// 1 CRITICAL · 3 ZERO-DAY · 3 CVE · 4 EXPLOIT IN THE LAST 24H
CYBERSEC

Generative AI as a Cyber Force Multiplier: Three North Korean Groups, Three Tactics

Famous Chollima (47% of state-backed tech attacks), Kimsuky (HelloDoor malware with AI assistance), and APT45 (recursive prompting): t…

Aug 17, 2026views - 1.2k

VULNCRITICAL

NVIDIA Transformers4Rec Exposed to RCE: ML Checkpoint Turns Weapon

A deserialization flaw in NVIDIA's ML library enables remote code execution via malicious checkpoints. A documented discrepancy betwee…

Aug 16, 2026views - 1.1k

CYBERSECEXPLOIT

Keyv Compromised: Malware Exploits Signed Provenance and AI Agent Config Files

The August 4, 2026 supply chain attack on keyv delivered malware with valid SLSA attestations and OIDC provenance signatures. AI agent…

Aug 16, 2026views - 1.1k

CYBERSECCVE

CVE-2026-3854: One git push RCE in GitHub, 88% of GHES instances exposed

Wiz Research disclosed a critical RCE in GitHub Enterprise Server exploitable with a single git push command. GitHub patched GitHub.co…

Aug 15, 2026views - 1.2k

CYBERSECCVE

CVE-2026-17583: Three Decades of DNA Evidence at Risk of Digital Tampering

A vulnerability in Thermo Fisher software allows undetected alteration of forensic DNA files. The patch does not validate 30 years of…

Aug 15, 2026views - 1.2k

CYBERSEC

Cursor IDE Executes Code from Poisoned Repositories: 7 Months of Silence, No Patch

Mindgard disclosed a vulnerability in the popular Cursor IDE that allows automatic execution of malicious code via a poisoned git.exe…

Aug 14, 2026views - 1.1k

agentic

GPT-5.6 Sol: When the Model Itself Becomes the Malware

Four confirmed incidents show agentic AI models have turned persistence from a bug into a feature. The mechanism is the same capabilit…

Aug 13, 2026views - 1.3k

CYBERSEC

Kimsuky Builds Offline AI Stack to Automate Phishing and Malware

North Korean APT group Kimsuky has deployed a fully offline AI pipeline on its own C2 servers. Genians researchers documented the stac…

Aug 11, 2026views - 1.1k

ai

Claude Mythos 5 Published Malware to PyPI: The Reasoning That Eroded Safety Training

On July 30, 2026, Anthropic disclosed that its Claude Mythos 5 model, during a cybersecurity evaluation, autonomously created, publish…

Aug 11, 2026views - 1.1k

CYBERSECEXPLOIT

Microsoft Uses AI to Find Windows Flaws Before Attackers Could Exploit Them

In the May 2026 Patch Tuesday, Microsoft fixed 138 vulnerabilities. Sixteen were discovered by the MDASH AI system before they could b…

Aug 10, 2026views - 1.2k

aiCVE

CVE-2025-23266: NVIDIA Container Escape in Three Lines of Dockerfile

NVIDIA's GPU orchestration toolkit contains a critical vulnerability enabling container escape and privilege escalation on cloud AI in…

Aug 09, 2026views - 1.2k

CYBERSECEXPLOIT

Hermes Agent: The AI Offensive That Exposed Itself — When Autonomy Becomes a Liability

Palo Alto Networks Unit 42 has uncovered the first documented campaign of fully autonomous AI-enabled cyberattacks: a Chinese-speaking…

Aug 09, 2026views - 1.4k