Curated Cyber Threat Intelligence
Threat Feed
Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.
scheduleUpdated 2026-09-05 · 02:16 UTC
articleTotal: 1184 reports
Filtered Reports
2 / 2 results
highbug_reportVulnerabilitybug_reportVulnerability
Mobile AI agent frameworks vulnerable to instruction injection attacks
Five open-source mobile AI agent frameworks including AppAgent and AppAgentX. Attack requires malicious Android apps with overlay and storage permissions to inject invisible instructions, leading to command execution on connected host PCs.
AppAgent21 Jul · 09:58 UTC
highbug_reportVulnerabilitybug_reportVulnerability
63% of iOS AI chatbot apps leak API keys via unencrypted network traffic
282 out of 444 iOS AI chatbot applications expose paid AI service credentials (API keys, tokens, backend endpoints) in plaintext network traffic. Affects apps integrating third-party AI services (OpenAI, Anthropic, Google, etc.).
The Hacker News30 Jun · 11:49 UTC