Every Old Vulnerability Is Now an AI Exploitability
Live threat intelligence feed

Targeted
Threat Intelligence

Aggregated threat intelligence from CISA, NVD, and leading security publications. AI-curated. Updated every 30 minutes.

Threat Matrix — All Time
Vuln
Malware
Intel
Advisory
Breach
APT
Critical
274
90
32
12
17
1
High
165
226
71
23
58
4
Medium
87
94
58
14
63
12
Low
20
22
14
12
Hover to preview · click to filter
All-time · 3529 totalintensity = volume
LIVE
PoC and Technical Details Released for SharePoint Remote Code Execution Vulnerability·Google Dialogflow CX Bug Allowed Attackers to Hijack AI Conversations·DuckDuckGo browser now blocks YouTube video ads·GitHub 'Verified' Commits Can Be Rewritten Into New Hashes Without Breaking Signatures·First-Ever 1- Click Android 17 Exploit Allows Attackers to Gain Full Control Over Your Android Phone·The Verification Step Is the New ATO Battleground in 2026·Telco giant KDDI says data breach affects over 12 million people·GitHub Copilot Refuses Harmful Requests in Chat, Then Writes Them in Code·New Bit2Watt attack uses AI GPU workloads to destabilize power grids·CISA Urges Immediate Patching of Exploited ColdFusion, Langflow, Joomla Flaws·Critical Vulnerability Exposes GitHub Agentic Workflows to Prompt Injection·CISA Warns of Adobe ColdFusion Path Traversal Vulnerability Exploited in Attacks·EU now one step away from reviving private message scanning rules·CISA orders feds to prioritize patching Langflow auth bypass flaw·70% of WordPress Sites Running Outdated PHP Versions Exposed to Cyberattacks·PoC and Technical Details Released for SharePoint Remote Code Execution Vulnerability·Google Dialogflow CX Bug Allowed Attackers to Hijack AI Conversations·DuckDuckGo browser now blocks YouTube video ads·GitHub 'Verified' Commits Can Be Rewritten Into New Hashes Without Breaking Signatures·First-Ever 1- Click Android 17 Exploit Allows Attackers to Gain Full Control Over Your Android Phone·The Verification Step Is the New ATO Battleground in 2026·Telco giant KDDI says data breach affects over 12 million people·GitHub Copilot Refuses Harmful Requests in Chat, Then Writes Them in Code·New Bit2Watt attack uses AI GPU workloads to destabilize power grids·CISA Urges Immediate Patching of Exploited ColdFusion, Langflow, Joomla Flaws·Critical Vulnerability Exposes GitHub Agentic Workflows to Prompt Injection·CISA Warns of Adobe ColdFusion Path Traversal Vulnerability Exploited in Attacks·EU now one step away from reviving private message scanning rules·CISA orders feds to prioritize patching Langflow auth bypass flaw·70% of WordPress Sites Running Outdated PHP Versions Exposed to Cyberattacks·

Latest IntelligencePage 27

Search by keyword →
TI
Dark Reading

Robinhood Cuts Access Approval Time to Support High-Velocity Development

The fintech company's engineering-first application security team re-engineered the process for granting system access, making it easier and more secure for dev...

25 Jun 2026
Poland busts SIM-swapping gang tied to millions in crypto theft
TI
Bleeping Computer

Poland busts SIM-swapping gang tied to millions in crypto theft

Authorities in Poland have arrested four members of an organized cybercrime group accused of breaching telecommunications partners and hijacking email accounts ...

25 Jun 2026
TI
Dark Reading

In Less Than 24 Hours, Attackers Weaponize Cisco CUCM Flaw

The flaw enables server-side request forgery (SSRF) and escalates privileges to root, impacting Cisco Unified CM and Unified CM SME deployments....

25 Jun 2026
TI
Dark Reading

Russian APT 'Gamaredon' Upgrades Its Arsenal, Requiring New Defenses

The FSB state-sponsored operation has gotten a lot better at loading its malware and hiding its servers....

25 Jun 2026
TI
Dark Reading

EdTech Attackers Shift From Schools to Their Software Suppliers

Educational institutions, the edtech companies they rely on, and, more concerningly, the challenges they pose for schools are the focus of the latest Reporters'...

25 Jun 2026
Order-tracking app Shop abused to push callback phishing attacks
TI
Bleeping Computer

Order-tracking app Shop abused to push callback phishing attacks

Threat actors are increasingly abusing Shop, the order-tracking app from Shopify, by adding fake purchase receipts in users' order histories to trick them into ...

