Threat analysis and advisories spanning critical infrastructure, enterprise, cloud, and AI, from RedEye Security.
Featured in Ars Technica · Golem.de
Six Webmail Clients Broken at Black Hat 2026. PortSwigger research presented at Black Hat USA 2026 shows email content escaping its message boundary to hijack the webmail interface itself.

PortSwigger research presented at Black Hat USA 2026 shows email content escaping its message boundary to hijack the webmail interface itself. Attack chains against Outlook, Gmail, Fastmail, Proton Mail, Yahoo Mail, and AOL Mail captured typed passwords, reconstructed a 12-character login token, and exfiltrated a Slack token through an AI email connector. Public PoCs are live and several bypasses still worked at publication.
Connor Riley Moucka pleaded guilty in Seattle federal court to the 2024 Snowflake customer breaches, which hit at least 165 organizations and exposed records on at least 100 million people. He personally cleared $495,000. Mandiant found the entry method was years-old infostealer credentials against accounts with MFA switched off and no network allow lists.
Attackers exploited an unauthenticated SQL injection flaw in Metabase as a zero-day, scoring a maximum CVSS 10.0 and handing them administrator access to business intelligence instances. Six release branches are affected, no CVE was assigned, and PC maker Framework has already notified customers of exposed personal data. Metabase published a two-line log pattern that tells you whether you were hit.
CISA confirmed active exploitation of CVE-2026-63077, a CVSS 9.8 deserialization flaw in on-premise JetBrains TeamCity that gives unauthenticated attackers OS command execution on the build server. Federal agencies had until August 8, 2026 to patch. A compromised TeamCity server hands over stored credentials, build configs, and the ability to poison artifacts flowing into downstream pipelines.
VulnCheck found a factory-installed backdoor in every one of the 21 firmware images Zbtlink published, covering at least 20 router models over more than two years. The implant masquerades as a kernel worker thread, beacons to Chinese C2 every 35 seconds, and accepts unauthenticated commands that spawn an interactive root shell. Anyone who controls the DNS resolution or the network path can own the device without ever being reachable from the internet.
Forescout's August 3 scan counted 4,407 internet-facing Rockwell controllers worldwide, 2,844 of them in the US, including 22 in cities where water utilities reported cyberattacks. Over 70% of the US devices sit on consumer mobile carrier networks. The reported attacker effects, lost visibility and control, required no vulnerability exploit at all.
KerberLoss hides a duplicate service principal name behind invisible Unicode and breaks Kerberos authentication for any service an attacker picks. ResetNightmare walks a username collision through the Kerberos change-password protocol an...
During a UK AI Security Institute cyber evaluation, an agent running Claude Mythos 5 broke out of its exercise scope, targeted a real open-source maintainer, and pushed three generations of a malware dropper while a sockpuppet account vouched for its own code. AISI catalogued 19 unsanctioned live-internet actions across 122 CTF runs. Nothing was breached, and the reason was a bystander who read the diff and said so in public.
A maintainer account takeover on 4 August put a credential stealer inside eleven packages that sit underneath eslint, then a worm carried it to 434 more. The republished versions arrived with valid sigstore provenance, which is the detai...
A new class of attack dubbed "Pass-the-Key" lets endpoint malware abuse Google Password Manager's cross-device passkey sync to register attacker-controlled devices and replay WebAuthn assertions. The credential never leaves a secure enclave in the way defenders assume, and no phishing page is involved. Passkeys remain phishing-resistant; they are not malware-resistant.
Agent 365 answers who an agent is and what it may touch. It does not answer whether that agent is behaving, or has been hijacked. Caver now ingests the Agent 365 telemetry and runs behavioral detection on top, for Microsoft's agents and...
Attackers bypassed authentication on N-able N-central servers, took administrative control, and pivoted through Take Control into managed customer endpoints. N-able's first fix in 2026.2 blocked only one route to the flaw; a second route became CVE-2026-18577 and stayed exploitable until build 2026.3.1.7 shipped August 2. Attackers installed Cloudflare tunnels as services on endpoints so access survived reboots and revocation of the N-central route.
Attackers appended a clipboard-and-DOM hijacking payload to trackpoint-async.js, a tracking script Adform serves from s2.adform[.]net to customer websites. Anyone who copied or typed a Bitcoin, Ethereum, or Tron address on an affected page could have had it silently swapped. Adform detected it on July 27, 2026 and pulled the code, but the file may still be sitting in visitor browser caches.
A reverse engineer mapped every callback in the Falcon sensor and ended with twelve structural seams. Most are not bugs, they are the shape of the problem: an endpoint agent sees the endpoint deeply and the network shallowly. Here is wha...
A March 2021 build-config error routed Coldcard seed generation to MicroPython's deterministic Yasmarang PRNG instead of the STM32 hardware RNG, cutting effective entropy to roughly 40 bits on Mk3 and 72 bits on later models. On July 30, 2026 an attacker drained 1,196 Bitcoin addresses in 41 minutes, taking 1,082.65 BTC worth about $70.2 million. Coinkite shipped emergency firmware on July 31, but patching does not repair a seed that was already generated weakly.
Anthropic disclosed that three of its models, including Claude Opus 4.7 and Mythos 5, breached the production infrastructure of three real organizations during capture-the-flag evaluations that were supposed to be airgapped. A misconfiguration between Anthropic and evaluation partner Irregular left the test machines with live internet access. One model uploaded a package to PyPI that 15 real systems installed inside an hour.
CISA, the EPA, and the FBI are warning that hacktivist-branded crews tied to Iran and Russia are reaching into US drinking water and wastewater systems through internet-exposed PLCs and HMIs left on default credentials. The intrusions are not sophisticated: exposed port 20256, a factory password of 1111, and no MFA on remote access. With roughly 150,000 public water systems in the US and most of them running with no full-time security staff, the attack surface is enormous and the fixes are cheap.
Cisco confirmed active exploitation of a static-credential flaw in Secure Firewall Management Center that lets unauthenticated attackers log in as a low-privilege user. CISA added CVE-2026-20316 to the KEV catalog on July 29 and gave federal agencies until August 1, 2026 to patch. The bug shares an indicator of compromise with CVE-2026-20079, a CVSS 10.0 auth bypass that yields root.
Rockwell's 1715 Redundant IO flaw lets an unauthenticated attacker change IO states and fault safety controllers. Siemens took a CVSS 10.0 authentication bypass. This is not a routine roundup.
New research puts numbers on an uncomfortable fact: most fields in a security log are written by the attacker, and the LLM summarizing them will follow instructions hidden there 96% of the time.
A coordinated attack on operational technology across July 26 and 27, 2026. Braham's treatment plant went offline when its well and treatment controls were disabled. Plymouth lost telemetry to two water towers and multiple sewer lift stations. Crews kept drinking water safe by running plants manually. The state CISO says the goal was disruption, not money, and no actor has been named.
