Microsoft Discloses AI-Assisted Invoice Fraud and Passkey Phishing Campaigns
Microsoft has disclosed details of two active campaigns targeting enterprise cloud environments through AI-assisted executive impersonation and passkey-themed social engineering. The attacks leverage third-party email delivery infrastructure to bypass…
CISA KEV Alert: IBM Langflow CVE Enables Unauthenticated RCE on AI Workflow Platform
August 8, 2026 The U.S. Cybersecurity and Infrastructure Security Agency has added CVE-2026-9198 to its Known Exploited Vulnerabilities catalog. This critical flaw in IBM Langflow OSS allows unauthenticated attackers to execute remote code with superuser…
Hermes AI Agent Automates Post-Exploitation Inside Thailand Ministry of Finance
July 24, 2026 A threat actor deployed the open-source Hermes AI agent in unattended “YOLO” mode to automate post-exploitation inside Thailand’s Ministry of Finance. The operation was uncovered after the attacker left 585 files and 470…
Hugging Face AI Agent Breach
July 20, 2026 Hugging Face, the world’s largest open-source artificial intelligence platform, disclosed that attackers breached its production infrastructure using an autonomous AI agent system. The intrusion marks one of the first confirmed cases…
Ghostcommit Prompt Injection Attack Steals Secrets via AI Code Review Blind Spot
July 11, 2026 Researchers from the University of Missouri Kansas City’s ASSET Research Group have disclosed a new supply-chain attack called Ghostcommit. This technique hides malicious prompt-injection instructions inside a PNG image embedded in an…
Langflow CVE Critical RCE Deploys Monero Miner on AI Endpoints
June 30, 2026 On June 30, 2026, Trend Micro published a technical report confirming that threat actors are actively exploiting CVE-2026-33017, a critical unauthenticated remote code execution vulnerability in Langflow. The flaw carries a CVSS score of…
FBI Dismantles Outsider Enterprise AI Phishing Ring: $1.9B in Losses
June 14, 2026 The FBI, working alongside Google and Black Lotus Labs, has dismantled a massive China-based phishing-as-a-service operation called Outsider Enterprise. This AI-powered cybercrime ring operated thousands of fake websites and sent millions…
US Government Orders Anthropic Fable 5 Suspension Over Jailbreak
June 13, 2026 The US government issued an export control directive ordering Anthropic to suspend access to Fable 5 and Mythos 5 for all users worldwide. The order, issued on June 12, 2026, cites national security concerns over a reported jailbreak of the…
AI Agent Discovers 21 FFmpeg Zero-Days: CVE-2026-39210-39218
June 6, 2026 An autonomous AI security agent has uncovered 21 zero-day vulnerabilities in FFmpeg, the ubiquitous media processing library that powers browsers, streaming platforms, and countless applications worldwide. The findings mark a significant…