notice: please create a custom view template for the cybersec class view-cybersec.html
Claude Code and Gemini CLI Flaws Let a GitHub Issue Reach CI Workflow Secrets
A GitHub issue opened by an account with no repository privileges was enough to execute code on the CI runners behind Anthropic's and Google's own coding-agent repositories. On OpenAI's, it was enough to hijack the next agent run.
Novee Security ran the attack against each vendor's agent in the configuration that the vendor ships by default, and presented the work at Black Hat USA on August 5.
10:10 am, August 7, 2026
guid
https://thehackernews.com/2026/08/claude-code-and-gemini-cli-flaws-let.html
source_url
https://thehackernews.com/2026/08/claude-code-and-gemini-cli-flaws-let.html
id: 2441
uid: iS2Uy
insdate: 2026-08-07 10:10:12
title: Claude Code and Gemini CLI Flaws Let a GitHub Issue Reach CI Workflow Secrets
additional: A GitHub issue opened by an account with no repository privileges was enough to execute code on the CI runners behind Anthropic's and Google's own coding-agent repositories. On OpenAI's, it was enough to hijack the next agent run.
Novee Security ran the attack against each vendor's agent in the configuration that the vendor ships by default, and presented the work at Black Hat USA on August 5.
category: Cybersecurity
md5:
guid: https://thehackernews.com/2026/08/claude-code-and-gemini-cli-flaws-let.html
source_url: https://thehackernews.com/2026/08/claude-code-and-gemini-cli-flaws-let.html
updated:
image:
author_name:
author_link:
uid: iS2Uy
insdate: 2026-08-07 10:10:12
title: Claude Code and Gemini CLI Flaws Let a GitHub Issue Reach CI Workflow Secrets
additional: A GitHub issue opened by an account with no repository privileges was enough to execute code on the CI runners behind Anthropic's and Google's own coding-agent repositories. On OpenAI's, it was enough to hijack the next agent run.
Novee Security ran the attack against each vendor's agent in the configuration that the vendor ships by default, and presented the work at Black Hat USA on August 5.
category: Cybersecurity
md5:
guid: https://thehackernews.com/2026/08/claude-code-and-gemini-cli-flaws-let.html
source_url: https://thehackernews.com/2026/08/claude-code-and-gemini-cli-flaws-let.html
updated:
image:
author_name:
author_link:
Add Comment
AI Testing

Page Views
This page has been viewed 3 times.
Search cybersec
Category List cybersec
- Cybersecurity
- "City-Forum" data-theft attacks target Salesforce, ServiceNow portals
- "Comment stuffing" in an HTML phishing attachment as a mechanism for evading AI-based detection?, (Fri, Jul 10th)
- $13.74M Hack Shuts Down Sanctioned Grinex Exchange After Intelligence Claims
- $285 Million Drift Hack Traced to Six-Month DPRK Social Engineering Operation
- [GUEST DIARY] Tearing apart website fraud to see how it works., (Wed, May 13th)
- [Guest Diary] New Malware Libraries means New Signatures, (Fri, May 15th)
- [Guest Diary] Beyond Cryptojacking: Telegram tdata as a Credential Harvesting Vector, Lessons from a Honeypot Incident, (Wed, Apr 22nd)
- [Guest Diary] Compromised DVRs and Finding Them in the Wild, (Thu, Apr 16th)
- _HELP_ME_ESCAPE_FROM_BELARUS_PLEASE_ [Guest Diary], (Tue, Jul 7th)
- 'Ghostcommit' hides prompt injection in images to fool AI agents, steal secrets
- 'NoVoice' Android malware on Google Play infected 2.3 million devices
- /proxy/ URL scans with IP addresses, (Mon, Mar 16th)
- 108 Malicious Chrome Extensions Steal Google and Telegram Data, Affecting 20,000 Users
- 11 Old Microsoft-Signed Linux UEFI Shims Could Let Attackers Bypass Secure Boot
- 13-year-old bug in ActiveMQ lets hackers remotely execute commands
- 14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2
- 144 Mastra npm Packages Compromised via Hijacked Contributor Account
- 148 npm Packages Disguised as Student Proxies Turned Browsers Into a DDoS Botnet
- 149 Hacktivist DDoS Attacks Hit 110 Organizations in 16 Countries After Middle East Conflict
- 15-Year-Old GhostLock Flaw Enables Root and Container Escape on Most Linux Distros
- 15-year-old detained over French govt agency data breach
- 152 Chrome Wallpaper Extensions with 105K Installs Linked to Adware and Fake Traffic
- 16 Typosquatted RubyGems Packages Steal Browser Credentials and Crypto Wallets
- 16-Year-Old Linux KVM Flaw Lets Guest VMs Escape to Host on Intel and AMD x86 Systems
- 18 Malicious npm Packages Deliver Cross-Platform RAT to Alibaba Tool Users
- 18-Year-Old Linux SCTP Flaw Could Let Local Users Gain Root and Escape Containers
- 18-Year-Old NGINX Rewrite Module Flaw Enables Unauthenticated RCE
- 18-year-old NGINX vulnerability allows DoS, potential RCE
- 19 Chrome and Edge Extensions Found With Wallet-Stealing and Crypto-Draining Code
- 19-Year-Old Scattered Spider Suspect Extradited to Face U.S. Hacking Charges
- 20+ Hijacked Government Websites Became an Attack Channel
- 2026 Browser Data Reveals Major Enterprise Security Blind Spots
- 2026 Cybersecurity Assessment: The Gap Between Awareness and Resilience
- 2026: The Year of AI-Assisted Attacks
- 22 BRIDGE:BREAK Flaws Expose 20,000 Lantronix and Silex Serial-to-IP Converters
- 22 BRIDGE:BREAK Flaws Expose Thousands of Lantronix and Silex Serial-to-IP Converters
- 22 Seconds to Compromise: How Automated SSH Actors Move From Login to Persistence Before You Can Blink [Guest Diary], (Thu, Aug 6th)
- 236,000 DCloud Uni-App Sites Used in Crypto Scams, Phishing, and Wallet Drainers
- 23andMe to pay $18 million in new genetics data breach settlement
- 24 npm Packages Abuse unpkg Mirrors to Host Fake Cloudflare CAPTCHA Pages
- 24,650 Internet-Exposed BMCs Disclose IPMI Password Hashes Before Login
- 26 FakeWallet Apps Found on Apple App Store Targeting Crypto Seed Phrases
- 282 iOS AI Apps Leak API Keys and Open AI Proxy Access in Network Traffic Study
- 29-Year-Old Squid Proxy Bug 'Squidbleed' Can Leak Cleartext HTTP Requests
- 3 Reasons Attackers Are Using Your Trusted Tools Against You (And Why You Don’t See It Coming)
- 3 SOC Process Fixes That Unlock Tier 1 Productivity
- 3 SOC Steps that Shut Down Incident Risks Early
- 3 Ways AI Powers Service Desk Attacks and How to Prevent Them
- 30,000 Facebook Accounts Hacked via Google AppSheet Phishing Campaign
- 36 Malicious npm Packages Exploited Redis, PostgreSQL to Deploy Persistent Implants
- 40 Malicious Firefox Extensions Pose as Web3 Products to Steal Wallet Secrets
- 400+ Arch Linux AUR Packages Hijacked to Install Rust Credential Stealer
- 5 Learnings from the First-Ever Gartner Market Guide for Guardian Agents
- 5 Places where Mature SOCs Keep MTTR Fast and Others Waste Time
- 5 Steps to Managing Shadow AI Tools Without Slowing Down Employees
- 5 Ways Zero Trust Maximizes Identity Security
- 5 reasons Microsoft 365 backup isn’t enough for business data protection
- 54 EDR Killers Use BYOVD to Exploit 34 Signed Vulnerable Drivers and Disable Security
- 54 EDR Killers Use BYOVD to Exploit 35 Signed Vulnerable Drivers and Disable Security
- 6 Reasons Why Device Code Phishing is the Fastest-Growing Threat of 2026
- 68-year-old imprisoned after making $1.3 million by pirating IPTV services
- 7 Ways to Prevent Privilege Escalation via Password Resets
- 7-Eleven confirms data breach claimed by the ShinyHunters gang
- 7-Eleven data breach exposes personal information of 185,000 people
- 73 Seconds to Breach, 24 Hours to Patch: The Case for Autonomous Validation
- 73% of Organizations Say They Are Not Fully Ready for a Major Cyberattack
- 737 Chrome VPN Extensions Caught Routing Traffic Through Proxies. Check If You Have One
- 77 Open VSX extensions found harvesting developer info
- 9 Critical IP KVM Flaws Enable Unauthenticated Root Access Across Four Vendors
- 9-Year-Old Linux Kernel Flaw Enables Root Command Execution on Major Distros
- A .WAV With A Payload, (Tue, Apr 21st)
- A Glimpse into the “Search Your Target” Market for Stolen Credentials
- A Little Bit Pivoting: What Web Shells are Attackers Looking for?, (Tue, Apr 7th)
- A Malicious SIM Card Can Run Attacker Code Inside the Modems Behind Cellular IoT Devices
- A Malicious Webpage Could Poison Your Local AI Model Behind NVIDIA NemoClaw
- A React-based phishing page with credential exfiltration via EmailJS, (Fri, Mar 13th)
- A Record-Breaking Patch Tuesday for June 2026
- A polymorphic phishing page (that occasionally breaks itself), (Thu, Aug 27th)
- ACR Stealer Uses ClickFix Lures to Steal Browser Tokens and Microsoft 365 Files
- ADT confirms data breach after ShinyHunters leak threat
- AI "Mind Viruses" Can Spread Between Agents Through Persistent Prompt Files
- AI 'watermark removers' flood the web. Almost none can prove they work.
- AI Agent Exploits Langflow RCE to Automate Database Ransomware Attack
- AI Agent Uncovers 21 Zero-Days in FFmpeg; Chrome Patches Record 429 Bugs
- AI Agents Broke the Security Playbook. Here's What Replaces It.
- AI Agents: The Next Wave Identity Dark Matter - Powerful, Invisible, and Unmanaged
- AI Attacks Move in Minutes. Join This Webinar on Building a Defense That Keeps Up
- AI Broke Vulnerability Management. That's Why CISOs Are Moving Budget to BAS.