25 Jun 2026
TI
Dark Reading

Local Police Collusion Hampers Crackdown on Asian Scam Centers

With tens of billions of dollars flowing into regional economies from cybercrime, scam centers continue to flourish, despite international and law-enforcement e...

25 Jun 2026
Microsoft quietly extends free Windows 10 ESU support to October 2027
TI
Bleeping Computer

Microsoft quietly extends free Windows 10 ESU support to October 2027

Microsoft has quietly extended its free Windows 10 Extended Security Updates (ESU) program for consumers by an additional year, allowing enrolled devices to con...

25 Jun 2026
Russia Used Cellebrite Tool to Hack Activist’s iPhone Despite Contract Cancellation
TI
Cyber Security News

Russia Used Cellebrite Tool to Hack Activist’s iPhone Despite Contract Cancellation

Russian authorities deployed Cellebrite’s Universal Forensic Extraction Device (UFED) to breach the iPhone of opposition politician Andrey Pivovarov in Ju...

25 Jun 2026
WhatsApp is now warning users attempting to message unknown numbers
TI
Cyber Insider

WhatsApp is now warning users attempting to message unknown numbers

WhatsApp has introduced a new security feature designed to make users think twice before starting conversations with unfamiliar phone numbers. The new “tr...

25 Jun 2026
Windows Secure Boot Certificate Expired — Billions of PCs Affected Including Linux Distros
TI
Cyber Security News

Windows Secure Boot Certificate Expired — Billions of PCs Affected Including Linux Distros

The clock has run out. As of June 24, 2026, the first of Microsoft’s original Secure Boot certificates, the Microsoft Corporation KEK CA 2011, has officia...

25 Jun 2026
New macOS malware embeds fake errors to confuse AI analysis tools
TI
Bleeping Computer

New macOS malware embeds fake errors to confuse AI analysis tools

A newly discovered macOS malware dubbed "Gaslight" is designed to confuse AI-assisted malware analysis tools by hiding prompt injection strings and fake debuggi...

25 Jun 2026
PirloTV sports piracy network disrupted as 44 domains seized
TI
Bleeping Computer

PirloTV sports piracy network disrupted as 44 domains seized

A major sports piracy ring linked to the illegal PirloTV streaming platform has been disrupted in an action that targeted 44 domains. [...]...

25 Jun 2026
Best Pentesting Tools for Internal vs External Testing
TI
Cyber Security News

Best Pentesting Tools for Internal vs External Testing

A penetration test should answer a simple question: where could an attacker get in, and what could they reach after that? The answer changes when the test looks...

25 Jun 2026
Bluekit phishing kit adopts browser-in-the-middle for login theft
TI
Bleeping Computer

Bluekit phishing kit adopts browser-in-the-middle for login theft

The Bluekit phishing-as-a-service platform continues to evolve with nearly 70 new hostnames identified over the past week and by adding browser-in-the-middle ca...

25 Jun 2026
Chrome Ad Blocker with 10M+ Installs Found with Dormant Script Injection Capability
TI
The Hacker News

Chrome Ad Blocker with 10M+ Installs Found with Dormant Script Injection Capability

An analysis of a popular Google Chrome ad block extension for YouTube has uncovered the ability to execute arbitrary JavaScript code. According to Island, the ...

25 Jun 2026
The Four Elevations of Effective Fraud Prevention
TI
Bleeping Computer

The Four Elevations of Effective Fraud Prevention

Fraudsters don't attack just one transaction. They target accounts, platforms, and entire ecosystems. IPQS explains the four elevations of fraud prevention and ...

25 Jun 2026
25-Year-Old Vulnerability in cURL Used by 30 Billion Devices Finally Patched
TI
Cyber Security News

25-Year-Old Vulnerability in cURL Used by 30 Billion Devices Finally Patched

A critical security flaw lurking in curl for over 25 years has been patched, as part of a record-breaking security release that fixed 18 CVEs, the most ever iss...

25 Jun 2026
Shopify Shop app users are seeing fake orders in purchase histories
TI
Cyber Insider

Shopify Shop app users are seeing fake orders in purchase histories

Scammers are placing fake purchase receipts inside Shopify's Shop app, exploiting users' trust in order-tracking applications to lure them into calling fraudule...

25 Jun 2026
LokiBot Campaign Uses JScript Attachment, .NET Injector, and Process Injection to Steal Credentials
TI
Cyber Security News

LokiBot Campaign Uses JScript Attachment, .NET Injector, and Process Injection to Steal Credentials

LokiBot, one of the oldest credential-stealing malware families still active today, has resurfaced in a new multi-stage campaign designed to steal credentials f...

25 Jun 2026
← PreviousNext →