2026-05-27
[The Record]
Dragomir was arrested in Romania in November 2024 and brought to the U.S. last year to face charges for hacking into the network belonging to Oregon’s Office of Emergency Management.
#cybercrime #news #news-briefs
2026-05-27
[SecurityWeek]
The speech is the latest in a string of warnings from intelligence experts that Russia is stepping up hostile activity in a “gray zone” that falls just below the threshold of war.
The post UK Cyberspying Chief Calls AI ‘an Unstoppable Force’ and Warns About Russia appeared first on SecurityWeek.
#cyberwarfare #russia #uk
2026-05-27
[Tenable Research]
Tenable Research has developed a graph-based model linking 600+ threat groups to real-world customer exposures. It reveals which vulnerabilities sit at the intersection of severity, active exploitation, and organizational risk.Key takeawaysThe “patch everything” strategy is dead: Vulnerability prior…
#vulnerability #apt #patch
2026-05-27
[Dark Reading]
A purported leak exposing 5.8 million records of Uruguayan citizens is the latest incident where cybercriminals targeted government agencies to monetize citizen data.
2026-05-27
[Dark Reading]
Attackers are using AI to dramatically reduce the time they need to develop a working exploit for a CVE, according to new research.
#vulnerability
2026-05-27
[The Hacker News]
Latin America and Europe become the target of two banking trojan campaigns that are designed to infect Windows and Android devices with Grandoreiro and BTMOB malware, respectively.
That’s according to new findings from WatchGuard and ESET, which have observed the two malware families being used to …
#malware #windows
2026-05-27
[The Hacker News]
Cybersecurity researchers have discovered a new malicious package on the npm registry that comes with information stealing capabilities.
According to OX Security, the package, named “mouse5212-super-formatter,” is designed to upload files from “/mnt/user-data,” a dedicated directory used by Anthrop…
2026-05-27
[The Record]
Army Gen. Joshua Rudd, who took the twin-leadership reins of Cyber Command and the NSA in March, recently tapped MITRE to conduct a potentially wide-ranging review into the organization, according to three people familiar with the matter.
#cybercrime #government #leadership #news
2026-05-27
[The Record]
In a public advisory issued Tuesday the FBI said a hacking group has targeted law firms using social engineering schemes to gain remote access to corporate systems and exfiltrate data.
#cybercrime #government #news #news-briefs
2026-05-27
[SecurityWeek]
Novee researchers discovered an account takeover vulnerability in the open source CFP management tool Pretalx.
The post Vulnerability in Popular Conference Software Granted Attackers a 100% Talk Acceptance Rate appeared first on SecurityWeek.
#vulnerabilities #pretalx #vulnerability
2026-05-27
[Schneier on Security]
The 2025 Internet Crime Report was published a few weeks ago, but I only just saw it.
Lots of interesting statistics.
Press release. News articles.
#uncategorized #crime #cybercrime #fbi #reports
2026-05-27
[Bleeping Computer]
Strong Active Directory passwords don’t have to come at the expense of usability. Specops Software explains how passphrases, breached password protection, and self-service resets can improve security without frustrating users. […]
#security
2026-05-27
[Infosecurity Magazine]
Operators of the malicious Glassworm botnet have been targeting software developers since at least early 2025
#malware
2026-05-27
[Black Hills InfoSec]
ANTISOC uses a mix of techniques from traditional penetration tests like red teams, cloud, web applications, externals, internals, and, of course, social engineering. We combine this mix of techniques with a wide-open scope, with the goal of going beyond what a typical pentest can discover.
The post…
#corey-ham #fun--games #informational #antisoc #continuous-penetration-testing
2026-05-27
[Infosecurity Magazine]
Cybermindz warns that cybersecurity burnout is a growing risk, urging organizations to move beyond wellness initiatives and adopt a measurable, risk-based approach to workforce stress
2026-05-27
[Bleeping Computer]
The Glassworm botnet targeting developers in software supply-chain attacks has been disrupted after researchers took down its resilient command-and-control infrastructure relying on Solana blockchain transactions and the BitTorrent DHT network. […]
#security
2026-05-27
[The Record]
The suspect was detained in the central Dutch town of Buren, where law enforcement officers also searched his home and seized multiple digital storage devices, according to a statement released Tuesday by the Dutch National Police.
#cybercrime #news #news-briefs
2026-05-27
[SecurityWeek]
Now in its third year, the AI Risk Summit is the leading conference that brings together CISOs, security leaders, AI researchers, developers, policymakers, and enterprise risk professionals.
The post SecurityWeek to Host AI Risk Summit August 11-12 at the Ritz-Carlton, Half Moon Bay appeared first o…
#artificial-intelligence #uncategorized #ai #conference
2026-05-27
[Infosecurity Magazine]
2026-05-27
[Dark Reading]
The cybersecurity industry of 2006 barely resembled today’s billion-dollar behemoth. As part of Dark Reading’s 20th anniversary celebration, we trace the industry’s evolution through a technology lens.
2026-05-27
[SecurityWeek]
Using an AI model called BinNet, RevEng hunts vulnerabilities and backdoors in released software binaries.
The post RevEng.AI Raises $15 Million to Hunt for Flaws and Backdoors in Software Binaries appeared first on SecurityWeek.
#cybersecurity-funding #funding #revengai
2026-05-27
[Bleeping Computer]
The FBI warned on Tuesday that the Silent Ransom Group (SRG) extortion gang is now targeting U.S.-based law firms in in-person data theft attacks. […]
#security
2026-05-27
[Malwarebytes Labs]
The FBI has warned that attackers are using a new phishing kit to gain long-term access to Microsoft Outlook, Teams, and OneDrive accounts.
#news #scams #kali365 #microsoft #phishing
2026-05-27
[SecurityWeek]
Catalin Dragomir previously pleaded guilty to selling access to an Oregon state government office’s network.
The post Romanian Hacker Sentenced to Prison in US for Selling Access to State Network appeared first on SecurityWeek.
#cybercrime #hacker #sentenced
2026-05-27
[SecurityWeek]
The new funding, led by BDC Capital’s StrongNorth Fund, will accelerate Lastwall’s North American expansion.
The post Lastwall Raises $11.5 Million for Quantum-Resilient Identity Platform appeared first on SecurityWeek.
#cybersecurity-funding #funding #lastwall #quantum
2026-05-27
[The Hacker News]
Cybersecurity researchers have disclosed a security flaw in Gitea, an open-source, self-hosted platform for version control, that allows unauthenticated remote attackers to pull private container images from Gitea deployments without requiring an account, password, or other credentials.
The vulnera…
#vulnerability #authentication
2026-05-27
[Bleeping Computer]
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has given U.S. federal agencies four days to secure their servers against a critical vulnerability in the LiteSpeed cPanel user-end plugin, which is actively being exploited in attacks. […]
#security
2026-05-27
[Malwarebytes Labs]
Cox Media said it could spy on users through their devices and use the information for targeted advertising, except it wasn’t true.
#news #privacy #brag #cox-media #ftc
2026-05-27
[SecurityWeek]
The attack was claimed by a hacktivist group, but evidence showed it used infrastructure linked to Iranian government threat actors.
The post LA Metro Cyberattack Linked to Iranian State-Sponsored Hackers appeared first on SecurityWeek.
#nation-state #hacktivists #iran #la-metro #nation-state
2026-05-27
[Malwarebytes Labs]
Phishers are stealing LinkedIn credentials while abusing Adobe Target to track victims and redirect them to real LinkedIn pages.
#privacy #scams #threat-intel #adobe-target #linkedin
2026-05-27
[Infosecurity Magazine]
UK firms plan higher cyber spending as AI adoption raises security concerns
2026-05-27
[Bleeping Computer]
The Dutch National Police arrested a 35-year-old man suspected of hacking the professional football club Ajax Amsterdam (AFC Ajax) earlier this year. […]
#security
2026-05-27
[Bleeping Computer]
Microsoft has released the KB5089573 preview cumulative update for Windows 11 versions 25H2 and 24H2, which comes with 30 changes, including performance and reliability improvements. […]
#microsoft
2026-05-27
[SecurityWeek]
The FBI has issued an alert warning of Silent Ransom Group attacks targeting law firms.
The post FBI: Hackers Sending Operatives in Person to Insert USB Drives and Steal Data appeared first on SecurityWeek.
#cybercrime #ransomware #tracking--law-enforcement #alert #fbi
2026-05-27
[Infosecurity Magazine]
FortiGuard Labs detailed a PureLogs campaign using JavaScript, PowerShell and process hollowing
2026-05-27
[The Hacker News]
Microsoft has warned of an active cryptojacking campaign that makes use of artificial intelligence (AI) chatbot interactions as a mechanism for surfacing malicious download sites.
“This emerging delivery technique extends social engineering beyond conventional search results and increases the visib…
#malware #phishing #windows
2026-05-27
[SecurityWeek]
Resolved last week, the vulnerability was exploited in the wild as a zero-day to execute scripts with root privileges.
The post CISA Urges Immediate Patching of Exploited LiteSpeed cPanel Plugin Zero-Day appeared first on SecurityWeek.
#vulnerabilities #cisa-kev #cpanel #exploited #litespeed
2026-05-26
[Microsoft Security]
Microsoft exposes a cryptojacking campaign using SEO poisoning and ScreenConnect to target high-performance PCs, with malicious sites also surfaced through AI chatbots.
The post From poisoned search results to GPU mining: A cryptojacking campaign abusing ScreenConnect and Microsoft .NET utilities ap…
#windows
2026-05-26
[Bleeping Computer]
Hackers exploited a critical zero-day vulnerability in a server running the KnowledgeDeliver learning management system (LMS) to deploy the Godzilla web shell. […]
#security
2026-05-26
[Dark Reading]
In just six hours, the campaign quietly pushed thousands of malicious commits to more than 5,500 GitHub repositories, stealing credentials, developer secrets, and more.
#malware #authentication
2026-05-26
[Bleeping Computer]
U.S. telecommunications giant Charter Communications has confirmed it suffered a data breach after the ShinyHunters extortion group threatened to leak stolen data unless a ransom is paid. […]
#security
2026-05-26
[Dark Reading]
A recent congressional hearing highlighted how states are reeling from federal cutbacks to important cyber grants and information sharing initiatives amid damaging attacks to critical infrastructure.
2026-05-26
[Dark Reading]
TeamPCP, the hackers behind the Shai-Hulud worm, has done significant damage to the open source ecosystem. But it’s not necessarily due to skill alone.
2026-05-26
[AWS Security]
May 26, 2026: This post was originally published in July 2022. It has been updated to reflect current engagement options, new threat intelligence resources such as the Threat Technique Catalog for AWS (TTC), additional open-source tools, and the distinction between AWS CIRT support and the AWS Secur…
#announcements #security-identity--compliance #incident-response #security-blog #threat-detection--incident-response
2026-05-26
[CrowdStrike]
#threat-hunting--intel
2026-05-26
[CrowdStrike]
#next-gen-identity-security
2026-05-26
[Dark Reading]
SharePoint access often means access to the keys of the kingdom, something attackers and defenders understand all too well.
#patch #windows
2026-05-26
[AWS Security]
There have been multiple notable supply chain attacks using the npm Registry since September: Shai-Hulud, Chalk/Debug, one abusing tea.xyz tokens, and recently axios. Thanks to community efforts involving the Amazon Inspector team, the Open Source Security Foundation, and others, the affected packag…
#advanced-300 #best-practices #security-identity--compliance #security-blog
2026-05-26
[The Hacker News]
The Iranian hacking group known as MuddyWater has been linked to a new campaign affecting at least nine organizations across nine countries on four continents in the first quarter of 2026.
The activity targeted industrial and electronics manufacturing, education and public-sector bodies, financial …
2026-05-26
[Schneier on Security]
Not identifying people based on their use of Wi-Fi routers, but identifying people using Wi-Fi signals.
This is accomplished through what is known as WiFi sensing, or the use of WiFi signals to infer information about a physical environment. When radio signals like WiFi travel through a space, they …
#uncategorized #identification #privacy #surveillance #wi-fi
2026-05-26
[Infosecurity Magazine]
Almost all organizations impersonated by Chinese phishing platforms are non-Chinese entities, suggesting operators deliberately avoid domestic targets
#phishing #apt #authentication
2026-05-26
[The Record]
The Lithuanian Prosecutor General’s Office said Friday that attackers gained unauthorized access to more than 600,000 records managed by the Centre of Registers, the state agency responsible for handling property and legal entity records.
#news #cybercrime #government
2026-05-26
[Tenable Research]
Cybersecurity leaders and practitioners brought their burning AI cybersecurity questions to EXPOSURE 2026. They left with clear answers and a blueprint for building an exposure management program. Get a recap and see highlights from the event in words and pictures. Key takeawaysAs frontier AI models…
2026-05-26
[Bleeping Computer]
AI governance requires visibility into how AI tools interact with enterprise data. Varonis explains how its Atlas platform uses Claude Compliance API data to help monitor usage, investigate risk, and support compliance. […]
#security
2026-05-26
[Infosecurity Magazine]
BTMOB Android RAT sold as a service with a no-code builder for fast, regional phishing lures
#phishing
2026-05-26
[SecurityWeek]
Marlin AI automatically analyzes SaaS misconfigurations, investigates related activity across enterprise environments, and recommends remediation steps — while stopping short of fully autonomous corrective action.
The post AppOmni’s Marlin AI Brings Autonomous Investigation to SaaS Security appeared…
#incident-response #ai #investigation #saas
2026-05-26
[SecurityWeek]
Nimbus Manticore has continued its operations during and after the US military campaign against Iran.
The post Iranian APT Targets Aviation, Software Companies With Updated Tools appeared first on SecurityWeek.
#malware--threats #apt #apt35 #charming-kitten #iran
2026-05-26
[Malwarebytes Labs]
We found fake installers and plugins for ChatGPT, Claude, AutoTune, and other popular software that can give attackers full control over your device.
#scams #threat-intel
2026-05-26
[Rapid7 Blog]
Security leaders are operating in an environment that is only getting more complex. Expanding attack surfaces, rapid AI adoption, growing toolsets, and increasing pressure to respond faster have made it harder to maintain a clear view of risk and priorities.At the Rapid7 Global Cybersecurity Summit,…
#events #managed-detection-and-response-mdr
2026-05-26
[Bleeping Computer]
Microsoft is testing a new Defender for Endpoint capability that will automatically isolate compromised endpoints to thwart attackers’ attempts to move laterally across the network. […]
#microsoft #security
2026-05-26
[Dark Reading]
The co-founder and former editor-in-chief passed away five years ago in November. As Dark Reading enters is third decade, we pause to celebrate and honor Wilson’s instrumental role in building and elevating the media site.
2026-05-26
[CISA Alerts]
View CSAF
Summary
Successful exploitation of this vulnerability could allow an attacker to gain full access to functionality and data with the bioreactor.
The following versions of Eppendorf BioFlo 320 are affected:
BioFlo 320 Bioreactor vers:all/*
CVSS
Vendor
Equipment
Vulnerabilities
v3 …
#vulnerability
2026-05-26
[CISA Alerts]
View CSAF
Summary
ABB is aware of public reports of vulnerabilities in a 3rd party component VLC media player Version 2.2.4 which was delivered together with the installation package of Camera Connect Version 1.5.0.14 and below. An update is available that resolves a privately reported outdated 3rd …
#vulnerability
2026-05-26
[The Hacker News]
Every single day, hackers are finding new ways to crash websites and steal data.
But right now, something has changed. Hackers are no longer working alone. They are now using powerful Artificial Intelligence (AI) tools to make their attacks faster, stronger, and much harder to stop.
According to r…
#ddos
2026-05-26
[The Hacker News]
Microsoft has rolled out updates to fix a remote code execution vulnerability impacting SharePoint that could be exploited by bad actors in attacks without requiring any specialized conditions to be met.
The vulnerability, tracked as CVE-2026-45659, carries a CVSS score of 8.8. It has been assigned…
#vulnerability #rce #patch #windows
2026-05-26
[Malwarebytes Labs]
Hackers are abusing a Ghost CMS website flaw to serve fake Cloudflare verification pages that pressure users into infecting their own PCs.
#bugs #news #clickfix #ghost-cms #sql-injection
2026-05-26
[The Hacker News]
Multi-factor authentication (MFA) was supposed to close a critical gap in identity security. It meant that, even if an attacker possessed the account credentials, they couldn’t log in without the second factor. While that logic was sound, attackers have now figured out that they don’t need to steal …
#authentication
2026-05-26
[Infosecurity Magazine]
CERT-In urges 12-hour patching of exposed flaws as AI compresses exploitation timelines
#vulnerability #patch
2026-05-26
[Check Point Research]
Executive Summary During the March–April 2026 reporting period, AI use in offensive operations advanced from development and planning to real-time operational deployment. Multiple independent cases, involving individual criminal actors, mass exploitation platforms, ransomware groups, and state-spons…
#ai-research #check-point-research-publications
2026-05-26
[Malwarebytes Labs]
Court documents reveal how tech support scammers relied on infrastructure supplied by a US business.
#news #scams
2026-05-26
[ESET WeLiveSecurity]
The malware pairs remote access capabilities with ready-made campaign tools, lowering the barrier for full device compromise
#malware
2026-05-26
[Bleeping Computer]
Microsoft has confirmed a new known issue affecting Windows Server 2016 systems that causes domain controller lookups to fail after installing the KB5087537 May 2026 security update. […]
#microsoft
2026-05-26
[Bleeping Computer]
The ShinyHunters extortion gang stole the personal information of over 183,000 people after hacking the systems of convenience store chain giant 7-Eleven in April, according to data breach notification service Have I Been Pwned. […]
#security
2026-05-26
[The Hacker News]
A now-patched high-severity security flaw affecting Digital Knowledge KnowledgeDeliver, a Learning Management System (LMS) popular in Japan, was exploited as a zero-day to deliver the Godzilla web shell and ultimately facilitate the deployment of Cobalt Strike Beacon.
The vulnerability, tracked as …
#zero-day #vulnerability #patch
2026-05-26
[Elastic Security Labs]
Tycoon 2FA bypasses MFA on Entra ID and Google Workspace. We map telemetry fingerprints across both platforms, ship detection rules for both tiers, and contain incidents in under 10 seconds with Elastic Workflows.
#security-labs
2026-05-25
[The Record]
Andrei Kozlov, the former head of a cybersecurity center within Russia’s state-owned defense conglomerate Rostec, was named an aide to Security Council Secretary Sergei Shoigu on Friday.
#government
2026-05-25
[The Record]
Investigators seized more than 800 servers as they arrested two men suspected of violating European sanctions and assisting pro-Russian cyberattacks and disinformation campaigns.
#government
2026-05-25
[Bleeping Computer]
Anthropic appears to be preparing for the public rollout of the Mythos model, which was announced in April as a restricted model that poses major security risks to private and public software. […]
#artificial-intelligence #software
2026-05-25
[The Hacker News]
Monday recap. Same mess, new week.
A sketchy dev tool got people pwned, old bugs came back from the dead, and security products somehow needed protecting from themselves. A bunch of companies spent the week checking old boxes and forgotten servers they should’ve patched years ago. Good times.
Phis…
#zero-day #malware #supply-chain #patch #network
2026-05-25
[Mandiant]
Written by: Takahiro Sugiyama, Peter Revelant, Mathew Potaczek
Introduction
In late 2025, Mandiant responded to a security incident involving a compromised web server running KnowledgeDeliver. KnowledgeDeliver is a Learning Management System (LMS) developed by Digital Knowledge commonly used in Jap…
#threat-intelligence
2026-05-25
[Mandiant]
Written by: Jamie Collier
While Russian-speaking threat actors have historically dominated the phishing-as-a-service (PhaaS) landscape, a rival ecosystem is rapidly growing within the Chinese-language underground. Google Threat Intelligence Group (GTIG) analyzed a dozen current PhaaS offerings in t…
#threat-intelligence
2026-05-25
[SecurityWeek]
Sites belonging to major universities such as Harvard and Oxford, as well as DuckDuckGo, have been compromised in the attack.
The post Ghost CMS Vulnerability Exploited to Hack Over 700 Websites appeared first on SecurityWeek.
#vulnerabilities #cms #exploited #ghost #vulnerability
2026-05-25
[SecurityWeek]
The affected third-party vendor has not been named, but one possible candidate is TriZetto.
The post Oncology Institute Discloses Data Breach appeared first on SecurityWeek.
#data-breaches #data-breach #healthcare #the-oncology-institute
2026-05-25
[The Hacker News]
Threat actors are exploiting a recently disclosed critical security flaw in Ghost CMS to inject malicious JavaScript code with an aim to fuel ClickFix attacks.
According to QiAnXin XLab, the activity involves the exploitation of CVE-2026-26980 (CVSS score: 9.4), an SQL injection vulnerability in Gh…
#vulnerability #apt #injection
2026-05-25
[The Hacker News]
Ask a cybersecurity pro about Network Detection and Response (NDR) and you might still hear “Noisy,” “Too much data.” But ask the teams running NDR that includes agentic AI capabilities and you’ll hear they’re actually using it to catch threats earlier, triage faster, and chase fewer false positives…
2026-05-25
[SecurityWeek]
Threat actors stole files containing names and protected health information from the healthcare organization’s systems.
The post 266,000 Affected by Data Breach at Radiology Associates of Richmond appeared first on SecurityWeek.
#data-breaches #data-breach #healthcare
2026-05-25
[SecurityWeek]
Many findings have been confirmed to be critical or high-severity vulnerabilities and the number will continue to increase.
The post Anthropic: Mythos Detected 23,000 Potential Vulnerabilities Across 1,000 OSS Projects appeared first on SecurityWeek.
#artificial-intelligence #vulnerabilities #ai #featured #mythos
2026-05-25
[The Hacker News]
Cybersecurity researchers have shed light on a cross-platform malware called RemotePE that has been put to use by the North Korea-linked Lazarus Group in attacks targeting financial and cryptocurrency organizations.
RemotePE, per NCC Group subsidiary Fox-IT, is part of a multi-stage attack chain th…
#malware
2026-05-25
[Infosecurity Magazine]
The Kali365 phishing-as-a-service platform lowers the barrier of entry for cybercriminals, said the FBI
#phishing #windows
2026-05-25
[Infosecurity Magazine]
From fake F1 streams to counterfeit merch, fraudsters are exploiting fans online and the Bitdefender Cybersecurity Grand Prix Fan Threat Index details how
#vulnerability
2026-05-25
[SecurityWeek]
Fake automated commits injected GitHub Actions workflows containing payloads to steal credentials, CI secrets, keys, and tokens.
The post Over 5,500 GitHub Repositories Infected in ‘Megalodon’ Supply Chain Attack appeared first on SecurityWeek.
#application-security #supply-chain-security #featured #github #megalodon
2026-05-25
[Malwarebytes Labs]
A list of topics we covered in the week of May 18 to May 24 of 2026
#news #chrome #defender #webcam
2026-05-25
[The Hacker News]
A new coordinated cross-ecosystem software supply chain attack campaign has targeted npm, PyPI, and Crates.io to distribute credential-stealing malware.
The campaign, codenamed TrapDoor, spans more than 34 malicious packages across over 384 versions. The earliest activity was recorded on May 22, 20…
#malware #supply-chain #authentication
2026-05-24
[Bleeping Computer]
A large-scale campaign is exploiting a critical SQL injection vulnerability (CVE-2026-26980) in Ghost CMS to inject malicious JavaScript code that triggers ClickFix attack flows. […]
#security
2026-05-23
[Bleeping Computer]
A supply chain attack targeting the Laravel Lang localization packages has exposed developers to a sophisticated credential-stealing malware campaign after attackers abused GitHub version tags to distribute malicious code through Composer packages. […]
#security
2026-05-23
[The Hacker News]
GitHub has rolled out new controls for npm to improve the security of the software supply chain, giving maintainers the ability to explicitly approve a release prior to the packages becoming publicly available for installation.
Called staged publishing, the feature is now generally available on npm…
#supply-chain #authentication
2026-05-23
[The Hacker News]
A new “coordinated” supply chain attack campaign has impacted eight packages on Packagist including malicious code designed to run a Linux binary retrieved from a GitHub Releases URL.
“Although the affected packages were all Composer packages, the malicious code was not added to composer.json,” Soc…
#malware #supply-chain #linux
2026-05-23
[Bleeping Computer]
Italian authorities have dismantled a piracy ecosystem centered around the CINEMAGOAL app that provided access to various streaming platforms, including Netflix, Disney+, and Spotify. […]
#legal
2026-05-23
[The Hacker News]
Anthropic on Friday disclosed that Project Glasswing has helped uncover more than 10,000 high- or critical-severity vulnerabilities across some of the most “systemically” important software across the world since the cybersecurity initiative went live last month.
Project Glasswing is an effort led …
#vulnerability
2026-05-23
[SecurityWeek]
The stealthy vulnerability impacts roughly 88 million domains and can be exploited to bypass DNS filtering and hide command-and-control traffic.
The post ‘Underminr’ Vulnerability Lets Attackers Hide Malicious Connections Behind Trusted Domains appeared first on SecurityWeek.
#network-security #cdn #dns #featured #vulnerability
2026-05-23
[The Hacker News]
Cybersecurity researchers have flagged a fresh software supply chain attack campaign that has targeted multiple PHP packages belonging to Laravel-Lang to deliver a comprehensive credential-stealing framework.
The affected packages include -
laravel-lang/lang
laravel-lang/http-statuses
lara…
#malware #supply-chain #authentication
2026-05-23
[The Hacker News]
A maximum-severity security vulnerability impacting LiteSpeed User-End cPanel Plugin has come under active exploitation in the wild.
The flaw, tracked as CVE-2026-48172 (CVSS score: 10.0), relates to an instance of incorrect privilege assignment that an attacker could abuse to run arbitrary scripts…
#vulnerability
2026-05-23
[CrowdStrike]
#securing-ai
2026-05-23
[The Hacker News]
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a recently patched critical security flaw impacting Drupal Core to its Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation.
The vulnerability in question is CVE-2026-9082 (CVSS score: 6.5)…
#vulnerability #patch #injection
2026-05-23
[The Record]
The Cybersecurity and Infrastructure Security Agency (CISA) announced the creation of a nomination form on Thursday that they said enables “researchers, vendors, and industry partners” to report bugs that need to be added to the Known Exploited Vulnerabilities catalog.
#government #cybercrime #industry #news
2026-05-22
[Schneier on Security]
The South Pacific Regional Fisheries Management Organization (SPRFMO) needs to regulate squid fishing in the South Pacific.
As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered.
Blog moderation policy.
#uncategorized #squid
2026-05-22
[The Record]
The law enforcement agency published an advisory on Thursday about Kali365 — a Telegram-based service for cybercriminals that allows them to capture legitimate “OAuth” tokens enabling widespread access to Microsoft 365 environments.
#cybercrime #government #news
2026-05-22
[The Record]
The bellwether lawsuit was the first of at least 1,200 to be brought by a school district against Meta, Snap, YouTube and TikTok for similar alleged harms. The other cases have not yet been tried.
#news #technology
2026-05-22
[Rapid7 Blog]
Another week, another authentication bypassOur humble Metasploit weekly(ish) blog has been blessed with a new network component vulnerability. The dynamic duo of @sfewer-r7 and @jburgess-r7 have discovered and authored the admin/networking/cisco_sdwan_vhub_auth_bypass module for CVE-2026-20182, a vu…
#metasploit #metasploit-weekly-wrapup
2026-05-22
[The Hacker News]
Authorities in Europe and North America have announced the dismantling of a criminal virtual private network (VPN) service used by criminal actors to obscure the origins of ransomware attacks, data theft, scanning, and denial-of-service attacks.
The disruption of First VPN Service was led by France…
#ransomware #ddos #network
2026-05-22
[Bleeping Computer]
Financial crime investigators in the Netherlands (FIOD) arrested two men and seized 800 servers linked to a web hosting company that enabled cyberattacks, interference operations, and disinformation campaigns. […]
#security #legal
2026-05-22
[SecurityWeek]
Drupal is warning users that it has already seen attempts to exploit CVE-2026-9082 and security firms are seeing attacks against thousands of websites.
The post Drupal Vulnerability in Hacker Crosshairs Shortly After Disclosure appeared first on SecurityWeek.
#vulnerabilities #drupal #exploited #featured
2026-05-22
[Microsoft Security]
Microsoft has been recognized as a Leader in The Forrester Wave™: Workforce Identity Security Platforms, Q2 2026, receiving the highest scores in both the current offering and strategy categories.
The post Microsoft recognized as a Leader in The Forrester Wave™ for Workforce Identity Security Platfo…
#forrester-waves
2026-05-22
[Microsoft Security]
A multi-stage attack on Linux devices began with an exposed F5 BIG-IP edge appliance and pivoted to an internal Confluence server for credential theft and identity compromise. Learn how the threat actor attempted Kerberos relay and lateral movement, and how Microsoft Defender detected, blocked, and …
#credential-theft #linux
2026-05-22
[Krebs on Security]
Lawmakers in both houses of Congress are demanding answers from the U.S. Cybersecurity & Infrastructure Security Agency (CISA) after KrebsOnSecurity reported this week that a CISA contractor intentionally published AWS GovCloud keys and a vast trove of other agency secrets on a public GitHub account…
#a-little-sunshine #data-breaches #latest-warnings #the-coming-storm #adam-boileau
2026-05-22
[The Hacker News]
The Belarus-aligned threat actor known as Ghostwriter (aka UAC-0057 and UNC1151Ukraine’s National Security and Defense Council) has been observed using lures related to Prometheus, a Ukrainian online learning platform, to target government organizations in the country.
The activity, per the Compute…
#malware #phishing #apt
2026-05-22
[Microsoft Security]
How Frontier firms secure AI at scale: read how Microsoft customers embed governance, identity, and cloud security to make protection an enabler of AI growth.
