Every Old Vulnerability Is Now an AI Exploitability
Live threat intelligence feed

Targeted
Threat Intelligence

Aggregated threat intelligence from CISA, NVD, and leading security publications. AI-curated. Updated every 30 minutes.

Threat Matrix — All Time
Vuln
Malware
Intel
Advisory
Breach
APT
Critical
274
90
32
12
17
1
High
165
226
71
23
58
4
Medium
87
94
58
14
63
12
Low
20
22
14
12
Hover to preview · click to filter
All-time · 3529 totalintensity = volume
LIVE
PoC and Technical Details Released for SharePoint Remote Code Execution Vulnerability·Google Dialogflow CX Bug Allowed Attackers to Hijack AI Conversations·DuckDuckGo browser now blocks YouTube video ads·GitHub 'Verified' Commits Can Be Rewritten Into New Hashes Without Breaking Signatures·First-Ever 1- Click Android 17 Exploit Allows Attackers to Gain Full Control Over Your Android Phone·The Verification Step Is the New ATO Battleground in 2026·Telco giant KDDI says data breach affects over 12 million people·GitHub Copilot Refuses Harmful Requests in Chat, Then Writes Them in Code·New Bit2Watt attack uses AI GPU workloads to destabilize power grids·CISA Urges Immediate Patching of Exploited ColdFusion, Langflow, Joomla Flaws·Critical Vulnerability Exposes GitHub Agentic Workflows to Prompt Injection·CISA Warns of Adobe ColdFusion Path Traversal Vulnerability Exploited in Attacks·EU now one step away from reviving private message scanning rules·CISA orders feds to prioritize patching Langflow auth bypass flaw·70% of WordPress Sites Running Outdated PHP Versions Exposed to Cyberattacks·PoC and Technical Details Released for SharePoint Remote Code Execution Vulnerability·Google Dialogflow CX Bug Allowed Attackers to Hijack AI Conversations·DuckDuckGo browser now blocks YouTube video ads·GitHub 'Verified' Commits Can Be Rewritten Into New Hashes Without Breaking Signatures·First-Ever 1- Click Android 17 Exploit Allows Attackers to Gain Full Control Over Your Android Phone·The Verification Step Is the New ATO Battleground in 2026·Telco giant KDDI says data breach affects over 12 million people·GitHub Copilot Refuses Harmful Requests in Chat, Then Writes Them in Code·New Bit2Watt attack uses AI GPU workloads to destabilize power grids·CISA Urges Immediate Patching of Exploited ColdFusion, Langflow, Joomla Flaws·Critical Vulnerability Exposes GitHub Agentic Workflows to Prompt Injection·CISA Warns of Adobe ColdFusion Path Traversal Vulnerability Exploited in Attacks·EU now one step away from reviving private message scanning rules·CISA orders feds to prioritize patching Langflow auth bypass flaw·70% of WordPress Sites Running Outdated PHP Versions Exposed to Cyberattacks·

Latest IntelligencePage 116

Search by keyword →
Microsoft Exchange zero-day chain nets DEVCORE $200K at Pwn2Own
TI
Cyber Insider

Microsoft Exchange zero-day chain nets DEVCORE $200K at Pwn2Own

Pwn2Own Berlin 2026 continued with another wave of successful zero-day demonstrations on Thursday, as security researchers earned $385,750 for 15 unique vulnera...

15 May 2026
TI
CIS Advisories

A Vulnerability in Microsoft Exchange Server Could Allow for Arbitrary Code Execution

A vulnerability has been discovered in Microsoft Exchange Server that could allow for arbitrary code execution. Microsoft Exchange Server is an enterprise-level...

15 May 2026
Funnel Builder WordPress plugin bug exploited to steal credit cards
TI
Bleeping Computer

Funnel Builder WordPress plugin bug exploited to steal credit cards

A critical vulnerability in the Funnel Builder plugin for WordPress is being actively exploited to inject malicious JavaScript snippets into WooCommerce checkou...

15 May 2026
Mullvad VPN exit IP patterns could enable user fingerprinting
TI
Cyber Insider

Mullvad VPN exit IP patterns could enable user fingerprinting

A researcher has disclosed a privacy weakness in Mullvad VPN that could allow users to be probabilistically identified across different VPN servers by correlati...

15 May 2026
Microsoft Exchange, Windows 11 hacked on second day of Pwn2Own
TI
Bleeping Computer

Microsoft Exchange, Windows 11 hacked on second day of Pwn2Own

​During the second day of Pwn2Own Berlin 2026, competitors collected $385,750 in cash awards after exploiting 15 unique zero-day vulnerabilities in multiple pro...

15 May 2026
Popular node-ipc npm package compromised to steal credentials
TI
Bleeping Computer

Popular node-ipc npm package compromised to steal credentials

Hackers have injected credential-stealing malware into newly published versions of node-ipc, a popular inter-process communication package, in a new supply chai...

