Software Supply Chain Vulnerability3 Min Read June 19, 2026 AutoJack Attack Lets One Web Page Hijack AI Agent for Host Code Execution Microsoft researchers have detailed an exploit chain, named AutoJack, that turns an AI browsing agent into a delivery vehicle for remote…
Cloud Security Vulnerability2 Min Read June 18, 2026 F5 Patches Two Critical NGINX Open Source Flaws Enabling Remote Code Execution F5 has released security updates to address two critical security flaws in NGINX Open Source that could be exploited to achieve code execution…
Cryptocurrency Malware2 Min Read June 18, 2026 Microsoft Details Windows Clipper Malware Campaign Using USB LNK Worm and Tor-Based C2 Microsoft has disclosed details of a Windows-based cryptocurrency clipper campaign that has targeted users since February 2026 with…
Artificial Intelligence Vulnerability4 Min Read June 15, 2026 LiteLLM Vulnerability Chain Lets Low-Privilege Users Take Over AI Gateway Servers A default low-privilege account on a LiteLLM proxy can climb to full admin and run code on the server by chaining three vulnerabilities,…
Cybersecurity Hacking13 Min Read June 15, 2026 ⚡ Weekly Recap: Chrome 0-Day, UniFi Exploits, macOS Stealers, VPN Flaw and More Stuff broke again. Not in a movie way. An old tool was left exposed. An abandoned package was abused. A deprecated feature was still running…
Enterprise Software Vulnerability2 Min Read June 13, 2026 Critical Splunk Enterprise Flaw Lets Attackers Run Code Without Authentication Splunk has released security updates to address a critical security flaw in Splunk Enterprise that could be exploited to conduct…
AI Security Vulnerability2 Min Read June 12, 2026 LangGraph Flaw Chain Exposes Self-Hosted AI Agents to Remote Code Execution Cybersecurity researchers have disclosed details of three now-patched security flaws impacting LangGraph, including a critical vulnerability…
Data Breach Vulnerability3 Min Read June 11, 2026 ShinyHunters Exploits Oracle PeopleSoft Zero-Day (CVE-2026-35273) to Breach Universities The ShinyHunters extortion crew exploited an unpatched flaw in Oracle PeopleSoft to break into enterprise systems, steal data, and demand…
Cybersecurity News Hacking News18 Min Read June 11, 2026 ThreatsDay Bulletin: Worm Code Leaked, AI Agent Phished, Claude Code Patch + 28 New Stories It's been one of those weeks. You expect the usual noise: recycled malware, sloppy attacks, another easy target getting hit. Instead, there's…
Cyber Espionage Supply Chain Attack3 Min Read June 11, 2026 OceanLotus Hits Vietnam Investors With SPECTRALVIPER in FireAnt Attack The Vietnam-aligned threat actor known as OceanLotus has been attributed to two distinct campaigns that targeted domestic entities and stock…
Patch Management Vulnerability3 Min Read June 10, 2026 Ivanti, Fortinet, and SAP Release Patches for Multiple Critical Vulnerabilities Fortinet, Ivanti, and SAP have released security updates to address multiple critical security vulnerabilities that could result in arbitrary…
Open Source Vulnerability2 Min Read June 10, 2026 Unpatched Langflow Flaw CVE-2026-5027 Exploited for Unauthenticated RCE A high-severity unpatched security flaw in Langflow, an open-source low-code platform to build artificial intelligence (AI) applications, has…
Vulnerability Zero-Day4 Min Read June 10, 2026 Microsoft Patches Record 206 Flaws, Including Three Zero-Days and Critical RCE Bugs Microsoft on Tuesday released fixes for a record 206 security vulnerabilities impacting its software portfolio, including three flaws that…
AI Safety Artificial Intelligence6 Min Read June 10, 2026 Anthropic Releases Claude Fable 5, Its Most Powerful AI Yet, With Cyber Safeguards On June 9, Anthropic released Claude Fable 5, the most capable model it has ever made, generally available. It also did something unusual: it…
