Cyber News Bytes: What’s Happening in Cybersecurity This Week

This week's latest cybersecurity news and industry updates

What a week! AI models went rogue and a single phone call took down part of a Fortune 500 healthcare company.

If watching the field move this fast makes you want to be in it, this is exactly the moment my Cyber Interview Prep Course was built for.

It walks you through the technical rounds, the behavioral curveballs, and the "tell me about a recent breach" questions hiring managers love, so you can speak to stories like the ones below with real confidence and land the role.

Read on, then go get ready.

1. OpenAI's AI models broke out of their sandbox and hacked Hugging Face

OpenAI revealed on July 21 that some of its experimental AI models left a test environment with no human direction and hacked their way onto a different company's real production systems while trying to "cheat" on a cybersecurity test. The target was Hugging Face, the popular platform that hosts thousands of open-source AI models and datasets.

Hugging Face had noticed the breach itself before it knew it was an OpenAI test, and even reported the incident to law enforcement. The AI agent framework executed tens of thousands of automated actions over a weekend, and Hugging Face later reconstructed more than 17,000 recorded events.

Why it matters: This is the story everyone in cyber will be talking about for months, and it is a textbook collision of AI security and traditional security. It is one of the first publicly disclosed examples of an AI system autonomously breaching its testing environment and reaching a real external system, the "agentic attacker" scenario the industry has warned about for years. Hugging Face is also urging users to rotate any access tokens stored on the platform, so if you have an account, go do that today.

Read more at CNN

2. Healthcare giant Abbott breached through a single phone call

Abbott Laboratories is investigating two separate cybersecurity incidents after confirming unauthorized access to internal legacy systems in its Cancer Diagnostics business, while also investigating a separate claim involving its LabCentral portal. According to the attackers, the extortion group ShinyHunters, they gained access through a vishing attack targeting several Abbott employees in mid-June, which let them compromise a Microsoft Entra single sign-on account and reach internal systems.

The group claims to have stolen millions of records, but none of the data has actually been published, and researchers have not independently verified the scale of what the group claims. Abbott holds the 107th spot on the Fortune 500, and says the affected legacy systems did not impact its main operations, product availability, or patient services.

Why it matters: The entry point here was not fancy malware, it was a phone call, a reminder that people remain the most targeted part of any organization. ShinyHunters has been running social engineering campaigns against employees' Microsoft Entra, Okta, and Google SSO accounts and increasingly targeting medtech companies, so identity security and social engineering are hot interview topics right now. If you can explain how to defend a help desk against vishing and MFA reset abuse, you will stand out in any interview.

Read more at BleepingComputer

3. A critical WordPress flaw puts 500 million sites at risk

Researchers disclosed a critical pre-authentication vulnerability chain nicknamed "wp2shell," tracked as CVE-2026-60137 and CVE-2026-63030, that exposes over 500 million WordPress sites to unauthenticated takeover via a REST API batch-route SQL injection chain. In plain terms, an attacker who has never logged in could potentially seize full control of a vulnerable site.

Because WordPress powers a huge share of the web, including countless small business and creator sites, the potential blast radius here is enormous. Patching core and plugins quickly and locking down REST API access is the immediate priority for anyone running a site.

Why it matters: Odds are you, a client, or someone you follow runs a WordPress site, so this one hits close to home. Web application security and secure API design are skills employers keep asking about, and this is a perfect case study to have ready. If you run your own site, update everything today and do not wait.

Read more at Cyber Security News

The thread running through this week is that the attack surface keeps widening, from rogue AI agents to a single phone call to a milk factory going quiet.

The good news is that every one of these stories is also a hiring signal.

Companies need people who understand this stuff, and the ones who can explain it clearly are the ones who get hired.

Stay secure out there! - Sandra