Timeline

Intelligence Timeline

A real, chronological record of every report as it was published — 300 most-recent entries. Refreshed automatically as new intelligence is ingested.

2026-07-30 · MEDIUM

Do you recommend TryHackMe?

2026-07-30 · MEDIUM

Russian hackers exploit Exchange OWA zero-day for long-term mailbox access

2026-07-29 · MEDIUM

Dealing with AI-Generated Extortion

2026-07-29 · HIGH

Cisco warns of FMC static credential flaw exploited in zero-day attacks

CVE-2026-20316
2026-07-29 · MEDIUM

Hugging Face built an interactive replay of the OAl agent that breached them

2026-07-29 · HIGH

Critical Rails Flaw Could Let Unauthenticated Attackers Read Server Files via Image Uploads

CVE-2026-66066
2026-07-29 · HIGH

CVE-2026-63077: Critical unauthenticated remote code execution in JetBrains TeamCity

CVE-2026-63077
2026-07-29 · HIGH

netfoil: Incorrect block responses could lead to localhost traffic

2026-07-29 · HIGH

proot-distro has a Container Isolation Bypass via Crafted Restore Archive

CVE-2026-54727CVE-2026-54727
2026-07-29 · CRITICAL

WP2Shell WordPress Exploit Technical Analysis and Real Attack Data

2026-07-29 · CRITICAL

AgentCore CLI Bedrock Agent Import Vulnerable to Code Injection via Improper Triple-Quote Escaping

CVE-2026-11393CVE-2026-11393
2026-07-29 · HIGH

Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory

CVE-2026-59726
2026-07-29 · HIGH

swagger-typescript-api vulnerable to code injection via unescaped `servers[0].url` in axios http-client template

CVE-2026-54661CVE-2026-54661
2026-07-29 · HIGH

swagger-typescript-api vulnerable to code injection via unescaped enum string values

CVE-2026-54664CVE-2026-54664
2026-07-29 · HIGH

swagger-typescript-api vulnerable to code injection via unescaped OpenAPI path strings in generated method bodies

CVE-2026-54666CVE-2026-54666
2026-07-29 · HIGH

swagger-typescript-api vulnerable to code injection via unescaped `servers[0].url` in fetch http-client template

CVE-2026-54662CVE-2026-54662
2026-07-29 · MEDIUM

Only 1% of AI-discovered vulnerabilities have actually been exploited in the wild - a rate that matches standard, human-found bugs.

2026-07-29 · HIGH

CodeAlpha_SecureCodingReview exploit

2026-07-29 · HIGH

Binary-Exploitation exploit

2026-07-29 · HIGH

Stored-XSS-via-Content-Tag-Names-Microweber- exploit

2026-07-29 · HIGH

Exploit for Improper Authentication in Redhat Keycloak exploit

2026-07-29 · HIGH

Exploit for CVE-2026-53921 exploit

CVE-2026-53921
2026-07-29 · HIGH

Exploit for Improper Authentication in Checkpoint Multi-Domain_Security_Management exploit

2026-07-29 · HIGH

Exploit for CVE-2026-65761 exploit

CVE-2026-65761
2026-07-29 · HIGH

exploit-counter exploit

2026-07-29 · MEDIUM

JFrog Zero-Days Exploited in OpenAI-Hugging Face Hack

2026-07-29 · CRITICAL

Critical: Dysphoria Botnet Uses Blockchain Domains to Hide C2 Infrastructure (CVE-2017-17215)

CVE-2017-17215
2026-07-29 · LOW

First-Ever Fully Autonomous AI Cyberattack Exploits 0-Day Flaws to Infiltrate Hugging Face

2026-07-29 · MEDIUM

Our biggest AI security issue wasn't prompt leakage. It was what people built afterward.

2026-07-29 · HIGH

FBI sees Anthropics Mythos as a law enforcement challenge

2026-07-29 · HIGH

handlebars-ssti-ast-rce exploit

2026-07-29 · HIGH

Exploit for CVE-2026-64725 exploit

CVE-2026-64725
2026-07-29 · HIGH

CVE-Vulnerability-Reproduction exploit

2026-07-29 · HIGH

Exploit for Use of Hard-coded Credentials in Solarwinds Web_Help_Desk exploit

2026-07-28 · HIGH

openhole-server vulnerable to path traversal via URL-decoded request path

CVE-2026-54650CVE-2026-54650
2026-07-28 · HIGH

Style Dictionary - Prototype Pollution in convertTokenData utility function

CVE-2026-54639CVE-2026-54639
2026-07-28 · HIGH

`datamodel-code-generator` vulnerable to code injection via unescaped carriage return in `--extra-template-data` `comment` field

CVE-2026-54654CVE-2026-54654
2026-07-28 · HIGH

`datamodel-code-generator` vulnerable to code injection in via attacker-controlled `default_factory` schema field

CVE-2026-54653CVE-2026-54653
2026-07-28 · HIGH

datamodel-code-generator vulnerable to SSRF via --url: no host/IP validation, follows redirects

CVE-2026-54691CVE-2026-54691
2026-07-28 · MEDIUM

OpenAI models used Artifactory zero-days to escape to the internet

2026-07-28 · HIGH

Fission: Zip Slip in pkg/utils/zip.go:Unarchive allows fetcher to write outside the destination directory

CVE-2026-50567CVE-2026-50567
2026-07-28 · HIGH

Fission: Incomplete capability denylist in Environment/Function PodSpec validation allows tenant-added CAP_SYS_TIME and cross-tenant node wall-clock corruption

CVE-2026-50570CVE-2026-50570
2026-07-28 · MEDIUM

What do you do with CVEs you can't fix? Auditor wants proof they're 'not exploitable'

2026-07-28 · MEDIUM

Claude Mythos degrades HAWK and developed new exploit for round-reduced AES

2026-07-28 · MEDIUM

CISA shares advice on isolating vital systems during cyberattacks

2026-07-28 · HIGH

JetBrains Urging Customers to Patch Critical TeamCity Flaw that Enables OS Command Execution

2026-07-28 · MEDIUM

vBulletin fixes critical pre-auth RCE flaw with public exploit

2026-07-28 · MEDIUM

Flying Eagle Android RAT: TLS Certificate Pivots, Panel Fingerprints, and 170 Servers Across Hong Kong ASNs

2026-07-28 · HIGH

BlackCloak extends deepfake protection to the executives trusted circle

2026-07-28 · HIGH

Bugcrowd introduces Savant Pathseeker for agentic penetration testing with exploit validation

2026-07-28 · HIGH

Root-My-Device-Payloads exploit

2026-07-28 · HIGH

Exploit for Classic Buffer Overflow in Tp-Link Tl-Wr841_Firmware exploit

2026-07-28 · HIGH

Exploit for Insertion of Sensitive Information into Log File in Ayesa Ibermatica_Rps exploit

2026-07-28 · HIGH

vulnerable-forum exploit

2026-07-28 · HIGH

Exploit for Incorrect Authorization in F5 Nginx_Plus exploit

2026-07-28 · HIGH

Hackers Exploiting FastJson RCE 0-Day in the Wild to Attack US-based Organizations

2026-07-28 · HIGH

OAuth: Cross-origin token-request redirects can expose signed request metadata

CVE-2026-54605CVE-2026-54605
2026-07-28 · HIGH

Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted `file.create` permissions

CVE-2026-54593CVE-2026-54593
2026-07-28 · HIGH

@wakaru/cli arbitrary file write during bundle unpack

CVE-2026-54545CVE-2026-54545
2026-07-28 · HIGH

Pterodactyl's shared global rate-limit key on login and 2FA checkpoint enables unauthenticated panel-wide authentication lockout (DoS)

CVE-2026-61609CVE-2026-61609
2026-07-28 · HIGH

GitHub MCP Server has Nil Pointer Dereference DoS in completion/complete Handler

CVE-2026-47427CVE-2026-47427
2026-07-28 · HIGH

Cedar-Java has policy injection, type confusion, and incorrect equality comparison vulnerabilities

CVE-2026-55771CVE-2026-55771
2026-07-28 · HIGH

Pocket ID: OIDC refresh token flow bypasses authorization revocation, account disabling, and group restrictions

CVE-2026-43983CVE-2026-43983
2026-07-28 · HIGH

Simple Job Board ≤ 2.11.0 - Unauthenticated RCE (CVE-2024-1813)

CVE-2024-1813
2026-07-28 · HIGH

java-client Allows Network Pivot via Unvalidated directConnect Redirect in AppiumCommandExecutor

CVE-2026-43910CVE-2026-43910
2026-07-28 · HIGH

WordPress Coding Standards (WordPressCS) contains an arbitrary code execution vulnerability

CVE-2026-45293CVE-2026-45293
2026-07-28 · MEDIUM

Researchers scored ISO 42001, COBIT, ISO 27001, and NIST CSF 2.0 on LLM risk oversight. None of them have a control for hallucination.

