Vulnerability Overview
Exploitation Activity
Exploitation Intelligence
A critical remote code execution (RCE) vulnerability has been identified in the Hugging Face Transformers library, tracked as CVE-2026-4372. This flaw allows attackers to execute arbitrary code during model loading by bypassing the trust_remote_code=False safeguard. The vulnerability affects all ver...
On June 4, 2026, Microsoft updated its 'Taxonomy of Failure Modes in Agentic AI Systems' based on a year of red teaming. The update highlights the emergence of zero-click attack chains that can bypass human-in-the-loop (HitL) controls, allowing attackers to exploit agentic AI systems without any use...
Cybercriminals are increasingly using legitimate system tools like PowerShell and WMI to deploy malware, creating stealthy threats that evade traditional defenses. The ANY.RUN Q1 2026 Cyber Risk report highlights a significant rise in loader-based attacks, which nearly doubled, alongside a 14.7% inc...