124Articles
9Categories
2026-05-14Date
🚨
Fragnesia (CVE-2026-46300): Frequently asked questions about new Linux Kernel XFRM ESP-in-TCP privilege escalationA new Linux kernel local privilege escalation exploit with a public proof-of-concept targets the same subsystem as Dirty Frag but requires a separate patch. Key Takeaways CVE-2026-46300 (Fragnesia) is the latest high severity local privilege escalation vulnerability in the Linux …
KEV
🚨
U.S. CISA adds a flaw in Cisco Catalyst SD-WAN  to its Known Exploited Vulnerabilities catalogThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a flaw in Cisco Catalyst SD-WAN to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a flaw in Cisco Catalyst SD-WAN, tracked as CVE-2026-20182 …
KEV
🚨
Frequently asked questions about the continued exploitation of Cisco Catalyst SD-WAN vulnerabilities (CVE-2026-20182)Multiple critical authentication bypass vulnerabilities in Cisco Catalyst SD-WAN Controller and Manager are under active exploitation by multiple threat clusters, including CVE-2026-20182, which has been exploited as a zero-day by a sophisticated threat actor. Key Takeaways CVE-2…
KEV
🐛
New Fragnesia Linux Kernel LPE Grants Root Access via Page Cache Corruption
🐛
18-Year-Old NGINX Rewrite Module Flaw Enables Unauthenticated RCE
🐛
Langflow CVE-2026-33017 Exploited to Steal AWS Keys, Deploy NATS Worker
KEV
🐛
MongoDB Security Flaw Enables Arbitrary Code Execution on Vulnerable Systems
🐛
Critical Exim Mailer Flaw Enables Remote Code Execution Attacks
🐛
PraisonAI vulnerability gets scanned within 4 hours of disclosure
🐛
PraisonAI CVE-2026-44338 Auth Bypass Targeted Within Hours of Disclosure
🐛
Windows DNS Client Security Flaw Exposes Systems to Remote Code Execution
🐛
CVE-2026-42945: NGINX Rewrite Heap Overflow Enables Remote DoS & Potential RCE
🐛
Critical WordPress Plugin Flaw Allows Unauthorized Access to Websites
🐛
NGINX Rift: an 18-year-old flaw in the world’s most deployed web server just came to light
🐛
Fragnesia: New Linux kernel LPE bug was spawned by Dirty Frag patch (CVE-2026-46300)
🐛
CVE-2026-42897 Microsoft Exchange Server Spoofing Vulnerability
🐛
CVE-2026-41615 Microsoft Authenticator Information Disclosure Vulnerability
🐛
Broadcom releases VMware Fusion security update for root access bug
🐛
CVE-2026-20182: Critical authentication bypass in Cisco Catalyst SD-WAN Controller (FIXED)
🐛
The Dark Side of Efficiency: When Network Controllers Become "God Mode" for Attackers
KEV
🐛
Ongoing exploitation of Cisco Catalyst SD-WAN vulnerabilities
🐛
Cisco Catalyst SD-WAN Controller Auth Bypass Actively Exploited to Gain Admin Access
KEV
🐛
Linux Kernel bug Fragnesia allows local root access attacks
🐛
CVE-2026-0265: Authentication Bypass in Palo Alto Networks PAN-OS
KEV
🐛
Meet Fragnesia, the third Linux kernel vulnerability in a month
🐛
AI agent finds 18-year-old remote code execution flaw in Nginx
⚠️
Amazon Quick Security Flaw Allowed Restricted Users to Access AI Chat Agents
⚠️
GitLab Security Flaw Allows Cross-Site Scripting and Unauthenticated DoS
⚠️
Hackers Hijack HWMonitor to Sideload Malicious DLL
⚠️
PoC Released for 18-Year-Old NGINX Flaw Allowing Remote Code Execution
⚠️
Packagist Warns: Update Composer Now After GitHub Actions Token Leak
⚠️
New Exim BDAT GnuTLS Vulnerability Enables Code Execution Attacks
⚠️
Gentlemen RaaS Exploits Fortinet and Cisco Edge Devices for Initial Access
⚠️
Abrigo - 711,099 breached accounts
⚠️
What CISOs need to land a board role
⚠️
Deepfake sextortion forces schools to remove student photos from websites
⚠️
My relationship status is “compromised.”
⚠️
CERN’s open source KiCad library gives the world 17,000 circuit board components
⚠️
Over 70% of organizations hit by identity breaches
⚠️
Machine identities outnumber humans 109 to 1
⚠️
Windows Zero-Days Expose BitLocker Bypasses And CTFMON Privilege Escalation
⚠️
Microsoft turns Copilot Studio into an AI agent control center
⚠️
New Malware Framework Enables Screen Control and UAC Bypass
⚠️
Canon MailSuite Security Flaw Allows Attackers to Execute Code Remotely
⚠️
How AI Hallucinations Are Creating Real Security Risks
⚠️
Chinese APT Exploits Microsoft Exchange to Breach Energy Sector Network
⚠️
TeamPCP, BreachForums Launch $1K Supply-Chain Attack Contest
⚠️
FlowerStorm phishing gang adopts virtual-machine obfuscation to evade email defenses
⚠️
Frontier AI models reap rapid discovery of security vulnerabilities
⚠️
ThreatsDay Bulletin: PAN-OS RCE, Mythos cURL Bug, AI Tokenizer Attacks, and 10+ Stories
⚠️
The time of much patching is coming
⚠️
ODNI taps officials to coordinate response to foreign election threats
⚠️
Regional routing for AWS access portals: Implementing custom vanity domains for IAM Identity Center
⚠️
The era of AI-powered attacks is here.
⚠️
Google announces hackers are using AI to create zero days.
