Microsoft Copilot for Word Can Copy Hidden Prompts Into New DocumentsThe Hacker News·Jul 30, 11:54 UTC · Jul 30, 2026Exploit / PoC145
One-Click Microsoft 365 Copilot Flaw Could Have Let Attackers Steal Emails, Files, and MFA CodesThe Hacker News·Jun 15, 00:00 UTC · Jun 15, 2026Exploit / PoC in the wildCVE-2026-42824CVE-2025-32711160
Invisible text that AI chatbots understand and humans can’t? Yep, it’s a thing.Ars Technica · Security·Oct 15, 00:00 UTC · Oct 15, 2024Exploit / PoC145
Microsoft Fixes ASCII Smuggling Flaw That Enabled Data Theft from Microsoft 365 CopilotThe Hacker News·Aug 29, 10:57 UTC · Aug 29, 2024Exploit / PoC157
Tines rolls out a governance layer for agents, copilots, and MCPsHelp Net Security·Jan 15, 00:00 UTC · Jan 15, 2026Exploit / PoC60
⚡ Weekly Recap: Fortinet Exploits, RedLine Clipjack, NTLM Crack, Copilot Attack & MoreThe Hacker News·Jan 20, 07:01 UTC · Jan 20, 2026Exploit / PoC in the wildCVE-2025-6415560
Tanium Automate reduces manual processes for repeatable tasksHelp Net Security·Apr 16, 00:00 UTC · Apr 16, 2024Exploit / PoC60
Microsoft 365 Android Apps Let Any App Steal Account Tokens via Leftover Debug FlagThe Hacker News·Jun 3, 14:56 UTC · Jun 3, 2026Exploit / PoCCVE-2026-41100CVE-2026-41101CVE-2026-41102+1 CVEs150
TotalRecall shows how easily data collected by Windows Recall can be stolenHelp Net Security·Jun 5, 00:00 UTC · Jun 5, 2024Exploit / PoC45
Public GitHub Issue Could Trick GitHub Agentic Workflows Into Leaking Private Repo DataThe Hacker News·Jul 7, 14:07 UTC · Jul 7, 2026Exploit / PoC145
Week in review: NIST updates DNS security guidance, compromised LiteLLM PyPI packagesHelp Net Security·Mar 29, 00:00 UTC · Mar 29, 2026Exploit / PoC in the wildCVE-2025-53521CVE-2026-21992CVE-2026-305560
How security teams are putting AI to work right nowHelp Net Security·Aug 18, 00:00 UTC · Aug 18, 2025Exploit / PoC45
New Agent Data Injection Attack Can Make AI Agents Misclick or Run Attacker CommandsThe Hacker News·Jul 15, 00:00 UTC · Jul 15, 2026Exploit / PoCCVE-2025-32711150
Capsule Security debuts with $7 million funding to secure AI agent behaviorHelp Net Security·Apr 15, 00:00 UTC · Apr 15, 2026Exploit / PoCCVE-2026-2152060
Week in review: Windows zero-day exploit leaked, Patch Tuesday forecastHelp Net Security·Apr 12, 00:00 UTC · Apr 12, 2026Exploit / PoC in the wildCVE-2026-34197160
Microsoft Issues Security Fixes for 56 Flaws, Including Active Exploit and Two ZeroThe Hacker News·Dec 10, 15:09 UTC · Dec 10, 2025Exploit / PoC in the wildCVE-2025-62223CVE-2025-62221CVE-2025-54100+6 CVEs60
⚡ Weekly Recap: Fortinet Exploited, China's AI Hacks, PhaaS Empire Falls & MoreThe Hacker News·Nov 17, 12:37 UTC · Nov 17, 2025Exploit / PoC in the wildCVE-2025-64446CVE-2025-64740CVE-2025-64741+24 CVEs60
Gurucul’s AI-IRM accelerates insider risk detectionHelp Net Security·Sep 18, 00:00 UTC · Sep 18, 2025Exploit / PoC in the wildCVE-2026-8749160
Man-in-the-Prompt: The invisible attack threatening ChatGPT and other AI systemsSecurity Affairs·Aug 16, 17:27 UTC · Aug 16, 2025Exploit / PoC45
