Critical mcp-remote Vulnerability Enables Remote Code Execution, Impacting 437,000+ DownloadsThe Hacker News·Jul 11, 04:05 UTC · Jul 11, 2025VulnerabilityCVE-2025-6514CVE-2025-49596CVE-2025-53110+1 CVEs60
Critical Vulnerability in Anthropic's MCP Exposes Developer Machines to Remote ExploitsThe Hacker News·Jul 4, 09:23 UTC · Jul 4, 2025VulnerabilityCVE-2025-4959660
Malicious AI Agent Server Reportedly Steals EmailsInfosecurity Magazine·Sep 25, 16:30 UTC · Sep 25, 2025Exploit / PoC60
Citrix launches MCP Gateway to secure enterprise AI agentsHelp Net Security·Jul 9, 00:00 UTC · Jul 9, 2026Exploit / PoC60
Security gap in Perplexity’s Comet browser exposed users to system-level attacksHelp Net Security·Apr 21, 12:59 UTC · Apr 21, 2026Ransomware60
Anthropic MCP Inspector: CVE-2025Recorded Future·Oct 14, 00:00 UTC · Oct 14, 2025Vulnerability in the wildCVE-2025-4959660
Anthropic MCP Design Vulnerability Enables RCE, Threatening AI Supply ChainThe Hacker News·Apr 22, 05:41 UTC · Apr 22, 2026VulnerabilityCVE-2025-65720CVE-2026-30623CVE-2026-30624+12 CVEs60
SmartLoader hackers clone Oura MCP project to spread StealC malwareSecurity Affairs·Feb 17, 18:54 UTC · Feb 17, 2026Malware55
Unisys unveils ClearPath MCP Software Series for Microsoft AzureHelp Net Security·Oct 1, 00:00 UTC · Oct 1, 2020Phishing & fraud55
Operant AI Endpoint Protector secures AI agents and MCP toolsHelp Net Security·May 4, 00:00 UTC · May 4, 2026Policy & legal55
Critical Nginx-ui MCP Flaw Actively Exploited in the WildInfosecurity Magazine·Apr 15, 13:00 UTC · Apr 15, 2026Exploit / PoC in the wildCVE-2026-3303260
Cursor AI Code Editor Vulnerability Enables RCE via Malicious MCP File Swaps Post ApprovalThe Hacker News·Aug 5, 13:04 UTC · Aug 5, 2025VulnerabilityCVE-2025-54136160
Veeam, Terraform MCP, Django Patch Critical Flaws, Led by CVSS 10.0 CrossThe Hacker News·Aug 5, 14:27 UTC · Aug 5, 2026Vulnerability in the wildCVE-2026-58073CVE-2026-58072CVE-2026-58067+10 CVEs60
Systemic Flaw in MCP Protocol Could Expose 150 Million DownloadsInfosecurity Magazine·Apr 16, 09:40 UTC · Apr 16, 2026Vulnerability55
Actively Exploited nginx-ui Flaw (CVE-2026-33032) Enables Full Nginx Server TakeoverThe Hacker News·Apr 15, 00:00 UTC · Apr 15, 2026Vulnerability in the wildCVE-2026-33032CVE-2026-27944CVE-2026-27825+1 CVEs60
AI Agents: The Next Wave Identity Dark MatterThe Hacker News·Mar 3, 11:30 UTC · Mar 3, 2026Policy & legal55
Docker Fixes Critical Ask Gordon AI Flaw Allowing Code Execution via Image MetadataThe Hacker News·Feb 3, 16:41 UTC · Feb 3, 2026Vulnerability155
⚡ Weekly Recap: AI Goes Rogue, Metabase 0-Day, MCP SupplyThe Hacker News·Aug 10, 15:03 UTC · Aug 10, 2026Ransomware in the wildCVE-2026-34348CVE-2026-18497CVE-2026-63508+43 CVEs160
ThreatsDay Bulletin: FortiGate RaaS, Citrix Exploits, MCP Abuse, LiveChat Phish & MoreThe Hacker News·Mar 19, 14:25 UTC · Mar 19, 2026Ransomware in the wildCVE-2024-55591CVE-2025-71257CVE-2025-71258+4 CVEs60
Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI MemoryThe Hacker News·Jul 29, 15:39 UTC · Jul 29, 2026VulnerabilityCVE-2026-59726160
New Zero-Click Flaw in Claude Extensions, Anthropic Declines FixInfosecurity Magazine·Feb 9, 17:30 UTC · Feb 9, 2026Vulnerability55
Tines rolls out a governance layer for agents, copilots, and MCPsHelp Net Security·Jan 15, 00:00 UTC · Jan 15, 2026Exploit / PoC60
How Pentera Turns AI Security Workflows into Validation EnginesThe Hacker News·Jul 15, 00:00 UTC · Jul 15, 2026Vulnerability55
Mimecast expands Incydr with runtime data security for AI and human riskHelp Net Security·Mar 24, 00:00 UTC · Mar 24, 2026Policy & legal55
Two Critical Flaws Uncovered in Wondershare RepairIt Exposing User Data and AI ModelsThe Hacker News·Sep 24, 13:55 UTC · Sep 24, 2025Exploit / PoCCVE-2025-10643CVE-2025-1064460
April 2026 CVE LandscapeRecorded Future·Jun 3, 00:00 UTC · Jun 3, 2026Ransomware in the wildCVE-2026-33032CVE-2026-39987CVE-2009-0238+30 CVEs60
Critical Flowise Flaw Gives Attackers Full Server ControlInfosecurity Magazine·Jun 1, 14:00 UTC · Jun 1, 2026Exploit / PoCCVE-2026-4093360
Microsoft Patch Tuesday for March 2026 — Snort rules and prominent vulnerabilitiesCisco Talos·Mar 10, 22:23 UTC · Mar 10, 2026VulnerabilityCVE-2026-26110CVE-2026-26113CVE-2026-26144+14 CVEs60
Cisco enhances security for enterprise AI adoptionHelp Net Security·Feb 11, 00:00 UTC · Feb 11, 2026Vulnerability55
Week in review: React, Node.js flaw patched, ransomware intrusion exposes espionage footholdHelp Net Security·Dec 7, 00:00 UTC · Dec 7, 2025RansomwareCVE-2025-48633CVE-2025-48572CVE-2025-5518260
Intel 471 expands Verity471 with AI agent and MCP support for threat intelligenceHelp Net Security·Jul 28, 00:00 UTC · Jul 28, 2026Industry55
New infosec products of the month: June 2026Help Net Security·Jun 26, 00:00 UTC · Jun 26, 2026Policy & legal155
New “Agentjacking” Attacks Could Hijack AI Coding AgentsInfosecurity Magazine·Jun 11, 09:15 UTC · Jun 11, 2026Phishing & fraud55
Week in review: cPanel vulnerability actively exploited, DigiCert breach, LinkedIn job scamsHelp Net Security·May 10, 00:00 UTC · May 10, 2026Vulnerability in the wildCVE-2026-41940CVE-2026-4670CVE-2026-5174+4 CVEs60
AIMap: Open-source tool finds and tests exposed AI endpointsHelp Net Security·May 6, 00:00 UTC · May 6, 2026Phishing & fraud55
XM Cyber advances AI security with enhanced exposure and attack path visibilityHelp Net Security·Mar 25, 09:46 UTC · Mar 25, 2026Vulnerability55
Microsoft Patches 84 Flaws in March Patch Tuesday, Including Two Public ZeroThe Hacker News·Mar 11, 09:15 UTC · Mar 11, 2026VulnerabilityCVE-2026-26127CVE-2026-21262CVE-2026-21536+3 CVEs60
DockerDash Exposes AI Supply Chain Weakness In Docker's Ask GordonInfosecurity Magazine·Feb 3, 15:15 UTC · Feb 3, 2026Vulnerability155
Researchers Find Serious AI Bugs Exposing Meta, Nvidia, and Microsoft Inference FrameworksThe Hacker News·Nov 15, 00:00 UTC · Nov 15, 2025VulnerabilityCVE-2024-50050CVE-2025-30165CVE-2025-23254+1 CVEs60