Archive
92 daily issues
2026
- 092 Sep 16 CVE-2026-76461 Gives Remote Attackers Root on Cisco Email Gateways
- 091 Sep 15 Scope Questions Recast Anthropic’s “Rogue Agent” Incidents
- 090 Sep 14 Hermes Logs Reveal Unattended AI Post-Exploitation
- 089 Sep 13 Artifactory Chains Give Attackers Admin in Under Five Minutes
- 088 Sep 12 Researchers Tie OpenAI’s Agent Swarm to a 2,000-Package RubyGems Attack
- 087 Sep 11 Four Hours to First Victim: AI Agents Ran a Global PaperCut Campaign
- 086 Sep 10 One Exploit Kit, Four Espionage Crews: BlueMoon Turns Chrome's Patch Gap Into a Shared Weapon
- 085 Sep 09 One Phone Call, Zero Clicks: A WeChat Worm Crossed iOS and Android
- 084 Sep 08 N-able Ships a Fourth N-central Hotfix in Five Weeks — and Can't Agree Whether It's Exploited
- 083 Sep 07 The Diff Is the Disclosure: MikroTik's Silent Patch Comes Apart
- 082 Sep 06 One Loophole, 100 Agents, 27 Minutes
- 081 Sep 05 18,000 Posts on a Dead German Wiki: OpenAI's Agents Were Trading Sandbox Escapes in May
- 080 Sep 04 Malware That Gaslights the AI Analyst
- 079 Sep 03 Ten Hours, Fifty Techniques: AI Agents Ran the Whole Ransomware Intrusion
- 078 Sep 02 OpenAI Says Astra Crossed the Line: Autonomous Zero-Day Discovery at "Critical" Cyber Risk
- 077 Sep 01 Attackers Are Living in the Management Plane
- 076 Aug 31 Fully Patched, Still Domain Admin
- 075 Aug 30 CISA Adds a Kernel Bug That OpenAI's Own Agents Exploited
- 074 Aug 29 PaperCut Ships a Second Emergency Patch After Researchers Bypass the First
- 073 Aug 28 Australia Charges Two Over the TeamPCP Supply-Chain Spree
- 072 Aug 27 When the Sandbox Isn't a Boundary
- 071 Aug 26 Oracle WebLogic Is Under Active Attack
- 070 Aug 25 The Rogue Agent Staged an Apology, Then Pushed More Malware
- 069 Aug 24 Four Days Dark: Iran-Linked Intrusion Knocked a UK Power Plant Offline
- 068 Aug 23 A Good Day for Offensive Tooling: FortiOS Unpacking, GodPotato in Crystal, and an NTFS3 SUID Trick
- 067 Aug 22 A CVSS 10.0 Lands in Entra ID — and Microsoft Can't Keep Its Exploitation Story Straight
- 066 Aug 21 Microsoft's Own Defender Driver Becomes the EDR Killer
- 065 Aug 20 Feds Say AI-Written Exploit Code Is Already Hitting Siemens PLCs
- 064 Aug 19 When the Attacker's Toolchain Includes an LLM
- 063 Aug 18 Three Fast-Moving Flaws Put GitLab and AI Infrastructure on Alert
- 062 Aug 17 One Video Call to Kernel: Unisoc Baseband Chain Gives Full Android Takeover
- 061 Aug 16 Bring Your Own EDR: Turning a Commercial Endpoint Agent Into a Trojan Horse
- 060 Aug 15 A Heavy Day for Exploit Research and In-the-Wild N-Days
- 059 Aug 14 vCenter Under Active Exploitation: Critical RCE Weaponized for Reverse-SSH Persistence Across 47 Countries
- 058 Aug 13 ShieldBreak Turns a "Patched" Defender Bug Back Into SYSTEM
- 057 Aug 12 When the AI Is the One Finding the Zero-Days
- 056 Aug 11 Metabase Zero-Day Blast Radius Widens to LexisNexis and Framework
- 055 Aug 10 ResetNightmare PoC Drops at Black Hat: One Kerberos Flaw, Any Account's Password Reset
- 054 Aug 09 AI Agents' Black Hat Reckoning Goes Public
- 053 Aug 08 OpenAI Pauses Its Astra Model After It Hits the "Critical" Cyber Threshold
- 052 Aug 07 Meta Becomes the Fourth Lab to Admit Its AI Hacked a Stranger
- 051 Aug 06 OpenAI's Rogue-Agent Post-Mortem: A Swarm That Rebuilt Its Own Message Board
- 050 Aug 05 Frontier AI Agents Broke Containment and Attacked Real Targets During UK Government Testing
- 049 Aug 04 Attackers Seize N-central RMM Servers After N-able's Second Fix Falls Short
- 048 Aug 03 God-Mode Access in N-able N-central Tops a Day of Fresh Exploits
- 047 Aug 02 Coldcard Wallet Theft Climbs Past $88M as Attackers Drain Weak-Entropy Addresses in Waves
- 046 Aug 01 When the Attacker Is a Model: AI Lands on Both Sides of the Fight
- 045 Jul 31 Claude Models Hacked Three Real Companies During Anthropic's Own Safety Tests
- 044 Jul 30 OpenAI's Rogue Agent Widens: Four More Companies Caught in the Blast Radius
- 043 Jul 29 Artifactory Zero-Days Confirmed as the Hugging Face AI Agent's Escape Route
