106Articles
9Categories
2026-05-18Date
🐛
Experts warn of active exploitation of critical NGINX flaw CVE-2026-42945
KEV
🐛
Critical Marimo RCE Flaw Could Let Attackers Execute Malicious Code Remotely
🐛
Chaotic Eclipse discloses MiniPlasma zero-day, suggesting a missing or undone 2020 Windows security fix
🐛
VU#777338: SGLang contains two remote code execution and one path traversal vulnerability
KEV
🐛
Ivanti, Fortinet, SAP, VMware, n8n Patch RCE, SQL Injection, Privilege Escalation Flaws
🐛
Critical NGINX Vulnerability Lets Hackers Launch Remote Code Execution Attacks
KEV
🐛
Gamaredon Deploys GammaDrop, GammaLoad in Phishing Campaigns
🐛
‘Patched’ Windows bug resurfaces 6 years later as working SYSTEM-level exploit
🐛
Attackers are exploiting critical NGINX vulnerability (CVE-2026-42945)
🐛
Microsoft Exchange Zero-Day Under Attack, No Patch Available
⚠️
The Boring Stuff is Dangerous Now
⚠️
When ransomware hits, confidence doesn’t restore endpoints
⚠️
Claude Code Vulnerability Allows Attackers to Run Commands Through Crafted Deeplinks
⚠️
Former CISA nominee Sean Plankey named US CEO of defense startup
⚠️
Crafted JPEGs Could Trigger PHP Memory Bugs for Exploitation
⚠️
Researchers Build First Public Apple M5 macOS Kernel Exploit with Mythos Preview
⚠️
Malicious npm Packages Steal SSH Keys, Cloud Credentials, and Crypto Wallets
⚠️
Lyrie: Open-source autonomous pentesting agent
⚠️
AI shrinks vulnerability exploitation window to hours
⚠️
Critical FunnelKit Vulnerability Puts 40,000+ WooCommerce Sites at Risk
⚠️
n8n Security Flaws Could Let Attackers Achieve Remote Code Execution
⚠️
201 arrested in INTERPOL disruption of phishing and fraud networks
⚠️
Why the best security investment a board can make in 2026 isn’t another tool
⚠️
AI coding is fueling a secrets-sprawl crisis few CISOs are containing
⚠️
AI Has a data problem, cascading breaches, and the weekly news - Dimitri Sirota - ESW #459
⚠️
Security Researchers Find 47 Zero-Days at Pwn2Own Berlin
⚠️
Attackers accessed, downloaded code from Grafana Labs’ GitHub
⚠️
MiniPlasma Windows 0-Day Enables SYSTEM Privilege Escalation on Fully Patched Systems
⚠️
Four Malicious npm Packages Deliver Infostealers and Phantom Bot DDoS Malware
⚠️
Zero-Day Exploit Against Windows BitLocker
⚠️
Gremlin Stealer Hides Payloads in .NET Resources to Evade Detection
⚠️
New image-based prompt injection attack targets multimodal AI models
⚠️
Open source tool maker Grafana Labs says hackers stole its code, refuses to pay ransom
⚠️
AI Security Shifts To Data Control
⚠️
ShinyHunters hack 7-Eleven: franchisee data and Salesforce records exposed
⚠️
⚡ Weekly Recap: Exchange 0-Day, npm Worm, Fake AI Repo, Cisco Exploit and More
⚠️
Researchers craft a kernel exploit on Apple's M5 chips, with help from Mythos.
⚠️
18th May – Threat Intelligence Report
⚠️
MY TAKE: AI agents force a rethink of enterprise service lines as vendors move up the tech tack
⚠️
AI cyberattackers are getting better faster
⚠️
Microsoft: Edge 148 will stop loading cleartext passwords in memory
⚠️
AI is drowning software maintainers in junk security reports
⚠️
Game over for 74 suspected scammers after Dutch cops plastered their faces on billboards
⚠️
AI Ends Productivity Guesswork
⚠️
Grafana confirms GitHub token breach cybercrime group claims the attack
⚠️
Microsoft May security patch fails for some due to boot partition size glitch
⚠️
The M5 just met its memory problem.
