Hmmnm
All articles published by

Hmmnm

Hands-on cybersecurity tutorials, CVE breakdowns, and guided learning paths. Every technique is explained, tested, and paired with its mitigation — so you learn the attack and the defense together.

Learning Paths · About Hmmnm · Editorial policy

Pwn2Own Berlin 2026: 47 Zero-Days & AI Assistants Exploited

Pwn2Own Berlin 2026 awarded $1.3M for 47 zero-days in three days - and AI coding assistants OpenAI Codex and Anthropic Claude Code were exploited on stage for the first time. DEVCORE took Master of Pwn with $505K. Full results, the AI-target analysis, and what AppSec teams must do now.

Continue ReadingPwn2Own Berlin 2026: 47 Zero-Days & AI Assistants Exploited

Bleeding Llama: The Ollama CVE That Leaked AI Memory

Two AI security incidents in 48 hours: Bleeding Llama (CVE-2026-7482, CVSS 9.1) leaks full process memory from 300K+ exposed Ollama servers via malicious GGUF files, while a fake OpenAI Privacy Filter on Hugging Face hit #1 trending and delivered a Rust infostealer to 244K+ victims. Verification and patching playbook inside.

Continue ReadingBleeding Llama: The Ollama CVE That Leaked AI Memory

Zero-Days & AI Supply Chain Attacks: May 2026 Briefing

Five threat streams converged in May 2026: the actively exploited Ivanti EPMM zero-day, a fake OpenAI repo on Hugging Face dropping infostealers, cPanel CVEs reaching CVSS 8.8, TCLBANKER worming through WhatsApp and Outlook, and ShinyHunters hitting Canvas LMS. One briefing, one action plan.

Continue ReadingZero-Days & AI Supply Chain Attacks: May 2026 Briefing