Recent Advisories

Severity ID Title Vendor Product Date Type
CRITICAL 9.8 TRENDMICROBLOG:...

From Langflow to Monero: Inside CVE-2026-33017 Cryptominer_TRENDMICROBLOG:D6D82F6102E243699FEABC242F869EE4

We tracked a cryptocurrency-mining campaign exploiting CVE-2026-33017, which revealed how threat actors are now scanning exposed AI application inf...

N/A N/A TRENDMICROBLOG
NONE HACKREAD:A41968...

New CryptoBandits Malware Uses USB Drives and Tor to Steal Crypto_HACKREAD:A419683ACF762DB1E281C5DEA5248AF1

Microsoft researchers warn of a new dual-action cryptocurrency clipper (CryptoBandits Malware) spreading through USB devices to alter wallet addres...

N/A N/A HACKREAD
NONE MALWAREBYTES:32...

Meta pauses controversial employee-tracking program after security review_MALWAREBYTES:3217C4695DDE3B50CC9820CDF4D81613

Meta has paused a controversial employee‑tracking program after an internal security review found that highly granular keystroke and screen‑capture...

N/A N/A MALWAREBYTES
NONE AKAMAIBLOG:F7FF...

AI Reconnaissance: The Missing Layer in Chatbot Security_AKAMAIBLOG:F7FF735B9CED18324CEDEF05F2700342

{“lastseen”:”2026-06-23T13:36:50″,”description”:””,”published”:”2026-06-23T15:00:...

N/A N/A AKAMAIBLOG
NONE HACKREAD:FBA757...

2 Scattered Spider-Linked Hackers Plead Guilty Over £39M TfL Cyberattack_HACKREAD:FBA7572946AB7B0A7A3BA36351A5085B

Two teenagers face sentencing after admitting to a massive Scattered Spider cyberattack that hit Transport for London (TfL) and US healthcare netwo...

N/A N/A HACKREAD
NONE MALWAREBYTES:9D...

Hackers steal passport and driver’s license data of 3 million Texans_MALWAREBYTES:9D69E222B6856BBA3932F0F2D0EB9073

You can change a password and cancel a card. But replacing a passport or driver's license number every time someone leaves yours unsecured in a ven...

N/A N/A MALWAREBYTES
NONE SCHNEIER:50F4F7...

Anthropic’s Fable 5 Model Jailbroken Within Days_SCHNEIER:50F4F7230D43E3BC04D9A48F355AFA7C

Fable 5 is the supposed safe version of Anthropic's Mythos Preview, with guardrails to ensure that it can't be used to create cyberattacks. Well, ...

N/A N/A SCHNEIER
NONE HACKREAD:A12835...

The Evolution of iGaming Fraud: What Security Teams Should Expect in 2027_HACKREAD:A12835505DD5B7C87C9F7B3FCD193AAD

Learn how AI, deepfakes, synthetic identities and fraud-as-a-service may reshape iGaming risk, and what security teams can do to detect future thre...

N/A N/A HACKREAD
NONE THN:C8E3569189F...

Agentic AI: The Weapon That No Longer Needs a Warrior_THN:C8E3569189F8451F92B2576E7286E31A

![](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg5YrdKJuy4ZmnWf_7L2RdXqS2QWC2BHJIbGsapJLmmYy1hBXfHxE7WMk-itWDkh-oCbAr8-CZOiUTyLftdM6...

N/A N/A THN
NONE H1:3817602

Node.js: Node –run POSIX positional argument escaping allows shell command injection_H1:3817602

# ## Summary Node.js `node --run -- ` attempts to append positional arguments to a package script after escaping each argument for the shell. ...

N/A N/A HACKERONE