The post Microsoft Security success stories: How St. Luke’s and ManpowerGroup are securing AI foundations appeared first on Microsoft Securit…
#microsoft-365
2026-05-22
[Dark Reading]
When Akamai announced its LayerX acquisition, the company joined a growing list of vendors adding secure enterprise browsers to their product portfolios.
2026-05-22
[Bleeping Computer]
Two former executives of a call-tracking and analytics company pleaded guilty to concealing a years-long tech support fraud scheme that victimized individuals worldwide. […]
#security
2026-05-22
[Check Point Research]
Key Findings Introduction During the recent geopolitical tensions in the Middle East, we reported on multiple Iran-nexus threat actors advancing Iran’s strategic objectives through cyber operations. These activities included targeting internet-connected cameras, conducting destructive attacks agains…
#check-point-research-publications #threat-research
2026-05-22
[The Record]
Lawyer Adam Unikowsky spoke with Recorded Future News about why he believes geofence searches are problematic and why the way the court rules could have a dramatic impact on Americans’ right to privacy.
#government #news #interviews #privacy
2026-05-22
[SecurityWeek]
Other noteworthy stories that might have slipped under the radar: CISA contractor exposes credentials, Mythos testing and new features, Huawei router flaw triggered telecom blackout.
The post In Other News: Industrial Router Exploitation, CISA KEV Nomination Form, Gas Station Hacking appeared first …
#malware--threats #in-other-news
2026-05-22
[Dark Reading]
Ransomware and vendor breaches persist, but the 2026 Data Breach Investigations Report (DBIR) highlights how evolving social engineering tactics make the sector more vulnerable.
#ransomware #phishing #data-breach
2026-05-22
[Bleeping Computer]
Drupal is warning that hackers are attempting to exploit a “highly critical” SQL injection vulnerability announced earlier this week. […]
#security
2026-05-22
[Palo Alto Unit 42]
Unit 42 details Screening Serpens’ use of AppDomainManager hijacking and new RAT variants to target tech and defense sectors in recent campaigns.
The post Tracking Iranian APT Screening Serpens’ 2026 Espionage Campaigns appeared first on Unit 42.
#malware #threat-actor-groups #advanced-persistent-threat #appdomainmanager #dll-sideloading
2026-05-22
[SecurityWeek]
Jacob Butler, 23, has been arrested in Canada and US authorities are seeking his extradition on computer hacking charges.
The post Canadian Man Arrested for Operating Kimwolf Botnet appeared first on SecurityWeek.
#cybercrime #arrested #botnet #hacker #kimwolf
2026-05-22
[Malwarebytes Labs]
This Chrome update fixes critical flaws attackers could exploit through malicious websites, but not the “Browser Fetch” vulnerability.
#bugs #news #browser-fetch #chrome #cve-2026-9110
2026-05-22
[Bleeping Computer]
Ubiquiti has released security updates to patch three maximum severity vulnerabilities in Unify OS that can be exploited by remote attackers without privileges. […]
#security
2026-05-22
[The Hacker News]
Cybersecurity researchers have disclosed details of a new automated campaign called Megalodon that has pushed 5,718 malicious commits to 5,561 GitHub repositories within a six-hour window.
“Using throwaway accounts and forged author identities (build-bot, auto-ci, ci-bot, pipeline-bot), the attacke…
2026-05-22
[The Hacker News]
1 Introduction
This article provides a technical analysis of how many Windows kernel mode drivers can be interacted with from user mode without the hardware they were developed for. This work was motivated by driver-oriented vulnerability research and the need to evaluate the exploitability of indi…
#vulnerability #windows #linux
2026-05-22
[Infosecurity Magazine]
The infostealer payload in this campaign collect a vast amount of data, from collaboration authentication keys to cryptocurrency wallets
#malware #authentication
2026-05-22
[Palo Alto Unit 42]
Open-source framework ROADtools is being misused by threat actors for cloud intrusions. Learn how to identify its malicious use.
The post Paved With Intent: ROADtools and Nation-State Tactics in the Cloud appeared first on Unit 42.
#cloud-cybersecurity-research #threat-research #curious-serpens #entra-id #microsoft-azure
2026-05-22
[SecurityWeek]
The FBI says First VPN has been used by dozens of ransomware groups for network reconnaissance and intrusions.
The post ‘First VPN’ Cybercrime Service Disrupted, Administrator Arrested appeared first on SecurityWeek.
#cybercrime #tracking--law-enforcement #cybercrime #first-vpn #law-enforcement
2026-05-22
[Kaspersky Securelist]
Cloud Atlas attacks the public sector and diplomatic structures of Russia and Belarus, using ReverseSocks, SSH, and Tor for persistence in infected systems and its new tool, PowerCloud.
#apt-reports #malware-technologies #microsoft-windows #targeted-attacks #malware-descriptions
2026-05-22
[Bleeping Computer]
U.S. and Canadian authorities arrested and charged a Canadian man with operating the KimWolf distributed denial-of-service (DDoS) botnet, which infected nearly two million devices worldwide. […]
#security
2026-05-22
[The Hacker News]
The U.S. Department of Justice (DoJ) on Thursday announced the arrest of a Canadian man in connection with allegedly operating a distributed denial-of-service (DDoS) botnet known as Kimwolf.
In tandem, Jacob Butler (aka Dort), 23, Ottawa, Canada, has been charged with offenses related to the develo…
#malware #ddos
2026-05-22
[ESET WeLiveSecurity]
Watch out for bogus World Cup websites that mimic official ticket and merchandise flows to steal money and personal data
#digital-security
2026-05-22
[SecurityWeek]
CVE-2026-34926 is a directory traversal flaw that can be exploited against the on-premise version of Apex One.
The post TrendAI Patches Apex One Zero-Day Exploited in the Wild appeared first on SecurityWeek.
#vulnerabilities #exploited #featured #trend-micro #trendai
2026-05-22
[SecurityWeek]
Hackers accessed Grafana’s GitHub repositories after a token compromised in the TanStack attack was not rotated.
The post Grafana Says Codebase and Other Data Stolen via TanStack Supply Chain Attack appeared first on SecurityWeek.
#data-breaches #supply-chain-security #grafana #mini-shai-hulud #source-code
2026-05-22
[Dark Reading]
The advanced persistent threat group also relied on SOCKS proxies like SoftEther VPN, tunneling tools that act as a middleman between victim and attacker.
#apt #network #windows
2026-05-22
[The Hacker News]
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added two security flaws impacting Langflow and Trend Micro Apex One to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation.
The vulnerabilities in question are listed below -
CVE-…
#vulnerability
2026-05-21
[The Record]
The large-scale data breach reportedly hit Unimed, a company that handles billing services for privately insured and self-paying patients on behalf of numerous German hospitals.
#cybercrime
2026-05-21
[The Record]
A Belarus-linked hacking group known as GhostWriter has launched a new espionage campaign against Ukrainian government officials using fake emails disguised as messages from a popular online learning platform to deliver malware.
#government
2026-05-21
[Krebs on Security]
Canadian authorities on Wednesday arrested a 23-year-old Ottawa man on suspicion of building and operating Kimwolf, a fast spreading Internet-of-Things botnet that enslaved millions of devices for use in a series of massive distributed denial-of-service (DDoS) attacks over the past six months. Krebs…
#a-little-sunshine #ddos-for-hire #internet-of-things-iot #neer-do-well-news #aisuru
2026-05-21
[Dark Reading]
Finding ways to document both component and execution attributes for AI bill of materials (AI BOM).
2026-05-21
[Dark Reading]
A security researcher discovered the API keys can still be used for 23 minutes after deletion, even though the cloud provider claims deletion is immediate.
2026-05-21
[CrowdStrike]
#agentic-soc
2026-05-21
[AWS Security]
We’re excited to announce that Amazon Web Services (AWS) has completed the S&P Global Know Your Third Party (KY3P) assessment of its security posture. This assessment demonstrates our continued commitment to meet the heightened expectations of cloud service providers. Customers can now use the AWS K…
#announcements #compliance #foundational-100 #security-identity--compliance #security-blog
2026-05-21
[The Record]
The regulator, Ofcom, had required Roblox, Snapchat, Instagram, Facebook, YouTube and TikTok to answer questions about their efforts to remove harmful algorithms, check kids’ ages and protect them from sexual predators by the end of April.
#government #industry #news #privacy
2026-05-21
[Bleeping Computer]
Google has accidentally leaked details about an unfixed issue in Chromium that keeps JavaScript running in the background even when the browser is closed, allowing remote code execution on the device. […]
#security
2026-05-21
[The Record]
Adam Young, 42, and Harrison Gevirtz, 33, pleaded guilty to misprision of a felony after they were accused of offering phone numbers, call routing services, call tracking tools and call forwarding services to India-based telemarketing fraudsters.
#cybercrime #government #news
2026-05-21
[Malwarebytes Labs]
CISA added seven known exploited vulnerabilities to its KEV catalog, including two Microsoft Defender flaws.
#bugs #news #cisa #defender #microsoft
2026-05-21
[Graham Cluley]
For almost 20 years, stolen credentials have been the most common route for attackers into organizations, according to the Verizon Data Breach Investigations Report (DBIR). But that’s no longer the case.
Read more in my article on the Fortra blog.
#ai #data-loss #guest-blog #phishing #ransomware
2026-05-21
[Schneier on Security]
A group used Anthropic’s Mythos AI model to help find a kernel memory corruption vulnerability and exploit on Apple’s M5.
News article.
#uncategorized #ai #apple #exploits #vulnerabilities
2026-05-21
[AWS Security]
Managing identities and access across complex environments has become more critical than ever. AWS Directory Service for Managed Microsoft Active Directory, also known as AWS Managed Microsoft AD, has added new capabilities to manage users and groups. Now, you can perform create, read, update, and d…
#amazon-eventbridge #amazon-guardduty #aws-cloudformation #aws-directory-service #aws-step-functions
2026-05-21
[Dark Reading]
AI agent projects are proliferating throughout the enterprise, and those AI agent identities require management, security, and governance. New Omdia research shows the AI agent identity budget dynamics are very different than traditional IAM projects.
2026-05-21
[Infosecurity Magazine]
First VPN, a service used by ransomware actors and fraudsters, was dismantled by Europol
#ransomware #network
2026-05-21
[Tenable Research]
A self-propagating worm has compromised more than 170 npm and PyPI packages, defeating provenance attestation and breaching OpenAI and Mistral AI. Here is what you need to know.Key takeawaysMini Shai-Hulud is a self-propagating worm by TeamPCP that steals developer and cloud credentials across the n…
#supply-chain #authentication
2026-05-21
[Bleeping Computer]
Apple revealed that it blocked over $11 billion in fraudulent App Store transactions over the last six years, more than $2.2 billion in potentially fraudulent App Store transactions in 2025 alone. […]
#apple #security
2026-05-21
[The Record]
The proposals would require researchers to cease activity the moment a vulnerability is identified, meaning they could not confirm it was real, assess its severity or determine its exploitability.
#government #cybercrime #industry #news #leadership
2026-05-21
[The Hacker News]
Cybersecurity researchers have disclosed details of a new Linux malware dubbed Showboat that has been put to use in a campaign targeting a telecommunications provider in the Middle East since at least mid-2022.
“Showboat is a modular post-exploitation framework designed for Linux systems, capable o…
#malware #vulnerability #linux
2026-05-21
[Bleeping Computer]
Modern crypto drainers don’t hack wallets. They trick users into approving malicious transactions. Flare explores how the Lucifer DaaS platform scales wallet theft through phishing and automation. […]
#security
2026-05-21
[Bleeping Computer]
A Chinese cyber-espionage campaign has been targeting telecommunications providers with newly discovered Linux and Windows malware dubbed Showboat and JFMBackdoor, respectively. […]
#security
2026-05-21
[Dark Reading]
“Showboat” doesn’t show off, but clearly it doesn’t need to, as it’s long helped China spy on small market communications providers.
#malware #linux
2026-05-21
[Tenable Research]
A highly critical SQL injection vulnerability in Drupal core’s database abstraction layer affects sites running PostgreSQL.Key TakeawaysCVE-2026-9082 is a highly critical SQL injection vulnerability in Drupal core’s database abstraction API that can be exploited by unauthenticated attackers on sites…
#vulnerability #injection
2026-05-21
[Dark Reading]
The Underminr domain-fronting attack allows threat actors to modify Web requests and leverage trusted websites to cloak malicious activity.
#vulnerability #apt
2026-05-21
[Infosecurity Magazine]
AI risks threaten to permeate supply chains through unvetted code and unaudited suppliers
#supply-chain
2026-05-21
[Rapid7 Blog]
The first quarter of 2026 reinforced that attackers are moving faster, operating with greater coordination, and exploiting weaknesses before most organizations can respond effectively. From escalating geopolitical tensions to increasingly aggressive ransomware operations, the latest quarterly Threat…
#research #ransomware #labs
2026-05-21
[Tenable Research]
The days of rigid, vendor-locked security stacks are over. The Tenable One Open Connector amplifies Tenable One’s extensive capacity to ingest and consolidate third-party security data, giving you more complete visibility across your attack surface, so you can keep using your preferred cybersecurity…
2026-05-21
[SecurityWeek]
Insufficient validation and authentication in the Secure Workload’s REST APIs provide remote attackers with Site Admin privileges.
The post Cisco Patches Critical Vulnerability in Secure Workload appeared first on SecurityWeek.
#vulnerabilities #cisco #patch #vulnerability
2026-05-21
[Infosecurity Magazine]
Qualys finds nine-year-old Linux ptrace flaw exposing SSH keys and password hashes locally
#linux
2026-05-21
[CISA Alerts]
View CSAF
Summary
Hitachi Energy is aware of the vulnerability, CVE-2022-4304 in the OSS component OpenSSL, that affects the GMS600 versions that are listed below. An attacker successfully exploiting this vulnerability could send trial messages to the server and record the time taken to process them…
#vulnerability
2026-05-21
[CISA Alerts]
View CSAF
Summary
ABB is aware of vulnerabilities in the product versions listed as affected in the advisory. An attacker who successfully exploited this vulnerability could cause the pollution of heap memory which potentially takes remote control of the product and performs a write operation to the…
#vulnerability
2026-05-21
[CISA Alerts]
View CSAF
Summary
ABB became aware of vulnerability in the product versions listed as affected in the advisory. An update is available that replaces an outdated third-party component. Although no successful exploitation was observed during testing of the affected B&R products, the identified vulnera…
#vulnerability
2026-05-21
[The Hacker News]
This week starts small.
A token leaks. A bad package slips in. A login trick works. An old tool shows up again. At first, it feels like the usual mess. Then you see the pattern: attackers are not always breaking in. They are using the parts we already trust.
That is what makes it worrying. The dan…
#zero-day #network #linux
2026-05-21
[SecurityWeek]
The company has developed a platform that uses specialized AI agents to inspect every incoming message.
The post Ocean Emerges From Stealth With $28M for Agentic Email Security Platform appeared first on SecurityWeek.
#cybersecurity-funding #email-security #email-security #funding #ocean
2026-05-21
[SecurityWeek]
The company blocked over 1.1 billion accounts and $2.2 billion in potentially fraudulent transactions.
