OpenAI Pauses Astra Model Over Critical Cybersecurity Risk ConcernsSecurity Affairs·Aug 10, 11:16 UTC · Aug 10, 2026Exploit / PoC160
OpenAI's Next AI Model Astra Shows Cyber Performance Strong Enough to Trigger PauseThe Hacker News·Aug 10, 05:50 UTC · Aug 10, 2026Exploit / PoC160
Critical Gitea Flaw Let Unauthenticated Attackers Read Server Files via OrgThe Hacker News·Aug 5, 11:04 UTC · Aug 5, 2026Exploit / PoC in the wildCVE-2026-59774CVE-2026-60004CVE-2026-20896+1 CVEs60
AI Runs the Hack: Chinese Actor Automates Cyberattacks With DeepSeekSecurity Affairs·Aug 3, 15:53 UTC · Aug 3, 2026Exploit / PoC in the wildCVE-2026-33017CVE-2026-3055CVE-2026-39987160
OpenAI Agent Used Exposed Credentials Across Four Services During Hugging Face BreachThe Hacker News·Aug 1, 05:20 UTC · Aug 1, 2026Exploit / PoC60
What the Hugging Face breach reveals about defense in the age of agentic AICyberScoop·Jul 31, 10:00 UTC · Jul 31, 2026Exploit / PoC160
AI agents are changing where cybersecurity seed funding landsHelp Net Security·Jul 31, 00:00 UTC · Jul 31, 2026Exploit / PoC60
Bugcrowd introduces Savant Pathseeker for agentic penetration testing with exploit validationHelp Net Security·Jul 28, 00:00 UTC · Jul 28, 2026Exploit / PoC60
n8n Sandbox Escape Lets Workflow Editors Run OS Commands as the n8n ProcessThe Hacker News·Jul 27, 13:05 UTC · Jul 27, 2026Exploit / PoC in the wildCVE-2026-2757760
Researcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as GitThe Hacker News·Jul 26, 07:47 UTC · Jul 26, 2026Exploit / PoC in the wild60
AI models keep getting caught cheatingCyberScoop·Jul 21, 19:20 UTC · Jul 21, 2026Exploit / PoC in the wild60
Xint Pulse offers on-demand black-box penetration testing for web applicationsHelp Net Security·Jul 15, 00:00 UTC · Jul 15, 2026Exploit / PoC60
CISA Adds 4 Actively Exploited Adobe, Joomla, and Langflow Flaws to KEVThe Hacker News·Jul 9, 10:22 UTC · Jul 9, 2026Exploit / PoC in the wildCVE-2026-48282CVE-2026-56290CVE-2026-55255+7 CVEs60
How to Evaluate an AI SOC Platform in 2026: 6 Capabilities That Separate Leaders from BoltThe Hacker News·Jul 6, 11:30 UTC · Jul 6, 2026Exploit / PoC45
Scientists Think They’ve Uncovered the 15-Million-Year404 Media·Jun 27, 17:02 UTC · Jun 27, 2026Exploit / PoC45
Unauthenticated file upload in Amasty Order Attributes for MagentoSansec (Magento / e-commerce security)·Jun 15, 20:13 UTC · Jun 15, 2026Exploit / PoC in the wildCVE-2026-5378760
Palo Alto Warns of Active Exploitation of PANThe Hacker News·Jun 15, 00:00 UTC · Jun 15, 2026Exploit / PoC in the wildCVE-2026-025760
Palo Alto Warns HighInfosecurity Magazine·Jun 1, 08:30 UTC · Jun 1, 2026Exploit / PoC in the wildCVE-2026-025760
U.S. CISA adds a flaw in Drupal Core to its Known Exploited Vulnerabilities catalogSecurity Affairs·May 24, 07:54 UTC · May 24, 2026Exploit / PoC in the wildCVE-2026-908260
