127Articles
10Categories
2026-05-13Date
🐛
May Patch Tuesday roundup: Critical holes in Windows Netlogon, DNS, and SAP S/4HANA
🐛
Patch Tuesday - May 2026
🐛
CVE-2026-43894 jq: Wild stack write via signed-integer overflow in decNumber D2U() macro
🐛
CVE-2026-43896 jq: Stack Overflow in Recursive Object Merge
🐛
CVE-2026-43895 jq: Embedded NUL in jq import paths causes local redaction-policy bypass and preserves sensitive fields in published artifacts
🐛
CVE-2026-40612 jq: Stack overflow via unbounded recursion in jv_contains
🐛
CVE-2026-41256 jq: Embedded NUL truncates top-level jq programs loaded with -f
🐛
CVE-2026-31767 drm/i915/dsi: Don't do DSC horizontal timing adjustments in command mode
🐛
CVE-2026-43249 9p/xen: protect xen_9pfs_front_free against concurrent calls
🐛
CVE-2026-8177 XML::LibXML versions through 2.0210 for Perl read out-of-bounds heap memory when parsing XML node names containing truncated UTF-8 byte sequences
🐛
CVE-2026-6210 Type confusion and heap-buffer-overflow in Qt SVG marker handling causing application crash
🐛
CVE-2026-41257 jq: Signed-int overflow in `stack_reallocate` (jq VM stack)
🐛
Critical Fortinet vulnerabilities fixed in FortiSandbox and FortiAuthenticator
🐛
Microsoft’s agentic security system found four critical Windows RCE flaws
🐛
Microsoft’s new AI system finds 16 Windows flaws, including four critical RCEs
🐛
Quest KACE SMA flaw CVE-2025-32975: when one unpatched tool opens the door to 60 organizations
🐛
When IT Support Calls: Dissecting a ModeloRAT Campaign from Teams to Domain Compromise
🐛
Fortinet fixes two critical RCE flaws in FortiAuthenticator and FortiSandbox
KEV
⚠️
Canvas Breach 'Deal' With ShinyHunters, AI Zero-Day Warning, Checkmarx Hit Again
⚠️
Researchers open-source a Wi-Fi cyber range for security training
⚠️
Risky Business #837 -- GitHub Actions footgun claims TanStack
⚠️
Sandyaa: Open-source autonomous security bug hunter
⚠️
ClickFix Evolves Using Decade-Old Open-Source Python SOCKS5 Proxy
⚠️
2026 CSO Award winners showcase business-enabling cyber innovation
KEV
⚠️
Google entdeckt erstmals KI-basierten Zero-Day-Exploit
⚠️
NetSPI AI-powered Continuous Pentesting identifies high-impact vulnerabilities
⚠️
Report: 4 in 10 UK Businesses Were Breached by Phishing Last Year
⚠️
CISA’s AI SBOM guidance pushes software supply-chain oversight into new territory
⚠️
Breaking things to keep them safe with Philippe Laulheret
⚠️
ClickFix finds a backup plan in PySoxy proxy chains
⚠️
May 2026 Patch Tuesday: no zero-days but plenty to fix
⚠️
KDE gets over €1 million investment to strengthen security and core infrastructure
⚠️
May 2026 Patch Tuesday: 137 Vulnerabilities, No Zero-Days
KEV
⚠️
Most Remediation Programs Never Confirm the Fix Actually Worked
⚠️
Microsoft Patches 138 Vulnerabilities, Including DNS and Netlogon RCE Flaws
⚠️
Palo Alto bets on identity security for autonomous AI with Idira launch
⚠️
Securing data centers in the agentic AI era
⚠️
Microsoft on pace to break annual vulnerability record as AI-driven patch wave takes hold
⚠️
Microsoft's MDASH AI System Finds 16 Windows Flaws Fixed in Patch Tuesday
⚠️
Azerbaijani Energy Firm Hit by Repeated Microsoft Exchange Exploitation
⚠️
What happens when China’s AI catches up to Mythos?
⚠️
How to Identify and Exploit New Vulnerabilities
⚠️
Rapid7 Partner Academy: Driving Impact with Gold Stevie Award-Winning Partner Services Certifications
⚠️
Microsoft Teams Vulnerability Allows Hackers to Perform Spoofing Attacks
⚠️
Patch Tuesday notes: Microsoft patches over a hundred flaws, none of which are zero-days.
⚠️
Viral ‘RuView’ GitHub project uses Wi-Fi to track movement through walls
⚠️
Microsoft’s Patch Tuesday Update Targets 120 Security Flaws
⚠️
Exaforce raises $125 million in Series B funding.
⚠️
Dark Reading Celebrates 20 Years as a Leading Authority on Cybersecurity, Highlighting the People, Events, Ideas, and Technologies Shaping the Modern Risk Landscape
⚠️
Tables Turn on 'The Gentlemen' RaaS Gang With Data Leak
⚠️
Fired employee sought AI help to hide deletion of hosting firm’s customer data
📋
Microsoft Fixes 17 Critical Flaws in May Patch Tuesday
📋
Microsoft Releases Cumulative Update for Windows 11, Version 25H2 and 24H2
📋
Google Launches New Android Security Features to Fight Scams, Theft
📋
Microsoft Patch Tuesday for May 2026 fix 138 bugs, some of them are alarming
📋
Every layer needs a patch now.
