// 1 CVE · 1 EXPLOIT IN THE LAST 24H
phishing

Italian Revenue Agency Phishing: CERT-AGID Alerts on Targeted SPID Credential Theft

CERT-AGID has identified a targeted phishing campaign impersonating Italy’s Revenue Agency. The attack uses pre-populated login forms…

May 22, 2026views - 102

CYBERSECEXPLOIT

Unit 42: Frontier AI Models Exploiting Open-Source Transparency to Automate Supply Chain Attacks

Frontier AI models are demonstrating the autonomous reasoning required to identify vulnerabilities in open-source code and orchestrate…

May 22, 2026views - 110

CYBERSEC

Talos Unveils AI Honeypots to Trap Malicious Agents: The Rise of Cognitive Warfare

Cisco Talos demonstrates how generative honeypots can deceive automated AI threats by weaponizing their lack of contextual awareness a…

May 22, 2026views - 112

VULNCRITICAL

Kemp LoadMaster Vulnerability: Authenticated RCE Found in customLocation Parameter

Advisory ZDI-26-319 reveals a command injection flaw in Progress Software’s Kemp LoadMaster. Authenticated users can exploit the custo…

May 21, 2026views - 126

CYBERSEC

PoC Zealot: Autonomous AI Executes End-to-End GCP Cloud Attack

Unit 42’s Zealot project demonstrates how multi-agent AI systems can autonomously chain SSRF, credential theft, and BigQuery exfiltrat…

May 21, 2026views - 99

malware

18 Malicious AI Extensions Exposed: Unit 42 Details Email Spying and RAT Risks

Palo Alto Networks Unit 42 has uncovered 18 AI browser extensions that masquerade as productivity tools while deploying RATs and spyin…

May 21, 2026views - 108

CYBERSEC

First VPN Seized: 'No-Log' Service Revealed as Law Enforcement Trap for Cybercriminals

Europol and Dutch police have dismantled First VPN, a specialized infrastructure hub for ransomware and data theft. The operation seiz…

May 21, 2026views - 3.4k

CYBERSEC

Chrome Internal Bug Reports Surge to 200+ as Google Leans on AI

Google addressed more than 200 internally discovered vulnerabilities in Chrome between March and May 2026. The spike aligns with the c…

May 21, 2026views - 110

CYBERSECCVE

Drupal Fixes 'Highly Critical' SQL Injection Vulnerability Impacting PostgreSQL

Drupal has released urgent security patches for CVE-2026-9082, an unauthenticated SQL injection flaw. The vulnerability specifically t…

May 21, 2026views - 99

CYBERSECZERO-DAY

Microsoft Defender Zero-Days Under Active Attack; CISA Mandates Patching by June 3

Microsoft has confirmed that two vulnerabilities in Microsoft Defender are being actively exploited in the wild. CISA has added both f…

May 21, 2026views - 172

linuxCVE

CVE-2026-46333: Nine-Year-Old Linux Kernel Flaw Enables Root Escalation

Qualys researchers have disclosed CVE-2026-46333, a Linux kernel vulnerability dormant since 2016 that enables local privilege escalat…

May 21, 2026views - 189

CYBERSEC

GitHub: 3,800 Internal Repos Exfiltrated via Trojanized VS Code Extension

GitHub has confirmed the theft of approximately 3,800 internal repositories after an employee installed a trojanized version of the Nx…

May 21, 2026views - 131

ransomwareEXPLOIT

Ransomware 2026: Extortion Tactics Pivot Beyond File Encryption

Kaspersky’s May 12, 2026 report reveals a fundamental shift in the threat landscape: as encryption loses its leverage, attackers are p…

May 21, 2026views - 139

VULNCVE

CVE-2025-68670: Pre-auth RCE Vulnerability Identified in xrdp Server Domain Field

A technical breakdown of CVE-2025-68670: A stack buffer overflow within xrdp's domain name processing logic enables unauthenticated re…

May 21, 2026views - 150

CYBERSECEXPLOIT

Mirai Variant Targets EOL TP-Link Routers via Flawed Exploit for Valid Vulnerability

Unit 42 has identified active exploitation attempts targeting CVE-2023-33538 on end-of-life TP-Link routers. While current in-the-wild…

May 21, 2026views - 94

CYBERSECEXPLOIT

Frontier AI: The Shift from Coding Assistant to Autonomous Threat Agent

Research from Unit 42 reveals that frontier AI models now possess the autonomous reasoning capabilities of full-spectrum security rese…

May 21, 2026views - 109

microsoft

Microsoft Open-Sources RAMPART and Clarity to Secure AI Agent Workflows

Microsoft has unveiled two open-source security tools for AI agents: RAMPART, a Pytest-native framework for build-time testing, and Cl…

May 20, 2026views - 138

ai

Trust3 AI Launches MCP Security: A Hardened Control Plane or Just Another Promise?

Trust3 AI has announced MCP Security to protect enterprise agentic workloads, focusing on connection verification, isolated tokens, an…

May 20, 2026views - 116

CYBERSEC

AI-Driven Mobile Attacks Hit New Record: Apps Compromised Within Two Hours of Release

The Digital.ai 2026 App Security Threat Report reveals that 87% of client-facing applications are now under systematic attack, with th…

May 20, 2026views - 122

CYBERSEC

1Password and OpenAI Partner to Provide Just-in-Time Credentials for AI Agents

1Password integrates its Environments MCP Server into OpenAI's Codex, enabling just-in-time credentialing for AI coding agents to prev…

May 20, 2026views - 141

CYBERSEC

CISA Faces Congressional Scrutiny After Months-Long AWS GovCloud Credential Leak on GitHub

Senator Maggie Hassan has demanded a classified briefing from CISA following the discovery of a public GitHub repository that exposed…

May 20, 2026views - 145

phishing

Italian Revenue Agency Phishing: Cloned SPID Portal Uses Pre-filled Emails to Target Public Sector

CERT-AGID has identified a targeted phishing campaign against the Italian Revenue Agency (Agenzia delle Entrate) featuring cloned SPID…

May 20, 2026views - 100

VULNCRITICAL

ExifTool RCE: Kaspersky GReAT Uncovers macOS Command Injection via Metadata

CVE-2026-3102 impacts ExifTool versions 13.49 and earlier on macOS. The vulnerability allows for command injection within the SetMacOS…

May 20, 2026views - 90

CYBERSEC

GitHub Breach: 3,800 Internal Repositories Stolen via Malicious VS Code Extension

GitHub has confirmed a security breach affecting approximately 3,800 internal repositories after an employee device was compromised by…

May 20, 2026views - 480