// 1 CRITICAL · 5 ZERO-DAY · 8 CVE · 8 EXPLOIT IN THE LAST 24H
VULNCRITICAL

Aeon RCE via Pickle Dataset: ML Pipeline Risk

CVE-2026-18285: The Python library Aeon executed arbitrary code through pickle deserialization of seemingly legitimate datasets. The b…

Aug 02, 2026views - 1.1k

CYBERSECCRITICAL

Aeon RCE Flaw in Benchmark Loading: The Risk Lies in the Datasets

Trend Micro's Zero Day Initiative published advisory ZDI-26-470 assigning CVE-2026-18287 to a code injection vulnerability in the Pyth…

Jul 30, 2026views - 1.3k

nvidiaCRITICAL

NVIDIA NVTabular: RCE via Pickle, CVE-2026-24237 Rated CVSS 7.8

A deserialization flaw in NVIDIA NVTabular enables remote code execution through malicious pickle files. User interaction is required;…

Jul 26, 2026views - 1.2k

ransomware

EncForge: JadePuffer Hits Irrecoverable AI Models With Agentic Ransomware

The agentic threat actor JadePuffer has deployed EncForge, ransomware purpose-built for AI/ML assets. Encrypted models cannot be recov…

Jul 24, 2026views - 1.3k

CYBERSEC

AssuranceAmerica: 7 Million Driver's Licenses Exposed, No Credit Monitoring Offered

A single compromised employee account opened access to nearly 7 million driver's license numbers. AssuranceAmerica is not offering cre…

Jul 09, 2026views - 1.4k

CYBERSEC

Beyond IOCs: Talos Unveils Vision for LLMs in Threat Intelligence

Cisco Talos explores how large language models transcend traditional indicators of compromise by indexing strategic reports in natural…

Jun 25, 2026views - 1.2k

CYBERSEC

'Snoopy' Sentenced: 18 Months for the Massive DraftKings Hack

Nathan Austad, known as 'Snoopy,' received an 18-month federal prison sentence for orchestrating the November 2022 credential-stuffing…

Jun 25, 2026views - 762

CYBERSEC

Infinite Campus: 137,123 Staff Emails Exposed in Salesforce Breach

ShinyHunters compromised an Infinite Campus employee's Salesforce account on March 18, 2026. After a failed extortion attempt, 137,123…

Jun 15, 2026views - 1.5k

VULNCVE

NVIDIA Transformers4Rec Flaw Enables RCE via Malicious ML Models

NVIDIA has patched a high-severity deserialization vulnerability (CVE-2026-24162, CVSS 7.8) in its Transformers4Rec library that allow…

Jun 13, 2026views - 845

CYBERSEC

BadBone: Dormant AI Backdoor Evades Six Major Security Defenses

BadBone research demonstrates that backdoors in pre-trained AI models remain invisible until customized, maintaining a 0.10% attack su…

Jun 02, 2026views - 262

CYBERSEC

Trojan Detection: 33 Behavioral Signals May Challenge Complex Machine Learning Models

A new framework utilizing 33 refined behavioral features aims to detect Windows Trojans with competitive performance on standard enter…

May 29, 2026views - 162

CYBERSEC

Vishing and AiTM Bypass MFA: Invisible Extortion in SaaS

Criminal groups like Cordial Spider use vishing and AiTM to bypass MFA and target SaaS environments. Protect your corporate data from…

May 01, 2026views - 117