Rapid7 warns AI-accelerated vulnerability discovery and exploit development are overwhelming patch cycles, pushing defenders to focus on exposure, not CVSS.
Varonis researchers detail a Copilot Personal flaw dubbed CoSnitch, where the AI is socially engineered into exposing a hidden autorun path for one-click data theft.
New TwinLoot Python malware routes command-and-control through Microsoft 365 services like SharePoint and Teams, stealing credentials while evading detection.
Researchers show self-propagating mind virus payloads can jump between autonomous AI agents through persistent prompt files, expanding risks for memory-enabled LLM systems.
A critical arbitrary file upload flaw in the Forminator Forms plugin, tracked as CVE-2026-15748, exposes over 600,000 WordPress sites to potential takeover.
Researchers warn Ruby developers after 16 typosquatted RubyGems packages were caught dropping StubMaker, a Windows info-stealer for browser and crypto data.
Apple ships new macOS, iOS and iPadOS updates that patch dozens of WebKit vulnerabilities and a Telephony bug that could impact VPN security on Apple devices.