Every Old Vulnerability Is Now an AI Exploitability
Live threat intelligence feed

Targeted
Threat Intelligence

Aggregated threat intelligence from CISA, NVD, and leading security publications. AI-curated. Updated every 30 minutes.

Threat Matrix — All Time
Vuln
Malware
Intel
Advisory
Breach
APT
Critical
237
75
32
11
14
1
High
145
184
63
21
44
4
Medium
78
82
49
13
44
11
Low
16
21
14
10
Hover to preview · click to filter
All-time · 2295 totalintensity = volume
LIVE
Critical Vulnerabilities Patched in Fortinet, Ivanti Products·Hackers Deploy MLTBackdoor Malware via Multi-Stage ClickFix Infection Chain·Hackers Abuse TikTok and Instagram Reels to Spread Malware via Fake Free Software Tutorials·ICS Patch Tuesday: Vulnerabilities Fixed by Siemens, Schneider, Phoenix Contact·Anthropic Releases Claude Fable 5, Its Most Powerful AI Yet, With Cyber Safeguards·ServiceNow Flaw Exploited to Gain Unauthorized Access to Customer Instances·No Patch Planned for Exploited Arista EOS Vulnerability·Ivanti: Max severity Sentry flaw allows code execution as root·Windows BitLocker 0-Day Vulnerability Allows Attackers to Bypass Security Feature·Microsoft Defender RoguePlanet Zero-Day Grants SYSTEM Access on Updated Windows·Six Proto6 Vulnerabilities in protobuf.js Expose Node.js Apps to RCE and DoS·Anthropic Released Claude Fable 5, the First Model in the Mythos Class·Anthropic Released Claude Fable 5, the First Model in Mythos Class·New Windows Defender 0-Day Exploit “RoguePlanet” Lets Attackers Gain SYSTEM-level Access·New Windows Defender 0-Day Exploit “RoguePlanet” Grants SYSTEM Access to Attackers·Critical Vulnerabilities Patched in Fortinet, Ivanti Products·Hackers Deploy MLTBackdoor Malware via Multi-Stage ClickFix Infection Chain·Hackers Abuse TikTok and Instagram Reels to Spread Malware via Fake Free Software Tutorials·ICS Patch Tuesday: Vulnerabilities Fixed by Siemens, Schneider, Phoenix Contact·Anthropic Releases Claude Fable 5, Its Most Powerful AI Yet, With Cyber Safeguards·ServiceNow Flaw Exploited to Gain Unauthorized Access to Customer Instances·No Patch Planned for Exploited Arista EOS Vulnerability·Ivanti: Max severity Sentry flaw allows code execution as root·Windows BitLocker 0-Day Vulnerability Allows Attackers to Bypass Security Feature·Microsoft Defender RoguePlanet Zero-Day Grants SYSTEM Access on Updated Windows·Six Proto6 Vulnerabilities in protobuf.js Expose Node.js Apps to RCE and DoS·Anthropic Released Claude Fable 5, the First Model in the Mythos Class·Anthropic Released Claude Fable 5, the First Model in Mythos Class·New Windows Defender 0-Day Exploit “RoguePlanet” Lets Attackers Gain SYSTEM-level Access·New Windows Defender 0-Day Exploit “RoguePlanet” Grants SYSTEM Access to Attackers·

Latest IntelligenceApplication SecurityPage 1

Search by keyword →
New “HTTP/2 Bomb” attack can exhaust server memory in seconds
TI
Cyber Insider

New “HTTP/2 Bomb” attack can exhaust server memory in seconds

Researchers have disclosed a new denial-of-service (DoS) technique dubbed HTTP/2 Bomb, a memory-exhaustion attack that can render major web servers inaccessible...

3 Jun 2026
Google “Won’t Fix” API key staying active for 23 mins after deletion
TI
Cyber Insider

Google “Won’t Fix” API key staying active for 23 mins after deletion

Deleted Google API keys remain valid for up to 23 minutes after revocation, potentially allowing attackers to continue accessing Google Cloud services and Gemin...

21 May 2026
Avada Builder WordPress plugin flaws allow site credential theft
TI
Bleeping Computer

Avada Builder WordPress plugin flaws allow site credential theft

Two vulnerabilities in the Avada Builder plugin for WordPress, with an estimated one million active installations, allow hackers to read arbitrary files and ext...

15 May 2026
Frame Security Emerges From Stealth With $50M for Awareness and Training Platform
TI
Security Week

Frame Security Emerges From Stealth With $50M for Awareness and Training Platform

Team8, Index Ventures, Picture Capital, Elad Gil, Cerca Partners, and Tesonet invested in Frame Security. The post Frame Security Emerges From Stealth With $50M...

11 May 2026
Hackers abuse Google ads for GoDaddy ManageWP login phishing
TI
Bleeping Computer

Hackers abuse Google ads for GoDaddy ManageWP login phishing

A phishing campaign delivered through Google sponsored search results is targeting credentials for ManageWP, GoDaddy's platform for managing fleets of WordPress...

6 May 2026
ConsentFix v3 attacks target Azure with automated OAuth abuse
TI
Bleeping Computer

ConsentFix v3 attacks target Azure with automated OAuth abuse

A new attack type, dubbed ConsentFix v3, has been circulating on hacker forums, building on the previous technique by adding automation and scaling potential. [...

2 May 2026
EU’s proposed Google data access rule could enable large-scale surveillance
TI
Cyber Insider

EU’s proposed Google data access rule could enable large-scale surveillance

The European Commission is facing criticism from security and privacy experts over a proposed Digital Markets Act (DMA) measure that would require Google to sha...

27 Apr 2026
Microsoft traces Universal Print issues to Graph API code change
TI
Bleeping Computer

Microsoft traces Universal Print issues to Graph API code change

Microsoft says that an ongoing Universal Print sharing issue that prevents users from creating some printer shares is due to a Microsoft Graph API code change. ...

22 Apr 2026
TI
Security Week

Lawmakers Gathered Quietly to Talk About AI. Angst and Fears of ‘Destruction’ Followed

Thursday’s discussion comes as leaders on Capitol Hill grapple with the dizzying pace of global developments in which technology plays a central role. The post ...

17 Apr 2026
TI
The Hacker News

[Webinar] Find and Eliminate Orphaned Non-Human Identities in Your Environment

In 2024, compromised service accounts and forgotten API keys were behind 68% of cloud breaches. Not phishing. Not weak passwords. Unmanaged non-human identities...

16 Apr 2026
TI
CIS Advisories

Multiple Vulnerabilities in Adobe Products Could Allow for Arbitrary Code Execution

Multiple vulnerabilities have been discovered in Adobe products, the most severe of which could allow for arbitrary code execution.Adobe Acrobat Reader is a fre...

14 Apr 2026
TI
The Hacker News

Backdoored Smart Slider 3 Pro Update Distributed via Compromised Nextend Servers

Unknown threat actors have hijacked the update system for the Smart Slider 3 Pro plugin for WordPress and Joomla to push a poisoned version containing a backdoo...

10 Apr 2026