Claude Code Security and Magecart: Getting the Threat Model RightThe Hacker News·Mar 18, 11:58 UTC · Mar 18, 2026Data breach60
Week in review: AiTM phishing kit used to hijack AWS accounts, year-long malware campaign targets HRHelp Net Security·Mar 15, 00:00 UTC · Mar 15, 2026Malware in the wildCVE-2026-21262CVE-2026-2612760
Untrusted repositories turn Claude code into an attack vectorSecurity Affairs·Feb 25, 21:39 UTC · Feb 25, 2026VulnerabilityCVE-2025-59536CVE-2026-2185260
Anthropic to put AI in charge of reviewing Claude Code actions by defaultHelp Net Security·Aug 10, 00:00 UTC · Aug 10, 2026Vulnerability155
AI’s constant patching treadmill can be a security problemCyberScoop·Jun 17, 22:36 UTC · Jun 17, 2026Exploit / PoC in the wild60
ThreatsDay Bulletin: Hybrid P2P Botnet, 13-YearThe Hacker News·Apr 9, 16:23 UTC · Apr 9, 2026MalwareCVE-2024-32114CVE-2026-34197CVE-2022-41678160
Anthropic Disrupts AI-Powered Cyberattacks Automating Theft and Extortion Across Critical SectorsThe Hacker News·Aug 27, 16:41 UTC · Aug 27, 2025Ransomware60
Anthropic and OpenAI Security Tools Could Fuel CyberInfosecurity Magazine·Jul 10, 13:45 UTC · Jul 10, 2026Exploit / PoC60
Magento Developers Impersonated in Targeted GitHub Malware OperationSansec (Magento / e-commerce security)·Apr 14, 19:49 UTC · Apr 14, 2026Malware55
Anthropic rolls out embedded security scanning for ClaudeCyberScoop·Feb 20, 21:41 UTC · Feb 20, 2026Exploit / PoC in the wild60
Week in review: High severity WordPress vulnerabilities, fake OAuth IDs bypass sign-in logsHelp Net Security·Jul 19, 00:00 UTC · Jul 19, 2026Vulnerability in the wildCVE-2026-15409CVE-2026-15410CVE-2026-56155+2 CVEs60
Chinese Hackers Automate Cyber-Attacks With AIInfosecurity Magazine·Nov 14, 12:15 UTC · Nov 14, 2025Vulnerability55
Anthropic's Claude Mythos Finds Thousands of ZeroThe Hacker News·Apr 8, 11:44 UTC · Apr 8, 2026Exploit / PoC60
⚡ Weekly Recap: Axios Hack, Chrome 0-Day, Fortinet Exploits, Paragon Spyware and MoreThe Hacker News·Apr 6, 12:46 UTC · Apr 6, 2026Malware in the wildCVE-2026-5281CVE-2026-3502CVE-2026-35616+1 CVEs60
Multi-OS Cyberattacks: How SOCs Close a Critical Risk in 3 StepsThe Hacker News·Apr 7, 11:50 UTC · Apr 7, 2026Malware55
ThreatsDay: AI Compute Hijacking, Apple Email Flaw, BlueHammer Ransomware + 14 StoriesThe Hacker News·Jul 7, 04:32 UTC · Jul 7, 2026Ransomware60
How AI Assistants are Moving the Security GoalpostsKrebs on Security·Mar 9, 00:57 UTC · Mar 9, 2026Vulnerability55
Citrix launches MCP Gateway to secure enterprise AI agentsHelp Net Security·Jul 9, 00:00 UTC · Jul 9, 2026Exploit / PoC60
Chinese Hackers Use Anthropic's AI to Launch Automated Cyber Espionage CampaignThe Hacker News·Nov 15, 00:00 UTC · Nov 15, 2025Threat actor in the wild60
Week in review: Fortibleed campaign’s impact on orgs, Cisco Unified CM flaw exploitedHelp Net Security·Jun 28, 00:00 UTC · Jun 28, 2026Threat actor in the wildCVE-2026-2023060
