On July 11, 2026, multiple malicious versions of the jscrambler npm package were published, exploiting a compromised npm publishing credential. The affected versions (8.14.0, 8.16.0, 8.17.0, 8.18.0, and 8.20.0) included…
During the Pwn2Own Berlin 2026 event, held from May 14 to 16, security researchers exploited numerous zero-day vulnerabilities, earning over $900,000 in cash prizes. On the first day, 24 unique vulnerabilities were…
Researchers from Tenet Security revealed a new attack method named 'GhostJacking' at DEF CON 34, which exploits AI agents' trusted access to manipulate infrastructure. This attack can reroute web and email traffic,…
In 2026, the Model Context Protocol (MCP) has been identified as a significant security risk due to its unverified package management and decentralized registry ecosystem. This vulnerability allows attackers to exploit…
On May 20, 2026, WordPress released version 7.0, which introduced an AI infrastructure that inadvertently exposed API keys due to a security vulnerability in the AI integration setup form. This flaw allows browser…
A new attack method has been discovered that exploits the Claude Desktop AI assistant, allowing attackers to achieve remote code execution on compromised machines. The attack begins with access to a third-party platform…
Zenity Labs disclosed a family of critical vulnerabilities known as PleaseFix, affecting agentic browsers including Perplexity Comet. These vulnerabilities enable zero-click agent hijacking, local file exfiltration, and…
In 2026, the rise of agentic AI is transforming how businesses operate, particularly in the financial services sector. This new technology allows for autonomous decision-making, which increases the potential impact of…