threat-intel XBOW tests Anthropic's Mythos Preview for offensive security BleepingComputer reports on XBOW’s testing of Anthropic’s Mythos Preview, a new AI model designed for offensive security. The testing revealed that Mythos Preview demonstrates significant advancements in vulnerability de… BleepingComputer · Jun 9, 2026 Medium aivulnerabilitysource code
threat-intel Russian Attackers Weaponize WinRAR Flaw Against Ukrainian Orgs Russian threat actors, including Shadow-Earth-066 (UAC-0226) and Earth Dahu (Primitive Bear, Shuckworm), are continuing to exploit a long-standing vulnerability (CVE-2025-8088) in WinRAR to conduct data theft and cyber e… Dark Reading · Jun 9, 2026 High CVE-2025-8088CVE-2023-38831RUUAwinrarvulnerabilitycyberespionage
threat-intel Claude Mythos Turns N-Days Into N-Hours With Rapid Exploit Creation Anthropic’s Claude Mythos AI model has demonstrated the ability to rapidly generate working exploits for known vulnerabilities in software like Firefox and Windows, significantly accelerating the attack process. The mode… SecurityWeek · Jun 9, 2026 High USaiexploitationn-day
vulnerability Siemens KACO Blueplanet Inverters This advisory from CISA details vulnerabilities within Siemens KACO Blueplanet Inverters, a series of industrial inverters used in energy systems. The vulnerabilities, specifically a CRC16-based algorithm for generating… CISA Advisories · Jun 9, 2026 High CVE-2025-40946CVE-2026-41125WOindustrial control systemsvulnerabilityauthentication
malware Researchers Build Self-Replicating AI Worm That Operates Entirely on Local, Open-Weight Models Researchers at the University of Toronto have developed a novel AI-driven computer worm that operates autonomously by leveraging locally hosted, open-weight large language models. The worm dynamically generates attack st… The Hacker News · Jun 9, 2026 Critical CVE-2026-39987CVE-2026-31431CVE-2026-43284GBaiwormllm
threat-intel Will AI Kill the Bug Bounty Industry? This article discusses the potential disruption of the bug bounty industry by advancements in artificial intelligence, specifically Anthropic’s Claude Mythos model. The rise of AI-powered tools like Claude is enabling bo… SecurityWeek · Jun 9, 2026 Medium aiartificial intelligencebug bounty
vulnerability Check Point links VPN zero-day attacks to Qilin ransomware gang Check Point identified a zero-day vulnerability (CVE-2026-50751) in its Remote Access VPN and Mobile Access deployments, exploited by the Qilin ransomware gang. The flaw allowed unauthenticated attackers to bypass authen… BleepingComputer · Jun 8, 2026 High CVE-2026-50751CVE-2026-50752ISJAAUzero-dayvpnauthentication
threat-intel The Hardest Fork This article discusses a concerning trend in the open-source software ecosystem – the emergence of sophisticated, chained vulnerabilities, potentially driven by actors like Move 37. While the specific 'Mythos' model may… The Hacker News · Jun 8, 2026 High USCHopen sourcevulnerabilitysupply chain
threat-intel Meta Says 20,000 Instagram Accounts Hacked via AI Tool Abuse Meta has reported that approximately 20,000 Instagram accounts were compromised due to abuse of its AI-powered account recovery tool, High Touch Support (HTS). Hackers exploited a vulnerability in the tool to reset passw… SecurityWeek · Jun 8, 2026 High aiaccount recoverypassword reset
data-breach Over 20,000 Instagram accounts stolen in Meta AI support hack Over 20,000 Instagram accounts were compromised due to a vulnerability in Meta’s AI-powered support system, High Touch Support (HTS). Attackers exploited the system to reset passwords, gaining unauthorized access to user… BleepingComputer · Jun 8, 2026 High IEaipasswordaccount takeover
vulnerability Critical Everest Forms Pro flaw exploited to take over WordPress sites A critical vulnerability (CVE-2026-3300) in the Everest Forms Pro WordPress plugin is being actively exploited by attackers to gain complete control over affected websites. This flaw allows for arbitrary code execution,… BleepingComputer · Jun 6, 2026 Critical CVE-2026-3300wordpresspluginvulnerability
threat-intel AI Agent Uncovers 21 Zero-Days in FFmpeg; Chrome Patches Record 429 Bugs This article details a significant surge in vulnerability discovery, driven largely by autonomous AI agents. Depthfirst identified 21 zero-days in FFmpeg using their AI agent, while Google patched 429 bugs in Chrome 149,… The Hacker News · Jun 6, 2026 High CVE-2026-39210CVE-2026-39218CVE-2026-10881USaivulnerabilityzero-day
vulnerability CISA: Hackers now exploit SolarWinds Serv-U flaw to crash servers CISA has issued a warning about hackers actively exploiting a recently patched vulnerability in SolarWinds Serv-U, a file transfer software, to crash servers. This vulnerability, CVE-2026-28318, stems from uncontrolled r… BleepingComputer · Jun 5, 2026 High CVE-2026-28318CVE-2021-35211CVE-2024-28995UNdenial-of-servicepatchingfile transfer
threat-intel OWASP Incubator Project Helps Developers Find and Fix Vulnerable Dependencies in Seconds This article discusses the launch of CVE Lite CLI, an open-source command-line security scanner developed by Sonu Kapoor to address the challenges of managing vulnerabilities within JavaScript and Typescript projects usi… SecurityWeek · Jun 5, 2026 Medium dependency-scanningvulnerabilityjavascript
threat-intel Adaptive, Agentic AI Worms Loom as Next Enterprise Threat This article discusses the emerging threat of adaptive, agentic AI worms, which are designed to autonomously seek out and exploit vulnerabilities in systems, similar to traditional worms but with the added capability of… Dark Reading · Jun 5, 2026 High CAUSaiwormadaptive
threat-intel Threat Brief: Active Exploitation of PAN-OS CVE-2026-0257 Palo Alto Networks Unit 42 has identified active exploitation of CVE-2026-0257, a PAN-OS vulnerability related to GlobalProtect authentication, by an unidentified threat actor. The vulnerability allows unauthorized VPN c… Palo Alto Unit 42 · Jun 5, 2026 High CVE-2026-0257vpnauthenticationvulnerability
ransomware Hackers Exploit Critical Everest Forms Pro WordPress Plugin Flaw to Take Over Sites A critical vulnerability (CVE-2026-3300) in the Everest Forms Pro WordPress plugin has been exploited by threat actors, allowing for remote code execution and potential site compromise. Attackers have been actively targe… The Hacker News · Jun 5, 2026 Critical CVE-2026-3300MDwordpressvulnerabilityremote code execution
vulnerability Cisco warns of unpatched SD-WAN zero-day exploited in attacks Cisco has issued a warning about a previously unknown zero-day vulnerability (CVE-2026-20245) in its Cisco Catalyst SD-WAN Manager software, which is being actively exploited to gain root privileges. The flaw, stemming f… BleepingComputer · Jun 5, 2026 High CVE-2026-20245CVE-2026-20182CVE-2026-20127zero-daysd-wanroot privilege
vulnerability Cisco Warns of 7th SD-WAN Zero-Day Exploited in 2026 Cisco has issued a security advisory regarding a newly discovered zero-day vulnerability (CVE-2026-20245) within its SD-WAN Manager product. This vulnerability, exploitable via command injection, has been actively used b… SecurityWeek · Jun 5, 2026 High CVE-2026-20245CVE-2026-20182CVE-2026-20127zero-daycommand injectionsd-wan
threat-intel 4 Critical Threats Where Attackers Have the Advantage This Dark Reading article highlights four critical cybersecurity threats identified by Gartner: deepfakes, software supply chain risks, prompt injections, and AI application compromises. Gartner analysts contend that cur… Dark Reading · Jun 4, 2026 High deepfakesai securitysupply chain