- AI Can Find Bugs, But Human Knowledge Still Proves Them
- AI Chatbot Recommendations Redirect Users to Cryptojacking Malware Sites
- AI Coding Agents Found Triggering Endpoint Security Rules Built to Catch Attackers
- AI Flaws in Amazon Bedrock, LangSmith, and SGLang Enable Data Exfiltration and RCE
- AI Is Accelerating Vulnerability Discovery. Can Defenders Keep Up?
- AI Phishing Is Crushing SOCs with Alert Volume: How to Reduce Tier 1 Overload
- AI Recommendation Poisoning: How "Ask AI" Buttons Silently Alter LLM Memory
- AI is Everywhere, But CISOs are Still Securing It with Yesterday's Skills and Tools, Study Finds
- AI-Assisted HTTP Terminator Finds Novel HTTP Desync Techniques and Apache Zero-Day
- AI-Driven Exploitation is Destroying Vulnerability Management. Here’s How to Handle It.
- AI-Driven Pushpaganda Scam Exploits Google Discover to Spread Scareware and Ad Fraud
- AI-Generated Browser Ransomware Abuses Chromium API on Windows and Android
- AI-Generated Exploit Scripts Target Siemens S7 PLCs in U.S. Critical Infrastructure
- AI-built ransomware toolkit automates EDR evasion, AD discovery
- AI-generated Slopoly malware used in Interlock ransomware attack
- APT28 Deploys PRISMEX Malware in Campaign Targeting Ukraine and NATO Allies
- APT28 Uses BEARDSHELL and COVENANT Malware to Spy on Ukrainian Military
- APT28 hackers deploy customized variant of Covenant open-source tool
- APT28-Linked Campaign Deploys BadPaw Loader and MeowMeow Backdoor in Ukraine
- APT28-Linked HOOKEDGE Backdoor Targets European Government and Diplomatic Organizations
- APT41-Linked Silver Dragon Targets Governments Using Cobalt Strike and Google Drive C2
- ARToken PhaaS exposes EvilTokens' Microsoft 365 phishing toolkit
- ATF confirms “major incident” after recent Qilin breach claims
- AWS Kiro Flaw Let a Poisoned Web Page Rewrite Its Config and Run Code
- AWS, Google, and Vercel Agent Flaws Let Attackers Trigger Tools Without Running the Model
- Abbott Laboratories probes two cyber incidents amid extortion claims
- Abbott probes two cyber incidents amid extortion claims
- Accenture confirms breach after hacker offers stolen data for sale
- Acer working to patch max severity zero-days in Wave 7 routers
- Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical Data
- Actively Exploited nginx-ui Flaw (CVE-2026-33032) Enables Full Nginx Server Takeover
- Actively exploited Apache ActiveMQ flaw impacts 6,400 servers
- Adding some Automation to the favicon.ico method of Host Recon, (Mon, Jun 29th)
- Adobe Acrobat Extension Flaw Let Malicious Sites Read WhatsApp Web Data
- Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction
- Adobe Chrome extension flaw let sites access private WhatsApp chats
- Adobe Patches 7 CVSS 10.0 Flaws in ColdFusion and Campaign Classic
- Adobe Patches Actively Exploited Acrobat Reader Flaw CVE-2026-34621
- Adobe Patches Three CVSS 10.0 ColdFusion and Campaign Classic Flaws
- Adobe Reader Zero-Day Exploited via Malicious PDFs Since December 2025
- Adobe patches seven max severity ColdFusion, Campaign flaws
- Adobe rolls out emergency fix for Acrobat, Reader zero-day flaw
- Adversarial Exposure Validation Turns Security Visibility into Confident Prioritization
- Adversaries Exploit Vacant Homes to Intercept Mail in Hybrid Cybercrime
- After Mythos: New Playbooks For a Zero-Window Era
- After the Break-In: What Attackers Do Once They're Already Inside
- Agent AI is Coming. Are You Ready?
- Agentic AI Has an Identity Problem and Attackers Know It
- Agentic AI Is Transforming Defense, But Only Secure IT Infrastructure Will Maximize It
- Agentic AI: The Weapon That No Longer Needs a Warrior
- Agentic GRC: Teams Get the Tech. The Mindset Shift Is What's Missing.
- Agentjacking Attack Tricks AI Coding Agents Into Running Malicious Code
- AirDrop and Quick Share Flaws Let Nearby Attackers Trigger Crashes and Bypass Checks
- AitM Phishing Targets TikTok Business Accounts Using Cloudflare Turnstile Evasion
- Ajax football club hack exposed fan data, enabled ticket hijack
- Akira hackers disable EDR with Safe Mode, steal data but fail to encrypt
- Alabama man pleads guilty to hacking, extorting hundreds of women
- Alleged Kimwolf Botmaster ‘Dort’ Arrested, Charged in U.S. and Canada
- Alleged Scattered Spider hacker extradited to the United States
- Alleged Silk Typhoon hacker extradited to US for cyberespionage
- Alleged TeamPCP Hackers Charged in Australia Over Major Supply Chain Attacks
- Amadey and StealC Malware Network Disrupted, 27M Stolen Credentials Recovered
- Amadey, StealC malware operations disrupted in Operation Endgame action
- Amazon Kiro Prompt Injection Can Exfiltrate Sensitive Data Through Kiro Powers
- Amazon Links Debug and Chalk npm Hijack to North Korea’s Sapphire Sleet
- Amazon Q Developer Flaw Could Let Malicious Repos Run Code via MCP Configs
- Amazon SES increasingly abused in phishing to evade detection
- Amazon fined $2.25M for withholding evidence from fraud victims
- Amazon links Debug, Chalk NPM supply-chain attacks to North Korean hackers
- Amazon: Drone strikes damaged AWS data centers in Middle East
- American utility firm Itron discloses breach of internal IT network
- Americans sentenced for running 'laptop farms' for North Korea
- Amgen says cloud data breach exposed patient health, proprietary info
- An AI SOC Evaluation Guide for Security Leaders
- An Adaptive Cyber Analytics UI for Web Honeypot Logs [Guest Diary], (Wed, May 6th)
- An Example of Stack String in High Level Language, (Sat, May 23rd)
- Analog Devices discloses data breach, says operations unaffected
- Analysis of 216M Security Findings Shows a 4x Increase In Critical Risk (2026 Report)
- Analysis of a Year of Files Uploaded to DShield Sensors, (Wed, May 27th)
- Analysis of one billion CISA KEV remediation records exposes limits of human-scale security
- Analyzing "Zombie Zip" Files (CVE-2026-0866), (Wed, Mar 11th)
- Android 17 Adds OS-Wide ECH to Hide Website Visits From Network Providers
- Android 17 Blocks Non-Accessibility Apps from Accessibility API to Prevent Malware Abuse
- Android 17 adds ECH support to make web browsing harder to track
- Android 17 to expand banking scam call and privacy protections
- Android Adds Intrusion Logging for Sophisticated Spyware Forensics
- Android Car Malware Spreads Through Built-In Updaters for Ad Fraud, Proxy Botnet
- Android Developer Verification Rollout Begins Ahead of September Enforcement
- Android Spyware Asin Targets Arabic Users via Fake News, PDF and War Map Apps
- Android gets patches for Qualcomm zero-day exploited in attacks
- Android malware combo takes out loans and relays victims' credit cards
- AnonyMousKIT PhaaS uses voice AI agents to phish iPhone passcodes
- Another Universal Linux Local Privilege Escalation (LPE) Vulnerability: Dirty Frag, (Fri, May 8th)
- Anthropic Finds 22 Firefox Vulnerabilities Using Claude Opus 4.6 AI Model
- Anthropic MCP Design Vulnerability Enables RCE, Threatening AI Supply Chain
- Anthropic Releases Claude Fable 5, Its Most Powerful AI Yet, With Cyber Safeguards
- Anthropic Restores Claude Fable 5 After U.S. Lifts Jailbreak-Linked Export Controls
- Anthropic Says Claude Mistook the Open Internet for a CTF and Breached Three Organizations
- Anthropic confirms Claude Mythos-class models will roll out to the public
- Anthropic confirms Claude is down in major outage affecting multiple services
- Anthropic confirms Claude is down worldwide
- Anthropic is testing desktop-like Claude Cowork for mobile
- Anthropic rolls out Claude Fable 5, but it's available for a limited time
- Anthropic rolls out Sonnet 5 with near-Opus 4.8 performance at a lower price
- Anthropic to restore Claude Fable access on Wednesday
- Anthropic's Claude Mythos Finds Thousands of Zero-Day Flaws Across Major Systems
- Anthropic's Claude breached 3 orgs, uploaded PyPI malware during tests
- Anthropic’s restricted Claude Mythos model may be coming to Claude Code
- Anti-DDoS Firm Heaped Attacks on Brazilian ISPs
- Anti-piracy coalition takes down AnimePlay app with 5 million users
- Anubis ransomware claims Coca-Cola Fairlife attack, threatens data leak
- Apache ActiveMQ CVE-2026-34197 Added to CISA KEV Amid Active Exploitation
- Apple Expands iOS 18.7.7 Update to More Devices to Block DarkSword Exploit
- Apple Fixes Hide My Email Bug That Exposed Real Addresses in Mail Logs
- Apple Fixes WebKit Vulnerability Enabling Same-Origin Policy Bypass on iOS and macOS
- Apple Fixes iOS Flaw That Let FBI Recover Deleted Signal Messages
- Apple Issues Security Updates for Older iOS Devices Targeted by Coruna WebKit Exploit
- Apple Patches (almost) everything again. March 2026 edition., (Wed, Mar 25th)
- Apple Patches 30+ iOS, macOS, Safari Flaws, Including AI-Discovered WebKit Bugs
- Apple Patches Beats Studio Buds Flaw Letting Nearby Attackers Spy via Microphone
- Apple Patches Everything (July 2026), (Wed, Jul 29th)
- Apple Patches Everything, (Mon, May 11th)
- Apple Patches Exploited Notification Flaw, (Thu, Apr 23rd)
- Apple Patches iOS Flaw That Stored Deleted Signal Notifications in FBI Forensic Case
- Apple Patches iOS and macOS, (Mon, Aug 17th)
- Apple Screen Sharing Security, (Mon, Aug 17th)
- Apple Sends Lock Screen Alerts to Outdated iPhones Over Active Web-Based Exploits
- Apple Warns Older iPhones Vulnerable to Coruna, DarkSword Exploit Kit Attacks
