Vulnerabilities
21 stories[UPDATE] [kritisch] Microsoft Windows: Mehrere Schwachstellen
Critical Windows vulnerabilities enable privilege escalation, RCE, and security bypass - patch immediately.
CERT-Bund (BSI)10/10IngressNightmare: CVE-2025-1974 - 9.8 Critical Unauthenticated Remote Code Execution Vulnerabilities in Ingress NGINX
CVE-2025-1974 enables unauthenticated cluster takeover in 40% of Kubernetes environments running Ingress NGINX.
Wiz BlogCVE-2025-19749.810/10RCE vulnerability in OpenSSH: everything you need to know
OpenSSH remote code execution vulnerability affects every Linux server connection, requiring immediate patching across enterprise infrastructure.
Wiz BlogCVE-2024-63878.110/10Backdoor in XZ Utils allows RCE: everything you need to know
Sophisticated supply chain attack embedded backdoor in XZ compression library, affecting SSH authentication on Linux systems.
Wiz BlogCVE-2024-309410.010/10Two new critical Spinnaker vulns allow RCE and production access
r/netsecCVE-2026-326049.910/10Adobe Patches Actively Exploited Zero-Day That Lingered for Months
Adobe patches zero-day in Acrobat/Reader actively exploited for four months via malicious PDFs.
Dark Reading9/10Three Microsoft Defender Zero-Days Actively Exploited; Two Still Unpatched
Three Microsoft Defender zero-days actively exploited for privilege escalation, two remain unpatched.
THN (Feedburner)9/10A Shortcut to Coercion: Incomplete Patch of APT28's Zero-Day Leads to CVE-2026-32202
r/blueteamsecCVE-2026-322024.39/10MOVEit WAF Critical Security Bulletin – April 2026 – (CVE-2026-3517, CVE-2026-3518, CVE-2026-3519, CVE-2026-4048, CVE-2026-21876)
r/blueteamsecCVE-2026-35178.49/10Microsoft April 2023 Patch Tuesday Highlights: everything you need to know
Active exploitation of privilege escalation flaw combined with critical RCE vulnerability demands immediate Windows patching.
Wiz BlogCVE-2023-215549.89/10CVE-2023-25610 a critical RCE vulnerability in FortiOS: everything you need to know
Buffer underwrite in FortiOS admin interface enables unauthenticated remote code execution against network perimeters.
Wiz BlogCVE-2023-256109.89/10OWASSRF, a new exploit for Exchange vulnerabilities, exploited in the wild: everything you need to know
OWASSRF bypass technique defeats previous Exchange workarounds, forcing immediate patching for email infrastructure protection.
Wiz BlogCVE-2022-410808.89/10Hell’s Keychain: Supply-chain vulnerability in IBM Cloud Databases for PostgreSQL allows potential unauthorized database access
IBM Cloud PostgreSQL supply chain vulnerability demonstrates how hardcoded secrets enable build system manipulation.
Wiz Blog9/10AttachMe: critical OCI vulnerability allows unauthorized access to customer cloud storage volumes
Oracle Cloud flaw enabled cross-tenant storage access, demonstrating fundamental cloud isolation risks for enterprises.
Wiz Blog9/10Version 1.0: Microsoft Windows IKE - Kritische Schwachstelle gefährdet Windows VPN-Server
BSI warns of critical Windows IKE vulnerability endangering Windows VPN servers across Germany.
BSI-IT-Sicherheitsmitteilungen (BITS)9/10[UPDATE] [hoch] Atlassian Bamboo, Bitbucket, Confluence, Jira: Mehrere Schwachstellen
Critical Atlassian suite vulnerabilities enable RCE across Bamboo, Bitbucket, Confluence, and Jira.
CERT-Bund (BSI)9/10Remote Code Execution in GitHub.com and GitHub Enterprise Server (CVE-2026-3854)
r/cybersecurityCVE-2026-38548.89/10[NEU] [hoch] cURL: Mehrere Schwachstellen
Critical cURL vulnerabilities affect virtually every networked application and API integration across enterprise environments.
