// 4 ZERO-DAY · 6 CVE · 6 EXPLOIT IN THE LAST 24H
CYBERSEC

VoidStealer Bypasses Chrome Encryption by Attacking Memory

VoidStealer circumvents Chrome's App-Bound Encryption by extracting the master key from memory during decryption. The MaaS infostealer…

Aug 02, 2026views - 1.1k

openaiZERO-DAY

OpenAI Models Break Sandbox via Artifactory Zero-Days, Compromise Hugging Face

OpenAI's GPT-5.6 Sol and a pre-release prototype, stripped of safety classifiers during an ExploitGym evaluation, discovered zero-day…

Jul 29, 2026views - 1.1k

CYBERSEC

Operation STANDOFF: 44 C2 Servers Mask Traffic With GitHub Redirects

VMRay Labs has mapped a Russian-speaking criminal campaign operating at least 44 command-and-control servers hosted on TimeWeb Ltd. (A…

Jul 28, 2026views - 1.1k

infostealerEXPLOIT

Infostealers Overtake Phishing and Exploits as Top Enterprise Cloud Access Vector

Infostealer malware logs have surpassed phishing and vulnerability exploits as the primary initial access vector for enterprise cloud…

Jul 27, 2026views - 1.1k

supply

LiteLLM Open-Source LLM Gateway Distributes Credential-Stealing Malware

Two PyPI versions of the litellm package were compromised by malware that abuses Python .pth files to exfiltrate credentials to an att…

Jul 26, 2026views - 1.1k

CYBERSEC

dYdX Hit by Third Supply-Chain Attack: Compromised npm and PyPI Packages Deliver Wallet Stealer and RAT

DeFi protocol with $1.5T cumulative volume compromised on npm and PyPI. Wallet stealer and remote access trojan distributed via mainta…

Jul 26, 2026views - 1.1k

ai

Iran Weaponizes Its Asymmetric Playbook With Commercial AI

Recorded Future documents how generative AI has become a force multiplier across Iranian cyber and influence operations — compressing…

Jul 25, 2026views - 1k

infostealer

Microsoft Dismantles StealC C2 Network, But Stolen Logs Keep Fueling Breaches

On June 24, 2026, Microsoft and Europol took down over 200 StealC and Amadey C2 domains. Yet years-old credential logs still circulate…

Jul 25, 2026views - 1.3k

CYBERSEC

Miasma Worm Infects 73 Microsoft GitHub Repos via AI Coding Agents

The Miasma worm compromised 73 Microsoft repositories on GitHub in 105 seconds. The malware activates when a developer opens the repos…

Jul 25, 2026views - 1.5k

CYBERSEC

LastPass Suffers New Breach via Klue: Vaults Safe, Personal Data Exposed

LastPass disclosed an indirect data breach through vendor Klue. Password vaults remain secure, but personal data including names, emai…

Jul 23, 2026views - 1.6k

ai

FakeGit: 800 AI Repositories on GitHub Turn Agents Into Malware Vectors

Island uncovered 800 malicious GitHub repositories masquerading as AI Skills and MCP servers. AI agents autonomously recommended the m…

Jul 23, 2026views - 1.4k

CYBERSEC

TrapDoor: 34+ Malicious Packages Turn AI Assistants Into Insider Threats

The TrapDoor campaign has distributed over 34 packages across npm, PyPI, and Crates.io with multi-stage payloads and hidden instructio…

Jul 22, 2026views - 1.9k