Cybersecurity

Google’s Gemini 3.5 Flash Cyber AI hunts and patches code flaws

Google DeepMind launched Gemini 3.5 Flash Cyber, a specialized AI model for vulnerability discovery and patching.The model is exclusively available to governments and trusted...

ServiceNow AI flaw exploited in wild, patch now

Threat actors are actively exploiting CVE-2026-6875, a critical sandbox escape vulnerability in the ServiceNow AI Platform.The flaw, rated 9.5 on the CVSS scale, allows...

FakeGit campaign uses 800 fake AI tools to spread SmartLoader malware

Cybersecurity researchers uncovered nearly 7,600 malicious GitHub repositories in the FakeGit campaign, with over 800 posing as AI skills or MCP servers.The repositories deliver...

7-Zip XZ flaw enables remote code execution

A critical heap-based buffer overflow vulnerability, tracked as CVE-2026-14266, was discovered in 7-Zip's XZ archive handler.An attacker could achieve remote code execution by tricking...

Hugging Face Hacked by Autonomous AI Agent System

Open-source AI platform Hugging Face was hacked by an autonomous AI agent system that gained unauthorized access to internal datasets and credentials.The attack originated...

Critical Nginx Flat Allows Unauthenticated Remote Code Execution

F5 patched a critical nginx heap buffer overflow (CVE-2026-42533) rated 9.2 on CVSS v4, affecting versions since 2011.The flaw allows remote code execution if...

Sandworm Uses ClickFix Fake CAPTCHA to Target Ukraine

Russian state-sponsored hackers from the Sandworm group are using fake CAPTCHA checks to trick Ukrainian targets into executing malware.The campaign, attributed to sub-cluster UAC-0145,...

WordPress core hit by zero-click RCE bug, patch now live

WordPress patched a pre-authentication remote code execution flaw in versions 6.9.5 and 7.0.2 on July 17, 2026.The bug, found by Adam Kues of Searchlight...

Latest news

SourTrade Malware Built in Browser Using Bun Runtime

SourTrade malvertising campaign targets cryptocurrency investors by assembling malware inside the victim's browser using a legitimate Bun runtime.It operates...

Critical Fastjson flaw lets attackers hijack Spring Boot apps

A critical remote code execution vulnerability (CVE-2026-16723, CVSS 9.0) affects Alibaba's Fastjson library versions 1.2.68 through 1.2.83 when used...

Micron Stock Split 2026? Odds Rise as MU Tops $900

Micron Technology stock has surged above $900, fueling speculation about its first stock split in over two decades.The company...