The post Apple Rejected 2 Million App Store Submissions in 2025 for Security and Fraud Prevention appeared first on SecurityWeek.
#application-security #apple #apple-app-store #fraud
2026-05-21
[Malwarebytes Labs]
Ofcom says TikTok and YouTube are “not safe enough” for children, but simply adding stricter age checks is not the answer.
#family-and-parenting #news #children #online-ssafety #roblox
2026-05-21
[Bleeping Computer]
Flipper Devices, the maker of the Flipper Zero pentesting tool, is asking the community to help build Flipper One, an open Linux platform for connected devices. […]
#hardware #linux
2026-05-21
[SecurityWeek]
CVE-2026-9082 can be exploited without authentication for information disclosure, privilege escalation, and remote code execution.
The post Drupal Patches Highly Critical Vulnerability Exposing Websites to Hacking appeared first on SecurityWeek.
#vulnerabilities #drupal #vulnerability
2026-05-21
[SecurityWeek]
The company will invest in its firewall, certified patches, protection extensions, new products, and team expansion.
The post Socket Raises $60 Million at $1 Billion Valuation appeared first on SecurityWeek.
#cybersecurity-funding #supply-chain-security #funding #socket #supply-chain
2026-05-21
[The Hacker News]
Consider a cached access key on a single Windows machine. It got there the way most cached credentials do - a user logged in, and the key stored itself automatically. Standard AWS behavior. No one misconfigured anything or violated a policy. Yet that single key, which was easily accessible to a mino…
#cloud #authentication #windows
2026-05-21
[Malwarebytes Labs]
Know when a program tries to access your webcam so you can allow or block, in real time.
#privacy #product
2026-05-21
[Malwarebytes Labs]
Told not to commit crimes, the AI agents mostly did anyway. Arson, violence, romance, self-deletion, and general chaos quickly ensued.
#ai #news
2026-05-21
[Bleeping Computer]
On Wednesday, Microsoft started rolling out security patches for two Defender vulnerabilities that have been exploited in zero-day attacks. […]
#security #microsoft
2026-05-21
[The Hacker News]
Cybersecurity researchers have disclosed details of a vulnerability in the Linux kernel that remained undetected for nine years.
The vulnerability, tracked as CVE-2026-46333 (CVSS score: 5.5), is a case of improper privilege management that could permit an unprivileged local user to disclose sensit…
#vulnerability #linux
2026-05-21
[Zero Day Initiative]
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Progress Software Kemp LoadMaster. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2026-3517.
#vulnerability #rce #authentication #injection
2026-05-21
[The Hacker News]
GitHub on Wednesday officially confirmed that the breach of its internal repositories was the result of a compromise of an employee device involving a poisoned version of the Nx Console Microsoft Visual Studio Code (VS Code) extension.
The development comes as the Nx team revealed that the extensi…
#windows
2026-05-21
[The Hacker News]
Drupal has released security updates for a “highly critical” security vulnerability in Drupal Core that could be exploited by attackers to achieve remote code execution, privilege escalation, or information disclosure.
The vulnerability, now tracked as CVE-2026-9082, carries a CVSS score of 6.5 out …
#vulnerability #rce #patch
2026-05-20
[Graham Cluley]
A 23-year-old radio enthusiast spent £300 on a piece of kit from the internet, and used it to bring four packed high-speed trains to a screeching halt. His defence in court? Possibly the most creative excuse we’ve heard all year.
Meanwhile, owners of $4,000 robot lawnmowers are discovering that the…
#ai #podcast #vulnerability #artificial-intelligence #robot
2026-05-20
[The Record]
In a lengthy joint statement, Moscow and Beijing pledged closer cooperation on satellite internet technologies and joint work on software development and open-source initiatives — part of a broader effort to reduce reliance on Western technology and build a more independent technological ecosystem c…
#china
2026-05-20
[The Record]
The international operation targeted a service known as First VPN, which had been marketed for years on Russian-speaking cybercrime forums as a secure way for criminals to evade law enforcement.
#cybercrime
2026-05-20
[Bleeping Computer]
The Ukrainian cyberpolice, working in conjunction with U.S. law enforcement, has identified an 18-year-old man from Odesa suspected of running an infostealer malware operation targeting users of an online store in California. […]
#security
2026-05-20
[Bleeping Computer]
Threat actors brute-forced VPN credentials and bypassed multi-factor authentication (MFA) on SonicWall Gen6 SSL-VPN appliances to deploy tools used in ransomware attacks. […]
#security
2026-05-20
[AWS Security]
Agents have agency: they adapt and find multiple ways to solve problems. This autonomy creates a fundamental security challenge: the large language model (LLM) at the heart of the agent is non-deterministic, and its decisions can’t be predicted or guaranteed in advance. It can hallucinate harmful ac…
#amazon-bedrock #amazon-bedrock-agentcore #generative-ai #intermediate-200 #open-source
2026-05-20
[Dark Reading]
There is nothing cybersecurity professionals are more excited about, and nothing they fear more, than AI.
2026-05-20
[Dark Reading]
Open source software giant GitHub confirmed a data breach this week involving the theft of thousands of repos. One threat actor — TeamPCP — took credit.
#data-breach #apt
2026-05-20
[Dark Reading]
The disguised apps use WebView automation, JavaScript injection, and OTP interception to avoid detection and complete fraudulent subscriptions.
#injection
2026-05-20
[Palo Alto Unit 42]
Unit 42 analyzes npm supply chain evolution post-Shai Hulud. Discover wormable malware, CI/CD persistence, multi-stage attacks and more.
The post The npm Threat Landscape: Attack Surface and Mitigations (Updated May 20) appeared first on Unit 42.
#high-profile-threats #malware #credential-harvesting #github #npm-packages
2026-05-20
[Microsoft Security]
Compromised @antv npm packages deploy the Mini Shai-Hulud payload to steal CI/CD secrets from Linux-based automation environments. The malware executes during npm install and targets credentials across GitHub, AWS, Kubernetes, Vault, npm, and 1Password platforms.
The post Mini Shai Hulud: Compromise…
#linux
2026-05-20
[AWS Security]
Our largest security services customers started the same way every customer does – with a click. They enabled Amazon GuardDuty, Amazon Inspector, AWS WAF, and AWS Security Hub, experienced the benefits in real time, and evaluated with transparent pay-as-you-go pricing. No RFP. No six-month evaluatio…
#aws-security-hub #foundational-100 #partner-solutions #security-identity--compliance #thought-leadership
2026-05-20
[The Record]
The law mandates that platforms make it easy for people to ask that nonconsensual intimate images be removed and to delete them within 48 hours of a request.
#government #industry #news #news-briefs
2026-05-20
[The Hacker News]
Microsoft has unveiled two new open-source tools called RAMPART and Clarity to assist developers in better testing the security of artificial intelligence (AI) agents.
RAMPART, short for Risk Assessment and Measurement Platform for Agentic Red Teaming, functions as a Pytest-native safety and securi…
#windows
2026-05-20
[CrowdStrike]
#next-gen-identity-security
2026-05-20
[The Record]
The investigation began after U.S. authorities informed their Ukrainian counterparts that hackers operating from Ukraine could be involved in attacks targeting users of American e-commerce platforms, Ukraine’s Prosecutor General said.
#cybercrime #government #news #news-briefs
2026-05-20
[The Record]
The move comes as other major social media platforms are killing end-to-end encryption for messaging. In recent months, Instagram and TikTok both announced they will no longer offer the feature.
#news #news-briefs #technology #privacy
2026-05-20
[Dark Reading]
An unauthenticated attacker can exploit the command injection vulnerability to gain remote access to robotic systems, causing significant disruption to the environment.
#vulnerability #patch #injection
2026-05-20
[Microsoft Security]
Read about the unique challenges and rewards of securing gaming platforms and how to better protect gaming communities.
The post Securing the gaming culture of cultures appeared first on Microsoft Security Blog.
#windows
2026-05-20
[Bleeping Computer]
The Grafana data breach was caused by a single GitHub workflow token that slipped through the rotation process following the TanStack npm supply-chain attack last week. […]
#security
2026-05-20
[SecurityWeek]
The new Series A funding round brings the total raised by Quantum Bridge to $16 million.
The post Quantum Bridge Raises $8 Million for Quantum-Safe Key Distribution Solution appeared first on SecurityWeek.
#cybersecurity-funding #funding #pqc #quantum #quantum-bridge
2026-05-20
[Qualys Threat Research]
The Qualys Threat Research Unit (TRU) has discovered and published the full advisory for CVE-2026-46333, a logic flaw in the Linux kernel’s __ptrace_may_access() function that permits an unprivileged local user to disclose sensitive files and execute arbitrary commands as root on default installatio…
#uncategorized #vulnerabilities-and-threat-research #security #vulnerabilities
2026-05-20
[SecurityWeek]
The exploitation is mitigated by preventing the FsTx Auto Recovery Utility from starting when the WinRE image launches.
The post Microsoft Rolls Out Mitigations for ‘YellowKey’ BitLocker Bypass appeared first on SecurityWeek.
#endpoint-security #vulnerabilities #bitlocker #windows #yellowkey
2026-05-20
[Infosecurity Magazine]
Premium Deception campaign uses 250 Android apps to silently sign victims up to paid services
#malware
2026-05-20
[Microsoft Security]
The AI systems shipping inside enterprises today are fundamentally different from the ones we were building even two years ago, because they have moved well past answering questions and into accessing your email, retrieving records from your CRM, writing and executing code, and taking actions on you…
2026-05-20
[SecurityWeek]
Digital.ai’s latest threat report warns that agentic AI has erased the distinction between emerging and primary targets, enabling attackers to strike mobile apps within hours of release across every industry.
The post AI-Powered App Attacks Are Faster, More Frequent and Harder to Stop appeared first…
#application-security #artificial-intelligence
2026-05-20
[The Hacker News]
Microsoft on Tuesday said it disrupted a malware-signing-as-a-service (MSaaS) operation that weaponized the company’s Artifact Signing system to deliver malicious code and conduct ransomware and other attacks, compromising thousands of machines and networks across the world.
The tech giant attribut…
#ransomware #malware #windows
2026-05-20
[Bleeping Computer]
Identity checks alone can’t stop attackers using stolen session tokens and compromised devices. Specops Software outlines why Zero Trust strategies increasingly depend on continuous device verification. […]
#security
2026-05-20
[Black Hills InfoSec]
There is a certain kind of conversation that doesn’t get written up in a post-mortem, doesn’t generate a ticket, and never makes it into an end-of-quarter report. It happens on the margins—at a conference, in a hallway, or, in this case, at 30,000 feet above sea level. It’s the conversation where tw…
#active-soc #blue-team #informational #red-team #bhisinterviews
2026-05-20
[SecurityWeek]
1Password says AI coding agents should never hold persistent secrets, introducing a just-in-time credential model for OpenAI Codex designed to keep credentials out of prompts, code repositories, and model context.
The post 1Password Teams With OpenAI to Stop AI Coding Agents From Leaking Credentials…
#artificial-intelligence #1password #openai
2026-05-20
[The Record]
In most complaints, victims said they were given detailed information by fraudsters on how to take money from their bank account, where to find a cryptocurrency kiosk and how to send the funds.
#cybercrime #government #news
2026-05-20
[Tenable Research]
As frontier AI models collapse the traditional exploit window, Tenable Hexa AI transforms the security operating model from manual triage to agentic orchestration. See how you can automate vulnerability remediation and super-charge exposure management with Tenable Hexa AI.Key takeawaysAI models like…
#vulnerability
2026-05-20
[SecurityWeek]
The researcher who found it says the vulnerability could have been chained with a prompt injection to exfiltrate data.
The post Anthropic Silently Patches Claude Code Sandbox Bypass appeared first on SecurityWeek.
#artificial-intelligence #ai #claude-code #sandbox #sandbox-escape
2026-05-20
[Bleeping Computer]
Drupal has announced a “core security release” scheduled for later today, warning that threat actors might develop exploits within hours of the update disclosure. […]
#security
2026-05-20
[The Hacker News]
Cybersecurity researchers have flagged fresh activity from a China-aligned threat actor known as Webworm in 2025, deploying custom backdoors that employ Discord and Microsoft Graph API for command-and-control (C2 or C&C) communications.
Webworm, first publicly documented by Broadcom-owned Symantec …
#malware #apt #windows
2026-05-20
[The Record]
Github, which hosts code for more than 100 million developers worldwide, confirmed the breach on social media after TeamPCP advertised stolen source code on a cybercrime forum.
#cybercrime #news #news-briefs
2026-05-20
[Rapid7 Blog]
Modern attack surfaces don’t sit still.Cloud expansion, SaaS sprawl, identity complexity, and shadow IT are continuously reshaping organizational risk. For security leaders, visibility isn’t the challenge anymore, but actually operationalizing that visibility is.Surface Command was built to unify as…
#cloud-security #surface-command
2026-05-20
[The Record]
U.S. Senator Maggie Hassan (D-NH) sent a letter to the acting director of the Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday demanding answers about an alleged breach uncovered by cybersecurity reporter Brian Krebs involving government contractor Nightwing.
#cybercrime #government #news #news-briefs
2026-05-20
[CISA Alerts]
CISA has added seven new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
CVE-2008-4250 Microsoft Windows Buffer Overflow Vulnerability
CVE-2009-1537 Microsoft DirectX NULL Byte Overwrite Vulnerability
CVE-2009-3459 Adobe Acrobat and Re…
#vulnerability #windows
2026-05-20
[The Hacker News]
New Industry Data Just Released Suggests Not.
On May 19th, 2026, Orchid Security released the results of our Identity Gap: Snapshot 2026. Among the findings, “identity dark matter” (the unseen, unmanaged elements of identity) now overshadows the visible elements 57% vs. 43%. And it couldn’t have oc…
2026-05-20
[Malwarebytes Labs]
Firefox 151 adds major privacy improvements and fixes high-priority security vulnerabilities, making this an update you shouldn’t ignore.
#bugs #news #privacy #cve-2026-8953 #end-private-session
2026-05-20
[Infosecurity Magazine]
China-linked Webworm APT expands beyond Asia, targeting European government organizations and refining its cyber espionage tactics, according to ESET research
#apt
2026-05-20
[SecurityWeek]
A compromised maintainer account was used to publish malicious package versions across the @antv namespace.
The post Over 320 NPM Packages Hit by Fresh Mini Shai-Hulud Supply Chain Attack appeared first on SecurityWeek.
#malware--threats #supply-chain-security #mini-shai-hulud #supply-chain-attack #teampcp
2026-05-20
[SecurityWeek]
SecurityWeek spoke with several ICS security experts and companies about their most memorable experiences in the field.
The post Real-World ICS Security Tales From the Trenches appeared first on SecurityWeek.
#icsot #featured #ics #ot
2026-05-20
[Palo Alto Unit 42]
Unit 42 analyzes TamperedChef malware clusters that use trojanized productivity apps and malvertising to deliver stealthy payloads to targets.
The post Tracking TamperedChef Clusters via Certificate and Code Reuse appeared first on Unit 42.
#malware #threat-research #adware #appsuite-pdf #certificates
2026-05-20
[SecurityWeek]
Don’t miss this virtual event as we explore how to cut through alert fatigue, leverage AI and unified platforms to accelerate investigations, and apply actionable threat intelligence.
The post Virtual Event Today: Threat Detection & Incident Response Summit appeared first on SecurityWeek.
#malware--threats #threat-intelligence #threat-detection
2026-05-20
[Infosecurity Magazine]
Barracuda reveals new CypherLoc scareware has featured in nearly three million attacks
2026-05-20
[SecurityWeek]
The TeamPCP hacking group accessed the repositories after a GitHub employee installed a poisoned VS Code extension.
The post GitHub Confirms Hack Impacting 3,800 Internal Repositories appeared first on SecurityWeek.
#data-breaches #featured #github #teampcp
2026-05-20
[Kaspersky Securelist]
We explain how a flaw in ExifTool allows attackers to compromise macOS systems via a malicious image (CVE-2026-3102).
#great-research #vulnerability-reports #research #security-technologies #vulnerabilities-and-exploits
2026-05-20
[ESET WeLiveSecurity]
ESET researchers describe new tools and techniques that the Webworm APT group recently added to its arsenal
#eset-research
2026-05-20
[Infosecurity Magazine]
Verizon DBIR finds 31% of data breaches began with software flaws last year
#vulnerability #data-breach #authentication
2026-05-20
[Graham Cluley]
Having receive a ransom payment for its attack on Canvas, ShinyHunters and other extortion gangs are only likely to be further incentivised to launch similar attacks in future.
Read more in my article on the Hot for Security blog.
#data-loss #guest-blog #law--order #ransomware #canvas
2026-05-20
[The Hacker News]
Microsoft on Tuesday released a mitigation for a BitLocker bypass vulnerability named YellowKey following its public disclosure last week.
The zero-day flaw, now tracked as CVE-2026-45585, carries a CVSS score of 6.8. It has been described as a BitLocker security feature bypass.
“Microsoft is awar…
#zero-day #vulnerability #windows
2026-05-20
[Bleeping Computer]
GitHub has confirmed that roughly 3,800 internal repositories were breached after one of its employees installed a malicious VS Code extension. […]
#security
2026-05-20
[Bleeping Computer]
Microsoft has shared mitigations for YellowKey, a recently disclosed Windows BitLocker zero-day vulnerability that grants access to protected drives. […]
#microsoft #security
2026-05-20
[Dark Reading]
While the numbers are modest, the crackdown on cybercrime involved 13 countries in the MENA region, the largest law enforcement collaboration to date.
2026-05-20
[The Hacker News]
Grafana Labs, on May 19, 2026, said an investigation into its recent breach found no evidence of customer production systems or operations being compromised.
It said the scope of the incident is limited to the Grafana Labs GitHub environment, which includes public and private source code along with…
2026-05-20
[Bleeping Computer]
GitHub is investigating a breach of its internal repositories after the TeamPCP hacker group claimed to have accessed approximately 4,000 repositories containing private code. […]
#security
2026-05-20
[The Hacker News]
GitHub on Tuesday said it’s investigating unauthorized access to its internal repositories after the notorious threat actor known as TeamPCP listed the platform’s source code and internal organizations for sale on a cybercrime forum.
“While we currently have no evidence of impact to customer inform…
#apt
2026-05-20
[SecurityWeek]
Verizon’s 2026 DBIR finds vulnerability exploitation has overtaken credential abuse as the leading breach vector, as AI accelerates attacks, patching delays worsen, and ransomware and third-party compromises continue to surge.
The post Verizon DBIR 2026: Vulnerability Exploitation Overtakes Credenti…
#data-breaches #incident-response #dbir #report #verizon
2026-05-19
[Bleeping Computer]
A max-severity vulnerability in the latest Python FastAPI version of the ChromaDB project allows unauthenticated attackers to run arbitrary code on exposed servers. […]
#security
2026-05-19
[Dark Reading]
A brief overview of the forces at play that will get more organizations on board with creating and consuming AI bill of materials (BOMs).
2026-05-19
[Dark Reading]
Verizon’s “2026 Data Breach Investigations Report” (“DBIR”) finds that exploits are now involved in 31% of initial access for breaches, while patching lags too far behind the bad guys.
#vulnerability #data-breach #patch
2026-05-19
[Bleeping Computer]
Microsoft says it has disrupted a malware-signing-as-a-service (MSaaS) operation that abused the company’s Artifact Signing service to generate fraudulent code-signing certificates used by ransomware gangs and other cybercriminals. […]
#security
2026-05-19
[AWS Security]
The AWS Customer Incident Response Team works with customers to help them recover from active security incidents. As part of this work, the team often uncovers new or trending tactics used by various threat actors that take advantage of specific customer configurations and designs. Understanding the…
#aws-organizations #best-practices #security-identity--compliance #security-blog
2026-05-19
[Dark Reading]
YellowKey, GreenPlasma, and MiniPlasma add to the growing list of vulnerabilities a security researcher disclosed over the past six weeks.
#zero-day #vulnerability #patch #windows
2026-05-19
[Bleeping Computer]
Discord announced that all voice and video calls through the communication platform are now protected by default with end-to-end encryption (E2EE). […]
#security
2026-05-19
[Dark Reading]
The agency’s GitHub repository, publicly available since November 2025, was ironically named “Private-CISA.”
#authentication
2026-05-19
[Dark Reading]
The SHub Reaper stealer, which hides behind fake WeChat and Miro installers, marks a shift from ClickFix social engineering to Apple script-based execution.
#malware #phishing #windows
2026-05-19
[Bleeping Computer]
The FBI says Americans have lost over $388 million last year to scams using cryptocurrency kiosks, also known as crypto ATMs or Bitcoin ATMs. […]
#security #cryptocurrency
2026-05-19
[Bleeping Computer]
A threat actor targeting Microsoft 365 and Azure production environments is stealing data in attacks that abuse legitimate applications and administration features. […]
#security #cloud #microsoft
2026-05-19
[The Record]
There is no evidence that the incident has recurred, but the flaw remains unexplained and has not been publicly acknowledged by the company.
#cybercrime #government #news #technology
2026-05-19
[The Record]
The regulator’s announcement said the change is being made due to the “urgent need to better protect women and girls online.”
#government #industry #news
2026-05-19
[The Hacker News]
Cybersecurity researchers have disclosed details of a new ad fraud and malvertising operation dubbed Trapdoor targeting Android device users.
The activity, per HUMAN’s Satori Threat Intelligence and Research Team, encompassed 455 malicious Android apps and 183 threat actor-owned command-and-control…
#apt
2026-05-19
[The Record]
The company unsealed a legal case in U.S. District Court on Tuesday detailing the disruption of Fox Tempest — a popular service that has operated since May 2025 and provides cybercriminals with code signing tools.
#cybercrime #news #technology
2026-05-19
[Qualys Threat Research]
The Verizon 2026 Data Breach Investigations Report has been published. Qualys is proud to have served as a research partner and contributor, contributing analysis of more than one billion anonymized vulnerability remediation records across four consecutive DBIR reporting cycles of CISA Known Exploit…
#vulnerabilities-and-threat-research #2026-verizon-dbir #dbir #tru #trurisk-research-report
2026-05-19
[Bleeping Computer]
Microsoft plans to raise the quality bar of Windows 11 drivers, as drivers “sit at the heart of every Windows experience” and connect the OS to the “silicon, components, and peripherals.” […]
#microsoft #software
2026-05-19
[SecurityWeek]
Drupal says attackers may develop an exploit for the vulnerability within hours or days.
The post Drupal to Patch Highly Critical Vulnerability at Risk of Quick Exploitation appeared first on SecurityWeek.
#vulnerabilities #drupal #vulnerability
2026-05-19
[AWS Security]
Organizations often struggle to enforce security and compliance requirements consistently across their cloud infrastructure. In one environment, a workload might be deployed in an AWS Region that was never approved for that class of data. In another, a security group might allow broader access than …
#advanced-300 #best-practices #security-identity--compliance #governance #security-blog
2026-05-19
[Bleeping Computer]
Microsoft has confirmed user reports that the Teams team collaboration app is displaying non-dismissible location prompts on some macOS systems. […]
#microsoft #apple
2026-05-19
[SecurityWeek]
Fox Tempest provides a service that cybercriminals use to distribute ransomware and other malware disguised as legitimate software.
The post Microsoft Disrupts Malware-Signing Service Run by ‘Fox Tempest’ appeared first on SecurityWeek.
#malware--threats #featured #fox-tempest #malware #microsoft
2026-05-19
[Malwarebytes Labs]
NYC Health + Hospitals says attackers accessed its systems for months through a third-party vendor compromise, affecting at least 1.8 million people.
#data-breaches #news #biometrics #nyc-hh
2026-05-19
[Rapid7 Blog]
Security teams are working in an environment where speed, scale, and complexity are all increasing at the same time. Across the Rapid7 2026 Global Cybersecurity Summit, the focus was not just on how the threat landscape is evolving, but on how teams are adapting their approach to keep up.The session…
#events
2026-05-19
[Infosecurity Magazine]
Microsoft’s Digital Crimes Unit has taken down the infrastructure of Fox Tempest, a prolific cybercrime-enabling threat group
#ransomware #windows
2026-05-19
[Bleeping Computer]
Threat actors earlier today published more than 600 malicious packages to the Node Package Manager (npm) index as part of a new Shai-Hulud supply-chain campaign. […]
#security
2026-05-19
[Bleeping Computer]
Convenience store chain giant 7-Eleven confirmed that its systems were breached in a cyberattack claimed by the ShinyHunters extortion group last month. […]
#security
2026-05-19
[Dark Reading]
Dark Reading editors reflect on two decades of dramatic change — from perimeter defense to assume-breach strategies — and warn that while AI, cloud, and COVID-19 have transformed the threat landscape, organizations are still failing at fundamental security hygiene that could stop sophisticated attac…
2026-05-19
[Tenable Research]
The 2026 Verizon Data Breach Investigations Report (DBIR) reveals a troubling trend: vulnerability exploitation has surged to become the number one initial access vector while remediation rates have worsened.Key takeawaysVulnerability exploitation has surged to become the leading initial access vect…
#vulnerability #data-breach
2026-05-19
[SecurityWeek]
Attackers are increasingly abusing Microsoft’s decades-old MSHTA utility to stealthily deliver stealers, loaders, and persistent malware through phishing, fake software downloads, and LOLBIN-based attack chains.
The post Legacy Windows Tool MSHTA Fuels Surge in Silent Malware Attacks appeared first …
#endpoint-security #malware--threats #malware #mshta #windows
2026-05-19
[SecurityWeek]
The security defect can be exploited remotely, without authentication, to execute arbitrary code and leak sensitive information.
The post Unpatched ChromaDB Vulnerability Can Lead to Server Takeover appeared first on SecurityWeek.
#vulnerabilities #chromadb #vulnerability
2026-05-19
[Malwarebytes Labs]
A fake Aldi “meat box” offer spreading on Facebook tricks victims into handing over personal and payment info.
#scams #threat-intel #aldi #meat-box
2026-05-19
[Infosecurity Magazine]
AI-powered vulnerability scanning leaves no excuse for unpatched bugs as the EU Cyber Resilience Act pushes firms toward secure-by-design software
#vulnerability #patch
2026-05-19
[Bleeping Computer]
IT teams are increasingly overwhelmed by alerts from disconnected systems, forcing responders to manually coordinate investigations during network incidents. This webinar explores how automation and AI-assisted workflows can help reduce response delays and improve operational coordination. […]
#security
2026-05-19
[CISA Alerts]
View CSAF
Summary
Successful exploitation of this vulnerability could result in information disclosure, including capture of camera account credentials.
The following versions of ZKTeco CCTV Cameras are affected:
SSC335-GC2063-Face-0b77 Solution
CVSS
Vendor
Equipment
Vulnerabilities
v3 9.1…
#vulnerability #authentication
2026-05-19
[CISA Alerts]
View CSAF
Summary
A buffer overflow vulnerability in the User-ID™ Authentication Portal (aka Captive Portal) service of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to execute arbitrary code with root privileges on the PA-Series and VM-Series firewalls by sending specially c…
#vulnerability #authentication #network
2026-05-19
[CISA Alerts]
View CSAF
Summary
Successful exploitation of this vulnerability could allow an attacker to take control of the victim’s browser.
The following versions of Kieback & Peter DDC Building Controllers are affected:
DDC4002 <=1.12.14 (CVE-2026-4293)
DDC4100 <=1.12.14 (CVE-2026-4293)
DDC4200 <=1.12.14 (CV…
#vulnerability
2026-05-19
[Infosecurity Magazine]
Digital.ai data reveals 87% of apps were attacked over the past year
2026-05-19
[CISA Alerts]
View CSAF
Summary
An update is available that resolves vulnerability in the product versions listed as affected in this advisory. A path traversal vulnerability in these products can allow unauthenticated users to gain access to restricted directories. Exploiting this vulnerability can lead to compl…
#vulnerability
2026-05-19
[SecurityWeek]
The stolen credit card data was released as a free download, allegedly in response to seller misconduct.
The post B1ack’s Stash Marketplace Gives Away 4.6 Million Stolen Credit Cards appeared first on SecurityWeek.
#cybercrime #b1ack-stash #credit-card #cybercrime #dark-web
2026-05-19
[The Hacker News]
In February 2026, a phishing-as-a-service (PhaaS) platform called EvilTokens went live. Within five weeks, it had compromised more than 340 Microsoft 365 organizations across five countries.
The targets of the platform received a message asking them to enter a short code at microsoft.com/devicelog…
#phishing #authentication #windows
2026-05-19
[SecurityWeek]
The organizations best prepared to face disruption are those that align security, continuity and risk management around what the business cannot afford to lose.
The post Cyber Resilience is the New Business Continuity Plan appeared first on SecurityWeek.
#risk-management #security-architecture #resilience
2026-05-19
[Bleeping Computer]
Microsoft says customers in restricted network environments may encounter Windows Update failures after installing the January 2026 optional non-security preview updates. […]
#microsoft #security
2026-05-19
[Schneier on Security]
Not by name, but Laurie Anderson quotes me in one of the tracks of her new album:
My favorite quote is from a cryptologist who said “If you think technology will solve your problems, you don’t understand technology and you don’t understand your problems.”
Also in interviews:
“Of course, it’s ridicul…
#uncategorized #music #schneier-news
2026-05-19
[Malwarebytes Labs]
“Likeness detection” promises protection from AI deepfakes, but some creators are uneasy about handing over biometric data in return.
#ai #privacy #youtube
2026-05-19
[The Hacker News]
Drupal has issued an alert stating that it intends to release a “core security release” for all supported branches on May 20, 2026, from 5-9 p.m. UTC.
“The Drupal Security Team urges you to reserve time for core updates at that time because exploits might be developed within hours or days,” the mai…
#vulnerability #patch
2026-05-19
[SecurityWeek]
The 13-country effort, named Operation Ramz, targeted cyber threats in the Middle East and North Africa region.
