AI & LLM
AI and LLM covers generative models, agents, prompt injection, data security and new artificial intelligence tools. The collection connects capabilities, limitations, operational risks and their impact on technical work.

Verizon DBIR 2026: Vulnerability Exploitation Overtakes Credentials as Patching Cycles Falter
The 2026 Verizon DBIR marks a structural shift in the threat landscape: vulnerability exploitation (31%) has surpassed credential abus…

Ollama Vulnerability: CVE-2026-7482 Risks Memory Exposure for 300,000 AI Servers
A critical heap out-of-bounds read vulnerability in Ollama (CVE-2026-7482) allows for memory leakage via GGUF files, putting API keys…

May Patch Tuesday: A Rare Zero-Day Break Amid Record AI Discovery Volumes
Microsoft’s May 2026 update ends a two-year streak of active zero-days, patching approximately 137 vulnerabilities. However, the integ…

Ollama Flaws Expose Local LLM Memory and Enable Windows Malware Persistence
Three critical CVEs in Ollama allow unauthenticated remote attackers to leak LLM process memory via crafted GGUF files and achieve per…

Cisco Talos Unveils AI-Driven Honeypot PoC to Deceive Malicious Agents
Cisco Talos researchers have demonstrated a proof-of-concept for adaptive honeypots powered by generative LLMs, designed to exploit th…

Mistral AI Hit by Supply Chain Attack; 450 Repositories Put Up for Sale
Mistral AI has confirmed a supply chain compromise involving contaminated SDKs and abused SLSA provenance. The threat actor TeamPCP is…

CVE-2026-7482: Technical Analysis of Ollama’s Memory Leak Vulnerability via GGUF
Technical breakdown of CVE-2026-7482 in Ollama. Discovered by Cyera, the vulnerability enables unauthenticated remote attackers to exf…

Yarix Y-Report 2026: Critical Security Events Surge 62% as Italy Falls to 6th in Global Ransomware Rankings
The Yarix Y-Report 2026 documents 522,486 security events and a 62% spike in critical threats, highlighting an increasingly aggressive…

CVE-2026-44338: Working Exploit Scanner for PraisonAI Deployed in Under 4 Hours
The first automated scanner targeting PraisonAI was detected less than four hours after the disclosure of CVE-2026-44338. The authenti…

May Patch Tuesday: AI-Driven Discovery Pushes 2026 Vulnerability Count Past 500
Microsoft's May 12, 2026, update addresses more than 130 vulnerabilities, revealing the impact of its internal MDASH AI system. The to…

ClawHavoc, Critical CVEs, and Agentic AI: Why Q1 2026 Shifted the Threat Model
The agentic AI ecosystem is under siege. From the coordinated ClawHavoc supply chain campaign to critical RCE vulnerabilities in Claud…

May 2026 Patch Tuesday: AI-Driven Discovery Marks a Turning Point in Vulnerability Management
Microsoft and industry partners address over 130 vulnerabilities as AI systems like MDASH and Project Glasswing accelerate the discove…