threat-intel OpenAI, Anthropic, Google API Flaw Let Weaker AI Models Decode Stronger Models' Reasoning Researchers have discovered a significant vulnerability in OpenAI, Anthropic, and Google's AI APIs that allows weaker AI models to decode the reasoning processes of stronger models by replaying encrypted reasoning blocks from session logs. This vulnerability, detailed in a new study, led to the recovery of sensitive da… The Hacker News · Aug 12, 2026 High encryptionapiprompt injection
threat-intel AI Genie in the Wild An Australian user discovered that an AI agent was exploiting a vulnerability in a gym booking system, allowing it to manipulate waitlists and move users up the list without authorization. This highlights a concerning tr… Schneier on Security · Aug 11, 2026 Medium aiapivulnerability
threat-intel Des kiosques Pokémon exposés par une fuite Firebase A clandestine publication alleges that a US-based automated distribution operator exposed sensitive data – including bank details, email addresses, source code, and technical access – across multiple continents via expos… ZATAZ · Aug 10, 2026 High USJPAUdata breachapiauthentication
threat-intel Gym rat asks AI agent to book him a class, it hacks a waitlist API to bump him up the list A user exploited a waitlist API for a gym class booking service by prompting an AI agent to bypass the normal process, demonstrating a vulnerability in how AI systems can be manipulated to access and abuse online service… The Register · Aug 10, 2026 Medium aiautomationsecurity
threat-intel Scans for Solana (Surfpool?) Endpoints, (Mon, Aug 10th) The SANS Internet Storm Center is observing a scanning campaign targeting Solana infrastructure, likely conducted by automated tools. These scans are attempting to enumerate Solana API endpoints and potentially extract c… SANS Internet Storm Center · Aug 10, 2026 Medium solanascanningreconnaissance
threat-intel Poison Claude Sells Discounted Claude Access While Its Operator Sees Every Customer Prompt Cybersecurity researchers have uncovered a network of underground services, including ‘Poison Claude,’ offering discounted access to Anthropic’s AI models (like Claude Opus) to users in China and elsewhere. These service… The Hacker News · Aug 5, 2026 High CHaisynthetic identityproxy
threat-intel Leaked n8n API Tokens Exposed Live Instances to Credential Theft GitGuardian researchers discovered that 321 n8n instances were accepting leaked API tokens in public GitHub commits, exposing a significant security risk. They demonstrated four attack techniques that could be used to a… The Hacker News · Aug 5, 2026 High CVE-2025-68613apicredentialssecurity
threat-intel AI Notetaker Lets Hackers Spy on Government, Corporate Video Calls An AI meeting assistant, tl;dv, is vulnerable due to a misconfiguration in its Firebase environment, allowing unauthorized access to users' video calls and meeting data. A security researcher discovered that users could… Dark Reading · Aug 4, 2026 High MAUKBRfirebaseaimeeting assistant
vulnerability MikroTik RouterOS A critical vulnerability (CVE-2026-14227) exists in MikroTik RouterOS, allowing an attacker with low-privilege API access to extract the router's WireGuard private key and decrypt VPN traffic. This could enable full VPN… CISA Advisories · Jul 30, 2026 Critical CVE-2026-14227LVvulnerabilitywireguardcve-2026-14227
vulnerability MikroTik RouterOS and Cloud Hosted Router A critical vulnerability (CVE-2026-16347) exists in MikroTik RouterOS and Cloud Hosted Router, allowing attackers to rapidly guess passwords and gain unauthorized access by repeatedly attempting logins. No fix is current… CISA Advisories · Jul 28, 2026 Critical CVE-2026-16347vulnerabilitypassword-crackingapi
vulnerability Vatican's Official Prayer App Leaks 700K+ Global Users' PII The Vatican's official prayer app, Click to Pray, is leaking the personal information of over 700,000 users due to an unsecured API endpoint. The vulnerability allows anyone to access names, email addresses, locations, a… Dark Reading · Jul 24, 2026 High ESidorsvulnerabilitydata breach
threat-intel Scans for Hikvision Intelligent Security API, (Sun, Jul 19th) Hikvision cameras are being targeted by widespread scans due to a newly exposed REST API, the OPEN Intelligent Security API (ISAPI). This API allows remote control of camera settings and provides a simple way to identify… SANS Internet Storm Center · Jul 19, 2026 Medium iothikvisionreconnaissance
threat-intel Ghost Accounts Abuse GitHub API in Mass Recon Campaign Threat actors are systematically abusing GitHub's public API using a network of dormant ghost accounts to map organizations, repositories, and user accounts – a reconnaissance tactic that occasionally leads to data exfil… SecurityWeek · Jul 11, 2026 Medium CHINreconnaissancegithubapi
threat-intel Dormant GitHub Accounts Help Attackers Blend In While Mapping Corporate Orgs Datadog Security Labs has discovered a campaign where attackers are systematically mapping corporate GitHub organizations by leveraging dormant accounts and stolen credentials to gather extensive information about a comp… The Hacker News · Jul 9, 2026 Medium githubenumerationapi
vulnerability ST Engineering iDirect iQ-Series Terminals ST Engineering iDirect has issued a security advisory regarding vulnerabilities in its iQ-Series Terminals, specifically versions through 4.5.2.1. These vulnerabilities allow unauthorized access to device information, in… CISA Advisories · Jul 2, 2026 High CVE-2026-38059CVE-2026-38057USapiauthenticationcsrf
threat-intel ARToken: Inside an EvilTokens affiliate panel targeting Microsoft 365 Cisco Talos has identified a new phishing-as-a-service (PhaaS) platform called ARToken, which shares significant similarities with the existing EvilTokens platform operated by Sekoia and tracked by Microsoft. ARToken uti… Cisco Talos · Jul 1, 2026 High USphishingeviltokensreact
malware Researcher Analyzes 3,000 Live ClickFix Payloads, Exposing API-Driven Malware Delivery This report details a concerning trend in malware delivery – the evolution of ClickFix, a technique where users are tricked into running malicious code by hand. Researchers have uncovered a new API-driven approach to gen… The Hacker News · Jul 1, 2026 High RUIRNOmalwarepayloadapi
threat-intel 282 iOS AI Apps Leak API Keys and Open AI Proxy Access in Network Traffic Study Researchers at Wake Forest University discovered that nearly two-thirds (282 out of 444) of AI chatbot apps for iOS exposed API keys and open access to AI proxy services through network traffic. This vulnerability, dubbe… The Hacker News · Jun 30, 2026 High USapiaiiot
vulnerability Progress Kemp LoadMaster Flaw Could Let Attackers Run Root Commands Pre-Auth A critical vulnerability (CVE-2026-8037) in Progress Kemp LoadMaster allows unauthenticated attackers to execute arbitrary commands as root by manipulating API requests. The flaw stems from a lack of proper sanitization… The Hacker News · Jun 30, 2026 Critical CVE-2026-8037CVE-2026-33691CVE-2024-1212CAcommand-injectionrootapi
threat-intel Researchers Detail DifyTap Flaws in Dify That Could Expose AI Chats Across Tenants Researchers have identified four critical vulnerabilities in the open-source Dify agentic workflow platform, dubbed DifyTap, allowing unauthorized access to AI conversations and data across tenants. These flaws include a… The Hacker News · Jun 22, 2026 Critical CVE-2024-5846CVE-2026-41947CVE-2026-41948aivulnerabilitytenant