The post 201 Arrested in Crackdown on Cybercrime in Middle East, North Africa appeared first on SecurityWeek.
#cybercrime #tracking--law-enforcement #arrested #cybercrime #interpol
2026-05-19
[SecurityWeek]
Patched in April, the underlying vulnerability allows local attackers to elevate their privileges to root.
The post PoC Released for DirtyDecrypt Linux Kernel Vulnerability appeared first on SecurityWeek.
#endpoint-security #vulnerabilities #dirtydecrypt #linux-vulnerability #privilege-escalation
2026-05-19
[The Hacker News]
Critical security vulnerabilities have been disclosed in SEPPMail Secure E-Mail Gateway, an enterprise-grade email security solution, that could be exploited to achieve remote code execution and enable an attacker to read arbitrary mails from the virtual appliance.
“These vulnerabilities could have …
#vulnerability #rce
2026-05-19
[Infosecurity Magazine]
Open source tool maker Grafana says hackers stole codebase via GitHub breach
2026-05-19
[ESET WeLiveSecurity]
A complete decoupling from US technology is neither realistic nor necessary, but the changing environment does require nations and companies to reassess their relationships and dependencies
#digital-security
2026-05-19
[Infosecurity Magazine]
Bridewell report calls out emergence of “fix-style” attacks
2026-05-19
[The Hacker News]
Cybersecurity researchers have flagged a compromised version of the Nx Console extension that was published to the Microsoft Visual Studio Code (VS Code) Marketplace.
The extension in question is rwl.angular-console (version 18.95.0), a popular user interface and plugin for code editors like VS Cod…
#malware #authentication #windows
2026-05-19
[SecurityWeek]
The vulnerability, CVE-2026-8153, affects Universal Robots PolyScope 5 and it can be exploited for OS command injection.
The post Critical Vulnerability Exposes Industrial Robot Fleets to Hacking appeared first on SecurityWeek.
#icsot #vulnerabilities #cobots #featured #ics
2026-05-19
[The Hacker News]
In yet another software supply chain attack, threat actors have compromised the popular GitHub Actions workflow, actions-cool/issues-helper, to run malicious code that harvests sensitive credentials and exfiltrates them to an attacker-controlled server.
“Every existing tag in the repository has bee…
#apt #supply-chain #authentication
2026-05-19
[The Hacker News]
Cybersecurity researchers have discovered a fresh software supply chain attack campaign that has compromised various npm packages associated with the @antv ecosystem as part of the ongoing Mini Shai-Hulud attack wave.
“The attack affects packages tied to the npm maintainer account atool, including …
#supply-chain
2026-05-18
[Microsoft Security]
Storm-2949 turned stolen credentials into a cloud-wide breach, moving from identity compromise to large-scale data theft without using malware. This incident shows how threat actors can exploit trusted systems to operate undetected.
The post How Storm-2949 turned a compromised identity into a cloud-…
#credential-theft #incident-response
2026-05-18
[Bleeping Computer]
More than 200 individuals were arrested for cybercrime activities during INTERPOL’s Operation Ramz, which focused on the Middle East and North Africa. […]
#security #legal
2026-05-18
[Dark Reading]
Understanding AI BOMs and where they fit into risk management for artificial intelligence.
2026-05-18
[Dark Reading]
CVE-2026-42897 stems from a cross-site scripting (XSS) vulnerability and can allow an attacker to compromise Outlook Web Access (OWA) mailboxes.
#zero-day #vulnerability #patch #xss #windows
2026-05-18
[Bleeping Computer]
A new variant of the ‘SHub’ macOS infostealer uses AppleScript to show a fake security update message and installs a backdoor. […]
#security #cryptocurrency
2026-05-18
[Dark Reading]
The now patched vulnerabilities in the rapidly growing AI agent framework allow attackers to steal credentials, escalate privileges, and maintain persistence.
#vulnerability #patch #authentication
2026-05-18
[The Record]
Investigators found hundreds of compromised devices that were used as part of the cybercriminal operation and notified device owners as part of the raids.
#government #cybercrime #news
2026-05-18
[Krebs on Security]
Until this past weekend, a contractor for the Cybersecurity & Infrastructure Security Agency (CISA) maintained a public GitHub repository that exposed credentials to several highly privileged AWS GovCloud accounts and a large number of internal CISA systems. Security experts said the public archive …
#a-little-sunshine #data-breaches #latest-warnings #the-coming-storm #aws-govcloud
2026-05-18
[Dark Reading]
The release of Shai-Hulud source code spells trouble for software developers as researchers worry the self-replicating worm could scale.
2026-05-18
[Bleeping Computer]
Many employees already use shadow AI tools at work without security review. Adaptive Security breaks down how teams can build practical AI governance without adding friction for employees. […]
#security
2026-05-18
[The Record]
On Saturday night, the company released a statement confirming the incident and outlining their decision not to pay a ransom issued by the hackers behind the attack.
#cybercrime #news #news-briefs
2026-05-18
[Bleeping Computer]
The Shai-Hulud malware leaked last week is now used in new attacks on the Node Package Manager (npm) index, as infected packages emerged over the weekend. […]
#security
2026-05-18
[The Hacker News]
INTERPOL has coordinated a first-of-its-kind cybercrime crackdown across the Middle East and North Africa (MENA) that led to 201 arrests and the identification of an additional 382 suspects.
The initiative involved the efforts of 13 countries from the region between October 2025 and February 2026, a…
2026-05-18
[The Record]
OpenAI announced Friday that it is rolling out a new ChatGPT feature allowing users to connect all of their financial accounts to the chatbot for personal finance advice.
#news #privacy
2026-05-18
[Microsoft Security]
See how built-in security helps keep your growing business running, protect customer trust, and support growth.
The post How to better protect your growing business in an AI-powered world appeared first on Microsoft Security Blog.
#microsoft-365
2026-05-18
[Dark Reading]
Security experts have long warned that insecure automatic tank gauge (ATG) systems exposed on the Internet can be tampered with by threat actors.
#apt
2026-05-18
[Check Point Research]
For the latest discoveries in cyber research for the week of 18th May, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Vodafone, a major international telecom, has sustained a source code leak claimed by the Lapsus$ extortion group. The company confirmed limited access to …
#global-cyber-attack-reports
2026-05-18
[Infosecurity Magazine]
Over 200 people were arrested in an anti-cybercrime operation that spanned 13 countries across the Middle East and North Africa
2026-05-18
[The Hacker News]
Monday opens with a trust problem. A mail server flaw is under active use. A network control system was targeted. Trusted packages were poisoned. A fake model page pushed a stealer. Then came the familiar ransom claim: the data was returned and deleted.
The pattern is clear. One weak dependency can …
#zero-day #malware #vulnerability
2026-05-18
[Bleeping Computer]
Grafana Labs disclosed that hackers have downloaded its source code after breaching its GitHub environment using a stolen access token. […]
#security
2026-05-18
[Infosecurity Magazine]
New for 2026, the Infosecurity Europe Startup competition will see five finalists pitch their ideas in front of a live audience, including senior industry leaders, investors and buyers
2026-05-18
[Dark Reading]
AI agents capable of discovering and exploiting obscure vulnerabilities are emerging alongside developers producing vast amounts of potentially flawed AI-generated code, forcing defenders to adapt accordingly.
#vulnerability
2026-05-18
[The Hacker News]
What happens when a phishing email looks clean enough to pass through security, but dangerous enough to expose the business after one click? That is the gap many SOCs still struggle with: the attacks that leave teams unsure what was exposed, who else was targeted, and how far the risk has spread.
Ea…
#phishing
2026-05-18
[SecurityWeek]
Several healthcare data breaches impacting hundreds of thousands and even millions were added to the HHS tracker.
The post Millions Impacted Across Several US Healthcare Data Breaches appeared first on SecurityWeek.
#data-breaches #data-breach #healthcare
2026-05-18
[SecurityWeek]
Four vulnerabilities in OpenClaw can be chained together to steal credentials, escape the sandbox, and plant persistent backdoors.
The post ‘Claw Chain’ OpenClaw Flaws Allow Sandbox Escape, Backdoor Delivery appeared first on SecurityWeek.
#artificial-intelligence #vulnerabilities #ai #openclaw #vulnerability
2026-05-18
[Kaspersky Securelist]
This report contains mobile threat statistics for Q1 2026, along with noteworthy discoveries and quarterly trends: new versions of SparkCat and Triada.
#malware-reports #google-android #adware #mobile-malware #malware-statistics
2026-05-18
[SecurityWeek]
The hackers claimed to have stolen more than 600,000 Salesforce records, including personal information and corporate data.
The post 7-Eleven Data Breach Confirmed After ShinyHunters Ransom Demand appeared first on SecurityWeek.
#data-breaches #7-eleven #data-breach #salesforce #shinyhunters
2026-05-18
[The Hacker News]
Supply chain attackers are not only trying to slip malicious code into trusted software. They are trying to steal the access that makes trusted software possible. Recently, three separate campaigns hit npm, PyPI, and Docker Hub in a 48-hour window, and all three targeted secrets from developer envir…
#supply-chain
2026-05-18
[Bleeping Computer]
Microsoft has finally brought back the resizable taskbar and Start menu to Windows 11 in the latest preview version rolling out to Insiders in the Experimental channel. […]
#microsoft
2026-05-18
[The Hacker News]
Ivanti, Fortinet, n8n, SAP, and VMware have released security fixes for various vulnerabilities that could be exploited by bad actors to bypass authentication and execute arbitrary code.
Topping the list is a critical flaw impacting Ivanti Xtraction (CVE-2026-8043, CVSS score: 9.6) that could be exp…
#vulnerability #rce #patch #authentication #injection
2026-05-18
[CERT/CC]
Overview
Three vulnerabilities have been discovered in the SGLang project, two enabling remote code execution (RCE), and one regarding a path traversal vulnerability. In order for an attacker to exploit these vulnerabilities, the multimodal generation mode must be enabled, and an attacker must have …
#vulnerability #rce
2026-05-18
[SecurityWeek]
The researcher dropped the MiniPlasma exploit that uses the original proof-of-concept (PoC) code targeting the bug.
The post Researcher Drops MiniPlasma Windows Exploit for Unpatched 2020 CVE appeared first on SecurityWeek.
#vulnerabilities #exploit #miniplasma #unpatched #vulnerability
2026-05-18
[Infosecurity Magazine]
The UK’s National Cyber Security Centre is helping organizations to understand agentic AI security risks
2026-05-18
[Infosecurity Magazine]
The research community was awarded $1.3m as it found dozens of novel vulnerabilities at Pwn2Own Berlin
#zero-day #vulnerability
2026-05-18
[Infosecurity Magazine]
The UK’s financial authorities have set expectations for the sector on cybersecurity and operational resilience
2026-05-18
[SecurityWeek]
Grafana appears to have been targeted by Coinbase Cartel, a cybercrime group linked to ShinyHunters, Scattered Spider, and Lapsus$.
The post Grafana Confirms Breach After Hackers Claim They Stole Data appeared first on SecurityWeek.
#cybercrime #data-breaches #cybercrime #data-breach #grafana
2026-05-18
[Bleeping Computer]
Microsoft has confirmed that the May 2026 Windows 11 security update (KB5089549) fails to install on some systems and triggers 0x800f0922 errors. […]
#microsoft #security
2026-05-18
[Bleeping Computer]
A recently patched local privilege escalation vulnerability in the Linux kernel’s rxgk module now has a proof-of-concept exploit that allows attackers to gain root access on some Linux systems. […]
#security #linux
2026-05-18
[The Hacker News]
A new analysis of the Lua-based fast16 malware has confirmed that it was a cyber sabotage tool designed to tamper with nuclear weapons testing simulations.
According to Broadcom-owned Symantec and Carbon Black teams, the pre-Stuxnet tool was engineered to corrupt uranium-compression simulations that…
#malware
2026-05-18
[Cloudflare Security]
In recent weeks, we pointed Mythos and other security-focused LLMs at live code across critical parts of our infrastructure. We share what we observed, the models’ strengths and weaknesses, and what the work around them needs to look like before any of it can scale.
#security #ai #agents #threat-intelligence #llm
2026-05-18
[The Hacker News]
Chaotic Eclipse, the security researcher behind the recently disclosed Windows flaws, YellowKey and GreenPlasma, has released a proof-of-concept (PoC) for a Windows privilege escalation zero-day flaw that grants attackers SYSTEM privileges on fully patched Windows systems.
Codenamed MiniPlasma, the …
#zero-day #patch #windows
2026-05-18
[SecurityWeek]
Participants demonstrated exploits for Windows, Linux, VMware, Nvidia, and AI products.
The post Hackers Earn $1.3 Million at Pwn2Own Berlin 2026 appeared first on SecurityWeek.
#artificial-intelligence #vulnerabilities #exploit #featured #hacking-contest
2026-05-18
[Malwarebytes Labs]
This week on the Lock and Code podcast, we speak with Clara Mansfeld about how AI-generated imagery is warping the history of the Holocaust.
#podcast #ai #ai-generated-content #auschwitz #foundation-of-hamburg-memorials
2026-05-18
[Dark Reading]
South Korea’s local elections next month will be a test bed for how effective regulations might be to stymie the flow of deepfakes.
2026-05-17
[Bleeping Computer]
The Tycoon2FA phishing kit now supports device-code phishing attacks and abuses Trustifi click-tracking URLs to hijack Microsoft 365 accounts. […]
#security
2026-05-17
[The Hacker News]
A newly disclosed security flaw impacting NGINX Plus and NGINX Open has come under active exploitation in the wild, days after its public disclosure, according to VulnCheck.
The vulnerability, tracked as CVE-2026-42945 (CVSS score: 9.2), is a heap buffer overflow in ngx_http_rewrite_module affecting…
#vulnerability #rce
2026-05-17
[The Hacker News]
Grafana has disclosed that an “unauthorized party” obtained a token that granted them the ability to access the company’s GitHub environment and download its codebase.
“Our investigation has determined that no customer data or personal information was accessed during this incident, and we have f…
2026-05-16
[Bleeping Computer]
A security researcher claims Microsoft quietly fixed an Azure Backup for AKS vulnerability after rejecting his report, and without issuing a CVE. Microsoft disputes the claim, telling BleepingComputer the behavior was expected and that “no product changes were made,” despite the researcher documenti…
#security
2026-05-16
[The Hacker News]
A critical security vulnerability impacting the
Funnel Builder
plugin for WordPress has come under active exploitation in the wild to
inject malicious JavaScript code
into WooCommerce checkout pages with the goal of stealing payment data.
Details of the activity were
published
by Sa…
#vulnerability
2026-05-16
[SecurityWeek]
Introduced in 2008, the critical-severity security defect was patched this week in NGINX Plus and NGINX open source.
The post PoC Code Published for Critical NGINX Vulnerability appeared first on SecurityWeek.
#vulnerabilities #exploit #nginx #poc #vulnerability
2026-05-15
[Dark Reading]
The House Committee on Homeland Security sent a letter about the Canvas cyberattack, the same day that the edtech company said it reached an “agreement” with the ShinyHunters cybercriminals.
