Every Old Vulnerability Is Now an AI Exploitability
Live threat intelligence feed

Targeted
Threat Intelligence

Aggregated threat intelligence from CISA, NVD, and leading security publications. AI-curated. Updated every 30 minutes.

Threat Matrix — All Time
Vuln
Malware
Intel
Advisory
Breach
APT
Critical
274
90
32
12
17
1
High
165
226
71
23
58
4
Medium
87
94
58
14
63
12
Low
20
22
14
12
Hover to preview · click to filter
All-time · 3529 totalintensity = volume
LIVE
PoC and Technical Details Released for SharePoint Remote Code Execution Vulnerability·Google Dialogflow CX Bug Allowed Attackers to Hijack AI Conversations·DuckDuckGo browser now blocks YouTube video ads·GitHub 'Verified' Commits Can Be Rewritten Into New Hashes Without Breaking Signatures·First-Ever 1- Click Android 17 Exploit Allows Attackers to Gain Full Control Over Your Android Phone·The Verification Step Is the New ATO Battleground in 2026·Telco giant KDDI says data breach affects over 12 million people·GitHub Copilot Refuses Harmful Requests in Chat, Then Writes Them in Code·New Bit2Watt attack uses AI GPU workloads to destabilize power grids·CISA Urges Immediate Patching of Exploited ColdFusion, Langflow, Joomla Flaws·Critical Vulnerability Exposes GitHub Agentic Workflows to Prompt Injection·CISA Warns of Adobe ColdFusion Path Traversal Vulnerability Exploited in Attacks·EU now one step away from reviving private message scanning rules·CISA orders feds to prioritize patching Langflow auth bypass flaw·70% of WordPress Sites Running Outdated PHP Versions Exposed to Cyberattacks·PoC and Technical Details Released for SharePoint Remote Code Execution Vulnerability·Google Dialogflow CX Bug Allowed Attackers to Hijack AI Conversations·DuckDuckGo browser now blocks YouTube video ads·GitHub 'Verified' Commits Can Be Rewritten Into New Hashes Without Breaking Signatures·First-Ever 1- Click Android 17 Exploit Allows Attackers to Gain Full Control Over Your Android Phone·The Verification Step Is the New ATO Battleground in 2026·Telco giant KDDI says data breach affects over 12 million people·GitHub Copilot Refuses Harmful Requests in Chat, Then Writes Them in Code·New Bit2Watt attack uses AI GPU workloads to destabilize power grids·CISA Urges Immediate Patching of Exploited ColdFusion, Langflow, Joomla Flaws·Critical Vulnerability Exposes GitHub Agentic Workflows to Prompt Injection·CISA Warns of Adobe ColdFusion Path Traversal Vulnerability Exploited in Attacks·EU now one step away from reviving private message scanning rules·CISA orders feds to prioritize patching Langflow auth bypass flaw·70% of WordPress Sites Running Outdated PHP Versions Exposed to Cyberattacks·

Latest IntelligencePage 99

Search by keyword →
CISA Warns of Drupal Core SQL Injection Vulnerability Exploited in Attacks
TI
Cyber Security News

CISA Warns of Drupal Core SQL Injection Vulnerability Exploited in Attacks

CISA has issued an urgent alert regarding a critical SQL injection vulnerability in Drupal Core, tracked as CVE-2026-9082, which is now being actively exploited...

25 May 2026
GitHub Adds Staged Publishing to npm to Block Automated Supply Chain Attacks
TI
Cyber Security News

GitHub Adds Staged Publishing to npm to Block Automated Supply Chain Attacks

GitHub has introduced a major security upgrade to the npm ecosystem with the general availability of staged publishing and new install-time controls, aimed at r...

25 May 2026
Hackers Use Browser-Locking CypherLoc Kit to Push Fake Microsoft Support Calls
TI
Cyber Security News

Hackers Use Browser-Locking CypherLoc Kit to Push Fake Microsoft Support Calls

A newly identified scareware kit called CypherLoc is locking victims’ browsers and tricking them into calling fake Microsoft support lines. The kit has be...

25 May 2026
TrapDoor Supply Chain Attack Spreads Credential-Stealing Malware via npm, PyPI, and CratesIO
TI
The Hacker News

TrapDoor Supply Chain Attack Spreads Credential-Stealing Malware via npm, PyPI, and CratesIO

A new coordinated cross-ecosystem software supply chain attack campaign has targeted npm, PyPI, and Crates.io to distribute credential-stealing malware. The ca...

25 May 2026
Pentest Agent Suite – Bug Bounty Framework for Claude Code and 6 AI Coding Tools
TI
Cyber Security News

Pentest Agent Suite – Bug Bounty Framework for Claude Code and 6 AI Coding Tools

A fully autonomous bug-bounty framework called Pentest Agent Suite has been open-sourced, delivering 50 specialized security agents, 26 slash commands, 19 CLI t...

25 May 2026
Wireshark 4.6.6 Released With Fix for Dissector Crash via Malformed Packet Injection
TI
Cyber Security News

Wireshark 4.6.6 Released With Fix for Dissector Crash via Malformed Packet Injection

The Wireshark Foundation has released Wireshark 4.6.6, addressing a critical security vulnerability in the ROHC (Robust Header Compression) protocol dissector t...

25 May 2026
Hackers Compromised 34 Packages in npm, PyPI, and Crates in New Supply Chain Attack
TI
Cyber Security News

Hackers Compromised 34 Packages in npm, PyPI, and Crates in New Supply Chain Attack

New TrapDoor supply chain campaign, an active attack deploying 34 malicious packages and over 384 related versions across npm, PyPI, and Crates.io to steal deve...

25 May 2026
Ghost CMS SQL injection flaw exploited in large-scale ClickFix campaign
TI
Bleeping Computer

Ghost CMS SQL injection flaw exploited in large-scale ClickFix campaign

A large-scale campaign is exploiting a critical SQL injection vulnerability (CVE-2026-26980) in Ghost CMS to inject malicious JavaScript code that triggers Clic...

24 May 2026
Top 10 Best Malware Sandbox Tools for Security Teams in 2026
TI
Cyber Security News

Top 10 Best Malware Sandbox Tools for Security Teams in 2026

The cybersecurity landscape in 2026 is defined by unprecedented sophistication. Threat actors are leveraging generative AI, highly evasive polymorphic code, and...

24 May 2026
PyrsistenceSniper – Tool that Detects 117 Persistence Malware Techniques on Windows, Linux, and macOS
TI
Cyber Security News

PyrsistenceSniper – Tool that Detects 117 Persistence Malware Techniques on Windows, Linux, and macOS

PyrsistenceSniper is an advanced tool for detecting offline persistence, enabling cybersecurity analysts to identify 117 separate persistence mechanisms across ...

24 May 2026
Charter Communications confirms data breach as hackers threaten leak of 42 million records
TI
Cyber Insider

Charter Communications confirms data breach as hackers threaten leak of 42 million records

Charter Communications has confirmed a cybersecurity incident after the ShinyHunters extortion group claimed it breached the telecommunications giant and stole ...

23 May 2026
Laravel Lang packages hijacked to deploy credential-stealing malware
TI
Bleeping Computer

Laravel Lang packages hijacked to deploy credential-stealing malware

A supply chain attack targeting the Laravel Lang localization packages has exposed developers to a sophisticated credential-stealing malware campaign after atta...

23 May 2026
npm Adds 2FA-Gated Publishing and Package Install Controls Against Supply Chain Attacks
TI
The Hacker News

npm Adds 2FA-Gated Publishing and Package Install Controls Against Supply Chain Attacks

GitHub has rolled out new controls for npm to improve the security of the software supply chain, giving maintainers the ability to explicitly approve a release ...

23 May 2026
Packagist Supply Chain Attack Infects 8 Packages Using GitHub-Hosted Linux Malware
TI
The Hacker News

Packagist Supply Chain Attack Infects 8 Packages Using GitHub-Hosted Linux Malware

A new "coordinated" supply chain attack campaign has impacted eight packages on Packagist including malicious code designed to run a Linux binary retrieved from...

23 May 2026
Italy disrupts CINEMAGOAL piracy app that stole streaming auth codes
TI
Bleeping Computer

Italy disrupts CINEMAGOAL piracy app that stole streaming auth codes

Italian authorities have dismantled a piracy ecosystem centered around the CINEMAGOAL app that provided access to various streaming platforms, including Netflix...

23 May 2026
Claude Mythos AI Finds 10,000 High-Severity Flaws in Widely Used Software
TI
The Hacker News

Claude Mythos AI Finds 10,000 High-Severity Flaws in Widely Used Software

Anthropic on Friday disclosed that Project Glasswing has helped uncover more than 10,000 high- or critical-severity vulnerabilities across some of the most "sys...

23 May 2026
Nginx-poolslip Vulnerability Enables DoS and Code Execution Attacks — Patch Now!
TI
Cyber Security News

Nginx-poolslip Vulnerability Enables DoS and Code Execution Attacks — Patch Now!

A newly disclosed flaw in one of the world’s most widely deployed web servers is forcing administrators into another emergency patch cycle. Tracked as CVE...

23 May 2026
‘Underminr’ Vulnerability Lets Attackers Hide Malicious Connections Behind Trusted Domains
TI
Security Week

‘Underminr’ Vulnerability Lets Attackers Hide Malicious Connections Behind Trusted Domains

The stealthy vulnerability impacts roughly 88 million domains and can be exploited to bypass DNS filtering and hide command-and-control traffic. The post ‘Under...

23 May 2026
Laravel-Lang PHP Packages Compromised to Deliver Cross-Platform Credential Stealer
TI
The Hacker News

Laravel-Lang PHP Packages Compromised to Deliver Cross-Platform Credential Stealer

Cybersecurity researchers have flagged a fresh software supply chain attack campaign that has targeted multiple PHP packages belonging to Laravel-Lang to deliv...

23 May 2026
Hackers Exploit F5 BIG-IP Appliance to Gain SSH Access and Pivot Into Enterprise Linux Networks
TI
Cyber Security News

Hackers Exploit F5 BIG-IP Appliance to Gain SSH Access and Pivot Into Enterprise Linux Networks

A multi-stage intrusion attack where a threat actor exploited an internet-facing F5 BIG-IP edge appliance as the entry point for a widespread, identity-focused ...

23 May 2026
← PreviousNext →