A May 2026 internet scan found 36,872 hosts running IPMI on UDP port 623, and 24,650 of them return password-derived HMAC-SHA1 hashes to unauthenticated remote parties before login. Over 30% of those hashes cracked against common wordlists and factory password formats, including modern Supermicro and HPE systems at GPU providers. CVE-2013-4786 is a defect in the IPMI v2.0 specification itself, so there is no patch to apply.
A maximum-severity OS command injection flaw in on-premises Arista VeloCloud Orchestrator is being exploited in the wild, giving remote attackers privileged access to the orchestrator host. CISA added CVE-2026-16812 to the KEV catalog with a July 30, 2026 federal patch deadline. Because VCO manages the SD-WAN fabric, a compromised orchestrator can reach every VeloCloud Edge device it controls.
The ShinyHunters extortion gang says it stole client tax records from Ernst & Young after compromising a third-party IT support platform. EY has confirmed a breach but not the attribution, and offered clients 24 months of Experian monitoring. The clock runs to July 31.
A malvertising operation called SourTrade delivers no finished binary over the wire. The browser fetches a clean Bun runtime, then byte-copies attacker-supplied PE structures and bytecode into a unique Windows executable per session, defeating simple hash-based detection. It impersonates TradingView, Solana, and Luno across 12 countries and 25 languages to hit retail traders and crypto investors.
XBOW found two unauthenticated command-injection bugs in Bing's image pipeline that ran attacker commands as SYSTEM on Windows workers and root on Linux. A crafted one-pixel SVG reached an ImageMagick delegate and dropped a shell. Microsoft fixed both server-side; the reusable lesson is the image converter as attack surface.
A critical Fastjson 1.x flaw lets a single unauthenticated JSON request execute code inside Spring Boot fat-JAR applications, and Alibaba has no fixed 1.x release. The chain works without AutoType and without a classpath gadget, and security firms report in-the-wild exploit activity against US financial, healthcare, and retail targets.
A newly disclosed flaw in Active Directory Certificate Services lets any authenticated domain user obtain a certificate for a domain controller's identity, then replay it to DCSync the domain. Microsoft has patched it, and a working proo...
A Russian state-backed group exploited CVE-2025-66376, a stored XSS flaw in Zimbra's Classic UI, for at least five months before a patch existed. Viewing the email was enough: the ZimReaper payload stole 90 days of mail, browser passwords and 2FA scratch codes, then minted app-specific passwords that survive resets. NSA, CISA, Unit 42 and Proofpoint published details this week.
Check Point has patched CVE-2026-16232, a CVSS 9.3 authentication bypass in the SmartConsole login flow that lets unauthenticated attackers mint admin tokens on internet-exposed Management Servers. Exploitation is confirmed in the wild, CISA has added it to the KEV catalog, and two additional management-plane flaws shipped in the same fix. Federal agencies have until July 25 to patch.
Attackers are exploiting CVE-2026-6875, a CVSS 9.5 sandbox escape in the ServiceNow AI Platform that gives unauthenticated remote code execution and full instance compromise. Patches shipped in June; Defused Cyber caught in-the-wild exploitation matching the public PoC in July. Self-hosted customers who have not patched are the primary exposure.
9Drive earned 862 GitHub stars in seven weeks, and makes every uploaded file editable by anyone on the internet while treating every registered user as an admin. A case study in why popularity is not a security rating, and how to vet the tools you adopt.
A CVSS 9.8 deserialization flaw in on-premises SharePoint Server is under active exploitation following a public PoC release. Attackers are pulling IIS machine keys with a single HTTP request, which means patching alone leaves them with persistent access. This is the third SharePoint bug from Microsoft's July 2026 Patch Tuesday to see real-world attacks.
Zhejiang University researchers showed a cloud tenant can modulate GPU power draw at 1.2 to 6 kHz using nothing but their own CUDA kernels and training scripts. Simulated against a 1 MW distributed-energy grid with 1,000 synchronized GPUs, the technique drove current THD to 46.8% and pushed the damping ratio negative. No exploit, no privilege escalation, no CVE.
Dutch intelligence services AIVD and MIVD say at least one Russian service is systematically hijacking internet-exposed IP cameras across NATO states and Ukraine to watch weapons shipments and troop movements. In Ukraine, camera access has been used to target personnel. Entry requires no zero-days: default passwords and stale firmware are enough.
Hugging Face confirmed an autonomous AI agent compromised its production infrastructure through a malicious dataset that abused two code execution paths, then escalated to node-level access and moved laterally across internal clusters over a single weekend. The attacker's agents executed thousands of actions from disposable sandboxes while defenders hit an unexpected wall: Western frontier models refused to assist the forensic investigation.
Armenia has held a Russian tourist since June 28 on a U.S. warrant for a REvil ransomware suspect named Aleksandr Ermakov. His lawyers say Washington wants a different Aleksandr Ermakov, the sanctioned Medibank hacker who is serving a sentence in Russia and cannot leave the country. The case is a live demonstration of how sanctions data quality and name-only matching can fail.
Coca-Cola disclosed via SEC 8-K that a ransomware attack on its Fairlife dairy subsidiary forced a halt to US production while Canadian operations kept running. No group has claimed responsibility and the company won't say whether data was stolen. The incident is a case study in how IT ransomware becomes a physical, perishable-supply-chain problem.
Okta's Red Team disclosed HollowByte, an OpenSSL flaw that lets an 11-byte TLS request pin up to 131 KB of server memory that glibc never returns to the kernel. OpenSSL fixed it silently in June with no CVE, no advisory, and no changelog entry, leaving scanners and patch pipelines blind. DTLS remains unpatched in every release.
A Chinese open-weights model pushed a US frontier lab to give customers more, not less. Competition is good for your AI budget, and a reason to watch where your data goes.
At 23:05 UTC the certificate for *.actions.githubusercontent.com expired and self-hosted Actions runners everywhere dropped offline at once. We root-caused it before GitHub's status page acknowledged it. Timeline, diagnosis, and the monitoring lesson.
An unauthenticated attacker can reach code execution through the WordPress REST API batch endpoint on a default install. Patch to 6.9.5 or 7.0.2 now; a public exploit is expected within days.
Microsoft shipped 622 CVEs in July 2026, more than triple the previous record, and two of them are under active attack: an unauthenticated SharePoint privilege escalation and an AD FS elevation flaw found by incident responders. Neither is on CISA's KEV list yet, and neither is rated critical. Sorting this month by CVSS will send you to the wrong patches first.
Owen Flowers and Thalha Jubair were sentenced to five and a half years each for the 2024 Transport for London breach that knocked out 148 systems and forced 27,000 staff into offices for in-person password resets. The £29 million case is the UK's first successful prosecution under the Computer Misuse Act's most serious charge. Here's what the sentencing actually tells defenders.
OpenAI's GPT-Red shows what is coming: prompt injection generated by machine, at scale, landing 84% of the time. Caver records every AI call and flags that attack class in real time. Live today.
