Vulnerabilities & Exploits
CVEs, zero-days, patching and exploited weaknesses.
How Google Catches AI Spam Clusters Before They Flood Your Search
Google’s Scalable Cluster Termination System uses infrastructure signals and generative artifacts to detect coordinated AI spam campaigns — shifting from content-level filters to cluster-level termination.
CISA Orders Federal Agencies to Patch Actively Exploited LangFlow Auth Bypass by Friday
The U.S. Cybersecurity and Infrastructure Security Agency has added a newly exploited IDOR flaw in the popular LangFlow AI-agent builder to its KEV catalog, giving FCEB agencies until Friday to remediate under BOD 26-04.
How a Silent Software Vulnerability Exposed 12 Million Users at Japan's KDDI and Partner ISPs
Logan Bastion breaks down the architecture failure behind the KDDI zero-day exploit, which exposed the email addresses and passwords of over 12 million users across five partner ISPs.
The Shadow in the Prompt: Understanding the Escalation of AI Vulnerabilities
As AI becomes integral to business operations, prompt injection has emerged as a primary security threat. This article explores how vulnerabilities in large language models are being exploited to facilitate large-scale malicious operations, including botnet assembly, and how security frameworks are evolving to counter these risks.
Zero-Day ColdFusion Flaw Hit by Attackers Hours After Adobe Disclosure
Attackers are exploiting a CVSS 10.0 path-traversal vulnerability in Adobe ColdFusion (CVE-2026-48282) within hours of patch release, prompting CISA to add it to its KEV catalog and issue a federal mandate under BOD 26-04.
Brands Exploited to Lure Job Seekers in Wide-Scale Phishing Operation
A persistent phishing campaign is impersonating more than 30 major global brands, exploiting legitimate CRM and marketing cloud services to execute nested redirect chains and steal Google account credentials via a convincing browser-based authentication mimicry technique.
AI Agent JadePuffer Ran Full Ransomware Attack Self-Correcting in 31 Seconds After Exploiting Langflow
An autonomous AI agent named JadePuffer executed the first fully end-to-end ransomware operation without human intervention, exploiting Langflow CVE-2025-3248, harvesting credentials across seven categories, pivoting to Nacos and MySQL via CVE-2021-29441, encrypting 1,342 config items, and fixing its own login error in 31 seconds.
June 2026 Patch Tuesday: Six Zero-Days, One Exchange Exploit, and the Researcher Who Broke the System
Microsoft fixed 200 flaws this Patch Tuesday—but the real story is how a single researcher’s protest exposed a broken security culture, and why Defender, BitLocker, and HTTP.sys are all now weapons in the wrong hands.
BioShocking: How Fictional Game Scenarios Expose AI Browser Vulnerabilities
A new prompt injection technique called 'BioShocking' demonstrates how browser-based AI agents can be manipulated into performing high-risk actions by framing them within game-like fictional contexts, bypassing safety guardrails.
Mapping the Exploit Speedrun: How Pre-Scanned Assets Fueled Rapid Attacks on Ivanti Sentry Flaws
Within 24 hours of Ivanti Sentry disclosing CVE-2026-10520 and CVE-2026-10523, threat actors used public proof-of-concept exploits to hijack vulnerable instances, leveraging pre-mapped internet-facing assets for immediate compromise.
The Teen Who Broke MGM: How Peter Stokes Became Scattered Spider’s Most Vulnerable Weapon
19-year-old dual U.S.-Estonian citizen Peter Stokes was arrested at Helsinki airport in April 2026 while attempting to flee to Japan, then extradited to Chicago to face fraud and conspiracy charges for his role in the Scattered Spider hacking collective's $100M+ ransom campaign against companies including MGM, Caesars, and DoorDash.
Your Voice Is a Biometric Target: How AI Cloning Exploits the Brain's Trust Wiring
New research reveals how AI voice cloning exploits vocal timbre to bypass human skepticism and force compliance. Learn the neuroscience behind these scams and practical defenses.