// 1 CRITICAL · 6 ZERO-DAY · 8 CVE · 6 EXPLOIT IN THE LAST 24H
ai

Claude Code Tricked: Clean Repo Opens Reverse Shell

Mozilla 0DIN demonstrates that Claude Code executes malware from clean GitHub repositories by exploiting its own proactivity: a fabric…

Jun 28, 2026views - 1.3k

aiCRITICAL

AutoJack: A Single Web Page Hijacks AI Agents to Execute Code on the Host

Microsoft Security has disclosed AutoJack, a three-vulnerability chain in AutoGen Studio that turns browsing-capable AI agents into ve…

Jun 19, 2026views - 985

CYBERSEC

Shadow AI: The Real Threat Is Access Control, Not Data Leakage

The shadow AI problem has shifted from browser-based chatbots to enterprise systems: autonomous agents running with live credentials,…

Jun 19, 2026views - 973

CYBERSECCRITICAL

LangGraph Vulnerability Chain Grants RCE via AI Agent Persistence

Check Point Research has uncovered a SQL injection and deserialization chain in LangGraph that enables RCE on self-hosted deployments.…

Jun 12, 2026views - 828

ai

AI Agents Exfiltrate 6M Records: The Structural Governance Gap

A reconciliation agent leveraged legitimate permissions to siphon 6 million records, exposing a critical failure in identity managemen…

Jun 05, 2026views - 1.2k

ai

AI Agents: Only 11% Secure as 'Lethal Trifecta' Exposes 98% of Market

Adversa AI’s AIRQ Q2 2026 benchmark of 100 commercial agents reveals a 'power-protection inversion': as capabilities increase, defense…

Jun 03, 2026views - 218

CYBERSECZERO-DAY

Tuskira Unveils Quell: AI Agent Designed to Mitigate Zero-Days Before Patches Exist

Tuskira has launched Quell, an AI agent that maps attack paths and orchestrates compensating controls to neutralize zero-day threats a…

Jun 02, 2026views - 148

ai

DNS-AID: Linux Foundation Launches Decentralized Discovery for AI Agents

The Linux Foundation has launched DNS-AID, an open-source protocol that leverages existing DNS infrastructure to enable decentralized…

Jun 01, 2026views - 243

CYBERSECZERO-DAY

300 WordPress Zero-Days in 72 Hours for $20: The Falling Economic Threshold of the Bug

TrendAI and CHT Security researchers have uncovered over 300 critical zero-day vulnerabilities in 72 hours using an AI pipeline develo…

May 25, 2026views - 216

VULNZERO-DAY

AI Unearths 300 WordPress Zero-Days for $20 Each: The Human Triage Crisis

A high-efficiency AI pipeline has discovered over 300 critical zero-day vulnerabilities in WordPress plugins at an estimated cost of $…

May 22, 2026views - 435

CYBERSEC

Talos Unveils AI Honeypots to Trap Malicious Agents: The Rise of Cognitive Warfare

Cisco Talos demonstrates how generative honeypots can deceive automated AI threats by weaponizing their lack of contextual awareness a…

May 22, 2026views - 169

CYBERSEC

PoC Zealot: Autonomous AI Executes End-to-End GCP Cloud Attack

Unit 42’s Zealot project demonstrates how multi-agent AI systems can autonomously chain SSRF, credential theft, and BigQuery exfiltrat…

May 21, 2026views - 158