2026-07-28 · MEDIUM

JFrog Confirms OpenAI Models Exploited Artifactory Zero-Day Before Hugging Face Breach

2026-07-28 · LOW

Exploit for CVE-2026-59891

CVE-2026-59891
2026-07-28 · HIGH

AI-Assisted Research Uncovers Linux Kernel Zero-Day Enabling Root Privilege Escalation

2026-07-28 · HIGH

How We Hacked Thousands of Data Centers in Minutes Using a 20-Year-Old Vulnerability

CVE-2013-4786
2026-07-28 · HIGH

Coca-Cola confirms hackers stole data in Fairlife ransomware attack

2026-07-28 · HIGH

Researcher Says AI Helped Develop Linux Traffic-Control Race Into Root Exploit

2026-07-28 · HIGH

Exploit for CVE-2026-8206 exploit

CVE-2026-8206
2026-07-28 · HIGH

Web-Server-Log-Parser-Threat-Detector exploit

2026-07-28 · HIGH

study_embedded_security exploit

2026-07-28 · HIGH

Exploit for Cross-site Scripting in Spip exploit

2026-07-28 · HIGH

kernel-exploit-dirty-cow-project exploit

2026-07-28 · LOW

LegacyHive Exploitation Chain Bypasses Windows Security Even With July 2026 Patches Installed

2026-07-28 · MEDIUM

Hacker Conversations: Tal Kollander’s Journey From Black Hat to Hack Blocker

2026-07-28 · CRITICAL

U.S. CISA adds Arista VeloCloud Orchestrator and Fortinet FortiOS flaws to its Known Exploited Vulnerabilities catalog

2026-07-28 · MEDIUM

Entering Security Tool Development

2026-07-28 · MEDIUM

Has the Hugging Face incident changed anyone else’s view on open vs closed AI models for cybersecurity?

2026-07-28 · HIGH

CVE-2026-59528: Subscriber Sensitive Data Exposure in ShipTime: Discounted Shipping Rates <= 1.1.1 versions.

CVE-2026-59528
2026-07-28 · HIGH

CVE-2026-59527: Unauthenticated SQL Injection in MapSVG <= 8.14.0 versions.

CVE-2026-59527
2026-07-28 · MEDIUM

Automated AI penetration testing with Claude Code or Codex: what setup actually works best?

2026-07-28 · HIGH

5 High-Impact Use Cases for Falcon Onum

2026-07-28 · HIGH

Download: The High-Performance Team Playbook

2026-07-28 · HIGH

Five Progress LoadMaster Flaws Let Attackers Execute Commands and Gain Root Access

2026-07-28 · HIGH

mt6897-unlock-attempt exploit

2026-07-28 · HIGH

Exploit for CVE-2026-40000 exploit

CVE-2026-40000
2026-07-28 · HIGH

Exploit for CVE-2026-39875 exploit

CVE-2026-39875
2026-07-28 · CRITICAL

Attackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw

2026-07-28 · CRITICAL

CISA Warns of Fortinet FortiOS Vulnerability Exploited in Attacks

2026-07-28 · CRITICAL

Hackers Exploiting Arista VeloCloud Orchestrator 0-Day Vulnerability in the Wild

2026-07-28 · MEDIUM

CVE-2025-59180: Ericsson Packet Core Controller (PCC) versions prior to 1.38 contain a hardcoded credential vulnerability in the alarm s

CVE-2025-59180
2026-07-28 · MEDIUM

CVE-2025-59181: Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain a directory traversal vulnerability in Configuratio

CVE-2025-59181
2026-07-28 · MEDIUM

CVE-2025-59178: Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain an Exposure of Sensitive System Information vulnera

CVE-2025-59178
2026-07-28 · MEDIUM

Outdated VPNs should be purged from federal agencies, senator says

2026-07-28 · HIGH

Microsoft debuts AI cybersecurity offerings as competition heats up

2026-07-28 · HIGH

AI Agent Drives Espionage Attack on Thai Ministry of Finance

2026-07-28 · HIGH

Cybersecurity jobs available right now: July 28, 2026

2026-07-28 · MEDIUM

Unpatched Fastjson Vulnerability Exploited in Attacks

2026-07-28 · HIGH

NVIDIA Forms 37-Member Open Secure AI Alliance and Open-Sources NOOA Framework

2026-07-28 · HIGH

Exploit for CVE-2026-9830 exploit

CVE-2026-9830
2026-07-28 · HIGH

flask-kvsession-pickle-rce exploit

2026-07-28 · MEDIUM

Critical Arista VeloCloud Orchestrator Vulnerability Exploited as Zero-Day

2026-07-28 · MEDIUM

Qualcomm Product Security Engineer – AI Software Development (Job ID: 3092777)

2026-07-28 · MEDIUM

AI security engineer

2026-07-28 · MEDIUM

Open Source Models

2026-07-28 · MEDIUM

Three Minnesota water utilities report cyber incidents days after CISA PLC warning

2026-07-28 · MEDIUM

Who’s getting phished these days, really?

