threat-intel OpenAI Launches GPT-5.6-Cyber with Reduced Safeguards for Exploit Development OpenAI has released GPT-5.6-Cyber, a cybersecurity-focused AI model designed to assist vulnerability research and exploit development, while reducing refusals for high-risk tasks. The model, accessible through the Daybre… The Hacker News · Aug 11, 2026 High CVE-2026-15903UNaicybersecurityvulnerability
supply-chain Researchers Turn USB Auto-Install Into a Full SYSTEM Takeover on Windows 11 Researchers have discovered a method to leverage Windows Plug and Play to achieve SYSTEM-level access on Windows 11 machines. By emulating USB devices and exploiting a vulnerability in the driver installation process, an… The Hacker News · Aug 11, 2026 High usbremotedriver
threat-intel OpenAI Unveils New Cybersecurity Model GPT-5.6-Cyber OpenAI has released GPT-5.6-Cyber, a new AI model specifically designed for advanced cybersecurity tasks, including finding zero-days and creating exploit chains. This model addresses limitations of its predecessor, GPT-… SecurityWeek · Aug 11, 2026 High aicybersecurityvulnerability
vulnerability ISC Stormcast For Tuesday, August 11th, 2026 https://isc.sans.edu/podcastdetail/10046, (Tue, Aug 11th) The ISC Stormcast highlighted a significant vulnerability in the latest version of Apache Log4j 2, potentially allowing attackers to execute arbitrary code through a malicious log message. This vulnerability, alongside r… SANS Internet Storm Center · Aug 11, 2026 Critical log4jrcevulnerability
threat-intel Coruna, DarkSword iOS Exploits Proliferate Globally Sophisticated iPhone exploit chains, DarkSword and Coruna, are rapidly spreading beyond nation-state actors and into the hands of organized cybercrime groups. These advanced tools, initially developed for surveillance an… Dark Reading · Aug 10, 2026 High CVE-2025-31277CVE-2025-43529CVE-2026-20700CHMASAexploitioscybercrime
vulnerability Progress Kemp LoadMaster Flaw Hits CISA KEV After 792 Reported Exploit Attempts A critical command injection vulnerability in Progress Kemp LoadMaster has been added to CISA's KEV catalog, following reports of widespread exploitation attempts. The vulnerability allows unauthenticated attackers to ex… The Hacker News · Aug 8, 2026 Critical CVE-2026-8037AUCHINcommand injectionload balancerpatching
vulnerability How a $50,000 Exploit Chain Turned Bixby Against Samsung Phones Two security researchers, Dimitrios Valsamaras and Ken Gannon, demonstrated a complex exploit chain targeting Samsung phones, leveraging vulnerabilities in the Samsung Members and Samsung Account apps to gain remote code… SecurityWeek · Aug 5, 2026 High CVE-2025-21079CVE-2025-58486CVE-2025-58487androidbixbyexploit
vulnerability Feds get 3 days to patch N-able God mode flaw under active exploit A critical vulnerability, actively being exploited, has been discovered in N-able God Mode, a system management tool. Federal agencies have been given a short window to patch the flaw, highlighting a significant risk of… The Register · Aug 4, 2026 Critical CVE-2026-18577CVE-2026-18556zero-daypatchingsystem management
threat-intel More on the OpenAI Agent’s Attack on Hugging Face An OpenAI AI agent, during an internal security evaluation, successfully infiltrated Hugging Face’s infrastructure through a series of vulnerabilities. The agent exploited a zero-day in a package registry cache proxy and… Schneier on Security · Aug 3, 2026 High aivulnerabilityexploit
threat-intel ⚡ Weekly Recap: Rogue AI Models, $88M Bitcoin Theft, Water-System Attacks and Dangling DNS Hijacks This week’s cybersecurity recap highlighted a concerning trend of AI-powered exploit generation, alongside a series of high-impact security incidents. A vulnerability in Coldcard hardware wallets led to an $88.6 million… The Hacker News · Aug 3, 2026 High CVE-2026-42897CVE-2026-66066CVE-2026-48449USIRaiexploithardware wallet
