Lyrie
Live · 8444 verified advisories · 542 actively exploited

Threat intelligence that never sleeps.

Critical CVEs, active exploitation, breach forensics, and original research — every story cross-validated by 3+ primary sources before publication. Powered by the same autonomous engine that defends Lyrie.ai customers from rogue-AI and machine-speed attackers.

✓ SOC 2 Type II✓ GDPR✓ PCI DSS✓ OWASP Top 10
Lyrie Cyber Guardian
Pipeline
Autonomous · Machine-speed · Anti-rogue-AI
1445
Deep dives
Active Exploitation

CISA KEV analysis: what gets actively exploited and why

We analyzed every CVE added to CISA KEV in the last 30 days. Breakdown: 41% remote management tools 23% network perimeter devices 18% enterprise software with exposed APIs 11% AI/ML serving infrastructure That last number was 0% two years ago.

Lyrie Threat Intelligence·1 min read·1 sources verified
Coverage

Five always-on streams

How it works →
Latest

Fresh advisories

RSS →
AI Threats1 sources

LiteLLM: MCP Authentication Bypass via OAuth2 Passthrough Fallback

### Impact LiteLLM's MCP Streamable HTTP endpoint could allow an unauthenticated attacker to establish an authenticated MCP session using an arbitrary Bearer token. The MCP auth handler supported OA

agent-threats-litellm-mcp-authentication-bypass-via-oauth2-pass-mrwoqp44·7/22/2026·1 min
AI Threats1 sources

n8n: Member-Level Users Can Execute Other Users' MCP Server Trigger Workflows via Missing OAuth Authorization

## Impact The OAuth 2.1 consent and token-issuance flow introduced in n8n 2.27.0 does not verify that the authenticated user has access to the workflow referenced as the OAuth resource. A member-level

agent-threats-n8n-member-level-users-can-execute-other-users-m-mrwoqp43·7/22/2026·1 min
Breaches3 sources

OpenAI Models Escaped Containment and Hacked Hugging Face

It’s happened. The nightmare of the future is now in our present. Or was this just old-fashioned negligence? Lily Hay Newman and Dell Cameron report: OpenAI disclosed on Tuesday that it lost control of two AI models during a security test that ended in a breach of the open AI res

breach-databreaches-net-openai-models-escaped-containment-and-ha·7/22/2026·1 min
Breaches3 sources

Upbound says hack caused $13 million in fraudulent Acima leases

The Upbound Group fintech company disclosed that threat actors who stole data from its systems leveraged it to create $13 million in Acima leases. [...]

breach-bleepingcomputer-upbound-says-hack-caused-13-million-in-f·7/22/2026·1 min
CVE Deep DivesCVSS 9.13 sources

CRITICAL: CVE-2026-62414 (CVSS 9.1) — multiple products

The Joomla extension Page Builder CK does not properly apply access control to frontend page list views.

CVE-2026-62414·7/22/2026·1 min
CVE Deep DivesCVSS 9.13 sources

CRITICAL: CVE-2026-59142 (CVSS 9.1) — multiple products

Data::HashMap::Shared versions before 0.14 for Perl allow an out-of-bounds read via an unvalidated arena offset and length in shm_str_copy. The attach-time validator shm_validate_header checks the header scalars and region layout against the file size, but does not validate the array contents it then trusts. shm_str_copy does memcpy(dst, arena + off, len) with off and len read raw from the mmap'd segment and unbounded, on the each, keys, values, pop, shift, take, swap, drain and cursor paths. The get path bounds off and len separately and is not affected. A local peer that can write the backing file can leave the header valid while poisoning a record's offset and length, so iterating or draining the map copies a file-controlled offset and length out of the arena, reading adjacent memory or crashing the process.

CVE-2026-59142·7/22/2026·1 min
CVE Deep DivesCVSS 9.13 sources

CRITICAL: CVE-2026-59141 (CVSS 9.1) — multiple products

Data::RadixTree::Shared versions before 0.02 for Perl allow an out-of-bounds read via unvalidated node and arena indices in rdx_find_locked. The attach-time validator rdx_validate_header checks the header scalars and region layout against the file size, but does not validate the node records it then trusts. rdx_find_locked indexes nodes[cur].children[k] and reads each node's label_off and label_len raw from the mmap'd segment, none bounded against the node count or the arena size. A local peer that can write the backing file can leave the header valid while poisoning the node records, so a lookup dereferences an out-of-bounds node or arena index, reading adjacent memory or crashing the process.

CVE-2026-59141·7/22/2026·1 min
CVE Deep DivesCVSS 9.13 sources

CRITICAL: CVE-2026-59140 (CVSS 9.1) — multiple products

Data::SortedSet::Shared versions before 0.03 for Perl allow an out-of-bounds read via unvalidated node indices in the rank and min/max query paths. The attach-time validator ss_validate_header bounds only the root index against the node pool (node_capacity). The order-statistics and min/max queries then follow children[], leftmost and rightmost node indices read raw from the mmap'd segment without bounding them against node_capacity. A full structural check (ss_validate_tree) exists but runs only via an explicit validate method, not on attach. A local peer that can write the backing file can leave the header valid while poisoning the tree links, so the next rank, min or max query dereferences an out-of-bounds node index, reading adjacent memory or crashing the process.

CVE-2026-59140·7/22/2026·1 min
CVE Deep DivesCVSS 9.13 sources

CRITICAL: CVE-2026-59139 (CVSS 9.1) — multiple products

Data::ReqRep::Shared versions before 0.05 for Perl allow an out-of-bounds read via an unvalidated arena offset and length in reqrep_recv_locked. The attach-time validator reqrep_validate_header checks the header scalars and region layout against the file size, but does not validate the array contents it then trusts. reqrep_recv_locked does memcpy(copy_buf, req_arena + arena_off, len) with arena_off and len read raw from the mmap'd segment and never bounded against the arena capacity (req_arena_cap). A local peer that can write the backing file can leave the header valid while poisoning a request slot's offset and length, so receiving the request copies a file-controlled offset and length out of the arena, reading adjacent memory or crashing the process.

CVE-2026-59139·7/22/2026·1 min
Breaches3 sources

South Korea discloses data breach impacting diplomats worldwide

South Korea disclosed that hackers breached the National Diplomatic Academy's online education system for ten months and stole personal information belonging to current and former employees of the Ministry of Foreign Affairs (MFA), including overseas diplomats. [...]

breach-bleepingcomputer-south-korea-discloses-data-breach-impact·7/22/2026·1 min
Active Exploitation1 sources

Beyond the Noise: Mert Mumtaz on Solana, Zcash and the Framework Behind Real Conviction In this episode of When Shift H

Beyond the Noise: Mert Mumtaz on Solana, Zcash and the Framework Behind Real Conviction In this episode of When Shift Happens, I sit down with @mert, CEO at @Helius, co-founder at @solana, and chief evangelist at @Zcash to discuss why he believes $SOL and $ZEC remain deeply https://t.co/4Xluq4Cfei

XHUNT-2079884220613452265·7/22/2026·1 min
Active Exploitation1 sources

Nonce-Generation Vulnerability in the Zilliqa Ledger App: A critical vulnerability has been identified in the Zilliqa Le

Nonce-Generation Vulnerability in the Zilliqa Ledger App: A critical vulnerability has been identified in the Zilliqa Ledger application affecting the generation of Schnorr signatures for native (non-EVM) Zilliqa transactions. The vulnerability causes signatures to be generated https://t.co/sudV7WA3

XHUNT-2079847348780536050·7/22/2026·1 min
Active Exploitation1 sources

Deep Dive: What Happens When AI Learns to Hack In 2026, cybersecurity stocks have outperformed the S&P 500 by more

Deep Dive: What Happens When AI Learns to Hack In 2026, cybersecurity stocks have outperformed the S&P 500 by more than 3x. At the same time, frontier AI is beginning to change both how cyberattacks are built and how organizations defend against them. This week, OpenAI https://t.co/S6xugkMRLV

XHUNT-2079984814963249594·7/22/2026·1 min
CVE Deep DivesCVSS 9.83 sources

CRITICAL: CVE-2026-16410 (CVSS 9.8) — multiple products

JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 153.

CVE-2026-16410·7/22/2026·1 min
CVE Deep DivesCVSS 9.83 sources

CRITICAL: CVE-2026-16407 (CVSS 9.8) — multiple products

Mitigation bypass in the DOM: Service Workers component. This vulnerability was fixed in Firefox 153.

CVE-2026-16407·7/22/2026·1 min
CVE Deep DivesCVSS 9.83 sources

CRITICAL: CVE-2026-16396 (CVSS 9.8) — multiple products

Privilege escalation in WebExtensions. This vulnerability was fixed in Firefox 153 and Firefox ESR 140.13.

CVE-2026-16396·7/22/2026·1 min
CVE Deep DivesCVSS 9.83 sources

CRITICAL: CVE-2026-16383 (CVSS 9.8) — multiple products

Mitigation bypass in the DOM: Networking component. This vulnerability was fixed in Firefox 153 and Firefox ESR 140.13.

CVE-2026-16383·7/22/2026·1 min
CVE Deep DivesCVSS 9.83 sources

CRITICAL: CVE-2026-52470 (CVSS 9.8) — multiple products

SQL injection vulnerability in Crocus v.1.3.44 allows a remote attacker to escalate privileges via the RecordStateMapper.xml file

CVE-2026-52470·7/22/2026·1 min
CVE Deep DivesCVSS 9.83 sources

CRITICAL: CVE-2026-52469 (CVSS 9.8) — multiple products

SQL injection vulnerability in Crocus v.1.3.44 allows a remote attacker to escalate privileges via the DeviceInfoMapper.xml file

CVE-2026-52469·7/22/2026·1 min
CVE Deep DivesCVSS 9.83 sources

CRITICAL: CVE-2026-50755 (CVSS 9.8) — multiple products

An issue in DayuanJiang next-ai-draw-io 0.4.13 allows a remote attacker to obtain sensitive information via the X-Forwarded-For header value

CVE-2026-50755·7/22/2026·1 min
CVE Deep DivesCVSS 9.83 sources

CRITICAL: CVE-2026-30631 (CVSS 9.8) — multiple products

An issue was discovered in bytebot-ai in commit 3d37894ce07ef8d8b40adc7fd309ad96c2a71313 (2025-09-11) allowing attackers to execute arbitrary code via crafted path to `computer_write_file`.

CVE-2026-30631·7/22/2026·1 min
CVE Deep DivesCVSS 9.83 sources

CRITICAL: CVE-2026-16402 (CVSS 9.8) — multiple products

Integer overflow in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 153.

CVE-2026-16402·7/22/2026·1 min
CVE Deep DivesCVSS 9.83 sources

CRITICAL: CVE-2026-16401 (CVSS 9.8) — multiple products

Privilege escalation in the Data Loss Prevention component. This vulnerability was fixed in Firefox 153.

CVE-2026-16401·7/22/2026·1 min
CVE Deep DivesCVSS 9.13 sources

CRITICAL: CVE-2026-16393 (CVSS 9.1) — multiple products

Incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 153.

CVE-2026-16393·7/22/2026·1 min
CVE Deep DivesCVSS 9.13 sources

CRITICAL: CVE-2026-16390 (CVSS 9.1) — multiple products

Mitigation bypass in the Enterprise Policies component. This vulnerability was fixed in Firefox 153 and Firefox ESR 140.13.

CVE-2026-16390·7/22/2026·1 min
CVE Deep DivesCVSS 9.83 sources

CRITICAL: CVE-2026-16389 (CVSS 9.8) — multiple products

Incorrect boundary conditions, integer overflow in the Libraries component in NSS. This vulnerability was fixed in Firefox 153.

CVE-2026-16389·7/22/2026·1 min
CVE Deep DivesCVSS 9.83 sources

CRITICAL: CVE-2026-16388 (CVSS 9.8) — multiple products

Sandbox escape in the DOM: Networking component. This vulnerability was fixed in Firefox 153.

CVE-2026-16388·7/22/2026·1 min
CVE Deep DivesCVSS 9.83 sources

CRITICAL: CVE-2026-16387 (CVSS 9.8) — multiple products

Site isolation issue in the Networking component. This vulnerability was fixed in Firefox 153 and Firefox ESR 140.13.

CVE-2026-16387·7/22/2026·1 min
CVE Deep DivesCVSS 9.83 sources

CRITICAL: CVE-2026-16382 (CVSS 9.8) — multiple products

Mitigation bypass in the DOM: Service Workers component. This vulnerability was fixed in Firefox 153.

CVE-2026-16382·7/22/2026·1 min
CVE Deep DivesCVSS 9.13 sources

CRITICAL: CVE-2026-16381 (CVSS 9.1) — multiple products

Same-origin policy bypass in the Networking: DNS component. This vulnerability was fixed in Firefox 153 and Firefox ESR 140.13.

CVE-2026-16381·7/22/2026·1 min