2026-07-28 · MEDIUM

Hackers target US firms in FastJson RCE zero-day attacks

2026-07-27 · MEDIUM

Arista patches VeloCloud Orchestrator zero-day exploited in attacks

2026-07-27 · CRITICAL

CVE-2025-68686: Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability

CVE-2025-68686
2026-07-27 · HIGH

Exploit for CVE-2026-42533 exploit

CVE-2026-42533
2026-07-27 · HIGH

pentest-confirm-mcp exploit

2026-07-27 · HIGH

Exploit for Path Traversal in Mate-Desktop Atril exploit

2026-07-27 · MEDIUM

DHS Official Resigns, Citing ‘War on Immigrants’

2026-07-27 · MEDIUM

FBI: Breaking Affiliate Trust Sped Along LockBit's Takedown

2026-07-27 · MEDIUM

New Certighost PoC exploit lets attackers hijack Windows domains

2026-07-27 · MEDIUM

GitHub, PyPI add time-based defenses against supply chain attacks

2026-07-27 · MEDIUM

Is DFIR the same as Threat Hunting?

2026-07-27 · CRITICAL

27th July Threat Intelligence Report

2026-07-27 · MEDIUM

Adversaries Don't Need a Zero-Day — They Read Your Rulebook

2026-07-27 · LOW

Sextortion scammers are exploiting ShinyHunters data leaks

2026-07-27 · MEDIUM

Coca-Cola confirms data theft in Fairlife ransomware attack

2026-07-27 · MEDIUM

Exploiting Volvo/Eicher’s fleet management platform to gain control over all users and vehicles

2026-07-27 · MEDIUM

Exploit for CVE-2026-65008

CVE-2026-65008
2026-07-27 · MEDIUM

New GitHub, PyPI Policies Boost Supply Chain Security

2026-07-27 · MEDIUM

⚡ Weekly Recap: Rogue AI Agents, Check Point Exploit, Slopsquatting, ClickFix Lures and More

2026-07-27 · HIGH

New vBulletin Vulnerability!

CVE-2026-61511
2026-07-27 · HIGH

n8n Sandbox Escape Lets Workflow Editors Run OS Commands as the n8n Process

CVE-2026-27577
2026-07-27 · MEDIUM

PTC Windchill Vulnerability Exploited in Ransomware Campaign

2026-07-27 · MEDIUM

Nvidia and Tech Giants Launch AI Security Alliance

2026-07-27 · HIGH

CVE-2026-64354: In the Linux kernel, the following vulnerability has been resolved: bpf: Validate BTF repeated field counts before expa

CVE-2026-64354
2026-07-27 · HIGH

Windows 11s File Explorer Is Now Faster at Deleting Large Files

2026-07-27 · HIGH

CVE-2026-65894 - Improper Authentication Vulnerability in CP PLUS EZ-P21 IP Camera

CVE-2026-65894
2026-07-27 · HIGH

CVE-2026-65893 - Arbitrary Code Execution Vulnerability in CP PLUS EZ-P21 IP Camera

CVE-2026-65893
2026-07-27 · HIGH

CVE-2026-14837 - SSH Enablement Signature Verification Bypass

CVE-2026-14837
2026-07-27 · CRITICAL

Top 10 Malware Used by Hackers Between July 20-26, 2026, to Launch Cyberattacks

2026-07-27 · MEDIUM

Coca-Cola Confirms Data Breach After Fairlife Ransomware Attack

2026-07-27 · HIGH

Marathon Petroleums CISO onOT security automation, supply chain risk

2026-07-27 · HIGH

Nono: Open-source sandbox for AI agents

2026-07-27 · HIGH

Ransomware Gangs Attack Palo Alto, Fortinet, Citrix, and Check Point VPNs to Target Corporate Networks

2026-07-27 · HIGH

CVE-64600-Refluxfs-POC exploit

2026-07-27 · HIGH

Exploit for Improper Restriction of Operations within the Bounds of a Memory Buffer in Wavlink Wl-Nu516U1_Firmware exploit

2026-07-27 · HIGH

Exploit for CVE-2026-58138 exploit

CVE-2026-58138
2026-07-27 · HIGH

mod-poc-msf-p3 exploit

2026-07-27 · HIGH

relay-secreport-bench exploit

2026-07-27 · HIGH

Web-Payloads-Arsenal exploit

2026-07-27 · HIGH

CSFR-XSS-IDOR exploit

2026-07-27 · MEDIUM

Anthropic’s Opus 5 Nears Mythos 5 on Finding Bugs, but Falls Short on Exploits

2026-07-27 · MEDIUM

Agentic AI Security

2026-07-27 · MEDIUM

MCBS Data Breach Affects 1.2 Million Individuals

2026-07-27 · HIGH

CVE Exploitation Campaign — Unattributed Threat Actor

2026-07-27 · HIGH

High-Severity: Certighost Active Directory CS Exploit Allows Low-Privileged Users to Compromise (CVE-2026-54121)

