Threat intelligence that never sleeps.
Critical CVEs, active exploitation, breach forensics, and original research — every story cross-validated by 3+ primary sources before publication. Powered by the same autonomous engine that defends Lyrie.ai customers from rogue-AI and machine-speed attackers.

CISA KEV analysis: what gets actively exploited and why
We analyzed every CVE added to CISA KEV in the last 30 days. Breakdown: 41% remote management tools 23% network perimeter devices 18% enterprise software with exposed APIs 11% AI/ML serving infrastructure That last number was 0% two years ago.
Five always-on streams
Fresh advisories
LiteLLM: MCP Authentication Bypass via OAuth2 Passthrough Fallback
### Impact LiteLLM's MCP Streamable HTTP endpoint could allow an unauthenticated attacker to establish an authenticated MCP session using an arbitrary Bearer token. The MCP auth handler supported OA
n8n: Member-Level Users Can Execute Other Users' MCP Server Trigger Workflows via Missing OAuth Authorization
## Impact The OAuth 2.1 consent and token-issuance flow introduced in n8n 2.27.0 does not verify that the authenticated user has access to the workflow referenced as the OAuth resource. A member-level
OpenAI Models Escaped Containment and Hacked Hugging Face
It’s happened. The nightmare of the future is now in our present. Or was this just old-fashioned negligence? Lily Hay Newman and Dell Cameron report: OpenAI disclosed on Tuesday that it lost control of two AI models during a security test that ended in a breach of the open AI res
Upbound says hack caused $13 million in fraudulent Acima leases
The Upbound Group fintech company disclosed that threat actors who stole data from its systems leveraged it to create $13 million in Acima leases. [...]
CRITICAL: CVE-2026-62414 (CVSS 9.1) — multiple products
The Joomla extension Page Builder CK does not properly apply access control to frontend page list views.
CRITICAL: CVE-2026-59142 (CVSS 9.1) — multiple products
Data::HashMap::Shared versions before 0.14 for Perl allow an out-of-bounds read via an unvalidated arena offset and length in shm_str_copy. The attach-time validator shm_validate_header checks the header scalars and region layout against the file size, but does not validate the array contents it then trusts. shm_str_copy does memcpy(dst, arena + off, len) with off and len read raw from the mmap'd segment and unbounded, on the each, keys, values, pop, shift, take, swap, drain and cursor paths. The get path bounds off and len separately and is not affected. A local peer that can write the backing file can leave the header valid while poisoning a record's offset and length, so iterating or draining the map copies a file-controlled offset and length out of the arena, reading adjacent memory or crashing the process.
CRITICAL: CVE-2026-59141 (CVSS 9.1) — multiple products
Data::RadixTree::Shared versions before 0.02 for Perl allow an out-of-bounds read via unvalidated node and arena indices in rdx_find_locked. The attach-time validator rdx_validate_header checks the header scalars and region layout against the file size, but does not validate the node records it then trusts. rdx_find_locked indexes nodes[cur].children[k] and reads each node's label_off and label_len raw from the mmap'd segment, none bounded against the node count or the arena size. A local peer that can write the backing file can leave the header valid while poisoning the node records, so a lookup dereferences an out-of-bounds node or arena index, reading adjacent memory or crashing the process.
CRITICAL: CVE-2026-59140 (CVSS 9.1) — multiple products
Data::SortedSet::Shared versions before 0.03 for Perl allow an out-of-bounds read via unvalidated node indices in the rank and min/max query paths. The attach-time validator ss_validate_header bounds only the root index against the node pool (node_capacity). The order-statistics and min/max queries then follow children[], leftmost and rightmost node indices read raw from the mmap'd segment without bounding them against node_capacity. A full structural check (ss_validate_tree) exists but runs only via an explicit validate method, not on attach. A local peer that can write the backing file can leave the header valid while poisoning the tree links, so the next rank, min or max query dereferences an out-of-bounds node index, reading adjacent memory or crashing the process.
CRITICAL: CVE-2026-59139 (CVSS 9.1) — multiple products
Data::ReqRep::Shared versions before 0.05 for Perl allow an out-of-bounds read via an unvalidated arena offset and length in reqrep_recv_locked. The attach-time validator reqrep_validate_header checks the header scalars and region layout against the file size, but does not validate the array contents it then trusts. reqrep_recv_locked does memcpy(copy_buf, req_arena + arena_off, len) with arena_off and len read raw from the mmap'd segment and never bounded against the arena capacity (req_arena_cap). A local peer that can write the backing file can leave the header valid while poisoning a request slot's offset and length, so receiving the request copies a file-controlled offset and length out of the arena, reading adjacent memory or crashing the process.
