Every Old Vulnerability Is Now an AI Exploitability
Live threat intelligence feed

Targeted
Threat Intelligence

Aggregated threat intelligence from CISA, NVD, and leading security publications. AI-curated. Updated every 30 minutes.

Threat Matrix — All Time
Vuln
Malware
Intel
Advisory
Breach
APT
Critical
274
90
32
12
17
1
High
165
226
71
23
58
4
Medium
87
94
58
14
63
12
Low
20
22
14
12
Hover to preview · click to filter
All-time · 3529 totalintensity = volume
LIVE
PoC and Technical Details Released for SharePoint Remote Code Execution Vulnerability·Google Dialogflow CX Bug Allowed Attackers to Hijack AI Conversations·DuckDuckGo browser now blocks YouTube video ads·GitHub 'Verified' Commits Can Be Rewritten Into New Hashes Without Breaking Signatures·First-Ever 1- Click Android 17 Exploit Allows Attackers to Gain Full Control Over Your Android Phone·The Verification Step Is the New ATO Battleground in 2026·Telco giant KDDI says data breach affects over 12 million people·GitHub Copilot Refuses Harmful Requests in Chat, Then Writes Them in Code·New Bit2Watt attack uses AI GPU workloads to destabilize power grids·CISA Urges Immediate Patching of Exploited ColdFusion, Langflow, Joomla Flaws·Critical Vulnerability Exposes GitHub Agentic Workflows to Prompt Injection·CISA Warns of Adobe ColdFusion Path Traversal Vulnerability Exploited in Attacks·EU now one step away from reviving private message scanning rules·CISA orders feds to prioritize patching Langflow auth bypass flaw·70% of WordPress Sites Running Outdated PHP Versions Exposed to Cyberattacks·PoC and Technical Details Released for SharePoint Remote Code Execution Vulnerability·Google Dialogflow CX Bug Allowed Attackers to Hijack AI Conversations·DuckDuckGo browser now blocks YouTube video ads·GitHub 'Verified' Commits Can Be Rewritten Into New Hashes Without Breaking Signatures·First-Ever 1- Click Android 17 Exploit Allows Attackers to Gain Full Control Over Your Android Phone·The Verification Step Is the New ATO Battleground in 2026·Telco giant KDDI says data breach affects over 12 million people·GitHub Copilot Refuses Harmful Requests in Chat, Then Writes Them in Code·New Bit2Watt attack uses AI GPU workloads to destabilize power grids·CISA Urges Immediate Patching of Exploited ColdFusion, Langflow, Joomla Flaws·Critical Vulnerability Exposes GitHub Agentic Workflows to Prompt Injection·CISA Warns of Adobe ColdFusion Path Traversal Vulnerability Exploited in Attacks·EU now one step away from reviving private message scanning rules·CISA orders feds to prioritize patching Langflow auth bypass flaw·70% of WordPress Sites Running Outdated PHP Versions Exposed to Cyberattacks·

Latest IntelligencePage 115

Search by keyword →
TI
Dark Reading

Can Laws Stop Deepfakes? South Korea Aims to Find Out

South Korea's local elections next month will be a test bed for how effective regulations might be to stymie the flow of deepfakes....

18 May 2026
New Windows 'MiniPlasma' zero-day exploit gives SYSTEM access, PoC released
TI
Bleeping Computer

New Windows 'MiniPlasma' zero-day exploit gives SYSTEM access, PoC released

A cybersecurity researcher has released a proof-of-concept exploit for a Windows privilege escalation zero-day dubbed "MiniPlasma" that lets attackers gain SYST...

17 May 2026
iodéOS review: Privacy-focused Android that doesn’t get in your way
TI
Cyber Insider

iodéOS review: Privacy-focused Android that doesn’t get in your way

iodéOS is a privacy-oriented Android operating system developed by the French company iodé, based on the Android Open Source Project (AOSP). The project focuses...

17 May 2026
Tycoon2FA hijacks Microsoft 365 accounts via device-code phishing
TI
Bleeping Computer

Tycoon2FA hijacks Microsoft 365 accounts via device-code phishing

The Tycoon2FA phishing kit now supports device-code phishing attacks and abuses Trustifi click-tracking URLs to hijack Microsoft 365 accounts. [...]...

17 May 2026
NGINX CVE-2026-42945 Exploited in the Wild, Causing Worker Crashes and Possible RCE
TI
The Hacker News

NGINX CVE-2026-42945 Exploited in the Wild, Causing Worker Crashes and Possible RCE

A newly disclosed security flaw impacting NGINX Plus and NGINX Open has come under active exploitation in the wild, days after its public disclosure, according ...

17 May 2026
Pwn2Own Berlin 2026 concludes with $1.29 million paid for 47 zero-days
TI
Cyber Insider

Pwn2Own Berlin 2026 concludes with $1.29 million paid for 47 zero-days

Pwn2Own Berlin 2026 wrapped up with another string of successful enterprise-targeted exploits, bringing the contest’s final tally to $1,298,250 awarded for 47 u...

