🚨 CISA KEV 97[−]
23 Jul KEVMicrosoft’s 3-day patching directive comes with added operational riskMicrosoft 365 Director Jeremy Chapman this month took to video to tell Windows admins that the days of delaying security patches are over. Complex enterprise systems and historic incidents involving patch problems have caused many admins to hold fire on immediately applying secur…CSOONLINE.COM
23 Jul KEVCVE-2026-16232: Critical Check Point SmartConsole Authentication Bypass Exploited in the WildOverview On July 22, 2026, Check Point published a security advisory for multiple vulnerabilities affecting Security Management, Multi-Domain Management, and firewall products. The most urgent of these is CVE-2026-16232 , an authentication bypass in the SmartConsole login process…RAPID7.COM
23 Jul KEVU.S. CISA adds Microsoft SharePoint and Check Point SmartConsole flaws to its Known Exploited Vulnerabilities catalogU.S. Cybersecurity and Infrastructure Security Agency (CISA) adds SharePoint and Check Point flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added DD-WRT, Langflow, and WordPress flaws to its Known Exploi…SECURITYAFFAIRS.COM
22 Jul KEVU.S. CISA adds DD-WRT, Langflow and WordPress flaws to its Known Exploited Vulnerabilities catalogU.S. Cybersecurity and Infrastructure Security Agency (CISA) adds DD-WRT, Langflow, and WordPress flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added DD-WRT, Langflow, and WordPress flaws to its Known Exploi…SECURITYAFFAIRS.COM
20 Jul KEVwp2shell (CVE-2026-63030, CVE-2026-60137): Frequently asked questions about remote code execution chain in WordPress CoreAn unauthenticated attacker can chain two WordPress Core vulnerabilities, CVE-2026-63030 and CVE-2026-60137, to achieve remote code execution against affected WordPress installations. Multiple security firms have confirmed active in-the-wild exploitation within days of public dis…TENABLE.COM
18 Jul KEVU.S. CISA adds Fortinet FortiSandbox and Microsoft SharePoint flaws to its Known Exploited Vulnerabilities catalogU.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Fortinet FortiSandbox and Microsoft SharePoint flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added Fortinet FortiSandbox and Microsoft ShareP…SECURITYAFFAIRS.COM
17 Jul KEVCISA Adds Exploited SharePoint RCE Zero-Day CVE-2026-58644 to KEVThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a newly patched security flaw impacting Microsoft SharePoint Server to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the fi…THEHACKERNEWS.COM
17 Jul KEVU.S. CISA adds KNX Association KNX Protocol Connection Authorization Option 1 and Oracle flaws to its Known Exploited Vulnerabilities catalogU.S. Cybersecurity and Infrastructure Security Agency (CISA) adds KNX Association KNX Protocol Connection Authorization Option 1 and Oracle flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added SonicWall and M…SECURITYAFFAIRS.COM
16 Jul KEVCISA urges immediate SharePoint hardening as exploits mountThe US Cybersecurity and Infrastructure Security Agency (CISA) has urged organizations to immediately secure Microsoft SharePoint deployments after warning that three vulnerabilities affecting the on-premises collaboration platform are being actively exploited. A recent advisory …CSOONLINE.COM
16 Jul KEVCVE-2026-32201, CVE-2026-45659, CVE-2026-56164: Frequently Asked Questions About Active Exploitation of Microsoft SharePoint Server VulnerabilitiesFour Microsoft SharePoint Server vulnerabilities are under active exploitation, prompting CISA to issue a hardening alert. An additional high-severity flaw recently patched adds pressure for organizations running on-premises deployments. Key Takeaways CISA confirmed active exploi…TENABLE.COM
15 Jul KEVU.S. CISA adds SonicWall and Microsoft flaws to its Known Exploited Vulnerabilities catalogU.S. Cybersecurity and Infrastructure Security Agency (CISA) adds SonicWall and Microsoft flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added SonicWall and Microsoft flaws to its Known Exploited Vulnerabilit…SECURITYAFFAIRS.COM
15 Jul KEVPatch These Joomla Vulnerabilities NowCISA added vulnerabilities affecting the iCagenda and Babioon Forms Joomla extensions to its Known Exploited Vulnerabilities catalog after evidence of active exploitation. The flaws can enable remote code execution through arbitrary file uploads. When CISA gives a vulnerability i…YOUTUBE.COM
14 Jul KEVPatch Tuesday - July 2026Microsoft is publishing 622 vulnerabilities on July 2026 Patch Tuesday , including a record-breaking 416 Windows vulnerabilities. Microsoft is aware of exploitation in the wild for two of the vulnerabilities published today, both of which are listed on CISA KEV, as well as public…RAPID7.COM
13 Jul KEVU.S. CISA adds a Cisco IOS flaw to its Known Exploited Vulnerabilities catalogU.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a Cisco IOS flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Cisco IOS flaw, tracked as CVE-2008-4128, to its Known Exploited Vulnerabili…SECURITYAFFAIRS.COM
12 Jul KEVSecurity Affairs newsletter Round 585 by Pierluigi Paganini – INTERNATIONAL EDITIONA new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including the international press. U.S. CISA adds iCagenda and B…SECURITYAFFAIRS.COM
11 Jul KEVU.S. CISA adds iCagenda and Balbooa Forms flaws to its Known Exploited Vulnerabilities catalogU.S. Cybersecurity and Infrastructure Security Agency (CISA) adds iCagenda and Balbooa Forms flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added iCagenda and Balbooa Forms flaws to its Known Exploited Vulner…SECURITYAFFAIRS.COM
9 Jul KEVAI Is Annoying & IoT Devices Still Get Hacked - PSW #934In the security news: - Son of Anton strikes again! - HalluSquatting and using Claude to defend itself - CISA KEV’s Revolving Door - LLM's hallucinate and companies get sued - Additionally - GitLost - Yet even more Linux vulnerabilities - Citrix just keeps bleeding - Old hardware…YOUTUBE.COM
8 Jul KEVCISA Adds 4 Actively Exploited Adobe, Joomla, and Langflow Flaws to KEVThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added four security flaws to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerabilities are listed below - CVE-2026-48282 (CVSS score: 10.0) - A path tr…THEHACKERNEWS.COM
8 Jul KEVU.S. CISA adds Adobe ColdFusion, Joomlack Page Builder, Langflow, and JoomShaper SP Page Builder flaws to its Known Exploited Vulnerabilities catalogU.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Adobe ColdFusion, Joomlack Page Builder, Langflow, and JoomShaper SP Page Builder flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added [1, 2] …SECURITYAFFAIRS.COM
8 Jul KEVCISA Urges Immediate Patching of Exploited ColdFusion, Langflow, Joomla FlawsTwo newly disclosed critical vulnerabilities in Adobe ColdFusion and Langflow join two Joomla extension flaws in CISA's Known Exploited Vulnerabilities catalog, with federal agencies given until July 10 to patch. The post CISA Urges Immediate Patching of Exploited ColdFusion, Lan…SECURITYWEEK.COM
8 Jul KEVAttackers using Langflow flaw for credential harvesting (CVE-2026-55255)The US Cybersecurity and Infrastructure Security Agency (CISA) is warning about yet another Langflow vulnerability (CVE-2026-55255) leveraged by attackers in the wild. The flaw was added to the agency’s Known Exploited Vulnerabilities catalog on Tuesday, July 7, nearly two …HELPNETSECURITY.COM
2 Jul KEVSharePoint RCE CVE-2026-45659 Added to CISA KEV After Active ExploitationThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a high-severity flaw impacting Microsoft SharePoint Server to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerability, tracked as CVE-2026-4565…THEHACKERNEWS.COM
2 Jul KEVU.S. CISA adds a Microsoft SharePoint Server flaw to its Known Exploited Vulnerabilities catalogU.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a Microsoft SharePoint Server flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Microsoft SharePoint Server flaw, tracked as CVE-2026-4565…SECURITYAFFAIRS.COM
30 Jun KEVHow CISA BOD 26-04 redefines vulnerability management metrics for security leadersCISA’s BOD 26-04 changes how federal agencies patch and how security leaders must measure, justify, and communicate cyber risk to executives and boards. Key takeaways BOD 26-04 requires agencies to make and defend risk-based vulnerability prioritization decisions, including decis…TENABLE.COM
30 Jun KEVU.S. CISA adds SimpleHelp flaw to its Known Exploited Vulnerabilities catalogU.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a SimpleHelp flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a SimpleHelp flaw, tracked as CVE-2026-48558 (CVSS score v3.1 …SECURITYAFFAIRS.COM
29 Jun KEVModernizing Global Vulnerability Standards For The Age Of AIAs AI-driven vulnerability discovery accelerates, the cybersecurity ecosystem is being forced to examine whether the standards, disclosure processes, and prioritization frameworks defenders rely on can still keep pace. Many of those systems were built around human-speed discovery…RAPID7.COM
29 Jun KEVJSP webshells being dropped on unpatched PTC Windchill instancesThe US Cybersecurity and Infrastructure Security Agency (CISA) added a vulnerability (CVE-2026-12569) in Windchill and FlexPLM, two product lifecycle management software platforms developed by PTC, to its Known Exploited Vulnerabilities (KEV) catalog. Entries in the KEV catalog d…HELPNETSECURITY.COM
26 Jun KEVFirst-Ever Exploitation of PTC Windchill Vulnerability Discovered in the WildCISA has added the remote code execution flaw CVE-2026-12569 to its Known Exploited Vulnerabilities catalog. The post First-Ever Exploitation of PTC Windchill Vulnerability Discovered in the Wild appeared first on SecurityWeek .SECURITYWEEK.COM
26 Jun KEVCISA Adds Exploited PTC Windchill RCE Flaw to KEV as Web Shell Attacks ContinueThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a critical remote code execution vulnerability impacting PTC Windchill PDMlink and PTC FlexPLM enterprise Product Data Management (PDM) and Product Lifecycle Management (PLM) software to its Known …THEHACKERNEWS.COM
26 Jun KEVWeekly Metasploit Update: Modules for Audiobookshelf, LiteLLM, Next.js, Dalfox and moreHelp shape the future of Metasploit Framework We are planning future work in relation to the evasion capabilities present in Metasploit Framework, and how they function/are presented to users. We are currently accepting responses to our feedback form, which means that you can sha…RAPID7.COM
25 Jun KEVCISA Adds Two Known Exploited Vulnerabilities to CatalogCISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-12569 PTC Windchill and FlexPLM Improper Input Validation Vulnerability CVE-2026-20230 Cisco Unified Communications Manager Serv…CISA.GOV
24 Jun KEVAttackers exploit Cisco Unified CM flaw weeks after patch releaseA critical Cisco Unified CM vulnerability is now under active exploitation, weeks after the company issued patches warning it could allow attackers to gain root access. Threat intelligence firm Defused reported the exploitation on June 23. The company said it observed the activit…CSOONLINE.COM
19 Jun KEVUnauthenticated RCE in Splunk Enterprise under active attack (CVE-2026-20253)CISA has added CVE-2026-20253, a critical, remotely exploitable vulnerability in Splunk Enterprise, to its Known Exploited Vulnerabilities catalog, and ordered US federal civilian agencies to apply mitigations by June 21, 2026. In-the-wild exploitation has also been confirmed by …HELPNETSECURITY.COM
17 Jun KEVWhat 22,000 breaches teach us about incident preparednessThe 2026 Verizon Data Breach Investigations Report analyzed more than 22,000 confirmed data breaches across 145 countries. Its findings point to a single uncomfortable truth: organizations cannot patch fast enough to prevent every incident. Exploitation of vulnerabilities surged …CSOONLINE.COM
17 Jun KEVOperationalize CISA BOD 26-04 with Tenable OneCISA’s new directive officially ends federal agencies’ reliance on static vulnerability scores. Learn how Tenable One helps federal agencies pivot to dynamic asset exposure, threat validation, and AI-powered automation to meet compressed compliance timelines. Key takeaways CISA’s…TENABLE.COM
15 Jun KEVCISA Adds Two Known Exploited Vulnerabilities to CatalogCISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-20262 Cisco Catalyst SD-WAN Manager Directory or Path Traversal Vulnerability CVE-2026-54420 LiteSpeed cPanel Plugin UNIX Symbolic Link…CISA.GOV
11 Jun KEVCISA Directs Federal Agencies to Prioritize Security Patches Based on RiskThe new BOD 26-04 requires agencies to review and update vulnerability management policies with a focus on KEV catalog entries. The post CISA Directs Federal Agencies to Prioritize Security Patches Based on Risk appeared first on SecurityWeek .SECURITYWEEK.COM
11 Jun KEVTrolling Microsoft With Vulnerabilities - PSW #930In the security news: - Trolling Microsoft With Vulnerabilities - Fable 5 loves guardrails - Binwalk vulnerability - EMBA and local models - EDRChoker - AI worms - Interesting Arista vulnerability added to KEV - BOD 26-04 and stakeholder specific vulnerability categorization - Br…YOUTUBE.COM
11 Jun KEVCISA BOD 26-04: Frequently asked questions about the new risk-based patching directiveCISA issued BOD 26-04, which replaces BOD 22-01 with a four-variable vulnerability prioritization model requiring federal agencies to patch the most dangerous vulnerabilities in as few as three days. Key takeaways BOD 26-04 replaces BOD 22-01 with a four-variable risk model that …TENABLE.COM
10 Jun KEVCVE-2026-10520, CVE-2026-10523 - Multiple critical vulnerabilities affecting Ivanti SentryOverview On June 9, 2026, Ivanti published a security advisory for two critical vulnerabilities affecting Ivanti Sentry (formerly known as MobileIron Sentry), which per the vendor website is an “in-line gateway that manages, encrypts, and secures traffic between the mobile device…RAPID7.COM
10 Jun KEVCISA Adds Cisco, Chrome, and Arista Flaws to KEV Catalog Amid Active ExploitationThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation. The list of vulnerabilities is as follows - CVE-2026-20245 (CVSS score: 7.8)…THEHACKERNEWS.COM
10 Jun KEVCISA tells agencies to patch smarter, not harder — foreshadowing broader industry practiceSecurity teams’ patching practices have come under intense pressure over the past year, as active exploitation is up, time-to-exploit windows are accelerating, and vulnerabilities have become attackers’ top initial access vector of choice. Last year, organizations fully remediate…CSOONLINE.COM
9 Jun KEVAI worm prototype shows attackers don’t need Mythos to take over your networkResearchers from the University of Toronto developed a computer worm prototype powered by an AI agent that successfully self-replicated to different systems within a simulated computer network. The worm used a free large language model (LLM) running on local hardware and exploite…CSOONLINE.COM
9 Jun KEVLiteLLM vulnerability under active attack, CISA warns (CVE-2026-42271)A command injection vulnerability (CVE-2026-42271) in BerryAI’s LiteLLM open-source AI gateway is being exploited by attackers, the US Cybersecurity and Infrastructure Security Agency (CISA) confirmed by adding the flaw to its Known Exploited Vulnerabilities catalog on Mond…HELPNETSECURITY.COM
9 Jun KEVMicrosoft’s June 2026 Patch Tuesday Addresses 198 CVEs ( CVE-2026-49160, CVE-2026-50507)32 Critical 166 Important 0 Moderate 0 Low Microsoft addresses 198 CVEs in the largest Patch Tuesday release, including three zero-days. Microsoft patched 198 CVEs in its June 2026 Patch Tuesday release, with 32 rated critical and 166 rated as important. Our counts omitted 6 CVEs…TENABLE.COM
9 Jun KEVPatch Tuesday - June 2026Microsoft is publishing 200 vulnerabilities on June 2026 Patch Tuesday . Microsoft is not aware of exploitation in the wild for any of these vulnerabilities, and is aware of public disclosure for three. This is similar to last month’s Patch Tuesday, however several of last month’…RAPID7.COM
8 Jun KEVCritical Check Point VPN Zero-Day Exploited in the Wild (CVE-2026-50751)Overview On June 8, 2026, Check Point published a security advisory for CVE-2026-50751 , a critical authentication bypass vulnerability affecting Check Point Remote Access VPN, Mobile Access, and Spark Firewall products. The vulnerability affects deployments configured to use the…RAPID7.COM
6 Jun KEVCISA Adds Actively Exploited SolarWinds Serv-U DoS Flaw to KEV CatalogThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a high-severity security flaw impacting SolarWinds Serv-U multi-protocol file server software to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerability…THEHACKERNEWS.COM
4 Jun KEVCISA Adds Exploited Magento RCE Flaw CVE-2026-45247 to KEV CatalogThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a critical flaw impacting Mirasvit Cache Warmer, a popular Magento full-page cache extension, to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation in the …THEHACKERNEWS.COM
4 Jun KEVThe June 2026 AI Executive Order: What federal agencies need to know and how Tenable can helpOn June 2, 2026, the White House signed an Executive Order directing federal agencies to harden their systems with AI-enabled cyber defenses and to stand up a new AI cybersecurity clearinghouse — most of it on a 30-day clock. Here’s what the EO requires and how Tenable can help. …TENABLE.COM
2 Jun KEVAttackers exploit Palo Alto GlobalProtect flaw days after disclosureA Palo Alto Networks vulnerability that allows attackers to establish unauthorized VPN access into corporate networks is being actively exploited in the wild, weeks after the company disclosed the flaw as a medium-severity issue and said it was unaware of any attacks. However, ac…CSOONLINE.COM
2 Jun KEVOracle WebLogic CVE-2024-21182 Added to KEV Catalog After Active ExploitationThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a high-severity security flaw impacting Oracle WebLogic Server to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. The vulnerability, CVE-2024-21182 (CVSS …THEHACKERNEWS.COM
2 Jun KEVTwo-year old Oracle WebLogic Server vulnerability is being exploitedUS federal government departments have been given until Thursday to patch a two-year old high severity vulnerability in Oracle WebLogic Server that could allow an unauthenticated attacker to access critical data. The vulnerability, CVE-2024-21182 , was added Monday to the Cyberse…CSOONLINE.COM
1 Jun KEVCISA adds critical Palo Alto Networks firewall flaw to KEV as company, researchers warn of exploitationThe vulnerability in a vital defensive technology creates serious risks for federal networks, CISA said.CYBERSECURITYDIVE.COM
27 May KEVInside the customer environment: Where threat actors, vulnerabilities, and exposed assets intersectTenable Research has developed a graph-based model linking 600+ threat groups to real-world customer exposures. It reveals which vulnerabilities sit at the intersection of severity, active exploitation, and organizational risk. Key takeaways The "patch everything" strategy is dea…TENABLE.COM
26 May KEVVulnerabilities have become cyber attackers’ No. 1 door to the enterprisePatching practices are coming under intense pressure of late, as time-to-exploit windows accelerate — a new reality likely to worsen as AI assistance in attack chains rises. Now cyber defenders have another cause for flaw alarm: Vulnerability exploitation has significantly pulled…CSOONLINE.COM
23 May KEVCISA to allow researchers to report vulnerabilities to exploited bugs catalogThe Cybersecurity and Infrastructure Security Agency (CISA) announced the creation of a nomination form on Thursday that they said enables “researchers, vendors, and industry partners” to report bugs that need to be added to the Known Exploited Vulnerabilities catalog.THERECORD.MEDIA
23 May KEVDrupal Core SQL Injection Bug Actively Exploited, Added to CISA KEVThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a recently patched critical security flaw impacting Drupal Core to its Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation. The vulnerability in question is CVE-2026-908…THEHACKERNEWS.COM
22 May KEVCISA Adds Exploited Langflow and Trend Micro Apex One Vulnerabilities to KEVThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added two security flaws impacting Langflow and Trend Micro Apex One to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerabilities in question are list…THEHACKERNEWS.COM
22 May KEVCISA’s new KEV nomination form opens reporting to vendors and researchersThe Cybersecurity and Infrastructure Security Agency launched a new nomination form that lets researchers, vendors, and industry partners report known exploited vulnerabilities for possible inclusion in its KEV catalog. The form gives outside contributors a direct way to submit v…HELPNETSECURITY.COM
22 May KEVU.S. CISA adds Trend Micro Apex One and Langflow to its Known Exploited Vulnerabilities catalogU.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Trend Micro Apex One and Langflow flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added Windows Shell and ConnectWise ScreenConnect flaws …SECURITYAFFAIRS.COM
22 May KEVCISA Adds Langflow Origin Validation Flaw to Known Exploited Vulnerabilities CatalogThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical Langflow vulnerability, tracked as CVE-2025-34291, to its Known Exploited Vulnerabilities (KEV) Catalog, highlighting active exploitation risks and urging immediate remediation. The vulnerabilit…GBHACKERS.COM
21 May KEVMicrosoft Defender vulnerabilities exploited in the wild (CVE-2026-41091, CVE-2026-45498)Attackers are exploiting two Microsoft Defender vulnerabilities (CVE-2026-41091 and CVE-2026-45498), Microsoft acknowledged and CISA confirmed by adding them to its Known Exploited Vulnerabilities catalog. The vulnerabilities CVE-2026-41091 allows for local privilege elevation (L…HELPNETSECURITY.COM
21 May KEVMini Shai-Hulud: Frequently asked questions about the TeamPCP npm and PyPI supply chain campaignA self-propagating worm has compromised more than 170 npm and PyPI packages, defeating provenance attestation and breaching OpenAI and Mistral AI. Here is what you need to know. Key takeaways Mini Shai-Hulud is a self-propagating worm by TeamPCP that steals developer and cloud cr…TENABLE.COM
21 May KEVMicrosoft Defender vulnerabilities are being exploited in the wildCISA added seven known exploited vulnerabilities to its KEV catalog, including two Microsoft Defender flaws.MALWAREBYTES.COM
21 May KEVU.S. CISA adds Microsoft and Adobe flaws to its Known Exploited Vulnerabilities catalogU.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Microsoft and Adobe flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added Windows Shell and ConnectWise ScreenConnect flaws to its Known Exploi…SECURITYAFFAIRS.COM
19 May KEVKey findings from the Verizon DBIR 2026: Slower vulnerability remediation meets faster exploitationThe 2026 Verizon Data Breach Investigations Report (DBIR) reveals a troubling trend: vulnerability exploitation has surged to become the number one initial access vector while remediation rates have worsened. Key takeaways Vulnerability exploitation has surged to become the leadi…TENABLE.COM
16 May KEVU.S. CISA adds a flaw in Microsoft Exchange Server to its Known Exploited Vulnerabilities catalogThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a flaw in Microsoft Exchange Server to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a flaw in Microsoft Exchange Server, tracked as CVE-202…SECURITYAFFAIRS.COM
15 May KEVCISA Adds Cisco SD-WAN CVE-2026-20182 to KEV After Admin Access ExploitsThe U.S.Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a newly disclosed vulnerability impacting Cisco Catalyst SD-WAN Controller to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to remedi…THEHACKERNEWS.COM
15 May KEVCisco warns of an actively exploited SD-WAN flaw with max severityCisco has disclosed a max-severity authentication bypass vulnerability affecting its Catalyst SD-WAN Controller and Catalyst SD-WAN Manager platforms, warning that the flaw has already been found to be exploited in the wild. The disclosure follows an earlier authentication bypass…CSOONLINE.COM
15 May KEVCVE-2026-20182: Cisco Catalyst SD-WAN Auth Bypass Added to CISA KEVCVE-2026-20182: Cisco Catalyst SD-WAN Auth Bypass Added to CISA KEV Cisco has disclosed CVE-2026-20182, a critical authentication bypass affecting Cisco Catalyst SD-WAN Controller (formerly vSmart) and Cisco Catalyst SD-WAN Manager (formerly vManage). The flaw is in the peering a…SOCRADAR.IO
14 May KEVFragnesia (CVE-2026-46300): Frequently asked questions about new Linux Kernel XFRM ESP-in-TCP privilege escalationA new Linux kernel local privilege escalation exploit with a public proof-of-concept targets the same subsystem as Dirty Frag but requires a separate patch. Key Takeaways CVE-2026-46300 (Fragnesia) is the latest high severity local privilege escalation vulnerability in the Linux …TENABLE.COM
14 May KEVU.S. CISA adds a flaw in Cisco Catalyst SD-WAN to its Known Exploited Vulnerabilities catalogThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a flaw in Cisco Catalyst SD-WAN to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a flaw in Cisco Catalyst SD-WAN, tracked as CVE-2026-20182 …SECURITYAFFAIRS.COM
14 May KEVFrequently asked questions about the continued exploitation of Cisco Catalyst SD-WAN vulnerabilities (CVE-2026-20182)Multiple critical authentication bypass vulnerabilities in Cisco Catalyst SD-WAN Controller and Manager are under active exploitation by multiple threat clusters, including CVE-2026-20182, which has been exploited as a zero-day by a sophisticated threat actor. Key Takeaways CVE-2…TENABLE.COM
12 May KEVWhy patching SLAs should be the floor, not the strategyI’ve been a CISO for two separate companies, know several CISOs personally, and interact with many others through various cybersecurity forums. We all have one thing in common. We can tell you our patching SLA numbers off the top of our heads. Ninety-five percent of criticals clo…CSOONLINE.COM
12 May KEVHow Rapid7 is bringing Cyber GRC closer to security operationsSabeen Malik is VP, Global Government Affairs and Public Policy at Rapid7. ⠀ Security teams need a better way to connect what they detect, what they fix, and what they can prove. The pace of modern security operations no longer works in defenders’ favor. IBM’s Cost of a Data Brea…RAPID7.COM
11 May KEVU.S. CISA adds a flaw in BerriAI LiteLLM to its Known Exploited Vulnerabilities catalogThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a flaw in BerriAI LiteLLM to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a flaw in BerriAI LiteLLM, tracked as CVE-2026-42208 (CVSS score …SECURITYAFFAIRS.COM
8 May KEVYour refresh plan has a CVE blind spotThe conversation is straightforward, but the problem behind it is not. The customer bought servers in 2017 and typically refresh every five to six years. Generally, around the 2022 to 2023 timeframe, they would have looked to buy new. Historically, that is what would have happene…CSOONLINE.COM
8 May KEVCVE-2026-6973: Authenticated Admin RCE In Ivanti EPMM Added to CISA KEVCVE-2026-6973: Authenticated Admin RCE In Ivanti EPMM Added to CISA KEV Ivanti has patched CVE-2026-6973, a high-severity remote code execution (RCE) vulnerability affecting Ivanti Endpoint Manager Mobile (EPMM) on-prem deployments. The vulnerability has been exploited in the wil…SOCRADAR.IO
8 May KEVWhy the approaching flood of vulnerabilities changes everything — and what to do about itAI-driven discovery, NIST’s retreat from universal enrichment, and the end of “good enough” vulnerability management Key takeaways AI-driven discovery tools are accelerating CVE volume, resulting in an expected deluge of 59,000 disclosed vulnerabilities this year. NIST has…TENABLE.COM
8 May KEVDirty Frag (CVE-2026-43284, CVE-2026-43500): Frequently asked questions about this Linux kernel privilege escalation vulnerability chainWeeks after the Copy Fail vulnerability was revealed, a new Linux kernel escalation vulnerability has been uncovered. Dubbed “Dirty Frag,” this flaw could allow a local user to gain root access on affected Linux distributions. Public exploit code has been released prior to patche…TENABLE.COM
8 May KEVFive new holes, one exploited, found in Ivanti Endpoint Manager MobileThe five new vulnerabilities discovered in Ivanti’s on-premises mobile endpoint management solution are a “classic example of the legacy trap” that CSOs must avoid, says an expert. “Patch today to survive the weekend,” said Robert Enderle of the Enderle Group, “but start planning…CSOONLINE.COM
7 May KEVU.S. CISA adds a flaw in Palo Alto Networks PAN-OS to its Known Exploited Vulnerabilities catalogThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a flaw in Palo Alto Networks PAN-OS to its Known Exploited Vulnerabilities catalog The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a flaw in the Palo Alto Networks PAN-OS, tracked as CVE-…SECURITYAFFAIRS.COM
7 May KEVU.S. CISA adds a flaw in Ivanti Endpoint Manager Mobile (EPMM) to its Known Exploited Vulnerabilities catalogThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a flaw in Ivanti Endpoint Manager Mobile (EPMM) to its Known Exploited Vulnerabilities catalog The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a flaw in the Ivanti Endpoint Manager Mobile…SECURITYAFFAIRS.COM
5 May KEVCISA mulls new three-day remediation deadline for critical flawsExperts have mixed reactions to a report that the US Cybersecurity and Infrastructure Security Agency (CISA) is considering reducing the timeline in which government agencies must address critical vulnerabilities from two weeks to only three days. The current 14-day window applie…CSOONLINE.COM
4 May KEVU.S. CISA adds a flaw in Linux Kernel to its Known Exploited Vulnerabilities catalogThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a flaw in Linux Kernel to its Known Exploited Vulnerabilities catalog The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a flaw in the Linux Kernel, tracked as CVE-2026-31431 (CVSS score of …SECURITYAFFAIRS.COM
3 May KEVCISA Adds Actively Exploited Linux Root Access Bug CVE-2026-31431 to KEVThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added a recently disclosed security flaw impacting various Linux distributions to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation in the wild. The vulnerability, t…THEHACKERNEWS.COM
3 May KEVU.S. CISA adds a flaw in WebPros cPanel to its Known Exploited Vulnerabilities catalogThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a flaw in WebPros cPanel to its Known Exploited Vulnerabilities catalog The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a flaw in Microsoft Defender, tracked as CVE-2026-41940 (CVSS score…SECURITYAFFAIRS.COM
30 Apr KEVCopy Fail (CVE-2026-31431): Frequently asked questions about Linux kernel privilege escalation vulnerabilityA flaw in the Linux kernel present since 2017 allows a local user to gain root access on virtually every major Linux distribution. A public exploit is available and reported to work reliably. Key Takeaways CVE-2026-31431 is a high severity local privilege escalation vulnerability…TENABLE.COM
29 Apr KEVU.S. CISA adds Microsoft Windows Shell and ConnectWise ScreenConnect flaws to its Known Exploited Vulnerabilities catalogU.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Windows Shell and ConnectWise ScreenConnect flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added Windows Shell and ConnectWise ScreenConnect f…SECURITYAFFAIRS.COM
29 Apr KEVCISA Adds Actively Exploited ConnectWise and Windows Flaws to KEVThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added two security flaws impacting ConnectWise ScreenConnect and Microsoft Windows to its Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation. The vulnerabilities are l…THEHACKERNEWS.COM
29 AprCISA adds Microsoft, ConnectWise vulnerabilities to active exploitation catalogRussia has used one of the flaws, security experts said, while North Korea has used the other.CYBERSECURITYDIVE.COM
27 Apr KEVAs the NVD scales back CVE enrichment, here’s what Tenable customers need to knowNIST’s shift toward selective CVE enrichment creates significant visibility gaps for teams relying solely on the National Vulnerability Database. As AI accelerates vulnerability disclosure rates, organizations need independent, high-fidelity intelligence to prioritize risks that …TENABLE.COM
27 Apr KEVTeamPCP Supply Chain Campaign: Update 008 - 26-Day Pause Ends with Three Concurrent Compromises (Checkmarx KICS, Bitwarden CLI Cascade, xinference PyPI), CanisterSprawl npm Worm Identified, and Tier 1 Coverage Returns, (Mon, Apr 27th)This update succeeds&#;x26;#;xc2;&#;x26;#;xa0; TeamPCP Supply Chain Campaign Update 007 , published April 8, 2026, which left the campaign in credential-monetization mode following the Cisco source code theft via Trivy-linke…ISC.SANS.EDU
26 Apr KEVSecurity Affairs newsletter Round 574 by Pierluigi Paganini – INTERNATIONAL EDITIONA new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including the international press. U.S. CISA adds SimpleHelp, Sa…SECURITYAFFAIRS.COM
25 Apr KEVCISA Adds 4 Exploited Flaws to KEV, Sets May 2026 Federal DeadlineThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added four vulnerabilities impacting SimpleHelp, Samsung MagicINFO 9 Server, and D-Link DIR-823X series routers to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation.…THEHACKERNEWS.COM
25 Apr KEVU.S. CISA adds SimpleHelp, Samsung, and D-Link flaws to its Known Exploited Vulnerabilities catalogU.S. Cybersecurity and Infrastructure Security Agency (CISA) adds SimpleHelp, Samsung, and D-Link flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added SimpleHelp, Samsung, and D-Link flaws to its Known Exploi…SECURITYAFFAIRS.COM
🐛 COMMON VULNERABILITIES AND EXPOSURES 2555[−]
23 JulCheck Point Patches Exploited SmartConsole Flaw Allowing Full Admin AccessCheck Point has released security updates to address multiple vulnerabilities impacting Security Management and Multi-Domain Management (MDSM) products, including a critical flaw that has come under active exploitation in the wild. The security flaw, tracked as CVE-2026-16232 (CV…THEHACKERNEWS.COM
23 JulCVE-2026-56145 Uncontrolled Resource Consumption in Elasticsearch Leading to Denial of ServiceInformation published.MSRC.MICROSOFT.COM
23 JulCVE-2026-63140 Reachable Assertion in Elasticsearch Leading to Denial of ServiceInformation published.MSRC.MICROSOFT.COM
23 JulCVE-2026-63136 Uncontrolled Resource Consumption in Elasticsearch Leading to Denial of ServiceInformation published.MSRC.MICROSOFT.COM
23 JulCVE-2026-53910 Heap-based Buffer Overflow in GNU diffutilsInformation published.MSRC.MICROSOFT.COM
23 JulCVE-2026-55973 'dns-error-reporting: yes' leads to stack buffer overflowInformation published.MSRC.MICROSOFT.COM
23 JulCVE-2026-44687 Off-by-one error in 'harden-below-nxdomain' logic can shadow a stub/forward zone by a legitimate parent's NXDOMAINInformation published.MSRC.MICROSOFT.COM
23 JulCVE-2026-50248 BOGUS configured primary hostname accepted for XFR in auth/rpz zonesInformation published.MSRC.MICROSOFT.COM
23 JulCVE-2026-55708 Privacy/configuration issue when adding local data in views through 'unbound-control'Information published.MSRC.MICROSOFT.COM
23 JulCVE-2026-44621 Libunbound applications configured with 'unwanted-reply-threshold' could eventually be abruptly terminatedInformation published.MSRC.MICROSOFT.COM
23 JulCVE-2026-55717 'serve-expired-client-timeout' and 'response-ip' CNAME redirect could lead to a crashInformation published.MSRC.MICROSOFT.COM
23 JulCVE-2026-32665 Remote DNS-over-QUIC denial of service due to `quic-size` budget bypassInformation published.MSRC.MICROSOFT.COM
23 JulCVE-2026-46582 A wildcard replay, as another piece of data, triggers poisoning in the serve expired reply pathInformation published.MSRC.MICROSOFT.COM
23 JulCVE-2026-42955 Extra fix for CVE-2026-40622 to also clamp the TTL of A/AAAA records disallowing a one-time 'ghost domain' delegation renewal via glue recordsInformation published.MSRC.MICROSOFT.COM
23 JulCVE-2026-50046 Possible heap use-after-free in an error path when a DoT forwarded query is jostled outInformation published.MSRC.MICROSOFT.COM
23 JulCVE-2026-55990 Packet of death for a DNSCrypt misconfigured UnboundInformation published.MSRC.MICROSOFT.COM
23 JulCVE-2026-55991 Remote DNS-over-QUIC (DoQ) flow-control assertion failure in libngtcp2Information published.MSRC.MICROSOFT.COM
23 JulCVE-2026-50251 Attacker supplied '0.0.0.0'/'::' glue triggers defensive full-cache flushInformation published.MSRC.MICROSOFT.COM
23 JulCVE-2026-50252 Possible cache poisoning attack by mapping source port population per threadInformation published.MSRC.MICROSOFT.COM
23 JulCVE-2026-50243 'response-ip'/'rpz' can rewrite BOGUS answers instead of returning SERVFAILInformation published.MSRC.MICROSOFT.COM
23 JulCVE-2026-63308 Helm Files.Lines Denial of Service via Empty Chart FilesInformation published.MSRC.MICROSOFT.COM
23 JulCVE-2026-15588 Gdbusserver: glib2: gdbusserver pre-authentication dos via unbounded sasl line bufferingInformation published.MSRC.MICROSOFT.COM
23 JulCVE-2026-26080 HAProxy Community Edition 3.2.x through 3.3.x before 3.3.3 can enter a loop or crash because varint is mishandled. HAProxy Enterprise and ALOHA are also affected.Information published.MSRC.MICROSOFT.COM
23 JulCVE-2026-26081 HAProxy Community Edition 3.0 through 3.3 before 3.3.3 lacks a length check for the NEW_TOKEN format. HAProxy Enterprise and ALOHA are also affected.Information published.MSRC.MICROSOFT.COM
23 JulCVE-2026-15788 WCOW cache mount source selector resolves NTFS junctions outside of cache rootInformation published.MSRC.MICROSOFT.COM
23 JulCVE-2026-12080 Qemu-kvm: qemu-guest-agent: local privilege escalation via symlink attack in guest-ssh-add-authorized-keysInformation published.MSRC.MICROSOFT.COM
23 JulCVE-2026-16277 Rpcbind: rpcbind: stack buffer overflow in rpcinfo rpcbaddrlist()Information published.MSRC.MICROSOFT.COM
23 JulCVE-2026-44509 Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-43619. Reason: This candidate is a duplicate of CVE-2026-43619. Notes: All CVE users should reference CVE-2026-43619 instead of this candidate.Information published.MSRC.MICROSOFT.COM
23 JulCVE-2026-44508 Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-43618. Reason: This candidate is a duplicate of CVE-2026-43618. Notes: All CVE users should reference CVE-2026-43618 instead of this candidate.Information published.MSRC.MICROSOFT.COM
23 JulCVE-2026-54171 Excon: redact additional sensitive/risky headers when following redirectsInformation published.MSRC.MICROSOFT.COM
23 JulCVE-2026-63263 Uncontrolled Resource Consumption in Elasticsearch Leading to Denial of ServiceInformation published.MSRC.MICROSOFT.COM
23 JulCVE-2026-62994 CoreDNS `k8s_external` headless AXFR can emit an empty transfer batch that panics the `transfer` pluginInformation published.MSRC.MICROSOFT.COM
23 JulCVE-2026-50045 'max-global-quota' reset by DNSSEC validation restartsInformation published.MSRC.MICROSOFT.COM
23 JulCVE-2026-44690 Cross-zone wildcard cache poisoning via RRSIG.labels manipulationInformation published.MSRC.MICROSOFT.COM
23 JulCVE-2026-52863 Memory corruption could lead to crash and denial of serviceInformation published.MSRC.MICROSOFT.COM
23 JulCVE-2026-56416 Possible heap buffer overflow when validator canonicalizes RDATA that contains domain nameInformation published.MSRC.MICROSOFT.COM
23 JulCVE-2026-56444 Degradation of resolution service when 'discard-timeout' and 'serve-expired-client-timeout' are combined in unusual configurationInformation published.MSRC.MICROSOFT.COM
23 JulCVE-2026-54478 DNS Cookie bypass when combined with proxy-protocol useInformation published.MSRC.MICROSOFT.COM
23 JulCVE-2026-14586 Assertion in libngtcp2 when under pressure in high concurrency DNS-over-QUIC environmentsInformation published.MSRC.MICROSOFT.COM
23 JulCVE-2026-41637 Degradation of resolution service from improperly accounted client-terminated DNS-over-QUIC queriesInformation published.MSRC.MICROSOFT.COM
23 JulCVE-2026-44510 Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-43620. Reason: This candidate is a duplicate of CVE-2026-43620. Notes: All CVE users should reference CVE-2026-43620 instead of this candidate.Information published.MSRC.MICROSOFT.COM
23 JulNine-Year-Old RefluXFS Linux Flaw Gives Local Users Root on Default RHEL InstallsRefluXFS, a new Linux kernel flaw disclosed on July 22 and tracked as CVE-2026-64600, lets an unprivileged local user overwrite root-owned files on an XFS filesystem and gain persistent root access. Qualys said default installations of Red Hat Enterprise Linux and its derivatives…THEHACKERNEWS.COM
23 Jul KEVNew Check Point Zero-Day Vulnerability Exploited in the WildThe vulnerability tracked as CVE-2026-16232 has been exploited against customers with certain configurations. The post New Check Point Zero-Day Vulnerability Exploited in the Wild appeared first on SecurityWeek .SECURITYWEEK.COM
23 Jul KEVCheck Point patches actively exploited SmartConsole authentication bypass flawCheck Point addressed a critical authentication bypass flaw, tracked as CVE-2026-16232, in SmartConsole that is being actively exploited. Check Point has released security updates to fix multiple vulnerabilities, including CVE-2026-16232 (CVSS score of 9.3), a critical authentica…SECURITYAFFAIRS.COM
23 JulAttackers exploit critical Check Point flaw to take over firewall management (CVE-2026-16232)Attackers are exploiting a critical authentication bypass vulnerability (CVE-2026-16232) that affects Check Point Security Management and Multi-Domain Security Management, the management servers that push policy to Check Point security gateways (i.e., firewalls). “An unauth…HELPNETSECURITY.COM
23 JulNew RefluXFS Linux flaw lets attackers gain root privilegesA nine-year-old race condition vulnerability in the Linux kernel's XFS filesystem, tracked as CVE-2026-64600, allows local attackers to overwrite protected files and gain root privileges. [...]BLEEPINGCOMPUTER.COM
23 JulLinux XFS has a decade-old race condition allowing full root accessLinux systems using the XFS filesystem suffer from a race condition that could enable an unprivileged local user to gain full root access. The flaw affects systems with Linux kernel 4.11 or later that have enabled the XFS feature reflink, which permits the creation of copies of a…CSOONLINE.COM
23 JulVU#492466: Logto Identity Platform has authentication and authorization failures in core protocol handlingOverview The Logto platform contains multiple vulnerabilities affecting the identity‑processing pipeline. These flaws reduce the reliability of authentication and authorization decisions and may allow attackers to bypass account‑ownership checks, skip MFA, replay externally issue…KB.CERT.ORG
23 Jul KEVCheck Point hole grants unauthenticated attackers full SmartConsole admin privilegesCheck Point has confirmed that a critical security hole in its SmartConsole management tool, one that allows unauthenticated attackers to assume full admin privileges, is now being exploited in the wild. The vulnerability, CVE-2026-16232 , was given a CVSS score of 9.3. In its se…CSOONLINE.COM
22 JulWordPress Feeding Frenzy, Another Healthcare Supply Chain Breach, Qillin Targets Palo Alto BugWP2Shell WordPress RCE feeding frenzy, AI agent breaches Hugging Face, Killin hits Palo Alto VPN flaw This episode covers five major incidents: a chained WordPress exploit dubbed WP2Shell (CVE-2026-6330 and CVE-2026-6137) enabling anonymous remote code execution on stock installs…CYBERSECURITYTODAY.LIBSYN.COM
22 JulCVE-2026-42533 NGINX Map directive and Regex matching vulnerabilityInformation published.MSRC.MICROSOFT.COM
22 JulCVE-2026-56434 NGINX ngx_http_ssi_module vulnerabilityInformation published.MSRC.MICROSOFT.COM
22 JulCVE-2026-26197 Array full size, element count, and element size are not checked to make sure they match in H5Odtype.cInformation published.MSRC.MICROSOFT.COM
22 JulCVE-2026-64192 bpf: Reject BPF_MAP_TYPE_INODE_STORAGE creation if BPF LSM is uninitializedInformation published.MSRC.MICROSOFT.COM
22 JulCVE-2026-64189 netfilter: ipset: fix race between dump and ip_set_list resizeInformation published.MSRC.MICROSOFT.COM
22 JulCVE-2026-64188 net: qualcomm: rmnet: fix endpoint use-after-free in rmnet_dellink()Information published.MSRC.MICROSOFT.COM
22 JulCVE-2026-26199 Buffer underflow in `H5Iget_name `/`H5G_get_name` if size is zeroInformation published.MSRC.MICROSOFT.COM
22 JulCVE-2026-64187 xfs: fail recovery on a committed log item with no regionsInformation published.MSRC.MICROSOFT.COM
22 JulCVE-2026-64205 i2c: i801: fix hardware state machine corruption in error pathInformation published.MSRC.MICROSOFT.COM
22 JulCVE-2026-64190 net: team: fix NULL pointer dereference in team_xmit during mode changeInformation published.MSRC.MICROSOFT.COM
22 JulCVE-2026-64206 Bluetooth: L2CAP: cancel pending_rx_work before taking conn->lockInformation published.MSRC.MICROSOFT.COM
22 JulCVE-2026-64191 i2c: stub: Reject I2C block transfers with invalid lengthInformation published.MSRC.MICROSOFT.COM
22 JulCVE-2026-39879 SQL injection in syslog-ng SQL destionation driverInformation published.MSRC.MICROSOFT.COM
22 JulFourth SharePoint Vulnerability Exploited in Past Month’s Wave of AttacksCVE-2026-50522 is being exploited by threat actors to steal machine keys and retain long-term access. The post Fourth SharePoint Vulnerability Exploited in Past Month’s Wave of Attacks appeared first on SecurityWeek .SECURITYWEEK.COM
22 JulAnother SharePoint RCE exploited: Patch, then rotate your machine keys (CVE-2026-50522)Attackers are exploiting a critical SharePoint remote code execution (RCE) vulnerability (CVE-2026-50522) to extract the servers’ IIS machine keys. “WatchTowr is observing active exploitation of CVE-2026-50522 against on-premise Microsoft SharePoint deployments follow…HELPNETSECURITY.COM
22 JulHackers Exploit Windmill Flaw to Read Arbitrary Server Files Without AuthenticationA high-severity security flaw impacting open-source developer platform Windmill has come under active exploitation in the wild, per VulnCheck. The vulnerability in question is CVE-2026-29059 (CVSS score: 7.5), a case of unauthenticated path traversal impacting Windmill's "get_log…THEHACKERNEWS.COM
22 JulCVE-2026-50441 Windows Resilient File System (ReFS) Elevation of Privilege VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
22 JulCVE-2026-50458 Microsoft Brokering File System Elevation of Privilege VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
22 JulVU#360868: Analog Way Picturall Quad Compact Mark II contains a local privilege escalation vulnerabilityOverview Version 3.5.8 of Analog Way's Picturall Quad Compact Mark II server contains a local privilege escalation vulnerability, tracked as CVE-2026-14985, due to improper privilege delegation and insufficient input validation in a maintenance script. Description The Picturall Q…KB.CERT.ORG
22 JulWhat’s New in Rapid7 Products and Services: Q2 2026 in ReviewIf Q1 set the pace for Rapid7's tools, Q2 accelerated it. This quarter brought a steady stream of product enhancements, platform investments, and customer-driven innovation across Rapid7’s portfolio. Each release was designed with a clear goal in mind: helping security teams redu…RAPID7.COM
22 JulAdobe fixes Chrome extension flaw that could expose WhatsApp chatsA chain of vulnerabilities in the Adobe Acrobat Chrome extension could have allowed attackers to steal content from a victim's WhatsApp Web session simply by luring them to a malicious website. Adobe fixed the flaws within days of the report and assigned the issue CVE-2026-48294.…CYBERINSIDER.COM
22 JulVU#847406: Duplicati backup software v2.3.0.1 is vulnerable to an incorrect permission assignment vulnerabilityOverview Duplicati v2.3.0.1 is vulnerable to arbitrary code execution when installed outside the default C:\Program Files\Duplicati 2\ directory. An attacker with local user privileges who can write files to the Duplicati installation directory can execute arbitrary code by placi…KB.CERT.ORG
22 JulUbuntu snap-confine Flaw Could Give Local Users Root on Default Desktop InstallsCybersecurity researchers have disclosed details of a new local privilege escalation (LPE) vulnerability in snap-confine that an unprivileged user can trigger to obtain root access and gain complete control of a target environment. The high-severity flaw, tracked as CVE-2026-8933…THEHACKERNEWS.COM
22 JulOracle’s July update fixes ten 10.0 vulnerabilities in Fusion MiddlewareOracle’s July 2026 Critical Patch Update, its largest ever, contains 1,449 new security patches spanning 32 product families, from Oracle Database and E-Business Suite to PeopleSoft, GoldenGate, Java SE, and Fusion Middleware. Fusion Middleware was particularly hard hit, with new…CSOONLINE.COM
22 JulCritical Zimbra security update fixes 9 vulnerabilitiesBusiness email and collaboration suite Zimbra has received a major security update that fixes several critical issues that could allow attackers to execute malicious code on the server or in users’ browsers. Available in commercial and open-source editions, Zimbra Collaboration S…CSOONLINE.COM
22 JulAdobe Acrobat Chrome extension bug enabled silent WhatsApp data theftAdobe patched CVE-2026-48294, a flaw in Adobe Acrobat Chrome extension that could let attackers steal WhatsApp Web chats by luring users to a webpage. Guardio Labs researcher Shaked Biner disclosed HermeticReader, a vulnerability chain in the Adobe Acrobat Chrome extension that a…SECURITYAFFAIRS.COM
22 JulCVE-2026-8933: Ubuntu security flaw breaks Snap sandbox protectionsQualys disclosed CVE-2026-8933, a high-severity Ubuntu flaw that lets local attackers gain root privileges through a race condition in snap-confine. Qualys has disclosed a high-severity local privilege escalation vulnerability, tracked as CVE-2026-8933 (CVSS score of 7.8), affect…SECURITYAFFAIRS.COM
21 Jul KEVWhite hat hacker Park Chan-am zeros in on the AI era’s key security challengesDubbed the “Genius Hacker,” Park Chan-am began his white hat hacker journey at the precocious age of 11, winning awards at domestic and international hacking competitions since his teenage years. He has since served as a cybersecurity advisor for various Korean government agencie…CSOONLINE.COM
21 JulAttackers Exploit Critical ServiceNow RCE Flaw CVE-2026-6875Attackers are exploiting critical ServiceNow flaw CVE-2026-6875, allowing unauthenticated remote code execution on self-hosted instances. Searchlight Cyber researchers disclosed a critical pre-authentication remote code execution vulnerability, tracked as CVE-2026-6875, in the Se…SECURITYAFFAIRS.COM
21 JulCritical ServiceNow AI Platform Flaw Exploited for Unauthenticated Code ExecutionThreat actors are now exploiting a recently disclosed critical security flaw impacting ServiceNow AI Platform, according to Defused Cyber. In a post shared on X, the threat intelligence firm said it's observing in-the-wild exploitation of CVE-2026-6875 (CVSS score: 9.5), a sandbo…THEHACKERNEWS.COM
21 JulCVE-2026-38754 A heap overflow in the ifsbreakup() function (shell/ash.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input.Information published.MSRC.MICROSOFT.COM
21 JulCVE-2026-3842 Qemu-kvm: hyperv/syndbg: missing mapped-length guard after cpu_physical_memory_map causes host oob writeInformation published.MSRC.MICROSOFT.COM
21 JulCVE-2026-64133 ALSA: asihpi: Fix potential OOB array access at reading cacheInformation published.MSRC.MICROSOFT.COM
21 JulCVE-2026-64097 drm/amd/display: Validate GPIO pin LUT table size before iteratingInformation published.MSRC.MICROSOFT.COM
21 JulCVE-2026-63940 KVM: SEV: Ignore Port I/O requests of length '0'Information published.MSRC.MICROSOFT.COM
21 JulCVE-2026-64077 netfilter: ebtables: move to two-stage removal schemeInformation published.MSRC.MICROSOFT.COM
21 JulCVE-2026-63879 drm/amdgpu: fix amdgpu_hmm_range_get_pagesInformation published.MSRC.MICROSOFT.COM
21 JulCVE-2026-63882 drm/amdkfd: fix NULL pointer bug in svm_range_set_attrInformation published.MSRC.MICROSOFT.COM
21 JulCVE-2026-64017 blk-mq: pop cached request if it is usableInformation published.MSRC.MICROSOFT.COM
21 JulCVE-2026-64146 erofs: fix metabuf leak in inode xattr initializationInformation published.MSRC.MICROSOFT.COM
21 JulCVE-2026-38755 A heap overflow in the evalcommand() function (shell/ash.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input.Information published.MSRC.MICROSOFT.COM
21 JulCVE-2026-64038 hwmon: (lm90) Stop work before releasing hwmon deviceInformation published.MSRC.MICROSOFT.COM
21 JulCVE-2026-64036 cgroup/rstat: validate cpu before css_rstat_cpu() accessInformation published.MSRC.MICROSOFT.COM
21 JulCVE-2026-64079 netfilter: x_tables: allocate hook ops while under mutexInformation published.MSRC.MICROSOFT.COM
21 JulCVE-2026-64001 ALSA: pcm: oss: Fix setup list UAF on proc write errorInformation published.MSRC.MICROSOFT.COM
21 JulCVE-2026-64160 netfs: Fix potential for tearing in ->remote_i_size and ->zero_pointInformation published.MSRC.MICROSOFT.COM
21 JulCVE-2026-64138 ksmbd: validate SID in parent security descriptor during ACL inheritanceInformation published.MSRC.MICROSOFT.COM
21 JulCVE-2026-63959 usb: typec: tcpm/tcpci_maxim: validate header NDO against RX_BYTE_CNTInformation published.MSRC.MICROSOFT.COM
21 JulCVE-2026-64070 powerpc/hv-gpci: fix preempt count leak in sysfs show pathsInformation published.MSRC.MICROSOFT.COM
21 JulCVE-2026-64015 security/keys: fix missed RCU read section on lookupInformation published.MSRC.MICROSOFT.COM
21 JulCVE-2026-63962 usb: typec: tcpm: bound altmode_desc[] per iteration in svdm_consume_modes()Information published.MSRC.MICROSOFT.COM
21 JulCVE-2026-63958 usb: typec: ucsi: validate connector number in ucsi_connector_change()Information published.MSRC.MICROSOFT.COM
21 JulCVE-2026-64117 wifi: mac80211: capture fast-RX rate before mesh reuses skb->cbInformation published.MSRC.MICROSOFT.COM
21 JulCVE-2026-63954 hpfs: fix a crash if hpfs_map_dnode_bitmap failsInformation published.MSRC.MICROSOFT.COM
21 JulCVE-2026-64078 netfilter: x_tables: add and use xtables_unregister_table_exitInformation published.MSRC.MICROSOFT.COM
21 JulCVE-2026-63983 net/sched: fix packet loop on netem when duplicate is onInformation published.MSRC.MICROSOFT.COM
21 JulCVE-2026-63964 usb: typec: ucsi: ccg: reject firmware images without a ':' record headerInformation published.MSRC.MICROSOFT.COM
21 JulCVE-2026-63960 usb: typec: wcove: don't write past struct pd_message in wcove_read_rx_buffer()Information published.MSRC.MICROSOFT.COM
21 JulCVE-2026-63881 drm/amdkfd: fix a vulnerability of integer overflow in kfd debuggerInformation published.MSRC.MICROSOFT.COM
21 JulCVE-2026-63961 usb: typec: altmodes/displayport: validate count before reading Status Update VDOInformation published.MSRC.MICROSOFT.COM
21 JulCVE-2026-63963 usb: typec: tcpm: validate VDO count in Discover Identity ACK handlersInformation published.MSRC.MICROSOFT.COM
21 JulCVE-2026-64111 lsm: hold cred_guard_mutex for lsm_set_self_attr()Information published.MSRC.MICROSOFT.COM
21 JulCVE-2026-64154 drm/msm/adreno: Fix a reference leak in a6xx_gpu_init()Information published.MSRC.MICROSOFT.COM
21 JulCVE-2026-64112 rbd: eliminate a race in lock_dwork draining on unmapInformation published.MSRC.MICROSOFT.COM
21 JulCVE-2026-64076 netfilter: bridge: eb_tables: close module init raceInformation published.MSRC.MICROSOFT.COM
21 JulCVE-2026-64060 netfs: Fix leak of request in netfs_write_begin() error handlingInformation published.MSRC.MICROSOFT.COM
21 JulCVE-2026-63979 net/handshake: hand off the pinned file reference to accept_doitInformation published.MSRC.MICROSOFT.COM
21 JulCVE-2026-63999 ethtool: rss: fix indir_table and hkey leak on get_rxfh failureInformation published.MSRC.MICROSOFT.COM
21 JulCVE-2026-63978 net/handshake: Drain pending requests at net namespace exitInformation published.MSRC.MICROSOFT.COM
21 JulCVE-2026-63974 Bluetooth: hci_sync: Set HCI_CMD_DRAIN_WORKQUEUE during device closeInformation published.MSRC.MICROSOFT.COM
21 JulCVE-2026-64082 riscv: Fix register corruption from uninitialized cregs on errorInformation published.MSRC.MICROSOFT.COM
21 JulCVE-2026-38753 A use-after-free in the awk_sub() function (editors/awk.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted AWK script.Information published.MSRC.MICROSOFT.COM
21 JulCVE-2026-38752 A stack overflow in the evaluate() function (editors/awk.c) of BusyBox commit 371fe9 allows attackers to cause a Denial of Service (DoS) via supplying a crafted AWK script.Information published.MSRC.MICROSOFT.COM
21 JulCVE-2026-42770 FFC-DH Peer Validation Uses Attacker-Supplied qInformation published.MSRC.MICROSOFT.COM
21 JulWordPress wp2shell Exploitation Grows as Public Exploit Fuels Mass ScanningAttackers have begun to exploit two critical vulnerabilities in WordPress that, when combined together, enable unauthenticated remote code execution (RCE) and complete compromise of vulnerable websites. The two security flaws, tracked as CVE-2026-63030 and CVE-2026-60137, have be…THEHACKERNEWS.COM
21 JulExploitation of ServiceNow Vulnerability Seen Days After DisclosureThe ServiceNow AI platform vulnerability tracked as CVE-2026-6875 can be exploited for remote code execution. The post Exploitation of ServiceNow Vulnerability Seen Days After Disclosure appeared first on SecurityWeek .SECURITYWEEK.COM
21 JulSonicWall SMA zero-days were exploited weeks before disclosureTwo recently disclosed SonicWall SMA 1000 vulnerabilities – CVE-2026-15409 and CVE-2026-15410 – were exploited in zero-day attacks for weeks, allowing threat actors to install custom malware on vulnerable VPN appliances, Volexity researchers revealed. The intrusions b…HELPNETSECURITY.COM
21 JulQilin Ransomware Attackers Exploit PAN-OS Authentication Bypass for Initial AccessThreat actors have been observed exploiting a now-patched high-severity Palo Alto Networks PAN-OS vulnerability as an entry point to deploy Qilin (aka Agenda) ransomware on victim environments. Arctic Wolf Labs said it investigated multiple intrusions in June 2026 that began with…THEHACKERNEWS.COM
21 JulCritical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoCA third SharePoint Server flaw patched by Microsoft as part of its Patch Tuesday update for July 2026 has come under active exploitation, per watchTowr. The vulnerability in question is CVE-2026-50522 (CVSS score: 9.8), a critical deserialization of untrusted data in Microsoft Of…THEHACKERNEWS.COM
21 JulCVE-2026-58640 Windows NTFS Remote Code Execution VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
21 JulCVE-2026-50462 Windows Ancillary Function Driver for WinSock Elevation of Privilege VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
21 JulVU#762226: Plane contains multi-tenant authorization bypass vulnerabilityOverview The project management tool Plane, versions 1.3.0 and earlier, contains a multi-tenant authorization bypass vulnerability in its asset-management API that allows unauthorized users to access, delete, or duplicate assets that belong to other workspaces. Description Plane …KB.CERT.ORG
21 JulCritical wp2shell WordPress flaws exploited to install webshellsHackers are exploiting the "wp2shell" critical vulnerability suite (CVE-2026-63030 and CVE-2026-60137) affecting WordPress Core to deploy persistent webshells and install malicious plugins on affected servers. [...]BLEEPINGCOMPUTER.COM
21 JulQilin Ransomware Affiliates Abuse CVE-2026-0257 to Gain Unauthorized VPN AccessQilin ransomware exploits the PAN-OS GlobalProtect flaw CVE-2026-0257 to gain unauthorized VPN access to unpatched networks. Arctic Wolf researchers warn that the Qilin ransomware gang is exploiting the critical PAN-OS GlobalProtect vulnerability CVE-2026-0257 to compromise corpo…SECURITYAFFAIRS.COM
21 JulCritical SharePoint RCE flaw exploited to steal machine keysHackers are actively exploiting the critical CVE-2026-50522 vulnerability in Microsoft SharePoint to steal machine keys and maintain access even after affected servers are patched. [...]BLEEPINGCOMPUTER.COM
21 Jul KEVPublic PoC triggers active exploitation of critical SharePoint RCE vulnerability CVE-2026-50522Critical SharePoint RCE vulnerability CVE-2026-50522 is under active exploitation after the release of a PoC exploit code. A critical Microsoft SharePoint vulnerability, tracked as CVE-2026-50522 (CVSS score of 9.8), is being actively exploited following the release of a public p…SECURITYAFFAIRS.COM
20 JulCritical NGINX Vulnerability Can Crash Workers and May Allow Remote Code ExecutionF5 has shipped fixes for a critical nginx flaw that lets a remote, unauthenticated attacker trigger a heap buffer overflow in the worker process with crafted HTTP requests. CVE-2026-42533 was patched on July 15 in nginx 1.30.4 (stable) and 1.31.3 (mainline), and in NGINX Plus 37.…THEHACKERNEWS.COM
20 Jul KEVWP2Shell WordPress Vulnerabilities Exploited in the WildExploitation of the new WordPress vulnerabilities tracked as CVE-2026-60137 and CVE-2026-63030 started soon after disclosure. The post WP2Shell WordPress Vulnerabilities Exploited in the Wild appeared first on SecurityWeek .SECURITYWEEK.COM
20 JulCVE-2026-63815 f2fs: bound i_inline_xattr_size for non-inline-xattr inodesInformation published.MSRC.MICROSOFT.COM
20 JulCVE-2026-53386 iio: adc: ti-ads1298: add bounds check to pga_settings indexInformation published.MSRC.MICROSOFT.COM
20 JulCVE-2026-63810 block: Avoid mounting the bdev pseudo-filesystem in userspaceInformation published.MSRC.MICROSOFT.COM
20 JulCVE-2026-53392 NFSv4/flexfiles: reject zero filehandle version countInformation published.MSRC.MICROSOFT.COM
20 JulCVE-2026-53374 drm/amdgpu: zero-initialize GART table on allocationInformation published.MSRC.MICROSOFT.COM
20 JulCVE-2026-53376 drm/amdkfd: Add upper bound check for num_of_nodesInformation published.MSRC.MICROSOFT.COM
20 JulCVE-2026-63806 KVM: Replace guest-triggerable BUG_ON() in ioeventfd datamatch with get_unaligned()Information published.MSRC.MICROSOFT.COM
20 JulCVE-2026-63833 ntfs3: reject direct userspace writes to reserved $LX* xattrsInformation published.MSRC.MICROSOFT.COM
20 JulCVE-2026-63826 fbdev: fix use-after-free in store_modes()Information published.MSRC.MICROSOFT.COM
20 JulCVE-2026-63829 net: ip_gre: require CAP_NET_ADMIN in the device netns for changelinkInformation published.MSRC.MICROSOFT.COM
20 JulCVE-2026-53375 drm/amdgpu/vce: Prevent partial address patchesInformation published.MSRC.MICROSOFT.COM
20 JulCVE-2026-53393 nfsd: reset write verifier on deferred writeback errorsInformation published.MSRC.MICROSOFT.COM
20 JulCVE-2026-63809 bpf: use kvfree() for replaced sysctl write bufferInformation published.MSRC.MICROSOFT.COM
20 JulCVE-2026-63803 hdlc_ppp: sync per-proto timers before freeing hdlc stateInformation published.MSRC.MICROSOFT.COM
20 JulCVE-2026-63834 batman-adv: tp_meter: restrict number of unacked list entriesInformation published.MSRC.MICROSOFT.COM
20 JulCVE-2026-53391 NFSv4/pNFS: reject zero-length r_addr in nfs4_decode_mp_ds_addrInformation published.MSRC.MICROSOFT.COM
20 JulCVE-2026-63822 wifi: ath11k: fix warning when unbindingInformation published.MSRC.MICROSOFT.COM
20 JulCVE-2026-53397 nfsd: fix posix_acl leak on SETACL decode failureInformation published.MSRC.MICROSOFT.COM
20 JulCVE-2026-63836 batman-adv: tp_meter: avoid divide-by-zero for dec_cwndInformation published.MSRC.MICROSOFT.COM
20 JulCVE-2026-63796 ocfs2: reject oversized group bitmap descriptorsInformation published.MSRC.MICROSOFT.COM
20 JulCVE-2026-63812 f2fs: fix incorrect FI_NO_EXTENT handling in __destroy_extent_node()Information published.MSRC.MICROSOFT.COM
20 JulCVE-2026-63801 tipc: fix slab-use-after-free Read in tipc_aead_decrypt_doneInformation published.MSRC.MICROSOFT.COM
20 JulCVE-2026-63828 apparmor: mediate the implicit connect of TCP fast open sendmsgInformation published.MSRC.MICROSOFT.COM
20 JulCVE-2026-53382 media: vidtv: fix NULL pointer dereference in vidtv_mux_push_siInformation published.MSRC.MICROSOFT.COM
20 JulCVE-2026-63795 9p: avoid putting oldfid in p9_client_walk() error pathInformation published.MSRC.MICROSOFT.COM
20 JulCVE-2026-63808 exfat: fix potential use-after-free in exfat_find_dir_entry()Information published.MSRC.MICROSOFT.COM
20 JulCVE-2026-45784 rust-openssl: Potential out-of-bounds write in `CipherCtxRef::cipher_update_inplace` for AES-KW-PAD ciphersInformation published.MSRC.MICROSOFT.COM
20 JulCVE-2026-62389 ws < 8.21.1 Default maxFragments Allows Memory Exhaustion DoSInformation published.MSRC.MICROSOFT.COM
20 JulCVE-2026-63805 crypto: nx - fix nx_crypto_ctx_exit argumentInformation published.MSRC.MICROSOFT.COM
20 JulCVE-2026-63816 f2fs: atomic: fix UAF issue on f2fs_inode_info.atomic_inodeInformation published.MSRC.MICROSOFT.COM
20 JulCVE-2026-63825 gcov: use atomic counter updates to fix concurrent access crashesInformation published.MSRC.MICROSOFT.COM
20 JulCVE-2026-63853 drm/amdgpu/vcn: set no_user_fence for VCN v4.0 enc ringInformation published.MSRC.MICROSOFT.COM
20 JulCVE-2026-53402 fbdev: fbcon: fix out-of-bounds read in err_out of fbcon_do_set_font()Information published.MSRC.MICROSOFT.COM
20 JulCVE-2026-63819 f2fs: fix to do sanity check on f2fs_get_node_folio_ra()Information published.MSRC.MICROSOFT.COM
20 JulCVE-2026-53401 fbdev: omap2: fix use-after-free in omapfb_mmapInformation published.MSRC.MICROSOFT.COM
20 JulCVE-2026-63811 f2fs: read COW data with the original inode during atomic writeInformation published.MSRC.MICROSOFT.COM
20 JulCVE-2026-53403 fbdev: Fix fb_new_modelist to prevent null-ptr-deref in fb_videomode_to_varInformation published.MSRC.MICROSOFT.COM
20 JulCVE-2026-53368 f2fs: fix fsck inconsistency caused by incorrect nat_entry flag usageInformation published.MSRC.MICROSOFT.COM
20 JulCVE-2026-53400 i2c: core: fix adapter registration raceInformation published.MSRC.MICROSOFT.COM
20 JulCVE-2026-63871 Bluetooth: ISO: Fix data-race on iso_pi fields in hci_get_route callsInformation published.MSRC.MICROSOFT.COM
20 JulCVE-2026-63872 esp: fix page frag reference leak on skb_to_sgvec failureInformation published.MSRC.MICROSOFT.COM
20 JulCVE-2026-53399 nfsd: release layout stid on setlease failureInformation published.MSRC.MICROSOFT.COM
20 JulCVE-2026-63858 netfilter: nf_tables: add hook transactions for device deletionsInformation published.MSRC.MICROSOFT.COM
20 JulCVE-2026-63818 f2fs: validate orphan inode entry countInformation published.MSRC.MICROSOFT.COM
20 JulCVE-2026-63832 wifi: mt76: add wcid publish check in mt76_sta_addInformation published.MSRC.MICROSOFT.COM
20 JulCVE-2026-53387 iio: light: veml6075: add bounds check to veml6075_it_ms indexInformation published.MSRC.MICROSOFT.COM
20 JulCVE-2026-63835 batman-adv: v: prevent OGM aggregation on disabled hardifInformation published.MSRC.MICROSOFT.COM
20 JulCVE-2026-63807 KVM: x86/mmu: Ensure hugepage is in by slot before checking max mapping levelInformation published.MSRC.MICROSOFT.COM
20 JulCVE-2026-53384 serial: 8250_dw: unregister 8250 port if clk_notifier_register() failsInformation published.MSRC.MICROSOFT.COM
20 JulCVE-2026-63830 net: skmsg: preserve sg.copy across SG transformsInformation published.MSRC.MICROSOFT.COM
20 JulCVE-2026-53388 fuse: re-lock request before replacing page cache folioInformation published.MSRC.MICROSOFT.COM
20 JulCVE-2026-63794 KVM: SVM: Fix page overflow in sev_dbg_crypt() for ENCRYPT pathInformation published.MSRC.MICROSOFT.COM
20 JulCVE-2026-63821 wifi: rtw88: usb: fix memory leaks on USB write failuresInformation published.MSRC.MICROSOFT.COM
20 JulCVE-2026-63824 KEYS: fix overflow in keyctl_pkey_params_get_2()Information published.MSRC.MICROSOFT.COM
20 JulCVE-2026-63798 irqchip/imgpdc: Fix resource leak, add missing chained handler cleanup on removeInformation published.MSRC.MICROSOFT.COM
20 JulCVE-2026-63823 keys: Pin request_key_auth payload in instantiate pathsInformation published.MSRC.MICROSOFT.COM
20 JulCVE-2026-63800 pNFS: Fix use-after-free in pnfs_update_layout()Information published.MSRC.MICROSOFT.COM
20 JulCVE-2026-63797 rpmsg: char: Fix use-after-free on probe error pathInformation published.MSRC.MICROSOFT.COM
20 JulCVE-2026-63817 f2fs: validate compress cache inode only when enabledInformation published.MSRC.MICROSOFT.COM
20 JulCVE-2026-63804 gfs2: fix use-after-free in gfs2_qd_deallocInformation published.MSRC.MICROSOFT.COM
20 JulCVE-2026-63831 mac802154: llsec: add skb_cow_data() before in-place cryptoInformation published.MSRC.MICROSOFT.COM
20 JulCVE-2026-63802 blk-cgroup: fix UAF in __blkcg_rstat_flush()Information published.MSRC.MICROSOFT.COM
20 JulCVE-2026-53385 vc_screen: fix null-ptr-deref in vcs_notifier() during concurrent vcs_writeInformation published.MSRC.MICROSOFT.COM
20 JulCVE-2026-53390 ksmbd: fix out-of-bounds read in smb_check_perm_dacl()Information published.MSRC.MICROSOFT.COM
20 JulCVE-2026-63814 f2fs: validate ACL entry sizes in f2fs_acl_from_disk()Information published.MSRC.MICROSOFT.COM
20 JulCVE-2026-53383 ksmbd: reject non-VALID session in compound request branchInformation published.MSRC.MICROSOFT.COM
20 JulCVE-2026-53398 NFSD: Fix SECINFO_NO_NAME decode error cleanupInformation published.MSRC.MICROSOFT.COM
20 JulCVE-2026-63827 apparmor: fix use-after-free in rawdata dedup loopInformation published.MSRC.MICROSOFT.COM
20 JulNew 7-Zip Vulnerability Could Let Crafted XZ Archives Run Code During ExtractionOpening a crafted XZ archive in 7-Zip could let an attacker run code on the machine. The flaw, CVE-2026-14266, is a heap-based buffer overflow in how the archiver processes XZ chunked data, and Trend Micro's Zero Day Initiative (ZDI) detailed it on July 15. A fix shipped on June …THEHACKERNEWS.COM
20 JulCritical ServiceNow code execution flaw now exploited in attacksAttackers have begun exploiting a critical vulnerability (CVE-2026-6875) in the ServiceNow AI Platform, according to threat intelligence company Defused. [...]BLEEPINGCOMPUTER.COM
20 JulCVE-2026-42533: Critical NGINX Bug Could Turn HTTP Requests Into Server TakeoversF5 fixes critical nginx flaw CVE-2026-42533 that can crash servers and, in some cases, allow remote code execution through crafted HTTP requests. F5 released patches for a critical nginx vulnerability, tracked as CVE-2026-42533 (CVSS score of 9.2), that can allow an unauthenticat…SECURITYAFFAIRS.COM
20 JulFrom a Single Alert to 1,000 Files: Inside an Exposed WebDAV Malware Delivery LabExecutive summary An MDR alert recently led our team to an exposed server that was doing more than hosting payloads. It was functioning as a fully operational malware delivery lab. Containing over 1,000 artifacts, the infrastructure served as a QA hub where attackers systematical…RAPID7.COM
20 JulSonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before PatchThe zero-days CVE-2026-15409 and CVE-2026-15410 were exploited by a threat actor tracked by Volexity as UTA0533. The post SonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before Patch appeared first on SecurityWeek .SECURITYWEEK.COM
20 Jul KEVServiceNow pre-auth RCE exploited in the wild (CVE-2026-6875)Attackers have begun exploiting CVE-2026-6875, a critical pre-authentication vulnerability in the ServiceNow AI Platform, according to threat intelligence firm Defused. About the vulnerability ServiceNow AI is a Platform-as-a-Service that lets organizations build and automate dig…HELPNETSECURITY.COM
20 JulCVE-2026-50650 .NET Framework Elevation of Privilege VulnerabilityUpdated product information in the Software Update table. This is an informational change only.MSRC.MICROSOFT.COM
20 JulExploitation in the Wild of wp2shellWiz Research has identified exploitation of "wp2shell", a critical pre-auth RCE vulnerability chain impacting WordPress Core (CVE-2026-63030 & CVE-2026-60137). Attackers are deploying persistent webshells on vulnerable servers. Organizations should prioritize patching or applying…WIZ.IO
20 JulWordPress Exploitation Underway (CVE-2026-63030), (Mon, Jul 20th)Last week, Searchlight Cyber released details about a vulnerability they are calling "wp2shell". The vulnerability was initially announced without a CVE number. But now has been assigned CVE-2026-63030. Many WordPress plugin vulnerabilities are never assigned CVE numbers. But wp2…ISC.SANS.EDU
20 JulCVE-2024-44000 (LiteSpeed Cache Account Takeover) Ranks in June’s Top ThreatsSensor Intel Series: July 2026 CVE TrendsF5.COM
20 Jul KEVServiceNow’s sandbox escape RCE hole now exploited in the wildA sandbox security hole that could lead to remote code execution (RCE), patched last week by ServiceNow, is being actively exploited in the wild, according to a report from threat intel firm Defused . The report, posted on X, said the firm is “observing in-the-wild exploitation o…CSOONLINE.COM
20 Jul'WP2Shell' Opens Millions of WordPress Sites to Remote TakeoverBarely three days after disclosure, attackers are widely chaining together CVE-2026-60137 and CVE-2026-63030 to lob exploit attempts against one of the largest attack surfaces on the Internet.DARKREADING.COM
19 JulAttackers Can Take Over WordPress Sites Using Newly Released wp2shell ExploitsPublic exploits are now available for two critical WordPress flaws that attackers can chain to gain remote code execution without authentication. Public proof-of-concept exploits are now available for the critical wp2shell vulnerabilities affecting WordPress Core. The flaws, trac…SECURITYAFFAIRS.COM
18 JulCVE-2026-62309 CoreDNS: proxyproto plugin panics on PPv2 datagram with non-UDP transport — single 28-byte packet remote DoSInformation published.MSRC.MICROSOFT.COM
18 JulCVE-2026-62299 CoreDNS: rewrite-plugin EDNS0 response-revert nil-pointer panic (remote DoS) when a downstream plugin returns a response with no OPT recordInformation published.MSRC.MICROSOFT.COM
18 JulCVE-2026-47729 Squid: Memory disclosure in FTP gatewayInformation published.MSRC.MICROSOFT.COM
18 JulCVE-2026-50012 Squid: Memory corruption in cache_digest reply handlingInformation published.MSRC.MICROSOFT.COM
18 JulTwo new high severity WordPress vulnerabilities, patch immediately!The 7.0.2 WordPress security release addresses one critical and one high severity security issue. The vulnerabilities reported to the WordPress security team include: CVE-2026-60137 – A facilitated SQL injection issue reported as a team by TF1T, dtro, and haongo CVE-2026-60…HELPNETSECURITY.COM
17 JulCVE-2026-48863 Libsolv: stack-based buffer overflow in libsolv eddsa pgp signature verification allows denial of serviceInformation published.MSRC.MICROSOFT.COM
17 JulCVE-2026-53366 ipv4: account for fraggap on the paged allocation pathInformation published.MSRC.MICROSOFT.COM
17 JulCVE-2026-15713 Libsoup: soupcache: libsoup: http/2 frame window exhaustion remote denial of service via memory leakInformation published.MSRC.MICROSOFT.COM
17 JulCVE-2026-15714 Libsoup: soupmultipartinputstream: libsoup: out-of-bounds read in soup_multipart_input_stream_read_headers via an oversized multipart boundary stringInformation published.MSRC.MICROSOFT.COM
17 JulCVE-2026-15712 Soupclientmessageiohttp2: libsoup3: libsoup: http/2 goaway frame parsing heap buffer over-read via invalid nul-termination assumptionInformation published.MSRC.MICROSOFT.COM
17 JulCVE-2026-60082 DBI versions before 1.651 for Perl do not enforce statement handle consistency with the rowInformation published.MSRC.MICROSOFT.COM
17 JulCVE-2026-60081 DBI::ProfileData versions before 1.651 for Perl do not limit the path indexInformation published.MSRC.MICROSOFT.COM
17 JulCVE-2026-59884 pyasn1 BER/CER/DER decoder denial of service via unbounded long-form tag IDsInformation published.MSRC.MICROSOFT.COM
17 JulCVE-2026-59886 pyasn1: Uncontrolled resource consumption when converting decoded REAL valuesInformation published.MSRC.MICROSOFT.COM
17 JulCVE-2026-15711 Libsoup: soupwebsocketconnection: libsoup: websocket remote denial of service via oversized control frame protocol violationInformation published.MSRC.MICROSOFT.COM
17 JulCVE-2026-15709 Soupwebsocketextensiondeflate: libsoup: libsoup: websocket permessage-deflate unbounded decompression remote denial of serviceInformation published.MSRC.MICROSOFT.COM
17 JulCVE-2026-57433 Storable versions before 3.41 for Perl have a signed integer overflow when deserializing a crafted SX_HOOK recordInformation published.MSRC.MICROSOFT.COM
17 JulCVE-2026-15043 DBI::SQL::Nano versions from 1.42 before 1.651 for Perl have inverted <= and >= SQL operators on textInformation published.MSRC.MICROSOFT.COM
17 JulCVE-2026-15392 DBD::File versions before 1.651 for Perl do not ensure the table file is not a symlink to an untrusted locationInformation published.MSRC.MICROSOFT.COM
17 JulCVE-2026-59885 pyasn1: Quadratic complexity in OBJECT IDENTIFIER and RELATIVE-OID processing allows denial of serviceInformation published.MSRC.MICROSOFT.COM
17 Jul KEVCVE-2026-58644: Microsoft SharePoint Server Unauthenticated Remote Code Execution Vulnerability Exploited in the WildOverview On July 14, 2026, Microsoft published a security advisory addressing CVE-2026-58644 , a critical remote code execution (RCE) vulnerability affecting on-premises Microsoft SharePoint Server deployments. The vulnerability, which carries a CVSS v3.1 score of 9.8 (Critical),…RAPID7.COM
17 JulChromium: CVE-2026-15904 Use after free in OzoneThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
17 JulChromium: CVE-2026-15903 Out of bounds read and write in V8This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
17 JulChromium: CVE-2026-15899 Use after free in CameraCaptureThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
17 JulChromium: CVE-2026-15900 Use after free in GPUThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
17 JulChromium: CVE-2026-15901 Use after free in NetworkThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
17 JulChromium: CVE-2026-15902 Use after free in CastThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
17 JulChromium: CVE-2026-15905 Use after free in AuraThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
17 JulCVE-2026-63030: wp2shell a Critical Remote Code Execution Vulnerability in WordPress CoreOverview On July 17, 2026, a GitHub Security Advisory was published for CVE-2026-63030 , a critical unauthenticated remote code execution vulnerability affecting WordPress Core . WordPress Core. While the official GitHub security advisory classifies the severity as Critical, the …RAPID7.COM
16 JulZoom Patches Critical Windows Flaw That Could Enable Account TakeoverZoom has released security updates for a critical security flaw impacting Zoom Workplace for Windows that could facilitate account takeover. The vulnerability, tracked as CVE-2026-53412 (CVSS score: 9.8), affects Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Z…THEHACKERNEWS.COM
16 JulZoom Fixes CVE-2026-53412, a Critical Account Takeover BugZoom warns of a critical Windows flaw, tracked as CVE-2026-53412, that could let attackers take over accounts without authentication. Zoom has fixed a critical Windows vulnerability, tracked as CVE-2026-53412 (CVSS score of 9.8) that could allow unauthenticated attackers to hijac…SECURITYAFFAIRS.COM
16 JulAge of Empires II patch fixes RCE bug exploitable through multiplayer lobbiesA recent update for Age of Empires II: Definitive Edition fixed a remote code execution (RCE) vulnerability that could have allowed attackers to compromise other players' systems through multiplayer. The flaw, tracked as CVE-2026-50663, stemmed from a relative path traversal bug …CYBERINSIDER.COM
16 JulVU#326070: SGLang contains a vulnerable pickle deserialization vulnerability through the expert-parallel subsystemOverview A Pickle deserialization vulnerability has been discovered within the SGLang project , enabling an attacker to perform remote code execution (RCE) on the target vulnerable server. In order for an attacker to exploit this vulnerability, the expert-parallel backup subsyste…KB.CERT.ORG
15 Jul KEVPatch Tuesday roundup: Microsoft fixes a monthly record 569 holes; SAP patches a critical memory corruption bugEarlier this month Microsoft warned that, because the latest AI models can now help discover vulnerabilities, CSOs will see a higher volume of security updates every month. It wasn’t kidding. Today the company issued a record number of patches , with 59 rated as critical. And Mic…CSOONLINE.COM
15 JulSonicWall Issues Urgent SMA Patch Warning for Two Zero-Day ExploitsSonicWall SMA1000 zero-day vulnerabilities CVE-2026-15409 and CVE-2026-15410 can be exploited for remote code execution. The post SonicWall Issues Urgent SMA Patch Warning for Two Zero-Day Exploits appeared first on SecurityWeek .SECURITYWEEK.COM
15 JulTwo SonicWall SMA 1000 Zero-Days Exploited, One Could Enable Admin CommandsSonicWall has warned of active exploitation of two zero-day vulnerabilities impacting Secure Mobile Access (SMA) 1000 series appliances, one of which could be exploited to achieve arbitrary command execution. The vulnerabilities are listed below - CVE-2026-15409 (CVSS score: 10.0…THEHACKERNEWS.COM
15 JulCVE-2026-57432 Perl versions through 5.43.10 have an integer overflow in S_measure_struct leading to an out-of-bounds heap read in pack and unpackInformation published.MSRC.MICROSOFT.COM
15 JulCVE-2026-39822 Root escape via symlink plus trailing slash in osInformation published.MSRC.MICROSOFT.COM
15 JulCVE-2026-42505 Invoking Encrypted Client Hello privacy leak in crypto/tlsInformation published.MSRC.MICROSOFT.COM
15 JulCVE-2026-15028 Libarchive: heap overflow oob read while parsing a tar archive contains a pax extended headerInformation published.MSRC.MICROSOFT.COM
15 JulCVE-2026-57219 RabbitMQ: Unauthenticated disclosure of OAuth client credentials via an HTTP API endpoint with certain less common OAuth 2 configurationsInformation published.MSRC.MICROSOFT.COM
15 JulCVE-2026-13221 Perl versions through 5.43.9 produce silently incorrect regular expression matches when an alternation of more than 65535 fixed string branches is compiled into a trie in Perl_study_chunkInformation published.MSRC.MICROSOFT.COM
15 JulCVE-2026-59875 node-tar: Uncaught Exception DoS via NUL byte in PAX path/linkpath recordsInformation published.MSRC.MICROSOFT.COM
15 JulCVE-2026-59831 GitHub CLI `gh codespace jupyter` could allow remote code execution when connecting to a malicious CodespaceInformation published.MSRC.MICROSOFT.COM
15 JulCVE-2026-57220 RabbitMQ: Stream listener does not enforce configured frame-size limit during authentication, permitting unauth'd mem-exhaust DoSInformation published.MSRC.MICROSOFT.COM
15 JulCVE-2026-57217 RabbitMQ: Topic authorization can lead to cross-tenant routing-key bypassInformation published.MSRC.MICROSOFT.COM
15 JulCVE-2026-57213 RabbitMQ: Stored XSS federation management plugin via unsanitized consumer_tag renderingInformation published.MSRC.MICROSOFT.COM
15 JulCVE-2026-57216 RabbitMQ: AMQP 1.0, AMQP 0-9-1, Stream Protocol loopback enforcement can lead to remote guest sessions due to listener-address loopback checksInformation published.MSRC.MICROSOFT.COM
15 JulCVE-2026-57211 RabbitMQ: UNC SSRF affecting the management UI on WindowsInformation published.MSRC.MICROSOFT.COM
15 JulCVE-2026-57215 RabbitMQ: Direct-reply-to binding persistence can lead to unauthorized reply-channel injection and persistent phantomInformation published.MSRC.MICROSOFT.COM
15 JulAI-driven bug hunting fuels record Microsoft Patch TuesdayMicrosoft has released patches for 570+ vulnerabilities on July 2026 Patch Tuesday, including two that are being leveraged by attackers (CVE-2026-56155 and CVE-2026-56164), and one that was previouly disclosed (CVE-2026-50661). The release was once again followed by Nightmare Ecl…HELPNETSECURITY.COM
15 JulFirefox, Chrome, Adobe, and VMware Updates Fix Multiple Critical Security FlawsMozilla has released updates to address two critical flaws in Firefox for which it warned that exploit code has been published. The vulnerabilities are listed below - CVE-2026-15718, an invalid pointer in the JavaScript: WebAssembly component CVE-2026-15719, a site isolation in t…THEHACKERNEWS.COM
15 JulVU#725167: node-forge Signature Forgery Vulnerabilities in RSA-PKCS and ED25519 ImplementationsOverview Two distinct cryptographic signature verification vulnerabilities exist in Digital Bazaar node-forge, a widely used JavaScript library implementing cryptographic primitives for Node.js and browser environments. These vulnerabilities allow attackers to forge RSA (PKCS#1 v…KB.CERT.ORG
15 Jul KEVRapid7 MDR Team Discovers New SonicWall SMA1000 Zero Days being Actively Exploited (CVE-2026-15409, CVE-2026-15410)Overview On July 14, 2026, SonicWall published a security advisory addressing two vulnerabilities affecting SMA1000 Series remote access appliances, including the critical server-side request forgery (SSRF) vulnerability CVE-2026-15409 (CVSS 10.0) and the high-severity code injec…RAPID7.COM
15 Jul KEVCVE-2026-15409, CVE-2026-15410: SonicWall SMA 1000 zero-day vulnerabilities exploited in the wildSonicWall patched two recently exploited zero-day vulnerabilities in its SMA 1000 Series secure remote access appliances which may have been chained for unauthenticated remote code execution. Key takeaways CVE-2026-15409 and CVE-2026-15410 are a pair of exploited vulnerabilities …TENABLE.COM
15 JulVU#529388: Privilege escalation vulnerability via unprotected IOCTL interface in Pegatron Tdelo64.sysOverview A privilege escalation vulnerability exists in the tdeio64.sys driver due to an unprotected input/output control (IOCTL) dispatch routine that fails to validate the origin and permissions of user-supplied requests. An unprivileged local attacker can abuse exposed IOCTL d…KB.CERT.ORG
15 JulAL26-017 - Critical vulnerabilities impacting Microsoft SharePoint Server – CVE-2026-56164, CVE-2026-55040 and CVE-2026-58644CYBER.GC.CA
14 JulGovernments to enterprises: Improve your router security hygieneGlobal security agencies say enterprises must clean up their act as Russian government-sponsored attackers exploit weaknesses in routers. According to a new multinational cybersecurity advisory , cyberattackers continue to exploit inadequately-protected and/or poorly-configured n…CSOONLINE.COM
14 JulAI-powered breaches provide wake-up call for incident responseEnterprises have worked for years to improve detection and response times in the face of increasingly sophisticated attacks that relied on manual hacking and living-of-the-land techniques. AI is now threatening to undo those efforts. An increasing number of threat actors are auto…CSOONLINE.COM
14 JulCVE-2026-55040: Microsoft SharePoint JWT Token Authentication Bypass (FIXED)Overview Rapid7 Labs conducted a zero-day research project against Microsoft SharePoint, resulting in the discovery of two new vulnerabilities that, when chained together, achieve unauthenticated remote code execution (RCE) against a vulnerable SharePoint server. Today, both Rapi…RAPID7.COM
14 Jul KEVSonicWall SMA appliances targeted in zero-day attacks (CVE-2026-15409, CVE-2026-15410)SonicWall has fixed two actively exploited vulnerabilities (CVE-2026-15409, CVE-2026-15410) affecting its Secure Mobile Access (SMA) 1000 Series appliances, and is urging customer organizations to upgrade to a fixed firmare version and search for evidence of potential compromise.…HELPNETSECURITY.COM
14 Jul KEVMicrosoft’s July 2026 Patch Tuesday Addresses 569 CVEs (CVE-2026-56155, CVE-2026-56164)56 Critical 510 Important 3 Moderate 0 Low Microsoft addresses 569 CVEs in the largest Patch Tuesday release yet. This month’s release includes three zero-days, two of which were exploited in the wild. Microsoft patched 569 CVEs in its July 2026 Patch Tuesday release, with 56 rat…TENABLE.COM
14 JulSAP Patches CVSS 9.9 NetWeaver ABAP Flaw That Could Expose or Modify DataSAP has rolled out updates to address multiple vulnerabilities as part of its July 2026 security updates, including a critical flaw in SAP NetWeaver Application Server ABAP. The vulnerability in question is CVE-2026-44747 (CVSS score: 9.9), an out-of-bounds write flaw that allows…THEHACKERNEWS.COM
14 Jul KEVMicrosoft Patch Tuesday for July 2026 — Snort rules and prominent vulnerabilitiesMicrosoft has released its monthly security update for July 2026, which includes 622 vulnerabilities affecting a range of products, including 57 that Microsoft marked as "critical". Microsoft notes that two of the vulnerabilities disclosed this month have been exploited…TALOSINTELLIGENCE.COM
14 JulSonicWall warns of SMA1000 flaws exploited in zero-day attacks, patch nowSonicWall warns that threat actors have been exploiting two SMA1000 vulnerabilities, tracked as CVE-2026-15409 and CVE-2026-15410, in zero-day attacks and urges customers to install the newly released security updates. [...]BLEEPINGCOMPUTER.COM
13 Jul KEViCagenda and Balbooa Forms Joomla Flaws Reportedly Exploited as Zero-DaysThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two maximum-severity security flaws impacting iCagenda and Balbooa extensions for Joomla to its Known Exploited Vulnerabilities (KEV) catalog, following reports of zero-day exploitation in the wild. The vu…THEHACKERNEWS.COM
13 JulRabbitMQ flaws expose OAuth secrets, risk complete takeover of the brokerRabbitMQ has patched two access control vulnerabilities affecting the widely used open-source message broker that could expose enterprise application data and, in some deployments, allow attackers to gain complete control over the messaging infrastructure. The flaws, discovered b…CSOONLINE.COM
12 JulCVE-2026-15308 Incremental HTMLParser feed() allows CPU-exhaustion DoS via repeated unterminated markup declarationsInformation published.MSRC.MICROSOFT.COM
12 JulCVE-2026-59871 node-tar: Process crash via PAX numeric path type confusionInformation published.MSRC.MICROSOFT.COM
12 JulCVE-2026-59873 node-tar: Decompression/parse DoS via unlimited inputInformation published.MSRC.MICROSOFT.COM
12 JulCVE-2026-59874 node-tar: Negative tar entry size causes infinite loop in archive replaceInformation published.MSRC.MICROSOFT.COM
11 JulWeekly Metasploit Update: Exploits for FlowiseAI CSV Agent and MacOS Package KitMore AI, more software, more bugs! AI, it's all you hear about nowadays and everyone's got an opinion on it. Here at Metasploit, we care less about those opinions and more about the growing attack surface all this new software brings with it (yeehaw exploits!). Take for example t…RAPID7.COM
11 JulCVE-2026-59856 Vim: Arbitrary Code Execution via PHP Omni-CompletionInformation published.MSRC.MICROSOFT.COM
11 JulCVE-2026-20214 ClamAV FSG File Format Processing Out-of-Bounds Memory Corruption VulnerabilityInformation published.MSRC.MICROSOFT.COM
11 JulCVE-2026-20215 ClamAV 7Zip File Format Processing Out-of-Bounds Memory Corruption VulnerabilityInformation published.MSRC.MICROSOFT.COM
11 JulCVE-2026-20216 ClamAV InstallShield File Format Processing Resource Exhaustion VulnerabilityInformation published.MSRC.MICROSOFT.COM
11 JulCVE-2026-20217 ClamAV PESpin File Format Processing Out-of-Bounds Memory Corruption VulnerabilityInformation published.MSRC.MICROSOFT.COM
11 JulCVE-2026-20244 ClamAV DMG File Processing Denial of Service VulnerabilityInformation published.MSRC.MICROSOFT.COM
11 JulCVE-2026-59998 sshd in OpenSSH before 10.4 has an undocumented security-relevant behavior: GSSAPIStrictAcceptorCheck has no value if the server is in Windows Active Directory.Information published.MSRC.MICROSOFT.COM
11 JulCVE-2026-14380 DBI versions before 1.650 for Perl are vulnerable to code injection via caller-influenced ProfileInformation published.MSRC.MICROSOFT.COM
11 JulCVE-2026-14740 DBI versions before 1.650 for Perl read one byte out-of-bounds in preparse when deleting an initial SQL commentInformation published.MSRC.MICROSOFT.COM
11 JulCVE-2026-59926 Mistune: XSS via unescaped class option in Admonition directiveInformation published.MSRC.MICROSOFT.COM
11 JulCVE-2026-59925 inline_parser: quadratic-time parsing on long runs of `**x**` and `***x***` emphasis pairsInformation published.MSRC.MICROSOFT.COM
11 JulCVE-2026-59930 Mistune toc / TableOfContents directive: heading IDs use predictable `toc_N` numbering with no slugification, allowing collision with attacker-controlled `id="toc_N"` contentInformation published.MSRC.MICROSOFT.COM
11 JulCVE-2026-59890 setuptools: MANIFEST.in exclusion bypass in sdist via Unicode normalization collision (NFC/NFD) on macOS APFS/HFS+Information published.MSRC.MICROSOFT.COM
11 JulCVE-2026-58207 NATS Server: Remote crash via integer overflow in Connz paginationInformation published.MSRC.MICROSOFT.COM
11 JulCVE-2026-58251 NATS Server: Queue Subscribe Authz BypassInformation published.MSRC.MICROSOFT.COM
11 JulCVE-2026-58208 NATS Server: MQTT-over-WebSocket Path Can Crash WebSocket-Only JetStream Servers Before MQTT Is EnabledInformation published.MSRC.MICROSOFT.COM
11 JulCVE-2026-58252 NATS Server: Subscribe Authz Bypass via Wildcard-OverlapInformation published.MSRC.MICROSOFT.COM
11 JulCVE-2026-58209 NATS Server: MQTT retained and QoS replay bypass subscribe deny filtersInformation published.MSRC.MICROSOFT.COM
11 JulCVE-2026-20213 ClamAV PE File Format Processing Out-of-Bounds Memory Corruption VulnerabilityInformation published.MSRC.MICROSOFT.COM
11 JulCVE-2026-20243 ClamAV ALZ Archive Processing Denial of Service VulnerabilityInformation published.MSRC.MICROSOFT.COM
11 JulCVE-2026-14739 DBI versions before 1.650 for Perl have a heap overflow when preparsing SQL statements with an extreme number of placeholdersInformation published.MSRC.MICROSOFT.COM
11 JulCVE-2026-59928 Mistune block_parser: quadratic-time parsing on long lists of repeated reference-link definitionsInformation published.MSRC.MICROSOFT.COM
11 JulCVE-2026-59922 Mistune plugins/formatting: quadratic-time parsing on long runs of `~~x~~`, `==x==`, and `^^x^^` markers (strikethrough / mark / insert)Information published.MSRC.MICROSOFT.COM
11 JulCVE-2026-59869 js-yaml: YAML merge-key chains can force quadratic CPU consumptionInformation published.MSRC.MICROSOFT.COM
11 JulCVE-2026-58250 NATS Server: Pre-auth server crash via double INFO in leafnode handshakeInformation published.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14428 Insufficient validation of untrusted input in DawnThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13777 Insufficient validation of untrusted input in iOSWebThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13778 Use after free in WebUSBThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14394 Use after free in V8This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14396 Out of bounds read in ANGLEThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14395 Out of bounds write in V8This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14397 Out of bounds write in ANGLEThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14398 Use after free in ANGLEThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14399 Uninitialized Use in DawnThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14400 Out of bounds write in ANGLEThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14401 Insufficient validation of untrusted input in ANGLEThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14402 Uninitialized Use in ANGLEThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14403 Use after free in V8This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14405 Uninitialized Use in V8This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14404 Inappropriate implementation in PDFiumThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14406 Out of bounds read in V8This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14410 Inappropriate implementation in SkiaThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14407 Inappropriate implementation in V8This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14409 Inappropriate implementation in V8This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14412 Insufficient validation of untrusted input in ANGLEThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14408 Uninitialized Use in DawnThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14411 Insufficient validation of untrusted input in ANGLEThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14413 Uninitialized Use in ANGLEThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14415 Inappropriate implementation in V8This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14418 Uninitialized Use in ANGLEThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14417 Use after free in DawnThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14416 Out of bounds read in DawnThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14419 Use after free in SkiaThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14420 Out of bounds read and write in DawnThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14421 Uninitialized Use in DawnThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14422 Out of bounds read and write in TintThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14423 Type Confusion in TintThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14425 Use after free in ANGLEThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14426 Use after free in V8This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14427 Heap buffer overflow in SkiaThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14424 Use after free in DawnThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14429 Insufficient validation of untrusted input in SkiaThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14430 Integer overflow in V8This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14432 Use after free in V8This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14431 Type Confusion in V8This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14414 Insufficient validation of untrusted input in SkiaThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13785 Use after free in BluetoothThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13788 Use after free in FullscreenThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13791 Insufficient validation of untrusted input in DownloadsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13807 Use after free in ImportThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13795 Insufficient policy enforcement in Chrome for iOSThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13792 Use after free in TouchbarThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13805 Use after free in GFXThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13808 Insufficient data validation in Chrome for iOSThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13812 Insufficient validation of untrusted input in Chrome for iOSThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13809 Side-channel information leakage in Safe BrowsingThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13813 Insufficient validation of untrusted input in Chrome for iOSThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13816 Insufficient validation of untrusted input in File InputThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13822 Inappropriate implementation in ExtensionsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13819 Out of bounds read in ANGLEThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13825 Uninitialized Use in DawnThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13826 Inappropriate implementation in AutofillThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13827 Use after free in UpdaterThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13842 Incorrect security UI in Chrome for iOSThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13843 Insufficient validation of untrusted input in Chrome for iOSThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13833 Uninitialized Use in ANGLEThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13846 Use after free in USBThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13847 Insufficient validation of untrusted input in Chrome for iOSThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13850 Insufficient validation of untrusted input in Chrome for iOSThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13851 Insufficient validation of untrusted input in WebAppInstallsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13856 Insufficient validation of untrusted input in SpeechThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13852 Insufficient validation of untrusted input in WebAppInstallsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13863 Insufficient validation of untrusted input in CustomTabsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13866 Insufficient validation of untrusted input in InputThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13872 Insufficient validation of untrusted input in WebAppInstallsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13868 Inappropriate implementation in NetworkThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13870 Use after free in WebViewThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13878 Use after free in BluetoothThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13885 Use after free in SkiaThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13880 Use after free in USBThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13889 Insufficient validation of untrusted input in WebAuthenticationThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13892 Inappropriate implementation in Chrome for iOSThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13887 Insufficient policy enforcement in NFCThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13902 Inappropriate implementation in Chrome for iOSThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13904 Incorrect security UI in Safe BrowsingThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13905 Incorrect security UI in Chrome for iOSThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13907 Inappropriate implementation in iOSWebThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13908 Insufficient validation of untrusted input in OmniboxThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13910 Insufficient policy enforcement in WebXRThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13912 Incorrect security UI in Safe BrowsingThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13914 Inappropriate implementation in PasswordsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13913 Insufficient policy enforcement in AutofillThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13915 Use after free in Chrome for iOSThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13916 Inappropriate implementation in Chrome for iOSThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13917 Insufficient validation of untrusted input in Chrome for iOSThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13918 Use after free in Chrome for iOSThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13924 Insufficient validation of untrusted input in WebViewThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13923 Uninitialized Use in GPUThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13926 Insufficient validation of untrusted input in NetworkThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13927 Insufficient validation of untrusted input in UIThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13932 Inappropriate implementation in SharingThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13929 Insufficient validation of untrusted input in DevToolsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13936 Inappropriate implementation in PasswordsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13939 Insufficient validation of untrusted input in WebShareThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13944 Inappropriate implementation in DataTransferThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13943 Uninitialized Use in CSSThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13949 Insufficient policy enforcement in PaymentsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13946 Inappropriate implementation in ScriptInjectionsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13955 Insufficient validation of untrusted input in CustomTabsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13964 Insufficient policy enforcement in WebViewThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13969 Uninitialized Use in UIThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13974 Integer overflow in Safe BrowsingThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13975 Out of bounds read in ANGLEThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13980 Incorrect security UI in Chrome for iOSThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13994 Inappropriate implementation in Credential ManagementThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13983 Incorrect security UI in Chrome for iOSThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13981 Inappropriate implementation in Chrome for iOSThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13991 Insufficient validation of untrusted input in Chrome for iOSThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13992 Inappropriate implementation in UIThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13987 Incorrect security UI in MobileThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13997 Incorrect security UI in ExtensionsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13998 Incorrect security UI in File InputThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14028 Incorrect security UI in Chrome for iOSThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-13995 Insufficient validation of untrusted input in AutofillThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14005 Use after free in OmniboxThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14066 Insufficient validation of untrusted input in Chrome for iOSThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14067 Use after free in Chrome for iOSThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14075 Policy bypass in Chrome for iOSThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14099 Use after free in Chrome for iOSThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14096 Object lifecycle issue in InputThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14101 Insufficient policy enforcement in SandboxThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14114 Inappropriate implementation in WebAppInstallsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14126 Incorrect security UI in UIThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14123 Incorrect security UI in Chrome for iOSThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14128 Insufficient data validation in Chrome for iOSThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14382 Insufficient validation of untrusted input in ANGLEThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14136 Incorrect security UI in Chrome for iOSThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14137 Insufficient validation of untrusted input in Chrome for iOSThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14386 Out of bounds read in ANGLEThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14385 Heap buffer overflow in ANGLEThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14388 Out of bounds read in ANGLEThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14390 Use after free in ANGLEThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14393 Use after free in V8This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14391 Integer overflow in ANGLEThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
11 JulChromium: CVE-2026-14392 Out of bounds write in TintThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
10 JulCVE-2026-59818 etcd: gRPC client listener does not enforce `--client-crl-file` certificate revocationInformation published.MSRC.MICROSOFT.COM
10 JulCVE-2026-56289 Loop with Unreachable Exit Condition in GNU patchInformation published.MSRC.MICROSOFT.COM
10 JulThe business case for burning down security debt: A practical approach for CISOsSecurity leaders have made strong progress in visibility. Most organizations can now identify vulnerabilities across their applications, dependencies and development pipelines with far more consistency than in the past. Yet a fundamental imbalance remains: Vulnerabilities are bei…CSOONLINE.COM
10 Jul“GhostLock” flaw survived in the Linux kernel code for 15 yearsA Linux kernel vulnerability remained hidden in virtually every major Linux distribution for more than 15 years before being fixed earlier this year. The flaw, tracked as CVE-2026-43499 and dubbed GhostLock, can be exploited by an unprivileged local attacker to gain root privileg…CYBERINSIDER.COM
10 JulVU#564823: GNU Wget enables SSRF via unvalidated FTP PASV IPsOverview GNU Wget, versions 1.25.0 and earlier, contains a server-side request forgery (SSRF) vulnerability in its implementation of FTP passive mode. Because Wget does not properly validate IP addresses obtained from PASV responses, an attacker-controlled FTP endpoint can redire…KB.CERT.ORG
9 JulUnpatched Backdoor in Tenda Firmware Grants Admin Access to DevicesTracked as CVE-2026-11405, the vulnerability allows unauthenticated attackers to access a device's web management interface. The post Unpatched Backdoor in Tenda Firmware Grants Admin Access to Devices appeared first on SecurityWeek .SECURITYWEEK.COM
9 JulCVE-2026-53359 KVM: x86: Fix shadow paging use-after-free due to unexpected roleInformation published.MSRC.MICROSOFT.COM
9 JulCVE-2026-14355 ext/openssl: Memory corruption in openssl_encrypt with AES-WRAP-PADInformation published.MSRC.MICROSOFT.COM
9 JulCVE-2026-59997 internal-sftp in sshd in OpenSSH before 10.4 recognizes only the first 9 command-line arguments, which can be important if a later command-line argument would have helped to ensure the intended security properties of an SFTP connection.Information published.MSRC.MICROSOFT.COM
9 JulCVE-2026-59996 scp in OpenSSH before 10.4 may place a file in the parent directory of an intended directory when the copy occurs between two remote destinations.Information published.MSRC.MICROSOFT.COM
9 JulCVE-2026-59995 sftp in OpenSSH before 10.4 does not properly constrain the location of downloaded files when "sftp server:/path ." is used with an attacker-controlled server.Information published.MSRC.MICROSOFT.COM
9 JulCVE-2026-60001 sshd in OpenSSH before 10.4 does not always honor the minimum authentication delay.Information published.MSRC.MICROSOFT.COM
9 JulCVE-2026-60000 sshd in OpenSSH before 10.4 allows remote attackers to cause a denial of service (resource consumption from excessive authentication attempts) because MaxAuthTries was mishandled for GSSAPIAuthentication.Information published.MSRC.MICROSOFT.COM
9 JulCVE-2026-59999 In sshd in OpenSSH before 10.4, DisableForwarding=yes was supposed to take precedence over PermitTunnel=yes, but did not.Information published.MSRC.MICROSOFT.COM
9 JulCVE-2026-60002 ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a key re-exchange. (This outcome occurs only on the client side.)Information published.MSRC.MICROSOFT.COM
9 JulCVE-2026-56002 libXfont2 PCF Font Parsing Heap Buffer OverflowInformation published.MSRC.MICROSOFT.COM
9 JulCVE-2026-56000 xorg-x11-server / xwayland GLX contextTags Use-After-Free in CommonMakeCurrent()Information published.MSRC.MICROSOFT.COM
9 JulCVE-2026-38968 ntopng through 6.6 is vulnerable to Predictable Session Identifier which can lead to Session Hijacking. HTTP session identifiers in src/HTTPserver.cpp use weak time-seeded pseudo-randomness during session creation. As a result, fresh authenticated logins can receive deterministic or colliding session cookies under attacker-controlled timing.Information published.MSRC.MICROSOFT.COM
9 JulCVE-2026-38969 ruby webrick through v1.9.2 WEBrick reparses trailer Content-Length into canonical request state, enabling request smuggling.Information published.MSRC.MICROSOFT.COM
9 JulCVE-2026-54908 Pion DTLS: Denial of service via panic while parsing a crafted ECDHE_PSK ServerKeyExchange messageInformation published.MSRC.MICROSOFT.COM
9 JulCVE-2026-53354 arm64: errata: Mitigate TLBI errata on various Arm CPUsInformation published.MSRC.MICROSOFT.COM
9 JulCVE-2026-53345 KVM: Don't WARN if memory is dirtied without a vCPU when the VM is dyingInformation published.MSRC.MICROSOFT.COM
9 JulCVE-2026-53332 slimbus: qcom-ngd-ctrl: Register callbacks after creating the ngdInformation published.MSRC.MICROSOFT.COM
9 JulCVE-2026-53336 nvmem: layouts: onie-tlv: fix hang on unknown typesInformation published.MSRC.MICROSOFT.COM
9 JulCVE-2026-53327 debugobjects: Do not fill_pool() if pi_blocked_onInformation published.MSRC.MICROSOFT.COM
9 JulCVE-2026-53339 i2c: qcom-cci: Fix NULL pointer dereference in cci_remove()Information published.MSRC.MICROSOFT.COM
9 JulCVE-2026-8927 env-set cross-proxy Digest auth state leakInformation published.MSRC.MICROSOFT.COM
9 JulCVE-2026-56001 libXfont2 BitmapScaleBitmaps Integer Overflow Heap Buffer OverflowInformation published.MSRC.MICROSOFT.COM
9 JulCVE-2026-56003 libXfont2 computeProps Property Buffer Heap Buffer OverflowInformation published.MSRC.MICROSOFT.COM
9 JulCVE-2026-55999 xorg-server / xwayland glamor font atlas Heap Buffer OverflowInformation published.MSRC.MICROSOFT.COM
9 JulCVE-2026-14191 WinRAR / UnRAR RAR5 recovery-volume (.rev) out-of-bounds heap write in RecVolumes5::ReadHeaderInformation published.MSRC.MICROSOFT.COM
9 JulCVE-2026-53269 netfilter: synproxy: add mutex to guard hook reference countingInformation published.MSRC.MICROSOFT.COM
9 JulCVE-2026-47241 Net::IMAP: Denial of Service via incomplete raw argument validationInformation published.MSRC.MICROSOFT.COM
9 JulCVE-2026-53167 fuse: limit FUSE_NOTIFY_RETRIEVE to uptodate foliosInformation published.MSRC.MICROSOFT.COM
9 JulMicrosoft Patches RoguePlanet Defender Flaw That Can Grant SYSTEM PrivilegesMicrosoft has released security updates for a Defender vulnerability known as RoguePlanet, nearly a month after details of the flaw became public. The vulnerability, tracked as CVE-2026-50656 (CVSS score: 7.8), is a privilege escalation issue in the Microsoft Malware Protection E…THEHACKERNEWS.COM
9 JulMicrosoft Patches Defender ‘RoguePlanet’ VulnerabilityThe privilege escalation vulnerability tracked as CVE-2026-50656 has been patched with a Microsoft Malware Protection Engine update. The post Microsoft Patches Defender ‘RoguePlanet’ Vulnerability appeared first on SecurityWeek .SECURITYWEEK.COM
9 JulMicrosoft fixed Defender flaw RoguePlanet (CVE-2026-50656)Microsoft fixed RoguePlanet (CVE-2026-50656), a Defender flaw allowing local attackers to gain higher privileges through the Malware Protection Engine. Microsoft released security updates for RoguePlanet, a vulnerability tracked as CVE-2026-50656 (CVSS score of 7.8) affecting the…SECURITYAFFAIRS.COM
9 JulVU#734812: Xerte Online Toolkit contains an authentication bypass that allows for RCEOverview Two vulnerabilities have been discovered in Xerte Online Toolkits, an open-source e-learning authoring toolsuite intended for the creation of learning materials within a web browser. CVE-2026-14261 tracks the persistence of the /setup/ directory after installation, which…KB.CERT.ORG
9 JulMicrosoft releases fix for RoguePlanet Defender flaw (CVE-2026-50656)Microsoft has finally released a security update for its Microsoft Malware Protection Engine, which fixes CVE-2026-50656, the Windows Defender local privilege escalation vulnerability triggered by the RoguePlanet exploit. The vulnerability and the fix CVE-2026-50656 is due to imp…HELPNETSECURITY.COM
9 JulVU#152953: PayRange Android app version 7.0.7 contains multiple vulnerabilitiesOverview PayRange is a mobile payment app that allows users to pay for vending machines, laundromats, and other unattended machines using a smartphone with Bluetooth. Two vulnerabilities were discovered in version 7.0.7 of the PayRange app that is available in the Google Play sto…KB.CERT.ORG
8 JulScattered Spider squashed, Rogue Agent AI flaw, 16 year-old Linux bug and new phish hunts marketersCybersecurity Today host David Shipley covers how a newly unsealed U.S. complaint tied an alleged Scattered Spider member to a luxury retailer intrusion using a persistent Windows device ID, with prosecutors alleging help-desk social engineering, admin account takeover, data exfi…CYBERSECURITYTODAY.LIBSYN.COM
8 Jul15-Year-Old GhostLock Flaw Enables Root and Container Escape on Most Linux DistrosResearchers at Nebula Security have disclosed GhostLock (CVE-2026-43499), a 15-year-old Linux kernel flaw that lets any logged-in user take full root control of a machine that has not been patched. The vulnerable code has shipped by default in essentially ever…THEHACKERNEWS.COM
8 JulUbiquiti Patches Critical UniFi Flaws Across Connect, Talk, Access, Protect, and OSUbiquiti has shipped updates to address multiple critical security flaws impacting UniFi Connect, UniFi Talk, UniFi Access, UniFi Protect, and UniFi OS that could result in privilege escalation and arbitrary command execution. The list of vulnerabilities is as follows - CVE-2026-…THEHACKERNEWS.COM
8 JulVU#849433: Adalo Database API Enables Cross-App User Data Extraction via Over-Fetching and Missing Authorization ControlsOverview Adalo’s no‑code application platform exposes complete user records through its database API for all applications built on both V1 and V2. Due to a platform-level flaw, authenticated users can retrieve full user data belonging to any Adalo application, regardless of confi…KB.CERT.ORG
8 JulUbiquiti Patches Critical UniFi OS Flaws Allowing Command Injection and Privilege EscalationUbiquiti patched seven UniFi OS flaws, including critical CVE-2026-50746, which allows command injection in UniFi Connect Application. Ubiquiti released security updates for seven critical UniFi OS vulnerabilities, including a maximum-severity flaw, tracked as CVE-2026-50746 (CVS…SECURITYAFFAIRS.COM
7 JulInsignary Closes SBOM Accuracy Gap With Binary-Level Clarity for Regulatory RiskMost software composition analysis tools read what developers declare. Insignary Clarity’s patented binary-first platform analyzes what is actually built, shipped, and deployed — including the open-source components that never appear in any manifest. Insignary, Inc. , whose paten…CSOONLINE.COM
7 JulBeyondTrust Patches Critical Auth Bypass Flaws in Remote Support and PRABeyondTrust has released updates to address two critical security flaws affecting Remote Support (RS) and Privileged Remote Access (PRA) products that, if successfully exploited, could allow unauthenticated attackers to take control of susceptible devices. The vulnerabilities are…THEHACKERNEWS.COM
7 JulCERT/CC Warns of Hidden Admin Backdoor in Tenda Router FirmwareSeveral versions of firmware released by Chinese network device manufacturer Tenda have been found to embed an undocumented authentication backdoor that enables administrative access to the devices' web management interfaces, the CERT Coordination Center (CERT/CC) warned Monday. …THEHACKERNEWS.COM
7 JulCVE-2026-8932 incomplete mTLS config matching in conn reuseInformation published.MSRC.MICROSOFT.COM
7 JulCVE-2026-55952 TLS 1.3 server denial of service via malformed ClientHello pre-shared key extensionInformation published.MSRC.MICROSOFT.COM
7 JulCVE-2026-54886 SSH SFTP server denial of service via extended channel data infinite loopInformation published.MSRC.MICROSOFT.COM
7 JulCVE-2026-12480 Arbitrary HDF5 File Read via Virtual Dataset Bypass in keras-team/kerasInformation published.MSRC.MICROSOFT.COM
7 JulCVE-2026-14647 onnx onnxruntime old.cc convPoolShapeInference_opset19 out-of-boundsInformation published.MSRC.MICROSOFT.COM
7 JulCVE-2026-54891 Plaintext APPLICATION_DATA injected during TLS handshake delivered to client application post-handshake in sslInformation published.MSRC.MICROSOFT.COM
7 JulSuspected China-Aligned Hackers Exploit Roundcube Flaws Against UniversitiesA suspected China-aligned threat activity cluster has been observed exploiting Roundcube webmail software belonging to physics and engineering departments of U.S. and Canadian universities as part of a new campaign. The activity involves the exploitation of now-patched, critical …THEHACKERNEWS.COM
7 JulHP DeskJet 2800 printer zero-day flaw leaks Wi-Fi credentialsHP DeskJet 2800 series printers are affected by a newly disclosed vulnerability that allows anyone on the same network to access sensitive configuration data without authentication. The flaw, tracked as CVE-2026-13753, affects devices running firmware version TBP1CN2612AR or earl…CYBERINSIDER.COM
7 JulHidden Tenda Router Backdoor Grants Admin Access, No Patch AvailableCERT/CC warns an unpatched backdoor in several Tenda routers lets attackers bypass login and gain full admin access with a hidden password. CERT/CC published an alert documenting an undocumented authentication backdoor in multiple Tenda firmware versions, tracked as CVE-2026-1140…SECURITYAFFAIRS.COM
7 JulCritical Adobe ColdFusion Vulnerability Exploited in AttacksHackers are exploiting a recently patched critical vulnerability (CVE-2026-48282) in Adobe ColdFusion that carries a CVSS score of 10/10. The post Critical Adobe ColdFusion Vulnerability Exploited in Attacks appeared first on SecurityWeek .SECURITYWEEK.COM
7 Jul KEVAttackers exploit critical Adobe ColdFusion vulnerability (CVE-2026-48282)CVE-2026-48282, one of the maximum severity vulnerabilities patched in Adobe ColdFusion on June 30, 2026, has been targeted by attackers in the wild. Exploitation attempts were detected on July 2, through the honeypot sensors of cybersecurity threat-intelligence service KEVIntel,…HELPNETSECURITY.COM
7 JulPicus Autonomous Exposure Validation Platform validates real-world CVE exploitabilityPicus Security has launched the Picus Autonomous Exposure Validation Platform, built for a world where frontier AI has collapsed the time between disclosure and attack. Adversaries now weaponize new CVEs in hours, against a backdrop of around 132 published every day. A CVE drops;…HELPNETSECURITY.COM
7 JulCVE-2026-45638 Windows Ancillary Function Driver for WinSock Elevation of Privilege VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
7 JulCritical Gitea Flaw Under Active Exploitation, Researchers WarnAttackers are exploiting the critical Gitea vulnerability CVE-2026-20896 to bypass authentication with a single HTTP header and access vulnerable repositories and secrets. The post Critical Gitea Flaw Under Active Exploitation, Researchers Warn appeared first on SecurityWeek .SECURITYWEEK.COM
7 Jul16-year-old KVM flaw allows attackers to escape VMs and take over Linux serversA critical vulnerability in the Kernel-based Virtual Machine (KVM) module of the Linux kernel allows attackers with root access in a guest VM to execute arbitrary code on the host system. This violates the most important security boundary that cloud providers and enterprises rely…CSOONLINE.COM
7 JulCritical Gitea Docker Bug Under Active Exploitation Exposes Repositories and SecretsAttackers are exploiting a critical Gitea flaw (CVE-2026-20896) that bypasses authentication with a single HTTP header, exposing repositories and sensitive data. Sysdig researchers warn that attackers are actively exploiting a critical authentication bypass flaw, tracked as CVE-2…SECURITYAFFAIRS.COM
6 JulAI-Run Ransomware, New Oracle Critical Flaw, NetNut bustedAI-Run Ransomware, New Oracle 9.8 Flaw Exploited, NetNut Proxy Network Busted, and Pegasus Hits EU Spyware Investigator This episode covers researchers' report of "Jade Puffer," the first ransomware attack run end-to-end by an autonomous AI agent, which exploited a patched Langfl…CYBERSECURITYTODAY.LIBSYN.COM
6 JulBad Epoll Flaw Gives Attackers Root Access on Linux and AndroidBad Epoll (CVE-2026-46242) lets local attackers gain root on Linux and Android. The flaw was missed by AI but found by a security researcher. A newly disclosed Linux kernel vulnerability, named Bad Epoll (CVE-2026-46242), allows a local attacker with no special privileg…SECURITYAFFAIRS.COM
6 JulThis AI agent autonomously hacked a network, adapted on the fly, and demanded a ransomA fully autonomous AI agent conducted an end-to-end cyber intrusion and extortion campaign after exploiting a vulnerable Langflow server, demonstrating how large language models could accelerate ransomware operations, according to research published by Sysdig. Sysdig detailed the…CSOONLINE.COM
6 JulMax severity Adobe ColdFusion flaw now exploited in attacksAttackers are now exploiting a maximum-severity Adobe ColdFusion vulnerability tracked as CVE-2026-48282, the Canadian Center for Cyber Security (CCCS) warned on Thursday. [...]BLEEPINGCOMPUTER.COM
6 JulThreat Actors Probe Gitea Docker Flaw CVE-2026-20896 13 Days After DisclosureThreat actors have been observed attempting to exploit a recently patched critical security flaw in Gitea Docker images, according to Sysdig. The vulnerability in question is CVE-2026-20896 (CVSS score: 9.8), a vulnerability that stems from the DevOps platform trusting the "X-WEB…THEHACKERNEWS.COM
6 JulVU#828543: HP Deskjet 2800 Printer Series Webservers contain Missing Authorization VulnerabilityOverview HP Printers in the Deskjet 2800 Series running firmware version <=TBP1CN2612AR contain a missing authorization vulnerability tracked as CVE-2026-13753. This vulnerability allows unauthenticated access to the printer's webserver API endpoints, exposing Wi-Fi credential…KB.CERT.ORG
6 Jul16-Year-Old Linux KVM Flaw Lets Guest VMs Escape to Host on Intel and AMD x86 SystemsA use-after-free bug in Linux's KVM hypervisor can be triggered from a guest virtual machine to corrupt the shadow-page state of the host kernel that runs it. Dubbed 'Januscape' and tracked as CVE-2026-53359, the flaw sits in the shadow MMU code that KVM shares across both I…THEHACKERNEWS.COM
6 JulVU#213560: Tenda firmware (multiple versions) contains hidden authentication backdoorOverview Several versions of Tenda firmware contain an undocumented authentication backdoor that grants administrative access to the devices' web management interfaces. An attacker can expoit this vulnerability, tracked as CVE-2026-11405, to bypass the password verification proce…KB.CERT.ORG
6 Jul KEVAdobe ColdFusion flaw CVE-2026-48282 now exploited in the wildAttackers are exploiting the critical Adobe ColdFusion flaw CVE-2026-48282, which allows remote code execution on unpatched servers. Attackers have started exploiting CVE-2026-48282, a maximum-severity vulnerability in Adobe ColdFusion. The flaw is a path traversal issue that cou…SECURITYAFFAIRS.COM
4 JulNew "Bad Epoll" Linux Kernel Flaw Lets Unprivileged Users Gain Root, Hits AndroidA newly disclosed Linux kernel flaw called Bad Epoll (CVE-2026-46242) lets an ordinary user with no special access take full control of a machine as root. It affects Linux desktops, servers, and Android, and a fix is out. Bad Epoll sits in the same small stretch of kernel code wh…THEHACKERNEWS.COM
4 JulCVE-2026-53223 net: guard timestamp cmsgs to real error queue skbsInformation published.MSRC.MICROSOFT.COM
3 JulRansomware Groups Turn to Citrix Bleed 2, BYOVD, and Supply Chain CredentialsThreat actors associated with the Anubis ransomware operation have been observed exploiting the Citrix Bleed 2 (CVE-2025-5777) vulnerability to obtain initial access. "Although tactics differ between affiliates, common patterns emerged in tradecraft through use of legitimate Remo…THEHACKERNEWS.COM
3 JulCVE-2026-56149 Allocation of Resources Without Limits or Throttling in Elasticsearch Leading to Denial of ServiceInformation published.MSRC.MICROSOFT.COM
3 JulCVE-2026-14258 Dhcpcd: dhcpcd infinite loop and out-of-bounds read via zero-length ipv6 nd option in router advertisement handlingInformation published.MSRC.MICROSOFT.COM
3 JulCVE-2026-49090 Uncontrolled Resource Consumption in Elasticsearch Leading to Denial of ServiceInformation published.MSRC.MICROSOFT.COM
3 JulCVE-2026-53357 Bluetooth: fix UAF in l2cap_sock_cleanup_listen() vs l2cap_conn_del()Information published.MSRC.MICROSOFT.COM
3 JulCVE-2026-53043 ocfs2/dlm: validate qr_numregions in dlm_match_regions()Information published.MSRC.MICROSOFT.COM
3 JulCVE-2026-52911 ksmbd: scope conn->binding slowpath to bound sessions onlyInformation published.MSRC.MICROSOFT.COM
3 JulCVE-2026-53045 memory: tegra124-emc: Fix dll_change checkInformation published.MSRC.MICROSOFT.COM
3 JulCVE-2026-53039 ocfs2: validate group add input before cachingInformation published.MSRC.MICROSOFT.COM
3 JulCVE-2026-53046 ksmbd: fix use-after-free from async crypto on Qualcomm crypto engineInformation published.MSRC.MICROSOFT.COM
3 JulCVE-2026-53048 gfs2: prevent NULL pointer dereference during unmountInformation published.MSRC.MICROSOFT.COM
3 JulCVE-2026-12912 Libtiff: libtiff: heap-based buffer overflow via crafted pixarlog-compressed tiff imageInformation published.MSRC.MICROSOFT.COM
3 JulCVE-2026-14164 Libarchive: double-free vulnerability in rar5 decompression logic via dangling filtered_buf pointer in init_unpack()Information published.MSRC.MICROSOFT.COM
3 JulCVE-2026-53195 USB: serial: io_ti: fix heap overflow in build_i2c_fw_hdr()Information published.MSRC.MICROSOFT.COM
3 JulCVE-2026-53052 ASoC: qcom: qdsp6: topology: check widget type before accessing dataInformation published.MSRC.MICROSOFT.COM
3 JulCVE-2026-53098 wifi: mt76: mt7915: fix use-after-free bugs in mt7915_mac_dump_work()Information published.MSRC.MICROSOFT.COM
3 JulCVE-2026-52992 fs/adfs: validate nzones in adfs_validate_bblk()Information published.MSRC.MICROSOFT.COM
3 JulCVE-2026-53130 fs/omfs: reject s_sys_blocksize smaller than OMFS_DIR_STARTInformation published.MSRC.MICROSOFT.COM
3 JulCVE-2026-53016 crypto: ccp - copy IV using skcipher ivsizeInformation published.MSRC.MICROSOFT.COM
3 JulCVE-2026-52935 xfrm: espintcp: do not reuse an in-progress partial sendInformation published.MSRC.MICROSOFT.COM
3 JulCVE-2026-52944 ksmbd: fix FSCTL permission bypass by adding a permission check for FSCTL_SET_SPARSEInformation published.MSRC.MICROSOFT.COM
3 JulCVE-2026-4360 Tarfile.extract() doesn't fully respect filter parameterInformation published.MSRC.MICROSOFT.COM
3 JulCVE-2026-13757 P11-kit: stack exhaustion via unbounded recursion in rpc attribute parsingInformation published.MSRC.MICROSOFT.COM
3 JulCVE-2026-57585 MessagePack: Out-of-bounds read/crash on Unpacker reuse after caught errorInformation published.MSRC.MICROSOFT.COM
3 Jul KEVNew CitrixBleed-like NetScaler flaw sees exploit attempts in the wildCitrix NetScaler appliances have been a constant target for attackers in recent years, most recently through an information leak vulnerability dubbed CitrixBleed 3, the latest in a series of NetScaler memory overreads going back to 2023. This week, Citrix patched yet another Citr…CSOONLINE.COM
3 JulAI helps find flaws in FatFs library used in millions of devicesResearchers at runZero have disclosed seven security vulnerabilities in the widely used FatFs filesystem library, warning that the flaws could expose millions of embedded devices to attacks through malicious USB drives, SD cards, and, in some cases, firmware update mechanisms. Th…CYBERINSIDER.COM
2 JulSandbox bypass flaws in Cursor IDE highlight prompt injection as an RCE vectorResearchers have discovered two vulnerabilities in the widely used Cursor AI-enabled integrated development environment (IDE) that can be exploited through prompt injection to achieve remote code execution (RCE). The two flaws, tracked as CVE-2026-50548 and CVE-2026-50549 , allow…CSOONLINE.COM
2 Jul KEVCISA Warns of Actively Exploited Microsoft SharePoint VulnerabilityCISA says threat actors are exploiting a recently patched SharePoint remote code execution vulnerability (CVE-2026-45659). The post CISA Warns of Actively Exploited Microsoft SharePoint Vulnerability appeared first on SecurityWeek .SECURITYWEEK.COM
2 JulVU#639124: Multiple local privilege escalation vulnerabilities in Little Orbits GameFirst Anti-CheatOverview The GamersFirst Anti-Cheat (GFAC) driver GFAC.sys contains multiple local privilege escalations and denial-of-service vulnerabilities stemming from insecure handling of user-controlled input through a minifilter communication port. A local attacker can abuse these flaws …KB.CERT.ORG
2 JulAL26-015 - Critical vulnerability impacting Microsoft SharePoint Server – CVE-2026-45659CYBER.GC.CA
1 JulCitrix Patches Six NetScaler Flaws Allowing File Read and Denial-of-ServiceCitrix on Tuesday released security updates to address multiple flaws in NetScaler ADC (formerly Citrix ADC) and NetScaler Gateway (formerly Citrix Gateway) that could be exploited by an attacker to facilitate arbitrary file reads or trigger a denial-of-service (DoS) condition. T…THEHACKERNEWS.COM
1 JulCVE-2026-57062 CMS (Cryptographic Message Syntax) parsing in gpgsm in GnuPG through 2.5.20 mishandles the CMS format for AES-GCM because aes-ICVlen is supposed to be 12 bytes but 4 bytes is accepted. NOTE: this is related to CVE-2026-34182.Information published.MSRC.MICROSOFT.COM
1 JulCVE-2026-42055 NGINX ngx_http_proxy_v2_module and ngx_http_grpc_module vulnerabilityInformation published.MSRC.MICROSOFT.COM
1 JulCVE-2026-48779 ws: Memory exhaustion DoS from tiny fragments and data chunksInformation published.MSRC.MICROSOFT.COM
1 JulCVE-2026-58010 Glib: buffer over-read in glib/gvariant-serialiser.c via gvs_tuple_is_normal()Information published.MSRC.MICROSOFT.COM
1 JulCVE-2026-58015 Glib: path traversal in glib/gio/gdbusauthmechanismsha1.c via keyring_lookup_entry and mechanism_client_data_receiveInformation published.MSRC.MICROSOFT.COM
1 JulCVE-2026-58016 Glib: integer underflow in gio/gdbusintrospection.c via "g_dbus_node_info_new_for_xml"Information published.MSRC.MICROSOFT.COM
1 JulCVE-2026-58012 Glib: buffer over-read in g_regex_replace() via glib/gregex.c:string_append() and g_utf8_next_char()Information published.MSRC.MICROSOFT.COM
1 JulCVE-2026-58011 Glib: out-of-bounds read in glib/gdatetime.c:g_date_time_get_ymd via invalid gdatetimeInformation published.MSRC.MICROSOFT.COM
1 JulCVE-2026-58013 Glib: buffer over-read in glib/giochannel.c via "g_io_channel_read_line_backend"Information published.MSRC.MICROSOFT.COM
1 JulCVE-2026-58014 Glib: off-by-one error in glib/gkeyfile.c via "g_key_file_get_locale_string_list"Information published.MSRC.MICROSOFT.COM
1 JulCVE-2026-13322 Kubevirt: virt-handler-rhel9: kubevirt: unbounded virtio-serial readline in virt-handler causes oom denial of serviceInformation published.MSRC.MICROSOFT.COM
1 JulCVE-2026-13208 Kubevirt: virt-handler-rhel9: kubevirt: virt-handler notify server trusts vmi identity from unauthenticated grpc request bodyInformation published.MSRC.MICROSOFT.COM
1 JulCVE-2026-13218 Kubevirt: kubevirt: symlink following in writetocachedfile allows host file overwrite from virt-launcherInformation published.MSRC.MICROSOFT.COM
1 JulCVE-2026-13325 Virt-handler-rhel9: kubevirt: kubevirt: disabletls migration setting removes authentication, exposing unauthenticated virtqemud proxy on all interfacesInformation published.MSRC.MICROSOFT.COM
1 JulCVE-2026-57918 libnfs through 6.0.2 before 935b8db has an xid integer underflow in READ_IOVEC in rpc_read_from_socket in lib/socket.c during a connection to a crafted NFS server, when the expected pdu size exceeds the absolute pdu size from the xid/record-marker.Information published.MSRC.MICROSOFT.COM
1 JulCVE-2026-6291 Bleichenbacher padding oracle in PKCS#7 KTRI RSA PKCS#1 v1.5 decryptionInformation published.MSRC.MICROSOFT.COM
1 JulCVE-2026-7532 iPAddress name constraints not enforced when WOLFSSL_IP_ALT_NAME is undefinedInformation published.MSRC.MICROSOFT.COM
1 JulCVE-2026-6450 CRL critical extension bypass in ParseCRL_ExtensionsInformation published.MSRC.MICROSOFT.COM
1 JulCVE-2026-55960 Un-negotiated Raw Public Key (RFC 7250) accepted in place of X.509, bypassing chain validationInformation published.MSRC.MICROSOFT.COM
1 JulCVE-2026-55964 Chain intermediate CA:TRUE without keyCertSign accepted as a signing CA (temporary CA exemption)Information published.MSRC.MICROSOFT.COM
1 JulCVE-2026-6329 PKCS#12 MAC verification uses attacker-controlled comparison lengthInformation published.MSRC.MICROSOFT.COM
1 JulCVE-2026-55961 wolfSSL_PKCS7_verify() reports success for degenerate (certs-only) PKCS#7 with no signerInformation published.MSRC.MICROSOFT.COM
1 JulCVE-2026-6678 Integer underflow in wc_PKCS7_DecryptOri handling crafted Other Recipient InfoInformation published.MSRC.MICROSOFT.COM
1 JulCVE-2026-6094 Heap buffer overread in wc_PKCS7_DecodeEnvelopedData parsing crafted PKCS7 EnvelopedDataInformation published.MSRC.MICROSOFT.COM
1 JulCVE-2026-6331 HMAC zero-length tag forgery in EVP_DigestVerifyFinalInformation published.MSRC.MICROSOFT.COM
1 JulCVE-2026-6330 ML-KEM ARM64 NEON ciphertext comparison only compares half of the inputInformation published.MSRC.MICROSOFT.COM
1 JulCVE-2026-6731 X.509 name constraint bypass via Subject CN treated as a DNS nameInformation published.MSRC.MICROSOFT.COM
1 JulCVE-2026-55958 Renesas TSIP TLS 1.3 transcript buffer out-of-bounds write in tsip_StoreMessageInformation published.MSRC.MICROSOFT.COM
1 JulCVE-2026-6325 Out-of-bounds write in SetSuitesHashSigAlgo on oversized signature algorithms listInformation published.MSRC.MICROSOFT.COM
1 JulCVE-2026-10592 Wildcard DNS SAN bypasses CA name-constraint checksInformation published.MSRC.MICROSOFT.COM
1 JulCVE-2026-10512 X25519 x86_64 assembly final reduction leaves non-canonical field elementInformation published.MSRC.MICROSOFT.COM
1 JulCVE-2026-8720 HMAC-BLAKE2 final discards message when key length exceeds block sizeInformation published.MSRC.MICROSOFT.COM
1 JulCVE-2026-10098 OCSP CertID serial-number length-confusion in wolfSSL_OCSP_resp_find_statusInformation published.MSRC.MICROSOFT.COM
1 JulCVE-2026-10097 ML-KEM-1024 x64 AVX2 incomplete cipher text comparison enables IND-CCA2 break and static private-key recoveryInformation published.MSRC.MICROSOFT.COM
1 JulCVE-2026-11310 X.509 trust-chain bypass in wolfSSL_X509_verify_cert() via untrusted intermediate anchoringInformation published.MSRC.MICROSOFT.COM
1 JulCVE-2026-13595 Util-linux: util-linux: heap use-after-free in libblkid nested partition probingInformation published.MSRC.MICROSOFT.COM
1 JulCVE-2026-13318 Virt-api-rhel9: kubevirt: kubevirt: ssrf in virt-api port-forward via unvalidated guest-agent-reported ipInformation published.MSRC.MICROSOFT.COM
1 JulCVE-2026-57231 Podman: Malformed Image can trick podman run into leaking host environment variables into the containerInformation published.MSRC.MICROSOFT.COM
1 JulCVE-2026-11703 Missing SNI/ALPN binding on stateful (session-ID) TLS session resumptionInformation published.MSRC.MICROSOFT.COM
1 JulCVE-2026-55967 AES-GCM streaming APIs do not reject >64 GiB cumulative single messages, enabling counter wrap and keystream reuseInformation published.MSRC.MICROSOFT.COM
1 JulCVE-2026-55962 TLS 1.3 post-handshake authentication: server accepts Finished without client Certificate/CertificateVerifyInformation published.MSRC.MICROSOFT.COM
1 JulCVE-2026-11999 X.509 trust-chain bypass via path-depth exhaustion in wolfSSL_X509_verify_cert()Information published.MSRC.MICROSOFT.COM
1 JulCVE-2026-7511 PKCS7_verify signer confusion allows forged signatures to be acceptedInformation published.MSRC.MICROSOFT.COM
1 JulCVE-2026-6091 Partial-chain verification accepts untrusted intermediate as trust anchorInformation published.MSRC.MICROSOFT.COM
1 JulCVE-2026-12340 Out-of-bounds heap read in SM2/SM3 certificate Subject Key Identifier computationInformation published.MSRC.MICROSOFT.COM
1 JulCVE-2026-6092 Encrypt-then-MAC could fall back to MAC-then-Encrypt when HAVE_ENCRYPT_THEN_MAC is configuredInformation published.MSRC.MICROSOFT.COM
1 JulCVE-2026-6412 Continued acceptance of SHA-1/MD5 digests in certificate processingInformation published.MSRC.MICROSOFT.COM
1 JulCVE-2026-7531 Use-after-free in PQC hybrid key-share handlingInformation published.MSRC.MICROSOFT.COM
1 JulCVE-2026-11625 Bytes::Random::Secure versions through 0.29 for Perl share internal state across forked processesInformation published.MSRC.MICROSOFT.COM
1 JulCISA Warns BlueHammer Flaw Is Now Exploited in Ransomware AttacksCISA confirms BlueHammer (CVE-2026-33825) is now used in ransomware attacks to gain SYSTEM privileges through Microsoft Defender. BlueHammer, tracked as CVE-2026-33825, has moved from proof-of-concept noise to real ransomware attacks in the wild, the US CISA confirms. BlueHammer …SECURITYAFFAIRS.COM
1 JulProgress Kemp LoadMaster Pre-Auth RCE Flaw Faces Active Exploitation AttemptsA recently disclosed critical security flaw impacting Progress Kemp LoadMaster is seeing active exploitation attempts, according to an advisory from eSentire's Threat Response Unit (TRU). The Canadian cybersecurity company said it identified exploitation attempts targeting CVE-20…THEHACKERNEWS.COM
1 JulCritical Cursor Flaws Could Let Prompt Injection Escape Sandbox and Run CommandsTwo flaws in Cursor, an AI code editor, could let a single, ordinary-looking prompt break out of the editor's safety sandbox and run any command on a developer's computer. There is no click to fall for and no approval box to ignore. Cato AI Labs found the pair and named them…THEHACKERNEWS.COM
1 Jul KEVOracle E-Business Suite Flaw Under Active Attack, 950 Systems ExposedOracle E-Business Suite flaw CVE-2026-46817 is under active attack, with about 950 vulnerable internet-facing instances still exposed. This week, Defused Cyber researchers warned that a critical vulnerability in Oracle E-Business Suite, tracked as CVE-2026-46817, is being activel…SECURITYAFFAIRS.COM
30 Jun KEVOracle E-Business Suite Flaw CVE-2026-46817 Actively Exploited in the WildA critical security flaw impacting Oracle E-Business Suite has come under active exploitation in the wild, according to Defused Cyber. The vulnerability, tracked as CVE-2026-46817 (CVSS score: 9.8), refers to an improper privilege management and authentication flaw in Oracle Paym…THEHACKERNEWS.COM
30 JunApple Patches 30+ iOS, macOS, Safari Flaws, Including AI-Discovered WebKit BugsApple on Monday released security updates for iOS, macOS, and the Safari web browser to address over three dozen flaws, including four vulnerabilities in WebKit that were discovered using artificial intelligence (AI) tools like Anthropic Claude and OpenAI Codex Security. The WebK…THEHACKERNEWS.COM
30 JunCVE-2026-54369 acl < 2.4.0 Symlink Traversal Privilege Escalation via libacl FunctionsInformation published.MSRC.MICROSOFT.COM
30 JunCVE-2026-54371 attr < 2.6.0 Symlink Traversal Privilege Escalation via getfattr/setfattrInformation published.MSRC.MICROSOFT.COM
30 JunCVE-2026-53325 agp/amd64: Fix broken error propagation in agp_amd64_probe()Information published.MSRC.MICROSOFT.COM
30 JunProgress Kemp LoadMaster Flaw Could Let Attackers Run Root Commands Pre-AuthA critical vulnerability in Progress Kemp LoadMaster can let an unauthenticated attacker execute arbitrary commands as root on the appliance by sending a crafted request to its API. The flaw, tracked as CVE-2026-8037, carries a CVSS score of 9.8 according to ZDI. A patc…THEHACKERNEWS.COM
30 Jun KEVAttackers actively exploit the Oracle E-Business Suite flaw CVE-2026-46817Attackers are exploiting a critical flaw in Oracle E-Business Suite, CVE-2026-46817, that allows remote, unauthenticated attackers to take over Oracle Payments. A critical vulnerability in Oracle E-Business Suite, tracked as CVE-2026-46817, is being actively exploited in the wild…SECURITYAFFAIRS.COM
30 JunSimpleHelp vulnerability exploited to deliver mighty Djinn Stealer (CVE-2026-48558)Attackers are exploiting CVE-2026-48558, a recently patched authentication bypass vulnerability in SimpleHelp RMM, to drop the novel Djinn Stealer malware on victim computers. The malware is capable of targeting Windows, macOS, and Linux systems, and “collects credentials a…HELPNETSECURITY.COM
30 JunAttackers Exploit SimpleHelp CVE-2026-48558 to Deploy TaskWeaver and Djinn StealerAn unknown threat actor has been observed exploiting a recently disclosed maximum-severity security flaw in SimpleHelp to deliver two previously unreported malware families, TaskWeaver and Djinn Stealer. The intrusion involves the exploitation of CVE-2026-48558 (CVSS score: 10.0)…THEHACKERNEWS.COM
30 Jun KEVBlueHammer Vulnerability Exploited in Ransomware AttacksThe Microsoft Defender vulnerability CVE-2026-33825 was exploited in the wild as a zero-day before patches were released. The post BlueHammer Vulnerability Exploited in Ransomware Attacks appeared first on SecurityWeek .SECURITYWEEK.COM
30 JunOracle E-Business Suite Payments flaw under attack (CVE-2026-46817)Exploitation attempts targeting a critical vulnerability (CVE-2026-46817) in Oracle Payments, the payment-processing module within Oracle’s E-Business Suite (EBS), have been spotted over the weekend, threat intelligence company Defused warned on Monday. The detected exploit…HELPNETSECURITY.COM
30 JunCVE-2026-42910 Windows Hotpatch Monitoring Service Elevation of Privilege VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
30 JunLangflow RCE Exploited to Deploy Monero Miner on Exposed AI App EndpointsThreat actors are continuing to exploit a critical Langflow vulnerability as part of fresh attacks designed to deliver a Monero cryptocurrency miner. The activity has been found to weaponize CVE-2026-33017 (CVSS score: 9.3), an unauthenticated remote code execution (RCE) vulnerab…THEHACKERNEWS.COM
30 JunCitrixBleed To Infinity And Beyond (Citrix NetScaler Pre-Auth Memory Overread CVE-2026-8451)Well, well, well - once again, the cat has dragged us in and spat us out. Today, we find ourselves questioning the reality we sit within. Must it be so predictable, and why us? “But watchTowr, what do you mean?” Well, if you’re here, you likely fitLABS.WATCHTOWR.COM
30 Jun KEVCitrix patches a new NetScaler flaw with echoes of CitrixBleedThe bulletin includes six NetScaler issues, but attention is centered on a high-severity flaw with similarities to earlier actively exploited bugs. The post Citrix patches a new NetScaler flaw with echoes of CitrixBleed appeared first on CyberScoop .CYBERSCOOP.COM
29 JunPublic PoC Released for Critical libssh2 CVE-2026-55200 Client-Side SSH FlawA public proof-of-concept is now out for CVE-2026-55200, a critical flaw in libssh2 that lets a malicious or compromised SSH server trigger memory corruption on a connecting client, with possible code execution. No credentials, no user interaction. The bug affects every release u…THEHACKERNEWS.COM
29 JunCVE-2026-52910 bpf: Free reuseport cBPF prog after RCU grace period.Information published.MSRC.MICROSOFT.COM
29 JunCVE-2026-52908 RDMA: During rereg_mr ensure that REREG_ACCESS is compatibleInformation published.MSRC.MICROSOFT.COM
29 JunCVE-2026-58050 libssh2 - Integer Overflow in publickey Subsystem Attribute AllocationInformation published.MSRC.MICROSOFT.COM
29 JunCVE-2026-58051 libssh2 - Free of Uninitialized Pointer in publickey List CleanupInformation published.MSRC.MICROSOFT.COM
29 JunCVE-2026-58058 Nmap - Integer Underflow in IPv6 Extension Header ParsingInformation published.MSRC.MICROSOFT.COM
29 JunCVE-2026-52909 ip6_vti: set netns_immutable on the fallback device.Information published.MSRC.MICROSOFT.COM
29 JunCVE-2026-58055 nghttp2 nghttpx - HTTP Request/Response Smuggling via Upgrade Request with Content-LengthInformation published.MSRC.MICROSOFT.COM
29 JunHackers now exploit critical Oracle E-Business flaw in attacksAttackers have begun exploiting a critical vulnerability (CVE-2026-46817) in the Oracle E-Business Suite (EBS) financial application, according to threat intelligence company Defused. [...]BLEEPINGCOMPUTER.COM
29 JunCritical SimpleHelp flaw exploited to deploy new stealer malwareHackers are exploiting a recently disclosed critical vulnerability (CVE-2026-48558) in SimpleHelp to deploy Djinn Stealer, a previously undocumented cross-platform information stealer targeting Windows, macOS, and Linux. [...]BLEEPINGCOMPUTER.COM
29 JunEnterprise Tech In, Shell Out (Progress Kemp LoadMaster Uninitialized Heap to Pre-Auth RCE CVE-2026-8037)Welcome back to another watchTowr Labs blog post. This time, we're looking at Progress Kemp LoadMaster, a load balancer that sits at the edge of a lot of enterprise networks. Edge appliances have a habit of becoming the way in rather than the thing keeping people out, andLABS.WATCHTOWR.COM
29 Jun'Djinn' Stealer Targets Cloud, AI CredentialsThe infostealer was delivered via CVE-2026-48558, a critical authentication bypass vulnerability in SimpleHelp, targeting credentials linking development and admin environments to wider enterprise systems.DARKREADING.COM
28 JunCVE-2026-46245 drm/amd/display: Fix dc_link NULL handling in HPD initInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-46252 regulator: core: fix locking in regulator_resolve_supply() error pathInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-46244 netfilter: nft_inner: Fix IPv6 inner_thoff desyncInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-12003 CPython >3.11 Insecure Input Validation resulting in privilege escalationInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-52953 iommu/vt-d: Fix oops due to out of scope accessInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-56405 libexpat before 2.8.2 has an integer overflow in getAttributeId.Information published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53005 af_unix: Drop all SCM attributes for SOCKMAP.Information published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53239 xfrm: policy: fix use-after-free on inexact bin in xfrm_policy_bysel_ctx()Information published.MSRC.MICROSOFT.COM
28 JunCVE-2026-52912 netfilter: nf_queue: hold bridge skb->dev while queuedInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-55653 Openssh: double free in red hat enterprise linux versions of openssh dh-gex client path during fips known-group validation leads to client-side denial of serviceInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-56406 libexpat before 2.8.2 has an integer overflow in XML_ParseBuffer because it lacked a check that was present in XML_Parse.Information published.MSRC.MICROSOFT.COM
28 JunCVE-2026-52931 batman-adv: tp_meter: avoid use of uninit sender varsInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-55655 Openssh: local mitm of x11 forwarding via abstract unix socket pre-binding in red hat enterprise linux openssh client versionsInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53147 thunderbolt: Validate XDomain request packet size before type castInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-9675 undici WebSocket client vulnerable to denial of service via cumulative fragment bypassInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53159 misc: fastrpc: fix DMA address corruption due to find_vma misuseInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-56131 libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_ResumeParser from within handlers in cases of a policy violation. Thus, a use-after-free can occur (similar to the CVE-2026-50219 situation).Information published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53274 net/smc: fix sleep-inside-lock in __smc_setsockopt() causing local DoSInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-52915 netfilter: ip6t_hbh: reject oversized option listsInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-9697 undici vulnerable to TLS certificate validation bypass via dropped requestTls in SOCKS5 ProxyAgentInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53230 net/mlx5: Fix slab-out-of-bounds in mlx5_query_nic_vport_mac_listInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-52956 libceph: Fix potential out-of-bounds access in __ceph_x_decrypt()Information published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53194 USB: serial: kl5kusb105: fix bulk-out buffer overflowInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53115 bus: fsl-mc: use generic driver_override infrastructureInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53161 misc: fastrpc: fix use-after-free of fastrpc_user in workqueue contextInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53163 locking/rtmutex: Skip remove_waiter() when waiter is not enqueuedInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53254 Bluetooth: RFCOMM: validate skb length in MCC handlersInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-52916 batman-adv: frag: disallow unicast fragment in fragmentInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53017 f2fs: fix data loss caused by incorrect use of nat_entry flagInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53089 bpf: Fix use-after-free in offloaded map/prog info fillInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53158 misc: fastrpc: Fix NULL pointer dereference in rpmsg callbackInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53120 PCI: use generic driver_override infrastructureInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53151 rxrpc: Fix the ACK parser to extract the SACK table for parsingInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-52934 batman-adv: tvlv: reject oversized TVLV packetsInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53267 netfilter: nft_ct: bail out on template ct in get evalInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53249 ipv4: restrict IPOPT_SSRR and IPOPT_LSRR optionsInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-52943 net: skbuff: fix missing zerocopy reference in pskb_carve helpersInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53139 drm/v3d: Skip CSD when it has zeroed workgroupsInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-52942 netfilter: nf_log: validate MAC header was set before dumping itInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-52957 libceph: Fix potential null-ptr-deref in decode_choose_args()Information published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53131 netfilter: require Ethernet MAC header before using eth_hdr()Information published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53198 ksmbd: fix use-after-free of a deferred file_lock on double SMB2_CANCELInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53214 ipv6: Fix a potential NPD in cleanup_prefix_route()Information published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53218 netfilter: nft_exthdr: fix register tracking for F_PRESENT flagInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53097 wifi: mt76: mt7996: fix use-after-free bugs in mt7996_mac_dump_work()Information published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53107 wifi: libertas: don't kill URBs in interrupt contextInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53166 futex/requeue: Prevent NULL pointer dereference in remove_waiter() on self-deadlockInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53179 staging: rtl8723bs: fix buffer over-read in rtw_update_protectionInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53228 ipv6: sit: reload inner IPv6 header after GSO offloadsInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53132 vsock/virtio: fix potential unbounded skb queueInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-52961 ceph: fix BUG_ON in __ceph_build_xattrs_blob() due to stale blob sizeInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53208 Bluetooth: L2CAP: reject BR/EDR signaling packets over MTUsigInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53010 ksmbd: fix use-after-free in smb2_open during durable reconnectInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-52937 tap: fix stack info leak in tap_ioctl() SIOCGIFHWADDRInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53109 powerpc/pgtable-frag: Fix bad page state in pte_frag_destroyInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53106 bpf: Do not allow deleting local storage in NMIInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53217 net: mvpp2: sync RX data at the hardware packet offsetInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53186 RDMA/srp: bound SRP_RSP sense copy by the received lengthInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53268 netfilter: conntrack_irc: fix possible out-of-bounds readInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53053 iommu/amd: Fix clone_alias() to use the original device's devidInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-52926 batman-adv: clear current gateway during teardownInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-52927 netfilter: ebtables: fix OOB read in compat_mtw_from_userInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53219 netfilter: x_tables: avoid leaking percpu counter pointersInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53157 net: phonet: free phonet_device after RCU grace periodInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53102 wifi: mt76: Fix memory leak after mt76_connac_mcu_alloc_sta_req()Information published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53247 net: ethernet: mtk_eth_soc: Fix use-after-free in metadata dst teardownInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-57452 Vim: Out-of-bounds Read with libsodium-encrypted FilesInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-55895 Vim: Vimscript Code Injection in netrw NetrwLocalRmFile() via crafted filenameInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53221 ip6_vti: fix incorrect tunnel matching in vti6_tnl_lookup()Information published.MSRC.MICROSOFT.COM
28 JunCVE-2026-55693 Vim: Out-of-bounds Write in Spell File Word CountInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53253 Bluetooth: bnep: reject short frames before parsingInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53196 USB: serial: io_ti: fix heap overflow in get_manuf_info()Information published.MSRC.MICROSOFT.COM
28 JunCVE-2026-57455 Vim: Stack out-of-bounds write in `spell_soundfold_sofo()` via an over-length `soundfold()` argumentInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53025 greybus: raw: fix use-after-free on cdev closeInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-57456 Vim: Arbitrary Code Execution via Python Omni-Completion DocstringsInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-57453 Vim: PowerShell Command Injection via Unescaped Filename in zip.vim ExtractionInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53215 net: mvpp2: refill RX buffers before XDP or skb useInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-55892 Vim: Out-of-bounds Write in Spell File Prefix DumpInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53154 mm/hugetlb: restore reservation on error in hugetlb folio copy pathsInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-52941 net/smc: avoid NULL deref of conn->lnk in smc_msg_event tracepointInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53263 6lowpan: fix off-by-one in multicast context address compressionInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-52947 net: qrtr: fix refcount saturation and potential UAF in qrtr_port_removeInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-52991 sched/psi: fix race between file release and pressure writeInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-52988 netfilter: nf_tables: join hook list via splice_list_rcu() in commit phaseInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-57454 Vim: Out-of-bounds Read with Text PropertiesInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-46243 smb: client: reject userspace cifs.spnego descriptionsInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-46254 AppArmor: Allow apparmor to handle unaligned dfa tablesInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2025-71313 PCI: endpoint: Add missing NULL check for alloc_workqueue()Information published.MSRC.MICROSOFT.COM
28 JunCVE-2026-43973 gun HTTP/1.1 response buffer has no size limit allowing server-controlled memory exhaustionInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-52948 i2c: dev: prevent integer overflow in I2C_TIMEOUT ioctlInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53136 drm/amd/display: Clamp VBIOS HDMI retimer register count to array sizeInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53227 net: openvswitch: fix possible kfree_skb of ERR_PTRInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-56407 libexpat before 2.8.2 has an integer overflow in doProlog that is related to storeEntityValue and entity textLen.Information published.MSRC.MICROSOFT.COM
28 JunCVE-2026-56404 libexpat before 2.8.2 has an integer overflow in addBinding.Information published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53207 mm/memory-failure: fix hugetlb_lock AA deadlock in get_huge_page_for_hwpoisonInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-52913 batman-adv: v: stop OGMv2 on disabled interfaceInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53027 fs/ntfs3: fix missing run load for vcn0 in attr_data_get_block_locked()Information published.MSRC.MICROSOFT.COM
28 JunCVE-2026-56403 libexpat before 2.8.2 has an integer overflow in storeAtts.Information published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53238 netlabel: validate unlabeled address and mask attribute lengthsInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-52921 netfilter: ipset: stop hash:* range iteration at endInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53024 greybus: raw: fix use-after-free if write is called after disconnectInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53270 ipvs: clear the svc scheduler ptr early on editInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-11525 undici vulnerable to Set-Cookie SameSite attribute downgrade via permissive substring matchingInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-56132 In libexpat before 2.8.2, there is a heap-based buffer overflow in doProlog in xmlparse.c because scaffold backing array reallocation is mishandled when there is data-structure sharing across parsers.Information published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53129 fs/mbcache: cancel shrink work before destroying the cacheInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-48142 NGINX ngx_http_charset_module vulnerabilityInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53242 ALSA: PCM: Fix wait queue list corruption in snd_pcm_drain() on linked streamsInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53236 tcp: restrict SO_ATTACH_FILTER to priv usersInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53118 vdpa: use generic driver_override infrastructureInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-56412 libexpat before 2.8.2 does not consider XML_TOK_DATA_CHARS in doCdataSection and thus lacks handler call depth tracking for various calls from within handlers in cases of a policy violation. Thus, a use-after-free can occur. NOTE: this issue exists because of an incomplete fix for CVE-2026-50219.Information published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53266 netfilter: bridge: make ebt_snat ARP rewrite writableInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53138 drm/amd/display: Bound VBIOS record-chain walk loopsInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53146 thunderbolt: Limit XDomain response copy to actual frame sizeInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53264 net/sched: act_api: use RCU with deferred freeing for action lifecycleInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-3195 Qemu-kvm: virtio-snd: heap buffer overflow in virtio_snd_pcm_in_cb (incomplete fix for cve-2024-7730)Information published.MSRC.MICROSOFT.COM
28 JunCVE-2026-3196 Qemu-kvm: virtio-snd: integer overflow leading to unbounded memory allocationInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53182 wifi: nl80211: reject oversized EMA RNR listsInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-11972 tarfile opened in streaming mode mishandles EOFInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-52924 sctp: purge outqueue on stale COOKIE-ECHO handlingInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-0864 Configuration Injection via Carriage Return (\r) in write() methodInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-55199 libssh2 - Pre-Authentication DoS via SSH_MSG_EXT_INFO HandlerInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-55200 libssh2 - Out-of-Bounds Write via Unchecked packet_length in transport.cInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53246 sctp: validate cached peer INIT chunk length in COOKIE_ECHO processingInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53150 thunderbolt: Reject zero-length property entries in validatorInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53149 thunderbolt: Bound root directory content to block sizeInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53181 vsock/vmci: fix sk_ack_backlog leak on failed handshakeInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53018 f2fs: avoid reading already updated pages during GCInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2025-15661 libssh2 - Heap Buffer Over-read via sftp_symlink() in sftp.cInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53184 udp: clear skb->dev before running a sockmap verdictInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-52923 ipc: limit next_id allocation to the valid ID rangeInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53178 staging: rtl8723bs: rtw_mlme: add bounds checks before ie_length subtractionInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53143 drm/amdkfd: Fix buffer overflow in SDMA queue checkpoint/restore on GFX11Information published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53209 Bluetooth: hci_sync: reject oversized Broadcast Announcement prependInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53275 ipv6: mcast: Fix use-after-free when processing MLD queriesInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53192 ALSA: timer: Fix UAF at snd_timer_user_params()Information published.MSRC.MICROSOFT.COM
28 JunCVE-2026-52960 ceph: put folios not suitable for writebackInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53133 RDMA/umem: Fix truncation for block sizes >= 4GInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-52919 batman-adv: fix tp_meter counter underflow during shutdownInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53078 bpf: Fix same-register dst/src OOB read and pointer leak in sock_opsInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-52946 fs/fcntl: fix SOFTIRQ-unsafe lock order in fasync signalingInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53255 Bluetooth: MGMT: validate advertising TLV before type checksInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53113 wifi: ath11k: fix memory leaks in beacon template setupInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53015 erofs: unify lcn as u64 for 32-bit platformsInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53265 dm cache policy smq: check allocation under invalidate lockInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-52922 batman-adv: dat: handle forward allocation errorInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53237 gpio: mvebu: fix NULL pointer dereference in suspend/resumeInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-52954 libceph: handle rbtree insertion error in decode_choose_args()Information published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53148 thunderbolt: Clamp XDomain response data copy to allocation sizeInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53000 netfilter: nat: use kfree_rcu to release opsInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53225 sctp: fix uninit-value in __sctp_rcv_asconf_lookup()Information published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53262 l2tp: pppol2tp: hold reference to session in pppol2tp_ioctl()Information published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53245 net/802/mrp: fix vector attribute parsing in mrp_pdu_parse_vecattrInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53199 hv_netvsc: use kmap_local_page in netvsc_copy_to_send_bufInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53258 wifi: fix leak if split 6 GHz scanning failsInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53160 misc: fastrpc: fix use-after-free race in fastrpc_map_createInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53226 gpio: rockchip: fix generic IRQ chip leak on removeInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-52930 ipc/shm: serialize orphan cleanup with shm_nattch updatesInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53135 drm/amd/display: Fix NULL deref and buffer over-read in SDP debugfsInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53080 net/sched: cls_fw: fix NULL dereference of "old" filters before change()Information published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53108 powerpc/64s: Fix unmap race with PMD migration entriesInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53091 net: pull headers in qdisc_pkt_len_segs_init()Information published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53232 net: phy: clean the sfp upstream if phy probing failsInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-52962 ceph: fix a buffer leak in __ceph_setxattr()Information published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53176 IB/isert: Reject login PDUs shorter than ISER_HEADERS_LENInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53070 sctp: disable BH before calling udp_tunnel_xmit_skb()Information published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53156 nvmem: core: fix use-after-free bugs in error pathsInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-57451 Vim: Out-of-bounds Read in Text Property CountInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53252 Bluetooth: fix memory leak in error path of hci_alloc_dev()Information published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53320 nilfs2: reject zero bd_oblocknr in nilfs_ioctl_mark_blocks_dirty()Information published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53296 mailbox: mailbox-test: free channels on probe errorInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53292 net: phonet: do not BUG_ON() in pn_socket_autobind() on failed bindInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53284 btrfs: only release the dirty pages io tree after successful writesInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53309 ocfs2/dlm: fix off-by-one in dlm_match_regions() region comparisonInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53304 scsi: sg: Resolve soft lockup issue when opening /dev/sgXInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53313 drm/amd/display: Avoid NULL dereference in dc_dmub_srv error pathsInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53306 tty: hvc_iucv: fix off-by-one in number of supported devicesInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53291 ALSA: hda/conexant: Fix missing error check for jack detectionInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53297 net: mana: Guard mana_remove against double invocationInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53293 drm/amdgpu: fix AMDGPU_INFO_READ_MMR_REGInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53294 mailbox: mailbox-test: don't free the reused channelInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53289 ice: fix NULL pointer dereference in ice_reset_all_vfs()Information published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53287 audit: fix incorrect inheritable capability in CAPSET recordsInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53303 f2fs: protect extension_list reading with sb_lock in f2fs_sbi_show()Information published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53314 padata: Put CPU offline callback in ONLINE section to allow failureInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-44889 WebOb: Location header normalization during redirect leads to open redirectInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53295 mailbox: add sanity check for channel arrayInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53279 drm/gma500/oaktrail_lvds: fix hang on init failureInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-53655 node-tar applies PAX size override to intermediary GNU long-name/long-link headers, causing tar parser interpretation differential (file smuggling)Information published.MSRC.MICROSOFT.COM
28 JunCVE-2024-42123 drm/amdgpu: fix double free err_addr pointer warningsInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2024-42155 s390/pkey: Wipe copies of protected- and secure-keysInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2024-42227 drm/amd/display: Fix overlapping copy within dml_core_mode_programmingInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2024-41085 cxl/mem: Fix no cxl_nvd during pmem region auto-assemblingInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2024-42158 s390/pkey: Use kfree_sensitive() to fix Coccinelle warningsInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2024-58012 ASoC: SOF: Intel: hda-dai: Ensure DAI widget is valid during paramsInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2024-50225 btrfs: fix error propagation of split biosInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2024-53056 drm/mediatek: Fix potential NULL dereference in mtk_crtc_destroy()Information published.MSRC.MICROSOFT.COM
28 JunCVE-2024-53084 drm/imagination: Break an object reference loopInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2024-50091 dm vdo: don't refer to dedupe_context after releasing itInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2024-50090 drm/xe/oa: Fix overflow in oa batch bufferInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2024-50102 x86: fix user address masking non-canonical speculation issueInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2024-50178 cpufreq: loongson3: Use raw_smp_processor_id() in do_service_request()Information published.MSRC.MICROSOFT.COM
28 JunCVE-2024-53051 drm/i915/hdcp: Add encoder check in intel_hdcp_get_capabilityInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2024-27010 net/sched: Fix mirred deadlock on device recursionInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2024-26962 dm-raid456, md/raid456: fix a deadlock for dm-raid456 while io concurrent with reshapeInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2024-27079 iommu/vt-d: Fix NULL domain on device releaseInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2024-53187 io_uring: check for overflows in io_pin_pagesInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2024-56544 udmabuf: change folios array from kmalloc to kvmallocInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2024-56702 bpf: Mark raw_tp arguments with PTR_MAYBE_NULLInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2024-56742 vfio/mlx5: Fix an unwind issue in mlx5vf_add_migration_pages()Information published.MSRC.MICROSOFT.COM
28 JunCVE-2024-49908 drm/amd/display: Add null check for 'afb' in amdgpu_dm_update_cursor (v2)Information published.MSRC.MICROSOFT.COM
28 JunCVE-2024-49918 drm/amd/display: Add null check for head_pipe in dcn32_acquire_idle_pipe_for_head_pipe_in_layerInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2024-49990 drm/xe/hdcp: Check GSC structure validityInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2024-47703 bpf, lsm: Add check for BPF LSM return valueInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2024-49910 drm/amd/display: Add NULL check for function pointer in dcn401_set_output_transfer_funcInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2024-49916 drm/amd/display: Add NULL check for clk_mgr and clk_mgr->funcs in dcn401_init_hwInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2024-49970 drm/amd/display: Implement bounds check for stream encoder creation in DCN401Information published.MSRC.MICROSOFT.COM
28 JunCVE-2024-50004 drm/amd/display: update DML2 policy EnhancedPrefetchScheduleAccelerationFinal DCN35Information published.MSRC.MICROSOFT.COM
28 JunCVE-2024-46681 pktgen: use cpus_read_lock() in pg_net_init()Information published.MSRC.MICROSOFT.COM
28 JunCVE-2024-46701 libfs: fix infinite directory reads for offset dirInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2024-46775 drm/amd/display: Validate function returnsInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2024-44956 drm/xe/preempt_fence: enlarge the fence critical sectionInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2024-46698 video/aperture: optionally match the device in sysfb_disable()Information published.MSRC.MICROSOFT.COM
28 JunCVE-2024-46778 drm/amd/display: Check UnboundedRequestEnabled's valueInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2024-46808 drm/amd/display: Add missing NULL pointer check within dpcd_extend_address_rangeInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2024-46842 scsi: lpfc: Handle mailbox timeouts in lpfc_get_sfp_infoInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2025-4035 Libsoup: cookie domain validation bypass via uppercase characters in libsoupInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2024-43886 drm/amd/display: Add null check in resource_log_pipe_topology_updateInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2024-43824 PCI: endpoint: pci-epf-test: Make use of cached 'epc_features' in pci_epf_test_core_init()Information published.MSRC.MICROSOFT.COM
28 JunCVE-2023-6606 Kernel: out-of-bounds read vulnerability in smbcalcsizeInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2025-21833 iommu/vt-d: Avoid use of NULL after WARN_ON_ONCEInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2025-40213 Bluetooth: MGMT: fix crash in set_mesh_sync and set_mesh_completeInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2026-0989 Libxml2: unbounded relaxng include recursion leading to stack overflowInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2025-68304 Bluetooth: hci_core: lookup hci_conn on RX path on protocol sideInformation published.MSRC.MICROSOFT.COM
28 JunCVE-2024-24864 Race condition vulnerability in Linux kernel media/dvb-core in dvbdmx_write()Information published.MSRC.MICROSOFT.COM
27 JunBypassing Windows authentication reflection mitigations for SYSTEM shells - Part ②In part 1 of this blogpost series, we proved our initial theory that the patch for CVE-2025-33073 was insufficient, by disclosing a trivial NTLM reflection vulnerability leading to LPE. In this second part, we turn to Kerberos and explain how we achieved a full-blown RCE primitiv…SYNACKTIV.COM
27 JunBypassing Windows authentication reflection mitigations for SYSTEM shells - Part 1A year ago, authentication reflection vulnerabilities resurfaced as a powerful attack vector through the discovery of CVE-2025-33073 by several security researchers, including us. This logical vulnerability allowed taking over almost any Windows machine without any user interacti…SYNACKTIV.COM
27 JunPaint it blue: Attacking the bluetooth stackBluetooth has always been an attractive target to attackers since it is present almost everywhere (TV, automotive charger, connected fridge, etc.). This is especially true on mobile devices, as it runs as a privileged process with a potential access to microphone, address book, e…SYNACKTIV.COM
27 JunSniffing Authentication References on macOSCVE-2017-7170 was a local priv-esc vulnerability that affected OSX/macOS for over a decade! Here (for the first time!), we dive into the technical details of finding the bug, the core flaw, and exploitation.OBJECTIVE-SEE.ORG
27 JunRootpipe Reborn (Part II)@CodeColorist continues writing about bugs, such as CVE-2019-8521 and CVE-2019-8565 that provide a mechanism to elevate privileges to root on macOS.OBJECTIVE-SEE.ORG
27 JunFrom the Top to the Bottom; Tracking down CVE-2017-7149High Sierra suffered from a nasty bug (CVE-2017-7149) that afforded local attackers access to the contents of encrypted APFS volumes.OBJECTIVE-SEE.ORG
27 JunCVE-2015-3673: Goodbye Rootpipe...(for now?)Details on bypassing Apple's original rootpipe patchOBJECTIVE-SEE.ORG
27 JunDirtyClone: Fourth Linux Kernel Flaw in Six Weeks Escalates to RootDirtyClone: a Linux kernel privilege escalation that silently rewrites executables in memory, leaving no disk trace. Patch now. JFrog Security Research published a working exploit walkthrough on June 25 for CVE-2026-43503 (CVSS score of 8.8), a Linux kernel privilege escalation t…SECURITYAFFAIRS.COM
26 JunCVE-2026-4367 Libxpm: libxpm: denial of service via out-of-bounds read in xpm file parsingInformation published.MSRC.MICROSOFT.COM
26 JunSynology issues critical fix for MailPlus Server vulnerabilitiesSynology has has fixed critical vulnerabilities in MailPlus Server, a software package used to run private email infrastructure on Synology NAS devices. The security update fixes three flaws: CVE-2026-13136, stemming from faulty authorization checks, may allow remote attackers to…HELPNETSECURITY.COM
26 JunNew DirtyClone Linux Kernel Flaw Lets Local Users Gain Root via Cloned PacketsDirtyClone is a new Linux kernel privilege escalation in the DirtyFrag family. JFrog Security Research published a working exploit walkthrough for the flaw on June 25, the first public demonstration for this variant. Tracked as CVE-2026-43503 (CVSS 8.8), it le…THEHACKERNEWS.COM
26 JunNew Linux pedit COW Exploit Enables Root Access by Poisoning Cached BinariesA flaw in the Linux kernel's traffic-control subsystem can let a local unprivileged user gain root on affected systems. CVE-2026-46331, nicknamed "pedit COW," is an out-of-bounds write in the packet-editing action (act_pedit) that corrupts shared page-cache memory. A public,…THEHACKERNEWS.COM
26 JunAmazon Q Developer Flaw Could Let Malicious Repos Run Code via MCP ConfigsA high-severity flaw in Amazon Q Developer let a malicious repository run commands and steal a developer's cloud credentials. The path was short: a developer opens the repo, trusts the workspace, and Amazon Q does the rest. Amazon has patched it. Tracked as CVE-2026-12957&nb…THEHACKERNEWS.COM
26 JunChromium: CVE-2026-13027 Use after free in FileSystemThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
26 JunChromium: CVE-2026-13026 Use after free in Digital CredentialsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
26 JunChromium: CVE-2026-13025 Insufficient validation of untrusted input in DevToolsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
26 JunChromium: CVE-2026-13024 Insufficient validation of untrusted input in NavigationThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
26 JunChromium: CVE-2026-13023 Uninitialized Use in GPUThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
26 JunChromium: CVE-2026-13022 Inappropriate implementation in AutofillThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
26 JunChromium: CVE-2026-13021 Inappropriate implementation in DeviceBoundSessionCredentialsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
26 JunChromium: CVE-2026-13036 Use after free in BlinkThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
26 JunChromium: CVE-2026-13035 Use after free in BluetoothThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
26 JunChromium: CVE-2026-13034 Inappropriate implementation in PasswordsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
26 JunChromium: CVE-2026-13033 Out of bounds read in Blink>InterestGroupsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
26 JunChromium: CVE-2026-13031 Use after free in BlinkThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
26 JunChromium: CVE-2026-13029 Use after free in Web AuthenticationThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
26 JunChromium: CVE-2026-13038 Use after free in AutofillThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
26 Jun KEVHackers exploit critical PTC Windchill PLM software flawHackers are exploiting a critical vulnerability recently patched in PTC Windchill and FlexPLM, two product lifecycle management solutions used by organizations across a range of industries, including defense, aerospace, automotive, medical, electronics, industrial machinery, and …CSOONLINE.COM
25 JunCisco Catalyst SD-WAN Zero-Day CVE-2026-20245 Exploited to Gain Root AccessAn unknown threat actor exploited a recently disclosed high-severity security flaw impacting Cisco Catalyst SD-WAN as a zero-day at least two months before it was publicly disclosed, according to new findings from Google-owned Mandiant. The vulnerability, tracked as CVE-2026-2024…THEHACKERNEWS.COM
25 JunCVE-2026-45637 Microsoft DWM Core Library Elevation of Privilege VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
25 JunCVE-2026-46140 Bluetooth: btmtk: validate WMT event SKB length before struct accessInformation published.MSRC.MICROSOFT.COM
25 JunWhy patch directives only go so farSix weeks of undetected access through a compromised VPN exposes why patching isn't a solution for the organizations already breached. The post Why patch directives only go so far appeared first on CyberScoop .CYBERSCOOP.COM
25 JunLantronix Serial-to-IP Converter Flaw Exploited in Attacks After OT Threat WarningThe exploited flaw, CVE-2025-67038, is one of the vulnerabilities disclosed in April as part of the BRIDGE:BREAK research project. The post Lantronix Serial-to-IP Converter Flaw Exploited in Attacks After OT Threat Warning appeared first on SecurityWeek .SECURITYWEEK.COM
24 JunHole in widely-used FFmpeg codec could crash media servers or enable RCEA newly discovered critical vulnerability in the FFmpeg media processing framework bundled in a huge number of open source and commercial applications points, again, to the need for CSOs to have strategies to deal with software supply chain vulnerabilities, which should include d…CSOONLINE.COM
24 JunHackers Exploiting Cisco Unified CM VulnerabilityCisco noted that a PoC had been available for CVE-2026-20230 when it announced patches in early June. The post Hackers Exploiting Cisco Unified CM Vulnerability appeared first on SecurityWeek .SECURITYWEEK.COM
24 JunCisco Unified CM Flaw Exploited After PoC Reveals File-Write Path to RootThreat actors have begun to exploit a recently disclosed critical security flaw impacting Cisco Unified Communications Manager (Unified CM) and Unified Communications Manager Session Management Edition (Unified CM SME). The vulnerability, tracked as CVE-2026-20230 (CVSS score: 8.…THEHACKERNEWS.COM
24 Jun KEVCisco Unified CM flaw actively exploited to drop webshells (CVE-2026-20230)CVE-2026-20230, a server-side request forgery (SSRF) vulnerability affecting Cisco’s Unified Communications Manager (Unified CM), is being exploited to drop webshells and achieve remote code execution capability on the underlying server. “Our honeypots are seeing auto…HELPNETSECURITY.COM
24 Jun KEVHow much cyber risk does AI create for organizations? 457 million security issues. Here’s what you can do about it.Over a 30 day period, Tenable detected 457 million AI-related security issues among 7,000-plus organizations, an average of 62,000 exposures per organization. If we didn’t already know that shadow AI was a problem, data like this makes it clear every organization needs to visuali…TENABLE.COM
24 Jun KEVCISA Warns Critical Lantronix EDS5000 Flaw Is Being Actively ExploitedThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday warned of active exploitation of a critical security flaw impacting Lantronix EDS5000 Series devices, urging Federal Civilian Executive Branch (FCEB) agencies to apply the fixes by June 26, 2026. The vuln…THEHACKERNEWS.COM
24 JunMandiant reveals how Cisco SD-WAN zero-day attacks gained root accessNew details have been revealed on how hackers exploited a Cisco Catalyst SD-WAN vulnerability tracked as CVE-2026-20245 in zero-day attacks to create rogue root accounts on targeted devices. [...]BLEEPINGCOMPUTER.COM
23 JunCVE-2024-40766: The Patch Fixed the Bug. Nobody Fixed the Configuration., (Tue, Jun 23rd)The vulnerability
ISC.SANS.EDU
23 JunCVE-2026-42915 Microsoft Windows VMSwitch Denial of Service VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
23 JunCisco Unified CM flaw CVE-2026-20230 now exploited in attacksA high-severity SSRF vulnerability, tracked as CVE-2026-20230, in Cisco Unified Communications Manager Server is now being exploited in attacks. [...]BLEEPINGCOMPUTER.COM
22 JunVU#226679: Microsoft WinRE allows for bypass of UEFI/BIOS password enforcementOverview Microsoft Windows Recovery Environment (WinRE) provides a mechanism for recovering and repairing Windows systems using an alternate boot environment. Under certain platform implementations, access to WinRE may allow an attacker to bypass firmware security controls, inclu…KB.CERT.ORG
22 JunFFmpeg ‘PixelSmash’ bug triggers code execution on media file openA critical vulnerability in FFmpeg, the widely used open-source multimedia framework, can be exploited through a specially crafted video file to achieve remote code execution (RCE). Tracked as CVE-2026-8461 and dubbed “PixelSmash,” the flaw affects FFmpeg's MagicYUV decoder. The …CYBERINSIDER.COM
22 JunVU#936962: Multiple file parsing vulnerabilities in FastStone Image Viewer 8.3.0.0Overview Two vulnerabilities have been identified in FastStone Image Viewer 8.3 that may allow remote code execution or control-flow corruption when processing specially crafted image files. The affected components include the JPEG 2000 (JP2) parser and the PSD file parser. An at…KB.CERT.ORG
20 JunHackers Exploit Gravity SMTP WordPress Plugin Bug to Expose API KeysThreat actors are exploiting a recently patched security flaw impacting Gravity SMTP, a WordPress plugin that's installed on about 100,000 sites. The vulnerability, tracked as CVE-2026-4020 (CVSS score: 5.3), is a medium-severity information disclosure flaw that can allow unauthe…THEHACKERNEWS.COM
20 JunCVE-2026-44967 opentelemetry-cpp: OTLP HTTP exporters read unbounded HTTP responseInformation published.MSRC.MICROSOFT.COM
20 JunCVE-2026-46331 net/sched: fix pedit partial COW leading to page cache corruptionInformation published.MSRC.MICROSOFT.COM
19 JunApple Patches Beats Studio Buds Flaw Letting Nearby Attackers Spy via MicrophoneApple has updated its Beats Studio Buds wireless earbuds to patch a high-severity vulnerability that could be exploited by nearby hackers to eavesdrop on users. The vulnerability, tracked as CVE-2025-20701 (CVSS score: 8.8), refers to a case of incorrect authorization impacting t…THEHACKERNEWS.COM
19 JunCVE-2026-45469 Microsoft Excel Remote Code Execution VulnerabilityMicrosoft is announcing the availability of the security updates for Microsoft Office for Mac. Customers running affected Mac software should install the update for their product to be protected from this vulnerability. Customers running other Microsoft Office software do not nee…MSRC.MICROSOFT.COM
19 JunCVE-2026-45472 Microsoft Office Remote Code Execution VulnerabilityMicrosoft is announcing the availability of the security updates for Microsoft Office for Android. Customers running affected Microsoft Office for Android software should install the update for their product to be protected from this vulnerability.MSRC.MICROSOFT.COM
19 JunCVE-2026-45471 Microsoft Word Remote Code Execution VulnerabilityMicrosoft is announcing the availability of the security updates for Microsoft Office for Mac. Customers running affected Mac software should install the update for their product to be protected from this vulnerability. Customers running other Microsoft Office software do not nee…MSRC.MICROSOFT.COM
19 JunCVE-2026-45474 Microsoft Office Remote Code Execution VulnerabilityMicrosoft is announcing the availability of the security updates for Microsoft Office for Android. Customers running affected Microsoft Office for Android software should install the update for their product to be protected from this vulnerability.MSRC.MICROSOFT.COM
19 JunCVE-2026-45486 Microsoft Word Remote Code Execution VulnerabilityMicrosoft is announcing the availability of the security updates for Microsoft Office for Mac. Customers running affected Mac software should install the update for their product to be protected from this vulnerability. Customers running other Microsoft Office software do not nee…MSRC.MICROSOFT.COM
19 JunCVE-2026-45485 Microsoft Office Information Disclosure VulnerabilityMicrosoft is announcing the availability of the security updates for Microsoft Office for Mac. Customers running affected Mac software should install the update for their product to be protected from this vulnerability. Customers running other Microsoft Office software do not nee…MSRC.MICROSOFT.COM
19 JunCVE-2026-44817 Microsoft Excel Remote Code Execution VulnerabilityMicrosoft is announcing the availability of the security updates for Microsoft Office for Mac. Customers running affected Mac software should install the update for their product to be protected from this vulnerability. Customers running other Microsoft Office software do not nee…MSRC.MICROSOFT.COM
19 JunCVE-2026-44818 Microsoft Excel Remote Code Execution VulnerabilityMicrosoft is announcing the availability of the security updates for Microsoft Office for Mac. Customers running affected Mac software should install the update for their product to be protected from this vulnerability. Customers running other Microsoft Office software do not nee…MSRC.MICROSOFT.COM
19 JunCVE-2026-44819 Microsoft Office Remote Code Execution VulnerabilityMicrosoft is announcing the availability of the security updates for Microsoft Office for Mac. Customers running affected Mac software should install the update for their product to be protected from this vulnerability. Customers running other Microsoft Office software do not nee…MSRC.MICROSOFT.COM
19 JunCVE-2026-44820 Microsoft Excel Remote Code Execution VulnerabilityMicrosoft is announcing the availability of the security updates for Microsoft Office for Mac. Customers running affected Mac software should install the update for their product to be protected from this vulnerability. Customers running other Microsoft Office software do not nee…MSRC.MICROSOFT.COM
19 JunCVE-2026-44821 Microsoft Office Information Disclosure VulnerabilityMicrosoft is announcing the availability of the security updates for Microsoft Office for Mac. Customers running affected Mac software should install the update for their product to be protected from this vulnerability. Customers running other Microsoft Office software do not nee…MSRC.MICROSOFT.COM
19 JunCVE-2026-44823 Microsoft Excel Remote Code Execution VulnerabilityMicrosoft is announcing the availability of the security updates for Microsoft Office for Mac. Customers running affected Mac software should install the update for their product to be protected from this vulnerability. Customers running other Microsoft Office software do not nee…MSRC.MICROSOFT.COM
19 JunCVE-2026-44824 Microsoft Office Remote Code Execution VulnerabilityMicrosoft is announcing the availability of the security updates for Microsoft Office for Mac. Customers running affected Mac software should install the update for their product to be protected from this vulnerability. Customers running other Microsoft Office software do not nee…MSRC.MICROSOFT.COM
19 JunCVE-2026-45456 Microsoft Outlook and Word Remote Code Execution VulnerabilityMicrosoft is announcing the availability of the security updates for Microsoft Office for Mac. Customers running affected Mac software should install the update for their product to be protected from this vulnerability. Customers running other Microsoft Office software do not nee…MSRC.MICROSOFT.COM
19 JunCVE-2026-45458 Microsoft Outlook and Word Remote Code Execution VulnerabilityMicrosoft is announcing the availability of the security updates for Microsoft Office for Mac. Customers running affected Mac software should install the update for their product to be protected from this vulnerability. Customers running other Microsoft Office software do not nee…MSRC.MICROSOFT.COM
19 JunCVE-2026-45460 Microsoft Office Information Disclosure VulnerabilityMicrosoft is announcing the availability of the security updates for Microsoft Office for Android. Customers running affected Microsoft Office for Android software should install the update for their product to be protected from this vulnerability.MSRC.MICROSOFT.COM
19 JunCVE-2026-45461 Microsoft Office Remote Code Execution VulnerabilityMicrosoft is announcing the availability of the security updates for Microsoft Office for Android. Customers running affected Microsoft Office for Android software should install the update for their product to be protected from this vulnerability.MSRC.MICROSOFT.COM
19 JunCVE-2026-45466 Microsoft Word Information Disclosure VulnerabilityMicrosoft is announcing the availability of the security updates for Microsoft Office for Mac. Customers running affected Mac software should install the update for their product to be protected from this vulnerability. Customers running other Microsoft Office software do not nee…MSRC.MICROSOFT.COM
19 JunCVE-2026-45643 Microsoft Word Remote Code Execution VulnerabilityMicrosoft is announcing the availability of the security updates for Microsoft Office for Mac. Customers running affected Mac software should install the update for their product to be protected from this vulnerability. Customers running other Microsoft Office software do not nee…MSRC.MICROSOFT.COM
19 JunCVE-2026-45645 Microsoft Office Remote Code Execution VulnerabilityMicrosoft is announcing the availability of the security updates for Microsoft Office for Mac. Customers running affected Mac software should install the update for their product to be protected from this vulnerability. Customers running other Microsoft Office software do not nee…MSRC.MICROSOFT.COM
19 JunCVE-2026-45649 Office for Android Spoofing VulnerabilityMicrosoft is announcing the availability of the security updates for Microsoft Word, PowerPoint, Excel for Android. Customers running affected Microsoft Office for Android software should install the update for their product to be protected from this vulnerability.MSRC.MICROSOFT.COM
19 JunCVE-2026-44822 Microsoft Excel Information Disclosure VulnerabilityMicrosoft is announcing the availability of the security updates for Microsoft Office for Mac. Customers running affected Mac software should install the update for their product to be protected from this vulnerability. Customers running other Microsoft Office software do not nee…MSRC.MICROSOFT.COM
19 JunCVE-2026-45455 Microsoft Excel Information Disclosure VulnerabilityMicrosoft is announcing the availability of the security updates for Microsoft Office for Mac. Customers running affected Mac software should install the update for their product to be protected from this vulnerability. Customers running other Microsoft Office software do not nee…MSRC.MICROSOFT.COM
19 JunCVE-2026-45457 Microsoft Word Remote Code Execution VulnerabilityMicrosoft is announcing the availability of the security updates for Microsoft Office for Mac. Customers running affected Mac software should install the update for their product to be protected from this vulnerability. Customers running other Microsoft Office software do not nee…MSRC.MICROSOFT.COM
19 JunCVE-2026-45459 Microsoft Excel Security Feature Bypass VulnerabilityMicrosoft is announcing the availability of the security updates for Microsoft Office for Mac. Customers running affected Mac software should install the update for their product to be protected from this vulnerability. Customers running other Microsoft Office software do not nee…MSRC.MICROSOFT.COM
19 JunCVE-2026-45463 Microsoft Office Remote Code Execution VulnerabilityMicrosoft is announcing the availability of the security updates for Microsoft Office for Android. Customers running affected Microsoft Office for Android software should install the update for their product to be protected from this vulnerability.MSRC.MICROSOFT.COM
19 JunChromium: CVE-2026-12439 Use after free in Digital CredentialsCorrected CVE title. This is an informational change only.MSRC.MICROSOFT.COM
19 JunChromium: CVE-2026-12440 Use after free in DigitalCredentialsCorrected CVE title. This is an informational change only.MSRC.MICROSOFT.COM
19 JunChromium: CVE-2026-12445 Use after free in ExtensionsCorrected CVE title. This is an informational change only.MSRC.MICROSOFT.COM
19 JunChromium: CVE-2026-12446 Insufficient data validation in PasswordsCorrected CVE title. This is an informational change only.MSRC.MICROSOFT.COM
19 JunChromium: CVE-2026-12451 Use after free in DigitalCredentialsCorrected CVE title. This is an informational change only.MSRC.MICROSOFT.COM
19 JunChromium: CVE-2026-12441 Use after free in File InputCorrected CVE title. This is an informational change only.MSRC.MICROSOFT.COM
19 JunChromium: CVE-2026-12447 Heap buffer overflow in WebRTCCorrected CVE title. This is an informational change only.MSRC.MICROSOFT.COM
19 JunChromium: CVE-2026-12443 Use after free in Web AuthenticationCorrected CVE title. This is an informational change only.MSRC.MICROSOFT.COM
19 JunChromium: CVE-2026-12452 Use after free in DownloadsCorrected CVE title. This is an informational change only.MSRC.MICROSOFT.COM
19 JunChromium: CVE-2026-12453 Insufficient validation of untrusted input in InputCorrected CVE title. This is an informational change only.MSRC.MICROSOFT.COM
19 JunChromium: CVE-2026-12455 Use after free in Tab StripCorrected CVE title. This is an informational change only.MSRC.MICROSOFT.COM
19 JunChromium: CVE-2026-12456 Insufficient validation of untrusted input in ExtensionsCorrected CVE title. This is an informational change only.MSRC.MICROSOFT.COM
19 JunChromium: CVE-2026-12458 Incorrect security UI in PasswordsCorrected CVE title. This is an informational change only.MSRC.MICROSOFT.COM
19 JunChromium: CVE-2026-12457 Insufficient data validation in ExtensionsCorrected CVE title. This is an informational change only.MSRC.MICROSOFT.COM
19 JunChromium: CVE-2026-12459 Inappropriate implementation in SerialCorrected CVE title. This is an informational change only.MSRC.MICROSOFT.COM
19 JunChromium: CVE-2026-12460 Insufficient policy enforcement in File System AccessCorrected CVE title. This is an informational change only.MSRC.MICROSOFT.COM
19 JunChromium: CVE-2026-12462 Use after free in MediaCorrected CVE title. This is an informational change only.MSRC.MICROSOFT.COM
19 JunChromium: CVE-2026-12464 Use after free in BrowserCorrected CVE title. This is an informational change only.MSRC.MICROSOFT.COM
19 JunChromium: CVE-2026-12463 Inappropriate implementation in ViewsCorrected CVE title. This is an informational change only.MSRC.MICROSOFT.COM
19 JunChromium: CVE-2026-12465 Insufficient validation of untrusted input in MetricsCorrected CVE title. This is an informational change only.MSRC.MICROSOFT.COM
19 JunChromium: CVE-2026-12454 Race in Safe BrowsingCorrected CVE title. This is an informational change only.MSRC.MICROSOFT.COM
19 JunChromium: CVE-2026-12467 Use after free in ExtensionsCorrected CVE title. This is an informational change only.MSRC.MICROSOFT.COM
19 JunChromium: CVE-2026-12468 Inappropriate implementation in UpdaterCorrected CVE title. This is an informational change only.MSRC.MICROSOFT.COM
19 JunChromium: CVE-2026-12449 Use after free in ChromotingCorrected CVE title. This is an informational change only.MSRC.MICROSOFT.COM
19 JunChromium: CVE-2026-12444 Out of bounds read in ChromotingCorrected CVE title. This is an informational change only.MSRC.MICROSOFT.COM
19 JunChromium: CVE-2026-12437 Use after free in WebShareCorrected CVE title. This is an informational change only.MSRC.MICROSOFT.COM
19 JunChromium: CVE-2026-12461 Out of bounds read in WebRTCCorrected CVE title. This is an informational change only.MSRC.MICROSOFT.COM
19 JunChromium: CVE-2026-12466 Heap buffer overflow in WebRTCCorrected CVE title. This is an informational change only.MSRC.MICROSOFT.COM
19 JunCVE-2026-42903 Windows Kerberos Denial of Service VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
19 JunCVE-2026-44803 Windows Graphics Component Remote Code Execution VulnerabilityMicrosoft is announcing the availability of the security updates for Microsoft Word, PowerPoint, Excel for Android. Customers running affected Microsoft Office for Android software should install the update for their product to be protected from this vulnerability.MSRC.MICROSOFT.COM
19 JunCVE-2026-44812 Windows Graphics Component Remote Code Execution VulnerabilityMicrosoft is announcing the availability of the security updates for Microsoft Word, PowerPoint, Excel for Android. Customers running affected Microsoft Office for Android software should install the update for their product to be protected from this vulnerability.MSRC.MICROSOFT.COM
19 JunCVE-2026-48914 Qemu-kvm: heap buffer overflow in virtio-blk scsi request handlingInformation published.MSRC.MICROSOFT.COM
19 JunCVE-2026-42014 Gnutls: fix use-after-free in gnutls_pkcs11_token_set_pinInformation published.MSRC.MICROSOFT.COM
19 JunCVE-2026-12087 Socket versions before 2.041 for Perl have an out-of-bounds heap readInformation published.MSRC.MICROSOFT.COM
19 JunCVE-2026-9669 bz2.BZ2Decompressor reuse after error can cause a stack buffer overflowInformation published.MSRC.MICROSOFT.COM
19 JunCVE-2026-43966 HTTP Response Splitting via Non-VCHAR Bytes in cow_http_struct_hd:escape_string/2Information published.MSRC.MICROSOFT.COM
19 JunCVE-2026-10275 OpenSC pkcs11-tool Key Generation pkcs11-tool.c test_kpgen_certwrite buffer overflowInformation published.MSRC.MICROSOFT.COM
19 JunM365 Copilot SearchLeak: Your prompt injection attack surface just got biggerA recent proof-of-concept attack against Microsoft’s M365 Copilot Enterprise highlights what could be a much broader prompt injection threat based on a common way many AI-enhanced web services operate. Dubbed SearchLeak, the attack hinged on a typical malicious objective: to leak…CSOONLINE.COM
19 Jun KEVOracle releases 245 new security patches, all rated ‘high-priority security’The Oracle Critical Security Patch update (CSPU) released this week contains 245 newly-announced fixes for supported on-premises software, some of which impact multiple products. It is in reaction to an industry trend to announce and fix security holes much more quickly , and com…CSOONLINE.COM
19 JunSplunk Enterprise Vulnerability Exploited in Attacks Days After DisclosureCISA has given federal agencies only three days to patch CVE-2026-20253, which can be exploited for unauthenticated remote code execution. The post Splunk Enterprise Vulnerability Exploited in Attacks Days After Disclosure appeared first on SecurityWeek .SECURITYWEEK.COM
19 JunWeekly Metasploit Update: NTLM Relay Priv Esc, MCP Server Integration, Paperclip AI RCE Chain, and moreThis week's release includes five new modules, including a full unauthenticated RCE chain for Paperclip AI and a VS Code extension persistence technique. On the post-exploitation side, the new windows/local/ntlm_relay_2_self module coerces the local machine account to authenticat…RAPID7.COM
18 JunCVE-2026-48854 Unbounded request body accumulation causes memory exhaustion in elixir-grpc/grpcInformation published.MSRC.MICROSOFT.COM
18 Jun KEVOracle June 2026 Critical Security Patch Update Addresses 243 CVEs (CVE-2026-35273)Oracle addresses 243 CVEs in its June 2026 Critical Security Patch Update with 245 patches, including 122 critical updates. Key Takeaways The June 2026 Critical Security Patch Update (CSPU) contains fixes for 243 unique CVEs in 245 security updates 122 issues (49.8% of all patche…TENABLE.COM
18 JunF5 Patches Two Critical NGINX Open Source Flaws Enabling Remote Code ExecutionF5 has released security updates to address two critical security flaws in NGINX Open Source that could be exploited to achieve code execution on affected systems. The vulnerabilities are listed below - CVE-2026-42530 (CVSS v4 score: 9.2) - A use-after-free vulnerability in the n…THEHACKERNEWS.COM
17 JunScam Losses Surge - Cybersecurity TodayCybersecurity Today host David Shipley reports that the FTC says Americans lost $3.5 billion to imposter scams in 2025—nearly triple 2020—with social media tied to $2.1 billion in losses and total fraud reaching about $16 billion, while the FBI estimates cyber-enabled losses near…CYBERSECURITYTODAY.LIBSYN.COM
17 Jun KEVCISA Warns of Actively Exploited Joomla JCE Flaw Allowing PHP Code ExecutionThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added a maximum-severity security flaw impacting Widget Factory Joomla Content Editor (JCE) to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerability,…THEHACKERNEWS.COM
17 JunMicrosoft working on patch for RoguePlanet Defender zero-day (CVE-2026-50656)Microsoft has acknowledged the local elevation of privilege issue in Microsoft Defender that can be triggered via the “RoguePlanet” exploit, and is “working to provide a high quality security update that addresses this vulnerability.” The vulnerability, wh…HELPNETSECURITY.COM
17 JunCVE-2026-47636 Microsoft SharePoint Server Spoofing VulnerabilityAcknowledgement added. This is an informational change only.MSRC.MICROSOFT.COM
17 JunCVE-2026-45475 Microsoft Office Remote Code Execution VulnerabilityAcknowledgement added. This is an informational change only.MSRC.MICROSOFT.COM
17 JunCVE-2026-42828 Windows Projected File System Elevation of Privilege VulnerabilityAcknowledgement added. This is an informational change only.MSRC.MICROSOFT.COM
17 JunMicrosoft Confirms RoguePlanet Defender Zero-Day, Says Patch is in DevelopmentMicrosoft has formally disclosed that it's working to release a patch to address a Defender zero-day codenamed RoguePlanet. The vulnerability has now been assigned the CVE identifier CVE-2026-50656 (CVSS score: 7.8), with the tech giant describing it as a privilege escalation fla…THEHACKERNEWS.COM
17 JunVU#380058: SignalRGB kernel driver contains improper access control and IOCTL vulnerabilitiesOverview The SignalRGB kernel driver, SignalIo.sys , contains two vulnerabilities involving improper access control and unsafe memory handling. The device object is created with an overly permissive Discretionary Access Control List (DACL) that allows user-mode processes to acces…KB.CERT.ORG
16 Jun KEVCisco Releases Security Updates for Actively Exploited SD-WAN Manager FlawCisco has released security updates for a medium-severity security flaw in Catalyst SD-WAN Manager that has come under active exploitation in the wild. The vulnerability, tracked as CVE-2026-20262, carries a CVSS score of 6.5 out of 10.0. "A vulnerability in the web UI of Cisco C…THEHACKERNEWS.COM
16 Jun KEVCISA Flags LiteSpeed cPanel Plugin Flaw Exploited for Root Privilege EscalationThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a security flaw impacting LiteSpeed cPanel Plugin to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the fixes by June 18, 2026. The …THEHACKERNEWS.COM
16 JunCisco Patches Another SD-WAN Zero-Day Exploited in AttacksCisco recently became aware of the exploitation of CVE-2026-20262, a Catalyst SD-WAN Manager zero-day that allows arbitrary file write. The post Cisco Patches Another SD-WAN Zero-Day Exploited in Attacks appeared first on SecurityWeek .SECURITYWEEK.COM
16 JunCisco patches SD-WAN flaw amid evidence of active exploitationCisco has released fixes for a vulnerability in its Catalyst SD-WAN Manager software after becoming aware of limited exploitation of the flaw, which could allow an authenticated attacker to create or overwrite files that may later be used to gain root privileges. The vulnerabilit…CSOONLINE.COM
16 JunAttackers Exploit Three Fortinet FortiSandbox Flaws, One Patched Last WeekBad actors are exploiting multiple security vulnerabilities in Fortinet FortiSandbox, according to threat intelligence firm Defused Cyber. In a post shared on X, the company said it has observed exploitation of CVE-2026-39813, CVE-2026-39808, and CVE-2026-25089 over the past 24 h…THEHACKERNEWS.COM
16 Jun KEVCISA warns of another cPanel plugin flaw exploited in attacksThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) has given U.S. government agencies three days to secure their servers against an actively exploited vulnerability (CVE-2026-54420) in the LiteSpeed cPanel user-end plugin. [...]BLEEPINGCOMPUTER.COM
16 JunCisco discloses second exploited SD-WAN vulnerability in two weeks (CVE-2026-20262)Cisco has revealed another Catalyst SD-WAN Manager vulnerability (CVE-2026-20262) that its Product Security Incident Response Team observed being exploited by attackers. But the associated security advisory also states that “the vulnerability was found during internal secur…HELPNETSECURITY.COM
16 JunSimpleHelp RMM flaw could give attackers full access to managed endpoints (CVE-2026-48558)A critical vulnerability (CVE-2026-48558) in SimpleHelp, a popular remote monitoring and management (RMM) tool, can be exploited remotely by unauthenticated attackers to create a new “Technician” account and use it to remote into managed endpoints, execute scripts, an…HELPNETSECURITY.COM
16 JunAttackers are exploiting FortiSandbox vulnerabilitiesAttackers have been spotted exploiting three vulnerabilities (CVE-2026-39813, CVE-2026-39808, CVE-2026-25089) in FortiSandbox, a platform that other Fortinet security products depend on for threat verdicts to enforce blocking decisions and trigger automated responses. The warning…HELPNETSECURITY.COM
15 JunPalo Alto Warns of Active Exploitation of PAN-OS GlobalProtect VPN FlawPalo Alto Networks has revealed that it has observed "active exploitation" of a recently disclosed PAN-OS vulnerability by an unknown threat actor to obtain unauthorized access to GlobalProtect portals. The vulnerability in question is CVE-2026-0257 (CVSS score: 7.8), an authenti…THEHACKERNEWS.COM
15 JunChromium: CVE-2026-12012 Use after free NetworkThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/search/label/Desktop%20Update) for more information.MSRC.MICROSOFT.COM
15 JunChromium: CVE-2026-12008 Use after free DigitalCredentialsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/search/label/Desktop%20Update) for more information.MSRC.MICROSOFT.COM
15 JunChromium: CVE-2026-12019 Out of bounds write CodecsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/search/label/Desktop%20Update) for more information.MSRC.MICROSOFT.COM
15 JunChromium: CVE-2026-12016 Insufficient validation of untrusted input DevToolsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/search/label/Desktop%20Update) for more information.MSRC.MICROSOFT.COM
15 JunChromium: CVE-2026-12015 Use after free AutofillThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/search/label/Desktop%20Update) for more information.MSRC.MICROSOFT.COM
15 JunChromium: CVE-2026-12018 Inappropriate implementation MojoThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/search/label/Desktop%20Update) for more information.MSRC.MICROSOFT.COM
15 JunChromium: CVE-2026-12007 Use after free CoreThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/search/label/Desktop%20Update) for more information.MSRC.MICROSOFT.COM
15 JunChromium: CVE-2026-12017 Insufficient validation of untrusted input ExtensionsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/search/label/Desktop%20Update) for more information.MSRC.MICROSOFT.COM
15 JunChromium: CVE-2026-12014 Use after free CastThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/search/label/Desktop%20Update) for more information.MSRC.MICROSOFT.COM
15 JunChromium: CVE-2026-12013 Use after free MediaThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/search/label/Desktop%20Update) for more information.MSRC.MICROSOFT.COM
15 JunChromium: CVE-2026-12010 Heap buffer overflow GPUThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/search/label/Desktop%20Update) for more information.MSRC.MICROSOFT.COM
15 JunChromium: CVE-2026-12009 Insufficient validation of untrusted input AccessibilityThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/search/label/Desktop%20Update) for more information.MSRC.MICROSOFT.COM
15 JunChromium: CVE-2026-12011 Use after free WebMIDIThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/search/label/Desktop%20Update) for more information.MSRC.MICROSOFT.COM
15 JunCVE-2026-11526 GD versions before 2.86 for Perl allow OS command injection and file overwrite via a 2-arg open() of filename arguments in _make_filehandleInformation published.MSRC.MICROSOFT.COM
15 JunLangflow RCE under active attack months after a patch was shippedEnterprises using the open-source AI orchestration platform Langflow are being urged to patch a high-severity path traversal flaw amid active exploitation, despite a fix having been available for more than two months. The bug, which stems from improper handling of filenames in La…CSOONLINE.COM
15 JunCisco fixes SD-WAN vManage flaw exploited in zero-day attacksCisco has released security updates to address a vulnerability in the Catalyst SD-WAN Manager, tracked as CVE-2026-20262, that was exploited in attacks to escalate to root privileges. [...]BLEEPINGCOMPUTER.COM
15 JunAI vulnerability discovery is pushing 2026 CVEs toward 66,000Vulnerability disclosures are piling up faster in 2026 than anyone expected at the start of the year. The running count for the first few months sits well above the original projection, and the Forum of Incident Response and Security Teams (FIRST) now expects the year to land nea…HELPNETSECURITY.COM
15 JunChromium: CVE-2026-11628 Use after free in OzoneThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
15 JunChromium: CVE-2026-11629 Use after free in OzoneThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
15 JunChromium: CVE-2026-11631 Use after free in AuraThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
15 JunChromium: CVE-2026-11630 Use after free in File InputThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
15 JunChromium: CVE-2026-11632 Use after free in TabStripThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
15 JunChromium: CVE-2026-11633 Use after free in BluetoothThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
15 JunChromium: CVE-2026-11634 Use after free in GamepadThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
15 JunChromium: CVE-2026-11635 Use after free in BluetoothThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
15 JunChromium: CVE-2026-11639 Use after free in CompositingThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
15 JunChromium: CVE-2026-11637 Use after free in ViewsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
15 JunChromium: CVE-2026-11636 Use after free in AutofillThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
15 JunChromium: CVE-2026-11638 Use after free in PrintingThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
15 JunChromium: CVE-2026-11641 Use after free in BluetoothThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
15 JunChromium: CVE-2026-11640 Integer overflow in libyuvThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
15 JunChromium: CVE-2026-11642 Use after free in Web AppsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
15 JunChromium: CVE-2026-11645 Out of bounds memory access in V8This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
15 JunChromium: CVE-2026-11643 Use after free in ProxyThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
15 JunChromium: CVE-2026-11644 Use after free in ViewsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
15 JunChromium: CVE-2026-11646 Use after free in ViewTransitionsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
15 JunChromium: CVE-2026-11657 Use after free in PaymentsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
15 JunChromium: CVE-2026-11658 Insufficient validation of untrusted input in ExtensionsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
15 JunChromium: CVE-2026-11660 Insufficient validation of untrusted input in New Tab PageThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
15 JunChromium: CVE-2026-11661 Use after free in ViewsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
15 JunChromium: CVE-2026-11659 Insufficient validation of untrusted input in UIThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
15 JunChromium: CVE-2026-11663 Use after free in SkiaThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
15 JunChromium: CVE-2026-11662 Type Confusion in BindingsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
15 JunChromium: CVE-2026-11664 Use after free in PaymentsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
15 JunChromium: CVE-2026-11665 Out of bounds read in DawnThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
15 JunChromium: CVE-2026-11666 Insufficient validation of untrusted input in InputThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
15 JunChromium: CVE-2026-11668 Uninitialized Use in CodecsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
15 JunChromium: CVE-2026-11669 Integer overflow in MediaThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
15 JunChromium: CVE-2026-11667 Out of bounds read in WebRTCThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
15 JunChromium: CVE-2026-11670 Use after free in PDFThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
15 JunChromium: CVE-2026-11671 Use after free in NavigationThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
15 JunChromium: CVE-2026-11672 Out of bounds write in GPUThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
15 JunChromium: CVE-2026-11673 Use after free in InterestGroupsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
15 JunChromium: CVE-2026-11675 Insufficient validation of untrusted input in SkiaThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
15 JunChromium: CVE-2026-11674 Use after free in Guest ViewThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
15 JunChromium: CVE-2026-11676 Insufficient validation of untrusted input in DawnThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
15 JunChromium: CVE-2026-11677 Race in NetworkThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
15 JunChromium: CVE-2026-11678 Integer overflow in libyuvThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
15 JunChromium: CVE-2026-11679 Use after free in CodecsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
15 JunChromium: CVE-2026-11681 Use after free in OzoneThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
15 JunChromium: CVE-2026-11682 Insufficient validation of untrusted input in ViewsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
15 JunChromium: CVE-2026-11680 Use after free in MediaThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
15 JunChromium: CVE-2026-11683 Use after free in WebCodecsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
15 JunChromium: CVE-2026-11684 Insufficient policy enforcement in NetworkThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
15 JunChromium: CVE-2026-11687 Use after free in DawnThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
15 JunChromium: CVE-2026-11686 Insufficient validation of untrusted input in DawnThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
15 JunChromium: CVE-2026-11688 Object lifecycle issue in SVGThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
15 JunChromium: CVE-2026-11685 Insufficient data validation in MediaCaptureThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
15 JunChromium: CVE-2026-11689 Insufficient validation of untrusted input in PasswordsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
15 JunChromium: CVE-2026-11690 Out of bounds read and write in MediaThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
15 JunChromium: CVE-2026-11691 Insufficient validation of untrusted input in New Tab PageThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
15 JunChromium: CVE-2026-11692 Use after free in Read AnythingThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
15 JunChromium: CVE-2026-11693 Inappropriate implementation in PluginsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
15 JunChromium: CVE-2026-11694 Use after free in ServiceWorkerThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
15 JunChromium: CVE-2026-11695 Inappropriate implementation in PasswordsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
15 JunChromium: CVE-2026-11696 Uninitialized Use in VideoThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
15 JunChromium: CVE-2026-11697 Insufficient validation of untrusted input in UIThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
15 JunChromium: CVE-2026-11698 Use after free in BluetoothThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
15 JunChromium: CVE-2026-11699 Use after free in BluetoothThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
15 JunChromium: CVE-2026-11700 Use after free in TracingThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
15 JunChromium: CVE-2026-11647 Use after free in PrintingThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
15 JunChromium: CVE-2026-11648 Use after free in FullScreenThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
15 JunChromium: CVE-2026-11651 Use after free in NetworkThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
15 JunChromium: CVE-2026-11649 Use after free in V8This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
15 JunChromium: CVE-2026-11652 Use after free in ExtensionsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
15 JunChromium: CVE-2026-11650 Use after free in V8This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
15 JunChromium: CVE-2026-11653 Insufficient validation of untrusted input in ExtensionsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
15 JunChromium: CVE-2026-11654 Use after free in CameraCaptureThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
15 JunChromium: CVE-2026-11656 Use after free in ServiceWorkerThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
15 JunChromium: CVE-2026-11655 Integer overflow in MediaThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
13 JunCVE-2023-5678 Excessive time spent in DH check / generation with large Q parameter valueInformation published.MSRC.MICROSOFT.COM
13 JunCVE-2026-47162 Vim: Vimscript Code Injection in netrw NetrwBookHistSave() via crafted directory nameInformation published.MSRC.MICROSOFT.COM
13 JunCVE-2026-45445 AES-OCB IV Ignored on EVP_Cipher() PathInformation published.MSRC.MICROSOFT.COM
13 JunCVE-2026-45447 Heap Use-After-Free in the PKCS7_verify() FunctionInformation published.MSRC.MICROSOFT.COM
13 JunCVE-2026-42764 NULL Pointer Dereference in QUIC Server Initial Packet HandlingInformation published.MSRC.MICROSOFT.COM
13 JunCVE-2026-34181 PKCS#12 Files with PBMAC1 Are Accepted with Short HMAC KeysInformation published.MSRC.MICROSOFT.COM
13 JunCVE-2026-52860 Vim: Arbitrary Code Execution via Python Omni-CompletionInformation published.MSRC.MICROSOFT.COM
13 JunCVE-2026-52859 Vim: Out-of-bounds Read in Terminal Screen SnapshotInformation published.MSRC.MICROSOFT.COM
13 JunCVE-2026-47167 Vim: Vimscript Code Injection in cucumber filetype plugin via crafted step-definition regexInformation published.MSRC.MICROSOFT.COM
13 JunCVE-2026-52858 Vim: Arbitrary Code Execution via Python Omni-CompletionInformation published.MSRC.MICROSOFT.COM
13 JunCVE-2026-44705 tmp: Path Traversal via unsanitized prefix/postfix enables directory escapeInformation published.MSRC.MICROSOFT.COM
13 JunCVE-2026-34183 Unbounded Memory Growth in the QUIC PATH_CHALLENGE HandlerInformation published.MSRC.MICROSOFT.COM
13 JunCVE-2026-34182 CMS AuthEnvelopedData Processing May Accept Forged MessagesInformation published.MSRC.MICROSOFT.COM
13 JunCVE-2026-7383 Possible Heap Buffer Overflow in ASN.1 Multibyte String ConversionInformation published.MSRC.MICROSOFT.COM
13 JunCVE-2026-42768 Multi-RecipientInfo Bleichenbacher Oracle in CMS_decrypt() and PKCS7_decrypt()Information published.MSRC.MICROSOFT.COM
13 JunCVE-2026-9076 Out-of-Bounds Read in CMS Password-Based DecryptionInformation published.MSRC.MICROSOFT.COM
13 JunCVE-2026-45446 Incorrect Tag Processing for Empty Messages in AES-GCM-SIV and AES-SIV modesInformation published.MSRC.MICROSOFT.COM
13 JunCVE-2026-42766 Possible NULL Dereference in Password-Based CMS DecryptionInformation published.MSRC.MICROSOFT.COM
13 JunCVE-2026-42767 NULL Pointer Dereference in CRMF EncryptedValue DecryptionInformation published.MSRC.MICROSOFT.COM
13 JunCVE-2026-42769 Trust-Anchor Substitution via cert/issuer Typo in CMP rootCaKeyUpdateInformation published.MSRC.MICROSOFT.COM
13 JunCVE-2026-34180 Heap Buffer Over-read in ASN.1 Content ParsingInformation published.MSRC.MICROSOFT.COM
13 JunCritical Splunk Enterprise Flaw Lets Attackers Run Code Without AuthenticationSplunk has released security updates to address a critical security flaw in Splunk Enterprise that could be exploited to conduct unauthenticated file operations and even remote code execution. The vulnerability, tracked as CVE-2026-20253, is rated 9.8 on the CVSS scoring system. …THEHACKERNEWS.COM
12 JunShinyHunters Exploits Oracle PeopleSoft Zero-Day (CVE-2026-35273) to Breach UniversitiesThe ShinyHunters extortion crew exploited an unpatched flaw in Oracle PeopleSoft to break into enterprise systems, steal data, and demand payment to keep it private. The campaign hit universities hardest. Google's Mandiant attributes it to the group it tracks as UNC6240, and date…THEHACKERNEWS.COM
12 JunGoogle Confirms Exploitation of Oracle PeopleSoft Zero-Day by ShinyHuntersOracle has mitigated CVE-2026-35273, but it has not publicly confirmed the vulnerability’s in-the-wild exploitation. The post Google Confirms Exploitation of Oracle PeopleSoft Zero-Day by ShinyHunters appeared first on SecurityWeek .SECURITYWEEK.COM
12 JunCVE-2026-46643 Snappy: Binary path is never shell-escaped due to an inverted is_executable checkInformation published.MSRC.MICROSOFT.COM
12 JunCVE-2026-46683 Snappy: SSRF and local file read via the xsl-style-sheet optionInformation published.MSRC.MICROSOFT.COM
12 Jun KEVOracle PeopleSoft zero‑day fuels ShinyHunters extortion spreeA newly disclosed Oracle PeopleSoft zero-day became the weapon of choice in a recent ShinyHunters extortion campaign that primarily targeted universities and other educational institutes. Attackers exploited the critical remote code execution (RCE) flaw in PeopleSoft’s Environmen…CSOONLINE.COM
12 Jun KEVResearchers release details, PoC for exploited Check Point VPN flaw (CVE-2026-50751)WatchTowr researchers have disclosed a technical analysis and a “Detection Artefact Generator” for CVE-2026-50751, an authentication bypass flaw in Check Point’s Remote Access VPN and Mobile Access, which the vendor confirmed to be actively exploited. The attack…HELPNETSECURITY.COM
12 Jun KEVActive Exploitation of Oracle PeopleSoft Zero-Day (CVE-2026-35273)Overview On June 10, 2026, Oracle published a security alert for CVE-2026-35273 , a critical vulnerability in the Updates Environment Management component of PeopleSoft Enterprise PeopleTools. Oracle released an out-of-band patch the same day as the advisory, underscoring the urg…RAPID7.COM
12 JunGoogle warns of Oracle PeopleSoft attacks hitting universitiesGoogle's Mandiant and Google Threat Intelligence Group (GTIG) say the ShinyHunters extortion group exploited a critical Oracle PeopleSoft vulnerability as a zero-day to compromise education institutes. The activity, tracked as UNC6240, was observed between May 27 and June 9 and i…CYBERINSIDER.COM
11 JunMicrosoft Patches Exploited Exchange Server VulnerabilityThe company warned about zero-day attacks exploiting the Exchange Server vulnerability CVE-2026-42897 on May 14. The post Microsoft Patches Exploited Exchange Server Vulnerability appeared first on SecurityWeek .SECURITYWEEK.COM
11 JunCVE-2026-11822 SQLite before 3.53.2 Memory Corruption in FTS5 ExtensionInformation published.MSRC.MICROSOFT.COM
11 JunCVE-2026-42536 Apache HTTP Server: mod_xml2enc heap overflowInformation published.MSRC.MICROSOFT.COM
11 JunCVE-2026-46433 lldpd: Heap OOB Read in VLAN Decapsulation memmoveInformation published.MSRC.MICROSOFT.COM
11 JunCVE-2026-11824 SQLite before 3.53.2 Heap Buffer Overflow via FTS5 fts5ChunkIterateInformation published.MSRC.MICROSOFT.COM
11 JunCVE-2026-10846 Insufficient verification that responses belong to a queryInformation published.MSRC.MICROSOFT.COM
11 JunCVE-2026-48913 Apache HTTP Server: mod_http2 memory corruption when file handles exhaustedInformation published.MSRC.MICROSOFT.COM
11 JunCVE-2026-44119 Apache HTTP Server: escalation of privilege through expressions in .htaccess in multiple modulesInformation published.MSRC.MICROSOFT.COM
11 JunCVE-2026-43951 Apache HTTP Server: OOB Read in `merge_response_headers` can cause crashInformation published.MSRC.MICROSOFT.COM
11 JunCVE-2026-29167 Apache HTTP Server: mod_ldap per-dir use-after-freeInformation published.MSRC.MICROSOFT.COM
11 JunCVE-2026-42535 Apache HTTP Server: mod_dav_fs protected directory accessInformation published.MSRC.MICROSOFT.COM
11 JunCVE-2026-44631 Apache HTTP Server: Heap Underflow in `ap_regname` via Signed Char OverflowInformation published.MSRC.MICROSOFT.COM
11 JunCVE-2026-44186 Apache HTTP Server: Loop in `proxy_ftp_handler` in mod_proxy_ftpInformation published.MSRC.MICROSOFT.COM
11 JunCVE-2026-34356 Apache HTTP Server: ProxyPassReverseCookieMap buffer overflowInformation published.MSRC.MICROSOFT.COM
11 JunCVE-2026-44185 Apache HTTP Server: Stack Buffer Over-Read in mod_ssl OCSP `send_request`Information published.MSRC.MICROSOFT.COM
11 JunCVE-2026-34355 Apache HTTP Server: mod_proxy_html buffer overflowInformation published.MSRC.MICROSOFT.COM
11 JunChina-linked recon botnet outpaces enterprise defensesA botnet made up of compromised small office and Internet of Things devices has grown into a larger reconnaissance network capable of rapidly identifying vulnerable internet-facing systems after public vulnerability disclosures, researchers said. The botnet, tracked by Lumen’s Bl…CSOONLINE.COM
11 Jun KEVOracle PeopleSoft servers under attack, Oracle pushes out-of-band security alertA zero-day vulnerability (CVE-2026-35273) in Oracle PeopleSoft PeopleTools is being exploited in the wild, Charles Carmakal, CTO at cybersecurity firm Mandiant, part of Google Cloud, warned today. The warning comes a day after Oracle published an out-of-band security alert about …HELPNETSECURITY.COM
11 JunOracle Addresses PeopleSoft Vulnerability Amid Reports of Zero-Day AttacksOracle has released a patch for CVE-2026-35273, but it has not said whether it’s a zero-day exploited in ShinyHunters attacks. The post Oracle Addresses PeopleSoft Vulnerability Amid Reports of Zero-Day Attacks appeared first on SecurityWeek .SECURITYWEEK.COM
11 JunVU#862559: crypton-x509-validation Haskell libraries do not enforce X.509 NameConstraintsOverview A vulnerability has been discovered in the Haskell TLS software stack, commonly used by applications built in the Haskell programming language to securely connect to servers over the internet. Specifically, the libraries "crypton-x509-validation" fail to enforce a key se…KB.CERT.ORG
11 Jun KEVOracle mitigates PeopleSoft zero-day exploited in data theft attacksOracle is warning about a critical PeopleSoft Suite zero-day vulnerability tracked as CVE-2026-35273 that allows unauthenticated remote code execution, with the flaw actively exploited in ShinyHunter data theft attacks. [...]BLEEPINGCOMPUTER.COM
11 JunDrupal Core CVE-2026-9082 Active Exploitation Confirmed Within Days of DisclosureSensor Intel Series: June 2026 CVE TrendsF5.COM
10 Jun KEVAI Worms, Hacks, and Insurance ShiftsInstagram AI Support Hack Hits 20,225 Accounts; AI Worm 'Hades' Lies to Security Tools; Chrome Zero-Day Patch Host David Shipley reports Meta says 20,225 Instagram accounts were hijacked after an AI support tool was tricked into sending reset links to attacker-controlled emails, …CYBERSECURITYTODAY.LIBSYN.COM
10 JunCVE-2026-43059 Bluetooth: MGMT: Fix list corruption and UAF in command complete handlersInformation published.MSRC.MICROSOFT.COM
10 JunCVE-2026-46275 Bluetooth: hci_uart: fix UAFs and race conditions in close and init pathsInformation published.MSRC.MICROSOFT.COM
10 JunCVE-2026-46285 mtd: docg3: fix use-after-free in docg3_release()Information published.MSRC.MICROSOFT.COM
10 JunCVE-2026-46280 lib: test_hmm: evict device pages on file close to avoid use-after-freeInformation published.MSRC.MICROSOFT.COM
10 JunCVE-2026-46282 iio: frequency: admv1013: fix NULL pointer dereference on strInformation published.MSRC.MICROSOFT.COM
10 JunCVE-2026-46312 media: videobuf2: Set vma_flags in vb2_dma_sg_mmapInformation published.MSRC.MICROSOFT.COM
10 JunCVE-2026-46301 spi: topcliff-pch: fix use-after-free on unbindInformation published.MSRC.MICROSOFT.COM
10 JunCVE-2026-46302 selinux: allow multiple opens of /sys/fs/selinux/policyInformation published.MSRC.MICROSOFT.COM
10 JunCVE-2026-46314 drm/v3d: Reject empty multisync extension to prevent infinite loopInformation published.MSRC.MICROSOFT.COM
10 JunCVE-2025-71315 drm/vkms: Convert to DRM's vblank timerInformation published.MSRC.MICROSOFT.COM
10 JunCVE-2026-46296 spi: s3c64xx: fix NULL-deref on driver unbindInformation published.MSRC.MICROSOFT.COM
10 JunCVE-2026-46287 net: txgbe: fix RTNL assertion warning when remove moduleInformation published.MSRC.MICROSOFT.COM
10 JunCVE-2026-46299 hfsplus: fix held lock freed on hfsplus_fill_super()Information published.MSRC.MICROSOFT.COM
10 JunCVE-2026-46321 tun: free page on short-frame rejection in tun_xdp_one()Information published.MSRC.MICROSOFT.COM
10 JunCVE-2026-46319 net/sched: act_ct: Only release RCU read lock after ct_ftInformation published.MSRC.MICROSOFT.COM
10 JunCVE-2026-46324 netfilter: nf_tables: use list_del_rcu for netlink hooksInformation published.MSRC.MICROSOFT.COM
10 JunCVE-2026-46320 tap: free page on error paths in tap_get_user_xdp()Information published.MSRC.MICROSOFT.COM
10 JunCVE-2026-46289 lib/scatterlist: fix length calculations in extract_kvec_to_sgInformation published.MSRC.MICROSOFT.COM
10 JunCVE-2026-46292 pmdomain: core: Fix detach procedure for virtual devices in genpdInformation published.MSRC.MICROSOFT.COM
10 JunCVE-2026-46274 io-wq: check that the predecessor is hashed in io_wq_remove_pending()Information published.MSRC.MICROSOFT.COM
10 JunCVE-2026-46291 crypto: caam - guard HMAC key hex dumps in hash_digest_keyInformation published.MSRC.MICROSOFT.COM
10 JunCVE-2026-46293 clk: microchip: mpfs-ccc: fix out of bounds access during output registrationInformation published.MSRC.MICROSOFT.COM
10 JunCVE-2026-46306 flow_dissector: do not dissect PPPoE PFC framesInformation published.MSRC.MICROSOFT.COM
10 JunCVE-2026-46304 nvmet: avoid recursive nvmet-wq flush in nvmet_ctrl_freeInformation published.MSRC.MICROSOFT.COM
10 JunCVE-2026-46303 isofs: validate Rock Ridge CE continuation extent against volume sizeInformation published.MSRC.MICROSOFT.COM
10 JunCVE-2026-49762 Unbounded integer parsing in the Version module enables CPU and memory exhaustion denial of serviceInformation published.MSRC.MICROSOFT.COM
10 JunCVE-2026-46322 tun: free page on build_skb failure in tun_xdp_one()Information published.MSRC.MICROSOFT.COM
10 JunCVE-2026-46325 RDMA/rxe: Fix iova-to-va conversion for MR page sizes != PAGE_SIZEInformation published.MSRC.MICROSOFT.COM
10 JunCVE-2026-46330 Revert "net/smc: Introduce TCP ULP support"Information published.MSRC.MICROSOFT.COM
10 Jun KEVMicrosoft feud escalates as researcher drops new Windows zero-dayThe long-running feud between Microsoft and security researcher Nightmare Eclipse has entered a new chapter. Eclipse, who has spent the past several months publicly releasing unpatched Windows vulnerabilities while sparring with Microsoft over vulnerability disclosure practices, …CSOONLINE.COM
10 Jun KEVCritical Ivanti Sentry flaw allows root-level remote code execution (CVE-2026-10520)Ivanti has patched two critical vulnerabilities (CVE-2026-10520 and CVE-2026-10523) in Ivanti Sentry and has urged customers to implement the fix right away. Though the vulnerabilities are not known to be actively exploited, security researchers have already released technical de…HELPNETSECURITY.COM
10 JunJune Patch Tuesday marks a ‘new normal’ with over 200 CVEs, 32 rated ‘critical’June’s Patch Tuesday security updates have arrived, with SAP fixing four critical vulnerabilities and Microsoft addressing over 200 CVEs. Microsoft’s to-do list includes fixes for three zero days, 32 patches rated as ‘critical’, and a batch of other high-risk vulnerabilities that…CSOONLINE.COM
10 JunIvanti, Fortinet, and SAP Release Patches for Multiple Critical VulnerabilitiesFortinet, Ivanti, and SAP have released security updates to address multiple critical security vulnerabilities that could result in arbitrary code execution and information disclosure. The security flaw patched by Fortinet relates to a command injection vulnerability in FortiSand…THEHACKERNEWS.COM
10 JunUnpatched Langflow Flaw CVE-2026-5027 Exploited for Unauthenticated RCEA high-severity unpatched security flaw in Langflow, an open-source low-code platform to build artificial intelligence (AI) applications, has come under active exploitation in the wild, according to findings from VulnCheck. The vulnerability in question is CVE-2026-5027 (CVSS sco…THEHACKERNEWS.COM
10 JunMicrosoft-signed UEFI bootloaders vulnerable to Secure Boot bypassMicrosoft has released security updates to address a Secure Boot bypass vulnerability affecting multiple Microsoft-signed UEFI shim bootloaders used by Linux distributions, recovery tools, and enterprise software. The flaw, tracked as CVE-2026-8863, could allow attackers to execu…CYBERINSIDER.COM
10 JunIvanti patches critical Sentry flaws that lead to full device takeoverIT software provider Ivanti fixed two vulnerabilities in Ivanti Sentry, a secure mobile gateway appliance formerly called MobileIron Sentry. The flaws could allow unauthenticated remote attackers to gain complete control of deployments. One of the vulnerabilities, CVE-2026-10523,…CSOONLINE.COM
10 JunPath traversal flaw in AI dev platform Langflow exploited in attacksAttackers are actively exploiting CVE-2026-5027, a high-severity path traversal vulnerability in the AI development platform Langflow, to write arbitrary files on exposed servers. [...]BLEEPINGCOMPUTER.COM
9 JunOne-Character Linux Kernel Flaw Enables Local Root Access, Exploits Now PublicSecurity researchers have published a detailed, working exploit for a Linux kernel use-after-free that lets an unprivileged local user escalate to root and break out of a container. The flaw, CVE-2026-23111, sits in the kernel's nf_tables packet-filtering code and was patched ups…THEHACKERNEWS.COM
9 JunGoogle Patches 5th Chrome Zero-Day Exploited in 2026The vulnerability is tracked as CVE-2026-11645 and it was reported in late April by an anonymous researcher. The post Google Patches 5th Chrome Zero-Day Exploited in 2026 appeared first on SecurityWeek .SECURITYWEEK.COM
9 Jun KEVLiteLLM Flaw CVE-2026-42271 Exploited in the Wild, Chains to Unauthenticated RCEThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a high-severity flaw impacting BerriAI LiteLLM to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerability, tracked as CVE-2026-42271 (CVSS score: …THEHACKERNEWS.COM
9 JunCVE-2026-46250 MIPS: Work around LLVM bug when gp is used as global register variableInformation published.MSRC.MICROSOFT.COM
9 JunCVE-2026-11463 USCiLab Cereal Shared Pointer type confusionInformation published.MSRC.MICROSOFT.COM
9 JunCVE-2026-49975 Apache HTTP Server: mod_http2 denial of serviceInformation published.MSRC.MICROSOFT.COM
9 JunCVE-2026-40930 LIBPNG: Chunk smuggling in push-mode APNG parser via unconsumed chunk bodyInformation published.MSRC.MICROSOFT.COM
9 JunCVE-2026-10879 DBI versions before 1.648 for Perl have a heap overflow when preparsing SQL statements with more than 9 bindersInformation published.MSRC.MICROSOFT.COM
9 JunCVE-2026-50256 Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: stack buffer overflow in font alias resolution due to libxfont2 name length mismatchInformation published.MSRC.MICROSOFT.COM
9 JunCVE-2026-50262 Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: out-of-bounds read/write in glx changedrawableattributesInformation published.MSRC.MICROSOFT.COM
9 JunCVE-2026-50260 Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: use-after-free in freecounter()Information published.MSRC.MICROSOFT.COM
9 JunCVE-2026-50257 Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: use-after-free in misyncdestroyfence()Information published.MSRC.MICROSOFT.COM
9 JunCVE-2026-50258 Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: stack buffer overflow in xkb key types due to unchecked shift levelsInformation published.MSRC.MICROSOFT.COM
9 JunCVE-2026-50263 Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: use-after-free information disclosure in createsaverwindow()Information published.MSRC.MICROSOFT.COM
9 JunCVE-2026-46272 coresight: tmc-etr: Fix race condition between sysfs and perf modeInformation published.MSRC.MICROSOFT.COM
9 JunCVE-2026-50292 In libinput before 1.30.4 and 1.31.x before 1.31.3, libinput-device-group unescaped phys output can inject udev properties leading to arbitrary root code executionInformation published.MSRC.MICROSOFT.COM
9 JunCVE-2026-50265 Rejected reason: This CVE ID was assigned as a duplicate of CVE-2026-50292Information published.MSRC.MICROSOFT.COM
9 JunCVE-2026-50261 Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: use-after-free in syncchangecounter()Information published.MSRC.MICROSOFT.COM
9 JunCVE-2026-50259 Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: stack buffer overflow in xkb setmap request via mapwidths indexingInformation published.MSRC.MICROSOFT.COM
9 Jun KEVGoogle Releases Patch for Chrome Vulnerability Exploited in the WildThe flaw, CVE-2026-11645, can allow a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML pageINFOSECURITY-MAGAZINE.COM
9 Jun KEVCheck Point warns of ransomware-linked attacks exploiting outdated VPN protocolCheck Point has issued emergency hotfixes for a pair of vulnerabilities affecting VPN deployments that still use the deprecated Internet Key Exchange version 1 (IKEv1) protocol, warning that one of the flaws is already being exploited in the wild. The more serious issue allows at…CSOONLINE.COM
9 Jun KEVGoogle patches Chrome zero-day exploited in the wild (CVE-2026-11645)Google has fixed 74 vulnerabilities in Chrome, including a high-severity zero-day (CVE-2026-11645) that has been exploited in the wild. “Google is aware that an exploit for CVE-2026-11645 exists in the wild,” the company said in a Monday security advisory. The fix has…HELPNETSECURITY.COM
9 JunWinRAR Flaw Exploited by Russia-Aligned Groups to Deploy Stealers in UkraineTwo Russia-aligned cyber attack campaigns have continued to exploit a security flaw in WinRAR to target Ukrainian organisations, almost a year after patches for the vulnerability were released. The activity has been attributed by Trend Micro to Earth Dahu (aka Gamaredon) and SHAD…THEHACKERNEWS.COM
9 Jun KEVChrome V8 Zero-Day CVE-2026-11645 Exploited in the Wild - Patch NowGoogle has released security updates to address 74 vulnerabilities, including one that has come under active exploitation in the wild. The high-severity vulnerability, tracked as CVE-2026-11645 (CVSS score: 8.8), has been described as an out-of-bounds memory access in V8, Chrome'…THEHACKERNEWS.COM
9 JunRussian Attackers Weaponize WinRAR Flaw Against Ukrainian OrgsTwo separate campaigns target CVE-2025-8088, fixed last July, to conduct data theft and cyberespionage against military and government targets in Ukraine.DARKREADING.COM
9 JunVeeam Backup & Replication RCE Flaw Lets Domain Users Run Remote CodeVeeam has released security patches to address a critical flaw in its Backup & Replication software that could result in remote code execution. Tracked as CVE-2026-44963, the vulnerability carries a CVSS score of 9.4 out of a maximum of 10.0. "A vulnerability allowing remote …THEHACKERNEWS.COM
9 JunVU#616257: Microsoft-signed UEFI shim bootloaders vulnerable to Secure Boot bypassOverview Microsoft-signed UEFI bootloaders of the open-source shim project, primarily from version 0.9 and earlier, were identified as vulnerable to Secure Boot bypass. To mitigate this risk, the affected bootloaders will be added to the Microsoft UEFI Forbidden Signature Databas…KB.CERT.ORG
8 Jun KEVCISA: Patch actively exploited SolarWinds Serv-U DoS vulnerability (CVE-2026-28318)A vulnerability (CVE-2026-28318) that can be exploited to crash SolarWinds Serv-U file transfer servers is being leveraged by attackers in the wild, the US Cybersecurity and Infrastructure Security Agency (CISA) confirmed on Friday. The agency has ordered US federal civilian agen…HELPNETSECURITY.COM
8 JunGoogle Protocol Buffers flaw turns schemas into shellsA widely used JavaScript implementation of Google’s Protocol Buffers format is placing too much trust in untrusted data, exposing affected applications to remote code execution and other attacks. Researchers at Cyera have disclosed six vulnerabilities affecting “ protobuf.js ,” a…CSOONLINE.COM
8 JunQilin ransomware affiliate exploited Check Point VPN zero-day (CVE-2026-50751)A Qilin ransomware affiliate is believed to be exploiting CVE-2026-50751, an authentication bypass vulnerability in Check Point VPN Remote Access and Mobile Access, the company announced on Monday. About CVE-2026-50751 Check Point Remote Access VPN enables and secures connections…HELPNETSECURITY.COM
8 Jun KEVCritical Check Point VPN Flaw Exploited to Bypass Passwords in IKEv1 SetupsCheck Point has warned of active exploitation of a critical vulnerability impacting Remote Access VPN and Mobile Access deployments that are configured to use the deprecated IKEv1 key exchange protocol. The vulnerability, tracked as CVE-2026-50751 (CVSS score: 9.3), is a case of …THEHACKERNEWS.COM
8 Jun KEVAttackers exploiting unpatched Cisco SD-WAN flawCisco warns customers of an actively exploited high-severity vulnerability in Catalyst SD-WAN Manager, an enterprise network management system that has been targeted by hackers multiple times in the past. Located in the command-line interface, the flaw allows authenticated attack…CSOONLINE.COM
7 JunCVE-2026-42504 Quadratic complexity in WordDecoder.DecodeHeader in mimeInformation published.MSRC.MICROSOFT.COM
7 JunCVE-2026-50219 libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_GetBuffer, XML_Parse, XML_ParseBuffer, XML_ParserFree, or XML_ParserReset from within handlers in cases of a policy violation. Thus, a use-after-free can occur,Information published.MSRC.MICROSOFT.COM
7 JunCVE-2026-10722 cilium ebpf LoadCollectionSpec/LoadCollectionSpecFromReader btf.go loadRawSpec integer overflowInformation published.MSRC.MICROSOFT.COM
7 JunCVE-2026-43958 Rrdtool: rrdtool: stack buffer overflow allows local code execution or denial of serviceInformation published.MSRC.MICROSOFT.COM
7 JunCVE-2026-8643 pip can extract console_scripts and gui_scripts outside installation directoryInformation published.MSRC.MICROSOFT.COM
7 JunCVE-2026-42507 Arbitrary inputs are included in errors without any escaping in net/textprotoInformation published.MSRC.MICROSOFT.COM
7 JunCVE-2026-27145 Inefficient candidate hostname parsing in crypto/x509Information published.MSRC.MICROSOFT.COM
7 JunCVE-2026-11332 Ansible-core: argument injection in ansible-galaxy role install leads to arbitrary code executionInformation published.MSRC.MICROSOFT.COM
7 JunCVE-2026-37460 Missing input validation in the rfapiRibBi2Ri() function (rfapi_rib.c) of FRRouting (FRR) stable/10.0 to stable/10.6 allows attackers to cause a Denial of Service (DoS) via supplying a crafted BGP UPDATE message.Information published.MSRC.MICROSOFT.COM
7 JunCVE-2026-5419 Guntls: gnutls: information disclosure via timing side-channel in pkcs#7 padding removalInformation published.MSRC.MICROSOFT.COM
7 JunCVE-2026-8829 HTML::Entities versions before 3.84 for Perl read freed heap memory in _decode_entitiesInformation published.MSRC.MICROSOFT.COM
7 JunCVE-2026-3276 Potential DoS via quadratic complexity in unicodedata.normalize()Information published.MSRC.MICROSOFT.COM
7 JunCVE-2026-7774 tarfile.data_filter path traversal bypass allows writing outside the extraction directoryInformation published.MSRC.MICROSOFT.COM
6 Jun KEVCisco Catalyst SD-WAN Manager CVE-2026-20245 Flaw Actively Exploited – No Patch AvailableCisco has warned that a high-severity security flaw impacting Catalyst SD-WAN Manager has come under active exploitation. The vulnerability, tracked as CVE-2026-20245, carries a CVSS score of 7.8 out of a maximum of 10.0. It affects the following deployment types - On-Prem Deploy…THEHACKERNEWS.COM
6 JunCritical Everest Forms Pro flaw exploited to take over WordPress sitesHackers are actively exploiting a critical vulnerability (CVE-2026-3300) in the Everest Forms Pro plugin, which lets them take complete control of a WordPress website. [...]BLEEPINGCOMPUTER.COM
5 JunHackers Exploit Critical Everest Forms Pro WordPress Plugin Flaw to Take Over SitesThreat actors are actively exploiting a critical security flaw in Everest Forms Pro, a WordPress plugin with about 4,000 active installations, to execute arbitrary code, leading to a complete site compromise. The vulnerability in question is CVE-2026-3300 (CVSS score: 9.8), a rem…THEHACKERNEWS.COM
5 JunUS government report slams NIST for NVD backlogA report from the US Commerce department’s inspector general blames the National Institute of Standards and Technology (NIST) for the ever-growing backlog of vulnerabilities for inclusion in the National Vulnerability Database (NVD). But cybersecurity practitioners say that the b…CSOONLINE.COM
5 JunCisco warns of unpatched SD-WAN zero-day exploited in attacksOn Thursday, Cisco warned of a high-severity, unpatched zero-day in the Cisco Catalyst SD-WAN Manager (tracked as CVE-2026-20245) actively exploited in attacks enabling root privilege escalation. [...]BLEEPINGCOMPUTER.COM
5 JunCisco Warns of 7th SD-WAN Zero-Day Exploited in 2026The vulnerability is tracked as CVE-2026-20245 and it can allow arbitrary command execution as root, but no patch yet. The post Cisco Warns of 7th SD-WAN Zero-Day Exploited in 2026 appeared first on SecurityWeek .SECURITYWEEK.COM
5 JunCisco SD-WAN 0-day exploited, no patch available (CVE-2026-20245)A 0-day privilege escalation vulnerability (CVE-2026-20245) in Cisco Catalyst SD-WAN Manager that has yet to be patched by Cisco is being leveraged by attackers. “To exploit this vulnerability, an attacker must have netadmin privileges on an affected system. This would requ…HELPNETSECURITY.COM
5 JunClaude Code has an MCP security problem — and your developers are already using itClaude Code is Anthropic’s AI coding assistant — a command-line tool that developers are adopting fast. It connects to external services through Model Context Protocol, the standard that lets AI tools interact with Jira, Confluence, GitHub, databases and internal APIs. When a dev…CSOONLINE.COM
5 JunThreat Brief: Active Exploitation of PAN-OS CVE-2026-0257We include indicators of activity and mitigations for PAN-OS vulnerability CVE-2026-0257. The post Threat Brief: Active Exploitation of PAN-OS CVE-2026-0257 appeared first on Unit 42 .UNIT42.PALOALTONETWORKS.COM
4 JunHugging Face Transformers RCE flaw enables stealthy compromise via AI model configsA high severity vulnerability in Hugging Face Transformers enables attackers to compromise systems that use the popular Python library to test and run AI models. The flaw impacts library versions that continue to be actively downloaded and comes at a time when attackers are incre…CSOONLINE.COM
4 JunHTTP/2’s speed abused to slow webserver performance in DoS attackSecurity researchers are warning of an issue with the default HTTP/2 configuration used by major web servers which reportedly survived more than a decade of human review before showing up in Codex-assisted analysis. A flaw in the handling of the HTTP/2 protocol made a denial-of-s…CSOONLINE.COM
4 JunCisco Patches CVE-2026-20230 in Unified CM as Exploit Code Goes PublicCisco has patched a bug in Unified Communications Manager that lets an unauthenticated attacker on the network write files to the box and, from there, climb to root. It is tracked as CVE-2026-20230, and proof-of-concept exploit code is already public. Cisco's PSIRT says it has no…THEHACKERNEWS.COM
4 JunSecurity Researchers Are Threat Actors - PSW #929This week in the security news: - Security Researchers Are Threat Actors according to Microsoft - Hands-free malicious firmware - If you've ever typed "ls" in Windows, this is for you - Cisco makes more patches, wants you to pay - Ambiguous Secure Boot bypass - Threat actors love…YOUTUBE.COM
3 Jun KEVGoogle June 2026 Android Update Patches 124 Flaws, One Actively ExploitedGoogle on Monday released patches for 124 security vulnerabilities impacting its Android operating system for the month of June 2026, including one high-severity flaw in the Framework component that has come under active exploitation. Tracked as CVE-2025-48595 (CVSS score: 8.4), …THEHACKERNEWS.COM
3 JunCVE-2025-4574 Crossbeam-channel: crossbeam-channel vulnerable to double free on dropInformation published.MSRC.MICROSOFT.COM
3 JunCVE-2019-11254 Kubernetes API Server denial of service vulnerability from malicious YAML payloadsInformation published.MSRC.MICROSOFT.COM
3 JunCVE-2023-1386 Qemu: 9pfs: suid/sgid bits not dropped on file writeInformation published.MSRC.MICROSOFT.COM
3 JunCVE-2026-33846 Gnutls: gnutls: denial of service via heap buffer overflow in dtls handshake fragment reassemblyInformation published.MSRC.MICROSOFT.COM
3 JunCVE-2026-44777 jq: stack overflow in module loading on mutual `include`Information published.MSRC.MICROSOFT.COM
3 JunCVE-2021-25740 Holes in EndpointSlice Validation Enable Host Network HijackInformation published.MSRC.MICROSOFT.COM
3 JunCVE-2013-1633 easy_install in setuptools before 0.7 uses HTTP to retrieve packages from the PyPI repository, and does not perform integrity checks on package contents, which allows man-in-the-middle attackers to execute arbitrary code via a crafted response to the default use of the product.Information published.MSRC.MICROSOFT.COM
3 JunCVE-2025-1150 GNU Binutils ld libbfd.c bfd_malloc memory leakInformation published.MSRC.MICROSOFT.COM
3 JunCVE-2025-1180 GNU Binutils ld elf-eh-frame.c _bfd_elf_write_section_eh_frame memory corruptionInformation published.MSRC.MICROSOFT.COM
3 JunUnpatched Windows Search URI Vulnerability Lets Attackers Steal NTLMv2 HashesCybersecurity researchers have disclosed details of an unpatched issue that could be exploited to disclose a user's NTLMv2 hash to the attacker. Like in the case of CVE-2026-33829, which impacted the Windows Snipping Tool's ms-screensketch: URI handler, the newly flagged issue re…THEHACKERNEWS.COM
3 JunTenable CTO Q&A: C-suite views AI as massive threat, as cyber teams adopt exposure management to counter AI attacksTenable CTO Vlad Korsunsky talks about participating in the World Economic Forum’s Annual Meeting on Cybersecurity and Tenable’s EXPOSURE 2026 conference, where he talked with global leaders about new game-changing AI threats and the groundbreaking benefits of exposure management…TENABLE.COM
3 JunVerizon VoLTE network found missing IPsec protections for SIP signalingThe CERT Coordination Center (CERT/CC) has disclosed a security issue affecting Verizon's Voice over LTE (VoLTE) infrastructure, warning that SIP signaling traffic on the carrier's IP Multimedia Subsystem (IMS) network appears to lack IPsec integrity protection required by indust…CYBERINSIDER.COM
3 JunVU#595768: Securly Chrome Extension contains multiple weak encryption and access control vulnerabilitiesOverview Version 3.0.7 of the Securly Chrome Extension contains multiple vulnerabilities involving insecure data transmission, weak cryptography, and improper access control. These issues may expose sensitive filtering rules, enable the manipulation of downloaded configuration fi…KB.CERT.ORG
2 JunCVE-2026-10028 Glib-networking: infinite loop in glib-networking gnutls backend allows remote denial of service via circular certificate chainInformation published.MSRC.MICROSOFT.COM
2 JunCVE-2026-6324 Libsoup: libsoup: http request smuggling via unsigned to signed conversion errorInformation published.MSRC.MICROSOFT.COM
2 JunCVE-2026-48959 IO::Uncompress::Unzip versions before 2.220 for Perl allow CPU exhaustion via per-byte read loop in fastForwardInformation published.MSRC.MICROSOFT.COM
2 Jun KEVOracle WebLogic Vulnerability Exploited in the WildThe vulnerability is CVE-2024-21182 and it can be exploited without authentication to hack affected WebLogic servers. The post Oracle WebLogic Vulnerability Exploited in the Wild appeared first on SecurityWeek .SECURITYWEEK.COM
2 Jun KEVGoogle fixes actively exploited Android vulnerability (CVE-2025-48595)Google has announced the June 2026 Android security updates, which fix a bucketload of vulnerabilities, including a high-severity vulnerability (CVE-2025-48595) in the Android Framework that “may be under limited, targeted exploitation.” About CVE-2025-48595 CVE-2025-…HELPNETSECURITY.COM
2 JunVU#873170: Collibra Agent contains improper authentication and path traversal vulnerabilitiesOverview The Collibra Platform Agent contains vulnerabilities that can be chained by a remote, unauthenticated attacker to achieve remote code execution. An attacker can exploit these issues by uploading a crafted ZIP archive that writes attacker-controlled files to arbitrary loc…KB.CERT.ORG
2 Jun KEVAndroid June 2026 update patches actively exploited zero-dayGoogle has released the June 2026 Android security updates, addressing dozens of vulnerabilities across the mobile operating system, including a high-severity zero-day flaw that is under active, targeted exploitation. The update also fixes multiple critical privilege-escalation a…CYBERINSIDER.COM
2 JunVU#615987: Missing IPsec Integrity Protection for IMS SIP Signaling in Verizon VoLTE DeploymentsOverview VoLTE deployments on Verizon’s IMS network have historically lacked IPsec-based integrity protection for SIP signaling, contravening well-established requirements in 3GPP TS 33.203 and GSMA IR.92. As a result, SIP messages—including registration ( REGISTER ), call setup …KB.CERT.ORG
2 JunVU#265691: Appsmiths SQL Query autocomplete renderer contains a cross site scripting vulnerabilityOverview A stored cross-site scripting (XSS) vulnerability has been discovered in Appsmith, specifically in the CodeMirror based SQL query editor’s autocomplete renderer. CVE-2026-7299 has been assigned to track the vulnerability. An attacker with developer level access to a shar…KB.CERT.ORG
2 JunAndroid Update Patches Exploited Zero-Day, 123 Other VulnerabilitiesGoogle says the Android vulnerability CVE-2025-48595 has been exploited in limited, targeted attacks. The post Android Update Patches Exploited Zero-Day, 123 Other Vulnerabilities appeared first on SecurityWeek .SECURITYWEEK.COM
2 JunPresident Trump picks housing director Bill Pulte to serve as acting DNI.Federal watchdog warns of management issues for NIST's NVD. Spanish National Police arrest suspect in government doxxing case.THECYBERWIRE.COM
2 JunGamaredon Exploits WinRAR to Deliver GammaWorm and GammaSteel Against UkraineThe Russian hacking group known as Gamaredon has been attributed to the continued exploitation of a WinRAR vulnerability to deliver multiple malware families aimed at data theft and propagation. Per Sekoia, the activity involves the weaponization of CVE-2025-8088, a path traversa…THEHACKERNEWS.COM
2 JunHP Poly VoIP vulnerability sets the stage for executive voice deepfakesHP has released patches for a critical buffer overflow vulnerability in multiple IP-enabled conference phones from its Poly Voice line. The flaw allows unauthenticated attackers to obtain root privileges on the underlying operating system, potentially enabling them to execute oth…CSOONLINE.COM
2 JunCritical Kirki flaw exploited to hijack WordPress admin accountsHackers are exploiting a critical privilege escalation vulnerability (CVE-2026-8206) in the Kirki plugin for WordPress to take over any user account, including those belonging to administrators. [...]BLEEPINGCOMPUTER.COM
1 Jun KEVMicrosoft Threatens Security Researcher | Palo Alto VPN Exploited | Google Insider Trading CaseMicrosoft's dispute with a former security researcher takes a dramatic turn as the company raises the possibility of criminal action over the publication of proof-of-concept code for unpatched zero-day vulnerabilities. David Shipley examines the escalating conflict between Micros…CYBERSECURITYTODAY.LIBSYN.COM
1 JunHackers are exploiting Palo Alto GlobalProtect VPN authentication bypass (CVE-2026-0257)Authentication bypass vulnerabilities (CVE-2026-0257) in Palo Alto Networks’ firewalls that the company disclosed on May 13 have been targeted in “limited exploit attempts”. “Across multiple customers, Rapid7 observed successful exploitation via authentica…HELPNETSECURITY.COM
1 JunRecent Palo Alto Networks Vulnerability Exploited for WeeksHackers began exploiting CVE-2026-0257, an authentication bypass in Palo Alto Networks PAN-OS, four days after public disclosure. The post Recent Palo Alto Networks Vulnerability Exploited for Weeks appeared first on SecurityWeek .SECURITYWEEK.COM
1 JunFlowise’s MCP implementation can run ghost commandsEnterprises using the lightweight, open-source Flowise platform to power self-hosted AI workloads have a new near-max severity issue to worry about. Researchers at Obsidian Security have detailed a one-click remote code execution (RCE) vulnerability affecting self-hosted Flowise …CSOONLINE.COM
1 JunHow NIST fumbled management of the National Vulnerability DatabaseA US federal watchdog has outlined how the National Institute of Standards and Technology (NIST) failed to effectively manage the growing backlog of unprocessed cybersecurity vulnerabilities in the National Vulnerability Database (NVD). How the NVD crisis unfolded The NVD was est…HELPNETSECURITY.COM
1 JunCVE-2026-0826: How an Old Bug Can Feed AI-Powered ImpersonationOne of the more persistent myths in security is that old bug classes become old problems. They don’t. They just show up in different places, under different conditions, and usually at the exact moment we’ve convinced ourselves not to pay attention to them. That’s part of what mak…RAPID7.COM
1 JunCVE-2026-0826: Critical unauthenticated stack buffer overflow in HP Poly VVX and Trio VoIP Phones (FIXED)Overview Rapid7 Labs conducted a zero-day research project against an HP Poly VVX 450 Voice over Internet Protocol (VoIP) phone. This research resulted in the discovery of a critical unauthenticated stack-based buffer overflow vulnerability, CVE-2026-0826. A remote attacker can l…RAPID7.COM
1 JunCritical Windows Netlogon Vulnerability in Attackers’ CrosshairsOrganizations are advised to patch CVE-2026-41089 as soon as possible, given its severity, the potential ongoing exploitation. The post Critical Windows Netlogon Vulnerability in Attackers’ Crosshairs appeared first on SecurityWeek .SECURITYWEEK.COM
1 Jun KEVWindows Netlogon RCE exploited, domain controllers at risk (CVE-2026-41089)CVE-2026-41089, a critical Windows Netlogon RCE flaw that allows remote code execution, is now actively exploited in the wild, the Centre for Cybersecurity Belgium (CCB) warned on Friday. About CVE-2026-41089 CVE-2026-41089 is a stack-based buffer overflow vulnerability in Window…HELPNETSECURITY.COM
1 JunVU#158530: PCTCore64.sys Windows kernel driver contains missing access control vulnerabilityOverview The PCTCore64.sys Windows kernel driver from PC Tools Internet Security exposes its \\.\PCTCoreDriver device interface with no access control, allowing any user-mode process to interact with the driver and invoke privileged IOCTL (I/O Control) commands. In a Bring Your O…KB.CERT.ORG
1 JunOracle’s first monthly patch release fixes 35 flaws, including 11 rated ‘critical’Oracle has released the first security fixes in its new monthly Critical Security Patch Update (CSPU) cycle, designed to address urgent vulnerabilities that can’t wait for the company’s quarterly patching. The initial batch addresses 35 flaws, including several for which exploit …CSOONLINE.COM
1 JunWP Maps Pro Vulnerability Exploited to Take Over WordPress SitesThe security defect (CVE-2026-8732) allows unauthenticated attackers to create administrative accounts on the affected installations. The post WP Maps Pro Vulnerability Exploited to Take Over WordPress Sites appeared first on SecurityWeek .SECURITYWEEK.COM
1 JunInspector general finds NIST mistakes have made vulnerability database ineffectiveNIST’s National Vulnerability Database (NVD) backlog mushroomed from 13,000 unprocessed security vulnerabilities in February 2024 to more than 27,000 by the end of 2025, “undermining the NVD’s utility and public trust," according to an inspector general report.THERECORD.MEDIA
1 JunAttackers are exploiting Palo Alto Networks defect that initially flew under the radarThe escalated threat posed by the defect showcases how quickly a seemingly mild vulnerability can turn into an urgent warning. The post Attackers are exploiting Palo Alto Networks defect that initially flew under the radar appeared first on CyberScoop .CYBERSCOOP.COM
31 MayCVE-2025-15504 lief-project LIEF ELF Binary Parser.tcc parse_binary null pointer dereferenceInformation published.MSRC.MICROSOFT.COM
31 MayCVE-2024-36137 A vulnerability has been identified in Node.js, affecting users of the experimental permission model when the --allow-fs-write flag is used.
