threat-intel Anthropic Restores Claude Fable 5 After U.S. Lifts Jailbreak-Linked Export Controls Anthropic has restored access to Claude Fable 5 following the U.S. Commerce Department’s lifting of export controls triggered by a jailbreak vulnerability discovered in the model. The controls, implemented in June, restr… The Hacker News · Jul 1, 2026 High USjailbreakaisecurity
threat-intel Phantom Squatting: AI-Hallucinated Domains as a Software Supply Chain Vector Palo Alto Unit 42 researchers have identified a new supply chain threat: "phantom squatting," where large language models (LLMs) hallucinate web domains that adversaries can then register to intercept traffic generated b… Palo Alto Unit 42 · Jul 1, 2026 High USllmaisupply chain
threat-intel Fake Bug Report Hijacks AI Coding Agents at Scale A research report by Tenet Security has revealed a critical vulnerability in AI coding agents, demonstrating how a simple, fabricated error report submitted to a bug tracking service (Sentry) can be used to hijack these… Dark Reading · Jun 30, 2026 Critical aiagentjackingerror-tracking
threat-intel Attackers Hijack Exposed AI Endpoints to Power Offensive Ops Researchers at Zenity discovered attackers are exploiting exposed AI endpoints, specifically Ollama and LiteLLM, to power offensive operations. Attackers leverage these AI agents – such as Strix and HexStrike AI – withou… Dark Reading · Jun 30, 2026 High FRaillmendpoint
threat-intel Why Identity Security Is Your Cyber Career Entry Point This Dark Reading article, part of their ‘Heard It From a CISO’ video series, discusses the evolving landscape of cybersecurity career entry points. It highlights that while AI is automating certain tasks, human oversigh… Dark Reading · Jun 30, 2026 Medium aicybersecurityidentity security
threat-intel Microsoft Warns Poisoned MCP Tool Descriptions Can Make AI Agents Leak Data This report details a new security vulnerability impacting AI agent-based systems, specifically leveraging the Model Context Protocol (MCP). Attackers can inject malicious instructions into tool descriptions used by AI a… The Hacker News · Jun 30, 2026 High N/aiagentsupply-chain
threat-intel House passes kids’ online safety bill, but Senate approval unlikely The House of Representatives passed the Kids Internet and Digital Safety (KIDS) Act, aiming to bolster online safety for children, but the bill faced criticism for lacking key provisions like a ‘duty of care’ and strong… The Record · Jun 30, 2026 Medium USonline safetychildrenprivacy
ransomware Langflow RCE Exploited to Deploy Monero Miner on Exposed AI App Endpoints A critical Remote Code Execution (RCE) vulnerability (CVE-2026-33017) in Langflow is being exploited by threat actors to deploy a Monero cryptocurrency miner on exposed AI application endpoints. The campaign, active from… The Hacker News · Jun 30, 2026 Critical CVE-2026-33017CVE-2025-3248NOrcemoneroai
threat-intel GuardFall Exposes Open-Source AI Coding Agents to Decades-Old Shell Injection Risks A research report by Adversa AI has revealed a significant security vulnerability in ten popular open-source AI coding agents, including GuardFall, which allows attackers to bypass safety checks and execute shell command… The Hacker News · Jun 30, 2026 High aishellsecurity
threat-intel 282 iOS AI Apps Leak API Keys and Open AI Proxy Access in Network Traffic Study Researchers at Wake Forest University discovered that nearly two-thirds (282 out of 444) of AI chatbot apps for iOS exposed API keys and open access to AI proxy services through network traffic. This vulnerability, dubbe… The Hacker News · Jun 30, 2026 High USapiaiiot
threat-intel AI-Generated Workflows Are a Silent Security Disaster This article highlights a growing security risk stemming from the use of AI-generated workflows within Microsoft 365 environments. Developers and users are leveraging AI assistants to automate tasks like document approva… Dark Reading · Jun 30, 2026 Medium aiautomationpermissions
threat-intel Hacker Conversations: Chris Thompson, Former Head of IBM X-Force Red, Co-Founder of RemoteThreat This article details the unconventional career path of Chris Thompson, a former IBM X-Force Red head and now CEO of RemoteThreat, tracing his journey from a teenage game hacker to a respected security professional. Thomp… SecurityWeek · Jun 30, 2026 Medium UKCAhackerred teamingai
threat-intel Attackers Exploit SimpleHelp CVE-2026-48558 to Deploy TaskWeaver and Djinn Stealer An attacker exploited a critical vulnerability (CVE-2026-48558) in SimpleHelp’s OpenID Connect (OIDC) flow to deploy the TaskWeaver and Djinn Stealer malware. This allowed for unauthorized access to authenticated ‘Techni… The Hacker News · Jun 30, 2026 Critical CVE-2026-48558USoidccredential theftai
threat-intel The AI Token Costs That Can Break Cybersecurity This article highlights a growing concern within the cybersecurity industry: the unexpectedly high costs associated with utilizing AI-powered security platforms, particularly those leveraging generative and agentic AI mo… SecurityWeek · Jun 30, 2026 High aitokenizationcost
threat-intel New BioShocking Attack Tricks AI Browsers Into Leaking User Credentials A LayerX security firm discovered a new attack technique, dubbed BioShocking, that exploits AI browsers to trick users into revealing their login credentials. The method involves manipulating the AI browser into believin… The Hacker News · Jun 30, 2026 High N/aiprompt injectioncredential theft
threat-intel Apple Patches 30+ iOS, macOS, Safari Flaws, Including AI-Discovered WebKit Bugs Apple released a significant security update addressing over 30 vulnerabilities across its iOS, macOS, and Safari platforms. Notably, several WebKit vulnerabilities were identified using AI tools, highlighting a new tren… The Hacker News · Jun 30, 2026 Medium CVE-2026-43707CVE-2026-43716CVE-2026-43745webkitaivulnerability
threat-intel 'Djinn' Stealer Targets Cloud, AI Credentials The ‘Djinn’ stealer, delivered via a SimpleHelp vulnerability (CVE-2026-48558), is targeting cloud and AI credentials, specifically focusing on developer and administrator environments. Blackpoint Cyber’s APG tracked an… Dark Reading · Jun 29, 2026 High CVE-2026-48558DKaicredentialsstealer
threat-intel Can Clothes Make You Invisible to Facial Recognition? This Dark Reading article details a research project spearheaded by Bill Swearingen aimed at developing clothing designs to evade facial recognition technology. Swearingen’s approach focuses on exploiting weaknesses in f… Dark Reading · Jun 29, 2026 Medium USfacial recognitionsurveillanceai
malware Malicious Perplexity Chrome Extension Intercepted Searches and Address Bar Input A malicious Chrome extension disguised as the Perplexity AI search engine was discovered by Microsoft, intercepting user searches and address bar input. The extension secretly logged this data by routing it through an at… The Hacker News · Jun 29, 2026 High chromeextensiondata collection
threat-intel ⚡ Weekly Recap: Linux Kernel Flaws, AI Malware Tricks, Turla Backdoor, Infostealers and More This week’s security news highlights several concerning vulnerabilities and attacks, including a DirtyClone Linux kernel flaw, exploitation of PTC Windchill vulnerabilities, and the emergence of new malware like Gaslight… The Hacker News · Jun 29, 2026 High CVE-2026-43503CVE-2026-12569CVE-2026-47729UKRUlinuxkernelai