threat-intel Writer AI Flaw Could Let Agent Previews Leak Session Tokens Across Tenants A critical session isolation vulnerability, dubbed WriteOut, has been discovered in Writer, an AI platform, allowing attackers to steal session tokens and gain control of user accounts across multiple organizations. The… The Hacker News · Jul 7, 2026 Critical session-hijackingtenant-isolationai
threat-intel ThreatsDay: AI Compute Hijacking, Apple Email Flaw, BlueHammer Ransomware + 14 Stories This week’s security news highlights several vulnerabilities and ongoing threats across various sectors. A phishing campaign targeting small businesses globally with ransomware, a root escape vulnerability in Claude Cowo… The Hacker News · Jul 2, 2026 High CVE-2026-33825CHUNGEphishingransomwaresandbox
threat-intel Critical Cursor Flaws Could Let Prompt Injection Escape Sandbox and Run Commands A critical vulnerability, dubbed DuneSlide, has been discovered in Cursor, an AI code editor used by over half of the Fortune 500, allowing attackers to bypass the editor's sandbox and execute arbitrary commands on a dev… The Hacker News · Jul 1, 2026 Critical CVE-2026-50548CVE-2026-50549CVE-2025-54135prompt-injectionsandboxai-code-editor
malware Malicious Edge extension abuses Native Messaging as bridge to malware A malicious Microsoft Edge extension, ‘Edgecution,’ was used in a ransomware attack by exploiting Native Messaging to bypass browser security sandboxes and deploy a Python-based backdoor. The attack, linked to the Payout… BleepingComputer · Jun 24, 2026 High USbrowser extensionnative messagingransomware
vulnerability Google patches new Chrome zero-day flaw exploited in the wild Google has released a security update to address a newly discovered and actively exploited zero-day vulnerability (CVE-2026-11645) within the Chrome browser. This flaw, originating in the V8 JavaScript engine, allows att… BleepingComputer · Jun 9, 2026 High CVE-2026-11645CVE-2024-0519CVE-2026-2441zero-daychromev8
threat-intel AI Phishing Is Crushing SOCs with Alert Volume: How to Reduce Tier 1 Overload This article discusses the increasing challenge of AI-powered phishing attacks overwhelming Security Operations Centers (SOCs). Attackers are leveraging AI to create more convincing and varied phishing campaigns, leading… The Hacker News · Jun 8, 2026 High USphishingaisoc
threat-intel With Complex Cloud Integrations, Small Errors Lead to Major Compromises This article details a near-breach at Zapier, a popular low-code automation service, highlighting the risks associated with complex cloud integrations and inadequate security practices. Researchers at Token Security disc… Dark Reading · May 29, 2026 High UScloud-securitysecretspermissions
vulnerability Anthropic Silently Patches Claude Code Sandbox Bypass Anthropic has addressed a vulnerability in its Claude Code network sandbox that could have allowed attackers to bypass security controls and potentially exfiltrate data. The vulnerability, discovered by researcher Aonan… SecurityWeek · May 20, 2026 High CVE-2025-66479sandboxprompt injectionsecurity
threat-intel 'Claw Chain' Vulnerabilities Threaten OpenClaw Deployments New vulnerabilities, dubbed 'Claw Chain,' have been discovered in the OpenClaw open-source AI agent framework, posing a significant risk to deployments. These four flaws – CVE-2026-44112, CVE-2026-44115, CVE-2026-44118,… Dark Reading · May 18, 2026 Critical CVE-2026-44112CVE-2026-44115CVE-2026-44118aiagentvulnerability
phishing How to Reduce Phishing Exposure Before It Turns into Business Disruption This article discusses the increasing risk posed by phishing attacks, particularly due to their ability to quickly escalate into significant business disruptions. It highlights the challenges SOC teams face in identifyin… The Hacker News · May 18, 2026 High USphishingsandboxcredential theft