PublicCVE

Newsroom

Security reporting and coverage, linked to the vulnerabilities it references.

GISEC GLOBAL
Dark Reading · just now
Nearly 700 rogue AI agents coordinated in the Hugging Face attack
BleepingComputer · 2h ago

New details about the July attack on Hugging Face reveal that hundreds of AI agents driven by OpenAI's internal IM1 model coordinated the compromise through an unauthorized message board. [...]

Chinese Routers Sold Worldwide Contain Backdoors
Dark Reading · 4h ago

An untold numbers of ZBT routers sold around the world as white-label products come with several implants built by the manufacturer.

OpenAI Says Reward Hacking Drove AI Agents to Exploit Zero-Days and Breach Hugging Face
The Hacker News · 5h ago

OpenAI on Wednesday revealed that reward hacking was a key driver behind the artificial intelligence (AI)-powered hack of Hugging Face last month, adding that it found evidence of misaligned behavior as early as late May. The incident, the company said, took place during cybersecurity evaluations of several OpenAI models, and that it was mainly fueled by what it described as a "highly capable

Agentic AI Risks, CVE Program Concerns Permeate Black Hat USA 2026
Dark Reading · 6h ago

This installment of the Reporters' Notebook video series discusses the topics that dominated the cybersecurity conference, such as AI's effects on vulnerability reporting and security research.

PaperCut warns of NG, MF flaw exploited in zero-day attacks
BleepingComputer · 7h ago

PaperCut is warning that hackers are actively exploiting a vulnerability in all versions of its PaperCut NG and PaperCut MF print management software in zero-day attacks. [...]

Manchester Airports Group says hackers stole travelers' data
BleepingComputer · 7h ago

The Manchester Airports Group (MAG) disclosed that hackers breached its systems and stole customer data, including Wi-Fi sign-ups from Manchester, Stansted, and East Midlands airports. [...]

Next.js Patches Critical AVIF and Windows Flaws Enabling Unauthenticated RCE
The Hacker News · 8h ago

Credit: Hacktron Vercel has released security patches for two critical-severity vulnerabilities in the Next.js web framework, both of which allow unauthenticated remote code execution, one exploitable via specially crafted AVIF image files and the other through a path traversal flaw affecting servers that use a Windows filesystem. The Windows path traversal, tracked as CVE-2026-75604&

ThreatsDay: 296K IoT Botnet, 100+ Water Systems Targeted, SharePoint RCE Chain + 27 New Stories
The Hacker News · 9h ago

A fake login page. A fake security scan. A fake productivity app. Apparently, pretending to be useful is still one of the easier ways into a machine. The rest of the week gets stranger: botnets borrowing AI, command traffic hiding in public infrastructure, malicious tools waiting before showing their real behavior, exposed systems getting scanned, and exploit windows shrinking again. Different

Claude, Codex, and Hermes installed unowned code inside corporate networks
Ars Technica Security · 10h ago

227 install commands were found in corporate docs pointing at code nobody owns.

How Threat Research and MDR Help SMBs Build a Defensive Edge
BleepingComputer · 10h ago

Threat research gives security teams insight into how attackers operate, while MDR turns that intelligence into faster detection and response. ESET explains how combining threat intelligence, continuous monitoring, and human expertise can help SMBs strengthen their defenses. [...]

Android 17 adds ECH support to make web browsing harder to track
BleepingComputer · 10h ago

Google is introducing new network security protections in Android 17 to strengthen connection privacy, address cellular vulnerabilities, and protect the privacy of users' home networks. [...]

Amazon Kiro Prompt Injection Can Exfiltrate Sensitive Data Through Kiro Powers
The Hacker News · 10h ago

Cybersecurity researchers have disclosed details of a vulnerability in Amazon Kiro, an artificial intelligence (AI)-powered, agentic integrated development environment (IDE), that could facilitate data exfiltration via prompt injection and Kiro Powers. The security flaw, which does not have a CVE identifier, works against Kiro IDE 0.7.45 on Windows, according to Mindguard. The latest version of

Australia arrests alleged TeamPCP hackers behind supply-chain attacks
BleepingComputer · 10h ago

Australian authorities have arrested and charged two young men accused of belonging to TeamPCP, a hacking group linked to a string of far-reaching developer supply chain attacks. [...]

How OpenAI let a mob of LLM agents game a test and ransack Hugging Face
Ars Technica Security · 11h ago

Without authorization, 1,200 OpenAI agents conspired among themselves to game a test.

Microsoft rolls out fix for Windows 11 crashes, gaming issues
BleepingComputer · 11h ago

Microsoft has started rolling out a permanent fix for a known issue that causes system crashes and gaming issues on Windows 11 devices. [...]

