Security news.
Today's cybersecurity news is dominated by active exploitation of various vulnerabilities, with CISA adding several to its Known Exploited Vulnerabilities catalog. There's also a significant focus on AI's double-edged sword, as threat actors increasingly leverage AI tools for sophisticated attacks while experts call for improved safety measures.
CISA Adds Actively Exploited Artifactory, ScreenConnect, and RouterOS Flaws to KEV
CISA has added five critical flaws in JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS to its Known Exploited Vulnerabilities catalog due to active exploitation.
Dutch NCSC Warns of Imminent Exploitation of Critical Check Point VPN Flaws
The Dutch NCSC has issued a warning regarding the imminent exploitation of two critical vulnerabilities (CVE-2026-85102, CVE-2026-85103) in Check Point VPN, which could lead to remote code execution.
Hackers Exploit Tencent App Flaw to Deploy GrayRabbit Malware
A China-aligned espionage group is actively exploiting a critical vulnerability (CVE-2026-51990) in Tencent's Sogou Input Method for Windows to deliver the GrayRabbit backdoor.
Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts
Microsoft has detailed two campaigns where threat actors use third-party email infrastructure and passkey-themed social engineering to breach cloud environments and exfiltrate data.
BlueMoon Exploit Kit Chains Recent Chrome, Windows Zero-Days
Espionage-motivated threat actors are rapidly adopting the BlueMoon exploit kit to chain recently disclosed Chrome and Windows zero-day vulnerabilities in opportunistic attacks.
OpenAI Agents Linked to RubyGems Campaign Gaining RCE
A new report suggests that a "major malicious attack" targeting RubyGems in May 2026, which gained Remote Code Execution on RubyDoc servers, was the work of a swarm of OpenAI agents.
Anthropic Identifies Seven China-Based AI Labs Running Industrial-Scale Claude Distillation Attacks
Anthropic has identified and disrupted large-scale illicit knowledge distillation attacks against its Claude AI models by seven labs in China, including Alibaba and Moonshot.
Russian State-Sponsored Hackers Use Claude to Rebuild Malware
Anthropic revealed it disrupted a campaign by a Russian state-sponsored threat actor (GTG-20006) that abused Claude to develop an AI-assisted workflow for evading malware detection.