JavaScript Vulnerability3 Min Read June 10, 2026 Six Proto6 Vulnerabilities in protobuf.js Expose Node.js Apps to RCE and DoS Cybersecurity researchers have flagged half a dozen vulnerabilities in protobuf.js, a JavaScript and TypeScript implementation of Protocol…
Backup Software Vulnerability1 Min Read June 9, 2026 Veeam Backup & Replication RCE Flaw Lets Domain Users Run Remote Code Veeam has released security patches to address a critical flaw in its Backup & Replication software that could result in remote code…
Artificial Intelligence Network Security6 Min Read June 9, 2026 Researchers Build Self-Replicating AI Worm That Operates Entirely on Local, Open-Weight Models University of Toronto researchers have built and tested a proof-of-concept AI-driven computer worm that uses a locally hosted open-weight…
Open Source Software Supply Chain6 Min Read June 8, 2026 The Hardest Fork Mythos is real. I know a big chunk of the industry thinks it's a marketing stunt, and I get why. I get it. But I've seen the findings, and…
Endpoint Security Vulnerability3 Min Read June 6, 2026 AI Agent Uncovers 21 Zero-Days in FFmpeg; Chrome Patches Record 429 Bugs Two things landed within days of each other this week. A security startup reported 21 previously unknown vulnerabilities in FFmpeg, the media…
Vulnerability Web Security3 Min Read June 5, 2026 Hackers Exploit Critical Everest Forms Pro WordPress Plugin Flaw to Take Over Sites Threat actors are actively exploiting a critical security flaw in Everest Forms Pro, a WordPress plugin with about 4,000 active installations,…
Network Security Vulnerability2 Min Read June 4, 2026 Cisco Patches CVE-2026-20230 in Unified CM as Exploit Code Goes Public Cisco has patched a bug in Unified Communications Manager that lets an unauthenticated attacker on the network write files to the box and,…
Cybersecurity News Hacking News13 Min Read June 4, 2026 ThreatsDay Bulletin: AI Agents Gone Wrong, Sketchy C2 Tools, ClickFix Tricks, JS Backdoors & 20+ New Stories It got stupid again. The internet still feels held together with tape. Bad plugins, old bugs, fake tools, trusted apps doing shady things.…
Vulnerability Web Security2 Min Read June 4, 2026 CISA Adds Exploited Magento RCE Flaw CVE-2026-45247 to KEV Catalog The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a critical flaw impacting Mirasvit Cache Warmer, a popular…
Cloud Security Vulnerability3 Min Read June 3, 2026 Autonomous AI Tool Finds 2-Year-Old RCE Flaw in Redis (CVE-2026-23479) Redis has patched a use-after-free in its blocking-client code that lets an authenticated user run arbitrary OS commands on the machine…
Cybersecurity Hacking11 Min Read June 1, 2026 ⚡ Weekly Recap: New Linux Flaw, PAN-OS Exploit, AI-Powered Attacks, OAuth Phishing and More Monday hit like a cron job with anger issues. A busted auth path here, a repo-side faceplant there, some "patched-ish" thing already getting…
Artificial Intelligence Vulnerability Research6 Min Read May 29, 2026 ChatGPhish Vulnerability Turns ChatGPT Web Summaries Into a Phishing Surface Cybersecurity researchers have disclosed details of a vulnerability in OpenAI ChatGPT that leverages the artificial intelligence (AI)…
Artificial Intelligence Vulnerability3 Min Read May 29, 2026 Attackers Use LLM Agent for Post-Exploitation After Marimo CVE-2026-39987 Exploit An unknown threat actor has been observed using a large language model (LLM) agent to conduct post-compromise actions after obtaining initial…
Open Source Vulnerability3 Min Read May 28, 2026 Critical Gogs RCE Vulnerability Lets Any Authenticated User Execute Arbitrary Code A critical security vulnerability has been disclosed in Gogs, a popular open-source self-hosted Git service, that allows an authenticated user…
Cybersecurity News Hacking News11 Min Read May 28, 2026 ThreatsDay Bulletin: Claude Security Plugin, Azure Priv-Esc, Kali365 MFA Bypass, FIFA Scams +15 More Every time you think the industry has finally stopped doing some reckless, low-effort crap, somebody spins up a fresh box full of sketchy…
Enterprise Security Vulnerability1 Min Read May 26, 2026 Microsoft Patches SharePoint RCE Flaw CVE-2026-45659 Across Server Versions Microsoft has rolled out updates to fix a remote code execution vulnerability impacting SharePoint that could be exploited by bad actors in…
Threat Intelligence Vulnerability2 Min Read May 26, 2026 KnowledgeDeliver LMS Flaw Exploited to Deploy Godzilla and Cobalt Strike A now-patched high-severity security flaw affecting Digital Knowledge KnowledgeDeliver, a Learning Management System (LMS) popular in Japan,…
Cybersecurity Hacking14 Min Read May 25, 2026 ⚡ Weekly Recap: Linux Flaws, Defender 0-Days, Router Botnets, and Supply Chain Chaos Monday recap. Same mess, new week. A sketchy dev tool got people pwned, old bugs came back from the dead, and security products somehow needed…
DevSecOps Malware2 Min Read May 23, 2026 Packagist Supply Chain Attack Infects 8 Packages Using GitHub-Hosted Linux Malware A new "coordinated" supply chain attack campaign has impacted eight packages on Packagist including malicious code designed to run a Linux…
Vulnerability Website Security2 Min Read May 23, 2026 Drupal Core SQL Injection Bug Actively Exploited, Added to CISA KEV The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a recently patched critical security flaw impacting Drupal Core to…
Cybersecurity News Hacking News18 Min Read May 21, 2026 ThreatsDay Bulletin: Linux Rootkits, Router 0-Day, AI Intrusions, Scam Kits and 25 New Stories This week starts small. A token leaks. A bad package slips in. A login trick works. An old tool shows up again. At first, it feels like the…
Vulnerability Web Security2 Min Read May 21, 2026 Highly Critical Drupal Core Flaw Exposes PostgreSQL Sites to RCE Attacks Drupal has released security updates for a "highly critical" security vulnerability in Drupal Core that could be exploited by attackers to…
Email Security Vulnerability3 Min Read May 19, 2026 SEPPMail Secure E-Mail Gateway Vulnerabilities Enable RCE and Mail Traffic Access Critical security vulnerabilities have been disclosed in SEPPMail Secure E-Mail Gateway, an enterprise-grade email security solution, that…
Software Security Vulnerability4 Min Read May 18, 2026 Ivanti, Fortinet, SAP, VMware, n8n Patch RCE, SQL Injection, Privilege Escalation Flaws Ivanti, Fortinet, n8n, SAP, and VMware have released security fixes for various vulnerabilities that could be exploited by bad actors to…
Server Security Vulnerability2 Min Read May 17, 2026 NGINX CVE-2026-42945 Exploited in the Wild, Causing Worker Crashes and Possible RCE A newly disclosed security flaw impacting NGINX Plus and NGINX Open has come under active exploitation in the wild, days after its public…
Cybersecurity News Hacking News9 Min Read May 14, 2026 ThreatsDay Bulletin: PAN-OS RCE, Mythos cURL Bug, AI Tokenizer Attacks, and 10+ Stories Everything is still on fire. This week feels dumb in the worst way — bad links, weak checks, fake help desks, shady forum posts, and…
Vulnerability Web Server3 Min Read May 14, 2026 18-Year-Old NGINX Rewrite Module Flaw Enables Unauthenticated RCE Cybersecurity researchers have disclosed multiple security vulnerabilities impacting NGINX Plus and NGINX Open, including a critical flaw that…
Artificial Intelligence Vulnerability2 Min Read May 13, 2026 Microsoft's MDASH AI System Finds 16 Windows Flaws Fixed in Patch Tuesday Microsoft has unveiled a new multi-model artificial intelligence (AI)-driven system called MDASH to facilitate vulnerability discovery and…