First reported · updated · 3 reports talosintelligence.com
Lead dispatch
First reported horizon3.ai
Anthropic's super bug-hunting model Mythos is hardcore good at math, as latest vuln under attack shows
CVE-2026-61500, a critical authentication-bypass bug in Rejetto HTTP File Server (HFS) that enables full admin access and remote code execution, was discovered by Horizon3 researcher Zach Hanley using Anthropic's Mythos bug-hunting model and came under active exploitation within a day of disclosure. VulnCheck's canaries detected a China-hosted IP targeting vulnerable hosts in the US and Japan; a public exploit video was also published, and users should update to HFS v3.2.1 or later.ai-discovered-vulnerability · remote-code-execution · authentication-bypass
llm · ai-agents
Severity
0.72
The wire · latest
First reported thehackernews.com
14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2
Trend Micro's TrendAI reported 14 trojanized npm packages posing as calendar and streak utilities that stealthily deliver RedC2 4.0, an AI-powered Linux implant. A single import anywhere in the dependency graph—even a transitive one—locates the bundled binary, marks it executable, and launches it as a detached background process, requiring no install hook. Details →How the wire is made
Poll & cluster
Internet is crawled for AI security news and near-duplicate coverage is embedded and grouped into durable items.
Curate
AI Agent filters for agentic-AI relevance, classifies and tags each item, scores severity for threats, and writes the summary.
Every item here is one machine-curated intelligence object, not a headline.
Read the wire for free. There is a small charge to ask the index questions.
The wire, open
The complete curated feed, no key required.
- GET /feed.xml — RSS 2.0, every item
- GET /api/items — read-only
The vector desk
Query the index by meaning, not just keyword.
- GET /api/items?tags=&minSeverity=&itemType=
- GET /api/search?q= — keyword
- GET /api/semantic?q= — vector