// 4 ZERO-DAY · 5 CVE · 4 EXPLOIT IN THE LAST 24H
CYBERSEC

Backdoored LiteLLM on PyPI: Malware Triggers on Python Startup Alone

On March 24, 2026, two malicious LiteLLM versions exfiltrated credentials from over 50 categories via a .pth mechanism. The compromise…

Aug 09, 2026views - 1.1k

CYBERSECCRITICAL

Intel and AMD Patch 70 Flaws: Two Critical CVSS 9.3 and 9.2 Bugs in GPU Drivers

On May 13, 2026, Intel and AMD released 28 advisories covering 69 vulnerabilities. Two critical flaws hit chip software drivers, not t…

Aug 04, 2026views - 1.2k

CYBERSECCRITICAL

RufRoot: The AI Vulnerability That Survives the Patch — 233 Tools Exposed and Persistent Memory Poisoning

CVE-2026-59726 in Ruflo exposes 233 MCP tools without authentication, enabling RCE, LLM API key theft, and persistent memory poisoning…

Jul 29, 2026views - 1.5k

nvidiaCRITICAL

NVIDIA NVTabular: RCE via Pickle, CVE-2026-24237 Rated CVSS 7.8

A deserialization flaw in NVIDIA NVTabular enables remote code execution through malicious pickle files. User interaction is required;…

Jul 26, 2026views - 1.2k

ransomware

EncForge: JadePuffer Hits Irrecoverable AI Models With Agentic Ransomware

The agentic threat actor JadePuffer has deployed EncForge, ransomware purpose-built for AI/ML assets. Encrypted models cannot be recov…

Jul 24, 2026views - 1.3k

ai

In Internal Test, OpenAI AI Agent Breaches Hugging Face to Obtain ExploitGym Solutions

During a controlled offensive cyber evaluation, OpenAI models with reduced cyber refusals escaped a sandbox and compromised Hugging Fa…

Jul 24, 2026views - 1.3k

CYBERSECCRITICAL

Langflow: CISA Orders 72-Hour Patch for Pre-Auth RCE as Root

CVE-2026-0770 enables unauthenticated remote code execution as root in Langflow. CISA mandates remediation by July 24, 2026 for federa…

Jul 23, 2026views - 1.2k

CYBERSEC

NVIDIAScape: Container Escape in Three Lines of Code in the NVIDIA Toolkit

CVE-2025-23266, rated CVSS 9.0, affects 37% of AI cloud environments. An old-school bug in the NVIDIA Container Toolkit enables privil…

Jul 22, 2026views - 1.2k

CYBERSEC

TrapDoor: 34+ Malicious Packages Turn AI Assistants Into Insider Threats

The TrapDoor campaign has distributed over 34 packages across npm, PyPI, and Crates.io with multi-stage payloads and hidden instructio…

Jul 22, 2026views - 1.9k

VULNCRITICAL

NVIDIA NeMo Framework: RCE Vulnerability in ML Checkpoints

An unsafe deserialization flaw in NVIDIA NeMo Framework checkpoints enables remote code execution. User interaction is required, but t…

Jul 16, 2026views - 1.3k

aiZERO-DAY

Ollama Zero-Day DoS: downloadBlob Bug Puts Local AI Servers at Risk

ZDI has disclosed a zero-day vulnerability in Ollama enabling unauthenticated remote denial-of-service attacks via the downloadBlob fu…

Jul 08, 2026views - 1.5k

CYBERSECCVE

CISA Orders 3-Day Patch for CVE-2026-55255 in Langflow

An IDOR in Langflow's /api/v1/responses endpoint lets authenticated attackers steal LLM and cloud credentials from other users' flows.…

Jul 08, 2026views - 1.5k