ThreatsDay: AI-Powered Hacking, 370 Chrome Flaws, SonicWall Attacks, DNS Hijacking + 22 More StoriesThe Hacker News·Jul 30, 15:25 UTC · Jul 30, 2026RansomwareCVE-2026-33017CVE-2026-21858CVE-2025-68613+5 CVEs60
Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI MemoryThe Hacker News·Jul 29, 15:39 UTC · Jul 29, 2026VulnerabilityCVE-2026-59726160
An AI agent can pass every safety check and still leak secretsHelp Net Security·Jul 29, 00:00 UTC · Jul 29, 2026Vulnerability142
GPT-Red beat human red teamers on a prompt injection testHelp Net Security·Jul 28, 12:10 UTC · Jul 28, 2026AI safety & security30
⚡ Weekly Recap: Rogue AI Agents, Check Point Exploit, Slopsquatting, ClickFix Lures and MoreThe Hacker News·Jul 28, 05:26 UTC · Jul 28, 2026Exploit / PoC in the wildCVE-2026-16232CVE-2025-66376CVE-2026-54121+52 CVEs60
Don’t swing at everythingCisco Talos·Jul 23, 18:00 UTC · Jul 23, 2026RansomwareCVE-2026-60137CVE-2026-6303060
GitHub Cuts Public Bug Bounty Payouts, Moves Top Rewards to VIP TierThe Hacker News·Jul 23, 04:14 UTC · Jul 23, 2026Vulnerability55
Small teams are the heaviest users of AI coding agentsHelp Net Security·Jul 22, 00:00 UTC · Jul 22, 2026Research130
Where’s the Trump administration line on AI regulation?CyberScoop·Jul 21, 18:34 UTC · Jul 21, 2026Policy & legal30
Researchers Build WordPress Exploit Using OpenAI's GPTInfosecurity Magazine·Jul 20, 14:00 UTC · Jul 20, 2026Exploit / PoC in the wildCVE-2026-63030CVE-2026-6013760
Week in review: High severity WordPress vulnerabilities, fake OAuth IDs bypass sign-in logsHelp Net Security·Jul 19, 00:00 UTC · Jul 19, 2026Vulnerability in the wildCVE-2026-15409CVE-2026-15410CVE-2026-56155+2 CVEs60
OpenAI and Anthropic are pulling in different directionsHelp Net Security·Jul 16, 03:52 UTC · Jul 16, 2026Policy & legal30
New Agent Data Injection Attack Can Make AI Agents Misclick or Run Attacker CommandsThe Hacker News·Jul 15, 00:00 UTC · Jul 15, 2026Exploit / PoCCVE-2025-32711150
Grok Build Uploaded Entire Git Repositories to xAI Storage, Not Just Files It ReadThe Hacker News·Jul 15, 00:00 UTC · Jul 15, 2026Advisory30
OpenAI’s GPT-Red Automates Prompt Injection Testing to Harden GPTThe Hacker News·Jul 15, 00:00 UTC · Jul 15, 2026AI safety & security30
Week in review: Accenture data breach, great open-source cybersecurity toolsHelp Net Security·Jul 12, 00:00 UTC · Jul 12, 2026Data breach in the wildCVE-2026-48282CVE-2026-55255CVE-2026-50656160
Malicious AI agent skills can slip past the scanners built to stop themHelp Net Security·Jul 9, 00:00 UTC · Jul 9, 2026Malware42
Public GitHub Issue Could Trick GitHub Agentic Workflows Into Leaking Private Repo DataThe Hacker News·Jul 7, 14:07 UTC · Jul 7, 2026Exploit / PoC145
Microsoft wants to keep your AI agents from going rogueHelp Net Security·Jul 7, 00:00 UTC · Jul 7, 2026AI tools & infra230
Researcher Explains Release of Undisclosed ZeroInfosecurity Magazine·Jul 2, 12:51 UTC · Jul 2, 2026Exploit / PoC in the wildCVE-2026-55200CVE-2026-58049CVE-2026-58050+10 CVEs160
Attackers Exploit SimpleHelp CVE-2026-48558 to Deploy TaskWeaver and Djinn StealerThe Hacker News·Jun 30, 11:18 UTC · Jun 30, 2026Vulnerability in the wildCVE-2026-48558260
Jamf enables AI Governance and shadow AI detection on MacHelp Net Security·Jun 30, 00:00 UTC · Jun 30, 2026AI policy30
Hottest cybersecurity open-source tools of the month: June 2026Help Net Security·Jun 30, 00:00 UTC · Jun 30, 2026Policy & legal30
SimpleHelp vulnerability exploited to deliver mighty Djinn Stealer (CVE-2026-48558)Help Net Security·Jun 30, 00:00 UTC · Jun 30, 2026Vulnerability in the wildCVE-2026-4855860
OpenAI Reveals GPT-5.6 Sol Cybersecurity Model, Restricts Early AccessInfosecurity Magazine·Jun 29, 15:00 UTC · Jun 29, 2026Vulnerability55
New infosec products of the month: June 2026Help Net Security·Jun 26, 00:00 UTC · Jun 26, 2026Policy & legal155
OpenAI Expands Daybreak With GPT-5.5-Cyber to Help Defenders Patch Security FlawsThe Hacker News·Jun 23, 05:25 UTC · Jun 23, 2026VulnerabilityCVE-2026-47729CVE-2026-4890CVE-2026-4891+3 CVEs35
OpenAI is locking down parts of ChatGPT to reduce data theft risksHelp Net Security·Jun 19, 11:20 UTC · Jun 19, 2026AI safety & security30
ThreatsDay Bulletin: Claude Chat Abuse, NastyC2 npm Packages, DeviceThe Hacker News·Jun 18, 15:29 UTC · Jun 18, 2026Exploit / PoCCVE-2026-2012760
AI’s constant patching treadmill can be a security problemCyberScoop·Jun 17, 22:36 UTC · Jun 17, 2026Exploit / PoC in the wild60
New “Agentjacking” Attacks Could Hijack AI Coding AgentsInfosecurity Magazine·Jun 11, 09:15 UTC · Jun 11, 2026Phishing & fraud55
New HTTP/2 Bomb Vulnerability Allows Remote DoS on NGINX, Apache, IIS, Envoy & CloudflareThe Hacker News·Jun 10, 14:36 UTC · Jun 10, 2026VulnerabilityCVE-2016-6581CVE-2025-53020CVE-2016-8740+3 CVEs35
A Record-Breaking Patch Tuesday for June 2026Krebs on Security·Jun 10, 01:28 UTC · Jun 10, 2026VulnerabilityCVE-2026-49160CVE-2026-45586CVE-2026-5050760
Hades PyPI Attack: 19 Packages Poisoned to AutoThe Hacker News·Jun 9, 10:34 UTC · Jun 9, 2026Malware142
IronWorm and New Miasma Worm Variant Hit npm in Supply Chain AttacksThe Hacker News·Jun 6, 06:23 UTC · Jun 6, 2026Data breach57
New infosec products of the week: June 5, 2026Help Net Security·Jun 5, 00:00 UTC · Jun 5, 2026Policy & legal155
Microsoft responds to security challenges facing code, AI agents, and modelsHelp Net Security·Jun 3, 00:00 UTC · Jun 3, 2026Vulnerability130
OpenAI requires stronger authentication for users of its most powerful AI modelsHelp Net Security·Jun 1, 00:00 UTC · Jun 1, 2026Vulnerability55
Depthfirst Adds Pre-Install Protection Against Malicious DependenciesHelp Net Security·Jun 1, 00:00 UTC · Jun 1, 2026Ransomware60