⚠️
AI might cut false positives, but it won’t stop the slop
⚠️
Shai-Hulud Worm Clones Spread After Code Release
⚠️
Multiple Vulnerabilities in NGINX Could Allow for Remote Code Execution
📢
Can Laws Stop Deepfakes? South Korea Aims to Find Out
📢
Microsoft Acknowledges Windows 11 Update Failure Linked to Error 0x800f0922
📢
NCSC Publishes Guidance on Securing Agentic AI Use
📢
CISA Admin Leaked AWS GovCloud Keys on Github
🔥
Weekly Update 504
🔥
Grafana Labs Confirms Security Incident Involving GitHub Codebase Access
🔥
Hackers Abuse Cloudflare Storage to Exfiltrate Network Files
🔥
Paper Werewolf APT Spreads EchoGather RAT via Fake Adobe Installer
🔥
The Canvas breach proved that prevention is no longer enough
🔥
NYC Health and Hospitals says hackers stole medical data and fingerprints during breach affecting at least 1.8 million people
🔥
Fuel Tank Breaches Expand Scope of Iran's Cyber Offensive
🔥
Grafana refuses to pay ransom after codebase theft
🔥
More than 200 arrested in cyber raids aimed at Middle East scam networks
🔥
Addi - 34,532,941 breached accounts
🕵️
Product showcase: McAfee + ChatGPT integration turns doubt into a scam check
🕵️
Linux Torvalds Warns AI Bug Report Spam Is Disrupting Linux Security Discussions
🕵️
1 Million WordPress Websites Exposed by Avada Builder Security Vulnerabilities
🕵️
The AI backdoor your security stack is not built to see
🕵️
Fast16 Malware Sabotages Nuclear Test Simulations by Altering Data
🕵️
Hackers Hide PureLogs Infostealer in PawsRunner Loader
🕵️
OtterCookie Malware Steals Dev Secrets, SSH Keys, Cloud Credentials, and Tokens
🕵️
ANY.RUN Turns 10: Special Offers for Stronger Security Operations
🕵️
Signal begins testing automatic key verification for encrypted chats
🕵️
How a government contest launched a revolution in AI-based bug hunting
🕵️
SmartBear expands ReadyAPI with AI-powered API testing capabilities
🕵️
What Is an Al Agent in Cybersecurity?
🕵️
Grafana Labs says hacker gained access to codebase through leaked token
🕵️
7 Hidden iPhone Features That Actually Make a Difference
🕵️
Fitbit Bug Leaves Pixel Watch Users Missing Sleep Data Again
🕵️
Windows 11 Start Menu, Taskbar Are Getting More Customization
🕵️
Mozilla calls on UK to exclude VPNs from age verification rules
🕵️
Apple’s Siri Revamp May Add Auto-Deleting Chats
🕵️
Banned Nvidia AI Chips Keep Reaching China Despite US Crackdown
🕵️
Apple’s Fall Lineup Could Include Foldable iPhone, New Macs
🕵️
Interpol leads cybercrime crackdown across 13 countries in Middle East, North Africa
🕵️
Poland urges officials to ditch Signal for state-run messaging apps
🕵️
TeamPCP Supply Chain Campaign: Activity Through 2026-05-17, (Mon, May 18th)
🕵️
FTC: Americans Lost $2.1 Billion to Social Media Scams Last Year
🌐
A week in security (May 11 – May 17)
🌐
Pre-Stuxnet Fast16 Malware Tampered with Nuclear Weapons Simulations
🌐
Developer Workstations Are Now Part of the Software Supply Chain
🌐
IT threat evolution in Q1 2026. Mobile statistics
🌐
IT threat evolution in Q1 2026. Non-mobile statistics
📰
N2K CyberWire's T-Minus returns with focus on the critical intersection of space and cybersecurity
🎙️
AI is distorting the Holocaust (Lock and Code S07E10)
📡
Bank of England, FCA and Treasury Raise Alarm Over Frontier AI
📡
An ICE Firearms Trainer Was Involved in At Least 4 Deadly Shootings
📡
Microsoft is changing Edge’s plaintext password behavior
📡
How to Reduce Phishing Exposure Before It Turns into Business Disruption
📡
Interpol Launches Sweeping Cybercrime Crackdown in MENA Region
📡
The Infosecurity Europe Cyber Startup Competition: Meet the Finalists
📡
Public Amazon bucket leaks sensitive guest data from Japanese hotel platform Tabiq
📡
B1ack’s Stash Releases 4.6 Million Stolen Credit Cards for Free
📡
Experts warn of privacy risks as AI firms looks to connect to financial accounts
📡
INTERPOL Operation Ramz Disrupts MENA Cybercrime Networks with 201 Arrests
📡
'Claw Chain' Vulnerabilities Threaten OpenClaw Deployments