Every Old Vulnerability Is Now an AI Exploitability
Live threat intelligence feed

Targeted
Threat Intelligence

Aggregated threat intelligence from CISA, NVD, and leading security publications. AI-curated. Updated every 30 minutes.

Threat Matrix — All Time
Vuln
Malware
Intel
Advisory
Breach
APT
Critical
274
90
32
12
17
1
High
165
226
71
23
58
4
Medium
87
94
58
14
63
12
Low
20
22
14
12
Hover to preview · click to filter
All-time · 3529 totalintensity = volume
LIVE
PoC and Technical Details Released for SharePoint Remote Code Execution Vulnerability·Google Dialogflow CX Bug Allowed Attackers to Hijack AI Conversations·DuckDuckGo browser now blocks YouTube video ads·GitHub 'Verified' Commits Can Be Rewritten Into New Hashes Without Breaking Signatures·First-Ever 1- Click Android 17 Exploit Allows Attackers to Gain Full Control Over Your Android Phone·The Verification Step Is the New ATO Battleground in 2026·Telco giant KDDI says data breach affects over 12 million people·GitHub Copilot Refuses Harmful Requests in Chat, Then Writes Them in Code·New Bit2Watt attack uses AI GPU workloads to destabilize power grids·CISA Urges Immediate Patching of Exploited ColdFusion, Langflow, Joomla Flaws·Critical Vulnerability Exposes GitHub Agentic Workflows to Prompt Injection·CISA Warns of Adobe ColdFusion Path Traversal Vulnerability Exploited in Attacks·EU now one step away from reviving private message scanning rules·CISA orders feds to prioritize patching Langflow auth bypass flaw·70% of WordPress Sites Running Outdated PHP Versions Exposed to Cyberattacks·PoC and Technical Details Released for SharePoint Remote Code Execution Vulnerability·Google Dialogflow CX Bug Allowed Attackers to Hijack AI Conversations·DuckDuckGo browser now blocks YouTube video ads·GitHub 'Verified' Commits Can Be Rewritten Into New Hashes Without Breaking Signatures·First-Ever 1- Click Android 17 Exploit Allows Attackers to Gain Full Control Over Your Android Phone·The Verification Step Is the New ATO Battleground in 2026·Telco giant KDDI says data breach affects over 12 million people·GitHub Copilot Refuses Harmful Requests in Chat, Then Writes Them in Code·New Bit2Watt attack uses AI GPU workloads to destabilize power grids·CISA Urges Immediate Patching of Exploited ColdFusion, Langflow, Joomla Flaws·Critical Vulnerability Exposes GitHub Agentic Workflows to Prompt Injection·CISA Warns of Adobe ColdFusion Path Traversal Vulnerability Exploited in Attacks·EU now one step away from reviving private message scanning rules·CISA orders feds to prioritize patching Langflow auth bypass flaw·70% of WordPress Sites Running Outdated PHP Versions Exposed to Cyberattacks·

Latest IntelligenceVulnerabilitiesPage 18

Search by keyword →
Google Gemini CLI Vulnerabilities Allow Attackers to Execute Commands on Host Systems
TI
Cyber Security News

Google Gemini CLI Vulnerabilities Allow Attackers to Execute Commands on Host Systems

A critical remote code execution vulnerability in the Google Gemini CLI and its associated GitHub Action. Assigned a maximum severity score of CVSS 10.0, the fl...

30 Apr 2026
New Linux ‘Copy Fail’ flaw gives hackers root on major distros
TI
Bleeping Computer

New Linux ‘Copy Fail’ flaw gives hackers root on major distros

An exploit has been published for a local privilege escalation vulnerability dubbed "Copy Fail" that impacts Linux kernels released since 2017, allowing an unpr...

30 Apr 2026
Jenkins Patches High-Severity Plugin Flaws Including Path Traversal and Stored XSS
TI
Cyber Security News

Jenkins Patches High-Severity Plugin Flaws Including Path Traversal and Stored XSS

Jenkins project published a security advisory detailing patches for seven plugin vulnerabilities, including high-severity path traversal and Stored Cross-Site S...

30 Apr 2026
“Copy Fail” gives root access to all Linux systems via 732-byte exploit
TI
Cyber Insider

“Copy Fail” gives root access to all Linux systems via 732-byte exploit

A new Linux kernel vulnerability dubbed “Copy Fail” enables unprivileged users to gain root access across nearly all major distributions using a tiny, highly re...

30 Apr 2026
EnOcean SmartServer Flaws Expose Buildings to Remote Hacking
TI
Security Week

EnOcean SmartServer Flaws Expose Buildings to Remote Hacking

Claroty researchers discovered two vulnerabilities that can be exploited for security bypass and remote code execution. The post EnOcean SmartServer Flaws Expos...

30 Apr 2026
Critical cPanel and WHM bug exploited as a zero-day, PoC now available
TI
Bleeping Computer

Critical cPanel and WHM bug exploited as a zero-day, PoC now available

The critical CVE-2026-41940 authentication bypass vulnerability in cPanel, WHM, and WP Squared is being actively exploited in the wild and has been leveraged in...

