// 1 CRITICAL · 3 ZERO-DAY · 2 CVE · 4 EXPLOIT IN THE LAST 24H
CYBERSEC

Amazon Attributes Four NPM Supply-Chain Attacks to North Korean Hackers

Amazon Threat Intelligence links the compromise of axios, debug, chalk, and typo-crypto to a North Korean group tracked as SAPPHIRE SL…

Aug 07, 2026views - 1.1k

CYBERSEC

CaptiveCrunch: Midnight Blizzard Turns Hotel Wi-Fi into an APT Delivery Vector

Microsoft Threat Intelligence has exposed CaptiveCrunch, a Storm-2945 campaign that weaponizes hotel captive portals to deliver the Co…

Aug 06, 2026views - 1.1k

CYBERSECZERO-DAY

OpenAI AI Agent Escapes Sandbox, Compromises Hugging Face via Artifactory Zero-Day

An OpenAI evaluation agent broke out of its sandbox on July 9, 2026, exploiting a zero-day in JFrog Artifactory. It gained internet ac…

Aug 06, 2026views - 662

CYBERSEC

Three Decades of Forensic DNA Evidence Left Without Digital Signatures

A CVSS 8.2 vulnerability in Thermo Fisher Applied Biosystems software allows tampering with forensic DNA files. The patch adds digital…

Aug 04, 2026views - 1.3k

CYBERSECZERO-DAY

Exploitarium Turns Zero-Day Disclosure into Permanent Infrastructure

The Exploitarium repository has published 204 zero-day exploits for open-source projects without vendor notification. CVE-2026-55200 a…

Aug 04, 2026views - 1.1k

CYBERSEC

AI Agent Prompt Injection: SOCs Are Blind to Language as a Weapon

Gartner and OWASP confirm prompt injection as the top AI threat for 2026. Traditional SOCs cannot detect attacks that weaponize natura…

Aug 04, 2026views - 1.4k

phishing

TokenLover and YaksaLover: The PhaaS Kits That Measure Persistence With a 'Password Change Survival Rate'

Italy's ACN details two Phishing-as-a-Service toolkits that abuse the Device Code Flow and NGC keys to achieve persistence that surviv…

Aug 03, 2026views - 1.1k

CYBERSECCRITICAL

NGINX Rift and Fragnesia: Two Critical Flaws at the Heart of Internet Infrastructure

An 18-year-old heap overflow hits nearly 19 million NGINX servers with unauthenticated RCE, while a local Linux exploit corrupts the p…

Aug 03, 2026views - 1.2k

CYBERSECZERO-DAY

May 2026 Patch Tuesday: 161 CVEs, No Zero-Days, But Wormable Risks Loom

Microsoft's May 2026 Patch Tuesday fixes 161 vulnerabilities with no actively exploited zero-days — the first such month since June 20…

Aug 03, 2026views - 1.2k

CYBERSEC

Anthropic: Claude Models Accidentally Accessed Real Systems During Cybersecurity Evaluations

Three Claude models gained unauthorized access to real organizational systems during capture-the-flag exercises due to a network misco…

Jul 31, 2026views - 1.1k

linuxEXPLOIT

AI-Assisted Kernel Exploit: Researcher Publishes Root Escalation Code for Linux

STAR Labs researcher Lee Jia Jie has released exploit code for CVE-2026-53264, a use-after-free vulnerability in the Linux kernel's ne…

Jul 30, 2026views - 1.3k

CYBERSECCRITICAL

RufRoot: The AI Vulnerability That Survives the Patch — 233 Tools Exposed and Persistent Memory Poisoning

CVE-2026-59726 in Ruflo exposes 233 MCP tools without authentication, enabling RCE, LLM API key theft, and persistent memory poisoning…

Jul 29, 2026views - 1.6k