Every Old Vulnerability Is Now an AI Exploitability
Live threat intelligence feed

Targeted
Threat Intelligence

Aggregated threat intelligence from CISA, NVD, and leading security publications. AI-curated. Updated every 30 minutes.

Threat Matrix — All Time
Vuln
Malware
Intel
Advisory
Breach
APT
Critical
274
90
32
12
17
1
High
165
226
71
23
58
4
Medium
87
94
58
14
63
12
Low
20
22
14
12
Hover to preview · click to filter
All-time · 3529 totalintensity = volume
LIVE
PoC and Technical Details Released for SharePoint Remote Code Execution Vulnerability·Google Dialogflow CX Bug Allowed Attackers to Hijack AI Conversations·DuckDuckGo browser now blocks YouTube video ads·GitHub 'Verified' Commits Can Be Rewritten Into New Hashes Without Breaking Signatures·First-Ever 1- Click Android 17 Exploit Allows Attackers to Gain Full Control Over Your Android Phone·The Verification Step Is the New ATO Battleground in 2026·Telco giant KDDI says data breach affects over 12 million people·GitHub Copilot Refuses Harmful Requests in Chat, Then Writes Them in Code·New Bit2Watt attack uses AI GPU workloads to destabilize power grids·CISA Urges Immediate Patching of Exploited ColdFusion, Langflow, Joomla Flaws·Critical Vulnerability Exposes GitHub Agentic Workflows to Prompt Injection·CISA Warns of Adobe ColdFusion Path Traversal Vulnerability Exploited in Attacks·EU now one step away from reviving private message scanning rules·CISA orders feds to prioritize patching Langflow auth bypass flaw·70% of WordPress Sites Running Outdated PHP Versions Exposed to Cyberattacks·PoC and Technical Details Released for SharePoint Remote Code Execution Vulnerability·Google Dialogflow CX Bug Allowed Attackers to Hijack AI Conversations·DuckDuckGo browser now blocks YouTube video ads·GitHub 'Verified' Commits Can Be Rewritten Into New Hashes Without Breaking Signatures·First-Ever 1- Click Android 17 Exploit Allows Attackers to Gain Full Control Over Your Android Phone·The Verification Step Is the New ATO Battleground in 2026·Telco giant KDDI says data breach affects over 12 million people·GitHub Copilot Refuses Harmful Requests in Chat, Then Writes Them in Code·New Bit2Watt attack uses AI GPU workloads to destabilize power grids·CISA Urges Immediate Patching of Exploited ColdFusion, Langflow, Joomla Flaws·Critical Vulnerability Exposes GitHub Agentic Workflows to Prompt Injection·CISA Warns of Adobe ColdFusion Path Traversal Vulnerability Exploited in Attacks·EU now one step away from reviving private message scanning rules·CISA orders feds to prioritize patching Langflow auth bypass flaw·70% of WordPress Sites Running Outdated PHP Versions Exposed to Cyberattacks·

Latest IntelligencePage 140

Search by keyword →
New Attribution Framework Connects APT Campaigns Through Strategic, Operational, and Technical Layers
TI
Cyber Security News

New Attribution Framework Connects APT Campaigns Through Strategic, Operational, and Technical Layers

Tracking Advanced Persistent Threat (APT) groups has never been a simple task. For years, security organizations have relied on identifying consistent behaviors...

5 May 2026
CloudZ malware hijacks Microsoft Phone Link to intercept SMS and OTPs
TI
Cyber Insider

CloudZ malware hijacks Microsoft Phone Link to intercept SMS and OTPs

A new malware campaign abuses Microsoft’s Phone Link app to intercept sensitive mobile data, including one-time passwords (OTPs), without compromising the phone...

5 May 2026
CloudZ malware abuses Microsoft Phone Link to steal SMS and OTPs
TI
Bleeping Computer

CloudZ malware abuses Microsoft Phone Link to steal SMS and OTPs

A new version of the CloudZ remote access tool (RAT) is deploying a previously unseen malicious plugin called Pheno that hijacks the Microsoft Phone Link connec...

5 May 2026
WhatsApp Vulnerability Lets Attackers Leverage Instagram Reels to Execute Malicious URLs
TI
Cyber Security News

WhatsApp Vulnerability Lets Attackers Leverage Instagram Reels to Execute Malicious URLs

Meta has disclosed a medium-severity security vulnerability in WhatsApp that could allow threat actors to exploit Instagram Reels integration to trigger arbitra...

5 May 2026
MetInfo, Weaver E-cology Vulnerabilities in Attackers’ Crosshairs
TI
Security Week

MetInfo, Weaver E-cology Vulnerabilities in Attackers’ Crosshairs

The security defects allow unauthenticated, remote attackers to execute arbitrary code through crafted requests. The post MetInfo, Weaver E-cology Vulnerabiliti...

