Every Old Vulnerability Is Now an AI Exploitability
Live threat intelligence feed

Targeted
Threat Intelligence

Aggregated threat intelligence from CISA, NVD, and leading security publications. AI-curated. Updated every 30 minutes.

Threat Matrix — All Time
Vuln
Malware
Intel
Advisory
Breach
APT
Critical
274
90
32
12
17
1
High
165
226
71
23
58
4
Medium
87
94
58
14
63
12
Low
20
22
14
12
Hover to preview · click to filter
All-time · 3529 totalintensity = volume
LIVE
PoC and Technical Details Released for SharePoint Remote Code Execution Vulnerability·Google Dialogflow CX Bug Allowed Attackers to Hijack AI Conversations·DuckDuckGo browser now blocks YouTube video ads·GitHub 'Verified' Commits Can Be Rewritten Into New Hashes Without Breaking Signatures·First-Ever 1- Click Android 17 Exploit Allows Attackers to Gain Full Control Over Your Android Phone·The Verification Step Is the New ATO Battleground in 2026·Telco giant KDDI says data breach affects over 12 million people·GitHub Copilot Refuses Harmful Requests in Chat, Then Writes Them in Code·New Bit2Watt attack uses AI GPU workloads to destabilize power grids·CISA Urges Immediate Patching of Exploited ColdFusion, Langflow, Joomla Flaws·Critical Vulnerability Exposes GitHub Agentic Workflows to Prompt Injection·CISA Warns of Adobe ColdFusion Path Traversal Vulnerability Exploited in Attacks·EU now one step away from reviving private message scanning rules·CISA orders feds to prioritize patching Langflow auth bypass flaw·70% of WordPress Sites Running Outdated PHP Versions Exposed to Cyberattacks·PoC and Technical Details Released for SharePoint Remote Code Execution Vulnerability·Google Dialogflow CX Bug Allowed Attackers to Hijack AI Conversations·DuckDuckGo browser now blocks YouTube video ads·GitHub 'Verified' Commits Can Be Rewritten Into New Hashes Without Breaking Signatures·First-Ever 1- Click Android 17 Exploit Allows Attackers to Gain Full Control Over Your Android Phone·The Verification Step Is the New ATO Battleground in 2026·Telco giant KDDI says data breach affects over 12 million people·GitHub Copilot Refuses Harmful Requests in Chat, Then Writes Them in Code·New Bit2Watt attack uses AI GPU workloads to destabilize power grids·CISA Urges Immediate Patching of Exploited ColdFusion, Langflow, Joomla Flaws·Critical Vulnerability Exposes GitHub Agentic Workflows to Prompt Injection·CISA Warns of Adobe ColdFusion Path Traversal Vulnerability Exploited in Attacks·EU now one step away from reviving private message scanning rules·CISA orders feds to prioritize patching Langflow auth bypass flaw·70% of WordPress Sites Running Outdated PHP Versions Exposed to Cyberattacks·

Latest IntelligencePage 100

Search by keyword →
LiteSpeed cPanel Plugin CVE-2026-48172 Exploited to Run Scripts as Root
TI
The Hacker News

LiteSpeed cPanel Plugin CVE-2026-48172 Exploited to Run Scripts as Root

A maximum-severity security vulnerability impacting LiteSpeed User-End cPanel Plugin has come under active exploitation in the wild. The flaw, tracked as CVE-2...

23 May 2026
Drupal Core SQL Injection Bug Actively Exploited, Added to CISA KEV
TI
The Hacker News

Drupal Core SQL Injection Bug Actively Exploited, Added to CISA KEV

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a recently patched critical security flaw impacting Drupal Core to its Known Exploite...

23 May 2026
Hackers Compromised 233 Versions of Laravel-Lang Packages by Hacking 700 GitHub Repos
TI
Cyber Security News

Hackers Compromised 233 Versions of Laravel-Lang Packages by Hacking 700 GitHub Repos

A highly sophisticated supply chain attack has compromised the Laravel-Lang ecosystem, injecting credential-stealing remote code execution backdoors into 233 pa...

23 May 2026
Anthropic’s Claude Mythos Preview Uncovers 10,000+ 0-Days in Project Glasswing
TI
Cyber Security News

Anthropic’s Claude Mythos Preview Uncovers 10,000+ 0-Days in Project Glasswing

Anthropic has revealed the staggering initial results of Project Glasswing, a collaborative cybersecurity initiative designed to secure critical infrastructure ...

23 May 2026
Hackers Abuse Middle East Telecom Networks for Large-Scale Command-and-Control Operations
TI
Cyber Security News

Hackers Abuse Middle East Telecom Networks for Large-Scale Command-and-Control Operations

Hackers are using telecom networks and hosting providers across the Middle East as a foundation for massive command-and-control operations, turning trusted infr...

22 May 2026
World Cup Phishing Campaign Nearly Triples With 203 Unique IP Addresses
TI
Cyber Security News

World Cup Phishing Campaign Nearly Triples With 203 Unique IP Addresses

A large-scale phishing campaign targeting the 2026 FIFA World Cup has grown far beyond what security researchers originally thought. What began as a documented ...