- Apple account change alerts abused to send phishing emails
- Apple adds macOS Terminal warning to block ClickFix attacks
- Apple blocked over $11 billion in App Store fraud in 6 years
- Apple expands iOS 18 updates to more iPhones to block DarkSword attacks
- Apple fixes Beats Studio Buds flaw that let hackers spy on conversations
- Apple fixes bug that let the FBI recover deleted Signal messages
- Apple fixes iOS bug that retained deleted notification data
- Apple iCloud Private Relay Can Expose Real IPs Through WebKit Proxy Bypasses
- Apple patches older iPhones and iPads against Coruna exploits
- Apple pushes first Background Security Improvements update to fix WebKit flaw
- Apple sends new ‘Threat Notification’ alerts over mercenary spyware attacks
- Apple sued over fake App Store crypto wallet app stealing $1.8M in Bitcoin
- Application Control Bypass for Data Exfiltration, (Tue, Mar 31st)
- AppsFlyer Web SDK hijacked to spread crypto-stealing JavaScript code
- April KB5083769 Windows 11 update causes backup software failures
- April Patch Tuesday Fixes Critical Flaws Across SAP, Adobe, Microsoft, Fortinet, and More
- Arch Linux disables AUR package adoption to stop malware flood
- Arista patches VeloCloud Orchestrator zero-day exploited in attacks
- Armenia Detains Russian Tourist on U.S. Warrant for REvil Hacker, Lawyers Say Wrong Man
- Armored Likho Targets Government Agencies, Power Sector with BusySnake Stealer
- AryStinger Malware Infects 4,300 Legacy Routers to Build Reconnaissance Proxy Network
- AryStinger botnet infected thousands of D-Link routers worldwide
- AssuranceAmerica data breach exposes records of 6.9 million drivers
- AsyncAPI npm packages infected with credential-stealing malware
- Atlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to Attackers
- Atomic MacOS (AMOS) stealer infection, (Sun, Aug 2nd)
- Attacker Uses Suspected AI-Generated PowerShell Script to Map Active Directory
- Attackers Chain Two PaperCut Flaws to Execute Code Without Authentication
- Attackers Compile khunt Inside Oracle to Turn SQL Injection Into Windows SYSTEM Access
- Attackers Don't Just Send Phishing Emails. They Weaponize Your SOC's Workload
- Attackers Exploit 'Ill Bloom' Vulnerability to Drain $3.1 Million From Cryptocurrency Wallets
- Attackers Exploit 'Ill Bloom' Vulnerability to Drain Over $5 Million From Cryptocurrency Wallets
- Attackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw
- Attackers Exploit MLflow SSRF Flaw to Steal Cloud Credentials and Secrets
- Attackers Exploit SharePoint Authentication Bypass After Public PoC Release
- Attackers Exploit SimpleHelp CVE-2026-48558 to Deploy TaskWeaver and Djinn Stealer
- Attackers Exploit Three Fortinet FortiSandbox Flaws, One Patched Last Week
- Attackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote Access
- Attackers Exploit Zimbra SNMP Flaw for Unauthenticated Remote Code Execution
- Attackers Target miniOrange SAML Flaws That Can Grant WordPress Admin Access
- Attackers Use LLM Agent for Post-Exploitation After Marimo CVE-2026-39987 Exploit
- Attackers Weaponize GitHub Actions Runners to Target cPanel and WHM Servers
- Attempts to Exploit Exposed "Vite" Installs (CVE-2025-30208), (Thu, Apr 2nd)
- Aura confirms data breach exposing 900,000 marketing contacts
- Australia arrests alleged TeamPCP hackers behind supply-chain attacks
- Australia warns of ClickFix attacks pushing Vidar Stealer malware
- Australia warns of global campaign targeting vulnerable CMS platforms
- Australian energy provider Origin says data breach exposes client data
- Authorities Disrupt SocksEscort Proxy Botnet Exploiting 369,000 IPs Across 163 Countries
- Authorities dismantle 'AudiA6' ransomware crypto-laundering service
- Authorities disrupt router DNS hijacks used to steal Microsoft 365 logins
- AutoIT Payload Injector , (Tue, Jul 28th)
- AutoJack Attack Lets One Web Page Hijack AI Agent for Host Code Execution
- Autonomous AI Tool Finds 2-Year-Old RCE Flaw in Redis (CVE-2026-23479)
- Avada Builder WordPress plugin flaws allow site credential theft
- Axios Supply Chain Attack Pushes Cross-Platform RAT via Compromised npm Account
- Axios npm hack used fake Teams error fix to hijack maintainer account
- Azerbaijani Energy Firm Hit by Repeated Microsoft Exchange Exploitation
- Azure CLI Password Spray Hits at Least 78 Microsoft Accounts in 81M+ Attempts
- Azure Cosmos DB Flaw Exposed Platform-Wide Key That Could Access Any Database
- BKA Identifies REvil Leaders Behind 130 German Ransomware Attacks
- BTMOB Android malware service generates custom phishing payloads
- Backdoored PyTorch Lightning package drops credential stealer
- Backdoored Smart Slider 3 Pro Update Distributed via Compromised Nextend Servers
- Backdoored Telnyx PyPI package pushes malware hidden in WAV audio
- BdThemes Supply Chain Attack Poisons JSON to Create Rogue WordPress Admins
- BdThemes plugins supply-chain hack creates rogue WordPress admins
- Bearlyfy Hits 70+ Russian Firms with Custom GenieLocker Ransomware
- Bearlyfy Hits Russian Firms with Custom GenieLocker Ransomware
- Betterleaks, a new open-source secrets scanner to replace Gitleaks
- Beyond the Zero-Day: See Your Network Like an Attacker | Webinar with HD Moore
- BeyondTrust Patches Critical Auth Bypass Flaws in Remote Support and PRA
- BeyondTrust warns of critical flaws in remote access software
- Bing AI promoted fake OpenClaw GitHub repo pushing info-stealing malware
- Bing Images Flaws Let Crafted SVGs Run Commands as SYSTEM on Microsoft's Servers
- Bitrefill blames North Korean Lazarus group for cyberattack
- Bitter-Linked Hack-for-Hire Campaign Targets Journalists Across MENA Region
- Bitwarden CLI Compromised in Ongoing Checkmarx Supply Chain Campaign
- Bitwarden CLI npm package compromised to steal developer credentials
- Bitwarden adds support for passkey login on Windows 11
- Blackfield ransomware asks Nidec Corporation for $2 million ransom
- Block the Prompt, Not the Work: The End of "Doctor No"
- BlueNoroff Zoom Phishing Kit Profiles Crypto Wallets Before Malware Delivery
- Bluekit phishing kit adopts browser-in-the-middle for login theft
- Boston Scientific says cyberattack disrupted operations globally
- Botnet Hunting for Vulnerabilities in Diagnostic Tools, (Tue, Aug 4th)
- Brave Software releases Origin for a paid, bloat-free browsing experience
- Brazilian LofyGang Resurfaces After Three Years With Minecraft LofyStealer Campaign
- Breach at the Beach: Play the Ultimate Entra ID CTF
- Bridging the AI Agent Authority Gap: Continuous Observability as the Decision Engine
- British Scattered Spider hacker pleads guilty to crypto theft charges
- Broken VECT 2.0 ransomware acts as a data wiper for large files
- Browser Extensions Are the New AI Consumption Channel That No One Is Talking About
- Bruteforce Scans for CrushFTP , (Tue, Mar 3rd)
- Bubble AI app builder abused to steal Microsoft account credentials
- Building a High-Impact Tier 1: The 3 Steps CISOs Must Follow
- C0XMO botnet spreads via DD-WRT router flaw, kills rival malware
- CDN Tsunami Attack Abuses HTTP/3 Translation for Up to 350x DoS Amplification
- CERT-EU: European Commission hack exposes data of 30 EU entities
- CERT-In Mandates 12-Hour Patching for Internet-Facing Flaws Amid AI-Assisted Attacks
- CERT-In Recommends 12-Hour Patching for Internet-Facing Flaws Amid AI-Assisted Attacks
- CERT-UA Impersonation Campaign Spread AGEWHEEZE Malware to 1 Million Emails
- CERT/CC Warns of Hidden Admin Backdoor in Tenda Router Firmware
- CISA Adds 4 Actively Exploited Adobe, Joomla, and Langflow Flaws to KEV
- CISA Adds 4 Exploited Flaws to KEV, Sets May 2026 Federal Deadline
- CISA Adds 6 Known Exploited Flaws in Fortinet, Microsoft, and Adobe Software
- CISA Adds 8 Exploited Flaws to KEV, Sets April-May 2026 Federal Deadlines
- CISA Adds Actively Exploited ConnectWise and Windows Flaws to KEV
- CISA Adds Actively Exploited Linux Root Access Bug CVE-2026-31431 to KEV
- CISA Adds Actively Exploited SolarWinds Serv-U DoS Flaw to KEV Catalog
- CISA Adds Actively Exploited VMware Aria Operations Flaw CVE-2026-22719 to KEV Catalog
- CISA Adds CVE-2025-53521 to KEV After Active F5 BIG-IP APM Exploitation
- CISA Adds Cisco SD-WAN CVE-2026-20182 to KEV After Admin Access Exploits
- CISA Adds Cisco, Chrome, and Arista Flaws to KEV Catalog Amid Active Exploitation
- CISA Adds Exploited Langflow and Trend Micro Apex One Vulnerabilities to KEV
- CISA Adds Exploited Magento RCE Flaw CVE-2026-45247 to KEV Catalog
- CISA Adds Exploited N-able N-central Flaw to KEV After Customer Compromises
- CISA Adds Exploited PTC Windchill RCE Flaw to KEV as Web Shell Attacks Continue
- CISA Adds Exploited SharePoint RCE Zero-Day CVE-2026-58644 to KEV
- CISA Adds Six Exploited Flaws to KEV, Including NetScaler, Linux, and SQL Server Bugs
- CISA Admin Leaked AWS GovCloud Keys on Github
- CISA Flags Actively Exploited Ray Flaw That Can Trigger Browser-Based RCE
- CISA Flags Actively Exploited Wing FTP Vulnerability Leaking Server Paths
- CISA Flags Actively Exploited n8n RCE Bug as 24,700 Instances Remain Exposed
- CISA Flags Apple, Craft CMS, Laravel Bugs in KEV, Orders Patching by April 3, 2026
- CISA Flags Langflow RCE, Tomcat, and N-central Flaws as Actively Exploited
- CISA Flags LiteSpeed cPanel Plugin Flaw Exploited for Root Privilege Escalation