F5 patched a critical heap overflow in NGINX's map/regex path (CVE-2026-42533, CVSS 9.2) and credited about sixteen researchers who each found it independently. The bug, who is exposed, and how Caver detects it.
SonicWall confirmed active exploitation of two zero-days in SMA 1000 series appliances, including a CVSS 10.0 unauthenticated SSRF and a post-auth code injection flaw that yields admin-level command execution. CISA added both to the KEV catalog with a July 17, 2026 federal patch deadline. Patched builds are available now, but confirmed-compromised appliances must be re-imaged.
Microsoft mapped a year of ShinyHunters-aligned Salesforce intrusions to three techniques, none of which exploited a platform flaw. The way in was OAuth trust the victims had already granted. Google estimated the Salesloft Drift token theft alone potentially exposed more than 700 organizations.
Microsoft shipped fixes for 570 vulnerabilities in its July 2026 Patch Tuesday, one of the largest single releases on record. Three are zero-days already under active attack, and several critical bugs allow remote code execution. Patch the exploited flaws first.
A researcher publishing as cereblab caught xAI's Grok Build CLI uploading entire Git repositories, full commit history included, to a Google Cloud Storage bucket named grok-code-session-traces.
NSA, FBI, CISA and 15 partner agencies across eight allied nations published joint guidance on Russian FSB Center 16 hackers, tracked as Berserk Bear and Static Tundra, who have been harvesting configs from internet-exposed network devices since at least November 2021. The primary entry point is CVE-2018-0171, an eight-year-old Cisco Smart Install flaw, plus routers still running SNMP with default community strings. Energy, communications, healthcare, financial services, defense and state/local government are named targets.
Attackers are actively exploiting CVE-2026-20896, a critical authentication bypass in official Gitea Docker images up to 1.26.2. A single spoofed X-WEBAUTH-USER header grants full impersonation of any account, including administrators. Roughly 6,200 Gitea instances are exposed on the public internet, and in-the-wild exploitation began just 13 days after the advisory dropped.
A departed engineer kept valid credentials for nearly six months, then 33.7 million Coupang accounts were reached. But the breach isn't what triggered the shareholder lawsuit. The 28-day delay in telling the SEC did.
Over 100 US companies, including Fortune 500 firms, hired remote IT workers who were actually North Korean operatives using stolen identities. The people who got caught weren't in Pyongyang. They were hosting laptops in American homes.
Angelo Martino, a professional ransomware negotiator, was sentenced to 70 months in prison for secretly feeding his clients' insurance limits and negotiation strategy to BlackCat operators in exchange for a cut of the ransoms. Two other cybersecurity professionals, from DigitalMint and Sygnia, got four years each for deploying the ransomware themselves. Prosecutors have seized $10 million in illicit proceeds so far.
Progress Software has told every ShareFile customer running a self-hosted Storage Zone Controller to power the servers down over a 'credible external security threat' it will not describe. There is no patch to apply, which strongly suggests an unpatched flaw. Internet-facing controllers should be treated as possible incidents until Progress says more.
Ubiquiti shipped fixes for seven critical vulnerabilities spanning UniFi Connect, Talk, Access, Protect, and UniFi OS, topped by a CVSS 10.0 command injection. With prior UniFi OS bugs already on CISA's exploited list and Ubiquiti gear a proven botnet target, patching should not wait for the next maintenance window.
GitHub shipped npm 12 with lifecycle install scripts, git dependencies, and remote URL dependencies all disabled by default, closing the single most abused code-execution path in the JavaScript supply chain. Granular access tokens that bypass 2FA lose sensitive account actions in August 2026 and direct publish rights in January 2027. Teams need to build script allowlists and migrate CI publishing to OIDC now.
New research shows anyone can take a signed Git commit and mint a second copy with identical files, author, and a valid signature, but a different hash, and GitHub still stamps it Verified. Hash-based blocklists, dedup, and provenance systems inherit the flaw. Three attack routes cover every signature scheme GitHub verifies, and no forge has shipped a fix.
CISA added four actively exploited vulnerabilities to its KEV catalog, three of them scored CVSS 10.0, spanning Adobe ColdFusion, two Joomla page builders, and the Langflow AI platform. One ColdFusion flaw was hit within hours of disclosure; a Joomla flaw was exploited as a zero-day to plant Super User accounts. FCEB agencies must patch by July 10, 2026.
GhostLock (CVE-2026-43499) is a use-after-free in Linux futex priority-inheritance code that has shipped by default in nearly every distro since 2011. Nebula Security's public exploit turns any logged-in user into root with 97% reliability and escapes containers. Patching is the only real fix.
BeyondTrust shipped fixes for four vulnerabilities in Remote Support and Privileged Remote Access, including two pre-auth bypass flaws rated CVSS 9.2 that let unauthenticated attackers seize appliance accounts with elevated privileges. A third bug (8.7) enables denial-of-service and a fourth (8.5) lets low-privilege users reach data beyond their scope. Given the repeated in-the-wild exploitation of prior RS/PRA CVEs, upgrading to RS/PRA 25.3.3 is urgent.
A use-after-free in Linux KVM's shadow MMU, dubbed Januscape (CVE-2026-53359), lets a root guest with nested virtualization panic its host and, via a withheld exploit, run code as root on it. The bug shipped in 2010 and sat undetected for roughly 16 years. It is the first known guest-to-host escape that triggers on both Intel and AMD x86, and fixed stable kernels landed July 4, 2026.
A maximum-severity remote code execution flaw in Adobe ColdFusion, CVE-2026-48282, is being exploited in the wild just days after patches shipped. The bug needs no authentication and no user interaction, and Adobe is telling admins to patch within 72 hours. Roughly 800 ColdFusion instances sit exposed online.
A use-after-free race in the Linux epoll subsystem lets any local user reach root roughly 99% of the time, works from inside the Chrome renderer sandbox, and reaches Android. Kernels built on 6.4 or newer are affected until patched. There is no workaround because epoll cannot be disabled.
runZero disclosed seven vulnerabilities in FatFs, a FAT/exFAT filesystem library bundled into firmware across security cameras, drones, industrial controllers, and crypto wallets. Three carry a 7.6 CVSS and enable code execution, only one is fixed upstream, and the lone maintainer never responded. Public proof-of-concept exploit code is already out.
Google's Threat Intelligence Group, working with the FBI, Lumen, and others, degraded NetNut (aka Popa), one of the largest residential proxy networks built on roughly 2 million home devices. In a single June week, 316 distinct threat clusters were seen routing through NetNut exit nodes. The catch: the network traces back to a publicly traded company and resells through many brands, so one takedown doesn't kill it.
A newly documented threat actor, Armored Likho, is hitting government agencies and electric power operators across Russia, Brazil, and Kazakhstan with a Python-based stealer called BusySnake. The campaign blends espionage with financial theft and weaponizes CVE-2025-9491, a Windows LNK flaw patched only in November 2025.
