SIGNAL//DESK

100 events tracked

Events

Named occurrences — releases, incidents, policy moves — each backed by evidence and read through every lens.

policy 2026-06-12

US govt orders Fable 5 & Mythos 5 disabled

ratified
incident 2026-06-10

Fable 5 jailbroken by Pliny

ratified
publication 2026-06-09

NIST publishes Gödel guardrail proof

ratified
release 2026-06-09

Claude Fable 5 released

ratified
expansion 2026-05-20

Project Glasswing expanded to ~150 orgs

ratified
release-preview 2026-04-07

Claude Mythos Preview announced

ratified
initiative 2026-04-07

Project Glasswing launched

ratified
other

Active Exploitation of PAN-OS GlobalProtect CVE-2026-0257

ratified
other

Cisco Patches Actively Exploited SD-WAN vManage Zero-Day Vulnerability

ratified
other

ShinyHunters Exploits Oracle PeopleSoft Zero-Day in Multi-Sector Extortion Campaign

ratified
other

Critical Pre-Auth Remote Code Execution in Splunk Enterprise

ratified
other

US Government Restricts Foreign Access to Anthropic Fable 5 and Mythos 5

ratified
other

CISA Warns of Exploited LiteSpeed cPanel Plugin Privilege Escalation Flaw

ratified
other

Active Exploitation of Langflow Unauthenticated RCE Vulnerability

ratified
other

Hades PyPI Supply Chain Attack Injects Credential Stealers

ratified
other

LiteLLM Vulnerability Chain Enables Unauthorized AI Gateway Server Takeover

ratified
other

CISA Adds Cisco, Chrome, and Arista Vulnerabilities to KEV Catalog

ratified
other

Veeam Backup & Replication Remote Code Execution Vulnerability

ratified
other

Russian Actors Exploit WinRAR Vulnerability to Deploy Malware in Ukraine

ratified
other

Chrome V8 Zero-Day CVE-2026-11645 Exploited in the Wild

ratified
other

Check Point Remote Access VPN Authentication Bypass Vulnerability

ratified
other

Ivanti Sentry Pre-Auth OS Command Injection Vulnerability

ratified
other

Multi-Agent AI Safety Research Initiative

ratified
other

Microsoft Confirms RoguePlanet Defender Zero-Day Vulnerability

ratified
other

CISA Warns of Active Exploitation of Joomla JCE Editor Vulnerability

ratified
other

Kodak Confirms Data Breach Following ShinyHunters Extortion Claim

ratified
other

Anthropic Faces Regulatory Compliance Challenges Under New Export Controls

ratified
other

Candidate: CVE-2026-25089

candidate
other

Open WebUI Multitenancy and File Access Vulnerabilities

ratified
other

Debate Over Safety Thresholds for High-Performance Open-Weights LLMs

ratified
other

Spyware Developers Embed Forbidden Text to Thwart AI Analysis

ratified
other

LobeHub Unauthenticated SSRF Vulnerability

ratified
other

Open WebUI OAuth SSRF Vulnerability

ratified
other

vLLM Anthropic Router Memory Address Leak

ratified
other

LiteLLM Authentication Bypass via Host Header Injection

ratified
other

OpenStack Nova Scheduler Hint Injection Vulnerability

ratified
other

yt-dlp Arbitrary File Creation via Filename Sanitization Bypass

ratified
other

F5 Patches Critical Remote Code Execution Flaws in NGINX

ratified
other

Kodak Confirms Data Breach Following ShinyHunters Claims

ratified
other

Unauthenticated Remote Control Vulnerability in Mitsubishi WiFi Adapters

ratified
other

Gemini-MCP-Tool OS Command Injection and File Exfiltration Vulnerability

ratified
other

BBOT Unarchive Module Zip-Slip Vulnerability

ratified
other

PraisonAI Platform Authorization Bypass Vulnerability

ratified
other

PraisonAI AgentOS Authentication Bypass via Incomplete Patch

ratified
other

PraisonAI Agents SSRF Vulnerability via DNS Resolution Bypass

ratified
other

US Government Bans Anthropic Fable 5 AI Release

ratified
other

Apple Patches Beats Studio Buds Unauthorized Microphone Access Vulnerability

ratified
other

Splunk Enterprise Vulnerability Exploited in Active Attacks

ratified
other

Squidbleed Memory Leak Vulnerability (CVE-2026-47729)