CVE-2026-54121
2026-07-26 · MEDIUM

Penetration Tester Path

2026-07-26 · HIGH

Weekly Cyber Security Newsletter Bulletin Certighost Exploit, Checkpoint 0-day, HTTP/2 Flaw, Notepad++ Plugin Abuse +20 Stories

2026-07-26 · HIGH

CVE-2026-66032: libssh2 through 1.11.1, fixed in commit 5e47761, contains a double-free vulnerability in the sftp_open() function in src

CVE-2026-66032
2026-07-26 · HIGH

CVE-2026-54342: In epa4all, prior to version 2026-05-20, an attacker on the network path between epa4all and any backend (ePA Aktensyste

CVE-2026-54342
2026-07-26 · HIGH

CVE-2026-48021: In epa4all, prior to version 2026-05-20, an attacker who can intercept the TLS connection between epa4all and the ePA ba

CVE-2026-48021
2026-07-26 · HIGH

CVE-2026-62835: Improper authorization in Azure Portal allows an unauthorized attacker to disclose information over a network.

CVE-2026-62835
2026-07-26 · HIGH

CVE-2026-17107: A flaw was found in the cluster-proxy service-proxy component used in Red Hat Advanced Cluster Management for Kubernetes

CVE-2026-17107
2026-07-26 · HIGH

SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 107

2026-07-26 · MEDIUM

PoCumentary, an agent-friendly tool for recording PoCs

2026-07-26 · HIGH

cis-hardening-metasploitable2 exploit

2026-07-26 · HIGH

vulnerability-exploitation-initial-access exploit

2026-07-26 · MEDIUM

GitHub, PyPI add time-absed defenses against supply chain attacks

2026-07-26 · HIGH

CVE-2026-65693: Microweber CMS through 2.0.20 contains a server-side template injection vulnerability that allows authenticated administ

CVE-2026-65693
2026-07-26 · HIGH

CVE-2026-66027: Suna before 0.9.102 contains a broken access control vulnerability in the message queue API that allows authenticated at

CVE-2026-66027
2026-07-26 · CRITICAL

Security Affairs newsletter Round 587 by Pierluigi Paganini INTERNATIONAL EDITION

2026-07-26 · HIGH

ethical-hacking-elewayte-projects exploit

2026-07-26 · HIGH

Exploit for CVE-2026-66012 exploit

CVE-2026-66012
2026-07-26 · HIGH

Exploit for CVE-2026-15981 exploit

CVE-2026-15981
2026-07-26 · HIGH

Exploit for CVE-2026-58480 exploit

CVE-2026-58480
2026-07-26 · HIGH

Exploit for CVE-2026-10818 exploit

CVE-2026-10818
2026-07-26 · CRITICAL

Week in review: ServiceNow pre-auth RCE exploited in the wild, Hugging Face breached

2026-07-26 · MEDIUM

Update: Thank you guys so much for all the help!

2026-07-26 · HIGH

CVE-2024-14040 - net: nexthop: Increase weight to u16

CVE-2024-14040
2026-07-26 · HIGH

vibe-playground exploit

2026-07-26 · HIGH

tri-services-exploitation-report exploit

2026-07-26 · HIGH

CVE-2026-58630: Improper access control in Azure App Service allows an unauthorized attacker to elevate privileges over a network.

CVE-2026-58630
2026-07-26 · HIGH

CVE-2026-57106: Server-side request forgery (ssrf) in Data Quality allows an unauthorized attacker to elevate privileges over a network.

CVE-2026-57106
2026-07-26 · HIGH

CVE-2026-56163: Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to el

CVE-2026-56163
2026-07-26 · HIGH

CVE-2026-8789: The Easy Appointments plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabilit

CVE-2026-8789
2026-07-26 · HIGH

CVE-2026-17433 - nanocoai NanoClaw MCP Server Approval chat-sdk-bridge.ts createChatSdkBridge.setup improper authorization

CVE-2026-17433
2026-07-26 · HIGH

CVE-2026-17434 - nanocoai NanoClaw add_mcp_server request.ts handleAddMcpServer improper authorization

CVE-2026-17434
2026-07-26 · HIGH

Exploit for Deserialization of Untrusted Data in Dataease exploit

2026-07-26 · HIGH

HTB-Writeups exploit

2026-07-26 · HIGH

Older call of duty titles on steam have remote code execution exploits yet are still sold on the store. How is this acceptable?

