// 1 ZERO-DAY · 4 CVE · 3 EXPLOIT IN THE LAST 24H
CYBERSEC

Malicious JetBrains Plugins Steal AI API Keys: 70,000 Downloads

A coordinated campaign of 15 malicious plugins on the JetBrains Marketplace exfiltrates AI API keys from developers' IDEs. Roughly 70,…

Jun 17, 2026views - 878

CYBERSEC

Chinese APT UNC6508: A Year of Espionage on REDCap Servers

Google exposes UNC6508: over a year of REDCap server compromise at U.S. and Canadian medical and military institutions using InfiniteR…

Jun 15, 2026views - 774

ai

Anthropic Disables Fable 5 and Mythos 5 on US Directive Restricting Foreign Access

On June 12, 2026, at 5:21 p.m. ET, Anthropic received a US government directive ordering the immediate suspension of all access to Fab…

Jun 15, 2026views - 1.7k

ransomware

The Gentlemen: LLMs Accelerate the Ransomware Attack Cycle

CERT-AGID reveals that The Gentlemen ransomware group uses LLMs to build platforms in three days and customize extortion. Technical cl…

Jun 15, 2026views - 937

ransomware

The Gentlemen: LLMs Cut Ransomware Development to Three Days

CERT-AGID reports the ransomware group The Gentlemen uses LLMs to build platforms in three days, personalize extortion, and replicate…

Jun 15, 2026views - 1.4k

CYBERSEC

HAMLOCK: Invisible AI Backdoor Spans Chip and Software

Researchers demonstrate HAMLOCK, a supply-chain attack that splits a neural-network backdoor between minimal software weight changes (…

Jun 15, 2026views - 1.1k

VULNCVE

NVIDIA Transformers4Rec Flaw Enables RCE via Malicious ML Models

NVIDIA has patched a high-severity deserialization vulnerability (CVE-2026-24162, CVSS 7.8) in its Transformers4Rec library that allow…

Jun 13, 2026views - 850

CYBERSECCRITICAL

LangGraph Vulnerability Chain Grants RCE via AI Agent Persistence

Check Point Research has uncovered a SQL injection and deserialization chain in LangGraph that enables RCE on self-hosted deployments.…

Jun 12, 2026views - 845

CYBERSECCVE

LiteLLM CVE-2026-42271: CISA Confirms Active Exploitation of CVSS 10.0 RCE Chain

CISA has added CVE-2026-42271 to its KEV catalog, confirming active exploitation of a command injection vulnerability in LiteLLM. When…

Jun 09, 2026views - 782

ai

ChatGPT Lockdown Mode: OpenAI Curbs Agentic Features to Thwart Data Exfiltration

OpenAI rolls out an optional Lockdown Mode for ChatGPT, disabling live browsing, Deep Research, and Agent Mode to neutralize data exfi…

Jun 08, 2026views - 1.4k

cybersec

DockSec: The Open-Source AI Healing Containers, Not Just Scanning Them

DockSec, an OWASP Incubator project, leverages LLMs to correlate data from three Docker scanners and generate line-specific fixes. Its…

Jun 08, 2026views - 1.5k

CYBERSEC

Emphere Secures $2.1M to Automate Vulnerability Remediation with AI

Seattle-based startup Emphere raises $2.1 million to automate open-source vulnerability remediation as the NVD backlog exceeds 27,000…

Jun 07, 2026views - 828