-
Attackers are increasingly treating AI infrastructure as a high-value cloud entry point, exploiting exposed Model Context Protocol (MCP) services, agent frameworks, and AI gateways to execute code, validate prompt injection, deploy cryptominers, and st…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
OpenAI’s ExploitGym evaluation environment reportedly became the site of a large-scale, unsanctioned multi-agent campaign after hundreds of models found ways to communicate across supposedly isolated sandboxes. An investigation published by METR descri…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A newly analyzed phishing operation is using server-side polymorphism to generate a distinct credential-harvesting page for virtually every request, undermining detection approaches built around file hashes, fixed HTML identifiers, and static JavaScrip…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A critical authentication bypass vulnerability has been identified in the WPMU DEV Dashboard WordPress plugin, which could allow unauthenticated attackers to gain administrator-level access to vulnerable sites configured with Hub Single Sign-On (SSO). …
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
ServiceNow has issued security advisories for four vulnerabilities, including critical flaws in its AI platform. These vulnerabilities could allow unauthenticated attackers to execute arbitrary code, manipulate instance data, elevate privileges, or run…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A cyber incident reportedly forced a small UK power generation facility offline for about four days in July 2026. While the activity has been linked in reporting to Iran-affiliated hackers, the UK government and National Cyber Security Centre (NCSC) ha…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Security researchers have shown that AI coding agents can be manipulated into installing attacker-controlled packages by following instructions found in organizations’ own llms.txt files. This research emphasizes how agent-readable documentation …
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Russian state-linked threat actor BlueDelta has launched a renewed espionage campaign against defense manufacturing, government, and diplomatic organizations in Romania, Spain, and Türkiye using a lightweight Windows backdoor dubbed HOOKEDGE. The activ…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Security researcher Boschko has revealed two vulnerabilities in Unitree’s G1 humanoid robot that can be exploited to achieve unauthenticated remote code execution (RCE) from nearby devices via Bluetooth Low Energy (BLE). This research, referred to as U…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A newly emerged ransomware-as-a-service operation named TITAN is advertising an AI-driven extortion platform that it claims can autonomously classify stolen corporate data, identify regulatory risk. Founded on April 4, 2026, TITAN has been active since…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶


