184Articles
9Categories
2026-05-11Date
🚨
U.S. CISA adds a flaw in BerriAI LiteLLM to its Known Exploited Vulnerabilities catalogThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a flaw in BerriAI LiteLLM to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a flaw in BerriAI LiteLLM, tracked as CVE-2026-42208 (CVSS score …
KEV
πŸ›
CVE-2026-31706 ksmbd: validate num_aces and harden ACE walk in smb_inherit_dacl()
πŸ›
CVE-2026-31723 usb: gadget: f_subset: Fix net_device lifecycle with device_move
πŸ›
CVE-2026-31724 usb: gadget: f_eem: Fix net_device lifecycle with device_move
πŸ›
CVE-2026-43036 net: use skb_header_pointer() for TCPv4 GSO frag_off check
πŸ›
CVE-2026-31707 ksmbd: validate response sizes in ipc_validate_msg()
πŸ›
CVE-2026-43042 mpls: add seqcount to protect the platform_label{,s} pair
πŸ›
CVE-2026-31771 Bluetooth: hci_event: move wake reason storage into validated event handlers
πŸ›
CVE-2026-43052 wifi: mac80211: check tdls flag in ieee80211_tdls_oper
πŸ›
CVE-2026-31709 smb: client: validate the whole DACL before rewriting it in cifsacl
πŸ›
CVE-2026-43010 bpf: Reject sleepable kprobe_multi programs at attach time
πŸ›
CVE-2026-43474 fs: init flags_valid before calling vfs_fileattr_get
πŸ›
CVE-2025-71302 drm/panthor: fix for dma-fence safe access rules
πŸ›
CVE-2026-43309 md raid: fix hang when stopping arrays with metadata through dm-raid
πŸ›
CVE-2026-43320 drm/amd/display: Fix dsc eDP issue
πŸ›
CVE-2026-43300 drm/panel: Fix a possible null-pointer dereference in jdi_panel_dsi_remove()
πŸ›
CVE-2026-43306 bpf: crypto: Use the correct destructor kfunc type
πŸ›
CVE-2026-43443 ASoC: amd: acp-mach-common: Add missing error check for clock acquisition
πŸ›
CVE-2026-43319 spi: spidev: fix lock inversion between spi_lock and buf_lock
πŸ›
CVE-2026-43344 perf/x86/intel/uncore: Fix die ID init and look up bugs
πŸ›
CVE-2026-43305 drm/amd/display: Fix mismatched unlock for DMUB HW lock in HWSS fast path
πŸ›
CVE-2026-43310 media: verisilicon: Avoid G2 bus error while decoding H.264 and HEVC
πŸ›
CVE-2026-43400 drm/amdgpu: add upper bound check on user inputs in signal ioctl
πŸ›
CVE-2026-43292 mm/vmalloc: prevent RCU stalls in kasan_release_vmalloc_node
πŸ›
CVE-2026-43398 drm/amdgpu: add upper bound check on user inputs in wait ioctl
πŸ›
CVE-2026-43311 soc/tegra: pmc: Fix unsafe generic_handle_irq() call
πŸ›
CVE-2026-43421 usb: gadget: f_ncm: Fix net_device lifecycle with device_move
πŸ›
CVE-2026-43308 btrfs: don't BUG() on unexpected delayed ref type in run_one_delayed_ref()
πŸ›
CVE-2026-42256 net-imap: Denial of service via high iteration count for `SCRAM-*` authentication
πŸ›
CVE-2026-42246 net-imap vulnerable to STARTTLS stripping via invalid response timing
πŸ›
CVE-2026-45186
πŸ›
CVE-2026-7261 SoapServer session-persisted object use-after-free via SOAP header fault
πŸ›
CVE-2026-7568 Signed integer overflow in metaphone()
πŸ›
CVE-2026-43053 xfs: close crash window in attr dabtree inactivation
πŸ›
CVE-2026-43048 HID: core: Mitigate potential OOB by removing bogus memset()
πŸ›
CVE-2026-31777 ALSA: ctxfi: Check the error for index mapping
πŸ›
CVE-2026-31722 usb: gadget: f_rndis: Fix net_device lifecycle with device_move
πŸ›
CVE-2026-31725 usb: gadget: f_ecm: Fix net_device lifecycle with device_move
πŸ›
CVE-2026-43049 HID: logitech-hidpp: Prevent use-after-free on force feedback initialisation failure
πŸ›
CVE-2026-31712 ksmbd: require minimum ACE size in smb_check_perm_dacl()
πŸ›
CVE-2026-43019 Bluetooth: hci_conn: fix potential UAF in set_cig_params_sync