ratified
other

CVE-2026-42530: Nginx HTTP/3 QPACK Encoder Use-After-Free Vulnerability

ratified
other

OpenBSD Kernel MPLS Stack Remote Information Disclosure

ratified
other

M365 Copilot Prompt Injection Vulnerability

ratified
other

Oracle Releases 245 Critical Security Patches

ratified
other

Network-AI Authentication Bypass via Incomplete Default Secret Patch

ratified
other

Anki User Script Iframe API Access Vulnerability

ratified
other

Home Assistant Konnected Integration Information Disclosure

ratified
other

Ouroboros-AI Incomplete CVE-2026-47211 Patch Enables RCE via .env Files

ratified
other

Gravity SMTP WordPress Plugin API Key Exposure Vulnerability

ratified
other

Anthropic Mythos Security Incident

ratified
other

Glances XML-RPC Vulnerabilities Enable DNS Rebinding and CORS Bypass

ratified
other

Squidbleed Vulnerability Exposes Sensitive User Data

ratified
other

ShinyHunters Data Breach Campaign

ratified
other

CVE-2026-25860: XSS to RCE Vulnerability

ratified
other

motionEye Configuration File Exposes Admin Password Hash

ratified
other

Scattered Spider Members Plead Guilty to Transport for London Hack

ratified
other

Candidate: mythos

ratified
other

Cisco Unified Communications Manager Vulnerability Exploited in Active Attacks

ratified
other

Flask-Security Open Redirect Vulnerability

ratified
other

OctoPrint File Exfiltration via Upload Endpoint Query Parameters

ratified
other

Glances Arbitrary Command Execution and File Write Vulnerability

ratified
other

Cisco Unified Communications Manager Root File-Write Vulnerability Exploited

ratified
other

Active Exploitation of Critical Lantronix EDS5000 Vulnerability

ratified
other

Cisco SD-WAN Zero-Day Exploited for Root Access

ratified
other

Scattered Spider Members Convicted for $38M Transport for London Cyberattack

ratified
other

Critical RCE Vulnerability Discovered in FFmpeg Codec

ratified
other

Spyware Developers Embed Forbidden Text to Thwart AI Analysis

ratified
other

Cisco Catalyst SD-WAN Zero-Day Exploited for Root Access

ratified
other

Lantronix Serial-to-IP Converter Vulnerability Exploited in Active Attacks

ratified
other

GeoServer Arbitrary File Write Vulnerability (CVE-2025-52465)

ratified
other

Cisco Security Vulnerability Surge

ratified
other

Miasma Malware Targets npm and GitHub Actions via AI Evasion

ratified
other

Chinese Cybersecurity Firm Claims Superiority Over Anthropic Mythos AI

ratified
other

Linux Pedit COW Vulnerability Enables Local Privilege Escalation

ratified
other

Amazon Q Developer MCP Configuration Remote Code Execution Vulnerability

ratified
other

DirtyClone Linux Kernel Vulnerability Enables Local Privilege Escalation

ratified
other

First In-the-Wild Exploitation of PTC Windchill Vulnerability

ratified
other

Muhammara LZWDecode NULL Pointer Dereference Vulnerability

ratified
other

Semantic-Router Compromised via Malicious LiteLLM Dependency

ratified
other

Pydantic-AI SSRF Protection Bypass via IPv6 Address Manipulation

ratified
other

US Government Authorizes Anthropic Mythos 5 for Enterprise and Agency Use

ratified
other

Critical PTC Windchill Remote Code Execution Vulnerability

ratified
other

Z.ai Claims Cybersecurity Performance Parity with Mythos

ratified
other

NAIC and Nissan Data Breaches Linked to Oracle PeopleSoft Exploitation

ratified
other

OpenAI Launches GPT-5.6 Sol Cybersecurity AI

ratified
other

Public PoC Released for Critical libssh2 Client-Side Vulnerability

ratified
other

Critical SimpleHelp Vulnerability Exploited for Stealer Malware Deployment

ratified
other

Active Exploitation of Critical Oracle E-Business Suite Vulnerability

ratified
other

Progress Kemp LoadMaster Pre-Auth RCE Vulnerability

ratified
other

Langflow RCE Exploited for Monero Mining

ratified
other

SimpleHelp CVE-2026-48558 Exploited to Deploy TaskWeaver and Djinn Stealer

ratified