CVE-2018-20817
2026-07-26 · HIGH

CVE-2026-16519: A DLL hijacking vulnerability exists in the GeoVision GV-IP Device Utility desktop application. The application loads on

CVE-2026-16519
2026-07-25 · HIGH

Exploit for SQL Injection in Trispark Novusedu exploit

2026-07-25 · HIGH

Exploit for SQL Injection in Fortra Delivernow exploit

2026-07-25 · HIGH

Exploit for Improper Authentication in Sonicwall Directory_Services_Connector exploit

2026-07-25 · MEDIUM

Someone build a Serverless Hermes Agent specialized in PenTest/SecAudit

2026-07-25 · MEDIUM

Researcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as Git

2026-07-25 · MEDIUM

Rockwell Patches Code Execution Flaws in Arena Simulation Software

2026-07-25 · MEDIUM

Reverse Engineering Windows Data Deduplication: From Research to an Open-Source Recovery Tool

2026-07-24 · HIGH

yt-dlp: Downstream command injection via improper sanitization of yt-dlp --write-link output

CVE-2026-55404CVE-2026-55404
2026-07-24 · HIGH

Open WebUI: Terminal proxy forwards a spoofable, integrity-unbound user identity to the upstream (X-User-Id header and ws_terminal session_id query injection)

CVE-2026-59224CVE-2026-59224
2026-07-24 · HIGH

CVE-2026-16632: A flaw has been found in boazsegev facil.io up to 0.7.4. Affected is the function websocket_on_protocol_error in the lib

CVE-2026-16632
2026-07-24 · HIGH

Microsoft, tech companies throw weight behind spread of open-source AI

2026-07-24 · HIGH

Ransomware is the Scoreboard

2026-07-24 · HIGH

CVE-2026-16723: A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.2.83. This vulnerability is exploitable

CVE-2026-16723
2026-07-24 · HIGH

Class06-Security-Vulnerability-Demo exploit

2026-07-24 · HIGH

Exploit for Relative Path Traversal in Microsoft exploit

2026-07-24 · HIGH

Exploit for Incorrect Authorization in Adobe Coldfusion exploit

2026-07-24 · HIGH

Exploit for Missing Authentication for Critical Function in Erlang Erlang\/Otp exploit

2026-07-24 · HIGH

Exploit for Out-of-bounds Read in Microsoft exploit

2026-07-24 · HIGH

Exploit for Command Injection in Paloaltonetworks Pan-Os exploit

2026-07-24 · MEDIUM

Hermes AI agent used to automate attack on Thai Finance Ministry

2026-07-24 · MEDIUM

Announcing the External Penetration Testing Program Pack

2026-07-24 · MEDIUM

Certighost Active Directory CS Exploit Allows Low-Privileged Users to Compromise Domain

2026-07-24 · HIGH

@fastify/static vulnerable to route guard bypass via path traversal

CVE-2026-15074CVE-2026-15074
2026-07-24 · HIGH

js-yaml: Exponential parsing time in flow collections leads to denial of service

2026-07-24 · HIGH

GitPython: Unsafe git option guard bypass via single-character kwarg value token smuggling enables arbitrary command execution

2026-07-24 · HIGH

Claude Code: Sandbox Escape via Git Worktree Path Confusion Allows Unsandboxed Code Execution

CVE-2026-55607CVE-2026-55607
2026-07-24 · MEDIUM

OpenAI's cyber eval models escaped their sandbox and hacked Hugging Face to cheat on a test

2026-07-24 · HIGH

Microsoft Kiota Workspace-config poisoning: out-of-repo file write + generation-time SSRF

CVE-2026-59863CVE-2026-59863
2026-07-24 · HIGH

Microsoft Kiota: Arbitrary file write + code-injection via x-ms-kiota-info clientClassName and clientNamespaceName

CVE-2026-59866CVE-2026-59866
2026-07-24 · HIGH

PostCSS: Path Traversal in Previous Source Map Auto-Loading (sourceMappingURL) leads to Arbitrary .map File Disclosure

2026-07-24 · MEDIUM

Looking for SOC analysts to roast/test my MVP

2026-07-24 · HIGH

Microsoft Kiota: Code Generation Literal Injection in Kiota Ruby Generator

CVE-2026-59861CVE-2026-59861
2026-07-24 · HIGH

Microsoft Kiota: Code Generation Literal Injection in Kiota Python Generator

CVE-2026-59862CVE-2026-59862
2026-07-24 · HIGH

Microsoft Kiota: Code Generation Literal Injection in Kiota PHP Generator

CVE-2026-59859CVE-2026-59859
2026-07-24 · HIGH

Better Auth: Account takeover via pre-account hijacking on magic-link and email-OTP sign-in

2026-07-24 · HIGH

Ray: Arbitrary code execution via ray.data.read_webdataset default decoder: pickle.loads(value) and torch.load(weights_only=False)

CVE-2026-57516CVE-2026-57516
2026-07-24 · HIGH

httplib2: Decompression Bomb Denial of Service via Unbounded gzip/deflate Response Handling

