vulnerability Anthropic Silently Patches Claude Code Sandbox Bypass Anthropic has addressed a vulnerability in its Claude Code network sandbox that could have allowed attackers to bypass security controls and potentially exfiltrate data. The vulnerability, discovered by researcher Aonan… SecurityWeek · May 20, 2026 High CVE-2025-66479sandboxprompt injectionsecurity
supply-chain Compromised Nx Console 18.95.0 Targeted VS Code Developers with Credential Stealer A compromised version of the Nx Console VS Code extension (version 18.95.0) was used to steal developer credentials through a supply chain attack. The extension, initially introduced by a developer whose machine was comp… The Hacker News · May 19, 2026 High RUUSsupply chaincredential theftvscode
threat-intel The Boring Stuff Is Dangerous Now This article highlights a growing security challenge stemming from the widespread adoption of AI coding tools and the emergence of AI agents capable of exploiting obscure vulnerabilities. The combination creates a situat… Dark Reading · May 18, 2026 High aivulnerabilitycybersecurity
threat-intel How Dangerous Is Anthropic’s Mythos AI? Anthropic’s Claude Mythos AI model demonstrates a significant capability in identifying software vulnerabilities, prompting concerns about its potential misuse by attackers. While the company initially restricted access… Schneier on Security · May 14, 2026 High UKaivulnerabilitycybersecurity
threat-intel Patch Tuesday, May 2026 Edition This article reports on Patch Tuesday, May 2026, highlighting a significant increase in security vulnerabilities addressed by major software vendors like Microsoft, Apple, Google, Mozilla, and Oracle. The updates, spurre… Krebs on Security · May 12, 2026 Critical CVE-2026-41089CVE-2026-41096CVE-2026-41103USpatch tuesdayaivulnerability
threat-intel LLMs and Text-in-Text Steganography This article discusses attempts to hide text within LLMs using techniques like phonological changes and unconventional formatting (e.g., white text on white backgrounds). The author explores the limitations of these meth… Schneier on Security · May 11, 2026 Low UKsteganographyllmstempeset
threat-intel Anthropic's Mythos Has Landed: Here's What Comes Next for Cyber This article reports on Anthropic’s release of Claude, dubbed ‘Mythos,’ an AI model capable of rapidly identifying and exploiting software vulnerabilities, including zero-day bugs, across major operating systems and web… Dark Reading · Apr 30, 2026 High aivulnerabilitycybersecurity
threat-intel Frontier AI and the Future of Defense: Your Top Questions Answered This article from Palo Alto Networks Unit 42 analyzes the emerging threat posed by frontier AI models, particularly Anthropic’s Mythos, to cybersecurity. The rapid capabilities of these models – including vulnerability i… Palo Alto Unit 42 · Apr 23, 2026 High frontier aivulnerabilityexploit chaining
threat-intel Can AI Attack the Cloud? Lessons From Building an Autonomous Cloud Offensive Multi-Agent System This report details a proof-of-concept (PoC) developed by Palo Alto Unit 42 demonstrating the potential of autonomous AI agents in launching offensive attacks against cloud environments. The PoC, utilizing a multi-agent… Palo Alto Unit 42 · Apr 23, 2026 High USaiautonomouscloud
threat-intel Fracturing Software Security With Frontier AI Models This report from Palo Alto Unit 42 highlights the emerging threat posed by advanced AI models, particularly "frontier AI models," which demonstrate autonomous vulnerability discovery and exploitation capabilities. The ra… Palo Alto Unit 42 · Apr 20, 2026 High UNNOaivulnerabilityzero-day
threat-intel Patch Tuesday, April 2026 Edition Microsoft released a substantial update, Patch Tuesday, addressing 167 vulnerabilities across its operating systems and software, including several zero-days. This update focused on critical flaws in SharePoint Server, W… Krebs on Security · Apr 14, 2026 High CVE-2026-32201CVE-2026-33825CVE-2026-34621zero-daypatch tuesdayvulnerability