100 events tracked
Events
Named occurrences — releases, incidents, policy moves — each backed by evidence and read through every lens.
policy 2026-06-12
US govt orders Fable 5 & Mythos 5 disabled
ratified incident 2026-06-10
Fable 5 jailbroken by Pliny
ratified publication 2026-06-09
NIST publishes Gödel guardrail proof
ratified release 2026-06-09
Claude Fable 5 released
ratified expansion 2026-05-20
Project Glasswing expanded to ~150 orgs
ratified release-preview 2026-04-07
Claude Mythos Preview announced
ratified initiative 2026-04-07
Project Glasswing launched
ratified other —
Active Exploitation of PAN-OS GlobalProtect CVE-2026-0257
ratified other —
Cisco Patches Actively Exploited SD-WAN vManage Zero-Day Vulnerability
ratified other —
ShinyHunters Exploits Oracle PeopleSoft Zero-Day in Multi-Sector Extortion Campaign
ratified other —
Critical Pre-Auth Remote Code Execution in Splunk Enterprise
ratified other —
US Government Restricts Foreign Access to Anthropic Fable 5 and Mythos 5
ratified other —
CISA Warns of Exploited LiteSpeed cPanel Plugin Privilege Escalation Flaw
ratified other —
Active Exploitation of Langflow Unauthenticated RCE Vulnerability
ratified other —
Hades PyPI Supply Chain Attack Injects Credential Stealers
ratified other —
LiteLLM Vulnerability Chain Enables Unauthorized AI Gateway Server Takeover
ratified other —
CISA Adds Cisco, Chrome, and Arista Vulnerabilities to KEV Catalog
ratified other —
Veeam Backup & Replication Remote Code Execution Vulnerability
ratified other —
Russian Actors Exploit WinRAR Vulnerability to Deploy Malware in Ukraine
ratified other —
Chrome V8 Zero-Day CVE-2026-11645 Exploited in the Wild
ratified other —
Check Point Remote Access VPN Authentication Bypass Vulnerability
ratified other —
Ivanti Sentry Pre-Auth OS Command Injection Vulnerability
ratified other —
Multi-Agent AI Safety Research Initiative
ratified other —
Microsoft Confirms RoguePlanet Defender Zero-Day Vulnerability
ratified other —
CISA Warns of Active Exploitation of Joomla JCE Editor Vulnerability
ratified other —
Kodak Confirms Data Breach Following ShinyHunters Extortion Claim
ratified other —
Anthropic Faces Regulatory Compliance Challenges Under New Export Controls
ratified other —
Candidate: CVE-2026-25089
candidate other —
Open WebUI Multitenancy and File Access Vulnerabilities
ratified other —
Debate Over Safety Thresholds for High-Performance Open-Weights LLMs
ratified other —
Spyware Developers Embed Forbidden Text to Thwart AI Analysis
ratified other —
LobeHub Unauthenticated SSRF Vulnerability
ratified other —
Open WebUI OAuth SSRF Vulnerability
ratified other —
vLLM Anthropic Router Memory Address Leak
ratified other —
LiteLLM Authentication Bypass via Host Header Injection
ratified other —
OpenStack Nova Scheduler Hint Injection Vulnerability
ratified other —
yt-dlp Arbitrary File Creation via Filename Sanitization Bypass
ratified other —
F5 Patches Critical Remote Code Execution Flaws in NGINX
ratified other —
Kodak Confirms Data Breach Following ShinyHunters Claims
ratified other —
Unauthenticated Remote Control Vulnerability in Mitsubishi WiFi Adapters
ratified other —
Gemini-MCP-Tool OS Command Injection and File Exfiltration Vulnerability
ratified other —
BBOT Unarchive Module Zip-Slip Vulnerability
ratified other —
PraisonAI Platform Authorization Bypass Vulnerability
ratified other —
PraisonAI AgentOS Authentication Bypass via Incomplete Patch
ratified other —
PraisonAI Agents SSRF Vulnerability via DNS Resolution Bypass
ratified other —
US Government Bans Anthropic Fable 5 AI Release
ratified other —
Apple Patches Beats Studio Buds Unauthorized Microphone Access Vulnerability
ratified other —
Splunk Enterprise Vulnerability Exploited in Active Attacks
ratified other —
Squidbleed Memory Leak Vulnerability (CVE-2026-47729)
ratified other —
CVE-2026-42530: Nginx HTTP/3 QPACK Encoder Use-After-Free Vulnerability
ratified other —
OpenBSD Kernel MPLS Stack Remote Information Disclosure
ratified other —
M365 Copilot Prompt Injection Vulnerability
ratified other —
Oracle Releases 245 Critical Security Patches
ratified other —
Network-AI Authentication Bypass via Incomplete Default Secret Patch
ratified other —
Anki User Script Iframe API Access Vulnerability
ratified other —
Home Assistant Konnected Integration Information Disclosure
ratified other —
Ouroboros-AI Incomplete CVE-2026-47211 Patch Enables RCE via .env Files
ratified other —
Gravity SMTP WordPress Plugin API Key Exposure Vulnerability
ratified other —
Anthropic Mythos Security Incident
ratified other —
Glances XML-RPC Vulnerabilities Enable DNS Rebinding and CORS Bypass
ratified other —
Squidbleed Vulnerability Exposes Sensitive User Data
ratified other —
ShinyHunters Data Breach Campaign
ratified other —
CVE-2026-25860: XSS to RCE Vulnerability
ratified other —
motionEye Configuration File Exposes Admin Password Hash
ratified other —
Scattered Spider Members Plead Guilty to Transport for London Hack
ratified other —
Candidate: mythos
ratified other —
Cisco Unified Communications Manager Vulnerability Exploited in Active Attacks
ratified other —
Flask-Security Open Redirect Vulnerability
ratified other —
OctoPrint File Exfiltration via Upload Endpoint Query Parameters
ratified other —
Glances Arbitrary Command Execution and File Write Vulnerability
ratified other —
Cisco Unified Communications Manager Root File-Write Vulnerability Exploited
ratified other —
Active Exploitation of Critical Lantronix EDS5000 Vulnerability
ratified other —
Cisco SD-WAN Zero-Day Exploited for Root Access
ratified other —
Scattered Spider Members Convicted for $38M Transport for London Cyberattack
ratified other —
Critical RCE Vulnerability Discovered in FFmpeg Codec
ratified other —
Spyware Developers Embed Forbidden Text to Thwart AI Analysis
ratified other —
Cisco Catalyst SD-WAN Zero-Day Exploited for Root Access
ratified other —
Lantronix Serial-to-IP Converter Vulnerability Exploited in Active Attacks
ratified other —
GeoServer Arbitrary File Write Vulnerability (CVE-2025-52465)
ratified other —
Cisco Security Vulnerability Surge
ratified other —
Miasma Malware Targets npm and GitHub Actions via AI Evasion
ratified other —
Chinese Cybersecurity Firm Claims Superiority Over Anthropic Mythos AI
ratified other —
Linux Pedit COW Vulnerability Enables Local Privilege Escalation
ratified other —
Amazon Q Developer MCP Configuration Remote Code Execution Vulnerability
ratified other —
DirtyClone Linux Kernel Vulnerability Enables Local Privilege Escalation
ratified other —
First In-the-Wild Exploitation of PTC Windchill Vulnerability
ratified other —
Muhammara LZWDecode NULL Pointer Dereference Vulnerability
ratified other —
Semantic-Router Compromised via Malicious LiteLLM Dependency
ratified other —
Pydantic-AI SSRF Protection Bypass via IPv6 Address Manipulation
ratified other —
US Government Authorizes Anthropic Mythos 5 for Enterprise and Agency Use
ratified other —
Critical PTC Windchill Remote Code Execution Vulnerability
ratified other —
Z.ai Claims Cybersecurity Performance Parity with Mythos
ratified other —
NAIC and Nissan Data Breaches Linked to Oracle PeopleSoft Exploitation
ratified other —
OpenAI Launches GPT-5.6 Sol Cybersecurity AI
ratified other —
Public PoC Released for Critical libssh2 Client-Side Vulnerability
ratified other —
Critical SimpleHelp Vulnerability Exploited for Stealer Malware Deployment
ratified other —
Active Exploitation of Critical Oracle E-Business Suite Vulnerability
ratified other —
Progress Kemp LoadMaster Pre-Auth RCE Vulnerability
ratified other —
Langflow RCE Exploited for Monero Mining
ratified other —