2026-05-15
[The Record]
THORChain officials said the investigation into the incident is ongoing but explained that one of their six vaults was compromised, leading to a loss of about $10.7 million.
#cybercrime #news #news-briefs #technology
2026-05-15
[Bleeping Computer]
A critical vulnerability in the Funnel Builder plugin for WordPress is being actively exploited to inject malicious JavaScript snippets into WooCommerce checkout pages. […]
#security
2026-05-15
[Rapid7 Blog]
Weaponizing a text editor for fun and profitGather round, dear readers, because today, we (by we, we mean @h00die) dropped the ultimate persistence mechanism: Vim plugin persistence. And honestly, calling it “persistence” feels redundant — Vim is already the most persistent thing ever. Somewhere, so…
#metasploit #metasploit-weekly-wrapup
2026-05-15
[AWS Security]
TL;DR for busy executives The AWS AI Security Framework helps security leaders move fast and stay secure with AI. Security compounds from day 1 as workloads evolve from prototype to production to scale. Assess first. Request a no-cost SHIP engagement to baseline your posture and build a prioritized …
#artificial-intelligence #best-practices #intermediate-200 #security-identity--compliance #security-blog
2026-05-15
[Bleeping Computer]
Hackers have injected credential-stealing malware into newly published versions of node-ipc, a popular inter-process communication package, in a new supply chain attack targeting npm. […]
#security
2026-05-15
[The Hacker News]
The Russian state-sponsored hacking group known as
Turla
has transformed its custom backdoor Kazuar into a modular peer-to-peer (P2P) botnet that’s engineered for stealth and persistent access to compromised hosts.
Turla, per the U.S. Cybersecurity and Infrastructure Security Agency…
#malware
2026-05-15
[Bleeping Computer]
Two vulnerabilities in the Avada Builder plugin for WordPress, with an estimated one million active installations, allow hackers to read arbitrary files and extract sensitive information from the database. […]
#security
2026-05-15
[Bleeping Computer]
Microsoft is updating the Edge web browser to ensure it no longer loads saved passwords into process memory in clear text at startup after previously stating it was “by design.” […]
#microsoft #security
2026-05-15
[Infosecurity Magazine]
A new Gremlin stealer variant has evolved into a modular toolkit with advanced evasion and data theft capabilities, according to new Unit 42 research
#malware
2026-05-15
[Bleeping Computer]
Stolen browser sessions and authentication tokens are becoming more valuable than stolen passwords. Flare explains how the REMUS infostealer evolved around session theft and operational scalability. […]
#security
2026-05-15
[Mandiant]
Written by: Austin Larsen, Tyler McLellan, Genevieve Stark, Dan Ebreo
Introduction
Google Threat Intelligence Group (GTIG) has continued to track an expansive extortion campaign by UNC6671, a threat actor operating under the “BlackFile” brand, that targets organizations via sophisticated voice phi…
#threat-intelligence
2026-05-15
[The Hacker News]
Cybersecurity researchers have disclosed a set of four security flaws in OpenClaw that could be chained to achieve data theft, privilege escalation, and persistence.
The vulnerabilities, collectively dubbed
Claw Chain
by Cyera, can permit an attacker to establish a foothold, expose s…
#vulnerability
2026-05-15
[The Record]
Cisco released a patch for the vulnerability on Thursday, writing in an advisory that it could “allow an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges on an affected system.”
#cybercrime #government #malware #news
2026-05-15
[Malwarebytes Labs]
The JDownloader website was compromised and installer download links served malware for several days.
#news #compromised-website #jdownloader #rat
2026-05-15
[Infosecurity Magazine]
The zero-day vulnerability affects on-premises installations for all versions of Exchange Server 2016, 2019 and Subscription Edition
#zero-day #vulnerability #windows
2026-05-15
[Malwarebytes Labs]
WhatsApp now offers disappearing AI chats Meta says it cannot read. While Instagram just removed the feature that stopped Meta reading your messages.
#ai #news #privacy #e2ee #instagram
2026-05-15
[Bleeping Computer]
Microsoft is introducing a new capability that will allow it to remotely roll back problematic Windows drivers delivered through Windows Update. […]
#microsoft
2026-05-15
[SecurityWeek]
Microsoft has shared mitigations for CVE-2026-42897 until a permanent patch can be released for affected Exchange Server versions.
The post Microsoft Warns of Exchange Server Zero-Day Exploited in the Wild appeared first on SecurityWeek.
#email-security #vulnerabilities #exchange #exploited #microsoft-exchange
2026-05-15
[Dark Reading]
Robert “RSnake” Hansen, Katie Moussouris, Rich Mogull, Richard Stiennon, and Bruce Schneier reflect on how their favorite columns penned for Dark Reading over the past 20 years have stood the test of time.
2026-05-15
[SecurityWeek]
The non-bank lender discovered a ransomware attack nearly one year ago, but only recently completed its investigation.
The post American Lending Center Data Breach Affects 123,000 Individuals appeared first on SecurityWeek.
#data-breaches #ransomware #alc #american-lending-center #data-breach
2026-05-15
[Schneier on Security]
Some AI-based video age-verification checks can be fooled with a fake mustache.
#uncategorized #ai #biometrics
2026-05-15
[The Hacker News]
In Your Biggest Security Risk Isn’t Malware — It’s What You Already Trust, we made a simple argument: the most dangerous activity inside most organizations no longer looks like an attack. It looks like administration. PowerShell, WMIC, netsh, Certutil, MSBuild — the same trusted utilities your IT te…
#malware
2026-05-15
[Palo Alto Unit 42]
Unit 42 analyzes the evolution of Gremlin stealer. This variant uses advanced obfuscation, crypto clipping and session hijacking to compromise data.
The post Gremlin Stealer’s Evolved Tactics: Hiding in Plain Sight With Resource Files appeared first on Unit 42.
#malware #threat-research #api #cryptocurrency #gremlin-stealer
2026-05-15
[SecurityWeek]
The hacking group is encouraging miscreants to use the code in supply chain attacks, promising monetary rewards.
The post TeamPCP Ups the Game, Releases Shai-Hulud Worm’s Source Code appeared first on SecurityWeek.
#malware--threats #supply-chain-security #malware #shai-hulud #source-code
2026-05-15
[ESET WeLiveSecurity]
Conflict is a boon for opportunistic fraudsters. Look out for their ploys.
#digital-security
2026-05-15
[Infosecurity Magazine]
A suspected China-linked threat actor targeted the Indian branch of a global manufacturer leveraging an open source offensive toolkit
#malware #apt
2026-05-15
[SecurityWeek]
The refresh resolves critical-severity use-after-free and other types of bugs in various browser components.
The post Chrome 148 Update Patches Critical Vulnerabilities appeared first on SecurityWeek.
#vulnerabilities #chrome #vulnerability
2026-05-15
[SecurityWeek]
The zero-day, tracked as CVE-2026-20182, has been exploited in targeted attacks by a sophisticated threat actor identified as UAT-8616.
The post Cisco Patches Another SD-WAN Zero-Day, the Sixth Exploited in 2026 appeared first on SecurityWeek.
#vulnerabilities #cisco #exploited #featured #sd-wan
2026-05-15
[The Hacker News]
Microsoft has disclosed a new security vulnerability impacting on-premise versions of Exchange Server that it said has come under active exploitation in the wild.
The vulnerability, tracked as CVE-2026-42897 (CVSS score: 8.1), has been described as a spoofing bug stemming from a cross-site scripting…
#vulnerability #xss #windows
2026-05-15
[The Hacker News]
The U.S.Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a newly disclosed vulnerability impacting Cisco Catalyst SD-WAN Controller to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to remediate the issue by May…
#vulnerability
2026-05-15
[Tenable Research]
Multiple critical authentication bypass vulnerabilities in Cisco Catalyst SD-WAN Controller and Manager are under active exploitation by multiple threat clusters, including CVE-2026-20182, which has been exploited as a zero-day by a sophisticated threat actor.Key TakeawaysCVE-2026-20182 is a critica…
#zero-day #vulnerability #apt #authentication
2026-05-15
[Dark Reading]
A Taiwanese student experimenting with software-defined radio technology shut down three bullet trains for nearly an hour, leading to an anti-terrorism response.
2026-05-15
[CrowdStrike]
#threat-hunting--intel
2026-05-14
[Bleeping Computer]
The TeamPCP hacker group is threatening to leak source code from the Mistral AI project unless a buyer is found for the data. […]
#security
2026-05-14
[Tenable Research]
Tenable Hexa AI eliminates “zombie” cloud infrastructure, helping you reduce risk and make a “killing” on cost reduction.Key takeawaysAs AI accelerates cloud growth, zombie cloud assets multiply in your environment. You need agentic AI to prevent a cloud zombie apocalypse.Cloud assets no longer in p…
2026-05-14
[Bleeping Computer]
Hackers are leveraging a critical authentication bypass vulnerability in the WordPress plugin Burst Statistics to obtain admin-level access to websites. […]
#security
2026-05-14
[Dark Reading]
The new acquisition looks to boost visibility into third-party ecosystems that are becoming a bigger concern as vectors for supply-chain attacks.
#supply-chain
2026-05-14
[AWS Security]
AWS IAM Identity Center provides a web-based access portal that gives your workforce a single place to view their AWS accounts and applications. With the recent launch of IAM Identity Center multi-Region replication, customers can replicate their IAM Identity Center instance across multiple AWS Regi…
#advanced-300 #amazon-route-53 #aws-iam-identity-center #networking--content-delivery #security-identity--compliance
2026-05-14
[Dark Reading]
This is the second time this year a threat actor has leveraged a CVSS 10.0 vulnerability in Cisco’s network control system.
#vulnerability #apt
2026-05-14
[Graham Cluley]
Lesson one for aspiring dark web kingpins: don’t have your laundered gold bars shipped to your home address.
Read more in my article on the Hot for Security blog.
#data-loss #guest-blog #law--order #security-threats #dark-web
2026-05-14
[Rapid7 Blog]
OverviewOn May 13, 2026, Palo Alto Networks published a security advisory for CVE-2026-0265, a signature verification vulnerability that facilitates authentication bypass on PAN-OS, the operating system that most Palo Alto Networks firewalls run. This vulnerability allows a remote unauthenticated at…
#emergent-threat-response #insightvm
2026-05-14
[Bleeping Computer]
OpenAI says two employees’ devices were breached in the recent TanStack supply chain attack that impacted hundreds of npm and PyPI packages, causing the company to rotate code-signing certificates for its applications as a precaution. […]
#security #education
2026-05-14
[Bleeping Computer]
On the first day of Pwn2Own Berlin 2026, security researchers collected $523,000 in cash awards after exploiting 24 unique zero-days. […]
#security #linux #microsoft #software
2026-05-14
[The Record]
Director of National Intelligence Tulsi Gabbard has tapped two individuals to coordinate work across U.S. spy agencies to monitor threats to the 2026 elections, according to multiple sources familiar with the matter.
#cybercrime #government #influence-operations #news
2026-05-14
[The Hacker News]
Cisco has released updates to address a maximum-severity authentication bypass flaw in Catalyst SD-WAN Controller that it said has been exploited in limited attacks.
The vulnerability, tracked as CVE-2026-20182, carries a CVSS score of 10.0.
“A vulnerability in the peering authentication in Cisco Ca…
#vulnerability #authentication
2026-05-14
[The Hacker News]
Cybersecurity researchers are sounding the alarm about what has been described as “malicious activity” in newly published versions of node-ipc.
According to Socket and StepSecurity, three different versions of the npm package have been confirmed as malicious -
node-ipc@9.1.6
node-ipc@9.2.3
node-ipc…
#malware
2026-05-14
[Dark Reading]
Attackers uniquely fingerprint victims before delivering spear-phishing payloads aimed at espionage, in the latest campaign from the Belarussian nation-state threat group.
#phishing #apt
2026-05-14
[AWS Security]
Migrating your TLS endpoints to Post-quantum cryptography (PQC) starts with understanding your current TLS endpoint inventory and posture. This post introduces the PQC Readiness Scanner — an automated tool that inventories your Application Load Balancer (ALB), Network Load Balancer (NLB), and Amazon…
#advanced-300 #aws-config #security-identity--compliance #technical-how-to #api-gateway
2026-05-14
[The Hacker News]
Everything is still on fire.
This week feels dumb in the worst way — bad links, weak checks, fake help desks, shady forum posts, and people turning supply chain attacks into some cursed little game for clout and cash. Half of it feels new. Half of it feels like crap we should have fixed years ago.
T…
#supply-chain #rce
2026-05-14
[Schneier on Security]
This is a current list of where and when I am scheduled to speak:
I’m giving a virtual talk on “The Security of Trust in the Age of AI,” hosted by the Financial Women’s Association of New York, at 6:00 PM ET on May 21, 2026.
I’m speaking at the Potsdam Conference on National Cybersecurity at the Ha…
#uncategorized #schneier-news
2026-05-14
[Rapid7 Blog]
Imagine you build a massive corporate campus with every security control money can buy. Blast resistant doors. Biometric scanners. Guards at every entrance. Maybe something similar to the infamous Death Star. On paper, it looks fantastic. Then, somewhere along the way, somebody decides the maintenan…
#research
2026-05-14
[Microsoft Security]
As AI agents gain autonomy, defense in depth must evolve, with application-layer design, identity, and human oversight at the center.
The post Defense in depth for autonomous AI agents appeared first on Microsoft Security Blog.
#windows
2026-05-14
[Rapid7 Blog]
OverviewWhile researching a critical authentication bypass vulnerability, CVE-2026-20127, which was exploited in-the-wild, Rapid7 Labs discovered a new authentication bypass vulnerability affecting Cisco Catalyst SD-WAN Controller (formerly known as vSmart), CVE-2026-20182.This new authentication by…
#vulnerability-disclosure #research #labs
2026-05-14
[Qualys Threat Research]
Qualys SaaS Security Posture Management (SSPM) introduces native support for the Secure Cloud Business Applications (SCuBA) compliance framework, bringing CISA’s toughest M365 security benchmarks directly into your continuous posture monitoring workflow. Key Takeaways What Is SCuBA and Why Does It M…
#product-and-tech #microsoft #saas-security-posture-management #sspm-security #total-cloud
2026-05-14
[Bleeping Computer]
An 18-year-old flaw in the NGINX open-source web server, discovered using an autonomous scanning system, can be exploited for denial of service and, under certain conditions, remote code execution. […]
#security #artificial-intelligence #healthcare
2026-05-14
[Bleeping Computer]
Cargo theft now starts with phishing emails and stolen credentials, not hijackings, to reroute and steal freight from supply chains. NMFTA outlines how cyber-enabled cargo crime is changing transportation security. […]
#security
2026-05-14
[Qualys Threat Research]
Executive Summary The 2025 SANS ASM Survey highlights a clear shift in cybersecurity operations. Organizations are moving beyond fragmented, alert-driven security approaches toward unified, automated, and business-aligned risk operations. Continuous visibility, intelligent automation, and business-c…
#product-and-tech #roc #sans
2026-05-14
[Infosecurity Magazine]
Mustang Panda campaign deploys updated FDMTP backdoor against Asia-Pacific and Japan networks
#malware
2026-05-14
[Microsoft Security]
Kazuar, a sophisticated malware family attributed to the Russian state actor Secret Blizzard, has been under constant development for years and continues to evolve in support of espionage-focused operations. Over time, Kazuar has expanded from a relatively traditional backdoor into a highly modular …
#blizzard #cyberespionage #secret-blizzard
2026-05-14
[Microsoft Security]
Exposed UIs, weak authentication, and risky defaults could turn cloud-native AI apps on Kubernetes into potential targets by threat actors. Learn how exploitable misconfigurations lead to RCE and data leaks.