Node.js Permission Model do not operate on file descriptors, however, operations such as fs.fchown or fs.fchmod can use a "read-only" file descriptor to change the owner and permissions of a file.Information published.MSRC.MICROSOFT.COM
31 MayCVE-2026-46242 eventpoll: fix ep_remove struct eventpoll / struct file UAFInformation published.MSRC.MICROSOFT.COM
31 MayCVE-2026-42790 nameConstraints DNS bypass via subject CommonName fallback in public_key hostname verificationInformation published.MSRC.MICROSOFT.COM
31 MayCVE-2026-42012 Gnutls: gnutls: certificate validation bypass due to improper handling of uri and srv sansInformation published.MSRC.MICROSOFT.COM
31 MayCVE-2026-9804 Kubevirt: kubevirt: vmexport directory symlink escape enables exporter pod file readInformation published.MSRC.MICROSOFT.COM
31 MayCVE-2026-48864 Libsolv: heap buffer overflow in libsolv repopagestore via unchecked decompression of malicious .solv page dataInformation published.MSRC.MICROSOFT.COM
31 MayCVE-2026-48962 IO::Compress versions before 2.220 for Perl can execute arbitrary code in File::GlobMapper via an attacker-controlled output globInformation published.MSRC.MICROSOFT.COM
31 MayCVE-2026-40034 gitoxide - Command Injection via Partial .gitmodules Override in gix-submoduleInformation published.MSRC.MICROSOFT.COM
31 MayCVE-2026-40528 OpenSC < 0.27.0 Buffer Overrun in do_key_value() via profile.cInformation published.MSRC.MICROSOFT.COM
31 MayCVE-2026-40510 OpenSC < 0.27.0-rc1 Stack Buffer Overflow via piv_process_history() in card-piv.cInformation published.MSRC.MICROSOFT.COM
31 MayCVE-2026-42789 Non-CA certificate accepted as intermediate issuer in public_key path validationInformation published.MSRC.MICROSOFT.COM
31 MayCVE-2026-42013 Gnutls: gnutls: certificate validation bypass due to oversized subject alternative nameInformation published.MSRC.MICROSOFT.COM
31 MayCVE-2026-42015 Gnutls: gnutls: memory corruption due to off-by-one error in pkcs#12 bag handlingInformation published.MSRC.MICROSOFT.COM
31 MayCVE-2026-5260 Gnutls: gnutls: information disclosure via heap overread in rsa key exchangeInformation published.MSRC.MICROSOFT.COM
31 MayCVE-2026-7374 Kubevirt: kubevirt virt-handler: privilege escalation and node compromise via symlink following vulnerabilityInformation published.MSRC.MICROSOFT.COM
31 MayCVE-2025-15649 IO::Uncompress::Unzip versions before 2.215 for Perl propagate uncaught exception when parsing zip header with malformed DOS dateInformation published.MSRC.MICROSOFT.COM
31 MayCVE-2026-44839 RabbitMQ: Unsanitized vhost names allow for XSS in management UIInformation published.MSRC.MICROSOFT.COM
30 MayPAN-OS GlobalProtect Authentication Bypass (CVE-2026-0257) Under Active ExploitationPalo Alto Networks has warned that a recently disclosed medium-severity security flaw impacting PAN-OS and Prisma Access has come under active exploitation in the wild. The vulnerability, tracked as CVE-2026-0257 (CVSS score: 7.8), refers to a case of authentication bypass that c…THEHACKERNEWS.COM
30 MayCVE-2026-41184 ServiceAccount token disclosure via install-cni container logsInformation published.MSRC.MICROSOFT.COM
30 MayPalo Alto GlobalProtect VPN auth bypass flaw now exploited in attacksPalo Alto Networks is warning that hackers are now exploiting a PAN-OS GlobalProtect authentication bypass flaw, tracked as CVE-2026-0257, in attacks attempting to breach corporate networks. [...]BLEEPINGCOMPUTER.COM
29 MayIBM and Red Hat want to become the ‘security clearinghouse’ for open source applications in the enterpriseOpen source code is everywhere in the enterprise; it’s estimated that upwards of 90% of Fortune 500 companies have it in their software supply chains. But open source code is notoriously rife with vulnerabilities, and identifying and patching those bugs can be an endless battle f…CSOONLINE.COM
29 MayCVE-2026-46219 spi: mpc52xx: fix use-after-free on unbindInformation published.MSRC.MICROSOFT.COM
29 MayCVE-2026-46214 vsock/virtio: fix accept queue count leak on transport mismatchInformation published.MSRC.MICROSOFT.COM
29 MayCVE-2026-46137 mptcp: pm: ADD_ADDR rtx: fix potential data-raceInformation published.MSRC.MICROSOFT.COM
29 MayCVE-2026-46186 Bluetooth: virtio_bt: validate rx pkt_type header lengthInformation published.MSRC.MICROSOFT.COM
29 MayCVE-2026-46172 ipv6: xfrm6: release dst on error in xfrm6_rcv_encap()Information published.MSRC.MICROSOFT.COM
29 MayCVE-2026-46168 mptcp: fix scheduling with atomic in timestamp sockoptInformation published.MSRC.MICROSOFT.COM
29 MayCVE-2026-46163 wifi: b43legacy: enforce bounds check on firmware key index in RX pathInformation published.MSRC.MICROSOFT.COM
29 MayCVE-2026-46131 KVM: x86: check for nEPT/nNPT in slow flush hypercallsInformation published.MSRC.MICROSOFT.COM
29 MayCVE-2026-46110 net: stmmac: Prevent NULL deref when RX memory exhaustedInformation published.MSRC.MICROSOFT.COM
29 MayCVE-2026-46128 ipmi: Check event message buffer response for bad dataInformation published.MSRC.MICROSOFT.COM
29 MayCVE-2026-42250 Off-by-One Leading to Out-of-Bounds Write in bzip2Information published.MSRC.MICROSOFT.COM
29 MayCVE-2026-46191 fbcon: Avoid OOB font access if console rotation failsInformation published.MSRC.MICROSOFT.COM
29 MayCVE-2026-46159 btrfs: fix btrfs_ioctl_space_info() slot_count TOCTOU which can lead to info-leakInformation published.MSRC.MICROSOFT.COM
29 MayCVE-2026-46226 spi: fsl: fix controller deregistrationInformation published.MSRC.MICROSOFT.COM
29 MayCVE-2026-46165 openvswitch: vport: fix self-deadlock on release of tunnel portsInformation published.MSRC.MICROSOFT.COM
29 MayCVE-2026-46158 mptcp: pm: ADD_ADDR rtx: always decrease sk refcountInformation published.MSRC.MICROSOFT.COM
29 MayCVE-2026-46232 HID: playstation: Clamp num_touch_reportsInformation published.MSRC.MICROSOFT.COM
29 MayCVE-2026-46197 drm/amdkfd: validate SVM ioctl nattr against buffer sizeInformation published.MSRC.MICROSOFT.COM
29 MayCVE-2026-46220 drm/amdgpu/sdma4: replace BUG_ON with WARN_ON in fence emissionInformation published.MSRC.MICROSOFT.COM
29 MayCVE-2026-46107 dm-thin: fix metadata refcount underflowInformation published.MSRC.MICROSOFT.COM
29 MayCVE-2026-46176 RDMA/mlx5: Fix error path fall-through in mlx5_ib_dev_res_srq_init()Information published.MSRC.MICROSOFT.COM
29 MayCVE-2026-46149 scsi: target: configfs: Bound snprintf() return in tg_pt_gp_members_show()Information published.MSRC.MICROSOFT.COM
29 MayCVE-2026-46208 batman-adv: stop tp_meter sessions during mesh teardownInformation published.MSRC.MICROSOFT.COM
29 MayCVE-2026-46116 xfrm: defensively unhash xfrm_state lists in __xfrm_state_deleteInformation published.MSRC.MICROSOFT.COM
29 MayCVE-2026-46225 spi: rspi: fix controller deregistrationInformation published.MSRC.MICROSOFT.COM
29 MayCVE-2026-46236 media: rc: xbox_remote: heed DMA restrictionsInformation published.MSRC.MICROSOFT.COM
29 MayCVE-2026-46164 btrfs: fix double free in create_space_info_sub_group() error pathInformation published.MSRC.MICROSOFT.COM
29 MayCVE-2026-46235 media: saa7164: add ioremap return checks and cleanupsInformation published.MSRC.MICROSOFT.COM
29 MayCVE-2026-46127 RDMA/ocrdma: Don't NULL deref uctx on errors in ocrdma_copy_pd_uresp()Information published.MSRC.MICROSOFT.COM
29 MayCVE-2026-46177 ipmi: Add limits to event and receive message requestsInformation published.MSRC.MICROSOFT.COM
29 MayCVE-2026-46155 smb/client: fix out-of-bounds read in smb2_compound_op()Information published.MSRC.MICROSOFT.COM
29 MayCVE-2026-46157 ALSA: pcm: oss: Fix data race at accessing runtime.oss.triggerInformation published.MSRC.MICROSOFT.COM
29 MayCVE-2026-46136 wifi: mt76: mt7921: fix a potential clc buffer length underflowInformation published.MSRC.MICROSOFT.COM
29 MayCVE-2026-46132 net: rtnetlink: zero ifla_vf_broadcast to avoid stack infoleak in rtnl_fill_vfinfoInformation published.MSRC.MICROSOFT.COM
29 MayCVE-2026-46170 mptcp: pm: ADD_ADDR rtx: free sk if lastInformation published.MSRC.MICROSOFT.COM
29 MayCVE-2026-46190 mtd: spi-nor: debugfs: fix out-of-bounds read in spi_nor_params_show()Information published.MSRC.MICROSOFT.COM
29 MayCVE-2026-46230 drm/amdgpu/vcn3: Prevent OOB reads when parsing dec msgInformation published.MSRC.MICROSOFT.COM
29 MayCVE-2026-46175 f2fs: fix fsck inconsistency caused by FGGC of node blockInformation published.MSRC.MICROSOFT.COM
29 MayCVE-2026-46123 Bluetooth: virtio_bt: clamp rx length before skb_putInformation published.MSRC.MICROSOFT.COM
29 MayCVE-2026-46238 batman-adv: stop caching unowned originator pointers in BAT IVInformation published.MSRC.MICROSOFT.COM
29 MayCVE-2026-46120 ip6_gre: Use cached t->net in ip6erspan_changelink().Information published.MSRC.MICROSOFT.COM
29 MayCVE-2026-46108 ipmi:si: Return state to normal if message allocation failsInformation published.MSRC.MICROSOFT.COM
29 MayCVE-2026-46152 wifi: mac80211: drop stray 'static' from fast-RX rx_resultInformation published.MSRC.MICROSOFT.COM
29 MayCVE-2026-46112 RDMA/hns: Fix unlocked call to hns_roce_qp_remove()Information published.MSRC.MICROSOFT.COM
29 MayCVE-2026-46114 RDMA/rxe: Reject non-8-byte ATOMIC_WRITE payloadsInformation published.MSRC.MICROSOFT.COM
29 MayCVE-2026-46122 wifi: b43: enforce bounds check on firmware key index in b43_rx()Information published.MSRC.MICROSOFT.COM
29 MayCVE-2026-46146 ALSA: usb-audio: Avoid potential endless loop in convert_chmap_v3()Information published.MSRC.MICROSOFT.COM
29 MayCVE-2026-46125 wifi: mac80211: remove station if connection prep failsInformation published.MSRC.MICROSOFT.COM
29 MayCVE-2026-46227 sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALLInformation published.MSRC.MICROSOFT.COM
29 MayCVE-2026-46153 8021q: delete cleared egress QoS mappingsInformation published.MSRC.MICROSOFT.COM
29 MayCVE-2026-46150 fanotify: fix false positive on permission eventsInformation published.MSRC.MICROSOFT.COM
29 MayCVE-2026-46241 spi: mpc52xx: fix use-after-free on registration failureInformation published.MSRC.MICROSOFT.COM
29 MayCVE-2026-46147 KVM: arm64: Fix pin leak and publication ordering in __pkvm_init_vcpu()Information published.MSRC.MICROSOFT.COM
29 MayCVE-2026-46135 nvmet-tcp: fix race between ICReq handling and queue teardownInformation published.MSRC.MICROSOFT.COM
29 MayCVE-2026-42496 Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directoryInformation published.MSRC.MICROSOFT.COM
29 MayCVE-2026-46189 RDMA/vmw_pvrdma: Fix double free on pvrdma_alloc_ucontext() error pathInformation published.MSRC.MICROSOFT.COM
29 MayCVE-2026-9538 Archive::Tar versions before 3.10 for Perl allow memory exhaustion via attacker controlled entry size field in tar headerInformation published.MSRC.MICROSOFT.COM
29 MayCVE-2026-46199 drm/amdgpu/vcn4: Prevent OOB reads when parsing dec msgInformation published.MSRC.MICROSOFT.COM
29 MayCVE-2026-46151 usb: usblp: fix heap leak in IEEE 1284 device ID via short responseInformation published.MSRC.MICROSOFT.COM
29 MayCVE-2026-42497 Archive::Tar versions before 3.08 for Perl extract hardlinks to attacker controlled paths outside the extraction directoryInformation published.MSRC.MICROSOFT.COM
29 MayCVE-2026-46124 isofs: validate block number from NFS file handle in isofs_export_igetInformation published.MSRC.MICROSOFT.COM
29 MayCVE-2026-46106 eventfs: Hold eventfs_mutex and SRCU when remount walks eventsInformation published.MSRC.MICROSOFT.COM
29 MayCVE-2026-46181 RDMA/mlx4: Fix mis-use of RCU in mlx4_srq_event()Information published.MSRC.MICROSOFT.COM
29 MayCVE-2026-46178 RDMA/mlx4: Fix resource leak on error in mlx4_ib_create_srq()Information published.MSRC.MICROSOFT.COM
29 MayCVE-2026-46231 batman-adv: bla: put backbone reference on failed claim hash insertInformation published.MSRC.MICROSOFT.COM
29 MayCVE-2026-46200 spi: mpc52xx: fix controller deregistrationInformation published.MSRC.MICROSOFT.COM
29 MayCVE-2026-46209 drm/gem: Fix inconsistent plane dimension calculation in drm_gem_fb_init_with_funcs()Information published.MSRC.MICROSOFT.COM
29 MayCVE-2026-46148 spi: microchip-core-qspi: control built-in cs manuallyInformation published.MSRC.MICROSOFT.COM
29 MayCVE-2026-46198 batman-adv: fix integer overflow on buff_posInformation published.MSRC.MICROSOFT.COM
29 MayCVE-2026-46111 Bluetooth: hci_conn: fix potential UAF in create_big_syncInformation published.MSRC.MICROSOFT.COM
29 MayCVE-2026-46195 smb: client: validate dacloffset before building DACL pointersInformation published.MSRC.MICROSOFT.COM
29 MayCVE-2026-46194 f2fs: fix node_cnt race between extent node destroy and writebackInformation published.MSRC.MICROSOFT.COM
29 MayCVE-2026-46109 usb: ulpi: fix memory leak on ulpi_register() error pathsInformation published.MSRC.MICROSOFT.COM
29 MayCVE-2026-46229 drm/amdkfd: Clear VRAM on allocation to prevent stale data exposureInformation published.MSRC.MICROSOFT.COM
29 MayCVE-2026-46173 exit: prevent preemption of oopsing TASK_DEAD taskInformation published.MSRC.MICROSOFT.COM
29 MayCVE-2026-46160 btrfs: fix missing last_unlink_trans update when removing a directoryInformation published.MSRC.MICROSOFT.COM
29 MayCVE-2026-46180 wifi: brcmfmac: Fix potential use-after-free issue when stopping watchdog taskInformation published.MSRC.MICROSOFT.COM
29 MayCVE-2026-46115 block: add pgmap check to biovec_phys_mergeableInformation published.MSRC.MICROSOFT.COM
29 MayCVE-2026-46185 smb/client: fix out-of-bounds read in symlink_data()Information published.MSRC.MICROSOFT.COM
29 MayCVE-2026-46161 md/raid10: fix divide-by-zero in setup_geo() with zero far_copiesInformation published.MSRC.MICROSOFT.COM
29 MayCVE-2026-46212 batman-adv: bla: prevent use-after-free when deleting claimsInformation published.MSRC.MICROSOFT.COM
29 MayCVE-2026-46205 staging: media: atomisp: Disallow all private IOCTLsInformation published.MSRC.MICROSOFT.COM
29 MayCVE-2026-46171 riscv: kvm: fix vector context allocation leakInformation published.MSRC.MICROSOFT.COM
29 MayCVE-2026-46179 ASoC: SOF: Don't allow pointer operations on unconfigured streamsInformation published.MSRC.MICROSOFT.COM
29 MayCVE-2026-46196 tracepoint: balance regfunc() on func_add() failure in tracepoint_add_func()Information published.MSRC.MICROSOFT.COM
29 MayCVE-2026-46143 ASoC: qcom: q6apm-lpass-dai: Fix multiple graph opensInformation published.MSRC.MICROSOFT.COM
29 MayCVE-2026-46133 RDMA/rxe: Reject unknown opcodes before ICRC processingInformation published.MSRC.MICROSOFT.COM
29 MayCVE-2026-46129 btrfs: fix double free in create_space_info() error pathInformation published.MSRC.MICROSOFT.COM
29 MayCVE-2026-46218 drm/amdgpu: Add bounds checking to ib_{get,set}_valueInformation published.MSRC.MICROSOFT.COM
29 MayCVE-2026-46204 drm/amdgpu/vcn4: Prevent OOB reads when parsing IBInformation published.MSRC.MICROSOFT.COM
29 MayCVE-2026-46233 batman-adv: bla: only purge non-released claimsInformation published.MSRC.MICROSOFT.COM
29 MayCVE-2026-46156 LoongArch: Fix potential ADE in loongson_gpu_fixup_dma_hang()Information published.MSRC.MICROSOFT.COM
29 MayCVE-2026-46138 Bluetooth: hci_event: Fix OOB read and infinite loop in hci_le_create_big_complete_evtInformation published.MSRC.MICROSOFT.COM
29 MayCVE-2026-46187 wifi: rsi: fix kthread lifetime race between self-exit and external-stopInformation published.MSRC.MICROSOFT.COM
29 MayCVE-2026-46167 usb: usblp: fix uninitialized heap leak via LPGETSTATUS ioctlInformation published.MSRC.MICROSOFT.COM
29 MayCVE-2026-46113 KVM: x86: Fix shadow paging use-after-free due to unexpected GFNInformation published.MSRC.MICROSOFT.COM
29 MayCVE-2026-46206 batman-adv: reject new tp_meter sessions during teardownInformation published.MSRC.MICROSOFT.COM
29 MayCVE-2026-46130 dm-verity-fec: fix reading parity bytes split across blocks (take 3)Information published.MSRC.MICROSOFT.COM
29 MayCVE-2026-46119 libceph: Fix slab-out-of-bounds access in auth message processingInformation published.MSRC.MICROSOFT.COM
29 MayCVE-2026-46169 hfsplus: fix uninit-value by validating catalog record sizeInformation published.MSRC.MICROSOFT.COM
29 MayCVE-2026-46142 net: libwx: fix VF illegal register accessInformation published.MSRC.MICROSOFT.COM
29 MayCVE-2026-46121 mm/damon/sysfs-schemes: protect memcg_path kfree() with damon_sysfs_lockInformation published.MSRC.MICROSOFT.COM
29 MayCVE-2026-46144 RDMA/mana: Fix error unwind in mana_ib_create_qp_rss()Information published.MSRC.MICROSOFT.COM
29 MayCVE-2026-46184 sound: ua101: fix division by zero at probeInformation published.MSRC.MICROSOFT.COM
29 MayCVE-2026-46174 x86/CPU/AMD: Prevent improper isolation of shared resources in Zen2's op cacheInformation published.MSRC.MICROSOFT.COM
29 MayCVE-2026-46193 xfrm: ah: account for ESN high bits in async callbacksInformation published.MSRC.MICROSOFT.COM
29 MayNotepad++ vulnerabilities could enable arbitrary code execution on Windows systemsTwo arbitrary code execution vulnerabilities in Notepad++ let local attackers run commands of their choice on Windows machines by tampering with the editor’s XML configuration files, with both flaws rated High at CVSS 7.8. The flaws, tracked as CVE-2026-48778 and CVE-2026-48800, …CSOONLINE.COM
29 MayNew infostealer reaches enterprise devices through FortiClient EMS vulnerabilityAttackers are delivering a broad-spectrum infostealer to enterprise computers by exploiting a known vulnerability (CVE-2026-35616) in FortiClient Enterprise Management Server (EMS). “The [malicious] payload was presented as a Fortinet endpoint update and executed through Fo…HELPNETSECURITY.COM
29 MayAttackers Use LLM Agent for Post-Exploitation After Marimo CVE-2026-39987 ExploitAn unknown threat actor has been observed using a large language model (LLM) agent to conduct post-compromise actions after obtaining initial access following the exploitation of a publicly-accessible Marimo network using a recently disclosed vulnerability. "The attacker compromi…THEHACKERNEWS.COM
29 MayFederal audit reveals NIST’s NVD is plagued by poor planning and duplicationA report from the Commerce Inspector General details how mismanagement allowed a backlog of 27,000 unprocessed security flaws to grow unchecked, while the agency duplicated work with a similar CISA program. The post Federal audit reveals NIST’s NVD is plagued by poor planni…CYBERSCOOP.COM
29 MayRapid7 Observed Exploitation of PAN-OS GlobalProtect Authentication Bypass Vulnerability (CVE-2026-0257)Overview On May 13, 2026, Palo Alto Networks published a security advisory for CVE-2026-0257, a medium severity authentication bypass affecting PAN-OS and Prisma Access when a specific configuration is present. Successful exploitation of this vulnerability allows a remote unauthe…RAPID7.COM
29 MayMetasploit Wrap Up 05/29/2026More Linux LPEs Hark the age of the Linux LPE has arrived. This week’s release follows up on recent work bringing new Linux LPEs to Metasploit users. Copy Fail seemed to have kicked off a trend of similar bugs and hot on its heels is Dirty Frag. Dirty Frag is actually two vulnera…RAPID7.COM
29 MayMicrosoft and security researcher’s dueling posts about cybersecurity disclosures get nastyMicrosoft and a prominent cybersecurity researcher have gotten into a very public and rather personal exchange of unpleasantries about what responsible cybersecurity disclosures should mean in 2026. A cybersecurity researcher going by the name Nightmare Eclipse, who has disclosed…CSOONLINE.COM
28 MayCVE-2026-46050 md/raid10: fix deadlock with check operation and nowait requestsInformation published.MSRC.MICROSOFT.COM
28 MayCVE-2026-46011 media: mtk-jpeg: fix use-after-free in release path due to uncancelled workInformation published.MSRC.MICROSOFT.COM
28 MayCVE-2026-45877 HID: intel-ish-hid: fix NULL-ptr-deref in ishtp_bus_remove_all_clientsInformation published.MSRC.MICROSOFT.COM
28 MayCVE-2026-45917 ipvs: do not keep dest_dst if dev is going downInformation published.MSRC.MICROSOFT.COM
28 MayCVE-2026-45841 netfilter: nfnetlink_osf: fix divide-by-zero in OSF_WSS_MODULOInformation published.MSRC.MICROSOFT.COM
28 MayCVE-2026-46062 ntfs3: fix integer overflow in run_unpack() volume boundary checkInformation published.MSRC.MICROSOFT.COM
28 MayCVE-2026-46005 xfs: fix a resource leak in xfs_alloc_buftarg()Information published.MSRC.MICROSOFT.COM
28 MayCVE-2026-45930 net: mctp: ensure our nlmsg responses are initialisedInformation published.MSRC.MICROSOFT.COM
28 MayCVE-2026-46021 thermal: core: Fix thermal zone governor cleanup issuesInformation published.MSRC.MICROSOFT.COM
28 MayCVE-2026-46037 ipv4: icmp: validate reply type before using icmp_pointersInformation published.MSRC.MICROSOFT.COM
28 MayCVE-2026-46084 RDMA/mana_ib: Disable RX steering on RSS QP destroyInformation published.MSRC.MICROSOFT.COM
28 MayCVE-2026-46012 rxrpc: Fix memory leaks in rxkad_verify_response()Information published.MSRC.MICROSOFT.COM
28 MayCVE-2026-46085 rxrpc: Fix rxkad crypto unalignment handlingInformation published.MSRC.MICROSOFT.COM
28 MayCVE-2026-46059 KVM: nSVM: Always use NextRIP as vmcb02's NextRIP after first L2 VMRUNInformation published.MSRC.MICROSOFT.COM
28 MayCVE-2026-46004 ALSA: caiaq: Handle probe errors properlyInformation published.MSRC.MICROSOFT.COM
28 MayCVE-2026-45901 netfilter: nf_tables: revert commit_mutex usage in reset pathInformation published.MSRC.MICROSOFT.COM
28 MayCVE-2026-46080 ocfs2: split transactions in dio completion to avoid credit exhaustionInformation published.MSRC.MICROSOFT.COM
28 MayCVE-2026-45894 iommu/vt-d: Clear Present bit before tearing down PASID entryInformation published.MSRC.MICROSOFT.COM
28 MayCVE-2026-45840 openvswitch: cap upcall PID array size and pre-size vport repliesInformation published.MSRC.MICROSOFT.COM
28 MayCVE-2026-46054 selinux: fix overlayfs mmap() and mprotect() access checksInformation published.MSRC.MICROSOFT.COM
28 MayCVE-2026-45991 udf: fix partition descriptor append bookkeepingInformation published.MSRC.MICROSOFT.COM
28 MayCVE-2026-46027 net/smc: avoid early lgr access in smc_clc_wait_msgInformation published.MSRC.MICROSOFT.COM
28 MayCVE-2026-46088 ALSA: control: Validate buf_len before strnlen() in snd_ctl_elem_init_enum_names()Information published.MSRC.MICROSOFT.COM
28 MayCVE-2026-46051 md/raid5: fix soft lockup in retry_aligned_read()Information published.MSRC.MICROSOFT.COM
28 MayCVE-2026-46018 ALSA: usb-audio: stop parsing UAC2 rates at MAX_NR_RATESInformation published.MSRC.MICROSOFT.COM
28 MayCVE-2026-45835 Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_new_connection_cb()Information published.MSRC.MICROSOFT.COM
28 MayCVE-2026-45834 Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_state_change_cb()Information published.MSRC.MICROSOFT.COM
28 MayCVE-2026-45944 iommu/vt-d: Clear Present bit before tearing down context entryInformation published.MSRC.MICROSOFT.COM
28 MayCVE-2026-45932 bpf: Fix tcx/netkit detach permissions when prog fd isn't givenInformation published.MSRC.MICROSOFT.COM
28 MayCVE-2026-45836 Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_get_sndtimeo_cb()Information published.MSRC.MICROSOFT.COM
28 MayCVE-2026-45961 gfs2: fix memory leaks in gfs2_fill_super error pathInformation published.MSRC.MICROSOFT.COM
28 MayCVE-2026-44844 eml_parser: Recursion DoS via nested message/rfc822 attachmentsInformation published.MSRC.MICROSOFT.COM
28 MayCVE-2026-45839 bpf: reject negative CO-RE accessor indices in bpf_core_parse_spec()Information published.MSRC.MICROSOFT.COM
28 MayCVE-2026-45940 net: stmmac: fix oops when split header is enabledInformation published.MSRC.MICROSOFT.COM
28 MayCVE-2026-44897 Mistune Heading ID Attribute Injection XSSInformation published.MSRC.MICROSOFT.COM
28 MayCVE-2026-45893 apparmor: Fix & Optimize table creation from possibly unaligned memoryInformation published.MSRC.MICROSOFT.COM
28 MayCVE-2026-45943 erofs: fix inline data read failure for ztailpacking pclustersInformation published.MSRC.MICROSOFT.COM
28 MayCVE-2026-46017 mm: fix deferred split queue races during migrationInformation published.MSRC.MICROSOFT.COM
28 MayCVE-2026-45897 netfilter: nft_counter: serialize reset with spinlockInformation published.MSRC.MICROSOFT.COM
28 MayCVE-2026-45997 scsi: sd: fix missing put_disk() when device_add(&disk_dev) failsInformation published.MSRC.MICROSOFT.COM
28 MayCVE-2026-45986 crypto: ccree - fix a memory leak in cc_mac_digest()Information published.MSRC.MICROSOFT.COM
28 MayCVE-2026-47104 libusb < 1.0.30 Out-of-Bounds Read in parse_iad_array()Information published.MSRC.MICROSOFT.COM
28 MayCVE-2026-46047 net: qrtr: ns: Fix use-after-free in driver remove()Information published.MSRC.MICROSOFT.COM
28 MayCVE-2026-45571 go-git: Crafted repositories may modify main and submodule .git directoriesInformation published.MSRC.MICROSOFT.COM
28 MayCVE-2026-45850 ipvs: skip ipv6 extension headers for csum checksInformation published.MSRC.MICROSOFT.COM
28 MayCVE-2026-46052 ceph: only d_add() negative dentries when they are unhashedInformation published.MSRC.MICROSOFT.COM
28 MayCVE-2026-46009 PCI: endpoint: pci-epf-ntb: Remove duplicate resource teardownInformation published.MSRC.MICROSOFT.COM
28 MayCVE-2026-46070 md/raid5: validate payload size before accessing journal metadataInformation published.MSRC.MICROSOFT.COM
28 MayCVE-2026-46043 RDMA/rxe: Validate pad and ICRC before payload_size() in rxe_rcvInformation published.MSRC.MICROSOFT.COM
28 MayCVE-2026-45994 ibmasm: fix OOB reads in command_file_write due to missing size checksInformation published.MSRC.MICROSOFT.COM
28 MayCVE-2026-46069 wifi: mwifiex: fix use-after-free in mwifiex_adapter_cleanup()Information published.MSRC.MICROSOFT.COM
28 MayCVE-2026-45859 netfilter: nfnetlink_queue: do shared-unconfirmed check before segmentationInformation published.MSRC.MICROSOFT.COM
28 MayCVE-2026-46032 KVM: nSVM: Triple fault if restore host CR3 fails on nested #VMEXITInformation published.MSRC.MICROSOFT.COM
28 MayCVE-2026-46101 netfilter: reject zero shift in nft_bitwiseInformation published.MSRC.MICROSOFT.COM
28 MayCVE-2026-46014 KVM: SVM: Add missing save/restore handling of LBR MSRsInformation published.MSRC.MICROSOFT.COM
28 MayCVE-2026-45845 net/sched: taprio: fix NULL pointer dereference in class dumpInformation published.MSRC.MICROSOFT.COM
28 MayCVE-2026-46086 net: bridge: use a stable FDB dst snapshot in RCU readersInformation published.MSRC.MICROSOFT.COM
28 MayCVE-2026-46065 fbdev: defio: Disconnect deferred I/O from the lifetime of struct fb_infoInformation published.MSRC.MICROSOFT.COM
28 MayCVE-2026-46098 net: caif: clear client service pointer on teardownInformation published.MSRC.MICROSOFT.COM
28 MayCVE-2026-45861 gfs2: Fix slab-use-after-free in qd_putInformation published.MSRC.MICROSOFT.COM
28 MayCVE-2026-46077 crypto: atmel-tdes - fix DMA sync directionInformation published.MSRC.MICROSOFT.COM
28 MayCVE-2026-46063 x86/shstk: Prevent deadlock during shstk sigreturnInformation published.MSRC.MICROSOFT.COM
28 MayCVE-2026-46056 Bluetooth: hci_event: fix potential UAF in SSP passkey handlersInformation published.MSRC.MICROSOFT.COM
28 MayCVE-2026-45956 drm/exynos: vidi: use priv->vidi_dev for ctx lookup in vidi_connection_ioctl()Information published.MSRC.MICROSOFT.COM
28 MayCVE-2026-46068 crypto: nx - fix bounce buffer leaks in nx842_crypto_{alloc,free}_ctxInformation published.MSRC.MICROSOFT.COM
28 MayCVE-2026-45843 slip: bound decode() reads against the compressed packet lengthInformation published.MSRC.MICROSOFT.COM
28 MayCVE-2026-46024 libceph: Prevent potential null-ptr-deref in ceph_handle_auth_reply()Information published.MSRC.MICROSOFT.COM
28 MayCVE-2026-45963 ASoC: nau8821: Cancel delayed work on component removeInformation published.MSRC.MICROSOFT.COM
28 MayCVE-2026-45998 rxrpc: Fix potential UAF after skb_unshare() failureInformation published.MSRC.MICROSOFT.COM
28 MayCVE-2026-46023 dm mirror: fix integer overflow in create_dirty_log()Information published.MSRC.MICROSOFT.COM
28 MayCVE-2026-45844 netfilter: arp_tables: fix IEEE1394 ARP payload parsingInformation published.MSRC.MICROSOFT.COM
28 MayCVE-2026-45892 ext4: drop extent cache after doing PARTIAL_VALID1 zerooutInformation published.MSRC.MICROSOFT.COM
28 MayCVE-2026-46022 misc: ibmasm: fix OOB MMIO read in ibmasm_handle_mouse_interrupt()Information published.MSRC.MICROSOFT.COM
28 MayCVE-2026-46102 net: strparser: fix skb_head leak in strp_abort_strp()Information published.MSRC.MICROSOFT.COM
28 MayCVE-2026-46016 remoteproc: xlnx: Only access buffer information if IPI is bufferedInformation published.MSRC.MICROSOFT.COM
28 MayCVE-2026-46000 rxrpc: Fix conn-level packet handling to unshare RESPONSE packetsInformation published.MSRC.MICROSOFT.COM
28 MayCVE-2025-71305 drm/display/dp_mst: Add protection against 0 vcpiInformation published.MSRC.MICROSOFT.COM
28 MayCVE-2026-46006 drm/nouveau: fix u32 overflow in pushbuf reloc bounds checkInformation published.MSRC.MICROSOFT.COM
28 MayCVE-2026-46003 net: qrtr: ns: Limit the total number of nodesInformation published.MSRC.MICROSOFT.COM
28 MayCVE-2026-46048 ALSA: caiaq: fix usb_dev refcount leak on probe failureInformation published.MSRC.MICROSOFT.COM
28 MayCVE-2026-46002 ext2: reject inodes with zero i_nlink and valid mode in ext2_iget()Information published.MSRC.MICROSOFT.COM
28 MayCVE-2026-46078 erofs: fix the out-of-bounds nameoff handling for trailing direntsInformation published.MSRC.MICROSOFT.COM
28 MayCVE-2026-46064 ibmasm: fix heap over-read in ibmasm_send_i2o_message()Information published.MSRC.MICROSOFT.COM
28 MayCVE-2026-46075 crypto: atmel-sha204a - Fix potential UAF and memory leak in remove pathInformation published.MSRC.MICROSOFT.COM
28 MayCVE-2026-45973 RDMA/mlx5: Fix UMR hang in LAG error state unloadInformation published.MSRC.MICROSOFT.COM
28 MayCVE-2026-45838 bpf: fix end-of-list detection in cgroup_storage_get_next_key()Information published.MSRC.MICROSOFT.COM
28 MayCVE-2026-45899 ext4: drop extent cache when splitting extent failsInformation published.MSRC.MICROSOFT.COM
28 MayCVE-2026-46071 KVM: nSVM: Avoid clearing VMCB_LBR in vmcb12Information published.MSRC.MICROSOFT.COM
28 MayCVE-2026-46049 ALSA: ctxfi: Add fallback to default RSR for S/PDIFInformation published.MSRC.MICROSOFT.COM
28 MayCVE-2026-46066 ceph: fix num_ops off-by-one when crypto allocation failsInformation published.MSRC.MICROSOFT.COM
28 MayCVE-2026-45989 of: unittest: fix use-after-free in testdrv_probe()Information published.MSRC.MICROSOFT.COM
28 MayCVE-2026-45855 ata: libata-scsi: avoid Non-NCQ command starvationInformation published.MSRC.MICROSOFT.COM
28 MayCVE-2026-46058 media: amphion: Fix race between m2m job_abort and device_runInformation published.MSRC.MICROSOFT.COM
28 MayCVE-2026-46031 net: ks8851: Reinstate disabling of BHs around IRQ handlerInformation published.MSRC.MICROSOFT.COM
28 MayCVE-2026-45912 ext4: don't cache extent during splitting extentInformation published.MSRC.MICROSOFT.COM
28 MayCVE-2026-45999 erofs: fix unsigned underflow in z_erofs_lz4_handle_overlap()Information published.MSRC.MICROSOFT.COM
28 MayCVE-2026-44896 Mistune: XSS via unescaped figclass/figwidth in Figure directiveInformation published.MSRC.MICROSOFT.COM
28 MayCVE-2026-46091 media: rc: igorplugusb: heed coherency rulesInformation published.MSRC.MICROSOFT.COM
28 MayCVE-2026-45958 drm/exynos: vidi: fix to avoid directly dereferencing user pointerInformation published.MSRC.MICROSOFT.COM
28 MayCVE-2026-45846 bareudp: fix NULL pointer dereference in bareudp_fill_metadata_dst()Information published.MSRC.MICROSOFT.COM
28 MayCVE-2026-44899 Mistune Image Directive CSS Injection VulnerabilityInformation published.MSRC.MICROSOFT.COM
28 MayCVE-2026-46089 zram: do not forget to endio for partial discard requestsInformation published.MSRC.MICROSOFT.COM
28 MayCVE-2026-46033 crypto: authencesn - reject short ahash digests during instance creationInformation published.MSRC.MICROSOFT.COM
28 MayCVE-2026-46046 ext4: fix missing brelse() in ext4_xattr_inode_dec_ref_all()Information published.MSRC.MICROSOFT.COM
28 MayCVE-2026-23679 libusb < 1.0.30 NULL Pointer Dereference in parse_interface()Information published.MSRC.MICROSOFT.COM
28 MayCVE-2026-45570 go-git: Improper single-quote escaping in go-git SSH transportInformation published.MSRC.MICROSOFT.COM
28 MayCVE-2026-46038 net: qrtr: ns: Free the node during ctrl_cmd_bye()Information published.MSRC.MICROSOFT.COM
28 MayCVE-2026-46040 inotify: fix watch count leak when fsnotify_add_inode_mark_locked() failsInformation published.MSRC.MICROSOFT.COM
28 MayCVE-2026-45988 rxrpc: Fix re-decryption of RESPONSE packetsInformation published.MSRC.MICROSOFT.COM
28 MayCVE-2026-45942 ext4: fix e4b bitmap inconsistency reportsInformation published.MSRC.MICROSOFT.COM
28 MayCVE-2026-46019 crypto: atmel-aes - Fix 3-page memory leak in atmel_aes_buff_cleanupInformation published.MSRC.MICROSOFT.COM
28 MayCVE-2026-46092 wifi: rtw88: check for PCI upstream bridge existenceInformation published.MSRC.MICROSOFT.COM
28 MayCVE-2026-45842 slip: reject VJ receive packets on instances with no rstate arrayInformation published.MSRC.MICROSOFT.COM
28 MayCVE-2026-45949 hwrng: core - use RCU and work_struct to fix race conditionInformation published.MSRC.MICROSOFT.COM
28 MayCVE-2026-46072 ntfs3: add buffer boundary checks to run_unpack()Information published.MSRC.MICROSOFT.COM
28 MayCVE-2026-46079 rbd: fix null-ptr-deref when device_add_disk() failsInformation published.MSRC.MICROSOFT.COM
28 MayCVE-2026-46099 net: ipv6: fix NOREF dst use in seg6 and rpl lwtunnelsInformation published.MSRC.MICROSOFT.COM
28 MayCVE-2026-46083 spi: fix resource leaks on device setup failureInformation published.MSRC.MICROSOFT.COM
28 MayCVE-2026-45987 KVM: nSVM: Sync interrupt shadow to cached vmcb12 after VMRUN of L2Information published.MSRC.MICROSOFT.COM
28 MayCVE-2026-46015 tcp: call sk_data_ready() after listener migrationInformation published.MSRC.MICROSOFT.COM
28 MayCVE-2026-45858 ext4: don't zero the entire extent if EXT4_EXT_DATA_PARTIAL_VALID1Information published.MSRC.MICROSOFT.COM
28 MayCVE-2026-45934 btrfs: fix EEXIST abort due to non-consecutive gaps in chunk allocationInformation published.MSRC.MICROSOFT.COM
28 MayCVE-2026-46090 ALSA: aloop: Fix peer runtime UAF during format-change stopInformation published.MSRC.MICROSOFT.COM
28 MayCVE-2026-46082 KVM: SVM: Inject #UD for INVLPGA if EFER.SVME=0Information published.MSRC.MICROSOFT.COM
28 MayCVE-2026-45993 LoongArch: Add spectre boundry for syscall dispatch tableInformation published.MSRC.MICROSOFT.COM
28 MayCVE-2026-46026 net: qrtr: ns: Limit the maximum number of lookupsInformation published.MSRC.MICROSOFT.COM
28 MayCVE-2026-46076 KVM: nSVM: Raise #UD if unhandled VMMCALL isn't intercepted by L1Information published.MSRC.MICROSOFT.COM
28 MayCVE-2026-46094 ext4: fix bounds check in check_xattrs() to prevent out-of-bounds accessInformation published.MSRC.MICROSOFT.COM
28 MayGlassWorm falls, but the repo problem is far from solvedTaking down a sprawling malware operation once signaled progress in securing the open-source ecosystem. Now, it barely registers. The GlassWorm campaign disruption comes at a moment when attackers can quickly reconstitute, and defenders are increasingly grappling with a new chall…CSOONLINE.COM
28 MayAuthenticated RCE via Argument Injection in Gogs (NOT FIXED)Overview Rapid7 Labs discovered a critical argument injection ( CWE-88 ) vulnerability in Gogs , a popular open-source self-hosted Git service. Rapid7 Labs scores this vulnerability as CVSSv4 9.4 (Critical). The vulnerability allows any authenticated user to achieve remote code e…RAPID7.COM
28 MayVU#780781: Casdoor contains multiple authentication bypass and access management vulnerabilitiesOverview Casdoor versions 2.362.0 and earlier contain several identity and access management vulnerabilities that enable broad authentication bypass and privilege escalation. These flaws relate to Casdoor’s Security Assertion Markup Language (SAML) processing, account binding, an…KB.CERT.ORG
28 MayHackers exploit FortiClient EMS flaw to push infostealer malwareHackers are exploiting an authentication bypass vulnerability (CVE-2026-35616) in FortiClient Enterprise Management Server (EMS) to deliver an undocumented credential stealer called EKZ. [...]BLEEPINGCOMPUTER.COM
27 May KEVCISA Orders Emergency Drupal Patch | Microsoft Server Bug | Google Fights Canada Surveillance BillCISA has ordered U.S. federal civilian agencies to urgently patch an actively exploited critical Drupal SQL injection vulnerability (CVE-2026-9082) affecting PostgreSQL-backed Drupal deployments, after Imperva reported more than 15,000 attack attempts across 65 countries. Microso…CYBERSECURITYTODAY.LIBSYN.COM
27 MayCVE-2026-43503 net: skbuff: propagate shared-frag marker through frag-transfer helpersInformation published.MSRC.MICROSOFT.COM
27 MayCVE-2026-46300 net: skbuff: preserve shared-frag marker during coalescingInformation published.MSRC.MICROSOFT.COM
27 MayCVE-2026-41401 libyang - Heap Use-After-Free Write in XML Metadata ParsingInformation published.MSRC.MICROSOFT.COM
27 MayCVE-2026-42506 Invoking incorrect handling of namespaced elements in foreign content in golang.org/x/net/htmlInformation published.MSRC.MICROSOFT.COM
27 MayCVE-2026-39824 Invoking integer overflow in NewNTUnicodeString in golang.org/x/sys/windowsInformation published.MSRC.MICROSOFT.COM
27 MayCVE-2026-42502 Invoking incorrect handling of HTML elements in foreign content in golang.org/x/net/htmlInformation published.MSRC.MICROSOFT.COM
27 MayCVE-2026-27136 Invoking duplicate attributes can cause XSS in golang.org/x/net/htmlInformation published.MSRC.MICROSOFT.COM
27 MayCVE-2026-25681 Invoking incorrect handling of character references in DOCTYPE nodes in golang.org/x/net/htmlInformation published.MSRC.MICROSOFT.COM
27 MayCVE-2026-39829 Invoking pathological RSA/DSA parameters may cause DoS in golang.org/x/crypto/sshInformation published.MSRC.MICROSOFT.COM
27 MayCVE-2026-39830 Invoking client can cause server deadlock on unexpected responses in golang.org/x/crypto/sshInformation published.MSRC.MICROSOFT.COM
27 MayCVE-2026-46597 Invoking byte arithmetic causes underflow and panic in golang.org/x/crypto/sshInformation published.MSRC.MICROSOFT.COM
27 MayCVE-2026-39831 Invoking bypass of FIDO/U2F security keys physical interaction in golang.org/x/crypto/sshInformation published.MSRC.MICROSOFT.COM
27 MayCVE-2026-39827 Invoking memory leak when rejecting channels can lead to DoS in golang.org/x/crypto/sshInformation published.MSRC.MICROSOFT.COM
27 MayCVE-2026-39835 Invoking server panic during CheckHostKey/Authenticate in golang.org/x/crypto/sshInformation published.MSRC.MICROSOFT.COM
27 MayCVE-2026-39834 Invoking infinite loop on large channel writes in golang.org/x/crypto/sshInformation published.MSRC.MICROSOFT.COM
27 MayCVE-2026-39828 Invoking bypass of certificate restrictions in golang.org/x/crypto/sshInformation published.MSRC.MICROSOFT.COM
27 MayCVE-2026-46598 Invoking pathological inputs can lead to client panic in golang.org/x/crypto/ssh/agentInformation published.MSRC.MICROSOFT.COM
27 MayCVE-2026-46595 Invoking VerifiedPublicKeyCallback permissions skip enforcement in golang.org/x/crypto/sshInformation published.MSRC.MICROSOFT.COM
27 MayCVE-2026-39833 Invoking key constraints not enforced in golang.org/x/crypto/ssh/agentInformation published.MSRC.MICROSOFT.COM
27 MayCVE-2026-42508 Invoking auth bypass via unenforced @revoked status in golang.org/x/crypto/ssh/knownhostsInformation published.MSRC.MICROSOFT.COM
27 MayCVE-2026-9150 Libsolv: stack-based buffer overflow in libsolv's debian metadata parser when handling sha384/sha512 checksumsInformation published.MSRC.MICROSOFT.COM
27 MayCVE-2026-9149 Libsolv: heap buffer overflow in libsolv repo_add_solv via negative maxsize from crafted .solv fileInformation published.MSRC.MICROSOFT.COM
27 MayCVE-2026-9256 NGINX ngx_http_rewrite_module vulnerabilityInformation published.MSRC.MICROSOFT.COM
27 MayCVE-2026-6402 webpack-dev-server vulnerable to cross-origin source code exposure on non-HTTPS originsInformation published.MSRC.MICROSOFT.COM
27 MayCVE-2026-5222 Cargo can be coerced to share credentials between registriesInformation published.MSRC.MICROSOFT.COM
27 MayCVE-2026-8376 Perl versions through 5.43.10 have a heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit buildsInformation published.MSRC.MICROSOFT.COM
27 MayCVE-2026-39821 Invoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idnaInformation published.MSRC.MICROSOFT.COM
27 MayCVE-2026-25680 Invoking denial of service when parsing arbitrary HTML in golang.org/x/net/htmlInformation published.MSRC.MICROSOFT.COM
27 MayCVE-2026-39832 Invoking agent constraints dropped when forwarding keys in golang.org/x/crypto/ssh/agentInformation published.MSRC.MICROSOFT.COM
27 MayCVE-2026-8466 Unbounded buffer accumulation in multipart header parsing causes denial of service in cowboyInformation published.MSRC.MICROSOFT.COM
27 MayCVE-2026-5223 Crates in third party registries can override the cached source of other cratesInformation published.MSRC.MICROSOFT.COM
27 MayThe NSA, ‘Mythos’ and the quiet emergence of AI cyber doctrineFor most of my career running security operations, the shape of cyber conflict has been defined by who could move faster than the other side. Faster at identifying a vulnerability, faster at patching, faster at detecting, faster at responding. The last few months have made me ree…CSOONLINE.COM
27 MayGitea Vulnerability Exposes Private Container Images without AuthenticationCybersecurity researchers have disclosed a security flaw in Gitea, an open-source, self-hosted platform for version control, that allows unauthenticated remote attackers to pull private container images from Gitea deployments without requiring an account, password, or other crede…THEHACKERNEWS.COM
27 MayClaude now reviews and fixes vulnerabilities as you write codeAnthropic introduced a security-guidance plugin for Claude Code that reviews code changes for common vulnerabilities and helps Claude identify and fix issues during the same development session. The company says the plugin is designed to catch issues such as injection flaws, unsa…HELPNETSECURITY.COM
27 MayFastAPI-based AI tools exposed to authentication bypass by flaw in Starlette frameworkA single malformed character in a web request can let an unauthenticated attacker slip past the access controls that guard applications built on Starlette, the open-source Python framework that powers FastAPI, researchers said. The flaw, tracked as CVE-2026-48710 could allow atta…CSOONLINE.COM
27 May KEVCISA orders federal agencies to patch actively exploited cPanel plugin flaw within 4 daysThe US Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to patch a critical vulnerability in the LiteSpeed cPanel plugin that is being actively exploited in attacks. The flaw, tracked as CVE-2026-48172, affects the LiteSpeed cPanel user-end plu…CYBERINSIDER.COM
26 MayKnowledgeDeliver LMS Flaw Exploited to Deploy Godzilla and Cobalt StrikeA now-patched high-severity security flaw affecting Digital Knowledge KnowledgeDeliver, a Learning Management System (LMS) popular in Japan, was exploited as a zero-day to deliver the Godzilla web shell and ultimately facilitate the deployment of Cobalt Strike Beacon. The vulnera…THEHACKERNEWS.COM
26 MayCVE-2025-3198 GNU Binutils objdump bucomm.c display_info memory leakInformation published.MSRC.MICROSOFT.COM
26 MayHigh-severity SharePoint RCE bug patched by Microsoft (CVE-2026-45659)Microsoft has released patches for a high-severity remote code execution vulnerability (CVE-2026-45659) in SharePoint that may be exploited in low-complexity attacks. It affects the SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Enterprise Server 2…HELPNETSECURITY.COM
26 MayMicrosoft Patches SharePoint RCE Flaw CVE-2026-45659 Across Server VersionsMicrosoft has rolled out updates to fix a remote code execution vulnerability impacting SharePoint that could be exploited by bad actors in attacks without requiring any specialized conditions to be met. The vulnerability, tracked as CVE-2026-45659, carries a CVSS score of 8.8. I…THEHACKERNEWS.COM
26 May KEVActively exploited Trend Micro Apex One flaw gets CISA warning (CVE-2026-34926)A relative directory path traversal vulnerability (CVE-2026-34926) in Trend Micro’s Apex One platform has been exploited in zero-day attacks, the company confirmed. “TrendAI has observed at least one attempt to exploit this vulnerability in the wild,” Trend Micr…HELPNETSECURITY.COM
26 MayCVE-2026-45495 Microsoft Edge (Chromium-based) Remote Code Execution VulnerabilityCWE added. Informational change only.MSRC.MICROSOFT.COM
26 MayCVE-2026-45498 Microsoft Defender Denial of Service VulnerabilityCWE added. Informational change only.MSRC.MICROSOFT.COM
26 MayCVE-2026-41091 Microsoft Defender Elevation of Privilege VulnerabilityIn the Security Updates table, added links to the Release Notes. This is an informational change only.MSRC.MICROSOFT.COM
26 MayCVE-2026-45584 Microsoft Defender Remote Code Execution VulnerabilityIn the Security Updates table, added links to the Release Notes. This is an informational change only.MSRC.MICROSOFT.COM
25 MayAI Vulnerability Explosion, Kim Wolf Botnet Arrest, Ghost CMS Hack, Iran Cyber EspionageIs AI about to trigger a cybersecurity vulnerability explosion? In this episode of Cybersecurity Today, David Shipley examines what some researchers are calling the early signs of a "vulnerability apocalypse" as Anthropic's Claude-powered Project Glasswing identifies thousands of…CYBERSECURITYTODAY.LIBSYN.COM
25 MayExploitation of KnowledgeDeliver via ViewState Deserialization VulnerabilityWritten by: Takahiro Sugiyama, Peter Revelant, Mathew Potaczek Introduction In late 2025, Mandiant responded to a security incident involving a compromised web server running KnowledgeDeliver . KnowledgeDeliver is a Learning Management System (LMS) developed by Digital Knowledge …CLOUD.GOOGLE.COM
25 MayCVE-2026-43029 mptcp: fix soft lockup in mptcp_recvmsg()Information published.MSRC.MICROSOFT.COM
25 MayCVE-2026-43414 scsi: qla2xxx: Completely fix fcport double freeInformation published.MSRC.MICROSOFT.COM
25 MayAs AI speeds coding, CVE Lite CLI keeps security deliberately AI-freeAs AI coding assistants accelerate software development, one OWASP-backed open-source project is arguing that dependency security tooling still arrives too late to be truly useful. CVE Lite CLI , a JavaScript and TypeScript dependency vulnerability scanner focused on local lockfi…CSOONLINE.COM
25 MayGhost CMS CVE-2026-26980 Exploited to Hijack 700+ Sites for ClickFix AttacksThreat actors are exploiting a recently disclosed critical security flaw in Ghost CMS to inject malicious JavaScript code with an aim to fuel ClickFix attacks. According to QiAnXin XLab, the activity involves the exploitation of CVE-2026-26980 (CVSS score: 9.4), an SQL injection …THEHACKERNEWS.COM
25 MayDrupal warns of active exploitation attempts targeting critical SQL injection flawDrupal is warning administrators that attackers are already attempting to exploit a newly disclosed SQL injection vulnerability affecting the open-source content management system just days after security patches were released. The flaw, tracked as CVE-2026-9082, impacts Drupal’s…CYBERINSIDER.COM
24 MayGhost CMS SQL injection flaw exploited in large-scale ClickFix campaignA large-scale campaign is exploiting a critical SQL injection vulnerability (CVE-2026-26980) in Ghost CMS to inject malicious JavaScript code that triggers ClickFix attack flows. [...]BLEEPINGCOMPUTER.COM
23 MayCVE-2026-3039 BIND 9 server memory exhaustion during GSS-API TKEY negotiationInformation published.MSRC.MICROSOFT.COM
23 MayCVE-2026-3592 Amplification vulnerabilities via self-pointed glue recordsInformation published.MSRC.MICROSOFT.COM
23 MayCVE-2026-3593 Heap use-after-free vulnerability in BIND 9 DNS-over-HTTPS implementationInformation published.MSRC.MICROSOFT.COM
23 MayCVE-2026-5950 Unbounded resend loop in BIND 9 resolverInformation published.MSRC.MICROSOFT.COM
23 MayCVE-2026-42009 Gnutls: gnutls: denial of service via dtls packet reordering vulnerabilityInformation published.MSRC.MICROSOFT.COM
23 MayCVE-2026-41054 Missing exit out of permission check in haveged could lead to root exploitInformation published.MSRC.MICROSOFT.COM
23 MayCVE-2026-8723 qs.stringify crashes on null/undefined entries in comma-format arrays under encodeValuesOnlyInformation published.MSRC.MICROSOFT.COM
23 MayCVE-2025-14575 Uncontrolled Search Path Element in Qt Network OpenSSL TLS backend allows rogue CA certificate loadingInformation published.MSRC.MICROSOFT.COM
23 MayCVE-2026-5947 SIG(0) validation during query flood may lead to undefined behaviorInformation published.MSRC.MICROSOFT.COM
23 MayLiteSpeed cPanel Plugin CVE-2026-48172 Exploited to Run Scripts as RootA maximum-severity security vulnerability impacting LiteSpeed User-End cPanel Plugin has come under active exploitation in the wild. The flaw, tracked as CVE-2026-48172 (CVSS score: 10.0), relates to an instance of incorrect privilege assignment that an attacker could abuse to ru…THEHACKERNEWS.COM
22 MayCisco Patches CVSS 10.0 Secure Workload REST API Flaw Enabling Data AccessCisco has rolled out updates for a maximum-severity security flaw impacting Secure Workload that could allow an unauthenticated, remote attacker to access sensitive data. Tracked as CVE-2026-20223 (CVSS score: 10.0), the vulnerability arises from insufficient validation and authe…THEHACKERNEWS.COM
22 May KEVCISA Warns Trend Micro Apex One Vulnerability Is Being Exploited in AttacksCISA has added a newly disclosed vulnerability in Trend Micro Apex One to its Known Exploited Vulnerabilities (KEV) catalog, warning that the flaw is actively being exploited in real-world attacks. The issue, tracked as CVE-2026-34926, affects on-premise deployments of Trend Micr…GBHACKERS.COM
22 MayCVE-2026-43331 x86/kexec: Disable KCOV instrumentation after load_segments()Information published.MSRC.MICROSOFT.COM
22 MayCVE-2026-43303 mm/page_alloc: clear page->private in free_pages_prepare()Information published.MSRC.MICROSOFT.COM
22 MayCVE-2026-43465 net/mlx5e: RX, Fix XDP multi-buf frag counting for striding RQInformation published.MSRC.MICROSOFT.COM
22 MayCVE-2026-43499 rtmutex: Use waiter::task instead of current in remove_waiter()Information published.MSRC.MICROSOFT.COM
22 MayCVE-2026-43497 fbdev: udlfb: add vm_ops to dlfb_ops_mmap to prevent use-after-freeInformation published.MSRC.MICROSOFT.COM
22 MayCVE-2026-43502 net/rds: handle zerocopy send cleanup before the message is queuedInformation published.MSRC.MICROSOFT.COM
22 MayCVE-2026-43501 ipv6: rpl: reserve mac_len headroom when recompressed SRH growsInformation published.MSRC.MICROSOFT.COM
22 MayCVE-2026-43496 net/sched: sch_red: Replace direct dequeue call with peek and qdisc_dequeue_peekedInformation published.MSRC.MICROSOFT.COM
22 MayCVE-2026-43464 net/mlx5e: RX, Fix XDP multi-buf frag counting for legacy RQInformation published.MSRC.MICROSOFT.COM
22 MayCVE-2026-43495 net: wwan: t7xx: validate port_count against message length in t7xx_port_enum_msg_handlerInformation published.MSRC.MICROSOFT.COM
22 MayCVE-2026-43494 net/rds: reset op_nents when zerocopy page pin failsInformation published.MSRC.MICROSOFT.COM
22 MayCVE-2024-26944 btrfs: zoned: fix use-after-free in do_zone_finish()Information published.MSRC.MICROSOFT.COM
22 MayCVE-2026-0968 Libssh: libssh: denial of service due to malformed sftp messageInformation published.MSRC.MICROSOFT.COM
22 May KEVCISA Issues Alert on Exploited Microsoft Defender Zero-Day VulnerabilitiesCISA has issued an urgent alert warning organizations about two newly disclosed zero-day vulnerabilities affecting Microsoft Defender, both added to the Known Exploited Vulnerabilities (KEV) catalog on May 20, 2026. CVE-2026-45498: Microsoft Defender DoS Vulnerability CVE-2026-45…GBHACKERS.COM
22 MayCVE-2025-38340 firmware: cs_dsp: Fix OOB memory read access in KUnit testInformation published.MSRC.MICROSOFT.COM
22 MayCVE-2024-41023 sched/deadline: Fix task_struct reference leakInformation published.MSRC.MICROSOFT.COM
22 MayDrupal Vulnerability in Hacker Crosshairs Shortly After DisclosureDrupal is warning users that it has already seen attempts to exploit CVE-2026-9082 and security firms are seeing attacks against thousands of websites. The post Drupal Vulnerability in Hacker Crosshairs Shortly After Disclosure appeared first on SecurityWeek .SECURITYWEEK.COM
22 MayMetasploit Wrap Up 05/22/2026Another week, another authentication bypass Our humble Metasploit weekly(ish) blog has been blessed with a new network component vulnerability. The dynamic duo of @sfewer-r7 and @jburgess-r7 have discovered and authored the admin/networking/cisco_sdwan_vhub_auth_bypass module for…RAPID7.COM
21 MayMicrosoft is working on a patch for ‘YellowKey’ attack on Bitlocker, offers temporary fixMicrosoft says it is considering a patch for a zero-day vulnerability, dubbed YellowKey, that allows attackers with access to a Windows device to bypass Bitlocker encryption protection and read and write files. The flaw was disclosed last week, and there is already a public proof…CSOONLINE.COM
21 MayHighly Critical Drupal Core Flaw Exposes PostgreSQL Sites to RCE AttacksDrupal has released security updates for a "highly critical" security vulnerability in Drupal Core that could be exploited by attackers to achieve remote code execution, privilege escalation, or information disclosure. The vulnerability, now tracked as CVE-2026-9082, carries a CV…THEHACKERNEWS.COM
21 MayCVE-2026-45585 Windows BitLocker Security Feature Bypass VulnerabilityAdded a script to implement a mitigation and removed the manual mitigations. Please read the information to decide if you need to run the provided script.MSRC.MICROSOFT.COM
21 MayCVE-2026-43619 Rsync < 3.4.3 Symlink Race Condition via Path-Based SyscallsInformation published.MSRC.MICROSOFT.COM
21 MayCVE-2026-43618 Rsync < 3.4.3 Integer Overflow Information DisclosureInformation published.MSRC.MICROSOFT.COM
21 MayCVE-2026-43620 Rsync < 3.4.3 Out-of-Bounds Array Read via recv_files()Information published.MSRC.MICROSOFT.COM
21 MayCVE-2026-47784 In memcached before 1.6.42, password data for SASL password database authentication has a timing side channel because memcmp is used by sasl_server_userdb_checkpass.Information published.MSRC.MICROSOFT.COM
21 MayCVE-2026-47783 In memcached before 1.6.42, username data for SASL password database authentication has a timing side channel because a loop exits as soon as a valid username is found by sasl_server_userdb_checkpass.Information published.MSRC.MICROSOFT.COM
21 MayCVE-2026-42960 Possible cache poisoning via promiscuous records for the authority sectionInformation published.MSRC.MICROSOFT.COM
21 MayCVE-2026-42959 Crash during DNSSEC validation of malicious contentInformation published.MSRC.MICROSOFT.COM
21 MayCVE-2026-44608 Use after free and crash under special conditions in RPZ codeInformation published.MSRC.MICROSOFT.COM
21 MayCVE-2026-33278 Possible arbitrary code execution during DNSSEC validationInformation published.MSRC.MICROSOFT.COM
21 MayCVE-2026-42923 Degradation of service with unbounded NSEC3 hash calculationsInformation published.MSRC.MICROSOFT.COM
21 MayCVE-2026-45803 gh: GitHub Actions log output in `gh run view` allows terminal escape sequence injectionInformation published.MSRC.MICROSOFT.COM
21 MayCVE-2026-43970 Decompression Bomb in cow_spdy:inflate/2 Allows Memory Exhaustion via Crafted SPDY FrameInformation published.MSRC.MICROSOFT.COM
21 MayCVE-2026-43617 Rsync < 3.4.3 Authorization Bypass via Hostname ResolutionInformation published.MSRC.MICROSOFT.COM
21 MayCVE-2026-45232 Rsync < 3.4.3 Off-by-One Stack Write via HTTP ProxyInformation published.MSRC.MICROSOFT.COM
21 MayCVE-2026-29518 Rsync < 3.4.3 TOCTOU Race Condition Allows Symlink-Based Arbitrary File WriteInformation published.MSRC.MICROSOFT.COM
21 MayCVE-2026-41292 Long list of incoming EDNS options degrades performanceInformation published.MSRC.MICROSOFT.COM
21 MayCVE-2026-42534 Jostle logic bypass degrades resolution performanceInformation published.MSRC.MICROSOFT.COM
21 MayCVE-2026-40622 Another 'ghost domain names' attack variantInformation published.MSRC.MICROSOFT.COM
21 MayCVE-2026-42944 Heap overflow with multiple NSID, COOKIE, PADDING EDNS optionsInformation published.MSRC.MICROSOFT.COM
21 MayCVE-2026-44390 Unbounded name compression in certain cases causes degradation of serviceInformation published.MSRC.MICROSOFT.COM
21 MayNine-Year-Old Kernel Flaw Puts Linux SSH Private Keys at RiskA newly disclosed Linux kernel vulnerability, tracked as CVE-2026-46333, poses a serious risk to SSH private keys and other sensitive credentials. The flaw, present in the kernel since 2016, allows a local attacker to escalate from a basic shell account to full root access on man…GBHACKERS.COM
21 May9-Year-Old Linux Kernel Flaw Enables Root Command Execution on Major DistrosCybersecurity researchers have disclosed details of a vulnerability in the Linux kernel that remained undetected for nine years. The vulnerability, tracked as CVE-2026-46333 (CVSS score: 5.5), is a case of improper privilege management that could permit an unprivileged local user…THEHACKERNEWS.COM
21 MayCritical Vulnerability in Cisco Secure Workload Threatens Enterprise API SecurityCisco has disclosed a critical security vulnerability in its Secure Workload platform that could allow unauthenticated attackers to gain high-level administrative access to sensitive enterprise environments. The flaw, tracked as CVE-2026-20223, carries a maximum CVSS score of 10.…GBHACKERS.COM
21 May KEVMicrosoft Warns of Two Actively Exploited Defender VulnerabilitiesMicrosoft has disclosed that a privilege escalation and a denial-of-service flaw in Defender has come under active exploitation in the wild. The former, tracked as CVE-2026-41091, is rated 7.8 on the CVSS scoring system. Successful exploitation of the flaw could allow an attacker…THEHACKERNEWS.COM
21 May KEVMicrosoft Defender Zero-Day Vulnerabilities Actively Exploited in the WildMicrosoft has disclosed two new zero-day vulnerabilities in Microsoft Defender that are actively being exploited in the wild, raising concerns among security professionals and enterprise users. The vulnerabilities, tracked as CVE-2026-41091 and CVE-2026-45498, were officially rel…GBHACKERS.COM
21 May KEVCVE-2026-9082: Highly Critical SQL Injection Vulnerability in Drupal Core (SA-CORE-2026-004)A highly critical SQL injection vulnerability in Drupal core's database abstraction layer affects sites running PostgreSQL. Key Takeaways CVE-2026-9082 is a highly critical SQL injection vulnerability in Drupal core's database abstraction API that can be exploited by unauthentica…TENABLE.COM
21 MayCisco fixed maximum severity flaw CVE-2026-20223 in Secure WorkloadCisco fixed a critical Secure Workload flaw (CVE-2026-20223) that could let attackers gain Site Admin privileges through crafted API requests. Cisco released patches for a critical vulnerability, tracked as CVE-2026-20223 (CVSS score of 10.0), in Secure Workload. The flaw stems f…SECURITYAFFAIRS.COM
21 MayUnpatched ChromaDB flaw leaves servers open to remote code executionResearchers have published details about a critical vulnerability in ChromaDB that could allow unauthenticated attackers to execute arbitrary code and access sensitive data on machines running the open-source vector database. The issue, tracked as CVE-2026-45829, is located in Ch…CSOONLINE.COM
21 MayCritical vulnerability in Cisco Secure Workload rated at maximum severityA critical vulnerability in the on-premises version of the Cisco Secure Workload security platform could allow a threat actor to obtain the privileges of a site admin, enabling them to compromise endpoints and read or modify configuration data. “CSOs need to drop what they are do…CSOONLINE.COM
21 May KEVMicrosoft patches two zero-day flaws in DefenderMicrosoft released emergency fixes for two zero-day vulnerabilities in the malware protection components of Microsoft Defender. The flaws allow local attackers to gain system-level privileges or cause the anti-malware service to stop working correctly. Both conditions are valuabl…CSOONLINE.COM
21 MayA New SonicWall Scanning Spike Echoes the Pattern That Preceded CVE-2026-0400A new SonicWall scanning surge mirrors the pattern that preceded CVE-2026-0400. GreyNoise details the activity and what defenders should watch.GREYNOISE.IO
20 MayFreePBX Security Flaw Lets Attackers Access User PortalsA critical security vulnerability has been discovered in FreePBX, a widely used open-source PBX platform, allowing unauthenticated attackers to access user portals under certain conditions. The flaw, tracked as CVE-2026-46376, carries a CVSS v4 base score of 9.1 and affects the U…GBHACKERS.COM
20 MayCVE Lite CLI: Open-source dependency vulnerability scannerDependency vulnerability scanning in JavaScript and TypeScript projects has long sat at the end of the development pipeline. Pull requests get opened, continuous integration runs, and a security scanner returns a list of CVE identifiers that developers then have to triage hours o…HELPNETSECURITY.COM
20 MayCVE-2026-43493 crypto: pcrypt - Fix handling of MAY_BACKLOG requestsInformation published.MSRC.MICROSOFT.COM
20 MayCVE-2026-43491 net: qrtr: ns: Limit the maximum server registration per nodeInformation published.MSRC.MICROSOFT.COM
20 MayCVE-2026-43492 lib/crypto: mpi: Fix integer underflow in mpi_read_raw_from_sgl()Information published.MSRC.MICROSOFT.COM
20 MayPardus Linux Vulnerability Lets Local Attackers Gain Silent Root AccessA critical privilege escalation vulnerability chain, tracked as CVE-2026-5140, has been discovered in the Pardus Linux update mechanism, allowing local users to gain full root access without authentication. The issue, rated CVSS 9.3 (Critical), affects the pardus-update package a…GBHACKERS.COM
20 MayDirtyDecrypt: PoC Released for yet another Linux flawDirtyDecrypt (CVE-2026-31635): working PoC out for a Linux kernel LPE flaw. Missing COW guard in rxgk_decrypt_skb lets local attackers reach root. After Copy Fail, Dirty Frag, and Fragnesia, here comes DirtyDecrypt, another local privilege escalation vulnerability in the kernel, …SECURITYAFFAIRS.COM
20 MayMicrosoft provides mitigation for “YellowKey” BitLocker bypass flaw (CVE-2026-45585)Microsoft is working on a fix for CVE-2026-45585 (aka “Yellowkey”), a vulnerability that can be used by attackers to bypass protections offered by BitLocker, the full-disk encryption feature built into Windows, and access users’ data. In the meantime, the compan…HELPNETSECURITY.COM
20 MayMicrosoft Releases Mitigation for YellowKey BitLocker Bypass CVE-2026-45585 ExploitMicrosoft on Tuesday released a mitigation for a BitLocker bypass vulnerability named YellowKey following its public disclosure last week. The zero-day flaw, now tracked as CVE-2026-45585, carries a CVSS score of 6.8. It has been described as a BitLocker security feature bypass. …THEHACKERNEWS.COM
20 MayWhy some security fixes never reach your vulnerability dashboardOn April 22, for roughly 90 minutes, a malicious version of Bitwarden CLI appeared on npm. Version 2026.4.0 contained a credential-stealing payload that executed an obfuscated loader and harvested AWS, Azure, GCP, GitHub, and npm tokens from any developer machine that ran npm ins…CSOONLINE.COM
20 MayHow an image could compromise your Mac: understanding an ExifTool vulnerability (CVE-2026-3102)We explain how a flaw in ExifTool allows attackers to compromise macOS systems via a malicious image (CVE-2026-3102).SECURELIST.COM
20 MayCritical ExifTool Vulnerability Lets Hackers Compromise Macs via Malicious ImagesA newly disclosed vulnerability in ExifTool, tracked as CVE-2026-3102, exposes macOS systems to command execution attacks through malicious image metadata, highlighting ongoing risks in widely used file processing tools. ExifTool is a popular utility used across media workflows t…GBHACKERS.COM
20 MayNVIDIA Triton Inference Server Flaw Raises Risk of Unauthorized AccessNVIDIA has disclosed a critical security vulnerability in its Triton Inference Server that could allow attackers to bypass authentication and gain unauthorized access to affected systems. The flaw, tracked as CVE-2026-24207, has been assigned a CVSS v3.1 score of 9.8, indicating …GBHACKERS.COM
20 MayMicrosoft issues YellowKey mitigation, no patch yetMicrosoft acknowledged the YellowKey BitLocker bypass flaw and released mitigations, urging admins to disable autofstx.exe and enable TPM+PIN. A week after Chaotic Eclipse publicly dropped the YellowKey vulnerability, Microsoft acknowledged it and published a mitigation. Not a pa…SECURITYAFFAIRS.COM
20 MayVU#980487: Local privilege escalation in Linux Kernel (Dirty Frag)Overview A privilege escalation vulnerability, nicknamed "Dirty Frag," has been discovered in the Linux kernel versions 4.10 and later. This vulnerability is a result of chaining together two previously discovered vulnerabilities, xfrm-ESP Page-Cache Write CVE-2026-43284 and the …KB.CERT.ORG
20 MayDrupal admins rushing to patch maximum severity SQL injection vulnerabilityAdministrators of the Drupal open source content management platform are rushing to install an emergency patch issued today to fix a “highly critical” SQL injection vulnerability in the application’s core. While the vulnerability only affects websites that use the PostgreSQL data…CSOONLINE.COM
19 May KEVExchange Zero-Day Under Attack, Ransomware Gets Smarter, Fortinet Critical FlawsA dangerous new Microsoft Exchange zero-day is being actively exploited, ransomware gangs are adopting nation-state-style tactics, two fired contractors were caught deleting U.S. government databases after accidentally recording themselves on Microsoft Teams, and Fortinet has pat…CYBERSECURITYTODAY.LIBSYN.COM
19 MayCVE-2026-7246 Pallets Click contains a command injection via Unsanitized Filename "click.edit()"Information published.MSRC.MICROSOFT.COM
19 MayCVE-2026-31721 usb: gadget: f_hid: move list and spinlock inits from bind to allocInformation published.MSRC.MICROSOFT.COM
19 MayCVE-2026-31704 ksmbd: use check_add_overflow() to prevent u16 DACL size overflowInformation published.MSRC.MICROSOFT.COM
19 MayCVE-2026-31702 f2fs: fix use-after-free of sbi in f2fs_compress_write_end_io()Information published.MSRC.MICROSOFT.COM
19 MayCVE-2026-37458 Missing input validation in the MP_REACH_NLRI component of FRRouting (FRR) stable/10.0 to stable/10.6 allows authenticated attackers to cause a Denial of Service (DoS) via supplying a crafted UPDATE message.Information published.MSRC.MICROSOFT.COM
19 MayCVE-2026-4873 connection reuse ignores TLS requirementInformation published.MSRC.MICROSOFT.COM
19 MayCVE-2026-6429 netrc credential leak with reused proxy connectionInformation published.MSRC.MICROSOFT.COM
19 MayCVE-2026-5545 wrong reuse of HTTP Negotiate connectionInformation published.MSRC.MICROSOFT.COM
19 MayCVE-2026-6253 proxy credentials leak over redirect-to proxyInformation published.MSRC.MICROSOFT.COM
19 MayCVE-2026-37459 An integer underflow in FRRouting (FRR) stable/10.0 to stable/10.6 allows attackers to cause a Denial of Service (DoS) via supplying a crafted BGP UPDATE message.Information published.MSRC.MICROSOFT.COM
19 MayCVE-2026-6276 stale custom cookie host causes cookie leakInformation published.MSRC.MICROSOFT.COM
19 MayCVE-2025-1176 GNU Binutils ld elflink.c _bfd_elf_gc_mark_rsec heap-based overflowInformation published.MSRC.MICROSOFT.COM
19 MayCVE-2025-1178 GNU Binutils ld libbfd.c bfd_putl64 memory corruptionInformation published.MSRC.MICROSOFT.COM
19 MayFour-Faith Industrial Routers Targeted in Botnet Hijacking CampaignFour-Faith industrial cellular routers are being actively targeted in a growing botnet campaign exploiting a critical authentication bypass flaw tracked as CVE-2024-9643. Security researchers warn that attackers are rapidly weaponizing the vulnerability to hijack exposed devices …GBHACKERS.COM
19 May20-Year-Old PostgreSQL Flaw Gets Public PoC Exploit for Remote Code ExecutionA newly released proof-of-concept (PoC) exploit for CVE-2026-2005 has brought renewed attention to a critical vulnerability in PostgreSQL’s pgcrypto extension, exposing systems to remote code execution (RCE). Security researchers warn that the flaw, rooted in legacy code paths da…GBHACKERS.COM
19 MayDirtyDecrypt PoC Released for Linux Kernel CVE-2026-31635 LPE VulnerabilityProof-of-concept (PoC) exploit code has now been released for a recently patched security flaw in the Linux kernel that could allow for local privilege escalation (LPE). Dubbed DirtyDecrypt (aka DirtyCBC), the vulnerability was discovered and reported by the Zellic and V12 securi…THEHACKERNEWS.COM
19 MaymacOS flaw allowed rogue apps to access chat and browser dataResearchers at mobile privacy firm Mysk have disclosed details of a now-patched macOS vulnerability that could allow malicious apps to bypass Apple’s sandbox and privacy protections to access sensitive user data stored by messaging, productivity, and browser applications. Tracked…CYBERINSIDER.COM
19 MayContractor’s public GitHub account exposed GovCloud and CISA credentialsUntil a few days ago, a publicly-accessible GitHub repository exposed credentials for both US government AWS accounts and internal Cybersecurity and Infrastructure Security Agency (CISA) systems. That’s according to cybersecurity reporter Brian Krebs, who first broke the news ove…CSOONLINE.COM
19 May9 Year-Old PHP Vulnerability Keeps Swinging As One of the Most Targeted VulnerabilitiesCVE-2017-9841 is still a primary exploit path for several botnets. What is old is still new in the eyes of cybercrime.VULNCHECK.COM
18 May KEVExperts warn of active exploitation of critical NGINX flaw CVE-2026-42945A critical NGINX flaw (CVE-2026-42945) is actively exploited, allowing crashes or possible code execution via malicious HTTP requests. A critical vulnerability in NGINX Plus and NGINX Open, tracked as CVE-2026-42945 (CVSS v4 score of 9.2), is already being actively exploited shor…SECURITYAFFAIRS.COM
18 MayCritical Marimo RCE Flaw Could Let Attackers Execute Malicious Code RemotelyA newly disclosed critical vulnerability in the Marimo Python notebook framework is raising serious alarms across the cybersecurity community, as it allows attackers to execute arbitrary commands remotely, without authentication. Tracked as CVE-2026-39987, the flaw exposes a WebS…GBHACKERS.COM
18 MayChaotic Eclipse discloses MiniPlasma zero-day, suggesting a missing or undone 2020 Windows security fixMiniPlasma: a Windows SYSTEM privilege escalation believed patched in 2020 (CVE-2020-17103) is still fully working on every patched Windows 11. Once again, security researcher Chaotic Eclipse has released a proof-of-concept exploit for a new Windows privilege escalation zero-day …SECURITYAFFAIRS.COM
18 May KEVVU#777338: SGLang contains two remote code execution and one path traversal vulnerabilityOverview Three vulnerabilities have been discovered in the SGLang project, two enabling remote code execution (RCE), and one regarding a path traversal vulnerability. In order for an attacker to exploit these vulnerabilities, the multimodal generation mode must be enabled, and an…KB.CERT.ORG
18 MayIvanti, Fortinet, SAP, VMware, n8n Patch RCE, SQL Injection, Privilege Escalation FlawsIvanti, Fortinet, n8n, SAP, and VMware have released security fixes for various vulnerabilities that could be exploited by bad actors to bypass authentication and execute arbitrary code. Topping the list is a critical flaw impacting Ivanti Xtraction (CVE-2026-8043, CVSS score: 9.…THEHACKERNEWS.COM
18 May KEVCritical NGINX Vulnerability Lets Hackers Launch Remote Code Execution AttacksA newly disclosed vulnerability in NGINX is already being actively exploited, raising serious concerns across the global cybersecurity community. Tracked as CVE-2026-42945, the flaw affects both NGINX Open Source and NGINX Plus, potentially allowing attackers to crash servers or …GBHACKERS.COM
18 MayGamaredon Deploys GammaDrop, GammaLoad in Phishing CampaignsGamaredon Uses GammaDrop and GammaLoad Downloaders in Multi-Stage Phishing Attacks. A sustained cyber-espionage campaign linked to the Gamaredon threat group is actively targeting Ukrainian government entities using multi-stage phishing attacks and evolving malware loaders. Gamar…GBHACKERS.COM
18 May‘Patched’ Windows bug resurfaces 6 years later as working SYSTEM-level exploitAn old elevation-of-privilege (EoV) vulnerability affecting the Cloud Filter driver “cldflt.sys” in Windows has come back to haunt Microsoft, as researchers claim it is still exploitable six years after it was supposedly patched. The flaw, originally reported to Microsoft by Goog…CSOONLINE.COM
18 MayAttackers are exploiting critical NGINX vulnerability (CVE-2026-42945)A critical NGINX vulnerability (CVE-2026-42945) disclosed last week is being exploited by attackers, VulnCheck security researcher Patrick Garrity revealed on Saturday. The vulnerability, dubbed NGINX Rift, can be reliably exploited to trigger a denial-of-service condition and ca…HELPNETSECURITY.COM
18 MayMicrosoft Exchange Zero-Day Under Attack, No Patch AvailableCVE-2026-42897 stems from a cross-site scripting (XSS) vulnerability and can allow an attacker to compromise Outlook Web Access (OWA) mailboxes.DARKREADING.COM
17 MayCVE-2026-46483 Vim: Command injection in tar#Vimuntar via missing shellescape {special} flagInformation published.MSRC.MICROSOFT.COM
17 MayCVE-2026-44283 etcd: Read access via PrevKv in etcd transactions may bypass RBAC authorization checksInformation published.MSRC.MICROSOFT.COM
17 MayCVE-2026-8368 LWP::UserAgent versions before 6.83 for Perl leak Authorization and Proxy-Authorization headers on cross-origin redirectsInformation published.MSRC.MICROSOFT.COM
17 MayCVE-2026-8328 FTP PASV SSRF, ftpcp() does not use actual peer address, trusts server-supplied PASV host addressInformation published.MSRC.MICROSOFT.COM
17 May KEVNGINX CVE-2026-42945 Exploited in the Wild, Causing Worker Crashes and Possible RCEA newly disclosed security flaw impacting NGINX Plus and NGINX Open has come under active exploitation in the wild, days after its public disclosure, according to VulnCheck. The vulnerability, tracked as CVE-2026-42945 (CVSS score: 9.2), is a heap buffer overflow in ngx_http_rewr…THEHACKERNEWS.COM
17 MaySECURITY AFFAIRS MALWARE NEWSLETTER ROUND 97Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter JDownloader site hacked to replace installers with Python RAT malware New TrickMo Variant: Device Take …SECURITYAFFAIRS.COM
16 MayCVE-2026-44673 libyang: lyb_read_string() integer overflow → heap buffer overflowInformation published.MSRC.MICROSOFT.COM
16 MayCVE-2026-6478 PostgreSQL discloses MD5-hashed passwords via covert timing channelInformation published.MSRC.MICROSOFT.COM
16 MayCVE-2026-6473 PostgreSQL server undersizes allocations, via integer wraparoundInformation published.MSRC.MICROSOFT.COM
16 MayCVE-2026-6638 PostgreSQL REFRESH PUBLICATION allows SQL injection via table nameInformation published.MSRC.MICROSOFT.COM
16 MayCVE-2026-6637 PostgreSQL refint allows stack buffer overflow and SQL injectionInformation published.MSRC.MICROSOFT.COM
16 MayCVE-2026-6477 PostgreSQL libpq lo_* functions let server superuser overwrite client stack memoryInformation published.MSRC.MICROSOFT.COM
16 MayCVE-2026-42934 NGINX ngx_http_charset_module vulnerabilityInformation published.MSRC.MICROSOFT.COM
16 MayCVE-2026-42946 NGINX ngx_http_scgi_module and ngx_http_uwsgi_module vulnerabilityInformation published.MSRC.MICROSOFT.COM
16 MayCVE-2026-44662 rust-openssl: Heap buffer overflow when encrypting with AES key-wrap-with-paddingInformation published.MSRC.MICROSOFT.COM
16 MayCVE-2026-44431 urllib3: Sensitive headers forwarded across origins in proxied low-level redirectsInformation published.MSRC.MICROSOFT.COM
16 MayCVE-2026-43490 ksmbd: validate inherited ACE SID lengthInformation published.MSRC.MICROSOFT.COM
16 MayCVE-2026-6475 PostgreSQL pg_basebackup and pg_rewind can overwrite unrelated files of origin superuser choiceInformation published.MSRC.MICROSOFT.COM
16 MayCVE-2026-6474 PostgreSQL timeofday() can disclose portions of server memoryInformation published.MSRC.MICROSOFT.COM
16 MayCVE-2026-6472 PostgreSQL CREATE TYPE does not check multirange schema CREATE privilegeInformation published.MSRC.MICROSOFT.COM
16 MayCVE-2026-6479 PostgreSQL SSL/GSS init causes denial of service, via uncontrolled recursionInformation published.MSRC.MICROSOFT.COM
16 MayCVE-2026-40701 NGINX ngx_http_ssl_module vulnerabilityInformation published.MSRC.MICROSOFT.COM
16 MayCVE-2026-42945 NGINX ngx_http_rewrite_module vulnerabilityInformation published.MSRC.MICROSOFT.COM
16 MayCVE-2026-46333 ptrace: slightly saner 'get_dumpable()' logicInformation published.MSRC.MICROSOFT.COM
16 MayLinux “ssh-keysign-pwn” Flaw Exposing Critical Authentication FilesA newly disclosed Linux kernel vulnerability, dubbed “ssh-keysign-pwn” by Qualys researchers, exposes millions of Linux systems to unauthorized access to sensitive SSH private keys and hashed passwords stored in /etc/shadow. Tracked as CVE-2026-463…GBHACKERS.COM
15 MayPalo Alto Firewalls Hit by Zero-Day Allowing Arbitrary Code Execution as RootA devastating zero-day vulnerability in Palo Alto Networks firewalls is under active exploitation by suspected state-sponsored hackers, allowing unauthenticated attackers to seize complete control of enterprise security infrastructure. The flaw, tracked as CVE-2026-0300 with a cr…GBHACKERS.COM
15 MayOn-Prem Microsoft Exchange Server CVE-2026-42897 Exploited via Crafted EmailMicrosoft has disclosed a new security vulnerability impacting on-premise versions of Exchange Server that it said has come under active exploitation in the wild. The vulnerability, tracked as CVE-2026-42897 (CVSS score: 8.1), has been described as a spoofing bug stemming from a …THEHACKERNEWS.COM
15 MayNext.js Security Flaw Leaks Cloud Credentials, API Keys, and Admin InterfacesNext.js, one of the most widely used React frameworks, has been hit by a high-severity vulnerability that could allow attackers to extract sensitive cloud credentials, API keys, and even access internal admin interfaces. The flaw, tracked as CVE-2026-44578, exposes a critical wea…GBHACKERS.COM
15 MayCVE-2026-42304 Twisted: Denial of Service (DoS) in twisted.names via Crafted DNS Compression Pointer ChainsInformation published.MSRC.MICROSOFT.COM
15 MayCVE-2026-42011 Gnutls: gnutls: security bypass due to incorrect name constraint handlingInformation published.MSRC.MICROSOFT.COM
15 MayCVE-2026-34956 Openvswitch: open vswitch: denial of service via malformed ftp epasv commandInformation published.MSRC.MICROSOFT.COM
15 MayCVE-2026-7210 The expat and elementtree parsers use insufficient entropy for XML hash-flooding protectionInformation published.MSRC.MICROSOFT.COM
15 MayCVE-2026-43969 Cookie Request Header Injection via Unvalidated Encoder in cow_cookie:cookie/1Information published.MSRC.MICROSOFT.COM
15 MayCVE-2026-42010 Gnutls: gnutls: authentication bypass via nul character in usernameInformation published.MSRC.MICROSOFT.COM
15 MayCVE-2026-7790 Unbounded chunk-size hex digits in cowlib cause quadratic CPU and memory DoSInformation published.MSRC.MICROSOFT.COM
15 MayCVE-2026-43968 CR Injection in SSE Encoder Enables Event Splitting via cow_sse:event/1Information published.MSRC.MICROSOFT.COM
15 May KEVCisco Catalyst SD-WAN Controller Flaw Under Active Exploitation for Admin AccessCisco has disclosed a critical vulnerability in its Catalyst SD-WAN platform that is already being exploited in the wild, allowing attackers to gain administrative control over enterprise networks without authentication. Critical SD-WAN flaw under attack The vulnerability, tracke…GBHACKERS.COM
15 MayAmazon Redshift JDBC Driver Flaws Expose Systems to RCE AttacksAmazon Redshift users are facing a serious security risk after researchers uncovered a high-severity vulnerability that could allow attackers to execute arbitrary code on affected systems. The flaw, tracked as CVE-2026-8178, affects the widely used Amazon Redshift JDBC Driver and…GBHACKERS.COM
15 MayUnpatched Microsoft Exchange Server vulnerability exploited (CVE-2026-42897)A critical cross-site scripting (XSS) vulnerability (CVE-2026-42897) in Microsoft Exchange Server is being exploited by attackers, Microsoft warned on Thursday. A permanent fix is still in the works. In the meantime, Microsoft provided temporary mitigations. About CVE-2026-42897 …HELPNETSECURITY.COM
15 May KEVPraisonAI Vulnerability Actively Exploited Within Hours of Being Made PublicA high-severity vulnerability in PraisonAI is drawing urgent attention after security researchers observed exploitation attempts within hours of public disclosure. The flaw, tracked as CVE-2026-44338 and documented in the GitHub advisory GHSA-6rmh-7xcm-cpxj, exposes a critical au…GBHACKERS.COM
15 MayVMware Fusion Flaw Could Allow Attackers to Gain Root PrivilegesA newly disclosed vulnerability in VMware Fusion has raised serious security concerns after researchers confirmed it could allow attackers to escalate privileges to root on affected systems. The flaw, tracked as CVE-2026-41702, has been rated high severity with a CVSS score of 7.…GBHACKERS.COM
15 May KEVCisco patches another actively exploited SD-WAN zero-day (CVE-2026-20182)Cisco has patched yet another Catalyst SD-WAN Controller authentication bypass vulnerability (CVE-2026-20182) that has been exploited as a zero-day by “a highly sophisticated cyber threat actor”. About CVE-2026-20182 CVE-2026-20182 – affecting both Cisco Catalys…HELPNETSECURITY.COM
15 MayCVE-2026-40379 Azure Entra ID Spoofing VulnerabilityCorrected CVE title. This is an informational change only.MSRC.MICROSOFT.COM
15 MayCVE-2026-42897: Microsoft confirms active exploitation of Exchange Server zero-dayMicrosoft warned that attackers are exploiting a new Exchange Server zero-day vulnerability, tracked as CVE-2026-42897, in the wild. Microsoft warned that threat actors are actively exploiting a new Exchange Server zero-day vulnerability tracked as CVE-2026-42897 (CVSS score 8.1)…SECURITYAFFAIRS.COM
15 May KEVExchange Server zero-day vulnerability can be triggered by opening a malicious emailA newly discovered zero-day vulnerability in Microsoft Exchange Server has experts declaring an emergency and urging CSOs to think about the need to abandon on-premises email solutions. “Because it’s already being exploited in the wild, this isn’t a ‘patch next week situation; it…CSOONLINE.COM
15 MayMetasploit Wrap-Up 05/15/2026Weaponizing a text editor for fun and profit Gather round, dear readers, because today, we (by we, we mean @h00die) dropped the ultimate persistence mechanism: Vim plugin persistence. And honestly, calling it "persistence" feels redundant — Vim is already the most persistent thin…RAPID7.COM
14 MayNew Fragnesia Linux Kernel LPE Grants Root Access via Page Cache CorruptionDetails have emerged about a new variant of the recent Dirty Frag Linux local privilege escalation (LPE) vulnerability that allows local attackers to gain root access, making it the third such bug to be identified in the kernel within a span of two weeks. Codenamed Fragnesia, the…THEHACKERNEWS.COM
14 May18-Year-Old NGINX Rewrite Module Flaw Enables Unauthenticated RCECybersecurity researchers have disclosed multiple security vulnerabilities impacting NGINX Plus and NGINX Open, including a critical flaw that remained undetected for 18 years. The vulnerability, discovered by depthfirst, is a heap buffer overflow issue impacting ngx_http_rewrite…THEHACKERNEWS.COM
14 May KEVLangflow CVE-2026-33017 Exploited to Steal AWS Keys, Deploy NATS WorkerLangflow instances left unpatched against CVE-2026-33017 are now being actively abused not just for remote code execution, but as launchpads to steal AWS keys and join a NATS-backed botnet-style worker pool dubbed “KeyHunter.” The vulnerability, now listed in CISA’s Known Exploit…GBHACKERS.COM
14 MayMongoDB Security Flaw Enables Arbitrary Code Execution on Vulnerable SystemsThe foundation of countless modern applications is under an emerging threat. A severe vulnerability in MongoDB could allow attackers to execute unauthorised code on targeted database servers undetected. Tracked officially as CVE-2026-8053, this critical flaw serves as a potential…GBHACKERS.COM
14 MayCritical Exim Mailer Flaw Enables Remote Code Execution AttacksA newly disclosed vulnerability in the widely used Exim mail transfer agent exposes thousands of internet-facing mail servers to unauthenticated remote code execution, threatening core email infrastructure across Linux and Unix-like systems. Tracked as CVE-2026-45185 and nickname…GBHACKERS.COM
14 MayPraisonAI vulnerability gets scanned within 4 hours of disclosureA newly disclosed authentication bypass flaw in the open-source AI orchestration framework PraisonAI was probed by internet scanners less than four hours after its public disclosure. According to Sysdig observations, roughly three hours and 44 minutes after a GitHub advisory drop…CSOONLINE.COM
14 MayPraisonAI CVE-2026-44338 Auth Bypass Targeted Within Hours of DisclosureThreat actors have been observed attempting to exploit a recently disclosed security vulnerability in PraisonAI, an open-source multi-agent orchestration framework, within four hours of public disclosure. The vulnerability in question is CVE-2026-44338 (CVSS score: 7.3), a case o…THEHACKERNEWS.COM
14 MayWindows DNS Client Security Flaw Exposes Systems to Remote Code ExecutionWindows systems worldwide are at risk from a new critical flaw in the Windows DNS Client that could allow remote code execution without any user interaction. Tracked as CVE-2026-41096, the vulnerability has been rated critical with a CVSS base score of 9.8. It is patched in Micro…GBHACKERS.COM
14 MayCVE-2026-42945: NGINX Rewrite Heap Overflow Enables Remote DoS & Potential RCECVE-2026-42945: NGINX Rewrite Heap Overflow Enables Remote DoS & Potential RCE CVE-2026-42945 is a heap-based buffer overflow in NGINX that occurs in ngx_http_rewrite_module (the rewrite module). The bug is remotely reachable over HTTP and can be triggered without authenticat…SOCRADAR.IO
14 MayCritical WordPress Plugin Flaw Allows Unauthorized Access to WebsitesA critical vulnerability in a widely used WordPress plugin has exposed more than 200,000 websites to potential takeover, raising urgent concerns across the security community. Security researchers at Wordfence, using their AI-driven PRISM platform, have uncovered a severe authent…GBHACKERS.COM
14 MayNGINX Rift: an 18-year-old flaw in the world’s most deployed web server just came to lightResearchers found a critical 18-year-old buffer overflow flaw in NGINX, tracked as CVE-2026-42945 and named NGINX Rift. If you run NGINX, and statistically speaking, there is a very good chance you do, this week brought news worth stopping for. Security researchers at depthfirst …SECURITYAFFAIRS.COM
14 MayFragnesia: New Linux kernel LPE bug was spawned by Dirty Frag patch (CVE-2026-46300)Researchers have found and disclosed yet another local privilege escalation (LPE) vulnerability in the Linux kernel: CVE-2026-46300, aka “Fragnesia”. The flaw is in the same class of vulnerabilities as the recently disclosed Dirty Frag bug(s). Like Dirty Frag, it affe…HELPNETSECURITY.COM
14 MayCVE-2026-42897 Microsoft Exchange Server Spoofing VulnerabilityImproper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.MSRC.MICROSOFT.COM
14 MayCVE-2026-41615 Microsoft Authenticator Information Disclosure VulnerabilityExposure of sensitive information to an unauthorized actor in Microsoft Authenticator allows an unauthorized attacker to disclose information over a network.MSRC.MICROSOFT.COM
14 MayBroadcom releases VMware Fusion security update for root access bugBroadcom patched a high-severity VMware Fusion flaw, CVE-2026-41702, that could let local attackers gain root privileges. Broadcom released a security update for VMware Fusion to address a high-severity vulnerability, tracked as CVE-2026-41702, that could allow local attackers to…SECURITYAFFAIRS.COM
14 MayCVE-2026-20182: Critical authentication bypass in Cisco Catalyst SD-WAN Controller (FIXED)Overview While researching a critical authentication bypass vulnerability, CVE-2026-20127 , which was exploited in-the-wild , Rapid7 Labs discovered a new authentication bypass vulnerability affecting Cisco Catalyst SD-WAN Controller (formerly known as vSmart), CVE-2026-20182 . T…RAPID7.COM
14 May KEVThe Dark Side of Efficiency: When Network Controllers Become "God Mode" for AttackersImagine you build a massive corporate campus with every security control money can buy. Blast resistant doors. Biometric scanners. Guards at every entrance. Maybe something similar to the infamous Death Star. On paper, it looks fantastic. Then, somewhere along the way, somebody d…RAPID7.COM
14 MayOngoing exploitation of Cisco Catalyst SD-WAN vulnerabilitiesCisco Talos is tracking the active exploitation of CVE-2026-20182, an authentication bypass vulnerability in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, and Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage.TALOSINTELLIGENCE.COM
14 May KEVCisco Catalyst SD-WAN Controller Auth Bypass Actively Exploited to Gain Admin AccessCisco has released updates to address a maximum-severity authentication bypass flaw in Catalyst SD-WAN Controller that it said has been exploited in limited attacks. The vulnerability, tracked as CVE-2026-20182, carries a CVSS score of 10.0. "A vulnerability in the peering authen…THEHACKERNEWS.COM
14 MayLinux Kernel bug Fragnesia allows local root access attacksFragnesia, a new Linux kernel flaw tracked as CVE-2026-46300, could let local attackers gain root access through page cache corruption. Researchers disclosed a new Linux kernel privilege escalation vulnerability named Fragnesia, tracked as CVE-2026-46300 (CVSS score of 7.8). The …SECURITYAFFAIRS.COM
14 May KEVCVE-2026-0265: Authentication Bypass in Palo Alto Networks PAN-OSOverview On May 13, 2026, Palo Alto Networks published a security advisory for CVE-2026-0265 , a signature verification vulnerability that facilitates authentication bypass on PAN-OS , the operating system that most Palo Alto Networks firewalls run. This vulnerability allows a re…RAPID7.COM
14 MayMeet Fragnesia, the third Linux kernel vulnerability in a monthLinux admins reeling from handling last month’s CopyFail and last week’s Dirty Frag kernel vulnerabilities have a new headache to deal with: Fragnesia. “This is a significant vulnerability,” Robert Beggs , head of incident response firm DigitalDefence, told CSO . “It is bypassing…CSOONLINE.COM
14 MayAI agent finds 18-year-old remote code execution flaw in NginxResearchers have found a critical vulnerability in the widely used Nginx web server that can potentially lead to remote code execution under certain conditions. The flaw is a heap buffer overflow that has gone undetected in the program’s code for the past 18 years. Tracked as CVE…CSOONLINE.COM
13 MayMay Patch Tuesday roundup: Critical holes in Windows Netlogon, DNS, and SAP S/4HANACritical vulnerabilities in Windows Server’s networking and identity infrastructure, as well as a serious hole in Microsoft Dynamics 365 on-premises version, highlight Microsoft’s May Patch Tuesday fixes. They are among the 118 vulnerabilities identified this month by the company…CSOONLINE.COM
13 MayPatch Tuesday - May 2026Microsoft is publishing 137 vulnerabilities on May 2026 Patch Tuesday . Microsoft is not aware of exploitation in the wild or public disclosure for any of these vulnerabilities. So far this month, Microsoft has provided patches to address 133 browser vulnerabilities, which are no…RAPID7.COM
13 MayCVE-2026-43894 jq: Wild stack write via signed-integer overflow in decNumber D2U() macroInformation published.MSRC.MICROSOFT.COM
13 MayCVE-2026-43896 jq: Stack Overflow in Recursive Object MergeInformation published.MSRC.MICROSOFT.COM
13 MayCVE-2026-43895 jq: Embedded NUL in jq import paths causes local redaction-policy bypass and preserves sensitive fields in published artifactsInformation published.MSRC.MICROSOFT.COM
13 MayCVE-2026-40612 jq: Stack overflow via unbounded recursion in jv_containsInformation published.MSRC.MICROSOFT.COM
13 MayCVE-2026-41256 jq: Embedded NUL truncates top-level jq programs loaded with -fInformation published.MSRC.MICROSOFT.COM
13 MayCVE-2026-31767 drm/i915/dsi: Don't do DSC horizontal timing adjustments in command modeInformation published.MSRC.MICROSOFT.COM
13 MayCVE-2026-43249 9p/xen: protect xen_9pfs_front_free against concurrent callsInformation published.MSRC.MICROSOFT.COM
13 MayCVE-2026-8177 XML::LibXML versions through 2.0210 for Perl read out-of-bounds heap memory when parsing XML node names containing truncated UTF-8 byte sequencesInformation published.MSRC.MICROSOFT.COM
13 MayCVE-2026-6210 Type confusion and heap-buffer-overflow in Qt SVG marker handling causing application crashInformation published.MSRC.MICROSOFT.COM
13 MayCVE-2026-41257 jq: Signed-int overflow in `stack_reallocate` (jq VM stack)Information published.MSRC.MICROSOFT.COM
13 MayCritical Fortinet vulnerabilities fixed in FortiSandbox and FortiAuthenticatorFortinet patched critical flaws in FortiSandbox and FortiAuthenticator that could let attackers remotely execute code on unpatched systems. Fortinet addressed two critical vulnerabilities affecting FortiSandbox and FortiAuthenticator. The flaws could allow attackers to execute ar…SECURITYAFFAIRS.COM
13 MayMicrosoft’s agentic security system found four critical Windows RCE flawsMicrosoft responded to growing competition in AI security by announcing that its new agentic security system helped researchers discover 16 new vulnerabilities in the Windows networking and authentication stack, including four critical remote code execution (RCE) flaws. MDASH arc…HELPNETSECURITY.COM
13 MayMicrosoft’s new AI system finds 16 Windows flaws, including four critical RCEsMicrosoft has unveiled a new AI-driven vulnerability discovery system that identified 16 previously unknown Windows vulnerabilities, including four critical remote code execution flaws, in what security analysts say could mark a major shift in how software vulnerabilities are dis…CSOONLINE.COM
13 MayQuest KACE SMA flaw CVE-2025-32975: when one unpatched tool opens the door to 60 organizationsCVE-2025-32975 is a critical flaw in Quest KACE SMA used for endpoint management. If exploited, it could impact all managed systems across organizations. CVE-2025-32975 is a critical flaw in Quest KACE SMA used for endpoint management. If exploited, it could impact all managed sy…SECURITYAFFAIRS.COM
13 MayWhen IT Support Calls: Dissecting a ModeloRAT Campaign from Teams to Domain CompromiseOverview Attackers do not need to break into the front door when they can convince employees to open it for them through the tools they already trust. In April 2026, Rapid7 investigated an enterprise intrusion that began with a Microsoft Teams message from a fake “IT Support” acc…RAPID7.COM
13 May KEVFortinet fixes two critical RCE flaws in FortiAuthenticator and FortiSandboxFortinet released a batch of patches across its products on Patch Tuesday, including two critical vulnerabilities that can lead to remote code execution. Fortinet flaws, both zero-day and n-day, have been exploited in the wild many times in the past, so companies should deploy pa…CSOONLINE.COM
12 MayLinux kernel maintainers suggest a ‘kill switch’ to protect systems until a zero-day vulnerability is patchedLinux server admins may get the ability to turn off a vulnerable function in the OS kernel until a patch for a zero-day vulnerability is ready, if a proposal from a kernel developer and maintainer is accepted by the open source community. The idea of a kill switch for privileged …CSOONLINE.COM
12 MayBitUnlocker Downgrade Attack Bypasses Windows 11 Disk Encryption in MinutesA proof-of-concept (PoC) exploit that demonstrates how attackers can bypass Windows 11 BitLocker disk encryption in under 5 minutes. Dubbed the “BitUnlocker” attack, this physical downgrade technique exploits a known vulnerability, CVE-2025-48804. Initially documented…GBHACKERS.COM
12 MayCVE-2026-43500 rxrpc: Also unshare DATA/RESPONSE packets when paged frags are presentInformation published.MSRC.MICROSOFT.COM
12 MayCline AI Agent Flaw Allows Attackers to Launch RCE AttacksA critical security vulnerability in the Cline AI coding assistant’s kanban package exposes developers to remote code execution, data theft, and denial-of-service attacks by simply visiting a malicious website. Security researcher Sagilayani disclosed CVE-2026-44211 on GitH…GBHACKERS.COM
12 MaycPanel flaw exposes enterprises to hosting supply-chain risksA newly disclosed cPanel vulnerability is being exploited at scale, giving attackers a route into web hosting environments that many enterprises may not monitor closely. Analysts say the risk highlights weak visibility into hosting supply chains. The flaw, tracked as CVE-2026-419…CSOONLINE.COM
12 MayCopy.Fail Linux VulnerabilityThis is the worst Linux vulnerability in years. TL;DR copy.fail is a Linux kernel local privilege escalation, not a browser or clipboard attack. Disclosed by Theori on 29 April 2026 with a working PoC. It abuses the kernel crypto API (AF_ALG sockets) plus splice() to write four b…SCHNEIER.COM
12 MayAttackers exploit cPanel CVE-2026-41940 to deploy Filemanager BackdoorAttackers are exploiting cPanel flaw CVE-2026-41940 to install the Filemanager backdoor and gain unauthorized admin access. Cybercriminals are actively exploiting the critical cPanel vulnerability CVE-2026-41940 (CVSS score of 9.3) to deploy a backdoor called Filemanager on compr…SECURITYAFFAIRS.COM
12 MayJetBrains TeamCity vulnerability allows privilege escalation, API exposure (CVE-2026-44413)JetBrains has patched a high-severity vulnerability (CVE-2026-44413) in TeamCity, its popular continuous integration and continuous delivery platform, and is urging organizations with on-premises and self-managed deployments to upgrade to the fixed version or implement a security…HELPNETSECURITY.COM
12 MayStealthy hackers exploit cPanel flaw in active backdoor campaign (CVE-2026-41940)Security researchers at XLab have outlined an active attack campaign targeting CVE-2026-41940, the recently disclosed vulnerability in cPanel & WHM, and have linked it to a stealthy hacking group that has been operating largely undetected for years. The vulnerability allows …HELPNETSECURITY.COM
12 MayCVE-2026-32204 Azure Monitor Agent Elevation of Privilege VulnerabilityExternal control of file name or path in Azure Monitor Agent allows an authorized attacker to elevate privileges locally.MSRC.MICROSOFT.COM
12 MayCVE-2026-32177 .NET Elevation of Privilege VulnerabilityHeap-based buffer overflow in .NET allows an unauthorized attacker to elevate privileges locally.MSRC.MICROSOFT.COM
12 MayCVE-2026-21530 Windows Rich Text Edit Elevation of Privilege VulnerabilityDouble free in Windows Rich Text Edit allows an authorized attacker to elevate privileges locally.MSRC.MICROSOFT.COM
12 MayCVE-2026-33117 Azure SDK for Java Security Feature Bypass VulnerabilityImproper authentication in Azure SDK allows an unauthorized attacker to bypass a security feature over a network.MSRC.MICROSOFT.COM
12 MayCVE-2026-33834 Windows Event Logging Service Elevation of Privilege VulnerabilityImproper access control in Windows Event Logging Service allows an authorized attacker to elevate privileges locally.MSRC.MICROSOFT.COM
12 MayCVE-2026-33839 Win32k Elevation of Privilege VulnerabilityConcurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.MSRC.MICROSOFT.COM
12 MayCVE-2026-33840 Win32k Elevation of Privilege VulnerabilityUse after free in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally.MSRC.MICROSOFT.COM
12 MayCVE-2026-33841 Windows Kernel Elevation of Privilege VulnerabilityHeap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.MSRC.MICROSOFT.COM
12 MayCVE-2026-34329 Microsoft Message Queuing (MSMQ) Remote Code Execution VulnerabilityHeap-based buffer overflow in Windows Message Queuing allows an unauthorized attacker to execute code over an adjacent network.MSRC.MICROSOFT.COM
12 MayCVE-2026-34330 Win32k Elevation of Privilege VulnerabilityInteger overflow or wraparound in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.MSRC.MICROSOFT.COM
12 MayCVE-2026-34331 Win32k Elevation of Privilege VulnerabilityConcurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.MSRC.MICROSOFT.COM
12 MayCVE-2026-34333 Windows Win32k Elevation of Privilege VulnerabilityUse after free in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.MSRC.MICROSOFT.COM
12 MayCVE-2026-34342 Windows Print Spooler Elevation of Privilege VulnerabilityConcurrent execution using shared resource with improper synchronization ('race condition') in Windows Print Spooler Components allows an authorized attacker to elevate privileges locally.MSRC.MICROSOFT.COM
12 MayCVE-2026-34343 Windows Application Identity (AppID) Subsystem Elevation of Privilege VulnerabilityHeap-based buffer overflow in Windows Application Identity (AppID) Subsystem allows an authorized attacker to elevate privileges locally.MSRC.MICROSOFT.COM
12 MayCVE-2026-34344 Windows Ancillary Function Driver for WinSock Elevation of Privilege VulnerabilityAccess of resource using incompatible type ('type confusion') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.MSRC.MICROSOFT.COM
12 MayCVE-2026-34345 Windows Ancillary Function Driver for WinSock Elevation of Privilege VulnerabilityConcurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.MSRC.MICROSOFT.COM
12 MayCVE-2026-34347 Windows Win32k Elevation of Privilege VulnerabilityUse after free in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.MSRC.MICROSOFT.COM
12 MayCVE-2026-34350 Windows Storport Miniport Driver Denial of Service VulnerabilityNull pointer dereference in Windows Storport Miniport Driver allows an unauthorized attacker to deny service over a network.MSRC.MICROSOFT.COM
12 MayCVE-2026-34351 Windows TCP/IP Elevation of Privilege VulnerabilityConcurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an authorized attacker to elevate privileges locally.MSRC.MICROSOFT.COM
12 MayCVE-2026-35415 Windows Storage Spaces Controller Elevation of Privilege VulnerabilityInteger overflow or wraparound in Windows Storage Spaces Controller allows an authorized attacker to elevate privileges locally.MSRC.MICROSOFT.COM
12 MayCVE-2026-35416 Windows Ancillary Function Driver for WinSock Elevation of Privilege VulnerabilityUse after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.MSRC.MICROSOFT.COM
12 MayCVE-2026-35417 Windows Win32k Elevation of Privilege VulnerabilityAccess of resource using incompatible type ('type confusion') in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally.MSRC.MICROSOFT.COM
12 MayCVE-2026-35418 Windows Cloud Files Mini Filter Driver Elevation of Privilege VulnerabilityUse after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.MSRC.MICROSOFT.COM
12 MayCVE-2026-35419 Windows DWM Core Library Information Disclosure VulnerabilityOut-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally.MSRC.MICROSOFT.COM
12 MayCVE-2026-35420 Windows Kernel Elevation of Privilege VulnerabilityHeap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.MSRC.MICROSOFT.COM
12 MayCVE-2026-35421 Windows GDI Remote Code Execution VulnerabilityHeap-based buffer overflow in Windows GDI allows an unauthorized attacker to execute code locally.MSRC.MICROSOFT.COM
12 MayCVE-2026-35422 Windows TCP/IP Driver Security Feature Bypass VulnerabilityAuthentication bypass using an alternate path or channel in Windows TCP/IP allows an authorized attacker to bypass a security feature over a network.MSRC.MICROSOFT.COM
12 MayCVE-2026-35423 Windows 11 Telnet Client Information Disclosure VulnerabilityOut-of-bounds read in Telnet Client allows an unauthorized attacker to disclose information over a network.MSRC.MICROSOFT.COM
12 MayCVE-2026-35424 Internet Key Exchange (IKE) Protocol Denial of Service VulnerabilityMissing release of memory after effective lifetime in Windows Internet Key Exchange (IKE) Protocol allows an unauthorized attacker to deny service over a network.MSRC.MICROSOFT.COM
12 MayCVE-2026-35433 .NET Elevation of Privilege VulnerabilityImproper input validation in .NET allows an unauthorized attacker to elevate privileges locally.MSRC.MICROSOFT.COM
12 MayCVE-2026-35438 Windows Admin Center Elevation of Privilege VulnerabilityMissing authorization in Windows Admin Center allows an authorized attacker to elevate privileges over a network.MSRC.MICROSOFT.COM
12 MayCVE-2026-35439 Microsoft SharePoint Server Remote Code Execution VulnerabilityDeserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.MSRC.MICROSOFT.COM
12 MayCVE-2026-35440 Microsoft Word Information Disclosure VulnerabilityFiles or directories accessible to external parties in Microsoft Office Word allows an unauthorized attacker to disclose information locally.MSRC.MICROSOFT.COM
12 MayCVE-2026-40360 Microsoft Excel Information Disclosure VulnerabilityOut-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.MSRC.MICROSOFT.COM
12 MayCVE-2026-40363 Microsoft Office Remote Code Execution VulnerabilityHeap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.MSRC.MICROSOFT.COM
12 MayCVE-2026-40364 Microsoft Word Remote Code Execution VulnerabilityAccess of resource using incompatible type ('type confusion') in Microsoft Office Word allows an unauthorized attacker to execute code locally.MSRC.MICROSOFT.COM
12 MayCVE-2026-40366 Microsoft Word Remote Code Execution VulnerabilityUse after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.MSRC.MICROSOFT.COM
12 MayCVE-2026-40368 Microsoft SharePoint Server Remote Code Execution VulnerabilityDeserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.MSRC.MICROSOFT.COM
12 MayCVE-2026-40374 Microsoft Power Automate Desktop Information Disclosure VulnerabilityExposure of sensitive information to an unauthorized actor in Power Automate allows an authorized attacker to disclose information over a network.MSRC.MICROSOFT.COM
12 MayCVE-2026-40377 Microsoft Cryptographic Services Elevation of Privilege VulnerabilityHeap-based buffer overflow in Windows Cryptographic Services allows an authorized attacker to elevate privileges locally.MSRC.MICROSOFT.COM
12 MayCVE-2026-40380 Windows Volume Manager Extension Driver Remote Code Execution VulnerabilityHeap-based buffer overflow in Volume Manager Extension Driver allows an authorized attacker to execute code with a physical attack.MSRC.MICROSOFT.COM
12 MayCVE-2026-40399 Windows TCP/IP Elevation of Privilege VulnerabilityStack-based buffer overflow in Windows TCP/IP allows an authorized attacker to elevate privileges locally.MSRC.MICROSOFT.COM
12 MayCVE-2026-40405 Windows TCP/IP Denial of Service VulnerabilityNull pointer dereference in Windows TCP/IP allows an unauthorized attacker to deny service over a network.MSRC.MICROSOFT.COM
12 MayCVE-2026-40406 Windows TCP/IP Information Disclosure VulnerabilityUse after free in Windows TCP/IP allows an unauthorized attacker to disclose information over a network.MSRC.MICROSOFT.COM
12 MayCVE-2026-40407 Windows Common Log File System Driver Elevation of Privilege VulnerabilityHeap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.MSRC.MICROSOFT.COM
12 MayCVE-2026-40408 Windows WAN ARP Driver Elevation of Privilege VulnerabilityUse after free in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges locally.MSRC.MICROSOFT.COM
12 MayCVE-2026-40410 Windows SMB Client Elevation of Privilege VulnerabilityUse after free in Windows SMB Client allows an authorized attacker to elevate privileges locally.MSRC.MICROSOFT.COM
12 MayCVE-2026-40414 Windows TCP/IP Denial of Service VulnerabilityNull pointer dereference in Windows TCP/IP allows an unauthorized attacker to deny service over an adjacent network.MSRC.MICROSOFT.COM
12 MayCVE-2026-40415 Windows TCP/IP Remote Code Execution VulnerabilityUse after free in Windows TCP/IP allows an unauthorized attacker to execute code over a network.MSRC.MICROSOFT.COM
12 MayCVE-2026-40417 Microsoft Dynamics 365 Business Central Elevation of Privilege VulnerabilityWeak authentication in Dynamics Business Central allows an authorized attacker to elevate privileges locally.MSRC.MICROSOFT.COM
12 MayCVE-2026-40419 Microsoft Office Click-To-Run Elevation of Privilege VulnerabilityUse after free in Microsoft Office allows an authorized attacker to elevate privileges locally.MSRC.MICROSOFT.COM
12 MayCVE-2026-40421 Microsoft Word Information Disclosure VulnerabilityExternal control of file name or path in Microsoft Office Word allows an unauthorized attacker to disclose information over a network.MSRC.MICROSOFT.COM
12 MayCVE-2026-41088 Windows Ancillary Function Driver for WinSock Elevation of Privilege VulnerabilityExternal control of file name or path in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.MSRC.MICROSOFT.COM
12 MayCVE-2026-41089 Windows Netlogon Remote Code Execution VulnerabilityStack-based buffer overflow in Windows Netlogon allows an unauthorized attacker to execute code over a network.MSRC.MICROSOFT.COM
12 MayCVE-2026-41094 Microsoft Data Formulator Remote Code Execution VulnerabilityImproper control of generation of code ('code injection') in Microsoft Data Formulator allows an unauthorized attacker to execute code over a network.MSRC.MICROSOFT.COM
12 MayCVE-2026-41095 Data Deduplication Elevation of Privilege VulnerabilityUse after free in Data Deduplication allows an authorized attacker to elevate privileges locally.MSRC.MICROSOFT.COM
12 MayCVE-2026-41096 Windows DNS Client Remote Code Execution VulnerabilityHeap-based buffer overflow in Microsoft Windows DNS allows an unauthorized attacker to execute code over a network.MSRC.MICROSOFT.COM
12 MayCVE-2026-41100 Microsoft 365 Copilot for Android Spoofing VulnerabilityImproper access control in M365 Copilot allows an authorized attacker to perform spoofing locally.MSRC.MICROSOFT.COM
12 MayCVE-2026-41101 Microsoft Word for Android Spoofing VulnerabilityImproper access control in Microsoft Office Word allows an authorized attacker to perform spoofing locally.MSRC.MICROSOFT.COM
12 MayCVE-2026-41102 Microsoft PowerPoint for Android Spoofing VulnerabilityImproper access control in Microsoft Office PowerPoint allows an authorized attacker to perform spoofing locally.MSRC.MICROSOFT.COM
12 MayCVE-2026-41109 GitHub Copilot and Visual Studio Code Security Feature Bypass VulnerabilityImproper neutralization of special elements in output used by a downstream component ('injection') in GitHub Copilot and Visual Studio allows an unauthorized attacker to bypass a security feature over a network.MSRC.MICROSOFT.COM
12 MayCVE-2026-41610 Visual Studio Code Security Feature Bypass VulnerabilityImproper neutralization of input during web page generation ('cross-site scripting') in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.MSRC.MICROSOFT.COM
12 MayCVE-2026-41611 Visual Studio Code Remote Code Execution VulnerabilityImproper neutralization of script-related html tags in a web page (basic xss) in Visual Studio Code allows an unauthorized attacker to execute code locally.MSRC.MICROSOFT.COM
12 MayCVE-2026-41612 Visual Studio Code Information Disclosure VulnerabilityRelative path traversal in Visual Studio Code allows an unauthorized attacker to disclose information locally.MSRC.MICROSOFT.COM
12 MayCVE-2026-41614 M365 Copilot for Desktop Spoofing VulnerabilityImproper access control in M365 Copilot for Desktop allows an unauthorized attacker to perform spoofing locally.MSRC.MICROSOFT.COM
12 MayCVE-2026-32161 Windows Native WiFi Miniport Driver Remote Code Execution VulnerabilityConcurrent execution using shared resource with improper synchronization ('race condition') in Windows Native WiFi Miniport Driver allows an unauthorized attacker to execute code over an adjacent network.MSRC.MICROSOFT.COM
12 MayCVE-2026-32170 Windows Rich Text Edit Elevation of Privilege VulnerabilityDouble free in Windows Rich Text Edit Control allows an authorized attacker to elevate privileges locally.MSRC.MICROSOFT.COM
12 MayCVE-2026-32185 Microsoft Teams Spoofing VulnerabilityFiles or directories accessible to external parties in Microsoft Teams allows an unauthorized attacker to perform spoofing locally.MSRC.MICROSOFT.COM
12 MayCVE-2026-42831 Microsoft Office Remote Code Execution VulnerabilityHeap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.MSRC.MICROSOFT.COM
12 MayCVE-2026-32175 .NET Core Tampering VulnerabilityA tampering vulnerability exists when .NET Core improperly handles specially crafted files. An attacker who successfully exploited this vulnerability could write arbitrary files and directories to certain locations on a vulnerable system. However, an attacker would have limited c…MSRC.MICROSOFT.COM
12 MayCVE-2026-42825 Windows Telephony Service Elevation of Privilege VulnerabilityUse after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.MSRC.MICROSOFT.COM
12 MayCVE-2026-42896 Windows DWM Core Library Elevation of Privilege VulnerabilityInteger overflow or wraparound in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.MSRC.MICROSOFT.COM
12 MayCVE-2026-42898 Microsoft Dynamics 365 On-Premises Remote Code Execution VulnerabilityImproper control of generation of code ('code injection') in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to execute code over a network.MSRC.MICROSOFT.COM
12 MayCVE-2026-42899 ASP.NET Core Denial of Service VulnerabilityLoop with unreachable exit condition ('infinite loop') in ASP.NET Core allows an unauthorized attacker to deny service over a network.MSRC.MICROSOFT.COM
12 MayCVE-2026-33110 Microsoft SharePoint Server Remote Code Execution VulnerabilityDeserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.MSRC.MICROSOFT.COM
12 MayCVE-2026-33112 Microsoft SharePoint Server Remote Code Execution VulnerabilityDeserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.MSRC.MICROSOFT.COM
12 MayCVE-2026-33833 Azure Machine Learning Notebook Spoofing VulnerabilityImproper neutralization of special elements in output used by a downstream component ('injection') in Azure Machine Learning allows an unauthorized attacker to perform spoofing over a network.MSRC.MICROSOFT.COM
12 MayCVE-2026-33835 Windows Cloud Files Mini Filter Driver Elevation of Privilege VulnerabilityUse after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.MSRC.MICROSOFT.COM
12 MayCVE-2026-33837 Windows TCP/IP Local Elevation of Privilege VulnerabilityHeap-based buffer overflow in Windows TCP/IP allows an authorized attacker to elevate privileges locally.MSRC.MICROSOFT.COM
12 MayCVE-2026-33838 Windows Message Queuing (MSMQ) Elevation of Privilege VulnerabilityDouble free in Windows Message Queuing allows an authorized attacker to elevate privileges locally.MSRC.MICROSOFT.COM
12 MayCVE-2026-34332 Windows Kernel-Mode Driver Remote Code Execution VulnerabilityUse after free in Windows Kernel-Mode Drivers allows an authorized attacker to execute code over a network.MSRC.MICROSOFT.COM
12 MayCVE-2026-34334 Windows TCP/IP Elevation of Privilege VulnerabilityConcurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an authorized attacker to elevate privileges locally.MSRC.MICROSOFT.COM
12 MayCVE-2026-34336 Windows DWM Core Library Information Disclosure VulnerabilityBuffer over-read in Windows DWM Core Library allows an authorized attacker to disclose information locally.MSRC.MICROSOFT.COM
12 MayCVE-2026-34337 Windows Cloud Files Mini Filter Driver Elevation of Privilege VulnerabilityUse after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.MSRC.MICROSOFT.COM
12 MayCVE-2026-34338 Windows Telephony Service Elevation of Privilege VulnerabilityUse after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.MSRC.MICROSOFT.COM
12 MayCVE-2026-34339 Windows Lightweight Directory Access Protocol (LDAP) Denial of Service VulnerabilityNull pointer dereference in Windows LDAP - Lightweight Directory Access Protocol allows an authorized attacker to deny service locally.MSRC.MICROSOFT.COM
12 MayCVE-2026-34340 Windows Projected File System Elevation of Privilege VulnerabilityUse after free in Windows Projected File System allows an authorized attacker to elevate privileges locally.MSRC.MICROSOFT.COM
12 MayCVE-2026-34341 Windows Link-Layer Discovery Protocol (LLDP) Elevation of Privilege VulnerabilityDouble free in Windows Link-Layer Discovery Protocol (LLDP) allows an authorized attacker to elevate privileges locally.MSRC.MICROSOFT.COM
12 MayCVE-2026-40357 Microsoft SharePoint Server Remote Code Execution VulnerabilityDeserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.MSRC.MICROSOFT.COM
12 MayCVE-2026-40358 Microsoft Office Remote Code Execution VulnerabilityUse after free in Microsoft Office allows an unauthorized attacker to execute code locally.MSRC.MICROSOFT.COM
12 MayCVE-2026-40359 Microsoft Excel Remote Code Execution VulnerabilityUse after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.MSRC.MICROSOFT.COM
12 MayCVE-2026-40361 Microsoft Word Remote Code Execution VulnerabilityUse after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.MSRC.MICROSOFT.COM
12 MayCVE-2026-40362 Microsoft Excel Remote Code Execution VulnerabilityHeap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.MSRC.MICROSOFT.COM
12 MayCVE-2026-40365 Microsoft SharePoint Server Remote Code Execution VulnerabilityInsufficient granularity of access control in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.MSRC.MICROSOFT.COM
12 MayCVE-2026-40367 Microsoft Word Remote Code Execution VulnerabilityUntrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code locally.MSRC.MICROSOFT.COM
12 MayCVE-2026-40370 SQL Server Remote Code Execution VulnerabilityExternal control of file name or path in SQL Server allows an authorized attacker to execute code over a network.MSRC.MICROSOFT.COM
12 MayCVE-2026-40369 Windows Kernel Elevation of Privilege VulnerabilityUntrusted pointer dereference in Windows Kernel allows an authorized attacker to elevate privileges locally.MSRC.MICROSOFT.COM
12 MayCVE-2026-40382 Windows Telephony Service Elevation of Privilege VulnerabilityUse after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.MSRC.MICROSOFT.COM
12 MayCVE-2026-40397 Windows Common Log File System Driver Elevation of Privilege VulnerabilityInteger underflow (wrap or wraparound) in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.MSRC.MICROSOFT.COM
12 MayCVE-2026-32209 Windows Filtering Platform (WFP) Security Feature Bypass VulnerabilityImproper access control in Windows Filtering Platform (WFP) allows an authorized attacker to bypass a security feature locally.MSRC.MICROSOFT.COM
12 MayCVE-2026-40398 Windows Remote Desktop Services Elevation of Privilege VulnerabilityHeap-based buffer overflow in Windows Remote Desktop allows an authorized attacker to elevate privileges locally.MSRC.MICROSOFT.COM
12 MayCVE-2026-40401 Windows TCP/IP Denial of Service VulnerabilityNull pointer dereference in Windows TCP/IP allows an unauthorized attacker to deny service locally.MSRC.MICROSOFT.COM
12 MayCVE-2026-40402 Windows Hyper-V Elevation of Privilege VulnerabilityUse after free in Windows Hyper-V allows an unauthorized attacker to elevate privileges locally.MSRC.MICROSOFT.COM
12 MayCVE-2026-40403 Windows Graphics Component Remote Code Execution VulnerabilityHeap-based buffer overflow in Windows Win32K - GRFX allows an authorized attacker to execute code locally.MSRC.MICROSOFT.COM
12 MayCVE-2026-40413 Windows TCP/IP Denial of Service VulnerabilityNull pointer dereference in Windows TCP/IP allows an unauthorized attacker to deny service over an adjacent network.MSRC.MICROSOFT.COM
12 MayCVE-2026-40418 Microsoft Office Click-To-Run Elevation of Privilege VulnerabilityUse after free in Microsoft Office Click-To-Run allows an authorized attacker to elevate privileges locally.MSRC.MICROSOFT.COM
12 MayCVE-2026-35436 Microsoft Office Click-To-Run Elevation of Privilege VulnerabilityInsufficient granularity of access control in Microsoft Office Click-To-Run allows an authorized attacker to elevate privileges locally.MSRC.MICROSOFT.COM
12 MayCVE-2026-40420 Microsoft Office Click-To-Run Elevation of Privilege VulnerabilityImproper access control in Microsoft Office Click-To-Run allows an authorized attacker to elevate privileges locally.MSRC.MICROSOFT.COM
12 MayCVE-2026-41086 Windows Admin Center in Azure Portal Elevation of Privilege VulnerabilityImproper access control in Windows Admin Center allows an authorized attacker to elevate privileges over a network.MSRC.MICROSOFT.COM
12 MayCVE-2026-41097 Secure Boot Security Feature Bypass VulnerabilityReliance on a component that is not updateable in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.MSRC.MICROSOFT.COM
12 MayCVE-2026-40381 Azure Connected Machine Agent Elevation of Privilege VulnerabilityImproper access control in Azure Connected Machine Agent allows an authorized attacker to elevate privileges locally.MSRC.MICROSOFT.COM
12 MayCVE-2026-41103 Microsoft SSO Plugin for Jira & Confluence Elevation of Privilege VulnerabilityIncorrect implementation of authentication algorithm in Microsoft SSO Plugin for Jira & Confluence allows an unauthorized attacker to elevate privileges over a network.MSRC.MICROSOFT.COM
12 MayCVE-2026-41613 Visual Studio Code Elevation of Privilege VulnerabilitySession fixation in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network.MSRC.MICROSOFT.COM
