supply-chain Over 2,500 Organizations Impacted by LiteLLM Supply Chain Attack Over 2,500 organizations and 434,000 CI/CD pipelines were impacted by a supply chain attack involving the LiteLLM AI library. The attack stemmed from a compromised version of Aqua Security’s Trivy vulnerability scanner, allowing threat actors (TeamPCP) to inject malicious code into LiteLLM, leading to widespread exposu… SecurityWeek · Aug 12, 2026 High supply chainaicredentials
threat-intel Mythos Asks the Right Question. It Doesn't Answer It. The article argues that AI-powered exploit discovery tools like Mythos are compressing the time between vulnerability disclosure and exploitation, but the real problem isn't faster patching – it's that most security team… The Hacker News · Jul 29, 2026 High vulnerabilitythreat-intelai
threat-intel Microsoft Maps Year-Long ShinyHunters-Linked Salesforce Data Theft Across Three Paths For a year, attackers leveraging the ShinyHunters group gained access to Salesforce environments not through exploiting vulnerabilities, but by exploiting trust placed in connected apps and vendors. They achieved this th… The Hacker News · Jul 14, 2026 High USoathconnected appsvendor compromise
threat-intel 'Yellow Teams' Are Defining the Future of AI Security A growing trend of ‘yellow teams’ – engineering groups building both attack and defense tools – is emerging as a crucial response to the increasing threat of AI-powered cyberattacks. These teams are using advanced AI mod… Dark Reading · Jul 13, 2026 High aicybersecurityvulnerability
threat-intel AI Attacks Move in Minutes. Join This Webinar on Building a Defense That Keeps Up AI-powered attacks are now executing significantly faster, requiring security teams to adapt their defenses. This article details a new attack methodology leveraging AI models like Mythos, highlighting the need for a shi… The Hacker News · Jul 9, 2026 High aiattackthreat
threat-intel Prompt Injection Attacks Trick AI Agents Into Making Crypto Payments Threat actors are exploiting prompt injection vulnerabilities in AI agents to trick them into making cryptocurrency payments and promoting fraudulent platforms. Zscaler identified two campaigns utilizing SEO poisoning an… SecurityWeek · Jul 6, 2026 Medium prompt-injectionaicybersecurity
threat-intel New Mistic Backdoor Linked to KongTuke in ClickFix and ModeloRAT Campaigns A new stealthy backdoor, Mistic (MLTBackdoor), linked to the KongTuke IAB has been used in financially motivated attacks targeting organizations across insurance, education, IT, and professional services since April 2026… The Hacker News · Jun 25, 2026 High USbackdoorremote access trojanclickfix
malware Malicious Edge extension abuses Native Messaging as bridge to malware A malicious Microsoft Edge extension, ‘Edgecution,’ was used in a ransomware attack by exploiting Native Messaging to bypass browser security sandboxes and deploy a Python-based backdoor. The attack, linked to the Payout… BleepingComputer · Jun 24, 2026 High USbrowser extensionnative messagingransomware
threat-intel Stealthy Mistic backdoor linked to ransomware access broker KongTuke A new stealthy backdoor, dubbed Mistic, has been identified as a tool used by the initial access broker KongTuke to facilitate ransomware attacks against organizations in the insurance, education, IT, and professional se… BleepingComputer · Jun 24, 2026 High USbackdoorinitial accessransomware
threat-intel Phishing Attack Volume Down 20%, but Risk Still Rising The volume of phishing attacks has decreased by 20% across multiple industries, despite a shift towards more sophisticated attacks utilizing AI. Threat actors are prioritizing targeted campaigns with higher conversion ra… Dark Reading · Jun 12, 2026 High CAESAUphishingaicloud
threat-intel ⚡ Weekly Recap: Instagram Account Hacks, Android Zero-Day, GitHub Worm and More This week’s security news highlights a series of attacks and vulnerabilities, including a supply chain attack targeting Microsoft GitHub repositories via the Miasma Worm, a zero-day exploit in Android, and ongoing cyberc… The Hacker News · Jun 8, 2026 High CVE-2025-48595CVE-2026-28318CVE-2026-39210CHUSGEsupply-chainzero-daycybercrime
threat-intel Cybersecurity M&A Roundup: 26 Deals Announced in May 2026 In May 2026, several cybersecurity firms announced a significant wave of mergers and acquisitions, primarily focused on expanding capabilities in areas like AI-powered security, zero trust architectures, and endpoint pro… SecurityWeek · Jun 8, 2026 High ISUKUSm&aai securityzero trust
threat-intel Akamai Joins Growing Chorus of Vendors Betting Big on Secure Enterprise Browsers Akamai has acquired LayerX, a Tel Aviv-based startup, for $205 million to bolster its Zero Trust Network Access (ZTNA) portfolio. This move reflects a growing trend among cybersecurity vendors adding secure enterprise br… Dark Reading · May 22, 2026 Medium ILsecure browserztnasaas