Week in review: Accenture data breach, great open-source cybersecurity toolsHelp Net Security·Jul 12, 00:00 UTC · Jul 12, 2026Data breach in the wildCVE-2026-48282CVE-2026-55255CVE-2026-50656160
Week in review: Infostealer dropped via FortiClient EMS flaw, exploited Trend Micro Apex One flawHelp Net Security·May 31, 00:00 UTC · May 31, 2026Malware in the wildCVE-2026-45659CVE-2026-34926CVE-2026-3561660
SAP-Related npm Packages Compromised in CredentialThe Hacker News·Apr 30, 16:39 UTC · Apr 30, 2026Data breach60
ThreatsDay: Cloud Bucket Hijacking, Windows LPE Chain, Global Fraud Bust + 17 More StoriesThe Hacker News·Jul 9, 15:09 UTC · Jul 9, 2026Phishing & fraudCVE-2026-918160
More evidence your AI agents can be turned against youCyberScoop·Dec 5, 20:48 UTC · Dec 5, 2025Exploit / PoC in the wild60
Week in review: Axios npm supply chain compromise, critical FortiClient EMS bugs exploitedHelp Net Security·Apr 5, 00:00 UTC · Apr 5, 2026Exploit / PoC in the wildCVE-2026-35616CVE-2026-21643CVE-2026-20093+2 CVEs160
Week in review: Self-spreading npm malware hits developers, Cisco SD-WAN 0-day exploited since 2023Help Net Security·Mar 1, 00:00 UTC · Mar 1, 2026Malware in the wildCVE-2026-25108CVE-2026-20127160
⚡ Weekly Recap: SD-WAN 0-Day, Critical CVEs, Telegram Probe, Smart TV Proxy SDK and MoreThe Hacker News·Mar 2, 13:26 UTC · Mar 2, 2026Data breach in the wildCVE-2026-20127CVE-2025-40538CVE-2025-40539+27 CVEs60
Week in review: NIST updates DNS security guidance, compromised LiteLLM PyPI packagesHelp Net Security·Mar 29, 00:00 UTC · Mar 29, 2026Exploit / PoC in the wildCVE-2025-53521CVE-2026-21992CVE-2026-305560
Capsule Security debuts with $7 million funding to secure AI agent behaviorHelp Net Security·Apr 15, 00:00 UTC · Apr 15, 2026Exploit / PoCCVE-2026-2152060
Pwn2Own Berlin 2026, Day Three: DEVCORE Crowned Master of Pwn, $1.298 Million TotalSecurity Affairs·May 17, 00:41 UTC · May 17, 2026Vulnerability55
Daxin Resurfaces in Taiwan Alongside Stupig PreThe Hacker News·Jul 15, 00:00 UTC · Jul 15, 2026Malware55
Anthropic Rolls Out Claude Security for AI Vulnerability ScanningInfosecurity Magazine·May 1, 12:00 UTC · May 1, 2026Vulnerability55
Claude published malicious code to the Internet and attacked 3 real companiesArs Technica · Security·Jul 31, 20:39 UTC · Jul 31, 2026Data breach160
New research finds that Claude breaks bad if you teach it to cheatCyberScoop·Nov 24, 22:41 UTC · Nov 24, 2025Exploit / PoC in the wild60
The democratisation of business email compromise fraudCisco Talos·Apr 2, 18:02 UTC · Apr 2, 2026Phishing & fraud in the wildCVE-2025-5518260
Week in review: SimpleHelp vulnerability exploited, Oracle EBS Payments flaw under attackHelp Net Security·Jul 5, 00:00 UTC · Jul 5, 2026Vulnerability in the wildCVE-2026-12569CVE-2026-48558CVE-2026-4681760
Claude Security enters public beta with Opus 4.7 vulnerability scanning and patchingHelp Net Security·May 4, 00:00 UTC · May 4, 2026Vulnerability55
‘Mini Shai-Hulud’ malware compromises hundreds of open-source packages in sprawling supplyCyberScoop·May 12, 21:38 UTC · May 12, 2026Malware155