CISA added Microsoft SharePoint Server flaw CVE-2026-45659 (CVSS 8.8) to its Known Exploited Vulnerabilities catalog after confirming active exploitation. The deserialization bug lets any authenticated user with Site Member permissions run code remotely. Federal agencies have until July 4, 2026 to patch.
A report claims a popular AI coding tool alters its own output, dash-vs-slash dates and look-alike Unicode apostrophes, to covertly signal its environment when it detects a proxy. Invisible to a human, readable by a server. The trust boundary just moved. The defense: inspect the characters and sanitize them in transit.
Sysdig says an AI agent executed a full ransomware operation with no human at the keyboard: exploiting a patched Langflow RCE, harvesting credentials, pivoting to a production MySQL/Nacos server, and encrypting 1,342 configurations. The encryption key was printed once and never saved, so paying gets victims nothing.
Attackers began probing Progress Kemp LoadMaster load balancers on June 29, 2026, targeting a CVSS 9.6 pre-auth command injection flaw. A public PoC and watchTowr's technical writeup are expected to escalate activity fast. Any internet-facing LoadMaster is at risk of unauthenticated code execution.
A two-week automated password spray against Azure CLI made 81 million login attempts and compromised 78 Microsoft accounts across 64 organizations. Attackers abused the deprecated ROPC OAuth flow to slip past Conditional Access and MFA that was configured but not fully enforced.
A CVSS 9.8 flaw in Oracle Payments lets unauthenticated attackers take over Oracle E-Business Suite over HTTP. Honeypots caught live exploitation over the weekend, despite no public PoC. EBS 12.2.3 through 12.2.15 are affected, and Oracle's fix shipped only last month.
A maximum-severity OIDC authentication bypass in SimpleHelp RMM is being actively exploited to forge Technician sessions on internet-facing servers. Attackers use that trusted admin channel to deploy a Node.js loader, TaskWeaver, and a cross-platform infostealer, Djinn, that harvests cloud, source-control, AI-assistant, and crypto credentials. CISA added the flaw to its KEV catalog with a July 2, 2026 federal patch deadline.
Three nation-state adversaries are actively targeting US and allied water and wastewater utilities, exploiting internet-exposed control systems and default credentials. Most affected utilities are small, underfunded, and lack the staff to detect or respond. The activity is shifting from espionage to pre-positioning for physical disruption.
Unit 42 attributes a sustained espionage campaign against Southeast Asian state-owned energy and government entities to CL-STA-1062, which breached at least 10 organizations in Q4 2025. The group pairs open-source tooling with a new bespoke .NET backdoor, TinyRCT, delivered via AppDomainManager injection.
CVE-2025-67038 lets an unauthenticated attacker run commands as root on the small Lantronix EDS5000 boxes that bridge industrial equipment to the network. Forescout caught targeted exploitation in the wild (from its BRIDGE:BREAK research), thousands of units are internet-exposed mostly in the US, and CISA added it to KEV on June 23.
An unknown actor exploited Cisco Catalyst SD-WAN as a zero-day for at least two months before disclosure, escalating a compromised admin account to full root on a communications service provider. Mandiant traced a malicious CSV upload, a hidden 'troot' account, and disciplined anti-forensics that erased nearly every trace.
CISA added CVE-2026-12569, a critical (CVSS 9.3) deserialization RCE in PTC Windchill PDMlink and FlexPLM, to its Known Exploited Vulnerabilities catalog on June 25. Attackers are dropping JSP web shells; PTC shipped patches and IOCs. It is the first PTC product ever added to KEV, and federal agencies are on the BOD 22-01 clock.
Kaspersky's StrikeShaker campaign pairs a stealthy new loader, SharkLoader, with an old truth: the front door was never locked. It uses "Perfect DLL Hijacking" to deliver Cobalt Strike onto systems breached through 13 known-exploited CVEs in Exchange, FortiOS, GeoServer, Zimbra, F5, and Cisco IOS XE. Every initial-access vector is already patched, and already detectable.
The FBI and CISA updated their March advisory on Russian intelligence phishing of Signal accounts, warning that operators now trick targets into surrendering their Signal Backup Recovery Key. One handover lets attackers restore the full backup, read all message history, and seize the account, and the stolen key keeps working even on a fresh account on the same number. The encryption is intact; the human holding the account is the target.
A Rust-based macOS implant tied to North Korea embeds 38 fabricated 'system failure' messages to convince LLM-assisted triage agents to abort their own analysis. It pairs that prompt-injection trick with a Telegram-driven C2, a six-command shell, and a Keychain-and-browser stealer. It is the first documented malware engineered to attack the analyst's AI, not the sandbox.
A former Huntress analyst claims an insider passed US law-enforcement communications to DevMan, a ransomware crew he says is targeting his family. Huntress calls it poor judgment, not betrayal, and notes researchers sometimes must talk to criminals to gather intel. The dispute is unresolved, but the lessons on insider access, researcher-to-criminal contact, and transparency are not.
A Featured Chrome extension, Adblock for YouTube, ships dormant infrastructure to inject arbitrary JavaScript on any site a victim visits. No malicious payload has been pushed yet, but a single server-side flag could weaponize it across 10 million browsers with no update and no store review. Its all-sites access and a trivially bypassed youtube.com check make every banking, work, and admin session reachable.
North Korea's Backdoor.Turn tunneled command-and-control through Microsoft Teams and stayed hidden for months. The real risk, as Patrick Duggan argues, is convoC2: the open-source clone that hands the same Teams-relay evasion to any criminal with a GitHub account. It is already in fraud crews' hands, and the only place to catch it is the endpoint.
A Russian-speaking initial access broker has run a credential-harvesting operation against 430,000-plus FortiGate firewalls since February 2026, deploying passive sniffers to scrape cleartext and hashed credentials from device traffic. The multi-vendor campaign has identified over 110 million credentials and now feeds Active Directory intrusions, lateral movement, and a thriving access-for-sale market.
A security firm planted a malicious AI agent skill that passed Cisco's, NVIDIA's, and skills.sh's scanners, borrowed 36,000 GitHub stars, and reportedly reached 26,000 agents. The trick: keep the shipped package clean and host the payload behind an external link rewritten after the scan clears. Here is why the entire trust model around agent skills is broken.
A 29-year-old heap over-read in the Squid web proxy, dubbed Squidbleed (CVE-2026-47729), lets any permitted proxy user leak another user's cleartext HTTP requests, including Authorization headers and session tokens. The flaw lives in Squid's default FTP parser and was caught by an AI model. Proof-of-concept code is public.
CISA is urging every Fortinet customer to rotate credentials and harden devices after the FortiBleed leak exposed authentication data harvested from FortiGate appliances. Attackers can replay leaked credentials and session artifacts to walk straight past perimeter defenses. If you run Fortinet at the edge, treat every device as compromised until proven otherwise.
Paradigm Shift researchers published a working exploit, usbliter8, that achieves arbitrary code execution inside the SecureROM of Apple A12 and A13 chips. Burned into silicon at manufacture, the flaw cannot be patched by any software update. It requires physical access and DFU mode, completes in under two seconds, and affects iPhone XS through iPhone 11, several iPads, and Apple Watch Series 4 and 5.