The post When configuration becomes a vulnerability: Exploitable misconfigurations in AI app…
#vulnerability #data-breach #apt #rce #authentication
2026-05-14
[The Hacker News]
The Belarus-aligned threat group known as Ghostwriter has been attributed to a fresh set of attacks targeting governmental organizations in Ukraine.
Active since at least 2016, Ghostwriter has been linked to both cyber espionage and influence operations targeting neighboring countries, particularly …
#phishing
2026-05-14
[SecurityWeek]
For AI data centers, where the stakes are the highest and performance constraints are the tightest, security and performance are no longer a zero-sum game.
The post Enhancing Data Center Security Without Sacrificing Performance appeared first on SecurityWeek.
#security-architecture #security-infrastructure #data-center
2026-05-14
[Infosecurity Magazine]
Google’s Android Advanced Protection Mode is getting a new feature allowing trusted security experts to investigate potential spyware infections
2026-05-14
[SentinelOne Labs]
Mick Baccio and Scott Roberts examine whether public breach signals and market timing models can turn cyber incidents into actionable trading opportunities.
#breach #labscon
2026-05-14
[Infosecurity Magazine]
New Fragnesia kernel flaw lets unprivileged local users escalate to root on Linux systems
#linux
2026-05-14
[SecurityWeek]
Independent benchmarking finds Mythos highly effective for source code audits, reverse engineering, and native-code analysis, though its exploit validation and reasoning capabilities remain inconsistent.
The post Mythos Proves Potent in Vulnerability Discovery, Less Convincing Elsewhere appeared fir…
#artificial-intelligence #vulnerabilities #ai #featured #mythos
2026-05-14
[Dark Reading]
In a role reversal, investment dollars in security startups exceeded the value of mergers and acquisitions in 1Q26 by more than $1 billion, a rare occurrence.
2026-05-14
[Qualys Threat Research]
Qualys TotalCloud™ has achieved FedRAMP High Authorization, marking a major milestone in delivering validated cloud security and compliance assurance for high-impact federal and regulated environments. Key Takeaways Cloud security and compliance expectations have fundamentally shifted. Organizations…
#product-and-tech #cnapp #fedramp-high #qualys-totalcloud
2026-05-14
[Bleeping Computer]
Initial access broker KongTuke has moved to Microsoft Teams for social engineering attacks, taking as little as five minutes to gain persistent access to corporate networks. […]
#security
2026-05-14
[SecurityWeek]
Salt Typhoon has hit an energy entity in Azerbaijan. Twill Typhoon has targeted Asian entities with an updated RAT.
The post Chinese APTs Expand Targets, Update Backdoors in Recent Campaigns appeared first on SecurityWeek.
#malware--threats #nation-state #china #china-apt #salt-typhoon
2026-05-14
[CISA Alerts]
View CSAF
Summary
SIMATIC CN 4100 contains multiple vulnerabilities which could potentially lead to a compromise in availability, integrity and confidentiality. Siemens has released a new version for SIMATIC CN 4100 and recommends to update to the latest version.
The following versions of Siemens SI…
#vulnerability
2026-05-14
[CISA Alerts]
View CSAF
Summary
ROS# contains a ROS service file_server, that before version 2.2.2 contains a path traversal vulnerability which could allow an attacker to access, i.e. read and write, arbitrary files, which are accessible with the user rights of the user that runs the service, on the system that …
#vulnerability
2026-05-14
[CISA Alerts]
View CSAF
Summary
Siemens gPROMS Web Applications Publisher (gWAP) is affected by a remote code execution vulnerability introduced through a third-party component, namely the Axios HTTP client library. The vulnerability stems from a specific “Gadget” attack chain that allows prototype pollution in o…
#vulnerability #rce
2026-05-14
[Dark Reading]
A Nitrogen ransomware attack on Foxconn’s North American facilities is one of 600 hits on manufacturers this year, as gangs increasingly target the sector for its low tolerance for downtime.
#ransomware
2026-05-14
[The Hacker News]
Threat actors have been observed attempting to exploit a recently disclosed security vulnerability in PraisonAI, an open-source multi-agent orchestration framework, within four hours of public disclosure.
The vulnerability in question is CVE-2026-44338 (CVSS score: 7.3), a case of missing authentica…
#vulnerability #apt #authentication
2026-05-14
[The Hacker News]
AI hallucinations are introducing serious security risks into critical infrastructure decision-making by exploiting human trust through highly confident yet incorrect outputs. When an AI model lacks certainty, it doesn’t have a mechanism to recognize that. Instead, it generates the most probable res…
#vulnerability
2026-05-14
[SecurityWeek]
The goal of the guidance, which outlines minimum elements, is to help organizations enhance transparency in AI systems and supply chains.
The post G7 Countries Release AI SBOM Guidance appeared first on SecurityWeek.
#artificial-intelligence #ai #featured #guidance #sbom
2026-05-14
[Schneier on Security]
Last month, Anthropic made a remarkable announcement about its new model, Claude Mythos Preview: it was so good at finding security vulnerabilities in software that the company would not release it to the general public. Instead, it would only be available to a select group of companies to scan and …
#uncategorized #ai #hacking #laws #llm
2026-05-14
[Kaspersky Securelist]
Kaspersky researchers analyze a range of new PebbleDash-based tools used in recent Kimsuky campaigns and reveal their connection to the AppleSeed malware cluster.
#great-research #apt-reports #targeted-attacks #spear-phishing #malware
2026-05-14
[SecurityWeek]
The company’s latest quarterly advisory describes high and medium-severity issues in BIG-IP, BIG-IQ, and NGINX.
The post F5 Patches Over 50 Vulnerabilities appeared first on SecurityWeek.
#vulnerabilities #f5 #patches #vulnerability
2026-05-14
[Malwarebytes Labs]
Some Yahoo Mail users may see repeated Malwarebytes alerts caused by background connections to suspicious third-party domains. Here’s why.
#privacy #product #threat-intel #redirects #yahoo
2026-05-14
[Bleeping Computer]
Dell confirmed that its SupportAssist software is causing blue-screen crashes on some Windows systems following a wave of user reports about random reboots affecting Dell devices since Friday. […]
#software
2026-05-14
[SecurityWeek]
The first exploitation attempts were observed less than four hours after the authentication bypass was publicly disclosed.
The post Hackers Targeted PraisonAI Vulnerability Hours After Disclosure appeared first on SecurityWeek.
#artificial-intelligence #vulnerabilities #ai #exploited #praisonai
2026-05-14
[Graham Cluley]
Pay up, or we’ll pay someone to pay you a visit. Cybercrime gangs are increasingly turning to real-world threats - and even hiring local muscle to deliver the message.
Read more in my article on the Hot for Security blog.
#data-loss #guest-blog #law--order #privacy #ransomware
2026-05-14
[The Hacker News]
An anonymous cybersecurity researcher who disclosed three Microsoft Defender vulnerabilities has returned with two more zero-days involving a BitLocker bypass and a privilege escalation impacting Windows Collaborative Translation Framework (CTFMON).
The security defects have been codenamed YellowKey…
#zero-day #vulnerability #windows
2026-05-14
[Infosecurity Magazine]
Semperis study finds 74% of organizations believe AI will increase attacks on identity infrastructure
2026-05-14
[Malwarebytes Labs]
Experts are urging schools to take down identifiable photos of students, after AI deepfakes have led to sextortion cases at UK schools.
#ai #family-and-parenting #privacy
2026-05-14
[Infosecurity Magazine]
The Information Commissioner’s Office has released new guidance on how to mitigate the risk of AI-powered attacks
2026-05-14
[ESET WeLiveSecurity]
ESET researchers uncovered new activities attributed to FrostyNeighbor, updating its compromise chain to support the group’s continual cyberespionage operations
#eset-research
2026-05-14
[SecurityWeek]
The patch was announced as Broadcom is attending the Pwn2Own hacking competition in Berlin this week.
The post High-Severity Vulnerability Patched in VMware Fusion appeared first on SecurityWeek.
#vulnerabilities #patches #vmware #vulnerability
2026-05-14
[Bleeping Computer]
Linux distros are rolling out patches for a new high-severity kernel privilege escalation vulnerability (known as Fragnasia and tracked as CVE-2026-46300) that allows attackers to run malicious code as root. […]
#security
2026-05-14
[SecurityWeek]
YellowKey is a BitLocker bypass that requires physical access. GreenPlasma enables elevation of privileges to System.
The post Researcher Drops YellowKey, GreenPlasma Windows Zero-Days appeared first on SecurityWeek.
#vulnerabilities #bitlocker #chaotic-eclipse #greenplasma #windows
2026-05-14
[The Hacker News]
Details have emerged about a new variant of the recent Dirty Frag Linux local privilege escalation (LPE) vulnerability that allows local attackers to gain root access, making it the third such bug to be identified in the kernel within a span of two weeks.
Codenamed Fragnesia, the security vulnerabil…
#vulnerability #linux
2026-05-14
[The Hacker News]
Cybersecurity researchers have disclosed multiple security vulnerabilities impacting NGINX Plus and NGINX Open, including a critical flaw that remained undetected for 18 years.
The vulnerability, discovered by depthfirst, is a heap buffer overflow issue impacting ngx_http_rewrite_module (CVE-2026-42…
#vulnerability #rce
2026-05-14
[CrowdStrike]
#cloud--application-security
2026-05-13
[Black Hills InfoSec]
In the ever-evolving world of cybersecurity, staying ahead of the curve is not just a goal—it’s a necessity. As new vulnerabilities emerge, the race to identify and mitigate them begins. But how do we, the guardians of the digital realm, rapidly pinpoint these threats as they become public? Let’s di…
#informational #infosec-101 #matthew-eidelberg #red-team #red-team-tools
2026-05-12
[Google Project Zero]
We recently published an exploit chain for the Google Pixel 9 that demonstrated it was possible to go from a zero-click context to root on Android in just two exploits. The Dolby 0-click vulnerability existed across all of Android, until it was patched in January 2026. While we had an exploit chain …
#vulnerability #patch
2026-05-12
[Zero Day Initiative]
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Siemens Simcenter Femap. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. Th…
#vulnerability #rce
2026-05-12
[Elastic Security Labs]
Elastic Security is the first security vendor to ship an interactive UI in AI tools. Triage alerts, hunt threats, correlate attack chains, and open cases, all from inside your AI conversation.
#security-labs
2026-05-11
[CERT/CC]
Overview
dnsmasq is affected by multiple memory safety and input validation vulnerabilities, including heap buffer overflows, heap corruption, and code execution flaws. Collectively, these vulnerabilities enable attackers to poison cached DNS records, bypass security controls, crash the dnsmasq proc…
#vulnerability #network
2026-05-09
[Elastic Security Labs]
This research analyzes the Linux kernel privilege escalation vulnerabilities Copy Fail and DirtyFrag, which exploit subtle page cache corruption bugs to create reliable paths to root access. Additionally, Elastic Security Labs is releasing detection logic for these vulnerabilities.
#security-labs
2026-05-07
[Cloudflare Security]
When a critical Linux kernel privilege escalation was publicly disclosed, Cloudflare’s security and engineering teams detected, investigated, and mitigated the threat across our global fleet, confirming zero customer impact and no malicious exploitation.
#linux #security #incident-response #kernel #vulnerabilities
2026-05-07
[SentinelOne Labs]
Cloud attack framework skips cryptomining, harvests financial, messaging, and enterprise credentials for fraud, spam, and potential extortion.
#kubernetes #pcpjack #teampcp
2026-05-06
[SentinelOne Labs]
Joe FitzPatrick reveals how consumer imports of networked devices pose a real security risk to small businesses and critical infrastructure alike.
#cn #iot #labscon25
2026-04-30
[Cloudflare Security]
Cloudflare IPsec now has generally available support for post-quantum encryption via hybrid ML-KEM. We’ve confirmed interoperability with Cisco and Fortinet.
#post-quantum #ipsec #cryptography #security #magic-wan
2026-04-23
[Google Security Blog]
Posted by Thomas Brunner, Yu-Han Liu, Moni PandeAt Google, our Threat Intelligence teams are dedicated to staying ahead of real-world adversarial activity, proactively monitoring emerging threats before they can impact users. Right now, Indirect Prompt Injection (IPI) is a top priority for the secur…
#injection
2026-04-10
[Google Security Blog]
Posted by Jiacheng Lu, Software Engineer, Google Pixel Team
Google is continuously advancing the security of Pixel devices. We have been focusing on hardening the cellular baseband modem against exploitation. Recognizing the risks associated within the complex modem firmware, Pixel 9 shipped with m…
#android #android-security #pixel
2026-04-09
[Google Security Blog]
Posted by Ben Ackerman, Chrome team, Daniel Rubery, Chrome team and Guillaume Ehinger, Google Account Security team
Following our April 2024 announcement, Device Bound Session Credentials (DBSC) is now entering public availability for Windows users on Chrome 146, and expanding to macOS in an upco…
#authentication #windows
2026-03-04
[Google Project Zero]
Mutational grammar fuzzing is a fuzzing technique in which the fuzzer uses a predefined grammar that describes the structure of the samples. When a sample gets mutated, the mutations happen in such a way that any resulting samples still adhere to the grammar rules, thus the structure of the samples …
2026-02-25
[Google Project Zero]
In my previous blog post I mentioned the GetProcessHandleFromHwnd API. This was an API I didn’t know existed until I found a publicly disclosed UAC bypass using the Quick Assist UI Access application. This API looked interesting so I thought I should take a closer look. I typically start by reading …
2026-02-05
[PortSwigger Research]
Welcome to the Top 10 Web Hacking Techniques of 2025, the 19th edition of our annual community-powered effort to identify the most innovative must-read web security research published in the last year
2025-12-10
[PortSwigger Research]
TLDR This post shows how to achieve a full authentication bypass in the Ruby and PHP SAML ecosystem by exploiting several parser-level inconsistencies: including attribute pollution, namespace confusi
#vulnerability #authentication
2025-05-07
[NCSC UK]
An NCSC assessment highlighting the impacts on cyber threat from AI developments between now and 2027.
2025-01-28
[NCSC UK]
Research from the NCSC designed to eradicate vulnerability classes and make the top-level mitigations easier to implement.
#vulnerability
2024-01-18
[Assetnote]
#vulnerability #rce #authentication
2023-10-23
[Assetnote]
#vulnerability
2023-10-03
[Assetnote]
#vulnerability #rce