State-sponsored hackers likely behind zero-day attacks on Palo Alto firewallsHelp Net Security·May 7, 00:00 UTC · May 7, 2026Exploit / PoC in the wildCVE-2026-030060
cPanel zero-day exploited for months before patch release (CVE-2026-41940)Help Net Security·May 5, 12:05 UTC · May 5, 2026Exploit / PoC in the wildCVE-2026-4194060
Mirai Variant Nexcorium Exploits CVE-2024The Hacker News·Apr 22, 15:13 UTC · Apr 22, 2026Exploit / PoC in the wildCVE-2024-3721CVE-2017-17215CVE-2023-33538+2 CVEs160
Why the Axios attack proves AI is mandatory for supply chain securityCyberScoop·Apr 20, 13:17 UTC · Apr 20, 2026Exploit / PoC in the wild60
SessionReaper attacks have started, 3 in 5 stores still vulnerableSansec (Magento / e-commerce security)·Apr 14, 19:49 UTC · Apr 14, 2026Exploit / PoC in the wildCVE-2025-54236CVE-2026-7565060
Fortinet customers confront actively exploited zeroCyberScoop·Apr 6, 21:12 UTC · Apr 6, 2026Exploit / PoC in the wildCVE-2026-35616CVE-2026-2164360
Citrix NetScaler Under Active Recon for CVE-2026The Hacker News·Mar 31, 06:09 UTC · Mar 31, 2026Exploit / PoC in the wildCVE-2026-3055CVE-2023-4966CVE-2025-5777+2 CVEs60
Week in review: NIST updates DNS security guidance, compromised LiteLLM PyPI packagesHelp Net Security·Mar 29, 00:00 UTC · Mar 29, 2026Exploit / PoC in the wildCVE-2025-53521CVE-2026-21992CVE-2026-305560
Kaspersky Global Report by Kaspersky Security Services 2026Kaspersky Securelist·Mar 25, 10:35 UTC · Mar 25, 2026Exploit / PoC in the wild60
State officials, election experts question California sheriff’s seizure of ballotsCyberScoop·Mar 23, 20:01 UTC · Mar 23, 2026Exploit / PoC in the wild60
Fortinet’s latest zero-day vulnerability carries frustrating familiarities for customersCyberScoop·Jan 29, 04:52 UTC · Jan 29, 2026Exploit / PoC in the wildCVE-2026-24858CVE-2025-5971860
U.S. CISA adds a flaw in Gogs to its Known Exploited Vulnerabilities catalogSecurity Affairs·Jan 12, 21:55 UTC · Jan 12, 2026Exploit / PoC in the wildCVE-2025-8110CVE-2024-5594760
Attacks on Kaspersky honeypots exploit CVE-2025Kaspersky Securelist·Dec 11, 07:30 UTC · Dec 11, 2025Exploit / PoC in the wildCVE-2025-5518260
The realities of CISO burnout and exhaustionCyberScoop·Nov 18, 11:00 UTC · Nov 18, 2025Exploit / PoC60
U.S. CISA adds Microsoft WSUS, and Adobe Commerce and Magento Open Source flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·Oct 24, 19:05 UTC · Oct 24, 2025Exploit / PoC in the wildCVE-2025-54236CVE-2025-5928760
Top 10 Takeaways from Predict 2025: Turning Intelligence Into ActionRecorded Future·Oct 21, 00:00 UTC · Oct 21, 2025Exploit / PoC in the wild60
Elderwood project, who is behind Op. Aurora and ongoing attacks?Security Affairs·Oct 6, 23:14 UTC · Oct 6, 2025Exploit / PoC60
Sitecore zero-day vulnerability exploited by attackers (CVE-2025-53690)Help Net Security·Sep 4, 00:00 UTC · Sep 4, 2025Exploit / PoCCVE-2025-5369060
Critical SAP flaw exploited to launch AutoSecurity Affairs·Jul 30, 07:46 UTC · Jul 30, 2025Exploit / PoCCVE-2025-3132460