- CISA Flags SolarWinds, Ivanti, and Workspace One Vulnerabilities as Actively Exploited
- CISA Flags TeamCity CVE-2026-63077 RCE Flaw Under Active Exploitation in the Wild
- CISA Red Team Compromised Two Critical Infrastructure Orgs, One Detected Nothing
- CISA Warns Critical Lantronix EDS5000 Flaw Is Being Actively Exploited
- CISA Warns Fortinet Customers as FortiBleed Hits 86,644 FortiGate Devices
- CISA Warns of Actively Exploited Joomla JCE Flaw Allowing PHP Code Execution
- CISA Warns of Zimbra, SharePoint Flaw Exploits; Cisco Zero-Day Hit in Ransomware Attacks
- CISA flags Apache ActiveMQ flaw as actively exploited in attacks
- CISA flags VMware Aria Operations RCE flaw as exploited in attacks
- CISA flags Windows Task Host vulnerability as exploited in attacks
- CISA flags Wing FTP Server flaw as actively exploited in attacks
- CISA flags new SD-WAN flaw as actively exploited in attacks
- CISA flags two-year-old Oracle flaw as actively exploited in attacks
- CISA gives feds 3 days to patch Check Point VPN bug exploited as zero-day
- CISA gives feds 4 days to patch actively exploited cPanel plugin flaw
- CISA gives feds four days to patch Ivanti flaw exploited as zero-day
- CISA orders feds to patch BlueHammer flaw exploited as zero-day
- CISA orders feds to patch Citrix NetScaler RCE flaw by Saturday
- CISA orders feds to patch DarkSword iOS flaws exploited attacks
- CISA orders feds to patch Fortinet flaw exploited in attacks by Friday
- CISA orders feds to patch Windows flaw exploited as zero-day
- CISA orders feds to patch Zimbra XSS flaw exploited in attacks
- CISA orders feds to patch actively exploited Citrix flaw by Thursday
- CISA orders feds to patch actively exploited Drupal vulnerability
- CISA orders feds to patch actively exploited Ivanti flaw by Sunday
- CISA orders feds to patch actively exploited Oracle flaw by Saturday
- CISA orders feds to patch actively exploited TrueConf Server flaws
- CISA orders feds to patch exploited Fortinet EMS flaw by Friday
- CISA orders feds to patch exploited Ivanti EPMM flaw by Sunday
- CISA orders feds to patch max severity ColdFusion flaw by Friday
- CISA orders feds to patch max severity Joomla plugin flaw by Friday
- CISA orders feds to patch max-severity Cisco flaw by Sunday
- CISA orders feds to patch n8n RCE flaw exploited in attacks
- CISA orders feds to prioritize patching Langflow auth bypass flaw
- CISA orders urgent action on actively exploited Langflow RCE flaw
- CISA orders urgent patching of actively exploited Zimbra flaw
- CISA says ‘Copy Fail’ flaw now exploited to root Linux systems
- CISA sets urgent deadline to fix Cisco flaw exploited in attacks
- CISA shares advice on isolating vital systems during cyberattacks
- CISA tells govt agencies to patch critical exploited flaws in 3 days
- CISA urges US orgs to secure Microsoft Intune systems after Stryker breach
- CISA urges immediate action on actively exploited Fortinet flaws
- CISA warns Fortinet users to secure devices after FortiBleed leak
- CISA warns admins to patch actively exploited SharePoint flaws
- CISA warns feds to patch iOS flaws exploited in crypto-theft attacks
- CISA warns of Apple flaws exploited in spyware, crypto-theft attacks
- CISA warns of active attacks exploiting Android, Linux bugs
- CISA warns of actively exploited RCE flaws in Joomla extensions
- CISA warns of another cPanel plugin flaw exploited in attacks
- CISA warns of cyberattacks disrupting U.S. water utilities
- CISA warns of cyberattacks targeting fuel tank monitoring systems
- CISA warns of hackers exploiting Langflow, N-central, Apache Tomcat flaws
- CISA warns of hackers exploiting critical MLflow vulnerability
- CISA warns of max severity Ubiquiti flaws exploited in attacks
- CISA: Hackers now exploit SolarWinds Serv-U flaw to crash servers
- CISA: Medusa ransomware hit over 500 critical infrastructure orgs
- CISA: Microsoft SharePoint RCE flaw now actively exploited
- CISA: Microsoft SharePoint flaw now exploited in ransomware attacks
- CISA: New Langflow flaw actively exploited to hijack AI workflows
- CISA: Recently patched Ivanti EPM flaw now actively exploited
- CISA: SonicWall SMA1000 flaws now exploited by ransomware gangs
- CISA: Splunk Enterprise flaw actively exploited, patch by Sunday
- CISA: Windows BlueHammer flaw now exploited by ransomware gangs
- CISA: Windows Task Host flaw now exploited by ransomware gangs
- COLDCARD security audit phishing attack installs remote access tool
- COLDCARD wallet RNG flaw likely linked to $88 million Bitcoin theft
- CPUID Breach Distributes STX RAT via Trojanized CPU-Z and HWMonitor Downloads
- CPUID hacked to deliver malware via CPU-Z, HWMonitor downloads
- CTM360 Research Reveals How Insurance Phishing Has Evolved Into Real-Time Account Hijacking
- CVE-2024-40766: The Patch Fixed the Bug. Nobody Fixed the Configuration., (Tue, Jun 23rd)
- California AG sues 23andMe over 2023 breach exposing health data
- Can the Security Platform Finally Deliver for the Mid-Market?
- Can you enforce strong Active Directory password rules without frustrating users?
- Canada arrests three for operating “SMS blaster” device in Toronto
- Canada’s Spy Agency Used First-of-Its-Kind Warrant to Clean Botnet-Infected Devices
- Canadian Man Pleads Guilty in Snowflake Extortions
- Canadian pleads guilty to Snowflake cloud data-theft attacks
- Canadian retail giant Loblaw notifies customers of data breach
- Canvas Breach Disrupts Schools & Colleges Nationwide
- Canvas login portals hacked in mass ShinyHunters extortion campaign
- Captive Portal Detection, (Tue, Jul 21st)
- Carhartt data breach exposes information of 12.9 million accounts
- Carnival Cruise confirms data breach affecting nearly 6 million people
- Casbaneiro Phishing Targets Latin America and Europe Using Dynamic PDF Lures
- Cavern C2 Uses DNS and Google Apps Script to Blend Into Legitimate Traffic
- Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller
- Certighost and the Privilege Hiding in Your Certificate Authority
- Chaos Ransomware Uses msaRAT to Route C2 Traffic Through Headless Chrome and Edge
- Charter Communications data breach affects 4.9 million accounts
- Charter confirms data breach after ShinyHunters extortion threat
- ChatGPT AgentForger Flaw Could Deploy Rogue Workspace Agents via a Phishing Link
- ChatGPT rolls out new $100 Pro subscription to challenge Claude
- ChatGPT share links abused to host fake outage pages to deliver malware
- ChatGPhish Vulnerability Turns ChatGPT Web Summaries Into a Phishing Surface
- Cheap Android TV Boxes Pose as Phones and Turn Owners’ Broadband Into Proxies
- Check Point Patches Exploited SmartConsole Flaw Allowing Full Admin Access
- Check Point links VPN zero-day attacks to Qilin ransomware gang
- Check Point warns of SmartConsole zero-day exploited in attacks
- Checkmarx Confirms GitHub Repository Data Posted on Dark Web After March 23 Attack
- Checkmarx confirms LAPSUS$ hackers leaked its stolen GitHub data
- Chick-fil-A data breach affects more than 13,000 customers
- Chick-fil-A discloses data breach after credential stuffing attacks
- China's Apple App Store infiltrated by crypto-stealing wallet apps
- China-Aligned Groups Ramp Up Attacks: Dragon Weave Hits Czech Republic & Taiwan
- China-Linked GopherWhisper Infects 12 Mongolian Government Systems with Go Backdoors
- China-Linked Hackers Backdoored Linux Login Software to Hide for Nearly a Decade
- China-Linked Hackers Deploy New StormEncryptor Ransomware, Likely via N-central Flaw
- China-Linked Hackers Target Asian Governments, NATO State, Journalists, and Activists
- China-Linked Hackers Use TernDoor, PeerTime, BruteEntry in South American Telecom Attacks
- China-Linked JDY Botnet Expands to 1,500+ Devices for Cyber Reconnaissance
- China-Linked Red Menshen Uses Stealthy BPFDoor Implants to Spy via Telecom Networks
- China-Linked SprySOCKS Backdoor Expands to Windows with Driver-Based Stealth
- China-Linked Storm-1175 Exploits Zero-Days to Rapidly Deploy Medusa Ransomware
- China-Linked TA416 Targets European Governments with PlugX and OAuth-Based Phishing
- China-Linked TA4922 Expands Phishing Attacks to U.K., Germany, Italy, and South Africa
- China-Linked TA4922 Expands Phishing Attacks to UK, Germany, Italy, and South Africa
- China-Linked UAT-7810 Expands ORB Network With New LONGLEASH Malware
- China-Linked UAT-8302 Targets Governments Using Shared APT Malware Across Regions
- China-Made ZBT Routers Ship With Two Implants Giving Unauthenticated Attackers Root Access
- China-Nexus JadeProx Uses New TriBack Loader in Government and Healthcare Attacks
- China-linked JDY botnet expands targeting of U.S. military networks
- Chinese APT deploys new malware to keep access to hacked networks
- Chinese Hacker Commands DeepSeek via Telegram to Launch Autonomous Attacks
- Chinese Hackers Abused Google Workspace Rules to Steal Research and Defense Emails
- Chinese Hackers Target Southeast Asian Militaries with AppleChris and MemFun Malware
- Chinese Silk Typhoon Hacker Extradited to U.S. Over COVID Research Cyberattacks
- Chinese Threat Actor Uses Leaked DarkSword Kit to Deploy GHOSTBLADE on iOS
- Chinese hackers breach REDCap servers, steal medical research
- Chinese hackers develop LONGLEASH malware to expand ORB network
- Chinese hackers hijack auth flow, spy on isolated network for a decade
- Chinese hackers target telcos with new Linux, Windows malware