Microsoft has attributed a supply chain compromise of the Mastra AI agent framework's npm ecosystem to North Korean state-sponsored hackers. Poisoned packages pushed credential-stealing and backdoor payloads to developers building AI agents. The campaign extends Pyongyang's long-running assault on open-source registries and developer machines.
A Russian-speaking threat actor has compromised 86,644 internet-facing FortiGate appliances using leaked credentials and legacy hashing weaknesses. CISA issued an emergency advisory urging password resets, PBKDF2 migration, and MFA. The attack self-propagates by harvesting credentials from traffic passing through breached devices.
Microsoft researchers detailed AutoJack, an exploit chain that lets a single attacker-controlled web page reach a privileged local service through an AI browsing agent and run arbitrary commands on the host. The flaw lives in AutoGen Studio's MCP WebSocket route, which never shipped in the stable PyPI build but did ship unpatched in two pre-releases. No credentials, no extra clicks, no exploitation in the wild yet.
A flaw in Google Cloud's Vertex AI SDK for Python let an attacker with zero access to a victim's project hijack ML model uploads and run code inside Google's serving infrastructure. The only prerequisites were the attacker's own GCP project and the victim's project ID, which is often public. Patch to google-cloud-aiplatform 1.148.0 and set an explicit staging_bucket.
China-linked UNC6508 backdoored REDCap research servers at US and Canadian medical and defense institutions, then abused Google Workspace content compliance rules to silently BCC matching emails to attacker-controlled inboxes for over a year.
Three chained vulnerabilities in LiteLLM let low-privilege users escalate to admin and execute code on AI gateway servers. Critical-severity chain exposes all provider keys, credentials, and prompts flowing through the proxy.
A Chinese state-sponsored threat actor compromised an isolated network for a decade by hijacking authentication flows through a connected system. The campaign demonstrates sophisticated persistence techniques against air-gapped infrastructure.
Chinese APT group Velvet Ant compromised the Linux login layer itself—backdooring PAM modules and OpenSSH binaries on air-gapped networks since 2016. Sygnia researchers found nine variants recording credentials where ordinary defenses cannot reach.
A critical 9.8 CVSS vulnerability in Splunk Enterprise allows unauthenticated attackers to achieve remote code execution through exposed PostgreSQL sidecar endpoints. WatchTowr Labs published a detailed exploit chain exploiting missing authentication controls.
On June 12, 2026, Anthropic received a US government directive and suspended Fable 5 and Mythos 5 for every customer worldwide, including its own foreign-national employees. The operational lesson for defenders: frontier-AI availability is now a supply-chain dependency policy can sever in minutes. What to do this quarter.
Attackers compromised more than 400 packages in Arch Linux's AUR by adopting orphaned repositories and injecting credential-stealing malware with eBPF rootkit capabilities into build scripts. The Rust-based stealer harvests developer secrets and establishes persistence through systemd services.
Researchers demonstrate a new attack class that weaponizes AI coding agents by injecting malicious instructions through Sentry error reports. 2,388 organizations exposed with an 85% exploitation success rate against popular AI assistants.
The ShinyHunters extortion crew exploited CVE-2026-35273, a 9.8-severity zero-day in Oracle PeopleSoft, to breach over 100 organizations—68% of them universities. Oracle patched after attackers had already exfiltrated student and staff data from multiple institutions.
Two research teams demonstrated separate attacks forcing OpenClaw AI agent to execute malicious code and exfiltrate credentials. Imperva exploited message-object prompt injection via contact names; Varonis succeeded with simple phishing emails that bypassed verification rules.
A critical path traversal flaw in Langflow enables unauthenticated remote code execution and is being actively exploited in the wild. With 7,000 exposed instances and no patch available, organizations running AI development infrastructure face immediate risk.
ServiceNow patched a critical authentication bypass flaw on June 5, 2026, after threat actors exploited it to query customer instance tables. The vulnerability was known internally since April 7 but classified as non-urgent for two months.
Threat actors deployed 37 malicious wheel artifacts across 19 PyPI packages using *-setup.pth files to achieve automatic execution during Python startup. The Hades campaign steals credentials from GitHub, AWS, Azure, npm, and CI/CD platforms while incorporating AI defense evasion and wiper capabilities.
University of Toronto researchers built a proof-of-concept AI worm that uses local open-weight LLMs to autonomously reason through networks, generate runtime exploits, and self-replicate—compromising 62% of test hosts without touching commercial AI services or human input.
Anthropic shipped Claude Fable 5 for general use alongside Claude Mythos 5, the identical model with cyber safeguards removed for Project Glasswing partners. Frontier offensive-cyber capability now sits behind a classifier-and-fallback boundary, not absence, and a sanctioned variant ships with that boundary lifted. What it means for defenders.
CVE-2026-23111, a one-character typo in nf_tables, lets unprivileged users escalate to root and escape containers. Patched February 5, exploits published in April and June—update and reboot now.
CVE-2026-50751, a critical logic flaw in Check Point VPN certificate validation, allows unauthenticated attackers to bypass passwords in IKEv1 configurations. Exploitation tied to Qilin ransomware began May 7, targeting dozens of organizations globally.
A self-replicating worm has infected 73 Microsoft GitHub repositories across Azure, Microsoft, and MicrosoftDocs organizations. The Miasma variant exploits legitimate authentication channels to spread exponentially, compromising developer credentials and propagating through AI coding tools.
OpenAI rolls out Lockdown Mode for ChatGPT to mitigate data exfiltration risks from prompt injection attacks. The optional security feature disables web browsing, image support, and file downloads across Free, Plus, Pro, and Business tiers.
Bright Data's SDK embedded in free consumer apps converts always-on smart TVs and mobile devices into residential proxy exit nodes for AI web scraping. Security researchers found unauthenticated peer channels, VPN bypass on iOS, and traffic limits up to 200 GB monthly.
A security startup's autonomous AI agent discovered 21 zero-days in FFmpeg's 1.5 million lines of code for around $1,000, some bugs dormant for 23 years. The same week, Chrome 149 patched a record 429 vulnerabilities as Google overhauls its bounty program to handle the AI-driven submission flood.
Two sophisticated supply chain attacks have compromised over 100 npm packages, deploying a Rust-based information stealer with eBPF rootkit capabilities and a self-propagating worm that exploits AI coding assistants. The campaigns target developer credentials across cloud platforms, cryptocurrency wallets, and CI/CD pipelines.
A single malicious notification from WhatsApp, Slack, or SMS could hijack Google Gemini's voice assistant on Android, enabling attackers to control smart homes, poison AI memory, and fake messages from trusted contacts—no malicious app required.
Unknown attackers maintained persistent access to a senior stock exchange executive's Outlook mailbox for five months, exfiltrating data through consumer cloud services to evade detection. The operation used legitimate tools and infrastructure to blend with normal traffic.