πŸ›
CVE-2026-31729 usb: typec: ucsi: validate connector number in ucsi_notify_common()
πŸ›
CVE-2026-43009 bpf: Fix incorrect pruning due to atomic fetch precision tracking
πŸ›
CVE-2026-31715 f2fs: fix UAF caused by decrementing sbi->nr_pages[] in f2fs_write_end_io()
πŸ›
CVE-2026-43338 btrfs: reserve enough transaction items for qgroup ioctls
πŸ›
CVE-2026-43318 drm/amdgpu: fix sync handling in amdgpu_dma_buf_move_notify
πŸ›
CVE-2026-43416 powerpc, perf: Check that current->mm is alive before getting user callchain
πŸ›
CVE-2026-43352 i3c: mipi-i3c-hci: Correct RING_CTRL_ABORT handling in DMA dequeue
πŸ›
CVE-2026-43284 xfrm: esp: avoid in-place decrypt on shared skb frags
πŸ›
CVE-2025-71299 spi: cadence-quadspi: Parse DT for flashes with the rest of the DT parsing
πŸ›
CVE-2026-43317 most: core: fix leak on early registration failure
πŸ›
CVE-2026-43321 bpf: Properly mark live registers for indirect jumps
πŸ›
CVE-2026-43456 bonding: fix type confusion in bond_setup_by_slave()
πŸ›
CVE-2026-43298 drm/amdgpu: Skip vcn poison irq release on VF
πŸ›
CVE-2026-43299 btrfs: do not ASSERT() when the fs flips RO inside btrfs_repair_io_failure()
πŸ›
CVE-2026-43294 drm: renesas: rz-du: mipi_dsi: fix kernel panic when rebooting for some panels
πŸ›
CVE-2026-43353 i3c: mipi-i3c-hci: Fix race in DMA ring dequeue
πŸ›
CVE-2026-42257 net-imap: Command Injection via "raw" arguments to multiple commands
πŸ›
CVE-2026-42258 net-imap: Command Injection via unvalidated Symbol inputs
πŸ›
CVE-2026-7258 Out-of-bounds read in urldecode() on NetBSD
πŸ›
CVE-2026-6722 Use-After-Free in SOAP using Apache map
πŸ›
CVE-2026-6735 XSS within PHP-FPM status endpoint
πŸ›
CVE-2026-7262 NULL pointer dereference in SOAP apache:Map decoder with missing <value>
πŸ›
CVE-2025-14179 SQL injection in pdo_firebird via NUL bytes in quoted strings
πŸ›
CVE-2026-7259 Null pointer dereference in php_mb_check_encoding() via mb_ereg_search_init()
πŸ›
CVE-2025-21723 scsi: mpi3mr: Fix possible crash when setting up bsg fails
πŸ›
CVE-2025-21714 RDMA/mlx5: Fix implicit ODP use after free
πŸ›
PoC Exploit Released for Android Zero-Click Flaw Enabling Remote Shell Access
πŸ›
1,800+ MCP servers exposed without authentication: How zero trust can secure the AI agent revolution
πŸ›
The impact of Mythos and Florida Man, confidence gaps, phishing, & AI adoption - Erich... - ESW #458
πŸ›
cPanel and WHM Servers Targeted in Attacks Exploiting CVE-2026-41940
πŸ›
New β€˜Dirty Frag’ exploit targets Linux kernel for root access
KEV
πŸ›
Linux developers weigh emergency β€œkillswitch” for vulnerable kernel functions
πŸ›
VU#937808: Casdoor contains Arbitrary File Write vulnerability
πŸ›
VU#471747: dnsmasq contains several vulnerabilities, including attacker DNS redirect, privilege escalation, and heap manipulation
πŸ›
cPanel CVE-2026-41940 Under Active Exploitation to Deploy Filemanager Backdoor
⚠️
Canvas Breach Exposes 275M Accounts | AI Targets Water Systems | GM OnStar Settlement
⚠️
New cPanel and WHM Vulnerabilities Expose Servers to Code Execution and DoS Attacks
⚠️
JDownloader Hack Spreads New Python RAT
⚠️
Security teams are turning to AI to survive alert overload
⚠️
macOS Malware Abuses Google Ads and Claude Shared Chats to Deliver Payloads
⚠️
ODINI Malware Uses CPU Magnetic Signals to Exfiltrate Data from Air-Gapped Systems
⚠️
Rustinel: Open-source endpoint detection for Windows and Linux
⚠️
Review: Foundations of Cybersecurity, 2nd edition
⚠️
Windows CreateFileW API Flaw Could Let Attackers Lock SMB Files at Scale
⚠️
