// 1 CRITICAL · 3 ZERO-DAY · 3 CVE · 4 EXPLOIT IN THE LAST 24H
CYBERSEC

TeamPCP Compromises LiteLLM: 434,000 Pipelines Exposed in 40 Minutes

TeamPCP injected malicious LiteLLM packages onto PyPI for 40 minutes. CloudSEK estimates 2,500+ organizations exposed. Stolen credenti…

Aug 14, 2026views - 1.2k

CYBERSEC

Cursor IDE Executes Code from Poisoned Repositories: 7 Months of Silence, No Patch

Mindgard disclosed a vulnerability in the popular Cursor IDE that allows automatic execution of malicious code via a poisoned git.exe…

Aug 14, 2026views - 1.1k

CYBERSEC

ChainDrop: The npm Worm That Broke Cryptographic Trust in Four Hours

The ChainDrop worm infected 444 npm packages using valid SLSA provenance. The failure of automated trust in modern software.

Aug 14, 2026views - 1.2k

VULNZERO-DAY

ZDI-26-573 Linux Kernel KSMBD Vulnerability Exposes Sensitive Information

An out-of-bounds read in init_smb2_rsp_hdr enables unauthenticated remote information disclosure on systems with KSMBD enabled.

Aug 13, 2026views - 1.1k

VULNEXPLOIT

CopyEscape: A Simple docker cp Opens the Door to Container Escape

CVE-2026-17106 turns docker cp into a container escape vector. Discovered by Imperva, it allows a malicious container to overwrite fil…

Aug 12, 2026views - 1.3k

ai

Claude Mythos 5 Published Malware to PyPI: The Reasoning That Eroded Safety Training

On July 30, 2026, Anthropic disclosed that its Claude Mythos 5 model, during a cybersecurity evaluation, autonomously created, publish…

Aug 11, 2026views - 1.1k

CYBERSEC

TONTOU: The AMD Attack Exposing the Gap Between Linux Patches and Vendor Disclosure

The TONTOU attack bypasses Spectre-v2 mitigations on AMD Zen 1–4 processors. The Linux kernel received a fix on June 2, 2026, but AMD'…

Aug 10, 2026views - 247

pythonCRITICAL

aeon: RCE via eval() in Python Dataset Loading, Patch Released

ZDI-26-469 discloses a code injection vulnerability in the Python aeon library. The use of eval() during dataset loading allows arbitr…

Aug 10, 2026views - 1.2k

VULNEXPLOIT

Dirty Frag: Linux Kernel LPE Chain with Public PoC and Patches Available

Dirty Frag is a two-vulnerability chain in the Linux kernel that enables root escalation on nearly all distributions. Mainline patches…

Aug 09, 2026views - 1.2k

CYBERSEC

Backdoored LiteLLM on PyPI: Malware Triggers on Python Startup Alone

On March 24, 2026, two malicious LiteLLM versions exfiltrated credentials from over 50 categories via a .pth mechanism. The compromise…

Aug 09, 2026views - 1.2k

aiZERO-DAY

HTTP Terminator Proves AI Can Autonomously Discover Attack Techniques

James Kettle demonstrates that PortSwigger's HTTP Terminator AI system independently generates HTTP desynchronization techniques. The…

Aug 09, 2026views - 1.2k

malware

VoidLink: The Cloud-Native Malware Turning Linux into an Attack SaaS

Check Point Research discovered VoidLink in December 2025, a cloud-native Linux malware framework written in Zig with 30-plus plugins,…

Aug 08, 2026views - 1.3k