// 1 CRITICAL · 11 ZERO-DAY · 9 CVE · 10 EXPLOIT IN THE LAST 24H
CYBERSEC

BadBone: Dormant AI Backdoor Evades Six Major Security Defenses

BadBone research demonstrates that backdoors in pre-trained AI models remain invisible until customized, maintaining a 0.10% attack su…

Jun 02, 2026views - 297

CYBERSEC

Gitea Bug Exposed Private Container Images for Four Years

CVE-2026-27771: A critical flaw in Gitea’s container registry left approximately 31,750 instances vulnerable for nearly four years. Di…

Jun 02, 2026views - 195

CYBERSECEXPLOIT

Insight Launches Managed Exposure Defense to Combat AI-Driven Exploit Speed

Insight consolidates CTEM, enterprise patching, supply chain risk, surge engineering, and XDR into a unified managed service designed…

Jun 01, 2026views - 204

CYBERSEC

Audit Slams NIST Over NVD Collapse: 27,000 CVE Backlog and $200,000 in Wasted Funds

A Department of Commerce OIG audit documents the systemic failure of the National Vulnerability Database pipeline, revealing a backlog…

Jun 01, 2026views - 274

CYBERSEC

Shadow AI: First 8-K Filing Signals Shift from Internal Policy to Regulatory Mandate

The first SEC 8-K filing for unauthorized AI use marks a turning point for corporate governance. As Shadow AI evolves into 'vibe-coded…

Jun 01, 2026views - 184

CYBERSECCRITICAL

Microsoft Patched a Critical SharePoint RCE but Omitted the CVE from Official Documentation

CVE-2026-45659, a CVSS 8.8 SharePoint Server RCE, was missing from Microsoft’s May 2026 security update list. While the patch was dist…

Jun 01, 2026views - 250

CYBERSECEXPLOIT

CERT-In Mandates 12-Hour Patching Window to Combat AI-Driven Exploits

India’s national cyber agency, CERT-In, has established a new 12-hour remediation standard for internet-facing and 'crown jewel' syste…

May 31, 2026views - 428

CYBERSEC

Poisoned AI Chatbots: A New Vector for High-Performance GPU Cryptojacking

Microsoft has identified an active campaign that manipulates AI chatbot recommendations to distribute GPU-based cryptojacking malware…

May 31, 2026views - 230

CYBERSECZERO-DAY

Cyber May: AI Attacks Emerge, but Basic Vectors Remain the Primary Threat

In ESET’s May roundup, Tony Anscombe documents critical infrastructure breaches in Poland, Mexico’s first 'AI-directed' attack, and Go…

May 30, 2026views - 185

CYBERSECZERO-DAY

AI-Directed Attacks and ICS Vulnerabilities: ESET’s Tony Anscombe on DynoWiper and the First AI Zero-Day

In his May 2026 security review, ESET’s Tony Anscombe analyzes a landscape of extremes: from the first AI-generated zero-day and 'AI-d…

May 30, 2026views - 186

CYBERSECZERO-DAY

World Cup 2026: A Cyber-Physical Attack Surface Spanning Three Nations

Unit 42 maps the sprawling perimeter of the USA-Mexico-Canada World Cup, identifying critical OT/IT interdependencies across 16 host c…

May 30, 2026views - 266

CYBERSEC

California AG Sues 23andMe Over Alleged Ransom Negotiations and Deception in 6.9M Record Breach

Attorney General Rob Bonta alleges the company engaged in undisclosed ransom negotiations while publicly downplaying a 2023 credential…

May 30, 2026views - 238