12 MayCVE-2026-42823 Azure Logic Apps Elevation of Privilege VulnerabilityImproper access control in Azure Logic Apps allows an authorized attacker to elevate privileges over a network.MSRC.MICROSOFT.COM
12 MayCVE-2026-42830 Azure Monitor Agent Metrics Extension Elevation of Privilege VulnerabilityUntrusted search path in Azure Monitor Agent allows an authorized attacker to elevate privileges locally.MSRC.MICROSOFT.COM
12 MayCVE-2026-42832 Microsoft Office Spoofing VulnerabilityImproper access control in Microsoft Office allows an unauthorized attacker to perform spoofing locally.MSRC.MICROSOFT.COM
12 MayCVE-2026-42833 Microsoft Dynamics 365 On-Premises Remote Code Execution VulnerabilityExecution with unnecessary privileges in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to execute code over a network.MSRC.MICROSOFT.COM
12 MayCVE-2025-54518 AMD: CVE-2025-54518 CPU OP Cache CorruptionThis vulnerability was found and addressed by AMD. We are documenting it in the Security Update Guide to encourage customers to install the May 2026 version of Windows as soon as possible. The vulnerability assigned to this CVE is in certain processor models offered by AMD. The m…MSRC.MICROSOFT.COM
12 MayCVE-2026-42893 Microsoft Outlook for iOS Tampering VulnerabilityImproper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to perform tampering over a network.MSRC.MICROSOFT.COM
12 May KEVMicrosoft’s May 2026 Patch Tuesday Addresses 118 CVEs (CVE-2026-41103)16 Critical 102 Important 0 Moderate 0 Low Microsoft addresses 118 CVEs in its May 2026 Patch Tuesday release, with no zero-days exploited in the wild or publicly disclosed for the first time since June 2024. Microsoft patched 118 CVEs in its May 2026 Patch Tuesday release, with …TENABLE.COM
12 MayNew Exim BDAT Vulnerability Exposes GnuTLS Builds to Potential Code ExecutionExim has released security updates to address a severe security issue affecting certain configurations that could enable memory corruption and potential code execution. Exim is an open-source Mail Transfer Agent (MTA) designed for Unix-like systems to receive, route, and deliver …THEHACKERNEWS.COM
12 May KEVMicrosoft May 2026 Patch Tuesday: Many fixes, but no zero-daysMicrosoft has marked May 2026 Patch Tuesday by releasing fixes for 120+ CVE-numbered vulnerabilities, none of which (for a change) are actively exploited or have been publicly disclosed. Still, some deserve more consideration and should be addressed sooner than others. Patches to…HELPNETSECURITY.COM
11 MayCVE-2026-31706 ksmbd: validate num_aces and harden ACE walk in smb_inherit_dacl()Information published.MSRC.MICROSOFT.COM
11 MayCVE-2026-31723 usb: gadget: f_subset: Fix net_device lifecycle with device_moveInformation published.MSRC.MICROSOFT.COM
11 MayCVE-2026-31724 usb: gadget: f_eem: Fix net_device lifecycle with device_moveInformation published.MSRC.MICROSOFT.COM
11 MayCVE-2026-43036 net: use skb_header_pointer() for TCPv4 GSO frag_off checkInformation published.MSRC.MICROSOFT.COM
11 MayCVE-2026-31707 ksmbd: validate response sizes in ipc_validate_msg()Information published.MSRC.MICROSOFT.COM
11 MayCVE-2026-43042 mpls: add seqcount to protect the platform_label{,s} pairInformation published.MSRC.MICROSOFT.COM
11 MayCVE-2026-31771 Bluetooth: hci_event: move wake reason storage into validated event handlersInformation published.MSRC.MICROSOFT.COM
11 MayCVE-2026-43052 wifi: mac80211: check tdls flag in ieee80211_tdls_operInformation published.MSRC.MICROSOFT.COM
11 MayCVE-2026-31709 smb: client: validate the whole DACL before rewriting it in cifsaclInformation published.MSRC.MICROSOFT.COM
11 MayCVE-2026-43010 bpf: Reject sleepable kprobe_multi programs at attach timeInformation published.MSRC.MICROSOFT.COM
11 MayCVE-2026-43474 fs: init flags_valid before calling vfs_fileattr_getInformation published.MSRC.MICROSOFT.COM
11 MayCVE-2025-71302 drm/panthor: fix for dma-fence safe access rulesInformation published.MSRC.MICROSOFT.COM
11 MayCVE-2026-43309 md raid: fix hang when stopping arrays with metadata through dm-raidInformation published.MSRC.MICROSOFT.COM
11 MayCVE-2026-43300 drm/panel: Fix a possible null-pointer dereference in jdi_panel_dsi_remove()Information published.MSRC.MICROSOFT.COM
11 MayCVE-2026-43306 bpf: crypto: Use the correct destructor kfunc typeInformation published.MSRC.MICROSOFT.COM
11 MayCVE-2026-43443 ASoC: amd: acp-mach-common: Add missing error check for clock acquisitionInformation published.MSRC.MICROSOFT.COM
11 MayCVE-2026-43319 spi: spidev: fix lock inversion between spi_lock and buf_lockInformation published.MSRC.MICROSOFT.COM
11 MayCVE-2026-43344 perf/x86/intel/uncore: Fix die ID init and look up bugsInformation published.MSRC.MICROSOFT.COM
11 MayCVE-2026-43305 drm/amd/display: Fix mismatched unlock for DMUB HW lock in HWSS fast pathInformation published.MSRC.MICROSOFT.COM
11 MayCVE-2026-43310 media: verisilicon: Avoid G2 bus error while decoding H.264 and HEVCInformation published.MSRC.MICROSOFT.COM
11 MayCVE-2026-43400 drm/amdgpu: add upper bound check on user inputs in signal ioctlInformation published.MSRC.MICROSOFT.COM
11 MayCVE-2026-43292 mm/vmalloc: prevent RCU stalls in kasan_release_vmalloc_nodeInformation published.MSRC.MICROSOFT.COM
11 MayCVE-2026-43398 drm/amdgpu: add upper bound check on user inputs in wait ioctlInformation published.MSRC.MICROSOFT.COM
11 MayCVE-2026-43311 soc/tegra: pmc: Fix unsafe generic_handle_irq() callInformation published.MSRC.MICROSOFT.COM
11 MayCVE-2026-43421 usb: gadget: f_ncm: Fix net_device lifecycle with device_moveInformation published.MSRC.MICROSOFT.COM
11 MayCVE-2026-43308 btrfs: don't BUG() on unexpected delayed ref type in run_one_delayed_ref()Information published.MSRC.MICROSOFT.COM
11 MayCVE-2026-42256 net-imap: Denial of service via high iteration count for `SCRAM-*` authenticationInformation published.MSRC.MICROSOFT.COM
11 MayCVE-2026-42246 net-imap vulnerable to STARTTLS stripping via invalid response timingInformation published.MSRC.MICROSOFT.COM
11 MayCVE-2026-7261 SoapServer session-persisted object use-after-free via SOAP header faultInformation published.MSRC.MICROSOFT.COM
11 MayCVE-2026-43053 xfs: close crash window in attr dabtree inactivationInformation published.MSRC.MICROSOFT.COM
11 MayCVE-2026-43048 HID: core: Mitigate potential OOB by removing bogus memset()Information published.MSRC.MICROSOFT.COM
11 MayCVE-2026-31777 ALSA: ctxfi: Check the error for index mappingInformation published.MSRC.MICROSOFT.COM
11 MayCVE-2026-31722 usb: gadget: f_rndis: Fix net_device lifecycle with device_moveInformation published.MSRC.MICROSOFT.COM
11 MayCVE-2026-31725 usb: gadget: f_ecm: Fix net_device lifecycle with device_moveInformation published.MSRC.MICROSOFT.COM
11 MayCVE-2026-43049 HID: logitech-hidpp: Prevent use-after-free on force feedback initialisation failureInformation published.MSRC.MICROSOFT.COM
11 MayCVE-2026-31712 ksmbd: require minimum ACE size in smb_check_perm_dacl()Information published.MSRC.MICROSOFT.COM
11 MayCVE-2026-43019 Bluetooth: hci_conn: fix potential UAF in set_cig_params_syncInformation published.MSRC.MICROSOFT.COM
11 MayCVE-2026-31729 usb: typec: ucsi: validate connector number in ucsi_notify_common()Information published.MSRC.MICROSOFT.COM
11 MayCVE-2026-43009 bpf: Fix incorrect pruning due to atomic fetch precision trackingInformation published.MSRC.MICROSOFT.COM
11 MayCVE-2026-31715 f2fs: fix UAF caused by decrementing sbi->nr_pages[] in f2fs_write_end_io()Information published.MSRC.MICROSOFT.COM
11 MayCVE-2026-43338 btrfs: reserve enough transaction items for qgroup ioctlsInformation published.MSRC.MICROSOFT.COM
11 MayCVE-2026-43318 drm/amdgpu: fix sync handling in amdgpu_dma_buf_move_notifyInformation published.MSRC.MICROSOFT.COM
11 MayCVE-2026-43416 powerpc, perf: Check that current->mm is alive before getting user callchainInformation published.MSRC.MICROSOFT.COM
11 MayCVE-2026-43352 i3c: mipi-i3c-hci: Correct RING_CTRL_ABORT handling in DMA dequeueInformation published.MSRC.MICROSOFT.COM
11 MayCVE-2026-43284 xfrm: esp: avoid in-place decrypt on shared skb fragsInformation published.MSRC.MICROSOFT.COM
11 MayCVE-2025-71299 spi: cadence-quadspi: Parse DT for flashes with the rest of the DT parsingInformation published.MSRC.MICROSOFT.COM
11 MayCVE-2026-43317 most: core: fix leak on early registration failureInformation published.MSRC.MICROSOFT.COM
11 MayCVE-2026-43321 bpf: Properly mark live registers for indirect jumpsInformation published.MSRC.MICROSOFT.COM
11 MayCVE-2026-43456 bonding: fix type confusion in bond_setup_by_slave()Information published.MSRC.MICROSOFT.COM
11 MayCVE-2026-43298 drm/amdgpu: Skip vcn poison irq release on VFInformation published.MSRC.MICROSOFT.COM
11 MayCVE-2026-43299 btrfs: do not ASSERT() when the fs flips RO inside btrfs_repair_io_failure()Information published.MSRC.MICROSOFT.COM
11 MayCVE-2026-43294 drm: renesas: rz-du: mipi_dsi: fix kernel panic when rebooting for some panelsInformation published.MSRC.MICROSOFT.COM
11 MayCVE-2026-43353 i3c: mipi-i3c-hci: Fix race in DMA ring dequeueInformation published.MSRC.MICROSOFT.COM
11 MayCVE-2026-42257 net-imap: Command Injection via "raw" arguments to multiple commandsInformation published.MSRC.MICROSOFT.COM
11 MayCVE-2026-42258 net-imap: Command Injection via unvalidated Symbol inputsInformation published.MSRC.MICROSOFT.COM
11 MayCVE-2026-7258 Out-of-bounds read in urldecode() on NetBSDInformation published.MSRC.MICROSOFT.COM
11 MayCVE-2026-7262 NULL pointer dereference in SOAP apache:Map decoder with missing <value>Information published.MSRC.MICROSOFT.COM
11 MayCVE-2025-14179 SQL injection in pdo_firebird via NUL bytes in quoted stringsInformation published.MSRC.MICROSOFT.COM
11 MayCVE-2026-7259 Null pointer dereference in php_mb_check_encoding() via mb_ereg_search_init()Information published.MSRC.MICROSOFT.COM
11 MayCVE-2025-21723 scsi: mpi3mr: Fix possible crash when setting up bsg failsInformation published.MSRC.MICROSOFT.COM
11 MayCVE-2025-21714 RDMA/mlx5: Fix implicit ODP use after freeInformation published.MSRC.MICROSOFT.COM
11 MayPoC Exploit Released for Android Zero-Click Flaw Enabling Remote Shell AccessPublic references indicate that a GitHub proof-of-concept is now circulating for CVE-2026-0073, the critical Android flaw documented in Google’s May 2026 security bulletin, raising the urgency for defenders with wireless ADB enabled on test or production devices. Google and multi…GBHACKERS.COM
11 May1,800+ MCP servers exposed without authentication: How zero trust can secure the AI agent revolutionWe find ourselves teetering upon a precipice of our own unwitting construction, and the vertiginous depth of our collective negligence ought to give every security practitioner profound pause. In our headlong rush to deploy AI agents across enterprise environments, we have erecte…CSOONLINE.COM
11 MayThe impact of Mythos and Florida Man, confidence gaps, phishing, & AI adoption - Erich... - ESW #458The Weekly Enterprise News This week, in the enterprise security news, 1. Copy Fail 2. The hits keep coming for CVE, NIST and NVD 3. Cyber attacks on breathalyzers 4. insurance carriers pulling support for AI 5. Florida Man pleads guilty 6. ignore the humanities at your own peril…YOUTUBE.COM
11 MaycPanel and WHM Servers Targeted in Attacks Exploiting CVE-2026-41940A critical authentication bypass vulnerability affecting cPanel and WHM servers, identified as CVE-2026-41940, is currently under active exploitation by a highly sophisticated and elusive cybercriminal syndicate known as Mr_Rot13. The vulnerability carries a maximum severity CVSS…GBHACKERS.COM
11 May KEVNew ‘Dirty Frag’ exploit targets Linux kernel for root accessA newly disclosed Linux privilege escalation issue dubbed “Dirty Frag” is giving attackers a cleaner path to post-compromise escalation to root privileges. According to Microsoft, a couple of vulnerabilities constituting the issue, affecting Linux kernel networking and memory-fra…CSOONLINE.COM
11 MayLinux developers weigh emergency “killswitch” for vulnerable kernel functionsLinux kernel developers are reviewing a proposal for an emergency risk mitigation mechanism (“Killswitch”) that would allow administrators to disable vulnerable kernel functions at runtime. The proposal, submitted by Linux kernel developer/maintainer Sasha Levin, arri…HELPNETSECURITY.COM
11 MayVU#937808: Casdoor contains Arbitrary File Write vulnerabilityOverview Casdoor contains an arbitrary file write vulnerability in the implementation of its "Local File System" storage provider. Due to insufficient sanitization of user-supplied paths, an authenticated user with file upload permissions can escape the intended storage directory…KB.CERT.ORG
11 MayVU#471747: dnsmasq contains several vulnerabilities, including attacker DNS redirect, privilege escalation, and heap manipulationOverview dnsmasq is affected by multiple memory safety and input validation vulnerabilities, including heap buffer overflows, heap corruption, and code execution flaws. Collectively, these vulnerabilities enable attackers to poison cached DNS records, bypass security controls, cr…KB.CERT.ORG
11 MaycPanel CVE-2026-41940 Under Active Exploitation to Deploy Filemanager BackdoorA threat actor named Mr_Rot13 has been attributed to the exploitation of a recently disclosed critical cPanel flaw to deploy a backdoor codenamed Filemanager on compromised environments. The attack exploits CVE-2026-41940, a vulnerability impacting cPanel and WebHost Manager (WHM…THEHACKERNEWS.COM
11 MayFlash Alert: EtherRat and TukTuk C2 End in The Gentleman RansomwareThe EtherRAT malware family was first reported by Sysdig back in December 2025. At that time, the initial access vector was exploitation of CVE-2025-55182 (React2Shell) targeting Linux servers. In March 2026, a Windows variant campaign was reported by Atos, with their investigati…THEDFIRREPORT.COM
10 MayCVE-2026-33814 Infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE in net/http/internal/http2 in golang.org/x/netInformation published.MSRC.MICROSOFT.COM
10 MayCVE-2026-39823 Bypass of meta content URL escaping causes XSS in html/templateInformation published.MSRC.MICROSOFT.COM
10 MayCVE-2026-41889 pgx: SQL Injection via placeholder confusion with dollar quoted string literalsInformation published.MSRC.MICROSOFT.COM
10 MayCVE-2026-6664 PgBouncer integer overflow in PgBouncer network packet parsingInformation published.MSRC.MICROSOFT.COM
10 MayCVE-2026-6667 PgBouncer missing authorization check in KILL_CLIENT admin commandInformation published.MSRC.MICROSOFT.COM
10 MayCVE-2026-6666 PgBouncer crash in kill_pool_logins_server_errorInformation published.MSRC.MICROSOFT.COM
10 MayCVE-2026-45130 Vim: Heap Buffer Overflow in spell file loadingInformation published.MSRC.MICROSOFT.COM
10 MayCVE-2026-44656 Vim: OS Command Injection via 'path' completionInformation published.MSRC.MICROSOFT.COM
10 MayCVE-2026-33811 Crash when handling long CNAME response in netInformation published.MSRC.MICROSOFT.COM
10 MayCVE-2026-39817 Invoking "go tool pack" does not sanitize output paths in cmd/goInformation published.MSRC.MICROSOFT.COM
10 MayCVE-2026-39819 Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/goInformation published.MSRC.MICROSOFT.COM
10 MayCVE-2026-39820 Quadratic string concatentation in consumeComment in net/mailInformation published.MSRC.MICROSOFT.COM
10 MayCVE-2026-39825 ReverseProxy forwards queries with more than urlmaxqueryparams parameters in net/http/httputilInformation published.MSRC.MICROSOFT.COM
10 MayCVE-2026-39826 Escaper bypass leads to XSS in html/templateInformation published.MSRC.MICROSOFT.COM
10 MayCVE-2026-39836 Panic in Dial and LookupPort when handling NUL byte on Windows in netInformation published.MSRC.MICROSOFT.COM
10 MayCVE-2026-42499 Quadratic string concatenation in consumePhrase in net/mailInformation published.MSRC.MICROSOFT.COM
10 MayCVE-2026-42501 Malicious module proxy can bypass checksum database in cmd/goInformation published.MSRC.MICROSOFT.COM
10 MayCVE-2026-33079 Mistune ReDoS in LINK_TITLE_RE allows denial of service with crafted Markdown titlesInformation published.MSRC.MICROSOFT.COM
10 MayOllama Out-of-Bounds Read Vulnerability Allows Remote Process Memory LeakCybersecurity researchers have disclosed a critical security vulnerability in Ollama that, if successfully exploited, could allow a remote, unauthenticated attacker to leak its entire process memory. The out-of-bounds read flaw, which likely impacts over 300,000 servers globally,…THEHACKERNEWS.COM
9 MaycPanel, WHM Release Fixes for Three New Vulnerabilities — Patch NowcPanel has released updates to address three vulnerabilities in cPanel and Web Host Manager (WHM) that could be exploited to achieve privilege escalation, code execution, and denial-of-service. The list of vulnerabilities is as follows - CVE-2026-29201 (CVSS score: 4.3) - An insu…THEHACKERNEWS.COM
8 May13 new critical holes in JavaScript sandbox allow execution of arbitrary codeThirteen critical vulnerabilities have been found in the vm2 JavaScript sandbox package that could allow an attacker’s code to escape the container and do nasty things to IT environments. As a result, developers using this library in their applications are urged to update the sof…CSOONLINE.COM
8 MayPalo Alto Networks firewall flaw has been exploited for several weeksPalo Alto Networks warns that a critical zero-day vulnerability has been discovered in the PAN-OS firewall system. The vulnerability has already been exploited by suspected state-sponsored hackers for nearly a month, reports Bleeping Computer . The vulnerability, CVE-2026-0300, i…CSOONLINE.COM
8 MayPoC Exploit Released for Dirty Frag Linux Kernel VulnerabilityA proof-of-concept exploit for a new Linux kernel vulnerability class dubbed “Dirty Frag”. This universal local privilege escalation vulnerability allows attackers to obtain root access across most major Linux distributions reliably. Because a third party unexpectedly…GBHACKERS.COM
8 MayLinux Kernel Dirty Frag LPE Exploit Enables Root Access Across Major DistributionsDetails have emerged about a new, unpatched local privilege escalation (LPE) vulnerability impacting the Linux kernel. Dubbed Dirty Frag, it has been described as a successor to Copy Fail (CVE-2026-31431, CVSS score: 7.8), a recently disclosed LPE flaw impacting the Linux kernel …THEHACKERNEWS.COM
8 MayAnother Universal Linux Local Privilege Escalation (LPE) Vulnerability: Dirty Frag, (Fri, May 8th)Less than two weeks after the public disclosure of the Copy Fail vulnerability (CVE-2026-31431), another local privilege escalation (LPE) vulnerability in the Linux kernel has been revealed. Referred to as "Dirty Frag," this vulnerability was discovered and reported by Hyunwoo Ki…ISC.SANS.EDU
8 MayCVE-2026-41673 xmldom: Denial of service via uncontrolled recursion in XML serializationInformation published.MSRC.MICROSOFT.COM
8 MayCVE-2026-43869 Apache Thrift: TSSLTransportFactory.java hostname verificationInformation published.MSRC.MICROSOFT.COM
8 MayCVE-2026-41672 xmldom: XML node injection through unvalidated comment serializationInformation published.MSRC.MICROSOFT.COM
8 MayCVE-2026-41674 xmldom: XML injection through unvalidated DocumentType serializationInformation published.MSRC.MICROSOFT.COM
8 MayCVE-2026-41675 xmldom: XML node injection through unvalidated processing instruction serializationInformation published.MSRC.MICROSOFT.COM
8 MayCVE-2026-25243 redis-server RESTORE invalid memory access may allow remote code executionInformation published.MSRC.MICROSOFT.COM
8 MayCVE-2026-31717 ksmbd: validate owner of durable handle on reconnectInformation published.MSRC.MICROSOFT.COM
8 MayCVE-2026-23631 redis-server Lua use-after-free may allow remote code executionInformation published.MSRC.MICROSOFT.COM
8 MayCVE-2026-31718 ksmbd: fix use-after-free in __ksmbd_close_fd() via durable scavengerInformation published.MSRC.MICROSOFT.COM
8 MayCVE-2026-23479 redis-server use-after-free in unblock client flow may allow remote code executionInformation published.MSRC.MICROSOFT.COM
8 MayCVE-2026-25588 RedisTimeSeries RESTORE invalid memory access may allow remote code executionInformation published.MSRC.MICROSOFT.COM
8 MayCVE-2026-25589 RedisBloom RESTORE invalid memory access may allow remote code executionInformation published.MSRC.MICROSOFT.COM
8 MayCritical Vulnerability in Rancher Fleet Enables Full Cluster-Admin PrivilegesThe SUSE Rancher Security team disclosed a critical vulnerability tracked as CVE-2026-41050. This severe flaw affects Rancher Fleet, a popular GitOps tool for managing Kubernetes clusters at scale. The vulnerability completely breaks the platform’s core multi-tenant isolati…GBHACKERS.COM
8 MayCVE-2025-68670: discovering an RCE vulnerability in xrdpDuring a security assessment of Kaspersky USB Redirector, we discovered CVE-2025-68670: a pre-auth RCE in the xrdp server component. Project maintainers promptly patched the vulnerability.SECURELIST.COM
8 MayYour CTEM program is probably ignoring MCP. Here’s how to fix itModel Context Protocol (MCP) is the connective tissue of modern AI tooling and has quietly become one of the most significant blind spots in modern security programs. Like shadow IT before it, shadow AI — especially as it relates to MCP risk — introduces a new class of exposures …CSOONLINE.COM
8 MayIvanti EPMM vulnerability exploited in zero-day attacks (CVE-2026-6973)Ivanti has released fixes for 5 high-severity vulnerabilities in its Endpoint Manager Mobile (EPMM) solution, one of which (CVE-2026-6973) has being exploited as a zero-day by attackers. “We are aware of a very limited number of customers exploited with CVE-2026-6973,”…HELPNETSECURITY.COM
8 MayDirty Frag: Unpatched Linux vulnerability delivers root accessA week after Copy Fail, another Linux local privilege escalation vulnerability dubbed “Dirty Frag” has been revealed, along with a PoC exploit. What is Dirty Frag In effect, Dirty Frag refers to two flaws: A xfrm-ESP Page-Cache Write vulnerability (CVE-2026-43284, aka…HELPNETSECURITY.COM
8 MayMetasploit Wrap-Up 05/08/2026Spring cleanup This week’s Metasploit updates focused on foundational improvements and expanded target reach. Key enhancements were made to the recently released Copy Fail exploit module, which now benefits from payload fixes in linux/x64/exec and linux/armle/exec. These changes …RAPID7.COM
8 MayVU#260001: Linux kernel contains local privilege escalation vulnerability (Copy Fail)Overview A privilege escalation vulnerability has been discovered in Linux kernel versions version 4.17 (released 2017) and later. Many popular distributions and Linux-based containers are affected. This vulnerability was publicly disclosed on April 29, 2026, has been assigned CV…KB.CERT.ORG
8 MayDirty Frag: Linux Kernel Local Privilege Escalation via ESP and RxRPCUnpatched kernel flaw chain (CVE-2026-43284, CVE-2026-43500) enables root escalation on major Linux distributions.WIZ.IO
7 MayThreat Brief: Exploitation of PAN-OS Captive Portal Zero-Day for Unauthenticated Remote Code ExecutionUnit 42 details CVE-2026-0300, a buffer overflow vulnerability in the PAN-OS User-ID Authentication Portal. Read now for details. The post Threat Brief: Exploitation of PAN-OS Captive Portal Zero-Day for Unauthenticated Remote Code Execution appeared first on Unit 42 .UNIT42.PALOALTONETWORKS.COM
7 MayCisco Network Flaw Exposes Devices to Remote Denial-of-Service ExploitsCisco has issued a high-severity security advisory detailing a critical connection exhaustion vulnerability affecting its network management software. Tracked as CVE-2026-20188, this flaw carries a CVSS base score of 7.5. It directly impacts both the Cisco Crosswork Network Contr…GBHACKERS.COM
7 MayCVE-2026-33190 CoreDNS TSIG authentication bypass on encrypted DNS transportsInformation published.MSRC.MICROSOFT.COM
7 MayCVE-2026-32936 CoreDNS DoH GET path missing size validation causes CPU and memory amplificationInformation published.MSRC.MICROSOFT.COM
7 MayCVE-2026-35579 CoreDNS TSIG authentication bypass on gRPC, QUIC, DoH, and DoH3 transportsInformation published.MSRC.MICROSOFT.COM
7 MayCVE-2026-42151 Prometheus Azure AD remote write OAuth client secret exposed via config APIInformation published.MSRC.MICROSOFT.COM
7 MayCVE-2026-42154 Prometheus: remote read endpoint allows denial of service via crafted snappy payloadInformation published.MSRC.MICROSOFT.COM
7 MayCVE-2026-43248 vhost: move vdpa group bound check to vhost_vdpaInformation published.MSRC.MICROSOFT.COM
7 MayCVE-2026-43127 ntfs3: fix circular locking dependency in run_unpack_exInformation published.MSRC.MICROSOFT.COM
7 MayCVE-2026-43161 iommu/vt-d: Skip dev-iotlb flush for inaccessible PCIe device without scalable modeInformation published.MSRC.MICROSOFT.COM
7 MayCVE-2026-43137 ASoC: SOF: Intel: hda: Fix NULL pointer dereferenceInformation published.MSRC.MICROSOFT.COM
7 MayCVE-2026-43234 team: avoid NETDEV_CHANGEMTU event when unregistering slaveInformation published.MSRC.MICROSOFT.COM
7 MayCVE-2026-43185 ksmbd: fix signededness bug in smb_direct_prepare_negotiation()Information published.MSRC.MICROSOFT.COM
7 MayCVE-2025-71273 wifi: rtw88: Use devm_kmemdup() in rtw_set_supported_band()Information published.MSRC.MICROSOFT.COM
7 MayCVE-2026-43116 netfilter: ctnetlink: ensure safe access to master conntrackInformation published.MSRC.MICROSOFT.COM
7 MayCVE-2026-43244 kcm: fix zero-frag skb in frag_list on partial sendmsg errorInformation published.MSRC.MICROSOFT.COM
7 MayCVE-2026-43191 drm/amd/display: Adjust PHY FSM transition to TX_EN-to-PLL_ON for TMDS on DCN35Information published.MSRC.MICROSOFT.COM
7 MayCVE-2025-71272 most: core: fix resource leak in most_register_interface error pathsInformation published.MSRC.MICROSOFT.COM
7 MayCVE-2026-33489 CoreDNS transfer plugin subzone ACL bypass via lexicographic zone comparisonInformation published.MSRC.MICROSOFT.COM
7 MayCVE-2026-32934 CoreDNS DNS-over-QUIC unbounded goroutine growth leads to denial of serviceInformation published.MSRC.MICROSOFT.COM
7 MayCVE-2026-43073 x86-64: rename misleadingly named '__copy_user_nocache()' functionInformation published.MSRC.MICROSOFT.COM
7 MayCVE-2026-43125 dlm: validate length in dlm_search_rsb_treeInformation published.MSRC.MICROSOFT.COM
7 MayCVE-2026-43176 wifi: rtw89: pci: validate release report content before using for RTL8922DEInformation published.MSRC.MICROSOFT.COM
7 MayCVE-2026-43204 ASoC: qcom: q6asm: drop DSP responses for closed data streamsInformation published.MSRC.MICROSOFT.COM
7 MayCVE-2026-43131 drm/amd/pm: Fix null pointer dereference issueInformation published.MSRC.MICROSOFT.COM
7 MayCVE-2026-43126 ALSA: mixer: oss: Add card disconnect checkpointsInformation published.MSRC.MICROSOFT.COM
7 MayCVE-2026-43198 tcp: fix potential race in tcp_v6_syn_recv_sock()Information published.MSRC.MICROSOFT.COM
7 MayCVE-2025-71290 misc: ti_fpc202: fix a potential memory leak in probe functionInformation published.MSRC.MICROSOFT.COM
7 MayCVE-2026-43115 srcu: Use irq_work to start GP in tiny SRCUInformation published.MSRC.MICROSOFT.COM
7 MayCVE-2025-71293 drm/amdgpu/ras: Move ras data alloc before bad page checkInformation published.MSRC.MICROSOFT.COM
7 MayCVE-2026-43172 wifi: iwlwifi: fix 22000 series SMEM parsingInformation published.MSRC.MICROSOFT.COM
7 MayCVE-2025-71285 net: qrtr: Drop the MHI auto_queue feature for IPCR DL channelsInformation published.MSRC.MICROSOFT.COM
7 MayCVE-2026-43197 netconsole: avoid OOB reads, msg is not nul-terminatedInformation published.MSRC.MICROSOFT.COM
7 MayCVE-2026-43118 btrfs: fix zero size inode with non-zero size after log replayInformation published.MSRC.MICROSOFT.COM
7 MayCVE-2026-43109 x86: shadow stacks: proper error handling for mmap lockInformation published.MSRC.MICROSOFT.COM
7 MayCVE-2026-43129 ima: verify the previous kernel's IMA buffer lies in addressable RAMInformation published.MSRC.MICROSOFT.COM
7 MayCVE-2026-43274 mailbox: mchp-ipc-sbi: fix out-of-bounds access in mchp_ipc_get_cluster_aggr_irq()Information published.MSRC.MICROSOFT.COM
7 MayCVE-2026-43258 alpha: fix user-space corruption during memory compactionInformation published.MSRC.MICROSOFT.COM
7 MayCVE-2025-71289 fs/ntfs3: handle attr_set_size() errors when truncating filesInformation published.MSRC.MICROSOFT.COM
7 MayCVE-2026-43107 xfrm: account XFRMA_IF_ID in aevent size calculationInformation published.MSRC.MICROSOFT.COM
7 MayCVE-2026-43243 drm/amd/display: Add signal type check for dcn401 get_phyd32clk_srcInformation published.MSRC.MICROSOFT.COM
7 MayCVE-2025-71294 drm/amdgpu: fix NULL pointer issue buffer funcsInformation published.MSRC.MICROSOFT.COM
7 MayCVE-2026-43250 usb: chipidea: udc: fix DMA and SG cleanup in _ep_nuke()Information published.MSRC.MICROSOFT.COM
7 MayCVE-2026-43237 drm/amdgpu: Refactor amdgpu_gem_va_ioctl for Handling Last Fence Update and Timeline Management v4Information published.MSRC.MICROSOFT.COM
7 MayCVE-2026-43201 APEI/GHES: ARM processor Error: don't go past allocated memoryInformation published.MSRC.MICROSOFT.COM
7 MayCVE-2026-43219 net: cpsw_new: Fix potential unregister of netdev that has not been registered yetInformation published.MSRC.MICROSOFT.COM
7 MayCVE-2026-43165 hwmon: (nct7363) Fix a resource leak in nct7363_present_pwm_faninInformation published.MSRC.MICROSOFT.COM
7 MayCVE-2026-43088 net: af_key: zero aligned sockaddr tail in PF_KEY exportsInformation published.MSRC.MICROSOFT.COM
7 MayCVE-2026-43195 drm/amdgpu: validate user queue size constraintsInformation published.MSRC.MICROSOFT.COM
7 MayCVE-2026-43213 wifi: rtw89: pci: validate sequence number of TX release reportInformation published.MSRC.MICROSOFT.COM
7 MayCVE-2026-43228 hfs: Replace BUG_ON with error handling for CNID count checksInformation published.MSRC.MICROSOFT.COM
7 MayCVE-2026-43216 net: Drop the lock in skb_may_tx_timestamp()Information published.MSRC.MICROSOFT.COM
7 MayCVE-2026-43119 Bluetooth: hci_sync: annotate data-races around hdev->req_statusInformation published.MSRC.MICROSOFT.COM
7 MayCVE-2026-43267 wifi: rtw89: fix potential zero beacon interval in beacon trackingInformation published.MSRC.MICROSOFT.COM
7 MayCVE-2026-43101 ipv6: ioam: fix potential NULL dereferences in __ioam6_fill_trace_data()Information published.MSRC.MICROSOFT.COM
7 MayCVE-2026-43199 net/mlx5e: Fix "scheduling while atomic" in IPsec MAC address queryInformation published.MSRC.MICROSOFT.COM
7 MayCVE-2026-43870 Apache Thrift: Node.js web_server.js multi-vulnerabilityInformation published.MSRC.MICROSOFT.COM
7 MayCVE-2026-43868 Apache Thrift: Rust implementation vulnerable to CVE-2020-13949 patternInformation published.MSRC.MICROSOFT.COM
7 MayCVE-2026-33523 Apache HTTP Server: multiple modules: HTTP response splitting forwarding malicious status lineInformation published.MSRC.MICROSOFT.COM
7 MayCVE-2026-23918 Apache HTTP Server: http2: double free and possible RCE on early resetInformation published.MSRC.MICROSOFT.COM
7 MayCVE-2026-34059 Apache HTTP Server: mod_proxy_ajp: Heap Over-Read and memory disclosure in ajp_parse_data()Information published.MSRC.MICROSOFT.COM
7 MayCVE-2026-34032 Apache HTTP Server: mod_proxy_ajp: Heap Buffer Over-Read Due to Missing Null-Termination Check (ajp_msg_get_string)Information published.MSRC.MICROSOFT.COM
7 MayCVE-2026-24072 Apache HTTP Server: mod_rewrite elevation of privileges via ap_exprInformation published.MSRC.MICROSOFT.COM
7 MayCVE-2026-33006 Apache HTTP Server: mod_auth_digest timing attackInformation published.MSRC.MICROSOFT.COM
7 MayCVE-2026-33007 Apache HTTP Server: mod_authn_socache crashInformation published.MSRC.MICROSOFT.COM
7 MayCVE-2026-29169 Apache HTTP Server: mod_dav_lock indirect lock crashInformation published.MSRC.MICROSOFT.COM
7 MayCVE-2026-29168 Apache HTTP Server: mod_md unrestricted OCSP responseInformation published.MSRC.MICROSOFT.COM
7 MayCVE-2026-33857 Apache HTTP Server: Off-by-one OOB reads in AJP getter functionsInformation published.MSRC.MICROSOFT.COM
7 MayRedis Security Flaws Expose Servers to Remote Code Execution RisksRedis has disclosed and patched five security vulnerabilities, including four rated High severity, that could allow authenticated attackers to achieve remote code execution (RCE) on affected Redis servers. The advisory, published May 5, 2026, by Redis Chief Information Security O…GBHACKERS.COM
7 MayCVE-2026-33845 Gnutls: gnutls: denial of service via dtls zero-length fragmentInformation published.MSRC.MICROSOFT.COM
7 MayCVE-2026-3833 Gnutls: gnutls: policy bypass due to case-sensitive nameconstraints comparisonInformation published.MSRC.MICROSOFT.COM
7 MayCVE-2026-3832 Gnutls: gnutls: security bypass allows acceptance of revoked server certificates via crafted ocsp responseInformation published.MSRC.MICROSOFT.COM
7 MayCVE-2026-6383 Kubevirt: kubevirt: unauthorized subresource access due to improper rbac evaluationInformation published.MSRC.MICROSOFT.COM
7 May KEVCISA Issues Warning Over Palo Alto PAN-OS Flaw Enabling Root-Level AccessThe Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent warning regarding a newly identified, severe vulnerability within Palo Alto Networks PAN-OS. Officially tracked as CVE-2026-0300, this critical flaw was aggressively added to CISA’s Known Explo…GBHACKERS.COM
7 May KEVCritical Palo Alto Networks software bug hits exposed firewallsPalo Alto Networks is warning customers about a critical buffer overflow vulnerability affecting its PAN-OS user-ID authentication portal that is already being exploited in the wild. The flaw allows attackers to execute arbitrary code with root privileges on exposed firewalls, th…CSOONLINE.COM
7 MayCVE-2026-26956: vm2 Sandbox Escape Enables Host RCE in Node.js 25CVE-2026-26956: vm2 Sandbox Escape Enables Host RCE in Node.js 25 CVE-2026-26956 is a critical sandbox escape affecting the Node.js sandbox library vm2. In vm2 3.10.4, attacker-controlled JavaScript executed through VM.run() can break out of the sandbox and reach the host process…SOCRADAR.IO
7 MayPAN-OS RCE Exploit Under Active Use Enabling Root Access and EspionagePalo Alto Networks has disclosed that threat actors may have attempted to unsuccessfully exploit a recently disclosed critical security flaw as early as April 9, 2026. The vulnerability in question is CVE-2026-0300 (CVSS score: 9.3/8.7), a buffer overflow vulnerability in the Use…THEHACKERNEWS.COM
7 MayIvanti EPMM CVE-2026-6973 RCE Under Active Exploitation Grants Admin-Level AccessIvanti is warning that a new security flaw impacting Endpoint Manager Mobile (EPMM) has been explored in limited attacks in the wild. The high-severity vulnerability, CVE-2026-6973 (CVSS score: 7.2), is a case of improper input validation affecting EPMM before versions 12.6.1.1, …THEHACKERNEWS.COM
7 MayOllama vulnerability highlights danger of AI frameworks with unrestricted accessA critical vulnerability in Ollama poses a direct risk of sensitive information leaks to more than 300,000 internet-exposed servers, researchers have found. The flaw, tracked as CVE-2026-7482, stems from an out-of-bounds heap read in Ollama’s model quantization pipeline. Ollama i…CSOONLINE.COM
7 MayNation-state actors exploit Palo Alto PAN-OS zero-day for weeksPalo Alto says hackers exploited PAN-OS zero-day CVE-2026-0300 for weeks, gaining root access to exposed firewalls and hiding traces. Palo Alto Networks warned that suspected state-sponsored hackers have been exploiting the critical PAN-OS zero-day CVE-2026-0300 for nearly a mont…SECURITYAFFAIRS.COM
6 MayQR Phishing Explodes, Ubuntu Under Attack, CISA Warns Critical Infrastructure Prepare for IsolationQR-code phishing is no longer a niche attack. Microsoft says QR phishing attacks jumped from 7.6 million in January to 18.7 million in March 2026 — a 146% increase in just three months. In this episode of Cybersecurity Today, David Shipley explains why QR-based attacks are bypass…CYBERSECURITYTODAY.LIBSYN.COM
6 May KEVPalo Alto PAN-OS Flaw Under Active Exploitation Enables Remote Code ExecutionPalo Alto Networks has released an advisory warning that a critical buffer overflow vulnerability in its PAN-OS software has been exploited in the wild. The vulnerability, tracked as CVE-2026-0300, has been described as a case of unauthenticated remote code execution. It carries …THEHACKERNEWS.COM
6 MayCVE-2026-43037 ip6_tunnel: clear skb2->cb[] in ip4ip6_err()Information published.MSRC.MICROSOFT.COM
6 MayCritical Palo Alto Firewall Vulnerability Enables Attackers to Gain Root PrivilegesPalo Alto Networks has issued an urgent security advisory concerning a critical vulnerability affecting its PAN-OS software. Tracked as CVE-2026-0300, this high-severity security flaw carries a CVSS 4.0 base score of 9.3 and is currently experiencing limited active exploitation i…GBHACKERS.COM
6 MayArgo CD ServerSideDiff Flaw Allows Attackers to Extract Kubernetes SecretsA critical vulnerability has been identified in Argo CD that could allow attackers with minimal privileges to extract highly sensitive Kubernetes Secrets directly from etcd clusters. Tracked as CVE-2026-42880 and rated 9.6, this severe security flaw exposes a missing authorisatio…GBHACKERS.COM
6 May KEVPalo Alto Networks PAN-OS flaw exploited for remote code executionPalo Alto Networks warns of a critical PAN-OS flaw (CVE-2026-0300) that is under active attack, allowing unauthenticated remote code execution. Palo Alto Networks has warned that a critical PAN-OS vulnerability, tracked as CVE-2026-0300 (CVSS score of 9.3), is actively exploited …SECURITYAFFAIRS.COM
6 MayApache fixes critical HTTP/2 double-free flaw CVE-2026-23918 enabling RCEApache fixed several flaws in HTTP Server, including CVE-2026-23918 (CVSS score of 8.8), a double-free bug in HTTP/2 that could allow remote code execution. The Apache Software Foundation has released updates to fix multiple vulnerabilities in its HTTP Server, including CVE-2026-…SECURITYAFFAIRS.COM
6 May KEVWhatsApp warns of Instagram Reels bug that could load risky contentMeta has released security updates for WhatsApp addressing two vulnerabilities that could have exposed users to malicious files or attacker-controlled content on Android, iOS, and Windows devices. The company says it has not seen evidence that either flaw was exploited in the wil…CYBERINSIDER.COM
6 May KEVRoot-level RCE vulnerability in Palo Alto firewalls exploited (CVE-2026-0300)A critical vulnerability (CVE-2026-0300) affecting Palo Alto Networks firewalls is being actively exploited by attackers, the security company acknowledged today, and urged customers to implement mitigations as they are still working on fixes. About CVE-2026-0300 CVE-2026-0300 is…HELPNETSECURITY.COM
6 May KEVCritical Buffer Overflow in Palo Alto Networks PAN-OS User-ID Authentication Portal (CVE-2026-0300)Overview On May 6, 2026, Palo Alto Networks published a security advisory for CVE-2026-0300 , a critical unauthenticated buffer overflow vulnerability affecting PAN-OS PA-Series and VM-Series firewall appliances. Prisma Access, Cloud NGFW, and Panorama appliances are not affected…RAPID7.COM
6 MayPalo Alto warns of critical software bug used in firewall attacksA patch for the bug, tracked as CVE-2026-0300, has not been published yet and Palo Alto Networks said it will be included in releases over the next two weeks.THERECORD.MEDIA
6 MayCritical Buffer Overflow Vulnerability in PAN-OS Exploited in-the-WildDetect and mitigate CVE-2026-0300, a critical vulnerability in Palo Alto Networks PAN-OS User-ID Authentication Portal that allows unauthenticated attackers to achieve remote code execution (RCE) with root privileges.WIZ.IO
5 MayApache HTTP Server Vulnerability Exposes Millions to Remote Code Execution ThreatsThe Apache Software Foundation has released an urgent security update for the Apache HTTP Server to patch a severe vulnerability. Tracked as CVE-2026-23918, this flaw could allow attackers to execute malicious code remotely on affected web servers, putting millions of websites at…GBHACKERS.COM
5 May KEVWeaver E-cology RCE Flaw CVE-2026-22679 Actively Exploited via Debug APIA critical security vulnerability in Weaver (Fanwei) E-cology, an enterprise office automation (OA) and collaboration platform, has come under active exploitation in the wild. The vulnerability (CVE-2026-22679, CVSS score: 9.8) relates to a case of unauthenticated remote code exe…THEHACKERNEWS.COM
5 MayCVE-2026-40170 ngtcp2 has a qlog transport parameter serialization stack buffer overflowInformation published.MSRC.MICROSOFT.COM
5 MayMetInfo CMS CVE-2026-29014 Exploited for Remote Code Execution AttacksThreat actors are actively exploiting a critical security flaw impacting an open-source content management system (CMS) known as MetInfo, according to new findings from VulnCheck. The vulnerability in question is CVE-2026-29014 (CVSS score: 9.8), a code injection flaw that could …THEHACKERNEWS.COM
5 May KEVCritical Weaver E-cology RCE Exploit Raises Alarm for Enterprise SystemsA critical unauthenticated remote code execution vulnerability in Weaver (Fanwei) E-cology is being actively exploited in the wild, with real-world intrusion activity traced back to mid-March 2026, weeks before public awareness. Tracked as CVE-2026-22679 with a CVSS score of 9.8,…GBHACKERS.COM
5 MayAI finds 20-year-old bugs in PostgreSQL and MariaDBOpen-source databases are facing a bit of a memory problem as AI helps surface decades-old buffer overflow issues in widely used components. Security researchers have disclosed a set of high and critical-severity vulnerabilities affecting PostgreSQL and MariaDB, with two bugs rep…CSOONLINE.COM
5 MayFive ways to use Kiro and Amazon Q to strengthen your security postureA Monday morning security alert flags unauthorized access attempts, security group misconfigurations, and AWS Identity and Access Management (IAM) policy violations. Your team needs answers fast. Security teams are using Kiro and Amazon Q Developer to handle repetitive tasks—scan…AWS.AMAZON.COM
5 MayCritical Android vulnerability CVE-2026-0073 fixed by GoogleGoogle patched a critical Android flaw (CVE‑2026‑0073) that lets attackers run code remotely without user action. Google released a security update for Android to address a critical remote code execution flaw, tracked as CVE‑2026‑0073, in the System component. The bug allowed att…SECURITYAFFAIRS.COM
5 MayCritical Apache HTTP/2 Flaw (CVE-2026-23918) Enables DoS and Potential RCEThe Apache Software Foundation (ASF) has released security updates to address several security vulnerabilities in the HTTP Server, including a severe vulnerability that could potentially lead to remote code execution (RCE). The vulnerability, tracked as CVE-2026-23918 (CVSS score…THEHACKERNEWS.COM
5 MayUnpatched flaws turn Ollama’s auto-updater into a persistent RCE vector, researchers sayResearchers at Striga have disclosed two vulnerabilities (CVE-2026-42248, CVE-2026-42249) in Ollama’s Windows auto-updater that, when chained together, may allow an attacker to covertly plant a persistent executable that runs on every login. CVE-2026-42248 and CVE-2026-4224…HELPNETSECURITY.COM
5 MayCopy Fail: What You Need to Know About the Most Severe Linux Threat in YearsCopy Fail (CVE-2026-31431) is a critical Linux kernel LPE that allows stealthy root access. This flaw impacts millions of systems. Read our analysis. The post Copy Fail: What You Need to Know About the Most Severe Linux Threat in Years appeared first on Unit 42 .UNIT42.PALOALTONETWORKS.COM
4 MayFreeBSD Systems at Risk From DHCP Client RCE VulnerabilityThe FreeBSD Project has issued a critical security advisory (FreeBSD-SA-26:12.dhclient) to address a severe Remote Code Execution (RCE) vulnerability in its default IPv4 DHCP client. Tracked as CVE-2026-42511, this flaw allows local network attackers to execute arbitrary code wit…GBHACKERS.COM
4 MaycPanel Vulnerability Exploited to Compromise Government and Military ServersA critical authentication bypass vulnerability in cPanel and Web Host Manager, officially tracked as CVE-2026-41940, is currently being exploited by unidentified threat actors. Security researchers at Ctrl-Alt-Intel recently uncovered an alarming campaign leveraging this vulnerab…GBHACKERS.COM
4 May KEVCISA Flags Linux Kernel Vulnerability as Threat Actors Launch AttacksThe Cybersecurity and Infrastructure Security Agency (CISA) has officially added a high-severity Linux kernel vulnerability to its Known Exploited Vulnerabilities (KEV) catalog. Tracked as CVE-2026-31431, this flaw is currently being exploited in the wild by threat actors. This a…GBHACKERS.COM
4 May KEVCISA warns “Copy Fail” Linux flaw is already actively exploitedThe US Cybersecurity and Infrastructure Security Agency (CISA) has added a critical Linux kernel flaw known as “Copy Fail” to its Known Exploited Vulnerabilities (KEV) catalog. This confirms that the issue, tracked as CVE-2026-31431, is already being actively exploited in the wil…CYBERINSIDER.COM
4 MayCritical MOVEit Automation auth bypass vulnerability fixed (CVE-2026-4670)Progress Software has fixed a critical authentication bypass (CVE-2026-4670) and a privilege escalation (CVE-2026-5174) vulnerability in MOVEit Automation, exploitation of which “may lead to unauthorized access, administrative control, and data exposure.” The vulnerab…HELPNETSECURITY.COM
4 MayMultiple threat actors actively exploit cPanel vulnerability (CVE-2026-41940)The situation around the critical cPanel authentication bypass vulnerability (CVE-2026-41940) has deteriorated significantly since our initial coverage. Exploratory probing has evolved into multi-actor exploitation, leading to disrupted websites, ransomware and malware deployment…HELPNETSECURITY.COM
4 MayHackers target governments and MSPs via critical cPanel flaw CVE-2026-41940Attackers exploit a critical cPanel flaw to target government and MSP networks across Southeast Asia and several countries, including the U.S. and Canada. A threat actor is exploiting critical cPanel vulnerability CVE-2026-41940 to target government and military organizations in …SECURITYAFFAIRS.COM
4 MayMOVEit automation flaws could enable full system compromiseProgress fixes critical MOVEit Automation flaws, including an authentication bypass bug that could let attackers gain unauthorized access to systems. Progress Software addressed two vulnerabilities in MOVEit Automation, a critical authentication bypass flaw tracked as CVE-2026-46…SECURITYAFFAIRS.COM
3 MayCVE-2026-6842 Nano: nano: local attacker can inject malicious .desktop launcher due to insecure directory permissionsInformation published.MSRC.MICROSOFT.COM
3 MayCVE-2026-6845 Binutils: binutils: denial of service via crafted elf fileInformation published.MSRC.MICROSOFT.COM
3 MayCVE-2026-6846 Binutils: binutils: arbitrary code execution via malformed xcoff object file processingInformation published.MSRC.MICROSOFT.COM
3 MayCVE-2026-6843 Nano: nano: format string vulnerability leads to denial of serviceInformation published.MSRC.MICROSOFT.COM
3 MayCVE-2017-20230 Storable versions before 3.05 for Perl has a stack overflowInformation published.MSRC.MICROSOFT.COM
3 MayCVE-2026-32148 Lockfile checksums not verified in Hex allows dependency integrity bypassInformation published.MSRC.MICROSOFT.COM
3 MayCVE-2025-11083 GNU Binutils Linker elfcode.h elf_swap_shdr heap-based overflowInformation published.MSRC.MICROSOFT.COM
3 MayCVE-2026-7598 libssh2 userauth.c userauth_password integer overflowInformation published.MSRC.MICROSOFT.COM
3 MayCVE-2026-43058 media: vidtv: fix pass-by-value structs causing MSAN warningsInformation published.MSRC.MICROSOFT.COM
3 MayCVE-2025-9403 jqlang jq JSON jq_test.c run_jq_tests assertionInformation published.MSRC.MICROSOFT.COM
3 MayCVE-2025-8224 GNU Binutils BFD Library elf.c bfd_elf_get_str_section null pointer dereferenceInformation published.MSRC.MICROSOFT.COM
2 MaycPanelSniper PoC Exploit Disclosed as 44,000 Servers Reportedly CompromisedA critical zero-day vulnerability in cPanel and WebHost Manager (WHM) is under massive active exploitation following the public release of a sophisticated proof-of-concept exploit. Tracked as CVE-2026-41940, this flaw has already compromised tens of thousands of servers worldwide…GBHACKERS.COM
2 MayCVE-2026-28532 FRRouting < 10.5.3 Integer Overflow in OSPF TLV Parser FunctionsInformation published.MSRC.MICROSOFT.COM
2 MayCVE-2026-4948 Firewalld: firewalld: local unprivileged user can modify firewall state due to d-bus setter mis-authorizationInformation published.MSRC.MICROSOFT.COM
2 MayMassive cPanel campaign compromised 44,000 servers worldwideA surge in attacks exploiting the critical cPanel & WHM vulnerability CVE-2026-41940 has resulted in at least 44,000 compromised systems now actively scanning and launching attacks. The warning was issued by Shadowserver, which reported a sharp spike in malicious traffic tar…CYBERINSIDER.COM
1 May‘Trivial’ exploit can give attackers root access to Linux kernelCSOs must ensure their Linux-based systems block unauthorized privilege escalation until distros release patches to plug a serious kernel vulnerability affecting all Linux distributions shipped since 2017. Until fixes are available for what’s been dubbed the Copy Fail logic bug (…CSOONLINE.COM
1 MayChromium: CVE-2026-7343 Use after free in ViewsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
1 MayChromium: CVE-2026-7363 Use after free in CanvasThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
1 MayChromium: CVE-2026-7359 Use after free in ANGLEThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
1 MayChromium: CVE-2026-7333 Use after free in GPUThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
1 MayChromium: CVE-2026-7360 Insufficient validation of untrusted input in CompositingThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
1 MayChromium: CVE-2026-7344 Use after free in AccessibilityThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
1 MayChromium: CVE-2026-7358 Use after free in AnimationThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
1 MayChromium: CVE-2026-7334 Use after free in ViewsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
1 MayChromium: CVE-2026-7357 Use after free in GPUThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
1 MayChromium: CVE-2026-7356 Use after free in NavigationThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
1 MayChromium: CVE-2026-7353 Heap buffer overflow in SkiaThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
1 MayChromium: CVE-2026-7351 Race in MHTMLThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
1 MayChromium: CVE-2026-7354 Out of bounds read and write in AngleThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
1 MayChromium: CVE-2026-7349 Use after free in CastThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
1 MayChromium: CVE-2026-7348 Use after free in CodecsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
1 MayChromium: CVE-2026-7335 Use after free in mediaThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
1 MayChromium: CVE-2026-7336 Use after free in WebRTCThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
1 MayChromium: CVE-2026-7350 Use after free in WebMIDIThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
1 MayChromium: CVE-2026-7345 Insufficient validation of untrusted input in FeedbackThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
1 MayChromium: CVE-2026-7347 Use after free in ChromotingThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
1 MayChromium: CVE-2026-7346 Inappropriate implementation in TintThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
1 MayChromium: CVE-2026-7337 Type Confusion in V8This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
1 MayChromium: CVE-2026-7338 Use after free in CastThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
1 MayChromium: CVE-2026-7341 Use after free in WebRTCThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
1 MayChromium: CVE-2026-7340 Integer overflow in ANGLEThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
1 MayChromium: CVE-2026-7339 Heap buffer overflow in WebRTCThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
1 MayChromium: CVE-2026-7355 Use after free in MediaThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.MSRC.MICROSOFT.COM
1 MayWhatsApp Encryption Under Fire After Probe Shut DownA U.S. federal investigation into WhatsApp encryption was shut down before reaching a conclusion — after an internal claim suggested Meta systems may access message content in ways that conflict with public descriptions. In this episode of Cybersecurity Today, Jim Love breaks dow…CYBERSECURITYTODAY.LIBSYN.COM
1 MayCVE-2026-31533 net/tls: fix use-after-free in -EBUSY error path of tls_do_encryptionInformation published.MSRC.MICROSOFT.COM
1 MayCVE-2026-3087 shutil.unpack_archive() doesn't check for Windows absolute paths in ZIPsInformation published.MSRC.MICROSOFT.COM
1 MayCVE-2026-31692 rtnetlink: add missing netlink_ns_capable() check for peer netnsInformation published.MSRC.MICROSOFT.COM
1 MayFederal agencies must patch cPanel bug by Sunday, CISA saysIncident responders at Rapid7 said successful exploitation of CVE-2026-41940 “grants an attacker control over the cPanel host system, its configurations and databases, and websites it manages.”THERECORD.MEDIA
1 May KEVWindows shell spoofing vulnerability puts sensitive data at riskMicrosoft and the US Cybersecurity and Infrastructure Security Agency (CISA) have sounded the alarm about a Windows shell spoofing vulnerability that is already being exploited by attackers. It is not clear by whom as yet, but the main suspects are hackers in Russia. CISA has man…CSOONLINE.COM
1 MayDangerous New Linux Exploit Gives Attackers Root Access to Countless ComputersThe exploit, dubbed CopyFail and tracked as CVE-2026-31431, allows hackers to take over PCs and data center servers. The Linux vulnerabilities have been patched—but many machines remain at risk.WIRED.COM
1 MayMetasploit Wrap-Up 05/01/2026MCP server This release our very own cdelafuente-r7 finished implementing the Metasploit MCP Server (msfmcpd), bringing Model Context Protocol support to Metasploit Framework. MCP lets AI applications like Claude, Cursor, or your own custom agents query Metasploit data. Think of …RAPID7.COM
1 MayCopy Fail: Universal Linux Local Privilege Escalation VulnerabilityDetect and mitigate Copy Fail (CVE-2026-31431), an easily exploitable vulnerability in the Linux kernel that allows escalation from an unprivileged local user account to root access.WIZ.IO
30 AprLinux Kernel 0-Day “Copy Fail” Grants Root Access Across Major Distros Since 2017Security researchers have disclosed a critical zero-day vulnerability in the Linux kernel dubbed “Copy Fail” (CVE-2026-31431), which allows unprivileged local users to gain root access. Using a tiny 732-byte Python script, attackers can exploit a logic flaw present in…GBHACKERS.COM
30 AprProFTPD SQL Injection Flaw Opens Door To Remote Code Execution AttacksA newly disclosed flaw in ProFTPD is drawing urgent attention because it can let attackers move from a simple SQL injection bug to authentication bypass, privilege escalation, and in some environments even remote code execution. Tracked as CVE-2026-42167, the issue was found in P…GBHACKERS.COM
30 AprCVE-2017-3731 Truncated packet could crash via OOB readInformation published.MSRC.MICROSOFT.COM
30 AprCVE-2026-31546 net: bonding: fix NULL deref in bond_debug_rlb_hash_showInformation published.MSRC.MICROSOFT.COM
30 AprCVE-2026-6357 pip self-update functionality can import newly installed modules after wheel installationInformation published.MSRC.MICROSOFT.COM
30 AprCVE-2026-41603 Apache Thrift: Java TSSLTransportFactory hostname verificationInformation published.MSRC.MICROSOFT.COM
30 AprCVE-2026-41636 Apache Thrift: Node.js skip() recursionInformation published.MSRC.MICROSOFT.COM
30 AprCVE-2026-34477 Apache Log4j Core: verifyHostName attribute silently ignored in TLS configuration, allowing hostname verification bypassInformation published.MSRC.MICROSOFT.COM
30 AprCVE-2026-31429 net: skb: fix cross-cache free of KFENCE-allocated skb headInformation published.MSRC.MICROSOFT.COM
30 AprCVE-2026-41305 PostCSS has XSS via Unescaped </style> in its CSS Stringify OutputInformation published.MSRC.MICROSOFT.COM
30 AprCVE-2026-3298 Out-of-bounds write in Windows asyncio.ProacterEventLoop.sock_recvfrom_into() when using nbytesInformation published.MSRC.MICROSOFT.COM
30 AprCVE-2026-31508 net: openvswitch: Avoid releasing netdev before teardown completesInformation published.MSRC.MICROSOFT.COM
30 AprCVE-2026-31540 drm/i915/gt: Check set_default_submission() before deferencingInformation published.MSRC.MICROSOFT.COM
30 AprCVE-2026-6238 Buffer overread in ns_printrrf with corrupted RDATA fieldInformation published.MSRC.MICROSOFT.COM
30 AprCVE-2026-31499 Bluetooth: L2CAP: Fix deadlock in l2cap_conn_del()Information published.MSRC.MICROSOFT.COM
30 AprCVE-2025-48431 Apache Thrift: Specially crafted input can crash a c_glib Thrift server with invalid pointer error.Information published.MSRC.MICROSOFT.COM
30 AprCVE-2026-41602 Apache Thrift: Go TFramedTransport uint32 overflowInformation published.MSRC.MICROSOFT.COM
30 AprCVE-2026-41604 Apache Thrift: Swift Range crash in skip()Information published.MSRC.MICROSOFT.COM
30 AprCVE-2026-41605 Apache Thrift: Swift Compact Protocol integer overflowInformation published.MSRC.MICROSOFT.COM
30 AprCVE-2026-41606 Apache Thrift: c_glib dispatch stack overflowInformation published.MSRC.MICROSOFT.COM
30 AprNew Linux 'Copy Fail' Vulnerability Enables Root Access on Major DistributionsCybersecurity researchers have disclosed details of a Linux local privilege escalation (LPE) flaw that could allow an unprivileged local user to obtain root. The high-severity vulnerability tracked as CVE-2026-31431 (CVSS score: 7.8) has been codenamed Copy Fail by Xint.io and Th…THEHACKERNEWS.COM
30 Apr KEVAttackers Exploit cPanel Authentication Bypass 0-Day After PoC ReleaseA critical zero-day vulnerability, tracked as CVE-2026-41940, is currently being actively exploited across the web hosting industry. This CVSS 9.8 flaw allows unauthenticated remote attackers to bypass cPanel and WHM login mechanisms, granting them full administrative control ove…GBHACKERS.COM
30 Apr KEVCritical cPanel zero-day auth bypass exploited since FebruaryA critical authentication bypass vulnerability in cPanel & WHM is being actively exploited, allowing remote attackers to gain full administrative access to affected servers without credentials. The flaw, tracked as CVE-2026-41940, has received a near-maximum severity score a…CYBERINSIDER.COM
30 AprPoC Disclosed for Critical Root ASUSTOR ADM RCE FlawA critical vulnerability, tracked as CVE-2026-6644, has been uncovered in ASUSTOR’s ADM (ASUSTOR Data Master) operating system. Specifically, the flaw exists within the PPTP VPN Client feature. Carrying a CVSS v4.0 score of 9.4, this OS command injection vulnerability allows an a…GBHACKERS.COM
30 AprNine-year-old Linux kernel flaw enables reliable local privilege escalation (CVE-2026-31431)Security researchers at Theori have disclosed a high-severity local privilege escalation (LPE) vulnerability (CVE-2026-31431) in the Linux kernel. The flaw, nicknamed “Copy Fail”, has affected virtually every major Linux distribution shipped since 2017, and a working …HELPNETSECURITY.COM
30 Apr“Copy Fail” gives root access to all Linux systems via 732-byte exploitA new Linux kernel vulnerability dubbed “Copy Fail” enables unprivileged users to gain root access across nearly all major distributions using a tiny, highly reliable exploit, affecting systems dating back to 2017. The flaw, tracked as CVE-2026-31431, was discovered by security r…CYBERINSIDER.COM
30 AprcPanel zero-day exploited for months before patch release (CVE-2026-41940)A critical authentication bypass vulnerability (CVE-2026-41940) in cPanel, a popular web-based control panel for managing web hosting accounts, is being exploited by attackers in the wild. What’s more, attackers didn’t have to wait for watchTowr security researchers t…HELPNETSECURITY.COM
30 AprCopy Fail: New Linux bug enables Root via page‑cache corruptionLinux flaw CVE‑2026‑31431, ‘Copy Fail,’ lets any local user write four bytes into page cache files, enabling easy escalation to root on major distros. Xint Code researchers warn of a serious Linux flaw, tracked as CVE-2026-31431 (CVSS score of 7.8), dubbed Copy Fail. …SECURITYAFFAIRS.COM
30 Apr KEVcPanel’s authentication bypass bug is being exploited in the wild, CISA warnsThe agency added the flaw to the KEV list days after hosting providers confirmed active, ongoing attacks. The post cPanel’s authentication bypass bug is being exploited in the wild, CISA warns appeared first on CyberScoop .CYBERSCOOP.COM
29 AprLiteLLM CVE-2026-42208 SQL Injection Exploited within 36 Hours of DisclosureIn yet another instance of threat actors quickly jumping on the exploitation bandwagon, a newly disclosed critical security flaw in BerriAI's LiteLLM Python package has come under active exploitation in the wild within 36 hours of the bug becoming public knowledge. The vulnerabil…THEHACKERNEWS.COM
29 AprGitHub.com and Enterprise Server Vulnerability Allows Remote Code ExecutionWiz Research has identified a critical remote code execution (RCE) vulnerability, tracked as CVE-2026-3854, deeply embedded within GitHub’s internal git infrastructure. This high-severity flaw enabled any authenticated user to execute arbitrary commands on backend servers u…GBHACKERS.COM
29 Apr KEVCISA Warns of Windows Shell Zero-Day Exploited in AttacksThe Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent alert regarding a newly discovered zero-day vulnerability affecting Microsoft Windows. On April 28, 2026, the agency officially added CVE-2026-32202 to its Known Exploited Vulnerabilities (KEV) catal…GBHACKERS.COM
29 AprCVE-2026-24051 OpenTelemetry-Go Affected by Arbitrary Code Execution via PATH HijackingInformation published.MSRC.MICROSOFT.COM
29 AprCVE-2019-1563 Padding Oracle in PKCS7_dataDecode and CMS_decrypt_set1_pkeyInformation published.MSRC.MICROSOFT.COM
29 AprCVE-2026-31686 mm/kasan: fix double free for kasan pXdsInformation published.MSRC.MICROSOFT.COM
29 AprCVE-2026-41898 rust-openssl: Unchecked callback-returned length in PSK and cookie generate trampolines can cause OpenSSL to leak adjacent memory to the network peerInformation published.MSRC.MICROSOFT.COM
29 AprCVE-2026-33999 Xorg: xwayland: x.org x server: denial of service via integer underflow in xkb compatibility map handlingInformation published.MSRC.MICROSOFT.COM
29 AprCVE-2026-31689 EDAC/mc: Fix error path ordering in edac_mc_alloc()Information published.MSRC.MICROSOFT.COM
29 AprCVE-2026-31688 driver core: enforce device_lock for driver_match_device()Information published.MSRC.MICROSOFT.COM
29 AprCVE-2026-31548 wifi: cfg80211: cancel pmsr_free_wk in cfg80211_pmsr_wdev_downInformation published.MSRC.MICROSOFT.COM
29 AprCVE-2026-31549 i2c: cp2615: fix serial string NULL-deref at probeInformation published.MSRC.MICROSOFT.COM
29 AprCVE-2026-31550 pmdomain: bcm: bcm2835-power: Increase ASB control timeoutInformation published.MSRC.MICROSOFT.COM
29 AprCVE-2026-31551 wifi: mac80211: Fix static_branch_dec() underflow for aql_disable.Information published.MSRC.MICROSOFT.COM
29 AprCVE-2026-31552 wifi: wlcore: Return -ENOMEM instead of -EAGAIN if there is not enough headroomInformation published.MSRC.MICROSOFT.COM
29 AprCVE-2026-31584 media: mediatek: vcodec: fix use-after-free in encoder release pathInformation published.MSRC.MICROSOFT.COM
29 AprCVE-2026-31661 wifi: brcmsmac: Fix dma_free_coherent() sizeInformation published.MSRC.MICROSOFT.COM
29 AprCVE-2026-31563 net: macb: Use dev_consume_skb_any() to free TX SKBsInformation published.MSRC.MICROSOFT.COM
29 AprCVE-2026-31648 mm: filemap: fix nr_pages calculation overflow in filemap_map_pages()Information published.MSRC.MICROSOFT.COM
29 AprCVE-2026-5435 Potential buffer overflow in ns_sprintrrf TSIG handling pathInformation published.MSRC.MICROSOFT.COM
29 AprCVE-2026-40556 Insecure Directory Permissions in GNU nano Leading to Privilege AbuseInformation published.MSRC.MICROSOFT.COM
29 AprCVE-2026-6861 Emacs: emacs: memory corruption vulnerability when processing svg cssInformation published.MSRC.MICROSOFT.COM
29 AprCVE-2026-2708 Libsoup: libsoup: http request smuggling via duplicate content-length headersInformation published.MSRC.MICROSOFT.COM
29 AprCVE-2026-6732 Libxml2: libxml2: denial of service via crafted xsd-validated documentInformation published.MSRC.MICROSOFT.COM
29 AprCVE-2026-6019 BaseCookie.js_output() does not neutralize embedded charactersInformation published.MSRC.MICROSOFT.COM
29 AprCVE-2026-34001 Xorg: xwayland: x.org x server: use-after-free vulnerability leads to server crash and potential memory corruptionInformation published.MSRC.MICROSOFT.COM
29 AprCVE-2026-34003 Xorg: xwayland: x.org x server: information exposure and denial of service via out-of-bounds memory accessInformation published.MSRC.MICROSOFT.COM
29 AprCISA, Microsoft warn of active exploitation of Windows Shell vulnerability (CVE-2026-32202)Attackers are exploiting CVE-2026-32202, a zero-click Windows Shell spoofing vulnerability that causes victims’ systems to authenticate the attacker’s server, CISA and Microsoft have warned. About CVE-2026-32202 CVE-2026-32202 stems from an incomplete patch for CVE-20…HELPNETSECURITY.COM
29 AprCVE-2026-3854 Exposes a Critical Weak Point in GitHub’s Git Push PipelineCVE-2026-3854 Exposes a Critical Weak Point in GitHub’s Git Push Pipeline A newly disclosed GitHub vulnerability, CVE-2026-3854, has drawn attention because it turned a routine git push operation into a path to remote code execution. The issue affected GitHub’s git push pipeline …SOCRADAR.IO
29 Apr KEVCISA Warns of ConnectWise ScreenConnect Flaw Exploited in AttacksThe Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent warning regarding a critical security flaw in ConnectWise ScreenConnect. CVE-2024-1708 is currently being exploited in real-world attacks. Because of this active threat, CISA officially added the fla…GBHACKERS.COM
29 AprCritical GitHub RCE bug exposed millions of repositoriesA critical remote code execution (RCE) vulnerability in GitHub could potentially allow attackers to execute arbitrary code on GitHub.com and GitHub Enterprise Server. Uncovered by Wiz researchers, the now-patched bug exploited how GitHub handles server-side “git push” operations.…CSOONLINE.COM
29 AprCVE-2026-42208: LiteLLM bug exploited 36 hours after its disclosureAttackers quickly exploited a critical LiteLLM flaw (CVE-2026-42208) to access and modify sensitive database data via SQL injection. Attackers rapidly exploited a critical vulnerability in LiteLLM Python package, tracked as CVE-2026-42208, just days after it became public. The vu…SECURITYAFFAIRS.COM
29 Apr KEVCVE-2026-41940: cPanel & WHM Authentication BypassOverview On April 28, 2026, cPanel issued a security update to fix a critical vulnerability affecting the cPanel & WHM and WP Squared products. In the cPanel release notes, the bug was described as "an issue with session loading and saving." CVE-2026-41940 , the identifier subseq…RAPID7.COM
28 Apr KEVMicrosoft Confirms Active Exploitation of Windows Shell CVE-2026-32202Microsoft on Monday revised its advisory for a now-patched, high-severity security flaw impacting Windows Shell to acknowledge that it has been actively exploited in the wild. The vulnerability in question is CVE-2026-32202 (CVSS score: 4.3), a spoofing vulnerability that could a…THEHACKERNEWS.COM
28 AprCritical LiteLLM Flaw Enables Database Attacks Through SQL InjectionA critical pre-authentication SQL injection vulnerability, identified as CVE-2026-42208, has been discovered in the popular LiteLLM gateway, allowing attackers to access databases without credentials. Cybercriminals have already been observed exploiting this flaw to target high-v…GBHACKERS.COM
28 AprNotepad++ Vulnerability Lets Attackers Crash App and Expose Memory DataA new string injection vulnerability, tracked as CVE-2026-3008, has been discovered in Notepad++ version 8.9.3. This critical flaw allows attackers to crash the application or to instantly and secretly extract sensitive memory information. The Cybersecurity Agency of Singapore (C…GBHACKERS.COM
28 AprInfected Cisco firewalls need cold start to clear persistent Firestarter backdoorSecurity researchers have discovered a chilling backdoor aimed at Cisco System firewalls that exploits unpatched vulnerabilities to maintain persistence, even after patching. This means that attackers can continue to access compromised devices without re-exploiting the holes. At …CSOONLINE.COM
28 AprCritical Unpatched Flaw Leaves Hugging Face LeRobot Open to Unauthenticated RCECybersecurity researchers have disclosed details of a critical security flaw impacting LeRobot, Hugging Face's open-source robotics platform with nearly 24,000 GitHub stars, that could be exploited to achieve remote code execution. The vulnerability in question is CVE-2026-25874 …THEHACKERNEWS.COM
28 AprHugging Face LeRobot Flaw Opens Door to Remote Code Execution AttacksA critical remote code execution (RCE) vulnerability has been uncovered in Hugging Face’s LeRobot, a popular open-source robotics machine learning framework. Tracked as CVE-2026-25874, the flaw carries a maximum CVSS severity score of 9.8 and allows unauthenticated attackers to e…GBHACKERS.COM
28 AprCritical Cursor bug could turn routine Git into RCESecurity researchers have disclosed a high-severity vulnerability affecting the Cursor IDE, allowing arbitrary code execution on a developer’s machine through a seemingly routine repository interaction. According to findings by AI pentesting platform Novee Security, once a develo…CSOONLINE.COM
28 AprResearchers Discover Critical GitHub CVE-2026-3854 RCE Flaw Exploitable via Single Git PushCybersecurity researchers have disclosed details of a critical security vulnerability impacting GitHub.com and GitHub Enterprise Server that could allow an authenticated user to obtain remote code execution with a single "git push" command. The flaw, tracked as CVE-2026-3854 (CVS…THEHACKERNEWS.COM
28 AprCVE-2026-3854 GitHub flaw enables remote code executionCritical GitHub flaw CVE-2026-3854 lets attackers run code with a single git push, exploiting a command injection bug. Researchers found a critical vulnerability in GitHub, tracked as CVE-2026-3854, that allows remote code execution through a simple git push. The vulnerability af…SECURITYAFFAIRS.COM
28 AprSecuring GitHub: Wiz Research uncovers Remote Code Execution in GitHub.com and GitHub Enterprise Server (CVE-2026-3854)Details on CVE-2026-3854: A critical flaw in GitHub’s internal git infrastructure enabling RCE on GitHub.com and GitHub Enterprise Server.WIZ.IO
27 AprCVE-2018-0735 Timing attack against ECDSA signature generationInformation published.MSRC.MICROSOFT.COM
27 AprNessus Agent Windows Flaw Enables SYSTEM-Level Code ExecutionTenable has disclosed a high-severity security vulnerability in its Nessus Agent software for Windows that could allow attackers to execute malicious code with full SYSTEM-level privileges. The flaw, tracked as CVE-2026-33694, has been patched in the newly released Nessus Agent v…GBHACKERS.COM
27 AprMetabase Enterprise RCE Flaw Now Has Public Proof-of-Concept ExploitSecurity researchers have published a working Proof of Concept (PoC) exploit for a critical vulnerability in Metabase Enterprise. Tracked as CVE-2026-33725, this security flaw allows attackers to achieve Remote Code Execution (RCE) and read arbitrary files on targeted systems. Th…GBHACKERS.COM
27 AprAI is reshaping DevSecOps to bring security closer to the codeArtificial intelligence tools are revamping DevSecOps processes, enabling security and development teams to more effectively build safeguards into software products from the get-go. But AI’s impact on DevSecOps goes well beyond tooling and processes, altering the scope, skills, a…CSOONLINE.COM
27 AprFirefox bug CVE-2026-6770 enabled cross-site tracking and Tor fingerprintingCVE-2026-6770 let attackers fingerprint Firefox and Tor users, even in Private mode. Firefox 150 and Tor Browser 15.0.10 fixed it. A vulnerability, tracked as CVE-2026-6770, allowed attackers to fingerprint Firefox users, even in Private Browsing, and also impacted the Tor Browse…SECURITYAFFAIRS.COM
27 AprNIST NVD Update: What it Means For Vulnerability ManagementThe shift from static CVE scoring to risk-based prioritization signals a new era for Vulnerability ManagersWIZ.IO
26 AprCVE-2022-2068 The c_rehash script allows command injectionInformation published.MSRC.MICROSOFT.COM
26 AprCVE-2026-31619 ALSA: fireworks: bound device-supplied status before string array lookupInformation published.MSRC.MICROSOFT.COM
26 AprCVE-2026-41079 OpenPrinting CUPS: Heap out-of-bounds read in SNMP supply-level polling leaks stack memory to authenticated usersInformation published.MSRC.MICROSOFT.COM
26 AprCVE-2026-31557 nvmet: move async event work off nvmet-wqInformation published.MSRC.MICROSOFT.COM
26 AprCVE-2026-31606 usb: gadget: f_hid: don't call cdev_init while cdev in useInformation published.MSRC.MICROSOFT.COM
26 AprCVE-2026-31646 net: lan966x: fix page_pool error handling in lan966x_fdma_rx_alloc_page_pool()Information published.MSRC.MICROSOFT.COM
26 AprCVE-2026-31620 ALSA: usx2y: us144mkii: fix NULL deref on missing interface 0Information published.MSRC.MICROSOFT.COM
26 AprCVE-2026-31593 KVM: SEV: Reject attempts to sync VMSA of an already-launched/encrypted vCPUInformation published.MSRC.MICROSOFT.COM
26 AprCVE-2026-31667 Input: uinput - fix circular locking dependency with ff-coreInformation published.MSRC.MICROSOFT.COM
26 AprCVE-2026-31590 KVM: SEV: Drop WARN on large size for KVM_MEMORY_ENCRYPT_REG_REGIONInformation published.MSRC.MICROSOFT.COM
26 AprCVE-2026-31618 fbdev: tdfxfb: avoid divide-by-zero on FBIOPUT_VSCREENINFOInformation published.MSRC.MICROSOFT.COM
26 AprCVE-2026-31617 usb: gadget: f_ncm: validate minimum block_len in ncm_unwrap_ntb()Information published.MSRC.MICROSOFT.COM
26 AprCVE-2026-31589 mm: call ->free_folio() directly in folio_unmap_invalidate()Information published.MSRC.MICROSOFT.COM
26 AprCVE-2026-31660 nfc: pn533: allocate rx skb before consuming bytesInformation published.MSRC.MICROSOFT.COM
26 AprCVE-2026-31605 fbdev: udlfb: avoid divide-by-zero on FBIOPUT_VSCREENINFOInformation published.MSRC.MICROSOFT.COM
26 AprCVE-2026-31566 drm/amdgpu: Fix fence put before wait in amdgpu_amdkfd_submit_ibInformation published.MSRC.MICROSOFT.COM
26 AprCVE-2026-31599 media: vidtv: fix NULL pointer dereference in vidtv_channel_pmt_match_sectionsInformation published.MSRC.MICROSOFT.COM
26 AprCVE-2026-31602 ALSA: ctxfi: Limit PTP to a single pageInformation published.MSRC.MICROSOFT.COM
26 AprCVE-2026-31637 rxrpc: reject undecryptable rxkad response ticketsInformation published.MSRC.MICROSOFT.COM
26 AprCVE-2026-31570 can: gw: fix OOB heap access in cgw_csum_crc8_rel()Information published.MSRC.MICROSOFT.COM
26 AprCVE-2026-31624 HID: core: clamp report_size in s32ton() to avoid undefined shiftInformation published.MSRC.MICROSOFT.COM
26 AprCVE-2026-31651 mmc: vub300: fix NULL-deref on disconnectInformation published.MSRC.MICROSOFT.COM
26 AprCVE-2026-23422 dpaa2-switch: Fix interrupt storm after receiving bad if_id in IRQ handlerInformation published.MSRC.MICROSOFT.COM
26 AprCVE-2026-31565 RDMA/irdma: Fix deadlock during netdev reset with active connectionsInformation published.MSRC.MICROSOFT.COM
26 AprCVE-2026-31621 bnge: return after auxiliary_device_uninit() in error pathInformation published.MSRC.MICROSOFT.COM
26 AprCVE-2026-31626 staging: rtl8723bs: initialize le_tmp64 in rtw_BIP_verify()Information published.MSRC.MICROSOFT.COM
26 AprCVE-2026-31663 xfrm: hold dev ref until after transport_finish NF_HOOKInformation published.MSRC.MICROSOFT.COM
26 AprCVE-2026-31615 usb: gadget: renesas_usb3: validate endpoint index in standard request handlersInformation published.MSRC.MICROSOFT.COM
26 AprCVE-2026-31610 ksmbd: fix mechToken leak when SPNEGO decode fails after token allocInformation published.MSRC.MICROSOFT.COM
26 AprCVE-2026-41066 lxml: Default configuration of iterparse() and ETCompatXMLParser() allows XXE to local filesInformation published.MSRC.MICROSOFT.COM
26 AprCVE-2026-31645 net: lan966x: fix page pool leak in error pathsInformation published.MSRC.MICROSOFT.COM
26 AprCVE-2026-41907 uuid: Missing buffer bounds check in `v3`/`v5`/`v6` when `buf` is providedInformation published.MSRC.MICROSOFT.COM
26 AprCVE-2026-41411 Vim: Command injection via backtick expansion in tag filenamesInformation published.MSRC.MICROSOFT.COM
26 AprCVE-2026-31598 ocfs2: fix possible deadlock between unlink and dio_end_io_writeInformation published.MSRC.MICROSOFT.COM
26 AprCVE-2026-31537 smb: server: make use of smbdirect_socket.send_io.bcreditsInformation published.MSRC.MICROSOFT.COM
26 AprCVE-2026-23414 tls: Purge async_hold in tls_decrypt_async_wait()Information published.MSRC.MICROSOFT.COM
26 AprCVE-2026-31603 staging: sm750fb: fix division by zero in ps_to_hz()Information published.MSRC.MICROSOFT.COM
26 AprCVE-2026-31608 smb: server: avoid double-free in smb_direct_free_sendmsg after smb_direct_flush_send_list()Information published.MSRC.MICROSOFT.COM
26 AprCVE-2026-31611 ksmbd: require 3 sub-authorities before reading sub_auth[2]Information published.MSRC.MICROSOFT.COM
26 AprCVE-2026-32147 SFTP chroot bypass via path traversal in SSH_FXP_FSETSTATInformation published.MSRC.MICROSOFT.COM
26 AprCVE-2026-31600 arm64: mm: Handle invalid large leaf mappings correctlyInformation published.MSRC.MICROSOFT.COM
26 AprCVE-2026-41676 rust-openssl: Deriver::derive and PkeyCtxRef::derive can overflow short buffers on OpenSSL 1.1.1Information published.MSRC.MICROSOFT.COM
26 AprCVE-2026-31627 i2c: s3c24xx: check the size of the SMBUS message before using itInformation published.MSRC.MICROSOFT.COM
26 AprCVE-2026-31671 xfrm_user: fix info leak in build_report()Information published.MSRC.MICROSOFT.COM
26 AprCVE-2026-31560 spi: spi-dw-dma: fix print error log when wait finish transactionInformation published.MSRC.MICROSOFT.COM
26 AprCVE-2026-41678 rust-openssl: Incorrect bounds assertion in aes key wrapInformation published.MSRC.MICROSOFT.COM
26 AprCVE-2026-31612 ksmbd: validate EaNameLength in smb2_get_ea()Information published.MSRC.MICROSOFT.COM
26 AprCVE-2026-31568 s390/mm: Add missing secure storage access fixups for donated memoryInformation published.MSRC.MICROSOFT.COM
26 AprCVE-2026-31587 ASoC: qcom: q6apm: move component registration to unmanaged versionInformation published.MSRC.MICROSOFT.COM
26 AprCVE-2026-31575 mm/userfaultfd: fix hugetlb fault mutex hash calculationInformation published.MSRC.MICROSOFT.COM
26 AprCVE-2026-31662 tipc: fix bc_ackers underflow on duplicate GRP_ACK_MSGInformation published.MSRC.MICROSOFT.COM
26 AprCVE-2026-31580 bcache: fix cached_dev.sb_bio use-after-free and crashInformation published.MSRC.MICROSOFT.COM
26 AprCVE-2026-41681 rust-openssl: MdCtxRef::digest_final() writes past caller buffer with no length checkInformation published.MSRC.MICROSOFT.COM
26 AprCVE-2026-31639 rxrpc: Fix key reference count leak from call->keyInformation published.MSRC.MICROSOFT.COM
26 AprCVE-2026-31657 batman-adv: hold claim backbone gateways by referenceInformation published.MSRC.MICROSOFT.COM
26 AprCVE-2026-31591 KVM: SEV: Lock all vCPUs when synchronzing VMSAs for SNP launch finishInformation published.MSRC.MICROSOFT.COM
26 AprCVE-2026-31629 nfc: llcp: add missing return after LLCP_CLOSED checksInformation published.MSRC.MICROSOFT.COM
26 AprCVE-2026-31579 wireguard: device: use exit_rtnl callback instead of manual rtnl_lock in pre_exitInformation published.MSRC.MICROSOFT.COM
26 AprCVE-2026-31630 rxrpc: proc: size address buffers for %pISpc outputInformation published.MSRC.MICROSOFT.COM
26 AprCVE-2026-31655 pmdomain: imx8mp-blk-ctrl: Keep the NOC_HDCP clock enabledInformation published.MSRC.MICROSOFT.COM
26 AprCVE-2026-31685 netfilter: ip6t_eui64: reject invalid MAC header for all packetsInformation published.MSRC.MICROSOFT.COM
26 AprCVE-2026-31649 net: stmmac: fix integer underflow in chain modeInformation published.MSRC.MICROSOFT.COM
26 AprCVE-2026-31669 mptcp: fix slab-use-after-free in __inet_lookup_establishedInformation published.MSRC.MICROSOFT.COM
26 AprCVE-2026-31680 net: ipv6: flowlabel: defer exclusive option free until RCU teardownInformation published.MSRC.MICROSOFT.COM
26 AprCVE-2026-31576 media: hackrf: fix to not free memory after the device is registered in hackrf_probe()Information published.MSRC.MICROSOFT.COM
26 AprCVE-2026-31678 openvswitch: defer tunnel netdev_put to RCU releaseInformation published.MSRC.MICROSOFT.COM
26 AprCVE-2026-31595 PCI: endpoint: pci-epf-vntb: Stop cmd_handler work in epf_ntb_epc_cleanupInformation published.MSRC.MICROSOFT.COM
26 AprCVE-2026-31681 netfilter: xt_multiport: validate range encoding in checkentryInformation published.MSRC.MICROSOFT.COM
26 AprCVE-2026-31586 mm: blk-cgroup: fix use-after-free in cgwb_release_workfn()Information published.MSRC.MICROSOFT.COM
26 AprCVE-2026-31578 media: as102: fix to not free memory after the device is registered in as102_usb_probe()Information published.MSRC.MICROSOFT.COM
26 AprCVE-2026-31682 bridge: br_nd_send: linearize skb before parsing ND optionsInformation published.MSRC.MICROSOFT.COM
26 AprCVE-2026-31659 batman-adv: reject oversized global TT response buffersInformation published.MSRC.MICROSOFT.COM
26 AprCVE-2026-31625 HID: alps: fix NULL pointer dereference in alps_raw_event()Information published.MSRC.MICROSOFT.COM
26 AprCVE-2026-31679 openvswitch: validate MPLS set/set_masked payload lengthInformation published.MSRC.MICROSOFT.COM
26 AprCVE-2026-31674 netfilter: ip6t_rt: reject oversized addrnr in rt_mt6_check()Information published.MSRC.MICROSOFT.COM
26 AprCVE-2026-31673 af_unix: read UNIX_DIAG_VFS data under unix_state_lockInformation published.MSRC.MICROSOFT.COM
26 AprCVE-2026-31664 xfrm: clear trailing padding in build_polexpire()Information published.MSRC.MICROSOFT.COM
26 AprCVE-2026-31622 NFC: digital: Bounds check NFC-A cascade depth in SDD response handlerInformation published.MSRC.MICROSOFT.COM
26 AprCVE-2026-31597 ocfs2: fix use-after-free in ocfs2_fault() when VM_FAULT_RETRYInformation published.MSRC.MICROSOFT.COM
26 AprCVE-2026-31592 KVM: SEV: Protect *all* of sev_mem_enc_register_region() with kvm->lockInformation published.MSRC.MICROSOFT.COM
26 AprCVE-2026-31656 drm/i915/gt: fix refcount underflow in intel_engine_park_heartbeatInformation published.MSRC.MICROSOFT.COM
26 AprCVE-2026-23401 KVM: x86/mmu: Drop/zap existing present SPTE even when creating an MMIO SPTEInformation published.MSRC.MICROSOFT.COM
26 AprCVE-2026-31555 futex: Clear stale exiting pointer in futex_lock_pi() retry pathInformation published.MSRC.MICROSOFT.COM
26 AprCVE-2026-31607 usbip: validate number_of_packets in usbip_pack_ret_submit()Information published.MSRC.MICROSOFT.COM
26 AprCVE-2026-31536 smb: server: let send_done handle a completion without IB_SEND_SIGNALEDInformation published.MSRC.MICROSOFT.COM
26 AprCVE-2026-31583 media: em28xx: fix use-after-free in em28xx_v4l2_open()Information published.MSRC.MICROSOFT.COM
26 AprCVE-2026-31638 rxrpc: Only put the call ref if one was acquiredInformation published.MSRC.MICROSOFT.COM
26 Apr KEVCVE-2026-31574 clockevents: Add missing resets of the next_event_forced flagInformation published.MSRC.MICROSOFT.COM
26 AprCVE-2026-31596 ocfs2: handle invalid dinode in ocfs2_group_extendInformation published.MSRC.MICROSOFT.COM
26 AprCVE-2026-31581 ALSA: 6fire: fix use-after-free on disconnectInformation published.MSRC.MICROSOFT.COM
26 AprCVE-2026-31604 wifi: rtw88: fix device leak on probe failureInformation published.MSRC.MICROSOFT.COM
26 AprCVE-2026-31585 media: vidtv: fix nfeeds state corruption on start_streaming failureInformation published.MSRC.MICROSOFT.COM
26 AprCVE-2026-31577 nilfs2: fix NULL i_assoc_inode dereference in nilfs_mdt_save_to_shadow_mapInformation published.MSRC.MICROSOFT.COM
26 AprCVE-2026-41140 Poetry: Path traversal in tar extraction on Python 3.10.0 - 3.10.12 and 3.11.0 - 3.11.4Information published.MSRC.MICROSOFT.COM
26 AprCVE-2026-31665 netfilter: nft_ct: fix use-after-free in timeout object destroyInformation published.MSRC.MICROSOFT.COM
26 AprCVE-2026-31670 net: rfkill: prevent unlimited numbers of rfkill events from being createdInformation published.MSRC.MICROSOFT.COM
26 AprCVE-2026-31642 rxrpc: Fix call removal to use RCU safe deletionInformation published.MSRC.MICROSOFT.COM
26 AprCVE-2026-31613 smb: client: fix OOB reads parsing symlink error responseInformation published.MSRC.MICROSOFT.COM
26 AprCVE-2026-31623 net: usb: cdc-phonet: fix skb frags[] overflow in rx_complete()Information published.MSRC.MICROSOFT.COM
26 AprCVE-2026-31594 PCI: endpoint: pci-epf-vntb: Remove duplicate resource teardownInformation published.MSRC.MICROSOFT.COM
26 AprCVE-2026-31609 smb: client: avoid double-free in smbd_free_send_io() after smbd_send_batch_flush()Information published.MSRC.MICROSOFT.COM
26 AprCVE-2026-41677 rust-openssl: Out-of-bounds read in PEM password callback when user callback returns an oversized lengthInformation published.MSRC.MICROSOFT.COM
26 AprCVE-2026-31616 usb: gadget: f_phonet: fix skb frags[] overflow in pn_rx_complete()Information published.MSRC.MICROSOFT.COM
26 AprCVE-2026-31601 vfio/xe: Reorganize the init to decouple migration from resetInformation published.MSRC.MICROSOFT.COM
26 AprCVE-2026-31668 seg6: separate dst_cache for input and output paths in seg6 lwtunnelInformation published.MSRC.MICROSOFT.COM
26 AprCVE-2026-31582 hwmon: (powerz) Fix use-after-free on USB disconnectInformation published.MSRC.MICROSOFT.COM
26 AprCVE-2026-31676 rxrpc: only handle RESPONSE during service challengeInformation published.MSRC.MICROSOFT.COM
26 AprCVE-2026-31588 KVM: x86: Use scratch field in MMIO fragment to hold small write valuesInformation published.MSRC.MICROSOFT.COM
26 AprCVE-2026-31677 crypto: af_alg - limit RX SG extraction by receive buffer budgetInformation published.MSRC.MICROSOFT.COM
26 AprCVE-2026-31675 net/sched: sch_netem: fix out-of-bounds access in packet corruptionInformation published.MSRC.MICROSOFT.COM
26 AprCVE-2026-31634 rxrpc: fix reference count leak in rxrpc_server_keyring()Information published.MSRC.MICROSOFT.COM
26 AprCVE-2026-31684 net: sched: act_csum: validate nested VLAN headersInformation published.MSRC.MICROSOFT.COM
26 AprCVE-2026-31658 net: altera-tse: fix skb leak on DMA mapping error in tse_start_xmit()Information published.MSRC.MICROSOFT.COM
26 AprCVE-2026-23394 af_unix: Give up GC if MSG_PEEK intervened.Information published.MSRC.MICROSOFT.COM
26 AprCVE-2026-23362 can: bcm: fix locking for bcm_op runtime updatesInformation published.MSRC.MICROSOFT.COM
26 AprCVE-2026-31788 xen/privcmd: restrict usage in unprivileged domUInformation published.MSRC.MICROSOFT.COM
26 AprCVE-2026-23360 nvme: fix admin queue leak on controller resetInformation published.MSRC.MICROSOFT.COM
26 AprCritical bug in CrowdStrike LogScale let attackers access filesCrowdStrike fixed CVE-2026-40050 in LogScale self-hosted, a critical flaw allowing unauthenticated file access via path traversal. CrowdStrike recently disclosed a critical vulnerability, tracked as CVE-2026-40050, affecting its LogScale self-hosted product. The flaw enables unau…SECURITYAFFAIRS.COM
25 AprCVE-2026-23438 net: mvpp2: guard flow control update with global_tx_fc in buffer switchingInformation published.MSRC.MICROSOFT.COM
25 AprCVE-2026-23439 udp_tunnel: fix NULL deref caused by udp_sock_create6 when CONFIG_IPV6=nInformation published.MSRC.MICROSOFT.COM
25 AprCVE-2026-23446 net: usb: aqc111: Do not perform PM inside suspend callbackInformation published.MSRC.MICROSOFT.COM
25 AprCVE-2026-23447 net: usb: cdc_ncm: add ndpoffset to NDP32 nframes bounds checkInformation published.MSRC.MICROSOFT.COM
25 AprCVE-2026-5450 scanf %mc off-by-one heap buffer overflowInformation published.MSRC.MICROSOFT.COM
25 AprCVE-2026-23428 ksmbd: fix use-after-free of share_conf in compound requestInformation published.MSRC.MICROSOFT.COM
25 AprCVE-2026-23434 mtd: rawnand: serialize lock/unlock against other NAND operationsInformation published.MSRC.MICROSOFT.COM
25 AprCVE-2026-41205 Mako: Path traversal via double-slash URI prefix in TemplateLookupInformation published.MSRC.MICROSOFT.COM
25 AprCVE-2025-13763 Libopensc: opensc: multiple uses of uninitialized variableInformation published.MSRC.MICROSOFT.COM
25 AprOver 400,000 sites at risk as hackers exploit Breeze Cache plugin flaw (CVE-2026-3844)Attackers exploit a Breeze Cache flaw (CVE-2026-3844) to upload files without login. Wordfence researchers detected over 170 attacks. Threat actors are exploiting a critical flaw, tracked as CVE-2026-3844 (CVSS score of 9.8), in the Breeze Cache WordPress plugin, allowing them to…SECURITYAFFAIRS.COM
24 AprHackers Track 900+ React2Shell Exploits via Telegram BotsHackers are using Telegram bots and AI tooling to run a structured, at-scale exploitation campaign abusing the critical React2Shell vulnerability (CVE-2025-55182), with evidence of 900+ confirmed compromises. Investigators found an exposed server tied to the Bissa scanner platfor…GBHACKERS.COM
24 AprHackers Exploit Ollama Model Uploads to Leak Server DataCybersecurity researchers have uncovered a severe, unpatched vulnerability in Ollama, a popular open-source platform used for running large language models locally. Tracked as CVE-2026-5757, this critical flaw exists in Ollama’s model quantization engine. If exploited, it allows …GBHACKERS.COM
24 AprCVE-2026-31531 ipv4: nexthop: allocate skb dynamically in rtm_get_nexthop()Information published.MSRC.MICROSOFT.COM
24 AprCVE-2026-31532 can: raw: fix ro->uniq use-after-free in raw_rcv()Information published.MSRC.MICROSOFT.COM
24 AprPython Vulnerability Enables Out-of-Bounds Write on WindowsA high-severity security vulnerability has been discovered in Python’s asyncio module on Windows, potentially allowing attackers to write data beyond the boundaries of an allocated memory buffer. The flaw, tracked as CVE-2026-3298, was publicly disclosed on April 21, 2026, …GBHACKERS.COM
24 AprLMDeploy CVE-2026-33626 Flaw Exploited Within 13 Hours of DisclosureA high-severity security flaw in LMDeploy, an open-source toolkit for compressing, deploying, and serving LLMs, has come under active exploitation in the wild less than 13 hours after its public disclosure. The vulnerability, tracked as CVE-2026-33626 (CVSS score: 7.5), relates t…THEHACKERNEWS.COM
24 AprHackers Exploit Cisco Firepower N-Day Flaws for Unauthorized AccessA state-sponsored threat actor known as UAT-4356 is actively exploiting known vulnerabilities in Cisco Firepower devices to deploy a sophisticated custom backdoor. UAT-4356 exploited two n-day vulnerabilities, CVE-2025-20333 and CVE-2025-20362m affecting Cisco’s Firepower e…GBHACKERS.COM
24 Apr12-year-old Pack2TheRoot bug lets Linux users gain root privileges‘Pack2TheRoot’ flaw lets local Linux users gain root via PackageKit. CVE-2026-41651 (8.8) has existed for nearly 12 years. The Pack2TheRoot flaw, tracked as CVE-2026-41651, lets unprivileged users install or remove system packages without authorization, potentially ga…SECURITYAFFAIRS.COM
24 AprMetasploit Wrap-Up 04/25/2026Check Method Visibility Metasploit has supported check methods for many years now. It’s not always desirable to jump straight into exploiting a vulnerability but instead to determine if the target is vulnerable. Metasploit tries to be very conservative with classifying a target a…RAPID7.COM
⚠️ VULNERABILITY DISCLOSURE 2280[−]
24 JulRussian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA CodesA Russian state-supported espionage group spent months reading Western mailboxes through a then-unknown flaw in Zimbra's webmail client. The payload goes after the last 90 days of email, the organization's entire email directory, the password saved in the browser and the codes ke…THEHACKERNEWS.COM
23 Julwp2shell hits WordPress: detecting pre-auth RCE from plugin drop to command executionWe ran the wp2shell WordPress RCE chain end-to-end with Elastic Defend. Detection rule walkthrough, IOCs, and hunt guidance.ELASTIC.CO
23 JulID: Kootenai County notifies residents of data breachNick Hawthorne reports: Kootenai County has begun notifying residents whose personal information may have been compromised in a ransomware attack detected on the county’s computer network in late March. According to a Kootenai County press release, the County discovered the…DATABREACHES.NET
23 JulTN: Data breach delays start of Sumner County school yearCamellia Burris reports: One Middle Tennessee school district is delaying the start of the school year due to a data breach in its computer network. School officials in Sumner County discovered the breach in its computer network earlier this week and subsequently revised the dist…DATABREACHES.NET
23 JulBuilding a defense in depth strategy for sensitive dataIn this Help Net Security video, Venkata Pavan Kumar Gummadi, Professional Software Engineer at Broadridge, explains how to build a defense in depth strategy for protecting sensitive data. He argues that a single control, like encrypting a disk or turning on DLP, leaves gaps that…HELPNETSECURITY.COM
23 JulRed flags ahead.This week, hosts of N2K CyberWire Maria Varmazis and Dave Bittner…THECYBERWIRE.COM
23 JulMulti-patch vulnerability fixes can leave open source exposedVulnerability management runs on a shorthand. A CVE shows a linked patch, someone applies it, and the ticket moves to closed. That shorthand covers most open source fixes. A share work in a different way, arriving as a run of two or more commits where the first one leaves the fla…HELPNETSECURITY.COM
23 Jul KEVCheck Point warns of SmartConsole zero-day exploited in attacksIsraeli cybersecurity firm Check Point Software has addressed an actively exploited zero-day flaw in the company's SmartConsole graphical user interface (GUI) admin panel. [...]BLEEPINGCOMPUTER.COM
23 JulGitHub revamps bug bounty program with new VIP tier, payout changesGitHub is changing its bug bounty program to reward higher-quality vulnerability reports and reduce low-effort submissions, including AI-generated reports. The changes will take effect on July 27, 2026. Reports submitted before that date will be honored under the previous bounty …HELPNETSECURITY.COM
23 JulMonths-long breach exposes South Korean diplomats’ personal dataSouth Korea’s Foreign Ministry has disclosed that attackers breached the Korea National Diplomatic Academy’s online education system, compromising personal data belonging to current and former ministry staff and diplomats stationed abroad. The Korea National Diplomati…HELPNETSECURITY.COM
23 JulEnd-to-End Encryption and “Going Dark”New paper: “ Encryption and Globalization 15 Years Later: End-to-End Encryption and the Third Round of the ‘Going Dark’ Debate “: Abstract : This Article updates and expands on 2012 research on encryption and globalization, analyzing what the authors call …SCHNEIER.COM
23 JulWhatsApp Web chats exposed by Adobe’s Acrobat extension flawHermeticReader is a now-patched vulnerability in Adobe's popular Acrobat Chrome extension that could have been used to spy on WhatsApp Web users.MALWAREBYTES.COM
23 JulAI Agents Now the Enterprises Fastest Growing Exposed Attack SurfaceSophos report warns that the rapid adoption of AI by businesses is leaving them vulnerable to a new source of cyber threatsINFOSECURITY-MAGAZINE.COM
23 Jul20-year-old web server flaw shipped in modern security cameraA popular Wansview indoor security camera was shipping in 2026 with a web server vulnerable to a flaw first disclosed more than two decades ago. The finding comes from firmware security company Finite State, whose researchers analyzed the Wansview WVC Q5, an inexpensive Wi-Fi cam…CYBERINSIDER.COM
23 JulCobalt adds Autonomous Pentest to scale application security testingCobalt has introduced Cobalt Autonomous Pentest, a new offering that enables continuous offensive security across an organization’s application portfolio by delivering actionable penetration testing results in as little as 24 hours. AI-assisted development enables organizat…HELPNETSECURITY.COM
23 JulGoogle Released Gemini 3.5 Flash Cyber AI, a Specialized AI Model for Vulnerability HuntingGoogle DeepMind unveiled Gemini 3.5 Flash Cyber, an AI model for vulnerability discovery and patching, available only to governments and trusted partners. Google DeepMind announced Gemini 3.5 Flash Cyber on Tuesday, a security-focused AI model built on top of the existing 3.5 Fla…SECURITYAFFAIRS.COM
23 JulHow attackers hosted a fake Claude download page on the claude.ai domainA threat actor abused Anthropic’s Claude Artifacts feature to funnel users toward malware, Huntress researchers have disclosed. Employees at at least 29 organizations were compromised over two days in July, after searching for the Claude desktop app and clicking a sponsored…HELPNETSECURITY.COM
23 JulWhat Happened Between OpenAI and Hugging Face?The OpenAI and Hugging Face incident lands like a warning shot for anyone thinking seriously about frontier AI and cybersecurity research. A model evaluation crossed the neat boundary of a research environment, reached a live third-party production system, and forced the industry…RAPID7.COM
23 JulIranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical InfrastructurePublication: April 7, 2026 Last Update: July 22, 2026 TLP: Clear From the updated version of the Joint Cybersecurity Advisory: Executive Summary The authoring agencies urgently warn U.S. organizations of ongoing Iranian-affiliated cyber targeting of internet-connected operational…DATABREACHES.NET
23 JulClaude Cowork Flaw Could Let AI Agent Escape Its VM and Access Mac FilesCybersecurity researchers have uncovered a sandbox escape vulnerability in Anthropic's Claude Cowork that makes it possible to break out of the confines of a Linux virtual machine (VM) within which the agent runs to read or write files anywhere on the Mac. Accomplish AI, which sh…THEHACKERNEWS.COM
23 JulAI Is Repeating Cloud's MistakesThe rapid adoption of AI shares similarities with the early cloud transition. Organizations moved quickly to adopt new capabilities while still learning how to manage costs, security, and governance. Moving fast without clear oversight can create new risks. However, unlike the ea…YOUTUBE.COM
23 JulIs Patching Dead? Vulnerability Management in the Post-Mythos EraYou cannot out-patch a machine that writes a working exploit from a vulnerability description in twenty hours. Stop trying to optimize a game you cannot win. The post Is Patching Dead? Vulnerability Management in the Post-Mythos Era appeared first on SecurityWeek .SECURITYWEEK.COM
23 JulJoint cyber security advisory on Russian state-sponsored phishing campaign targeting Zimbra webmailThe joint advisory warns that Russia-sponsored threat actors associated with an advanced persistent threat group, known as Laundry Bear, are exploiting a known vulnerability in Zimbra webmail.CYBER.GC.CA
23 Jul KEVEU hits Google with a $1 billion fine.Check Point warns of actively exploited flaw. South Korea discloses a breach affecting diplomats.THECYBERWIRE.COM
23 JulRussia-backed threat actor targets Western organizations in phishing campaignThe threat actor exploited a zero-day flaw in Zimbra to exfiltrate months of emails and other sensitive information.CYBERSECURITYDIVE.COM
23 JulCISA, FBI warn that Iran-linked hackers are expanding target set for water, energyThe agencies said threat groups have disrupted critical infrastructure sites by exploiting vulnerable PLC devices.CYBERSECURITYDIVE.COM
23 JulRussian Hackers Exploit New ‘Zero-Click’ Attack Against Western OrganizationsInternational agencies issue joint alert over state-backed campaign exploiting a critical vulnerability in the Zimbra Collaboration SuiteINFOSECURITY-MAGAZINE.COM
23 JulRussian hackers exploit Zimbra zero-click flaw for email theftCISA is warning that the Russian state-sponsored hacking group Laundry Bear, also known as Void Blizzard, is targeting organizations using Zimbra Collaboration email servers by combining phishing attacks with the exploitation of a now-patched Zimbra vulnerability. [...]BLEEPINGCOMPUTER.COM
23 JulUS government says Iran-linked hackers are disrupting American water and energy providersAn updated government advisory warns that Iranian hackers are exploiting systems used by water and energy providers.TECHCRUNCH.COM
23 JulRussian espionage group using novel Zimbra exploit to steal sensitive data from Western countriesLaundry Bear exploited a zero-day vulnerability for five months before it was patched in July 2025, and the group is still actively exploiting vulnerable environments. The post Russian espionage group using novel Zimbra exploit to steal sensitive data from Western countries appea…CYBERSCOOP.COM
23 JulmacOS flaw lets malware replace trusted apps without security warningsSecurity researchers Talal Haj Bakry and Tommy Mysk have disclosed a macOS weakness that allows malware already running under a user's account to silently replace the executable of trusted applications downloaded from the web and relaunch them without triggering Gatekeeper warnin…CYBERINSIDER.COM
23 JulBeyond the Vulnerability Apocalypse: Scaling Your Basics and Vulnerability ManagementDeveloped together with Usman Chaudhary @ Google for Public Sector ( his post ) Let’s call it what some in the industry are calling it: the vulnerability apocalypse . For years, finding vulnerabilities was slow, expensive, specialized work. LLMs made it cheap — in its first weeks…MEDIUM.COM
23 Jul4 ways AI-driven defense is rewriting the cybersecurity playbookThe cybersecurity landscape has evolved beyond human scale. Today’s adversaries have replaced predictable, manual playbooks with machine-generated attack chains that can breach traditional controls in seconds. To bridge the gap, organizations must move past legacy, reactive contr…CSOONLINE.COM
23 JulChaos ransomware deploys browser-based msaRAT to evade network detectionCisco Talos uncovered msaRAT, a Chaos ransomware RAT that hides C2 traffic by routing it through Chrome or Edge using the Chrome DevTools Protocol. Cisco Talos disclosed msaRAT, a Rust-based remote access trojan attributed to the Chaos ransomware group that routes its entire comm…SECURITYAFFAIRS.COM
23 JulDo not pass Go(ogle).Google gets a billion dollar fine from the EU. The White House considers sanctions against Chinese AI developers. The GAO criticizes overlap in cyber reporting regulations. The Feds warn of Iranian agents targeting OT systems. Researchers disclose a high-severity Linux kernel vul…THECYBERWIRE.COM
22 JulApple Fixes Hide My Email Bug That Exposed Real Addresses in Mail LogsApple has moved to address a security flaw in its Hide My Email service that enabled users' real email addresses to be unmasked, effectively undermining the feature's privacy guarantees. 404 Media reported Tuesday that a fix for the issue was deployed by Apple on July 3, 2026, af…THEHACKERNEWS.COM
22 JulMilford, New Hampshire Confirms Unauthorized Activity, Withholds Details of Suspected CyberattackMilford, New Hampshire is a quintessential New England town. But charm is no defense against cyberattackers, and it appears that the town may have been attacked last week. As DysruptionHub was the first to report, the town began experiencing problems early on July 15. Town email …DATABREACHES.NET
22 JulLG to Ban Residential Proxies from Smart TV AppsThe home appliance giant LG Electronics USA said this week it plans to suspend any apps built for its smart TVs that turn one's television into an always-on residential proxy node. The move comes less than a month after researchers found that more than 42 percent of games and oth…KREBSONSECURITY.COM
22 JulCloud operations become the next big role for agentic AICompanies are using agentic AI to manage growing application environments, automate routine tasks, and support decisions. Business and IT leaders increasingly see the technology as part of cloud application management, according to Unisys’ AI & Cloud Insights Report. T…HELPNETSECURITY.COM
22 JulSecurity teams keep finding critical flaws after scheduled testing endsEnterprise environments change between scheduled security assessments, leaving organizations with periods where new vulnerabilities can go undetected. Synack’s State of Continuous Security Validation report found that 95% of surveyed organizations identified high- or critic…HELPNETSECURITY.COM
22 JulAI can’t fix cybersecurity’s hiring problemOrganizations are redefining cybersecurity roles through workforce frameworks and placing greater emphasis on verified skills as AI and new regulatory requirements change hiring. The SANS 2026 Cybersecurity Workforce Survey found demand for specialists in new roles more than doub…HELPNETSECURITY.COM
22 JulSnowpick: Open-source ServiceNow exposure scannerAn employee opens a company service portal, searches the knowledge base, and drops a file onto a ticket. Someone who never signed in can send a request to that same portal and get records back. Bishop Fox ran that test across 166 ServiceNow instances during authorized penetration…HELPNETSECURITY.COM
22 Jul10 survival tips for CSOs who report to the CEOAs the CSO grows in prominence, security leaders are increasingly earning a seat at the executive table, reporting directly to the CEO with the expectation to help drive business strategy and ensure organizational success. Reporting to the CEO unlocks greater access and influence…CSOONLINE.COM
22 JulRisky Bulletin: Rogue OpenAI models were behind the Hugging Face breachRogue OpenAI models were behind last week’s Hugging Face breach, the Linux kernel discloses 442 vulnerabilities as the AI bugpocalypse settles in, France becomes the first EU country to pass a social media age limit, and Germany takes down the Kratos phishing service.RISKY.BIZ
22 JulPolice Dismantle Kratos Phishing Kit Built to Steal Microsoft 365 Sessions and Bypass MFAGerman and US law enforcement have taken down the core infrastructure of Kratos, described by German investigators as one of the world's most widely used criminal phishing kits, and Indonesian authorities arrested the man they say developed and ran it. In a joint announcement on …THEHACKERNEWS.COM
22 JulOpenAI Says Its AI Models Broke Loose and Hacked Hugging FaceThe admission comes days after Hugging Face disclosed an attack powered by autonomous AI agents. The post OpenAI Says Its AI Models Broke Loose and Hacked Hugging Face appeared first on SecurityWeek .SECURITYWEEK.COM
22 JulPolice dismantle Kratos phishing platform behind 15,000 monthly campaignsGerman and US law enforcement have dismantled the infrastructure behind Kratos, a notorious phishing-as-a-service (PhaaS) platform. Its alleged developer and administrator was arrested in Indonesia by local police. Seizure banner (Source: BKA) The takedown was led by the Frankfur…HELPNETSECURITY.COM
22 JulAI, security operations and the new race against timeWhen Anthropic unveiled Project Glasswing and the Mythos model, much of the discussion focused on the capabilities themselves. Security leaders debated what these systems could mean for vulnerability discovery, exploit development and the pace of offensive innovation. Researchers…CSOONLINE.COM
22 JulGoogle’s Gemini 3.5 Flash Cyber becomes a vulnerability hunterGoogle’s Gemini 3.5 Flash Cyber model finds, validates, and patches vulnerabilities before they can be exploited while helping mitigate broader misuse. It is part of a limited-access pilot program that will soon be available to governments and trusted partners through CodeMender,…HELPNETSECURITY.COM
22 JulEndpoint Security Firm Glow Launches With $180M in Funding at $1.2B ValuationUsing AI, the startup provides adaptive prevention through environment mapping, risk analysis, and automated policy enforcement. The post Endpoint Security Firm Glow Launches With $180M in Funding at $1.2B Valuation appeared first on SecurityWeek .SECURITYWEEK.COM
22 JulOpenAI AI models exploited zero-days to reach Hugging Face in benchmark testOpenAI confirmed its AI models exploited zero-days during internal testing, reaching Hugging Face servers in an unintended real-world cyberattack. OpenAI admitted on July 21 that its own AI models, including GPT-5.6 Sol and an unnamed pre-release system, were behind the cyberatta…SECURITYAFFAIRS.COM
22 JulUbuntu snap-confine Vulnerability Enables Local Root AccessNew Ubuntu snap-confine race condition lets local users escalate to root on default installsINFOSECURITY-MAGAZINE.COM
22 JulGoogle Makes CodeMender Available as Managed AI Security AgentCodeMender actively builds and runs exploits in customer-managed sandboxes to verify if vulnerabilities are truly exploitableINFOSECURITY-MAGAZINE.COM
22 JulChick-fil-A hit by credential stuffing attack exposing customer dataChick-fil-A has notified customers that attackers accessed some Chick-fil-A One loyalty accounts after launching a credential stuffing attack against the company's website and mobile application. The incident, which occurred in June, allowed unauthorized parties to view personal …CYBERINSIDER.COM
22 JulUS seizes over 1,000 domains used for illegal World Cup 2026 streamsThe US Department of Justice has seized more than 1,000 internet domains that streamed FIFA World Cup 2026 matches without a license. The domain seizure notice (Source: US Department of Justice) The seizures came in three waves over the course of the tournament. The first two rou…HELPNETSECURITY.COM
22 JulLookout identifies exploitable vulnerabilities in mobile appsLookout has announced the launch of the Lookout Mobile Software Exposure Center (MSEC). Integrated natively into the Lookout Mobile Endpoint Security platform, MSEC enables organizations to continuously detect, validate, prioritize, and remediate exploitable vulnerabilities acros…HELPNETSECURITY.COM
22 JulOpen AI Claims Its AI Models Went Rogue and Hacked Another CompanyHugging Face recently disclosed a security breach. OpenAI has now said that it was its AI models which broke containment and hacked Hugging Face themselvesINFOSECURITY-MAGAZINE.COM
22 Jul KEVCISA orders urgent action on actively exploited Langflow RCE flawThe Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday ordered U.S. government agencies to prioritize patching an actively exploited vulnerability in the Langflow visual framework for building AI agents. [...]BLEEPINGCOMPUTER.COM
22 JulThe Fastest Path to AI Adoption Runs Through SecuritySecurity leaders who build fast, visible paths to AI adoption are becoming the most valued partners in their organizations. AI governance done right gives security teams the visibility they need, employees the tools they want, and CISOs the strategic influence they have earned. A…THEHACKERNEWS.COM
22 JulOpenAI model escape puts enterprise AI defenses on noticeSome of OpenAI’s most powerful AI models teamed up to escape their sandbox and attack systems at Hugging Face in a cybersecurity evaluation gone wrong, the company has admitted. The models under test were modified to allow them to perform potentially harmful actions that producti…CSOONLINE.COM
22 JulVibe-Coded Apps Riddled With Exploitable Security FlawsAnalysis found 434 exploitable flaws in AI-generated apps, with denial-of-service, authorization and secrets exposure risks among the most common issues. The post Vibe-Coded Apps Riddled With Exploitable Security Flaws appeared first on SecurityWeek .SECURITYWEEK.COM
22 JulOpenAI Presence connects AI agents to enterprise data with built-in guardrailsOpenAI has introduced Presence, a product designed to help companies deploy AI agents that handle customer support and internal service requests across voice and chat. (Source: OpenAI) The company describes Presence as a deployment platform rather than a standalone model. “…HELPNETSECURITY.COM
22 JulAstelia extends reachability analysis with agentic AI for vulnerability managementAstelia has added agentic capabilities to its reachability analysis platform as organizations face shrinking exploit windows and the growing challenge of managing vulnerabilities. At the core of the platform is Astelia’s reachability analysis, which determines whether a vul…HELPNETSECURITY.COM
22 JulInfraTrust Knowledgebase Unlocks Critical Hardware Risk IntelligenceToday we’re excited to announce InfraTrust, a global hardware infrastructure security knowledgebase making mission critical infrastructure security data available faster, so you have it when you need it to defend your enterprise. InfraTrust is a searchable, continuously updated s…ECLYPSIUM.COM
22 JulAI Added a Third EmployeeAI isn't just another software tool. It's increasingly being treated like a worker that operates around the clock, helping companies automate tasks and improve productivity. That changes the incentives for employers. If AI can reliably handle part of the workload, businesses may …YOUTUBE.COM
22 JulOpenAI: Our models breached Hugging Face during a cyber capability testThe recent Hugging Face breach was the work of several OpenAI models, the AI research company claimed in a blog post. The breach Late last week, the company behind Hugging Face, a platform that enables users to share machine learning models and datasets, said some of its internal…HELPNETSECURITY.COM
22 JulThreat group claims credit for ransomware attack on Coca-Cola’s dairy unitThe attackers previously exploited vulnerabilities or used stolen credentials for initial access. CYBERSECURITYDIVE.COM
22 JulGreedy ransomware crews return for seconds after victims cough up first extortion paymentsConnor Jones reports: Authorities have long warned organizations not to pay ransoms, and fresh figures underline why: handing over the money doesn’t mean the crooks leave you alone. Proofpoint survey data suggests that 58 percent of affected UK organizations paid a ransom. …DATABREACHES.NET
22 JulCisco’s new AI model tells code reviewers where to look for vulnerabilitiesCisco has revealed a family of open-weight AI models called Antares that, it said, can help security teams isolate potentially vulnerable parts of a software repository before deeper investigation begins. Rather than detecting a specific CVE or generating a patch, these models se…CSOONLINE.COM
22 JulApple patches Hide My Email flaw after media reports and class-action lawsuitApple has fixed a vulnerability in its iCloud+ Hide My Email service that could expose users' real email addresses. The fix comes over a year after a security researcher privately reported the issue and only weeks after 404 Media publicly disclosed it. The company confirmed to 40…CYBERINSIDER.COM
22 JulThe AI has entered the chat.GPT escapes the sandbox and hacks Huggingface. SolarWinds patches multiple critical flaws. CISA orders patching of a critical Langflow AI vulnerability. A Paidwork breach affects over 23 million users. A recently patched SharePoint vulnerability is under active exploitation. Orac…THECYBERWIRE.COM
22 JulSouth Korea discloses data breach impacting diplomats worldwideSouth Korea disclosed that hackers breached the National Diplomatic Academy's online education system for ten months and stole personal information belonging to current and former employees of the Ministry of Foreign Affairs (MFA), including overseas diplomats. [...]BLEEPINGCOMPUTER.COM
22 JulFake Bahrain Alert App Deploys Android Surveillance MalwareA malicious application delivers four-stage Android spyware via phony Google Play sites, exploiting civilian fear during Iranian missile strikes.DARKREADING.COM
22 JulAre Schools Falling Behind AI?Rapid advances in AI are forcing organizations to rethink how people learn new skills. The question isn't only how employees adapt, but whether K–12 education, universities, and professional development can keep pace. Waiting until workforce shortages appear could mean reacting t…YOUTUBE.COM
22 JulUpbound says hack caused $13 million in fraudulent Acima leasesThe Upbound Group fintech company disclosed that threat actors who stole data from its systems leveraged it to create $13 million in Acima leases. [...]BLEEPINGCOMPUTER.COM
22 JulAttackers Are Learning to Live Off the AI ToolchainSandworm_Mode is an early example of malware that exploits trusted AI tools and workflows to make malicious activity virtually indistinguishable from normal activity.DARKREADING.COM
22 JulSmashing Security podcast #477: How 14 orders of chicken McNuggets helped nail a suspected Russian hackerA Russian intelligence-linked hacker is arrested in Thailand while enjoying a beach holiday - and the trail of evidence that nailed him to the Russian government includes 14 separate orders of chicken McNuggets. Meanwhile, AI music generator Suno has been hacked - and the stolen …GRAHAMCLULEY.COM
22 JulGerman law enforcement claims to have ‘dismantled’ mega phishing-as-a-service group KratosA global law enforcement crackdown has seized infrastructure serving the massive phishing-as-a-service (PhaaS) group Kratos, as well resulting in the arrest of an unnamed Kratos “developer and technical administrator” in Indonesia. The effort was managed by German law enforcement…CSOONLINE.COM
22 JulOpenAI Models Escaped Containment and Hacked Hugging FaceIt’s happened. The nightmare of the future is now in our present. Or was this just old-fashioned negligence? Lily Hay Newman and Dell Cameron report: OpenAI disclosed on Tuesday that it lost control of two AI models during a security test that ended in a breach of the open …DATABREACHES.NET
22 JulInstructure Incident Driving 58 Percent of Breach Notices in 2026GovTech reports: The mega breach is back in 2026, according to a new report from the Identity Theft Resource Center (ITRC). The nonprofit group, which works to prevent and reduce incidences of identify theft, found that 1,029 data compromises generated 471 million breach notices …DATABREACHES.NET
21 JulAI-generated reports push GNOME to shorten its disclosure windowVolunteer maintainers of open source projects now receive a steady flow of security vulnerability reports produced with AI tools. Many arrive with no mention that a language model helped write them. The volume has grown enough that GNOME is revising the rules it uses to track and…HELPNETSECURITY.COM
21 Jul177: National Public DataThis is the story of the hacker known as "USDoD". When he was young he had a vengeance on the US, and this lead him down a road of continual data breaches, until he hacked into National Public Data, which is when his spree went one step too far. Sponsors Support for this show com…DARKNETDIARIES.COM
21 JulContext bombing heralds a new AI era of deceptive defenseAttackers are increasingly using AI agents to automate all phases of cyberattacks , prompting the security industry and enterprises to find new network defense approaches. One technique that shows promise is to intentionally plant decoy files with prompts that trigger the content…CSOONLINE.COM
21 JulNew ENCFORGE Ransomware Targets AI Model Files in Langflow RCE AttackResearchers at Sysdig have linked a second attack on the same Langflow server to JADEPUFFER, the AI-agent-driven operator it first documented earlier this month. The same operator has now been spotted deploying ENCFORGE, a new compiled Go ransomware designed to encrypt model weig…THEHACKERNEWS.COM
21 JulWindows LegacyHive zero-day flaw gets free, unofficial patchesFree unofficial patches are available for a recently disclosed Windows zero-day flaw that allows attackers to escalate privileges on up-to-date Windows systems. [...]BLEEPINGCOMPUTER.COM
21 JulWeekly Update 513: Clauding The Home NetworkPresently sponsored by: CoreView: Misconfigurations in Microsoft 365 leave doors open. Scan your tenant for free?. I reckon this week's video on how Claude is tying together info from UniFi, Home Assistant and the Pi-Hole is an absolute ripper. Or at least the concept is - i…TROYHUNT.COM
21 JulEstée Lauder discloses data breach tied to Oracle EBS vulnerabilityCosmetics company Estée Lauder disclosed a data breach tied to a vulnerability in Oracle E-Business Suite (EBS) used for the company’s human resources operations. Estée Lauder is one of the largest beauty companies in the world, known for its prestige skincare, makeup, frag…HELPNETSECURITY.COM
21 JulOpen-source maintainers still work underfunded as sponsorship crosses $100 millionA maintainer patches a library late at night that ships inside thousands of products, and no invoice follows. Sebastián Ramírez and Caleb Porzio spent years in that position. Ramírez, known as tiangolo, builds tools that other Python projects depend on. Porzio built Livewire and …HELPNETSECURITY.COM
21 JulUS Hospital Finance Software Provider Craneware Reports Data TheftCraneware, a provider of financial software for US healthcare organizations, has disclosed a cyber incident involving unauthorized access and data theftINFOSECURITY-MAGAZINE.COM
21 JulThe Triumphs and Failures of France's Foreign Intel ServiceThe DGSE, or Directorate General for External Security, is France's foreign intelligence service. It's found inside the Ministry of Defense but reports to the president. It was established under that name in 1982, learning the hard way, through a string of high-profile blunders, …THECYBERWIRE.COM
