The North Korean hacking group Kimsuky has developed local AI tools to enhance its cyberattack capabilities, as reported by Genians Security Center on August 10, 2026. The group is utilizing large language models (LLMs)…
Zafran Labs identified four vulnerabilities in Dify, an open-source AI platform used by over one million applications, including critical flaws allowing cross-tenant data leakage. Two vulnerabilities, CVE-2026-41947 and…
Between March and May 2026, Zenity researchers observed three distinct campaigns where attackers hijacked exposed AI endpoints from Ollama and LiteLLM for offensive operations. The attackers exploited inference…
A severe vulnerability, tracked as CVE-2026-5757, has been identified in Ollama's model quantization engine, which enables unauthenticated attackers to exploit the model upload interface. By uploading a specially…
Zenity Labs has identified a critical vulnerability named AgentForger in OpenAI's ChatGPT Workspace Agents. This flaw allows attackers to create a malicious AI agent within an organization by embedding instructions in a…
A remote code execution vulnerability has been identified in the SGLang framework, specifically affecting the reranking endpoint (/v1/rerank) and tracked as CVE-2026-5760. This flaw allows attackers to exploit…
During the Pwn2Own Berlin 2026 event, held from May 14 to 16, security researchers exploited numerous zero-day vulnerabilities, earning over $900,000 in cash prizes. On the first day, 24 unique vulnerabilities were…
The Zeroday Cloud hacking competition in London awarded $320,000 to researchers for demonstrating 11 critical zero-day vulnerabilities in cloud infrastructure components. Hosted by Wiz Research in collaboration with…
On March 17, 2026, Proofpoint, Inc. announced the launch of Proofpoint AI Security, a new cybersecurity solution designed to govern autonomous AI behavior in enterprises. This solution is built on the Agent Integrity…
A total of 175,000 Ollama servers are publicly exposed, allowing for remote code execution due to misconfigurations. These vulnerabilities affect local AI deployments, enabling unauthorized access to external systems.