Webinar: How Google Workspace breaches happen and what to do next
BleepingComputer · 11h ago

Google Workspace breaches can begin with social engineering or forgotten third-party integrations rather than sophisticated exploits. This webinar examines real-world breaches, what happens during the critical first hours, and the security controls that can make the greatest difference. [...]

Learn How to Build Security Operations Ready for AI-Powered Attacks
The Hacker News · 12h ago

Security teams have spent years trying to detect threats faster. AI is changing the harder part: how much time defenders have left to act. Advanced AI models can now help attackers discover vulnerabilities, generate exploit code, and move through weaknesses faster than traditional security processes were built to handle. The challenge is no longer just finding another vulnerability or

Alleged TeamPCP Hackers Charged in Australia Over Major Supply Chain Attacks
The Hacker News · 12h ago

The Australian Federal Police (AFP) has charged two Western Australian men with a combined total of 14 offences over their alleged role in TeamPCP, the cybercrime group behind the March 2026 compromise of the open-source security scanners Trivy and Checkmarx KICS and the AI gateway LiteLLM. Louis Michael Gaebler, 23, and Ruben Ian Thomson, 21, appeared in Perth Magistrates Court on August 27,

What the Data Says About AI in Security Operations in 2026
The Hacker News · 12h ago

AI is officially mainstream in security operations. According to Prophet Security's State of AI in Security Operations 2026 report (produced from ViB’s survey of 250+ cybersecurity pros), 40% of security teams now use AI daily. Another 56% are currently testing it out, and only 4% have no plans to adopt it. For the teams already using AI, what is actually changing? Here are the ten biggest

Russian Hackers Phish EU Officials Over Messaging Apps
Dark Reading · 12h ago

EU governments are trying to move away from popular messaging apps as nation-state threat groups shift their focus from email to Signal and WhatsApp.

Carhartt data breach exposes information of 12.9 million accounts
BleepingComputer · 13h ago

The ShinyHunters extortion group has published sensitive data from nearly 13 million accounts stolen from clothing retailer giant Carhartt earlier this month, according to data breach notification service Have I Been Pwned. [...]

Spark RAT Targets Cambodia, Abuses Vulnerable OPSWAT Driver to Disable Security Tools
The Hacker News · 13h ago

Individuals and organizations in Cambodia have emerged as the target of a new campaign that delivers an open-source remote access trojan (RAT) called Spark RAT. "The samples employ diverse lure themes, suggesting an effort to appeal to a broad range of potential victims. These include government notices, public health materials, real estate-related content, and other topics," Acronis Threat

GoCaracal Malware Uses Ethereum Smart Contract to Fetch Replacement C2 Address
The Hacker News · 14h ago

Threat actors linked by Arctic Wolf to Dark Caracal with medium confidence deployed a previously undocumented Go-based malware framework, GoCaracal, during a June 2026 intrusion at an unnamed communications organization in Venezuela. GoCaracal provides operators with remote shell access and payload execution, while the extended profile adds browser data theft, keylogging, remote desktop control

CISA orders feds to patch Citrix NetScaler RCE flaw by Saturday
BleepingComputer · 14h ago

CISA has ordered U.S. government agencies to patch their Citrix NetScaler appliances against an actively exploited remote code execution vulnerability by Saturday. [...]

ATF confirms “major incident” after recent Qilin breach claims
BleepingComputer · 15h ago

ATF, the regulatory agency that enforces federal laws governing firearms and explosives in the United States, has confirmed that one of its systems was compromised after breach claims made by the Qilin ransomware gang. [...]

New GPUThor Rowhammer Defeats ECC on NVIDIA RTX A6000 to Gain Host Root Access
The Hacker News · 15h ago

Academic researchers have disclosed a Rowhammer attack impacting NVIDIA workstation GPUs with GDDR6 memory that defeats error correction codes (ECC), the mitigation NVIDIA recommends against GPU Rowhammer, and enables denial-of-service (DoS) and privilege escalation to a root shell. Dubbed GPUThor, the attack was developed by researchers at the University of Toronto, who hammered four DRAM

CISA Adds Six Exploited Flaws to KEV, Including NetScaler, Linux, and SQL Server Bugs
The Hacker News · 17h ago

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added six flaws to its Known Exploited Vulnerabilities (KEV) catalog, including a high-severity security vulnerability impacting Citrix NetScaler ADC and NetScaler Gateway, citing evidence of active exploitation. The vulnerabilities are listed below - CVE-2019-1068 - A remote code execution vulnerability in 

News
Critical Avada WordPress theme flaw enables zero-click RCE
BleepingComputer · 1d ago

A critical vulnerability chain in the popular Avada theme for WordPress can be exploited by an unauthenticated attacker to execute arbitrary PHP code on the server. [...]

Dark Caracal Adds New Malware to Cyber Espionage Arsenal
Dark Reading · 1d ago

GoCaracal is a new modular malware framework that broadens Dark Caracal's capabilities to steal data and maintain access to victims.