- Chinese hackers use new Atlas RAT malware in European cyberattacks
- Chinese state hackers target telcos with new malware toolkit
- Chinese-Made Zbtlink Routers Ship With Backdoor That Opens Unauthenticated Root Shells
- Chinese-Speaking APT Deploys New TinyRCT Backdoor in Southeast Asia Campaign
- ChocoPoc malware delivered via trojanized exploits on GitHub
- Chrome Ad Blocker with 10M+ Installs Found with Dormant Script Injection Capability
- Chrome Extension Turns Malicious After Ownership Transfer, Enabling Code Injection and Data Theft
- Chrome V8 Zero-Day CVE-2026-11645 Exploited in the Wild - Patch Now
- Cisco ASA and FTD Flaw Exploited in the Wild Can Trigger Remote DoS
- Cisco Catalyst SD-WAN Controller Auth Bypass Actively Exploited to Gain Admin Access
- Cisco Catalyst SD-WAN Manager CVE-2026-20245 Flaw Actively Exploited – No Patch Available
- Cisco Catalyst SD-WAN Zero-Day CVE-2026-20245 Exploited to Gain Root Access
- Cisco Confirms Active Exploitation of Two Catalyst SD-WAN Manager Vulnerabilities
- Cisco FMC Zero-Day Actively Exploited, Static Credentials Could Expose Sensitive Data
- Cisco Patches 12 SD-WAN and IOS XE Flaws, Including Three 9.8 CVSS Score Bugs
- Cisco Patches 12 SD-WAN and IOS XE Flaws, Including Three 9.9 CVSS Score Bugs
- Cisco Patches 9.8 CVSS IMC and SSM Flaws Allowing Remote System Compromise
- Cisco Patches CVE-2026-20230 in Unified CM as Exploit Code Goes Public
- Cisco Patches CVSS 10.0 Secure Workload REST API Flaw Enabling Data Access
- Cisco Patches Four Critical Identity Services, Webex Flaws Enabling Code Execution
- Cisco Patches Nine Crosswork and Secure Workload Flaws, Five Scoring CVSS 10.0
- Cisco Releases Security Updates for Actively Exploited SD-WAN Manager Flaw
- Cisco Unified CM Flaw Exploited After PoC Reveals File-Write Path to Root
- Cisco Unified CM flaw CVE-2026-20230 now exploited in attacks
- Cisco finally confirms attackers exploiting Unified CM flaw
- Cisco fixes SD-WAN vManage flaw exploited in zero-day attacks
- Cisco flags more SD-WAN flaws as actively exploited in attacks
- Cisco says critical Webex Services flaw requires customer action
- Cisco source code stolen in Trivy-linked dev environment breach
- Cisco warns of ASA and FTD VPN flaw exploited to crash devices
- Cisco warns of FMC static credential flaw exploited in zero-day attacks
- Cisco warns of critical Unified CM flaw with PoC exploit code
- Cisco warns of high-severity ClamAV flaws with public exploits
- Cisco warns of max severity Secure FMC flaws giving root access
- Cisco warns of new critical SD-WAN flaw exploited in zero-day attacks
- Cisco warns of unpatched SD-WAN zero-day exploited in attacks
- Citizen Lab: Law Enforcement Used Webloc to Track 500 Million Devices via Ad Data
- Citrix NetScaler Under Active Recon for CVE-2026-3055 (CVSS 9.3) Memory Overread Bug
- Citrix Patches Six NetScaler Flaws Allowing File Read and Denial-of-Service
- Citrix Urges Patching Critical NetScaler Flaw Allowing Unauthenticated Data Leaks
- Citrix urges admins to patch NetScaler flaws as soon as possible
- Citrix urges admins to patch new NetScaler flaws as soon as possible
- Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE
- Claude AI Just Cracked a Post-Quantum Test Scheme and Found a Faster 7-Round AES Attack
- Claude AI finds Vim, Emacs RCE bugs that trigger on file open
- Claude Chrome extension flaw lets malicious extensions trigger AI actions
- Claude Code GitHub Action Flaw Let One Malicious Issue Hijack Repositories
- Claude Code Security and Magecart: Getting the Threat Model Right
- Claude Code Source Leaked via npm Packaging Error, Anthropic Confirms
- Claude Code and Gemini CLI Flaws Let a GitHub Issue Reach CI Workflow Secrets
- Claude Code leak used to push infostealer malware on GitHub
- Claude Code source code accidentally leaked in NPM package
- Claude Cowork Flaw Could Let AI Agent Escape Its VM and Access Mac Files
- Claude Extension Flaw Enabled Zero-Click XSS Prompt Injection via Any Website
- Claude Fable 5 isn’t permanently leaving subscriptions, Anthropic says
- Claude Fable 5 stays free for paid users until July 19 as Anthropic buys more time
- Claude Fable relaunch disappoints users with nerfed performance
- Claude Mythos 5 Tried to Backdoor a Real Open-Source Project in Testing, Then Vouched for Itself
- Claude Mythos AI Finds 10,000 High-Severity Flaws in Widely Used Software
- Claude Opus 4.6 Bypasses Gym Booking Limit, Cancels Other Users' Reservations in Tests
- Clean GitHub repo tricks AI coding agents into running malware
- Cleartext Passwords in MS Edge? In 2026?, (Mon, May 4th)
- ClickFix Attacks Deliver macOS Stealer That Can Drain Crypto Wallets
- ClickFix Campaigns Expand Malware Delivery With New Loaders and Fake Update Lures
- ClickFix Campaigns Spread MacSync macOS Infostealer via Fake AI Tool Installers
- ClickFix attack pushes macOS infostealer for crypto theft attacks
- Clop created custom web shell for Windchill data theft attacks
- Clop ransomware targets Windchill, FlexPLM in data theft attacks
- Clop-Linked Windchill Web Shell Decrypts Credentials and Maps Engineering Data
- Closing the Identity Gaps in Critical Infrastructure Security
- CloudZ malware abuses Microsoft Phone Link to steal SMS and OTPs
- Cloudflare Workers Spectre Attack Leaks JWT From Co-Located Worker at 12 Bits/Second
- Coca-Cola confirms data theft in Fairlife ransomware attack
- Coca-Cola says Fairlife ransomware attack halts US dairy production
- Cognizant TriZetto breach exposes health data of 3.4 million patients
- Cohere AI Terrarium Sandbox Flaw Enables Root Code Execution, Container Escape
- Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes
- Comcast turns your Xfinity WiFi into a home motion detector
- Compromised AsyncAPI npm Packages Deliver Multi-Stage Botnet Malware
- Compromised Nx Console 18.95.0 Targeted VS Code Developers with Credential Stealer
- Compromised Site Management Panels are a Hot Item in Cybercrime Markets
- Compromised jscrambler 8.14.0 npm Release Drops Rust Infostealer During Install
- ConnectWise patches new flaw allowing ScreenConnect hijacking
- ConsentFix and ClickFix: How Microsoft 365 Accounts are Hijacked in 3 Seconds
- ConsentFix v3 attacks target Azure with automated OAuth abuse
- Continuing Scans for swagger.json, (Wed, Jun 3rd)
- Coordinated Cyberattack Targets 30+ Minnesota Water Systems as One Plant Goes Offline
- Cordyceps CI/CD Flaws Expose 300+ GitHub Repositories to Supply-Chain Attacks
- Coruna iOS Exploit Kit Uses 23 Exploits Across Five Chains Targeting iOS 13–17.2.1
- Coruna iOS Kit Reuses 2023 Triangulation Exploit Code in New Mass Attacks
- Coruna iOS exploit framework linked to Triangulation attacks
- Cosmetics giant Rituals discloses data breach affecting customers
- Cosmos EVM Flaw Exploited After Cosmos Labs Knew Every Blockchain Running It Was Vulnerable
- Council of Europe investigates ShinyHunters data breach claims
- Coupang hit with record $409 million data breach fine in Korea
- Court Filing Reveals Windows Device ID Helped FBI Trace Alleged Scattered Spider Hacker
- CrashStealer macOS Malware Uses Notarized Dropper to Pass Gatekeeper Checks
- Credit card theft campaign abuses Stripe to host stolen payment info
- Criminal IP and Securonix ThreatQ Collaborate to Enhance Threat Intelligence Operations
- Critical Apache HTTP/2 Flaw (CVE-2026-23918) Enables DoS and Potential RCE
- Critical Avada WordPress theme flaw enables zero-click RCE
- Critical Check Point VPN Flaw Exploited to Bypass Passwords in IKEv1 Setups
- Critical Cisco IMC auth bypass gives attackers Admin access
- Critical Citrix NetScaler memory flaw actively exploited in attacks
- Critical Cursor Flaws Could Let Prompt Injection Escape Sandbox and Run Commands
- Critical Elementor Pro bug exposes WordPress sites to RCE attacks
- Critical Everest Forms Pro flaw exploited to take over WordPress sites
- Critical Fortinet FortiSandbox flaws now exploited in attacks
- Critical Fortinet Forticlient EMS flaw now exploited in attacks
- Critical GitLab GraphQL Flaw Could Let Unauthenticated Attackers Delete Public Projects
- Critical Gitea Flaw Let Unauthenticated Attackers Read Server Files via Org-Mode Markup
- Critical Gitea RCE Actively Exploited as Reported Attack Drops Miner-Like Payload
- Critical Gogs RCE Vulnerability Lets Any Authenticated User Execute Arbitrary Code
- Critical Keycloak Password Reset Flaw Could Let Unauthenticated Attackers Take Over Any Account
- Critical Kirki flaw exploited to hijack WordPress admin accounts
- Critical Langflow Flaw CVE-2026-33017 Triggers Attacks within 20 Hours of Disclosure
- Critical Marimo pre-auth RCE flaw now under active exploitation
- Critical Microsoft SharePoint flaw now exploited in attacks
- Critical Microsoft Vulnerabilities Doubled: From Exposure to Escalation
- Critical NGINX Vulnerability Can Crash Workers and May Allow Remote Code Execution
- Critical NetScaler Flaw Can Bypass Authentication on Certain Gateway and AAA Servers
- Critical Nginx UI auth bypass flaw now actively exploited in the wild
- Critical OpenWrt DHCPv6 Flaw Could Let Unauthenticated Attackers Run Code as Root
- Critical Palo Alto VPN bug now exploited by Qilin ransomware gang
- Critical Progress LoadMaster flaw now actively exploited in attacks
- Critical RCE flaw in Windows IKE Extension now actively exploited