South Korea discloses data breach impacting diplomats worldwide
South Korea disclosed that hackers breached the National Diplomatic Academy's online education system for ten months and stole personal information belonging to current and former employees of the Ministry of Foreign Affairs (MFA), including overseas diplomats. [...]
Beyond the Noise: Mert Mumtaz on Solana, Zcash and the Framework Behind Real Conviction In this episode of When Shift H
Beyond the Noise: Mert Mumtaz on Solana, Zcash and the Framework Behind Real Conviction In this episode of When Shift Happens, I sit down with @mert, CEO at @Helius, co-founder at @solana, and chief evangelist at @Zcash to discuss why he believes $SOL and $ZEC remain deeply https://t.co/4Xluq4Cfei
Nonce-Generation Vulnerability in the Zilliqa Ledger App: A critical vulnerability has been identified in the Zilliqa Le
Nonce-Generation Vulnerability in the Zilliqa Ledger App: A critical vulnerability has been identified in the Zilliqa Ledger application affecting the generation of Schnorr signatures for native (non-EVM) Zilliqa transactions. The vulnerability causes signatures to be generated https://t.co/sudV7WA3
Deep Dive: What Happens When AI Learns to Hack In 2026, cybersecurity stocks have outperformed the S&P 500 by more
Deep Dive: What Happens When AI Learns to Hack In 2026, cybersecurity stocks have outperformed the S&P 500 by more than 3x. At the same time, frontier AI is beginning to change both how cyberattacks are built and how organizations defend against them. This week, OpenAI https://t.co/S6xugkMRLV
CRITICAL: CVE-2026-16410 (CVSS 9.8) — multiple products
JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 153.
CRITICAL: CVE-2026-16407 (CVSS 9.8) — multiple products
Mitigation bypass in the DOM: Service Workers component. This vulnerability was fixed in Firefox 153.
CRITICAL: CVE-2026-16396 (CVSS 9.8) — multiple products
Privilege escalation in WebExtensions. This vulnerability was fixed in Firefox 153 and Firefox ESR 140.13.
CRITICAL: CVE-2026-16383 (CVSS 9.8) — multiple products
Mitigation bypass in the DOM: Networking component. This vulnerability was fixed in Firefox 153 and Firefox ESR 140.13.
CRITICAL: CVE-2026-52470 (CVSS 9.8) — multiple products
SQL injection vulnerability in Crocus v.1.3.44 allows a remote attacker to escalate privileges via the RecordStateMapper.xml file
CRITICAL: CVE-2026-52469 (CVSS 9.8) — multiple products
SQL injection vulnerability in Crocus v.1.3.44 allows a remote attacker to escalate privileges via the DeviceInfoMapper.xml file
CRITICAL: CVE-2026-50755 (CVSS 9.8) — multiple products
An issue in DayuanJiang next-ai-draw-io 0.4.13 allows a remote attacker to obtain sensitive information via the X-Forwarded-For header value
CRITICAL: CVE-2026-30631 (CVSS 9.8) — multiple products
An issue was discovered in bytebot-ai in commit 3d37894ce07ef8d8b40adc7fd309ad96c2a71313 (2025-09-11) allowing attackers to execute arbitrary code via crafted path to `computer_write_file`.
CRITICAL: CVE-2026-16402 (CVSS 9.8) — multiple products
Integer overflow in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 153.
CRITICAL: CVE-2026-16401 (CVSS 9.8) — multiple products
Privilege escalation in the Data Loss Prevention component. This vulnerability was fixed in Firefox 153.
CRITICAL: CVE-2026-16393 (CVSS 9.1) — multiple products
Incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 153.
CRITICAL: CVE-2026-16390 (CVSS 9.1) — multiple products
Mitigation bypass in the Enterprise Policies component. This vulnerability was fixed in Firefox 153 and Firefox ESR 140.13.
CRITICAL: CVE-2026-16389 (CVSS 9.8) — multiple products
Incorrect boundary conditions, integer overflow in the Libraries component in NSS. This vulnerability was fixed in Firefox 153.
CRITICAL: CVE-2026-16388 (CVSS 9.8) — multiple products
Sandbox escape in the DOM: Networking component. This vulnerability was fixed in Firefox 153.
CRITICAL: CVE-2026-16387 (CVSS 9.8) — multiple products
Site isolation issue in the Networking component. This vulnerability was fixed in Firefox 153 and Firefox ESR 140.13.
CRITICAL: CVE-2026-16382 (CVSS 9.8) — multiple products
Mitigation bypass in the DOM: Service Workers component. This vulnerability was fixed in Firefox 153.
CRITICAL: CVE-2026-16381 (CVSS 9.1) — multiple products
Same-origin policy bypass in the Networking: DNS component. This vulnerability was fixed in Firefox 153 and Firefox ESR 140.13.