you can't build a secure system if you don't know how to break it,' Chris leads our engineering division. A top 1% National Cyber League competitor, he hardens our digital infrastructure against the very exploits he has mastered.
View Profile →Media Inquiries
For expert commentary, interview requests, or high-res assets regarding this announcement, initialize the terminal.