5 May 2026
Instagram’s to End Encrypted Chats for Direct Messages
TI
Cyber Security News

Instagram’s to End Encrypted Chats for Direct Messages

Meta has announced that Instagram will officially discontinue its optional end-to-end encrypted direct message feature on May 8, 2026. The feature was initially...

5 May 2026
APT37 hacks gaming platform to spread new BirdCall Android spyware
TI
Cyber Insider

APT37 hacks gaming platform to spread new BirdCall Android spyware

North Korean hackers compromised a gaming platform in a supply-chain attack, using trojanized Windows and Android games to deploy a previously undocumented mobi...

5 May 2026
ScarCruft hackers push BirdCall Android malware via game platform
TI
Bleeping Computer

ScarCruft hackers push BirdCall Android malware via game platform

The North Korean hacker group APT37 has been delivering an Android version of a backdoor called BirdCall in a supply-chain attack through a video game platform....

5 May 2026
WhatsApp Discloses File Spoofing, Arbitrary URL Scheme Vulnerabilities
TI
Security Week

WhatsApp Discloses File Spoofing, Arbitrary URL Scheme Vulnerabilities

The vulnerabilities were reported to Meta through its bug bounty program and were patched with updates released earlier this year. The post WhatsApp Discloses F...

5 May 2026
Beware of Fake ‘Notepad++ for Mac’ Website, Possibly Could Harm your Machine
TI
Cyber Security News

Beware of Fake ‘Notepad++ for Mac’ Website, Possibly Could Harm your Machine

A fake website claiming to offer an official macOS version of the popular text editor Notepad++ has been making rounds online, raising serious cybersecurity con...

5 May 2026
Critical Android Zero-Click Vulnerability Grants Remote Shell Access
TI
Cyber Security News

Critical Android Zero-Click Vulnerability Grants Remote Shell Access

Google has published the May 2026 Android Security Bulletin, alerting the ecosystem to a highly severe remote code execution (RCE) flaw. Tracked as CVE-2026-007...

5 May 2026
pnpm 11 Turns On Minimum Release Age by Default to Reduce npm Supply Chain Risk
TI
Cyber Security News

pnpm 11 Turns On Minimum Release Age by Default to Reduce npm Supply Chain Risk

The npm ecosystem has long been a target for supply chain attacks, where threat actors exploit the open nature of public package registries to push malicious co...

5 May 2026
Microsoft Edge Stores All Saved Passwords in Cleartext Process Memory at Launch
TI
Cyber Security News

Microsoft Edge Stores All Saved Passwords in Cleartext Process Memory at Launch

A security researcher has discovered that Microsoft Edge decrypts every stored password into process memory the moment the browser launches and keeps them there...

5 May 2026
Apache HTTP Server Exposes Millions of Servers to Remote Code Execution Attacks
TI
Cyber Security News

Apache HTTP Server Exposes Millions of Servers to Remote Code Execution Attacks

The Apache Software Foundation has released a critical security update for Apache HTTP Server, patching five vulnerabilities, including a dangerous double-free ...

5 May 2026
Critical Apache HTTP Server Flaw Exposes Millions of Servers to RCE Attacks
TI
Cyber Security News

Critical Apache HTTP Server Flaw Exposes Millions of Servers to RCE Attacks

The Apache Software Foundation has released a critical security update for Apache HTTP Server, patching five vulnerabilities, including a dangerous double-free ...

5 May 2026
Weaver E-cology critical bug exploited in attacks since March
TI
Bleeping Computer

Weaver E-cology critical bug exploited in attacks since March

Hackers have been exploiting a critical vulnerability (CVE-2026-22679) in the Weaver E-cology office automation since mid-March to run discovery commands. [...]...

4 May 2026
TI
Dark Reading

Physical Cargo Theft Gets a Boost From Cybercriminals

Cargo theft is no longer about small groups of criminals operating on the ground, but transnational cybercriminal syndicates using access to supply chain system...

4 May 2026
TI
Dark Reading

RMM Tools Fuel Stealthy Phishing Campaign

Attackers are abusing two remote monitoring and management (RMM) tools to evade detection in a campaign that has impacted over 80 organizations so far....

4 May 2026
Amazon SES increasingly abused in phishing to evade detection
TI
Bleeping Computer

Amazon SES increasingly abused in phishing to evade detection

The Amazon Simple Email Service (SES) is being increasingly abused to send convincing phishing emails that can bypass standard security filters and render reput...

4 May 2026
Researchers report Amazon SES abused in phishing to evade detection
TI
Bleeping Computer

Researchers report Amazon SES abused in phishing to evade detection

Cybersecurity firm Kaspersky reports that the Amazon Simple Email Service (SES) is being increasingly abused to send convincing phishing emails that can bypass ...

4 May 2026
← PreviousNext →