21 JulCritical Palo Alto VPN bug now exploited by Qilin ransomware gangThe Qilin ransomware gang is exploiting a critical PAN-OS GlobalProtect authentication bypass flaw to breach victims' networks, according to cybersecurity company Arctic Wolf. [...]BLEEPINGCOMPUTER.COM
21 JulMeta Paid $78,000 Bounty for Vulnerability Exposing Customer Support DataA security researcher discovered a broken access control vulnerability in Meta’s support infrastructure. The post Meta Paid $78,000 Bounty for Vulnerability Exposing Customer Support Data appeared first on SecurityWeek .SECURITYWEEK.COM
21 JulAI agents can escape sandboxes without ever breaking themSandboxes have become a key security control for AI coding agents, but new research suggests they may not provide the isolation many organizations assume. Pillar Security has disclosed a series of vulnerabilities showing how agents in tools such as Cursor, Codex, Gemini CLI, and …CSOONLINE.COM
21 JulEstée Lauder Discloses Impact From Oracle EBS Zero-Day HackHackers exfiltrated personal, financial, and health information from the company’s Oracle EBS instance in August 2025. The post Estée Lauder Discloses Impact From Oracle EBS Zero-Day Hack appeared first on SecurityWeek .SECURITYWEEK.COM
21 JulOpen-Source Android AI Agents Could Let Invisible Screen Text Run Code on Host PCsAn Android app that can draw over other windows and write to shared storage can slip instructions to the AI agent driving that phone, in text no human eye will ever see. Two more steps, and the same app is running commands on the PC driving the agent. Researchers demonstrated tha…THEHACKERNEWS.COM
21 JulN-day is Becoming N-Hour. Patching Faster Won't Save You.Every patch is a confession. The moment a vendor ships a security fix, the diff between the old code and the new code tells anyone watching exactly what was broken and where. Turn that diff back into a working exploit, and you can hit every system that hasn't updated yet. This is…THEHACKERNEWS.COM
21 JulNew Bit2Watt Attack Could Let Cloud Tenants Disrupt Power Grids Without an ExploitA cloud tenant using nothing but ordinary GPU access can push a data center's power draw up and down fast enough to threaten the grid it runs on, with no exploit and no break-in. That is the claim behind Bit2Watt, described by three Zhejiang University researchers in a paper acce…THEHACKERNEWS.COM
21 JulYour AI agent’s config is now the payload: How attackers are targeting the developer agent harnessAttackers have shifted from hiding from AI tools to running inside them. By poisoning the config files that govern AI coding assistants, a new worm class achieves silent persistence, evades AI-based scanners, and spreads across an organization's repositories through developers' o…TENABLE.COM
21 JulCisco’s open-weight Antares models make vulnerability localization cheaperA security analyst opens an unfamiliar repository, pulls up a vulnerability advisory, and starts hunting for the file where the weakness lives. The naming conventions belong to someone else. Evidence sits in scattered corners of a codebase that runs to thousands of files. That fi…HELPNETSECURITY.COM
21 JulPersonal data of all South Korean diplomats believed leaked in ‘unprecedented’ cyberattackSeo Ji-Eun reports: The personal information of nearly all of South Korea’s diplomatic personnel is presumed to have been compromised in what the Foreign Ministry on Tuesday called an “unprecedented” cyberattack, exposing up to 10,000 administrative and intellig…DATABREACHES.NET
21 JulNYSDFS Secures $50 Million Penalty from Swedbank for Withholding Information from InvestigatorsOne of the biggest breaches of 2016 was the Panama Papers leak. The law firm at the heart of it, Mossack Fonseca, closed its doors in 2018, unable to recover from all the damage. But while the law firm folded, investigations continued. The New York Department of Financial Service…DATABREACHES.NET
21 JulSuno Data Breach had a breach in 2025. Why is it first being known now?Millions here, tens of millions there. Are we all getting breach fatigue by now? Over on HaveIBeenPwned, Troy Hunt reports that Suno experienced a data breach in November 2025, which 404 Media first made public this month: In November 2025, AI music generation tool Suno suffered …DATABREACHES.NET
21 JulSeoul Notifies 4.62 Million of Ttareungyi Data Breach, Offers Free PassesKim Eun-bi reports: The Seoul Metropolitan Government will send individual text messages to about 4.62 million citizens affected by a data breach involving membership information for Ttareungyi, the city’s public bike-sharing service, notifying them of the leaked items and …DATABREACHES.NET
21 JulTaiwan to slow mobile data during national resilience drillsThe speed of 5G and 4G networks across much of Taiwan will be temporarily reduced to 1 percent of capacity as the island holds annual civilian and military drills.THERECORD.MEDIA
21 JulZimbra Patches Critical SNMP Command Injection and Four XSS VulnerabilitiesZimbra has rolled out fixes to address multiple critical security issues, including a command injection flaw in the Simple Network Management Protocol (SNMP) monitoring component. As many as nine security vulnerabilities have been patched in Zimbra 10.1.20. Topping the list is a …THEHACKERNEWS.COM
21 JulMacOS Security Design Features, Flaws, And Futures - Patrick Wardle - ASW #392Appsec often frames usability and security as at odds with each other. Apple's software has famously emphasized the importance of usability while also creating a solid security foundation. Patrick Wardle talks about how he's seen malware shift from Windows to macOS, how Apple's a…YOUTUBE.COM
21 JulAI agents tricked into recommending malicious GitHub repositoriesRoughly 7,600 malicious GitHub repositories were uncovered, more than 800 of them posing as AI Skills or Model Context Protocol (MCP) servers, in a wave that peaked in April 2026, according to Island. The scale of the FakeGit operation (Source: Island) The fake repositories are t…HELPNETSECURITY.COM
21 JulWhat happens if you visit a WordPress site hacked through wp2shell?Attackers started exploiting the critical wp2shell vulnerability chain within hours of patches being released, putting sites and their visitors at risk.MALWAREBYTES.COM
21 JulAWS Kiro Flaw Let a Poisoned Web Page Rewrite Its Config and Run CodeHidden text on a web page was enough to make Kiro, AWS's agentic coding IDE, rewrite its own configuration file and run an attacker's code on a developer's machine, with no approval step able to stop it. Intezer, in research with Kodem Security, found that a request as ordinary a…THEHACKERNEWS.COM
21 JulMicrosoft SharePoint under attack via new exploitSecurity researchers warn the potential risk could rival the widespread ToolShell campaign of 2025.CYBERSECURITYDIVE.COM
21 JulCisco Launches Low-Cost AI Models for Source Code SecurityThe open-weight Antares models are designed to pinpoint known vulnerabilities in codebases faster and at a fraction of the cost of larger AI models. The post Cisco Launches Low-Cost AI Models for Source Code Security appeared first on SecurityWeek .SECURITYWEEK.COM
21 JulZimbra 10.1.20 patches multiple security issues, including a critical command injection bugZimbra patched nine flaws in version 10.1.20, including a critical SNMP monitoring command injection issue enabling arbitrary command execution. Zimbra released version 10.1.20 to fix nine security vulnerabilities, including a critical command injection flaw in the SNMP monitorin…SECURITYAFFAIRS.COM
21 JulCyberattack against Maine telecom disrupted municipal internet service in 23 townsColin Wood reports: At least one municipal government was among those to see their internet service disrupted after a cyberattack against a Maine telecommunications firm Sunday caused an outage affecting 23 towns along the state’s midcoastal region. A local NBC affiliate reported…DATABREACHES.NET
21 JulLegacyHive, ACR Stealer, Hugging Face, Route 53, and Kieran Human from Threatlocker - SWN #600Nudification, Yeats, LegacyHive, ACR Stealer, Hugging Face, Route 53, 764, Wordpress, Kieran Human from Threatlocker, and More. Segment Resources: Malicious Edge extension abuses Native Messaging as bridge to malware: https://www.bleepingcomputer.com/news/security/malicious-edge-…YOUTUBE.COM
21 JulOracle July 2026 Critical Patch Update Addresses 1235 CVEsOracle addresses 1235 CVEs in its third quarterly update of 2026 with 1449 patches, including 261 critical updates. Key Takeaways The third Critical Patch Update (CPU) for 2026 contains fixes for 1235 unique CVEs in 1449 security updates, the largest CPU release. 261 issues (18% …TENABLE.COM
21 JulOpenAI Models Escaped Containment and Hacked HuggingFaceThe cybersecurity-focused models, including GPT-5.6 Sol, broke out of a testing sandbox, exploited a zero-day, and gained access to the open internet to pull off the attack.WIRED.COM
21 JulPay up or not? Ransomware surge has victims facing tough choices.Hannah Murphy reports: Nearly half of companies that are targets of a ransomware cyber attack end up paying a ransom to release their data or systems, according to 2025 research from cybersecurity group Sophos, while the median amount demanded is rising. Globally, some jurisdicti…DATABREACHES.NET
21 JulSN 1088: A Nefarious Novel Use for AI - Ransomware Negotiations Go High-TechCybercriminals are harnessing AI not to break in, but to make sense of their stolen loot and increase their leverage in multi-million dollar ransomware heists. This episode unpacks how AI is now turbocharging extortion and negotiations on the dark side. The "bone crushing" didn't…TWIT.TV
20 JulWordpress RCE, New Windows 0-day and Coca-Cola's Fairline ransomedNew Windows zero-day, Coca-Cola's Fairlife hit by ransomware, and a core WordPress RCE David Shipley covers a new Windows zero-day disclosure from "Nightmare Eclipse" called LegacyHive, a local privilege escalation flaw in the Windows User Profile Service that could be weaponized…CYBERSECURITYTODAY.LIBSYN.COM
20 JulNearly half of open-source AI projects never reach productionOpen models are moving into production across more organizations, and the work of securing those deployments increasingly extends beyond the model weights. Mozilla’s The State of Open Source AI 2026 identifies deployment, governance and operational tooling as persistent obstacles…HELPNETSECURITY.COM
20 JulWorld's Largest AI Model Repository Hugging Face Breached by Autonomous AI AgentIn an ironic twist, open-source artificial intelligence (AI) platform Hugging Face revealed that it was the victim of a hack perpetrated by an autonomous AI agent system. The company said it detected and responded to the incident targeting its production infrastructure earlier la…THEHACKERNEWS.COM
20 JulMeet Dusseldorf, Microsoft’s open-source out-of-band security platformOut-of-band vulnerabilities surface when an application quietly reaches out to an external system during an attack, and capturing that traffic calls for infrastructure that many researchers assemble on their own. A new open-source project from Microsoft supplies that infrastructu…HELPNETSECURITY.COM
20 JulRisky Bulletin: Hacker wipes Romania's entire land registry databaseA hacker wipes Romania’s entire land registry database, Magnet Forensics sues a former employee for leaking an iPhone exploit, an autonomous AI agent hacked Hugging Face, and an unauthenticated remote code execution bug was finally found in WordPress.RISKY.BIZ
20 JulSOCs face a human challenge as AI speeds alerts and threatsSecurity operations centers (SOCs) have spent years struggling under the weight of growing alert volumes, expanding attack surfaces, and chronic staffing shortages. Now artificial intelligence is adding a new complication: not just more information, but more machine-generated inf…CSOONLINE.COM
20 Jul KEVClaude Mythos FAQ: Capabilities, access, competitors, implications1. What is Claude Mythos? Claude Mythos is an advanced AI model developed by Anthropic and is optimized for cybersecurity and healthcare applications. Mythos 5 was originally released in April to a small group of vetted technology partners ahead of a planned wider rollout. Anthro…CSOONLINE.COM
20 JulHow agentic endpoint security shuts down IDE-based supply chain attacksAttention shifts from EDR to Agentic Endpoint Security to close visibility gaps that AI can exploit.CYBERSECURITYDIVE.COM
20 JulChrome 150 Update Patches Severe Memory Safety BugsThe fresh security update resolves six critical and high-severity use-after-free vulnerabilities. The post Chrome 150 Update Patches Severe Memory Safety Bugs appeared first on SecurityWeek .SECURITYWEEK.COM
20 JulThe Windows 10 hangover is becoming a security problemWindows 11 now runs on 78.8% of Windows devices after Microsoft ended support for Windows 10 on 14 October 2025, according to Lansweeper. Windows 10 still accounts for 16.9% of devices and no longer receives security updates, leaving newly discovered vulnerabilities unpatched. “T…HELPNETSECURITY.COM
20 JulAI Agents Turned Into Attackers: Hugging Face Reveals Autonomous Intrusion CampaignHugging Face says an autonomous AI agent breached part of its production infrastructure and accessed internal data and service credentials. Hugging Face is one of the world’s leading open-source AI companies. It provides a platform where developers and organizations can bui…SECURITYAFFAIRS.COM
20 JulVolexity Uncovers Zero-Day Campaign Targeting SonicWall VPN AppliancesUnknown hackers exploited two SonicWall SMA 1000 zero-days to gain root access on VPN appliances before patches became available. Volexity published its findings after conducting an incident response investigation involving a compromised organization whose SonicWall SMA 1000 seri…SECURITYAFFAIRS.COM
20 JulRussian-Speaking Hacker Uses Google Gemini CLI to Control Botnet of Eight Dental Clinic PCsA solo Russian-speaking threat actor known as "bandcampro" outsourced a chunk of their operations to Google's open-source Gemini CLI artificial intelligence (AI) and commandeered a live botnet. The findings come from an analysis of 200 Gemini CLI session logs between March 19 and…THEHACKERNEWS.COM
20 JulAI Security at Scale, CMMC phase II paused, and the Weekly Enterprise News - ESW #468Interview with Keith Hollender, CEO and Co-Founder of Arcova Why AI Security Is Becoming an Execution Problem, Not Just a Governance Problem As enterprises move from AI experimentation to adoption at scale, security leaders are under pressure to enable innovation without introduc…YOUTUBE.COM
20 JulEstée Lauder discloses data breach tied to Oracle E-Business Suite attacksThe Estée Lauder Companies is notifying current and former employees that their personal information was stolen after attackers compromised the company's Oracle E-Business Suite (EBS) human resources environment in August 2025. The intrusion is linked to the wider Oracle EBS expl…CYBERINSIDER.COM
20 JulCapital One Open Sources AI-Powered ‘VulnHunter’ Security ToolThe agentic security tool identifies potentially exploitable code flaws, traces attack paths, and recommends targeted remediations. The post Capital One Open Sources AI-Powered ‘VulnHunter’ Security Tool appeared first on SecurityWeek .SECURITYWEEK.COM
20 JulHugging Face breached by autonomous AI agentHugging Face, the widely used platform for sharing open-source machine learning models and datasets, has disclosed a security breach it says was carried out by an autonomous AI agent system. How the attack unfolded In a blog post published Thursday (July 16), the company said tha…HELPNETSECURITY.COM
20 JulNew ACR Stealer campaigns use WebDAV, MSHTA to evade detectionMicrosoft has issued a warning about a recent surge in ACR Stealer activity that uses ClickFix-style social engineering to steal credentials, browser data, and sensitive business documents. In a new report, Microsoft researchers detailed two separate campaigns observed between la…CSOONLINE.COM
20 JulHugging Face discloses breach linked to autonomous AI agentThe Hugging Face artificial intelligence repository disclosed that attackers gained access to internal datasets and credentials after breaching its production infrastructure using an autonomous AI agent system. [...]BLEEPINGCOMPUTER.COM
20 JulNew Index Tracks Material Breaches — And Refuses to Add Up the LossesLongtime cybersecurity executive Richard Bird built the resource for security experts, journalists, policymakers, and everyday citizens. The post New Index Tracks Material Breaches — And Refuses to Add Up the Losses appeared first on SecurityWeek .SECURITYWEEK.COM
20 JulCritical 7-Zip Flaw Allows Code Execution by Opening Crafted XZ-Compressed Files. Update it now!7-Zip fixed a vulnerability that could let attackers run code by tricking users into opening malicious XZ-compressed archive files. 7-Zip released version 26.02 to address a remote code execution vulnerability in its handling of XZ-compressed data. The flaw, discovered by researc…SECURITYAFFAIRS.COM
20 JulPatch now: WordPress REST API bug allows remote code executionOrganizations running recent versions of WordPress are being asked to patch a newly detailed pre-authentication remote code execution (RCE) vulnerability affecting the platform’s built-in REST Batch API. The flaw, dubbed wp2shell, enables attackers to execute arbitrary code again…CSOONLINE.COM
20 Jul20th July – Threat Intelligence ReportFor the latest discoveries in cyber research for the week of 20th July, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Ernst & Young, a global accounting and professional services company, has disclosed a data breach involving a compromised third-p…RESEARCH.CHECKPOINT.COM
20 JulOpenSSL Silently Fixes ‘HollowByte’ DoS VulnerabilityAttackers could send waves of malicious payloads to trigger buffer pre-allocations that are not freed, exhausting server memory. The post OpenSSL Silently Fixes ‘HollowByte’ DoS Vulnerability appeared first on SecurityWeek .SECURITYWEEK.COM
20 JulBroken Promises of Anonymity: Four Months Later, Still No Transparency. Now We’re Seeking Accountability.On March 18, 2026, Navigate360 learned that 8.3 million anonymous tips had been exposed. The company’s response—and the silence of the programs that depend on its platform—has persisted for months. We’re now seeking accountability through state and federal regulators.…DATABREACHES.NET
20 Jul⚡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and MoreA single request should not be able to do this much. But this week, small inputs led to code execution, memory loss, stolen keys, and disabled security tools. The paths were often simple: exposed systems, weak checks, old drivers, fake prompts, and public code used for malware de…THEHACKERNEWS.COM
20 JulResearchers Build WordPress Exploit Using OpenAI's GPTA researcher who discovered a critical vulnerability in WordPress has used OpenAI’s latest model to develop an exploit chainINFOSECURITY-MAGAZINE.COM
20 JulItaly fines WINDTRE €1.7 million over security flaws behind two data breachesItaly’s data protection authority, the Garante per la Protezione dei Dati Personali, fined WINDTRE €1.7 million over “serious data security shortcomings” that let hackers breach its systems twice and exfiltrate personal data belonging to more than 365,000 custom…HELPNETSECURITY.COM
20 JulAI adoption and business acceleration are changing the expectations of technology risk managementAs AI becomes embedded in customer experiences, internal workflows, and throughout the supply chain, security leaders are being asked to do more than manage risk. They are being asked to help the business make more informed decisions and move faster. At the same time, AI has evol…CSOONLINE.COM
20 JulHackers are exploiting recently patched WordPress bugs, putting millions of websites at riskTwo critical security flaws in WordPress’ software have given hackers the chance to remotely take over tens of millions of websites, according to an estimate by a cybersecurity researcher.TECHCRUNCH.COM
20 JulResearchers trace SonicWall SMA1000 exploitation to late JuneMultiple threat actors, including INC ransomware, have targeted vulnerable firewall systems.CYBERSECURITYDIVE.COM
20 JulAI helped uncover WordPress ‘wp2shell’ RCE now exploited in attacksThe critical WordPress vulnerability chain known as “wp2shell” was discovered with substantial assistance from an AI model, which identified both the initial pre-authentication SQL injection and a complex path to remote code execution. Patchstack now says attackers are actively e…CYBERINSIDER.COM
20 JulMillions of Shark robot vacuums vulnerable to remote code executionMillions of internet-connected Shark robot vacuums may be vulnerable to a critical remote code execution (RCE) flaw that could allow attackers to take over devices, access onboard cameras, and retrieve sensitive data stored on the robots. Independent security researcher ‘to…CYBERINSIDER.COM
20 JulDirector of Commerce AI standards office out after three monthsThe Center for AI Standards and Innovation has quietly become a key hub for the federal government to assess potential threats and harms that AI systems pose. The post Director of Commerce AI standards office out after three months appeared first on CyberScoop .CYBERSCOOP.COM
20 JulMore AI Bugs, Less Security?AI is exceptionally good at identifying code patterns that lead to crashes and other common programming mistakes. That capability can dramatically increase the number of reported bugs. Finding more bugs doesn't necessarily reduce real-world cyber risk. If the proportion of high-i…YOUTUBE.COM
20 JulBehind the friendly face.Hugging Face reports an autonomous AI-powered breach. Ernst & Young discloses a client data breach. Attackers are actively exploiting a critical ServiceNow flaw. Ransomware gangs sharpen their tactics against law firms. Capital One open-sources an AI security tool. Text salting f…THECYBERWIRE.COM
20 JulEstée Lauder discloses data breach via Oracle E-Business flawCosmetics giant Estée Lauder is notifying customers of a data breach after hackers exploited a flaw in Oracle E-Business Suite that the company used for human resources (HR) operations. [...]BLEEPINGCOMPUTER.COM
20 JulSonicWall SMA1000 flaws exploited as zero-days to push custom malwareTwo recently disclosed SonicWall SMA1000 vulnerabilities were exploited in zero-day attacks for weeks, allowing threat actors to install custom malware on vulnerable VPN appliances. [...]BLEEPINGCOMPUTER.COM
19 JulWeek in review: High severity WordPress vulnerabilities, fake OAuth IDs bypass sign-in logsHere’s an overview of some of last week’s most interesting news, articles, interviews and videos: Two new high severity WordPress vulnerabilities, patch immediately! The 7.0.2 WordPress security release addresses one critical and one high severity security issue. Cynative: Open-s…HELPNETSECURITY.COM
19 JulSonicWall SMA Zero-Days Exploited Before Disclosure to Gain Root AccessA previously undocumented threat actor has been attributed to the exploitation of recently disclosed SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances as zero-days prior their public disclosure since June 22, 2026. Cybersecurity company Volexity is tracking the acti…THEHACKERNEWS.COM
19 JulMedical giant Abbott investigates two cyber incidents as ShinyHunters and ShadowByt3$ both claim breachesAnna Zhadan reports: American healthcare giant Abbott Laboratories is investigating two cyber incidents that appear to be unrelated: one involving its Cancer Diagnostics business and another affecting its LabCentral portal. Although unrelated, the two disclosures came within days…DATABREACHES.NET
18 JulOpenSSL HollowByte Flaw Could Freeze Server Memory with 11-Byte TLS RequestsEleven bytes will make an unpatched OpenSSL server set aside up to 131 KB of memory for a message that never arrives. On the glibc systems Okta tested, that memory is gone until the process restarts. OpenSSL shipped the HollowByte fix in June with no CVE, no advisory, and no chan…THEHACKERNEWS.COM
18 JulNew wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run CodeAn anonymous HTTP request can run code on a WordPress site. The bug is in core, so a bare install with zero plugins is exploitable. Every 6.9 and 7.0 site was in range until Friday, when WordPress shipped 6.9.5 and 7.0.2 and enabled what it calls forced updates through its auto-u…THEHACKERNEWS.COM
18 JulAI Is Supercharging Cyberattacks | Cybersecurity Today On The Weekend | July 18, 2026Artificial intelligence is changing cybersecurity on both sides of the battle. While defenders are adopting AI to improve detection and response, attackers are using it to discover vulnerabilities, automate exploitation, and dramatically accelerate the pace of attacks. In this ep…CYBERSECURITYTODAY.LIBSYN.COM
18 JulWordPress releases emergency update for critical ‘wp2shell’ RCE flawThe WordPress project has released emergency security updates to fix a critical vulnerability chain dubbed wp2shell, that can allow unauthenticated attackers to achieve remote code execution (RCE) on vulnerable websites. The flaws affect WordPress 6.9 through 7.0.1 and have alrea…CYBERINSIDER.COM
18 JulNY Attorney General James Secures $18 Million From 23andMe for Failing to Protect Customers’ Genetic DataThere’s another update in the litigation involving 23andMe, below, but this won’t be the last update, as California’s Attorney General has also recently sued them under California’s privacy laws. New York Attorney General Letitia James and a bipartisan coa…DATABREACHES.NET
18 JulWordPress Core "wp2shell" RCE flaws get public exploits, patch nowPublic exploits have been released for the critical "wp2shell" remote code execution vulnerabilities affecting WordPress Core, making it imperative that administrators patch their sites immediately. [...]BLEEPINGCOMPUTER.COM
18 JulUpdate now: 7-Zip fixes RCE flaw exploitable with malicious archives7-Zip version 26.02 was released to fix a remote code execution vulnerability that could allow attackers to execute malicious code by convincing users to open specially crafted compressed files. [...]BLEEPINGCOMPUTER.COM
18 JulOpenSSL Fixes HollowByte Memory Exhaustion BugOkta disclosed HollowByte, an 11-byte OpenSSL flaw that lets remote attackers exhaust server memory and trigger denial-of-service attacks. Okta’s Red Team disclosed a denial-of-service vulnerability in OpenSSL they named HollowByte, and the attack payload is exactly 11 byte…SECURITYAFFAIRS.COM
17 JulScattered Spiders sentenced, OpenAI builds an AI that breaks AIs, and Iran leans on ChatGPTTwo leading Scattered Spider members, Thaila Jubar and Owen Flowers, were sentenced to five years and six months for the 2024 Transport for London hack that knocked 148 systems offline, forced 27,000 password resets, stole customer data, and cost TfL £29 million, with wider losse…CYBERSECURITYTODAY.LIBSYN.COM
17 Jul KEVCISA urges immediate action on actively exploited Fortinet flawsCISA on Thursday ordered government agencies to prioritize patching two actively exploited vulnerabilities in the Fortinet FortiSandbox threat detection platform. [...]BLEEPINGCOMPUTER.COM
17 JulFresh SharePoint Vulnerability Exploited Soon After DisclosureThe critical-severity security defect allows remote, authenticated attackers to execute arbitrary code on the server. The post Fresh SharePoint Vulnerability Exploited Soon After Disclosure appeared first on SecurityWeek .SECURITYWEEK.COM
17 JulThe SaaS blind spot: Why security teams can’t get inside their own appsMost organizations I work with have invested heavily in cloud security. They have endpoint detection tools, SIEM platforms, cloud security posture management, and skilled security teams running on a 24/7 shift. And yet, when I ask them a simple question — who has admin access in …CSOONLINE.COM
17 JulFake TTF files deliver stealthy malware in global phishing campaignThreat actors are now abusing an ordinary font file to deliver low-detection malware capable of stealing credentials and establishing persistence on compromised Windows systems. According to a new research from Fortinet’s FortiGuard Labs, a global phishing campaign is actively us…CSOONLINE.COM
17 JulRansomware attack halts Coca-Cola’s Fairlife US milk productionA ransomware attack has stopped milk production at Fairlife, the Coca-Cola dairy brand known for its high-protein milk, protein shakes, and nutrition drinks. Coca-Cola disclosed the incident on July 16, 2026, in a Form 8-K filed with the U.S. Securities and Exchange Commission (S…HELPNETSECURITY.COM
17 Jul KEVCISA Mandates Urgent Patch for Actively Exploited Critical Fortinet VulnerabilitiesUS government agencies have until July 19 to patch two critical Fortinet vulnerabilitiesINFOSECURITY-MAGAZINE.COM
17 JulThree Steps to the Terminal: A Siemens ROX II Zero-Day TrilogyA technical analysis of three chained zero-day vulnerabilities in Siemens ROX II OT switches that allow privilege escalation and persistent root access. The post Three Steps to the Terminal: A Siemens ROX II Zero-Day Trilogy appeared first on Unit 42 .UNIT42.PALOALTONETWORKS.COM
17 JulCoca-Cola discloses ransomware attack disrupting fairlife production in the USThe Coca-Cola Company has disclosed that a ransomware attack affecting its wholly owned dairy subsidiary, fairlife, has temporarily halted fairlife's US production operations after attackers gained unauthorized access to part of its network, including production-related systems. …CYBERINSIDER.COM
17 JulNew Windows LegacyHive zero-day gives hackers admin privilegesA security researcher using the "Nightmare Eclipse" handle has released a Windows zero-day exploit dubbed LegacyHive that allows attackers to escalate privileges on up-to-date Windows systems. [...]BLEEPINGCOMPUTER.COM
17 JulThe Race to Field Military Autonomy Is On, Can Trusted Information Infrastructure Keep Pace?Military forces are under increasing pressure to field autonomous capabilities faster than ever before. Across the U.S., UK, and NATO, new investment, evolving defense strategies, and accelerated acquisition pathways are transforming how capability is delivered, rewarding program…THEHACKERNEWS.COM
17 JulGold Eagle Clearinghouse Targets Security Gap, But How Is UnclearThe White House launched Gold Eagle to coordinate vulnerability response in a new AI world, but multiple questions linger over how it's being implemented.DARKREADING.COM
17 JulItaly fines Wind Tre $2 million for data breaches affecting 365k customersItaly's data protection authority (Garante per la Protezione dei Dati Personali) has fined telecommunications provider Wind Tre €1.715 million (approximately $2 million) after finding serious security shortcomings that led to two data breaches affecting more than 365,000 customer…CYBERINSIDER.COM
17 JulIn Other News: Iran Tracks US Military Phones, CrashStealer macOS Malware, CVD BlueprintNoteworthy stories that might have slipped under the radar: OpenClaw AI agents exploited via WhatsApp, ransomware hits naval defense firm TKMS, Lidl discloses data breach. The post In Other News: Iran Tracks US Military Phones, CrashStealer macOS Malware, CVD Blueprint appeared f…SECURITYWEEK.COM
17 JulNightmare Eclipse drops another Windows zero-day.The Gentlemen topped the ransomware leaderboard in Q2 2026. Ransomware attack disrupts Fairlife dairy production.THECYBERWIRE.COM
17 JulRansomware attack forces Coca-Cola to suspend US production at dairy unitThe beverage company is still working to determine the full scope of the breach at its Fairlife business.CYBERSECURITYDIVE.COM
17 JulOnlyFans performers become unlikely allies of CISOs in securing websitesCISOs at government organizations and universities have an unexpected ally coming to their aid: OnlyFans models. For some time, hackers have exploited weaknesses in the websites of universities or government departments to host scams or malware, using content stolen from the Only…CSOONLINE.COM
17 JulHollowByte DDoS flaw bloats OpenSSL server memory with 11-byte payloadA vulnerability dubbed HollowByte allows unauthenticated attackers to trigger a denial-of-service (DoS) condition on OpenSSL servers with a malicious payload of just 11 bytes. [...]BLEEPINGCOMPUTER.COM
17 JulFBI arrests man accused of using Steam games to drain victims’ crypto walletsLorenzo Franceschi-Bicchierai reports: U.S. prosecutors have accused a Florida man of uploading fake video games that contained malware to Steam, the popular PC games platform. Once victims downloaded and installed the games, the malware was designed to infect their computers, st…DATABREACHES.NET
17 JulUS Military Smartphones Targeted Through Roaming and Ad TechSenior research fellow Gary Miller spoke to Financial Times about attempts to exploit mobile network vulnerabilities to track US personnel during the Iran war. The post US Military Smartphones Targeted Through Roaming and Ad Tech appeared first on The Citizen Lab .CITIZENLAB.CA
17 JulMetasploit Wrap Up: An HTTP to SMB relay plus Payload ImprovementsMetasploit Wrap Up Housekeeping While the Metasploit Framework will be continuing its weekly release cadence, bringing you dear reader our latest content, the Weekly Wrap Up is being shifted to a bi-weekly cadence. The team is planning to use the additional time between posts to …RAPID7.COM
17 JulA nightmare on Windows street.Nightmare Eclipse drops another Windows zero-day. The Gentlemen take the ransomware crown. CISA orders emergency Fortinet patching. Canada’s surveillance bill faces U.S. scrutiny. Meta’s Oversight Board flags AI censorship bias. Commerce tops the cyber target list. An active espi…THECYBERWIRE.COM
17 JulInc Ransomware Exploits SonicWall SMA Zero-DaysWhen chained together, the two vulnerabilities allow threat actors to gain root-level capabilities on SonicWall's mobile access appliances.DARKREADING.COM
17 JulProxying to Compromise: SonicWall Secure Mobile Access 0-day ExploitationIn early July 2026, Volexity was engaged to perform an incident response investigation where it discovered a threat actor had successfully compromised SonicWall Secure Mobile Access (SMA) VPN appliances through […] The post Proxying to Compromise: SonicWall Secure Mobile Ac…VOLEXITY.COM
17 JulErnst & Young (EY) Investigates Data Breach Involving Third-Party Support TicketsErnst & Young (EY) disclosed a data breach after attackers compromised a third-party IT support system containing client documents and tax information. Ernst & Young (EY) is disclosed a data breach linked to a compromised third-party support ticket system used by its IT t…SECURITYAFFAIRS.COM
16 JulTuxBot v3 Evolution Shows Signs of LLM-Assisted IoT Botnet DevelopmentCybersecurity researchers have disclosed details of a previously unreported Internet-of-Things (IoT) botnet framework dubbed TuxBot v3 Evolution that shows signs of being developed with assistance from a large language model (LLM), albeit with not so successful results. "While th…THEHACKERNEWS.COM
16 JulGPT-Red beat human red teamers on a prompt injection testGPT-Red is an automated red-teaming model that OpenAI trains to find prompt injection weaknesses. It works the way a human red-teamer does. It sends a prompt, watches how a GPT model responds, and iterates toward a goal such as a successful data exfiltration. Training runs on sel…HELPNETSECURITY.COM
16 JulFinance phishing works because it sounds boringly normalFinance departments process a constant stream of invoices, contracts, payment notices, and procurement emails, making email one of the most common initial access vectors for threat actors. According to Cofense, attackers exploit those workflows with phishing emails that resemble …HELPNETSECURITY.COM
16 JulCaught on ScamTokThis week, while Maria is out hosts Dave Bittner and Joe Carrigan are discussing the latest in social engineering…THECYBERWIRE.COM
16 JulCompanies keep getting breached by vulnerabilities they already knew aboutScanning tools have gotten good at their work. Organizations now find more weaknesses across more of their systems than at any earlier point in the industry’s history. A survey from the security firm Vicarius points to a gap that opens after that discovery, in the work of a…HELPNETSECURITY.COM
16 JulReading between the lines of a cyber insurance policyEnterprises in regulated industries often carry cyber insurance policies because contracts require it or boards ask for documented risk transfer. The global market for these policies reached about $16 billion in premiums in 2024. Coverage has become widespread. Payouts have grown…HELPNETSECURITY.COM
16 JulWhat public money does to open-source projectsMost of the software running inside a typical company was written by volunteers the company never paid. Open-source code sits under web apps, build pipelines, and the machine learning stacks getting so much attention right now. Roughly 96 percent of codebases carry some of it. Th…HELPNETSECURITY.COM
16 Jul KEVFlaw surge fuels need for CISOs to rethink vulnerability managementSecurity experts are calling on enterprises to revise their vulnerability management strategies and move towards “just in time” patching in response the increased pace of vulnerability exploitation. Attackers are turning to AI to increase the rate of vulnerability exploitation an…CSOONLINE.COM
16 JulNightmare Eclipse Drops ‘LegacyHive’ Windows Zero-DayThe researcher stripped the proof-of-concept (PoC) exploit to prevent immediate exploitation of the vulnerability. The post Nightmare Eclipse Drops ‘LegacyHive’ Windows Zero-Day appeared first on SecurityWeek .SECURITYWEEK.COM
16 JulSrsly Risky Biz: Ransomware uses AI to amp up negotiationsTom Uren and James Wilson talk about different ways ransomware groups are taking advantage of AI. The relatively new FulcrumSec group uses simple techniques to breach companies and then uses AI to get more leverage over victims in its extortion negotiations. They also discuss the…RISKY.BIZ
16 JulThe executive profile your security team isn’t defendingA few years ago, I was retained to conduct a digital risk review for the chief executive of a mid-sized financial services firm. The brief was standard. Assess what was publicly available about the executive, identify exposure and advise on remediation. The AI tools I used comple…CSOONLINE.COM
16 JulUS Launches Gold Eagle to Coordinate AI-Driven Vulnerability ManagementThe White House announced Gold Eagle to help accelerate the discovery, prioritization and patching of flaws found by AIINFOSECURITY-MAGAZINE.COM
16 JulMicrosoft makes Windows SSO prompts easier to manageMicrosoft is introducing a new registry-based policy that lets IT administrators automatically accept Windows SSO permissions on Windows 11 versions 24H2 and 25H2 devices managed with Microsoft Entra ID. Users with personal Microsoft accounts and devices outside policy-managed en…HELPNETSECURITY.COM
16 JulOpenAI’s GPT-Red Automates Prompt Injection Testing to Harden GPT-5.6 SolOpenAI has disclosed details of GPT-Red, an internal automated red-teaming model that scales prompt injection vulnerability discovery with an aim to fix issues before the tools are deployed widely. "GPT‑Red is a strong red-teamer, and our previous models are highly vulnerable to …THEHACKERNEWS.COM
16 JulWhen AI gets a body, it inherits an attack surfaceMost security leaders I know working on AI robotics are being shown the same kind of video. A humanoid folds a shirt, sorts a bin, walks a warehouse aisle and a vendor uses the clip to move an embodied AI system from pitch to purchase order. Someone then has to sign off. Robot de…CSOONLINE.COM
16 JulF5 Patches Multiple NGINX, BIG-IP VulnerabilitiesAttackers could exploit the bugs to modify configurations, terminate or restart processes, cross security boundaries, leak memory, and execute code. The post F5 Patches Multiple NGINX, BIG-IP Vulnerabilities appeared first on SecurityWeek .SECURITYWEEK.COM
16 JulTenable One unifies code risks with enterprise exposure dataTenable has announced the expansion of the Tenable One Exposure Management Platform, unifying application security risks with all other exposure data. By integrating static code vulnerability data, Tenable One delivers complete, code-to-runtime visibility across the entire attack…HELPNETSECURITY.COM
16 JulUnpatched Shark Vacuum Flaw Could Let Attackers Control Other Vacuums Region-WidePull the certificate off the flash of a Shark RV2320EDUS robot vacuum, and you can run root commands on other people's Shark vacuums across the same AWS region: watch the camera, drive the robot, read the map of the house, and take the Wi-Fi password in plaintext. A researcher pu…THEHACKERNEWS.COM
16 JulCISA urges software vendors to formalize vulnerability disclosure programsThe Cybersecurity and Infrastructure Security Agency (CISA) and four international cybersecurity agencies have published guidance urging software manufacturers and online service providers to establish coordinated vulnerability disclosure (CVD) programs, saying structured engagem…CSOONLINE.COM
16 Jul KEVCISA orders feds to patch actively exploited Oracle flaw by SaturdayCISA has ordered federal agencies to secure their systems by Saturday against ongoing attacks exploiting a critical vulnerability in the Oracle E-Business Suite financial application. [...]BLEEPINGCOMPUTER.COM
16 JulSpaceXAI admits Grok retained developer data in open-source announcementSpaceXAI has acknowledged that Grok Build retained coding data for some users during its early beta, days after security researchers disclosed that the AI coding tool was uploading entire developer repositories. Alongside the admission, the company announced it is open-sourcing t…CYBERINSIDER.COM
16 JulValorC3 extends SaaS protection with immutable cloud backupsValorC3 Data Centers today announced the general availability of Backup as a Service, a fully managed offering that protects the SaaS data businesses rely on most, including Microsoft 365, Entra ID and Salesforce. Every backup is immutable, so data stays recoverable after deletio…HELPNETSECURITY.COM
16 JulThe best defenders build AI agents together: Join Tenable for Swarm at Black Hat ’26Agentic AI use is exploding, yet most security teams are building agents in isolation. Tenable is hosting Swarm, a build event at Black Hat 2026, for security practitioners to create and collaborate on agentic, open-source tooling to drive collective defense and stop adversaries …TENABLE.COM
16 JulRussian cybercriminal used jailbroken Gemini CLI to rebuild botnet infrastructure in six minutesA Russian-speaking threat actor known as “bandcampro” used a jailbroken Gemini CLI, Google’s open-source terminal-based AI agent, to deploy and operate a small command-and-control (C2) botnet, according to TrendAI. Operational overview (Source: TrendAI) In more …HELPNETSECURITY.COM
16 JulAU: Regulator’s preliminary findings did not indicate Qantas breached privacy obligationsVlad Constantinescu reports that the Office of the Australian Information Commissioner has determined that although the Qantas data breach of 2025 resulted in 5.67 million customer records being compromised and leaked, the regulator’s preliminary inquiry did not indicate th…DATABREACHES.NET
16 JulThalha Jubair and Owen Flowers sentenced to prisonStanley Murphy-Johns, Rosie Shead, and Alex Levy report that Thalha Jubair, 20, and Owen Flowers, 18, were both sentenced at Woolwich Crown Court to 5 years and six months in prison for hacking Transport for London. In a televised sentencing, Mr Justice Turner addressed the defen…DATABREACHES.NET
16 JulModular macOS Stealer Uses Kill Loops to Force Password EntryNew ClickLock macOS stealer locked victims out of their own system until they surrendered a passwordINFOSECURITY-MAGAZINE.COM
16 JulCISA folds its own hard-won lessons into coordinated vulnerability disclosure guidanceOn Wednesday, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) and four allied cyber authorities published a guide telling software vendors how to build a coordinated vulnerability disclosure (CVD) program. Six days earlier, CISA published a blog post explaining h…HELPNETSECURITY.COM
16 JulSunsetting the Public AttackerKB PlatformWhat’s changing, where AttackerKB-style analysis will live, and how users can continue finding Rapid7 vulnerability intelligence. On August 18, Rapid7 will sunset the standalone public AttackerKB website as part of a broader effort to unify our vulnerability intelligence, exploit…RAPID7.COM
16 Jul KEVCISA warns of actively exploited SharePoint flaws.A new stealthy ransomware family emerges. Law enforcement operation disrupts international fraud scheme.THECYBERWIRE.COM
16 JulLegacy Systems, Real-World Impacts: The Reality of OT SecurityLegacy systems, safety concerns, and critical infrastructure risks make OT vulnerability disclosure one of cybersecurity's most challenging balancing acts. The post Legacy Systems, Real-World Impacts: The Reality of OT Security appeared first on SecurityWeek .SECURITYWEEK.COM
16 JulZoom patches account takeover holeZoom has identified, and patched, a critical security hole that “may allow an unauthenticated user to conduct an account takeover via network access.” The issue is especially significant given Zoom’s extensive reach; it reportedly has more than 300 million daily active users, inc…CSOONLINE.COM
16 JulTwo Scattered Spider Hackers Get 5.5 Years Each for £29 Million TfL HackOwen Flowers, 18, and Thalha Jubair, 20, were each sentenced to five and a half years at Woolwich Crown Court on Thursday, 16 July 2026, for the 2024 hack of Transport for London. The attack left 148 TfL systems inoperable and forced all 27,000 of the transport authority's employ…THEHACKERNEWS.COM
16 JulVU#885548: Denial-of-service vulnerability in HTTP/2 servers via stalled flow-control conditionsOverview A denial-of-service (DoS) vulnerability exists in some HTTP/2 server implementations that fail to adequately limit resource consumption when buffering response data under stalled flow-control conditions. A remote, unauthenticated attacker can trigger memory exhaustion an…KB.CERT.ORG
16 JulBTS #78 - Patching: The Race Against TimeIn this episode of Below the Surface, host Paul Asadoorian is joined by Vlad Babkin and Chase Snyder for a wide-ranging discussion on modern vulnerability management, network appliance visibility, AI-assisted exploitation, Linux kernel bugs, cold boot attacks, and software supply…ECLYPSIUM.COM
16 JulItaly fines WINDTRE €1.7 million over data breachesGianluca Semeraro reports: Italy’s data protection authority has fined telecoms operator WINDTRE €1.7 million ($1.94 million) for “serious shortcomings” in its data security systems, leading to two unauthorised breaches and the exposure of personal information belonging to more…DATABREACHES.NET
16 JulProgram to rotate cyber personnel through federal agencies saw little useThe number of people who got approval to be in the Federal Rotational Cyber Workforce program was in the single digits, GAO found. The post Program to rotate cyber personnel through federal agencies saw little use appeared first on CyberScoop .CYBERSCOOP.COM
16 JulClaude Chrome extension flaw lets malicious extensions trigger AI actionsA flaw in Anthropic's Claude for Chrome browser extension could allow a malicious extension to trigger predefined AI actions by simulating user clicks, potentially allowing it to abuse Claude's access to connected services such as Gmail, Google Docs, Google Calendar, and Salesfor…BLEEPINGCOMPUTER.COM
16 JulFor hackers, sharing is caring.CISA warns of active SharePoint attacks. The NSA pushes coordinated vulnerability disclosure. ClickLock Stealer targets macOS. Splunk and Zoom patch critical flaws. Spirals ransomware strikes in under 24 hours. New Windows evasion techniques emerge. LabubaRAT poses as NVIDIA soft…THECYBERWIRE.COM
16 Jul1999 Called and It Wants It's Exploits Back - PSW #935This week, our technical segment covers a new open-source tool written by Paul (and Claude) that helps you keep your Linux systems up to date and assess supply chain risks. It's called "fettle" and is a pure Python implementation that gives you even more features than previously …YOUTUBE.COM
16 JulNew ClickLock macOS malware traps users into revealing login passwordA new macOS information-stealing malware dubbed ClickLock terminates all visible processes to force users into entering their system login password. [...]BLEEPINGCOMPUTER.COM
16 JulCoca-Cola says Fairlife ransomware attack halts US dairy productionThe Coca-Cola Company disclosed today that a ransomware attack impacting its Fairlife dairy subsidiary has disrupted operations, temporarily suspending production of Fairlife products across the United States. [...]BLEEPINGCOMPUTER.COM
16 JulThe Breach That Won’t End: An Update on Canvas, and how they created an EdTech’s Vendor Trust ProblemJeff Piontek comments on the Instructure breach: The forensic review has taken far longer than anyone expected. Through June, Instructure was still finalizing customer-specific findings and asking institutions to designate a security contact to receive them. In early July, the co…DATABREACHES.NET
15 JulMicrosoft Patches Record 622 Flaws, Including Two Zero-Days Under Active AttackMicrosoft shipped its largest Patch Tuesday on record today, and two of the fixes close holes that attackers are already exploiting. The release covers 622 of Microsoft's own CVEs by its Security Update Guide count, more than triple June's previous high of around 2…THEHACKERNEWS.COM
15 JulICYMI: June 2026 @AWS SecurityRead all about the latest AWS security features, compliance updates, and hands-on resources in our new, monthly digest posts. You’ll find expert blog posts, new service capabilities, code samples, and workshops. AWS Security Blog posts This month’s AWS Security Blog posts covered…AWS.AMAZON.COM
15 JulShareFile explained, healthcare in critical cyber condition and click fix tops malware chartsShareFile emergency explained, a year of Salesforce breaches examined, healthcare cybersecurity in critical condition and click fix goes number one for malware. David Shipley covers Progress Software's emergency ShareFile shutdown, now tied to a previously unknown high-severity p…CYBERSECURITYTODAY.LIBSYN.COM
15 JulAI used to help plan the break-in, now it’s doing the break-inOver the past twelve months, researchers documented intrusions in which AI ran exploitation workflows autonomously, generating thousands of commands across dozens of sessions with minimal human direction, according to Check Point’s AI Security Report 2026. AI-powered cyber attack…HELPNETSECURITY.COM
15 JulThe MDR renewal question: What changes when AI can handle the alertsFor most of the past decade, the managed detection and response (MDR) decision was a simple one: teams that couldn’t staff a 24/7 SOC outsourced detection and response to a provider who could. It solved a resources problem, and the alternatives (hiring a team you couldnR…HELPNETSECURITY.COM
15 JulGoose Creek - 6,574,121 breached accountsIn June 2026, a party claiming to have access to data from Goose Creek Candle Company sent emails to a number of the company's customers , claiming the company had a security vulnerability and suffered a data breach. The data was subsequently sent to Have I Been Pwned and contain…HAVEIBEENPWNED.COM
15 JulSingGuard-NSFA: Open-source guardrails for agentic AISingGuard-NSFA is an open-source guardrail framework aimed at operational threats in agent workflows. Four models ship at 0.8B, 2B, 4B, and 9B parameters, all built on Qwen3.5 base backbones. Risk taxonomy The NSFA risk taxonomy organizes threats along the CIA triad of confidenti…HELPNETSECURITY.COM
15 Jul7 skills and traits of elite security engineersSecurity engineers play a pivotal role in enterprise cybersecurity, because they are the professionals who design, build, and deploy security systems to protect an organization’s data, applications, systems, networks, and other IT components against a variety of cyber threats. Fi…CSOONLINE.COM
15 JulCritical Vulnerabilities Patched With Fresh Chrome 150, Firefox 152 UpdatesPublic exploit code targeting the Firefox flaws exists, but no in-the-wild exploitation has been observed. The post Critical Vulnerabilities Patched With Fresh Chrome 150, Firefox 152 Updates appeared first on SecurityWeek .SECURITYWEEK.COM
15 JulNigeria Deepens Cybersecurity Efforts as Cybercriminals See More ProfitsThe West African country advanced rules to force organizations to disclose cyberattacks, joining other nations in a shift to mandated transparency.DARKREADING.COM
15 JulFortinet adds AI controls and data loss prevention to FortiEndpointFortinet has announced new capabilities for its unified endpoint platform, FortiEndpoint, designed to help organizations securely adopt AI, protect sensitive data, and reduce risk. By bringing AI visibility and control, native data security, endpoint risk scoring, and FortiAI-ass…HELPNETSECURITY.COM
15 JulCybersecurity needs more prevention and less reliance on cureAsk any medical doctor, and they’ll tell you that prevention is better than cure. It’s more cost-effective and it has better outcomes. The same is true in cybersecurity. But we believe that our industry has veered too far away from this simple concept. We observe that most new to…CSOONLINE.COM
15 JulSonicWall warns of active exploitation of two SMA 1000 zero-daysSonicWall warns of active attacks exploiting two SMA 1000 zero-days, including a flaw enabling arbitrary command execution. SonicWall confirmed the active exploitation of two zero-day vulnerabilities affecting Secure Mobile Access (SMA) 1000 appliances. The vulnerabilities were i…SECURITYAFFAIRS.COM
15 JulCompromised AsyncAPI npm Packages Deliver Multi-Stage Botnet MalwareFour compromised npm packages in the @asyncapi namespace have been observed distributing a multi-stage botnet loader, according to findings from OX Security, SafeDep, Socket, and StepSecurity. The affected packages are listed below - @asyncapi/generator-helpers@1.1.1 @asyncapi/ge…THEHACKERNEWS.COM
15 Jul KEVTake Back Control as Enterprises Struggle to Incorporate Risks They Don't Understand - BSW #456More than 48,000 vulnerabilities were disclosed in 2025, yet only about 1% are actively exploited. However, you’re expected to mitigate all vulnerabilities, or at least critical and high. But what if there is no patch to fix the vulnerability or the software is unsupported? Ben L…YOUTUBE.COM
15 JulMicrosoft Patches 570 CVEs in Record Patch TuesdayMicrosoft released fixes for a record 570 CVEs in its July Patch Tuesday update, as experts warn AI is dramatically accelerating vulnerability discovery and increasing patch volumesINFOSECURITY-MAGAZINE.COM
15 Jul KEVCISA warns admins to patch actively exploited SharePoint flawsThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned Tuesday that attackers are actively exploiting three vulnerabilities to hack Internet-exposed on-premises SharePoint Server instances. [...]BLEEPINGCOMPUTER.COM
15 JulProgress Confirms Zero-Day Vulnerability Behind ShareFile DisruptionThe company has rolled out a fix and is restoring access for Storage Zones Controller customers who apply it. The post Progress Confirms Zero-Day Vulnerability Behind ShareFile Disruption appeared first on SecurityWeek .SECURITYWEEK.COM
15 JulCursor Flaw Lets Malicious Cloned Repositories Trigger Windows Code ExecutionOpen a repository in Cursor on Windows and, if a file named git.exe is sitting in the project root, Cursor runs it. No click, no approval dialog, no warning that anything in the folder is about to execute. Whatever that binary does, it does as you, with your source…THEHACKERNEWS.COM
15 JulChrome Sync increasingly abused to stalk unsuspecting victimsCyberstalkers are increasingly exploiting Google Chrome's built-in synchronization feature to secretly monitor victims' web activity without installing spyware or compromising their devices. Security firm Certo says it has received a growing number of reports involving the tactic…CYBERINSIDER.COM
15 JulWhite House Launches AI-Driven ‘Gold Eagle’ Vulnerability Coordination InitiativeThe new program stems from an AI-focused Executive Order signed by President Trump on June 2. The post White House Launches AI-Driven ‘Gold Eagle’ Vulnerability Coordination Initiative appeared first on SecurityWeek .SECURITYWEEK.COM
15 JulClickFix is changing the economics of social engineeringClickFix has moved from a one-off social engineering trick into an industrialized attack ecosystem that is outpacing conventional antivirus and endpoint defenses, according to ReversingLabs. The technique first showed up in late 2023 and early 2024, and Proofpoint named it in mid…HELPNETSECURITY.COM
15 JulProgress Restores ShareFile Storage Zones Access After Vulnerability Exploit ConcernsProgress has restored access to its ShareFile Storage Zones Controller after a four-day suspension triggered by a credible external security threatINFOSECURITY-MAGAZINE.COM
15 JulPolygraf AI Meeting Guard delivers real-time deepfake detection for enterprise meetingsPolygraf AI has announced Meeting Guard, a real-time AI fraud detection solution for enterprise meetings built to detect fraud and protect meeting security. AI can clone a voice, animate a face, and answer every interview question in real time, making trust signals obsolete acros…HELPNETSECURITY.COM
15 JulResearcher Drops New Windows Zero-Day PoC Hours After Microsoft Patch TuesdaySecurity researcher Chaotic Eclipse (aka Nightmare-Eclipse) has released a new proof-of-concept (PoC) exploit called LegacyHive. It has been described as a Windows User Profile Service arbitrary hive load elevation of privileges vulnerability. The Windows User Profile Service, al…THEHACKERNEWS.COM
15 JulNew Windows Bind Link techniques let attackers evade EDR, security controlsAttackers who already have administrator privileges on a Windows machine have newer ways to slip past endpoint security without exploiting a vulnerable driver or modifying trusted binaries. Bitdefender researchers have warned against three techniques that abuse Windows Bind Links…CSOONLINE.COM
15 JulWhite House launches AI-driven vulnerability clearinghouse to speed cyber remediationThe White House is expanding the use of AI beyond cyber threat detection into vulnerability management, launching a new program that aims to help government agencies and critical infrastructure operators identify, prioritize, and remediate software vulnerabilities faster. Called …CSOONLINE.COM
15 JulNew bugs in Claude for Chrome allow extensions to abuse AI privilegesTwo vulnerabilities found in Anthropic’s Claude for Chrome extension remain exploitable months after they were reported to the company, a research by Manifold Security noted. According to the researchers, the flaws can allow a malicious browser extension to trigger Claude into pe…CSOONLINE.COM
15 Jul5 reasons to bring application security data into your exposure management platformWhen you incorporate data from application security scanners into your exposure management platform, you can assess the threat from formerly isolated code flaws using a broader risk context, which illuminates hidden exposures that your security and development teams can eliminate…TENABLE.COM
15 JulJuly 2026 Patch Tuesday fixes 622 Microsoft CVEs, including three zero-daysMicrosoft's July 2026 Patch Tuesday sets yet another record, fixing 622 Microsoft CVEs—three times as many as last month.MALWAREBYTES.COM
15 JulMicrosoft smashes Patch Tuesday record for second successive monthVulnerability counts have been surging this year, and Microsoft's mammoth disclosure this week of 622 bugs is larger than the three previous months combined.THERECORD.MEDIA
15 JulCompromised Logins Surge as the Most Common Entry Point for Ransomware AttacksResearch of incidents by Sophos finds that phishing, brute force attacks and other identity-based threats have surpassed software vulnerabilities as means of delivering ransomwareINFOSECURITY-MAGAZINE.COM
15 Jul2-Click Cursor Exploit Enables Dev Environment TakeoverSimple age-old bugs give bad actors access to developers' secrets and source code-rich environments.DARKREADING.COM
15 JulNayax updates its incident status; states it won’t pay any extortion demandIt’s common for victims and threat actors to disagree sharply over the scope of an attack or its significance. Today’s example involves Israeli fintech Nayax and a group called The Syndicate. In previous coverage, DataBreaches cited Nayax’s submission to the Sec…DATABREACHES.NET
15 JulAU: Partnered Health Data Breach Exposes Patient Records at Family ClinicsTrevor Long reports: A large health care chain that owns family medical clinics across Australia has been the victim of a cyber breach which has exposed the data of their patients, including potentially treatment information. Partnered Health runs a large number of clinics across…DATABREACHES.NET
15 JulAsyncAPI npm Supply Chain Attack: Malware Injected Into Packages With 2 Million Weekly DownloadsAsyncAPI npm packages with 2M weekly downloads were compromised, spreading malware with info-stealing, crypto-theft and RAT capabilities. OX Security researchers disclosed on July 14 that the AsyncAPI npm organization was compromised, with malicious code injected into four packag…SECURITYAFFAIRS.COM
15 JulWe built a vulnerability vending machine: AI tokens in, zero-days outIntruder built an AI-powered "vulnerability vending machine" that combines code slicing with LLMs to automatically discover complex software vulnerabilities. The company explains how the system found and exploited a previously unknown WordPress plugin zero-day, with additional di…BLEEPINGCOMPUTER.COM
15 JulF5 Insight for ADSP enhances BIG-IP operations with guided updates and AI audit trailsF5 has announced new fleet management capabilities for F5 Insight for ADSP that help enterprises reduce risk exposure across F5 BIG-IP environments as frontier AI compresses vulnerability response timelines. The new F5 Insight workflows give security and operations teams fleet-wi…HELPNETSECURITY.COM
15 JulInvestigating Persistence Mechanisms in AWSOverview In the cloud, your infrastructure may be short-lived, but an attacker’s persistence doesn't have to be. While your environment scales and changes in seconds, adversaries are embedding themselves into your IAM policies, Lambda functions, and federated sessions, creating i…RAPID7.COM
15 JulAttackers Find Bugs Before CVEsResponsible disclosure gives vendors time to develop patches before vulnerabilities are publicly disclosed. That process can take months, while attackers may already be searching for and exploiting the same weaknesses. By combining AI with large-scale vulnerability data, security…YOUTUBE.COM
15 JulClaude for Chrome flaw could let rogue extensions access your GmailThe ClaudeBleed vulnerability still lets malicious Chrome extensions abuse Claude for Chrome's permissions.MALWAREBYTES.COM
15 JulUnpatched Cursor Vulnerability Exposes Users to Code ExecutionAn attacker can create a malicious repository containing a git.exe in the project root, and Cursor executes it automatically. The post Unpatched Cursor Vulnerability Exposes Users to Code Execution appeared first on SecurityWeek .SECURITYWEEK.COM
15 Jul KEVCISA Urges Immediate Patching of Exploited SharePoint VulnerabilitiesThree vulnerabilities are actively exploited in attacks, including two that have been targeted as zero-days. The post CISA Urges Immediate Patching of Exploited SharePoint Vulnerabilities appeared first on SecurityWeek .SECURITYWEEK.COM
15 JulUnderstanding Claude Tag’s access model in Slack and how to configure it securelyAnthropic’s new AI agent for Slack acts under an admin-configured access bundle rather than each user’s own credentials. Here’s how that model works, what admins should understand and how to securely configure it. Key takeaways Claude Tag, Anthropic’s newly launched AI agent for …TENABLE.COM
15 JulPatch Tuesday notes: Microsoft fixes a record 570 flaws.SonicWall warns of a maximum-severity zero-day. Business news: Valarian raises $50 million in Series A funding.THECYBERWIRE.COM
15 JulCISA warns that multiple vulnerabilities in SharePoint are under exploitationSecurity researchers say additional flaws are being chained together and a patch will not be available until August.CYBERSECURITYDIVE.COM
15 JulUS launches vulnerability clearinghouse amid AI-fueled surge in flawsThe Trump administration hopes the program will accelerate the discovery and fixing of serious technical problems before hackers exploit them.CYBERSECURITYDIVE.COM
15 JulClaude Flaw Automatically Sends Malicious Prompts to AI AgentsWhen combined with another exploit, the "PromptFiction" vulnerability, which has been fixed, could have enabled an end-to-end attack on a targeted system.DARKREADING.COM
15 JulChaotic Eclipse Unveils LegacyHive Exploit Affecting Fully Patched Windows SystemsLegacyHive PoC exposes a Windows Privilege Escalation flaw affecting fully patched Windows desktop and server systems. Just hours after Microsoft’s July 2026 Patch Tuesday, security researcher Nightmare Eclipse, also known as Chaotic Eclipse, published a new Windows zero-da…SECURITYAFFAIRS.COM
15 JulMicrosoft patches bug in video game Age of Empires IIThe vulnerability in the decades-old game could have allowed hackers to take over victims’ computers with a malicious game invite.TECHCRUNCH.COM
15 JulHack suggests AI music generator Suno scraped YouTube for training dataThe hacker used an employee's credentials to access source code, which revealed how Suno scraped decades of audio.TECHCRUNCH.COM
15 JulSonicWall customers under threat as attackers exploit 2 zero-daysResearchers said the vulnerabilities, which attackers are chaining together, were first exploited three weeks before the vendor disclosed and patched the defects. The post SonicWall customers under threat as attackers exploit 2 zero-days appeared first on CyberScoop .CYBERSCOOP.COM
15 JulGoogle Gemini CLI abused as a hacking agent, malware botnet operatorA Russian-speaking threat actor known as "bandcampro" used Google's open-source Gemini CLI AI tool as a hacking agent and to operate a small-scale botnet. [...]BLEEPINGCOMPUTER.COM
15 JulGuten Tag, Bonjour, Hola to Our European Cyber Defenders!We're thrilled to unveil the latest evolution of Dark Reading's DR Global section — your go-to source for region-specific cybersecurity intelligence beyond North America.DARKREADING.COM
15 JulWilmerHale Sued Over Client Personal Information Data BreachAlex Ebert reports: Wilmer Cutler Pickering Hale & Dorr should pay millions of dollars in damages for loss of clients’ personal information in a May data breach, a putative class action claims. The lawsuit, filed Tuesday in the US District Court for the District of Columbia, …DATABREACHES.NET
15 JulFiles relating to India’s largest nuclear power plant Kudankulam exposed in data breachMunsif Vengattil and Aditya Kalra Ransomware group World Leaks has posted on the dark web a huge cache of files related to India’s largest nuclear plant, including purported blueprints of parts of its facilities and supplier details — information it labelled as coming from…DATABREACHES.NET
15 JulNPM ecosystem hit with two new supply chain compromisesAttacks targeting developer ecosystems are increasing in frequency and sophistication, with Node.js developers firmly in this week’s crosshairs, as multiple npm packages belonging to the open-source AsyncAPI and Jscrambler Code Integrity were poisoned with malware following compr…CSOONLINE.COM
15 Jul KEVPatchapalooza packs a punch.Patch Tuesday. SonicWall urges immediate patching of actively exploited vulnerabilities. The White House launches an AI-backed vulnerability clearinghouse. The Air Force contends with widespread cybersecurity quarantines. The UK and EU blame Russia for last year’s cyberattack on …THECYBERWIRE.COM
15 JulSecurity researchers find stalkers abusing Chrome’s sync featureCerto Software warns that the capability, designed for convenience, can easily be used to spy on online activity. The post Security researchers find stalkers abusing Chrome’s sync feature appeared first on CyberScoop .CYBERSCOOP.COM
15 JulZoom warns of critical account takeover vulnerabilityZoom is warning of a critical vulnerability in its desktop client and software development kit for Windows that could be exploited by an unauthenticated party to hijack accounts. [...]BLEEPINGCOMPUTER.COM
15 JulIdentity Attacks Overtake Exploits as Top Ransomware CauseEmail attacks overtook exploits as the top ransomware root cause last year. Multifactor authentication (MFA) was deployed in 97% of credential-based attacks but failed to prevent compromise.DARKREADING.COM
15 JulCalgary 911 employee charged with breach of trustManjot Singh reports: Calgary police say a City of Calgary 911 employee has been charged following an investigation into the unauthorized disclosure of confidential information. Police say the investigation began in January after allegations that sensitive information was being a…DATABREACHES.NET
15 JulUS and allied Governments’ Recommendations: Securing Network Devices Against Russian APT GroupsUS and allies warn of Russian APT groups targeting routers and network devices to compromise critical infrastructure worldwide. The US and allied governments warn that Russian state-sponsored APT groups are scanning and exploiting poorly secured network devices, especially router…SECURITYAFFAIRS.COM
15 Jul“AI Normal Tech” vs “AGI by Tuesday”: Security Advice That Survives Either FutureIf you look at social media debates about AI, two extreme patterns emerge. Studying extreme patterns is very useful because understanding boundary conditions helps you understand the whole phenomenon — in this case of security in AI adoption (recent extreme example ). You can als…MEDIUM.COM
14 JulBetween Two Nerds: Exploits are not cyber powerIn this edition of Between Two Nerds Tom Uren and The Grugq discuss just how important exploits are for cyber operations using data published in a new paper authored by two members of Ukraine’s cyber security agency. This episode is also available on YouTube.RISKY.BIZ
14 JulAI Security Report 2026For years, the cyber security industry tracked AI as a force multiplier: something that made existing attack techniques faster, cheaper, and more accessible. That framing was accurate. But the Annual AI Security Report 2026 from Check Point Research documents a transition that go…RESEARCH.CHECKPOINT.COM
14 JulChatto: Open-source team messenger with privacy at its coreTeams that want their group chats off commercial platforms have a growing menu of self-hosted options. Chatto joined that group when its developer released the code under an open-source license and posted binaries for anyone to run on their own hardware. The software aims at the …HELPNETSECURITY.COM
14 JulThe best defense against AI attacks turns out to be a skeptical humanAnalysts across the security industry now run generative AI through their daily work, from log triage to incident write-ups. Active use in cybersecurity strategy reached 78% of practitioners in 2026, up from half the field a year earlier. The 2026 SANS AI Survey, drawn from 536 I…HELPNETSECURITY.COM
14 JulFake smart home residents could stand in for real ones in security researchSmart home security research runs on a scarce ingredient: recordings of how real people use the gadgets in their homes. Getting that data means wiring up someone’s house and watching for months, which is slow, costly, and about as invasive as it sounds. So the datasets stay…HELPNETSECURITY.COM
14 JulMicrosoft Maps Year-Long ShinyHunters-Linked Salesforce Data Theft Across Three PathsAttackers whose methods line up with the data-extortion group ShinyHunters have spent the past year walking into corporate Salesforce environments without exploiting a single flaw in the platform. The way in has been the trust the organization had already extended, usua…THEHACKERNEWS.COM
14 JulPentagon Suspends CMMC Phase 2 as It Rethinks Contractor Cybersecurity RulesA new CMMC review and reform task force will conduct a comprehensive review of the program. The post Pentagon Suspends CMMC Phase 2 as It Rethinks Contractor Cybersecurity Rules appeared first on SecurityWeek .SECURITYWEEK.COM
14 JulNew tutorials on underground hacking forums have roughly doubledUnderground hacking forums are producing more original tutorials again, with growing attention on financial fraud, particularly the theft and fraudulent use of payment card data, known as carding, and cash-out techniques. New tutorials per month versus reposts (Source: Radware) F…HELPNETSECURITY.COM
14 JulDiscovering & Securing Your AI Agent Attack Surface - Jeremy Snyder - ASW #391While LLMs and agents are new to appsec and everyone else, a lot of AI security requirements translate to well-known API security requirements. Jeremy Snyder helps us frame the OWASP LLM Top 10 into five layers in order to help orgs understand and prioritize their attack surface.…YOUTUBE.COM
14 JulRapid7 and Mindshare Partner to Accelerate Cyber Resilience Across the Middle EastGopan Sivasankaran is Regional Director, Middle East & Africa, at Rapid7 From AI adoption and cloud-first strategies to smart cities and critical infrastructure modernization, organizations across the United Arab Emirates are embracing innovation at an unprecedented rate. The cou…RAPID7.COM
14 JulGrok Build Uploads Entire Git Repositories to xAI Storage, Not Just Files It ReadsxAI's Grok Build coding CLI was uploading entire Git repositories, full commit history and all, to a Google Cloud Storage bucket run by xAI, not just the files a coding task needed. A researcher publishing as cereblab, testing version 0.2.93, captured one of those uploads, cloned…THEHACKERNEWS.COM
14 JulAI incidents need a new playbook. Here’s how to build oneSeventy-one percent of organizations say AI has access to core business systems. Only 16% govern that access effectively, according to the 2026 CISO AI Risk Report . Ask your IR team three questions: Where is your AI system inventory? What happens if a production model starts gen…CSOONLINE.COM
14 JulThe inside job that cost ransomware victims millionsInstead of helping victims negotiate with BlackCat, a trusted ransomware negotiator secretly helped the gang extort them.MALWAREBYTES.COM
14 JulMalware Hits Japan’s Largest Taxi Company Nihon Kotsu, Services Temporarily SuspendedJapan’s largest taxi operator Nihon Kotsu shut down systems after a malware attack, disrupting dispatch and bookings. Nihon Kotsu, Japan’s largest taxi company, disclosed on July 13, 2026 that its internal systems suffered an unauthorized external access involving mal…SECURITYAFFAIRS.COM
14 JulThe serpent’s tongue: Luring the Python out of its denThis blog examines the full lifecycle of a Python package, from hosting on repositories such as PyPI or custom web servers, through source and wheel distribution formats, to the final installation into virtual or system-wide Python environments.TALOSINTELLIGENCE.COM
14 JulInside China's Cyber Espionage BusinessAhana Datta Fasel became the British government’s first ethical hacker in 2014, testing vulnerabilities in computer systems and networks that hackers could potentially exploit. She was only 23, but that gave her an early look at state-sponsored cyber intrusions, which have of cou…THECYBERWIRE.COM
14 JulGoogle adds FIDO2 keys and phone passkeys to Windows login via GCPWGoogle has started rolling out FIDO2-compliant physical security key support as a second factor for authentication in Google Credential Provider for Windows (GCPW) to all Google Workspace customers. GCPW is a free tool that lets users sign in to Windows computers with their Googl…HELPNETSECURITY.COM
14 JulVulnerability in FIFA’s NetworkFIFA’s network was vulnerable to anyone with even minimal access.SCHNEIER.COM
14 JulWarning: Scammers are using FaceTime to empty bank accountsCybercriminals are combining social engineering through apps like FaceTime with unpatched devices to steal credentials and drain bank accounts.MALWAREBYTES.COM
14 JulNew MacOS Malware Exploits Legitimate Developer ID to Pose as Apple Crash ReporterResearchers at Jamf Threat Labs detail CrashStealer, which steals passwords, cryptocurrency wallets and moreINFOSECURITY-MAGAZINE.COM
14 JulSAP warns of critical flaws in NetWeaver and Commerce CloudSAP has addressed 16 vulnerabilities across multiple products as part of its July 2026 security updates, including three critical flaws in NetWeaver, Commerce Cloud, and AppRouter. [...]BLEEPINGCOMPUTER.COM
14 JulSAP Patches Critical Vulnerabilities in NetWeaver, Approuter, Commerce CloudThe flaws could allow attackers to access and modify data, and cause system unavailability and request-response desynchronization. The post SAP Patches Critical Vulnerabilities in NetWeaver, Approuter, Commerce Cloud appeared first on SecurityWeek .SECURITYWEEK.COM
14 JulUnpatched Claude for Chrome Flaw Lets Extensions Read Gmail, CalendarA ClaudeBleed-linked vulnerability reportedly persists across eight patches, exposing potentially sensitive data to other extensions. The post Unpatched Claude for Chrome Flaw Lets Extensions Read Gmail, Calendar appeared first on SecurityWeek .SECURITYWEEK.COM
14 JulCursor IDE Auto-Executes Malicious Code in Poisoned ReposResearchers reported the vulnerability to Cursor in December, but it still remains in the popular AI coding platform and can be exploited in poisoned repository attacks.DARKREADING.COM
14 Jul“Context bombs” can frustrate AI-driven attacks, researchers foundA new approach tried out by Tracebit researchers has proven very effective at stopping AI agents from fully compromising targeted environments. What makes it notable isn’t the technique – prompt injection is old news – but the direction it’s pointed: not t…HELPNETSECURITY.COM
14 Jul11 Old Microsoft-Signed Linux UEFI Shims Could Let Attackers Bypass Secure BootCybersecurity researchers have discovered 11 old, Microsoft-signed, Unified Extensible Firmware Interface (UEFI) applications that could be abused to bypass Secure Boot on most systems using the modern firmware standard. "An attacker exploiting one of these vulnerable application…THEHACKERNEWS.COM
14 JulYou Don't Have to Run an Exploit to Know If You're VulnerableMany vulnerabilities cannot be safely validated with live exploits, either because no exploit exists or the affected systems are too critical to test. Picus explains how TTP chaining helps organizations determine exploitability by validating the attack techniques an exploit depen…BLEEPINGCOMPUTER.COM
14 Jul7 Severe Vulnerabilities Patched in VMware Avi Load BalancerThe flaws can be exploited for authentication bypass, remote code execution, privilege escalation, and directory traversal. The post 7 Severe Vulnerabilities Patched in VMware Avi Load Balancer appeared first on SecurityWeek .SECURITYWEEK.COM
14 JulRabbitMQ Flaws Could Leak OAuth Secrets and Expose Cross-Tenant Queue MetadataCybersecurity researchers have disclosed details of two access control-related flaws impacting the RabbitMQ message broker service that could allow attackers to leak OAuth client secrets, expose enterprise messaging infrastructure to takeover risks, and bypass tenant boundaries. …THEHACKERNEWS.COM
14 JulIran abused mobile networks’ vulnerabilities to locate US military in the Middle East, report saysThe Iranian government exploited well-known flaws in cellphone networks to locate and then strike U.S. military personnel in the build-up and beginning of the war.TECHCRUNCH.COM
14 JulGrapheneOS says Google will cut security backports for older Android releasesGrapheneOS claims Google has significantly reduced security patch backports for older Android versions. This change could leave devices on previous releases with fewer vulnerability fixes despite continuing to receive monthly security updates. Google has not publicly documented t…CYBERINSIDER.COM
14 JulProgress confirms ShareFile zero-day flaw behind Storage Zone shutdownProgress Software has confirmed that a high-severity zero-day vulnerability is behind the emergency shutdown of ShareFile Storage Zone Controllers last week and has released security updates to patch the flaw. [...]BLEEPINGCOMPUTER.COM
14 JulMicrosoft July 2026 Patch Tuesday fixes massive 570 flaws, 3 zero-daysToday is Microsoft's July 2026 Patch Tuesday, and with it comes security updates for a record-breaking 570 flaws, including two zero-day vulnerabilities exploited in attacks and one publicly disclosed. [...]BLEEPINGCOMPUTER.COM
14 JulMicrosoft Patches Record 622 Vulnerabilities, Including Two Exploited Zero-DaysTwo flaws in Active Directory and SharePoint Server have been exploited as zero-days, and a BitLocker bug was publicly disclosed. The post Microsoft Patches Record 622 Vulnerabilities, Including Two Exploited Zero-Days appeared first on SecurityWeek .SECURITYWEEK.COM
14 JulDoxbin admin jailed for egging on swatters from behind a screenConnor Jones reports: A Welshman was sentenced to prison on Tuesday for his role in numerous swattings in the UK, US, and Canada. Callum Dare, 26, was an administrator of Doxbin, a dark web platform frequented by individuals that expose the personally identifiable information (PI…DATABREACHES.NET
14 JulMicrosoft Patches a Record 570 Security FlawsMicrosoft Corp. today released software updates to plug at least 570 security holes in its Windows operating systems and other software, almost triple the number of vulnerabilities the software giant fixed in its record-smashing Patch Tuesday release last month. Microsoft attribu…KREBSONSECURITY.COM
14 JulMicrosoft Patch Tuesday July 2026 - The AI Acopolypse is Here , (Tue, Jul 14th)This patch Tuesday includes a staggering&#;x26;#;xc2;&#;x26;#;xa0;622 vulnerabilities, not including another 427 vulnerabilities in Chromium, affecting Microsoft&#;x26;#;39;s Edge browser. 62 of t…ISC.SANS.EDU
14 Jul KEVThe ransomware toll road.Treasury sanctions a VPN provider tied to ransomware. The Pentagon hits pause on CMMC audits. Critical flaws surface in Google Cloud’s Dialogflow CX. Estée Lauder discloses a data breach. Mobile networks become a battlefield for tracking U.S. personnel. Australia calls out Big Te…THECYBERWIRE.COM
14 JulMicrosoft discloses ‘the mother of all’ vulnerability loads, tripling June’s previous recordThe company forewarned customers and defenders that a flood of defects would be uncovered by AI. It delivered with a striking exponential increase. The post Microsoft discloses ‘the mother of all’ vulnerability loads, tripling June’s previous record appeared first on CyberScoop .CYBERSCOOP.COM
14 JulDefending SaaS-based applications against ShinyHunters OAuth abuseFrom Microsoft Security Research and Microsoft Defender Security Research Team: In a series of campaigns observed between mid-2025 and mid-2026, Microsoft identified threat actor activity with overlapping tradecraft commonly associated with ShinyHunters, including voice phishing …DATABREACHES.NET
14 Jul KEVMicrosoft rolls out massive Windows 11 security update with 416 fixesMicrosoft has released the July 2026 Patch Tuesday cumulative updates for Windows 11, fixing hundreds of security vulnerabilities while introducing Secure Boot improvements, security hardening changes, and compatibility fixes. The updates also patch a publicly disclosed BitLocker…CYBERINSIDER.COM
14 JulRecords Are Made to Be Broken: Patch Tuesday Raises Triage StakesThree of the 622 CVEs for which Microsoft issued patches this week are zero-days; there are more than 60 critical vulnerabilities.DARKREADING.COM
14 JulElon Musk promises to delete all data following a leak of users’ confidential informationAbror Shuhratov reports: xAI, the company founded by Elon Musk, has announced emergency measures following a serious controversy involving the unauthorized uploading of users’ private code and confidential information to a server via the Grok Build CLI tool. The companyR…DATABREACHES.NET
14 JulSynopsys Finds No Evidence of Data Breach Amid Bosch Hack ClaimsEduard Kovacs reports: A new ransomware group named D1R in recent days listed Synopsys and Bosch on its Tor-based leak website. The cybercriminals claimed to have exploited a vulnerability in Synopsys’ website to access a corporate client database containing 40,000 entries, and t…DATABREACHES.NET
14 JulFinland issues wanted notice for hacker behind massive psychotherapy data breachI was really unpleasantly surprised when they let him out while on appeal, and now they may not be able to return him to prison? Did no one foresee that he might not stick around to be sent back to prison? Daryna Antoniuk reports: Finnish police have reportedly issued a wanted no…DATABREACHES.NET
14 JulRewards For Justice offers reward for info on Media Land, ML.Cloud, and three individuals associated with itRewards for Justice announced a $10M reward for information on the Russian-based bulletproof hosting (BPH) services company Media Land, its associated company ML.Cloud, and associated staff Aleksandr Alexandrovich Volosovik, Kirill Andreevich Zatolokin, and Yuliya Vladimirovna Pa…DATABREACHES.NET
14 JulPatch Tuesday security updates for July 2026, the largest update ever. 621 CVEs in one monthPatch Tuesday: Microsoft fixes a record 621 CVEs, including 2 exploited zero-days and critical flaws affecting SharePoint, RDP, Hyper-V, and AD FS. Microsoft’s July 2026 Patch Tuesday is, by a significant margin, the largest single-month security release in the company̵…SECURITYAFFAIRS.COM
14 JulSN 1087: HalluSquatting, GhostApproval & GitLost - Patch Tuesday Breaks RecordsAI is rewriting the rules of cybersecurity, and this week, massive government and private sector moves show just how quickly the stakes are rising. Find out how regulators, attackers, and defenders are all scrambling to keep up as vulnerabilities surface at record speed. Europe w…TWIT.TV
13 JulShareFile shutdown, double-agent ransomware negotiator sentenced, Helix uses vishingShareFile shutdown order, a double-agent ransomware negotiator sentenced, and vishing crews raid SharePoint Progress Software ordered customers running ShareFile Storage Zone Controllers to shut down the Windows servers immediately amid a credible external threat, offering no CVE…CYBERSECURITYTODAY.LIBSYN.COM
13 Jul99.9% of fixable AI vulnerabilities remain unpatchedOrganizations build, deploy, and operate AI in the cloud, but basic cybersecurity hygiene is often sacrificed for speed, according to Orca Security’s 2026 State of AI Security Report. Building AI without security Fifty-six percent of AI adopters have deployed agent frameworks int…HELPNETSECURITY.COM
13 JulCynative: Open-source deep research agentRunning a large language model against a live cloud account to hunt for security holes comes with an obvious hazard. An agent that holds real credentials and a mandate to poke around can delete a bucket, flip a permission, or leak a secret on its way to a finding. Cynative, an op…HELPNETSECURITY.COM
13 JulCan AI narrow cybersecurity’s class divide?At Amazon Web Services (AWS), artificial intelligence is already compressing security work that once took months into minutes. In the old world, human red teams would find vulnerabilities, write reports, refine those reports, and eventually hand them to defenders, who would then …CSOONLINE.COM
13 JulCopy-paste might be the riskiest thing your enterprise employees do all dayThis source of data leakage takes them less than a second and happens hundreds of times a day.CYBERSECURITYDIVE.COM
13 JulAustralian Cyber Agency Warns of Global CMS Exploitation CampaignAustralian Cyber Security Centre warns CMS users of mass scanning and exploitation campaignINFOSECURITY-MAGAZINE.COM
13 JulAustralia Alerts Organizations to Ongoing CMS Exploitation AttacksAustralia warns of a global campaign exploiting CMS flaws to deploy webshells on WordPress, Joomla, and other websites. Australia’s Signals Directorate has issued an alert about a large-scale exploitation campaign actively targeting content management systems (CMS) worldwid…SECURITYAFFAIRS.COM
13 JulJurassic Park, cybersecurity and the dangerous myth of controlJurassic Park wasn’t really about dinosaurs. It was about arrogant people building systems they believed were controllable. “Life finds a way” is probably the most famous line from the entire franchise. Ian Malcolm’s warning that no matter how sophisticated the technology becomes…CSOONLINE.COM
13 JulYour AI risk register is not an incident response planPicture the moment after an AI issue is reported. A security analyst is reviewing a ticket reporting that an internal AI tool produced the wrong recommendation in a live business workflow. The risk is not theoretical anymore. Someone wants to know whether this is a security incid…CSOONLINE.COM
13 JulHungry? We talk Smoked Meat, Poutine, and Bagel - also, Identiverse Interviews! - ESW #467Interview with François Proulx from Boost Security Software Supply Chain Security: Build Pipeline (CI/CD) Exploitation Boost Security is the creator of some very popular build pipeline security tools, like Bagel and Poutine. Today, we discuss their latest tool, Smoked Meat. They …YOUTUBE.COM
13 JulZimbra Patches Critical Code Execution VulnerabilityThe flaw results in malicious code embedded in crafted emails being executed when the emails are opened. The post Zimbra Patches Critical Code Execution Vulnerability appeared first on SecurityWeek .SECURITYWEEK.COM
13 JulOrganizations Warned of Exploited Joomla Extension VulnerabilitiesThreat actors have been targeting Balbooa Forms and iCagenda Joomla extension flaws for remote code execution. The post Organizations Warned of Exploited Joomla Extension Vulnerabilities appeared first on SecurityWeek .SECURITYWEEK.COM
13 JulIntel agencies warn of Russian state hackers targeting routers worldwideA coalition of 21 cybersecurity and intelligence agencies has warned that Russian state-sponsored hackers continue to compromise internet-facing routers by exploiting weak configurations and known vulnerabilities, enabling them to steal device configurations and gain insight into…CYBERINSIDER.COM
13 JulRabbitMQ Vulnerability Threatens Enterprise SystemsUnauthenticated attackers could obtain the broker's confidential OAuth client secret, allowing them to take control of the broker. The post RabbitMQ Vulnerability Threatens Enterprise Systems appeared first on SecurityWeek .SECURITYWEEK.COM
13 JulTurning the Tables on Email Scammers With 'ScamBuster'An open source, AI-driven system adopts victim personas to engage with phishing attackers, allowing organizations and law enforcement to gather relevant data on cybercriminal operations.DARKREADING.COM
13 JulRansomware negotiator who betrayed clients sentenced to 70 months in prisonA former ransomware negotiator at incident response firm DigitalMint has been sentenced to 70 months in prison after admitting he shared confidential client information with the BlackCat ransomware group and later helped carry out ransomware attacks. Prosecutors say Angelo Martin…HELPNETSECURITY.COM
13 JulEU and UK hit Russia with joint sanctions over cyberattacksBGNES News reports: The European Union and the United Kingdom have imposed coordinated sanctions against Russia in connection with cyberattacks in Europe. Brussels and London have accused the Federal Security Service of the Russian Federation (FSB) of recent malicious activities.…DATABREACHES.NET
13 JulA cyberattack in March resulted in ZEGO filing for insolvencyA statement on ZEGO Textilveredelungszentrum GmbH’s website explains why they are filing for insolvency: Insolvency proceedings have been initiated – and why we are still looking ahead Ladies and gentlemen, dear business partners, Today we are contacting you with a message …DATABREACHES.NET
13 JulProgress urges ShareFile admins to shut down servers over “credible” threatLawrence Abrams reports: Progress Software is emailing ShareFile customers who use Storage Zone Controllers to immediately shut down their servers after identifying what it describes as a “credible external security threat” targeting the on-premises secure file-sharin…DATABREACHES.NET
13 JulWhy cloud security is mission-critical for federal civilian and defense agenciesBeyond IT compliance, cloud security is now the backbone of civilian agency resilience, national defense, and warfighter safety, as cloud environments become increasingly complex. Key takeaways For the Department of War (DoW), cloud security is an IT concern and a requirement for…TENABLE.COM
13 JulGhostcommit attack hides malicious AI instructions in imagesA proof-of-concept attack hides prompt injection in a PNG file, turning routine code reviews into a path for secret theft.MALWAREBYTES.COM
13 Jul13th July – Threat Intelligence ReportFor the latest discoveries in cyber research for the week of 13th July, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES U.S. auto insurer AssuranceAmerica has disclosed a data breach affecting approximately 7 million people. Attackers targeted an employ…RESEARCH.CHECKPOINT.COM
13 JulTidal Cyber connects assets, vulnerabilities, and threats through Threat-Led DefenseTidal Cyber has announced Threat-Led Asset Visibility and Vulnerability Prioritization, new innovations extending the company’s Threat-Led Defense platform. The announcement marks a significant advancement in defensive security, shifting the industry beyond static asset inv…HELPNETSECURITY.COM
13 JulPakistani Police Systems Hit by Chinese and Indian EspionageChinese and Indian spies converged on the same Balochistan police force, SentinelLabs foundINFOSECURITY-MAGAZINE.COM
13 JulCenters Lab NJ discloses data breach incident impacting 542,000 peopleCenters Lab NJ has revealed that a cybersecurity incident disclosed last month affected 542,377 individuals, according to a filing with the US Department of Health and Human Services (HHS) Office for Civil Rights (OCR). The figure, published on the agency's breach portal, provide…CYBERINSIDER.COM
13 JulCloud Security Meets AI: What CISOs Need to Govern Before They Scale - Brent Neal - CSP #226AI is changing cloud security fast, but the biggest challenge is not just adoption. It is governance. In this episode, Jess sits down with Brent Neil, CISO at RapidScale, to talk about what CISOs should be watching as AI becomes embedded in cloud environments, business workflows,…YOUTUBE.COM
13 JulUS authorities warn that state-linked hackers are targeting vulnerable networking devicesHackers linked to Russian intelligence have exploited vulnerabilities in Cisco Smart Install devices.CYBERSECURITYDIVE.COM
13 Jul KEVCISA warns of actively exploited RCE flaws in Joomla extensionsThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning that attackers are exploiting vulnerabilities in the iCagenda and Balbooa Forms extensions for Joomla to achieve remote code execution through arbitrary file uploads. [...]BLEEPINGCOMPUTER.COM
13 JulEffective Patch Management Strategies: 7 Best Practices | HuntressStop letting bad actors exploit old bugs. Build a practical patch management strategy to keep them out and learn to stay secure without all the fluff.HUNTRESS.COM
13 JulApple says former employee exploited ‘rare’ bug to download confidential files after leaving for OpenAIApple would not comment on the "security breach," which allegedly allowed a former employee to download sensitive files from Apple's network long after he departed the company for rival OpenAI.TECHCRUNCH.COM
13 JulHackers backdoor Jscrambler npm package with infostealer malwareThe Jscrambler client-side web security company disclosed that a threat actor published a malicious version of its npm package that has been downloaded almost 1,500 times. [...]BLEEPINGCOMPUTER.COM
13 JulNG: Zenith Bank, Others To Be Arraigned Over Alleged Data BreachFatima Abdullahi reports: The Federal High Court in Abuja has fixed July 21, 2026, for the arraignment of Zenith Bank Plc and three other defendants over allegations of illegally accessing and disclosing the confidential financial records of Makers Island Company Limited. The oth…DATABREACHES.NET
13 JulLidl Notified Online Shop Customers in Germany, Belgium, and the Netherlands of a Data BreachLidl disclosed a third-party data breach affecting online shop customers in Germany, Belgium, and the Netherlands. Payment data was not exposed. Lidl contacted customers of its online shop in Germany, Belgium, and the Netherlands last week to inform them that their personal data …SECURITYAFFAIRS.COM
13 JulVPN service favored by ransomware groups is sanctioned by USSuzanne Smalley reports: The U.S. government on Monday sanctioned a VPN provider and its Ukrainian administrator for abetting ransomware gangs behind attacks on American municipalities, hospitals, schools and businesses. First VPN Service (1VPNS) provided ransomware groups with t…DATABREACHES.NET
12 JulWeek in review: Accenture data breach, great open-source cybersecurity toolsHere’s an overview of some of last week’s most interesting news, articles, interviews and videos: Securing the inbox: Where identity, brand and security meet Getting a verified logo to appear next to your email has traditionally meant having to work with two separate entities. Yo…HELPNETSECURITY.COM
12 JulKR: Military targeted in nearly 19,000 cyberattack attempts in 2025: lawmakerChae Yun-hwan reports: Cyberattack attempts against the South Korean military reached nearly 19,000 last year, marking the highest figure in five years, a lawmaker said Sunday. The military was targeted in 18,951 cyberattack attempts in 2025, compared with 11,700 in 2021, 9,115 i…DATABREACHES.NET
11 JulAI Export Controls, FortiBleed, Third-Party Breaches & CISO Burnout | Cybersecurity Today PanelCan governments decide who gets access to advanced AI models? Are third-party breaches becoming impossible to control? And why are so many CISOs reaching burnout? In this special Cybersecurity Today Month in Review Panel, host Jim Love is joined by cybersecurity experts Laura Pay…CYBERSECURITYTODAY.LIBSYN.COM
11 JulCritical Zimbra Flaw Could Let Crafted Emails Run Malicious Code in User SessionsZimbra is urging customers to apply updates to address a critical security vulnerability impacting the Classic Web Client that could result in arbitrary code execution. The vulnerability has been described as a case of stored cross-site scripting (XSS) that could allow specially …THEHACKERNEWS.COM
11 JulPatching Isn't Fast Enough AnymoreCritical vulnerabilities can be exploited before organizations have time to deploy patches. This shifts attention toward time to mitigate (TTM)—the speed at which defenders can reduce risk through actions such as isolating systems, closing ports, or increasing monitoring while wa…YOUTUBE.COM
11 JulAustralia warns of global campaign targeting vulnerable CMS platformsThe Australian Cyber Security Centre (ACSC) issued an alert about a global exploitation campaign targeting vulnerable content management systems (CMS) and plugins. [...]BLEEPINGCOMPUTER.COM
11 JulArmenian National Extradited to the United States Pleads Guilty to Ransomware Extortion ConspiracyPORTLAND, Ore.— An Armenian national extradited from Ukraine to the United States pleaded guilty yesterday for his role in Ryuk ransomware attacks and an extortion conspiracy targeting companies throughout the United States, including a technology company operating in Oregon. Kar…DATABREACHES.NET
11 JulRansomware negotiator who conspired with BlackCat threat actors sentenced to 70 months in prisonJon Brodkin reports that a third co-conspirator who helped BlackCat attackers by giving them inside information on victims’ defense strategies has now been sentenced. A former ransomware negotiator was sentenced to 70 months in prison yesterday after colluding with BlackCat…DATABREACHES.NET
11 JulTikTok class action alleges data breach affected 2.4B usersBrandon Richards reports: California resident Sean Mortazi filed a class action lawsuit against TikTok Inc. on June 11, 2026, alleging a data breach exposed the personal data of more than 2.4 billion users worldwide. The complaint, filed in the U.S. District Court for the Central…DATABREACHES.NET
11 JulDutch police trace Odido telco cyberattack to suspected local accomplice; May leak voice recordingDaryna Antoniuk reports: Dutch police said Thursday they had uncovered evidence suggesting that Dutch criminals were involved in the cyberattack on telecom provider Odido that exposed the personal data of more than 6 million customers earlier this year. Authorities said a Dutch-s…DATABREACHES.NET
11 JulHackers Weaponize Balochistan Police Portal in Multi-Group Espionage CampaignsCybersecurity researchers have disclosed details of sustained cyber espionage activity against several Pakistani law enforcement organizations undertaken by suspected China- and India-aligned threat actors between February 2024 and April 2026. "At Balochistan Police, the compromi…THEHACKERNEWS.COM
11 JulCritical U-Boot Bugs Undermine Secure Boot on Millions of DevicesBinarly found six U-Boot flaws, including two that enable code execution during boot image verification, impacting 50+ releases. Binarly’s research team has found six vulnerabilities in U-Boot, the open-source bootloader that runs on home routers, smart cameras, server mana…SECURITYAFFAIRS.COM
10 JulFormer DigitalMint ransomware negotiator who duped clients sentenced to 70 months in jailAngelo Martino exploited his insider position and fed confidential information to ransomware co-conspirators to extort a combined $75.3 million from five U.S.-based victims. The post Former DigitalMint ransomware negotiator who duped clients sentenced to 70 months in jail appeare…CYBERSCOOP.COM
10 JulA questionable breach, bad routers at home and at work and AI gives defenders a winThis episode covers a hacker's claim of stealing 35GB from Accenture—including source code, Azure personal access tokens, RSA keys, and SSH keys—while Accenture calls it an isolated, remediated matter, leaving uncertainty about potential downstream risk to its Fortune 500-heavy c…CYBERSECURITYTODAY.LIBSYN.COM
10 JulOnly 28% of financial workforce MFA is phishing-resistantPasswords remain part of many workforce authentication flows in financial organizations, making phishing and credential theft major identity security risks, according to a new Secret Double Octopus report. Key challenges preventing universal implementation of phishing-resistant M…HELPNETSECURITY.COM
10 JulMicrosoft is rewriting Windows patch guidance because of AIMicrosoft is recommending that organizations shorten Windows update deployment timelines, warning that advances in AI are reducing the time attackers need to identify and exploit vulnerabilities after security updates are released. The company says organizations should reassess h…HELPNETSECURITY.COM
10 JulTurning software supply chain security into a daily habitIn this Help Net Security video, Anastasia Tikhonova, Global Threat Research Lead at Group-IB, explains how to operationalize software supply chain risk. Instead of filing an SBOM away as a compliance document, she argues teams should use it every day for vulnerability triage, ve…HELPNETSECURITY.COM
10 JulCheck Point CTO Jonathan Zanger sees AI elevating the value of cyberCheck Point Software CTO Jonathan Zanger met with CSO Spain during the software company’s Engage 2026 user conference last week in Paris. At the event, Check Point executives and representatives discussed how the company is dealing with various types of threats, how it is adoptin…CSOONLINE.COM
10 JulThe open source library holding up your stack might have one maintainerEvery serious software product runs on code that someone else wrote and released for free. A web service leans on a cryptography library, a data pipeline pulls in a parser, and a mobile app ships a handful of small utilities that one person maintains in spare time. All of it carr…HELPNETSECURITY.COM
10 JulWorkato expands Agent Studio with Headless API, AI guardrailsWorkato has announced two new capabilities for Agent Studio: Headless API and Agent Guardrails. Headless API lets Genies, Workato’s AI agents built on Agent Studio, be embedded into any business application surface, on web, mobile, or inside another agent’s own enviro…HELPNETSECURITY.COM
10 Jul‘HalluSquatting’ Turns AI Hallucinations Into Botnet Delivery MechanismResearchers demonstrate adversarial hallucination squatting against popular AI assistants to achieve remote code execution. The post ‘HalluSquatting’ Turns AI Hallucinations Into Botnet Delivery Mechanism appeared first on SecurityWeek .SECURITYWEEK.COM
10 JulAttackers Exploit 'Ill Bloom' Vulnerability to Drain $3.1 Million From Cryptocurrency WalletsSecurity firm Coinspect has disclosed a crypto wallet flaw it calls Ill Bloom, and attackers are already using it. The flaw is in how some wallet software generated its recovery phrase, the words that control the money. When that phrase is made with weak randomness…THEHACKERNEWS.COM
10 JulAI Surveillance and Social ProgressIn the near future, AI -powered surveillance systems will be able to track everything we do in public, and much of what we do in private. And if we do something wrong—shoplift, litter, jaywalk, you name it—the system will notice, retain it, tie it to your official gov…SCHNEIER.COM
10 JulUnpatched XRING Flaw in XQUIC Lets Remote Clients Crash HTTP/3 ServersA single wrong variable on one line in XQUIC, Alibaba's QUIC and HTTP/3 library, lets any remote client crash the server with a short burst of completely legal traffic. There is no patch. FoxIO researcher Sébastien Féry disclosed the flaw on July 8 and nicknamed it XRIN…THEHACKERNEWS.COM
10 JulZimbra urges customers to patch critical web client XSS flawThe Zimbra security team urged customers to patch a critical vulnerability affecting the Classic Web Client used to access the Zimbra Collaboration suite. [...]BLEEPINGCOMPUTER.COM
10 JulChina, India-Linked Hackers Both Targeted Same Pakistani Police ForceBoth foes and allies have targeted the Balochistan Police force in Pakistan for at least two years, according to SentinelOne. The post China, India-Linked Hackers Both Targeted Same Pakistani Police Force appeared first on SecurityWeek .SECURITYWEEK.COM
10 JulNew Ransomware Exploits Malicious Driver to Remove Cybersecurity ProtectionsGodDamn ransomware uses remote desktop application to secretly move around networks and drop the malicious PoisonX kernel driverINFOSECURITY-MAGAZINE.COM
10 JulIncode brings on-device processing to age estimation for privacy-focused verificationIncode has launched On-Device Age Estimation, an age verification capability that performs age estimation and liveness detection directly on the user’s device, without transmitting facial data off the device. The company’s age estimation models are now available to ru…HELPNETSECURITY.COM
10 JulChina, India ran separate spying campaigns against same Pakistani police forceThe activity, in some cases breaching the exact same systems, ran between February 2024 and April 2026 and centered on the force responsible for the country’s southwestern province that has been the site of a long-running separatist insurgency.THERECORD.MEDIA
10 JulAnthropic and OpenAI Security Tools Could Fuel Cyber-Attacks, Researchers WarnResearchers at the AI Now Institute developed a proof-of-concept exploit showing common AI tools used for security could backfireINFOSECURITY-MAGAZINE.COM
10 JulResearcher Details WhatsApp-to-Host Attack Chain Using Three OpenClaw FlawsDetails have emerged about three now-patched security flaws in the OpenClaw personal artificial intelligence (AI) assistant that, if successfully exploited, could enable credential theft, privilege escalation, and arbitrary code execution on the host. A brief description of the h…THEHACKERNEWS.COM
10 JulEU extends mass scanning of messages without a warrantMembers of the European Parliament (MEPs) have failed to block a proposal extending the mass scanning of private communications, a measure they have previously rejected twice. This time too, more votes were cast against the proposal than in favor, but due to the absence of numero…CSOONLINE.COM
10 JulCrowdStrike identifies five new prompt injection threats to AISecurity company CrowdStrike has identified five new prompt injection techniques that could leave enterprises at risk. Prompt injections attacks exploit the growing use of AI within organizations . They work by tricking LLMs into accepting instructions that a human operator would…CSOONLINE.COM
10 Jul KEVThe 72-Hour Vulnerability DeadlineThe EU Cyber Resilience Act introduces strict reporting requirements for vulnerabilities, including a 72-hour reporting window after becoming aware of an actively exploited vulnerability. Organizations must rapidly assess both technical evidence and regulatory obligations. Distin…YOUTUBE.COM
10 JulHackers exploit critical auth bypass in Gitea Docker imageHackers are actively exploiting a critical vulnerability in the official Docker image for the Gitea self-hosted Git service that allows attackers to impersonate any user, including administrators. [...]BLEEPINGCOMPUTER.COM
10 JulAWS designated as a critical third party to the UK financial sectorAmazon Web Services EMEA Sarl (AWS) has been designated as a critical third party (CTP) to the UK financial sector by HM Treasury. The CTP regime came into force on January 1, 2025, and establishes a framework through which the Bank of England, PRA, and FCA (collectively the UK r…AWS.AMAZON.COM
10 JulInitial access broker linked to weaponization of CitrixBleed2 flawA similar pattern of exploitation was seen in prior attacks involving an open-source machine emulator. CYBERSECURITYDIVE.COM
10 JulGoshDarn it, that’s advanced.Researchers track ransomware they say is getting GoshDarn sophisticated. Zimbra patches a critical vulnerability affecting its Classic Web Client. A sophisticated vishing campaign targeting Microsoft 365 accounts. GigaWiper combines espionage capabilities with multiple destructiv…THECYBERWIRE.COM
10 JulFriday Squid Blogging: “Squidbleed” VulnerabilityIn a rare combined cybersecurity/squid post, a twenty-nine-year-old squid proxy bug can leak HTTP requests. As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered. Blog moderation policy.SCHNEIER.COM
10 JulUpdate Now: Critical Zimbra Classic Web Client Flaw Could Expose MailboxesZimbra addressed a critical stored XSS vulnerability in its Classic Web Client that lets malicious emails execute code when opened. Zimbra has released version 10.1.19 to fix a critical stored XSS vulnerability in its Classic Web Client, which is widely used to access Zimbra Coll…SECURITYAFFAIRS.COM
9 JulNayax investigating breach; The Syndicate claims it acquired 1 billion card records and other important dataNayax is a global fintech company headquartered in Israel that provides cashless payment and management solutions for unattended retail and self-service machines. The firm is publicly traded on both the Tel Aviv and Nasdaq stock exchanges. This month, Nayax submitted a Form 6-K t…DATABREACHES.NET
9 JulFake 7-Zip Installers Turn Devices Into Residential Proxy NodesCybersecurity researchers have disclosed details of a new threat actor dubbed Lurking Lizard that has been operating an end-to-end malicious residential proxy business using an infrastructure comprising more than 230 lookalike domains. The activity dates back to at least August 2…THEHACKERNEWS.COM
9 JulWood you fall for this?This week, hosts of N2K CyberWire Maria Varmazis and Dave Bittner…THECYBERWIRE.COM
9 JulTop AI Agents Built to Catch Malicious Code Can Be Tricked Into Running ItAsk an AI coding agent to scan open-source code for security holes, and it might run the attacker's code on your own machine instead. That is the finding in a proof-of-concept published Wednesday by the AI Now Institute, an attack it calls "Friendly Fire." It works agai…THEHACKERNEWS.COM
9 JulMicrosoft patches RoguePlanet Defender zero-day vulnerabilityMicrosoft has released a security patch to address a Defender zero-day vulnerability known as "RoguePlanet," disclosed after the June 2026 Patch Tuesday. [...]BLEEPINGCOMPUTER.COM
9 JulOpen-source collaboration is growing worldwide and putting pressure on maintainersDevelopers are pushing code and opening pull requests across economy borders at a rate GitHub has rarely seen. Outbound collaboration, the sum of git pushes and pull requests sent from developers in one economy to public repositories in another, grew by 16% from Q4 2025 to Q1 202…HELPNETSECURITY.COM
9 JulLateral movement risk rises as enterprises emphasize convenience over containmentPoorly segmented networks and weak security controls continue to undercut security organizations’ ability to identify and contain attacks, giving attackers free rein after initial compromise, according to a recent study based on real-world enterprise security telemetry. Zero Netw…CSOONLINE.COM
9 JulCybercriminals Plant Malicious AI Agents in Open Source Tool RepositoriesCybersecurity researchers at ESET identify big rise in suspicious and malicious toolsets which put users at risk from cyber-attacksINFOSECURITY-MAGAZINE.COM
9 JulAssuranceAmerica data breach exposes records of 6.9 million driversAmerican insurance company AssuranceAmerica has disclosed a data breach impacting nearly 7 million drivers after attackers gained access to its systems earlier this year. [...]BLEEPINGCOMPUTER.COM
9 JulChrome 150 Update Patches 27 VulnerabilitiesThe security refresh resolves 13 use-after-free bugs, including two critical-severity flaws found by Google. The post Chrome 150 Update Patches 27 Vulnerabilities appeared first on SecurityWeek .SECURITYWEEK.COM
9 JulAI Coding Tools Tricked Into Hacking Developer Machine via Decades-Old TechniqueWiz has disclosed the details of a new AI coding assistant attack method it has dubbed GhostApproval. The post AI Coding Tools Tricked Into Hacking Developer Machine via Decades-Old Technique appeared first on SecurityWeek .SECURITYWEEK.COM
9 JulAgentic AI identity: A 6-stage maturity model for non-human identitiesIn a client engagement last year, an LLM-based deployment agent with standing access to a production Kubernetes cluster triggered a four-hour outage through a malformed configuration push. In the IAM, the agent appeared as a service account with a long-lived API key, no MFA, no s…CSOONLINE.COM
9 JulWhy fixing your data architecture matters more than upgrading your detection modelsSecurity leaders have been on a spending sprint. The global AI in cybersecurity market is valued at $44 billion in 2026 and is projected to reach $213 billion by 2034 , a trajectory that reflects genuine belief that machine learning will close the gap between the volume of threat…CSOONLINE.COM
9 JulPolice arrests 5,800 suspects in global anti-fraud crackdownLaw enforcement agencies have arrested 5,811 suspects and seized $293 million in illicit assets in a global anti-fraud operation spanning 97 countries. [...]BLEEPINGCOMPUTER.COM
9 JulAssuranceAmerica data breach exposed driver’s licenses of 7 million peopleAssuranceAmerica is notifying nearly 7 million people that hackers stole sensitive customer information, including driver's license numbers, following a cyberattack discovered in March. The incident affected 6.99 million individuals, making it the largest known exposure of Americ…CYBERINSIDER.COM
9 JulSecure self-hosted team chat platform Chatto goes open sourceGerman developer Hendrik Mans has released the source code for Chatto, a privacy-focused team messaging platform, making the project open source and available for anyone to self-host. The milestone fulfills a promise made when the project was first unveiled in late 2025 and opens…CYBERINSIDER.COM
9 Jul15-Year-Old Linux Vulnerability ‘GhostLock’ Earns Researchers $92k From GoogleAffecting every major distribution since 2011, the Linux kernel vulnerability allows attackers to gain root access. The post 15-Year-Old Linux Vulnerability ‘GhostLock’ Earns Researchers $92k From Google appeared first on SecurityWeek .SECURITYWEEK.COM
9 Jul5,811 arrests, $293 million seized over social engineering scamsCriminals who pose as police officers, romantic partners, and business suppliers have built fraud operations that reach across continents. A four-month enforcement campaign against these schemes wrapped up, and police in 97 countries and territories took part. Thousands of arrest…HELPNETSECURITY.COM
9 JulTwo arrests this week in unrelated crimes involved Japanese teenagers using ChatGPT to assist in their crimesThe Japan Times reports: An 18-year-old man has been arrested for his suspected involvement in a cyberattack on the operator of the Kaikatsu Club internet cafe chain, according to investigative sources. On Wednesday, the Metropolitan Police Department’s cybercrime countermeasure …DATABREACHES.NET
9 JulAttack on Amazon Bedrock-linked AI gateway highlights new cloud security riskA cloud intrusion that ended with the deployment of cryptomining malware has exposed a bigger risk for enterprises: AI gateways that concentrate access to cloud identities, permissions, and foundation models in a single, highly privileged system. Researchers from cybersecurity fi…CSOONLINE.COM
9 JulUK cyber agency unveils AI-powered Cyber Shield to counter attacks at machine speedThe UK’s National Cyber Security Centre (NCSC) wants to deploy autonomous AI agents capable of finding and neutralizing cyberattacks on national networks in real time, marking Britain’s push toward a sovereign, machine-speed cyber defense system. The blueprint, called Cyber Shiel…CSOONLINE.COM
9 JulOne Target, Two Flags | Rival Espionage Actors Converge On Pakistani Law EnforcementChina and India ran separate espionage operations against the same Pakistani police force, each drawn by different stakes in Pakistan's internal security.SENTINELONE.COM
9 JulMicrosoft fixes RoguePlanet zero-day in DefenderThe RoguePlanet zero-day is now fixed in Microsoft Defender. Here's how to make sure your system is protected.MALWAREBYTES.COM
9 Jul12 Million Impacted by Data Breach at Japanese Telco KDDIHackers exploited a zero-day vulnerability in a third-party system to access a KDDI email system for ISPs. The post 12 Million Impacted by Data Breach at Japanese Telco KDDI appeared first on SecurityWeek .SECURITYWEEK.COM
9 JulPalo Alto Networks Patches 13 VulnerabilitiesBuffer overflow, DoS, command injection, SSRF, authentication bypass, and other types of vulnerabilities have been found in PAN-OS software. The post Palo Alto Networks Patches 13 Vulnerabilities appeared first on SecurityWeek .SECURITYWEEK.COM
9 Jul764 splinter group leader sentenced to 40 years in jailAlexis Chavez coerced multiple girls to commit self harm and produce child sexual abuse material for notoriety in a sprawling violent extremist collective affiliated with the Com. The post 764 splinter group leader sentenced to 40 years in jail appeared first on CyberScoop .CYBERSCOOP.COM
9 JulThe Intercept’s Signal tipline username was hijacked for monthsThe Intercept has warned that its official Signal tipline username was compromised and used by an impersonator to pose as the investigative news outlet, potentially exposing confidential sources who attempted to submit sensitive information. Dr. Martin Shelton, of the Freedom of …CYBERINSIDER.COM
9 JulGhostApproval flaw exploits trust in major AI coding assistants.Interpol operation cracks down on social engineering scams. Chinese APT exploits Roundcube flaws to target US and Canadian universities.THECYBERWIRE.COM
9 JulThreatsDay: Cloud Bucket Hijacking, Windows LPE Chain, Global Fraud Bust + 17 More StoriesMost security mess starts as admin work. A link gets clicked. A tool gets trusted. A bucket name gets reused. A setting stays loose because nobody wants to touch it. This week is full of that kind of damage. Not loud. Not clever. Just small gaps doing big jobs. The worst par…THEHACKERNEWS.COM
9 JulWiz in the Verizon DBIR: How AI Acceleration and Cloud Sprawl Impact Modern DefenseVerizon's latest DBIR highlights how attackers are exploiting familiar weaknesses at increasing speed and scale. Here's what Wiz research reveals about vulnerabilities, trust relationships, and AI in modern cloud environments.WIZ.IO
9 JulWho you gonna call?GhostApproval puts AI coding assistants under the microscope. Microsoft fixes the RoguePlanet zero-day. More than 70 cybersecurity firms back a new AI Charter. An Ohio county may have paid a $1 million ransom. AssuranceAmerica discloses a breach affecting nearly seven million peo…THECYBERWIRE.COM
9 JulIran's Cyber Crosshairs Focus Beyond Critical InfrastructureObscurity isn't a defense. If your company has any Internet-facing vulnerability, you're at risk from multiple threats.DARKREADING.COM
9 JulMicrosoft Reins in RoguePlanet Zero-Day ThreatThe researcher known as "Nightmare-Eclipse" published a proof-of-concept (PoC) exploit for the Windows Defender vulnerability in early June after dropping several other Microsoft zero-days.DARKREADING.COM
9 JulWolfSSL, GeoVision, VTK vulnerabilitiesCisco Talos’ Vulnerability Discovery & Research team recently disclosed three vulnerabilities in WolfSSF, fourteen in GeoVision, and one vulnerability in VTK-DICOM. The vulnerabilities mentioned in this blog post have been patched by their respective vendors, in adhere…TALOSINTELLIGENCE.COM