- Critical Rails Flaw Could Let Unauthenticated Attackers Read Server Files via Image Uploads
- Critical ServiceNow AI Platform Flaw Exploited for Unauthenticated Code Execution
- Critical ServiceNow code execution flaw now exploited in attacks
- Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC
- Critical SharePoint RCE flaw exploited to steal machine keys
- Critical SimpleHelp flaw exploited to deploy new stealer malware
- Critical Splunk Enterprise Flaw Lets Attackers Run Code Without Authentication
- Critical TeamCity Flaw Could Let Attackers Run OS Commands Without Logging In
- Critical UniFi OS bug lets hackers gain root without authentication
- Critical Unpatched Flaw Leaves Hugging Face LeRobot Open to Unauthenticated RCE
- Critical Unpatched Telnetd Flaw (CVE-2026-32746) Enables Unauthenticated Root RCE
- Critical Unpatched Telnetd Flaw (CVE-2026-32746) Enables Unauthenticated Root RCE via Port 23
- Critical VMware vCenter RCE flaw exploited for reverse SSH access
- Critical WP Maps Pro Flaw Actively Exploited to Create Admin Accounts
- Critical Windows Netlogon RCE flaw now exploited in attacks
- Critical Zimbra Flaw Could Let Crafted Emails Run Malicious Code in User Sessions
- Critical Zimbra RCE flaw now actively exploited in attacks
- Critical cPanel Authentication Vulnerability Identified — Update Your Server Immediately
- Critical cPanel Flaw Could Let One Hosting Customer Take Root Control of a Whole Server
- Critical cPanel Vulnerability Weaponized to Target Government and MSP Networks
- Critical cPanel and WHM bug exploited as a zero-day, PoC now available
- Critical flaw in Protobuf library enables JavaScript code execution
- Critical flaw in wolfSSL library enables forged certificate use
- Critical macOS, SharePoint, vCenter, and Microsoft IKE Flaws Under Active Exploitation
- Critical n8n Flaws Allow Remote Code Execution and Exposure of Stored Credentials
- Critical vm2 sandbox bug lets attackers execute code on hosts
- Critical wp2shell WordPress flaws exploited to install webshells
- Critrical cPanel flaw mass-exploited in "Sorry" ransomware attacks
- Cross-Platform NPM Stealer, (Fri, May 22nd)
- Cruciferra Crypter Uses BYOVD and Process Ghosting to Hide Windows Malware
- Crunchyroll probes breach after hacker claims to steal 6.8M users' data
- Crypto Clipper Campaign Abuses Fake Reviews, AI Narrators, and VirusTotal Comments
- Crypto gang member gets 6.5 years for role in $230 million heist
- Crypto-exchange Kraken extorted by hackers after insider breach
- CryptoJS Weak RNG Behind $5.7 Million in Drains Affects Five Crypto Wallet Apps
- CubePilot drone software dev hit by DNS hijacking to intercept traffic
- Cursor Flaw Lets Malicious Cloned Repositories Trigger Windows Code Execution
- Cursor, Codex, Gemini CLI, Antigravity hit by sandbox escapes
- Cyber-Enabled Cargo Crime: How Cybercrime Tradecraft is Used to Steal Freight
- CyberStrikeAI tool adopted by hackers for AI-powered attacks
- Cybercrime Groups Using Vishing and SSO Abuse in Rapid SaaS Extortion Attacks
- Cybercrime service disrupted for abusing Microsoft platform to sign malware
- Cybersecurity Stars Awards 2026: Winners Announced Across 95 Categories
- Cybersecurity firms targeted by fraudulent OpenAI organization invites
- DAEMON Tools Supply Chain Attack Compromises Official Installers with Malware
- DAEMON Tools devs confirm breach, release malware-free version
- DAEMON Tools trojanized in supply-chain attack to deploy backdoor
- DDoS attacks over 1 Tbps surged fivefold in the second quarter
- DEBULL Tooling Abuses Microsoft Device-Code Flow to Target M365 Accounts
- DHS confirms hackers breached HSIN info-sharing platform
- DOJ seizes CFAKE, SOCFAKE deepfake nude sites under TAKE IT DOWN Act
- DORA and operational resilience: Credential management as a financial risk control
- DOUBLECUP Uses ClickFix and Cached PNGs to Deliver CountLoader and DeviceManager RAT
- DOUBLECUP's PNG Payload, (Mon, Aug 24th)
- DPRK-Linked Hackers Use GitHub as C2 in Multi-Stage Attacks Targeting South Korea
- DPRK-Linked macOS Malvertising Uses Fake Updates to Deliver Crypto-Stealing Malware
- DRILLAPP Backdoor Targets Ukraine, Abuses Microsoft Edge Debugging for Stealth Espionage
- DShield (Cowrie) Honeypot Stats and When Sessions Disconnect, (Mon, Mar 30th)
- DShield Honeypot Update, (Mon, May 4th)
- Danger of Libredtail [Guest Diary], (Wed, Apr 29th)
- Dark web Nemesis Market vendor gets 26 years for selling drugs
- DarkSword iOS Exploit Kit Uses 6 Flaws, 3 Zero-Days for Full Device Takeover
- Dashlane Discloses Brute-Force Attack, Encrypted Vaults of Fewer Than 20 Users Downloaded
- Dashlane password manager users locked out by brute force attacks
- Data analyst sent to prison for stealing data, extorting employer
- Data breach at edtech giant McGraw Hill affects 13.5 million accounts
- Data breach at medical billing firm MCBS affects 1.26 million people
- Data breach exposes up to 14.2 million email logins at six ISPs
- Dawn of the Apex Agentic Adversary
- Daxin Resurfaces in Taiwan Alongside Stupig Pre-Login SYSTEM Backdoor
- Day Zero Readiness: The Operational Gaps That Break Incident Response
- DeadLock Ransomware Uses Polygon Smart Contracts to Make Extortion Infra Harder to Disrupt
- DeadLock ransomware uses blockchain to resist infrastructure takedown
- DeepLoad Malware Uses ClickFix and WMI Persistence to Steal Browser Credentials
- Deepfake Voice Attacks are Outpacing Defenses: What Security Leaders Should Know
- Dell confirms its SupportAssist software causes Windows BSOD crashes
- Delta probes Wi-Fi deauth attack on flight carrying DEF CON attendees
- DentaQuest data breach exposed info of 2.6 million accounts
- Detecting IP KVMs, (Tue, Mar 24th)
- Deterministic + Agentic AI: The Architecture Exposure Validation Requires
- DevMan RaaS Portal Centralizes Payload Builds, Victim Management, and Affiliate Payouts
- Developer Workstations Are Now Part of the Software Supply Chain
- Device Code Phishing Hits 340+ Microsoft 365 Orgs Across Five Countries via OAuth Abuse
- Device code phishing attacks surge 37x as new kits spread online
- Die Linke German political party confirms data stolen by Qilin ransomware
- Differentiating Between a Targeted Intrusion and an Automated Opportunistic Scanning [Guest Diary], (Wed, Mar 4th)
- DirtyDecrypt PoC Released for Linux Kernel CVE-2026-31635 LPE Vulnerability
- Discord rolls out end-to-end encryption on voice, video calls
- Disgruntled researcher leaks “BlueHammer” Windows zero-day exploit
- DoJ Disrupts 3 Million-Device IoT Botnets Behind Record 31.4 Tbps Global DDoS Attacks
- DoJ Disrupts Southeast Asia Crypto Fraud Networks, Freezes $3.8 Million in Assets
- DoJ Seizes Huione Cloud Account Tied to Cyber Scam Money Laundering
- Docker CVE-2026-34040 Lets Attackers Bypass Authorization and Gain Host Access
- Don't Revoke That Token Yet: Inside the keyv/cacheable npm Worm, (Wed, Aug 5th)
- Dormant GitHub Accounts Help Attackers Blend In While Mapping Corporate Orgs
- Dozens of Vendors Patch Security Flaws Across Enterprise Software and Network Devices
- DraftKings hacker 'Snoopy' sentenced to 18 months in prison
- DragonForce Hackers Abuse Microsoft Teams Relays to Hide Backdoor.Turn C2 Traffic
- Drift $280M crypto theft linked to 6-month in-person operation
- Drift Loses $285 Million in Durable Nonce Social Engineering Attack Linked to DPRK
- Drift loses $280 million North Korean hackers seize Security Council powers
- Drift loses $280 million as hackers seize Security Council powers
- Drupal Core SQL Injection Bug Actively Exploited, Added to CISA KEV
- Drupal critical update to fix bug with high exploitation risk
- Drupal to Release Urgent Core Security Updates on May 20, Sites Told to Prepare
- Drupal: Critical SQL injection flaw now targeted in attacks
- DuckDuckGo browser now blocks YouTube video ads
- Dust Specter Targets Iraqi Officials with New SPLITDROP and GHOSTFORM Malware
- Dutch Authorities Dismantle Botnet Linked to 17 Million Infected Devices
- Dutch Finance Ministry takes treasury banking portal offline after breach
- Dutch Ministry of Finance discloses breach affecting employees
- Dutch Police discloses security breach after phishing attack
- Dutch govt disrupts malware botnet with 17 million infected devices
- Dutch govt warns of Signal, WhatsApp account hijacking attacks
- Dutch police arrests suspect linked to Ajax football club hack
- Dutch police bust investment fraud ring stealing over €100 million
- Dysphoria IoT Botnet Adds Blockchain C2 and Victim Relays After JackSkid Disruption
- E.U. Orders Google to Open Android Mic, Camera and Screen to Rival AI Assistants
- E4del and PINHOLE RATs Turn FTP Banners Into Dead Drops for Malware Commands
- EC-Council Expands AI Certification Portfolio to Strengthen U.S. AI Workforce Readiness and Security
- ESET tracks rise in malicious AI skills and adaptable malware
- EU court adviser says banks must immediately refund phishing victims
- EU fines Google $1 billion for search, app store antitrust violations
- EU sanctions Russian GRU military hackers over cyberattacks
- Early Warning Signs of Supply-Chain Attacks Live in the Dark Web
- Edu tech firm Instructure discloses cyber incident, probes impact
- Elementor Pro Flaw Could Let Unauthenticated Attackers Upload PHP and Execute Code
- Encrypted Client Hello: Ready for Prime Time?, (Mon, Mar 9th)
