AutoJack Attack Lets One Web Page Hijack AI Agent for Host Code ExecutionThe Hacker News·Jun 19, 15:30 UTC · Jun 19, 2026Exploit / PoCCVE-2026-26030CVE-2026-25592160
ThreatsDay Bulletin: Claude Chat Abuse, NastyC2 npm Packages, DeviceThe Hacker News·Jun 18, 15:29 UTC · Jun 18, 2026Exploit / PoCCVE-2026-2012760
Unauthenticated file upload in Amasty Order Attributes for MagentoSansec (Magento / e-commerce security)·Jun 15, 20:13 UTC · Jun 15, 2026Exploit / PoC in the wildCVE-2026-5378760
LiteLLM Vulnerability Chain Lets Low-Privilege Users Take Over AI Gateway ServersThe Hacker News·Jun 15, 00:00 UTC · Jun 15, 2026AI safety & security in the wildCVE-2026-47101CVE-2026-47102CVE-2026-40217+1 CVEs50
GitHub to Disable npm Install Scripts by Default to Stop Supply Chain AttacksThe Hacker News·Jun 11, 06:23 UTC · Jun 11, 2026Industry42
Mythos Preview can weaponize N-day vulnerabilities in hoursHelp Net Security·Jun 9, 00:00 UTC · Jun 9, 2026Vulnerability55
Canonical releases Workshop for one-command sandboxed dev environments on UbuntuHelp Net Security·May 28, 00:00 UTC · May 28, 2026AI tools & infra130
VMware fixed a code execution flaw in Fusion hypervisorSecurity Affairs·Sep 3, 21:26 UTC · Sep 3, 2024VulnerabilityCVE-2024-3881147
Experts Find Flaw in Replicate AI Service Exposing Customers' Models and DataThe Hacker News·May 27, 05:55 UTC · May 27, 2024Data breach in the wild60
Suspected Iranian cyber-espionage campaign targets Middle East aerospace, defense industriesThe Record·Feb 28, 20:30 UTC · Feb 28, 2024Threat actor57
Actively exploited 0-days in Ivanti VPN are letting hackers backdoor networksArs Technica · Security·Jan 10, 22:18 UTC · Jan 10, 2024Malware in the wildCVE-2023-46805CVE-2024-2188760
Google quietly corrects previously submitted disclosure for critical webp 0Ars Technica · Security·Sep 27, 00:47 UTC · Sep 27, 2023VulnerabilityCVE-2023-4863CVE-2023-512960
Remote sex toys might spice up your love life – but crooks could also get a kick out of themSecurity Affairs·Feb 15, 05:37 UTC · Feb 15, 2022Vulnerability130
Cyberium malware-hosting domain employed in multiple Mirai variants campaignsSecurity Affairs·Jun 16, 06:17 UTC · Jun 16, 2021Malware in the wildCVE-2020-10987CVE-2017-17215CVE-2014-8361160
Apache Software Foundation fixes code execution flaw in Apache Struts 2Security Affairs·Dec 9, 07:36 UTC · Dec 9, 2020Exploit / PoCCVE-2020-17530CVE-2019-0230160
Mozilla ups bug bounty rewards to $15,000 on critical sitesCyberScoop·Nov 20, 17:31 UTC · Nov 20, 2019Exploit / PoC60
A critical Linux Wi-Fi bug could be exploited to fully compromise systemsSecurity Affairs·Oct 19, 13:45 UTC · Oct 19, 2019VulnerabilityCVE-2019-17666160
Researchers discovered a code execution flaw in NSA GHIDRASecurity Affairs·Oct 9, 07:21 UTC · Oct 9, 2019VulnerabilityCVE-2019-1694160
Crooks leverages .htaccess injector on Joomla and WordPress sites for malicious redirectsSecurity Affairs·May 27, 12:39 UTC · May 27, 2019Exploit / PoCCVE-2018-920660
Mozilla will fix the cross-platform RCE flaw that threatened Tor anonymitySecurity Affairs·Sep 18, 11:36 UTC · Sep 18, 2016Vulnerability42
The Epic Turla OperationKaspersky Securelist·Aug 7, 13:55 UTC · Aug 7, 2014Threat actorCVE-2013-5065CVE-2013-3346CVE-2012-172360