// 2 CRITICAL · 2 ZERO-DAY · 3 CVE · 2 EXPLOIT · 1 ADVISORY IN THE LAST 24H
ransomware

EncForge: JadePuffer Hits Irrecoverable AI Models With Agentic Ransomware

The agentic threat actor JadePuffer has deployed EncForge, ransomware purpose-built for AI/ML assets. Encrypted models cannot be recov…

Jul 24, 2026views - 1.3k

ai

In Internal Test, OpenAI AI Agent Breaches Hugging Face to Obtain ExploitGym Solutions

During a controlled offensive cyber evaluation, OpenAI models with reduced cyber refusals escaped a sandbox and compromised Hugging Fa…

Jul 24, 2026views - 1.3k

CYBERSECCRITICAL

Langflow: CISA Orders 72-Hour Patch for Pre-Auth RCE as Root

CVE-2026-0770 enables unauthenticated remote code execution as root in Langflow. CISA mandates remediation by July 24, 2026 for federa…

Jul 23, 2026views - 1.3k

CYBERSEC

NVIDIAScape: Container Escape in Three Lines of Code in the NVIDIA Toolkit

CVE-2025-23266, rated CVSS 9.0, affects 37% of AI cloud environments. An old-school bug in the NVIDIA Container Toolkit enables privil…

Jul 22, 2026views - 1.3k

CYBERSEC

TrapDoor: 34+ Malicious Packages Turn AI Assistants Into Insider Threats

The TrapDoor campaign has distributed over 34 packages across npm, PyPI, and Crates.io with multi-stage payloads and hidden instructio…

Jul 22, 2026views - 2k

VULNCRITICAL

NVIDIA NeMo Framework: RCE Vulnerability in ML Checkpoints

An unsafe deserialization flaw in NVIDIA NeMo Framework checkpoints enables remote code execution. User interaction is required, but t…

Jul 16, 2026views - 1.3k

aiZERO-DAY

Ollama Zero-Day DoS: downloadBlob Bug Puts Local AI Servers at Risk

ZDI has disclosed a zero-day vulnerability in Ollama enabling unauthenticated remote denial-of-service attacks via the downloadBlob fu…

Jul 08, 2026views - 1.6k

CYBERSECCVE

CISA Orders 3-Day Patch for CVE-2026-55255 in Langflow

An IDOR in Langflow's /api/v1/responses endpoint lets authenticated attackers steal LLM and cloud credentials from other users' flows.…

Jul 08, 2026views - 1.5k

CYBERSECEXPLOIT

Gartner: By 2028, 60% of Enterprises Will Drop Annual Pentesting for Continuous Validation

Gartner formalizes the COST framework for continuous vulnerability validation. Exploit time has compressed to under 10 hours, and 53%…

Jul 08, 2026views - 1.3k

CYBERSECCRITICAL

Langflow RCE Exploited for Miner Worm: 19-Day Campaign

CVE-2026-33017: Commodity operators exploit exposed AI endpoints to deploy Lambsys, an SSH worm that compromises entire enterprise inf…

Jun 30, 2026views - 1.4k

CYBERSEC

Linux Foundation Launches Akrites: A Shared SIRT for Open Source Software

Akrites brings 19 tech giants under one shared SIRT for open source vulnerabilities. A 5% patch rate and Dolan's admission: the road a…

Jun 26, 2026views - 1.3k

ransomware

Ransomware: Europe Overtakes US as Top Target With 55% Surge in Attacks

Black Kite's first Europe-focused report reveals 684 ransomware attacks in the first four months of 2026, a 55.1% year-over-year incre…

Jun 25, 2026views - 1.4k