- EngageLab SDK Flaw Exposed 50M Android Users, Including 30M Crypto Wallet Installs
- EngageLab SDK Flaw Exposed 50M Android Users, Including 30M Crypto Wallets
- England Hockey investigating ransomware data breach
- Enterprise Defenses Recovered at the Edge and Collapsed Inside
- Entra passkey enrollment vishing targets Microsoft 365 users
- Ericsson US discloses data breach after service provider hack
- Ernst & Young data breach claimed by ShinyHunters extortion gang
- Ernst & Young discloses data breach after support system hack
- Estée Lauder discloses data breach via Oracle E-Business flaw
- EtherRAT Distribution Spoofing Administrative Tools via GitHub Facades
- Eurail says December data breach impacts 300,000 individuals
- Europe sanctions Chinese and Iranian firms for cyberattacks
- European Commission confirms data breach after Europa.eu hack
- European Commission investigating breach after Amazon cloud account hack
- European Commission investigating breach after Amazon cloud hack
- European Gym giant Basic-Fit data breach affects 1 million members
- European Parliament Member Investigating Spyware Was Hacked With Pegasus
- European police dismantles €50 million crypto investment fraud ring
- Europol Disrupts AudiA6 Crypto Laundering Service Used by Ransomware Gangs
- Europol flags 4,340 URLs for removal in 'The Com' crackdown
- Europol-Led Operation Takes Down Tycoon 2FA Phishing-as-a-Service Linked to 64,000 Attacks
- Europol-coordinated action disrupts Tycoon2FA phishing platform
- Even MOAR Powershell, looking at Entra logins - the good, the bad and the password sprays, (Fri, Aug 21st)
- Every AI Agent Is an Identity. Most Organizations Don't Treat Them That Way
- Evil MSI Background: BASE64 Statistical Analysis, (Mon, Jun 15th)
- Evolution of Ransomware: Multi-Extortion Ransomware Attacks
- Evooo1Bot Linux Botnet Exploits Known Flaws to Turn Edge Devices Into SOCKS5 Proxies
- Ex-data analyst stole company data in $2.5M extortion scheme
- Ex-school district employee jailed for hacks on former employer
- ExfilSquad hackers leak info of over 100,000 UK police officers, staff
- Exploit available for new DirtyDecrypt Linux root escalation flaw
- Exploit released for new PinTheft Arch Linux root escalation flaw
- Exposed Hacker Server Reveals WP-SHELLSTORM Backdooring Thousands of WordPress Sites
- Exposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware Campaign
- F5 Patches Two Critical NGINX Open Source Flaws Enabling Remote Code Execution
- F5 issues out-of-band patches for critical NGINX vulnerabilities
- FBI Disrupts China-Linked QTFY Infrastructure Used to Steal Data From U.S. Organizations
- FBI Seizes NetNut Proxy Platform, Popa Botnet
- FBI Warns Russian Hackers Target Signal, WhatsApp in Mass Phishing Attacks
- FBI Warns Russian Intelligence Hackers Target Signal Backup Recovery Keys
- FBI and Europol Seize LeakBase Forum Used to Trade Stolen Credentials
- FBI and Indonesian Police Dismantle W3LL Phishing Network Behind $20M Fraud Attempts
- FBI arrests suspect linked to $46M crypto theft from US Marshals
- FBI confirms hack of Director Patel's personal email inbox
- FBI disrupts massive AI-powered phishing service using a million URLs
- FBI disrupts proxy network enabling Chinese espionage operations
- FBI investigates breach of surveillance and wiretap systems
- FBI links Signal phishing attacks to Russian intelligence services
- FBI links cybercriminals to sharp surge in cargo theft attacks
- FBI seeks victims of Steam games used to spread malware
- FBI seizes Handala data leak site after Stryker cyberattack
- FBI seizes LeakBase cybercrime forum, data of 142,000 members
- FBI takedown of W3LL phishing service leads to developer arrest
- FBI warns against using Chinese mobile apps due to privacy risks
- FBI warns of Handala hackers using Telegram in malware attacks
- FBI warns of Kali365 phishing service targeting Microsoft 365 accounts
- FBI warns of fake FIFA websites running World Cup fraud schemes
- FBI warns of in-person data theft attacks from extortion gang
- FBI warns of phishing attacks impersonating US city, county officials
- FBI: Americans lost a record $21 billion to cybercrime last year
- FBI: Americans lost over $388 million to scams using crypto ATMs in 2025
- FBI: Fraudsters use couriers to steal money in crypto scams
- FBI: Hackers target online accounts to steal nude photos
- FBI: Russian hackers now target Signal backup recovery keys
- FCC Bans New Foreign-Made Routers Over Supply Chain and Cyber Risk Concerns
- FCC Blocks New Foreign-Produced Robots and Power Inverters Over Cyber Risks
- FCC bans new routers made outside the USA over security risks
- FFmpeg fixes PixelSmash flaw in widely used video decoder
- FIFA World Cup 2026 Scams Are Already Live: Fake Sites, Banking Malware, and Stolen Logins
- FIRESTARTER Backdoor Hit Federal Cisco Firepower Device, Survives Security Patches
- FOMO in the SOC: Where AI Platforms like Claude Actually Fit
- FTC to ban data broker Kochava from selling Americans’ location data
- FTC warns of record $3.5 billion losses to imposter scams in 2025
- FTC: Americans lost over $2.1 billion to social media scams in 2025
- Facebook accounts unavailable in worldwide outage
- Fake 7-Zip Installers Turn Devices Into Residential Proxy Nodes
- Fake AI Agent Skill Passed Security Scans and Reportedly Reached 26,000 Agents
- Fake Adobe and Zoom Updates Install ScreenConnect for Persistent Remote Access
- Fake Apple Support AI Calls Target Stolen-Device Owners for Passcodes and 2FA Codes
- Fake CAPTCHA IRSF Scam and 120 Keitaro Campaigns Drive Global SMS, Crypto Fraud
- Fake Call History Apps Stole Payments From Users After 7.3 Million Play Store Downloads
- Fake Claude AI website delivers new 'Beagle' Windows malware
- Fake Claude Code install guides push infostealers in InstallFix attacks
- Fake Claude app promoted by Bing ads pushes SectopRAT malware
- Fake Coding Tests Deliver OtterCookie-Aligned Malware Hidden in SVG Flag Images
- Fake Google Security site uses PWA app to steal credentials, MFA codes
- Fake IT support calls on Microsoft Teams push EtherRAT malware
- Fake Laravel Packages on Packagist Deploy RAT on Windows, macOS, and Linux
- Fake LastPass support email threads try to steal vault passwords
- Fake Ledger Live app on Apple’s App Store stole $9.5M in crypto
- Fake Microsoft Alerts Used to Deploy North Korean NarwhalRAT Malware
- Fake Notepad++ Plugin Delivers MATCHBOIL.V2 in UAC-0099 Attacks
- Fake OpenAI Privacy Filter Repo Hits #1 on Hugging Face, Draws 244K Downloads
- Fake OpenAI repository on Hugging Face pushes infostealer malware
- Fake Paysafe, Skrill SDKs on NPM and PyPi steal credentials
- Fake Perplexity extension on Chrome Web Store tracked searches
- Fake Roblox Xeno script launcher pushes infostealer, RAT malware
- Fake Sites Mimicking Open-Source Tools Rank High on Google to Deliver Malware via TDS
- Fake Tech Support Spam Deploys Customized Havoc C2 Across Organizations
- Fake VS Code alerts on GitHub spread malware to developers
- Fake enterprise VPN downloads used to steal company credentials
- Fake enterprise VPN sites used to steal company credentials
- FakeGit Campaign Uses 7,600 GitHub Repositories to Spread SmartLoader Malware
- FakeGit campaign uses 7,600 GitHub repos to push SmartLoader malware
- Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available
- FedRAMP Rev5 Is Ending: What the 20x Transition Really Requires
- Feds Disrupt IoT Botnets Behind Huge DDoS Attacks
- Felons, Fraudsters Flog Offensive Cybersecurity Startup
- File read flaw in Smart Slider plugin impacts 500K WordPress sites
- Firefox now has a free built-in VPN with 50GB monthly data limit
- Firefox, Chrome, Adobe, and VMware Updates Fix Multiple Critical Security Flaws
- Firestarter malware survives Cisco firewall updates, security patches
- First VPN Dismantled in Global Takedown Over Use by 25 Ransomware Groups
- Five Malicious Rust Crates and AI Bot Exploit CI/CD Pipelines to Steal Developer Secrets
- Flipper One project needs community help to build open Linux platform
- Flipper Zero firmware development continues with community help
- Florida woman imprisoned for massive Microsoft license fraud scheme
- Flowise AI Agent Builder Under Active CVSS 10.0 RCE Exploitation; 12,000+ Instances Exposed
- FlutterShell Backdoor Spreads to macOS via Malicious Google and YouTube Ads
- Flying Eagle Android RAT Traces Found on 170 Servers as Source Code Circulates
- Forg365 PhaaS Targets Microsoft 365 with Device Code and AitM Session Theft
- Forget Data Leakage: Shadow AI's Real Threat Is Access Control
- Former US execs plead guilty to aiding tech support scammers
- Former govt contractor convicted for wiping dozens of federal databases
- Former ransomware negotiator gets 4 years for BlackCat attacks
- Former ransomware negotiator pleads guilty to BlackCat attacks
- Forminator WordPress Flaw Can Enable Unauthenticated RCE via Malicious PHP Uploads
- FortiBleed Credential Theft Linked to INC and Lynx Ransomware Operations
- FortiBleed Targeted FortiGate Firewalls in 110 Million-Credential Harvesting Operation
- FortiBleed campaign used custom FortiGate sniffer to steal credentials
- FortiBleed credential-theft campaign linked to Lynx ransomware
- FortiBleed leak exposes Fortinet VPN credentials for 73,000 devices.
