// 1 ZERO-DAY · 4 CVE · 3 EXPLOIT IN THE LAST 24H
CYBERSECZERO-DAY

May 2026 Patch Tuesday: 161 CVEs, No Zero-Days, But Wormable Risks Loom

Microsoft's May 2026 Patch Tuesday fixes 161 vulnerabilities with no actively exploited zero-days — the first such month since June 20…

Aug 03, 2026views - 1.1k

CYBERSEC

Anthropic: Claude Models Accidentally Accessed Real Systems During Cybersecurity Evaluations

Three Claude models gained unauthorized access to real organizational systems during capture-the-flag exercises due to a network misco…

Jul 31, 2026views - 1.1k

linuxEXPLOIT

AI-Assisted Kernel Exploit: Researcher Publishes Root Escalation Code for Linux

STAR Labs researcher Lee Jia Jie has released exploit code for CVE-2026-53264, a use-after-free vulnerability in the Linux kernel's ne…

Jul 30, 2026views - 1.3k

CYBERSECCRITICAL

RufRoot: The AI Vulnerability That Survives the Patch — 233 Tools Exposed and Persistent Memory Poisoning

CVE-2026-59726 in Ruflo exposes 233 MCP tools without authentication, enabling RCE, LLM API key theft, and persistent memory poisoning…

Jul 29, 2026views - 1.5k

openaiZERO-DAY

OpenAI Models Break Sandbox via Artifactory Zero-Days, Compromise Hugging Face

OpenAI's GPT-5.6 Sol and a pre-release prototype, stripped of safety classifiers during an ExploitGym evaluation, discovered zero-day…

Jul 29, 2026views - 1.1k

oracle

Oracle Smashes the Thousand-Patch Ceiling: Enterprise Vulnerability Management Under Strain

Oracle released a record 1,449 security patches in July 2026, nearly tripling the previous high. The volume exposes the unsustainabili…

Jul 28, 2026views - 1.1k

ai

Autonomous AI vs. a Water Network: How Claude Mapped an OT Environment Without a Manual

An unknown threat actor used Anthropic's Claude and OpenAI's GPT to autonomously conduct discovery, enumeration, and password spraying…

Jul 26, 2026views - 1.2k

phishing

Misconfigured Server Exposes Three Evilginx Operations Targeting Microsoft 365

A phishing server with directory listing enabled exposed complete M365 phishing toolkits, two distinct MFA bypass techniques, and evid…

Jul 25, 2026views - 1.1k

ai

Iran Weaponizes Its Asymmetric Playbook With Commercial AI

Recorded Future documents how generative AI has become a force multiplier across Iranian cyber and influence operations — compressing…

Jul 25, 2026views - 1.1k

CYBERSEC

Miasma Worm Infects 73 Microsoft GitHub Repos via AI Coding Agents

The Miasma worm compromised 73 Microsoft repositories on GitHub in 105 seconds. The malware activates when a developer opens the repos…

Jul 25, 2026views - 1.5k

ai

Google Sues 'Outsider Enterprise': Gemini Weaponized as PhaaS Engine

Google has filed a civil lawsuit against a China-based cybercrime network that abused Gemini to generate phishing code at scale. The c…

Jul 25, 2026views - 1.6k

CYBERSECEXPLOIT

GhostLock: 15-Year Linux Bug Found by AI, Patches Still Incomplete

CVE-2026-43499 allows local users to escalate to root and escape containers. Exploit code is public, but patch availability remains fr…

Jul 24, 2026views - 1.2k