September 7, 2026
- JetBrains is telling Cadence users to revoke and rotate every credential and secret and to treat all executions, inputs and outputs as untrusted, after attackers exploited CVE-2026-63077 (CVSS 9.8, deserialization to unauthenticated OS command execution) against a TeamCity server in JetBrains' own environment. The flaw has been in CISA's KEV catalog since 5 August; JetBrains discovered the intrusion on 23 August. The actor reached a 2024 Cadence backup and storage containing current-user data — usernames, real names, email addresses, last-login timestamps and last-accessed IPs, project source code and credentials — and defenders should hunt authentication activity using Cadence-stored credentials from 8 August onward (The Hacker News).
· CI/CD & Identity
in The Diff Is the Disclosure: MikroTik's Silent Patch Comes Apart
August 8, 2026
in OpenAI Pauses Its Astra Model After It Hits the "Critical" Cyber Threshold
August 7, 2026
in Meta Becomes the Fourth Lab to Admit Its AI Hacked a Stranger
July 30, 2026
in OpenAI's Rogue Agent Widens: Four More Companies Caught in the Blast Radius
July 29, 2026
- JetBrains TeamCity On-Premises got a critical unauth OS-command-execution fix (CVE-2026-63077, CVSS 9.8) across all versions — a high-value target given its position in build pipelines (The Hacker News). Separately, OpenWrt 24.10.8 closes a critical DHCPv6 stack overflow (CVE-2026-53921, CVSS 9.8) letting an unauthenticated attacker on the network run code as root through odhcpd (The Hacker News).
· Vulnerabilities & Exploits
in Artifactory Zero-Days Confirmed as the Hugging Face AI Agent's Escape Route
June 21, 2026
Fortinet networks face massive credential exposure via FortiBleed affecting 86,644 devices, while North Korea's Sapphire Sleet compromised 145 Mastra npm packages with an infostealer, and Google Cloud Vertex AI SDK suffered a cross-tenant RCE vulnerability. Critical CVEs in Splunk, NGINX, Cisco SD-WAN, and Joomla are under active exploitation, alongside emerging AI-focused attacks including AutoJack and malicious JetBrains plugins stealing API keys.
June 20, 2026
FortiBleed has compromised ~86,644 internet-facing FortiGate devices in a credential-harvesting campaign, while a leaked GitHub token gave FulcrumSec access to Novo Nordisk, exfiltrating 1.3TB including unreleased drug formulas and internal AI models. Mastra npm packages were trojanized by Sapphire Sleet (North Korea–nexus), and multiple AI infrastructure flaws emerged: SearchLeak (CVE-2026-42824) in Microsoft 365 Copilot, Pickle in the Middle in Google Vertex AI, and vulnerabilities in LiteLLM. Ransomware gangs including Qilin, Gentlemen, and DragonForce continue dominating the threat landscape with EDR-killing tradecraft and cloud-based C2 abuse.
June 19, 2026
FortiBleed exposed working SSL-VPN credentials for 70,000+ Fortinet devices across 194 countries via industrialized hash-cracking by a Russian-speaking group, while a forgotten GitHub token cost Novo Nordisk 1.3TB of drug formulas and internal AI models. Critical vulnerabilities in NGINX (CVE-2026-42530), Cisco SD-WAN and ISE, Splunk, and Joomla are under active exploitation, alongside AI pipeline supply-chain attacks hitting Mastra, JetBrains Marketplace, and Google Vertex AI. The AtomicArch campaign compromised ~1,500 Arch Linux AUR packages with Rust infostealers and eBPF rootkits.
June 18, 2026
- 15 malicious JetBrains Marketplace plugins, all posing as DeepSeek-based AI coding assistants, exfiltrated developers' AI provider API keys — paired with Chrome extensions capturing chatbot conversations (BleepingComputer, Aikido).
· AI & Model Security
in ShinyHunters Burns a PeopleSoft Zero-Day Through Higher Ed as Copilot "SearchLeak" Shows AI Is the New Exfil Channel
June 17, 2026
in Microsoft 365 Copilot 'SearchLeak' Enables One-Click Data Theft as Novo Nordisk Loses Internal AI Models to Extortionists