Every Old Vulnerability Is Now an AI Exploitability
Live threat intelligence feed

Targeted
Threat Intelligence

Aggregated threat intelligence from CISA, NVD, and leading security publications. AI-curated. Updated every 30 minutes.

Threat Matrix — All Time
Vuln
Malware
Intel
Advisory
Breach
APT
Critical
274
90
32
12
17
1
High
165
226
71
23
58
4
Medium
87
94
58
14
63
12
Low
20
22
14
12
Hover to preview · click to filter
All-time · 3529 totalintensity = volume
LIVE
PoC and Technical Details Released for SharePoint Remote Code Execution Vulnerability·Google Dialogflow CX Bug Allowed Attackers to Hijack AI Conversations·DuckDuckGo browser now blocks YouTube video ads·GitHub 'Verified' Commits Can Be Rewritten Into New Hashes Without Breaking Signatures·First-Ever 1- Click Android 17 Exploit Allows Attackers to Gain Full Control Over Your Android Phone·The Verification Step Is the New ATO Battleground in 2026·Telco giant KDDI says data breach affects over 12 million people·GitHub Copilot Refuses Harmful Requests in Chat, Then Writes Them in Code·New Bit2Watt attack uses AI GPU workloads to destabilize power grids·CISA Urges Immediate Patching of Exploited ColdFusion, Langflow, Joomla Flaws·Critical Vulnerability Exposes GitHub Agentic Workflows to Prompt Injection·CISA Warns of Adobe ColdFusion Path Traversal Vulnerability Exploited in Attacks·EU now one step away from reviving private message scanning rules·CISA orders feds to prioritize patching Langflow auth bypass flaw·70% of WordPress Sites Running Outdated PHP Versions Exposed to Cyberattacks·PoC and Technical Details Released for SharePoint Remote Code Execution Vulnerability·Google Dialogflow CX Bug Allowed Attackers to Hijack AI Conversations·DuckDuckGo browser now blocks YouTube video ads·GitHub 'Verified' Commits Can Be Rewritten Into New Hashes Without Breaking Signatures·First-Ever 1- Click Android 17 Exploit Allows Attackers to Gain Full Control Over Your Android Phone·The Verification Step Is the New ATO Battleground in 2026·Telco giant KDDI says data breach affects over 12 million people·GitHub Copilot Refuses Harmful Requests in Chat, Then Writes Them in Code·New Bit2Watt attack uses AI GPU workloads to destabilize power grids·CISA Urges Immediate Patching of Exploited ColdFusion, Langflow, Joomla Flaws·Critical Vulnerability Exposes GitHub Agentic Workflows to Prompt Injection·CISA Warns of Adobe ColdFusion Path Traversal Vulnerability Exploited in Attacks·EU now one step away from reviving private message scanning rules·CISA orders feds to prioritize patching Langflow auth bypass flaw·70% of WordPress Sites Running Outdated PHP Versions Exposed to Cyberattacks·

Latest IntelligencePage 36

Search by keyword →
TI
Dark Reading

DifyTap Bugs Let Attackers 'Wiretap' AI Chat Histories

Four vulnerabilities allow attackers to exploit Dify, a platform for AI application building and management, to silently access and exfiltrate sensitive data....

22 Jun 2026
FFmpeg fixes PixelSmash flaw in widely used video decoder
TI
Bleeping Computer

FFmpeg fixes PixelSmash flaw in widely used video decoder

A newly disclosed FFmpeg flaw dubbed 'PixelSmash' could be exploited for remote code execution on Jellyfin servers under certain conditions, and can also trigge...

22 Jun 2026
23 ClawHub Plugins Abuse Official Org Scopes to Impersonate Trusted AI Agent Tools
TI
Cyber Security News

23 ClawHub Plugins Abuse Official Org Scopes to Impersonate Trusted AI Agent Tools

A new supply chain threat has surfaced in the AI agent ecosystem that is both subtle and serious. Researchers uncovered 23 plugins on the ClawHub registry publi...

22 Jun 2026
Windows RAT Uses Encrypted HTTP C2 and Registry Persistence After npm Infection
TI
Cyber Security News

Windows RAT Uses Encrypted HTTP C2 and Registry Persistence After npm Infection

A newly discovered malware campaign is targeting Windows systems through a deceptive package on the npm registry. Disguised as a legitimate CSS build tool, the ...

22 Jun 2026
Malicious GST Debit Note Attachment Deploys Remcos RAT Through Multi-Stage Loader
TI
Cyber Security News

Malicious GST Debit Note Attachment Deploys Remcos RAT Through Multi-Stage Loader

A sophisticated phishing campaign is actively targeting users in India by disguising malware as a routine GST debit note. The attack delivers a powerful remote ...

22 Jun 2026
FortiBleed campaign used custom FortiGate sniffer to steal credentials
TI
Bleeping Computer

FortiBleed campaign used custom FortiGate sniffer to steal credentials

Security firm SOCRadar says the large-scale FortiBleed campaign targeting Fortinet FortiGate devices used custom sniffers to harvest authentication secrets from...

