A 15-Year-Old Unpatched Python bug potentially impacts +350K projectsSecurity Affairs·Sep 22, 13:28 UTC · Sep 22, 2022VulnerabilityCVE-2007-4559CVE-2001-1267160
Researchers Uncover Flaws in Python Package for AI Models and PDF.js Used by FirefoxThe Hacker News·May 21, 10:22 UTC · May 21, 2024VulnerabilityCVE-2024-34359CVE-2024-4367160
New n8n Vulnerability (9.9 CVSS) Lets Authenticated Users Execute System CommandsThe Hacker News·Jan 15, 00:00 UTC · Jan 15, 2026VulnerabilityCVE-2025-68668CVE-2025-68613160
Python tarfile vulnerability affects 350,000 open-source projects (CVE-2007-4559)Help Net Security·Sep 22, 00:00 UTC · Sep 22, 2022VulnerabilityCVE-2007-455960
ThreatsDay Bulletin: PAN-OS RCE, Mythos cURL Bug, AI Tokenizer Attacks, and 10+ StoriesThe Hacker News·May 15, 00:00 UTC · May 15, 2026VulnerabilityCVE-2026-030060
SGLang CVE-2026-5760 (CVSS 9.8) Enables RCE via Malicious GGUF Model FilesThe Hacker News·Apr 20, 17:14 UTC · Apr 20, 2026VulnerabilityCVE-2026-5760CVE-2024-34359CVE-2025-6162060
Critical Vulnerabilities Found in NVIDIA's Triton Inference ServerInfosecurity Magazine·Aug 5, 15:45 UTC · Aug 5, 2025VulnerabilityCVE-2025-23319CVE-2025-23320CVE-2025-23334+1 CVEs60
Critical and High Severity n8n Sandbox Flaws Allow RCEInfosecurity Magazine·Jan 28, 16:00 UTC · Jan 28, 2026VulnerabilityCVE-2026-1470CVE-2026-086360
Critical Grist-Core Vulnerability Allows RCE Attacks via Spreadsheet FormulasThe Hacker News·Jan 27, 14:07 UTC · Jan 27, 2026VulnerabilityCVE-2026-24002CVE-2025-6866860
Chaining NVIDIA's Triton Server flaws exposes AI systems to remote takeoverSecurity Affairs·Aug 5, 07:35 UTC · Aug 5, 2025VulnerabilityCVE-2025-23319CVE-2025-23320CVE-2025-2333460
Unmasking the new persistent attacks on JapanCisco Talos·Mar 6, 11:00 UTC · Mar 6, 2025VulnerabilityCVE-2024-4577160
Researchers Find Bugs in Over A Dozen Widely Used URL Parser LibrariesThe Hacker News·Aug 2, 11:07 UTC · Aug 2, 2022VulnerabilityCVE-2021-33056CVE-2021-23414CVE-2021-37352+5 CVEs160
Vulnerability Spotlight: YAML Parsing Remote Code Execution Vulnerabilities in Ansible Vault and TablibCisco Talos·Sep 14, 14:30 UTC · Sep 14, 2017Vulnerability in the wildCVE-2017-2809CVE-2017-2810160
Ubuntu’s Crash Report Tool Allows Remote Code ExecutionThe Hacker News·Dec 15, 00:00 UTC · Dec 15, 2016VulnerabilityCVE-2016-9949CVE-2016-995060
Cohere AI Terrarium Sandbox Flaw Enables Root Code Execution, Container EscapeThe Hacker News·Apr 22, 07:16 UTC · Apr 22, 2026VulnerabilityCVE-2026-5752160
Critical Langflow Flaw CVE-2026-33017 Triggers Attacks within 20 Hours of DisclosureThe Hacker News·Mar 26, 06:26 UTC · Mar 26, 2026Vulnerability in the wildCVE-2026-33017CVE-2025-3248160
Critical n8n Flaw CVE-2026-25049 Enables System Command Execution via Malicious WorkflowsThe Hacker News·Feb 6, 09:39 UTC · Feb 6, 2026VulnerabilityCVE-2026-25049CVE-2025-68613CVE-2026-21893+10 CVEs160
Warning: New Malware Emerges in Attacks Exploiting Ivanti VPN VulnerabilitiesThe Hacker News·Feb 2, 04:53 UTC · Feb 2, 2024Vulnerability in the wildCVE-2023-46805CVE-2024-21887CVE-2024-21888+1 CVEs60
Week in review: cPanel vulnerability actively exploited, DigiCert breach, LinkedIn job scamsHelp Net Security·May 10, 00:00 UTC · May 10, 2026Vulnerability in the wildCVE-2026-41940CVE-2026-4670CVE-2026-5174+4 CVEs60
⚡ Weekly Recap: AI-Powered Phishing, Android Spying Tool, Linux Exploit, GitHub RCE & MoreThe Hacker News·May 5, 05:41 UTC · May 5, 2026Vulnerability in the wildCVE-2026-41940CVE-2026-31431CVE-2026-3854+2 CVEs160