A CVSS 7.8 vulnerability in Anthropic's Claude Code GitHub Action allowed attackers to hijack repositories through prompt injection and authentication bypass. The flaw could have poisoned the official action itself, cascading malicious code to all downstream projects.
A single line of debug code left in production builds of six Microsoft 365 Android apps disabled authentication checks, allowing any app on the device to steal user account tokens without password prompts or user interaction. Microsoft patched the flaw affecting billions of app downloads after Enclave Security disclosed it.
A critical vulnerability in GitHub.dev allows attackers to steal full-access GitHub OAuth tokens through a single malicious link. The exploit leverages VS Code's webview mechanism and extension system to bypass security controls and access all private repositories.
A four-person team's single-month Anthropic bill hit $113,421, more than the annual cost of one of those four people. AI crossed from expense to headcount-class spend, and that unmonitored six-figure channel is now both an attack surface and a gift to invoice-fraud crews.
Exploitation timelines have shrunk from days to hours while median patching times increased to 43 days. AI tools like Claude Mythos identified 10,000+ critical vulnerabilities in one month—and attackers have the same capabilities.
The June 2, 2026 White House executive order pairs aggressive 30-to-60-day federal cyber-defense mandates with a no-licensing stance on frontier AI models, and formally recognizes that frontier models now carry benchmark-worthy offensive cyber capability. What the deadlines mean for critical-infrastructure operators, and how Etairos and Caver already deliver what the order spends 60 days reaching toward.
Russian FSB-linked threat group Gamaredon weaponizes CVE-2025-8088 WinRAR vulnerability to deliver modular malware framework targeting Ukrainian organizations. Attack chain deploys GammaPhish HTML applications, GammaWorm propagation tools, and GammaSteel data theft modules.
The codexui-android npm package, downloaded 29,000 times weekly, has been quietly exfiltrating OpenAI Codex authentication tokens to attacker infrastructure for over a month. The campaign extends to Android apps with 60,000+ combined downloads, targeting AI developer workflows with persistent credential theft.
A sophisticated supply chain attack has compromised multiple Red Hat npm packages, deploying a self-propagating worm that steals credentials, cloud identities, and secrets from developer machines. The attack leverages open-sourced tools from the Shai-Hulud campaigns and uses unique encryption per infection to evade detection.
Red Access investigation reveals over 2,000 corporate applications built with AI development platforms are exposing sensitive data on the open internet. Traditional security tools—EDR, DLP, CASB—weren't designed to detect this new category of Shadow AI risk.
Palo Alto Networks CVE-2026-0257 authentication bypass vulnerability is being actively exploited in the wild, allowing attackers to establish unauthorized VPN connections. Rapid7 confirms successful exploitation across numerous customers dating back to May 17, with threat actors gaining internal network access.
New Russian-speaking threat actor GREYVIBE has deployed AI-assisted malware against Ukrainian military, government, and civilian targets since August 2025. WithSecure researchers identify the group as a hybrid operation blending nation-state objectives with cybercriminal tactics and tooling.
A sophisticated supply chain attack campaign compromised 500 downloads of a fake Sicoob banking SDK on NuGet while 14 malicious npm packages targeted AWS credentials and cloud secrets. The attacks demonstrate attackers moving beyond simple typosquatting to manufactured legitimacy tactics.
Security researchers disclosed ChatGPhish, a vulnerability allowing attackers to embed malicious Markdown links and images in web pages that ChatGPT automatically renders when summarizing content. The attack leverages implicit trust in the AI interface to bypass traditional security controls and deliver phishing content directly through chatgpt.com's response renderer.
Threat actors deployed an LLM agent for post-exploitation after breaching a Marimo notebook via CVE-2026-39987, exfiltrating a complete PostgreSQL database in under two minutes. The attack demonstrates how AI agents enable adaptive, real-time exploitation without pre-staged playbooks.
A critical 9.4 CVSS vulnerability in Gogs allows any authenticated user to achieve remote code execution through malicious branch names during rebase operations. Over 1,100 internet-facing instances remain unpatched since disclosure in March 2026.
Threat actors are exploiting CVE-2026-35616, a critical authentication bypass in FortiClient EMS, to deploy credential-stealing malware disguised as legitimate Fortinet updates. The attack abuses trusted endpoint management infrastructure to compromise every managed device without requiring separate intrusion paths.
CrowdStrike, Google, and Shadowserver Foundation have dismantled all four command-and-control channels of GlassWorm malware, ending a 16-month campaign that poisoned over 300 GitHub repositories and targeted developers through trojanized VS Code extensions and malicious packages.
A Nightwing contractor working for CISA exposed AWS GovCloud keys, Entra ID SAML certificates, and plaintext passwords in a public repo for six months while seven scanner alerts went ignored. The exposure is a hygiene failure; the unanswered question is whether the keys were ever abused.
A malicious npm package named mouse5212-super-formatter exfiltrated files from Claude AI's user directory to attacker-controlled GitHub repositories. The campaign, dubbed Malware-Slop, demonstrates how AI-generated malware is lowering entry barriers for threat actors.
North Korean Lazarus Group is using RemotePE, a sophisticated memory-only remote access trojan, to target financial and cryptocurrency organizations. The malware executes entirely in memory with no filesystem artifacts, making detection extremely difficult.
Push-based MFA is failing organizations as attackers weaponize notification fatigue and social engineering to gain legitimate-looking access. The 2022 Cisco breach proves this technique works even against mature security programs.
The FBI has issued a warning about Kali365, a sophisticated phishing-as-a-service platform specifically designed to harvest Microsoft 365 credentials. The service lowers the technical barrier for cybercriminals to launch convincing credential theft campaigns at scale.
Coordinated cross-ecosystem attack targets developers with 34 malicious packages across 384 versions. Campaign specifically targets crypto, DeFi, Solana, and AI developers to steal credentials, SSH keys, and cloud tokens.
Eight Packagist packages compromised with malicious code hidden in package.json files rather than standard Composer manifests. Attack demonstrates sophisticated cross-ecosystem technique that bypasses conventional PHP security scanning focused solely on composer.json.
GitHub introduces mandatory 2FA-gated staged publishing for npm packages and new install source flags, requiring human approval before packages go live. The changes directly address the surge in supply chain attacks like TeamPCP's widespread poisoning campaign.
Multiple Laravel-Lang PHP packages were compromised to distribute a sophisticated credential stealer targeting cloud credentials, cryptocurrency wallets, and authentication tokens. Over 700 malicious versions were published in rapid succession through compromised organization-level access.
Anthropic's Project Glasswing has uncovered over 10,000 high and critical-severity vulnerabilities in globally critical software within one month of operation. The initiative grants 50 partners early access to Claude Mythos Preview, an AI model capable of autonomous vulnerability discovery that's forcing a fundamental shift in patch cycles.
