World’s First AI-Built Zero-Day Exploit: Hackers Used AI to Create a 2FA Bypass — And Nearly Pulled It Off
Google's GTIG confirmed the first zero-day exploit built by AI — a 2FA bypass targeting a popular open-source admin tool,…
CVEs, exploits, pentesting & threat intel
Google's GTIG confirmed the first zero-day exploit built by AI — a 2FA bypass targeting a popular open-source admin tool,…
Microsoft reveals how Russia's Turla group (FSB Center 16) evolved its Kazuar backdoor into a modular P2P botnet with Kernel,…
A critical FunnelKit Funnel Builder vulnerability is being actively exploited to inject credit card skimmers into 40,000+ WooCommerce checkout pages.…
CloudZ RAT with its Pheno plugin exploits Microsoft Phone Link to steal SMS OTPs from Windows PCs without touching your…
TeamPCP's Mini Shai-Hulud worm compromised 170+ npm and PyPI packages including TanStack, Mistral AI, and UiPath in just 6 minutes…
Microsoft detected 8.3 billion phishing threats in Q1 2026. QR code phishing surged 146% as attackers use images to bypass…
NGINX Rift (CVE-2026-42945) is a critical 9.2 CVSS heap buffer overflow enabling unauthenticated RCE on NGINX servers. Present since 2008,…
ShinyHunters breached Instructure's Canvas LMS affecting 8,800+ institutions and 275 million people. Instructure paid the ransom — a decision cybersecurity…
Microsoft confirmed CVE-2026-42897, an actively exploited Exchange Server zero-day that lets attackers execute JavaScript by sending a crafted email. All…
Get 20+ curated tech stories, tutorials, and a free tool every week. Join 10,000+ developers.
No spam. Unsubscribe anytime.