
Zscaler: Two Active Campaigns Hijack AI Agents for Crypto Theft
Zscaler found two active campaigns that embed hidden instructions in web pages, causing 4 of 26 AI agents tested to

Zscaler found two active campaigns that embed hidden instructions in web pages, causing 4 of 26 AI agents tested to

Apple’s iCloud+ Hide My Email vulnerability still exposes real addresses at 100% success, with multiple claimed fixes from Apple failing

Unit 42 documented phantom squatting, with 13,229 malicious URLs active on AI-hallucinated domains and 250,000 more unregistered sites available to

Sysdig identified JADEPUFFER, the first ransomware campaign run by an LLM autonomous agent exploiting CVE-2026-33017 in Langflow to complete full

CISA confirmed active exploitation of CVE-2026-45659, a CVSS 8.8 SharePoint Server deserialization flaw enabling authenticated remote code execution in enterprise

Red teamers showed that email inbox prompt injection turns Claude Desktop into a reverse shell when MCP connectors with command

Adobe patched seven maximum-severity CVSS 10.0 vulnerabilities in ColdFusion and Campaign Classic, enabling unauthenticated code execution and privilege escalation.

Synacktiv disclosed an unpatched unauthenticated RCE in Argo CD’s repo-server component that can lead to full Kubernetes cluster takeover with

Cato AI Labs disclosed CVE-2026-50548 and CVE-2026-50549 in Cursor IDE, CVSS 9.8 flaws enabling zero-click prompt injection to escape the

Check Point researchers showed DeepSeek generated InfernoGrabber 9000, near-functional browser ransomware using Chrome’s File System Access API to encrypt files
Subscribe to the Daily Security Review Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.