Every Old Vulnerability Is Now an AI Exploitability
Live threat intelligence feed

Targeted
Threat Intelligence

Aggregated threat intelligence from CISA, NVD, and leading security publications. AI-curated. Updated every 30 minutes.

Threat Matrix — All Time
Vuln
Malware
Intel
Advisory
Breach
APT
Critical
274
90
32
12
17
1
High
165
226
71
23
58
4
Medium
87
94
58
14
63
12
Low
20
22
14
12
Hover to preview · click to filter
All-time · 3529 totalintensity = volume
LIVE
PoC and Technical Details Released for SharePoint Remote Code Execution Vulnerability·Google Dialogflow CX Bug Allowed Attackers to Hijack AI Conversations·DuckDuckGo browser now blocks YouTube video ads·GitHub 'Verified' Commits Can Be Rewritten Into New Hashes Without Breaking Signatures·First-Ever 1- Click Android 17 Exploit Allows Attackers to Gain Full Control Over Your Android Phone·The Verification Step Is the New ATO Battleground in 2026·Telco giant KDDI says data breach affects over 12 million people·GitHub Copilot Refuses Harmful Requests in Chat, Then Writes Them in Code·New Bit2Watt attack uses AI GPU workloads to destabilize power grids·CISA Urges Immediate Patching of Exploited ColdFusion, Langflow, Joomla Flaws·Critical Vulnerability Exposes GitHub Agentic Workflows to Prompt Injection·CISA Warns of Adobe ColdFusion Path Traversal Vulnerability Exploited in Attacks·EU now one step away from reviving private message scanning rules·CISA orders feds to prioritize patching Langflow auth bypass flaw·70% of WordPress Sites Running Outdated PHP Versions Exposed to Cyberattacks·PoC and Technical Details Released for SharePoint Remote Code Execution Vulnerability·Google Dialogflow CX Bug Allowed Attackers to Hijack AI Conversations·DuckDuckGo browser now blocks YouTube video ads·GitHub 'Verified' Commits Can Be Rewritten Into New Hashes Without Breaking Signatures·First-Ever 1- Click Android 17 Exploit Allows Attackers to Gain Full Control Over Your Android Phone·The Verification Step Is the New ATO Battleground in 2026·Telco giant KDDI says data breach affects over 12 million people·GitHub Copilot Refuses Harmful Requests in Chat, Then Writes Them in Code·New Bit2Watt attack uses AI GPU workloads to destabilize power grids·CISA Urges Immediate Patching of Exploited ColdFusion, Langflow, Joomla Flaws·Critical Vulnerability Exposes GitHub Agentic Workflows to Prompt Injection·CISA Warns of Adobe ColdFusion Path Traversal Vulnerability Exploited in Attacks·EU now one step away from reviving private message scanning rules·CISA orders feds to prioritize patching Langflow auth bypass flaw·70% of WordPress Sites Running Outdated PHP Versions Exposed to Cyberattacks·

Latest IntelligencePage 3

Search by keyword →
The Gentlemen Ransomware With Custom EDR/AV Killers Scaling Faster to Attack Industries Worldwide
TI
Cyber Security News

The Gentlemen Ransomware With Custom EDR/AV Killers Scaling Faster to Attack Industries Worldwide

The Gentlemen is one of the most rapidly escalating ransomware threats observed in 2026. Emerging in mid-2025 from a payment dispute within the Qilin RaaS progr...

7 Jul 2026
VECT and TeamPCP Reverse Ransomware Kill Chain With Supply Chain Credential Theft
TI
Cyber Security News

VECT and TeamPCP Reverse Ransomware Kill Chain With Supply Chain Credential Theft

A ransomware strain called VECT has formed an unusual supply chain partnership with a threat group known as TeamPCP, quietly exposing thousands of organizations...

7 Jul 2026
4,982 Security Issues Identified Across 2,259 Affected in Public MCP Servers
TI
Cyber Security News

4,982 Security Issues Identified Across 2,259 Affected in Public MCP Servers

A sweeping security crisis across public Model Context Protocol (MCP) servers, cataloging 4,982 security issues across 2,259 affected servers, exposing serious ...

7 Jul 2026
The $50K-to-$5M Gap: Why Your SOC SLA Is Stuck in 2019 — Here’s the 2026 AI SLA Vendor Guide
TI
Cyber Security News

The $50K-to-$5M Gap: Why Your SOC SLA Is Stuck in 2019 — Here’s the 2026 AI SLA Vendor Guide

A technical breakdown of why legacy MDR contract language fails in the age of AI-driven security operations — and the measurable standards that should replace i...

7 Jul 2026
TI
Dark Reading

'GitLost' Flaw Leaks Private Data from GitHub's Agentic Workflows

The flaw allows an unauthenticated attacker to craft a GitHub Issue in an org's public repository and then silently pull data from its private repos, too....

7 Jul 2026
GitLost Vulnerability Tricks GitHub’s AI Agent into Leaking Private Repos
TI
Cyber Security News

GitLost Vulnerability Tricks GitHub’s AI Agent into Leaking Private Repos

A newly disclosed vulnerability dubbed “GitLost” shows how attackers can weaponize a single GitHub Issue to trick GitHub’s new AI-powered Agen...