AI-powered honeypots: Turning the tables on malicious AI agentsCisco Talos·Apr 29, 10:00 UTC · Apr 29, 2026VulnerabilityCVE-2014-627160
Picklescan Bugs Allow Malicious PyTorch Models to Evade Scans and Execute CodeThe Hacker News·Dec 3, 11:44 UTC · Dec 3, 2025VulnerabilityCVE-2025-10155CVE-2025-10156CVE-2025-10157+1 CVEs60
Researchers Find Serious AI Bugs Exposing Meta, Nvidia, and Microsoft Inference FrameworksThe Hacker News·Nov 15, 00:00 UTC · Nov 15, 2025VulnerabilityCVE-2024-50050CVE-2025-30165CVE-2025-23254+1 CVEs60
Russia-Aligned TAG-110 Targets Asia and Europe with HATVIBE and CHERRYSPYRecorded Future·Aug 22, 00:00 UTC · Aug 22, 2025VulnerabilityCVE-2024-2369260
Exploits for unauthenticated FortiWeb RCE are public, so patch quickly! (CVE-2025-25257)Help Net Security·Jul 19, 15:00 UTC · Jul 19, 2025Vulnerability in the wildCVE-2025-2525760
Meta's Llama Framework Flaw Exposes AI Systems to Remote Code Execution RisksThe Hacker News·Jan 28, 05:26 UTC · Jan 28, 2025VulnerabilityCVE-2024-50050CVE-2024-3660160
Citrix Bleed: Mass exploitation in progress (CVE-2023-4966)Help Net Security·Nov 2, 14:31 UTC · Nov 2, 2023Vulnerability in the wildCVE-2023-496660
FreakOut! Ongoing Botnet Attack Exploiting Recent Linux VulnerabilitiesThe Hacker News·Jan 19, 13:40 UTC · Jan 19, 2021VulnerabilityCVE-2020-28188CVE-2021-3007CVE-2020-796160
Week in review: vBulletin 0-day, open source projects under attack, critical security updates galoreHelp Net Security·Aug 16, 00:00 UTC · Aug 16, 2020VulnerabilityCVE-2020-11552CVE-2019-1675960
Vulnerability Spotlight: Python.org certificate parsing denial-ofCisco Talos·Jan 28, 19:12 UTC · Jan 28, 2019Vulnerability in the wildCVE-2018-501060
Hugging Face Diffusers Flaws Could Let Model Repositories Execute Arbitrary CodeThe Hacker News·Aug 3, 06:40 UTC · Aug 3, 2026VulnerabilityCVE-2026-44827CVE-2026-45804CVE-2026-44513160
Langflow RCE Exploited to Deploy Monero Miner on Exposed AI App EndpointsThe Hacker News·Jun 30, 15:47 UTC · Jun 30, 2026Vulnerability in the wildCVE-2026-33017CVE-2025-3248160
CVE-2026-39987: Marimo RCE exploited in hours after disclosureSecurity Affairs·Apr 11, 09:44 UTC · Apr 11, 2026Vulnerability in the wildCVE-2026-39987CVE-2026-3301760
CVE-2026-1731 fuels ongoing attacks on BeyondTrust remote access productsSecurity Affairs·Feb 23, 12:09 UTC · Feb 23, 2026Vulnerability in the wildCVE-2026-173160
Week in review: Fully patched FortiGate firewalls are getting compromised, attackers probe Cisco RCE flawHelp Net Security·Jan 25, 00:00 UTC · Jan 25, 2026VulnerabilityCVE-2026-20045CVE-2025-5971860
ThreatsDay Bulletin: AI Voice Cloning Exploit, Wi-Fi Kill Switch, PLC Vulns, and 14 More StoriesThe Hacker News·Jan 19, 06:25 UTC · Jan 19, 2026VulnerabilityCVE-2025-62507CVE-2025-23304CVE-2026-22584160
China-linked APT UAT-9686 abused now patched maximum severity AsyncOS bugSecurity Affairs·Jan 16, 10:17 UTC · Jan 16, 2026Vulnerability in the wildCVE-2025-2039360
⚡ Weekly Recap: IoT Exploits, Wallet Breaches, Rogue Extensions, AI Abuse & MoreThe Hacker News·Jan 5, 12:56 UTC · Jan 5, 2026VulnerabilityCVE-2025-55182CVE-2025-13915CVE-2025-52691+7 CVEs60
Critical PickleScan Vulnerabilities Expose AI Model Supply ChainsInfosecurity Magazine·Dec 2, 16:00 UTC · Dec 2, 2025VulnerabilityCVE-2025-10155CVE-2025-10156CVE-2025-1015760