DIGEST
Curated intelligence at the intersection of offensive security and AI — the latest items, newest first. See Top Picks for the highest-impact stories.
Friday, August 21, 2026
HIGHTrojanized npm Packages Deliver AI-Powered RedC2 Linux BackdoorHIGHThousands of Leaked AWS Keys Remain Active, Granting Full Account ControlCRITICALMicrosoft Defender Driver Can Be Abused to Delete Security SoftwareHIGHAndroid Car Head Units Infected with Proxy Botnet MalwareCRITICALGitLab Code Injection Flaw (CVE-2026-19478) Under Active ExploitationCRITICALMicrosoft Patches Critical Entra ID Flaw (CVSS 10.0)
Thursday, August 20, 2026
CRITICALRust Crates Compromised in Supply Chain Attack, Delivering MalwareHIGHUnprecedented Number of Apple Users Receive Spyware AlertsCRITICALAI-Generated Exploit Scripts Target Siemens S7 PLCs in U.S. Critical InfrastructureHIGHCryptographic Context Injection Attack Can Steal Grok Chat DataHIGHIsolated-vm Flaw Allows JavaScript Sandbox Escape to HostCRITICALCritical NetScaler Flaw Allows Authentication BypassCRITICALZimbra SNMP Flaw Actively Exploited for Remote Code ExecutionHIGHZombie Card Attack Revives Expired Visa Cards for Contactless PaymentsHIGHCDN Tsunami Attack Exploits HTTP/3 Translation for DoS AmplificationCRITICALNASA AIT-GUI Flaws Allow Unauthenticated Spacecraft Command ExecutionHIGHMalicious Firefox Extensions Steal Web3 Wallet Secrets
Wednesday, August 19, 2026
MEDIUMOpenAI Pauses Frontier RL Training to Enhance AI Security DefensesCRITICALCISA Warns of Actively Exploited macOS, SharePoint, vCenter, and Microsoft IKE Flaws
Friday, August 14, 2026
CRITICALMaximum Severity SAP Commerce Cloud Flaw Actively ExploitedHIGHAPT Group HoneyMyte Upgrades CoolClient with Kernel-Level Windows RootkitCRITICALCitrix NetScaler Pre-Auth RCE Vulnerability Disclosed
Wednesday, August 12, 2026
CRITICALAPI Flaw in OpenAI, Anthropic, Google AI Models Exposes Internal Reasoning and SecretsCRITICALAdobe Patches Critical ColdFusion and Campaign Classic FlawsCRITICALAttackers Actively Exploiting VMware vCenter Vulnerability for Persistent Access
Tuesday, August 11, 2026
CRITICALMicrosoft Patches 398 Flaws, Including a Windows Driver Zero-Day Under Active AttackHIGHKimwolf v7 Android Botnet Uses HTTP/2 DDoS and Ethereum ENS for ResilienceCRITICALAI-Assisted Exploit Chain Achieves Unauthenticated RCE in SharePointHIGHDeadLock Ransomware Uses Polygon Smart Contracts for Extortion InfrastructureHIGHOpenAI Launches GPT-5.6-Cyber for Exploit Development with Reduced SafeguardsCRITICALMalicious SIM Cards Can Execute Attacker Code on Cellular IoT DevicesHIGHMozilla Revokes Firefox and Thunderbird Linux Signing Key After ExposureHIGHHead Mare APT Exploits Unpatched TrueConf Server to Deliver BackdoorsHIGHMalicious MCP Servers Can Exfiltrate Secrets from AI Coding AgentsHIGHProject CAV3RN Continues with Google Apps Script C2 and DNS-based RoutingCRITICALHackers Breach Polish Power Plant via Private Cellular Network, Shut Down Turbine