7 Jul 2026
Spain arrests suspected member of pro-Russian hacktivist groups
TI
Bleeping Computer

Spain arrests suspected member of pro-Russian hacktivist groups

The National Police in Spain have arrested a man who is suspected of being an active member of the CyberArmy of Russia Reborn (CARR) and Z-Pentest, both pro-Rus...

7 Jul 2026
AnyDesk Phishing Attack Uses Scheduled Task Persistence and Artifact Deletion to Evade Detection
TI
Cyber Security News

AnyDesk Phishing Attack Uses Scheduled Task Persistence and Artifact Deletion to Evade Detection

A new phishing campaign is turning a trusted remote access tool into a long term backdoor for espionage. Attackers hide behind fake invoices to slip past email ...

7 Jul 2026
DEBULL Tooling Abuses Microsoft Device-Code Flow to Target M365 Accounts
TI
The Hacker News

DEBULL Tooling Abuses Microsoft Device-Code Flow to Target M365 Accounts

A Microsoft 365 device code phishing campaign has been observed leveraging collaboration-themed lures to take control of victim accounts between the last week o...

7 Jul 2026
Ubiquiti Disclosed 25 Security Vulnerabilities Across the UniFi Ecosystem
TI
Cyber Security News

Ubiquiti Disclosed 25 Security Vulnerabilities Across the UniFi Ecosystem

Ubiquiti has disclosed 25 security vulnerabilities affecting its UniFi ecosystem in Security Advisory Bulletin 066, including several critical flaws rated 9.9 a...

7 Jul 2026
STOCKSTAY Backdoor Uses Malicious RDP Files and WinRAR Exploit to Target Ukraine
TI
Cyber Security News

STOCKSTAY Backdoor Uses Malicious RDP Files and WinRAR Exploit to Target Ukraine

A newly detailed cyber-espionage campaign is using fake remote desktop files and a recently patched WinRAR flaw to plant a stealthy backdoor called STOCKSTAY on...

7 Jul 2026
Public GitHub Issue Could Trick GitHub Agentic Workflows Into Leaking Private Repo Data
TI
The Hacker News

Public GitHub Issue Could Trick GitHub Agentic Workflows Into Leaking Private Repo Data

A public issue can trick GitHub Agentic Workflows into leaking the contents of an organization's private repositories, researchers at Noma Security have shown. ...

7 Jul 2026
The GitHub Actions Attack Pattern Your CI Security Scanners Miss
TI
Bleeping Computer

The GitHub Actions Attack Pattern Your CI Security Scanners Miss

ActiveState explains how GitHub Actions attack chains can evade traditional CI security scanners, why passing a scan doesn't guarantee a secure pipeline, and ho...

7 Jul 2026
Windows Adds Microsoft Execution Containers to Secure AI Agent Workflows
TI
Cyber Security News

Windows Adds Microsoft Execution Containers to Secure AI Agent Workflows

Microsoft has introduced Microsoft Execution Containers (MXC), a new security capability designed to protect AI agent workflows on Windows, marking a significan...

7 Jul 2026
U.S. Cyber Defense Agency Reportedly Using Anthropic’s Mythos to Audit Government Code Repositories
TI
Cyber Security News

U.S. Cyber Defense Agency Reportedly Using Anthropic’s Mythos to Audit Government Code Repositories

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is reportedly deploying Anthropic’s advanced AI model, Mythos, to audit federal governmen...

7 Jul 2026
Critical PHP PDO Driver Bugs Expose Firebird SQL Injection and PostgreSQL DoS Risks
TI
Cyber Security News

Critical PHP PDO Driver Bugs Expose Firebird SQL Injection and PostgreSQL DoS Risks

A newly disclosed pair of flaws in PHP’s database driver layer shows that even mature code can hide dangerous surprises. The bugs live inside PHP Data Obj...

7 Jul 2026
Court Filing Reveals Windows Device ID Helped FBI Trace Alleged Scattered Spider Hacker
TI
The Hacker News

Court Filing Reveals Windows Device ID Helped FBI Trace Alleged Scattered Spider Hacker

U.S. prosecutors linked an alleged Scattered Spider hacker to a break-in at a luxury jewelry retailer using a persistent Windows device ID, according to a newly...

7 Jul 2026
Writer AI Flaw Could Let Agent Previews Leak Session Tokens Across Tenants
TI
The Hacker News

Writer AI Flaw Could Let Agent Previews Leak Session Tokens Across Tenants

Cybersecurity researchers have disclosed details of a now-patched critical session isolation vulnerability in Writer, an enterprise generative artificial intell...

7 Jul 2026
CISA Reportedly Using Anthropic’s Mythos to Scan Government Software for Flaws
TI
Security Week

CISA Reportedly Using Anthropic’s Mythos to Scan Government Software for Flaws

The audits are reportedly being spearheaded by CISA’s Attack Surface Evaluation team, a specialized unit tasked with conducting digital defense assessments and ...

7 Jul 2026
Critical Adobe ColdFusion Vulnerability Exploited in Attacks
TI
Security Week

Critical Adobe ColdFusion Vulnerability Exploited in Attacks

Hackers are exploiting a recently patched critical vulnerability (CVE-2026-48282) in Adobe ColdFusion that carries a CVSS score of 10/10. The post Critical Adob...

7 Jul 2026
← PreviousNext →