CERT-Bund (BSI)9/10[NEU] [UNGEPATCHT] [mittel] GNU libc: Mehrere Schwachstellen
Unpatched core library flaws threaten all Linux systems with arbitrary code execution capabilities.
CERT-Bund (BSI)9/10CISA orders feds to patch Windows flaw exploited as zero-day
Active zero-day exploitation prompts federal emergency patching mandate for Windows enterprise environments.
BleepingComputer9/10Microsoft stopft Lücke mit Risiko-Höchstwertung in Entra ID
Heise Security9/10
AI Security
20 storiesWhat Anthropic’s Mythos Means for the Future of Cybersecurity
Anthropic's Claude Mythos autonomously finds and weaponizes vulnerabilities, reshaping cybersecurity fundamentally.
Schneier on Security10/10Google Fixes Critical RCE Flaw in AI-Based 'Antigravity' Tool
Critical RCE in Google's AI 'Antigravity' tool via prompt injection allowed sandbox escape and arbitrary code execution.
Dark Reading9/10Mythos and Cybersecurity
Anthropic restricts access to Claude Mythos AI model deemed too dangerous for public release due to vulnerability exploitation.
Schneier on Security9/10LMDeploy CVE-2026-33626 Flaw Exploited Within 13 Hours of Disclosure
Critical LMDeploy LLM toolkit vulnerability exploited within 13 hours of disclosure, highlighting AI infrastructure risks.
THN (Feedburner)CVE-2026-336267.59/10Project Glasswing Proved AI Can Find the Bugs. Who's Going to Fix Them?
Anthropic delays Project Glasswing AI vulnerability discovery tool, giving early access to major tech companies first.
THN (Feedburner)9/10SGLang CVE-2026-5760 (CVSS 9.8) Enables RCE via Malicious GGUF Model Files
Critical CVE-2026-5760 (CVSS 9.8) in SGLang enables RCE via malicious GGUF model files.
THN (Feedburner)CVE-2026-57609.89/10Can AI Attack the Cloud? Lessons From Building an Autonomous Cloud Offensive Multi-Agent System
Multi-agent AI systems demonstrate autonomous cloud attack capabilities with critical security implications.
Unit 42 (Palo Alto)9/10Fracturing Software Security With Frontier AI Models
Frontier AI models demonstrate autonomous zero-day discovery capabilities, revolutionizing vulnerability research.
Unit 42 (Palo Alto)9/10Parsing Agentic Offensive Security's Existential Threat
Analysis of agentic offensive security threats from frontier LLMs like Claude Mythos and GPT-5.5.
Dark Reading9/10Mythos Changed the Math on Vulnerability Discovery. Most Teams Aren't Ready for the Remediation Side
Anthropic's Claude Mythos Preview enables AI-driven vulnerability discovery at unprecedented scale, outpacing remediation.
THN (Feedburner)9/10PARASITE: Conditional System Prompt Poisoning to Hijack LLMs
PARASITE attack poisons system prompts conditionally to hijack LLMs via supply chain compromise.
arXiv Crypto & Security9/10MEASER: Malware embedding attacks on open-source LLMs
MEASER attack embeds malware into open-source LLMs, creating supply chain security risks.
arXiv Crypto & Security9/10After Mythos: New Playbooks For a Zero-Window Era
New AI models like Claude Mythos eliminate patch windows by instantly weaponizing vulnerabilities autonomously.
THN (Feedburner)9/10How are you securing the "execution-layer" for AI agents like Cursor or Claude Code to prevent destructive API calls?
r/AskNetsec9/10Blocked standalone AI tools but teams are still feeding data to Copilot and Notion AI in approved SaaS how do I even see this
r/AskNetsec9/10[Research] Full-chain RCE in Microsoft Semantic Kernel & Agent Framework 1.0 (6 Bypasses)
r/netsec9/10Anthropic Claude Code Leak Reveals Critical Command Injection Vulnerabilities
Lobsters (Security)9/10Hackers are exploiting a critical LiteLLM pre-auth SQLi flaw
Critical pre-auth SQLi in LiteLLM gateway exposes sensitive AI infrastructure data across enterprise deployments.
