Cisco FMC Zero-Day Actively Exploited, Static Credentials Could Expose Sensitive DataThe Hacker News·Aug 6, 16:41 UTC · Aug 6, 2026Exploit / PoC in the wildCVE-2026-20316CVE-2026-2007960
AI Recommendation Poisoning: How "Ask AI" Buttons Silently Alter LLM MemoryThe Hacker News·Aug 6, 11:30 UTC · Aug 6, 2026Exploit / PoC60
Paperclip AI Flaws Let Attackers Run Host Commands via Malicious Agent ImportsThe Hacker News·Aug 5, 15:14 UTC · Aug 5, 2026Exploit / PoC in the wildCVE-2026-41679160
New OVSwrap Linux Kernel Flaw Lets Local Users Gain Root via Open vSwitchThe Hacker News·Aug 5, 11:43 UTC · Aug 5, 2026Exploit / PoCCVE-2026-6453150
Critical Gitea Flaw Let Unauthenticated Attackers Read Server Files via OrgThe Hacker News·Aug 5, 11:04 UTC · Aug 5, 2026Exploit / PoC in the wildCVE-2026-59774CVE-2026-60004CVE-2026-20896+1 CVEs60
Leaked n8n API Tokens Exposed Live Instances to Credential TheftThe Hacker News·Aug 5, 10:35 UTC · Aug 5, 2026Exploit / PoC in the wildCVE-2025-6861360
Google Deletes 3 ADK AI Workflows After Malicious GitHub Issue Could Trigger Privileged AgentThe Hacker News·Aug 4, 11:16 UTC · Aug 4, 2026Exploit / PoC in the wild60
CISA Adds Exploited N-able N-central Flaw to KEV After Customer CompromisesThe Hacker News·Aug 4, 07:00 UTC · Aug 4, 2026Exploit / PoC in the wildCVE-2026-18577CVE-2026-18556CVE-2025-8875+1 CVEs60
Researchers Report 84 Flaws in 4G and 5G Cores, Including a Session Hijacking FlawThe Hacker News·Aug 3, 08:23 UTC · Aug 3, 2026Exploit / PoCCVE-2026-8233CVE-2026-36884CVE-2025-6677650
OpenAI Agent Used Exposed Credentials Across Four Services During Hugging Face BreachThe Hacker News·Aug 1, 05:20 UTC · Aug 1, 2026Exploit / PoC60
Critical Rails Flaw Could Let Unauthenticated Attackers Read Server Files via Image UploadsThe Hacker News·Jul 31, 11:17 UTC · Jul 31, 2026Exploit / PoC in the wildCVE-2026-66066CVE-2025-24293160
Microsoft Copilot for Word Can Copy Hidden Prompts Into New DocumentsThe Hacker News·Jul 30, 11:54 UTC · Jul 30, 2026Exploit / PoC145
JFrog Confirms OpenAI Models Exploited Artifactory ZeroThe Hacker News·Jul 30, 03:54 UTC · Jul 30, 2026Exploit / PoCCVE-2026-65617CVE-2026-65923CVE-2026-66018+1 CVEs60
Researchers Show a Single Malicious Webpage Visit Can Compromise Tor BrowserThe Hacker News·Jul 29, 11:57 UTC · Jul 29, 2026Exploit / PoCCVE-2026-10702CVE-2026-4349950
Public PoC Released for Exploited Check Point SmartConsole Authentication BypassThe Hacker News·Jul 29, 08:59 UTC · Jul 29, 2026Exploit / PoC in the wildCVE-2026-1623260
Critical OpenWrt DHCPv6 Flaw Could Let Unauthenticated Attackers Run Code as RootThe Hacker News·Jul 28, 13:10 UTC · Jul 28, 2026Exploit / PoC in the wildCVE-2026-53921CVE-2026-62948CVE-2026-62947160
Microsoft Says New Cybersecurity AI Model Helps MDASH Score 95.95% at Half the CostThe Hacker News·Jul 28, 09:21 UTC · Jul 28, 2026Exploit / PoC45
Critical TeamCity Flaw Could Let Attackers Run OS Commands Without Logging InThe Hacker News·Jul 28, 08:11 UTC · Jul 28, 2026Exploit / PoC in the wildCVE-2026-6307760
Researcher Says AI Helped Develop Linux TrafficThe Hacker News·Jul 28, 08:04 UTC · Jul 28, 2026Exploit / PoC in the wildCVE-2026-5326460