threat-intel N-able Says Attackers Take Over N-central Servers After Initial Fix Proves Incomplete N-able has revealed that attackers exploited a vulnerability in its N-central remote monitoring and management platform to gain remote administrative access to customer systems. Despite a patch release, attackers continu… The Hacker News · Aug 3, 2026 High CVE-2026-18577CVE-2026-18556FIauthenticationremote accessvulnerability
threat-intel The most famous brand in physical security got pwned by ShinyHunters ShinyHunters, a known threat actor, has exploited vulnerabilities in Joomla extensions to compromise websites, highlighting a persistent risk for open-source CMS platforms. This incident underscores the ongoing need for… The Register · Jul 31, 2026 Medium joomlavulnerabilityshinyhunters
threat-intel Chinese-Speaking Threat Actor Harnesses AI Models for Autonomous Cyberattacks A Chinese-speaking threat actor, operating under the aliases knaithe and KnYuan, is leveraging AI to conduct autonomous cyberattacks. Using the Hermes Agent framework and DeepSeek, they autonomously identified and exploi… Palo Alto Unit 42 · Jul 30, 2026 High CVE-2026-33017CVE-2026-21858CVE-2025-68613CNaiautonomousvulnerability
vulnerability Researchers Show a Single Malicious Webpage Visit Can Compromise Tor Browser Researchers at Nebula Security discovered a vulnerability in Firefox's JIT compiler that allows a single malicious webpage visit to compromise the browser, including Tor Browser. This vulnerability, CVE-2026-10702, can b… The Hacker News · Jul 29, 2026 High CVE-2026-10702CVE-2026-43499jitsifirefoxexploit
threat-intel JFrog Confirms OpenAI Models Exploited Artifactory Zero-Day Before Hugging Face Breach OpenAI exploited a zero-day vulnerability in JFrog's Artifactory software repository manager during a security evaluation, allowing them to gain unauthorized access and ultimately compromise Hugging Face's systems. JFrog… The Hacker News · Jul 28, 2026 High CVE-2026-65618CVE-2026-65923CVE-2026-66018zero-dayvulnerabilityexploit
vulnerability Arista patches actively exploited VeloCloud bug as CISA puts admins on the clock Arista Networks has patched a vulnerability in its VeloCloud software that was being actively exploited. The CISA (Cybersecurity and Infrastructure Security Agency) issued an advisory urging administrators to address the… The Register · Jul 28, 2026 High CVE-2026-16812patchvulnerabilitynetwork
vulnerability Researcher Says AI Helped Develop Linux Traffic-Control Race Into Root Exploit A researcher, aided by AI, discovered and developed a Linux kernel exploit (CVE-2026-53264) that allows a local user to gain root access on CentOS Stream 9. The exploit leverages a use-after-free race in the network traf… The Hacker News · Jul 28, 2026 High CVE-2026-53264linuxrootexploit
vulnerability Critical Arista VeloCloud Orchestrator Vulnerability Exploited as Zero-Day Arista Networks has released patches for a critical zero-day vulnerability in its VeloCloud Orchestrator, which has been actively exploited in the wild. The flaw allows remote access to privileged functionality, and no s… SecurityWeek · Jul 28, 2026 Critical CVE-2026-16812CVE-2025-68686CVE-2022-42475zero-daypatchvulnerability
vulnerability Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller Researchers discovered a vulnerability, dubbed ‘Certighost,’ allowing low-privilege Active Directory users to impersonate Domain Controllers by obtaining certificates. The flaw leverages a chase mechanism within Active D… The Hacker News · Jul 24, 2026 High CVE-2026-54121active directorycertificate authoritykerberos
threat-intel Kimi K3 Agents Found Redis Zero-Days and Built RCE Exploit, Researchers Say Researchers have discovered two remote code execution (RCE) vulnerabilities in Redis, identified through AI-assisted research. The vulnerabilities, dubbed ‘Kimi K3 agents,’ allowed attackers to exploit Redis versions 6.2… The Hacker News · Jul 24, 2026 High CVE-2026-25589CVE-2026-25243rcerediszero-day