- FortiGate Devices Exploited to Breach Networks and Steal Service Account Credentials
- Fortinet Patches Actively Exploited CVE-2026-35616 in FortiClient EMS
- Fortinet warns of critical RCE flaws in FortiSandbox and FortiAuthenticator
- Four Malicious npm Packages Deliver Infostealers and Phantom Bot DDoS Malware
- Four OpenClaw Flaws Enable Data Theft, Privilege Escalation, and Persistence
- Foxconn confirms cyberattack claimed by Nitrogen ransomware gang
- Free Apps Are Quietly Turning Smart TVs Into Web-Scraping Proxies for AI
- French govt agency confirms breach as hacker offers to sell data
- French govt messaging service breached in account hijacking attack
- French tax authority data breach affects 678,000 individuals
- From $5 Attacks to Botnet-Powered Platforms: Inside the DDoS-as-a- Service Market
- From 17,000 to 1.1 Million Assets: How Lumen Technologies Rebuilt Exposure Management at Scale
- From Assistive to Agentic: The AI Shift That's Redefining Threat Management
- From Fake Workers to Account Recovery: The Growing Identity Verification Risk
- From VMware to what’s next: Protecting data during hypervisor migration
- From a VHDX File to a Remcos RAT, (Tue, Jun 16th)
- Frontier AI: Vulnerability Management's Systemic Revolution
- Funnel Builder Flaw Under Active Exploitation Enables WooCommerce Checkout Skimming
- Funnel Builder WordPress plugin bug exploited to steal credit cards
- GIGABYTE Control Center vulnerable to arbitrary file write flaw
- GM agrees to $12.75M California settlement over sale of drivers’ data
- GPU mining malware spreads via SEO poisoning, AI chatbots
- GSocket Backdoor Delivered Through Bash Script, (Fri, Mar 20th)
- Gamaredon Expands Ukraine Attacks with New Malware and Cloud Service Abuse
- Gamaredon Exploits WinRAR to Deliver GammaWorm and GammaSteel Against Ukraine
- GemStuffer Abuses 150+ RubyGems to Exfiltrate Scraped U.K. Council Portal Data
- Gentlemen ransomware uses multiple EDR killers to disable defenses
- German authorities identify REvil and GandCrab ransomware bosses
- German authorities identify REvil and GangCrab ransomware bosses
- Germany Doxes “UNKN,” Head of RU Ransomware Gangs REvil, GandCrab
- Ghanain man pleads guilty to role in $100 million fraud ring
- Ghost CMS CVE-2026-26980 Exploited to Hijack 700+ Sites for ClickFix Attacks
- Ghost CMS SQL injection flaw exploited in large-scale ClickFix campaign
- Ghost Campaign Uses 7 npm Packages to Steal Crypto Wallets and Credentials
- GhostApproval Symlink Flaws Could Let Malicious Repos Run Code in AI Coding Agents
- GhostTree Attack Abused Recursive Windows Junctions to Hide Malware
- Ghostwriter Targets Ukraine Government Entities with Prometheus Phishing Malware
- Ghostwriter Targets Ukrainian Government With Geofenced PDF Phishing, Cobalt Strike
- GitHub 'Verified' Commits Can Be Rewritten Into New Hashes Without Breaking Signatures
- GitHub Actions Supply Chain Attack Redirects Tags to Steal CI/CD Credentials
- GitHub Adds 3-Day Dependabot Cooldown to Limit Poisoned Package Adoption
- GitHub Breached — Employee Device Hack Led to Exfiltration of 3,800+ Internal Repos
- GitHub Copilot Refuses Harmful Requests in Chat, Then Writes Them in Code
- GitHub Cuts Public Bug Bounty Payouts, Moves Top Rewards to VIP Tier
- GitHub Internal Repositories Breached via Malicious Nx Console VS Code Extension
- GitHub Investigating TeamPCP Claimed Breach of ~4,000 Internal Repositories
- GitHub Updates actions/checkout to Block Common Pwn Request Attack Patterns
- GitHub adds AI-powered bug detection to expand security coverage
- GitHub announces npm security changes to tackle supply-chain attacks
- GitHub confirms breach of 3,800 repos via malicious VSCode extension
- GitHub disables Microsoft repos pushing password-stealing malware
- GitHub fixes RCE flaw that gave access to millions of private repos
- GitHub investigates internal repositories breach claimed by TeamPCP
- GitHub links repo breach to TanStack npm supply-chain attack
- GitHub to Disable npm Install Scripts by Default to Stop Supply Chain Attacks
- GitHub, PyPI add time-absed defenses against supply chain attacks
- GitHub, PyPI add time-based defenses against supply chain attacks
- GitLab CVE-2026-19478 Comes Under Active Exploitation Within Days of Disclosure
- Gitea Vulnerability Exposes Private Container Images without Authentication
- GiveWP WordPress donation plugin flaw lets hackers execute server commands
- GlassWorm Attack Uses Stolen GitHub Tokens to Force-Push Malware Into Python Repos
- GlassWorm Campaign Uses Zig Dropper to Infect Multiple Developer IDEs
- GlassWorm Malware Takedown Disrupts Developer Supply Chain Attack Infrastructure
- GlassWorm Malware Uses Solana Dead Drops to Deliver RAT and Steal Browser, Crypto Data
- GlassWorm Supply-Chain Attack Abuses 72 Open VSX Extensions to Target Developers
- GlassWorm malware attacks return via 73 OpenVSX "sleeper" extensions
- GlassWorm malware hits 400+ code repos on GitHub, npm, VSCode, OpenVSX
- Glassworm botnet disrupted after resilient C2 infrastructure takedown
- Global Crackdown Arrests 276, Shuts 9 Crypto Scam Centers, Seizes $701M
- GoCaracal Malware Uses Ethereum Smart Contract to Fetch Replacement C2 Address
- GodDamn Ransomware Uses PoisonX Driver to Disable Endpoint Defenses
- Gogs patches critical zero-day enabling remote code execution
- Going the Extra Mile: Travel Rewards Turn into Underground Currency.
- Golden Chickens Resurfaces With Four New Malware Families and Modular Implants
- GoldenEyeDog Subgroup Linked to DigiCert Breach and Code-Signing Certificate Theft
- Google Adds 24-Hour Wait for Unverified App Sideloading to Reduce Malware and Scams
- Google Adds Rust-Based DNS Parser into Pixel 10 Modem to Enhance Security
- Google Adds Selfie Video Recovery for Users Locked Out of Their Accounts
- Google Attributes Axios npm Supply Chain Attack to North Korean Group UNC1069
- Google Blocks 8.3B Policy-Violating Ads in 2025, Launches Android 17 Privacy Overhaul
- Google Blogger locks hundreds of blogs in malware false positive
- Google Chrome adds infostealer protection against session cookie theft
- Google Chrome adds session cookie theft protection for all users
- Google Chrome may soon block New Tab hijacker extensions by default
- Google Chrome shifts to two-week release cycle for increased stability
- Google Confirms CVE-2026-21385 in Qualcomm Android Component Exploited
- Google Deletes 3 ADK AI Workflows After Malicious GitHub Issue Could Trigger Privileged Agent
- Google Details Turla's New STOCKSTAY Backdoor Used in Ukraine Espionage Attacks
- Google Develops Merkle Tree Certificates to Enable Quantum-Resistant HTTPS in Chrome
- Google Disrupts NetNut Residential Proxy Network Spanning 2 Million Home Devices
- Google DoubleClick Abused in New Malspam Campaign to Deliver DesckVB RAT
- Google Drive ransomware detection now on by default for paying users
- Google Fixes CVSS 10 Gemini CLI CI RCE and Cursor Flaws Enable Code Execution
- Google Fixes Two Chrome Zero-Days Exploited in the Wild Affecting Skia and V8
- Google Gemini CLI abused as a hacking agent, malware botnet operator
- Google June 2026 Android Update Patches 124 Flaws, One Actively Exploited
- Google Launches Gemini 3.5 Flash Cyber AI to Find and Fix Software Vulnerabilities
- Google Password Manager Attacks Could Let Malware Hijack Passkey-Protected Accounts
- Google Patches Antigravity IDE Flaw Enabling Prompt Injection Code Execution
- Google Rolls Out DBSC in Chrome 146 to Block Session Theft on Windows
- Google Sets Sept. 30 Deadline for Android Developer Verification in Four Countries
- Google Sues Chinese Smishing Network Accused of Using Gemini AI in Phishing
- Google Vertex AI SDK Flaw Let Attackers Hijack Model Uploads via Bucket Squatting
- Google accidentally exposed details of unfixed Chromium flaw
- Google adds Android protection against AI deepfake scam calls
- Google adds ‘Advanced Flow’ for safe APK sideloading on Android
- Google and Microsoft Pull ModHeader With 1.6 Million Installs After Dormant Collector Found
- Google expands Gemini AI use to fight malicious ads on its platform
- Google fixes fourth Chrome zero-day exploited in attacks in 2026
- Google fixes one actively exploited Android zero-day, 124 flaws
- Google fixes two new Chrome zero-days exploited in attacks
- Google loses final appeal to overturn €4.1 billion EU fine
- Google now allows you to change your @gmail.com address
- Google now offers up to $1.5 million for some Android exploits
- Google paid $17.1 million for vulnerability reports in 2025
- Google patches new Chrome zero-day flaw exploited in the wild
- Google releases new privacy controls for activity history, personalization
- Google rolls out Gmail end-to-end encryption on mobile devices
- Google says 90 zero-days were exploited in attacks last year
- Google says AI helped Chrome fix 1,072 security bugs in two releases
- Google says Chrome cuts 7 billion unwanted Android notifications a day to fight abuse
- Google to use UK and EU user IP addresses for ad personalization
- Google's Android Apps Get Public Verification to Stop Supply Chain Attacks
- Google: Cloud attacks exploit flaws more than weak credentials
- Google: Hackers used AI to develop zero-day exploit for web admin tool
- Google: New UNC6783 hackers steal corporate Zendesk support tickets
- Grafana GitHub Breach Exposes Source Code via TanStack npm Attack
- Grafana GitHub Token Breach Led to Codebase Download and Extortion Attempt
- Grafana breach caused by missed token rotation after TanStack attack
- Grafana says stolen GitHub token let hackers steal codebase
- Grandoreiro Malware and BTMOB RAT Campaigns Target Windows and Android Users
- Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal Tokens
- GreyVibe hackers use ChatGPT, Gemini to power cyberattacks
- Grinex exchange blames "Western intelligence" for $13.7M crypto hack
- Grok Build Uploaded Entire Git Repositories to xAI Storage, Not Just Files It Read
- Grok Build Uploads Entire Git Repositories to xAI Storage, Not Just Files It Reads
- Growing Up The Hard Way
- GuardFall Exposes Open-Source AI Coding Agents to Decades-Old Shell Injection Risks
- Guardian Agents: The Next Layer of Identity Governance
- Gunra Ransomware Exploits Fortinet and Schneider Electric Flaws to Breach Networks