CVE-2026-59939CVE-2026-59939
2026-07-24 · HIGH

Microsoft Kiota: XML Doc-Comment Newline Breakout Code Injection

CVE-2026-59860CVE-2026-59860
2026-07-24 · MEDIUM

In Other News: Dolphin X AI-Powered Malware, Car Anti-Theft Device Hack, 400 Linux Kernel Flaws

2026-07-24 · HIGH

LiquidJS: `pop` filter bypasses `memoryLimit` accounting that its array-filter siblings enforce

CVE-2026-55575CVE-2026-55575
2026-07-24 · HIGH

Quinn: Remote memory exhaustion in quinn-proto from unbounded out-of-order stream reassembly

2026-07-24 · HIGH

electron-updater: Cross-origin redirect leaks `PRIVATE-TOKEN` and mixed-case `Authorization` credentials in `builder-util-runtime`

CVE-2026-54673CVE-2026-54673
2026-07-24 · HIGH

React Router: Unauthenticated Denial of Service via Inefficient Route Matching

CVE-2026-55685CVE-2026-55685
2026-07-24 · CRITICAL

Thailands Ministry of Finance Targeted With Hermes AI Agent Running Unattended, Hades Implant Staged

2026-07-24 · CRITICAL

UAC-0099 Is Now Hiding Malware Inside a Fake Notepad++ Plugin to Target Ukrainian Organizations

2026-07-24 · HIGH

electron-updater: Uncontrolled search path elements within `AppImage` built by `app-builder-lib`

CVE-2026-54672CVE-2026-54672
2026-07-24 · HIGH

CVE-2026-14172 - Rapid7 InsightVM, Nexpose, and Insight Agent Local Privilege Escalation via Unvalidated Executable Invocation

CVE-2026-14172
2026-07-24 · HIGH

CVE-2026-12877 - Software Issue Manager < 5.1.0 - Unauthenticated SQL Injection via Search Parameter

CVE-2026-12877
2026-07-24 · HIGH

Google Rolls Out Emergency Chrome Update for Four High-Severity Security Flaws

2026-07-24 · HIGH

CVE-2026-12688 - ProfileGrid < 5.9.9.7 - Unauthenticated Payment Bypass and Forced Group Membership via PayPal IPN Forgery

CVE-2026-12688
2026-07-24 · HIGH

CVE-2026-12497 - ProfilePress < 4.16.18 - Unauthenticated Privilege Escalation via Registration Role Selection

CVE-2026-12497
2026-07-24 · CRITICAL

US Agencies Warn of Laundry Bear Campaign Targeting Unpatched Zimbra Servers

2026-07-24 · HIGH

2026-07-tare-nightbox33-cloud exploit

2026-07-24 · HIGH

Vulhub-vulnerability-reproduction-reports exploit

2026-07-24 · HIGH

exploitarium exploit

2026-07-24 · HIGH

Exploit for CVE-2026-63766 exploit

CVE-2026-63766
2026-07-24 · HIGH

Ransomware gangs go after EMEA healthcares supply chain

2026-07-24 · HIGH

Russian Hackers Exploiting Zimbra Zero-Day to Steal 90 Days of Emails

2026-07-24 · CRITICAL

Critical: WhatsApp Web chats exposed by Adobes Acrobat extension flaw (CVE-2026-48294)

CVE-2026-48294
2026-07-24 · MEDIUM

Clop ransomware targets Windchill, FlexPLM in data theft attacks

2026-07-24 · CRITICAL

Critical: U.S. CISA adds Microsoft SharePoint and Check Point SmartConsole flaws to its Kn (CVE-2026-16232)

CVE-2026-16232
2026-07-24 · CRITICAL

Critical: Wordfence Intelligence Weekly WordPress Vulnerability Report (July 13, 2026 to J (CVE-2026-11324)

CVE-2026-11324
2026-07-24 · CRITICAL

Critical: Cal.com before 5.9.9 Remote Code Execution via RSC (CVE-2025-55182)

CVE-2025-55182
2026-07-24 · CRITICAL

Critical: Hackers Abuse GitHub Actions to Exploit cPanel and WHM Servers and Steal Cloud C (CVE-2026-41940)

CVE-2026-41940
2026-07-24 · CRITICAL

Critical: Critical Check Point SmartConsole Authentication Bypass Exploited in the Wild (CVE-2024-24919)

CVE-2024-24919
2026-07-24 · CRITICAL

CVE-2025-71389 - Cal.com before 5.9.9 Remote Code Execution via RSC

CVE-2025-71389
2026-07-23 · MEDIUM

Where do AI agents actually add value for defenders, and where do they produce confident nonsense?