22 Jun 2026
AryStinger Botnet Hijacks 4,300+ Routers to Build Global Attack Proxy Network
TI
Cyber Security News

AryStinger Botnet Hijacks 4,300+ Routers to Build Global Attack Proxy Network

A newly discovered botnet called AryStinger has quietly hijacked more than 4,300 routers across the globe, turning them into a silent army of attack proxies. Th...

22 Jun 2026
ShapedPlugin WordPress Pro Plugins Backdoored in Supply Chain Attack
TI
The Hacker News

ShapedPlugin WordPress Pro Plugins Backdoored in Supply Chain Attack

Multiple WordPress plugins from ShapedPlugin were compromised in a supply chain attack after unknown threat actors managed to tamper with the official release c...

22 Jun 2026
Microsoft says Windows 11 26H2 is coming soon, details upgrade process
TI
Bleeping Computer

Microsoft says Windows 11 26H2 is coming soon, details upgrade process

Microsoft has confirmed that Windows 11 version 26H2 will be the next feature update and that devices running Windows 11 24H2 and 25H2 will be able to upgrade u...

22 Jun 2026
TI
CIS Advisories

A Vulnerability in PAN-OS Could Allow for Authentication Bypass

A vulnerability has been discovered in the GlobalProtect portal and gateway of PAN-OS which could allow for authentication bypass. The PAN-OS GlobalProtect Port...

22 Jun 2026
FFmpeg ‘PixelSmash’ bug triggers code execution on media file open
TI
Cyber Insider

FFmpeg ‘PixelSmash’ bug triggers code execution on media file open

A critical vulnerability in FFmpeg, the widely used open-source multimedia framework, can be exploited through a specially crafted video file to achieve remote ...

22 Jun 2026
Microsoft fixes AutoGen Studio flaw that enabled code execution
TI
Bleeping Computer

Microsoft fixes AutoGen Studio flaw that enabled code execution

A vulnerability chain dubbed AutoJack in Microsoft's AutoGen Studio interface for prototyping AI agents could let attackers manipulate an agent into executing a...

22 Jun 2026
Microsoft Entra Conditional Access Policies Can Be Bypassed Via Nested App Authentication
TI
Cyber Security News

Microsoft Entra Conditional Access Policies Can Be Bypassed Via Nested App Authentication

Microsoft Entra Conditional Access Policies (CAPs), a core security control for Azure and Microsoft 365 tenants, were recently found vulnerable to a bypass tech...

22 Jun 2026
AI-Powered iOS Apps Leaking LLM API Credentials Through Network Traffic
TI
Cyber Security News

AI-Powered iOS Apps Leaking LLM API Credentials Through Network Traffic

AI-powered iOS applications are increasingly leaking large language model (LLM) API credentials through network traffic, exposing developers to large-scale abus...

22 Jun 2026
Apple Beats Studio Buds Vulnerability Allows Hackers to Eavesdrop on Users
TI
Cyber Security News

Apple Beats Studio Buds Vulnerability Allows Hackers to Eavesdrop on Users

Apple has addressed a high-severity vulnerability in the Beats Studio Buds that could allow nearby attackers to eavesdrop on users via the device’s microp...

22 Jun 2026
Researchers Detail DifyTap Flaws in Dify That Could Expose AI Chats Across Tenants
TI
The Hacker News

Researchers Detail DifyTap Flaws in Dify That Could Expose AI Chats Across Tenants

Cybersecurity researchers have disclosed details of four vulnerabilities in Dify, an open-source agentic workflow platform with more than 146,000 GitHub stars, ...

22 Jun 2026
TI
Dark Reading

Crypto Heist Fueled by Elaborate Fake Reputation-Boosting Campaign

Attackers are using multiple online channels — including GitHub, YouTube, and VirusTotal — to build an illusion of trust to spread a cross-platform clipboard hi...

22 Jun 2026
Klue Hack Leads to Data Breach Across Multiple Cybersecurity Companies
TI
Cyber Security News

Klue Hack Leads to Data Breach Across Multiple Cybersecurity Companies

A sophisticated supply chain attack on market intelligence platform Klue has compromised Salesforce data across at least nine organizations, including several h...

22 Jun 2026
Hackers Use RemotePC RMM and PowerShell Stagers to Deploy Prinz Eugen Ransomware
TI
Cyber Security News

Hackers Use RemotePC RMM and PowerShell Stagers to Deploy Prinz Eugen Ransomware

A newly identified ransomware group is using remote management software and scripted attack tools to compromise organizations and deploy a sophisticated encrypt...

22 Jun 2026
29-Year-Old ‘Squidbleed’ Vulnerability Discovered With the Aid of Claude Mythos Preview
TI
Cyber Security News

29-Year-Old ‘Squidbleed’ Vulnerability Discovered With the Aid of Claude Mythos Preview

A Heartbleed-style heap buffer overread lurking in Squid Proxy since 1997 can silently leak HTTP headers, including passwords and API keys, from other users on ...

22 Jun 2026
← PreviousNext →