Microsoft rolls back ‘dumbest cybersecurity move in a decade’CyberScoop·Jun 7, 20:01 UTC · Jun 7, 2024Exploit / PoC in the wild60
Windows Recall will be opt-in and the data more secure, Microsoft saysHelp Net Security·Jun 7, 00:00 UTC · Jun 7, 2024Exploit / PoC145
Week in review: PoC for Splunk Enterprise RCE flaw released, scope of Okta breach widensHelp Net Security·Dec 3, 00:00 UTC · Dec 3, 2023Exploit / PoC in the wildCVE-2023-46214CVE-2023-49103CVE-2023-41998+5 CVEs260
AWS Kiro Flaw Let a Poisoned Web Page Rewrite Its Config and Run CodeThe Hacker News·Jul 24, 04:46 UTC · Jul 24, 2026Exploit / PoC in the wildCVE-2026-1059160
Microsoft Azure DevOps MCP Flaw Lets Hidden PR Comments Hijack AI Review AgentsThe Hacker News·Jul 22, 14:13 UTC · Jul 22, 2026Exploit / PoC145
Cursor Flaw Lets Malicious Cloned Repositories Trigger Windows Code ExecutionThe Hacker News·Jul 15, 00:00 UTC · Jul 15, 2026Exploit / PoCCVE-2026-26268CVE-2026-10591150
Top AI Agents Built to Catch Malicious Code Can Be Tricked Into Running ItThe Hacker News·Jul 9, 05:17 UTC · Jul 9, 2026Exploit / PoCCVE-2026-3986150
Seven Bugs in FatFs Put IoT and Embedded Devices at RiskSecurity Affairs·Jul 6, 10:20 UTC · Jul 6, 2026Exploit / PoCCVE-2026-6682CVE-2026-6683CVE-2026-6687+4 CVEs150
Security Affairs newsletter Round 559 by Pierluigi PaganiniSecurity Affairs·Jan 18, 13:46 UTC · Jan 18, 2026Exploit / PoC in the wild60
Microsoft Fixes Three ZeroInfosecurity Magazine·Dec 10, 09:45 UTC · Dec 10, 2025Exploit / PoC in the wildCVE-2025-62221CVE-2025-54100CVE-2025-64671+4 CVEs60
The Bug That Won't Die: 10 Years of the Same MistakeRecorded Future·Dec 9, 00:00 UTC · Dec 9, 2025Exploit / PoCCVE-2025-55182CVE-2025-66478CVE-2015-485260
Top 10 Takeaways from Predict 2025: Turning Intelligence Into ActionRecorded Future·Oct 21, 00:00 UTC · Oct 21, 2025Exploit / PoC in the wild60
Cato Networks acquires AI security startup Aim SecurityCyberScoop·Sep 3, 20:11 UTC · Sep 3, 2025Exploit / PoC in the wild60
Exabeam Nova accelerates threat detection and responseHelp Net Security·Apr 2, 00:00 UTC · Apr 2, 2025Exploit / PoC60
Microsoft Fixes AI, Cloud, and ERP Security Flaws; One Exploited in Active AttacksThe Hacker News·Dec 1, 07:13 UTC · Dec 1, 2024Exploit / PoC in the wildCVE-2024-49035CVE-2024-49038CVE-2024-49052+1 CVEs160
Microsoft fixes 6 zero-days under active attackHelp Net Security·Aug 15, 07:12 UTC · Aug 15, 2024Exploit / PoC in the wildCVE-2024-38178CVE-2024-38106CVE-2024-38107+10 CVEs60
SASE Threat Report: 8 Key Findings for Enterprise SecurityThe Hacker News·Jun 3, 10:56 UTC · Jun 3, 2024Exploit / PoCCVE-2021-4422860
Week in review: Google fixes yet another Chrome zero-day exploit, YouTube as a cybercrime channelHelp Net Security·May 26, 00:00 UTC · May 26, 2024Exploit / PoC in the wildCVE-2024-5274CVE-2024-4985CVE-2023-43208+4 CVEs60
Log4Shell shows no sign of fading, spotted in 30% of CVE exploitsHelp Net Security·May 14, 00:00 UTC · May 14, 2024Exploit / PoCCVE-2017-9841CVE-2021-4422860
Everything You Wanted to Know About AI Security but Were Afraid to AskThe Hacker News·Sep 4, 11:29 UTC · Sep 4, 2023Exploit / PoC60