17 May 2026
Grafana Labs Security Breach – Hackers Access GitHub and Download Codebase
TI
Cyber Security News

Grafana Labs Security Breach – Hackers Access GitHub and Download Codebase

A threat actor infiltrated Grafana Labs’ GitHub environment, stealing a privileged token to download the company’s private codebase, and then attemp...

17 May 2026
Grafana GitHub Token Breach Led to Codebase Download and Extortion Attempt
TI
The Hacker News

Grafana GitHub Token Breach Led to Codebase Download and Extortion Attempt

Grafana has disclosed that an "unauthorized party" obtained a token that granted them the ability to access the company's GitHub environment and download its co...

17 May 2026
First Public macOS Kernel Exploit on Apple M5 Prepared Using Mythos Preview in Five Days
TI
Cyber Security News

First Public macOS Kernel Exploit on Apple M5 Prepared Using Mythos Preview in Five Days

Apple’s M5 silicon has reportedly been exploited for the first time in a public macOS kernel memory corruption attack, successfully bypassing the company&...

17 May 2026
Microsoft rejects critical Azure vulnerability report, no CVE issued
TI
Bleeping Computer

Microsoft rejects critical Azure vulnerability report, no CVE issued

A security researcher claims Microsoft quietly fixed an Azure Backup for AKS vulnerability after rejecting his report, and without issuing a CVE. Microsoft disp...

16 May 2026
Funnel Builder Flaw Under Active Exploitation Enables WooCommerce Checkout Skimming
TI
The Hacker News

Funnel Builder Flaw Under Active Exploitation Enables WooCommerce Checkout Skimming

A critical security vulnerability impacting the Funnel Builder plugin for WordPress has come under active exploitation in the wild to inject malicious Jav...

16 May 2026
Russian hackers turn Kazuar backdoor into modular P2P botnet
TI
Bleeping Computer

Russian hackers turn Kazuar backdoor into modular P2P botnet

The Russian hacker group Secret Blizzard has developed its long-running Kazuar backdoor into a modular peer-to-peer (P2P) botnet designed for long-term persiste...

16 May 2026
Microsoft Exchange, Windows 11, and Cursor Zero-Days Exploited on Pwn2Own Day 2
TI
Cyber Security News

Microsoft Exchange, Windows 11, and Cursor Zero-Days Exploited on Pwn2Own Day 2

Pwn2Own Berlin 2026 is rapidly escalating into one of the most intense offensive security contests in recent years, with Day Two delivering a fresh wave of crit...

16 May 2026
TI
Cyber Security News

JDownloader Website Compromised to Distribute Malicious Windows and Linux Installers

A widely used download manager trusted by millions has briefly turned into a malware delivery platform after attackers compromised the official JDownloader webs...

16 May 2026
PoC Code Published for Critical NGINX Vulnerability
TI
Security Week

PoC Code Published for Critical NGINX Vulnerability

Introduced in 2008, the critical-severity security defect was patched this week in NGINX Plus and NGINX open source. The post PoC Code Published for Critical NG...

16 May 2026
Malicious JPEG Images Could Trigger PHP Memory Safety Vulnerabilities
TI
Cyber Security News

Malicious JPEG Images Could Trigger PHP Memory Safety Vulnerabilities

Two critical memory-safety vulnerabilities in PHP’s image-processing functions could allow attackers to leak sensitive heap memory or to execute denial-of...

16 May 2026
Linux Kernel Vulnerability “ssh-keysign-pwn” Lets Attackers Read SSH Keys and Shadow Passwords
TI
Cyber Security News

Linux Kernel Vulnerability “ssh-keysign-pwn” Lets Attackers Read SSH Keys and Shadow Passwords

A newly disclosed Linux kernel vulnerability is raising serious concerns across the security community, as it allows attackers to access highly sensitive data, ...

16 May 2026
Critical Linux Kernel Flaw ‘ssh-keysign-pwn’ Exposes SSH Keys and Shadow Passwords
TI
Cyber Security News

Critical Linux Kernel Flaw ‘ssh-keysign-pwn’ Exposes SSH Keys and Shadow Passwords

A newly disclosed Linux kernel vulnerability is raising serious concerns across the security community, as it allows attackers to access highly sensitive data, ...

16 May 2026
Google Project Zero Discloses Zero-Click Exploit Chain for Pixel 10 Devices
TI
Cyber Security News

Google Project Zero Discloses Zero-Click Exploit Chain for Pixel 10 Devices

A newly disclosed zero-click exploit chain targeting Google Pixel 10 devices has raised fresh concerns about Android’s low-level security. Google Project Zero r...

16 May 2026
Android 16 VPN Bypass Lets Malicious Apps Reveal Users Real IP Address
TI
Cyber Security News

Android 16 VPN Bypass Lets Malicious Apps Reveal Users Real IP Address

A newly disclosed flaw in Android 16 is raising serious privacy concerns after researchers revealed that malicious apps can bypass VPN protections and expose a ...

16 May 2026
← PreviousNext →