Crimenetwork Bust Reveals 22,000 Members and Over 100 Illicit Vendors
⚠️
ShinyHunters Exploits Canvas LMS Free Teacher Accounts in New Breach
⚠️
Mythos finds a curl vulnerability
⚠️
8 guiding principles for reskilling the SOC for agentic AI
⚠️
The scam economy has found its AI upgrade
⚠️
Microsoft 365 Copilot Flaws Could Let Attackers Access Sensitive Data
⚠️
AI security is repeating endpoint security’s biggest mistake
⚠️
Instructure confirms Canvas user data exposed in cyberattack
⚠️
Your Purple Team Isn't Purple β€” It's Just Red and Blue in the Same Room
⚠️
PHP SOAP Extension Flaw Could Let Attackers Execute Code Remotely
⚠️
Malicious Hugging Face model masquerading as OpenAI release hits 244K downloads
⚠️
Hackers Observed Using AI to Develop Zero-Day for the First Time
⚠️
Hackers Use AI for Exploit Development, Attack Automation
⚠️
Police take down relaunched criminal marketplace with 22,000 users, €3.6 million in revenue
⚠️
fsnotify Maintainer Access Change Sparks Supply Chain Security Concerns
⚠️
Lyrie.ai Joins First Batch of Anthropic’s Cyber Verification Program
⚠️
Google discovers weaponized zero-day exploits created with AI
⚠️
GTIG AI Threat Tracker: Adversaries Leverage AI for Vulnerability Exploitation, Augmented Operations, and Initial Access
⚠️
Google spotted an AI-developed zero-day before attackers could use it
⚠️
Google researchers uncover criminal zero-day exploit likely built with AI
⚠️
Why we use CAPTCHAs, (Mon, May 11th)
⚠️
AI used to develop working zero-day exploit, researchers warn
⚠️
Google warns artificial intelligence is accelerating cyberattacks and zero-day exploits
⚠️
'Dirty Frag' Exploit Poised to Blow Up on Enterprise Linux Distros
⚠️
Final Countdown: Last Chance to Join the Rapid7 Global Cybersecurity Summit
⚠️
Hackers Used AI to Develop First Known Zero-Day 2FA Bypass for Mass Exploitation
⚠️
IAM for MSSPs: The Hidden Risk of Blind Trust - Dustin Sachs - CSP #224
⚠️
Red Hat extends open source technology into space
⚠️
Identity security firm SailPoint discloses GitHub repository breach
⚠️
FCC Robocall Crackdown Raises Privacy Concerns Over Mandatory ID Checks
⚠️
AI Isn’t Replacing Cybersecurity
⚠️
California hits GM with record $12.75M fine for selling driver location data
⚠️
Google says cybercriminals used AI to develop zero-day exploit
⚠️
Foreign routers get a longer lifeline.
⚠️
Inside AD CS Escalation: Unpacking Advanced Misuse Techniques and Tools
πŸ“‹
US: FCC Relaxes Foreign-Made Router Ban to Allow for Security Updates
πŸ“‹
FCC pushes ban on security updates for foreign-made routers, drones to 2029
πŸ“’
Police Shut Relaunched Crimenetwork Dark Web Marketplace
πŸ“’
Dirty Frag: Linux kernel hit by second major security flaw in two weeks
πŸ“’
Alation AI Governance creates a system of record for AI oversight
πŸ“’
When Ransomware Negotiators Flip Sides
πŸ”₯
Welcoming the Costa Rican Government to Have I Been Pwned
πŸ”₯
Weaponized JPEG file Drops Trojanized ScreenConnect Malware
πŸ”₯
Zara Data Breach Impacts Nearly 200,000 Customers
πŸ”₯
The State of Ransomware – Q1 2026
πŸ”₯
ShinyHunters Escalates Canvas Extortion with School by School Ransom Campaign
πŸ”₯
UK water company allowed hackers to lurk undetected for nearly two years, regulator finds
πŸ”₯
11th May – Threat Intelligence Report
πŸ”₯
Cyber Espionage Group Targets Aviation Firms to Steal Map Data
πŸ”₯
A 2nd Canvas data breach causes major disruptions for schools, colleges
πŸ”₯
Poor security left hackers inside water company network for nearly two years
πŸ”₯
