// 1 CRITICAL · 11 ZERO-DAY · 9 CVE · 10 EXPLOIT IN THE LAST 24H
VULN

DifyTap: Four CVEs Expose Broken Cross-Tenant Isolation in Dify

Zafran Security disclosed DifyTap, four vulnerabilities in Dify that allowed cross-tenant reading of conversations and files. Three we…

Jun 22, 2026views - 823

CYBERSEC

iOS AI Apps: 282 Exposed, Only 28% Fixed

Wake Forest study finds 282 of 444 analyzed iOS LLM apps leak API credentials. After 90 days of responsible disclosure, just 28% remed…

Jun 22, 2026views - 1.2k

aiCRITICAL

AutoJack: A Single Web Page Hijacks AI Agents to Execute Code on the Host

Microsoft Security has disclosed AutoJack, a three-vulnerability chain in AutoGen Studio that turns browsing-capable AI agents into ve…

Jun 19, 2026views - 1k

CYBERSEC

Agentic AI Replaces Assistive AI in Threat Management

Agentic AI is turning Gartner's CTEM framework from a strategic document into a continuous operational cycle. The shift, documented Ju…

Jun 19, 2026views - 1.3k

CYBERSEC

Shadow AI: The Real Threat Is Access Control, Not Data Leakage

The shadow AI problem has shifted from browser-based chatbots to enterprise systems: autonomous agents running with live credentials,…

Jun 19, 2026views - 1k

CYBERSEC

Interpol: $40 Billion Scam Economy in Asia, Cybercrime Tops 30% of All Crime

Interpol's 2025/2026 assessment documents a nearly $40 billion organized scam economy in Asia-Pacific, with cybercrime exceeding 30% o…

Jun 19, 2026views - 1.3k

CYBERSEC

June 2026 ThreatsDay Bulletin: When Claude’s Shared Chat Becomes a Malware Vector

The June 2026 ThreatsDay Bulletin documents the abuse of Anthropic Claude’s shared chat feature to distribute the MacSync credential s…

Jun 18, 2026views - 914

CYBERSEC

Novo Nordisk: Exposed GitHub Token Leads to 1.3 TB Theft Over Two Months

A GitHub personal access token exposed in client-side JavaScript opened a two-month dwell window: roughly 1.3 TB of data, AI models, a…

Jun 18, 2026views - 955

ai

vbdec Disassembler Becomes Local AI Server via COM/ROT

Cisco Talos demonstrates how exposing vbdec's object model to the Windows Running Object Table enables local agentic automation withou…

Jun 18, 2026views - 1.1k

ai

AI Agents Used to Breach 14 Companies: Over 1,000 Sessions Recovered

A low-skill attacker leveraged local Claude and Codex agents to compromise at least 14 organizations, bypassing guardrails through nar…

Jun 17, 2026views - 889

CYBERSEC

Malicious JetBrains Plugins Steal AI API Keys: 70,000 Downloads

A coordinated campaign of 15 malicious plugins on the JetBrains Marketplace exfiltrates AI API keys from developers' IDEs. Roughly 70,…

Jun 17, 2026views - 906

CYBERSEC

Chinese APT UNC6508: A Year of Espionage on REDCap Servers

Google exposes UNC6508: over a year of REDCap server compromise at U.S. and Canadian medical and military institutions using InfiniteR…

Jun 15, 2026views - 794