BleepingComputerCVE-2026-422089.89/10Claude Mythos Has Found 271 Zero-Days in Firefox
Mozilla's breakthrough AI vulnerability hunting found 271 Firefox zero-days since February, signaling industry-wide shift.
Schneier on Security9/10What is Mythos AI and why could it be a threat to global cybersecurity?
The Guardian Cybercrime9/10
Threat Intel
9 storiesFIRESTARTER Backdoor Hit Federal Cisco Firepower Device, Survives Security Patches
FIRESTARTER backdoor compromises federal Cisco Firepower device, persists through security patches and updates.
THN (Feedburner)9/10SentinelLABS just cracked a 20-year-old mystery: Fast16, a state-grade sabotage tool that predates Stuxnet by five years
r/ReverseEngineering9/10Ransomware attacks targeting VMware ESXi servers: everything you need to know
VMware ESXi ransomware campaigns exploit virtualization vulnerabilities critical to European data center operations.
Wiz BlogCVE-2021-219748.89/10CVE-2022-27518 exploited in the wild by APT5: everything you need to know
Nation-state APT5 campaign exploiting Citrix ADC zero-day highlights urgency of patching network appliances exposed to internet.
Wiz BlogCVE-2022-275189.89/10Inside Lazarus: How North Korea uses AI to industrialize attacks on developers
Lobsters (Security)9/10Firestarter malware survives Cisco firewall updates, security patches
Firestarter malware persists on Cisco firewalls through updates, prompting US-UK agency warnings.
BleepingComputer9/10UAT-4356's Targeting of Cisco Firepower Devices
UAT-4356 APT actively exploits Cisco Firepower devices using n-day vulnerabilities for persistent access.
Cisco TalosCVE-2025-203339.99/10VECT 2.0 Ransomware Irreversibly Destroys Files Over 131KB on Windows, Linux, ESXi
VECT 2.0 ransomware's flawed encryption irreversibly destroys files over 131KB, making recovery impossible.
THN (Feedburner)9/10Vercel April 2026 security incident
Hacker News (Security)8/10
Cloud
4 storiesChaosDB: How we hacked thousands of Azure customers’ databases
Critical Azure Cosmos DB flaw granted full admin privileges to any customer's database without authentication.
Wiz Blog10/10OMIGOD: Critical Vulnerabilities in OMI Affecting Countless Azure Customers
Four critical vulnerabilities in Azure's OMI agent affected vast numbers of Linux VMs across the platform.
Wiz Blog9/10[NEU] [hoch] Microsoft Entra ID: Schwachstelle ermöglicht Darstellen falscher Informationen
Microsoft Entra ID SSRF vulnerability enables spoofing attacks - critical for Azure AD environments.
CERT-Bund (BSI)9/10[UPDATE] [hoch] Microsoft Cloud-Produkte: Mehrere Schwachstellen
Microsoft Cloud RCE and privilege escalation flaws - immediate patching required for Azure/M365 users.
CERT-Bund (BSI)9/10
DevSecOps
4 storiesThe Vercel breach: OAuth attack exposes risk in platform environment variables
Hacker News (Security)9/10pushed unified vuln dashboard with live criticals to public github repo. team is melting down
r/AskNetsec9/10Researchers Discover Critical GitHub CVE-2026-3854 RCE Flaw Exploitable via Single Git Push
Critical GitHub RCE vulnerability CVE-2026-3854 allows authenticated users to achieve code execution via git push.
THN (Feedburner)CVE-2026-38548.89/10GitHub fixes RCE flaw that gave access to millions of private repos
RCE vulnerability granted unauthorized access to millions of private enterprise repositories on GitHub platform.
BleepingComputerCVE-2026-38548.89/10
OT/IoT Security
2 storiesGlobal Campaign Discovered with Modbus PLCs Targeted and China-Geolocated Infrastructure Observed
r/blueteamsec9/10Lotus Wiper Attack Targets Venezuelan Energy Firms, Utilities
Critical infrastructure wipers now blend advanced LotL techniques with energy sector targeting across Latin America.
Dark Reading9/10