Related Threat Clusters
-
AI-Driven Cyber Attack Compromises 440+ PaperCut Servers Globally
A Russian-speaking cyber actor has launched an AI-driven campaign exploiting vulnerabilities in PaperCut NG/MF, specifically CVE-2026-81578 and CVE-2026-82078. This attack has compromised at least 440 instances across…
5 articles · Updated September 9, 2026 -
Vibe Coding Tools Found to Generate Critical Security Flaws
A study by security startup Tenzai revealed that popular vibe coding platforms produce insecure code, including critical vulnerabilities, when responding to common programming prompts. The assessment, conducted in…
3 articles · Updated January 14, 2026 -
Microsoft June 2026 Patch Tuesday: Record 206 Vulnerabilities Addressed
On June 9, 2026, Microsoft released its largest Patch Tuesday update, addressing 206 vulnerabilities, including three zero-day flaws. Among the critical vulnerabilities, 32 were rated as critical, with 28 classified as…
57 articles · Updated June 9, 2026 -
Critical OpenAI Codex Flaw Exposes GitHub Tokens to Attackers
A critical command injection vulnerability in OpenAI's Codex has been discovered, allowing attackers to steal GitHub OAuth tokens from developers. The flaw originated from improper input validation during the branch…
4 articles · Updated April 1, 2026 -
Attackers Exploit Exposed AI Endpoints for Offensive Operations
Between March and May 2026, Zenity researchers observed three distinct campaigns where attackers hijacked exposed AI endpoints from Ollama and LiteLLM for offensive operations. The attackers exploited inference…
2 articles · Updated July 1, 2026 -
Critical Vulnerability in MCP Protocol Exposes 200,000 AI Servers to Remote Code Execution
A report by OX Security has identified a critical vulnerability in the Model Context Protocol (MCP) developed by Anthropic, potentially exposing over 200,000 AI servers to remote code execution. The flaw lies in the…
12 articles · Updated April 16, 2026 -
GitSpawn Vulnerabilities Allow Code Execution in AI Coding Agents
A series of vulnerabilities, termed GitSpawn, have been disclosed affecting multiple AI coding agents, including Claude Code, Codex, and Cursor. These flaws allow malicious Git configurations to execute arbitrary code…
8 articles · Updated September 2, 2026 -
Pwn2Own Berlin 2026: Major Exploits Target Windows 11 and Microsoft Exchange
During the Pwn2Own Berlin 2026 event, held from May 14 to 16, security researchers exploited numerous zero-day vulnerabilities, earning over $900,000 in cash prizes. On the first day, 24 unique vulnerabilities were…
26 articles · Updated May 15, 2026 -
Malicious Codex Tool Steals OpenAI Tokens from Developers
A malicious npm package named 'codexui-android' has been discovered, which masquerades as a legitimate remote UI for OpenAI Codex. This tool, downloaded approximately 27,000 times weekly, has been silently exfiltrating…
12 articles · Updated May 29, 2026 -
AI Tools Used in Ransomware Campaigns to Exploit Vulnerable Systems
A recent report from Gambit Security reveals that threat actors are leveraging AI tools like Claude Code and OpenAI Codex in ransomware operations. These tools have been used to breach internet-exposed VPN appliances,…
4 articles · Updated August 18, 2026
Recent Intelligence Reports
- PaperCut MF/NG flaws attacked with hundreds of AI agents | news — Scworld · September 10, 2026
- PaperCut Attacker Uses Hundreds of AI Agents to Compromise 440+ Instances — Thehackernews · September 10, 2026
- ZDI-26-649: (Pwn2Own) OpenAI Codex Improper Neutralization of Control Sequences Remote Code Execution Vulnerability — Zerodayinitiative · September 10, 2026
- ZDI-26-648: (Pwn2Own) OpenAI Codex External Control of System or Configuration Setting Remote Code Execution Vulnerability — Zerodayinitiative · September 10, 2026
- ZDI-26-650: (Pwn2Own) OpenAI Codex External Control of Configuration Setting Remote Code Execution Vulnerability — Zerodayinitiative · September 10, 2026
- ZDI-26-651: (Pwn2Own) OpenAI Codex External Control of System or Configuration Setting Remote Code Execution Vulnerability — Zerodayinitiative · September 10, 2026
- Agents Gone Wild: An AI-Orchestrated Global Campaign Against PaperCut NG/MF — Greynoise · September 9, 2026
- GitSpawn Flaw Enables Arbitrary Code Execution in Claude Code, Codex, Cursor and Grok — Gbhackers · September 3, 2026