threat-intel Choose your fighter: Balancing competing requirements to select models for your AI SOC Cisco Talos conducted a comprehensive study to determine the best Large Language Model (LLM) for Security Operations Center (SOC) and Digital Forensics & Incident Response (DFIR) tasks, moving beyond simply identifying t… Cisco Talos · 4d ago High llmsocdfir
threat-intel Exploits and vulnerabilities in Q2 2026 Q2 2026 saw a significant surge in the number of registered vulnerabilities, largely driven by the increasing adoption of AI tools for vulnerability discovery. Researchers are now publishing exploits for vulnerabilities… Securelist · 4d ago High CVE-2018-0802CVE-2017-11882CVE-2017-0199vulnerabilitythreat-intelapt
vulnerability Chrome 152 Patches Over 300 Vulnerabilities Google released Chrome 152, addressing over 300 vulnerabilities, a significant portion of which were identified using internal AI. This update represents a substantial increase in patching activity for Chrome this year,… SecurityWeek · 4d ago High CVE-2026-79282chromevulnerabilitypatch
threat-intel OpenAI Bans Russian ChatGPT Accounts Used to Run Influence Operation OpenAI has banned a cluster of Russian ChatGPT accounts that were used to run an influence operation, primarily to promote the International Burke Institute (IBI) and its associated website. The operation involved genera… The Hacker News · 4d ago High RUUNCHinfluence operationai manipulationrussian disinformation
threat-intel Interpol's Jackal IV Disrupts West African Crime Infrastructure Interpol's Jackal IV operation successfully disrupted West African crime infrastructure networks involved in various cybercrime activities, including business email compromise, romance scams, and money laundering. The op… Dark Reading · 4d ago High ARAUCAcybercrimefraudmoney laundering
threat-intel INTERPOL Operation Jackal IV Arrests 58, Identifies 263 in Global Cyber Fraud Crackdown INTERPOL’s fourth iteration of Operation Jackal has resulted in the arrest of 58 individuals and the identification of 263 suspects globally, targeting West African organized crime groups involved in cyber fraud, includi… The Hacker News · 4d ago High AUARBEcybercrimefraudmoney laundering
threat-intel Newly SLEEPWALKER Backdoor Waits for One Crafted Packet, Then Runs Its Own Bytecode A previously unreported Windows backdoor, dubbed SLEEPWALKER, has been identified by a malware researcher. The backdoor remains dormant until a specific crafted network packet is received, at which point it executes a cu… The Hacker News · 4d ago High backdoorside-loadingvmci
threat-intel Fake Apple Support AI Calls Target Stolen-Device Owners for Passcodes and 2FA Codes A sophisticated phishing-as-a-service platform, dubbed AnonyMousKIT, is being used to target stolen Apple devices and trick owners into providing their passcodes and 2FA codes, enabling Activation Lock removal. Operated… The Hacker News · 4d ago High ZABRUSphishingactivation lock2fa
threat-intel Hidden Prompts Trick AI Into False Email Summaries Researchers at Forcepoint X-Labs demonstrated how attackers can manipulate AI-powered email summarizers by embedding malicious prompts within seemingly normal emails. The AI then generated false and altered summaries, hi… Dark Reading · 5d ago High prompt injectionai securityhtml injection
threat-intel 58 arrested in international cybercrime crackdown Interpol and law enforcement agencies across 22 countries concluded Operation Jackal IV, resulting in the arrest of 58 individuals involved in a coordinated cybercrime operation. The operation targeted a crime-as-a-servi… The Record · 5d ago High ARITROcybercrimeromance scamsmoney laundering
vulnerability Finding Nemo(Claw): Networking Issue Allows for LLM Poisoning in OpenClaw A vulnerability in NVIDIA's NemoClaw tool, used for deploying AI agents with OpenClaw, allows unauthenticated attackers to poison a large language model's chat template and corrupt the AI agents using it. The issue stems… Dark Reading · 5d ago High aiagentdns rebinding
threat-intel U.S. Sanctions Iran-Linked Hackers Behind Critical Infrastructure Breaches The U.S. Treasury has imposed fresh sanctions on nearly 60 Iran-linked entities, including individuals and vessels, as part of "Operation Economic Outcast." These sanctions target a cyber group affiliated with Iran's Min… The Hacker News · 5d ago High IRUKsanctionscyber espionagecritical infrastructure
vulnerability You could've applied all 1,449 Oracle patches and still been hit by this attack A zero-day vulnerability in on-prem SharePoint, stemming from improperly applied patches, is being exploited by attackers. Despite applying 1,449 Oracle patches, attackers successfully leveraged this flaw to gain unautho… The Register · 5d ago High UNzero-dayvulnerabilitysharepoint
threat-intel Is Cyber Facing an Affordability Crisis? The cybersecurity industry is facing an ‘affordability crisis’ driven by rapidly rising breach costs and defense spending, disproportionately impacting small and medium-sized businesses (SMBs) who often lack the resource… Dark Reading · 5d ago High cybersecurityaffordabilitysmb
vulnerability A Malicious Webpage Could Poison Your Local AI Model Behind NVIDIA NemoClaw A vulnerability in NVIDIA NemoClaw allows an attacker to poison an AI model by serving a malicious webpage that can inject hidden instructions into every conversation. The vulnerability stems from a misconfigured Ollama… The Hacker News · 5d ago High CVE-2024-28224aimodel poisoningdns rebinding
vulnerability WordPress Websites Targeted via MiniOrange Plugin Vulnerabilities Threat actors are actively exploiting two recently patched vulnerabilities within the MiniOrange SAML 2.0 Single Sign-On plugin for WordPress websites. These vulnerabilities allow attackers to bypass authentication and g… SecurityWeek · 5d ago High CVE-2026-61979CVE-2026-15981wordpressvulnerabilityauthentication
threat-intel UK government seeks powers to secretly block risky tech suppliers The UK government is seeking new powers to secretly block technology suppliers deemed to pose a national security risk, particularly to critical sectors like energy, water, and transport. These powers, modeled after thos… The Record · 5d ago High UKnational securitycybersecurityvendor risk
vulnerability Marimo Notebook Flaw Could Run MCP Commands Before Cells Execute in Edit Mode A high-severity vulnerability (CVE-2026-75149) in Marimo notebook software allows an attacker to execute arbitrary commands by crafting a malicious notebook file. The vulnerability is addressed in version 0.23.15 and req… The Hacker News · 5d ago High CVE-2026-75149CVE-2026-67618CVE-2026-39987code injectionnotebookmcp
vulnerability Ebyte NE2-D11 A CISA advisory highlights critical vulnerabilities in Ebyte NE2-D11 devices, primarily due to a lack of consistent authentication enforcement and cleartext transmission of sensitive information. The vendor, Ebyte, has n… CISA Advisories · 5d ago High CVE-2026-73125CVE-2026-73809CVE-2026-73839CHvulnerabilityauthenticationencryption
threat-intel A Tale of Two SOCs: Insights From Two Red Team Assessments Two separate red team assessments at a Government Services and Facilities Sector organization (Organization A) and a Water and Wastewater Systems Sector organization (Organization B) revealed significant vulnerabilities… CISA Advisories · 5d ago High credential abuseactive directorymicrosoft