9 JulAI coding tool hole illustrates a big problem with human in the loopA security hole within AI dev tools has allowed attackers to escape sandboxes by misleading the humans in the loop who were supposed to knowingly approve the tool’s actions, according to cybersecurity research firm Wiz. “We discovered GhostApproval, a systematic vulnerability pat…CSOONLINE.COM
9 JulWhen Your Smart Vacuum DiesMany smart home devices depend on cloud services to function. When manufacturers discontinue products or shut down those services, expensive hardware can lose key features—or stop working entirely. Open-source alternatives offer a different model. By running locally and avoiding …YOUTUBE.COM
9 JulINTERPOL Operation First Light Nets 5,811 Arrests and Seizes $293 MillionINTERPOL’s Operation First Light 2026 led to 5,811 arrests, blocked $293M in criminal assets, and disrupted global fraud and money laundering networks. INTERPOL coordinated a four-month operation across 97 countries and territories that ended with 5,811 arrests and the inte…SECURITYAFFAIRS.COM
8 Jul20 open-source cybersecurity tools to keep your team ready for anythingAI is changing how security teams find vulnerabilities, analyze code, test applications, and protect infrastructure. Developers are building tools to secure AI systems themselves, from coding agents and memory protection to model exposure discovery. This roundup covers recent ope…HELPNETSECURITY.COM
8 JulRisky Bulletin: DHS IG investigates forced CISA reassignmentsThe DHS inspector general will investigate forced CISA reassignments, Canada hacked a ransomware gang, Taiwan charges two executives with helping Chinese hackers, and new vulnerabilities can disable Hoymiles solar panels.RISKY.BIZ
8 Jul13 in-demand IT security certifications for higher payWith change a constant, cybersecurity professionals looking to improve their careers can benefit from the latest insights into employers’ needs. Data from Foote Partners on the skills and certification most in demand today may provide helpful signposts. Analyzing more than 660 ce…CSOONLINE.COM
8 Jul KEVCISA orders feds to patch max severity ColdFusion flaw by FridayThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered government agencies to patch an actively exploited maximum-severity flaw in the Adobe ColdFusion commercial web app development platform by Friday. [...]BLEEPINGCOMPUTER.COM
8 JulMy threat feed told me it was ‘Chalubo.’ The binary disagreedI’ve spent two years doing incident response and threat intel, and the one habit I’d keep if I had to give up every other is also the most boring. I don’t act on a piece of intelligence until I’ve checked it against the thing it claims to describe. It’s slow. It’s tedious. Almost…CSOONLINE.COM
8 JulWhy AI Just Broke Traditional IT Security as Leaders Clash Over AI's Value and Hiring - BSW #455The latest generation of AI models has collapsed the time from vulnerability discovery to weaponized exploit from weeks to minutes, and reactive, module-based tools built around static dashboards simply can't keep up. In this episode, Tanium COO Matt Quinn joins Business Security…YOUTUBE.COM
8 JulFound fast, fixed slow: The gap the AI clearinghouse must closeThe government's new AI clearinghouse risks becoming a committee that discovers more problems than it solves — unless it's designed around patching, not just scanning. The post Found fast, fixed slow: The gap the AI clearinghouse must close appeared first on CyberScoop .CYBERSCOOP.COM
8 JulUbiquiti warns of new max severity UniFi OS vulnerabilityUbiquiti has released security updates to patch seven critical vulnerabilities in UniFi OS, including a maximum-severity flaw that can be exploited in command injection attacks. [...]BLEEPINGCOMPUTER.COM
8 JulCISA Deploys Anthropic’s Mythos AI to Hunt Vulnerabilities in U.S. Government CodeCISA is using Anthropic’s Mythos AI to scan federal code for vulnerabilities, aiming to find flaws before hackers and foreign intelligence services. Three sources familiar with the matter told Reuters that CISA, the U.S. government’s civilian cyber defense agency, is …SECURITYAFFAIRS.COM
8 Jul KEVCISA orders feds to prioritize patching Langflow auth bypass flawThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) gave federal agencies until Friday to patch an actively exploited vulnerability in the Langflow visual framework for building AI agents. [...]BLEEPINGCOMPUTER.COM
8 JulCrusoe brings serverless fine-tuning to AI model developmentCrusoe has announced Serverless Fine-Tuning and Self-Serve Deployments in Crusoe Intelligence Foundry, the managed AI platform for Crusoe Cloud. These capabilities give data scientists and ML engineers a complete path from proprietary data to production-ready models, on purpose-b…HELPNETSECURITY.COM
8 JulNew Bit2Watt attack uses AI GPU workloads to destabilize power gridsA new cyber-physical attack called Bit2Watt uses carefully crafted GPU workloads to manipulate a data center's power consumption in ways that interfere with modern electricity infrastructure. While the work is primarily a proof-of-concept supported by simulations and laboratory e…CYBERINSIDER.COM
8 JulCritical Vulnerability Exposes GitHub Agentic Workflows to Prompt InjectionResearchers show how attackers can use a crafted public GitHub Issue to trick AI-powered workflows into exposing data from private repositories without authentication. The post Critical Vulnerability Exposes GitHub Agentic Workflows to Prompt Injection appeared first on SecurityW…SECURITYWEEK.COM
8 JulCybercriminals exploit India’s tax filing season with a dual-malware campaignCybercriminals are exploiting India’s tax filing season with a new malware campaign that refuses to put all its eggs in one basket. Researchers at Cyderes have uncovered a sophisticated phishing operation that poses as the Indian Tax Department to deliver two remote access trojan…CSOONLINE.COM
8 JulMutation testing comes to DAMLIn April we released Mewt , our open-source mutation-testing engine that finds the gaps in your test suite. Today we’re expanding it with support for DAML, the language Canton Network applications are written in. Mewt now reads DAML, generates several classes of mutants (includin…TRAILOFBITS.COM
8 JulAccenture acknowledges security incident following 35GB data theft claimAccenture appears to have suffered a data breach, the extent of which is currently unknown. On Monday, a threat actor going by the handle “888” posted on the cybercrime forum PwnForums, claiming to have breached the technology consulting company and stolen “just…HELPNETSECURITY.COM
8 JulFelons, Fraudsters Flog Offensive Cybersecurity StartupA cybersecurity startup dangling millions of dollars to acquire zero-day security vulnerabilities in popular software is run by a pair of far-right conspiracy theorists and convicted felons whose most recent ventures included fake intelligence companies and a now-defunct AI-based…KREBSONSECURITY.COM
8 JulGitHub AI agent leaks private repositories via prompt injection attackA prompt injection attack can trick GitHub’s preview Agentic Workflows into retrieving content from private repositories and publishing it publicly, exposing a broader risk as enterprises deploy AI agents with privileged access to software development environments, according to n…CSOONLINE.COM
8 JulGoogle Dialogflow CX Bug Allowed Attackers to Hijack AI ConversationsThe "Rogue Agent" vulnerability could have enabled attackers to silently manipulate AI conversations, exfiltrate data, and compromise every Dialogflow CX agent within the same Google Cloud project. The post Google Dialogflow CX Bug Allowed Attackers to Hijack AI Conversations app…SECURITYWEEK.COM
8 Jul"Good Enough" Patching Is OverFor years, many organizations relied on fixed patching schedules, accepting 60-day, 90-day, or even annual update cycles as "good enough." That assumption is becoming harder to defend. As AI speeds up vulnerability discovery and attackers move faster, security teams face increasi…YOUTUBE.COM
8 JulSecurity Teams Are Ready To Become More Preemptive. What’s Holding Them Back?The shift toward preemptive security is underway, but most organizations are still navigating the realities of limited resources, fragmented tools, and emerging AI risk. At Rapid7’s recent Global Security Summit , we surveyed attendees to better understand where security leaders …RAPID7.COM
8 JulAccenture faces massive data breach that could put clients at riskThe threat actor claiming responsibility says they stole source code, encryption keys and more.CYBERSECURITYDIVE.COM
8 JulPatients Sue Healthcare Corporations Over Data Breaches, Sharing of Personal InformationMikeie Honda Reiland reports: A suite of recent class action lawsuits in state and federal courts seeks to hold large healthcare corporations accountable for exposing or leaking patients’ personally identifiable information (PII) and protected health information (PHI). On June 11…DATABREACHES.NET
8 JulWhy Bangladesh’s new data protection law may fail to protect your dataMeem Arafat Manab reports: On August 19, 2025, hackers broke into Shwapno’s customer database. They took 410 gigabytes of data: the names, phone numbers, and purchase histories of forty lakh registered customers. They demanded $1.5 million. Shwapno refused, secured its systems, a…DATABREACHES.NET
8 JulAttackers Won't Wait for Patch TuesdayOrganizations continue to be compromised through vulnerabilities that have been known and exploited for years. At the same time, the time between vulnerability disclosure and active exploitation continues to shrink. Traditional patching cycles and lengthy change approval processe…YOUTUBE.COM
8 JulAccenture Confirms Data Breach After Hacker Claims Source Code TheftThe professional services giant says it contained the incident, remediated its source, and experienced no operational or service delivery impact. The post Accenture Confirms Data Breach After Hacker Claims Source Code Theft appeared first on SecurityWeek .SECURITYWEEK.COM
8 JulHackers exploit Roundcube flaw to spy on academic researchersA China-linked threat cluster has been exploiting vulnerable Roundcube servers at U.S. and Canadian universities to steal credentials and deploy backdoor malware. [...]BLEEPINGCOMPUTER.COM
8 JulUniondale Union Free School District – Audit Follow-Up by New York State Comptroller (2023M-61-F)In October 2023, NYS Comptroller Thomas DiNapoli released an IT audit of the Uniondale Union Free School District on Long Island. The purpose of the audit was to examine management of non-student user network controls. The audit report found, in part: District officials did not a…DATABREACHES.NET
8 JulA Hacker Claims 35 GB of Accenture Source Code. The Company discloses the data breachAccenture confirmed a breach after a hacker claimed to steal 35 GB of source code, keys, and Azure credentials now offered for sale. A threat actor using the handle “888” claimed on the cybercrime forum PwnForums this week to have stolen 35 gigabytes of data from Acce…SECURITYAFFAIRS.COM
8 JulAzure you concerned?Accenture confirms a data breach. An Australian telecom investigates a nationwide outage. It’s shields up for the UK. CISA eyes September for its critical infrastructure reporting rule. NewsJunkie fakes CTV ad traffic. Agentic AI triggers EDR. CISA taps Mythos for vulnerability s…THECYBERWIRE.COM
8 JulLone Attacker Uses AI to Breach AWS Cloud Environment in 72 HoursThe attacker exploited AI workflows, chained cloud weaknesses, and stolen credentials to extort a large Amazon customer.DARKREADING.COM
8 JulGitHub’s public APIs are becoming an enterprise reconnaissance toolGitHub continues to be a scintillating target for attackers because it sits in the middle of the software supply chain and gives threat actors three things they crave: source code, secrets, and automated pipelines to run amok in. Datadog Security Research has been tracking what i…CSOONLINE.COM
7 JulZscaler finds autonomous agents succumb to IPI trapsIn a test of major LLMs, Zscaler found that some autonomous AI agents fell victim to frauds, reinforcing how easily some high-end enterprise agents can be conned by schemes that would fool few, if any, humans. The security vendor looked at various forms of indirect prompt injecti…CSOONLINE.COM
7 JulCybersecurity jobs available right now: July 7, 2026Application Security Lead Gett | Israel | Hybrid – View job details As an Application Security Lead, you will lead application and cloud security initiatives by integrating security into the SDLC, overseeing threat modeling, secure architecture, application securi…HELPNETSECURITY.COM
7 JulApple Container: Open-source tool for Linux containers on the MacDevelopers on Apple silicon Macs have run Linux containers through software built around a single shared virtual machine for years. Apple’s open-source Container project gives each Linux workload its own lightweight virtual machine. Container is written in Swift and tuned f…HELPNETSECURITY.COM
7 JulMicrosoft wants to keep your AI agents from going rogueMicrosoft has introduced Microsoft Execution Containers (MXC), a cross-platform, policy-driven execution layer for AI agents on Windows and Windows Subsystem for Linux (WSL), now available in early preview. Updated Agent 365 platform (Source: Microsoft) Developers can define cons…HELPNETSECURITY.COM
7 JulPower shortages could slow AI data center expansionAI adoption is increasing demand for data center capacity at the same time operators are running into limits around power, equipment, land, and permitting, according to NTT Data. Access to electricity is becoming a deciding factor in where new data centers are built, when new cap…HELPNETSECURITY.COM
7 Jul176: NSLOne day Nick got a visit from the FBI demanding he give them data on one of his customers. They asked for it in the form of a National Security Letter or NSL. Something wasn’t right about this letter. It seemed to violate the constitution. So he set out to change the law. Learn m…DARKNETDIARIES.COM
7 JulJanuscape: 16-Year-Old Linux KVM Bug Enables Cloud VM Escape AttacksJanuscape: A 16-year-old Linux KVM flaw lets cloud VM tenants crash hosts and potentially escape guests. It affects Intel and AMD systems. Security researcher Hyunwoo Kim has published details of a use-after-free vulnerability in Linux’s KVM hypervisor that allows code runn…SECURITYAFFAIRS.COM
7 JulSuspected Chinese espionage group used a Roundcube exploit chain to burrow into universitiesProofpoint researchers said attackers targeted physics and engineering departments, and warn that the campaign is likely ongoing. The post Suspected Chinese espionage group used a Roundcube exploit chain to burrow into universities appeared first on CyberScoop .CYBERSCOOP.COM
7 JulHackers Exploit Maximum Severity Adobe ColdFusion FlawThreat actors are exploiting an Adobe ColdFusion vulnerability which has a CVSS score of 10.0INFOSECURITY-MAGAZINE.COM
7 JulWhy The Gentlemen ransomware is a test of identity and recovery controlsThe Gentlemen ransomware underscores a challenge many CISOs face: stopping attackers after they gain an initial foothold. Researchers say the malware can spread across enterprise networks using legitimate Windows management tools while simultaneously attempting to weaken security…CSOONLINE.COM
7 JulThe modern CISO is becoming the next CFOAt some point, every security leader gets asked a version of the same question: Are we good? It tends to arrive when something is at stake and the person asking needs to know they can rely on the answer. I learned what that question really means at a firm I was with earlier in my…CSOONLINE.COM
7 JulDefense-in-depth strategies for securing mobile applications - Ryan Lloyd - ASW #390Mobile applications have unique risks and threat models compared to server-side applications and infrastructure. Consequently, they need different strategies to ensure their business logic and workflows well secured. We'll dive into some of these defense-in-depth strategies and w…YOUTUBE.COM
7 JulThreat landscape for industrial automation systems. Q1 2026This report contains industrial threat statistics for Q1 2026, including industrial threat distribution by type, source, region and industry.SECURELIST.COM
7 JulLinux Kernel Vulnerability Allows VM Escape on Intel and AMD SystemsThe 16-year-old Januscape flaw affects Linux's KVM hypervisor, allowing attackers to escape virtual machines and potentially execute code on the underlying host. The post Linux Kernel Vulnerability Allows VM Escape on Intel and AMD Systems appeared first on SecurityWeek .SECURITYWEEK.COM
7 JulWhat Changes When Your Software Supply Chain Includes AI Writing Your Code?Software supply chain security was hard enough. Then AI joined the build pipeline. For five years, "software supply chain security" meant one question: what's in your code? Which open-source packages, which versions, which transitive dependencies three layers deep that nobody cho…THEHACKERNEWS.COM
7 JulNew Januscape Linux flaw allows VM escape on Intel, AMD devicesA 16-year-old Linux kernel vulnerability, dubbed Januscape, allows attackers to escape a virtual machine and execute arbitrary code on the host. [...]BLEEPINGCOMPUTER.COM
7 JulCommvault measures cyber recovery readiness with AI attack simulationsCommvault has announced Commvault Minutes to Recovery, a scenario-driven cyber resilience simulation that lets participants act as a hacker and run their own attacks using frontier AI tools. Then, participants are challenged to defend against and recover from an incident under pr…HELPNETSECURITY.COM
7 JulCourt Filing Reveals Windows Device ID Helped FBI Trace Alleged Scattered Spider HackerU.S. prosecutors linked an alleged Scattered Spider hacker to a break-in at a luxury jewelry retailer using a persistent Windows device ID, according to a newly unsealed federal complaint. Microsoft records tied that ID first to the account the attackers used to keep access durin…THEHACKERNEWS.COM
7 JulWriter AI Flaw Could Let Agent Previews Leak Session Tokens Across TenantsCybersecurity researchers have disclosed details of a now-patched critical session isolation vulnerability in Writer, an enterprise generative artificial intelligence (AI) platform, that could result in cross-tenant compromise. The one-click vulnerability has been codenamed Write…THEHACKERNEWS.COM
7 JulBojangles sued again by workers over Russian hacker data breach. NC judge weighs inChase Jordan reports an update in the litigation stemming from a 2024 breach by Hunters International. This case has raised a number of issues about standing and negligence and has been up and down in the courts, with plaintiffs seeming to fare better in state court: A class-acti…DATABREACHES.NET
7 JulJacksonville, Texas, keeps some city systems offline after cyber incidentDysruptionHub reports: Jacksonville, Texas, took some city systems offline after detecting suspicious network activity Friday, leaving some online services unavailable Monday as officials investigated a cybersecurity incident. The city said it detected the activity July 3 and lat…DATABREACHES.NET
7 JulCERT/CC warns of an unpatched backdoor affecting Tenda routers.Maximum-severity ColdFusion flaw is under active exploitation. Canadian intelligence agencies hacked criminal groups.THECYBERWIRE.COM
7 JulSuspected Chinese Threat Group Targets Universities via Vulnerable Roundcube ServersA suspected Chinese threat cluster is exploiting Roundcube vulnerabilities to compromise university networks in the US and Canada and harvest user credentialsINFOSECURITY-MAGAZINE.COM
7 JulSophisticated threat campaign pushes Cisco to the very edgeA monthslong exploitation wave against Cisco SD-WAN systems raises larger questions about trust and the insecurity of network infrastructure.CYBERSECURITYDIVE.COM
7 JulOMB M-26-14: Why federal agencies must fix asset visibility firstThe new OMB logging directive raises the bar on log collection and explicitly ties every maturity milestone to how well agencies know what’s on their networks. Learn why asset visibility is the first problem to solve. Key takeaways M-26-14 rescinds M-21-31 and replaces blanket da…TENABLE.COM
7 JulEnforce zero data retention on Amazon Bedrock with Bedrock Projects and service control policiesWith the introduction of models that require data sharing with third-party providers—such as Claude Fable 5—organizations need a way to centrally enforce data retention policies. Amazon Bedrock gives you control over whether your prompts and model outputs are retained after an in…AWS.AMAZON.COM
7 JulChinese hackers develop LONGLEASH malware to expand ORB networkChinese hackers tracked as 'UAT-7810' are actively evolving their malware to expand their Operational Relay Box (ORB) network by compromising internet-facing networking devices, primarily unpatched Ruckus routers. [...]BLEEPINGCOMPUTER.COM
7 JulWhy Streaming Apps Protect ContentFor streaming platforms, the most security-sensitive asset is often the content itself. Licensing agreements require providers to protect movies, shows, and live events from unauthorized distribution. Technologies like DRM and digital watermarking help enforce those protections a…YOUTUBE.COM
7 Jul KEVWelcome home, hacker.CERT/CC warns of an unpatched Tenda router backdoor. Adobe races to patch an actively exploited ColdFusion flaw. Canada pulls back the curtain on offensive cyber operations. Anthropic quietly removes hidden tracking from Claude Code. Chinese AI gains momentum as U.S. providers sw…THECYBERWIRE.COM
7 JulAccenture confirms breach after hacker offers stolen data for saleIT services giant Accenture has confirmed it suffered a security breach after a threat actor claimed to have stolen 35 GB of source code and other data from the company. [...]BLEEPINGCOMPUTER.COM
7 JulWashington Dept. of Social and Health Services announces massive data breachKIRO7 reports: The Washington Department of Social and Health Services (DSHS) is issuing a notice of a massive data breach that happened in March, potentially compromising the personal data of around 8,600 people. An internal investigation revealed that a former DSHS employee acc…DATABREACHES.NET
7 JulSN 1086: The Apex Agentic Adversary - Visual Prompt Injection StrikesFrom the sudden retirement of Internet pioneer Vint Cerf to the unstoppable advance of "apex agentic adversaries," get a front-row seat to the unfolding security revolution and its massive real-world stakes. Why Fable5's re-release has disappointed. Opera becomes the first browse…TWIT.TV
6 JulThe future of payment fraud could be automatedPayment fraud is becoming more organized as criminal groups use fake websites, large-scale operations, and, in some cases, forced labor to steal money and personal information. Advances in agentic AI could automate many stages of payment fraud, from collecting and assembling stol…HELPNETSECURITY.COM
6 JulFlipper Zero firmware development gets a fresh set of community rulesOwners of the Flipper Zero, the pocket-sized wireless testing tool, spent recent weeks worried that its official firmware had gone quiet. Pavel Zhovner, CEO of Flipper Devices, moved to settle that concern with word that the company has set aside staff to keep the firmware mainta…HELPNETSECURITY.COM
6 JulRisky Bulletin: EU official’s phone infected with PegasusA European MP’s phone was infected by Pegasus spyware, Android drops its PIN guessing limit from 1,800 attempts to 20, Alibaba bans employees from using Claude at work, and there’s a new vulnerability in the Linux kernel.RISKY.BIZ
6 JulSecuring the inbox: Where identity, brand and security meetGetting a verified logo to appear next to your email has traditionally meant having to work with two separate entities. You have to work with a DMARC partner for setting up DMARC and BIMI, then use a trusted Certificate Authority (CA) to purchase a Mark Certificate, and this mean…HELPNETSECURITY.COM
6 JulOmnigent: Open-source AI agent framework and meta-harnessPlenty of developers now keep several coding agents close at hand, reaching for Claude Code on one task and Codex or Cursor on the next. Each tool arrives with its own command line, its own handling of credentials, and its own way of running shell commands against a working direc…HELPNETSECURITY.COM
6 Jul7 cyber risk assessment gotchas to avoidA cyber risk assessment helps security teams identify, estimate, and prioritize potential threats and vulnerabilities to key enterprise digital and physical assets. Yet, despite its importance, many CISOs fall victim to several types of “gotchas” that prevent them from fully achi…CSOONLINE.COM
6 JulAI isn’t closing the skills gap — it’s exposing the validation gapIf you wanted to become a basketball star, how would you get started? You wouldn’t read a book on basketball and take an online course. You’d set up a hoop in your driveway, join a local team to train, and play in real matches. So why do we expect cybersecurity professionals to l…CSOONLINE.COM
6 JulFinding vulnerabilities was never the hard partAI is surfacing vulnerabilities at a scale the industry has never seen, and most organizations have no way to determine which ones actually matter. The post Finding vulnerabilities was never the hard part appeared first on CyberScoop .CYBERSCOOP.COM
6 JulNCA Issues Warning to Parents As Shared Child Photos Exploited by AI ToolsIWF and NCA warn that growing numbers of images and videos are being manipulated into sexual abuse materialINFOSECURITY-MAGAZINE.COM
6 JulSingle points of failure fail. The SaaS layer is not an exceptionHigher education has consolidated its entire academic operation into a handful of massive SaaS platforms. The LMS manages instruction, grading and communication. The SIS owns enrollment, records and financial aid. Identity and productivity live in a small number of cloud provider…CSOONLINE.COM
6 JulMastering agent permissions and Identiverse interviews - ESW #466Interview with Sandy Bird, co-founder of Sonrai Security In this week's interview, we kick off the conversation with how Sonrai's expertise in securing cloud identity permissions had the company well placed to address the explosion of AI agents and the clear risks they represente…YOUTUBE.COM
6 JulFrance to Stop Certifying Non-Quantum-Safe EncryptionFrance is accelerating its transition to post-quantum encryption: France’s cybersecurity agency ANSSI said on Tuesday it would stop certifying security products that lack quantum-resistant encryption, a move that will force government bodies and critical operators to shift …SCHNEIER.COM
6 JulPrompt Injection Attacks Trick AI Agents Into Making Crypto PaymentsResearchers uncovered two campaigns embedding indirect prompt injections in malicious websites to exploit autonomous AI agents browsing the web. The post Prompt Injection Attacks Trick AI Agents Into Making Crypto Payments appeared first on SecurityWeek .SECURITYWEEK.COM
6 JulSeven Bugs in FatFs Put IoT and Embedded Devices at RiskrunZero found 7 flaws in FatFs, a filesystem used in IoT and embedded devices. Bugs can cause memory corruption, crashes, or data leaks via crafted storage. Cybersecurity firm runZero has disclosed seven vulnerabilities in FatFs, a compact open-source library that lets embedded d…SECURITYAFFAIRS.COM
6 JulProof-of-Concept Exploit Released for Linux ‘Bad Epoll’ Root Access VulnerabilityOrganizations are urged to patch after proof-of-concept code makes the Linux root escalation flaw easier to exploit. The post Proof-of-Concept Exploit Released for Linux ‘Bad Epoll’ Root Access Vulnerability appeared first on SecurityWeek .SECURITYWEEK.COM
6 Jul⚡ Weekly Recap: Proxy Botnets, Browser Ransomware, AI Agent Tricks, Fake PoC Malware and MoreA streaming box should not need a threat model. Neither should a username field, a demo repo, a reset flow, or a browser permission prompt. That is the irritating part this week: the risky pieces were ordinary. Home devices became a routing cover. Clean code pulled dirt from a de…THEHACKERNEWS.COM
6 JulNorth Korean Hackers Target Open Source Developers in Supply Chain AttacksThe PolinRider campaign has compromised more than 100 legitimate open source packages and repositories to deliver a backdoor and information stealer to developers. The post North Korean Hackers Target Open Source Developers in Supply Chain Attacks appeared first on SecurityWeek .SECURITYWEEK.COM
6 JulCriminal IP integrates threat intelligence with OpenCTI for automated indicator enrichmentCriminal IP has integrated its threat intelligence with OpenCTI, enabling security teams to automatically convert IP addresses, domains, and URLs into structured intelligence within the platform’s knowledge graph. The integration automatically enriches ingested indicators w…HELPNETSECURITY.COM
6 JulLTM’s BlueVerse RightLogic combines AI risk assessment with cyber remediation planningLTM has launched BlueVerse RightLogic, a cybersecurity assessment and risk assurance framework designed to help enterprises identify, assess and remediate cyber exposure as they accelerate AI adoption. AI is now capable of autonomously identifying and exploiting vulnerabilities, …HELPNETSECURITY.COM
6 JulA Day With Your Vector Command Red Team PodAnyone trying to understand continuous red teaming usually gets the same high-level explanation: it is ongoing, attacker-informed, and designed to uncover risk between formal assessments. Useful as that description is, it still leaves most people with the same question, which is …RAPID7.COM
6 JulAlberta, Centurion Project sued over alleged data breach that affected millions of votersCarrie Tait reports: A retired lawyer is suing Alberta, its Chief Electoral Officer and two organizations that support secession for their respective roles in an alleged data breach affecting 2.9 million residents in the province. Clint Docken, a former class-action lawyer, last …DATABREACHES.NET
6 JulCanadian spy agency says it hacked drug traffickers, extremists and a ransomware gang last yearThe hacking operations disclosed in a Canadian spy agency's annual report underscores some pressing national security threats facing the country and its top allies.TECHCRUNCH.COM
6 JulThe agentic blind spots in your zero trust programStephen Wilson, field chief technology officer for HashiCorp, an IBM company, likens AI agents to “really smart kindergartners.” “They know how to do something, but they have no clue as to why they should do it,” Wilson says. This combination of superior execution power and lack …CSOONLINE.COM
6 JulIdentity: The operational control plane for agentic AIExisting security controls weren’t designed for AI agents. Static credentials and standing privileges aren’t sufficient for an emerging model where organizations need to rapidly authorize, limit, and revoke permissions from autonomous agents, sometimes more than once within a sin…CSOONLINE.COM
6 JulEnforce least-privilege authorization in multi-agent AI chains using CedarIf you’re building multi-agent AI systems, you need to prevent authorization scope from silently expanding as agents delegate tasks through multi-hop chains. Without proper controls, an agent can potentially act beyond what the originating user authorized, even when role-based ac…AWS.AMAZON.COM
6 JulJapanese teen arrested over cyberattack that disrupted anime streaming serviceThe unnamed student, who lives in a city near Tokyo, allegedly exploited a flaw in a subscription-based anime streaming platform to fraudulently cancel more than 46,000 user subscriptions.THERECORD.MEDIA
6 JulJadePuffer: The First Complete LLM-Driven Ransomware AttackAn "agentic threat actor" successfully exploited a Langflow flaw to steal data from a production database server and encrypt other systems.DARKREADING.COM
6 JulGoogle Chrome extensions must meet new privacy standards by August 1Google has announced a set of Chrome Web Store policy changes that tighten rules around extension data collection, improve transparency requirements, and prohibit new categories of software. The updated Developer Program Policies will take effect on August 1, 2026, giving extensi…CYBERINSIDER.COM
6 JulNetNut gets cracked.The FBI disrupts a major residential proxy service. Attackers exploit Fortinet firewalls to target UK officials. European lawmakers call for a spyware investigation. A new macOS infostealer masquerades as a clipboard manager. Prompt injection campaigns targeting AI agents through…THECYBERWIRE.COM
6 JulCitrixBleed-ing Again? NetScaler Vulnerability Under AttackAttackers wasted little time targeting the latest memory disclosure flaw in Citrix's NetScaler products, after researchers published a proof-of-concept exploit (PoC).DARKREADING.COM
6 JulThe “Anonymous” Tip System That Wasn’t: Three Months Later, Why Hasn’t Navigate360 Notified Anyone?Trigger Warning: This post includes content from tips submitted to anonymous tiplines by or about students. While identity information is redacted, tips may include obscenities and explicit references to sexual abuse, rape, assault, self-harm, violence, suicidal ideation, pornogr…DATABREACHES.NET
5 JulWeek in review: SimpleHelp vulnerability exploited, Oracle EBS Payments flaw under attackHere’s an overview of some of last week’s most interesting news, articles, interviews and videos: Companies keep bolting AI onto their products, and the security bill is coming due Companies keep bolting AI and LLM features onto their products, and the security results are starti…HELPNETSECURITY.COM
5 JulNew ClamAV security patch closes seven scanner bugs dating back two decadesOpen source antivirus scanning sits inside mail gateways, file upload checks, and endpoint tooling at organizations of every size. Much of that work runs through ClamAV, the scanning engine maintained by Cisco’s Talos group. The project released two patch versions, 1.5.3 an…HELPNETSECURITY.COM
4 JulUnpatched Flaws Disclosed in Filesystem Bundled Into Millions of Embedded DevicesSecurity firm runZero has disclosed seven vulnerabilities in FatFs, a small filesystem library that lets a device read and write the FAT and exFAT formats used on USB drives and SD cards. The flaws matter because FatFs is nearly everywhere. It ships inside the firm…THEHACKERNEWS.COM
4 JulAdaptHealth says attackers sweet-talked their way into cloud systems and stole patient dataConnor Jones reports: AdaptHealth says attackers used social engineering to breach its systems and steal sensitive patient data, including passwords associated with insurance billing. The medical equipment company disclosed the attack to the Securities and Exchange Commission (SE…DATABREACHES.NET
3 JulTeams battles bots, Bioshocking AI browser guardrails, Fortibleed fuels ransomwareTeams cracks down on meeting bots, AI guardrails get bypassed, FortiBleed fuels ransomware, and Nissan confirms PeopleSoft breach Microsoft rolls out a new Teams admin policy, "Manage External Bots and Their Access to Meetings," to detect third‑party bots, hold them in the lobby …CYBERSECURITYTODAY.LIBSYN.COM
3 JulOrganizations struggle to prioritize known cyber risksOrganizations collect more cyber risk data than ever, with many still struggling to build a unified view of their exposure. The latest State of Threat Management report from Filigran found that security teams continue to work across disconnected tools, leaving important context s…HELPNETSECURITY.COM
3 JulCritical Cursor AI Code Editor Flaws Could Lead to OS-Level Remote Code ExecutionThe DuneSlide vulnerabilities enable zero-click prompt injection attacks that escape Cursor's sandbox and execute arbitrary code on the underlying operating system. The post Critical Cursor AI Code Editor Flaws Could Lead to OS-Level Remote Code Execution appeared first on Securi…SECURITYWEEK.COM
3 JulPamStealer Uses Fake Maccy Sites and PAM Checks to Steal Mac Login PasswordsCybersecurity researchers have flagged a new macOS information stealer called PamStealer that employs a series of clever tricks to infect systems and siphon sensitive data. The stealer, discovered by Jamf Threat Labs, is distributed as a compiled AppleScript (.scpt) file imperson…THEHACKERNEWS.COM
3 JulLaw enforcememt operation disrupted Malicious Residential Proxy Networks NetNutGoogle disrupted NetNut, a major proxy network that routed internet traffic through compromised home devices used by cybercriminals. Google has disrupted NetNut, one of the world’s largest residential proxy networks. The service routed internet traffic through home devices,…SECURITYAFFAIRS.COM
3 JulAgentic AI Used to Conduct Ransomware Attack via LangflowAttack demonstrates how LLM agents can combine known exploitation techniques with real-time reasoning to automate complex, multi-stage intrusions. The post Agentic AI Used to Conduct Ransomware Attack via Langflow appeared first on SecurityWeek .SECURITYWEEK.COM
3 JulFlock Cameras Can Surveil Cars Without License PlatesThis is from a 2024 company presentation : Officers can also tap into data showing a car’s decals, bumper stickers, back and top racks—along with temporary and unique state tags. Flock calls it a “Vehicle Fingerprint” and it’s touted as a way for law…SCHNEIER.COM
3 JulThe Anatomy of a Shadow AI Supply-Chain Breach: Lessons from the 2026 Vercel IncidentVercel breach happened after an employee used an unvetted AI tool. Attackers exploited it as a trusted link to access systems, steal data, and extort $2M. The Vercel breach of April 2026 did not begin with a classic zero-day exploit, a misconfigured cloud bucket, or a sophisticat…SECURITYAFFAIRS.COM
3 JulJADEPUFFER: First End-to-End AI-Driven Ransomware OperationSysdig reports an AI agent ran a full ransomware attack end-to-end, exploiting flaws, stealing creds, moving laterally, and encrypting data without humans. Sysdig’s Threat Research Team has documented what it assesses to be the first ransomware operation driven end-to-end b…SECURITYAFFAIRS.COM
3 JulVerified X ad spreads Mac malware, while ConsentFix steals Microsoft accountsTwo new campaigns show how cybercriminals are increasingly relying on social engineering instead of software exploits to compromise devices and accounts.MALWAREBYTES.COM
3 JulHK: Shun Hing Group data breach affects 920,000 customers, 1.05m files encrypted in cyber attackErwin Wong reports: Shun Hing Group has confirmed that its computer systems were compromised by hackers in March, resulting in a significant data breach affecting customers and staff. Founded in 1953 by the late Dr William Mong, Shun Hing Group has grown into a leading and divers…DATABREACHES.NET
3 JulAdobe premieres a second Patch Tuesday each month to deliver fixes fasterAdobe will now issue security patches for its products twice as often to deal with the increasing pace of software vulnerability discovery and exploitation. This follows Oracle’s decision to increase its quarterly patch program to a monthly one. Adobe issues patches on the second…CSOONLINE.COM
3 JulEveryone Owns Security—Or Nobody DoesMany e-commerce sites rely on multiple third-party providers for hosting, application development, payment processing, JavaScript, and other core functions. That convenience creates a shared responsibility problem. When a vulnerability, outage, or compliance issue occurs, each ve…YOUTUBE.COM
3 JulMicrosoft 365 users fall victim to one-in-a-million password spray attackMicrosoft users have been hit by a massive, automated password spray attack. Among those targeted by the attack were clients of security company Huntress. It reported that the attackers made 81 million attempts to log into its customers’ accounts between June 12 and 26 — and succ…CSOONLINE.COM
3 JulIn Other News: Canadian Hacker Jailed, Open Source Zero-Days, Two Sentenced for ATM JackpottingNoteworthy stories that might have slipped under the radar: Anonymous-linked Canadian hacker jailed, researcher drops zero-days in open source projects, Venezuelans sentenced in the US over ATM jackpotting. The post In Other News: Canadian Hacker Jailed, Open Source Zero-Days, Tw…SECURITYWEEK.COM
3 JulAn AI just carried out a cyber attack without any human oversight for the first timeAnthony Cuthbertson reports: Security researchers have uncovered what they believe to be the first ever instance of an artificial intelligence agent executing a cyber attack from start to finish without human assistance. The AI-powered attack marks a major milestone for both arti…DATABREACHES.NET
3 JulWeekly Metasploit Update: Modules for SMB-to-Meterpreter, Peyara Remote Mouse RCE exploit, and moreIt's Time to Upgrade Your SMB Session This week, Metasploit contributor Dean Welch has added an SMB to Meterpreter session upgrade module. It uses PsExec to facilitate the upgrade. Users can load the module with use windows/manage/smb_to_meterpreter and specify the session number…RAPID7.COM
2 JulUnpatched Argo CD Repo-Server Flaw Could Let Attackers Take Over Kubernetes ClustersArgo CD, a widely used tool for deploying software to Kubernetes, has an unpatched flaw in its repo-server component that lets an unauthenticated attacker run code, provided they can reach the component's internal network port. Synacktiv, which found the bug, says it can lead to …THEHACKERNEWS.COM
2 JulGitHub’s new tool helps prevent costly open-source license violationsGitHub’s Open Source Program Office (OSPO) uses the new GitHub License Compliance feature, now in public preview, to manage thousands of open-source dependencies and identify dependencies whose licenses require review. The feature is available to GitHub Advanced Security cu…HELPNETSECURITY.COM
2 JulDrawing a digital line for geofencing.This week, Dave and Ben take a look at the Supreme Court's recent ruling that has significantly changed how the law enforcement must approach collecting user location data. Alongside this conversation, Ben also sits down with former Congressman and current President of Americans …THECYBERWIRE.COM
2 JulWhat the AI patch gap means for enterprise securityOpen-source maintainers are receiving more vulnerability reports than they can act on, and a rising share now comes from an AI system working at machine speed. Over roughly two months this spring, Anthropic’s Claude Mythos Preview combed through more than 23,000 open-source…HELPNETSECURITY.COM
2 JulNew ChocoPoC RAT Targets Vulnerability Researchers via Fake PoC Exploit ReposAttackers are hiding a data-stealing trojan inside fake exploit code aimed at the people who hunt bugs for a living. The malware, called ChocoPoC, travels in Python proof-of-concept (PoC) repositories on GitHub that claim to exploit hot new CVEs. Run one, and it quietly lifts you…THEHACKERNEWS.COM
2 JulExploring cross-domain & cross-forest RBCD: part 2Kerberos delegation capabilities in Linux-based tooling have been extended to allow impersonating any user within a forest. This assumed identity can then be leveraged to access resources across any domain within that forest, or even in a remote forest, provided that a trust rela…SYNACKTIV.COM
2 JulAI Agent Exploits Langflow RCE to Automate Database Ransomware AttackSecurity firm Sysdig says it has found what it believes is the first ransomware attack run from start to finish by an AI agent. Its Threat Research Team calls the operator JADEPUFFER and says a large language model handled the whole job: breaking in, stealing credential…THEHACKERNEWS.COM
2 JulAdobe fixed multiple maximum-severity flaws in ColdFusion and Campaign ClassicAdobe fixed multiple critical flaws, including max severity bugs in ColdFusion and Campaign Classic that could lead to remote code execution Adobe has released security updates for ColdFusion and Campaign Classic, fixing multiple critical vulnerabilities, including seven maximum-…SECURITYAFFAIRS.COM
2 JulArgo CD flaw shows why GitOps infrastructure should be treated as tier zeroA newly disclosed vulnerability in Argo CD is drawing attention to the security risks of GitOps platforms, with researchers warning that the flaw could allow attackers who gain a foothold inside a Kubernetes cluster to execute code and manipulate application deployments. Security…CSOONLINE.COM
2 JulField reports from Patch the PlanetWe’re running Patch the Planet , an ongoing collaboration with OpenAI that pairs Trail of Bits engineers directly with more than 30 open-source projects. Its goal is to front-run a serious problem facing open-source maintainers: highly capable models like GPT-5.5-Cyber will soon …TRAILOFBITS.COM
2 Jul KEVCISA: Microsoft SharePoint RCE flaw now actively exploitedCISA warned on Wednesday that attackers have begun exploiting a high-severity Microsoft SharePoint remote code execution vulnerability patched in May. [...]BLEEPINGCOMPUTER.COM
2 JulCisco Confirms In-the-Wild Exploitation of Unified CM VulnerabilityA PoC exploit has been available since public disclosure, and the first exploitation attempts were observed last week. The post Cisco Confirms In-the-Wild Exploitation of Unified CM Vulnerability appeared first on SecurityWeek .SECURITYWEEK.COM
2 JulCisco finally confirms attackers exploiting Unified CM flawCisco confirmed that attackers are now exploiting a Unified Communications Manager (Unified CM) vulnerability patched in early June. [...]BLEEPINGCOMPUTER.COM
2 JulResearcher Behind 'Exploitarium' Explains Release of Undisclosed Zero-Day ExploitsInfosecurity spoke with the researcher who dumped over 30 proof-of-concept exploits without disclosing the vulnerabilities firstINFOSECURITY-MAGAZINE.COM
2 JulAnthropic's AI Finds Bugs. IBM Bets $5B It Can Fix Them.IBM and Red Hat assign 20,000 engineers to the new Project Lightwell service as Anthropic's Mythos findings ignite debate over how to secure the open-source software supply chain.DARKREADING.COM
2 JulNew iboss platform gives organizations instant visibility into AI tools and usageiboss has launched the AI Security Platform, a new service that gives any organization visibility into the AI tools its people are using, free of charge. Signup is instant, deployment takes an afternoon, and a complete AI footprint appears within hours. Organizations that want to…HELPNETSECURITY.COM
2 JulNew CitrixBleed Vulnerability Exploited Immediately After Public DisclosureHackers are targeting NetScaler appliances using public PoC code to retrieve arbitrary memory content in the HTTP response. The post New CitrixBleed Vulnerability Exploited Immediately After Public Disclosure appeared first on SecurityWeek .SECURITYWEEK.COM
2 JulFormalizing Red Teaming Offensive Methodology as a Multi-Agent AI ArchitectureThreat actors are integrating AI into their exploit chains, accelerating reconnaissance, automating vulnerability discovery, and scaling social engineering in ways that compress the timeline between initial access and impact. The barrier to sophisticated offensive operations is d…RAPID7.COM
2 JulCisco confirms exploitation of critical Unified CM flaw.DHS investigates hack of information-sharing network. Suspected Scattered Spider member extradited to the US.THECYBERWIRE.COM
2 JulFortiBleed campaign traced to INC and Lynx ransomware operationsResearchers are also investigating the role of a suspected zero-day vulnerability.CYBERSECURITYDIVE.COM
2 JulApple’s Hide My Email doesn’t hide it very wellA year ago a researcher found a vulnerability in Apple's Hide My Email feature and now he's tired of waiting for a fix.MALWAREBYTES.COM
2 JulFrom Cloud to Chaos: Defining Shared Responsibility for AI SecurityFor 15 years (!), many of us who have touched cloud security have struggled with the shared responsibility model for cloud security. As with many “cyber things,” the theory is simple. Multiple vendors, consulting firms, and industry bodies have published deceptively clear matrice…MEDIUM.COM
2 JulCatan and MouseWhat do board games and cybersecurity have in common? Pattern recognition. Strategy. Adaptation. In this week’s Threat Source Bill explores why curiosity may be a defender’s most valuable skill.TALOSINTELLIGENCE.COM
2 JulApple Reverses Age-Old Patch Policy to Keep Up With AIExpect more compressed patching cycles from Apple going forward, as attackers leverage artificial intelligence to reduce time to exploit.DARKREADING.COM
2 JulFortiBleed Actors Collaborating With Inc, Lynx Ransomware GangsAfter gaining a foothold in thousands of Fortinet firewalls, the attackers are starting to monetize that access, and are also piling on a Nextcloud zero-day bug.DARKREADING.COM
2 JulGlobal Schools Holdings Cites Two Injunctions in a Bid to Chill Our Reporting. It Won’t Work.My About page is pretty clear about legal threats: If you want to send me legal threats about my reporting or comments, knock yourself out, but don’t be surprised to see me report on your threat, any confidentiality sig blocks you may attach notwithstanding. I have been threatene…DATABREACHES.NET
2 JulThe people's AI?OpenAI considers an equity plan to share AI wealth with the public. Cisco confirms active exploitation of its unified CM platform. Researchers discover autonomous ransomware. The Vect ransomware operation partners with TeamPCP. The FortiBleed credential-harvesting campaign is lin…THECYBERWIRE.COM
2 JulLaunch of UK's National Cyber Action Plan delayed amid Labour leadership crisisThe plan had been due for publication on Monday, the sources said. It has been postponed amid the uncertainty over the governing Labour Party’s leadership contest, which opens July 9.THERECORD.MEDIA
2 JulLinux Tech Segment & Vulnerabilities Galore - PSW #933This week we have a technical segment based on the response to "Atomic Arch", an updated open-source tool to help you catch malicious packages. In the security news: - Exploitarium - A hot messy summer of vulnerabilities - AI Squatting - Linux LPE - no shortage of those - Fingerp…YOUTUBE.COM
2 JulDefense Gap in AI Security RaceAI is improving offensive security capabilities like vulnerability discovery and exploit generation at a rapid pace. Offensive work can tolerate high error rates, since only occasional success is needed. Defensive security cannot operate that way—detection, patching, and response…YOUTUBE.COM
1 JulPhantom Squatting: AI-Hallucinated Domains as a Software Supply Chain VectorAttackers can exploit LLM domain hallucinations through phantom squatting to target supply chains. Read the analysis to learn more. The post Phantom Squatting: AI-Hallucinated Domains as a Software Supply Chain Vector appeared first on Unit 42 .UNIT42.PALOALTONETWORKS.COM
1 JulMicrosoft wants to stop unwanted bots from entering Teams meetingsA new Microsoft Teams admin policy, Manage external bots and their access to meetings, gives organizations greater visibility and control over external bots in meetings. The policy identifies bots and applies safeguards before they are admitted. Microsoft will begin retiring the …HELPNETSECURITY.COM
1 Jul KEVDetection engineering: A programmatic approach to identifying cyber threatsDetection engineering, which was once a niche practice among mostly large companies, appears to have evolved into a capability that organizations across industries now consider essential to their security operations. What is detection engineering? Detection engineering is about c…CSOONLINE.COM
1 JulNika: Open-source code analysis toolMany serious security bugs in web applications sit across several files at once. Request data enters through a controller, moves through data objects and service layers, and turns dangerous only when it reaches a sensitive operation such as a database query or a file action. A sc…HELPNETSECURITY.COM
1 JulRisky Bulletin: Researcher drops giant cache of zero-daysAn anonymous researcher has dropped a giant cache of zero-day exploits, a sensitive DHS network got hacked, the US Supreme Court restricts geofence warrants, and security firm Huntress has denied accusations of a malicious insider.RISKY.BIZ
1 JulAnthropic Restores Claude Fable 5 After U.S. Lifts Jailbreak-Linked Export ControlsAnthropic is putting Claude Fable 5 back online worldwide. On June 30, the U.S. Commerce Department lifted the export controls it had imposed on Fable and its more tightly controlled sibling Mythos 5 about two and a half weeks earlier. Fable 5 returns to users on Wednesday, …THEHACKERNEWS.COM
1 JulCasey Ellis on How AI Is Reshaping Vulnerability Research and PatchingIn this episode of the Microsoft Threat Intelligence Podcast, host Sherrod DeGrippo sits down with Casey Ellis, founder of Bugcrowd and co-founder of disclose.io, to explore how AI is reshaping vulnerability research, bug bounty programs, and the future of cyber defense. The…THECYBERWIRE.COM
1 JulClaude Sonnet 5 includes safeguards against dangerous cyber useAnthropic has introduced Claude Sonnet 5, the latest version of its general-purpose AI model, with improved reasoning, coding, tool use, and knowledge work capabilities. The model can make plans, use tools such as browsers and terminals, and complete tasks autonomously. Scores fo…HELPNETSECURITY.COM
1 JulPerformance Through People as Executives Struggle and Mentorship Matters - Greg Hoffman - BSW #454One of the biggest questions most executives ask is "Why does it still feel this hard when the talent is clearly there?" The answer, in almost every case, is not a people problem. It is an environment problem. And environment is something a leader can build. Greg Hoffman, Preside…YOUTUBE.COM
1 JulClaude Helped a Hacker Find a Way to Issue Tickets to Almost Every US Music FestivalA researcher found that using Anthropic’s Claude Opus 4.7, he could break into the website of Front Gate—used by every festival from Lollapalooza to Bonnaroo—and freely issue any ticket he chose.WIRED.COM
1 JulGuardFall Flaw Hits 10 of 11 Popular Open-Source AI AgentsResearchers found a shell injection flaw in 10 of 11 popular open-source AI agents, allowing attackers to bypass command filters. Adversa AI just published a survey, titled “GuardFall: a universal shell injection vulnerability in open-source AI agents,” of eleven open…SECURITYAFFAIRS.COM
1 JulNetzilo adds runtime governance for AI agents across major platformsNetzilo has announced expanded AI agent governance and runtime enforcement capabilities for Amazon Bedrock AgentCore and other major AI agent harnesses. As enterprises move AI agents from experimentation into production, agents are becoming a new enterprise edge. They operate acr…HELPNETSECURITY.COM
1 JulIntruder offers Free security plan for lean IT and security teamsIntruder has announced the launch of its Free plan, providing security, IT, and DevOps teams ongoing access to professional-grade vulnerability management, cloud security, and attack surface management at no cost. Smaller organizations face the same threats as Fortune 500 compani…HELPNETSECURITY.COM
1 JulRustDuck: The Botnet That’s Still Small but Engineering Like It Plans to GrowRustDuck is a small, evolving DDoS botnet migrating to Rust. It uses advanced encryption, anti-analysis evasion, and exploits known IoT flaws. Since February 2026, researchers at QiAnXin’s XLab have been tracking a new malware family, called RustDuck, that hijacks routers, …SECURITYAFFAIRS.COM
1 JulOver 900 Oracle E-Business instances exposed to ongoing attacksOver 900 Oracle E-Business Suite (EBS) instances have been found exposed online amid ongoing attacks exploiting a critical security flaw. [...]BLEEPINGCOMPUTER.COM
1 JulBioShocking: when “gaming” AI agents is no longer a gameResearchers warned AI vendors about a proof-of-concept called BioShiocking that tricks agents by gamifying the outcome.MALWAREBYTES.COM
1 JulU.S. lifting export control restrictions on Anthropic’s Mythos, FableThe company and the Commerce Department say they have reached an agreement that will see the AI models released publicly with new guardrails and classifiers. The post U.S. lifting export control restrictions on Anthropic’s Mythos, Fable appeared first on CyberScoop .CYBERSCOOP.COM
1 JulCaught in the Octopus Trap: Unauthenticated RCE in Argo CD with CodeQLSynacktiv has discovered an unauthenticated arbitrary code execution vulnerability in ArgoCD's repo-server component, potentially allowing full cluster compromise. This article explains how the vulnerability was identified using CodeQL, details the exploitation process to gain co…SYNACKTIV.COM
1 JulAdobe Patches 7 CVSS 10.0 Flaws in ColdFusion and Campaign ClassicAdobe has released patches for multiple maximum-severity security flaws impacting Adobe ColdFusion and Adobe Campaign Classic. The ColdFusion updates "resolves critical and important vulnerabilities that could lead to arbitrary code execution, privilege escalation, arbitrary file…THEHACKERNEWS.COM
1 JulCritical flaw in Oracle E-Business Suite is under immediate threatResearchers warn that successful exploitation of the vulnerability could allow an attacker to compromise Oracle Payments.CYBERSECURITYDIVE.COM
1 Jul5 Myths About AI in the SOC Security Teams Need to RethinkAI is now part of almost every conversation in security operations. Most teams are already investing in it, experimenting with it, or trying to understand where it fits. The challenge is not whether to adopt AI, but how to apply it in a way that actually improves outcomes. At the…RAPID7.COM
1 JulWebinar: Why traditional email security is no longer enoughModern phishing, business email compromise, and account takeover attacks increasingly exploit trusted identities and legitimate business workflows, making them harder for traditional email defenses to detect. This webinar explores how behavioral AI can help organizations automate…BLEEPINGCOMPUTER.COM
1 JulResearchers spot exploitation of another critical Oracle defectThe defect impacts a popular collection of business applications that attackers have hit before in widespread attack sprees. The post Researchers spot exploitation of another critical Oracle defect appeared first on CyberScoop .CYBERSCOOP.COM
1 JulThe AI lock comes off.The US restores exports of Anthropic’s most advanced AI models. Adobe and Citrix rush out critical patches. RustDuck emerges as a fast-evolving DDoS threat. The Gentlemen raise the stakes with a new EDR-killing exploit. Rocket lab bets big on Iridium. Researchers unveil browser-o…THECYBERWIRE.COM
1 JulNew ChocoPoC malware targets researchers via trojanized PoC exploitsMultiple weaponized proof-of-concept (PoC) exploits on GitHub were found delivering a Python-based remote access trojan (RAT) named ChocoPoC that can execute commands and steal sensitive data in a campaign believed to target cybersecurity researchers. [...]BLEEPINGCOMPUTER.COM
1 JulOONI: LaLiga piracy blocks disrupted over 500,000 legitimate sitesThe Open Observatory of Network Interference (OONI) reports that Spain's IP-based anti-piracy blocking campaign against unauthorized LaLiga streams caused widespread collateral damage. Specifically, the actions have temporarily disrupted access to more than half a million legitim…CYBERINSIDER.COM
1 JulKubota says hackers had month-long access to network systemsKubota North America Corporation disclosed that hackers had access to some of its network systems for more than a month earlier this year. [...]BLEEPINGCOMPUTER.COM
30 JunMalicious Perplexity Chrome Extension Intercepted Searches and Address Bar InputMicrosoft has found a malicious Chrome extension that posed as the AI search engine Perplexity and quietly logged what people searched for. It routed every query and every character typed into the address bar through an attacker-controlled server before redirecting users to real …THEHACKERNEWS.COM
30 JunCybersecurity jobs available right now: June 30, 2026AI Offensive Security Engineer AGAPI | UAE | On-site – View job details As an AI Offensive Security Engineer, you will leverage AI and LLMs to accelerate offensive security research, exploit development, vulnerability discovery, and security automation. You will v…HELPNETSECURITY.COM
30 JunVulnerability reports are arriving faster than GitHub can review themAcross the open source world, people are reporting software flaws in record numbers, and the systems built to verify those reports are straining under the weight. The GitHub Advisory Database, which feeds automated security alerts to millions of projects, has reached a point wher…HELPNETSECURITY.COM
30 JunHottest cybersecurity open-source tools of the month: June 2026Presented here is a curated selection of noteworthy open-source cybersecurity solutions that have drawn recognition for their ability to enhance security postures across diverse settings. OWASP Agent Memory Guard: Stop AI agents from being weaponized through their own memory AI a…HELPNETSECURITY.COM
30 JunOpenClaw for iOS: The viral open-source AI agent comes to iPhone and iPadOpenClaw, a self-hosted personal AI assistant that connects to existing chat apps, is now available on iPhone, iPad and Apple Watch. The release brings chat, real-time voice conversations, approvals, device capabilities, and private automations to iOS. Connecting OpenClaw to iPho…HELPNETSECURITY.COM
30 JunReducing Attack Surface & Evaluating Efficiency in Agents - ASW #389SquidBleed reveals another vuln that's been lurking for decades, but its real lesson is in managing an attack surface. Regardless of whatever programming language you use, removing code is one of the best security steps you can take, followed by changing default configs to turn o…YOUTUBE.COM
30 JunHow ransomware syndicates weaponize corporate-style organizationFrom outsourced labor to tiered pricing models, an inside look at how today's top ransomware threats operate less like rogue hackers and more like Fortune 500 companies. The post How ransomware syndicates weaponize corporate-style organization appeared first on CyberScoop .CYBERSCOOP.COM
30 JunCISA: Windows BlueHammer flaw now exploited by ransomware gangsCISA confirmed on Monday that ransomware gangs are now exploiting a Microsoft Defender privilege escalation vulnerability, dubbed BlueHammer, that has previously been abused in zero-day attacks. [...]BLEEPINGCOMPUTER.COM
30 JunCritical SimpleHelp Vulnerability Exploited for Malware DeliveryThe threat actor is focused on collecting credentials, SSH keys, cryptocurrency wallets, and development tooling. The post Critical SimpleHelp Vulnerability Exploited for Malware Delivery appeared first on SecurityWeek .SECURITYWEEK.COM
30 JunShipping post-quantum cryptography to PythonPost-quantum cryptography is now one pip-install away for the entire Python ecosystem. With funding from the Sovereign Tech Agency , we implemented support for ML-KEM, the NIST-standard key-establishment primitive, and ML-DSA, the NIST-standard digital-signature primitive, in pyc…TRAILOFBITS.COM
30 JunCloser than Cuba: the Able Archer Nuclear Crisis of 1983It's November of 1983, the closest the world came to nuclear war, some may argue even closer than the Cuban Missile Crisis of 1962. Yet the Able Archer 1983 exercise incident is relatively unknown by comparison. A series of events that started with the Soviet shootdown of a Korea…THECYBERWIRE.COM
30 JunMalicious Chromium extension spoofs Perplexity AI to hijack browser searchesGoogle has removed a malicious browser extension masquerading as Perplexity AI after Microsoft researchers found it was intercepting users’ search traffic and routing queries through attacker-controlled servers before forwarding them to legitimate search engines. Microsoft Threat…CSOONLINE.COM
30 JunInsurance giant Aflac discloses data breach after subsidiary hackAmerican insurance giant Aflac has disclosed a new data breach after attackers breached its Japan subsidiary's systems and stole personal and bank account information. [...]BLEEPINGCOMPUTER.COM
30 JunHacker Conversations: Chris Thompson, Former Head of IBM X-Force Red, Co-Founder of RemoteThreatChris Thompson's journey took him from hacking game controls as a teenager to founding IBM’s X-Force Red team. The post Hacker Conversations: Chris Thompson, Former Head of IBM X-Force Red, Co-Founder of RemoteThreat appeared first on SecurityWeek .SECURITYWEEK.COM
30 JunExploitation of Recent Oracle E-Business Suite Vulnerability BeginsThe critical-severity defect allows unauthenticated attackers to take over the E-Business Suite’s Payments product. The post Exploitation of Recent Oracle E-Business Suite Vulnerability Begins appeared first on SecurityWeek .SECURITYWEEK.COM
30 JunDecades-Old Bash Tricks Expose AI Coding Agents to Supply Chain AttacksDecades-old Bash shell tricks can bypass safeguards in most open source AI coding agents, potentially turning malicious repositories into supply chain attack vectors. The post Decades-Old Bash Tricks Expose AI Coding Agents to Supply Chain Attacks appeared first on SecurityWeek .SECURITYWEEK.COM
30 JunAikido Security acquires Root to expand backported fixes for open source vulnerabilitiesAikido Security has acquired Root, uniting behind a shared mission to make it easy for developers and agents to build with secure open source and tackle the growing threat of supply chain attacks. Open source is the foundation of almost every application in the world, and it has …HELPNETSECURITY.COM
30 JunJamf enables AI Governance and shadow AI detection on MacJamf has announced general availability of AI Governance, a new capability within Jamf for Mac that enables IT and security teams to discover actively-used AI tools, enforce policy controls, and generate audit-ready reporting. Many organizations struggle to confidently audit and …HELPNETSECURITY.COM
30 JunInsurance giant Aflac discloses data breach at Japan subsidiarySergiu Gatlan reports: American insurance giant Aflac has disclosed a new data breach after attackers breached its Japan subsidiary’s systems and stole personal and bank account information. Aflac (short for American Family Life Assurance Company) is a Fortune 500 company a…DATABREACHES.NET
30 JunGuardFall Exposes Open-Source AI Coding Agents to Decades-Old Shell Injection RisksThe safety check that is supposed to stop an AI coding agent from running a dangerous command can be walked straight past using a shell trick that has been public for decades. New research from Adversa AI, which is named the bypass GuardFall, found it works against ten of th…THEHACKERNEWS.COM
30 Jun KEVUS Supreme Court rules that geofence searches generally require warrants.Maximum-severity SimpleHelp flaw is now actively exploited. US government offers $10 million reward for info on Russian state-backed hackers.THECYBERWIRE.COM
30 JunCritical flaw in SimpleHelp exploited in attacks targeting sensitive credentialsResearchers found two previously undisclosed malware samples used to steal AI assistant tokens and other valuable secrets.CYBERSECURITYDIVE.COM
30 JunNissan Discloses Employee Data Breach Linked to Oracle Zero-DayNissan says employees' data was stolen via the Oracle PeopleSoft zero-day campaignINFOSECURITY-MAGAZINE.COM
30 JunCritical SimpleHelp Vulnerability Exploited For Malware DeliveryAttackers exploited a critical SimpleHelp RMM bug to deploy TaskWeaver and Djinn Stealer malwareINFOSECURITY-MAGAZINE.COM
30 JunFake Perplexity extension on Chrome Web Store tracked searchesA malicious extension in the Chrome Web Store is masquerading as the Perplexity AI answer engine, intercepting search traffic and collecting browsing information. [...]BLEEPINGCOMPUTER.COM
30 JunThe Human Element: Building A Trusted Workforce in the Age of DPRK Employment FraudFrom Nisos: Earlier this year, our DPRK employment fraud investigation revealed how North Korean operatives infiltrate US companies at industrial scale. In June, we released Part 2 of our research, featured on Nicole Perlroth’s “To Catch a Thief” podcast, that t…DATABREACHES.NET
30 JunThe Fall of XSS Forum: From DaMaGeLaB to the 2025 takedownRansomnews has published a history and analysis of XSS Forum from its inception to its seizure in 2025. There is so much that is interesting and informative in their report that it’s hard to know what to mention here, but here are just two portions below: As an overview: XS…DATABREACHES.NET
30 JunHackers Steal Data of 4.38 Million Aflac Japan CustomersHackers stole data from 4.38 million Aflac Japan customers after accessing its systems for 10 days before the breach was detected. Aflac Japan disclosed that hackers stole the personal information of 4.38 million customers and agents after gaining access to its systems between Ju…SECURITYAFFAIRS.COM
30 JunKaspersky Lab experts have discovered a new attack vector and toolkit for compromising corporate Gmail accountsKaspersky Labs writes: It is used by the ToddyCat group. Kaspersky Lab experts have discovered a new attack vector and toolkit for compromising corporate Gmail accounts. Using this toolkit, attackers can access user accounts via an API, read conversations, and harvest data from c…DATABREACHES.NET
30 Jun KEVAnton’s Security Blog Quarterly Q2 2026My Anton’s Security Blog Quarterly covers both Anton on Security and my posts from Google Cloud blog , Google Cloud community blog , and our Cloud Security Podcast ( subscribe on Spotify, now with VIDEO ). Top 10 posts with the most lifetime views (excluding paper announcement bl…MEDIUM.COM
30 JunThe court draws a privacy line.The Supreme Court limits geofence warrants. DHS moves to expand CISA. The State Department offers $10 million for Russian hackers. A legal theory could reshape EU-U.S. data sharing. Plus, cyberattacks hit D.C. housing, Oracle and SimpleHelp flaws face active exploitation, malware…THECYBERWIRE.COM
30 JunScammers race to cash in on Venezuelan earthquake disasterScammers wasted no time exploiting Venezuela's devastating earthquake, with researchers uncovering 212 newly-registered relief-themed domains in just five days. Read more in my article on the Hot for Security blog.BITDEFENDER.COM
30 JunFake Bug Report Hijacks AI Coding Agents at Scale"Agentjacking" is the latest demonstration of how easily attackers can exploit an AI agent's inability to differentiate between content and instructions.DARKREADING.COM
30 JunUK journalists and NGOs risk terrorism prosecutions under new security billMEE reports: New national security legislation being rushed through the UK’s parliament could criminalise British foreign correspondents and NGO workers engaging with designated state-backed groups, experts warn. The National Security (State Threats) Bill, which is moving t…DATABREACHES.NET
30 JunThe Green Shirt AI JailbreakAn LLM refused a request until the prompt included fabricated internal reasoning claiming the action was acceptable because of a "green shirt." The model then complied, illustrating how prompt-based attacks can bypass intended restrictions. Unlike traditional software exploits, m…YOUTUBE.COM
30 JunUS Supreme Court limits police access to people’s location historyThe US Supreme Court has ruled that law enforcement's acquisition of historical location data through geofence warrants constitutes a Fourth Amendment search, marking a major victory for digital privacy. While the Court stopped short of declaring geofence warrants unconstitutiona…CYBERINSIDER.COM
30 JunAnthropic to restore Claude Fable access on WednesdayAnthropic has confirmed that the Department of Commerce has lifted export controls on Claude's two most powerful models, Fable 5 and Mythos 5. [...]BLEEPINGCOMPUTER.COM
30 JunXSS.is, The Forum That Ran the Ransomware Supply Chain Is Down. The Market Isn’tPolice arrested the alleged admin of XSS.is, a major cybercrime forum whose trusted escrow service helped power the underground economy. On 22 July 2025, French and Ukrainian police arrested a 38-year-old man in Kyiv and shut down XSS.is, the most influential Russian-language cyb…SECURITYAFFAIRS.COM
30 Jun KEVSN 1085: A SOTA State-Sponsored Campaign - AI's New Superpower: Loop EngineeringAI is now uncovering and fixing thousands of hidden software bugs faster than humans can keep up, but not everyone is playing by the rules. Find out how state-sponsored attackers and careless disclosures are turning the cybersecurity playbook upside down. Win10's popularity force…TWIT.TV
29 JunSponsored: Corelight’s blueprint for AI-era defenceIn this sponsored interview James Wilson chats with Corelight’s VP of Product Vijit Nair about defence strategies for the AI era. When agents can find and exploit vulnerabilities at machine speed, you need to balance between proactive and reactive measures. On the proactive side,…RISKY.BIZ
29 JunUS Restricts Frontier AI modelsUS Loosens Anthropic Claude Mythos Access, Unpatchable iPhone Exploit Emerges, and CISO Burnout Drives Fractional Shift Washington granted a partial reprieve allowing Anthropic's Claude Mythos to be released to more than 100 approved U.S. firms and institutions after export contr…CYBERSECURITYTODAY.LIBSYN.COM
29 JunDarkMoon: Open-source AI pentesting platformPenetration testing has long run on expert time, with specialists spending days probing a network or web application by hand. Manual engagements stretch across weeks, expert consultants run into thousands of dollars a day, and results vary with the tester. Automation promises to …HELPNETSECURITY.COM
29 JunFrom mythos to reality: Why the 2026 state of pentesting report proves the need for programmatic defensesAI can find zero-days in minutes. Your defense strategy must evolve now.CYBERSECURITYDIVE.COM
29 JunFixing pentesting, Meta is destroying its engineering org, the weekly news - ESW #465Interview with Adriel Desautels - the pentest is broken Adriel joins us for a discussion on the state of penetration testing, why it hasn't done much to help security teams over the last 20 years, and why AI won't save it. Segment Resources: - https://hbr.org/2026/04/boards-are-f…YOUTUBE.COM
29 JunUS Federal Insurance Regulator Confirms Data Breach Via Oracle FlawAn attacker has exploited a zero day in Oracle Peoplesoft to gain access to the IT systems of the NAIC, the standard-setting association for the US federal insurance systemINFOSECURITY-MAGAZINE.COM
29 JunRobot Police OfficersWe’ve taken one small step towards robot police officers: a drone capable of disarming a suspect: In a June 22 video posted on the Sacramento County Sheriff’s Office’s Instagram page, an officer wearing goggles can be seen operating a drone to retrieve a knife from an armed…SCHNEIER.COM
29 JunMozilla warns of indirect prompt injection risk in AI coding agentsA malicious GitHub repository can silently compromise a developer’s machine without containing a single line of malicious code, security researchers at Mozilla’s Zero Day Investigative Network (0DIN) warned. The attack The proof-of-concept attack targets AI-powered co…HELPNETSECURITY.COM
29 Jun‘DirtyClone’ Linux Kernel Vulnerability Leads to Root AccessA variant of DirtyFrag, the flaw allows unprivileged local users to manipulate the Linux page cache and gain root privileges. The post ‘DirtyClone’ Linux Kernel Vulnerability Leads to Root Access appeared first on SecurityWeek .SECURITYWEEK.COM
29 JunThe Red Agent POV: Exploiting Broken Object-Level Authorization in an Airline GraphQL APIPart 2: How the Red Agent bypassed backend resolvers to expose an entire airline booking database in fifteen minutesWIZ.IO
29 Jun236,000 DCloud Uni-App Sites Used in Crypto Scams, Phishing, and Wallet DrainersNew findings unearthed by Infoblox show that more than 236,000 websites are using investment scam templates built using a legitimate Chinese open-source, cross-platform application development framework called DCloud Uni-App. The templates power bogus cryptocurrency exchanges, mu…THEHACKERNEWS.COM
29 JunCharting your way in: Helm template injectionDuring the audit of a Kubernetes cluster, we encountered an injection in a Helm template applied through ArgoCD. To our surprise, very few resources exist regarding YAML injection in vulnerable Helm templates. In this blog post, we will explore this kind of vulnerability and how …SYNACKTIV.COM
29 JunUK businesses fear stigma of ransomwareAlex Scroxton reports: Fear of stigmatisation is likely leading businesses across the UK to drastically underreport data on ransomware attacks, especially when they have paid a ransom to a cyber criminal gang, as admission of such is often seen as supporting further criminal acti…DATABREACHES.NET
29 JunCentral Bank of Libya investigates alleged data leak after cyberattackSafaAlharathy reports: Libya’s central bank (CBL) says it is investigating data published on the dark web following a recent cyberattack. In a statement, the bank said its technical teams, working with international experts, were analysing the data to determine its nature and whe…DATABREACHES.NET
29 JunZA: Copying the wrong person on an email could be considered a data breach in South AfricaJan Vermeulen reports: Misdirected internal emails that expose personal information can trigger mandatory data breach reporting under South Africa’s data privacy law, POPIA, even when the disclosure was accidental. Armand Swart, Hlonelwa Lutuli, and Isabella Keeves from Werksmans…DATABREACHES.NET
29 JunOne Honeypot Ends the AttackMany attackers spend their first moments inside a compromised network performing discovery. According to this red team perspective, a properly deployed honeypot or canary token can immediately reveal that activity. That means organizations don't always have to catch every exploit…YOUTUBE.COM
29 JunFactoring RSA Keys with Many ZerosInteresting research on a new class of weak RSA keys: keys with lots of zeros. It turns out that these keys are out in the wild. The badkeys project is an open-source service that checks public keys for known vulnerabilities. While developing this tool, Hanno collected a massive …SCHNEIER.COM
29 JunInside the Advisory Database and what happens when vulnerability volume breaks recordsThe GitHub Advisory Database is processing more vulnerability reports than ever before. Here's what's driving the surge, how we're responding, and how the community can help. The post Inside the Advisory Database and what happens when vulnerability volume breaks records appeared …GITHUB.BLOG
29 JunUS racks up about 400 wins over illegal World Cup streaming sitesThe World Cup’s organizing body, FIFA, helped identify hundreds of domains taken down in an action organized by the U.S., along with the help of U.S. broadcaster NBC Universal and other entities.THERECORD.MEDIA
29 JunNissan hit by Oracle PeopleSoft cyberattack exposing internal dataNissan North America has informed employees that a cyberattack targeting Oracle PeopleSoft systems exposed sensitive personnel records, making the automaker one of the latest known victims linked to a broader campaign exploiting a critical vulnerability in the widely used HR plat…CYBERINSIDER.COM
29 JunNI: Updated warning to parents over schools cyber attackNiall Glynn and Auryn Cox report: The number of schools in Northern Ireland affected by a recent cyber-attack is larger than previously thought. In a letter issued by the Education Authority (EA) on Thursday, some parents were warned that their child’s personal data may hav…DATABREACHES.NET
29 JunMOVEit Breach Defendants Lose 2nd Bid to Toss Negligence ClaimsChristopher Brown reports: Bellwether defendants in multi-district litigation over a massive data breach of Progress Software’s MOVEit file-transfer application failed to convince a federal court to toss negligence claims against them under the laws of California, Indiana, Michig…DATABREACHES.NET
29 JunAI behind the velvet rope.The White House keeps frontier AI models on a short leash. Russian threat actors increasingly target secure messaging platforms. DirtyClone is a high-severity Linux kernel privilege escalation flaw. An investigation claims federal websites are violating privacy rules. Microsoft d…THECYBERWIRE.COM
29 JunNissan discloses employee data breach linked to Oracle zero-day attacksNissan is warning that it suffered a data breach affecting current and former employees after threat actors exploited an Oracle PeopleSoft vulnerability in data theft attacks previously linked to the ShinyHunters extortion group. [...]BLEEPINGCOMPUTER.COM
29 JunNAIC says public data stolen in ShinyHunters' PeopleSoft breachThe National Association of Insurance Commissioners (NAIC) says the ShinyHunters extortion group stole only publicly available data, outdated logs, and configuration files after breaching its systems by exploiting a zero-day vulnerability in an Oracle PeopleSoft server. [...]BLEEPINGCOMPUTER.COM
29 JunStop Building a 2003 SOC with AI: A Modern People & Process Framework (Part 1)One particular aspect of an agentic or AI-powered SOC (but NOT “humanless SOC ”) has bothered me over the last few months: specifically, the people and process side of such a SOC. If you recall my blog posts ( part 1 , part 2 and this video ) about AI SOC readiness, I hinted at c…MEDIUM.COM
29 JunVulnerabilities Expose Private Data in Indian Government SystemsOne critical vulnerability, among many discovered by a researcher, could have allowed anyone to walk in and take over a national government portal.DARKREADING.COM
29 JunEXCLUSIVE: Top-100 Law Firm Fox Rothschild Suffers Data Breach and Leak by Silent Ransom GroupFox Rothschild is a top-100 law firm whose articles and resources have been cited on DataBreaches.net and PogoWasRight.org dozens of times over the years. This time, however, they are the subject of a post because they were victims of a data breach by a well-known group that targ…DATABREACHES.NET
28 JunWeek in review: Fortibleed campaign’s impact on orgs, Cisco Unified CM flaw exploitedHere’s an overview of some of last week’s most interesting news, articles, interviews and videos: Encrypted DNS still tells an eavesdropper where to look Encrypted DNS runs across much of the Internet. DNS over TLS, HTTPS, and QUIC keep the contents of a query away from anyone wa…HELPNETSECURITY.COM
28 JunData breach exposes up to 14.2 million email logins at six ISPsJapanese telecommunications operator KDDI Corporation disclosed a data breach where threat actors gained access to one of its email systems used by five other internet service providers (ISPs) in the country. [...]BLEEPINGCOMPUTER.COM
28 JunAssuranceAmerica breach may have affected more than 1.1 million people in seven statesKrys Shahin and Christopher Buchanan report: State officials are warning at least 1.1 million people across seven states may be impacted by an AssuranceAmerica data breach. Notices about the breach were sent to California, Massachusetts, Nebraska, South Carolina, Texas, Vermont, …DATABREACHES.NET
28 JunNZ pharmacy scrambles to scrub internet of patients’ private messagesMary Argue reports: A Wellington pharmacy at the centre of a data leak says sensitive patient information has now been scrubbed from the internet. Unichem Petone said it was contacting 29 patients affected by what it described as an error on the website that saw patients’ p…DATABREACHES.NET
28 JunSysco - 2,691,852 breached accountsIn June 2026, the food distribution company Sysco was targeted by a ShinyHunters "pay or leak" extortion campaign . Data was subsequently published containing 2.7M unique email addresses belonging to staff and customers. The data also contained largely corporate contact informati…HAVEIBEENPWNED.COM
28 JunKDDI Data Breach Impacts up to 14.2 Million Email Accounts at Six ISPsKDDI Corporation disclosed a breach affecting up to 14.2 million email accounts after attackers exploited a vulnerability in third-party software. KDDI Corporation disclosed a data breach that exposed up to 14.2 million email accounts across six Japanese internet service provider…SECURITYAFFAIRS.COM
28 JunA KDDI data breach has put up to 14.2 million ISP email logins at risk across JapanJames Whitmore reports: Data breach at Japanese telecoms operator KDDI may have exposed up to 14.22 million email addresses and passwords linked to ISP mail services, after attackers gained unauthorised access to a system used by six providers in Japan. KDDI said it confirmed the…DATABREACHES.NET
27 JunWhy Car Dealerships Are Prime Cyber Targets: Fraud, Resilience, and Security Leadership with Jennifer HuttonCybersecurity Today would like to than Material Security for their support of this podcast. On Cybersecurity Today on the Weekend, the host speaks with Jennifer Hutton, a cybersecurity leader in the car dealership sector, about how she entered cybersecurity through increasing cyb…CYBERSECURITYTODAY.LIBSYN.COM
27 Jun KEVKlue supply-chain attack impacts cybersecurity firms.Tata Electronics and Bajaj Auto continue recovery from cyberattacks. CISA warns of actively exploited PTC and Cisco vulnerabilities.THECYBERWIRE.COM
27 JunSurviving the surge of new Linux LPE : Defense in Depth not deadThanks to AI-assisted vulnerability research and kernel patch diffing that breaks "responsible disclosure" embargos, it's quite the overwhelming time for defenders. There's been a weekly reveal of new Linux critical vulnerabilities, with full exploit scripts made public days befo…SYNACKTIV.COM
27 JunExploiting the Tesla Wall Connector from its charge port connector - Part 2: bypassing the anti-downgradeIn a previous article, we presented an attack against the Tesla Wall Connector Gen 3 used during Pwn2Own Automotive 2025. The exploit chain relied on a simple fact: there was no anti-downgrade mechanism. Once we could speak UDS over the charging cable, we could just write an old,…SYNACKTIV.COM
27 JunMake it Blink: Over-the-Air Exploitation of the Philips Hue BridgeThe year-end edition of Pwn2Own took place in Cork, Ireland. For the first time, this event featured smart home devices, including the Amazon Smart Plug, Home Assistant Green, and the Philips Hue Bridge. The attack scenario defined by the ZDI involved an adversary with access to …SYNACKTIV.COM
27 JunExploring cross-domain & cross-forest RBCDThe Resource-based Constrained Delegation (RBCD) attack is well-known from pentesters and attackers: by editing the msDS-AllowedToActOnBehalfOfOtherIdentity attribute of a machine account, an attacker can impersonate users on said machine. Even though this attack mechanism has be…SYNACKTIV.COM
27 Junmitmproxy for fun and profit: Interception and Analysis of Application TrafficA solid understanding of the protocols used by applications is a necessary prerequisite when assessing application security. In recent projects, we have had to intercept various types of network traffic across different platforms, including Linux, Android, and iOS. The purpose of…SYNACKTIV.COM
27 JunBeyond ACLs: Mapping Windows Privilege Escalation Paths with BloodHoundWindows privileges are special rights that grant processes the ability to perform sensitive operations. Some privileges allow bypassing standard Access Control List (ACL) checks, which can lead to significant security implications. While privileges like SeDebugPrivilege, SeImpers…SYNACKTIV.COM
27 JunOn the clock: Escaping VMware Workstation at Pwn2Own Berlin 2025At Pwn2Own Berlin 2025, we exploited VMware Workstation by abusing a Heap-Overflow in its PVSCSI controller implementation. The vulnerable allocation landed in the LFH allocator of Windows 11, whose exploit mitigations posed a major challenge. We overcame this through a complex i…SYNACKTIV.COM
27 JunLivewire: remote command execution through unmarshalingLivewire revolutionizes Laravel development by enabling real-time, interactive web interfaces using only PHP and Blade, removing the need of heavy JavaScript frameworks. Its innovative hydration system seamlessly instantiate and restores component states, supporting complex data …SYNACKTIV.COM
27 JunExploiting Anno 1404Anno 1404 is a strategy game developed by Related Designs and published by Ubisoft. It is a real-time strategy game that focuses on city management and construction. The Anno 1404: Venice expansion, released in 2010, includes an online and local area network multiplayer mode. Dur…SYNACKTIV.COM
27 Jun2025 Winter Challenge: QuinindromeA few months have passed and the first snowflakes have fallen since the end of the Synacktiv Summer Challenge. This event was a success, with one of the participants even finding a zero-day vulnerability while working on his solution! Although it hasn't been made public yet, it w…SYNACKTIV.COM
27 JunBreaking the BeeStation: Inside Our Pwn2Own 2025 Exploit JourneyThis article documents our successful exploitation at Pwn2Own Ireland 2025 against the BeeStation Plus. We walk through the full vulnerability research process, including attack surface enumeration, code auditing, exploit development, and ultimately obtaining a root shell on the …SYNACKTIV.COM
27 JunSite Unseen: Enumerating and Attacking Active Directory SitesActive Directory Sites are a feature allowing to optimize network performance and bandwidth usage in AD internal environments. They are commonly implemented by large, geographically dispersed organizations spanning across multiple countries or continents. Sites did not receive mu…SYNACKTIV.COM
27 Junappledb_rs, a research support tool for Apple platformsOver the years, research on Apple platforms has become significantly more complex, largely due to the numerous countermeasures deployed by the Cupertino company. To address this challenge during our missions on these platforms, we developed appledb_rs: an open-source tool (https:…SYNACKTIV.COM
27 JunThe 'S' in Zoom, Stands for SecurityToday we uncover two (local) security flaws in Zoom's latest macOS client. First, a privilege escalation vulnerability, and second, a method to surreptitiously access a user's webcam and microphone (via Zoom).OBJECTIVE-SEE.ORG
27 Jun[0day] Abusing XLM Macros in SYLK FilesA 0day logic flaw in Microsoft Excel leads to 'remote' code execution on macOS, via malicious macros.OBJECTIVE-SEE.ORG
27 JunBurned by Fire(fox) (Part III)Recently, an attacker targeted (Mac) users via a Firefox 0day. In this third post, we analyze a second backdoor used in the attack, detailing its persistence, capabilities, and ultimate identify it a new variant of the cross-platform Mokes malware!OBJECTIVE-SEE.ORG
27 JunBurned by Fire(fox) (Part II)Recently, an attacker targeted (Mac) users via a Firefox 0day. In this second post, we fully reverse OSX.NetWire.A, revealing (for the first time!), its inner workings and complex capabilities.OBJECTIVE-SEE.ORG
27 JunBurned by Fire(fox) (Part I)Recently, an attacker targeted (Mac) users via a Firefox 0day. In this first post, we triage and identify the malware (OSX.NetWire.A) utilized in this attack, identifying its methods of persistence, and more!OBJECTIVE-SEE.ORG
27 Jun[0day] Mojave's Sandbox is LeakyThe macOS sandbox is seeks to prevent malicious applications from surreptitiously spy on unsuspecting users. Turns out, it's trivial to sidestep some of these protections, resulting in significant privacy implications!OBJECTIVE-SEE.ORG
27 JunRemote Mac Exploitation Via Custom URL SchemesThe WINDSHIFT APT group is successfully infecting Macs with a novel infection mechanism. By abusing custom URL scheme handlers and minimal user interaction, Macs can be remotely compromised!OBJECTIVE-SEE.ORG
27 Jun[0day] Synthetic RealityIf you can programmatically generate synthetic mouse clicks, you can break macOS! Approving kernel extensions, dismissing privacy alerts, and much more more...OBJECTIVE-SEE.ORG
27 JunEscaping the Microsoft Office SandboxImagine you've gained remote code execution on a Mac via a malicious Word document. Turns out, you're still stuck in a sandbox. However, via a faulty regex, you can escape and persist!OBJECTIVE-SEE.ORG
27 Jun[0day] Bypassing SIP via SandboxingIn this guest blog post @CodeColorist writes about a neat macOS vulnerability. Ironically, by abusing security mechanisms such as sandboxing, macOS can be coerced to load an untrusted library, into a SIP-entitled process!OBJECTIVE-SEE.ORG
27 JunAn Unpatched Kernel BugOn my flight to ShmooCon, I managed to panic my fully-patched MacBook. Here we analyze the kernel panic report, finding that Apple's AMDRadeonX4150 kext is responsible for the crash.OBJECTIVE-SEE.ORG
27 JunTwo Bugs, One Func(), part threeAnalyzing code within the macOS kernel audit subsystem uncovered an exploitable heap overflow.OBJECTIVE-SEE.ORG
27 JunNew Attack, Old TricksA Word document targets Mac users with malicious macros and an open-source payload.OBJECTIVE-SEE.ORG
27 Jun[0day] Bypassing Apple's System Integrity ProtectionRead how an attacker can bypass Apple's SIP, via the local OS upgrade processOBJECTIVE-SEE.ORG
27 JunPhoenix: RootPipe lives! ...even on OS X 10.10.3Exploiting RootPipe on OS X 10.10.3OBJECTIVE-SEE.ORG
27 JunNAIC suspends investment risk designations after cyber attackThe National Association of Insurance Commissioners (NAIC) is the U.S. standard-setting and regulatory support organization. It is governed by the chief insurance regulators from the 50 states, the District of Columbia, and five U.S. territories. The organization serves the publi…DATABREACHES.NET
26 JunMalware gaslights AIMac Malware Gaslights AI, Major Info-Stealer Takedown, OpenAI's Patch the Planet, and FortiBleed Fallout Mac malware called "Gaslight," attributed to North Korea-aligned actors, plants fake system messages designed to derail AI-based analysis while stealing data and exfiltrating …CYBERSECURITYTODAY.LIBSYN.COM
26 JunGDPR at 10: Landmark data protections, increasing business burdenTen years have passed since the General Data Protection Regulation (GDPR) came into force, and the results are mixed. While data protection has become more firmly established in European companies — and beyond — than ever before, the business world remains critical of the regulat…CSOONLINE.COM
26 JunModelplane: Open-source control plane for AI inferenceOrganizations that run open-weight models on hardware they own operate GPU fleets spread across clouds, neoclouds, and on-premise data centers. Each fleet handles model placement, replica scaling, infrastructure provisioning, weight distribution, and traffic routing. Teams have b…HELPNETSECURITY.COM
26 JunNew infosec products of the month: June 2026Here’s a look at the most interesting products from the past month, featuring releases from AISLE, Asimily, Blue Planet, depthfirst, Diligent, Drata, Elastic, Filigran, Flip, Hyland, IDnow, Legit Security, MazeBolt, Noma, Qodo, Ridge Security, Tigera, and WitnessAI. Asimily turns…HELPNETSECURITY.COM
26 JunWhat CISOs need to tell the board about zero trust in OT: A 90-day communication and action planI work as a principal specialist at a pipeline operator where Operational Technology (OT) is the backbone of the business. I do not report to the board or act as a CISO, but the issues that get raised to those levels affect my job every single day. Since the Colonial pipeline ran…CSOONLINE.COM
26 JunProposed US law would make AI risk reporting a legal obligationUS lawmakers on Thursday introduced a bill that would require developers of advanced AI models to report major safety and security incidents to the Commerce Department, establishing a federal oversight framework for high-risk AI systems. The proposed AI Incident Reporting Act wou…CSOONLINE.COM
26 JunMythos is a signal, not a siren: What frontier AI should change for CISOsWhen a new AI capability starts making headlines, I see the same pattern play out in boardrooms and executive staff meetings. The technology is introduced as a looming breakthrough for attackers. The conversation quickly shifts to worst-case scenarios. Then security leaders are a…CSOONLINE.COM
26 JunJapanese telco suffers breach exposing 14.2 million email passwordsKDDI has disclosed that an email system it operates for internet service providers (ISPs) was breached in a cyberattack, potentially exposing email account information belonging to customers of six Japanese service providers. The company says the intrusion exploited a vulnerabili…CYBERINSIDER.COM
26 JunLinux Foundation Unveils New Open Source Security Project AkritesIt will provide the tools and channels to report, patch, and disclose open source software vulnerabilities. The post Linux Foundation Unveils New Open Source Security Project Akrites appeared first on SecurityWeek .SECURITYWEEK.COM
26 JunRansomware gangs find Europe’s weakest link in third-party suppliersRansomware attacks against European organizations increased during the first months of 2026, with third-party suppliers becoming a major entry point for attackers. Black Kite examined 2,066 ransomware incidents across 31 countries between January 2025 and April 2026 in its 2026 E…HELPNETSECURITY.COM
26 JunCritical open-source projects get a new security frameworkOpen source software projects are getting a new framework for handling security vulnerabilities as AI shortens the time between flaw discovery and exploitation. The Linux Foundation has launched Akrites, an industry initiative that brings together technology companies, financial …HELPNETSECURITY.COM
26 JunCyberattacks pose a ‘threat to life’ in AustraliaAustralia’s Security Intelligence Organization (ASIO) has uncovered an attack on a critical infrastructure operator’s network. State-sponsored actors had compromised the network and were preparing to sabotage it, according to its director general, Mike Burgess. Other countries fa…CSOONLINE.COM
26 JunStop Chasing Every New ThreatCybersecurity teams naturally focus on new vulnerabilities, exploits, and attack techniques. But basic practices like patch management, firmware updates, and consistent security hygiene still prevent many successful compromises. Organizations that maintain strong fundamentals are…YOUTUBE.COM
26 JunMore Klue Breach Victims Identified as Hackers Get HackedRoughly two dozen companies have notified their customers of the Klue-Salesforce incident impact. The post More Klue Breach Victims Identified as Hackers Get Hacked appeared first on SecurityWeek .SECURITYWEEK.COM
26 Jun KEVTata Electronics and Bajaj Auto continue recovery from cyberattacks.Threat actors target critical infrastructure across Southeast Asia. CISA warns of actively exploited PTC vulnerability. Polish police disrupt SIM-swapping gang.THECYBERWIRE.COM
26 JunSoftware, AI companies form alliance to tackle open-source security flawsThe emergence of frontier AI models has increased the speed and capabilities of malicious hackers.CYBERSECURITYDIVE.COM
26 JunAmazon Q Flaw Enabled Cloud Credential Theft via Malicious RepositoriesAWS has patched the vulnerability and published its own advisory to inform customers about the potential impact. The post Amazon Q Flaw Enabled Cloud Credential Theft via Malicious Repositories appeared first on SecurityWeek .SECURITYWEEK.COM
26 JunMalware authors subvert AI detection systemsEnterprises that have turned to AI in order to boost their security defenses may have to reconsider their approach. Malware containing code that commands LLM-assisted products to abort their analysis or refuse to implement it is already circulating, according to a post from secur…CSOONLINE.COM
26 JunUnpatched macOS bug could allow tampering trusted applicationsSecurity duo Mysk has disclosed an unpatched macOS vulnerability that they say allows web-installed applications to silently modify other apps' binaries, potentially bypassing key macOS security protections. In a post published on X, Mysk said the issue affects macOS 26 and macOS…CYBERINSIDER.COM
26 JunCisco Adds NHI to Security Stack With Astrix, WideField AcquisitionsCisco joins a growing list of security platform providers who are betting that securing the agentic workforce means turning identity into the primary control plane.DARKREADING.COM
26 Jun KEVCISA sets urgent deadline to fix Cisco flaw exploited in attacksThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) is giving federal agencies until Sunday to patch a vulnerability in Cisco Unified Communications Manager Server that is being actively exploited. [...]BLEEPINGCOMPUTER.COM
26 JunThe Chinese Control the Majority of Argentina’s Squid FleetChinese companies control nearly two-thirds of Argentina’s own squid fleet.SCHNEIER.COM
26 Jun KEVFactory reset required.Tata Electronics and Bajaj Auto continue recovery from cyberattacks. FCC tightens undersea cable rules to bolster national security. CISA warns of actively exploited PTC vulnerability. Gamaredon expands toolkit, hides behind legitimate services. Iran-linked hackers turn public wa…THECYBERWIRE.COM
25 JunInteresting Paper Exploring Prompt InjectionThis is a fascinating explotation of how LLMs fall for prompt injection attacks. It turns out that they learn to recognize the style of text in different role/instruction blocks, and not just the tags. Their conclusion: Role tags were a formatting trick that became the security a…SCHNEIER.COM
25 JunRethinking the balance between AI oversight and innovationThe new CIO mandate is clear: facilitate AI adoption across the enterprise at speed. According to CIO.com’s State of the CIO survey, CEOs’ to p priority for their IT executives is to capitalize on AI . From researching to evaluating AI products, CIOs are now the central figures i…CSOONLINE.COM
25 JunGRC is broken. FedRAMP 20x might fix itWe are auditing a curated version of history. I’ve worked in security long enough now to know something most of us don’t really say out loud. A lot of compliance is theatre. Not all of it, and not all auditors or frameworks, but enough of it that most experienced CISOs know exact…CSOONLINE.COM
25 JunThe Policy Nobody Actually EnforcedMany organizations generate least-privilege IAM policies but never deploy them. That leaves existing permissions available for attackers to abuse after compromising workloads like CI/CD runners. Instead of depending on thousands of manually applied policies, Sandy Bird describes …YOUTUBE.COM
25 JunCloud Visibility, Fortibleed, hacking things the easy way - Sandy Bird - PSW #932First up is Sandy Bird from Sonrai discussing how to protect our cloud infrastructure! This segment is sponsored by Sonrai Security. Visit https://securityweekly.com/sonrai to learn more about them! Next up in the security news: - Help, I am Fortibleeding - Cisco SD-WAN needs hel…YOUTUBE.COM
25 JunYour Small Business Is a TargetMore than 90% of the economy depends on small and medium-sized businesses. At the same time, critical infrastructure spans far beyond power grids or defense systems. It includes industries like healthcare, financial services, food and agriculture, IT, communications, water, and c…YOUTUBE.COM
25 JunBeyond IOCs: AI-enabled threat intelligenceIn this week’s newsletter, Martin considers how AI will help threat intelligence by creating an easily queryable data source of intelligence reports.TALOSINTELLIGENCE.COM
25 JunBeware of “Parcel Expert” job offers: They’re parcel mule scamsMost parcel mule scams start with fake job offers that trick victims into handling stolen goods.MALWAREBYTES.COM
25 JunFraud goes door-to-door.This week, hosts of N2K CyberWire Maria Varmazis and Dave Bittner…THECYBERWIRE.COM
25 JunCisco Vulnerability Exploited Months Before Disclosure, Google WarnsA high-severity flaw in Cisco Catalyst SD-WAN Manager disclosed in early June was exploited as early as MarchINFOSECURITY-MAGAZINE.COM
25 JunTrust in Automated AI Vulnerability Scanning Collapses to 9%, New Study FindsCobalt study finds 20-percentage-point drop in number of organizations relying solely on AI automation for testingINFOSECURITY-MAGAZINE.COM
25 JunShopify Shop app users are seeing fake orders in purchase historiesScammers are placing fake purchase receipts inside Shopify's Shop app, exploiting users' trust in order-tracking applications to lure them into calling fraudulent customer support numbers. The campaign moves the long-running fake invoice scam beyond email, placing fraudulent rece…CYBERINSIDER.COM
25 JunJapan’s army used USB drives with Chinese malware for a yearJapan's Ground Self-Defense Force (JGSDF) reportedly used counterfeit USB flash drives infected with malware linked to previously identified Chinese threat activity on computers connected to sensitive military networks for nearly a year before the devices were discovered. Accordi…CYBERINSIDER.COM
25 JunCal Water Says No OT Systems Breached in Iranian Handala CyberattackMandiant has helped the California water utility investigate the cyberattack launched by Iranian hacker group Handala. The post Cal Water Says No OT Systems Breached in Iranian Handala Cyberattack appeared first on SecurityWeek .SECURITYWEEK.COM
25 Jun25-Year-Old Vulnerability Patched in CurlThe latest version of the open source data transfer tool resolves 18 medium and low-severity vulnerabilities. The post 25-Year-Old Vulnerability Patched in Curl appeared first on SecurityWeek .SECURITYWEEK.COM
25 JunLocal Police Collusion Hampers Crackdown on Asian Scam CentersWith tens of billions of dollars flowing into regional economies from cybercrime, scam centers continue to flourish, despite international and law-enforcement efforts.DARKREADING.COM
25 JunExperts on Experts: Why AI and Compliance Are Forcing A New Security Operating ModelThis week on Experts on Experts, I sat down with Sabeen Malik , Rapid7’s VP of Global Government Affairs and Public Policy, to discuss a shift security leaders can’t afford to treat as separate threads: frontier AI, vulnerability discovery, cybersecurity compliance, and operation…RAPID7.COM
25 JunNVIDIA GEN3C: Unauthenticated RCE via Pickle Deserialization in the Inference APIVulnCheck's Initial Access Intelligence team details an unauthenticated remote code execution in NVIDIA's GEN3C, where two FastAPI inference endpoints deserialize raw HTTP request bodies with pickle.loads() with no authentication.VULNCHECK.COM
24 JunMeta pauses employee monitoring program after data protections failAn extensive program at Meta to gather a wide range of data from employees to train its AI model has been frozen after employees reportedly broke through its guardrails and accessed restricted data, and then did so again after Meta claimed to have fixed the vulnerability. Whether…CSOONLINE.COM
24 JunAnthropic’s Mythos Model Found Vulnerabilities in Classified US Government Systems, Official SaysCome vulnerabilities were found within hours, but that does not mean the model was able to exploit them within that time, the official said. The post Anthropic’s Mythos Model Found Vulnerabilities in Classified US Government Systems, Official Says appeared first on SecurityWeek .SECURITYWEEK.COM
24 JunCybersecurity jobs available right now: June 24, 2026Application Security Leader DriveNets | Israel | Hybrid – View job details As an Application Security Leader, you will define security requirements, drive secure coding practices, oversee vulnerability management, and integrate security testing and automation into…HELPNETSECURITY.COM
24 JunRisky Business #843 -- Fortibleed is kinda awesome, actuallyOn this week’s show special guest co-host Rob Joyce joins Patrick Gray and James Wilson to discuss the week’s cybersecurity news. Rob served as an advisor to Donald Trump during his first term as president and also served at NSA for 34 years. While at the agency, Joyce led Tailor…RISKY.BIZ
24 JunPraxen: Open-source AI agent behavior verificationPraxen is an open-source tool with a simple job: it checks whether an AI agent does what it claims to do. The tool takes an agent’s declared policy, looks at how the agent operates, and points out every spot where the two drift apart. It is the reference implementation of A…HELPNETSECURITY.COM
24 JunBrinqa BYOAI lets organizations use any AI platform with trusted risk dataBrinqa BYOAI (Bring Your Own AI), a capability that enables organizations to connect any AI agent, large language model (LLM), or automation platform to Brinqa’s exposure intelligence layer. As enterprises adopt AI, they need to ensure that AI systems use accurate, up-to-date ris…HELPNETSECURITY.COM
24 JunWebinar Today: Modern Exposure Validation in the AI EraThe exploit timeline collapsed. Make sure your validation didn't. The post Webinar Today: Modern Exposure Validation in the AI Era appeared first on SecurityWeek .SECURITYWEEK.COM
24 JunKahneman, ‘Where’s Waldo’ and the Nexus pass: A CISO’s mental model for the AI eraSecurity awareness training as a defense against phishing is dead. It has been dead for a while. The industry never held a funeral because the training budget is comfortable, the compliance box gets checked and no CISO wants to tell the board that the program everyone funds does …CSOONLINE.COM
24 JunThe Strategic Human Firewall as AI Impacts Regulations, Cyber Pros, and Employees - BSW #453The 2026 Verizon DBIR has arrived and the results are in... Even with a substantial increase in Exploitation of Vulnerabilities, All Credential Abuse is still the top initial access vector for breaches, which means the human is still the weakest link. Why haven't security awarene…YOUTUBE.COM
24 JunOpen-source security is posing challenges governments can’t easily solveA diffuse landscape, fruitful targets, companies not stepping up, AI’s influence and flagging U.S. government efforts all figure into a shifting threat. The post Open-source security is posing challenges governments can’t easily solve appeared first on CyberScoop .CYBERSCOOP.COM
24 JunLastPass customer data exposed through Klue supply chain attackLastPass disclosed that attackers used OAuth tokens compromised in a supply chain attack on Klue, a market intelligence platform that integrates with CRM and sales tools across organizations, to access customer data stored in its Salesforce environment. “On June 12th LastPass was…HELPNETSECURITY.COM
24 JunHow a malicious AI agent skill passed security checks and reached 26,000 usersA fake AI agent skill that passed security checks reached over 26,000 users through Instagram, highlighting new risks as enterprises rely on AI-driven tools. Some of the agents involved were tied to corporate accounts, AIR said . The company said a similar attack could have expos…CSOONLINE.COM
24 JunExploitable CI/CD Vulnerabilities Expose Millions of Repositories to HijackingThe security defects allow unauthenticated users to take control of the open source software supply chain. The post Exploitable CI/CD Vulnerabilities Expose Millions of Repositories to Hijacking appeared first on SecurityWeek .SECURITYWEEK.COM
24 JunBeyondTrust, LastPass Impacted by Klue-Salesforce IncidentOver a dozen Klue customers have confirmed that hackers stole data from their Salesforce instances. The post BeyondTrust, LastPass Impacted by Klue-Salesforce Incident appeared first on SecurityWeek .SECURITYWEEK.COM
24 JunApple's MacOS Gap Lets Users Disable Security ToolsAttackers can exploit the issue to disable security and integrated browser tools without needing administrator privileges or kernel exploits.DARKREADING.COM
24 JunIn a first, a court takedown goes after two cybercrime tools at onceMicrosoft, with law enforcement and industry partners, disrupted more than 200 command and control servers for Amadey and StealC, often used in conjunction. The post In a first, a court takedown goes after two cybercrime tools at once appeared first on CyberScoop .CYBERSCOOP.COM
24 JunCordyceps CI/CD Flaws Expose 300+ GitHub Repositories to Supply-Chain AttacksCybersecurity researchers have flagged a new class of CI/CD workflow weakness that allows attackers to hijack workflows and compromise open-source supply chains. The "critical exploitable pattern" has been codenamed Cordyceps by Novee Security. The issue can allow full attacker c…THEHACKERNEWS.COM
24 JunmacOS Weaknesses Chained to Silently Disable Endpoint Security AgentsA standard non-admin account is sufficient to conduct an attack that exploits legitimate OS behavior rather than software vulnerabilities. The post macOS Weaknesses Chained to Silently Disable Endpoint Security Agents appeared first on SecurityWeek .SECURITYWEEK.COM
24 JunCISA warns of max severity Ubiquiti flaws exploited in attacksThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning of hackers actively exploiting flaws in Ubiquity UniFi OS and Lantronix serial-to-ethernet servers. [...]BLEEPINGCOMPUTER.COM
24 JunMicrosoft and Allies Smash Shared Infrastructure of Amadey and StealC MalwareHundreds of C&C servers were disrupted in an operation involving law enforcement and several cybersecurity companies. The post Microsoft and Allies Smash Shared Infrastructure of Amadey and StealC Malware appeared first on SecurityWeek .SECURITYWEEK.COM
24 JunAmadey, StealC, and SocGholist malware disrupted by ‘Operation Endgame’A coordinated international law enforcement and private-sector operation has dismantled major parts of the infrastructure behind the SocGholish, Amadey, and StealC malware families, seizing more than €41 million ($47 million) in cryptocurrency and disrupting hundreds of servers t…CYBERINSIDER.COM
24 JunLaw enforcement hits StealC and Amadey malware networksOperation Endgame, the largest international law enforcement operation aimed at disrupting ransomware and cybercrime infrastructure across the world, has claimed its latest targets: StealC and Amadey. The notice on disrupted websites (Source: Microsoft) While developed by separat…HELPNETSECURITY.COM
24 JunLastPass says Klue breach affected customer information, but passwords remain secure.Attackers begin exploiting Cisco Unified CM vulnerability. Alleged criminal marketplace administrator extradited to the US. Business news: Accenture acquires Dragos, runZero, and NetRise for more than $4 billion.THECYBERWIRE.COM
24 JunAmadey and StealC Malware Network Disrupted, 27M Stolen Credentials RecoveredA coordinated law enforcement operation, in partnership with private sector companies, including Bitdefender, Bitsight, ESET, and Microsoft, has resulted in the takedown of criminal infrastructure powering Amadey and StealC. "The main common goal was to disrupt the 'assembly line…THEHACKERNEWS.COM
24 JunScattered Spider duo convicted over $38M Transport for London attackTwo members of the Scattered Spide r cybercrime collective have admitted launching a cyberattack against Transport for London (TfL) that caused millions in damages. Thalha Jubair, 20, from East London, and Owen Flowers, 18, from Walsall, West Midlands, were due to stand trial for…CSOONLINE.COM
24 JunRansomware Will Hit You TwiceRansomware incidents are often treated as one-time events: pay, decrypt, recover, move on. But this conversation challenges that assumption. If the underlying vulnerability or access path isn’t fixed, attackers can return quickly and repeat the attack. In some scenarios, paying a…YOUTUBE.COM
24 JunWhen Information Becomes the Attack Surface – Understanding AI Agent TrapsFrom hidden content injections to cognitive state poisoning, attackers are turning trusted data sources into traps for autonomous AI. The post When Information Becomes the Attack Surface – Understanding AI Agent Traps appeared first on SecurityWeek .SECURITYWEEK.COM
24 JunMalicious hackers exploit Cisco zero-day for highest access level at communications service providerMandiant detailed the incident in a blog post Wednesday, but it’s unclear who was behind it or if they managed to get broad visibility into the victim’s internal traffic. The post Malicious hackers exploit Cisco zero-day for highest access level at communications service provider…CYBERSCOOP.COM
24 JunRestrict AWS Management Console access to expected networks with sign-in resource-based policies and RCPsAmazon Web Services (AWS) recently announced support for resource-based policies and resource control policies (RCPs) for AWS Sign-In. By using resource-based policies and RCPs, you can restrict access to the AWS Management Console sign-in and aws login CLI sessions to requests f…AWS.AMAZON.COM
24 Jun KEVKlue me in on the breach.LastPass says Klue breach affected customer information, but passwords remain secure. Attackers begin exploiting Cisco Unified CM vulnerability. CISA flags actively exploited Ubiquiti and Lantronix flaws, urges rapid patching. DifyTap flaws could expose private AI conversations a…THECYBERWIRE.COM
24 JunThree ‘cybercrime as a service’ operations undercut by Microsoft, law enforcementMicrosoft touted its latest action against malware infrastructure as a new approach aimed at the full cybercrime "supply chain." Europol said more than 300 servers were targeted.THERECORD.MEDIA
24 JunCNAPP evolution: How Microsoft aligns with leading cloud risk management platformsLearn how CNAPP platforms are helping organizations prioritize exploitable risks, reduce exposure, and operationalize security across the application lifecycle. The post CNAPP evolution: How Microsoft aligns with leading cloud risk management platforms appeared first on Microsoft…MICROSOFT.COM
23 JunChange your cyber risk strategy to meet AI threats, Five Eyes countries warn CSOsCSOs must re-write their cyber risk strategies because threat actors are increasing using AI to evade defenses, says a group of national cybersecurity agencies – a call that one expert immediately complained is too vague to be of use. In its call to action on Monday , the group w…CSOONLINE.COM
23 JunFree, no-signup World Cup streams serve scams instead of footballResearchers at Malwarebytes identified dozens of websites claiming to offer free access to FIFA World Cup matches. Instead of streaming games, the sites directed visitors through a chain of advertising pages designed to generate revenue for their operators. Fake World Cup streami…HELPNETSECURITY.COM
23 JunA $1,400 experiment in AI security auditing outperformed OpenAI’s Codex SecurityA research team has built a system that teaches AI agents to hunt for software bugs by writing the audit method down as plain text. The system, called EVOHUNT, keeps the underlying AI model fixed and improves only an external “playbook” that tells the agent how to wor…HELPNETSECURITY.COM
23 JunResidential proxy SDKs are hiding in LG and Samsung smart TV appsSmart TVs in living rooms run small apps that show fish tanks, clocks, solitaire games, and slideshows of puppies. A share of those apps can also send other people’s internet traffic out through the home connection. Spur Intelligence scanned 6,038 apps across LG webOS and S…HELPNETSECURITY.COM
23 JunCybersecurity is no longer about protection. It’s about survival.For years, cybersecurity professionals have been repeating the same warning: Every company will eventually be breached. Fine. Let’s accept that. Then why do so many organizations still behave as if the near sole purpose of cybersecurity is to prevent the breach from ever happenin…CSOONLINE.COM
23 JunOpenAI wants AI to fix vulnerabilities, not just find themOpenAI expanded Daybreak, its cybersecurity initiative that combines AI models, Codex Security, security researchers, maintainers, industry partners, and access controls to support vulnerability discovery and remediation. Organizations can use the initiative to identify, validate…HELPNETSECURITY.COM
23 JunPhishing hides in routine Microsoft 365 workflowsAttackers are abusing Outlook Groups and Microsoft 365 collaboration features to make phishing campaigns appear routine, according to Fortra. “The technique shifts malicious intent away from a single phishing email into a trusted productivity workflow. A user may see what l…HELPNETSECURITY.COM
23 JunHow AI Is Reshaping Identity Security at the Infrastructure Layer - Ev Kontsevoy, Neha... - ASW #388Appsec has seen machine identities from daemons and processes to services, microservices, and cloud accounts. And now we have agents. Ev Kontsevoy talks about what it means to have engineers and agents interacting in an environment, and why a focus on actions can be more effectiv…YOUTUBE.COM
23 JunHack The Box adds crisis simulations and SOC training to strengthen cyber readinessHack The Box (HTB) has announced new capabilities to help security leaders gain greater visibility into skills, performance and operational readiness. As AI transforms cyberattacks and cybersecurity operations, HTB is expanding its cyber readiness platform to help organizations i…HELPNETSECURITY.COM
23 JunOpenAI rolls out AI-led push to fix open-source software flawsOpenAI has launched a program with cybersecurity firm Trail of Bits to use AI to find and fix vulnerabilities in widely used open-source software, as enterprises face growing risks from flaws buried deep in their software supply chains. The initiative, called Patch the Planet , u…CSOONLINE.COM
23 JunPutin’s Paramilitary 2.0Since its emergence in 2014, the Wagner Group operated as the Kremlin's shadow army, deploying mercenaries across Africa and the Middle East. It gave Vladimir Putin plausible deniability, expanding Moscow's geopolitical influence by propping up leaders through military assistance…THECYBERWIRE.COM
23 JunLastPass says customer data exposed in Klue supply chain breachLastPass has disclosed that customer contact and CRM data were exposed after attackers compromised Klue, a third-party market intelligence platform used by its go-to-market teams. According to a security advisory published by LastPass, the company was notified on June 12 about a …CYBERINSIDER.COM
23 JunFFmpeg PixelSmash Flaw Allows RCE on Video Players, Media Servers, NAS AppliancesAttackers can send crafted media files to execute code in any application that uses FFmpeg’s libavcodec library. The post FFmpeg PixelSmash Flaw Allows RCE on Video Players, Media Servers, NAS Appliances appeared first on SecurityWeek .SECURITYWEEK.COM
