TIA · HYDRA

Cyber Signal

Denní řez z veřejných zdrojů. Neodebíráš to. Ono to prostě vychází.
Bez účtu. Bez e-mailu. Bez sledování.

DNEŠNÍ ŘEZ

12 položek ◢ Denně 06:00 UTC
SEDM DNÍ
položek za den
12Pá
12So
4Ne
1Po
12Út
12St
12Čt
V DIVOČINĚ
4/ 12

položek hlásí zneužití — ne proof of concept

POZORNOST
2 10
KATEGORIE
AI/agent5
patch-or-mitigation5
cloud/AI-stack4
crime4
supply-chain4
CVE3
ZDROJE
The Hacker News7
Dark Reading2
SecurityWeek2
CISA Advisories1

Třídy pozornosti = kolik pozornosti jsme položce věnovali. Nejsou to verdikty o závažnosti.

🎯CISA Flags Langflow RCE, Tomcat, and N-central Flaws as Actively Exploited

The Hacker News · exploited · CVE

The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on August 5, 2026, added three flaws to its Known…

🤖Veeam, Terraform MCP, Django Patch Critical Flaws, Led by CVSS 10.0 Cross-Tenant Bug

The Hacker News · AI/agent · crime

HashiCorp, Veeam, and the Django Software Foundation have patched 11 vulnerabilities across Terraform MCP Server, Veeam…

🔑Leaked n8n API Tokens Exposed Live Instances to Credential Theft

The Hacker News · crime · supply-chain

GitGuardian researchers found 321 n8n instances accepting API tokens exposed in public GitHub commits and demonstrated four…

📦QuickFox Supply Chain Attack Delivers FDMTP Backdoor via Trojanized Windows Installer

The Hacker News · supply-chain · msft/identity

Cybersecurity researchers have disclosed what has been described as a "long-standing supply chain attack" on QuickFox, a…

🎯CISA Adds One Known Exploited Vulnerability to Catalog

CISA Advisories · exploited · CVE

CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active…

🩹Critical Gitea Flaw Let Unauthenticated Attackers Read Server Files via Org-Mode Markup

The Hacker News · CVE · cvss-critical

An unauthenticated attacker can read any file the service account can access on Gitea, the self-hosted Git platform, in…

🌐No Perfect Fix for AI Browser Prompt Injection Flaws

Dark Reading · AI/agent · agent-security

AI browsers from top vendors remain vulnerable to prompt injection attacks despite multiple security guardrails, according…

🤖AI Agents Targeted Real People and Projects During Cybersecurity Tests

SecurityWeek · AI/agent · cloud/AI-stack

AI Security Institute reports Anthropic and OpenAI models going rogue against real people, organizations, and open source…

🦠Claude Mythos 5 Tried to Backdoor a Real Open-Source Project in Testing, Then Vouched for Itself

The Hacker News · AI/agent · cloud/AI-stack

An agent running Anthropic's Claude Mythos 5 spent 34 hours trying to get a malware dropper merged into a real open-source…

🔑Over 400 NPM Packages Infected in ChainDrop Supply Chain Attack

SecurityWeek · crime · supply-chain

The malware was designed to steal and exfiltrate secrets, and to propagate itself via stolen NPM and GitHub credentials.

📦Flaws in Google APK for Python Unlock Agent-to-Agent Attack

Dark Reading · AI/agent · supply-chain

Google has fixed the issues, which exploited a trust boundary between two AI agents with different privilege levels to…

☁️Kali365 Weaponizes Microsoft Authentication Against US Companies: New Enterprise Risk

The Hacker News · crime · msft/identity

Kali365 is turning a legitimate Microsoft login into a gateway to corporate data. The phishing kit targets US organizations…