15 May 2026
Turla Turns Kazuar Backdoor Into Modular P2P Botnet for Persistent Access
TI
The Hacker News

Turla Turns Kazuar Backdoor Into Modular P2P Botnet for Persistent Access

The Russian state-sponsored hacking group known as Turla has transformed its custom backdoor Kazuar into a modular peer-to-peer (P2P) botnet that's ...

15 May 2026
Avada Builder WordPress plugin flaws allow site credential theft
TI
Bleeping Computer

Avada Builder WordPress plugin flaws allow site credential theft

Two vulnerabilities in the Avada Builder plugin for WordPress, with an estimated one million active installations, allow hackers to read arbitrary files and ext...

15 May 2026
Gunra Ransomware Expands RaaS Operations After Shifting From Conti-Based Locker
TI
Cyber Security News

Gunra Ransomware Expands RaaS Operations After Shifting From Conti-Based Locker

Gunra ransomware has quickly grown from a new threat into a serious global problem, hitting dozens of organizations in less than a year. The group behind it is ...

15 May 2026
OpenClaw Chain Vulnerabilities Expose 245,000 Public AI Agent Servers to Attack
TI
Cyber Security News

OpenClaw Chain Vulnerabilities Expose 245,000 Public AI Agent Servers to Attack

A chain of four critical vulnerabilities discovered in OpenClaw, one of the fastest-growing open-source platforms for autonomous AI agents, has left an estimate...

15 May 2026
Shai-Hulud Worm Steals npm, GitHub, AWS, and Kubernetes Secrets From Developers
TI
Cyber Security News

Shai-Hulud Worm Steals npm, GitHub, AWS, and Kubernetes Secrets From Developers

A dangerous new piece of malware called Shai-Hulud has emerged as one of the most alarming supply chain threats of 2026. It is a self-propagating worm that quie...

15 May 2026
Hackers Abuse OAuth Device Authorization Flow to Steal Microsoft 365 Tokens
TI
Cyber Security News

Hackers Abuse OAuth Device Authorization Flow to Steal Microsoft 365 Tokens

Hackers are exploiting a little-known feature of Microsoft’s authentication system to steal account credentials at scale. Device code phishing campaigns n...

15 May 2026
In Other News: Big Tech vs Canada Encryption Bill, Cisco’s Free AI Security Spec, Audi App Flaws
TI
Security Week

In Other News: Big Tech vs Canada Encryption Bill, Cisco’s Free AI Security Spec, Audi App Flaws

Other noteworthy stories that might have slipped under the radar: Nvidia cloud gaming data breach, Android 17 security upgrades, FBI warning after ShinyHunters ...

15 May 2026
Microsoft Edge to stop loading cleartext passwords in memory on startup
TI
Bleeping Computer

Microsoft Edge to stop loading cleartext passwords in memory on startup

Microsoft is updating the Edge web browser to ensure it no longer loads saved passwords into process memory in clear text at startup. [...]...

15 May 2026
Microsoft backpedals: Edge to stop loading passwords into memory
TI
Bleeping Computer

Microsoft backpedals: Edge to stop loading passwords into memory

Microsoft is updating the Edge web browser to ensure it no longer loads saved passwords into process memory in clear text at startup after previously stating it...

15 May 2026
Inside the REMUS Infostealer: Session Theft, MaaS, and Rapid Evolution
TI
Bleeping Computer

Inside the REMUS Infostealer: Session Theft, MaaS, and Rapid Evolution

Stolen browser sessions and authentication tokens are becoming more valuable than stolen passwords. Flare explains how the REMUS infostealer evolved around sess...

15 May 2026
Researchers claim the first macOS kernel exploit on Apple M5 chips
TI
Cyber Insider

Researchers claim the first macOS kernel exploit on Apple M5 chips

Security researchers have announced what they describe as the first public macOS kernel memory corruption exploit capable of bypassing Apple’s Memory Integrity ...

15 May 2026
Four OpenClaw Flaws Enable Data Theft, Privilege Escalation, and Persistence
TI
The Hacker News

Four OpenClaw Flaws Enable Data Theft, Privilege Escalation, and Persistence

Cybersecurity researchers have disclosed a set of four security flaws in OpenClaw that could be chained to achieve data theft, privilege escalation, and persist...

15 May 2026
Microsoft Edge, Windows 11 and LiteLLM Hacked in Pwn2Own Berlin 2026
TI
Cyber Security News

Microsoft Edge, Windows 11 and LiteLLM Hacked in Pwn2Own Berlin 2026

Pwn2Own Berlin 2026 opened with a surge of zero-day exploits targeting modern browsers, operating systems, and emerging AI platforms. On Day One alone, security...

15 May 2026
Hackers Use OrBit Rootkit to Harvest SSH and Sudo Credentials From Linux Systems
TI
Cyber Security News

Hackers Use OrBit Rootkit to Harvest SSH and Sudo Credentials From Linux Systems

A dangerous rootkit called OrBit has been quietly targeting Linux systems for years, stealing login credentials and hiding deep inside infected machines without...

15 May 2026
← PreviousNext →