Researchers at Sysdig have linked a second attack on the same Langflow server to JADEPUFFER, the AI-agent-driven operator it first documented earlier this month. The same operator has now been...
Threat actors are now exploiting a recently disclosed critical security flaw impacting ServiceNow AI Platform, according to Defused Cyber. In a post shared on X, the threat intelligence firm said...
French cloud backported a patch into Debian and didn’t seek customer consent, despite chance of downtime
French cloud backported a patch into Debian and didn’t seek customer consent, despite chance of downtime
Plus dozens of PoCs in the public domain
Cybersecurity researchers have discovered nearly 7,600 malicious GitHub repositories, out of which more than 800 pose as artificial intelligence (AI) skills or Model Context Protocol (MCP) servers...
A malware operator left its delivery server wide open, and Rapid7 pulled down the whole toolkit: 1,048 files spanning lure templates, filename-spoofing tests, execution experiments, droppers,...
IC3 says any account claiming to represent it is fake
Datacenters tax utilities normally, so just imagine what they could do if workloads were designed to destroy
Chinese open-weight model GLM 5.2 happily obliged
A newly discovered espionage implant has been using a hijacked Microsoft 365 calendar as its command channel, planting operator instructions and smuggling out stolen files as attachments on...
"Community consultation" is one of the reasons automated license plate reader (ALPR) company Flock Safety cited in its decision to drop voice-oriented tech from a gunshot detection system.
In November 2025, AI music generation tool Suno suffered a data breach that later came to light in July the following year. The data contained over 55M unique email addresses. Phone numbers were...
WordPress security advisory (AV26-723)
A single request should not be able to do this much. But this week, small inputs led to code execution, memory loss, stolen keys, and disabled security tools. The paths were often simple: exposed...
Wiz Research has identified exploitation of "wp2shell", a critical pre-auth RCE vulnerability chain impacting WordPress Core (CVE-2026-63030 & CVE-2026-60137). Attackers are deploying persistent...
At least one Russian intelligence service is systematically hijacking internet-connected security cameras across Europe and Ukraine, using the feeds to watch military transport routes, weapons...
The industry spent the initial months after Anthropic's April 7 Mythos reveal focused on volume. How many new CVEs would Mythos add to an already overloaded pipeline? How quickly would the flood...
Malware hides commands in appointments set for 2050 and uses Redmond's own cloud to phone home
HPE security advisory (AV26-722)
GitHub security advisory (AV26-720)
Zimbra security advisory (AV26-721)
[Control systems] CISA ICS security advisories (AV26-718)
Red Hat security advisory (AV26-719)
Bulletin de sécurité GitHub (AV26-720)
Dell security advisory (AV26-716)
Ubuntu security advisory (AV26-717)
IBM security advisory (AV26-715)
CERT Polska has received a report about 3 vulnerabilities (from CVE-2026-57309 to CVE-2026-57311) found in Windu CMS software.
Opening a crafted XZ archive in 7-Zip could let an attacker run code on the machine. The flaw, CVE-2026-14266, is a heap-based buffer overflow in how the archiver processes XZ chunked data, and...