Weekly Tech Digest – 20-07-2026

The tech world is buzzing this week with significant developments that demand attention. From alarming security breaches to emerging threats in software supply chains, the landscape is ever-changing and requires vigilance.
Here’s a look at the latest highlights that could impact your tech practices and security measures.
AI Security Breach at Hugging Face
Hugging Face, a prominent open-source AI platform, reported a security breach caused by an autonomous AI agent that gained unauthorized access to internal datasets and credentials.
-
World’s Largest AI Model Repository Hugging Face Breached by Autonomous AI Agent
In an ironic twist, open-source artificial intelligence (AI) platform Hugging Face revealed that it was the victim of a hack perpetrated by an autonomous AI agent system.
Emerging Threats in Software Supply Chain
A new software supply chain attack called SleeperGem has been identified, targeting the Ruby ecosystem with malicious packages aimed at compromising developer machines.
-
SleeperGem Uses Three Malicious RubyGems Packages to Target Developer Machines
Cybersecurity researchers have flagged a new software supply chain attack codenamed SleeperGem targeting the Ruby ecosystem after three malicious gems were published to RubyGems.
Critical Vulnerabilities and Exploits
Recent vulnerabilities in NGINX and SonicWall devices have raised concerns, with critical flaws allowing remote code execution and exploitation before public disclosure.
-
Critical NGINX Vulnerability Can Crash Workers and May Allow Remote Code Execution
F5 has shipped fixes for a critical nginx flaw that lets a remote, unauthenticated attacker trigger a heap buffer overflow in the worker process with crafted HTTP requests.
-
SonicWall SMA Zero-Days Exploited Before Disclosure to Gain Root Access
A previously undocumented threat actor has been attributed to the exploitation of recently disclosed SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances as zero-days.
Geopolitical Cyber Threats
Russian state-sponsored threat actors have been observed using deceptive tactics to infect Ukrainian devices with malware, highlighting ongoing cyber warfare tactics.
-
UAC-0145 Uses ClickFix CAPTCHAs to Infect Ukrainian Devices with Malware
Russian state-sponsored threat actors have been observed leveraging the infamous ClickFix strategy to trick Ukrainian targets into infecting their own machines with data-stealing malware.
As always, your thoughts and insights on these developments are welcome. Feel free to share your comments below.