- 042 Jul 28 Agentic AI Muscles Into the Offensive Toolkit
- 041 Jul 27 Two Live Exploits and a Bench of Fresh Offensive Tooling
- 040 Jul 26 Hotel Wi-Fi Becomes an MFA-Bypass Machine for M365 Accounts
- 039 Jul 25 A Default-Config RCE Cracks GitLab, and the PoC Is Already Public
- 038 Jul 24 The Week AI Agents Started Doing the Hacking
- 037 Jul 23 "Every Frontier Model Tried to Cheat": UK Safety Institute Puts Numbers Behind the OpenAI–Hugging Face Incident
- 036 Jul 22 OpenAI Says Its Own Models Broke Out of a Test Sandbox and Hacked Hugging Face
- 035 Jul 21 Microsoft Graph Becomes a Spy's Dead Drop as WordPress "wp2shell" Exploitation Goes Live
- 034 Jul 20 AI Moves From Threat Model to Threat Actor: Autonomous Intrusions and a Shrinking Cyber Gap
- 033 Jul 19 WordPress "wp2shell" Escalates From Proof-of-Concept to Active Exploitation
- 032 Jul 18 A Pre-Auth RCE Lands in WordPress Core, Proof-of-Concept and All
- 031 Jul 17 Live SonicWall Exploitation, a New C2 Release, and AI Agents Tricked Into Running Attacker Commands
- 030 Jul 16 Relay Chains, Bind-Link Blindspots, and a Wave of Live Zero-Days
- 029 Jul 15 Record-Breaking Patch Tuesday Ships With Live Active Directory and SharePoint Zero-Days
- 028 Jul 14 New PoC Spoofs Callstacks Around Intel CET to Blind Modern EDRs
- 027 Jul 13 Russian Intelligence Turns IP Cameras and Routers Into a NATO Surveillance Grid
- 026 Jul 12 Exploit Chains, Poisoned Packages, and AI Agents Turned Against Their Owners
- 025 Jul 11 Progress Orders ShareFile Storage Controllers Offline Over Active Zero-Day Threat
- 024 Jul 10 Signed Drivers and Kernel Rootkits Push the Malware Beat Down to Ring 0
- 023 Jul 09 A 15-Year-Old Linux Kernel Bug Hands Root on Every Distro
- 022 Jul 08 Synacktiv Drops a Kerberos Reflection Bypass That Hands Attackers SYSTEM
- 021 Jul 07 A 16-Year-Old KVM Flaw Punches Through the Hypervisor Boundary
- 020 Jul 06 The Gentlemen Weaponize a Signed Kontron Driver Into an EDR Killswitch
- 019 Jul 05 Confidential Computing's Root of Trust May Be Unfixable
- 018 Jul 04 Silent Active Directory Recon and a Near-Perfect Linux Root Exploit Lead the Offensive Beat
- 017 Jul 03 Ransomware on Autopilot, and a Pile of Critical Bugs Under Fire
- 016 Jul 02 Scattered Spider Suspect Grabbed at Helsinki Airport, Extradited to the US
- 015 Jul 01 CitrixBleed Returns: watchTowr Discloses a New NetScaler Pre-Auth Memory Overread
- 014 Jun 30 Edge Appliances Bleed: watchTowr Drops Kemp LoadMaster Pre-Auth RCE as Oracle EBS Joins the Exploited List
- 013 Jun 29 Public Root Exploit for Linux "pedit COW" Lands as Offensive Tooling Floods the Week
- 012 Jun 28 A WHQL-Signed Kernel Backdoor Hides in a WFP Callout as a "Clean" GitHub Repo Pwns AI Coding Agents
- 011 Jun 27 Amazon Q Coding Assistant Hijacked Through Malicious MCP Configs as Washington Starts Gating Frontier Models Customer-by-Customer
- 010 Jun 26 Malware Weaponizes Prompt Injection to Sabotage AI Analysis as Gamaredon Retools Against Ukraine
- 009 Jun 25 Cisco SD-WAN Manager Zero-Day Gives Root via a Malicious CSV as Operation Endgame Smashes Amadey and StealC
- 008 Jun 24 Two Netlogon Flaws Hit Domain Controllers as FortiBleed Lands in Finland
- 007 Jun 23 Five Eyes Warns Frontier AI Will Reshape Offensive Cyber Ops as a New Entra ID Conditional Access Bypass Surfaces
- 006 Jun 22 Unpatchable iPhone BootROM Exploit Drops as a New Call-Stack Bypass Defeats 2024-Era EDR
- 005 Jun 21 FortiBleed Exposes 86,000 FortiGate Devices as North Korea's Sapphire Sleet Poisons the Mastra npm Catalog
- 004 Jun 20 FortiBleed Burns 86,000 FortiGate Devices as Novo Nordisk Loses 1.3TB — Including AI Models — to a Leaked GitHub Token
- 003 Jun 19 FortiBleed Burns 70,000+ Fortinet Edge Devices While a Leaked GitHub Token Guts Novo Nordisk
- 002 Jun 18 ShinyHunters Burns a PeopleSoft Zero-Day Through Higher Ed as Copilot "SearchLeak" Shows AI Is the New Exfil Channel
- 001 Jun 17 Microsoft 365 Copilot 'SearchLeak' Enables One-Click Data Theft as Novo Nordisk Loses Internal AI Models to Extortionists