Zimperium Mobile App Response Agent helps security teams counter mobile attacks
πŸ”₯
Welcoming the Bangladesh Government to Have I Been Pwned
πŸ•΅οΈ
ISC Stormcast For Monday, May 11th, 2026 https://isc.sans.edu/podcastdetail/9926, (Mon, May 11th)
πŸ•΅οΈ
Top 10 Best Secure Code Review Services For Developers in 2026
πŸ•΅οΈ
Top 10 Best DevSecOps Companies For Secure SDLC 2026
πŸ•΅οΈ
Checkmarx Jenkins Plugin Backdoored in New TeamPCP Supply Chain Attack
πŸ•΅οΈ
OpenClaw Malware Targets Crypto Wallets and Bitwarden Credentials
πŸ•΅οΈ
The missing cybersecurity leader in small business
πŸ•΅οΈ
Fake Claude Campaign Uses PlugX-Style DLL Sideloading Chain
πŸ•΅οΈ
Trending Hugging Face Repo With 200K Downloads Spreads Windows Malware
πŸ•΅οΈ
Sandboxie Escape Flaw Could Let Attackers Gain SYSTEM-Level Privileges
πŸ•΅οΈ
Instagram messaging encryption removed, and privacy advocates are pushing back
πŸ•΅οΈ
The questionnaire-based TPRM model is broken, and TrustCloud has a fix
πŸ•΅οΈ
LLMs and Text-in-Text Steganography
πŸ•΅οΈ
New cybersecurity industry alliance aims to lead US critical infrastructure protection
πŸ•΅οΈ
Python Infostealer Hides in GitHub Releases to Bypass Detection
πŸ•΅οΈ
SailPoint Agentic Fabric expands identity governance to autonomous AI agents
πŸ•΅οΈ
Google’s new reCAPTCHA system restricts access to the open web
πŸ•΅οΈ
Lyrie.ai Joins First Batch of Anthropic’s Cyber Verification Program
πŸ•΅οΈ
Apple, Intel Reportedly Near Chip Deal That Could Reduce TSMC Reliance
πŸ•΅οΈ
Microsoft’s Voluntary Retirement Offer: New Details Reveal Who Qualifies
πŸ•΅οΈ
Your Team of 10 Gets This AI Project Management Platform for Just $99
πŸ•΅οΈ
SS&C Intralinks FundCentre AI vs. Juniper Square: Which platform better supports modern private markets fund managers?
πŸ•΅οΈ
macOS 27 May Get a New Look: Here’s What Apple Could Change
πŸ•΅οΈ
Entries now open for the 2026 CSO30 Australia Awards
πŸ•΅οΈ
News Alert: Lyrie.ai joins Anthropic verification program, unveils protocol for securing AI agents
πŸ•΅οΈ
TikTok Launches Β£3.99 Ad-Free Plan for UK Users
πŸ•΅οΈ
Mac Users Warned Over Fake Claude Install Instructions
πŸ•΅οΈ
1.8 Billion Gmail Users May Want to Check This AI Privacy Setting
πŸ•΅οΈ
FCC moves to impose β€œKnow Your Customer” rules for VoIP providers
πŸ•΅οΈ
iOS 26.5 is out, bringing encrypted RCS messaging to iPhone and Android users
πŸ•΅οΈ
Pressure mounts on Canvas as data leak extortion deadline looms
🌐
A week in security (May 4 &#8211; May 10)
🌐
⚑ Weekly Recap: Linux Rootkit, macOS Crypto Stealer, WebSocket Skimmers and More
🌐
TrickMo Variant Routes Android Trojan Traffic Through TON
🌐
FCC eases restrictions on foreign-made routers.
πŸ“‘
Instagram removed end-to-end encryption for DMs. What should users do?
πŸ“‘
Fake OpenAI Privacy Filter Repo Hits #1 on Hugging Face, Draws 244K Downloads
πŸ“‘
Identity is the new perimeter as rapid NHI proliferation threatens visibility and control
πŸ“‘
Crimenetwork returns after takedown, dismantled again by German authorities
πŸ“‘
Yarbo responds to robot flaws that could mow down their owners
πŸ“‘
Fake Claude Code Page Pushes PowerShell Stealer at Devs
πŸ“‘
Rushed Patches Follow Broken Embargo on New Linux Kernel Vulnerabilities
πŸ“‘
Complimentary virtual training: Get hands-on with AWS Security Services
πŸ“‘
Texas sues Netflix over alleged data practices that create β€˜surveillance machinery’ without user consent
πŸ“‘
Apple Patches Everything, (Mon, May 11th)
πŸ“‘
FCC Softens Ban on Foreign-Made Routers
πŸ“‘
Tech Can't Stop These Threats β€” Your People Can