2026-07-23 · MEDIUM

Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes

2026-07-23 · MEDIUM

Chaos Ransomware Turns Your Chrome and Edge Web Browser Into an Invisible Malware Command Channel

2026-07-23 · CRITICAL

Hackers Abuse GitHub Actions to Exploit cPanel and WHM Servers and Steal Cloud Credentials

2026-07-23 · MEDIUM

Russian hackers exploit Zimbra zero-click flaw for email theft

2026-07-23 · HIGH

Swiss train maker Stadler refuses Everest $12 million ransomware demand

2026-07-23 · HIGH

CVE-2026-16445: A flaw was found in dracut. A remote attacker on the adjacent network can exploit this vulnerability by providing specia

CVE-2026-16445
2026-07-23 · HIGH

Exploit for SQL Injection in Ivanti Endpoint_Manager exploit

2026-07-23 · HIGH

Exploit for Authentication Bypass Using an Alternate Path or Channel in Fortinet Fortiproxy exploit

2026-07-23 · HIGH

Fastjson1.2.83_EXP exploit

2026-07-23 · HIGH

fastjson-jsontype-rce-hzhsec exploit

2026-07-23 · HIGH

open-redirect-poc exploit

2026-07-23 · HIGH

Exploit for OS Command Injection in Php exploit

2026-07-23 · CRITICAL

Exploit for CVE-2025-2783 exploit

CVE-2025-2783
2026-07-23 · CRITICAL

New Check Point Zero-Day Vulnerability Exploited in the Wild

2026-07-23 · MEDIUM

Nuclear-Sabotage Malware Benchmark Trips Up Most Frontier AI Models

2026-07-23 · LOW

Exploit for CVE-2026-64600

CVE-2026-64600
2026-07-23 · LOW

CISA Warns Iran-Linked Hackers Exploit Rockwell PLCs to Disrupt U.S. Critical Infrastructure

2026-07-23 · MEDIUM

Exploit for CVE-2026-56121

CVE-2026-56121
2026-07-23 · CRITICAL

July 2026 InfraTrust Report Flags 26 Unauthenticated Vulnerabilities and Exploited SonicWall Flaws

2026-07-23 · CRITICAL

Check Point patches actively exploited SmartConsole authentication bypass flaw

2026-07-23 · MEDIUM

Check Point warns of SmartConsole zero-day exploited in attacks

2026-07-23 · MEDIUM

US Warns of Iranian Hackers Targeting Siemens, Schneider, and Rockwell ICS Devices

2026-07-23 · MEDIUM

Synology stale DNS allows practical interception of traffic from vulnerable DSM clients

2026-07-23 · MEDIUM

Amplitude customers using domain proxies should update their configuration immediately.

2026-07-23 · MEDIUM

A project is publishing full analyses of AI-discovered 0-days - first batch of 10 with reproducible exploits

2026-07-22 · MEDIUM

Transitioning out of cyber

2026-07-22 · MEDIUM

Swiss rail giant Stadler rejects 12.3M ransom demand after cyberattack

2026-07-22 · MEDIUM

Cybersecurity statistics of the week (July 13th - July 19th)

2026-07-22 · HIGH

CVE-2026-50458: Finding a UAF in the Windows Brokering File System

CVE-2026-50458
2026-07-22 · MEDIUM

I ran a paid bug-bounty-style game against my own multimodal prompt firewall, it didn't make money, so here's the code, the model and 13k real bypass attempts

2026-07-22 · MEDIUM

Swiss rail giant Stadler rejects $12.3M ransom demand after cyberattack

2026-07-22 · HIGH

I was reporter #11 for a WPForms PayPal webhook vulnerability (CVE-2026-4986)

CVE-2026-4986
2026-07-22 · HIGH

Oracle Patches 1,400+ Vulnerabilities, Critical Flaws Expose Enterprise Servers to Remote Attacks

2026-07-22 · CRITICAL

CISA Warns of WordPress Core SQL Injection Vulnerability Actively Exploited in the Wild

2026-07-22 · CRITICAL

U.S. CISA adds DD-WRT, Langflow and WordPress flaws to its Known Exploited Vulnerabilities catalog

2026-07-22 · HIGH

Police Dismantle Kratos Phishing Kit Built to Steal Microsoft 365 Sessions and Bypass MFA

2026-07-22 · HIGH

Russian Hacker Jailbreaks Claude to Turn into an AI-Powered Penetration Testing Platform

2026-07-22 · HIGH

Authorities Shut Down Phishing Empire Launching 15,000 Attacks Every Month

2026-07-22 · MEDIUM

CISA orders urgent action on actively exploited Langflow RCE flaw

2026-07-22 · HIGH

Security teams keep finding critical flaws after scheduled testing ends

2026-07-22 · HIGH

CVE-2026-35198: HeyForm is an open-source form builder. Prior to version 3.0.0-rc.7, a stored cross-site scripting (XSS) vulnerability i

CVE-2026-35198