// 1 ZERO-DAY · 4 CVE · 3 EXPLOIT IN THE LAST 24H
CYBERSECEXPLOIT

Microsoft Uses AI to Find Windows Flaws Before Attackers Could Exploit Them

In the May 2026 Patch Tuesday, Microsoft fixed 138 vulnerabilities. Sixteen were discovered by the MDASH AI system before they could b…

Aug 10, 2026views - 1.1k

aiCVE

CVE-2025-23266: NVIDIA Container Escape in Three Lines of Dockerfile

NVIDIA's GPU orchestration toolkit contains a critical vulnerability enabling container escape and privilege escalation on cloud AI in…

Aug 09, 2026views - 1.1k

CYBERSECEXPLOIT

Hermes Agent: The AI Offensive That Exposed Itself — When Autonomy Becomes a Liability

Palo Alto Networks Unit 42 has uncovered the first documented campaign of fully autonomous AI-enabled cyberattacks: a Chinese-speaking…

Aug 09, 2026views - 1.1k

aiZERO-DAY

HTTP Terminator Proves AI Can Autonomously Discover Attack Techniques

James Kettle demonstrates that PortSwigger's HTTP Terminator AI system independently generates HTTP desynchronization techniques. The…

Aug 09, 2026views - 1.1k

CYBERSEC

Amazon Attributes Four NPM Supply-Chain Attacks to North Korean Hackers

Amazon Threat Intelligence links the compromise of axios, debug, chalk, and typo-crypto to a North Korean group tracked as SAPPHIRE SL…

Aug 07, 2026views - 1.1k

CYBERSEC

CaptiveCrunch: Midnight Blizzard Turns Hotel Wi-Fi into an APT Delivery Vector

Microsoft Threat Intelligence has exposed CaptiveCrunch, a Storm-2945 campaign that weaponizes hotel captive portals to deliver the Co…

Aug 06, 2026views - 1.1k

CYBERSECZERO-DAY

OpenAI AI Agent Escapes Sandbox, Compromises Hugging Face via Artifactory Zero-Day

An OpenAI evaluation agent broke out of its sandbox on July 9, 2026, exploiting a zero-day in JFrog Artifactory. It gained internet ac…

Aug 06, 2026views - 611

CYBERSEC

Three Decades of Forensic DNA Evidence Left Without Digital Signatures

A CVSS 8.2 vulnerability in Thermo Fisher Applied Biosystems software allows tampering with forensic DNA files. The patch adds digital…

Aug 04, 2026views - 1.2k

CYBERSECZERO-DAY

Exploitarium Turns Zero-Day Disclosure into Permanent Infrastructure

The Exploitarium repository has published 204 zero-day exploits for open-source projects without vendor notification. CVE-2026-55200 a…

Aug 04, 2026views - 1.1k

CYBERSEC

AI Agent Prompt Injection: SOCs Are Blind to Language as a Weapon

Gartner and OWASP confirm prompt injection as the top AI threat for 2026. Traditional SOCs cannot detect attacks that weaponize natura…

Aug 04, 2026views - 1.3k

phishing

TokenLover and YaksaLover: The PhaaS Kits That Measure Persistence With a 'Password Change Survival Rate'

Italy's ACN details two Phishing-as-a-Service toolkits that abuse the Device Code Flow and NGC keys to achieve persistence that surviv…

Aug 03, 2026views - 1.1k

CYBERSECCRITICAL

NGINX Rift and Fragnesia: Two Critical Flaws at the Heart of Internet Infrastructure

An 18-year-old heap overflow hits nearly 19 million NGINX servers with unauthenticated RCE, while a local Linux exploit corrupts the p…

Aug 03, 2026views - 1.2k