What the Hugging Face breach reveals about defense in the age of agentic AICyberScoop·Jul 31, 10:00 UTC · Jul 31, 2026Exploit / PoC160
JFrog Confirms OpenAI Models Exploited Artifactory ZeroThe Hacker News·Jul 30, 03:54 UTC · Jul 30, 2026Exploit / PoCCVE-2026-65617CVE-2026-65923CVE-2026-66018+1 CVEs60
Microsoft Launches Flurry of AI Security InitiativesInfosecurity Magazine·Jul 28, 12:45 UTC · Jul 28, 2026Vulnerability30
NVIDIA Forms 37-Member Open Secure AI Alliance and OpenThe Hacker News·Jul 27, 18:10 UTC · Jul 27, 2026Exploit / PoC60
Dysphoria IoT Botnet Adds Blockchain C2 and Victim Relays After JackSkid DisruptionThe Hacker News·Jul 27, 17:16 UTC · Jul 27, 2026MalwareCVE-2025-952835
OpenAI Says Its AI Models Escaped Sandbox, Targeted Hugging Face to Cheat BenchmarkThe Hacker News·Jul 22, 20:30 UTC · Jul 22, 2026Exploit / PoC60
White House accuses Chinese company of distilling Anthropic’s FableCyberScoop·Jul 22, 16:45 UTC · Jul 22, 2026Exploit / PoC in the wild60
WordPress wp2shell Exploitation Grows as Public Exploit Fuels Mass ScanningThe Hacker News·Jul 22, 15:41 UTC · Jul 22, 2026Exploit / PoC in the wildCVE-2026-63030CVE-2026-6013760
OpenAI says model test was behind Hugging Face hackCyberScoop·Jul 21, 22:39 UTC · Jul 21, 2026Exploit / PoC in the wild60
AI models keep getting caught cheatingCyberScoop·Jul 21, 19:20 UTC · Jul 21, 2026Exploit / PoC in the wild60
Two new high severity WordPress vulnerabilities, patch immediately!Help Net Security·Jul 21, 09:06 UTC · Jul 21, 2026Vulnerability in the wildCVE-2026-60137CVE-2026-63030160
Week in review: SimpleHelp vulnerability exploited, Oracle EBS Payments flaw under attackHelp Net Security·Jul 5, 00:00 UTC · Jul 5, 2026Vulnerability in the wildCVE-2026-12569CVE-2026-48558CVE-2026-4681760
Using Reddit to manipulate AI search results is surprisingly easyHelp Net Security·Jun 23, 00:00 UTC · Jun 23, 2026Research30
Fake CAPTCHA IRSF Scam and 120 Keitaro Campaigns Drive Global SMS, Crypto FraudThe Hacker News·Apr 30, 06:30 UTC · Apr 30, 2026Threat actor45
Critical Unpatched Telnetd Flaw (CVE-2026The Hacker News·Mar 20, 15:41 UTC · Mar 20, 2026Vulnerability in the wildCVE-2026-32746CVE-2026-24061CVE-2005-046960
Malicious npm Package Posing as OpenClaw Installer Deploys RAT, Steals macOS CredentialsThe Hacker News·Mar 10, 14:30 UTC · Mar 10, 2026Malware30
Malicious VSX Extension "SleepyDuck" Uses Ethereum to Keep Its Command Server AliveThe Hacker News·Nov 4, 04:23 UTC · Nov 4, 2025Malware30
European crypto platform SwissBorg to reimburse users after $41 million theftThe Record·Sep 10, 12:18 UTC · Sep 10, 2025Data breach45
Malicious npm Package Masquerades as Popular Email LibraryInfosecurity Magazine·Sep 2, 16:45 UTC · Sep 2, 2025Malware30
Malicious npm Package nodejs-smtp Mimics Nodemailer, Targets Atomic and Exodus WalletsThe Hacker News·Sep 2, 04:40 UTC · Sep 2, 2025Malware30
Clorox lawsuit says help-desk contractors handed over passwords in 2023 cyberattackThe Record·Jul 23, 13:22 UTC · Jul 23, 2025Policy & legal55
El ICE ya usa una nueva app de reconocimiento facial para identificar personas, revelan correos filtrados404 Media·Jul 22, 13:00 UTC · Jul 22, 2025Industry42
New MassJacker Malware Targets Piracy Users, Hijacking Cryptocurrency TransactionsThe Hacker News·Mar 15, 00:00 UTC · Mar 15, 2025Malware30
Mandiant's X Account Was Hacked Using BruteThe Hacker News·Jan 11, 13:55 UTC · Jan 11, 2024Data breach45
Mandiant X Account was hacked because not adequately protectedSecurity Affairs·Jan 11, 12:27 UTC · Jan 11, 2024Threat actor45
Mandiant’s X Account Was Hacked in BruteInfosecurity Magazine·Jan 11, 12:15 UTC · Jan 11, 2024Data breach45
University of Michigan warns that personal information was leaked during cyberattackThe Record·Oct 24, 18:08 UTC · Oct 24, 2023Ransomware57
Clorox takes servers offline, notifies law enforcement after ‘unauthorized activity’The Record·Aug 15, 19:59 UTC · Aug 15, 2023Ransomware57
HITB Lockdown: Hands-on technical trainings coming next week!Help Net Security·Mar 9, 20:05 UTC · Mar 9, 2023Malware30
Cryptocurrency platform Wormhole hacked for an estimated $322 millionThe Record·Jan 17, 00:00 UTC · Jan 17, 2023Vulnerability30
Nearly $9 million stolen from DeFi platform Crema FinanceThe Record·Jan 12, 00:00 UTC · Jan 12, 2023Vulnerability30
US Nuclear Security Administration criticized by watchdog over cybersecurity failuresThe Record·Jan 10, 00:00 UTC · Jan 10, 2023Ransomware57
Crypto trading platform Mango Markets drained of more than $100 million in flash loan attackThe Record·Jan 10, 00:00 UTC · Jan 10, 2023Vulnerability30
Friday Squid Blogging: Squid ImagesSchneier on Security·Sep 2, 21:32 UTC · Sep 2, 2022Policy & legal30
Multiple Backdoored Python Libraries Caught Stealing AWS Secrets and KeysThe Hacker News·Jun 27, 05:58 UTC · Jun 27, 2022Malware42
Multiple malicious packages in PyPI repository found stealing AWS secretsSecurity Affairs·Jun 25, 17:52 UTC · Jun 25, 2022Data breach45
Cloudflare's Project Pangea helps underserved communities expand access to the internet for freeHelp Net Security·Jul 28, 00:00 UTC · Jul 28, 2021Policy & legal30
LV ransomware operators repurposed a REvil binary to launch a new RaaSSecurity Affairs·Jun 23, 19:09 UTC · Jun 23, 2021Ransomware57