The intelligence feedUpdated as material events develop
Analysis / Research / Guidance
The Briefing
Independent reporting on AI security, exploited vulnerabilities, and enterprise cyber risk. Built to help defenders understand what changed and what deserves action.
Anthropic's June 2, 2026 expansion of Project Glasswing turns AI-driven vulnerability discovery into a critical infrastructure scaling story. The real shift is not just that Claude Mythos can find more flaws. It is that software vendors, maintainers, and defenders now need industrial-speed triage, disclosure, and patching to keep up.
The Windows Netlogon vulnerability moved from serious patch item to urgent incident-response priority on June 1, 2026, when fresh reporting showed active exploitation in the wild. If you run Windows domain controllers, CVE-2026-41089 is no longer something to queue behind the next maintenance window.
The WP Maps Pro vulnerability moved from plugin flaw to live operational risk on May 31, 2026, when fresh reporting showed attackers trying to create rogue administrator accounts on exposed WordPress sites. If your site runs the plugin, this is not a niche bug. It is a direct path to full content, plugin, and data control.
The FortiClient EMS vulnerability behind CVE-2026-35616 is no longer just an appliance flaw. Fresh May 29 reporting shows attackers using enterprise endpoint management itself to push EKZ Infostealer across managed devices, turning a trusted update path into a fleet-wide risk.
Gogs zero-day RCE turns a routine pull request flow into a server takeover path for self-hosted Git platforms. Fresh May 29 reporting shows why this is not just another developer bug, but a trust failure that can expose private repos, credentials, and downstream systems.
2026 FIFA World Cup scams are already scaling across fake FIFA websites, typosquatted domains, phishing kits, and counterfeit ticket offers. Fresh May 28 reporting shows the fraud infrastructure is not hypothetical anymore. It is live, global, and built to turn fan urgency into stolen data and stolen money.
Fresh May 27 reporting on Anthropic's Claude Code security guidance plugin and self-hosted sandbox shows how AI coding security is shifting left into the development workflow itself. For teams adopting coding agents, the real story is not convenience. It is where trust, review, and execution boundaries now live.
Fresh May 26 reporting on CERT-In's new guidance shows why defenders can no longer treat internet-facing patching as a weekly chore when AI-assisted attackers are collapsing the time between discovery and exploitation.
Fresh May 25 reporting shows the TrapDoor campaign planting malicious npm, PyPI, and Crates.io packages that target crypto and AI developers, steal secrets across workstations and cloud accounts, and abuse AI project config files for persistence.