// 1 CRITICAL · 11 ZERO-DAY · 9 CVE · 10 EXPLOIT IN THE LAST 24H
CYBERSECZERO-DAY

Google Uncovers First Confirmed AI-Generated Zero-Day Exploit Bypassing 2FA

Google has confirmed the discovery of the first zero-day exploit developed with AI assistance. The vulnerability, identified on May 11…

May 13, 2026views - 246

CYBERSEC

OpenAI Unveils Daybreak: AI-Powered Cybersecurity with Tiered Access Controls

OpenAI has debuted Daybreak, a new AI cybersecurity platform featuring the GPT-5.5-Cyber model and a tiered governance framework desig…

May 13, 2026views - 221

CYBERSEC

Mini Shai-Hulud: 84 Malicious TanStack Packages Signed with Valid SLSA Level 3 Attestations

On May 11, 2026, the TeamPCP threat group compromised TanStack's CI/CD pipeline to inject 84 malicious npm versions. Despite carrying…

May 13, 2026views - 159

CYBERSECCRITICAL

Exim 'Dead.Letter' Vulnerability: Unauthenticated RCE Threatens GnuTLS-Based Mail Servers

A critical use-after-free vulnerability in Exim’s BDAT parser (CVE-2026-45185) allows for unauthenticated remote code execution on ser…

May 13, 2026views - 173

CYBERSECZERO-DAY

Google Identifies First AI-Generated Zero-Day Weaponized in the Wild

Google confirms the first documented case of an AI-developed zero-day exploit used in the wild, targeting a 2FA vulnerability in an op…

May 13, 2026views - 155

CYBERSECZERO-DAY

Google Disrupts AI-Generated Zero-Day: 2FA Bypass Found in Open-Source Tool

The Google Threat Intelligence Group (GTIG) has neutralized an AI-generated zero-day exploit targeting 2FA in a system administration…

May 13, 2026views - 196

CYBERSEC

Mini Shai-Hulud Worm: 170+ Packages Compromised as SLSA Protections Bypassed

The Mini Shai-Hulud worm has compromised over 170 npm and PyPI packages by exploiting GitHub Actions to generate valid SLSA attestatio…

May 12, 2026views - 231

CYBERSECCVE

Bleeding Llama: Why "On-Premises" Doesn't Mean "Safe" — CVE-2026-7482 and the 300,000 Exposed Servers

CVE-2026-7482 allows unauthenticated remote attackers to leak Ollama process memory via crafted GGUF files, exposing sensitive API key…

May 12, 2026views - 282

CYBERSECCRITICAL

Ivanti EPMM Authenticated RCE Under Active Exploitation; CISA Sets Patch Deadline

Ivanti has confirmed active exploitation of CVE-2026-6973 in its on-premises Endpoint Manager Mobile (EPMM) solution. The authenticate…

May 11, 2026views - 195

CYBERSECCRITICAL

Critical Palo Alto Networks PAN-OS RCE (CVE-2026-0300) Under Active Exploitation

A critical unauthenticated root RCE vulnerability in the PAN-OS User-ID Portal is being exploited in the wild. Unit 42 has confirmed t…

May 11, 2026views - 219

CYBERSEC

Why an Active Directory Password Reset Isn't Enough to Evict an Attacker

A simple Active Directory password reset often fails to eliminate persistence. Valid Kerberos tickets, local hash caching, and ACL-bas…

May 11, 2026views - 365

CYBERSECZERO-DAY

Google Detects First AI-Weaponized Zero-Day Bypassing 2FA

A May 11, 2026, report from Google’s Threat Intelligence Group reveals a milestone in offensive AI: an exploit targeting an authorizat…

May 11, 2026views - 150