Every Old Vulnerability Is Now an AI Exploitability
Live threat intelligence feed

Targeted
Threat Intelligence

Aggregated threat intelligence from CISA, NVD, and leading security publications. AI-curated. Updated every 30 minutes.

Threat Matrix — All Time
Vuln
Malware
Intel
Advisory
Breach
APT
Critical
237
75
32
11
14
1
High
145
184
63
21
44
4
Medium
78
82
49
13
44
11
Low
16
21
14
10
Hover to preview · click to filter
All-time · 2295 totalintensity = volume
LIVE
Critical Vulnerabilities Patched in Fortinet, Ivanti Products·Hackers Deploy MLTBackdoor Malware via Multi-Stage ClickFix Infection Chain·Hackers Abuse TikTok and Instagram Reels to Spread Malware via Fake Free Software Tutorials·ICS Patch Tuesday: Vulnerabilities Fixed by Siemens, Schneider, Phoenix Contact·Anthropic Releases Claude Fable 5, Its Most Powerful AI Yet, With Cyber Safeguards·ServiceNow Flaw Exploited to Gain Unauthorized Access to Customer Instances·No Patch Planned for Exploited Arista EOS Vulnerability·Ivanti: Max severity Sentry flaw allows code execution as root·Windows BitLocker 0-Day Vulnerability Allows Attackers to Bypass Security Feature·Microsoft Defender RoguePlanet Zero-Day Grants SYSTEM Access on Updated Windows·Six Proto6 Vulnerabilities in protobuf.js Expose Node.js Apps to RCE and DoS·Anthropic Released Claude Fable 5, the First Model in the Mythos Class·Anthropic Released Claude Fable 5, the First Model in Mythos Class·New Windows Defender 0-Day Exploit “RoguePlanet” Lets Attackers Gain SYSTEM-level Access·New Windows Defender 0-Day Exploit “RoguePlanet” Grants SYSTEM Access to Attackers·Critical Vulnerabilities Patched in Fortinet, Ivanti Products·Hackers Deploy MLTBackdoor Malware via Multi-Stage ClickFix Infection Chain·Hackers Abuse TikTok and Instagram Reels to Spread Malware via Fake Free Software Tutorials·ICS Patch Tuesday: Vulnerabilities Fixed by Siemens, Schneider, Phoenix Contact·Anthropic Releases Claude Fable 5, Its Most Powerful AI Yet, With Cyber Safeguards·ServiceNow Flaw Exploited to Gain Unauthorized Access to Customer Instances·No Patch Planned for Exploited Arista EOS Vulnerability·Ivanti: Max severity Sentry flaw allows code execution as root·Windows BitLocker 0-Day Vulnerability Allows Attackers to Bypass Security Feature·Microsoft Defender RoguePlanet Zero-Day Grants SYSTEM Access on Updated Windows·Six Proto6 Vulnerabilities in protobuf.js Expose Node.js Apps to RCE and DoS·Anthropic Released Claude Fable 5, the First Model in the Mythos Class·Anthropic Released Claude Fable 5, the First Model in Mythos Class·New Windows Defender 0-Day Exploit “RoguePlanet” Lets Attackers Gain SYSTEM-level Access·New Windows Defender 0-Day Exploit “RoguePlanet” Grants SYSTEM Access to Attackers·

Latest IntelligenceData BreachesPage 2

Search by keyword →
Telegram’s MTProto protocol leaks persistent identifiers enabling user tracking
TI
Cyber Insider

Telegram’s MTProto protocol leaks persistent identifiers enabling user tracking

A newly published technical review of Telegram’s MTProto protocol warns that the messaging platform exposes persistent device identifiers to passive network obs...

22 May 2026
McDonald’s France resets accounts after customer data breach
TI
Cyber Insider

McDonald’s France resets accounts after customer data breach

McDonald’s France has confirmed that attackers accessed customer loyalty account information after a breach affecting partners tied to its McDo+ rewards program...

22 May 2026
Google accidentally exposed details of unfixed Chromium flaw
TI
Bleeping Computer

Google accidentally exposed details of unfixed Chromium flaw

Google has accidentally leaked details about an unfixed issue in Chromium that keeps JavaScript running in the background even when the browser is closed, allow...

21 May 2026
GitHub links repo breach to TanStack npm supply-chain attack
TI
Bleeping Computer

GitHub links repo breach to TanStack npm supply-chain attack

GitHub says the hackers who breached 3,800 internal repositories gained access via a malicious version of the Nx Console VS Code extension, compromised in last ...

21 May 2026
Grafana breach caused by missed token rotation after TanStack attack
TI
Bleeping Computer

Grafana breach caused by missed token rotation after TanStack attack

The Grafana data breach was caused by a single GitHub workflow token that slipped through the rotation process following the TanStack npm supply-chain attack la...