U.S. CISA adds Microsoft SharePoint and Check Point SmartConsole flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·Jul 28, 08:02 UTC · Jul 28, 2026Exploit / PoC in the wildCVE-2026-16232CVE-2026-50522CVE-2026-5864460
Attackers Exploit Arista VeloCloud Orchestrator Command Injection FlawThe Hacker News·Jul 28, 04:43 UTC · Jul 28, 2026Exploit / PoC in the wildCVE-2026-16812CVE-2025-68686CVE-2026-1672360
Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain ControllerThe Hacker News·Jul 28, 04:01 UTC · Jul 28, 2026Exploit / PoC in the wildCVE-2026-54121160
NVIDIA Forms 37-Member Open Secure AI Alliance and OpenThe Hacker News·Jul 27, 18:10 UTC · Jul 27, 2026Exploit / PoC60
n8n Sandbox Escape Lets Workflow Editors Run OS Commands as the n8n ProcessThe Hacker News·Jul 27, 13:05 UTC · Jul 27, 2026Exploit / PoC in the wildCVE-2026-2757760
Researcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as GitThe Hacker News·Jul 26, 07:47 UTC · Jul 26, 2026Exploit / PoC in the wild60
CISA Adds Exploited PTC Windchill RCE Flaw to KEV as Web Shell Attacks ContinueThe Hacker News·Jul 25, 09:59 UTC · Jul 25, 2026Exploit / PoC in the wildCVE-2026-1256960
OpenSSL HollowByte Flaw Could Freeze Server Memory with 11The Hacker News·Jul 24, 05:12 UTC · Jul 24, 2026Exploit / PoCCVE-2025-66199CVE-2026-3418360
AWS Kiro Flaw Let a Poisoned Web Page Rewrite Its Config and Run CodeThe Hacker News·Jul 24, 04:46 UTC · Jul 24, 2026Exploit / PoC in the wildCVE-2026-1059160
Nine-Year-Old RefluXFS Linux Flaw Gives Local Users Root on Default RHEL InstallsThe Hacker News·Jul 24, 04:42 UTC · Jul 24, 2026Exploit / PoCCVE-2026-64600CVE-2026-893350
OpenAI Says Its AI Models Escaped Sandbox, Targeted Hugging Face to Cheat BenchmarkThe Hacker News·Jul 22, 20:30 UTC · Jul 22, 2026Exploit / PoC60
WordPress wp2shell Exploitation Grows as Public Exploit Fuels Mass ScanningThe Hacker News·Jul 22, 15:41 UTC · Jul 22, 2026Exploit / PoC in the wildCVE-2026-63030CVE-2026-6013760
Microsoft Azure DevOps MCP Flaw Lets Hidden PR Comments Hijack AI Review AgentsThe Hacker News·Jul 22, 14:13 UTC · Jul 22, 2026Exploit / PoC145
OpenAI Claims Its AI Models Went Rogue and Hacked Another CompanyInfosecurity Magazine·Jul 22, 11:40 UTC · Jul 22, 2026Exploit / PoC60
Public PoC triggers active exploitation of critical SharePoint RCE vulnerability CVE-2026Security Affairs·Jul 21, 21:38 UTC · Jul 21, 2026Exploit / PoC in the wildCVE-2026-50522CVE-2026-58644CVE-2026-45659+2 CVEs160
Critical ServiceNow AI Platform Flaw Exploited for Unauthenticated Code ExecutionThe Hacker News·Jul 21, 18:17 UTC · Jul 21, 2026Exploit / PoC in the wildCVE-2026-687560
Researcher Drops New Windows Zero-Day PoC Hours After Microsoft Patch TuesdayThe Hacker News·Jul 21, 11:38 UTC · Jul 21, 2026Exploit / PoC in the wildCVE-2026-56164CVE-2026-56155CVE-2026-32201+2 CVEs60
Stop Your Legacy Infrastructure from Hijacking Your AI AgentsThe Hacker News·Jul 20, 06:32 UTC · Jul 20, 2026Exploit / PoC in the wildCVE-2025-2481360
New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run CodeThe Hacker News·Jul 18, 05:23 UTC · Jul 18, 2026Exploit / PoC in the wildCVE-2026-63030CVE-2026-6013760
CISA Adds Exploited SharePoint RCE Zero-Day CVE-2026The Hacker News·Jul 17, 06:42 UTC · Jul 17, 2026Exploit / PoC in the wildCVE-2026-58644CVE-2026-32201CVE-2026-45659+3 CVEs60