// 1 CRITICAL · 11 ZERO-DAY · 9 CVE · 10 EXPLOIT IN THE LAST 24H
VULNZERO-DAY

OpenAI Codex: Reported Sandbox Escape Disclosed (ZDI-26-305)

A reported sandbox escape in OpenAI Codex (ZDI-26-305) could potentially allow code execution via specific JavaScript repositories. Th…

May 27, 2026views - 364

CYBERSEC

Nimbus Manticore: Iranian APT Leverages AI-Assisted Backdoors to Target Aviation and Software Sectors

The Iranian threat group Nimbus Manticore has expanded its operations, targeting aviation and software entities across Saudi Arabia, A…

May 26, 2026views - 260

CYBERSEC

India’s CERT-In Mandates 12-Hour Patch Window to Counter AI-Driven Exploitation

A new 38-page blueprint from CERT-In slashes the remediation window to just 12 hours for exposed systems, citing the rapid weaponizati…

May 26, 2026views - 201

CYBERSECZERO-DAY

300 WordPress Zero-Days in 72 Hours for $20: The Falling Economic Threshold of the Bug

TrendAI and CHT Security researchers have uncovered over 300 critical zero-day vulnerabilities in 72 hours using an AI pipeline develo…

May 25, 2026views - 272

malware

NGate Malware Trojanizes HandyPay App to Steal Contactless PINs in Brazil

ESET Research has uncovered a new NGate variant that trojanizes the legitimate HandyPay Android app to relay NFC data and intercept PI…

May 24, 2026views - 234

phishing

Fake Data Breach Alerts: When the Warning Becomes the Trap

Cybercriminals are weaponizing 'breach fatigue' and generative AI to craft hyper-realistic phishing alerts that mimic official inciden…

May 24, 2026views - 272

anthropic

Anthropic’s Project Glasswing Unearths 10,000 Flaws, Triggering 'Patching Paralysis'

Project Glasswing identified over 10,000 critical vulnerabilities in just one month. As Anthropic’s Claude Mythos model accelerates di…

May 23, 2026views - 444

VULNZERO-DAY

AI Unearths 300 WordPress Zero-Days for $20 Each: The Human Triage Crisis

A high-efficiency AI pipeline has discovered over 300 critical zero-day vulnerabilities in WordPress plugins at an estimated cost of $…

May 22, 2026views - 573

CYBERSEC

GitLab 19.0 Debuts Native Secrets Management and Air-Gapped AI

GitLab 19.0 integrates native secrets management, agentic merge request workflows, and self-hosted AI models, reinforcing its 'single…

May 22, 2026views - 219

CYBERSEC

30-Minute Lateral Breakouts: Why the SOC is Losing the Race Against AI-Driven Threats

Average breakout times have accelerated by 29%, with the fastest recorded exfiltration dropping from over four hours to just six minut…

May 22, 2026views - 226

CYBERSECEXPLOIT

Unit 42: Frontier AI Models Exploiting Open-Source Transparency to Automate Supply Chain Attacks

Frontier AI models are demonstrating the autonomous reasoning required to identify vulnerabilities in open-source code and orchestrate…

May 22, 2026views - 236

CYBERSEC

Talos Unveils AI Honeypots to Trap Malicious Agents: The Rise of Cognitive Warfare

Cisco Talos demonstrates how generative honeypots can deceive automated AI threats by weaponizing their lack of contextual awareness a…

May 22, 2026views - 238