20 May 2026
GitHub confirms internal repository theft as TeamPCP claims attack
TI
Cyber Insider

GitHub confirms internal repository theft as TeamPCP claims attack

GitHub disclosed that it is investigating unauthorized access to its internal repositories after attackers compromised an employee's device through a malicious ...

20 May 2026
GitHub confirms breach of 3,800 repos via malicious VSCode extension
TI
Bleeping Computer

GitHub confirms breach of 3,800 repos via malicious VSCode extension

GitHub has confirmed that roughly 3,800 internal repositories were breached after one of its employees installed a malicious VS Code extension. [...]...

20 May 2026
GitHub investigates internal repositories breach claimed by TeamPCP
TI
Bleeping Computer

GitHub investigates internal repositories breach claimed by TeamPCP

GitHub is investigating a breach of its internal repositories after the TeamPCP hacker group claimed to have accessed approximately 4,000 repositories containin...

20 May 2026
Grafana says stolen GitHub token let hackers steal codebase
TI
Bleeping Computer

Grafana says stolen GitHub token let hackers steal codebase

Grafana Labs disclosed that hackers have downloaded its source code after breaching its GitHub environment using a stolen access token. [...]...

18 May 2026
OpenAI confirms security breach in TanStack supply chain attack
TI
Bleeping Computer

OpenAI confirms security breach in TanStack supply chain attack

OpenAI says two employees' devices were breached in the recent TanStack supply chain attack that impacted hundreds of npm and PyPI packages, causing the company...

14 May 2026
Cyber-Enabled Cargo Crime: How Cybercrime Tradecraft is Used to Steal Freight
TI
Bleeping Computer

Cyber-Enabled Cargo Crime: How Cybercrime Tradecraft is Used to Steal Freight

Cargo theft now starts with phishing emails and stolen credentials, not hijackings, to reroute and steal freight from supply chains. NMFTA outlines how cyber-en...

14 May 2026
TI
Cyber Security News

Packagist Urges Immediate Composer Update After GitHub Actions Token Leak

Packagist is sounding the alarm for PHP developers everywhere. A flaw in Composer, the widely used PHP dependency manager, briefly caused GitHub authentication ...

14 May 2026
Foxconn Confirms Cyberattack After Nitrogen Ransomware Gang Claim
TI
Cyber Security News

Foxconn Confirms Cyberattack After Nitrogen Ransomware Gang Claim

Foxconn has officially confirmed a cyberattack targeting its North American operations after the Nitrogen ransomware gang publicly listed the company on its dat...

13 May 2026
Government to Scrutinize Instructure Over Canvas Disruption, Data Breach
TI
Security Week

Government to Scrutinize Instructure Over Canvas Disruption, Data Breach

The Committee on Homeland Security has requested to be briefed on the incident and Instructure’s remediation steps. The post Government to Scrutinize Instructur...

13 May 2026
Škoda warns of customer data breach after online shop hack
TI
Bleeping Computer

Škoda warns of customer data breach after online shop hack

Škoda Auto, a wholly owned subsidiary of the Volkswagen Group, has disclosed a data breach after attackers hacked its online shop and stole the personal informa...

12 May 2026
Mullvad shares workaround for Android 16 VPN leak that remains unfixed
TI
Cyber Insider

Mullvad shares workaround for Android 16 VPN leak that remains unfixed

Mullvad has warned that a recently disclosed Android 16 flaw can allow malicious applications to bypass VPN protections and leak a device’s real IP address, eve...

12 May 2026
Canvas owner reaches agreement with ShinyHunters, says user data was deleted
TI
Cyber Insider

Canvas owner reaches agreement with ShinyHunters, says user data was deleted

Instructure says it reached an agreement with the threat actors behind the recent cyberattack targeting its Canvas learning platform. The company stated that st...

12 May 2026
Instructure reaches 'agreement' with ShinyHunters to stop data leak
TI
Bleeping Computer

Instructure reaches 'agreement' with ShinyHunters to stop data leak

Instructure, the edtech giant behind the widely popular Canvas learning management system (LMS), has reached an "agreement" with the ShinyHunters extortion grou...

12 May 2026
Why Changing Passwords Doesn’t End an Active Directory Breach
TI
Bleeping Computer

Why Changing Passwords Doesn’t End an Active Directory Breach

Resetting a password doesn't always remove attackers from Active Directory. Specops Software explains how cached credentials and Kerberos tickets can keep attac...

11 May 2026
ShinyHunters Breaches Instructure Canvas LMS Through Free-For-Teacher Account Program
TI
Cyber Security News

ShinyHunters Breaches Instructure Canvas LMS Through Free-For-Teacher Account Program

The infamous hacking group ShinyHunters has struck again, this time targeting Instructure, the company behind Canvas Learning Management System (LMS). In early ...

11 May 2026
← PreviousNext →