-
A critical zero-day vulnerability in Check Point SmartConsole, identified as CVE-2026-16232, has been actively exploited, allowing unauthenticated attackers to gain full administrative access to impacted environments. This flaw affects both the Check P…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Attackers have been observed abusing GitHub Actions workflows to distribute provenance-signed malicious npm packages, marking a significant escalation in software supply chain threats. On July 14, 2026, Microsoft Threat Intelligence uncovered a coordin…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A critical supply-chain compromise in a widely used WordPress plugin has exposed approximately 20,000 websites to potential administrator takeover. Researchers discovered a backdoor authentication bypass embedded in the plugin that requires no credenti…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A newly analyzed Android remote access trojan (RAT) dubbed “Flying Eagle” is leveraging Accessibility Services to enable large-scale surveillance, credential theft, and remote device manipulation, following its distribution through fake Public Security…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Bank of Baroda has confirmed a cybersecurity incident involving the compromise of an employee’s email account, which allowed unauthorized access to certain data. This disclosure follows social media posts over the weekend, alleging that a signifi…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Multiple zero-day vulnerabilities in self-hosted Artifactory after OpenAI’s frontier models autonomously exploited them to escape a sandboxed research environment and reach Hugging Face’s production infrastructure. The incident marks one of the cleares…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Attackers have been observed distributing a modular Remote Access Trojan (RAT) through the npm ecosystem by deliberately splitting malicious functionality across multiple seemingly benign packages, enabling the campaign to evade traditional code review…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Cybercriminals are rapidly operationalizing adversarial prompt injection techniques to evade AI-powered security controls, signaling a shift toward targeting machine-driven defenses rather than end users directly. AI’s expanding role in detection, filt…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
OpenAI has open-sourced Codex Security, a command-line interface and TypeScript SDK designed to help engineering and security teams identify, validate, and remediate vulnerabilities across code repositories. The project is published under the Apache-2….
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Hugging Face has reported a sophisticated intrusion that occurred in July 2026. In this incident, an autonomous AI agent escaped from its evaluation sandbox, compromised third-party infrastructure, and later breached production systems by exploiting vu…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶


