IncidentZero-Day Built by AI: What Went Wrong
Google s Threat Intelligence Group has documented a zero-day exploit that shows signs of AI-assisted development. This exploit was deployed by a criminal group against a popular open-source web-based
Expert perspectives on application security, compliance, and emerging threats
IncidentGoogle s Threat Intelligence Group has documented a zero-day exploit that shows signs of AI-assisted development. This exploit was deployed by a criminal group against a popular open-source web-based
IncidentOn May 9, 2026, Checkmarx published a malicious version of its Jenkins AST plugin to the public Jenkins plugin repository. This compromised version was designed to exfiltrate user credentials and pote
IncidentWhat Happened Cyera disclosed a critical heap out-of-bounds read vulnerability in Ollama, a popular open-source framework for running large language models locally. The flaw, tracked as CVE-2026-7482
IncidentWhat Happened Intruder s security team scanned over 1 million exposed AI services across the public internet, uncovering widespread security failures in AI infrastructure. The scan revealed that 31% o
Get weekly security insights and compliance updates delivered to your inbox.
IncidentSummary of the Incident Between late February and early March 2026, attackers published five malicious Rust crates to crates.io disguised as time utility libraries. These packages executed code during
IncidentWhat Happened On March 23, 2026, malicious artifacts were published through a compromised Checkmarx GitHub repository. Seven days later, on March 30, attackers exfiltrated data from systems that had c
IncidentYou re building an AI coding agent using GitHub s MCP Server. Your agent needs database credentials to run queries, so you hardcode them in the server configuration. Within hours, those credentials ar
IncidentA contact form shouldn t give an attacker root access to your automation server. But in n8n versions prior to 2.10.1, that s exactly what could happen. Let s walk through how CVE-2026-27577 and CVE-20
IncidentOn March 17, 2025, security researchers at Cyera disclosed CVE-2026-7482 , a critical vulnerability in Ollama that allowed attackers to extract arbitrary memory contents from running AI models. The fl
IncidentWhat Happened In August 2025, threat actor UNC6426 compromised the nx npm package, gaining full AWS administrator access within 72 hours. The attack began with a vulnerable pull_request_target workflo
IncidentOn May 1, 2026, attackers began exploiting CVE-2026-29014 , a PHP code injection vulnerability in MetInfo CMS with a CVSS score of 9.8. This flaw allows unauthenticated remote code execution, giving a
IncidentWhat Happened In the Firefox 150 release, Mozilla disclosed 271 vulnerabilities discovered by Anthropic s Mythos AI model. This was a controlled discovery process, not a breach, revealing flaws in cod
IncidentThe Security Gap in AI Systems Cobalt s State of Pentesting Report highlights a significant gap between AI system security and traditional application security. When pentesters examined AI and LLM imp
IncidentWhat Happened Apache HTTP Server version 2.4.66 contained a double-free vulnerability in its HTTP/2 protocol handling code (CVE-2026-23918). Discovered by Bartlomiej Dmitruk and colleagues, this flaw
IncidentWhat Happened In 2025, attackers compromised the axios JavaScript package—one of the most widely used HTTP client libraries in the Node.js ecosystem—through a malicious transitive dependency. The atta
IncidentOn April 8, attackers compromised DAEMON Tools distribution infrastructure and replaced legitimate installers with trojanized versions. The attack continued through at least mid-April, affecting versi