23 JunUnpatched SharePoint servers opened the door to multiple attackers, Microsoft findsWhat began as a routine ransomware investigation uncovered two unrelated attackers operating inside the same victim network at the same time, each obscuring the other’s activity and complicating the response. The discovery emerged during a Microsoft Detection and Response Team (D…CSOONLINE.COM
23 JunWhat the Miasma campaign reveals about the new supply chain threat model and the underground market for developer credentialsA stolen session cookie sat in underground markets for seven weeks before attackers used it to poison 32 Red Hat packages in the npm software registry, an example of the industrial approach behind modern supply chain attacks. Key takeaways Miasma is a self-propagating npm worm de…TENABLE.COM
23 JunEight-Year-Old Samsung KNOX Flaw Exposed Millions of Galaxy Devices to Kernel AttacksThe high-severity use-after-free vulnerability in Samsung's KNOX security framework affected Android-powered Galaxy devices from the S9 through S25. The post Eight-Year-Old Samsung KNOX Flaw Exposed Millions of Galaxy Devices to Kernel Attacks appeared first on SecurityWeek .SECURITYWEEK.COM
23 JunAlgerian Man Extradited to US for Running Cybercrime Marketplaces26-year-old Abdellah Belmili faces up to 30 years in prison for allegedly operating the marketplaces Market0Day and Spoxy. The post Algerian Man Extradited to US for Running Cybercrime Marketplaces appeared first on SecurityWeek .SECURITYWEEK.COM
23 JunLastPass confirms data breach in Klue supply chain attackLastPass announced that hackers accessed customer data from its Salesforce environment after stealing the company's OAuth tokens in the Klue supply chain attack earlier this month. [...]BLEEPINGCOMPUTER.COM
23 JunUsing Reddit to manipulate AI search results is surprisingly easyA Reddit comment that takes only a few seconds to write can end up influencing the answers generated by AI research tools. A Cornell Tech study found that a short snippet of user-generated text, sometimes as little as 13 words, was enough to affect the output of deep-research age…HELPNETSECURITY.COM
23 JunGitHub Updates actions/checkout to Block Common Pwn Request Attack PatternsGitHub is moving to strengthen software supply chain security by updating "actions/checkout" to block pwn request attacks that exploit the risky use of the "pull_request_target workflow" trigger to run malicious code with the workflow's full privileges. Effective June 18, 2026, t…THEHACKERNEWS.COM
23 JunThe Exploit Doesn't Exist. You Can Still Prove It Works Against YouAttackers can now weaponize newly disclosed vulnerabilities far faster than most organizations can patch them. Picus Security explains how security teams can validate exploitability before a public exploit even exists. [...]BLEEPINGCOMPUTER.COM
23 JunFive Eyes allies warn of dangers posed by frontier AI models.Researchers publish a new analysis of FortiBleed. BootROM exploit can bypass Apple's SecureROM. Scattered Spider members plead guilty in the UK.THECYBERWIRE.COM
23 JunKlue investigating supply chain attack that targeted Salesforce integrationsCustomer data from several prominent cybersecurity firms was among that of hundreds of potential enterprise victims.CYBERSECURITYDIVE.COM
23 JunWhy SIEM is Moving Toward Unified Security Operations: Rapid7 Named a Major Player in IDC MarketScapeRapid7 has been named a Major Player in the IDC MarketScape: Worldwide SIEM 2026 Vendor Assessment (#US54126826, June 2026). This is the first IDC SIEM MarketScape to bring the enterprise and SMB markets into a single evaluation, and we believe it arrives at a time when the way t…RAPID7.COM
23 JunTrump sets post-quantum crypto deadlines, launches broader federal quantum initiativeUS President Donald Trump on Monday signed a pair of executive orders aimed at accelerating the federal government’s transition to post-quantum cryptography while expanding US investment in quantum technologies, establishing what the administration describes as a coordinated stra…CSOONLINE.COM
23 JunAll eyes on AI.Five Eyes warns AI could supercharge cyberattacks within months. Tata Electronics confirms breach as stolen data allegedly includes Apple and Tesla documents. Researchers publish new analysis of FortiBleed. Gizmodo breach exposes readers to ClickFix malware campaign. BootROM expl…THECYBERWIRE.COM
23 JunTuring, BODS, Struwwelpeter, EO-14409, VBScript, Pixemsmash, Cloudflare, Aaran Leylan - SWN #592Turing's Entscheidungsproblem, BODS, Struwwelpeter, EO-14409, VBScript, Pixemsmash, Cloudflare, Aaran Leyland, and More on the Security Weekly News. Visit https://www.securityweekly.com/swn for all the latest episodes! Show Notes: https://securityweekly.com/swn-592YOUTUBE.COM
23 JunScope of Salesforce Attacks Expands as Icarus Leaks DataMore victims have emerged after attackers breached application vendor Klue and used its OAuth tokens to steal customers' Salesforce data.DARKREADING.COM
22 JunStolen OAuth Tokens Hit Security Firms, AryStinger Router Botnet Emerges, AI Deepfake CyberstalkingA breach at market intelligence platform Klue allowed attackers to steal OAuth tokens linking Clue to customers' Salesforce environments, enabling quiet API-driven data extraction from firms including Huntress, Recorded Future, Tanium, and Jamf; Clue revoked tokens, removed the l…CYBERSECURITYTODAY.LIBSYN.COM
22 JunWhy Southeast Asia CISOs Need Zero Trust as Their AI Control Plane – AI Agents, Data Borders and Supply ChainsAt Zenith Live 2026 held on 16-17 June in Vienna, Zscaler sharpened a reality that Southeast Asia CIOs and CISOs are already sensing, which are, AI agents are quickly becoming digital workers inside their organisations, while regulators tighten data residency rules and supply‑cha…CSOONLINE.COM
22 JunHundreds of AI-powered iOS apps found exposing credentialsMobile app developers are packing AI features into everything from writing assistants to productivity tools and lifestyle apps. New research shows that securing access to those services remains a challenge. LLM API credential leakage via network traffic interception (Source: Rese…HELPNETSECURITY.COM
22 JunAgent Beacon: Open-source telemetry layer for AI agentsAI coding agents such as Claude Code, Codex CLI, Cursor, and Claude Cowork run on developer laptops, CI jobs, cloud environments, where they edit files, run commands, and call outside tools. Beacon, an open-source project from Asymptote Labs, configures telemetry for those runtim…HELPNETSECURITY.COM
22 JunAnatomy of a retail ransomware attack: Tabletop simulates modern mayhem methodsAttacks on AI systems and disinformation starred as key elements of a ransomware tabletop exercise CSO participated in during this month’s Infosecurity Europe conference. The “Enter the War Room” exercise — organised and run by cybersecurity vendor Semperis — featured a scenario …CSOONLINE.COM
22 Jun6 security leader tips for mastering business riskLongtime security leader Doug Kersten has expanded his list of responsibilities. As CISO of software maker Appfire, he now has accountability for business risks, such as how security tools and processes within customer products and services impact their costs and, thus, profitabi…CSOONLINE.COM
22 JunNavigating Shadow AI in the Enterprise, Verizon's SECOND 2026 report, and the news - ESW #464Interview with Ankita Gupta, CEO of Akto _How to Navigate Shadow AI Risk in the enterprise_ This week, we discuss AI governance in the enterprise, starting with the nuts and bolts of how to discover and understand shadow AI. Following that, we dive into what security and tech lea…YOUTUBE.COM
22 JunKlue Breach Enables Hackers to Compromise Cybersecurity Firms via OAuth TokensAt least five cybersecurity firms confirmed they have been affected by a breach of business intelligence platform Klue via Salesforce integrationINFOSECURITY-MAGAZINE.COM
22 JunWhat the Latest ShinyHunters Breaches Reveal About Modern CyberattacksGroups like ShinyHunters are demonstrating that attackers do not necessarily need malware or zero-day exploits to cause massive damage. The post What the Latest ShinyHunters Breaches Reveal About Modern Cyberattacks appeared first on SecurityWeek .SECURITYWEEK.COM
22 JunNew Exploit Bypasses Apple’s Boot Defenses, Affects Millions of iPhonesThe vulnerability exploited by the Usbliter8 exploit cannot be patched and a PoC exploit has been released by researchers. The post New Exploit Bypasses Apple’s Boot Defenses, Affects Millions of iPhones appeared first on SecurityWeek .SECURITYWEEK.COM
22 JunAttackers Exploit Gravity SMTP Plugin Flaw to Harvest Valuable WordPress DataVulnerable WordPress plugin iterations leak API keys, secrets, tokens, server information, and other data. The post Attackers Exploit Gravity SMTP Plugin Flaw to Harvest Valuable WordPress Data appeared first on SecurityWeek .SECURITYWEEK.COM
22 JunNew OXLOADER Loader Uses Malicious Google Ads to Deliver CastleStealerCybersecurity researchers have disclosed details of a new campaign that delivers CastleStealer by means of a previously unreported malware loader dubbed OXLOADER. According to Elastic Security Labs, the campaign leverages malicious Google Ads as a starting point to distribute the…THEHACKERNEWS.COM
22 JunThe Hidden Risk of Shadow AIShadow AI now includes far more than employees casually using ChatGPT. Organizations are seeing AI agents, MCPs, LLMs, and AI databases quietly appear across enterprise environments. The danger isn’t necessarily the technology itself. It’s visibility. Security teams often have no…YOUTUBE.COM
22 JunUnpatchable BootROM Flaw Impacts Apple A12, A13 ChipsApple BootROM exploit exposes unpatchable USB flaw on A12 and A13 devicesINFOSECURITY-MAGAZINE.COM
22 JunDecades-Old Squid Proxy Flaw ‘Squidbleed’ Can Expose User DataSquidbleed, discovered with the aid of Claude Mythos Preview, has been described as a Heartbleed-style vulnerability. The post Decades-Old Squid Proxy Flaw ‘Squidbleed’ Can Expose User Data appeared first on SecurityWeek .SECURITYWEEK.COM
22 Jun29-Year-Old Squid Proxy Bug 'Squidbleed' Can Leak Cleartext HTTP RequestsA heap over-read in the Squid web proxy can leak another user's cleartext HTTP request, including any credentials or session tokens it carries, to anyone already allowed to send traffic through the same proxy. The bug traces to a 1997 FTP-parsing change and is still live in Squid…THEHACKERNEWS.COM
22 JunResearchers Detail DifyTap Flaws in Dify That Could Expose AI Chats Across TenantsCybersecurity researchers have disclosed details of four vulnerabilities in Dify, an open-source agentic workflow platform with more than 146,000 GitHub stars, that could allow attackers to stealthily read artificial intelligence (AI) conversions from other customers' application…THEHACKERNEWS.COM
22 JunAWS Continuum offers devs help with securing codeAI coding agents are making it easier than ever to produce software. Ensuring that software is secure before deployment is another matter — one that AWS thinks AI should help with too. As enterprises adopt agentic development workflows, the volume of first-party code being create…CSOONLINE.COM
22 JunKlue breach exposed Salesforce CRM data through stolen OAuth tokensAn attacker broke into competitive-intelligence vendor Klue, stole OAuth tokens its customers use to connect to Salesforce and other platforms, and accessed data across multiple customer environments prompting the company to revoke customer OAuth tokens and disable affected integ…CSOONLINE.COM
22 JunIntroducing Patch the PlanetWhat happens when you clear dozens of Trail of Bits engineers’ schedules, pair them with every open-source maintainer they can contact, and unleash the latest frontier models like GPT-5.5-Cyber on critical open-source targets? Thanks to our partnership with OpenAI and its Daybrea…TRAILOFBITS.COM
22 JunOpenAI Launches Full-Scale Effort to Patch Open-Source Bugs as It Takes on Anthropic’s MythosAmid concerns about AI models’ cybersecurity capabilities, OpenAI revealed an improved version of GPT-5.5-Cyber and its “Patch the Planet” initiative to fix open-source software bugs.WIRED.COM
22 JunMicrosoft fixes AutoGen Studio flaw that enabled code executionA vulnerability chain dubbed AutoJack in Microsoft's AutoGen Studio interface for prototyping AI agents could let attackers manipulate an agent into executing arbitrary commands on its host system simply by visiting a malicious webpage. [...]BLEEPINGCOMPUTER.COM
22 JunA new unpatchable flaw in Apple chips opens the door to an iPhone jailbreakEuropean offensive cybersecurity company Paradigm Shift released details of a flaw and a technique to exploit it that opens the door for hackers to unlock and break into older iPhones.TECHCRUNCH.COM
22 JunAI Guardrails Could BackfireAs commercial AI systems add more restrictions and moderation layers, some users are already moving toward open-source alternatives that offer fewer limitations and more control. The argument here is simple: once AI capability exists publicly, it becomes extremely difficult to su…YOUTUBE.COM
22 JunTrump administration to order agencies to speed up post-quantum migration, boost industryBoth EOs are expected to be signed as soon as Monday per an industry source with knowledge of timing. The White House has a signing ceremony scheduled this afternoon. The post Trump administration to order agencies to speed up post-quantum migration, boost industry appeared first…CYBERSCOOP.COM
22 JunFFmpeg fixes PixelSmash flaw in widely used video decoderA newly disclosed FFmpeg flaw dubbed 'PixelSmash' could be exploited for remote code execution on Jellyfin servers under certain conditions, and can also trigger a denial-of-service condition in applications like Kodi, Emby, Nextcloud, PhotoPrism, and OBS Studio. [...]BLEEPINGCOMPUTER.COM
22 JunThe Global Namespace Risk: Universal Bucket Hijacking Technique for Cloud Data ExfiltrationUnit 42 research details how attackers could exploit global name uniqueness in bucket hijacking to redirect cloud data streams across major CSPs. The post The Global Namespace Risk: Universal Bucket Hijacking Technique for Cloud Data Exfiltration appeared first on Unit 42 .UNIT42.PALOALTONETWORKS.COM
22 JunGitHub Actions hardens checkout security to block ‘pwn request’ attacksStung by a surge in cyberattacks that have run amok in developer environments, GitHub has strengthened the security of actions/checkout to block ‘pwn request’ attacks that exploit insecure use of the pull_request_target workflow trigger to run an attacker’s code with the workflow…CSOONLINE.COM
21 JunVulnerability response: Built for humans, outpaced by machines.For years, security teams had time between discovery and exploitation. Time to triage. Time to validate. Time to prioritize what to fix first. AI has compressed that window. Frontier models now discover and chain vulnerabilities faster than human analysts can confirm them, and th…THECYBERWIRE.COM
21 JunWeek in review: 74k Fortinet firewall credentials stolen, Splunk Enterprise RCE under active attackHere’s an overview of some of last week’s most interesting news, articles, interviews and videos: A hardware neural network backdoor that hides in plain sight Deep learning systems on edge devices often rely on third-party-designed FPGAs and ASICs for performance and efficiency, …HELPNETSECURITY.COM
20 Jun5 People You Meet In Cybersecurity - David Shipley Interviews Amy LeeIn this special Cybersecurity Today weekend interview, host David Shipley speaks with Amy Yee about leadership, resilience, and the human side of cybersecurity. Amy shares her remarkable journey from electrical engineering and venture capital to becoming the inaugural Chief Digit…CYBERSECURITYTODAY.LIBSYN.COM
20 JunUnpatchable 'usbliter8' Exploit Breaks Apple A12 and A13 SecureROM Boot ChainSecurity researchers at Paradigm Shift have published a working exploit, dubbed usbliter8, that achieves arbitrary code execution inside the SecureROM of Apple's A12 and A13 chips. That code is burned into the silicon at manufacture. No software update can reach it…THEHACKERNEWS.COM
20 JunJCPenney - 368,418 breached accountsIn June 2026, retailer JCPenney and associated brands were targeted in a ShinyHunters "pay or leak" extortion campaign . Data allegedly obtained from JCPenney through the exploitation of a critical zero-day vulnerability in Oracle PeopleSoft was later published publicly. The expo…HAVEIBEENPWNED.COM
20 JunPeeling back Banana RAT.This week, we are joined by Tom Kellermann, Trend Micro's VP of AI Security and Threat Research, discussing their work on "Inside SHADOW-WATER-063’s Banana RAT: From Build Server to Banking Fraud." Researchers from Trend Micro's MDR team uncovered the full operation behind Banana…THECYBERWIRE.COM
20 JunAnthropic suspends Fable over US national security concerns.ShinyHunters leaks data allegedly stolen from Madison Square Garden. Law enforcement cleans up 15,000 malware-infected websites.THECYBERWIRE.COM
19 JunFriday Squid Blogging: Victims of Unregulated Squid FishingDolphins, sharks, turtles, and human workers are all victims of unregulated squid fishing fleets. Another news article . As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered. Blog moderation policy.SCHNEIER.COM
19 JunAutoJack Attack Lets One Web Page Hijack AI Agent for Host Code ExecutionMicrosoft researchers have detailed an exploit chain, named AutoJack, that turns an AI browsing agent into a delivery vehicle for remote code execution. Steer the agent to load an attacker's web page, and that page's JavaScript can reach a privileged local service on the sam…THEHACKERNEWS.COM
19 JunOperation Endgame Disrupts SocGholish Servers, Cleans 14,971 WordPress SitesDutch law enforcement authorities, along with counterparts from Canada , Germany, and the U.S., have disrupted malicious infrastructure associated with SocGholish and cleaned up nearly 15,000 infected WordPress websites. "With these actions we deprive cybercriminals of access to …THEHACKERNEWS.COM
19 JunSalesforce Disables Klue App Integration After OAuth Token Abuse Exposes Customer DataSalesforce has revealed that it disabled the Klue Battlecards app integration within its platform in response to a security incident impacting the competitive intelligence company on June 11, 2026. To that end, organizations will be unable to connect to Salesforce via the app unt…THEHACKERNEWS.COM
19 JunThreat actor adds advanced ‘EDR killer’ tools to ransomware-as-a-service platformOne of the world’s top ransomware groups has given its criminal affiliates access to advanced tools capable of successfully disabling many of today’s enterprise endpoint detection and response (EDR) products, new research by security company ESET has found. The group in question …CSOONLINE.COM
19 JunBreaking the SOC triangle: How AI reshapes security operations trade-offsA simple framework has always governed security operations that I call the SOC Triangle. It is a balance between quality, consistency and cost efficiency. Every SOC operates within it. Push for higher-quality investigations, deeper analysis, richer context, fewer missed signals a…CSOONLINE.COM
19 JunSecurity considerations for adopting Claude Code and Cowork for SMBsYou are a security leader at a small or medium-sized business (SMB), and your organization has decided to adopt Claude. If you are like me, after the initial “surprise” wears off, you probably want to quickly get your arms around what adopting Claude means for the business, and f…CSOONLINE.COM
19 JunMicrosoft says web-enabled AI agents can trigger host-level RCEMicrosoft is warning of a novel remote code execution (RCE) path possible through web-enabled AI agents, demonstrating the technique against AutoGen Studio, its open-source interface for building and testing multi-agent applications. The demonstration showed that a malicious webp…CSOONLINE.COM
19 JunLLMS, Identity, EDR, JiGong, QiLin, Warlock, with Rob Allen from Threatlocker - SWN #591Doug and Rob Allen talk about Identity, EDR, Your Great Aunt Ida Meets some hot firefighters, and more. Segment Resources: Qilin and Warlock Ransomware Use Vulnerable Drivers to Disable 300+ EDR Tools: https://thehackernews.com/2026/04/qilin-and-warlock-ransomware-use.html This s…YOUTUBE.COM
19 JunMost Companies Needed To Be Forced#PCI #ComplianceThe clip argues that standards like PCI helped push organizations toward foundational cybersecurity practices by tying security requirements directly to payment processing and business operations. For many companies, compliance became the forcing function that mov…YOUTUBE.COM
19 JunApple patches Beats Studio Buds flaw that could turn earbuds into a wiretapApple has patched a year-old Bluetooth vulnerability that could have let nearby attackers listen through Beats Studio Buds' microphone.MALWAREBYTES.COM
19 JunCyberWire Daily at 10: A decade of leaks, espionage, and influence operations.In this special edition of CyberWire Daily’s 10th anniversary series, N2K CyberWire's Maria Varmazis and Dave Bittner discuss leaks, espionage and influence operations over the past 10 years. Together they reflect on a decade of cybersecurity developments, focusing on the piv…THECYBERWIRE.COM
19 JunAWS Unveils 'Continuum,' an AI-Powered Vulnerability Management PlatformWorking with frontier AI models, this new platform aims to help discovering, prioritizing, validating and remediating code vulnerabilitiesINFOSECURITY-MAGAZINE.COM
19 JunUnpatchable BootROM exploit for Apple A12-A13 chips now publicSecurity researchers at Paradigm Shift have disclosed usbliter8, a new SecureROM exploit affecting Apple's A12 and A13 chipsets. The proof-of-concept exploit achieves BootROM compromise through a combination of a USB controller hardware bug and a firmware configuration weakness, …CYBERINSIDER.COM
19 JunTexas exposed data of 3 million hunting and fishing license holdersThe Texas Parks and Wildlife Department (TPWD) has disclosed a cybersecurity incident affecting its hunting and fishing license system vendor, potentially exposing the personal information of more than 3 million people. The incident was identified by the Texas Cyber Command, whic…CYBERINSIDER.COM
19 JunKlue OAuth breach victim list grows as Icarus hackers claim attackMarket intelligence platform Klue has publicly confirmed a recent security incident that allowed threat actors to steal OAuth tokens used to connect to customers' Salesforce environments, as the new "Icarus" extortion group publicly claims the attack. [...]BLEEPINGCOMPUTER.COM
19 JunHackers exploit info disclosure bug in Gravity SMTP WordPress pluginThreat actors are exploiting an unauthenticated information disclosure vulnerability in the WordPress plugin Gravity SMTP, active on 100,000 sites. [...]BLEEPINGCOMPUTER.COM
19 JunTexas govt data breach exposes over 3 million driver’s licensesThe Texas Parks and Wildlife Department (TPWD) disclosed a data breach at its license system vendor that exposed personal information for more than three million individuals. [...]BLEEPINGCOMPUTER.COM
19 Jun KEVCISA: Splunk Enterprise flaw actively exploited, patch by SundayCISA has urged U.S. federal agencies to secure their systems by Sunday against a critical Splunk Enterprise vulnerability that is being exploited in attacks. [...]BLEEPINGCOMPUTER.COM
19 JunIn Other News: Apple Patches Beats Eavesdropping Flaw, DOT Closes Delta CrowdStrike Probe, AWS ContinuumOther noteworthy stories that might have slipped under the radar: Android TV botnet Popa linked to Israeli firm, Velvet Ant maintained decade-long stealth, unpatched GCP Config Connector flaw enables takeover. The post In Other News: Apple Patches Beats Eavesdropping Flaw, DOT Cl…SECURITYWEEK.COM
19 JunCryptoBandits Malware Doubles as a Backdoor, Abuses TorCryptoBandits uses a local SOCKS5 proxy for traffic routing, blending data theft with remote code execution. The post CryptoBandits Malware Doubles as a Backdoor, Abuses Tor appeared first on SecurityWeek .SECURITYWEEK.COM
19 JunCybersecurity Firms Impacted by Klue Supply Chain AttackThe hackers exfiltrated data from Salesforce instances of Klue customers, such as Huntress and Recorded Future. The post Cybersecurity Firms Impacted by Klue Supply Chain Attack appeared first on SecurityWeek .SECURITYWEEK.COM
19 Jun15,000 WordPress Websites Cleaned Up in SocGholish Botnet TakedownLaw enforcement and private partners took down 106 SocGholish C&C servers and domains as part of Operation Endgame. The post 15,000 WordPress Websites Cleaned Up in SocGholish Botnet Takedown appeared first on SecurityWeek .SECURITYWEEK.COM
19 JunKlue breach lead to Salesforce data theft, Huntress affectedCybersecurity vendor Huntress was among multiple companies hit by a breach originating at Klue, a market intelligence platform used to integrate CRM and sales data across various business tools. Huntress published a detailed account of the incident on June 18, framing it as a …HELPNETSECURITY.COM
19 JunMastodon 4.6 adds profile Collections and two-factor controlsPeople who run accounts on the open source social network Mastodon can now group profiles together and share those groups across the web. The 4.6 release centers on a feature called Collections, along with reworked profiles, email newsletters, server administration controls, and …HELPNETSECURITY.COM
19 JunGoogle sets timeline for Android developer verification enforcementAndroid’s developer verification protections will take effect on September 30, 2026, starting with users in Brazil, Indonesia, Singapore, and Thailand. Developers distributing apps through participating stores in those markets must complete the verification process by the deadlin…HELPNETSECURITY.COM
19 JunCompanies are discarding the logs they need to catch a breachMany large enterprises discard most of the log data their systems generate, and they do it on purpose to keep costs down. A Dynatrace survey of 450 senior IT leaders at large enterprises found that half of organizations drop or never collect an average of 86 percent of their logs…HELPNETSECURITY.COM
19 JunAutoJack: How a single page can RCE the host running your AI agentAutoJack is a novel exploit chain showing how a single malicious webpage can turn an AI browsing agent into a remote code execution vector on the host machine. By abusing trust in localhost, missing authentication, and unsafe parameter handling, attackers can trigger arbitrary pr…MICROSOFT.COM
18 JunThe Behavior of Coordinated SSH Brute Force Attacks over the last three months [Guest Diary], (Wed, Jun 17th)[This is a Guest Diary by Adam Nason, an ISC intern as part of the SANS.edu BACS program]
ISC.SANS.EDU
18 JunMost agentic AI projects in production have stalled over data problemsEnterprises are connecting AI agents to live data feeds and putting them to work on tasks that once required human review, from IT operations to software development. The number doing this in production reached 32 percent in 2026, up from 29 percent the year before, according to …HELPNETSECURITY.COM
18 JunCan Agentic AI Really Find Zero-Days? Ask the Hacker Who Won Pwn2Own Berlin 2026At Pwn2Own Berlin 2026, a security researcher used agentic AI to help her win. The AI surfaced real, verified bugs, then wrongly called her winning bug “not unexploitable in practice.” Spoiler - it was.That uneven record is exactly what security leaders need to understand about t…THECYBERWIRE.COM
18 JunNever gonna give you up, never gonna take this call.This week, hosts of N2K CyberWire Maria Varmazis and Dave Bittner …THECYBERWIRE.COM
18 JunAWS Continuum brings AI models to code vulnerability managementAWS Continuum for code vulnerabilities, a system built to handle a vulnerability across its lifecycle, from discovery through to a fix, is now available in gated preview. It reasons over a customer’s environment, confirms which findings are real, and works toward resolution…HELPNETSECURITY.COM
18 JunGoogle’s open standard for AI agents to discover and verify toolsAI agents depend on tools, skills, and other agents spread across many teams, organizations, and platforms. These capabilities live in separate systems with their own registries, and an agent working in one environment has limited means to locate and connect to a resource hosted …HELPNETSECURITY.COM
18 JunCybersecurity was built for predictable systems. AI changes the rulesEvery major technology shift changes cybersecurity. I’ve spent much of my career working through major technology transitions, from the rise of the commercial internet to mobile and cloud computing. Each shift created new opportunities for innovation, but it also created new secu…CSOONLINE.COM
18 JunNew CISO appointments 2026The upper ranks of corporate security are seeing a high rate of change as companies try to adapt to the evolving threat landscape. Many companies are hiring a chief security officer (CSO) or chief information security officer (CISO) for the first time to support a deeper commitme…CSOONLINE.COM
18 JunMicrosoft warns of USB worm-like malware using Tor for stealthMicrosoft has identified a cryptocurrency clipper malware campaign, active since February 2026, that combines USB-based propagation, a Tor-hidden command-and-control infrastructure, and remote code execution capabilities. The malware steals cryptocurrency seed phrases and private…CYBERINSIDER.COM
18 JunCritical Command Execution Vulnerability Patched in Cisco ISEInsufficient validation of user input allows an attacker to gain access to the underlying OS and elevate their privileges to root. The post Critical Command Execution Vulnerability Patched in Cisco ISE appeared first on SecurityWeek .SECURITYWEEK.COM
18 Jun KEVFortiBleed campaign exposes 75,000 Fortinet firewalls worldwideA massive credential-compromise campaign dubbed “Fortibleed” has been found to expose tens of thousands of Fortinet devices worldwide, with researchers warning of persistent attacker access to affected enterprise environments. The campaign was first flagged by security researcher…CSOONLINE.COM
18 JunLATAM Infrastructure Hit by Fortinet and Ivanti ExploitsCloudSEK maps Operation Escaneo, a campaign hitting Latin American infrastructure via perimeter bugsINFOSECURITY-MAGAZINE.COM
18 JunAttackers abuse Google Ads, GitLab, and Claude to deliver malwareThreat actors are abusing trusted platforms, including Google Ads, GitLab pages, and Claude’s shared chat feature, to trick users into executing malicious commands on their systems. Disguised as popular AI developer tools, the threat actors used ClickFix social engineering attack…CSOONLINE.COM
18 JunNo Exploits RequiredFour decades of incident response experience suggest that exploits are often the symptom, not the root cause, of today’s cybersecurity failures. The post No Exploits Required appeared first on SecurityWeek .SECURITYWEEK.COM
18 JuneSentire links AI-led penetration testing with MDR through Atlas PreempteSentire has announced the launch of Atlas Preempt, a component of the company’s Atlas Platform. Atlas Preempt performs continuous, AI-driven offensive testing against customer environments to identify which exposures attackers can reach and feeds that data into eSentire’s 24/7 M…HELPNETSECURITY.COM
18 JunDragonForce Hackers Abuse Microsoft Teams Relays to Hide Backdoor.Turn C2 TrafficThreat actors associated with the DragonForce ransomware have been observed using a custom Go-based remote access trojan (RAT) called Backdoor.Turn to conceal command-and-control (C2) traffic inside Microsoft Teams relay infrastructure. According to findings from Broadcom-owned S…THEHACKERNEWS.COM
18 JunMicrosoft working on a fix for RoguePlanet, a flaw that grants full PC controlMicrosoft says it's working on a fix for an unpatched Defender vulnerability that can give attackers the highest level of access on Windows.MALWAREBYTES.COM
18 JunPolice cleans nearly 15,000 SocGholish-infected sites tied to Evil CorpInternational law enforcement agencies cleaned nearly 15,000 malware-infected WordPress websites and took down more than 100 servers linked to the SocGholish botnet and the Evil Corp Russian cybercrime group. [...]BLEEPINGCOMPUTER.COM
18 JunMicrosoft Details Windows Clipper Malware Campaign Using USB LNK Worm and Tor-Based C2Microsoft has disclosed details of a Windows-based cryptocurrency clipper campaign that has targeted users since February 2026. "The clipper in this campaign relies on Windows Script Host and ActiveX-driven logic to launch a bundled Tor proxy and poll a hidden-service C2 [command…THEHACKERNEWS.COM
18 JunAssume You’ve Already Been HackedThe idea that an organization will “never be hacked” is becoming increasingly unrealistic. Many security teams now operate with an “assumed breach” mindset, planning around the expectation that compromise will eventually happen. That changes the entire defensive strategy. Instead…YOUTUBE.COM
18 JunKlue OAuth breach linked to 'Icarus' Salesforce data theft attacksMarket intelligence platform Klue suffered a OAuth breach that enabled the "Icarus" threat actors to steal Salesforce CRM data from multiple organizations in an ongoing extortion campaign. [...]BLEEPINGCOMPUTER.COM
18 JunLaw enforcement hits SocGholish: 106 servers down, 15,000 sites cleanedSocGholish, an operation that’s been delivering malware to users via fake software updates, has suffered a major blow: the international law enforcement coalition behind Operation Endgame has taken down 106 of its servers and domains, and cleaned up nearly 15,000 websites c…HELPNETSECURITY.COM
18 JunHow software development’s speed obsession enabled TeamPCP’s chaos crusadeThe threat group’s remarkable success targeting open-source software was inevitable and fueled by the industry’s decision to prioritize code shipping over security. The post How software development’s speed obsession enabled TeamPCP’s chaos crusade appeared first on CyberSc…CYBERSCOOP.COM
18 JunApple fixes Beats Studio Buds flaw that allowed nearby attackers to eavesdropApple has released Beats Firmware Update 1B211 to address a Bluetooth vulnerability affecting Beats Studio Buds that could allow a nearby attacker to listen through a device's microphone before it has been paired. The flaw is part of a broader set of vulnerabilities disclosed las…CYBERINSIDER.COM
18 JunWhy Security Teams Need To Start EarlierSecurity leaders are facing an unusual set of circumstances. The drumbeat for better security prioritization has been rising for years in boardrooms around the world. The desire is there, but the processes of the past aren’t meeting the needs of the new moment we find ourselves i…RAPID7.COM
18 JunThreatsDay Bulletin: Claude Chat Abuse, NastyC2 npm Packages, Device-Code Phishing + 25 More StoriesThe internet did not break this week. It got used exactly as designed, which is worse. Searches were siphoned through shady browser add-ons. AI chat links turned into malware delivery paths. macOS attacks ran in memory and left almost nothing behind. Cloud agents looked like help…THEHACKERNEWS.COM
18 JunLaw enforcement cleans up 15,000 malware-infected websites.Dutch police arrest alleged helpdesk scammers. The Gentlemen ransomware-as-a-service group maintains a mature suite of EDR killers.THECYBERWIRE.COM
18 Jun‘Popa’ Botnet Linked to Publicly-Traded Israeli FirmFor the past four years, a sprawling Android-based botnet called Popa has forced millions of consumer TV boxes to relay Internet traffic linked to advertising fraud, account takeovers, and mass data-scraping efforts. This week, researchers from multiple security firms concluded t…KREBSONSECURITY.COM
18 JunSalesforce Data Thefts Continue via Klue App CompromiseKlue's Battlecards is now the third integrated application that has been compromised to steal customers' Salesforce data, and victims include Huntress, the cybersecurity vendor.DARKREADING.COM
18 JunClose Encounters of the Human KindIn the latest Threat Source, Hazel channels her inner Spielberg to explore why humans are delightfully irrational, reminding us that while security best practices are simple in theory, they’re a lot harder to pull off when you’re busy dealing with real life.TALOSINTELLIGENCE.COM
18 JunBuild your own vulnerability harnessWe break down the technical architecture behind our multi-stage vulnerability discovery harness and automated triage loop. Learn how we manage state controls, squash false positives through adversarial review, and route around LLM context limits.CLOUDFLARE.COM
18 JunFIFA Bug Exposed World Cup Streams to Remote TakeoverA hacker could have "Rickrolled" the World Cup — or worse — thanks to FIFA's unenforced Entra access controls.DARKREADING.COM
18 JunVU#457458: Vendor-signed UEFI applications found vulnerable to Secure Boot bypassOverview Multiple vendor-signed UEFI applications are vulnerable to Secure Boot bypass via a "Bring Your Own Vulnerable Driver" (BYOVD)-style attack. If a target system trusts the affected vendor’s certificate, an attacker can exploit these applications to execute arbitrary code …KB.CERT.ORG
18 JunBulgaria allowed surveillance tech firm to sell products to repressive regimes, report saysThe nonprofit Human Rights Watch obtained export licensing records covering 2018 through 2023, which show the Bulgarian government allowed the surveillance firm Circles to peddle the tech to law enforcement and intelligence agencies in several countries known for human rights abu…THERECORD.MEDIA
18 JunThe botnet browser blues.International law enforcement disrupts the SocGholish botnet. The UK’s cyber chief says cybersecurity is a contest, not a risk register. Ukraine joins the EU’s cyber reserve. The Gentlemen gang sharpens its ransomware toolkit. A WordPress supply chain attack spreads malware. Crit…THECYBERWIRE.COM
18 JunOperation Endgame 4.0 - 153,527 breached accountsOn 18 June 2026, the latest phase of Operation Endgame targeted the SocGholish malware operation , a prolific malware distribution network used to compromise systems and facilitate further cybercrime. Coordinated by international law enforcement agencies with support from Europol…HAVEIBEENPWNED.COM
18 JunRalph Lauren - 139,903 breached accountsIn June 2026, fashion retailer Ralph Lauren was targeted in a ShinyHunters "pay or leak" extortion campaign . The group subsequently published hundreds of gigabytes of data they claimed was obtained from the organisation's Salesforce instance, including 140k unique email addresse…HAVEIBEENPWNED.COM
17 JunGoogle Vertex AI SDK Flaw Let Attackers Hijack Model Uploads via Bucket SquattingA flaw in the Google Cloud Vertex AI SDK for Python let an attacker with no access to a victim's project hijack the victim's machine learning model upload and run code inside Google's serving infrastructure. Palo Alto Networks Unit 42, which found and reported the bug through Goo…THEHACKERNEWS.COM
17 JunMicrosoft says you don’t need another email security tool; experts say, not so fastDespite best efforts by defenders, malicious emails continue to slip through the cybersecurity cracks , leading some enterprises to implement a layered “defense in depth” strategy that incorporates multiple tools. Microsoft seems to be challenging this idea, revealing that there …CSOONLINE.COM
17 JunMicrosoft AntiSSRF open-source library helps block server-side request forgeryAntiSSRF is an open-source code library from Microsoft that validates URLs and network connections to reduce server-side request forgery (SSRF) risks in web applications. It supports .NET and Node.js applications and is distributed under the MIT license. The library works as a dr…HELPNETSECURITY.COM
17 Jun144 Mastra npm Packages Compromised via Hijacked Contributor AccountAs many as 144 npm packages associated with the Mastra namespace ("@mastra/*"), a popular open-source JavaScript and TypeScript framework for building artificial intelligence (AI) applications, have been compromised as part of a software supply chain attack codenamed easy-day-js,…THEHACKERNEWS.COM
17 JunHot Cybercrime Summer: Smishing, Supply Chains, and SleuthconIn this episode of the Microsoft Threat Intelligence Podcast, host Sherrod DeGrippo sits down with Aurora Johnson of SpyCloud and Amitai Cohen of Wiz ahead of SleuthCon to explore two rapidly changing corners of the cybercrime landscape. Aurora breaks down the highly organiz…THECYBERWIRE.COM
17 JunJoomla, LiteSpeed Vulnerabilities Exploited in AttacksThe flaws allow attackers to execute arbitrary PHP code and gain root privileges on shared hosting servers. The post Joomla, LiteSpeed Vulnerabilities Exploited in Attacks appeared first on SecurityWeek .SECURITYWEEK.COM
17 JunMicrosoft working on Defender patch for RoguePlanet zero-dayMicrosoft confirmed that it's working on a security patch for a Defender zero-day vulnerability named "RoguePlanet," disclosed one week ago. [...]BLEEPINGCOMPUTER.COM
17 JunChrome and Firefox Updated to Patch Critical, High-Severity VulnerabilitiesThe browser updates address multiple memory safety bugs that could potentially lead to remote code execution. The post Chrome and Firefox Updated to Patch Critical, High-Severity Vulnerabilities appeared first on SecurityWeek .SECURITYWEEK.COM
17 Jun5 AI risk management frameworks for shoring up key gapsOrganizations racing to embed AI into business operations are realizing that the risk management frameworks they’ve relied on for decades aren’t built for the behaviors, failure modes, and ethical complexities AI systems introduce. Fortunately, a new generation of AI-specific fra…CSOONLINE.COM
17 JunMicrosoft Working on Patch for ‘RoguePlanet’ Zero-DayThe public PoC code exploits a race condition in Microsoft Defender to spawn a command prompt with System privileges. The post Microsoft Working on Patch for ‘RoguePlanet’ Zero-Day appeared first on SecurityWeek .SECURITYWEEK.COM
17 JunThe Chainguard Athena coalition already shipped 2,000 patches across 500 open source projectsChainguard launched Athena, an industry coalition that pools open source vulnerability findings and remediates them under embargo before public disclosure. The group went live with more than two dozen member organizations. Founding members include BNY, Chainguard, Cisco, Cloudfla…HELPNETSECURITY.COM
17 JunThe Top 10 Attack Surface Exposures in 2026Breaches don't always start with a zero-day. An exposed admin panel can get brute-forced, or credentials reused from a previous attack. But when a vulnerability does drop — like MongoBleed earlier this year, which let attackers pull credentials and session tokens from server memo…THEHACKERNEWS.COM
17 Jun KEVCISA orders feds to patch max severity Joomla plugin flaw by FridayThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to patch a maximum-severity flaw in the Widget Factory Joomla Content Editor (JCE) plugin that is being actively exploited in the wild. [...]BLEEPINGCOMPUTER.COM
17 JunMicrosoft Teams Relay Servers Abused in DragonForce Ransomware AttackThe attackers deployed a new Go-based backdoor that uses Microsoft Teams servers for command-and-control. The post Microsoft Teams Relay Servers Abused in DragonForce Ransomware Attack appeared first on SecurityWeek .SECURITYWEEK.COM
17 JunAI Use by the US GovernmentOn 14 April, the Trump administration quietly acknowledged the widespread use of AI to automate government processes. The office of management and budget (OMB) disclosed a staggering 3,611 active or planned use cases for AI across the federal government. The list has ballooned by…SCHNEIER.COM
17 JunGoogle’s Vertex AI SDK could allow RCE through bucket squattingA design flaw in the Vertex AI software development kit (SDK) for Python, Google Cloud’s managed platform for building, training, and deploying AI agents, could allow hijacking and poisoning of models outside of a developer’s own Google Cloud project. According to Unit 42 researc…CSOONLINE.COM
17 JunMalware à la Mode: Tracking Dropping Elephant Tradecraft Through a China-Themed Loader ChainExecutive summary Rapid7 researchers have identified a sophisticated malware campaign attributed to the threat actor "Dropping Elephant," characterized by the use of a China-themed decoy document to deliver a heavily reworked, in-memory remote access trojan (RAT). This campaign d…RAPID7.COM
17 JunFirefox AI Chatbot feature exposed users to email theft riskA vulnerability in Firefox's AI chatbot integration could allow malicious websites to inject hidden instructions into AI prompts and extract data from connected services such as email accounts. Mozilla has implemented mitigations, though the researchers who discovered the problem…CYBERINSIDER.COM
17 JunArmorCode helps product manufacturers prepare for EU Cyber Resilience Act requirementsArmorCode has announced new Cyber Resilience Act (CRA) capabilities within the ArmorCode Agentic AI Platform. The capabilities help manufacturers of products with digital elements (PDEs) prepare for the European Union’s cybersecurity regulation that will impact all sellers …HELPNETSECURITY.COM
17 JunLegit Security brings agentic AI to AppSec remediation and risk reductionLegit Security has launched new remediation agents that independently prioritize issues, generate fixes, open pull requests, and confirm results using context learned from each organization’s distinct codebase. As AI allows attackers to exploit vulnerabilities faster than ever, r…HELPNETSECURITY.COM
17 JunTenable One adds continuous security control validation to improve exposure prioritizationTenable has announced extended continuous security control and validation capabilities within the Tenable One Exposure Management Platform. With security control visibility and evidence-based, contextualized insights, Tenable One confirms which cyber exposures are accessible and …HELPNETSECURITY.COM
17 JunTigera introduces unified control plane for Kubernetes-based AI agent securityTigera has announced the general availability of Tigera Lynx, a unified control plane for Kubernetes-native AI agents. Lynx gives enterprises a single place to find every agent in their Kubernetes estate, tighten security posture, assign sandboxes, provide each agent with a crypt…HELPNETSECURITY.COM
17 JunRokarolla Android trojan targets banking and crypto users, enables device takeoverA newly discovered Android banking trojan, dubbed Rokarolla, targets 217 banking and cryptocurrency applications and can execute 137 commands on infected devices, according to researchers at Zimperium. Named after its command-and-control (C2) infrastructure, Rokarolla is primaril…HELPNETSECURITY.COM
17 JunReactive Patching Is FailingOrganizations are increasingly reconsidering support for multiple browsers as threat environments become faster and more difficult to manage. Every additional browser increases the attack surface security teams must manage. Historically, user choice often outweighed standardizati…YOUTUBE.COM
17 JunApple’s Hide My Email service will soon be easier to identify and blockApple has announced plans to consolidate the email domains used by Sign in with Apple and iCloud+ Hide My Email under a new shared domain, private.icloud.com, later this summer. The change will affect newly generated anonymous email addresses, while existing addresses will contin…CYBERINSIDER.COM
17 JunAnother healthcare firm attacked days after Novo Nordisk breachMedical technology company iRhythm Holdings disclosed a cyberattack involving certain third-party-hosted business applications that resulted in the theft of patient protected health information, proprietary data, and other personal data. The company discovered unauthorized activi…HELPNETSECURITY.COM
17 JunAttackers hit pair of critical Fortinet vulnerabilities the vendor disclosed in AprilMultiple firms have observed active exploitation of the FortiSandbox defects, and warn that the attacks originate from multiple sources, not a single campaign. The post Attackers hit pair of critical Fortinet vulnerabilities the vendor disclosed in April appeared first on CyberSc…CYBERSCOOP.COM
17 JunAI isn’t solving cybersecurity workforce woesMore than half of cybersecurity professionals say they’re thinking about leaving the industry, according to a new report.CYBERSECURITYDIVE.COM
17 JunIntroducing the Red Agent POV SeriesAn inside look at how the Red Agent, our AI-Powered Attacker, uncovers complex, exploitable risks in the wildWIZ.IO
17 JunCrypto Clipper Campaign Abuses Fake Reviews, AI Narrators, and VirusTotal CommentsAn unknown threat actor has been observed leveraging paid or promoted posts on legitimate news websites to drum up buzz for their warez, according to new findings from Check Point Research. The threat actor also has at their disposal a dedicated WordPress phishing page that acts …THEHACKERNEWS.COM
17 JunBeyond the benchmark: Advancing security at AI speedRead how Microsoft Security has advanced its agentic vulnerability detection system, codename MDASH, integrating into real-world workflows across Windows, Azure, and identity systems. The post Beyond the benchmark: Advancing security at AI speed appeared first on Microsoft Securi…MICROSOFT.COM
17 JunSmashing Security podcast #472: AI gets hacked, and BitLocker gets bypassedWhat if your AI coding assistant could be tricked into stealing your own company's secrets - by reading a single booby-trapped bug report? No phishing email. No malware. No password ever stolen. Just an AI doing exactly what it was told. Meanwhile, someone themselves Nightmare Ec…GRAHAMCLULEY.COM
16 JunCybersecurity jobs available right now: June 16, 2026Android Vulnerability Researcher Byteria | USA | Remote – View job details As an Android Vulnerability Researcher, you will analyze the Android attack surface, including the Linux kernel, system services, drivers, firmware, applications, and Trusted Execution Envi…HELPNETSECURITY.COM
16 JunThe rise of machine identities and agentic AI: Securing trust in the next era of digital autonomyIn the latest episode of Identity Insider, I sat down with Chris Hughes, a cybersecurity expert who’s involved in OWASP’s work on non-human and machine identity security. Unsurprisingly, our discussion centered on the rapidly changing cybersecurity landscape, driven b…HELPNETSECURITY.COM
16 JuniRhythm discloses data breach, says hackers stole patient infoDigital healthcare company iRhythm Holdings has disclosed a data breach after hackers stole patients' personal and health information stored on third-party-hosted business applications. [...]BLEEPINGCOMPUTER.COM
16 JunReachability makes AI threat modeling worth the trustIn this interview with Help Net Security, Oscar Andersson, CTO at Oplane, explains why most scanning tools fail. They cry wolf, flagging threats that cannot run in real code. The argument centers on reachability. A finding counts only when someone walks the path to impact on a wo…HELPNETSECURITY.COM
16 JunZero trust isn’t broken. Most companies just do it wrong.Zero trust is 15 years old, and like many teenagers, it can feel misunderstood and underappreciated. The concept of zero trust was first defined by John Kindervag , a Forrester analyst at the time, as a strategy to replace the outmoded perimeter security model with a “never trust…CSOONLINE.COM
16 JunPlanning a trip? Fake travel sites are multiplying this summerCyberattacks against hospitality, travel, and recreation organizations rose 24% year over year, reaching an average of 2,291 incidents per organization each week in May 2026, according to Check Point. (Source: Check Point) “The sector has more than doubled its attack volume since…HELPNETSECURITY.COM
16 JunCritical Fortinet FortiSandbox flaws now exploited in attacksAttackers are now exploiting several critical vulnerabilities in Fortinet's FortiSandbox cyber threat detection platform, according to threat intelligence company Defused. [...]BLEEPINGCOMPUTER.COM
16 JunSoftware supply chains are heading for a transparency testSoftware supply chain visibility is becoming part of product security work as the EU Cyber Resilience Act (CRA) moves toward application in December 2027. ENISA’s SBOM Adoption State of Play 2026 shows organizations preparing for CRA obligations through SBOM tooling, automa…HELPNETSECURITY.COM
16 JunChainguard, JPMorgan, BNY Team Up to Secure Open Source from AI ThreatsAthena is a new an industry coalition to fix the vulnerabilities frontier AI models find before attackers can exploit themINFOSECURITY-MAGAZINE.COM
16 JunPickle in the Middle – Hijacking Vertex AI Model Uploads for Cross-Tenant RCEUnit 42 discovered a Vertex AI Python SDK vulnerability that allows remote code execution via bucket squatting. Read the article for more. The post Pickle in the Middle – Hijacking Vertex AI Model Uploads for Cross-Tenant RCE appeared first on Unit 42 .UNIT42.PALOALTONETWORKS.COM
16 JunRansomware gang abuses Microsoft Teams relays to hide malicious trafficDragonForce ransomware used a custom malware named 'Backdoor.Turn' to hide command-and-control traffic inside Microsoft Teams relay infrastructure. [...]BLEEPINGCOMPUTER.COM
16 JunChina-linked hackers target US, Canada research using legacy REDCap exploitsGoogle is warning of a cyber espionage campaign linked to a China-nexus threat actor, UNC6508, that kept close tabs on valuable US and Canadian research environments for over a year. The campaign abused REDCap, a widely adopted platform for collecting and managing research data. …CSOONLINE.COM
16 JunDragonForce Ransomware Exploited Microsoft Teams to Hide in Attack Against Major CompanyCommand and control traffic exploited a Teams visitor token to make malicious activity look legitimate to defendersINFOSECURITY-MAGAZINE.COM
16 JunWiz Exposure Management Dashboard: Your CTEM Command CenterNew exposure management dashboard helps organizations align with CTEM to stay ahead in an era of AI exploiting vulnerabilities faster than everWIZ.IO
16 JunImproving precision in CTEM: How continuous controls validation in Tenable One transforms exposure managementDiscover how continuous control validation in Tenable One can improve your CTEM program by filtering out alert noise and factoring in your active cyber defenses. Focus your team on accessible and exploitable attack paths. Key takeaways: With vulnerability exploitation ranki…TENABLE.COM
16 JunRadware AI Xploit Shield delivers virtual patching for newly identified application and API flawsRadware has announced AI Xploit Shield, a new service that provides organizations with protection for their applications and APIs from exploitation of newly discovered vulnerabilities. As emerging frontier AI models like Mythos from Anthropic accelerate vulnerability discovery, o…HELPNETSECURITY.COM
16 JunCybercriminals mask malicious communications through Microsoft Teams relaysThe DragonForce ransomware group used a custom malware called Backdoor.Turn to hide command-and-control traffic inside Microsoft Teams relay infrastructure during an intrusion at a U.S. services company, according to Symantec. DragonForce is a ransomware-as-a-service operation th…HELPNETSECURITY.COM
16 JunIndia temporarily blocks Telegram over medical exam cheating fearsAuthorities said scammers previously exploited the feature by posting fake exam questions before the test and later replacing them with the real questions, making it look like they had leaked the exam in advance.THERECORD.MEDIA
16 JunTrump administration keeps Fable 5 restrictions in place.DragonForce ransomware operators abuse Microsoft Teams to hide C2 traffic. Ukrainian national pleads guilty to assisting in Conti ransomware attacks.THECYBERWIRE.COM
16 JunSession avoids shutdown as community donations save the projectSession, the decentralized encrypted messaging platform that warned earlier this year it could shut down due to a funding crisis, will continue operating after receiving financial support from thousands of users. The community-funded effort has provided enough resources to keep d…CYBERINSIDER.COM
16 JunThreat tactic spotlight: Subdomain takeoverIn this blog post you’ll learn how to detect and prevent subdomain takeover – a tactic where threat actors exploit dangling DNS records to redirect traffic to attacker-controlled resources. We’ll explain the issue, how the situation arises, and how you can use various AWS feature…AWS.AMAZON.COM
16 JunNo Mythos of escape.Emergency talks fail to free Anthropic’s Fable 5. Trump moves to strengthen national security systems. Microsoft patches a critical Copilot flaw. ShinyHunters weaponize a PeopleSoft zero-day. DragonForce hides in Microsoft Teams for months. Plus, Amos Stealer targets Macs, CISA i…THECYBERWIRE.COM
16 JunWhy AI Is Breaking Network-Based SASEMike Fey, co-founder and CEO of Island, joins Dave Bittner on the CyberWire Daily podcast for a sponsored Industry Voices. Mike explores why AI workflows and emerging quantum computing threats are challenging the assumptions behind traditional network-based SASE architectures. He…THECYBERWIRE.COMHTTPS:
16 JunAttackers Rarely Use Real IPsAccording to an industry study referenced in the discussion, anonymizing infrastructure such as VPNs, proxy networks, and Tor appeared in nearly all analyzed security incidents, with 94% of respondents reporting its use during attacks. Traditional IP-based detection becomes far l…YOUTUBE.COM
16 JunCyberRisk TV Live Coverage from Identiverse 2026CyberRisk TV is broadcasting live from Identiverse 2026 in Las Vegas! Join us for exclusive interviews with identity, security, and technology leaders, actionable insights, and the latest thinking from practitioners shaping the future of digital identity at the industry's premier…YOUTUBE.COM
16 JunSN 1083: Patch Tuesday à la AI - Arch Linux Repo Under SiegeThis episode unpacks the jaw-dropping surge in vulnerabilities unearthed by AI, revealing how Microsoft shattered its own patch records while adversaries and defenders race to outpace each other. The conversation gets real about whether AI is fixing our broken software or just ma…TWIT.TV
15 JunAnthropic Models Blocked, FBI Takes Down $1.9B Phishing Network, Critical Splunk Flaw, and moreThe U.S. government orders Anthropic to shut down foreign access to its Fable 5 and Mythos 5 AI models after the Pentagon labels the company a supply-chain risk. David Shipley examines what may be behind the decision and what it means for countries and businesses that depend on A…CYBERSECURITYTODAY.LIBSYN.COM
15 JunLiteLLM Vulnerability Chain Lets Low-Privilege Users Take Over AI Gateway ServersA default low-privilege account on a LiteLLM proxy can climb to full admin and run code on the server by chaining three vulnerabilities, researchers at Obsidian Security disclosed LiteLLM is a widely deployed open-source AI gateway that brokers calls to more than 100 model provid…THEHACKERNEWS.COM
15 Jun⚡ Weekly Recap: Chrome 0-Day, UniFi Exploits, macOS Stealers, VPN Flaw and MoreStuff broke again. Not in a movie way. An old tool was left exposed. An abandoned package was abused. A deprecated feature was still running in prod. This week is the same lesson in a new form: phishing kits are easier to rent, AI names are useful bait, old login paths still fail…THEHACKERNEWS.COM
15 JunSniper Dz Scams Target MENA Users via Fake Facebook Offers and Browser AlertsCybersecurity researchers have disclosed details of fraudulent activity targeting users across the Middle East and North Africa by employing various fraudulent Facebook accounts impersonating politicians, public figures, and trusted organizations. "These accounts promoted fake of…THEHACKERNEWS.COM
15 JunThe US government’s Anthropic models ban was never about an AI jailbreakThe Trump administration's decision that forced Anthropic to pull its latest cybersecurity models could be reactionary, retaliatory, or both, but the message is clear: The AI industry isn't immune from U.S. government interference.TECHCRUNCH.COM
15 JunMaine forced to take down data breach portal after fake notices filed with authoritiesThe US state of Maine has taken its public data breach notification portal offline after someone submitted fraudulent breach disclosures impersonating two well-known technology companies. Read more in my article on the Hot for Security blog.BITDEFENDER.COM
15 JunJune 2026 Stealer Logs - 56,278,397 breached accountsIn June 2026, a collection of accumulated stealer logs from various sources was added to HIBP. The corpus comprised 56M unique email addresses across hundreds of millions of stealer log records. The data also contained 124M unique passwords, which have been added to Pwned Passwor…HAVEIBEENPWNED.COM
15 JunBerkadia - 305,216 breached accountsIn March 2026, the commercial real estate finance company Berkadia was the target of a ShinyHunters "pay or leak" extortion campaign . The group subsequently published data they alleged was taken from Berkadia's Salesforce instance, including over 300k unique email addresses as w…HAVEIBEENPWNED.COM
15 JunAttackers can turn AI agent guardrails into denial-of-service weaponsAttackers can turn AI agent guardrails into denial-of-service weapons, according to new research that found a single poisoned document can dramatically slow shared AI agent workflows by trapping reasoning-based safety systems in extended thinking loops. “Reasoning-based guardrail…CSOONLINE.COM
15 JunGoverning the ghost workforceEvery enterprise security team is fighting a workforce problem they cannot see on any org chart. Bots, service accounts, API keys, OAuth tokens, machine certificates — non-human identities now outnumber human ones in most large organisations, often by a factor of ten to one. They…CSOONLINE.COM
15 JunSovereign cloud won’t fix your AI risk. Identity governance willYour board is asking. Your legal team is asking. Your auditors will be asking: Should AI workloads move to sovereign cloud, or stay on AWS, Azure or GCP? European enterprises have already run this experiment — under real regulatory pressure, with real money and real consequences.…CSOONLINE.COM
15 Jun5 runtime signals for catching a compromised AI agentIn June 2025, Simon Willison, the engineer who coined the term “prompt injection,” published a warning that circulated widely through the security community. He called it the lethal trifecta — three capabilities that, when combined in a single AI agent, create a near-guaranteed p…CSOONLINE.COM
15 JunAI Agents Break Data PerimetersThe discussion highlights a shift in security architecture driven by agentic AI systems. Instead of traditional network perimeters, the focus is moving toward data-centric security, including lineage, contextualization, and data security posture management (DSPM). As AI agents in…YOUTUBE.COM
15 JunSafe AI at scale, what happens after initial access, and the weekly enterprise news - ESW #463Interview with Shiva Pillay from Veeam Safe AI at Scale AI investment is exploding, yet nearly 90% of enterprise initiatives fail because the data powering AI cannot be trusted. That’s the uncomfortable truth the industry is facing right now. Safe AI at scale requires more than j…YOUTUBE.COM
15 JunPublic and Private Medical Community Targeted by China-Nexus Threat Actor Pursuing Artificial Intelligence, Cyber, Medical, and National Defense ResearchWritten by: Patrick Whitsell, John McGuiness Google Threat Intelligence Group (GTIG) has identified a sophisticated campaign attributed to UNC6508, a People's Republic of China (PRC)-nexus threat actor, targeting institutions in the North American academic, medical, and military …CLOUD.GOOGLE.COM
15 JunCyberattack on Russian tech firm Astral disrupts business, government services for weekAccording to customer complaints, the disruption affected a range of services used by businesses, leading to interruptions in cash register operations, difficulties selling certain regulated goods, loss of access to customer portals and corporate email and problems with electroni…THERECORD.MEDIA
15 JunAnthropic says US government forced it to disable cybersecurity AI modelsAccording to the company, the directive cited national security authorities. It appears to be the first time such authorities have been used to curtail the export of AI models rather than chips or hardware.THERECORD.MEDIA
15 JunGoogle exposes China espionage group that’s been lurking in networks undetected since 2023The revelation mirrors an alarming pattern of Chinese espionage groups dropping backdoors into critical infrastructure to intercept research and steal data with national security implications. The post Google exposes China espionage group that’s been lurking in networks undetecte…CYBERSCOOP.COM
15 JunMS-ISAC enters uncertain new era after losing federal funding and thousands of membersThe information-sharing group, a vital resource for state and local governments, has cut staff and pinned its hopes on a membership surge.CYBERSECURITYDIVE.COM
15 JunSimpleHelp bug lets hackers create rogue remote support accountsA vulnerability in the SimpleHelp remote management software allows unauthenticated attackers to create privileged technician accounts on servers using the OpenID Connect (OIDC) authentication protocol. [...]BLEEPINGCOMPUTER.COM
15 JunNew attack turned Microsoft 365 Copilot into 1-click data theft toolA critical vulnerability chain dubbed SearchLeak in Microsoft 365 Copilot Enterprise could allow attackers to steal sensitive data from a target's mailbox, OneDrive, or SharePoint account through a specially crafted URL. [...]BLEEPINGCOMPUTER.COM
15 JunInfinite Campus data breach affects 137,000 school staff accountsThe ShinyHunters extortion gang stole personal information from more than 137,000 school staff accounts in a Salesforce data theft attack that targeted the widely used Infinite Campus K-12 student information system in March. [...]BLEEPINGCOMPUTER.COM
15 JunChinese hackers breached North American research institutions via REDCap serversA China-linked cyber espionage operation targeted North American medical research institutions through compromised REDCap servers, using custom malware to gain persistent access and collect sensitive information, Google’s Threat Intelligence Group (GTIG) researchers found. …HELPNETSECURITY.COM
15 Jun1Password Credential Broker reduces secret sprawl through identity-based credential delivery1Password has announced 1Password Credential Broker, a new product that securely brokers credentials, tokens, and federated access from 1Password to trusted requesters. The 1Password Credential Broker is available in private beta today, with support for GitHub Actions and a roadm…HELPNETSECURITY.COM
15 JunPhishLumos: Exposing phishing campaigns that evade detection by hiding contentPhishing remains one of the most stubbornly persistent threats in cybersecurity: humans are tired, distracted, trusting, and susceptible to urgency and authority in ways that no amount of awareness training can completely overcome. The security community has largely accepted this…HELPNETSECURITY.COM
15 JunNIS2 is raising the bar. Here’s how to turn readiness into resilience.The NIS2 directive asks covered organizations to take a more structured approach to risk management, governance, supply chain security, and incident reporting. It expands the scope of who may be covered, raises expectations around management body accountability, introduces cleare…RAPID7.COM
15 JunDoes Your Security Programme Align With NIS2 Requirements?If your organization operates in the EU, or works with organizations that do, NIS2 is no longer something on the horizon. It is here and it applies to a far wider range of sectors than its predecessor, the original NIS Directive (Directive (EU) 2016/1148), and it comes with real …RAPID7.COM
15 JunBeyond the Score: Using AI to Translate CVEs into Real-World Business RiskSecurity leaders rarely struggle to gather data, but they often struggle to turn that data into something clear and meaningful for the business. In a typical week, a CISO might receive a report listing hundreds or even thousands of vulnerabilities, most of them accompanied by CVS…RAPID7.COM
14 JunVulnerability management at AI speed.In large enterprise software companies, vulnerability management teams are facing unprecedented speed and scale as AI accelerates both discovery and exploitation of security issues. In this episode of CyberWire-X, N2K’s Dave Bittner is joined by Adobe’s Daniel Ventura, Senior…THECYBERWIRE.COM
14 JunWeek in review: Exploited Check Point VPN zero-day, Oracle PeopleSoft servers under attackHere’s an overview of some of last week’s most interesting news, articles, interviews and videos: DockSec: Open-source AI-powered Docker security scanner DockSec is an OWASP Incubator Project that combines three container security scanners with a language-model layer for explanat…HELPNETSECURITY.COM
13 JunWeekly Metasploit Update: New Kerberos/Certificate tracing options, and multiple new modulesNew Tracing Options As hard as we try to ensure that Metasploit is bug free, issues inevitably come up. Whether you’re running a module on an op or writing a new one, what we can do is make the debugging experience easier. To that end one of our two Google Summer of Code (GSoC) p…RAPID7.COM
13 JunThis Sparrow doesn't migrate.Martin Zugec, Technical Solutions Director at Bitdefender, discussing their work on "FamousSparrow APT Targets Azerbaijani Oil and Gas Industry." Bitdefender researchers uncovered a sustained cyber espionage campaign by the China-linked FamousSparrow group targeting an Azerbai…THECYBERWIRE.COM
13 JunShai-Hulud variant compromises dozens of open-source Microsoft packages.Patch Tuesday notes: Microsoft fixes a record 200 flaws. German court holds Google liable for AI-generated claims.THECYBERWIRE.COM
13 JunThe FCC Wants to Kill Burner PhonesPlus: AI bug hunting fuels Microsoft’s biggest-ever Patch Tuesday, ShinyHunters ransomware gang exploits an Oracle zero-day, and more.WIRED.COM
13 JunYour Replacement Phone Was ManagedA customer reportedly received a refurbished replacement phone that still contained an active Mobile Device Management (MDM) profile. MDM platforms are commonly used by enterprises to remotely manage company-owned devices, enforce policies, disable lost phones, and control access…YOUTUBE.COM
13 JunAnthropic disables new models after government calls them a national security concernThe Commerce Department’s expert control decree led to the company shutting off access to Fable 5 and Mythos 5 worldwide, drawing sharp criticism from researchers and industry analysts. The post Anthropic disables new models after government calls them a national security concern…CYBERSCOOP.COM
13 JunAmazon CEO reportedly raised Anthropic model concerns before government crackdownAmazon CEO Andy Jassy may have been the source of security concerns that led Anthropic to cut off worldwide access to two models on Friday.TECHCRUNCH.COM
12 JunAnthropic Warns AI Risks Are Real, RoguePlanet Zero-Day Drops, Crypto Laundering TakedownAnthropic is calling for governments to have the authority to stop deployment of advanced AI systems that pose unacceptable risks. CEO Dario Amodei points to the company's Mythos cybersecurity model as proof that AI has become a matter of national and strategic consequence, warni…CYBERSECURITYTODAY.LIBSYN.COM
12 JunComcast Business SecurityEdge Preferred strengthens security for small businessesComcast Business announced SecurityEdge Preferred, its most advanced network-native cybersecurity solution for small businesses. Because SecurityEdge Preferred is built directly into the Comcast Business network, security can be activated in minutes without deploying additional h…HELPNETSECURITY.COM
12 Jun‘Harvest now, decipher later’: The quantum threat few are preparing forQuantum technology may feel far off but certain risks are already with us in the form of “harvest now, decrypt later” — an attack vector in which malicious actors steal data now for a future in which they have access to quantum computational tools capable of breaking encryption d…CSOONLINE.COM
12 JunAuthorities dismantle crypto laundering service that moved €336 million for cybercriminalsAn international law enforcement operation has dismantled a cryptocurrency laundering service linked to ransomware groups and other cybercriminals that processed more than €336 million in illicit funds. The domain seizure notice (Source: Europol) Europol said the service, known a…HELPNETSECURITY.COM
12 Jun KEVCISA orders feds to patch actively exploited Ivanti flaw by SundayThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) ordered government agencies to patch an actively exploited Ivanti Sentry flaw within three days, as mandated by the newly issued Binding Operational Directive (BOD) 26-04. [...]BLEEPINGCOMPUTER.COM
12 JunLangGraph Flaw Chain Exposes Self-Hosted AI Agents to Remote Code ExecutionCybersecurity researchers have disclosed details of three now-patched security flaws impacting LangGraph, including a critical vulnerability chain that could result in remote code execution. LangGraph is an open-source framework created by LangChain to build complex, stateful, an…THEHACKERNEWS.COM
12 JunAI is exposing the biggest weakness in cybersecurity: We never built a health model. Until now!For 30 years, cybersecurity has operated like an emergency room. Reactive. Crisis-driven. Always triaging. We are extraordinarily good at it — our detection is faster, our response playbooks are sharper, our incident teams are more capable than they have ever been. When something…CSOONLINE.COM
12 JunIvanti Sentry Exploitation Attempts Hitting HoneypotsThe critical-severity OS command injection vulnerability allows attackers to execute arbitrary code with root privileges. The post Ivanti Sentry Exploitation Attempts Hitting Honeypots appeared first on SecurityWeek .SECURITYWEEK.COM
12 JunChrome 149 Update Patches 28 VulnerabilitiesThe browser refresh resolved critical and high-severity security defects, including a dozen use-after-free bugs. The post Chrome 149 Update Patches 28 Vulnerabilities appeared first on SecurityWeek .SECURITYWEEK.COM
12 JunPrompt injection breaks today’s AI agents, study warnsToday’s AI web agents have no dependable defenses against prompt injection, according to new research showing that not a single attack scenario was consistently blocked across leading systems powered by GPT‑5 and Gemini. The findings come from StakeBench, a stakeholder-centric be…CSOONLINE.COM
12 JunPharma giant Novo Nordisk discloses breach of clinical trials dataDanish pharmaceutical giant Novo Nordisk, the world's largest producer of insulin, disclosed a data breach affecting patient information from some clinical trials. [...]BLEEPINGCOMPUTER.COM
12 Jun KEVFactoring "short-sleeve" RSA keys with polynomialsWhat happens when the bits of an RSA private key are heavily biased toward 0 instead of being randomly generated? The public key’s bits could be biased enough for us to detect these incorrectly generated keys in the wild. Together with Hanno Böck of the badkeys project, we found …TRAILOFBITS.COM
12 JunAgentjacking Attack Tricks AI Coding Agents Into Running Malicious CodeCybersecurity researchers have described what they say is a new class of attack that can trick artificial intelligence (AI) coding agents into running arbitrary code on developer machines. Called Agentjacking by Tenet Security, the attack can be triggered by means of a fake error…THEHACKERNEWS.COM
12 JunSecurity Tools Are Breaking SOCsMany organizations now operate dozens of security tools across incident response, threat intelligence, detection, investigation, and remediation. While these tools increasingly include AI features, they often lack proper integration across platforms. This creates operational frag…YOUTUBE.COM
12 JunCISA directs agencies to “patch smarter, not harder.”Anthropic rejects Fable 5 jailbreak claims. Google confirms ShinyHunters exploited a critical Oracle PeopleSoft vulnerability.THECYBERWIRE.COM
12 JunShinyHunters linked to exploitation of critical flaw in Oracle PeopleSoftMore than 100 organizations, more than two-thirds in higher education, have been notified of potential impact.CYBERSECURITYDIVE.COM
12 JunShinyHunters is actively extorting universities after exploiting an unpatched Oracle flawOracle still hasn't patched the vulnerability the group has been using in its attacks since late May. The post ShinyHunters is actively extorting universities after exploiting an unpatched Oracle flaw appeared first on CyberScoop .CYBERSCOOP.COM
12 JunphpBB forum fixes auth bypass bug lurking for a decadeA 10-year-old authentication bypass vulnerability discovered in the phpBB forum software allows an attacker to log in as any user, including administrators. [...]BLEEPINGCOMPUTER.COM
12 JunDeadline-driven defense.CISA directs agencies to “patch smarter, not harder.” The House fails to extend FISA. Europol pulls over AudiA6. GitHub announces npm security updates. Anthropic rejects Fable 5 jailbreak claims. CISA gives feds three days to patch a critical Ivanti Sentry vulnerability. Google c…THECYBERWIRE.COM
12 JunShinyHunters Uses Oracle Zero-Day to Rampage Higher EdA major bug in Oracle's ERP software disproportionately affected American universities, and hackers have capitalized by stealing gobs of data.DARKREADING.COM
12 JunGreatXML zero-day BitLocker bypass doesn’t seem to work, yetA disgruntled researcher who has been publishing zero-day Microsoft Windows vulnerabilities for the past several months released a new exploit Thursday that promises to bypass BitLocker encryption on locked devices. A well respected security expert reported that the exploit doesn…CSOONLINE.COM
12 Jun KEVShiny Hunters Hit PeopleSoftOracle mitigated a critical PeopleSoft vulnerability affecting PeopleTools versions 8.61 and 8.62. Reports indicate the vulnerability was actively exploited as a zero-day by the group known as Shiny Hunters to access organizational data. The issue was described as an unauthentica…YOUTUBE.COM
11 JunGitHub finally pulls the plug on automatic install script execution for npmThe ability for attackers to leverage automatic install script execution in npm will finally come to an end when expected changes arrive from GitHub in July. Coders will still be able to enable the function, but the default setting will block it. In V12, default settings are chan…CSOONLINE.COM
11 JunWhatsAppening here?This week, hosts of N2K CyberWire Maria Varmazis and Dave Bittner alongs…THECYBERWIRE.COM
11 JunX Square Robot open sources its robot-free data collection frameworkCompanies building robots for physical work spend large amounts of time and money operating machines by hand to gather training examples. Each session with a physical robot produces a small number of demonstrations per day, which slows the growth of datasets used to train embodie…HELPNETSECURITY.COM
11 JunMax severity Ivanti Sentry vulnerability now exploited in attacksAttackers are now targeting a recently patched maximum-severity flaw in Ivanti Sentry, enabling them to execute code with root privileges on Internet-exposed secure mobile gateways. [...]BLEEPINGCOMPUTER.COM
11 JunAged-domain acquisition: The tradecraft phishing operators are using to bypass your mail filter’s reputation scoreI’ve spent the past two years working on incident response and threat intelligence, and the pattern I’m about to describe is one I keep seeing show up in cases that should have been caught at the email gateway. The kit families change. The lure templates change. The constant is t…CSOONLINE.COM
11 JunFrontier AI models offer sneak peak of seismic cyber shifts aheadThe advent of Claude Mythos combined with the release of OpenAI’s GPT-5.5 have changed the threat model for CISOs . The arrival of those frontier AI models — and the ones soon to follow — makes it much easier to discover and chain vulnerabilities at a speed and scale that will re…CSOONLINE.COM
11 Jun‘GreatXML’ Zero-Day Exploit Bypasses BitLockerThe PoC exploits Microsoft Defender’s offline scan to spawn a SYSTEM shell when rebooting in Recovery Mode. The post ‘GreatXML’ Zero-Day Exploit Bypasses BitLocker appeared first on SecurityWeek .SECURITYWEEK.COM
11 JunEnhanced License Plate TrackingThe surveillance company Leonardo wants more data : A surveillance company plans to add sensors to automatic license plate readers (ALPRs) that would mean the devices, as well as capture the license plate of passing vehicles, would also sweep up unique identifiers of mobile phone…SCHNEIER.COM
11 JunWhat SRE teams need before they trust AI agentsThe future of reliability will not be defined by whether site reliability engineering (SRE) teams use AI agents, but by the conditions under which they choose to trust them. In high-stakes systems, trust is never granted because a demo looks impressive; it is earned through obser…CSOONLINE.COM
11 JunSplunk, Palo Alto Networks Patch Severe VulnerabilitiesThe security defects could allow attackers to create or modify arbitrary files and access and modify protected resources. The post Splunk, Palo Alto Networks Patch Severe Vulnerabilities appeared first on SecurityWeek .SECURITYWEEK.COM
11 JunAI Broke Vulnerability Management. That's Why CISOs Are Moving Budget to BAS.For thirty years, vulnerability management ran on a buffer: the months between when a vulnerability was found and when someone could figure out how to weaponize it. The solution was straightforward enough; triage by severity, schedule the fix, validate, and move on. The buffer wa…THEHACKERNEWS.COM
11 JunSignal Alums Reveal ‘Encrypted Spaces,’ a System for Making Private Collaboration AppsThe new open-source project could serve as the basis for a future of apps with features as complex as Slack, Discord, or Google Docs—but with added protection against surveillance.WIRED.COM
11 JunKyushu Electric lost backup drive containing data of 10.9 million clientsKyushu Electric Power Transmission and Distribution Co. has disclosed that an external storage device used for system backups has gone missing from a secure server room. While no evidence of data leakage has been identified so far, the company warns that the device contained pers…CYBERINSIDER.COM
11 JunVRChat discloses cloud breach exposing data of 2.4 million usersVRChat has disclosed a data breach affecting 2,436,782 users after attackers gained unauthorized access to data stored in the company's cloud environment. The incident exposed account-related information, including email addresses, usernames, login history, and linked platform id…CYBERINSIDER.COM
11 JunHackers Exploit Langflow Vulnerability for Remote Code ExecutionDisclosed in March, the security defect enables unauthenticated attackers to write files to arbitrary locations on the system. The post Hackers Exploit Langflow Vulnerability for Remote Code Execution appeared first on SecurityWeek .SECURITYWEEK.COM
11 JunCoupang hit with record $409 million data breach fine in KoreaThe Personal Information Protection Commission (PIPC), South Korea's data protection regulator, has fined e-commerce giant Coupang a record 624.6 billion won (roughly $409 million) following a massive data breach affecting more than 37 million customers [...]BLEEPINGCOMPUTER.COM
11 JunCISA tells govt agencies to patch critical exploited flaws in 3 daysThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) announced a new Binding Operational Directive, 26-04, that prioritizes security updates for Federal Civilian Executive Branch (FCEB) agencies. [...]BLEEPINGCOMPUTER.COM
11 JunServiceNow fixes API issue after reports of suspicious tenant activityServiceNow is notifying customers after discovering and remediating a vulnerability that could have exposed data via an unauthenticated API endpoint on affected instances. The issue emerged publicly after customers began discussing security notifications from ServiceNow and repor…CSOONLINE.COM
11 JunFrom SQLi to RCE – Exploiting LangGraph’s CheckpointerBy Yarden Porat AI agents need memory. Frameworks like LangGraph provide it through checkpointers – persistence layers that store execution state. But what happens when that persistence layer isn’t locked down? Key Points Background LangGraph is an open-source framewo…RESEARCH.CHECKPOINT.COM
11 JunCriminal AI-as-a-Service in 2026: How the Underground Market Is Operationalizing CybercrimeIntroduction The underground market for criminally oriented generative AI has moved beyond the early hype surrounding 'malicious chatbots.' The gradual integration of AI as a productivity layer within cybercrime operations has become the dominant story, indicating that while the …RAPID7.COM
11 JunAuthorities dismantle 'AudiA6' ransomware crypto-laundering serviceLaw enforcement has dismantled the “AudiA6” cryptocurrency service allegedly used by ransomware actors and other cybercriminals to launder more than $380 million. [...]BLEEPINGCOMPUTER.COM
11 JunThe Gentlemen Ransomware Claims 478 Victims, Can Spread Like a WormA new analysis of The Gentlemen operation has revealed that the financially motivated threat group initially operated as an affiliate responsible for conducting double extortion attacks, while leveraging resources from various ransomware-as-a-service (RaaS) schemes like LockBit (…THEHACKERNEWS.COM
11 JunCyber Force not included in Senate defense policy roadmapAn amendment by Sen. Kirsten Gillibrand (D-NY) to the chamber’s fiscal 2027 national defense authorization bill that would have created the digital-focused service was defeated 14-13 when the Senate Armed Services Committee took up the nearly $1.2 trillion legislation behind clos…THERECORD.MEDIA
11 JunCoupang hit by massive $456 million fine for 2025 data breach incidentSouth Korea's Personal Information Protection Commission (PIPC) has fined e-commerce giant Coupang 624.68 billion won ($456 million) after concluding that poor security practices led to a data breach affecting approximately 37.5 million people. The decision follows a November 202…CYBERINSIDER.COM
11 JunCISA orders federal agencies to “patch smarter”The US Cybersecurity and Infrastructure Security Agency (CISA) has issued a Binding Operational Directive that will change how the US federal government approaches vulnerability management. The directive arrives as the patching problem has become nearly unmanageable, driven by a …HELPNETSECURITY.COM
11 JunNew GreatXML Exploit Bypasses Windows BitLocker via Recovery Partition XML FilesSecurity researcher Chaotic Eclipse (aka Nightmare-Eclipse and MSNightmare) has released a new Windows BitLocker bypass dubbed GreatXML, a day after they published an exploit for Microsoft Defender. "This was an accidental discovery, it took a total of 4 hours to find this," the …THEHACKERNEWS.COM
11 JunNexstar investigates potential breach after ShinyHunters claims theft of 1.1M Salesforce recordsNexstar Media Group is investigating a potential cybersecurity incident after the ShinyHunters extortion group claimed to have stolen more than one million Salesforce records and additional internal corporate data from the broadcasting giant. While the threat actors have not publ…CYBERINSIDER.COM
11 JunMax-Severity Ivanti Flaw Exploited 24 Hours After DisclosureInitial methods suggest attackers had likely mapped out Ivanti's asset landscape upfront and acted quickly once the exploit became public.DARKREADING.COM
11 JunOracle warns of security bug that hackers abused to breach 100+ companiesThe tech giant warned of a security flaw that a cybercrime gang said it's exploiting as part of a mass-hacking campaign. Google said it notified more than 100 organizations that had potentially vulnerable servers.TECHCRUNCH.COM
11 JunNightmare Eclipse Trolling MicrosoftThe discussion centers on a persona called “Nightmare Eclipse,” which appears to act as a single researcher or group releasing vulnerabilities in a highly public and strategic way. This includes dropping zero-day vulnerabilities outside of standard vendor patch cycles. This style…YOUTUBE.COM
11 JunJapanese energy firm loses drive with data of 10.9 million clientsKyushu Electric Power Co., Inc. has disclosed a physical security incident that affects private data of more than 10 million customers. [...]BLEEPINGCOMPUTER.COM
10 JunEnterprises know AI-generated code is vulnerable; they’re shipping it anywayAI-generated code is riddled with security flaws, yet enterprises are shipping more of it than ever before. Why? Perhaps they’re over-confident, lack true visibility into security risks, or are simply choosing to ignore the problem and hope it goes away. It’s a dangerous game to …CSOONLINE.COM
10 JunUK move to filter photos and messages triggers encryption worries for CISOsUK Prime Minister Keir Starmer’s speech on Monday insisting that tech companies create device controls to somehow block children from viewing or creating sexually explicit imagery has raised alarms among CISOs, who worry that the same technology could undermine enterprise securit…CSOONLINE.COM
10 JunHiring Hot Takes from a Three-Time Exit CMO, Mary YangMary Yang has been a CMO in cybersecurity for 6 years, helped 3 companies exit, and now works on a fractional basis with founders and teams she wants to work with. On this CyberCMO Confidential episode, the three of them get into a discussion on hiring. Mary skips the job descrip…THECYBERWIRE.COM
10 JunProduct showcase: Staying ahead of the threat horizon with AunooAunoo is an open strategic intelligence platform that uses AI agents to monitor intelligence sources, including for cybersecurity, to compile a daily briefing and alert on defined criteria. Each source is checked for credibility and quality before it is included. The platform run…HELPNETSECURITY.COM
10 JunScams now operate like real businesses with budgets and targetsSocial media has overtaken email as a primary attack vector, showing changes in how people consume information and interact online, according to Bitdefender’s Global Scam Intelligence Report 2026. Fraud campaigns use advertisements, sponsored content, impersonation pages, a…HELPNETSECURITY.COM
10 JunSix Proto6 Vulnerabilities in protobuf.js Expose Node.js Apps to RCE and DoSCybersecurity researchers have flagged half a dozen vulnerabilities in protobuf.js, a JavaScript and TypeScript implementation of Protocol Buffers (Protobuf), that, if successfully exploited, could result in remote code execution (RCE) and denial-of-service (DoS) attacks. "In aff…THEHACKERNEWS.COM
10 JunNOVA microhypervisor brings AMD DMA isolation to shared AI infrastructureBlueRock has issued the latest open-source release of its NOVA Microhypervisor with DMA remapping support for AMD platforms that have IOMMU hardware virtualization. The capability is enabled by default and extends hardware-level isolation across virtual machines, devices, and mem…HELPNETSECURITY.COM
10 JunMicrosoft Defender RoguePlanet Zero-Day Grants SYSTEM Access on Updated WindowsThe anonymous security researcher going by the name Chaotic Eclipse (aka Nightmare-Eclipse) has released a proof-of-concept (PoC) exploit for yet another Microsoft Defender zero-day named RoguePlanet. "The exploit is a race condition, so it's a hit or miss," the researcher, who p…THEHACKERNEWS.COM
10 JunRisky Business #841 -- Microsoft gets owned and 0day'dOn this week’s show special guest co-host Chris Wade, the founder of Corellium turned Cellebrite CTO, joins Patrick Gray and James Wilson to discuss the week’s cybersecurity news. They cover: Microsoft has repos owned, GitHub tokens popped, and a new 0day dropped on them Meanwhil…RISKY.BIZ
10 JunNo Patch Planned for Exploited Arista EOS VulnerabilityOrganizations are advised to apply vendor-supplied mitigations or discontinue the vulnerable devices. The post No Patch Planned for Exploited Arista EOS Vulnerability appeared first on SecurityWeek .SECURITYWEEK.COM
10 JunServiceNow Flaw Exploited to Gain Unauthorized Access to Customer InstancesServiceNow has warned about a security incident in which unknown threat actors exploited a flaw to obtain deeper unauthorized access to susceptible instances. "On June 5, 2026, ServiceNow applied a security update to hosted customer instances," the company revealed in an advisory…THEHACKERNEWS.COM
10 JunMicrosoft Fixes 200 CVEs in June Patch TuesdayMicrosoft has patched 200 vulnerabilities including three zero-daysINFOSECURITY-MAGAZINE.COM
10 JunCritical Vulnerabilities Patched in Fortinet, Ivanti ProductsTwo OS command injection flaws can be exploited remotely, without authentication, for arbitrary code execution. The post Critical Vulnerabilities Patched in Fortinet, Ivanti Products appeared first on SecurityWeek .SECURITYWEEK.COM
10 JunAI red teaming comes of ageWhen Ram Shankar Siva Kumar launched Microsoft’s AI red team in 2019, the discipline barely existed. “The running joke used to be that people who used to work in AI red teaming, you can round them up in a 14-foot catamaran,” he tells CSO. At the time, Microsoft’s approach looked …CSOONLINE.COM
10 JunInnovation Without Data Security Risk as AI Unlocks Budgets and Identity Challenges - BSW #451AI is reshaping innovation as businesses embed it into core operations and move more processes online. This transformation is often seen as a tradeoff between innovation and data risk, but that assumption is wrong. Businesses can innovate and scale in the AI era while maintaining…YOUTUBE.COM
10 JunMicrosoft patches YellowKey, GreenPlasma, MiniPlasma zero-daysOn Tuesday, Microsoft patched two zero-day vulnerabilities that let attackers gain SYSTEM privileges on fully patched Windows systems, and a third one that grants access to BitLocker-protected drives. [...]BLEEPINGCOMPUTER.COM
10 JunServiceNow Patches Vulnerability Exploited Against Some CustomersThe company updated hosted customer instances to patch a security issue it reportedly had known about since April 7. The post ServiceNow Patches Vulnerability Exploited Against Some Customers appeared first on SecurityWeek .SECURITYWEEK.COM
10 JunRubrik launches Autonomous Business Recovery to rebuild cloud applications after cyberattacksRubrik has unveiled Autonomous Business Recovery (ABR) for Cloud Applications, the agentic cyber resilience solution that recovers cloud applications from data to network, identity and configurations. The end result is a rebuild of an organization’s Minimum Viable Business …HELPNETSECURITY.COM
10 JunF5 adds AI-powered threat detection and API security for on-premises environmentsF5 has introduced new web application and API protection (WAAP) capabilities for its Application Delivery and Security Platform. The company said the updates are intended to address a threat landscape in which AI models can accelerate the time between vulnerability discovery and …HELPNETSECURITY.COM
10 JunMicrosoft Patches Record 206 Flaws, Including Three Zero-Days and Critical RCE BugsMicrosoft on Tuesday released fixes for a record 206 security vulnerabilities impacting its software portfolio, including three flaws that have been publicly disclosed at the time of release. Of the 206 flaws, 39 are rated Critical, and 167 are rated Important in severity. This i…THEHACKERNEWS.COM
10 JunAutonomous AI agents duped into leaking sensitive data in phishing testAI agents given access to corporate email and business applications could become a new phishing target for attackers, according to cybersecurity researchers, after a test agent built on OpenClaw was tricked into sharing cloud credentials and customer data with an external attacke…CSOONLINE.COM
10 JunRecord Microsoft Patch Tuesday, fresh zero-dayMicrosoft marked its largest-ever Patch Tuesday this month, by shipping fixes for nearly 200 vulnerabilities. Within hours, “Nightmare Eclipse”, the researcher behind weeks of escalating Windows exploit releases, dropped a proof-of-concept exploit for a new zero-day: …HELPNETSECURITY.COM
10 JunNew Windows Zero-Day Exploit ‘RoguePlanet’ ReleasedExploiting a race condition in Microsoft Defender, the exploit leads to local privilege escalation to SYSTEM. The post New Windows Zero-Day Exploit ‘RoguePlanet’ Released appeared first on SecurityWeek .SECURITYWEEK.COM
10 JunMicrosoft’s biggest-ever Patch Tuesday fixes 206 bugs, including 3 zero-daysJune 2026 is the largest Patch Tuesday in history, fixing 206 vulnerabilities and three publicly disclosed zero-days.MALWAREBYTES.COM
10 JunAryon Security Raises $29 Million in Series A FundingIn the post-Mythos era, the company’s platform helps organizations enforce security controls across environments. The post Aryon Security Raises $29 Million in Series A Funding appeared first on SecurityWeek .SECURITYWEEK.COM
10 JunMicrosoft ships largest Patch Tuesday on record, with one bug under active attackThe release comes after Microsoft’s security leadership acknowledged last month that AI tools are driving a surge in vulnerability discovery across the industry.THERECORD.MEDIA
10 Jun KEVMicrosoft patches Exchange Server zero-day exploited in attacksMicrosoft has patched an actively exploited Exchange Server vulnerability that allows threat actors to execute arbitrary JavaScript code in cross-site scripting (XSS) attacks targeting Outlook Web Access users. [...]BLEEPINGCOMPUTER.COM
10 JunInfostealers Turn Millions of Devices Into Credential Theft MachinesAs attackers increasingly favor stolen credentials over exploits, infostealers have become a primary source of access for ransomware and other cybercrime operations. The post Infostealers Turn Millions of Devices Into Credential Theft Machines appeared first on SecurityWeek .SECURITYWEEK.COM
10 JunAISLE Snapshot keeps source code under enterprise control during vulnerability scanningAISLE has introduced AISLE Snapshot, a new offering that gives regulated and security-sensitive enterprises access to frontier-class vulnerability detection inside their own environments, at a fraction of the cost, with source code and security data that never leave their control…HELPNETSECURITY.COM
10 JunWho Runs the Ransomware Group ‘The Gentlemen?’A cybercrime group known as The Gentlemen has emerged as the second most active ransomware gang by victim count, rapidly attracting a talented pool of hackers through an aggressive recruitment strategy that promises affiliates 90 percent of any ransom paid by victims. This post e…KREBSONSECURITY.COM
10 JunThe Shadow AI ProblemOrganizations are rapidly adopting generative AI tools, but many employees are experimenting with unauthorized platforms outside official IT oversight. Security leaders are now being forced to decide which AI services meet enterprise requirements and which should be blocked. Not …YOUTUBE.COM
10 JunIdentity theft is turning into a chain reaction for victimsFor a growing number of victims, identity theft no longer ends with a fraudulent charge or a compromised account. More than one in four people who contacted the Identity Theft Resource Center during the reporting period were dealing with multiple identity-related incidents, accor…HELPNETSECURITY.COM
10 JunPatch Tuesday notes: Microsoft fixes a record 200 flaws.Nightmare Eclipse leaks another Windows zero-day. Researchers disclose two critical flaws in AI Chrome extensions. Business news: Cyera closes a $600 million Series G round.THECYBERWIRE.COM
10 JunCISA gives agencies new vulnerability remediation deadlines that take risk levels into accountThe cybersecurity agency says it wants to help network defenders prioritize the fixes that matter the most.CYBERSECURITYDIVE.COM
10 JunCISA directive orders agencies to prioritize vulnerability patching in a new wayA vulnerability that meets all four criteria would need to be fixed within three days, for instance. The post CISA directive orders agencies to prioritize vulnerability patching in a new way appeared first on CyberScoop .CYBERSCOOP.COM
10 JunNightmare-Eclipse Drops Yet Another Microsoft Exploit, RoguePlanetThe disgruntled researcher released yet another PoC for a Windows Defender bug that allows for system takeover, showing no signs of abandoning their ongoing feud with Microsoft.DARKREADING.COM
10 JunAutomated Threat Hunting: Turning Threat Intelligence into Executable Hunt PlansBlake McDermott is Senior Threat Hunter at Rapid7. Every week, threat hunt teams are faced with a steady flow of blogs, advisories, and DFIR reports containing valuable intelligence about adversary behaviors, tactics, techniques, and procedures. The challenge is turning that inte…RAPID7.COM
10 JunPhones Hacked Without ClickingNSO Group’s Pegasus spyware is once again tied to attacks involving WhatsApp. Pegasus uses zero-click exploits, meaning targets do not need to click a link or open an attachment for compromise to occur. A successful zero-click exploit against modern smartphones can provide near-t…YOUTUBE.COM
10 JunTurn specs into evals for any agent with ASSERTAdaptive Spec-driven Scoring for Evaluation and Regression Testing (ASSERT) is an open-source framework for converting natural language behavior requirements into executable evaluations of AI models and agents. The post Turn specs into evals for any agent with ASSERT appeared fir…COMMANDLINE.MICROSOFT.COM
10 JunThe patch pile reaches new heights.Patch Tuesday goes big. Congress looks to harden critical infrastructure. A new Windows zero-day drops. Mobile AI creates security blind spots. AI agents fall for phishing. Browser extensions expose millions. Spammers hide behind Google Cloud Storage. CISA crowns its cyber champi…THECYBERWIRE.COM
10 JunThe ‘Miasma’ worm source code briefly leaked on GitHubThe Miasma credential-stealing attack framework, which has recently targeted open-source ecosystems through supply-chain attacks, was briefly open-sourced on GitHub. [...]BLEEPINGCOMPUTER.COM
10 JunToo Vulnerable for the C-Suite?The discussion explores how vulnerability is perceived at executive levels, especially in high-pressure leadership environments like the C-suite. Speakers argue there is a narrow balance between appearing confident and appearing weak. Leadership advice often promotes vulnerabilit…YOUTUBE.COM
9 JunMeet Hades: The malware that lies to AI security agentsThreat actors are continuing their onslaught against software supply chains, now with malware named after death itself. The newly-discovered Hades Campaign is a “highly sophisticated” supply chain compromise that targets Python developer environments and runs as soon as infected …CSOONLINE.COM
9 JunThe architecture of subtraction: Why it’s time to erase the roads, not just map the trafficThe advent of AI-assisted vulnerability discovery and autonomous exploit development has brought about a new age in cybersecurity—one in which we can no longer rely on patching as a primary defense mechanism. Patching is, by definition, a reactive approach to security. It cannot …HELPNETSECURITY.COM
9 JunTreating AI agents like service accounts for federated query securityIn this interview with Help Net Security, Paras Malhotra, CISO at Starburst, explains how the company handles data governance across federated query environments. Topics include layering Starburst’s access controls above native source permissions, tiering vendor risk across…HELPNETSECURITY.COM
9 JunMalware ships with bugs that defenders could use against itStatic analysis tools have spent years scanning legitimate software for security bugs before it goes out the door. The same scanners work on malware, and malware carries a steady supply of its own bugs. Researchers ran four of these tools across 658 leaked malware projects and fo…HELPNETSECURITY.COM
9 JunThe Anatomy of Cloud Ransomware with Matt CastriottaAre your cloud security controls actually protecting your infrastructure, or are they just keeping the lights on? With host Caleb Tolin, Matt Castriotta, Field CTO for Cloud at Rubrik, breaks down the tactical gaps exposed when organizations blindly replicate data center mi…THECYBERWIRE.COM
9 Jun KEVGoogle patches new Chrome zero-day flaw exploited in the wildGoogle has released emergency updates to patch another Chrome zero-day vulnerability that has been exploited in the wild, the fifth such flaw patched since the start of the year. [...]BLEEPINGCOMPUTER.COM
9 JunScanner Results Are a Starting Point. Here's What Comes Next. - Federico Kirschbaum - ASW #386Most AppSec teams are working through more findings than their teams can validate. SAST surfaces thousands of potential issues. DAST generates alert volume that outpaces triage capacity. Somewhere in that output are the vulnerabilities that matter, the ones that are actually expl…YOUTUBE.COM
9 JunInfosecurity Europe: Why JLR’s CISO Enforced In-Person Password Resets Following Cyber-AttackSpeaking at Infosecurity Europe, Ashish Shrestha, former CISO at Jaguar Land Rover revealed why he wanted over 30,000 employees to change their passwords in the immediate aftermath of the incidentINFOSECURITY-MAGAZINE.COM
9 Jun KEVGoogle Chrome emergency update fixes actively exploited flaw in V8Google has released Chrome 149.0.7827.102/.103 for Windows and macOS, as well as Chrome 149.0.7827.102 for Linux, addressing 74 security vulnerabilities, including a high-severity zero-day flaw in the V8 JavaScript engine that the company says has been exploited in the wild. The …CYBERINSIDER.COM
9 JunCISA gives feds 3 days to patch Check Point VPN bug exploited as zero-dayCISA has ordered U.S. government agencies to secure their Check Point Remote Access VPN and Mobile Access deployments against a critical vulnerability exploited in zero-day attacks by Qilin ransomware affiliates. [...]BLEEPINGCOMPUTER.COM
9 Jun KEVCheck Point Warns Critical Auth Bypass Bug Exploited in the WildCheck Point says a critical vulnerability in its Remote Access VPN and Mobile Access solutions has been exploited by QilinINFOSECURITY-MAGAZINE.COM
9 JunCheck Point VPN Zero-Day Exploited in Qilin Ransomware AttacksThe authentication bypass vulnerability allows attackers to establish VPN connections without a valid password. The post Check Point VPN Zero-Day Exploited in Qilin Ransomware Attacks appeared first on SecurityWeek .SECURITYWEEK.COM
9 JunMythos Preview can weaponize N-day vulnerabilities in hoursMythos Preview can develop working exploits from newly disclosed software vulnerabilities in hours, cutting down a process that has historically taken days or weeks, according to Anthropic. Anthropic’s recent cybersecurity research has largely focused on zero-days, vulnerab…HELPNETSECURITY.COM
9 JunThe Flip That Broke the Cali CartelNow that drug cartels can be labeled foreign terrorist organizations, how do you dismantle one? As part of his 26 years at the Drug Enforcement Administration, retired Special Agent Chris Feistl was on a team that brought the demise of the Cali Cartel in Colombia. One of the worl…THECYBERWIRE.COM
9 JunWill AI Kill the Bug Bounty Industry?Anthropic's Mythos is accelerating vulnerability discovery to machine speed, forcing the bug bounty industry and offensive security teams to adapt to a future where finding flaws is no longer the hard part. The post Will AI Kill the Bug Bounty Industry? appeared first on Security…SECURITYWEEK.COM
9 JunSecurity shifts to the human layer as AI scams surgeCybercriminals are increasingly reshaping familiar social-engineering campaigns around the way employees use AI, with separate advisories from Microsoft and Google documenting how attackers are adapting scams to AI-powered tools, trusted digital services, and changing workplace b…CSOONLINE.COM
9 Jun KEVUpdate Chrome: Google patches actively exploited vulnerability and 73 othersGoogle's latest Chrome update fixes 74 security vulnerabilities, including one under active attack.MALWAREBYTES.COM
9 JunApple Intelligence can now replace weak passwords without user interventionApple’s next generation of Apple Intelligence, the company’s personal intelligence system, expands its capabilities and introduces new security features in Passwords. Automatically Fix Passwords (Source: Apple) Introduced as a standalone app in 2024, Passwords gives users a centr…HELPNETSECURITY.COM
9 JunResearchers Build Self-Replicating AI Worm That Operates Entirely on Local, Open-Weight ModelsUniversity of Toronto researchers have built and tested a proof-of-concept AI-driven computer worm that uses a locally hosted open-weight large language model to reason its way through a network, generate tailored attack strategies for each target it encounters, and replicate its…THEHACKERNEWS.COM
9 JunNew Platform Uses Cryptographic Invisibility to Protect AI-Built ApplicationsAtsign’s AI Architect applies cryptographic protections to agentic software development, aiming to prevent attackers from exploiting vulnerabilities by making application identities effectively invisible. The post New Platform Uses Cryptographic Invisibility to Protect AI-Built A…SECURITYWEEK.COM
9 JunSAP Patches Critical NetWeaver, Commerce VulnerabilitiesThe flaws could lead to the disclosure of sensitive information, memory corruption, and disruption of normal system usage. The post SAP Patches Critical NetWeaver, Commerce Vulnerabilities appeared first on SecurityWeek .SECURITYWEEK.COM
9 JunHackers pose as women seeking romance to spy on Russian soldiersThe group, dubbed SiribClone by Russian cybersecurity firm F6, has been active since at least the summer of 2025 and has primarily targeted members of the Russian armed forces stationed in border regions and combat zones.THERECORD.MEDIA
9 JunWhy AI Can’t Replace PentestersA “clean” pentest report is not always enough. The real value often comes from explaining what attacks were attempted, what defenses held up, and why exploitation failed. That missing context is part of why AI alone struggles to replace experienced pentesters. Automated tools can…YOUTUBE.COM
9 Jun KEVCisco customers encounter another SD-WAN zero-day under attackThe defect marks the seventh actively exploited zero-day in Cisco SD-WANs this year, and the vendor has yet to release a patch. The post Cisco customers encounter another SD-WAN zero-day under attack appeared first on CyberScoop .CYBERSCOOP.COM
9 JunNew Veeam vulnerability exposes backup servers to RCE attacksVeeam has released security updates to patch a critical Backup & Replication security flaw that can be exploited to gain remote code execution (RCE) on domain-joined backup servers. [...]BLEEPINGCOMPUTER.COM
9 Jun KEVShai-Hulud variant compromises dozens of open-source Microsoft packages.Check Point patches actively exploited VPN zero-day. Hacker breaches the French government's encrypted messaging app.THECYBERWIRE.COM
9 JunClaude Mythos Turns N-Days Into N-Hours With Rapid Exploit CreationPublic LLM models with safeguards turned off can also build working exploits, increasing patch gap risks. The post Claude Mythos Turns N-Days Into N-Hours With Rapid Exploit Creation appeared first on SecurityWeek .SECURITYWEEK.COM
9 JunFrench government messaging platform breached through account hijackingFrench authorities are investigating a compromise of Tchap, the government’s secure messaging platform, after hackers hijacked a user account and gained access to public chat rooms. Tchap is the French government’s messaging platform for civil servants, ministries, an…HELPNETSECURITY.COM
9 JunMicrosoft Restores Some GitHub Repos, Keeps Others Offline as Miasma Probe ContinuesMicrosoft on Monday confirmed that it temporarily removed some GitHub repositories in response to a recent security incident that led to 73 of its open-source projects being compromised to inject an information stealer into the code. "Our priority is to protect customers and the …THEHACKERNEWS.COM
9 JunCISA is rethinking how it prioritizes risks and vulnerabilities for feds, private sectorActing director Nick Andersen said a binding operational directive is en route for agencies, and that more specific discussions need to happen with critical infrastructure owners. The post CISA is rethinking how it prioritizes risks and vulnerabilities for feds, private sector ap…CYBERSCOOP.COM
9 JunCheck Point warns of zero-day flaw targeted by ransomware affiliateA vulnerability in the company’s VPN deployments has faced exploitation since early May.CYBERSECURITYDIVE.COM
9 JunXBOW tests Anthropic's Mythos Preview for offensive securityAnthropic's Mythos Preview was highly effective at finding vulnerability candidates, especially when analyzing source code. XBOW explores how the model performed across exploit discovery, reverse engineering, and live-site validation. [...]BLEEPINGCOMPUTER.COM
9 JunOpenSSL Patches High-Severity Vulnerability Found With AIA total of 18 vulnerabilities have been patched in the latest OpenSSL releases, including many that were potentially discovered by AI. The post OpenSSL Patches High-Severity Vulnerability Found With AI appeared first on SecurityWeek .SECURITYWEEK.COM
9 JunMicrosoft June 2026 Patch Tuesday, (Tue, Jun 9th)Microsoft today released patches for 204 vulnerabilities. 38 of these vulnerabilities are considered critical, and three have been disclosed before today. Six of the vulnerabilities affect Microsoft cloud solutions and do not require any user action. In addition, Microsoft incorp…ISC.SANS.EDU
9 JunCISA gives US federal agencies three days to fix a VPN bug under attack by a ransomware gangCheck Point said hackers broke into dozens of organizations by exploiting a VPN bug in several of its products used across the government.TECHCRUNCH.COM
9 JunMicrosoft June 2026 Patch Tuesday fixes 3 zero-day, 200 flawsToday is Microsoft's June 2026 Patch Tuesday, with security updates for 200 flaws and three publicly disclosed zero-day vulnerabilities. [...]BLEEPINGCOMPUTER.COM
9 JunAnthropic releases Mythos-class Fable 5 model with safeguards for cyber risksAnthropic unveiled two new powerful AI models built on its previously restricted Mythos architecture: Claude Fable 5, which is being made broadly available, and Claude Mythos 5, which remains limited to a small group of cybersecurity and infrastructure partners. Anthropic describ…CSOONLINE.COM
9 JunSAP fixes critical flaws in NetWeaver and Commerce CloudSAP has released fixes for 15 vulnerabilities as part of its June 2026 Security Patch package, including four critical-severity flaws affecting SAP NetWeaver and SAP Commerce Cloud. [...]BLEEPINGCOMPUTER.COM
9 JunMicrosoft Patches 200 VulnerabilitiesThree of the vulnerabilities fixed with the latest Patch Tuesday updates were publicly disclosed before Microsoft addressed them. The post Microsoft Patches 200 Vulnerabilities appeared first on SecurityWeek .SECURITYWEEK.COM
9 JunA checkmark for trust, a payload for theft.Miasma malware meddles with Microsoft. SAP fixes critical flaws, Google patches an exploited Chrome zero-day, CanisterWorm spreads through npm, Mac users face a new malvertising threat, France investigates a breach of its secure messaging platform, insurers rethink AI risk, the F…THECYBERWIRE.COM
9 JunServiceNow discloses security incident exposing customer dataServiceNow is warning about a security incident after attackers exploited an unauthenticated access flaw through a vulnerable API endpoint, allowing them to query data from customer instances. [...]BLEEPINGCOMPUTER.COM
9 JunBlame AI: Patch Tuesday Hits Record 206 CVEsVoluminous patch updates could soon be the norm, as artificial intelligence accelerates the speed and scale of vulnerability discovery.DARKREADING.COM
9 JunA Record-Breaking Patch Tuesday for June 2026Microsoft today released software updates to plug nearly 200 security holes across its Windows operating systems and supported software, a record number of fixes for the company's monthly Patch Tuesday cycle. Nearly three dozen of those bugs earned Microsoft's most dire "critical…KREBSONSECURITY.COM
9 JunSN 1082: The Malicious Use of AI - Anthropic's Red Team ReportDiscover how Anthropic's secretive red team and the MITRE ATT&CK framework are mapping the chilling rise of malicious AI use, revealing cyber threats that now move faster than defenders can respond. Was a U.S. law firm right to pay a $20 million ransom. Could Cisco have yet a…TWIT.TV
8 JunGoogle Colab CLI opens runtimes to Claude Code and CodexGoogle released the Google Colab Command-Line Interface, a tool that connects local terminals to remote Colab runtimes. The CLI provides an execution platform for developers and AI agents, letting users provision compute, run local Python scripts on remote runtimes, and retrieve …HELPNETSECURITY.COM
8 JunDockSec: Open-source AI-powered Docker security scannerDockSec is an OWASP Incubator Project that combines three container security scanners with a language-model layer for explanation and remediation. Created by Advait Patel, the Python tool runs Trivy, Hadolint, and Docker Scout against a developer’s Dockerfile and image, cor…HELPNETSECURITY.COM
8 JunMeta AI Bug Exposes Over 20,000 Instagram AccountsMeta confirms an AI tool vulnerability led to unauthorized access to Instagram accounts after a failure in email verification during password resetINFOSECURITY-MAGAZINE.COM
8 Jun KEVSolarWinds Serv-U Vulnerability Exploited in the WildUnauthenticated attackers can exploit the flaw via specially crafted POST requests that crash the Serv-U service. The post SolarWinds Serv-U Vulnerability Exploited in the Wild appeared first on SecurityWeek .SECURITYWEEK.COM
8 JunOpenAI is locking down parts of ChatGPT to reduce data theft risksOpenAI has started rolling out Lockdown Mode for ChatGPT, an optional security setting that restricts access to external resources and several product capabilities. It is available for personal accounts, including Free, Go, Plus, and Pro plans, as well as self-serve ChatGPT Busin…HELPNETSECURITY.COM
8 JunUNC3753 Used Vishing and Physical Intrusions in U.S. Data Theft Extortion CampaignCybersecurity researchers have disclosed details of a financially motivated data theft extortion campaign that has targeted dozens of organizations across professional, legal, and financial services in the U.S. between January and May 2026. The activity has been attributed by Goo…THEHACKERNEWS.COM
8 JunWhy most enterprise security teams would fail a military readiness testHave you ever watched a military cyber ops team go to work responding to a cyberattack simulation? It’s like that scene from Die Hard 4.0 when all the screens start flashing red and systems start shutting down; however, unlike the movies, where bumbling government IT workers are …CSOONLINE.COM
8 Jun15 tough cybersecurity questions every CISO must answerAs CISOs know, an effective security program cannot be static. Rather, it must adapt to the evolving threat landscape and an ever-changing business environment. To adapt and improve, CISOs must continuously evaluate their existing program. That starts with asking tough questions …CSOONLINE.COM
8 JunThe State of AI in SecOps, the Unintended Consequences of Vulnmaxxing, and the News - ESW #462Interview with Filip Stojkovski on the State of AI in SecOps Filip joins us to talk through the 2+ year rollercoaster that Security Operations tooling has been on since AI entered the chat. We discuss the AI SecOps market, which Filip closely tracks through his SecOps Unpacked pr…YOUTUBE.COM
8 JunMeta notifies 20,000 Instagram users whose accounts were hijacked via AI support botMeta has begun notifying approximately 20,000 Instagram users that their accounts may have been compromised after attackers exploited a flaw in an AI-assisted account recovery tool. The company says the vulnerability allowed unauthorized parties to obtain password reset links for…CYBERINSIDER.COM
8 JunOxford University discloses data breach after careers platform hackThe University of Oxford disclosed a new data breach last week after being informed by its third-party provider, Group GTI, that its CareerConnect career services platform had been compromised. [...]BLEEPINGCOMPUTER.COM
8 JunRidgeBot 7.0 automates Active Directory attack simulations for security validationRidge Security has announced the release of RidgeBot 7.0, an update to its automated security validation platform that introduces automated Windows Active Directory penetration testing capabilities. The new version enables organizations to conduct end-to-end domain compromise sim…HELPNETSECURITY.COM
8 JunConnectSecure’s Patch 360 gives MSPs control over patch testing and deploymentConnectSecure has announced the launch of Patch 360, a patch management solution built for managed service providers (MSPs) to reduce deployment risk while accelerating vulnerability remediation. Patch management has long followed a “deploy-and-hope” model, with teams addressing …HELPNETSECURITY.COM
8 JunThe Hardest ForkMythos is real. I know a big chunk of the industry thinks it's a marketing stunt, and I get why. I get it. But I've seen the findings, and they're bad. These aren't "whoops, this line right here is wrong, and that's RCE." They're novel combinations of a few dozen issues out of th…THEHACKERNEWS.COM
8 Jun KEVEverest Forms Vulnerability Exploited to Hack WordPress SitesThe flaw allows attackers to execute arbitrary code remotely and has been exploited in the wild for two months. The post Everest Forms Vulnerability Exploited to Hack WordPress Sites appeared first on SecurityWeek .SECURITYWEEK.COM
8 JunCheck Point links VPN zero-day attacks to Qilin ransomware gangIsraeli cybersecurity company Check Point has released security updates to patch a critical flaw affecting Remote Access VPN and Mobile Access deployments, which was exploited in zero-day attacks. [...]BLEEPINGCOMPUTER.COM
8 JunHackers used Meta’s AI support system to hijack over 20,000 Instagram accountsMeta has revealed that attackers hijacked 20,225 Instagram accounts by exploiting a flaw in the company’s AI-assisted account recovery system. According to the company, a vulnerability in High Touch Support (HTS) allowed unauthorized parties to perform password resets on In…HELPNETSECURITY.COM
