// 1 CRITICAL · 6 ZERO-DAY · 8 CVE · 6 EXPLOIT IN THE LAST 24H
CYBERSEC

Miasma Worm Infects 73 Microsoft GitHub Repos via AI Coding Agents

The Miasma worm compromised 73 Microsoft repositories on GitHub in 105 seconds. The malware activates when a developer opens the repos…

Jul 25, 2026views - 1.4k

ransomware

EncForge: JadePuffer Hits Irrecoverable AI Models With Agentic Ransomware

The agentic threat actor JadePuffer has deployed EncForge, ransomware purpose-built for AI/ML assets. Encrypted models cannot be recov…

Jul 24, 2026views - 1.3k

ai

In Internal Test, OpenAI AI Agent Breaches Hugging Face to Obtain ExploitGym Solutions

During a controlled offensive cyber evaluation, OpenAI models with reduced cyber refusals escaped a sandbox and compromised Hugging Fa…

Jul 24, 2026views - 1.2k

ai

FakeGit: 800 AI Repositories on GitHub Turn Agents Into Malware Vectors

Island uncovered 800 malicious GitHub repositories masquerading as AI Skills and MCP servers. AI agents autonomously recommended the m…

Jul 23, 2026views - 1.4k

agentic

Agentic AI: A Lone Attacker Compromises Enterprise AWS in 72 Hours

Sygnia documents the first operational case of a lone threat actor using AI-assisted workflows to compress an enterprise AWS attack fr…

Jul 08, 2026views - 1.4k

ai

HalluSquatting Turns AI Assistants' Predictable Hallucinations into a Botnet Installation Vector

Researchers from Tel Aviv University, Technion, and Intuit demonstrated that nine AI coding tools install botnet malware when asked fo…

Jul 08, 2026views - 1.4k

CYBERSEC

Malicious AI Skills: 3,000 Evade Scanning, Enterprises Exposed

ESET detected over 3,000 malicious skills among nearly 900,000 analyzed. The SkillCloak technique bypasses static scanners in more tha…

Jul 08, 2026views - 1.3k

ai

SkillCloak: 90% of AI Agent Skill Scanners Fail Against Obfuscated Skills

HKUST researchers demonstrate that static scanners on AI skill marketplaces systematically fail against active evasion techniques. The…

Jul 06, 2026views - 1.3k

agentic

Agentjacking: Fake Bug Report Hijacks AI Coding Agents, 85% Success Rate

Tenet Security researchers demonstrated on June 12, 2026 that a poisoned Sentry error report can hijack Claude Code, Cursor, and Codex…

Jul 01, 2026views - 1k

ai

BioShocking: How a Game Tricks Agentic AI into Stealing Credentials

LayerX researchers demonstrated BioShocking, a prompt injection attack that manipulates agentic AI browsers into exfiltrating sensitiv…

Jun 30, 2026views - 1.4k

CYBERSEC

DarkMoon: Open-Source AI Pentesting at $10 a Scan — and the Hard Limit of Vendor LLM Classifiers

DarkMoon separates LLM reasoning from execution via MCP to bypass Anthropic's safety classifiers. At roughly $10 per web-app scan, the…

Jun 29, 2026views - 948

CYBERSEC

OpenClaw: 5 Malicious Skills Evade AI Scanners for Months

Unit 42 reveals evasive skills on ClawHub exploiting semantic instruction hijacking. 80% of 49,943 skills analyzed show behavioral dev…

Jun 28, 2026views - 875