AI & LLM
AI and LLM covers generative models, agents, prompt injection, data security and new artificial intelligence tools. The collection connects capabilities, limitations, operational risks and their impact on technical work.

Microsoft MDASH Deployment Identifies 16 Windows Flaws via 100+ AI Agents
Microsoft’s MDASH, an agentic multi-model system, discovered 16 vulnerabilities—including four critical RCEs—patched in the May 2026 u…

Google Uncovers First Confirmed AI-Generated Zero-Day Exploit Bypassing 2FA
Google has confirmed the discovery of the first zero-day exploit developed with AI assistance. The vulnerability, identified on May 11…

OpenAI Unveils Daybreak: AI-Powered Cybersecurity with Tiered Access Controls
OpenAI has debuted Daybreak, a new AI cybersecurity platform featuring the GPT-5.5-Cyber model and a tiered governance framework desig…

CVE-2026-3854: Critical GitHub RCE Leaves 88% of On-Premise Servers Exposed
Wiz Research has detailed CVE-2026-3854, a critical RCE vulnerability in GitHub’s internal Git pipeline. While GitHub.com was patched…

Google Identifies First AI-Generated Zero-Day Weaponized in the Wild
Google confirms the first documented case of an AI-developed zero-day exploit used in the wild, targeting a 2FA vulnerability in an op…

Google Disrupts AI-Generated Zero-Day: 2FA Bypass Found in Open-Source Tool
The Google Threat Intelligence Group (GTIG) has neutralized an AI-generated zero-day exploit targeting 2FA in a system administration…

CVE-2026-7482: Malicious GGUF Files Trigger Memory Leaks in Ollama
A heap out-of-bounds read vulnerability in Ollama allows unauthenticated remote attackers to exfiltrate the entire memory of the infer…

Bleeding Llama: Why "On-Premises" Doesn't Mean "Safe" — CVE-2026-7482 and the 300,000 Exposed Servers
CVE-2026-7482 allows unauthenticated remote attackers to leak Ollama process memory via crafted GGUF files, exposing sensitive API key…

Bleeding Llama: Critical Ollama Vulnerability Exposes Secrets on 300,000 AI Servers
Cyera researchers have disclosed CVE-2026-7482, a critical memory leak in the Ollama framework. A malformed GGUF file allows unauthent…

Critical GitHub RCE: Single Git Push Triggers Backend Code Execution
CVE-2026-3854 allows RCE on GitHub.com and GHES via a single git push. The discovery, facilitated by AI-assisted reverse engineering o…

Google Raises Android Bug Bounty to $15M — Chrome AI Rewards Cut
Google has overhauled its Vulnerability Reward Programs, offering up to $1.5 million for sophisticated Pixel exploits while reducing p…

PromptMink: North Korean Hackers Weaponize AI to Poison npm Supply Chain
Researchers have uncovered 'PromptMink,' a sophisticated North Korean campaign leveraging code generated by Anthropic's Claude Opus to…