30 Apr 2026
Critical cPanel & WHM Vulnerability Exploited as Zero-Day for Months
TI
Security Week

Critical cPanel & WHM Vulnerability Exploited as Zero-Day for Months

The authentication bypass flaw allows attackers to gain administrative access to vulnerable servers. The post Critical cPanel & WHM Vulnerability Exploited...

30 Apr 2026
Critical cPanel zero-day auth bypass exploited since February
TI
Cyber Insider

Critical cPanel zero-day auth bypass exploited since February

A critical authentication bypass vulnerability in cPanel & WHM is being actively exploited, allowing remote attackers to gain full administrative access to...

30 Apr 2026
CVE MCP Server Turns Claude Into a Fully Capable Security Analyst With 27 Tools Across 21 APIs
TI
Cyber Security News

CVE MCP Server Turns Claude Into a Fully Capable Security Analyst With 27 Tools Across 21 APIs

A new open-source project called CVE MCP Server is redefining how security teams triage vulnerabilities, transforming Anthropic’s Claude AI into a fully c...

30 Apr 2026
CVE MCP Server Turns Claude Into a Full-Spectrum Security Analyst With 27 Tools Across 21 APIs
TI
Cyber Security News

CVE MCP Server Turns Claude Into a Full-Spectrum Security Analyst With 27 Tools Across 21 APIs

A new open-source project called CVE MCP Server is redefining how security teams triage vulnerabilities, transforming Anthropic’s Claude AI into a fully c...

30 Apr 2026
Qinglong Task Scheduler RCE Vulnerabilities Exploited in the Wild
TI
Cyber Security News

Qinglong Task Scheduler RCE Vulnerabilities Exploited in the Wild

In early 2026, two critical authentication bypass vulnerabilities in the popular open-source Qinglong task scheduler were actively exploited by hackers. Accordi...

30 Apr 2026
ProFTPD’s SQL Injection Vulnerability Enables Remote Code Execution Attacks
TI
Cyber Security News

ProFTPD’s SQL Injection Vulnerability Enables Remote Code Execution Attacks

A critical SQL injection vulnerability in ProFTPD, one of the Internet’s most widely deployed FTP servers. Tracked as CVE-2026-42167, this flaw carries a ...

30 Apr 2026
Europol Busts €50 Million Online Fraud Network Running Corporate-Style Scam Call Centres
TI
Cyber Security News

Europol Busts €50 Million Online Fraud Network Running Corporate-Style Scam Call Centres

A major international law enforcement operation has brought down a large-scale online fraud network that stole more than EUR 50 million from victims across Euro...

30 Apr 2026
cPanel 0-Day Authentication Bypass Vulnerability Actively Exploited in the Wild — PoC Released
TI
Cyber Security News

cPanel 0-Day Authentication Bypass Vulnerability Actively Exploited in the Wild — PoC Released

A critical authentication bypass vulnerability in cPanel & WHM has been confirmed to be actively exploited in the wild, sending shockwaves through the globa...

30 Apr 2026
Cursor AI Extension Access Developer Tokens Leads to Full Credential Compromise
TI
Cyber Security News

Cursor AI Extension Access Developer Tokens Leads to Full Credential Compromise

A high-severity access-control vulnerability (CVSS 8.2) in Cursor, a widely used AI-powered coding environment. The flaw uncovered by LayerX has allowed any ins...

30 Apr 2026
TI
Cyber Security News

Linux Kernel 0-Day “Copy Fail” Roots Every Major Distribution Since 2017

A critical zero-day vulnerability in the Linux kernel has been publicly disclosed, enabling any unprivileged local user to obtain root access on virtually every...

30 Apr 2026
Hackers exploit RCE flaws in Qinglong task scheduler for cryptomining
TI
Bleeping Computer

Hackers exploit RCE flaws in Qinglong task scheduler for cryptomining

Hackers are exploiting two authentication bypass vulnerabilities in the Qinglong open-source task scheduling tool to deploy cryptominers on developers' servers....

29 Apr 2026
TI
Dark Reading

Reverse Engineering With AI Unearths High-Severity GitHub Bug

Wiz used an AI reverse-engineering tool to pinpoint a vulnerability that previously would have been too costly and time-consuming to undertake....

29 Apr 2026
cPanel, WHM emergency update fixes critical auth bypass bug
TI
Bleeping Computer

cPanel, WHM emergency update fixes critical auth bypass bug

A critical vulnerability affecting all but the latest versions of cPanel and the WebHost Manager (WHM) dashboard could be exploited to obtain access to the cont...

29 Apr 2026
Learning from the Vercel breach: Shadow AI & OAuth sprawl
TI
Bleeping Computer

Learning from the Vercel breach: Shadow AI & OAuth sprawl

A single third-party OAuth integration can become a direct path into your environment. Push explains how the Vercel breach shows a compromised OAuth app can lea...

29 Apr 2026
← PreviousNext →