This website uses cookies
Read our Privacy policy and Terms of use for more information.
Weekly deep dive on cybersecurity threats, AI security, and digital defence strategies — plus daily tactical tips. Stay hardened.
I consent to receive newsletters via email. Terms of use and Privacy policy.
May 25, 2026
Langflow's permissive CORS and a SameSite=None cookie let any web page run arbitrary Python as an authenticated user — no credentials required, active exploitation confirmed.
May 22, 2026
Poisoned developer tool allows attackers to exfiltrate and sell 3,800 internal code repositories.
May 21, 2026
No vulnerability in the extension itself was needed: a stolen publisher token, a hidden orphan commit in the official nrwl/nx repository, and Marketplace trust did the work — confirming that IDE extensions hold direct access to every credential a developer carries.
May 20, 2026
Georgia Tech's Vibe Security Radar formally attributed 35 CVEs to AI-generated code in March 2026 — up from 6 in January — while a researcher at Aikido Security demonstrated that hallucinated package names reach 237 repositories before any package exists, giving attackers a ready-made supply chain entry point.
May 19, 2026