📢
Versa CSPM brings continuous visibility to cloud risk and compliance exposure
📢
Apricorn hardens ASK3 encrypted USB drive for extreme conditions
📢
Signal responds to phishing attacks with new in-app security warnings
📢
Navigating the Cybersecurity Landscape in India Empowering Human and AI Agents
📢
PCI PIN and P2PE compliance packages for AWS Payment Cryptography are now available
📢
Introducing the updated AWS User Guide to Governance, Risk, and Compliance for Responsible AI Adoption
📢
Checkbox Assessments Aren't Fit to Measure to Risk
🔥
GemStuffer Abuses 150+ RubyGems to Exfiltrate Scraped U.K. Council Portal Data
🔥
Ransomware Gangs Use BYOVD and EDR Killers to Disable Security Tools
🔥
Infostealer Malware Fuels Corporate Breaches From Personal Devices
🔥
Q1 2026 Ransomware Attacks Hits 2,122 Orgs Amid Fewer, More Impactful Groups
🔥
Canada Life - 237,810 breached accounts
🔥
Optimize Legal Operations as the CISO Role Changes to Address Skills Gaps and AI - BSW #447
🔥
New SOC-Ready Reporting for Faster Triage, Escalation, and Incident Response with ANY.RUN
🔥
Instructure settles with hackers following massive student data theft
🔥
Ransomware: Over Half of CISOs Would Consider Paying Ransom to Hackers
🔥
Canvas owner reaches ‘agreement’ with threat actors after data breach
🔥
Thus Spoke…The Gentlemen
🔥
Tuskira’s Kairo exposes hidden AI-driven breach paths
🔥
US lawmakers demand answers from Instructure after Canvas data breaches
🔥
The Real Work Starts After Breach
🔥
Canvas Owner Reaches Agreement With Cybercriminals After Ransomware Attack
🔥
Ransomware hackers claim breach at Foxconn, a major electronics manufacturer for Apple, Google, and Nvidia
🔥
Hackers Claim 11M Files Stolen From Foxconn, Supplier to Apple and Nvidia
🔥
Canvas Breach Hackers Reach Deal After Claiming 275M Records Stolen
🔥
Google Enhances Android Mobile Security with New AI-powered Protections
🔥
Foxconn confirms cyberattack affecting some North American facilities
🔥
Student Messages Were the Real Target
🔥
OpenLoop Health confirms January 2026 Data breach affecting 716,000
🔥
Smashing Security podcast #467: How ShinyHunters hacked the world’s biggest universities
🕵️
ISC Stormcast For Wednesday, May 13th, 2026 https://isc.sans.edu/podcastdetail/9930, (Wed, May 13th)
🕵️
Android pushes new scam, theft, and AI protections in 2026 update wave
🕵️
The hidden risk of non-human identities in AI adoption
🕵️
Fake FinalShell and Xshell Sites Push Kong RAT Malware
🕵️
Proton Pass rated “well above par” in independent security audit
🕵️
OpenAI’s GPT-5.5 is as Good as Mythos at Finding Security Vulnerabilities
🕵️
LW ROUNDTABLE: Microsoft Edge normalizes credential exposure — security pros push back
🕵️
Android adds ‘Intrusion Logging’ system to detect spyware attacks
🕵️
AI Agents Generate Custom Hacking Tools on the Fly
🕵️
China's 'FamousSparrow' APT Nests in South Caucasus Energy Firm
🕵️
The Rise of Cyber Threats and AI in the Philippines: A New Era Beyond Legacy Security
🕵️
Daybreak is OpenAI’s answer to the AI arms race in cybersecurity
🕵️
OpenAI launches Daybreak to combat cyber threats
🕵️
WhatsApp adds Incognito Chat for private Meta AI conversations
🕵️
Weaponized AI: The new frontier of fraud and identity spoofing
🕵️
Google Introduces Googlebook, a Gemini-First Laptop Platform
🕵️
TIOBE Index for May 2026: R Ascends as Statistical Tools Consolidate
🕵️
DOJ releases legal rationale for nationwide voter data collection
🕵️
WhatsApp launches “Incognito Chat” for private AI conversations
🕵️
AI Won’t Invent the Future
🕵️
Attackers Weaponize RubyGems for Data Dead Drops
🕵️
Researchers say AI just broke every benchmark for autonomous cyber capability
🕵️
Closed briefing sets stage for House hearing on Anthropic’s Mythos and cyber risks
🌐
Android Adds Intrusion Logging for Sophisticated Spyware Forensics
🌐
Global Cyber Agencies Issue New SBOMs for AI Guidance to Tackle AI Supply Chain Risks
🌐
This is what some the world’s largest banks of malware look like stacked as hard drives
📰
[Webinar] Why Your AppSec Tools Miss the "Lethal Path" (and How to Fix It)
📰
UK moves to shield security researchers in cybercrime law overhaul
🎙️
Cyber Creator Tyler Ramsbey Shares How to Grow an Audience & Community in Cyber
📡
Weekly Threat Bulletin – May 13th, 2026
📡
Proxying the Unproxyable? Sending EXE traffic to a Proxy, (Wed, May 13th)
📡
[GUEST DIARY] Tearing apart website fraud to see how it works., (Wed, May 13th)
📡
UK Cybersecurity Market Expands to £14.7bn with Strong Growth in AI Security Firms
📡
Dark Web Profile: Keymous+
📡
Texas sued Netflix over claims it secretly collected and sold users’ data
📡
Avada Builder Flaws Expose One Million WordPress Sites
📡
WhatsApp Adds Meta AI Chats That Are Built to Be Fully Private
📡
European Commission head pushes creation of new law delaying teens’ social media access
📡
Alleged Dream Market admin arrested in Germany after US indictment
📡
DHS Plans Experiment Running ‘Reconnaissance’ Drones Along the US-Canada Border
📡
Detecting and preventing crypto mining in your AWS environment