Every Old Vulnerability Is Now an AI Exploitability
Live threat intelligence feed

Targeted
Threat Intelligence

Aggregated threat intelligence from CISA, NVD, and leading security publications. AI-curated. Updated every 30 minutes.

Threat Matrix — All Time
Vuln
Malware
Intel
Advisory
Breach
APT
Critical
376
119
40
16
30
1
High
227
309
82
24
93
7
Medium
118
142
70
17
98
14
Low
24
31
21
—
14
—
Hover to preview · click to filter
All-time · 6526 totalintensity = volume
LIVE
Top 10 Best Patch Management Software in 2026·Top 10 Best Mobile Threat Defense (MTD) Solutions in 2026·Hackers Turn More Than 3,500 Redis Servers Into Cryptocurrency Miners·Top 10 Best Mobile Device Management (MDM) Solutions in 2026·Top 10 Best Unified Endpoint Management (UEM) Solutions in 2026·New Microsoft Defender 'ShieldCrash' zero-day grants SYSTEM access·Google warns of new Chrome zero-day bug exploited in attacks·Chrome 153 Fixes 230 Vulnerabilities, Including One 0-Day Exploited in the Wild·Microsoft Patches Record 974 Flaws, Including Two Exploited Windows Zero-Days·N-able N-central Pre-Auth RCE Flaw Exploited in the Wild·FortiSandbox Vulnerability Allows Attackers to Access Sensitive Information via Crafted HTTP Requests·Microsoft adds age-awareness APIs that can tell if users are children, teens, or adults·Patch Tuesday Sets Another Record With 974 CVEs·Attackers Use Multi-Hop Google Redirects for Phishing Campaign·OpenAI Agents Took Over Wiki Site Before Hugging Face Attack·Top 10 Best Patch Management Software in 2026·Top 10 Best Mobile Threat Defense (MTD) Solutions in 2026·Hackers Turn More Than 3,500 Redis Servers Into Cryptocurrency Miners·Top 10 Best Mobile Device Management (MDM) Solutions in 2026·Top 10 Best Unified Endpoint Management (UEM) Solutions in 2026·New Microsoft Defender 'ShieldCrash' zero-day grants SYSTEM access·Google warns of new Chrome zero-day bug exploited in attacks·Chrome 153 Fixes 230 Vulnerabilities, Including One 0-Day Exploited in the Wild·Microsoft Patches Record 974 Flaws, Including Two Exploited Windows Zero-Days·N-able N-central Pre-Auth RCE Flaw Exploited in the Wild·FortiSandbox Vulnerability Allows Attackers to Access Sensitive Information via Crafted HTTP Requests·Microsoft adds age-awareness APIs that can tell if users are children, teens, or adults·Patch Tuesday Sets Another Record With 974 CVEs·Attackers Use Multi-Hop Google Redirects for Phishing Campaign·OpenAI Agents Took Over Wiki Site Before Hugging Face Attack·

Latest IntelligenceSocial EngineeringPage 1

Search by keyword →
BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations
TI
Bleeping Computer

BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations

A phishing-as-a-service framework called BigBear 2.0 has been used to bypass multi-factor authentication at 258 organizations and steal more than 5,000 Microsof...

7 Sept 2026
How MSPs can catch phishing attacks email filters miss
TI
Bleeping Computer

How MSPs can catch phishing attacks email filters miss

AI is making phishing attacks more personalized, convincing, and difficult for traditional email filters to detect. Kaseya explains how MSPs can monitor identit...

20 Aug 2026
When Credentials Are No Longer Enough: Device Trust in the AI Era
TI
Bleeping Computer

When Credentials Are No Longer Enough: Device Trust in the AI Era

AI is making phishing, credential theft, and social engineering faster and more efficient, while traditional trust signals such as passwords, MFA, IP reputation...

10 Aug 2026
Phishing service spoofs RingCentral to steal Microsoft 365 accounts
TI
Bleeping Computer

Phishing service spoofs RingCentral to steal Microsoft 365 accounts

The Greatness phishing-as-a-service (PhaaS) platform has expanded from credential phishing to adversary-in-the-middle attacks and device-code phishing targeting...

4 Aug 2026
Your AI Agents Are Guessing at Scale: Permissions Decide the Damage
TI
Bleeping Computer

Your AI Agents Are Guessing at Scale: Permissions Decide the Damage

AI agents are designed to improvise as they complete tasks, making broad permissions a growing security risk. Token Security explains why identity, intent-based...

