// 1 CRITICAL · 2 ZERO-DAY · 2 CVE · 3 EXPLOIT IN THE LAST 24H
CYBERSEC

OpenClaw: 5 Malicious Skills Evade AI Scanners for Months

Unit 42 reveals evasive skills on ClawHub exploiting semantic instruction hijacking. 80% of 49,943 skills analyzed show behavioral dev…

Jun 28, 2026views - 914

ai

Claude Code Tricked: Clean Repo Opens Reverse Shell

Mozilla 0DIN demonstrates that Claude Code executes malware from clean GitHub repositories by exploiting its own proactivity: a fabric…

Jun 28, 2026views - 1.3k

aiCVE

CVE-2026-12957: Cloud Credential Theft via Amazon Q Developer

A high-severity vulnerability (CVSS 8.5) in the Amazon Q Developer extension for VS Code allowed automatic execution of malicious MCP…

Jun 27, 2026views - 1.5k

CYBERSEC

Beyond IOCs: Talos Unveils Vision for LLMs in Threat Intelligence

Cisco Talos explores how large language models transcend traditional indicators of compromise by indexing strategic reports in natural…

Jun 25, 2026views - 1.2k

CYBERSEC

ThreatsDay June 2026: Miasma Toolkit Leaked, Claude Code Patched, AI Agent Phishing

The June 2026 ThreatsDay Bulletin, published June 11 by Rescana, is an aggregated cyber threat digest. This analysis relies primarily…

Jun 25, 2026views - 1.1k

malware

Gaslight: macOS Malware Tricks AI Analyzers with Prompt Injection

SentinelOne researchers have documented Gaslight, a previously unknown Rust-based macOS implant that embeds a prompt-injection payload…

Jun 25, 2026views - 799

ransomware

Europe Overtakes US: 684 Ransomware Attacks in Four Months

Europe has become the fastest-growing ransomware region in 2026, logging 684 publicly known attacks in the first four months — a 55% y…

Jun 25, 2026views - 1.1k

CYBERSECCRITICAL

FlowiseAI CSV Agent RCE: Arbitrary Python Code Execution with Authentication Bypass

ZDI-26-365 discloses a remote code execution vulnerability in FlowiseAI's CSV Agent: Python code injection via customReadCSV with auth…

Jun 25, 2026views - 1.3k

CYBERSEC

Railway Cybersecurity: The IT/OT Boundary Has Collapsed

Rail systems are abandoning isolated SCADA for IP networks and AI. DNV's Jorge Aldegunde explains why security is now an active interf…

Jun 24, 2026views - 1.2k

aiZERO-DAY

Mythos AI Finds Vulnerabilities in Classified U.S. Systems in Hours

Anthropic's Mythos model identified vulnerabilities in classified U.S. government systems during a Project Glasswing test, completing…

Jun 24, 2026views - 796

openai

OpenAI Shifts the Remediation Paradox: From Finding Bugs to Patching Them

OpenAI releases GPT-5.5-Cyber and the Patch the Planet initiative. AI has solved vulnerability discovery, creating a larger problem: t…

Jun 23, 2026views - 1.2k

VULN

DifyTap: Four CVEs Expose Broken Cross-Tenant Isolation in Dify

Zafran Security disclosed DifyTap, four vulnerabilities in Dify that allowed cross-tenant reading of conversations and files. Three we…

Jun 22, 2026views - 819