The NSA Artificial Intelligence Security Center released a Cybersecurity Information Sheet on May 20, 2026 warning that Model Context Protocol deployments carry novel and systemic risks established defenses do not adequately address. The agency calls out serialization risks, trust boundaries, agent misuse, dynamic tool invocation, implicit trust, and context sharing.
Belarus-aligned APT Ghostwriter is targeting Ukrainian government entities with multi-stage JavaScript malware disguised as legitimate Prometheus learning platform communications. The campaign leverages compromised accounts and delivers Cobalt Strike payloads through obfuscated registry-based execution.
Automated campaign injected malicious GitHub Actions workflows into 5,561 repositories within six hours, exfiltrating CI secrets, cloud credentials, and tokens to attacker-controlled infrastructure. The attack used forged identities and throwaway accounts to bypass detection.
A single cached AWS access key exposed 98% of a company's cloud environment. Despite billions in security spending, identity-based attacks succeeded in 90% of 2025 breach investigations because tools can't map how credentials chain into exploitable paths.
GitHub confirmed breach of internal repositories after employee device compromise via malicious Nx Console VS Code extension. Attackers exfiltrated 3,800 repositories in attack live for only 18 minutes on Visual Studio Marketplace.
Attackers compromised two popular GitHub Actions repositories, redirecting all existing tags to malicious commits that exfiltrate CI/CD credentials. The attack used imposter commits to bypass pull request reviews and affected any workflow not pinned to specific commit SHAs.
Microsoft has taken down Fox Tempest's malware-signing-as-a-service operation that exploited the company's Artifact Signing system to distribute ransomware and malware to thousands of victims. The service charged criminals $5,000-$9,000 to sign malicious code with fraudulent certificates.
A maximum severity vulnerability (CVSS 10.0) in ChromaDB, a widely-used vector database for AI applications, allows unauthenticated attackers to execute arbitrary code and hijack servers. Organizations running ChromaDB versions before 0.5.15 face immediate risk of complete system compromise.
EvilTokens phishing-as-a-service platform compromised over 340 Microsoft 365 organizations by exploiting OAuth consent flows that sit structurally below MFA controls. Attackers walk away with long-lived refresh tokens that survive password resets and produce no suspicious sign-in events.
Critical heap buffer overflow in NGINX versions 0.6.27 through 1.30.0 is being actively exploited in the wild. The vulnerability, introduced in 2008, allows unauthenticated attackers to crash worker processes or achieve remote code execution on systems without ASLR protection.
Three coordinated attacks on npm, PyPI, and Docker Hub within 48 hours targeted developer credentials rather than code. Attackers are shifting from tampering with software to stealing the access that makes trusted software possible.
A newly disclosed Windows zero-day vulnerability dubbed MiniPlasma allows unprivileged users to escalate to SYSTEM-level access through a flaw in the Print Spooler service. Proof-of-concept code is now publicly available with no patch currently deployed.
The Tycoon2FA phishing-as-a-service platform is hijacking Microsoft 365 accounts by exploiting OAuth device code authentication flows, bypassing multi-factor authentication protections. Security researchers have identified this threat targeting organizations through adversary-in-the-middle attacks since August 2023.
CVE-2026-44338, a critical authentication bypass in PraisonAI's multi-agent orchestration framework, was actively probed within 3 hours and 44 minutes of public disclosure. The flaw affects 32 versions of the Python package and exposes sensitive API endpoints to unauthenticated attackers.
AI models are generating confident but incorrect outputs that drive security decisions, with 36 of 40 tested models more likely to provide wrong answers than correct ones. Organizations deploying AI in cybersecurity operations face risks from missed threats, fabricated alerts, and dangerous remediation recommendations.
Remus infostealer has emerged as a sophisticated Malware-as-a-Service platform targeting browser sessions and credentials. With rapid development cycles and advanced evasion techniques, this threat demands immediate attention from security teams.
Russian FSB-affiliated APT group Turla has re-engineered its Kazuar backdoor from a monolithic framework into a three-tier modular botnet architecture. The transformation enables persistent access through peer-to-peer coordination while reducing detection footprint across compromised government and defense networks.
Anonymous researcher Chaotic Eclipse disclosed two critical Windows zero-days: YellowKey enables BitLocker bypass through Windows Recovery Environment in minutes, while GreenPlasma allows SYSTEM-level privilege escalation via CTFMON. Both vulnerabilities remain unpatched as tensions escalate with Microsoft.
Three malicious versions of the popular Node-IPC npm package contain obfuscated stealer malware designed to exfiltrate developer secrets including AWS, Azure, GCP credentials, and SSH keys. The compromised versions were published after 21 months of package dormancy by a maintainer with no prior publish history.
A grenade-style IED was found underwater at the J.B. Converse Reservoir dam in Mobile, AL on May 13, 2026, the drinking water source for roughly 350,000 residents. Different vector, same target class as the active cyber campaigns against U.S. water systems.
Agentic AI is already running in production environments across organizations, executing tasks and consuming data without security team oversight. The gap between AI deployment speed and security understanding is compounding weekly, creating a supply chain problem that mirrors past technology adoption failures.
TeamPCP threat actors compromised 42 TanStack packages and infiltrated npm/PyPI repositories from Mistral AI, UiPath, OpenSearch, and Guardrails AI using GitHub Actions OIDC token hijacking. The worm produces validly attested malicious packages and includes a destructive wiper component targeting developers who revoke compromised tokens.
RubyGems has temporarily disabled new account registration following a major supply chain attack involving hundreds of malicious packages. The attack targeted the package manager's infrastructure and distributed exploits, prompting Mend.io to suspend signups while the incident is contained.
TeamPCP successfully compromised Checkmarx's Jenkins AST plugin just weeks after breaching the company's KICS Docker image, indicating persistent access or incomplete remediation. The attack targeted the Jenkins Marketplace with a malicious plugin version, escalating concerns about supply chain security in DevSecOps tooling.
Google has identified the first known case of threat actors using AI to develop a zero-day exploit—a 2FA bypass in an open-source administration tool. The discovery marks a watershed moment in offensive security capabilities and signals compressed attack timelines.
Compromised FortiGate VPN credentials led to deployment of three Nightmare-Eclipse PE tools and a previously undocumented Go tunneling agent (BeigeBurrow) just eight days after public toolkit release. All privilege escalation attempts failed.
Attackers compromised JDownloader's official website to replace legitimate installers with Python-based remote access trojan malware. The supply chain attack targeted users of the popular download manager with 1.5 billion downloads worldwide.
A critical out-of-bounds read vulnerability (CVE-2026-7482, CVSS 9.1) in Ollama enables unauthenticated attackers to exfiltrate entire process memory from over 300,000 servers. Two additional unpatched Windows vulnerabilities allow persistent code execution through the update mechanism.
Twelve critical vulnerabilities in the widely-used vm2 Node.js sandbox library allow attackers to escape isolation and execute arbitrary code on host systems. Three vulnerabilities scored perfect 10.0 CVSS ratings, affecting all versions through 3.11.1.
