AI Threat Intelligence

Threat intelligence, automated.

AI-researched threat write-ups, live IOC feeds, and MITRE ATT&CK mappings — human-reviewed before every publish. Built for defenders.

Threats tracked—
IOCs published—
MITRE techniques—
Last updated—
Latest Report
CRITICALvulnerability

CVE-2026-73570: Unauthenticated Command Injection in Zimbra

CVE-2026-73570 is a critical unauthenticated command injection vulnerability affecting Zimbra mail servers. Successful exploitation allows remote attackers to execute arbitrary commands, potentially leading to full system compromise of internet-facing mail infrastructure.

Read full report →
Recent Threats
CRITICALvulnerability

CVE-2026-76504: Cisco Catalyst SD-WAN Manager Authentication Bypass

A critical authentication bypass vulnerability (CVE-2026-76504) in Cisco Catalyst SD-WAN Manager allows unauthenticated remote attackers to gain admin privileges. The flaw stems from improper URI encoding handling, enabling attackers to bypass API authentication rules via crafted HTTP requests.

Read report →
HIGHvulnerability

OpenAI Disrupts Reasoning Extraction Campaign Linked to Moonshot AI

OpenAI has identified and disrupted a coordinated ‘distillation campaign’ aimed at illicitly extracting protected reasoning from its AI models. The activity, traced back to early July, has been attributed to individuals associated with the Chinese AI company Moonshot AI. This incident highlights a novel form of intellectual property theft targeting advanced AI capabilities.

Read report →
HIGHvulnerability

AI Coding Agents Expose Internal Company Data on GitHub

AI coding agents, when prompted to share screenshots of code changes, have inadvertently uploaded over 13,000 sensitive internal company images to public GitHub repositories. This exposure includes customer billing records and unreleased product features from more than 300 organizations, highlighting a significant data leakage risk in development workflows utilizing AI tools.

Read report →
HIGHphishing

Phishing Abuses RMM Tools for Persistent Access

Microsoft has observed phishing campaigns leveraging legitimate Remote Monitoring and Management (RMM) tools, specifically MSP360 RMM and ScreenConnect. Attackers use this method to establish redundant and persistent remote access channels on compromised systems. This tactic allows threat actors to maintain control for follow-on activities, bypassing traditional security controls.

Read report →
CRITICALcve

Apple Emergency Patch for iOS 26, macOS 26, macOS 15 (CVE-2026-86950)

Apple has released emergency patches for iOS 26, macOS 26, and macOS 15 to address a critical vulnerability, CVE-2026-86950, which is actively being exploited in the wild. Users of affected older operating system branches are urged to update immediately. iOS and macOS 27 are not impacted by this specific security flaw.

Read report →
HIGHvulnerability

CVE-2026-86950: Apple CoreGraphics Out-of-Bounds Write Leading to RCE

CVE-2026-86950 is an out-of-bounds write vulnerability in Apple’s CoreGraphics framework affecting iOS, iPadOS, and macOS. Processing a maliciously crafted file can lead to arbitrary code execution. Apple is aware of reports indicating in-the-wild exploitation against targeted individuals.

Read report →
CRITICALcve

Apple Zero-Day Vulnerability CVE-2026-86950 Weaponized in Targeted Attacks

Apple has confirmed active exploitation of CVE-2026-86950, an out-of-bounds write vulnerability, in targeted attacks. This zero-day flaw is being leveraged in a highly sophisticated manner. Users are advised to apply updates as soon as they become available to mitigate the risk.

Read report →
HIGHransomware

Keio Corporation Confirms Ransomware Attack Disrupting Business Systems

Keio Corporation, a major Japanese private railway operator, has confirmed a ransomware attack that disrupted some of its business systems over the weekend. While public transportation services were not affected, the incident impacted internal administrative and operational support functions. Investigations are ongoing to determine the full scope and nature of the attack.

Read report →

Transparently AI-authored

Every report on this site is researched and drafted by an AI agent, then reviewed and approved by a human analyst before publication. The Agent Logbook shows every step — sources consulted, enrichment calls, tokens used, and approval status — in real time.