22 May 2026
Russian Threat Groups Use RDP, VPN, Supply Chain Attacks, and Social Engineering for Initial Access
TI
Cyber Security News

Russian Threat Groups Use RDP, VPN, Supply Chain Attacks, and Social Engineering for Initial Access

Russian state-sponsored threat groups significantly stepped up their cyber operations in 2025, using a range of methods to break into targeted systems. From exp...

22 May 2026
Hackers Backdoor Popular art-template npm Package to Launch Watering-Hole Attacks
TI
Cyber Security News

Hackers Backdoor Popular art-template npm Package to Launch Watering-Hole Attacks

A widely-used JavaScript templating library called art-template has been weaponized to deliver a sophisticated iOS browser exploit kit through a supply chain at...

22 May 2026
Hackers Use Six-Layer Persistence to Maintain Access on Compromised FreePBX Systems
TI
Cyber Security News

Hackers Use Six-Layer Persistence to Maintain Access on Compromised FreePBX Systems

A hacker group known as INJ3CTOR3 has been running an active campaign against FreePBX systems, deploying a newly discovered PHP webshell called JOMANGY that use...

22 May 2026
Hackers Use NF-e Invoice Lures to Deliver Banana RAT Through Malicious Batch Files
TI
Cyber Security News

Hackers Use NF-e Invoice Lures to Deliver Banana RAT Through Malicious Batch Files

A newly discovered banking trojan is targeting Brazilians by disguising itself as a legitimate electronic invoice. The malware, known as Banana RAT, uses fake N...

22 May 2026
Telegram’s MTProto protocol leaks persistent identifiers enabling user tracking
TI
Cyber Insider

Telegram’s MTProto protocol leaks persistent identifiers enabling user tracking

A newly published technical review of Telegram’s MTProto protocol warns that the messaging platform exposes persistent device identifiers to passive network obs...

22 May 2026
Ubiquiti Patches Critical UniFi OS Vulnerabilities Allowing Remote Privilege Escalation
TI
Cyber Security News

Ubiquiti Patches Critical UniFi OS Vulnerabilities Allowing Remote Privilege Escalation

Ubiquiti Networks has released urgent security updates to address a series of highly critical vulnerabilities affecting its UniFi OS platform. These severe flaw...

22 May 2026
First VPN Dismantled in Global Takedown Over Use by 25 Ransomware Groups
TI
The Hacker News

First VPN Dismantled in Global Takedown Over Use by 25 Ransomware Groups

Authorities in Europe and North America have announced the dismantling of a criminal virtual private network (VPN) service used by criminal actors to obscure th...

22 May 2026
Netherlands seizes 800 servers of hosting firm enabling cyberattacks
TI
Bleeping Computer

Netherlands seizes 800 servers of hosting firm enabling cyberattacks

Financial crime investigators in the Netherlands (FIOD) arrested two men and seized 800 servers linked to a web hosting company that enabled cyberattacks, inter...

22 May 2026
LiteSpeed cPanel Plugin 0-Day Exploited in the wild to Gain Server Root Access
TI
Cyber Security News

LiteSpeed cPanel Plugin 0-Day Exploited in the wild to Gain Server Root Access

LiteSpeed has disclosed and patched a critical 0‑day privilege escalation flaw in its user-end cPanel plugin that is already being actively exploited to gain ro...

22 May 2026
Drupal Vulnerability in Hacker Crosshairs Shortly After Disclosure
TI
Security Week

Drupal Vulnerability in Hacker Crosshairs Shortly After Disclosure

Drupal is warning users that it has already seen attempts to exploit CVE-2026-9082 and security firms are seeing attacks against thousands of websites. The post...

22 May 2026
Proton VPN vows to resist Canadian surveillance demands under Bill C-22
TI
Cyber Insider

Proton VPN vows to resist Canadian surveillance demands under Bill C-22

Proton VPN General Manager David Peterson said the Swiss-based VPN provider will not comply with any Canadian surveillance demands stemming from the country’s p...

22 May 2026
NordVPN wins early court victory against LaLiga’s VPN blocking campaign
TI
Cyber Insider

NordVPN wins early court victory against LaLiga’s VPN blocking campaign

A Spanish court has rejected LaLiga’s request to fine NordVPN over alleged failures to comply with a controversial anti-piracy blocking order. The decision was ...

22 May 2026
CISA adds Langflow Origin Validation Flaw to Known Exploited Vulnerabilities Catalog
TI
Cyber Security News

CISA adds Langflow Origin Validation Flaw to Known Exploited Vulnerabilities Catalog

 The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical Langflow vulnerability, tracked as CVE-2025-34291, to its Known Expl...

22 May 2026
Deleted Google API Keys Continue Accessing Gemini, BigQuery, and Maps APIs
TI
Cyber Security News

Deleted Google API Keys Continue Accessing Gemini, BigQuery, and Maps APIs

A newly disclosed issue with Google Cloud API keys reveals that deleted credentials may remain usable for up to 23 minutes, exposing projects to potential abuse...

22 May 2026
← PreviousNext →