AWS Secrets Manager is a technology platform tracked across 10 threat clusters and 13 intelligence report mentions on ThreatCluster. First observed December 3, 2025; most recent activity July 15, 2026.
Security firm Tracebit has introduced a novel defense mechanism called 'context bombs' that can thwart AI-powered cyberattacks. By embedding specific strings of text within cloud decoy resources, these context bombs…
On July 11, 2026, multiple malicious versions of the jscrambler npm package were published, exploiting a compromised npm publishing credential. The affected versions (8.14.0, 8.16.0, 8.17.0, 8.18.0, and 8.20.0) included…
OrcaRouter Security Research released its AI Threat Report 2026, identifying prompt injection as the leading risk to large language model (LLM) applications, with a 340% increase in such attacks year-over-year. The…
On May 10, 2026, threat actors exploited CVE-2026-39987, a remote code execution vulnerability in the marimo notebook environment, to gain unauthorized access to internal databases. The attackers utilized a large…
A security flaw in AWS Bedrock's AgentCore Code Interpreter allows attackers to bypass network isolation through DNS queries. Researchers from BeyondTrust demonstrated that the sandbox mode permits outbound DNS queries…
Multi-agent AI systems are vulnerable to privilege abuse when agents delegate tasks across complex chains. This risk, classified by OWASP as Identity & Privilege Abuse, can lead to agents exceeding their original…
A recent Trendmicro report identified over 15,000 vulnerabilities across 19,000 open-source MCP servers, with a significant portion potentially influenced by AI-generated code. The research utilized a Gemini-powered AI…
On March 3, 2026, the threat actor FulcrumSec claimed responsibility for a data breach at LexisNexis Legal & Professional, resulting in the exfiltration of 2.04 GB of structured data from the company's AWS cloud…
A new wave of the Shai-Hulud malware has compromised nearly 500 npm packages, affecting over 26,000 GitHub repositories. This self-replicating worm, which targets developers' credentials and secrets, has been linked to…
On May 15, 2026, AWS introduced the AI Security Framework aimed at helping organizations secure AI workloads. The framework provides a structured model that aligns security controls with specific AI use cases, layers,…