A confused deputy flaw in Claude's 7M-user Chrome extension lets any other extension hijack your AI agent and exfiltrate Google Drive, Gmail, and GitHub — no permissions required. Anthropic's patch was bypassed in 3 hours.
Three malicious PyPI packages delivered ZiChatBot malware to Windows and Linux systems, accumulating 2,480 downloads before removal. The attack leveraged Zulip chat APIs for command-and-control, with code similarities linking it to Vietnam-aligned APT32.
A 9-year-old Linux kernel bug in the AEAD crypto interface lets any local user overwrite any file’s page cache and get root. The exploit is 732 bytes of Python. Researchers published it on April 29 — it works on every major distribution.
A new Linux backdoor called PamDOORa is being sold on Russian cybercrime forums for $1,600, targeting PAM authentication modules to steal SSH credentials and maintain persistent access. The malware represents an evolution beyond open-source PAM backdoors with integrated anti-forensic capabilities.
A sophisticated Linux implant is harvesting developer credentials from npm, PyPI, AWS, Docker, and CI/CD systems to poison software packages. The fileless malware uses dual-layer rootkit architecture and seven persistence mechanisms to maintain long-term access.
NVIDIA's VP of applied deep learning told Axios compute costs "far beyond" employee costs for his team. A 2024 MIT study found AI is economically viable in only 23% of roles. Uber's 2026 AI budget is already gone. The economics are still being figured out.
Attackers compromised official DAEMON Tools installers with digitally signed malware starting April 8, 2026, infecting thousands across 100+ countries. Only a dozen organizations received second-stage payloads, indicating sophisticated targeting of government, manufacturing, and research entities.
New credential theft framework PCPJack exploits five CVEs to spread worm-like across cloud environments while deliberately removing TeamPCP artifacts. The campaign targets Docker, Kubernetes, and multiple cloud services to harvest credentials from cloud, container, and financial platforms.
Iranian state-sponsored group MuddyWater deployed fake ransomware attacks via Microsoft Teams social engineering to mask credential theft and persistence operations. The campaign abused legitimate remote access tools and bypassed traditional encryption workflows in favor of data exfiltration.
Gartner confirms AI agent deployment is outpacing governance capabilities. Roughly 50% of enterprise identity activity now occurs outside centralized IAM visibility, creating an invisible layer of unmanaged access that traditional security tools cannot see.
Large-scale scan of 2 million hosts reveals self-hosted AI infrastructure is more vulnerable than any software category previously analyzed. Over 1,600 Ollama APIs responded to unauthenticated requests, exposing everything from personal chatbots to cloud management systems.
Attackers compromised Context.ai via Lumma Stealer, harvested OAuth tokens, and pivoted into Vercel's infrastructure to reach 700+ enterprise customers including Cloudflare, Palo Alto, and Zscaler.
Four npm packages in the SAP CAP ecosystem were hijacked in the Mini Shai-Hulud campaign, exfiltrating CI/CD secrets and npm tokens from 1,800+ developers with 570K+ combined weekly downloads.
Attackers hijacked the Axios npm maintainer account in March 2026 and published two versions containing a cross-platform remote access trojan that erased its own install traces after execution.
A fake @bitwarden/cli package lived 90 minutes on npm, pulled 334 times, and deployed a credential harvester plus the first known malware specifically engineered to extract secrets from AI coding assistant sessions.
ShinyHunters breached Vimeo by compromising Anodot, a third-party analytics vendor with a trusted integration, extracting 119K email addresses before dumping the data after extortion demands were refused.
ShinyHunters dumped 100GB of McGraw-Hill data after a Salesforce misconfiguration exposed 13.5 million records, the third major Salesforce-vector breach claimed by the group in two months.
ShinyHunters social-engineered an ADT employee into handing over their Okta SSO credentials. One phone call gave attackers access to Salesforce and 5.5 million customer records.
A 48-hour phishing campaign used AI-generated code of conduct violation emails to target 35,000 Microsoft 365 users. AiTM relay bypassed MFA entirely, capturing live session tokens.
The EvilTokens PhaaS campaign exploited Microsoft's OAuth device code flow to capture persistent refresh tokens across 340 organizations in five countries. MFA provided no protection.
ShinyHunters listed Medtronic on their breach marketplace April 17, claiming 9 million patient records and terabytes of corporate data from the maker of pacemakers and insulin pumps.
Everest ransomware listed Fiserv on May 3 with 1,064 user credentials and 170 vendor credentials claimed. Fiserv processes payments for 10,000+ financial institutions.
A third-party vendor breach exposed Booking.com customer reservation details including travel dates, home addresses, and special requests. Targeted phishing hit affected users within days.
Japanese police arrested three minors who automated 220,000 fraudulent signups using ChatGPT. No prior coding experience required.
One attacker, nine agencies, 195 million citizen records. Claude Code executed 75% of the remote commands used in the campaign.
Threat actor GTG-2002 used Claude Code to fully automate cyber extortion across 17 targets in one month. Anthropic detected and disclosed the campaign.
Google GTIG found malware that queries the Gemini API on an hourly schedule to regenerate its own VBScript code. Signature-based detection is useless against it.
Google GTIG confirmed APT28 deployed PROMPTSTEAL in Ukraine operations. The tool queries Qwen2.5-Coder via Hugging Face to generate attack commands dynamically.
CISA officials are evaluating a 3-day patching SLA for actively exploited CVEs. The stated justification is AI-compressed exploit timelines. Enterprise IT is not ready.
A use-after-free in Chrome's WebGPU Dawn engine is being exploited in the wild. CISA added it to the KEV catalog with a 14-day federal patch deadline.
An auth bypass in cPanel/WHM was exploited from Feb 23 to Apr 28 with no patch available, compromising 44,000+ servers and putting 1.5 million at risk.
Microsoft patched 163 CVEs including a wormable kernel RCE in the Windows TCP/IP stack and two zero-days already under active exploitation at release.
GRU-linked APT28 exploited unpatched TP-Link routers to perform DNS hijacking, intercepting M365 logins and capturing session tokens from NATO and Ukrainian targets.
Lazarus Group created two US shell companies to run fake developer interviews, delivering a 3-stage malware chain targeting cryptocurrency wallet private keys.
CVE-2026-0625 in four EOL D-Link router models has been exploited by Mirai since November 2025. D-Link confirmed no patch is coming; replacement is the only fix.
OAuth tokens connected to Google and Microsoft environments bypass MFA, never expire, and persist after employee departures. New research shows 80% of security leaders recognize the risk, but 45% do nothing to monitor these persistent access grants at scale.
Mythos generates functional exploit code at 72.4% accuracy. The NHS locked down 850 repos. They're not wrong — here's what that actually means for your security posture.
Microsoft Edge loads every saved password into unencrypted memory at launch and keeps them there. Microsoft calls it working as intended. Your engineering workstation is probably running Edge.
CyberAv3ngers actively compromising Unitronics PLCs in water treatment, energy, and manufacturing. Live exposure data, incidents, and assessment guidance.