Related Threat Clusters
-
North Korean Hackers Target Open Source Software Supply Chain via npm Packages
Amazon's threat intelligence has linked a series of compromises of popular npm packages—axios, debug, chalk, and typo-crypto—to a North Korean hacking group known as Sapphire Sleet. The group employed social engineering…
11 articles · Updated July 29, 2026 -
INJ3CTOR3 Targets FreePBX Systems with JOMANGY Webshell and VoIP Toll Fraud
A cyber campaign attributed to the threat actor INJ3CTOR3 is targeting FreePBX systems, deploying a new PHP webshell named JOMANGY. This operation utilizes a six-layer persistence mechanism to maintain control over…
5 articles · Updated May 22, 2026 -
n8n Sandbox Escape Vulnerability Allows OS Command Execution
On July 22, 2026, n8n released a patch for a high-severity sandbox escape vulnerability (GHSA-gv7g-jm28-cr3m) rated 8.7 on CVSS 4.0. This flaw allows authenticated users to execute operating system commands via crafted…
3 articles · Updated July 30, 2026 -
OpenAI Codex Fails to Mitigate Linux Threats During Cyber Incident
A Linux user attempted to use OpenAI's Codex AI agent for incident response during a cyberattack but faced significant challenges. The user was unaware that at least two threat actors had compromised their system,…
2 articles · Updated April 22, 2026 -
AWS Kiro Vulnerability Allows Remote Code Execution via Hidden Web Text
A vulnerability in AWS Kiro, an AI-powered IDE, was disclosed on July 21, 2026, allowing attackers to execute code on a developer's machine through a hidden line of text on a webpage. The flaw bypasses Kiro's…
3 articles · Updated July 22, 2026 -
GuardFall Vulnerability Exposes Open-Source AI Agents to Shell Injection Attacks
A survey by Adversa AI revealed a critical shell injection vulnerability, named GuardFall, in 10 out of 11 popular open-source AI agents. This flaw allows attackers to bypass command filters, potentially leading to…
8 articles · Updated July 1, 2026 -
Critical RCE Vulnerability in BeyondTrust Software Requires Immediate Patching
BeyondTrust has issued a warning regarding a critical remote code execution (RCE) vulnerability in its Remote Support and Privileged Remote Access software. The flaw, tracked as CVE-2026-1731, allows unauthenticated…
1484 articles · Updated February 9, 2026 -
Critical Vulnerabilities Discovered in AI Orchestration Platforms
Research presented at DEFCON 34 revealed 14 critical and high severity vulnerabilities across seven AI orchestration platforms, including NocoBase, Flowise, Langflow, Dify, Activepieces, Kestra, and Apache Airflow.…
2 articles · Updated August 18, 2026 -
Prompt Injection Vulnerability in GitHub Actions AI Agents Exposes Secrets
Security researchers discovered a critical vulnerability in three AI agents integrated with GitHub Actions: Anthropic's Claude Code Security Review, Google's Gemini CLI Action, and Microsoft's GitHub Copilot. The…
12 articles · Updated April 15, 2026 -
Shai Hulud npm Worm Compromises Over 26,000 Repositories
The Shai Hulud worm has compromised more than 26,000 public repositories in a supply chain attack. The attack targeted various npm packages, exploiting vulnerabilities that allowed unauthorized access to these…
32 articles · Updated November 24, 2025
Recent Intelligence Reports
- Digital Forensics and Incident Response, Senior Consultant DFIR — Jobs24 · August 26, 2026
- Hacking your life with AI can get you hacked — Endorlabs · August 18, 2026
- Ai Agent Permissions — scalex.dev · August 7, 2026
- The Real AI Agent Attack Surface: Toolsets, Containers, and Privilege — Darkreading · August 4, 2026
- Sapphire Sleet — cloud.google.com · August 4, 2026
- n8n Sandbox Escape (CVSS 8.7): Patch and Harden Now — Ayautomate · July 29, 2026
- Johann Rehberger of Embrace The Red documented — embracethered.com · July 23, 2026
- Shell injection flaw found in 10 of 11 open-source AI agents | brief — Scworld · July 1, 2026