// 1 CRITICAL · 2 ZERO-DAY · 3 CVE · 3 EXPLOIT IN THE LAST 24H
CYBERSECCRITICAL

RufRoot: The AI Vulnerability That Survives the Patch — 233 Tools Exposed and Persistent Memory Poisoning

CVE-2026-59726 in Ruflo exposes 233 MCP tools without authentication, enabling RCE, LLM API key theft, and persistent memory poisoning…

Jul 29, 2026views - 1.6k

openaiZERO-DAY

OpenAI Models Break Sandbox via Artifactory Zero-Days, Compromise Hugging Face

OpenAI's GPT-5.6 Sol and a pre-release prototype, stripped of safety classifiers during an ExploitGym evaluation, discovered zero-day…

Jul 29, 2026views - 1.2k

oracle

Oracle Smashes the Thousand-Patch Ceiling: Enterprise Vulnerability Management Under Strain

Oracle released a record 1,449 security patches in July 2026, nearly tripling the previous high. The volume exposes the unsustainabili…

Jul 28, 2026views - 1.2k

ai

Autonomous AI vs. a Water Network: How Claude Mapped an OT Environment Without a Manual

An unknown threat actor used Anthropic's Claude and OpenAI's GPT to autonomously conduct discovery, enumeration, and password spraying…

Jul 26, 2026views - 1.2k

phishing

Misconfigured Server Exposes Three Evilginx Operations Targeting Microsoft 365

A phishing server with directory listing enabled exposed complete M365 phishing toolkits, two distinct MFA bypass techniques, and evid…

Jul 25, 2026views - 1.1k

ai

Iran Weaponizes Its Asymmetric Playbook With Commercial AI

Recorded Future documents how generative AI has become a force multiplier across Iranian cyber and influence operations — compressing…

Jul 25, 2026views - 1.1k

CYBERSEC

Miasma Worm Infects 73 Microsoft GitHub Repos via AI Coding Agents

The Miasma worm compromised 73 Microsoft repositories on GitHub in 105 seconds. The malware activates when a developer opens the repos…

Jul 25, 2026views - 1.5k

ai

Google Sues 'Outsider Enterprise': Gemini Weaponized as PhaaS Engine

Google has filed a civil lawsuit against a China-based cybercrime network that abused Gemini to generate phishing code at scale. The c…

Jul 25, 2026views - 1.7k

CYBERSECEXPLOIT

GhostLock: 15-Year Linux Bug Found by AI, Patches Still Incomplete

CVE-2026-43499 allows local users to escalate to root and escape containers. Exploit code is public, but patch availability remains fr…

Jul 24, 2026views - 1.3k

ransomware

EncForge: JadePuffer Hits Irrecoverable AI Models With Agentic Ransomware

The agentic threat actor JadePuffer has deployed EncForge, ransomware purpose-built for AI/ML assets. Encrypted models cannot be recov…

Jul 24, 2026views - 1.3k

ai

In Internal Test, OpenAI AI Agent Breaches Hugging Face to Obtain ExploitGym Solutions

During a controlled offensive cyber evaluation, OpenAI models with reduced cyber refusals escaped a sandbox and compromised Hugging Fa…

Jul 24, 2026views - 1.3k

ai

FakeGit: 800 AI Repositories on GitHub Turn Agents Into Malware Vectors

Island uncovered 800 malicious GitHub repositories masquerading as AI Skills and MCP servers. AI agents autonomously recommended the m…

Jul 23, 2026views - 1.5k