⚠️
OpenAI asks macOS users to update after TanStack npm supply chain attack
⚠️
Maximum Severity Cisco SD-WAN Bug Exploited in the Wild
KEV
⚠️
You're not going to patch your way out of this - PSW #926
⚠️
Bring out your dead: How agentic AI for cybersecurity helps you rid your cloud of forgotten, risky assets
⚠️
AI Just Hacked Hardware
📢
The Human Side of Threat Intelligence
📢
Sony's failed attempt to stop piracy.
📢
HYCU aiR detects insider risk and AI activity from backups
📢
Pentagon cyber official calls advanced AI ‘revolutionary warfare’
🔥
Welcoming the Bahamian Government to Have I Been Pwned
🔥
When ransomware gets physical: cybercriminals turn to threats of violence
🔥
FamousSparrow targets Azerbaijani energy sector in multi-wave espionage campaign
🔥
Nitrogen Ransomware claims massive data theft from Foxconn
🔥
BreachForums & TeamPCP Promote Supply Chain Competition as Cybercrime Gets Gamified
🔥
Microsoft Research: AI Can Generate Realistic Command-Line and Process Telemetry
🔥
LATAM Under Siege: Agent Tesla’s 18-Month Credential Theft Campaign Against Chilean Enterprises
🔥
Foxconn Attack Highlights Manufacturing's Cyber Crisis
🔥
Top 5 Surface Web Hacker Forums in 2026
🔥
Sandworm Hackers Shift From IT Breaches to Critical OT Targets
🔥
LABScon25 Replay | Breach Alpha: Trading on Cyber Fallout
🔥
When Nobody Reports the Threat
🔥
Major tech manufacturer Foxconn confirms cyberattack hit North American factories
🔥
West Pharmaceutical starts restoring operations after ransomware attack
🔥
Fighting AI-Assisted Ransomware Threats
🕵️
ISC Stormcast For Thursday, May 14th, 2026 https://isc.sans.edu/podcastdetail/9932, (Thu, May 14th)
🕵️
Lyrie.ai Unveils Open Standard for Agent Security and Joins Anthropic’s Cyber Verification Program
🕵️
Russian official admits VPNs cannot be fully blocked without breaking the internet
🕵️
Texas sues Netflix for profiling children and selling data to advertisers
🕵️
AI cyber capability is speeding past earlier projections
🕵️
Vector embedding security gap exposes enterprise AI pipelines
🕵️
Closing the AI governance gap in your enterprise
🕵️
170 npm Packages Hijacked to Steal GitHub, AWS & Kubernetes Secrets
🕵️
Microsoft’s WinUI agent plugin trims token use by over 70% during development
🕵️
How Dangerous Is Anthropic’s Mythos AI?
🕵️
Kimsuky targets organizations with PebbleDash-based tools
🕵️
Cofense adds AI-powered campaign detection to stop phishing attacks
🕵️
Warning: Netflix Phishing Scams Can Lead to Serious Consequences
🕵️
Ghostwriter Targets Ukrainian Government With Geofenced PDF Phishing, Cobalt Strike
🕵️
A spyware investigator exposed Russian government hackers trying to hijack Signal accounts
🕵️
Mustang Panda Linked to Updated FDMTP Backdoor in Asia-Pacific Espionage Campaign
🕵️
Apple’s iPhone Privacy Feature Expands to More Users Worldwide
🕵️
Jeff Bezos’ Blue Origin May Need Outside Cash to Catch SpaceX
🕵️
LinkedIn Cuts Jobs Despite Revenue Growth as Tech Layoffs Keep Spreading
🕵️
Upcoming Speaking Engagements
🕵️
Phishing Attacks Begin Targeting the 2026 FIFA World Cup
🕵️
More money is going to physical security, but it’s often CISOs that oversee it: EY
🕵️
Microsoft: Russian hackers evolved Kazuar malware into stealthy P2P botnet
🕵️
'FrostyNeighbor' APT Carefully Targets Govt Orgs in Poland, Ukraine
🕵️
Trump’s China Summit Turns Into a Big Tech Power Play
🕵️
Top New Features in Android 17 You’ll Notice This Year
🕵️
Microsoft Retires ‘Copilot Mode’ as Edge Gets Built-In AI Tools
🕵️
Kevin O’Leary’s ‘Wonder Valley’ Data Center Advances as Job Estimates Shift
KEV
🕵️
White House cyber official: identity security matters more than ever in the age of AI
🕵️
SecurityScorecard Snags Driftnet to Level Up Threat Intelligence
🌐
Why Malwarebytes blocks some Yahoo Mail redirects
🌐
Google Launches Android Spyware Forensics Tool for High-Risk Users
🌐
Stealer Backdoor Found in 3 Node-IPC Versions Targeting Developer Secrets
📰
Daily Briefing for 05.14.26
📡
Simple bypass of the link preview function in Outlook Junk folder, (Thu, May 14th)
📡
Most Organizations Now Use AI Agents for Sensitive Security Tasks
📡
ICO Publishes Five-Step Plan to Counter Emerging AI-Powered Attacks
📡
Your iPhone Gets Stolen. Then the Hacking Begins
📡
New Fragnesia Flaw Hands Linux Local Users Root Access
📡
AI Drives Cybersecurity Investments, Widening 'Valley of Death'
📡
Cisco cuts nearly 4,000 jobs to spend more on AI, reports ‘record quarterly revenue’
📡
OpenAI says hackers stole some data after latest code security issue
📡
Automating post-quantum cryptography readiness using AWS Config
📡
Suspected Dream Market kingpin arrested after gold bars sent to his home address
📡
13 Cybersecurity Frameworks for 2026 and How to Choose | Huntress