29 Jul 2026
Is Your SSO Protected Against Modern Credential Attacks?
TI
Bleeping Computer

Is Your SSO Protected Against Modern Credential Attacks?

A compromised SSO login can provide attackers with access to multiple enterprise applications and services. Specops Software explains how stronger passwords, ph...

28 Jul 2026
Mozilla study ranks Euki as the most private period tracker
TI
Cyber Insider

Mozilla study ranks Euki as the most private period tracker

A Mozilla privacy investigation into six popular period-tracking apps found that some services expose device identifiers, usage details, or sensitive logs to an...

17 Jul 2026
Spanish Police take down €140 million cyber fraud ring, arrest four
TI
Bleeping Computer

Spanish Police take down €140 million cyber fraud ring, arrest four

The Spanish Police dismantled a cybercrime and money-laundering organization that made €140 million ($160 million) from investment fraud and business email comp...

14 Jul 2026
Microsoft Entra ID gets passkeys default authentication starting September
TI
Bleeping Computer

Microsoft Entra ID gets passkeys default authentication starting September

Microsoft has announced that passkeys will become the default authentication method for the Entra ID enterprise identity service starting September 2026. [...]...

14 Jul 2026
New phishing kits target Microsoft 365 accounts, evade MFA
TI
Bleeping Computer

New phishing kits target Microsoft 365 accounts, evade MFA

Two new phishing kits, Jalisco and OmegaLord, have been discovered in attacks targeting Microsoft 365 accounts, using techniques that defeat multi-factor authen...

14 Jul 2026
New Helix vishing group emerges in SharePoint data theft attacks
TI
Bleeping Computer

New Helix vishing group emerges in SharePoint data theft attacks

A new data-extortion group called Helix is using identity-focused tactics such as voice phishing (vishing), device code phishing, and multi-factor authenticatio...

9 Jul 2026
Entra passkey enrollment vishing targets Microsoft 365 users
TI
Bleeping Computer

Entra passkey enrollment vishing targets Microsoft 365 users

A threat actor has been targeting organizations across multiple sectors with voice-based fake security requests that ask Microsoft 365 users to enroll a new Ent...

8 Jul 2026
Phishing poses as big-brand job interview to steal Google accounts
TI
Bleeping Computer

Phishing poses as big-brand job interview to steal Google accounts

A phishing campaign is impersonating more than 30 well-known brands, including Adobe, Netflix, Coca-Cola, and OpenAI, in fake job interviews to steal Google acc...

6 Jul 2026
Agentic AI Has an Identity Problem and Attackers Know It
TI
Bleeping Computer

Agentic AI Has an Identity Problem and Attackers Know It

AI agents can access data, trigger workflows, and take action across enterprise systems. Token Security explains why governing these privileged identities is be...

29 Jun 2026
Order-tracking app Shop abused to push callback phishing attacks
TI
Bleeping Computer

Order-tracking app Shop abused to push callback phishing attacks

Threat actors are increasingly abusing Shop, the order-tracking app from Shopify, by adding fake purchase receipts in users' order histories to trick them into ...

25 Jun 2026
Webinar: Why email security teams are drowning in alerts
TI
Bleeping Computer

Webinar: Why email security teams are drowning in alerts

Phishing, BEC, and account takeover attacks continue to overwhelm security teams with alerts and investigations. This webinar explores how behavioral AI can hel...

23 Jun 2026
Every AI Agent Is an Identity. Most Organizations Don't Treat Them That Way
TI
Bleeping Computer

Every AI Agent Is an Identity. Most Organizations Don't Treat Them That Way

AI agents can access data, trigger workflows, deploy code, and interact with critical business systems, often with little oversight. Token Security breaks down ...

19 Jun 2026
Why Account Takeovers Are Rising and How to Stop Them
TI
Bleeping Computer

Why Account Takeovers Are Rising and How to Stop Them

Account takeovers are rising as attackers bypass traditional defenses through phishing, session hijacking, and MFA fatigue. Specops Software explores how device...

17 Jun 2026
Webinar: How behavioral AI stops phishing and account takeovers
TI
Bleeping Computer

Webinar: How behavioral AI stops phishing and account takeovers

Modern phishing, BEC, and account takeover attacks increasingly bypass traditional email defenses and create operational strain for security teams. This webinar...

15 Jun 2026
The 5 Best Practices for Secure Identity Verification
TI
Bleeping Computer

The 5 Best Practices for Secure Identity Verification

Attackers are increasingly bypassing weak authentication through phishing, MFA fatigue, and service desk social engineering. Specops Software breaks down five b...

10 Jun 2026
Next →