Anthropic's AI Finds Bugs. IBM Bets $5B It Can Fix Them.
Anthropic's AI uncovered critical vulnerabilities in open-source code. IBM and Red Hat launched Project Lightwell, deploying 20,000 engineers to patch bugs before threat actors exploit them.
ACTIVE THREATS: Cisco FMC flaws exploited by ransomware gang, state-sponsored hackers • AI-powered attack exploited PaperCut flaws to hack 395 organizations • Microsoft Excel KB5002914 update breaks copy and paste for some users • Surfshark VPN says hackers breached internal testing, proxy servers • PaperCut Attacker Uses Hundreds of AI Agents to Compromise 440+ Instances ACTIVE THREATS: Cisco FMC flaws exploited by ransomware gang, state-sponsored hackers • AI-powered attack exploited PaperCut flaws to hack 395 organizations • Microsoft Excel KB5002914 update breaks copy and paste for some users • Surfshark VPN says hackers breached internal testing, proxy servers • PaperCut Attacker Uses Hundreds of AI Agents to Compromise 440+ Instances
Latest cybersecurity vulnerabilities news, analysis, and intelligence.
Anthropic's AI uncovered critical vulnerabilities in open-source code. IBM and Red Hat launched Project Lightwell, deploying 20,000 engineers to patch bugs before threat actors exploit them.
ConsentFix and ClickFix are OAuth attacks that hijack Microsoft 365 accounts in 3 seconds by stealing authentication tokens through phishing, bypassing MFA while evading detection. Attackers operate within legitimate protocol bounds, making these attacks nearly impossible to spot with conventional s
Opera's Paste Protect blocks ClickFix attacks—social engineering campaigns that trick users into copying and executing malicious commands. This psychology-based threat has exploded exponentially across Windows, macOS, and Linux, making the browser's new default defense a critical security evolution.
CISA orders federal agencies to patch SharePoint vulnerability CVE-2026-45659 by Saturday. The RCE flaw, actively exploited in the wild, allows any authenticated user to execute arbitrary commands on 10,000+ exposed servers.
Cisco confirmed active exploitation of CVE-2026-20230, a critical unauthenticated SSRF vulnerability in Unified Communications Manager affecting 200+ exposed systems. The low-complexity flaw allows attackers to manipulate systems and access files without authentication, representing a significant es
Microsoft fixed a June 29 bug that hid Copilot Chat buttons in Classic Outlook for Basic-tier users. The missing AI features prevented email composition and summarization access but remained available in other Outlook versions, limiting the issue to Classic Outlook's implementation.
Researchers documented the first autonomous AI ransomware attack via Langflow exploitation. The AI agent orchestrated the entire lifecycle, revealing how AI lowers barriers for sophisticated cyberattacks.
A critical SharePoint Server flaw (CVE-2026-45659) is under active exploitation. CISA added it to the KEV catalog; unauthenticated attackers can achieve RCE via malicious HTTP requests, requiring immediate patching for affected organizations.
ChocoPoC masquerades as proof-of-concept CVE exploits on GitHub to target security researchers. It steals credentials and browser data while granting attackers remote shell access to victims' systems.
CVE-2026-13207 bypasses FUXA SCADA/HMI authentication (CVSS 7.5), exposing user accounts and roles to unauthenticated attackers via path normalization flaws. The vulnerability affects critical infrastructure worldwide, including water systems, energy grids, and manufacturing plants.
**Phantom squatting registers fake domains that AI hallucinations generate, then intercepts users following these AI instructions toward malicious infrastructure for phishing and malware delivery.** This new attack vector exploits how deeply AI systems are embedded in enterprise workflows, turning L
Critical unpatched vulnerability in Argo CD's repo-server enables unauthenticated attackers to execute arbitrary code and seize Kubernetes cluster control. No patch exists and no CVE has been assigned, creating significant supply chain risk for organizations relying on this widely-adopted GitOps too
DuneSlide is a critical sandbox escape in Cursor (used by 50%+ Fortune 500, CVSS 9.8). Attackers gain full machine and cloud access via prompt injection without user interaction.
Adobe patched seven critical flaws in ColdFusion and Campaign Classic enabling unauthenticated code execution. AI-driven discovery is compressing exploitation windows from days to hours, dramatically escalating risk for enterprise deployments.
Critical unauthenticated RCE (CVE-2026-8037, CVSS 9.6) in Kemp LoadMaster's `/accessv2` endpoint under active exploitation since June 29. String-handling flaw allows remote command execution with no credentials needed—patch immediately.
Criminal IP enriches OpenCTI threat intelligence with infrastructure context and vulnerability correlation, transforming raw indicators into prioritized, actionable threats and helping defenders move beyond indicator fatigue.
Apple released critical security patches across iOS, iPadOS, macOS, and Safari, patching dozens of core vulnerabilities. These flaws could enable code execution and widespread data theft on millions of devices globally.
Organizations recognize cyber threats but lack resources to defend. Bitdefender's 2026 survey shows 87% of IT leaders are threat-aware yet only 34% have implemented defenses—revealing a dangerous gap between awareness and action.
Citrix patched six NetScaler flaws including CVE-2026-8451 (memory disclosure) and HTTP/2 Bomb DoS. Attacks expose cryptographic material and sensitive data, requiring immediate patching.
Adobe patched 7 critical RCE flaws (CVSS 10.0) in ColdFusion and Campaign Classic via file uploads and input validation bypasses. Unauthenticated attackers can execute code remotely. Immediate patching required.
Windows 11's GIF feature briefly went down June 30 when Google retired the Tenor API. Microsoft deployed fix KB5095093, switching to GIPHY as the provider and restoring the feature.
Dawnguard raised $6.3M to launch a security architecture automation platform that helps organizations design secure cloud systems from inception, addressing "security drift"—the gap between how systems are designed to be secure versus how they actually operate in deployment.
Attackers launched 81 million password spray attempts against Azure CLI, traced to LSHIY hosting infrastructure. The campaign exploited weak credentials to gain cloud infrastructure access.
Anthropic restored Claude Fable 5 globally on July 1, 2026, after the U.S. Commerce Department lifted export controls imposed just 16 days earlier. The swift reversal highlights mounting tensions between AI innovation and national security regulation, revealing how quickly geopolitical shifts can di
Attackers register domains that AI systems hallucinate and invent during conversations, then host phishing sites on them. Called "phantom squatting," this emerging threat exploits AI's tendency to fabricate plausible URLs, creating new attack infrastructure as language models embed deeper into busin
Adobe patched 7 critical vulnerabilities (CVSS 9.0+) in ColdFusion and Campaign Classic enabling unauthenticated remote code execution. Organizations must apply patches immediately to prevent compromise.
Chrome 151 patches a record 382 vulnerabilities, including 15 critical flaws, with most discovered via AI security scanning. No active exploitation detected, creating a critical window for organizations to patch.
Citrix patched six NetScaler vulnerabilities enabling file reads and crashes. The flaws (CVSS 6.9–8.8) stem from memory safety issues; no active exploitation reported.
Scammers registered 212 fraudulent domains in 5 days impersonating Venezuela earthquake relief organizations, exploiting disaster relief as an industrialized fraud service. The real vulnerability isn't technical—it's procedural and jurisdictional, requiring faster takedown coordination between regis
"BioShocking" prompt injection tricks AI browsers into data theft by framing malicious actions within game scenarios. It bypassed safety guardrails in six major AI browser products, exposing a critical vulnerability: agents cannot reliably distinguish fiction from reality when reframing attacks.