8 JunNew Relic expands observability into AI-assisted software developmentNew Relic has announced AI Coding Observability, an open-source tool for monitoring AI-assisted software development workflows. As organizations adopt AI coding assistants, these tools often operate outside existing observability systems, limiting visibility into their use. AI Co…HELPNETSECURITY.COM
8 Jun⚡ Weekly Recap: Instagram Account Hacks, Android Zero-Day, GitHub Worm and MoreMonday again. The weekend was meant to be quiet. It wasn't. Last week had poisoned packages, a broken AI helper, and a worm tearing through repos. The ugly part: basic tricks still worked. A chatbot got fooled. A bot token got leaked inside the malware. The same old mistakes show…THEHACKERNEWS.COM
8 JunTurning Cloudflare’s threat indicators into real-time WAF rulesCloudflare customers can now use Cloudforce One threat intelligence directly within the WAF to block high-risk traffic. By using new cf.intel fields, security teams can automate protection against specific threat actors and targeted industries in real time.CLOUDFLARE.COM
8 JunNew open-source app Loupe reveals how iPhones are fingerprintedPrivacy researchers Mysk have released Loupe, a free and open-source iOS app that shows users what information apps can learn about their devices through publicly available iOS APIs. The tool highlights how data such as language settings, device characteristics, installed apps, a…CYBERINSIDER.COM
8 JunGogs patches critical zero-day enabling remote code executionGogs has patched a critical security zero-day flaw that can allow attackers to compromise Internet-facing instances and access any repositories (including private ones). [...]BLEEPINGCOMPUTER.COM
8 JunCritical Zcash Vulnerability Found and FixedIf you’re a user—owner?—of this cryptocurrency, this is important: On May 29, the security researcher Taylor Hornby found a critical vulnerability in Zcash Orchard privacy pool using Claude Opus 4.8. The Zcash team hired Hornby specifically to look for this kind…SCHNEIER.COM
8 JunTeamPCP Supply Chain Campaign: Activity Through 2026-06-07, (Mon, Jun 8th)This diary continues the Internet Storm Center&#;x26;#;39;s tracking of the TeamPCP supply chain campaign, first documented in the SANS white paper When the Security Scanner Became the Weapon and most recently in the handler diary Activity Through 2026…ISC.SANS.EDU
8 JunWhen Executives Force AI AdoptionThe clip contrasts traditional security operations — where tooling and processes evolve from practitioner feedback — with modern AI adoption, which is often driven by executive-level spending decisions. When large AI purchases happen before teams define real operational needs, or…YOUTUBE.COM
8 JunMicrosoft’s open source tools were hacked to steal passwords of AI developersMicrosoft shut down dozens of GitHub code repositories for Azure and AI coding tools after a reported hack.TECHCRUNCH.COM
8 JunICYMI: May 2026 @AWS SecurityRead all about the latest AWS security features, compliance updates, and hands-on resources in our new, monthly digest posts. You’ll find expert blog posts, new service capabilities, code samples, and workshops. AWS Security Blog posts This month’s AWS Security Blog posts covered…AWS.AMAZON.COM
8 JunCheck Point VPN Flaw Exploited Since Early MayA newly discovered, critical zero-day vulnerability is under attack; a Qilin ransomware affiliate has been blamed for at least one incident.DARKREADING.COM
7 JunBaker Distributing - 102,935 breached accountsIn May 2026, the HVAC/R wholesale distributor Baker Distributing Company was added to the ShinyHunters data extortion group's "pay or leak" site . In early June, the group publicly published data they claimed had been obtained from Baker's SharePoint and Salesforce infrastructure…HAVEIBEENPWNED.COM
7 JunWeek in review: Cisco SD-WAN 0-day exploited, Patch Tuesday forecastHere’s an overview of some of last week’s most interesting news, articles, interviews and videos: OWASP Agent Memory Guard: Stop AI agents from being weaponized through their own memory Agent Memory Guard is an open-source runtime defense layer that sits between an agent and its …HELPNETSECURITY.COM
7 JunEmphere Raises $2.1 Million for AI-Powered Vulnerability RemediationEmphere’s solution delivers AI-driven remediation to software companies to speed up releases. The post Emphere Raises $2.1 Million for AI-Powered Vulnerability Remediation appeared first on SecurityWeek .SECURITYWEEK.COM
7 JunHands on with Intelligent Terminal, an AI-powered Windows TerminalMicrosoft has created an open-source fork of Windows Terminal called "Intelligent Terminal," and it allows you to use AI directly inside Terminal without interfering with the regular session. [...]BLEEPINGCOMPUTER.COM
6 JunCybersecurity Today Month in Review: Microsoft Zero-Days, AI DeregulationHost Jim Love and panelists David Shipley, Laura Payne, and Jeff Williams discuss a researcher ("Chaotic/Nightmare Eclipse") publicly disclosing multiple Windows zero-days affecting components including Defender and BitLocker, frustration with Microsoft's vulnerability disclosure…CYBERSECURITYTODAY.LIBSYN.COM
6 JunAI Agent Uncovers 21 Zero-Days in FFmpeg; Chrome Patches Record 429 BugsTwo things landed within days of each other this week. A security startup reported 21 previously unknown vulnerabilities in FFmpeg, the media library inside almost everything that touches video, all of them found by an autonomous AI agent. The same week, Google shipped Chrome 149…THEHACKERNEWS.COM
6 JunMiasma Worm Hits 73 Microsoft GitHub Repositories in Major Supply Chain AttackMicrosoft's GitHub repositories have become the latest to fall victim to the ongoing Miasma self-replicating supply chain attack campaign. The incident impacted 73 Microsoft repositories across four of its GitHub organizations, including Azure, Azure-Samples, Microsoft, and Micro…THEHACKERNEWS.COM
6 JunPresident Trump signs an executive order on AI oversight.Anthropic is reportedly helping the NSA deploy Mythos. Acer warns of two maximum-severity zero-days.THECYBERWIRE.COM
5 JunNew HTTP/2 Bomb Attack, Trump's AI Security Reviews, Android Zero-Day & The Patching CrisisA newly disclosed attack called HTTP/2 Bomb can crash major web servers in seconds using a single computer and a modest internet connection. Researchers say the attack combines two known techniques into a powerful memory-exhaustion exploit affecting widely used platforms includin…CYBERSECURITYTODAY.LIBSYN.COM
5 JunAI tools becoming hot commodities on ransomware marketplacesSales of AI-based tools is accelerating within underground ransomware marketplaces, lowering the barrier to entry for new actors in the process. An analysis of Telegram channels, 20 dark web forums, and five underground markets by anti-ransomware platform vendor Halcyon found tha…CSOONLINE.COM
5 JunAgentGG: Open-source agentic SAST scannerStatic analysis tools have spent years matching source code against known-bad patterns and handing engineers long lists of candidate issues to triage by hand. AgentGG approaches the same job with AI agents that read the code, follow imports, walk the call graph, and confirm a fin…HELPNETSECURITY.COM
5 JunThieves can pull off keyless car theft in under a minute and here’s how to stop themA keyless car can be stolen in under a minute. Two people, a pair of cheap radio amplifiers, and a fob sitting on a hallway table inside the house. That is enough. No broken glass. No alarm. No sound. Most keyless cars remain vulnerable The vulnerability runs across the global ma…HELPNETSECURITY.COM
5 JunNew infosec products of the week: June 5, 2026Here’s a look at the most interesting products from the past week, featuring releases from Asimily, depthfirst, Diligent, Hyland, MazeBolt, and Noma. Asimily turns device risk into automated network policy Asimily has launched Segmentation Orchestration, enabling connected-device…HELPNETSECURITY.COM
5 JunChrome 149 Patches 429 VulnerabilitiesOver 100 bugs are critical or high-severity, mainly use-after-free and insufficient validation of untrusted input flaws. The post Chrome 149 Patches 429 Vulnerabilities appeared first on SecurityWeek .SECURITYWEEK.COM
5 JunAttackers obtained encrypted password vaults from some Dashlane user accountsDashlane has disclosed new details about a brute-force attack that let a threat actor access some customer accounts and copy encrypted vaults. Dashlane said it found no evidence that the attackers compromised its internal systems. The company first acknowledged the incident on Ma…HELPNETSECURITY.COM
5 JunBinary Choice Researcher Or Threat ActorMicrosoft stated that uncoordinated vulnerability disclosures, especially those including proof-of-concept exploit code before patches exist, can create real-world risk by enabling attackers to weaponize vulnerabilities faster. The debate reflects a long-standing conflict in cybe…YOUTUBE.COM
5 JunEU unveils tech sovereignty package to cut reliance on US, Chinese suppliersThe package bundles two draft laws — a Chips Act 2.0 and a Cloud and AI Development Act (CADA) — alongside an Open Source Strategy and a roadmap for digitalizing the energy system.THERECORD.MEDIA
5 JunIn Other News: Anthropic Maps AI Threats, Unpatched Comodo Flaw, Palantir Chief Eyed for CISAOther noteworthy stories that might have slipped under the radar: Ultrahuman data leak, The Gentlemen ransomware analysis, Hola Browser bundles miner. The post In Other News: Anthropic Maps AI Threats, Unpatched Comodo Flaw, Palantir Chief Eyed for CISA appeared first on Security…SECURITYWEEK.COM
5 JunSeeking Counsel: Ongoing Targeted Campaign Against US Law FirmsWritten by: Chad Reams, Tufail Ahmed, Keith Knapp, Ashley Frazer, Tyler McLellan Introduction From January through May 2026, Mandiant identified a financially motivated data theft extortion campaign executed by the threat cluster UNC3753 (also tracked as "Luna Moth," “Chatty Spid…CLOUD.GOOGLE.COM
5 JunNightmare Eclipse incident shows the researcher-vendor fights may never fully go awayWhen a researcher went public with Microsoft vulnerabilities, it laid bare a conflict that has never really been solved. The post Nightmare Eclipse incident shows the researcher-vendor fights may never fully go away appeared first on CyberScoop .CYBERSCOOP.COM
5 JunCisco warns zero-day flaw in SD-WAN is being exploitedThe company cautioned that no current patches are available and the flaw could allow an attacker to conduct command injection attacks.CYBERSECURITYDIVE.COM
5 JunSprawling new House AI bill includes frontier model oversight, open-source security grantsThe legislation has already drawn widespread criticism for its proposal to preempt state AI laws.CYBERSECURITYDIVE.COM
5 JunAndroid Spyware Asin Targets Arabic Users via Fake News, PDF and War Map AppsArabic-speaking users have emerged as the target of a new Android spyware codenamed Asin, according to findings from ESET. The Slovakian cybersecurity company said it first detected the malware spread via multiple campaigns in early 2025, with each attack wave making use of disti…THEHACKERNEWS.COM
5 JunOWASP Incubator Project Helps Developers Find and Fix Vulnerable Dependencies in SecondsCVE Lite CLI is a free, open-source command line tool that scans your projects in seconds and tells you exactly which included packages contain a vulnerability. The post OWASP Incubator Project Helps Developers Find and Fix Vulnerable Dependencies in Seconds appeared first on Sec…SECURITYWEEK.COM
5 JunPatching fast and slow: Ruby devs delay to defend against supply chain attackThe team behind RubyGems, a package hosting site for Ruby developers, has added a new feature to bundler, a tool for managing Ruby packages (or ‘gems’) to protect developers against the recent wave of software supply chain attacks : A cooling-off period before recently updated pa…CSOONLINE.COM
5 JunBuilding secure B2C applications with fine-grained access control using Amazon Cognito and Amazon Verified PermissionsModern web applications require robust security controls to protect user data and application resources. Authentication and authorization are two fundamental pillars of application security that answer critical questions: Who are you? and What are you allowed to do? Implementing …AWS.AMAZON.COM
5 JunCISA: Hackers now exploit SolarWinds Serv-U flaw to crash serversCISA warned today that hackers are now actively exploiting a recently patched high-severity SolarWinds Serv-U flaw to crash servers. [...]BLEEPINGCOMPUTER.COM
5 Jun KEVSeven Cisco Zero-Days AlreadyThis discussion covers another actively exploited Cisco SD-WAN vulnerability affecting Cisco Catalyst SD-WAN Manager. According to the clip, this marks the seventh SD-WAN zero-day reported in 2026. Successful exploitation can allow authenticated attackers to execute commands as r…YOUTUBE.COM
5 JunLocal AI, Salesforce, Fluttershell, Aspose, http/2, Cisco, Used Tech, Josh Marpet - SWN #587Local AI, Salesforce, Fluttershell, Aspose, http/2 bomb, Passwords, Cisco, Used Tech, Josh Marpet, and More on this episode of the Security Weekly News Visit https://www.securityweekly.com/swn for all the latest episodes! Show Notes: https://securityweekly.com/swn-587YOUTUBE.COM
5 JunCybersecurity Hygiene Reinforced by the 2026 Verizon DBIRThe 2026 Verizon DBIR highlights how CIS Controls and CIS Benchmarks strengthen cybersecurity hygiene and defend against today’s top attacks.CISECURITY.ORG
4 JunBeware the ‘son of Mythos,’ security experts warnLONDON — Enterprise security teams were urged by security experts at Infosecurity Europe to brace for impact as both Anthrophic and OpenAI expand access to their frontier AI models for vulnerability discovery. Anthropic, in particular, is significantly expanding Project Glasswing…CSOONLINE.COM
4 JunHole in GitHub’s browser-based VSCode editor could lead to stolen tokenA vulnerability in GitHub’s browser-based VSCode editor could lead to the theft of a developer’s token under certain circumstances, says a researcher. The issue, revealed this week in a blog by Ammar Askar , has apparently been already addressed by GitHub owner Microsoft. But it …CSOONLINE.COM
4 JunHearing Is no longer believing.This week, hosts of N2K CyberWire Maria Varmazis and Dave Bittner alongside …THECYBERWIRE.COM
4 JunCISA directive for AI executive order to be released this week, Andersen saysThe binding operational directive will focus in part on “vulnerability alleviation and vulnerability management,” Andersen said in remarks delivered at the TechNet Cyber conference in Baltimore.THERECORD.MEDIA
4 JunCisco Warns of Available PoC for Critical Unified CM VulnerabilityThe high-severity flaw can be exploited remotely, without authentication, in server-side request forgery (SSRF) attacks. The post Cisco Warns of Available PoC for Critical Unified CM Vulnerability appeared first on SecurityWeek .SECURITYWEEK.COM
4 JunVS Code Vulnerability Allows One-Click GitHub Token TheftA researcher has disclosed the full details of the vulnerability and released a PoC without notifying Microsoft in advance. The post VS Code Vulnerability Allows One-Click GitHub Token Theft appeared first on SecurityWeek .SECURITYWEEK.COM
4 JunFrom critical to controlled: Cutting vulnerabilities in a live manufacturing environmentA vulnerability scanner flags a critical CVSS 10 vulnerability on an industrial asset. The report lands in the boss’ inbox and now he wants to know why we’re sitting on a critical vulnerability. In a normal IT environment, you patch it then close the ticket and call it a day. If,…HELPNETSECURITY.COM
4 JunFake Sites Mimicking Open-Source Tools Rank High on Google to Deliver Malware via TDSCybersecurity researchers have flagged a large-scale operation that impersonates open-source and freeware projects to funnel unsuspecting users through a Traffic Distribution System (TDS) and deliver malware families like Remus Stealer, AnimateClipper, and the SessionGate framewo…THEHACKERNEWS.COM
4 JunOver 1.4 Million Accounts Disrupted in Cybercrime CrackdownLaw enforcement and tech companies disrupted infrastructure linked to scammers operating across Southeast Asia. The post Over 1.4 Million Accounts Disrupted in Cybercrime Crackdown appeared first on SecurityWeek .SECURITYWEEK.COM
4 JunCisco warns of critical Unified CM flaw with PoC exploit codeCisco has released security updates to patch a critical-severity Unified Communications Manager (Unified CM) flaw that allows attackers to gain root privileges. [...]BLEEPINGCOMPUTER.COM
4 JunInfosecurity Europe: Mythos Outperforms GPT5.5 on Google Chrome Vulnerability Exploits, Says New BenchmarkA Bugcrowd researcher has unveiled ExploitBench, an independent benchmark of AI models for vulnerability exploitationINFOSECURITY-MAGAZINE.COM
4 JunResearchers built AI worm that can adapt to infect diverse devicesResearchers at the University of Toronto have unveiled an AI-powered computer worm capable of autonomously adapting its attack methods as it moves through a network. The proof-of-concept malware was built using publicly available open-weight AI models, showing that advanced offen…CYBERINSIDER.COM
4 JunMirasvit Vulnerability Exploited to Execute Code on Magento ServersA flaw in the Full Page Cache Warmer extension can be exploited without authentication via serialized PHP object payloads. The post Mirasvit Vulnerability Exploited to Execute Code on Magento Servers appeared first on SecurityWeek .SECURITYWEEK.COM
4 JunResearcher publishes GitHub token-stealing exploit, blames Microsoft’s disclosure processThe security researcher, Ammar Askar, released the new proof-of-concept exploit on his personal blog — alongside the public tracker for issues in VS Code — giving a GitHub security contact roughly one hour's notice beforehand.THERECORD.MEDIA
4 JunHackers Are After the Gaps in Your Vulnerability Program: Here's Their PlaybookThreat actors are actively teaching newcomers how to find, exploit, and profit from vulnerable systems. Flare explores what a popular underground hacking tutorial reveals about modern attacker workflows. [...]BLEEPINGCOMPUTER.COM
4 JunHow the “Swiss Cheese” model can help you choose the right MDR providerNot all managed detection and response (MDR) solutions are equal. Finding the differences between vendors can be quite hard, and then understanding how those differences impact your business can be even harder. For instance, you may come across an MDR provider whose pricing is ba…RAPID7.COM
4 JunCrowdStrike, Palo Alto Networks defy estimates as AI fuels cyber demandThe cybersecurity sector has been under perceived pressure due to accelerating deployment of AI tools.CYBERSECURITYDIVE.COM
4 JunOpenAI responds to White House executive order on AI governanceOpenAI has proposed mandatory federal evaluations of the most capable AI models before public release while arguing that regulators should stop short of deciding whether those systems can be deployed, staking out a middle ground in the debate over how frontier AI should be govern…CSOONLINE.COM
4 JunEverest Forms Pro Vulnerability Allows Remote Code Execution on WordPress SitesCritical Everest Forms Pro RCE flaw exploited to create rogue WordPress admin accountsINFOSECURITY-MAGAZINE.COM
4 JunMeta’s own AI chatbot to blame for Instagram accounts being stolen in secondsHackers have been hijacking Instagram accounts at scale by exploiting Meta's AI support chatbot. And, as if that weren't bad enough, the technique required no technical skill whatsoever. Read more in my article on the Fortra blog.FORTRA.COM
4 JunGain visibility into DDoS attacks with flow logs in AWS Shield AdvancedReconstructing distributed denial of service (DDoS) attack traffic used to mean combining data from multiple sources after the fact. AWS Shield Advanced attack flow logs change that—they capture traffic metadata during attacks so you can pinpoint sources, verify mitigations, and …AWS.AMAZON.COM
4 JunTenable joins Anthropic’s Project Glasswing to advance AI-era cyber defenseBy participating in Project Glasswing and working with Claude Mythos Preview, Tenable can help customers better understand how emerging frontier AI models behave, their evolving risks and benefits for cybersecurity, and the kinds of controls organizations will need as AI adoption…TENABLE.COM
4 JunNot every headhunter is hiring.The Five Eyes issue a rare joint warning on China. Jen Easterly weighs in on Trump’s AI EO. Researchers warn everyday notifications can become AI attack vectors. IronWorm is a sophisticated Rust-based infostealer targeting software developers. Cisco patches a critical vulnerabili…THECYBERWIRE.COM
4 JunTrump considers Palantir exec to lead CISAShyam Sankar, the chief technology officer at Palantir Technologies, has emerged as a lead contender for the long vacant Cybersecurity and Infrastructure Security Agency (CISA) director role, according to the sources, who requested anonymity to discuss the administration’s search…THERECORD.MEDIA
3 JunAnthropic grants Project Glasswing access to 150 more companies, with a focus on critical infrastructureAnthropic on Tuesday announced that it was adding 150 more companies to its Project Glasswing AI-based vulnerability hunting initiative, with a particular focus on critical infrastructure companies including those involved in “power, water, healthcare, communications and hardware…CSOONLINE.COM
3 JunCarnival Data Breach Exposes Millions as Microsoft Backs Down on Researcher ThreatsCybersecurity Today for June 2, 2026. Microsoft has backed away from its hard-line stance against vulnerability researchers after widespread criticism from the security community. The dispute began after independent researcher Nightmare Eclipse published proof-of-concept code for…CYBERSECURITYTODAY.LIBSYN.COM
3 JunRisky Business #840 -- Microsoft walks back researcher threatsOn this week’s show special guest co-host Andy Boyd joins Patrick Gray and James Wilson to discuss the week’s cybersecurity news. Andy is the CEO of REDLattice, which makes the Paragon “intelligence collection and reconnaissance” solution. They cover: Adversaries are tracking US …RISKY.BIZ
3 JunWhat AI Security Research Actually Looks Like with John Zenick of Harmonic SecurityJohn Zenick started his cybersecurity journey modding a Nintendo Wii in middle school. He is now an AI Security Researcher at Harmonic Security and a Teaching Fellow at Harvard, and joins our show to discuss everything AI! Even though we're a marketing podcast, of course we love …THECYBERWIRE.COM
3 JunKnown vulnerabilities behind most application security incidentsEight in ten organizations took an application security hit during the past year tied to a vulnerability their team had already cataloged, according to a survey of 902 IT and security professionals conducted by the Cloud Security Alliance. The pattern points to a structural condi…HELPNETSECURITY.COM
3 JunVS Code zero-day lets hackers steal GitHub tokens in one clickA security researcher has released exploit code for a Visual Studio Code (VS Code) zero-day vulnerability that allows attackers to steal GitHub authentication tokens by tricking users into clicking a link. [...]BLEEPINGCOMPUTER.COM
3 JunSupply Chain Attacks: Open Source or Open Door?In this episode of the Microsoft Threat Intelligence Podcast, host Sherrod DeGrippo is joined by Allie Luhrs and Mario Samolis from Microsoft Security to explore the growing threat of open source software supply chain attacks. They discuss how malicious NPM packages, comprom…THECYBERWIRE.COM
3 JunMazeBolt brings AI-generated attack simulation to DDoS security testingMazeBolt has announced the launch of RADAR VectorAI, a new MazeBolt module that creates AI-generated DDoS attacks. As AI outpaces human response, enterprises need to have access to validated DDoS vulnerability data about both known and AI-generated attack vectors. Mythos has rais…HELPNETSECURITY.COM
3 JunGoogle adds a silent check to catch scammers posing as your contactsAndroid is introducing fake call detection to help protect users from impersonation scams. The feature can detect and flag suspected spoofed calls when both parties use Phone by Google on Android 12 or later. It will roll out globally this month, starting with Pixel devices. Stor…HELPNETSECURITY.COM
3 JunAnthropic expands Project Glasswing to 150 organizations in more than 15 countriesAnthropic is expanding Project Glasswing, its cybersecurity initiative built around the Claude Mythos Preview model, by adding about 150 organizations following several weeks of work with its initial group of partners, security firms, open-source maintainers, and government agenc…HELPNETSECURITY.COM
3 JunNew HTTP/2 Bomb Vulnerability Allows Remote DoS on NGINX, Apache, IIS, Envoy & CloudflareCybersecurity researchers have discovered a remote denial-of-service exploit that affects major web servers, including NGINX, Apache HTTPD, Microsoft IIS, Envoy, and Cloudflare Pingora. The vulnerability has been codenamed HTTP/2 Bomb by Calif. "The vulnerable behavior exists in …THEHACKERNEWS.COM
3 JunLessons from the Canvas cyberattackCanvas cyberattack: Who, what, when, how? What and when? Over May 6 and 7, 2026, Canvas learning management system (LMS) users were served up a defaced web page in place of the expected login page. The altered web page displayed a warning by the ShinyHunters criminal hacker and e…CSOONLINE.COM
3 JunScaling to $100M as the Security Weekly Index Hits an All Time High - Joshua Gould - BSW #450The ultimate goal, scale a company to $100M and go IPO. Easier said than done. We've seen some make it and others that get stuck. What's he difference? Joshua Gould, CEO at thebigword, joins Business Security Weekly to discuss how to scale to $100M. From startup to platform, Josh…YOUTUBE.COM
3 JunMicrosoft Tries to Calm Legal Threat Fears After Zero-Day Disclosure BacklashMicrosoft has responded to backlash over its initial threats of legal action against researchers who publicly disclose zero-day vulnerabilities without coordinated notification. The controversy concerns a researcher known online as Chaotic Eclipse and Nightmare Eclipse, who in re…SECURITYWEEK.COM
3 JunAI may finally unlock the cyber budgets CISOs have wanted for yearsFor nearly two decades, cybersecurity leaders have faced the same reality: No matter how catastrophic the latest breach, ransomware attack, or nation-state intrusion, security spending often struggled against competition with every other business priority. AI may finally be chang…CSOONLINE.COM
3 JunNew cyber force would cost up to $11 billion to start, commission saysThe military branch would take 12 to 18 months to get up and running and also include roughly 5,000 members of the National Guard and up to 6,000 civilians, according to the commission.THERECORD.MEDIA
3 JunNew “HTTP/2 Bomb” attack can exhaust server memory in secondsResearchers have disclosed a new denial-of-service (DoS) technique dubbed HTTP/2 Bomb, a memory-exhaustion attack that can render major web servers inaccessible within seconds. The attack affects the default HTTP/2 configurations of nginx, Apache HTTP Server, Microsoft IIS, Envoy…CYBERINSIDER.COM
3 JunPolice dismantles 9 crime groups in illegal streaming crackdownEuropean and international law enforcement agencies have dismantled nine organized crime groups and arrested 29 suspects in a major crackdown on illegal streaming operations. [...]BLEEPINGCOMPUTER.COM
3 Jun‘HTTP/2 Bomb’ Exploit Knocks Web Servers Offline in SecondsThe default HTTP/2 configuration of major web servers is vulnerable to an attack chain combining a compression bomb and a Slowloris-style hold. The post ‘HTTP/2 Bomb’ Exploit Knocks Web Servers Offline in Seconds appeared first on SecurityWeek .SECURITYWEEK.COM
3 JunMicrosoft wants to put AI agents on a short leashAs enterprises race to adopt AI agents across software development workflows, Microsoft is rolling out new controls aimed at keeping the transformation from becoming a security headache. At its annual developer conference, Microsoft Build, the company unveiled a set of initiative…CSOONLINE.COM
3 JunThe sorry state of skill distributionPublic skill marketplaces are being flooded with malicious skills that steal credentials, exfiltrate data, and hijack agents. In response, a segment of the security industry released skill scanners, a new family of tools designed to detect malicious skills before they’re installe…TRAILOFBITS.COM
3 JunAcer working to patch max severity zero-days in Wave 7 routersAcer is working to address two maximum-severity zero-day vulnerabilities affecting its Wave 7 mesh routers. [...]BLEEPINGCOMPUTER.COM
3 JunOrganizations Warned of Exploited Linux Kernel VulnerabilityAn improper authentication bug allows attackers to escalate their privileges and escape containers. The post Organizations Warned of Exploited Linux Kernel Vulnerability appeared first on SecurityWeek .SECURITYWEEK.COM
3 JunBeyond the Zero-Day: See Your Network Like an Attacker | Webinar with HD MooreAssume the breach. Zero-days keep shipping, AI is writing exploits faster than anyone patches, and "patch everything in time" stopped working years ago. Stop betting the org on winning that race. You don't control which bug lands. You control what it can reach once it does. That …THEHACKERNEWS.COM
3 JunKirki, Burst Statistics WordPress Plugin Flaws in Attackers’ CrosshairsThreat actors are exploiting vulnerable Kirki and Burst Statistics deployments to elevate privileges and take over websites. The post Kirki, Burst Statistics WordPress Plugin Flaws in Attackers’ Crosshairs appeared first on SecurityWeek .SECURITYWEEK.COM
3 JunSimplify security management with CIS SecureSuite PlatformNew operating systems prioritize usability, a reality which threat actors use to exploit security gaps. Every misconfiguration creates an opportunity for compromise, and lean teams struggle in their security management efforts to harden hundreds or thousands of endpoints. CIS Sec…HELPNETSECURITY.COM
3 JunAutonomous AI-driven worm can reason its way through corporate networksResearchers at the University of Toronto, the Vector Institute, and the University of Cambridge have built and tested a proof-of-concept AI-driven worm that does not operate on a fixed list of exploits. Instead, it analyzes each target it encounters, reasons about how to attack i…HELPNETSECURITY.COM
3 JunOne-Click GitHub Dev Attack Lets Attackers Steal Full GitHub OAuth TokensCybersecurity researchers have disclosed a one-click attack via Microsoft Visual Studio Code (VS Code) that makes it possible to steal a user's GitHub token. "Just by clicking a link, it's possible for an attacker to steal a GitHub token that can read and write to your repos, inc…THEHACKERNEWS.COM
3 JunInfosecurity Europe: Vulnerability Management Innovator Konvu Wins Cyber Startup AwardInaugural Infosecurity Europe Cyber Startup Award Winner Impresses Panel with Ability Help Prioritize Vulnerabilities in AI eraINFOSECURITY-MAGAZINE.COM
3 JunMicrosoft responds to security challenges facing code, AI agents, and modelsMicrosoft has introduced a series of security tools and capabilities focused on AI-driven vulnerability discovery, AI agents, and AI models. The updates include a multi-agent vulnerability discovery system, new controls for managing and securing AI agents, data protection capabil…HELPNETSECURITY.COM
3 JunCISA warns of active attacks exploiting Android, Linux bugsThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning that hackers are exploiting vulnerabilities in the Linux kernel and Android operating system. [...]BLEEPINGCOMPUTER.COM
3 JunWhen Pages Hijack AI ResponsesAI assistants that summarize third-party content may render markdown links and images from those sources directly in their response UI. These elements can be displayed as clickable or embedded content inside what users perceive as a trusted assistant interface. A malicious page c…YOUTUBE.COM
3 JunOver 100 Dutch hotels hit by breach exposing guest reservation dataMore than 100 hotels in the Netherlands have been impacted by a data breach that exposed guest and reservation information. The stolen data enabled cybercriminals to send convincing phishing messages to travelers, while similar incidents have also been reported by hotels in Belgi…CYBERINSIDER.COM
3 JunA Day in the Life of an MDR Analyst: Inside the Modern SOCWhat actually happens inside a SOC when an incident unfolds? Most teams see the alerts and the outcomes, but the decision-making in between is often less visible. At the Rapid7 2026 Global Cybersecurity Summit, the signature session Inside the Modern SOC: Who Carries You Through …RAPID7.COM
3 JunThe AI race gets a referee.AI oversight arrives at the White House. A Cyber Force gains momentum. Critical infrastructure comes under cyberattack. Acer faces zero-day trouble. A stock exchange executive gets spied on for months. HTTP/2 Bomb threatens web servers. Quantum’s classical side grows bigger. Brit…THECYBERWIRE.COM
2 JunTrusting the wrong package.Welcome in! You’ve entered, Only Malware in the Building. Join us each month to sip tea and solve mysteries about today’s most interesting threats. Your host is Selena Larson, Proofpoint intelligence analyst and host of their podcast …THECYBERWIRE.COM
2 JunDashlane Discloses Brute-Force Attack, Encrypted Vaults of Fewer Than 20 Users DownloadedPassword manager Dashlane has disclosed that "fewer than" 20 users on the personal subscription plan had their encrypted vaults downloaded following a brute-force attack launched by an unknown party. On May 31, 2026, the company said an "external" threat actor launched a brute-fo…THEHACKERNEWS.COM
2 JunWhy you need BAS and autonomous pentesting togetherMost security teams know the drill: A new autonomous penetration testing tool gets deployed, and the first run is genuinely impressive. The dashboard surfaces critical findings, maps lateral movement paths nobody had documented before, and exposes a legacy service account that ha…HELPNETSECURITY.COM
2 Jun175: BayrobIt started with a fake car listing on eBay. What looked like a simple online scam quietly grew, over more than a decade, into one of the most sophisticated cybercrime operations the FBI had ever traced. Custom malware. Opsec off the charts. Fleets of infected computers mining cry…DARKNETDIARIES.COM
2 Jun7 tabletop exercise mistakes that sabotage incident responseDiscussion-based, low-stress simulations during which IT, legal, and other key leadership stakeholders walk through theoretical scenarios to test their preparedness for cyber incidents is a popular and highly useful tool. Yet unless tabletop training is properly handled, the resu…CSOONLINE.COM
2 JunDashlane Brute-Force Attack Leads to Limited Encrypted Vault DownloadsDashlane’s security systems automatically locked accounts to protect them against the hacking attempts. The post Dashlane Brute-Force Attack Leads to Limited Encrypted Vault Downloads appeared first on SecurityWeek .SECURITYWEEK.COM
2 JunPakistan-Linked SideCopy Targets Afghanistan Finance Ministry with Xeno RATCybersecurity researchers have disclosed details of a spear-phishing campaign likely undertaken by the Pakistan-aligned SideCopy group targeting Afghanistan's Ministry of Finance with an open-source remote access trojan called Xeno RAT. "The campaign opens with a spear phishing d…THEHACKERNEWS.COM
2 JunAttack targeting OpenAI Codex users exposes AI software supply chain risksA malicious npm package posing as a remote user interface for OpenAI Codex exfiltrated developer authentication tokens, after attackers allegedly published code to npm that was not visible in the project’s public GitHub repository. Researchers at Aikido said the package, called c…CSOONLINE.COM
2 JunThe Manhattan Institute Helped Kill DEI. Now It’s Coming for ProtestsThe right-wing think tank is actively pushing “civil terrorism”—increasing penalties for minor crimes committed while people engage in constitutionally protected free speech.WIRED.COM
2 JunRed Hat npm packages compromised in new Mini Shai-Hulud malware waveUnknown attackers have compromised 30+ Red Hat Cloud Services npm packages with malware that goes after credentials stored in developers’ build environment. What the malware stole and how it can spread further The compromised packages were published in two different GitHub …HELPNETSECURITY.COM
2 JunMicrosoft Threatening Security ResearcherAn anonymous security researcher called “Nightmare Eclipse” has been publishing a series of significant security exploits against Microsoft Windows—including one that breaks BitLocker. Microsoft has threatened legal action against the researcher. Lots of recrimi…SCHNEIER.COM
2 JunMeta AI Hands Over High-Profile Instagram Accounts to HackersExploiting a confused deputy weakness, the hackers simply asked the chatbot to link the account to a new email address. The post Meta AI Hands Over High-Profile Instagram Accounts to Hackers appeared first on SecurityWeek .SECURITYWEEK.COM
2 Jun KEVGoogle fixes one actively exploited Android zero-day, 124 flawsGoogle has released the June 2026 Android security patches to address 124 vulnerabilities, including one zero-day flaw exploited in targeted attacks. [...]BLEEPINGCOMPUTER.COM
2 JunAI-Driven Exploitation is Destroying Vulnerability Management. Here’s How to Handle It.AI-driven exploitation timelines are rapidly shrinking, and they are not going to stop shrinking. Vulnerabilities are being discovered, reproduced, and weaponized faster than ever in the history of enterprise security. As a result, the window between a vulnerability being disclos…THEHACKERNEWS.COM
2 JunInfected Red Hat npm packages expose developer credentialsDevelopers who pulled packages from Red Hat’s @redhat-cloud-services npm namespace over the weekend got a secret-stealing worm instead. Security researchers from several cybersecurity outlets are warning of a new supply chain attack compromising over 30 Red Hat Cloud Services-rel…CSOONLINE.COM
2 Jun KEVCISA flags two-year-old Oracle flaw as actively exploited in attacksCISA has ordered government agencies to secure their systems against a high-severity Oracle WebLogic Server vulnerability that was patched two years ago and is now actively exploited in attacks. [...]BLEEPINGCOMPUTER.COM
2 JunCritical Vulnerability in HP VoIP Phones Enables Enterprise Network BreachesA stack-based buffer overflow bug can be exploited for remote code execution on a vulnerable device. The post Critical Vulnerability in HP VoIP Phones Enables Enterprise Network Breaches appeared first on SecurityWeek .SECURITYWEEK.COM
2 JunCodex knowledge work expands into research, reports, and spreadsheetsOffice workers in the United States lose hours each week to email triage and to searching for files spread across disconnected systems. Roughly 40 percent of US labor, about 72 million people, works primarily with information such as analysis, documents, designs, and communicatio…HELPNETSECURITY.COM
2 JunEuro-Office adds encrypted email provider Tuta ahead of public releaseTuta has announced that it has joined the Euro-Office project, a European initiative developing an open-source, cloud-based office suite designed to reduce dependence on Microsoft and Google services. The announcement has been released just one week before the launch of Euro-Offi…CYBERINSIDER.COM
2 JunDashlane confirms user vaults were copied by hackers in recent attackDashlane has disclosed that attackers were able to download copies of encrypted password vaults for a small subset of users during a brute-force attack that targeted customer accounts over the weekend. The company says the incident did not involve a breach of its internal systems…CYBERINSIDER.COM
2 JunNoma brings visibility and access governance to AI agents and MCP serversNoma has announced the launch of Noma Agent Access Control, which helps security teams discover, govern, and enforce access policies for AI agents and Model Context Protocol (MCP) servers throughout the enterprise. AI agents and MCP servers have proliferated across developer envi…HELPNETSECURITY.COM
2 JunTuskira Quell identifies, mitigates, and validates zero-day risk before breachTuskira launched Quell, its exposure-led zero-day defense capability. Quell helps enterprises survive the window between a zero-day’s disclosure and a patch by determining which zero-days are reachable in their environment, whether existing controls would stop them, and whi…HELPNETSECURITY.COM
2 JunMeta adds stricter guardrails for teen feedsMeta has expanded its Teen Accounts 13+ content settings globally on Instagram, Facebook, and Messenger. The safeguards are designed to help young users see age-appropriate content by default. The company also introduced Limited Content on Instagram for parents seeking stricter r…HELPNETSECURITY.COM
2 JunAnthropic scales Claude Mythos to critical infrastructure in 15+ countriesAnthropic is expanding Project Glasswing, its security vulnerability program, and access to Mythos to 150 organizations across 15 countries — targeting critical infrastructure in power, water, healthcare, and communications where a cyberattack could affect 100 million people.TECHCRUNCH.COM
2 JunAnthropic shares Mythos with 150 more organizations, including critical infrastructure operatorsThe AI firm also said it’s exploring how to help open-source developers deal with a flood of vulnerability reports.CYBERSECURITYDIVE.COM
2 JunPassword manager Dashlane says hackers stole some customers’ password vaultsThe password manager giant said hackers were able to 'brute-force' its two-factor system, allowing them to access customer accounts and download their password vaults.TECHCRUNCH.COM
2 JunSecure multi-tenant AI agents with Amazon Bedrock AgentCore resource-based policiesSoftware as a service (SaaS) providers building AI-powered applications on Amazon Bedrock AgentCore often need to serve multiple tenants with distinct security requirements from a shared infrastructure. Some tenants require cross-account access from their own Amazon Web Services …AWS.AMAZON.COM
2 JunUnpatched NTLM Coercion in Windows search: URI Handler, Same Bug, No CVE, No FixThe same NTLM coercion primitive that got patched in the Snipping Tool exists in Windows Explorer's search: handler. No CVE. No fix. If your patching relies on CVE coverage, you have a blind spot.HUNTRESS.COM
2 JunTwo New Reports Offer Competing Explanations for Cybersecurity’s Growing CrisisAs AI shortens the path from vulnerability disclosure to exploitation, researchers disagree on whether the problem is inadequate security tools or inadequate operational control. The post Two New Reports Offer Competing Explanations for Cybersecurity’s Growing Crisis appear…SECURITYWEEK.COM
2 JunTrump revives parts of canceled AI order with cybersecurity-focused directiveUS President Donald Trump signed an executive order aimed at strengthening cybersecurity defenses and establishing a voluntary framework for cooperation between the federal government and developers of advanced artificial intelligence models, reviving portions of a broader AI ini…CSOONLINE.COM
2 JunThe Rise of Shadow AISecurity teams once worried about shadow IT and shadow cloud. Now a growing concern is shadow AI: employees using AI services outside approved corporate accounts and workflows. According to the discussion, a large percentage of AI usage may still be occurring through non-corporat…YOUTUBE.COM
2 JunThe bugs are piling up faster than the fixes.A federal watchdog questions NIST over its vulnerability database backlog. Google patches an Android zero-day. Citizen Lab exposes a powerful location-tracking platform. Malware hides commands in Steam comments. Researchers spot AI-assisted malware development. Attackers compromi…THECYBERWIRE.COM
2 JunSN 1081: AI Captured the Flag - Personal AI: Productivity Superpower or Privacy Threat?AI vulnerability discovery just upended the legendary Capture the Flag competitions, leaving top hackers sidelined while algorithms dominate the scoreboard. Hear why one seasoned researcher says the entire game is over for humans. As expected, UnFiOS devices are under attack. CIS…TWIT.TV
1 JunPress Release: CSO30 ASEAN & Hong Kong Awards 2026 open for nominations>The CSO30 ASEAN & Hong Kong Awards return in 2026, as an important moment to recognise the cybersecurity leaders and teams who are making resilience measurable across the region. In a landscape shaped by rapid threat evolution, board-level scrutiny and rising expectations of…CSOONLINE.COM
1 JunGoverning shadow AI without killing innovationIn this Help Net Security video, Alan Snyder, CEO at NowSecure, talks about governing shadow AI without stopping innovation. He frames the problem as two opposing forces. Companies need to adopt AI fast because attackers and competitors will outpace them otherwise, but they also …HELPNETSECURITY.COM
1 Jun145 AI laws passed in 2025 and privacy teams aren’t catching a break145 AI-related laws were enacted by state legislatures in 2025, and more than 1,000 additional bills were introduced or revised, according to DataGrail’s Privacy and AI Trends Report 2026. Average cost of manual data subject request management (Source: DataGrail) Shadow AI …HELPNETSECURITY.COM
1 JunOWASP Agent Memory Guard: Stop AI agents from being weaponized through their own memoryAI agents keep memory across sessions. Conversation history, vector stores, scratchpads, and RAG indexes persist between runs, and anything written into that store becomes a privileged input the agent reads back later. An attacker who plants text in the wrong field can override a…HELPNETSECURITY.COM
1 Jun6 critical security gaps every CISO must addressCISOs acknowledge that no organization is completely safe, but many also admit their security measures aren’t where they’d like them to be. One-third of CISOs surveyed for Proofpoint’s 2025 Voice of the CISO Report said the data within their organization is not adequately protect…CSOONLINE.COM
1 JunAsimily turns device risk into automated network policyAsimily has launched Segmentation Orchestration, enabling connected-device risk intelligence to flow directly into enforceable network policy without manual translation. No other platform combines full asset visibility, vulnerability prioritization, and segmentation orchestration…HELPNETSECURITY.COM
1 Jun KEVPalo Alto Warns High-Severity Bug Is Being Actively ExploitedA vulnerability in Palo Alto Networks’ PAN-OS software is being exploited in attacksINFOSECURITY-MAGAZINE.COM
1 JunNVIDIA goes open source with a big batch of physical AI agent toolsNVIDIA just dropped a big batch of open-source “physical AI” skills and tools, and they’re designed to make a roboticist’s life a whole lot easier. The idea? Take the messy, complicated work behind robots, self-driving cars, vision AI, and industrial digit…HELPNETSECURITY.COM
1 Jun KEVCritical WP Maps Pro Flaw Actively Exploited to Create Admin AccountsThreat actors are attempting to actively exploit a critical security flaw impacting WP Maps Pro, a WordPress plugin that has had over 15,000 sales on the Envato Market, to create malicious administrator accounts on susceptible sites. WP Maps Pro allows site owners to embed custom…THEHACKERNEWS.COM
1 JunHelping defense's use of AI catch up with offense, cost of the vulnpocalypse, news - ESW #461Interview with Evan Powell - Generative and agentic AI are improving cyberattacks faster than they're improving cyber defenses. Offensive folks have been having the most luck with AI so far, which is further eroding any advantage defenders might have had. Evan Powell joins us to …YOUTUBE.COM
1 JunTop 4 data security best practices for the AI-enabled enterpriseTo maximize AI’s value without increasing security risk, organizations must enforce best‑practice data protections across their environment.CYBERSECURITYDIVE.COM
1 JunDashlane hit by brute-force campaign triggering account suspensionsDashlane has confirmed that a brute-force attack over the weekend triggered a wave of account suspension emails, unusual login notifications, and authentication issues. The password manager says the incident was caused by attacks against individual accounts rather than a breach o…CYBERINSIDER.COM
1 JunOpenAI Codex Authentication Tokens Stolen in codexui-android npm Supply Chain AttackCybersecurity researchers have disclosed details of a new malicious supply chain campaign that's targeting developers using OpenAI Codex through a legitimate-looking remote web UI. The tool, named codexui-android, is advertised on GitHub and npm as a remote web UI for OpenAI Code…THEHACKERNEWS.COM
1 Jun19-Year-Old Linux Kernel Vulnerability Exposes Systems to Root Accessproof-of-concept (PoC) exploit code has been released for the CIFSwitch flaw, which allows low-privileged users to escalate to root on vulnerable Linux systems. The post 19-Year-Old Linux Kernel Vulnerability Exposes Systems to Root Access appeared first on SecurityWeek .SECURITYWEEK.COM
1 JunMicrosoft says it will not pursue security researchers after zero-day backlashMicrosoft said it is taking the feedback seriously, adding: “To be clear about our approach to legal matters, we have no intention to pursue action against individuals conducting or publishing their security research.”THERECORD.MEDIA
1 JunCritical Windows Netlogon RCE flaw now exploited in attacksThe Centre for Cybersecurity Belgium (CCB), the country's national authority for cybersecurity, warned on Friday that threat actors are now exploiting a recently patched critical Windows Netlogon vulnerability in attacks. [...]BLEEPINGCOMPUTER.COM
1 JunMicrosoft Defender Vulnerability Management gets a smarter exposure scoreMicrosoft Defender Vulnerability Management’s updated exposure score model adds vulnerability risk signals and asset context to help teams understand where risk is concentrated and which remediation actions are likely to have the greatest impact. The model is available in public …HELPNETSECURITY.COM
1 Jun KEVHorizon3.ai introduces Rapid Response to prioritize and verify vulnerability remediationHorizon3.ai has introduced Rapid Response, a capability that helps organizations assess exposure to newly disclosed threats, prioritize remediation, and verify that vulnerabilities have been addressed. Security teams are inundated with vulnerability disclosures, threat intelligen…HELPNETSECURITY.COM
1 JunMiasma: Supply Chain Attack Targeting RedHat npm PackagesDetect and mitigate malicious npm packages linked to the latest npm supply chain attack, based on the open sourced Mini Shai-Hulud malware.WIZ.IO
1 JunCritical Flowise Flaw Gives Attackers Full Server ControlObsidian publishes PoC for a 1-click Flowise RCE that can fully compromise self-hosted serversINFOSECURITY-MAGAZINE.COM
1 JunRace Against Time: Why Faster Vulnerability Alerts MatterAttackers are exploiting vulnerabilities faster than many organizations can identify and patch them. SecAlerts explains why faster vulnerability alerts can help reduce exposure and improve response times. [...]BLEEPINGCOMPUTER.COM
1 JunBrute-force attack triggers Dashlane account lockoutsPassword manager Dashlane has confirmed that a brute-force attack targeting user accounts triggered temporary account suspensions and authentication issues. The company first acknowledged the incident on May 31 after users reported receiving account suspension emails and experien…HELPNETSECURITY.COM
1 JunInsight bundles exposure management, patch operations, and XDR into one serviceInsight has launched Insight Managed Exposure Defense, a managed security service designed to help organizations identify and address vulnerabilities. The service aims to help organizations reduce exposure and implement protections without lengthy procurement processes or relianc…HELPNETSECURITY.COM
1 Jundepthfirst adds pre-install protection against malicious dependenciesdepthfirst has introduced Dependency Firewall, a product that reviews every open-source package being downloaded anywhere in a company and blocks the malicious ones before they reach the person or system that requested them. Developers, AI agents, and any employee using Claude, C…HELPNETSECURITY.COM
1 JunCato cuts vulnerability protection time to 45 minutes with agentic threat researchCato Networks announced a new capability that reduces time-to-protect for newly disclosed vulnerabilities to 45 minutes. The company attributes this reduction to the use of agentic threat research designed to accelerate protection against emerging exploits. Traditional appliance-…HELPNETSECURITY.COM
1 Jun⚡ Weekly Recap: New Linux Flaw, PAN-OS Exploit, AI-Powered Attacks, OAuth Phishing and MoreMonday hit like a cron job with anger issues. A busted auth path here, a repo-side faceplant there, some "patched-ish" thing already getting chewed on in the wild, and then the usual bonus round: poisoned dev tools, sketchy forum chatter, phishing kits pretending to be productivi…THEHACKERNEWS.COM
1 JunAI Is Reviving Anomaly DetectionSecurity teams are revisiting anomaly detection using architectures inspired by modern large language models. Instead of relying on static signatures or isolated events, these “log LLMs” analyze large behavioral sequences across high-volume telemetry sources such as DNS, WAF logs…YOUTUBE.COM
1 JunPatch Now: Another Palo Alto Auth Bypass Bug Under Active ExploitExploiting the PAN-OS GlobalProtect VPN vulnerability requires certain conditions, but adversaries have done so in two attack waves that started in mid-May.DARKREADING.COM
1 JunEliminate Critical API Attack Paths with Wiz API SPMWiz API SPM is now GA, enabling customers to discover APIs, assess APIs for exploitability, and prioritize remediation to mitigate the risk of an API-related breach.WIZ.IO
1 JunVulnerability Disclosure in the Age of AINew article: “ Responsible Disclosure in the Age of AI: A Call for Urgent Action ,” by Melissa Hathaway. Abstract: Artificial intelligence is fundamentally reshaping the balance between vulnerability discovery and remediation. Frontier AI models are now capable of aut…SCHNEIER.COM
1 JunCritical Netlogon flaw is under active exploitation.Military leaders debate battlefield AI. California sues 23andMe over 2023 data breach.THECYBERWIRE.COM
1 JunBrave’s new AgentStop system reduces wasted AI battery drain by 23%Brave has introduced AgentStop, a new open-source system designed to reduce the energy consumed by local AI agents running on consumer hardware. The technology monitors AI agent behavior in real time and can terminate tasks that are unlikely to succeed, helping conserve battery l…CYBERINSIDER.COM
1 JunHackers Used Meta’s AI Support Bot to Seize Instagram AccountsThe Instagram accounts for the Obama White House and the Chief Master Sergeant of the U.S. Space Force were briefly defaced with pro-Iranian images and messages over the weekend, after instructions began circulating on Telegram showing how to trick Meta's "AI support assistant" b…KREBSONSECURITY.COM
1 JunDashlane password manager users locked out by brute force attacksMultiple Dashlane users have been locked out of their accounts following brute-force attacks that attempted logins from distant locations and unknown devices. [...]BLEEPINGCOMPUTER.COM
1 JunMicrosoft's Zero-Day Legal Threats Spark BacklashAfter a disgruntled security researcher published several zero-day exploits in recent weeks, Microsoft seemingly indicated criminal charges were in order.DARKREADING.COM
31 MayWeek in review: Infostealer dropped via FortiClient EMS flaw, exploited Trend Micro Apex One flawHere’s an overview of some of last week’s most interesting news, articles, interviews and videos: Coinflow CISO on crypto payments security under AI pressure Crypto payment firms sit near the top of the target list for advanced persistent threat groups, and the workload on their …HELPNETSECURITY.COM
31 MayWP Maps Pro bug exploited to create admin accounts on WordPress sitesHackers are targeting WordPress websites running a vulnerable version of the WP Maps Pro plugin, which allows creating rogue administrator accounts without authentication. [...]BLEEPINGCOMPUTER.COM
30 MayLaw enforcement and industry disrupt criminal infrastructure.Researchers blame Iranian government for LA transit authority hack. Extortion group sends individuals to infiltrate organizations in person.THECYBERWIRE.COM
30 MayNew CIFSwitch Linux flaw gives root on multiple distributionsA newly discovered local privilege escalation vulnerability dubbed 'CIFSwitch' in the Linux kernel could allow attackers to forge CIFS authentication key descriptions, abuse the kernel's key request mechanism, and gain root privileges. [...]BLEEPINGCOMPUTER.COM
30 MayExploit Code Published for Critical Flowise RCE VulnerabilityThe one-click vulnerability allows attackers to execute arbitrary code on self-hosted Flowise servers by tricking users into importing a malicious chatflow. The post Exploit Code Published for Critical Flowise RCE Vulnerability appeared first on SecurityWeek .SECURITYWEEK.COM
29 MayLack of response to critical vulnerability in Gogs is a reminder of the limits of open source projectsA newly discovered and so far unpatched critical vulnerability in the open source Gogs Git service not only demands immediate action from developers to secure their code, it also puts a spotlight on the potential issues in using self-hosted code platforms from small maintainers. …CSOONLINE.COM
29 MayBuilding a risk-based vulnerability management program that scalesIn this Help Net Security video, Shankar Somasundaram, CEO at Asimily, explains how to build a risk-based vulnerability program. He notes that vulnerabilities are exploding by an order of magnitude in the age of AI-driven attacks, with one customer finding a thousand vulnerabilit…HELPNETSECURITY.COM
29 MayGDPR set the tone for regulatory action — and the AI fine pushback to comeBig tech firms continue to push back against fines levied for alleged violations of European data protection law, in what could be a harbinger for AI regulations to come. While lawyers and experts quizzed by CSO broadly argue that big tech firms contesting data protection rules i…CSOONLINE.COM
29 MayAnthropic launches Claude Opus 4.8, prepares Mythos-class models for all customersAnthropic has released Claude Opus 4.8 and outlined plans for broader access to its Mythos-class models, which the company expects to make available to all customers in the coming weeks. Claude Opus 4.8 (Source: Anthropic) Claude Opus 4.8 is available to all users, with pricing u…HELPNETSECURITY.COM
29 MayThe Gentlemen are coming for your files, and then your networkRansomware operators have spent years refining the art of locking files. Now, some are working harder to get those lockers to every reachable system first. Microsoft’s recent warning of the Gentlemen ransomware revealed its operators using a self-propagating Go-based encryptor ca…CSOONLINE.COM
29 MayChinese Hackers Exploit Iran War to Target Maritime and Energy CompaniesESET’s 2026 APT Activity Report suggests China-backed APTs are using instability in the region to target victims, as well as continuing activity against organizations around the globeINFOSECURITY-MAGAZINE.COM
29 MayCybersecurity trends in SEC filingsIn 2023, the Securities and Exchange Commission (SEC) required public companies to include a new section in their 10-K annual filings that is devoted to cybersecurity. This section is meant to address “cybersecurity risk management, strategy, governance and incidents.” I got curi…CSOONLINE.COM
29 May KEVChrome security update addresses 22 critical severity flawsGoogle has released a major Chrome security update that fixes 151 vulnerabilities in the browser, including 22 critical-severity flaws. While no actively exploited zero-days were disclosed, the unusually large number of vulnerabilities and the predominance of internally discovere…CYBERINSIDER.COM
29 MayChrome 148 Update Patches 151 VulnerabilitiesThe browser update resolves critical-severity security defects that could potentially lead to remote code execution. The post Chrome 148 Update Patches 151 Vulnerabilities appeared first on SecurityWeek .SECURITYWEEK.COM
29 MayLinkedIn-themed phishing abuses Adobe’s A/B testing platformA newly documented phishing campaign is targeting professionals with fake LinkedIn business emails and abusing a trusted service operated by Adobe. The attack from the victim’s perspective The attack starts with an email that looks, at first glance, like a routine business …HELPNETSECURITY.COM
29 MayGogs Zero-Day Exposes Servers to Remote Code ExecutionThe critical-severity issue, assigned a CVSS score of 9.4, is an argument injection flaw that can be exploited by authenticated attackers via pull requests with malicious branch names. The post Gogs Zero-Day Exposes Servers to Remote Code Execution appeared first on SecurityWeek …SECURITYWEEK.COM
29 MayWith Complex Cloud Integrations, Small Errors Lead to Major CompromisesResearchers discover an exploit chain combining over-permissioned roles, secrets discovery, and non-human identities that could have compromised a popular automation service.DARKREADING.COM
29 May'The Com' Cyberattacks Support Violence & SexploitationYour organization's security failures have consequences for everyone else too, since this neo-Nazi-infested criminal gang uses its cyber winnings to support more violent and widespread crimes.DARKREADING.COM
29 MayMicrosoft calls zero-day releases ‘never justifiable’ as researcher threatens to drop moreEach vulnerability was published with working proof-of-concept code to the Microsoft-owned code repository GitHub, making them immediately available to both attackers and security professionals.THERECORD.MEDIA
29 MayDutch police disrupts botnet composed of 17 million devicesThe Dutch National Police and the country’s National Cyber Security Center (NCSC) have taken offline 200 servers controlling a botnet of 17 million devices, the law enforcement agency announced on Thursday. The investigation was launched after the NCSC received a report by …HELPNETSECURITY.COM
29 MayCertifiably random: Swiss researchers claim perfect random number sourceResearchers in Switzerland claim to have built a perfect random number generator from two quantum superconducting chips, a 30-meter-long pipe, and some software. The resulting device could be used to generate cryptographic keys, or to offer a “public randomness service” for lotte…CSOONLINE.COM
29 MayChatGPhish Vulnerability Turns ChatGPT Web Summaries Into a Phishing SurfaceCybersecurity researchers have disclosed details of a vulnerability in OpenAI ChatGPT that leverages the artificial intelligence (AI) assistant's implicit trust in Markdown links and images to trigger prompt injections and open the door to phishing attacks. The technique has been…THEHACKERNEWS.COM
29 MayTennessee man linked to 764 accused of series of crimes against children dating back to 2022Zachary Sweeney allegedly traveled to New York, Indiana, Missouri and Georgia to meet and harm numerous victims in person. The FBI began investigating him in 2023. The post Tennessee man linked to 764 accused of series of crimes against children dating back to 2022 appeared first…CYBERSCOOP.COM
29 MayMind the gap between IT and OT.Iranian hackers hit LA transit. Chinese cyber operators target Middle East infrastructure. Dutch police take down a 17-million-device botnet. Researchers uncover a phishing risk in ChatGPT. Anthropic prepares its Mythos model for release. Chrome patches 22 critical bugs. Zapier f…THECYBERWIRE.COM
29 MayYour AI Doesn’t Understand AnythingLarge language models are statistical prediction systems trained to generate likely sequences of words based on massive datasets. They do not reason, understand context, or interpret meaning the same way humans do, even when their responses sound conversational or emotionally awa…YOUTUBE.COM
28 MayEmployees are unknowingly inviting tech support impersonators into firms, says FBIOnline or telephone IT support scams have been tricking employees into downloading or clicking on malware for years. But according to the FBI, one group that targets US-based law firms has recently found success in person, by convincing firms to allow a supposed IT support person…CSOONLINE.COM
28 MayGraduation day griftsThis week, hosts of N2K CyberWire Maria Varmazis and Dave Bittner alongside …THECYBERWIRE.COM
28 MayThe bipartisan case for CISA.This week, Dave and Ben sit down to discuss a growing bipartisan effort to support CISA. Throughout the conversation, the two look at how lawmakers from both sides of the aisle are showing greater support for CISA after the Trump administration cut its budget and workforce. Both …THECYBERWIRE.COM
28 MayCompanies built AI into core systems before figuring out how to govern it70% of organizations use GenAI in live environments, and 64% have AI agents in pilot or production deployments. Some of those agents have privileged access to core systems, according to Check Point’s 2026 Cloud Security Report. Confirmed and suspected AI incidents (Source: Check …HELPNETSECURITY.COM
28 MayCanonical releases Workshop for one-command sandboxed dev environments on UbuntuCanonical released Workshop, a tool that launches sandboxed development environments on Ubuntu with a single command. Environments are configured once and reproduced on different machines, giving teams consistent setups across development workstations and deployment pipelines. A …HELPNETSECURITY.COM
28 MayHottest cybersecurity open-source tools of the month: May 2026Presented here is a curated selection of noteworthy open-source cybersecurity solutions that have drawn recognition for their ability to enhance security postures across diverse settings. Pipelock: Open-source AI agent firewall AI coding agents run with shell access, environment …HELPNETSECURITY.COM
28 MayKemper - 269,299 breached accountsIn April 2026, the American insurance holding company Kemper Corporation was named by the ShinyHunters ransomware group in a "pay or leak" extortion campaign . The attackers allegedly accessed Kemper's Salesforce environment via social engineering as part of a broader campaign ta…HAVEIBEENPWNED.COM
28 MayKetch brings multi-agent AI orchestration to enterprise privacy programsKetch has unveiled its vision for agentic privacy with the Ketch Agent Network, a multi-agent orchestration layer for enterprise privacy programs. The platform is designed to continuously reason across legal obligations, internal policies, and operational realities within a unifi…HELPNETSECURITY.COM
28 MayWhat the industrialization of exploitation means for defendersFor decades, cybersecurity was a battle of skill. Elite attackers versus elite defenders. The rules of engagement were understood, even if the playing field wasn’t level. If you hired better analysts and bought better tools, hopefully you hardened your systems well enough and bui…CSOONLINE.COM
28 MayDownload pumping: New npm deception technique for supply chain attacksLearn how attackers exploit automated bot traffic as part of software supply chain attacks to artificially inflate download counters and mask malicious payloads as legitimate. Key takeaways Volume doesn’t equal trust. Packages with numerous versions and high download counts might…TENABLE.COM
28 MayMicrosoft’s new cloud PCs place AI agents under enterprise controlsMicrosoft’s Windows 365 for Agents, a cloud PC platform for agentic workloads, runs AI agents in secure environments. Organizations can direct agents with natural language to interact with applications, browsers, files, and enterprise systems. The platform is available in public …HELPNETSECURITY.COM
28 MayOil shipments, drone makers, and a poisoned code library targeted in recent APT campaignsGeopolitical pressure drove much of the state-sponsored cyber activity recorded between October 2025 and March 2026, according to ESET’s latest APT Activity Report. Espionage groups aligned with China, North Korea, Russia, and Iran adjusted their targets to match the econom…HELPNETSECURITY.COM
28 MayThe AI governance imperative you can’t afford to ignoreCIOs rushing to roll out AI agents without real visibility into their decision-making processes are flirting with disaster. According to AI experts, deploying agents without observability processes and tools creates a ticking time bomb with the potential for huge negative consequ…CSOONLINE.COM
28 MayDICOM, Pydicom, GDCM, and Orthanc: A technical tour of what really happens in the heapThis white paper presents a concrete case study demonstrating the creation of a heap overflow vulnerability through the exploitation of the DICOM file format.TALOSINTELLIGENCE.COM
28 MayMicrosoft Condemns "Uncoordinated" Zero Day DisclosuresMicrosoft warned the disclosure of several unpatched vulnerabilities without notice has put “customers at unnecessary risk”INFOSECURITY-MAGAZINE.COM
28 MayGitea Vulnerability Exposed 30,000 Deployments to AttacksThe security flaw allowed attackers to pull private container images, exposing source code, credentials, and infrastructure. The post Gitea Vulnerability Exposed 30,000 Deployments to Attacks appeared first on SecurityWeek .SECURITYWEEK.COM
28 May KEVCritical FortiClient EMS Vulnerability Exploited in Fresh AttacksFortinet rolled out hotfixes for the security defect in April, warning that it had been exploited in the wild as a zero-day and urging immediate patching. The post Critical FortiClient EMS Vulnerability Exploited in Fresh Attacks appeared first on SecurityWeek .SECURITYWEEK.COM
28 MayIBM and Red Hat Commit $5 Billion to Secure Open Source Supply Chains Under “Project Lightwell”Project Lightwell is designed to fix vulnerabilities without breaking what is already in production. The post IBM and Red Hat Commit $5 Billion to Secure Open Source Supply Chains Under “Project Lightwell” appeared first on SecurityWeek .SECURITYWEEK.COM
28 MayQumulo NeuralProtect uses AI to detect and stop ransomware before encryptionQumulo has unveiled Qumulo NeuralProtect, a ransomware resilience solution built to protect data at the storage layer by detecting and stopping threats before data is encrypted, corrupted, or lost. Integrated directly into the Qumulo Data Platform, NeuralProtect inspects every fi…HELPNETSECURITY.COM
28 MayQevlar’s new AI agents correlate CVEs, incident data, and active exploitation signalsQevlar has announced a new set of AI agents designed to bridge the disconnect between Security Operations Centers (SOCs) and vulnerability management teams. The new capabilities help security teams correlate CVEs with live incident data for real-time risk prioritization, automati…HELPNETSECURITY.COM
28 MayMicrosoft Slams Public Zero-Day Disclosures Amid GitHub Researcher Account RemovalMicrosoft has come out strongly in favor of Coordinated Vulnerability Disclosure (CVD), urging the research community to share their findings and give affected vendors an opportunity to better understand the impact and address them before they are publicly disclosed. The developm…THEHACKERNEWS.COM
28 May KEVIndian CERT urges firms to contain exploited internet-facing flaws within 12 hoursIndia’s cybersecurity agency, CERT-In, has urged organizations to patch, mitigate, or isolate known exploited vulnerabilities affecting internet-facing “crown jewel” systems within 12 hours where feasible, warning that AI-assisted attacks are dramatically compressing the time bet…CSOONLINE.COM
28 MayCanadian man gets 33 years for using social media to coerce US children into sending sexual contentProsecutors said the man spent years using fake online identities to contact children and manipulate them into sending sexually explicit images and videos.THERECORD.MEDIA
28 MayDuckDuckGo sees 30% growth spike as Google forces AI on SearchDuckDuckGo says it experienced a significant spike in users following Google’s announcement of a sweeping AI-powered overhaul of Search at Google I/O 2026. According to figures shared by the privacy-focused search company, installs and visits increased sharply in the six days aft…CYBERINSIDER.COM
28 MayZapier exploit chain shows how known anti-patterns compose into critical riskA five-stage exploit chain disclosed by Token Security researchers turned a free Zapier account into write access on Zapier’s public developer SDK packages and on internal packages that load in every authenticated zapier.com session. Each link in the chain was a known anti-…HELPNETSECURITY.COM
28 MayNew Gogs zero-day flaw lets hackers get remote code executionAn unpatched zero-day vulnerability in the Gogs self-hosted Git service can allow attackers to gain remote code execution (RCE) on Internet-facing instances. [...]BLEEPINGCOMPUTER.COM
28 MayIBM and Red Hat are betting $5 billion that open source needs a security guardIBM and Red Hat announced Project Lightwell, a $5 billion commitment backed by new frontier AI capabilities and a global force of more than 20,000 engineers to help enterprises secure open source software. Together, these investments establish a new model for enterprise use of op…HELPNETSECURITY.COM
28 MayState of Post Quantum CryptographyDiscussion of PQC relevant statistics that we see across our customers and other data sources.WIZ.IO
28 MayIBM’s new $5B initiative will help enterprises rapidly patch open-source vulnerabilitiesThe tech giant’s project could make it easier for businesses to safely use open-source packages.CYBERSECURITYDIVE.COM
28 MayAttackers Move Past Typosquatting to Realistic Package ImpersonationMost malicious open source packages now mimic real code rather than rely on typosquattingINFOSECURITY-MAGAZINE.COM
28 MayThreat Actors Exploit Critical FortiClient EMS Flaw to Deploy Credential StealerThreat actors are continuing to exploit a critical, now-patched security flaw impacting FortiClient Endpoint Management Server (EMS) deployments to deliver credential-stealing malware. "The campaign abused trusted endpoint management infrastructure to deliver malware across manag…THEHACKERNEWS.COM
28 MayCritical Gogs RCE Vulnerability Lets Any Authenticated User Execute Arbitrary CodeA critical security vulnerability has been disclosed in Gogs, a popular open-source self-hosted Git service, that allows an authenticated user to execute arbitrary code under certain conditions. The security flaw, per Rapid7, is rated 9.4 on the CVSS scoring system. It does not h…THEHACKERNEWS.COM
28 MayDutch Raid Fails to Dent Russian Bulletproof HostDutch law enforcement seized 800 servers and arrested two operators of THE.Hosting but left the hosting provider's core IP address space intact.DARKREADING.COM
28 MayThe military wants to move at cyber speed.Cyber Command’s new chief pushes modernization as lawmakers warn commercial location data is exposing U.S. troops. A third-party UK visa site leaks passports and selfies. Microsoft slams unpatched zero-day disclosures. Researchers uncover a new macOS malware campaign targeting cr…THECYBERWIRE.COM
28 MayLinux Supply Chain How-To - PSW #928This week we have a technical segment focused on Linux! Paul released a script that helps you get a handle on Linux supply chain security, and new features allow you to assess the state of Secure Boot on your Linux systems (that also use MS certificates, ironically). The script i…YOUTUBE.COM
28 MayMITRE Couldn’t Scale Caldera AloneMITRE is transferring the Caldera cybersecurity platform to the Apache Foundation to encourage broader open source collaboration and long-term project support. Caldera is widely used for testing systems against the MITRE ATT&CK framework and simulating adversary behavior acro…YOUTUBE.COM
28 MayBreaking the Patch Sound Barrier Part 2: So Is The Apocalypse Coming and What Is It?So, you read my previous blog post about breaking the patch sound barrier , but it left you wanting more? Well, this is that “more.” Gemini blog illustration / steampunk vuln apoc Here are three useful ideas to advance the conversation. 1. Defining the “Vulnerability Apocalypse” …MEDIUM.COM
28 MayOracle May 2026 Critical Security Patch Update Addresses 35 CVEsOracle addresses 35 CVEs in its May 2026 Critical Security Patch Update with 35 patches, including 11 critical updates. Key Takeaways The May 2026 Critical Security Patch Update (CSPU) contains fixes for 35 unique CVEs in 35 security updates 11 issues (31.4% of all patches) were …TENABLE.COM
27 MayMicrosoft previews automatic device isolation in Defender for EndpointMicrosoft is previewing a new automatic device isolation capability in Defender for Endpoint’s auto attack disruption tool to help security pros contain cyber attacks in progress on their IT networks. The company announced the capability earlier this month in a column about new f…CSOONLINE.COM
27 MayEuropean AI adoption hits 99% with regulated data driving most policy violationsGenerative AI tools operate inside nearly every European workplace, embedded in meeting transcription services, writing assistants, coding copilots, and search features. Workers in the region pull these tools into daily routines that involve customer records, financial informatio…HELPNETSECURITY.COM
27 May KEVRisky Business #839 -- TeamPCP stole GitHub's internal reposOn this week’s show Patrick Gray, Adam Boileau and James Wilson discuss the week’s cybersecurity news. They cover: TeamPCP breached GitHub’s internal repos. Now what? Some absolute plonker glued Coruna to a hijacked npm package CISA is worried about about open source and wants th…RISKY.BIZ
27 MayVigolium: Open-source vulnerability scannerVigolium, an open-source vulnerability scanner that combines deterministic scanning with AI-driven auditing, launched its initial open-source release this month. The project ships 235+ scanner modules and an in-process agent runtime called olium that handles autonomous endpoint d…HELPNETSECURITY.COM
27 MayMytheresa - 84,108 breached accountsIn April 2026, the luxury fashion e-commerce platform Mytheresa was listed as a victim of the ShinyHunters "pay or leak" extortion group . After the ransom deadline passed, the group publicly released the data which contained 84k unique email addresses. The exposed data also incl…HAVEIBEENPWNED.COM
27 May KEVCISA Urges Immediate Patching of Exploited LiteSpeed cPanel Plugin Zero-DayResolved last week, the vulnerability was exploited in the wild as a zero-day to execute scripts with root privileges. The post CISA Urges Immediate Patching of Exploited LiteSpeed cPanel Plugin Zero-Day appeared first on SecurityWeek .SECURITYWEEK.COM
27 MayNovee’s Agentic Fix turns validated exploits into fixes through AI coding agentsNovee has announced Agentic Fix, an enhancement to its AI penetration testing platform that helps teams move from validating security findings to deploying fixes in a single step. Agentic Fix extends Novee’s platform by generating remediation guidance from the same exploit contex…HELPNETSECURITY.COM
27 MayJetico expands BestCrypt Data Shelter with zero-trust file access controlsJetico has announced the extension of BestCrypt Data Shelter to include centrally managed enterprise data access control for sensitive files. The solution allows security teams to define and enforce policies governing which applications, processes and users can access protected f…HELPNETSECURITY.COM
27 MayProofpoint Introduces Active Exploits Protection to Help Organizations Prioritize Vulnerability Patching for Real-World Attacks in the AI EraPROOFPOINT.COM
27 May KEVCISA gives feds 4 days to patch actively exploited cPanel plugin flawThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) has given U.S. federal agencies four days to secure their servers against a critical vulnerability in the LiteSpeed cPanel user-end plugin, which is actively being exploited in attacks. [...]BLEEPINGCOMPUTER.COM
27 MayFake ChatGPT and Claude installers on GitHub are dropping Deno RAT malwareAttackers are hosting counterfeit installers and plugins on GitHub and SourceForge that pose as widely used software, including ChatGPT, Claude, AutoTune, Kontakt, Ableton Live, and ZENOLOGY. The downloads deliver a backdoor called DinDoor, which then loads a remote access Trojan…HELPNETSECURITY.COM
27 MayApple makes its quantum-resistant encryption open sourceApple has published its post-quantum cryptography implementations in corecrypto, together with mathematical proofs and verification tools for independent expert evaluation, allowing external researchers to review the work and reproduce the company’s analysis. Post-quantum cryptog…HELPNETSECURITY.COM
27 MayDutch police arrest man over cyber breach at Ajax football clubThe suspect was detained in the central Dutch town of Buren, where law enforcement officers also searched his home and seized multiple digital storage devices, according to a statement released Tuesday by the Dutch National Police.THERECORD.MEDIA
27 MayCrowdStrike disrupts Glassworm botnet that preyed on open-source supply chainCrowdStrike has dismantled the Glassworm botnet in an operation aided by Google and Shadowserver, stripping the operators’ access to infrastructure that helped threat actors infect hundreds of pieces of open-source software with malware since early 2025, the company said Tuesday.…CYBERSCOOP.COM
27 MayInfosecurity Europe: Why Burnout in Cybersecurity Demands Risk-Based ResponseCybermindz warns that cybersecurity burnout is a growing risk, urging organizations to move beyond wellness initiatives and adopt a measurable, risk-based approach to workforce stressINFOSECURITY-MAGAZINE.COM
27 MayCogent targets exploit-to-remediation gap with new AI-powered security capabilitiesCogent has launched two new platform capabilities designed to reduce the time between vulnerability disclosure and confirmed remediation. Zero Day Response identifies exposure within minutes of public disclosure, without waiting for scanner signatures. Autonomous Remediation dete…HELPNETSECURITY.COM
27 MayMediaArea heap-based buffer overflow vulnerabilitiesTalos researchers find 4 heap-based buffer overflow vulnerabilities in MediaArea's MediaInfoLib.TALOSINTELLIGENCE.COM
27 MayCan you enforce strong Active Directory password rules without frustrating users?Strong Active Directory passwords don't have to come at the expense of usability. Specops Software explains how passphrases, breached password protection, and self-service resets can improve security without frustrating users. [...]BLEEPINGCOMPUTER.COM
27 MayVulnerability in Popular Conference Software Granted Attackers a 100% Talk Acceptance RateNovee researchers discovered an account takeover vulnerability in the open source CFP management tool Pretalx. The post Vulnerability in Popular Conference Software Granted Attackers a 100% Talk Acceptance Rate appeared first on SecurityWeek .SECURITYWEEK.COM
27 MayGoogle AI Threat Defense targets attackers using AI to find flaws fasterGoogle Cloud introduced AI Threat Defense, an automated cybersecurity platform that combines several of the company’s security assets to find, prioritize, and patch software vulnerabilities at machine speed. The product is aimed at enterprises contending with attackers who …HELPNETSECURITY.COM
27 MayCoordinated operation takes down Glassworm botnetThe botnet began in early 2025, targeting software developers across the open-source supply chain.CYBERSECURITYDIVE.COM
27 MayCrowdStrike and Google take down botnet used by hackers to target software developers in supply chain attacksCybercriminals used the Glassworm botnet to infect open source software projects with malware, and in turn hack the developers and companies that use that software.TECHCRUNCH.COM
27 MayAI-Assisted Exploit Development Outpaces Scanner DetectionAttackers are using AI to dramatically reduce the time they need to develop a working exploit for a CVE, according to new research.DARKREADING.COM
27 MayOpen Source Trust Is CollapsingDoug White talks about manually vetting software downloads from GitHub, NPM, and PyPI before allowing them onto a normal machine. That process included sandboxing the code in a Linux VM, reviewing it manually, and even using multiple AI models to inspect the files before installa…YOUTUBE.COM
27 MayGlassworm botnet targeting developers disrupted in coordinated takedownA coordinated cybersecurity operation has disrupted a botnet known as “Glassworm” that targeted software developers through malicious open-source packages, compromised GitHub repositories, and infected development tools. The takedown took place on May 26 with support from CrowdSt…CYBERINSIDER.COM
27 MayUK Cyberspying Chief Calls AI ‘an Unstoppable Force’ and Warns About RussiaThe speech is the latest in a string of warnings from intelligence experts that Russia is stepping up hostile activity in a “gray zone” that falls just below the threshold of war. The post UK Cyberspying Chief Calls AI ‘an Unstoppable Force’ and Warns About Russia appeared first …SECURITYWEEK.COM
27 MayAI chatbot recommendations lure users to cryptojacking malware sitesCybercriminals are using AI chatbot interactions alongside poisoned search results to direct users to malicious download sites in an active cryptojacking campaign, Microsoft has warned. The campaign impersonates legitimate software tools such as CrystalDiskInfo, HWMonitor, Displa…HELPNETSECURITY.COM
27 MayUK spy chief labels AI ‘unstoppable force’ with offensive, defensive ramifications for cyberspaceAnne Keast-Butler, head of the GCHQ, said her agency was developing an artificial intelligence-powered cyber shield as other nations were deploying AI in warfare. The post UK spy chief labels AI ‘unstoppable force’ with offensive, defensive ramifications for cyberspace appeared f…CYBERSCOOP.COM
27 MayReconstructing an Akira Ransomware Kill Chain from Perimeter and Endpoint Logs, (Wed, May 27th)Most Akira write-ups focus on the ransom note or the encryption routine. By the time those show up the interesting forensic work is over. The questions that matter to defenders sit earlier. How did they get in. When did they get domain admin. What did they touch before the binary…ISC.SANS.EDU
27 MayAI models more vulnerable than claimed when faced with iterative attacksCISOs relying on LLM runtime guardrails and official safety scores when making security decisions about their organizations’ AI usage and model selection are due for a wakeup call. According to a new study from Cisco, frontier models from OpenAI, Anthropic, Google, xAI, and Amazo…CSOONLINE.COM
27 MaySmashing Security podcast #469: What your Oura ring won’t tell youCISA, the US government agency whose entire job is keeping America's critical infrastructure safe from hackers, has had a contractor publish dozens of plain-text credentials to a public GitHub profile. Meanwhile, your Oura ring is quietly transmitting some of its data unencrypted…GRAHAMCLULEY.COM
27 MayAnother IT governance headache: AI-enabled sanction evasionOver the next three to five years, both governments and the private sector will need to rapidly adapt identification and mitigation protocols as adversaries move from AI-assisted to AI-enabled sanctions evasion and proliferation financing (PF), a new research paper warns. The rep…CSOONLINE.COM
26 MayProject Glasswing has uncovered 10,000 vulnerabilities: AnthropicAnthropic says it and upwards of 50 partners involved in Project Glasswing have uncovered an estimated 10,000 critical or high-severity vulnerabilities in their software offerings. The company launched the cybersecurity initiative, which is built around Claude Mythos Preview , in…CSOONLINE.COM
26 MaySecurity experts caution MFA alone can no longer stop threat actorsCybersecurity experts are warning enterprise admins about an increasing number of phishing campaigns aimed at stealing Microsoft 365 (M365) access tokens to bypass multifactor authentication login protection. Phishing kits aimed at capturing M365 tokens aren’t new; some reports s…CSOONLINE.COM
26 MayCybersecurity jobs available right now: May 26, 2026Application Security Engineer IG Group | India | Hybrid – View job details As an Application Security Engineer, you will assess the security of web, mobile, and cloud applications through penetration testing, secure code reviews, threat modeling, and architecture …HELPNETSECURITY.COM
26 May KEVCISA orders feds to patch actively exploited Drupal vulnerabilityCISA has given U.S. government agencies until Wednesday evening to secure their servers against an SQL injection vulnerability in the Drupal content management system (CMS) that it flagged as actively exploited. [...]BLEEPINGCOMPUTER.COM
26 MayCERT-In Mandates 12-Hour Patching for Internet-Facing Flaws Amid AI-Assisted AttacksThe Indian Computer Emergency Response Team (CERT-In) has issued new guidelines requiring organizations to patch critical security vulnerabilities in internet-exposed systems within 12 hours of being flagged where "feasible" to safeguard against potential threats stemming from th…THEHACKERNEWS.COM
26 MayStop treating AI governance as a review layer. Make it release infrastructureI’ve spent years building compliance into security products. FedRAMP and Department of War Impact Level authorizations, vulnerability management pipelines: They all follow the same pattern. Build the product, then prove it meets requirements. The compliance layer sits outside the…CSOONLINE.COM
26 MayAppSec Conversations on Agents, LLMs, and OWASP from RSAC - ASW #384We showcase recordings from this year's RSAC. At RSAC Conference 2026, Scott Clinton, Co-Chair and co-founder of the OWASP GenAI Security Project, shares insights from the project’s latest research, including new landscape guides and evolving approaches to securing generative and…YOUTUBE.COM
26 MayUS Law Enforcement Warns of ‘Anti-Tech Extremism’ as AI Hatred GrowsAs Americans stew over the looming risk of job-stealing AI and data centers in their back yards, the feds are raising the alarm about a new category of threat, documents obtained by WIRED show.WIRED.COM
26 MayWhat happens when security teams inherit identityAt the Span Cyber Security Arena conference, I sat down with Eric Woodruff, Chief Identity Architect at Semperis, to talk about how organizations perceive identity and the challenges those perceptions create for security. He shared his perspective on where organizations struggle …HELPNETSECURITY.COM
26 MayIndia's CERT-In Sets 12-Hour Patch Deadline for Exposed FlawsCERT-In urges 12-hour patching of exposed flaws as AI compresses exploitation timelinesINFOSECURITY-MAGAZINE.COM
26 MayAI Threat Landscape Digest March-April 2026Executive Summary During the March–April 2026 reporting period, AI use in offensive operations advanced from development and planning to real-time operational deployment. Multiple independent cases, involving individual criminal actors, mass exploitation platforms, ransomware gro…RESEARCH.CHECKPOINT.COM
26 MayOpen Source DockSec Uses AI to Cut Through Vulnerability Noise in Docker ImagesDockSec, an OWASP incubator project, correlates findings from multiple container security scanners and uses AI to generate plain-English remediation guidance and exact Dockerfile fixes. The post Open Source DockSec Uses AI to Cut Through Vulnerability Noise in Docker Images appea…SECURITYWEEK.COM
26 MayMFA Prompt Bombing: Why Your Second Factor Isn't Saving YouMulti-factor authentication (MFA) was supposed to close a critical gap in identity security. It meant that, even if an attacker possessed the account credentials, they couldn't log in without the second factor. While that logic was sound, attackers have now figured out that they …THEHACKERNEWS.COM
26 MayTrapDoor malware campaign puts developer workstations in CISO spotlightA malicious package campaign across npm, PyPI, and Crates.io has put developer workstations back under scrutiny, after researchers said it targeted developer workflows and AI coding assistant files. Researchers at Socket said the campaign, which they are tracking as TrapDoor, “sp…CSOONLINE.COM
26 MayHackers Exploited KnowledgeDeliver Zero-Day for Web Shell DeploymentHardcoded machineKey values in a configuration file enabled ViewState deserialization attacks leading to remote code execution. The post Hackers Exploited KnowledgeDeliver Zero-Day for Web Shell Deployment appeared first on SecurityWeek .SECURITYWEEK.COM
26 MayTamnoon introduces skill-based AI orchestration for autonomous cloud defenseTamnoon has expanded its AI engine, Tami, into a skill-based orchestrator that generates customer-specific remediation skills tailored to each enterprise environment. Trained on more than 6 million real cloud fixes across 800+ accounts, Tami coordinates specialized AI skills to s…HELPNETSECURITY.COM
26 MayFake software on GitHub and SourceForge distribute Deno RATWe found fake installers and plugins for ChatGPT, Claude, AutoTune, and other popular software that can give attackers full control over your device.MALWAREBYTES.COM
26 MayHow Security Leaders Cut Through Complexity to Drive Better OutcomesSecurity leaders are operating in an environment that is only getting more complex. Expanding attack surfaces, rapid AI adoption, growing toolsets, and increasing pressure to respond faster have made it harder to maintain a clear view of risk and priorities. At the Rapid7 Global …RAPID7.COM
26 MayGitHub Actions abused by Megalodon attack to slip malicious commits into 5,500 reposA large-scale automated GitHub backdooring campaign was caught pushing thousands of malicious commits into public repositories while posing as routine CI/CD upkeep. Researchers at SafeDep observed the campaign, Megalodon, touching more than five thousand repositories over a six-h…CSOONLINE.COM
26 MayEXPOSURE 2026 prepares cybersecurity professionals for the AI eraCybersecurity leaders and practitioners brought their burning AI cybersecurity questions to EXPOSURE 2026. They left with clear answers and a blueprint for building an exposure management program. Get a recap and see highlights from the event in words and pictures. Key take…TENABLE.COM
26 MayChinese Threat Actors Ditch Static Phishing Pages for Live Credential InterceptionAlmost all organizations impersonated by Chinese phishing platforms are non-Chinese entities, suggesting operators deliberately avoid domestic targetsINFOSECURITY-MAGAZINE.COM
26 MayAnthropic: Claude Mythos identified 10,000+ software flawsAnthropic and its Project Glasswing partners have identified more than 10,000 high- or critical-severity vulnerabilities in critical software systems, the company announced in an update on the project’s progress. Mythos identifies thousands of high-severity vulnerabilities …HELPNETSECURITY.COM
26 MayChinese phishing gangs grow into a force to be reckoned withChinese-language phishing-as-a-service (PhaaS) communities are expanding in an area historically dominated by Russian-speaking cybercriminal groups. The Google Threat Intelligence Group (GTIG) analyzed a dozen active PhaaS offerings operating in Chinese-language underground commu…HELPNETSECURITY.COM
26 MayDetectify brings AppSec automation to AI agents with MCP Server and continuous testingDetectify has unveiled the Detectify MCP (Model Context Protocol) Server, a new integration layer that brings Detectify’s security testing engines directly into AI-driven development workflows, helping coding agents find and validate exploitable vulnerabilities and interpret atta…HELPNETSECURITY.COM
26 May7-Eleven data breach exposes personal information of 185,000 applicantsConvenience store giant 7-Eleven is notifying more than 185,000 individuals that their personal information was exposed in a cybersecurity incident linked to the ShinyHunters extortion group. The company disclosed the breach in filings with multiple US state attorneys general, st…CYBERINSIDER.COM
26 MayNew phishing kit targets Microsoft 365 accounts.Anthropic says Mythos has found over 23,000 flaws in open-source software. Dutch police arrest two alleged bulletproof hosting admins.THECYBERWIRE.COM
26 MayWell-architected best practices for software supply chain securityThere have been multiple notable supply chain attacks using the npm Registry since September: Shai-Hulud, Chalk/Debug, one abusing tea.xyz tokens, and recently axios. Thanks to community efforts involving the Amazon Inspector team, the Open Source Security Foundation, and others,…AWS.AMAZON.COM
26 MayWelcoming the AWS Customer Incident Response TeamMay 26, 2026: This post was originally published in July 2022. It has been updated to reflect current engagement options, new threat intelligence resources such as the Threat Technique Catalog for AWS (TTC), additional open-source tools, and the distinction between AWS CIRT suppo…AWS.AMAZON.COM
26 MayApple open-sources quantum-resistant encryption codeThe release includes implementations of two quantum-secure algorithms and demonstrates how formal verification caught bugs that traditional testing would have missed. The post Apple open-sources quantum-resistant encryption code appeared first on CyberScoop .CYBERSCOOP.COM
26 MayThe Hackers Behind Shai-Hulud: Lucky or Skilled?TeamPCP, the hackers behind the Shai-Hulud worm, has done significant damage to the open source ecosystem. But it's not necessarily due to skill alone.DARKREADING.COM
26 MayAttackers found a new way around MFA.The FBI warns attackers are abusing Microsoft OAuth authentication. India pushes faster patching as AI speeds up cyberattacks. Iranian hackers blend phishing with SEO poisoning. Anthropic’s AI finds thousands of open source flaws, while AI also reshapes bug bounties and fuels sup…THECYBERWIRE.COM
26 MayFake GTA 6 pre-orders and beta scams spread malware ahead of game launchCybercriminals are exploiting excitement around Grand Theft Auto 6 to spread malware, phishing pages, and fake pre-order scams ahead of the game’s official release, according to new research from NordVPN. Researchers at NordVPN’s Threat Protection team said they identified dozens…CYBERINSIDER.COM
26 MayKnowledgeDeliver flaw exploited as a zero-day to install web shellsHackers exploited a critical zero-day vulnerability in a server running the KnowledgeDeliver learning management system (LMS) to deploy the Godzilla web shell. [...]BLEEPINGCOMPUTER.COM
26 MayAI Isn’t Creating Better HackersAaran describes a wartime-style cyber environment where experienced developers and reviewers may be unavailable, overwhelmed, or gone entirely. In that situation, junior operators end up shipping malware and attack variants rapidly using public resources, copied code, and LLM ass…YOUTUBE.COM
26 MayAmeriprise - 502,597 breached accountsIn March 2026, the financial services firm Ameriprise Financial was named by the ShinyHunters group in a "pay or leak" extortion campaign . The group claimed possession of more than 200GB of compressed data exfiltrated from Ameriprise's Salesforce environment and internal SharePo…HAVEIBEENPWNED.COM
26 MaySN 1080: Vulnerability Debt Repayment - Will Mythos Change Cybersecurity Forever?Mozilla found 271 unknown Firefox vulnerabilities in days using AI—bugs that millions of automated test runs had missed for years. Steve Gibson argues this isn't a crisis. It's the industry finally paying down decades of security debt, and for the first time, defenders may have t…TWIT.TV
25 MayTurns out the C-suite loves shadow AISenior decision-makers are the heaviest users of unapproved AI tools, and they continue using them despite being aware of the security and privacy risks linked to shadow AI, according to TrustedTech’s Shadow AI in the Workplace report. The study found that 65% of decision-makers …HELPNETSECURITY.COM
25 May2 PhaaS 2 Furious: The Evolution of Chinese-language Phishing ServicesWritten by: Jamie Collier While Russian-speaking threat actors have historically dominated the phishing-as-a-service (PhaaS) landscape, a rival ecosystem is rapidly growing within the Chinese-language underground. Google Threat Intelligence Group (GTIG) analyzed a dozen current P…CLOUD.GOOGLE.COM
25 MayOpenHack: Open-source AI-powered vulnerability researchSource-guided vulnerability research increasingly leans on coding harnesses such as Claude Code, Codex, and Cursor to drive agent-based reviews of application code. A new MIT-licensed project from the Dutch security firm Hadrian, called OpenHack, packages that approach into a fil…HELPNETSECURITY.COM
25 MayTo pay, or not to pay: 58% of CISOs say they would pay the ransom for their dataIf you were hit by ransomware tomorrow, would you pay to get your data back? That’s what more than half of CISOs in a recent survey said their organization would do. It’s a situation more companies are going to face in future. “Attacks are increasing and continuing to increase,” …CSOONLINE.COM
25 MayVisibility with EDR/MDR is still important, 'the basics' are impossible, and the news - ESW #460Interview with Rob Allen from Threatlocker This week, Rob Allen from Threatlocker is with us to discuss the importance of EDR and MDR visibility. We discuss some real world attacks and anecdotes where EDR was able to save the day when threats were missed by other controls. Topic:…YOUTUBE.COM
25 MayFake Streams, Counterfeit Merch and Other Scams: How Fraudsters Target F1 FansFrom fake F1 streams to counterfeit merch, fraudsters are exploiting fans online and the Bitdefender Cybersecurity Grand Prix Fan Threat Index details howINFOSECURITY-MAGAZINE.COM
25 MayThe AI Era Is Creating a Bug Hunting Arms RaceAs attackers ramp up their AI exploit development, the search for software vulnerabilities is changing rapidly.WIRED.COM
25 MayUS states step up cyber defenses to protect local communitiesU.S. state governments are taking on a larger role in cybersecurity to help protect local communities and essential services. Many states are building state-led cyber defense programs, including cybersecurity clinics, regional security operations centers (RSOCs), and state cyber …HELPNETSECURITY.COM
25 MayAI security needs a shift from models to systems, researchers argueEnterprises cannot secure AI agents by making the underlying models more robust and must instead enforce security controls at the system level around them, researchers behind a paper published this month argued, warning that traditional AI-security approaches are increasingly mis…CSOONLINE.COM
25 MayTeamPCP Supply Chain Campaign: Activity Through 2026-05-24, (Mon, May 25th)TeamPCP now operates across three package ecosystems in parallel, it reached GitHub&#;x26;#;39;s own internal codebase, it trojanized an officially Microsoft-published Python SDK, and it appears to have open-sourced its own framework on GitHub.
ISC.SANS.EDU
25 MayTeamPCP Supply Chain Campaign: Activity Through 2026-05-24, (Mon, May 25th)TeamPCP now operates across three package ecosystems in parallel, it reached GitHub&#;x26;#;39;s own internal codebase, it trojanized an officially Microsoft-published Python SDK, and it appears to have open-sourced its own framework on GitHub.
ISC.SANS.EDU
25 MayGhost CMS Vulnerability Exploited to Hack Over 700 WebsitesSites belonging to major universities such as Harvard and Oxford, as well as DuckDuckGo, have been compromised in the attack. The post Ghost CMS Vulnerability Exploited to Hack Over 700 Websites appeared first on SecurityWeek .SECURITYWEEK.COM
25 MayAuthorities seize 800 servers used for cyberattacks and disinformationDutch authorities arrested two men and seized 800 servers linked to a hosting provider that investigators say supported Russian activities aimed at undermining democracy and security through cyberattacks, disinformation, and disruption of public and economic systems. Servers seiz…HELPNETSECURITY.COM
25 May⚡ Weekly Recap: Linux Flaws, Defender 0-Days, Router Botnets, and Supply Chain ChaosMonday recap. Same mess, new week. A sketchy dev tool got people pwned, old bugs came back from the dead, and security products somehow needed protecting from themselves. A bunch of companies spent the week checking old boxes and forgotten servers they should've patched years ago…THEHACKERNEWS.COM
25 May25th May – Threat Intelligence ReportFor the latest discoveries in cyber research for the week of 25th May, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES 7-Eleven, the global convenience store chain, confirmed a breach after an unauthorized access to systems used for franchisee documents…RESEARCH.CHECKPOINT.COM
25 MayCisco refines its risk-based vulnerability disclosure for the AI eraSecurity teams already struggle with long lists of vulnerabilities and limited time to patch them. Cisco believes AI could increase that pressure by accelerating vulnerability discovery and increasing the number of findings security teams need to review. The company said it is mo…HELPNETSECURITY.COM
25 MayWhen Firewalls Become LiabilityCyber insurance providers are increasingly publishing reports explaining how ransomware attacks actually happened. In this clip, the discussion centers on Akira ransomware repeatedly targeting SonicWall firewalls — especially older or poorly maintained systems. One joke in the co…YOUTUBE.COM
24 MayThe current state of GPS following OCX with Dr. Sean Gorman, CEO of Zephr.xyz.Despite being an indispensable technology, traditional GPS remains vulnerable to exploitation and is needed for an update. In this week's episode, host Maria Varmazis sits down with Dr. Sean Gorman, CEO of Zephr.xyz, to discuss the current state of GPS. For decades, GPS has b…THECYBERWIRE.COM
24 MayWeek in review: GitHub breached via poisoned VS Code extension, critical NGINX flaw exploitedHere’s an overview of some of last week’s most interesting news, articles, interviews and videos: TeamPCP breached GitHub’s internal codebase via poisoned VS Code extension Following TeamPCP’s claim that they’ve breached GitHub’s own private code repositories, the Microsoft-owned…HELPNETSECURITY.COM
24 MayWireshark 4.6.6 Released, (Sun, May 24th)Wireshark release 4.6.6 fixes 1 vulnerability and 11 bugs.
ISC.SANS.EDU
23 MayGoogle leaks details for Chromium bug that can turn browsers into botsChromium — the open-source browser that underpins Google Chrome, Microsoft Edge, and Opera, among others — contains an unpatched vulnerability that attackers can exploit to execute JavaScript code persistently across browser restarts. As a result, the flaw can be used to hijack u…CSOONLINE.COM
23 MayGhosted by GrafanaToday we are joined by Sasi Levi, Security Research Lead at Noma Security, sharing their team's work on "GrafanaGhost: The Phantom Stealing Your Data." Researchers at Noma Security disclosed “GrafanaGhost,” a vulnerability that could allow attackers to silently exfiltrate sen…THECYBERWIRE.COM
23 MayGitHub discloses breach of 3,800 internal code repositories.CISA contractor exposed AWS GovCloud keys on GitHub. Researchers craft a kernel exploit on Apple's M5 chips, with help from Mythos.THECYBERWIRE.COM
23 MayThe FBI Wants ‘Near Real-Time’ Access to US License Plate ReadersPlus: Google publishes a live exploit for an unpatched flaw, the feds arrest two men accused of creating thousands of nonconsensual deepfake nudes, and more.WIRED.COM
23 May‘Underminr’ Vulnerability Lets Attackers Hide Malicious Connections Behind Trusted DomainsThe stealthy vulnerability impacts roughly 88 million domains and can be exploited to bypass DNS filtering and hide command-and-control traffic. The post ‘Underminr’ Vulnerability Lets Attackers Hide Malicious Connections Behind Trusted Domains appeared first on SecurityWeek .SECURITYWEEK.COM
23 MayClaude Mythos AI Finds 10,000 High-Severity Flaws in Widely Used SoftwareAnthropic on Friday disclosed that Project Glasswing has helped uncover more than 10,000 high- or critical-severity vulnerabilities across some of the most "systemically" important software across the world since the cybersecurity initiative went live last month. Project Glasswin…THEHACKERNEWS.COM
23 MayShipping Vulnerable Code On PurposeA large percentage of organizations knowingly ship software with unresolved vulnerabilities in order to meet business deadlines. This clip highlights the ongoing tension between production pressure and security requirements: one side wants to release features immediately, while t…YOUTUBE.COM
22 MayMini Shai-Hulud Attack Prompts npm to Revoke 2FA-Bypass Tokensnpm has forced a platform-wide reset of granular access tokens that bypass two-factor authentication (2FA) after a wave of supply chain attacks linked to the “Mini Shai-Hulud” campaign compromised hundreds of JavaScript packages. The emergency action, rolled out on May 19, invali…GBHACKERS.COM
22 MayMegalodon Malware Rapidly Infects Over 5,500 GitHub RepositoriesA newly identified malware campaign dubbed “Megalodon” has compromised more than 5,500 GitHub repositories, raising serious concerns about the security of open-source ecosystems. Security researchers from SafeDep report that the malware spreads through malicious code injections h…GBHACKERS.COM
22 MayFBI Warns Kali365 PhaaS Platform Targets Microsoft 365 Users to Steal LoginsThe U.S. Federal Bureau of Investigation (FBI) has issued a Public Service Announcement (Alert I-052126-PSA) warning about a newly identified Phishing-as-a-Service (PhaaS) platform named Kali365, which is actively targeting Microsoft 365 users. First observed in April 2026, the p…GBHACKERS.COM
22 MayGoogle folds CodeMender into agent ecosystem amid push for AI-led AppSecGoogle is expanding the role of its CodeMender security agent from autonomous vulnerability remediation toward a larger agentic development ecosystem, signalling a broader push toward AI-driven AppSec. Months after introducing CodeMender, an AI-powered agent designed to autonomou…CSOONLINE.COM
22 MaySplunk Patches Multiple Vulnerabilities Enabling DoS Attacks and Data ExposureSplunk has released security updates to fix three newly disclosed vulnerabilities that could allow low-privileged users to access sensitive data or disrupt Splunk Enterprise deployments through denial-of-service (DoS) conditions. The patches address issues in both Splunk Enterpri…GBHACKERS.COM
22 MayIdentity as the primary attack surface: What modern breaches are really exploitingThe “retro” way “The thing about the old days is… they are the old days” – Slim Charles , The Wire Protecting a specified network perimeter was the main focus of enterprise security strategy for several decades. Businesses made significant investments in firewalls, intrusion dete…CSOONLINE.COM
22 MayHackers Use Six-Layer Persistence on FreePBX SystemsHackers are actively exploiting FreePBX systems using a highly resilient six-layer persistence mechanism. The campaign has been attributed with high confidence to the threat actor INJ3CTOR3, known for targeting VoIP infrastructure for financial gain since 2019. The operation depl…GBHACKERS.COM
22 MayWhy your AI strategy stops where the PLC starts: Hard lessons from the OT frontlinesI spent two days at a substation connecting a major offshore wind farm to the grid. The control room featured three new AI-ready dashboards and a board mandate to “leverage machine learning for resilience.” It also had a maintenance laptop running Windows 7, literally taped to th…CSOONLINE.COM
22 MayPaved With Intent: ROADtools and Nation-State Tactics in the CloudOpen-source framework ROADtools is being misused by threat actors for cloud intrusions. Learn how to identify its malicious use. The post Paved With Intent: ROADtools and Nation-State Tactics in the Cloud appeared first on Unit 42 .UNIT42.PALOALTONETWORKS.COM
22 MayGitLab 19.0 adds AI workflows, secrets management, and self-hosted model supportGitLab released GitLab 19.0 with expanded secrets management, agentic merge request workflows, improved CI pipeline visibility, support for self-hosted open-source models, and supply chain visibility enhancements. Engineering organizations shipping more code than ever are confron…HELPNETSECURITY.COM
22 MayRussian Hackers Exploit RDP, VPNs, Supply Chains for Initial AccessRussian state-sponsored and aligned threat groups are increasingly combining Remote Desktop Protocol (RDP), Virtual Private Networks (VPNs), supply chain compromise, and sophisticated social engineering to gain initial access to targeted networks across government, critical infra…GBHACKERS.COM
22 MayPopular npm Package “art-template” Backdoored in Watering-Hole AttackHackers compromised the popular art-template npm package to inject a stealthy backdoor that redirected users’ browsers to a malicious watering‑hole site delivering a Coruna‑class iOS exploit framework. The campaign turned a widely used JavaScript templating library into a deliver…GBHACKERS.COM
22 MayWe hardened zizmor's GitHub Actions static analyzerIn March 2026, attackers exploited a pull_request_target misconfiguration in the aquasecurity/trivy-action GitHub Action to exfiltrate organization and repository secrets, then used those credentials to backdoor LiteLLM on PyPI (see Trivy’s post-mortem for the full timeline…TRAILOFBITS.COM
22 MayKore.ai unveils AI-native platform for enterprise multiagent systemsKore.ai has launched the new-generation Kore.ai Agent Platform Artemis edition, the AI-programmable, AI-native foundation that builds, governs, and optimizes the agents, systems, and workflows running across the enterprise. The platform launches initially on Microsoft Azure, with…HELPNETSECURITY.COM
22 MayMegalodon GitHub Attack Targets 5,561 Repos with Malicious CI/CD WorkflowsCybersecurity researchers have disclosed details of a new automated campaign called Megalodon that has pushed 5,718 malicious commits to 5,561 GitHub repositories within a six-hour window. "Using throwaway accounts and forged author identities (build-bot, auto-ci, ci-bot, pipelin…THEHACKERNEWS.COM
22 MayMaking Vulnerable Drivers Exploitable Without Hardware - The BYOVD Perspective1 Introduction This article provides a technical analysis of how many Windows kernel mode drivers can be interacted with from user mode without the hardware they were developed for. This work was motivated by driver-oriented vulnerability research and the need to evaluate the exp…THEHACKERNEWS.COM
22 MayUpdate Chrome now: Critical bugs could let attackers run codeThis Chrome update fixes critical flaws attackers could exploit through malicious websites, but not the “Browser Fetch” vulnerability.MALWAREBYTES.COM
22 MayHackers Exploit Middle East Telecoms for Massive C2 OperationsHackers are increasingly abusing Middle East telecommunications networks and hosting providers to operate large-scale command-and-control (C2) infrastructure. The findings highlight a strategic shift away from disposable indicators toward infrastructure-level tracking, allowing d…GBHACKERS.COM
22 MayGoogle’s Exploit Code Release Raises Concern Over Unfixed Chromium Security BugGoogle’s recent release of proof-of-concept (PoC) exploit code for a still-unpatched Chromium vulnerability has sparked significant concern across the cybersecurity community. The flaw, first reported in late 2022 by security researcher Lyra Rebane, remains unresolved after more …GBHACKERS.COM
22 MayCanadian arrested for operating KimWolf botnet tied to record DDoS attackCanadian authorities have arrested a 23-year-old Ottawa man who is accused of operating the DDoS-for-hire KimWolf IoT botnet platform. The arrest follows a broader international law enforcement operation earlier this year that dismantled infrastructure tied to the KimWolf, Aisuru…CYBERINSIDER.COM
22 May$20 per zero-day is already the WordPress plugin realityVulnerability researchers have spent the past year arguing about whether AI agents can find real bugs at scale or whether they mostly generate noise. A pipeline built in three days by researchers from TrendAI and CHT Security supplies an answer, along with a price tag that the se…HELPNETSECURITY.COM
22 May KEVPresident Trump delays signing of AI executive order.CISA warns of actively exploited Trend Micro and Langflow vulnerabilities. Two Americans admit to participation in tech support scam operations.THECYBERWIRE.COM
22 MayPolice take down VPN service (this time with a good reason)European authorities have cracked down on a VPN that has been used for various criminal activities. The operation, led by investigators in France and the Netherlands with help from Europol and Eurojust, has dismantled First VPN, a service that has been heavily promoted within Rus…CSOONLINE.COM
22 MayBreaking down the new Qualcomm chip vulnerability | Kaspersky official blogKaspersky experts have discovered an unpatchable vulnerability in popular Qualcomm chips used in smartphones, cars, smart devices, industrial equipment, and much more. We explain what this vulnerability is and what device owners should do.KASPERSKY.COM
22 MayProtect your devices from IMSI catchers (ITSAP.00.106)An international mobile subscriber identity (IMSI) catcher is a type of cell site simulator (CSS) that impersonates a legitimate cell tower to exploit connected mobile devices. It is important to understand how IMSI catchers work in order to detect them and protect your sensitive…CYBER.GC.CA
22 MayCell site simulators - ITSM.00.108This publication provides information on how CSS devices work, the security risks you should consider, and the mitigation actions you can take to better protect from CSS exploitations.CYBER.GC.CA
22 MayFBI warns of Kali Oauth stealersThe FBI has warned of the danger from a new wave of phishing attack s generated by a tool called Kali365. It enables cyber criminals to obtain Microsoft 365 access tokens and bypass multi-factor authentication (MFA) protocols without intercepting the user’s credentials by capturi…CSOONLINE.COM
22 MayMicrosoft recognized as a Leader in The Forrester Wave™ for Workforce Identity Security PlatformsMicrosoft has been recognized as a Leader in The Forrester Wave™: Workforce Identity Security Platforms, Q2 2026, receiving the highest scores in both the current offering and strategy categories. The post Microsoft recognized as a Leader in The Forrester Wave™ for Workforce Iden…MICROSOFT.COM
22 MayFBI warns of Kali365 phishing-as-a-service after April Microsoft 365 attacksThe law enforcement agency published an advisory on Thursday about Kali365 — a Telegram-based service for cybercriminals that allows them to capture legitimate "OAuth" tokens enabling widespread access to Microsoft 365 environments.THERECORD.MEDIA
22 MayAI Deleted Production CodeA developer claimed that an AI coding assistant deleted roughly 30,000 lines of production code while modifying a live application. According to the story, the AI introduced unrelated changes, broke core functionality, and forced the team to roll the entire deployment back. The c…YOUTUBE.COM
21 MayNew GhostTree Attack Causes EDR Tools to Hang, Leaving Files UnscannedA newly disclosed attack technique dubbed “GhostTree” is raising concerns among defenders after researchers demonstrated how it can disrupt endpoint detection and response (EDR) tools and bypass file scanning mechanisms on Windows systems. The technique, discovered by Varonis Thr…GBHACKERS.COM
21 MayClaude Code Sandbox Flaw May Compromise User SecretsA newly disclosed security flaw in Anthropic’s Claude Code platform has exposed a critical weakness in its network sandbox, potentially allowing attackers to bypass restrictions and exfiltrate sensitive data. The issue, identified by security researcher Aonan Guan, marks the seco…GBHACKERS.COM
21 MayCyber threats push SMBs to spend more on securityCybersecurity has become a key priority for small and medium-sized businesses due to growing threats and wider AI adoption. An IDC survey of 2,200 SMBs in eight markets examined how organizations manage cyber risks, prepare for AI-related threats, and handle third-party vendor se…HELPNETSECURITY.COM
21 MayPoC Released for PinTheft Linux Flaw Enabling Root Privilege EscalationA public proof-of-concept (PoC) exploit called “PinTheft” has been released for a newly disclosed Linux kernel flaw that allows local attackers to escalate privileges to root on certain systems. PinTheft is a Linux local privilege escalation (LPE) exploit that targets a reference…GBHACKERS.COM
21 MayWantToCry Ransomware Exploits SMB to Encrypt Remote FilesA new ransomware campaign named “WantToCry” that leverages exposed Server Message Block (SMB) services to gain access and encrypt victim data without deploying traditional malware on compromised systems. This approach significantly reduces the detection surface, making it harder …GBHACKERS.COM
21 MayWindows93 / Myspace93 - 46,105 breached accountsIn January 2021, the parody site Windows93 suffered a data breach of the Myspace93 sub-site after a beta application was exploited to download server files. The compromised data was later leaked in June and included 46k Myspace93 accounts containing email and IP addresses, userna…HAVEIBEENPWNED.COM
21 MayThe friendly skies aren’t friendly.This week, hosts of N2K CyberWire Maria Varmazis and Dave Bittner alongside …THECYBERWIRE.COM
21 MayWhy AI changed the threat model for travel technologyIn this Help Net Security interview, Devon Bryan, SVP, Global CSO at Booking Holdings, reflects on his path from Air Force network security engineer to global CSO across financial services, hospitality, and travel technology. He discusses why the travel industry’s interconn…HELPNETSECURITY.COM
21 MayAI red teaming agents change how LLMs get testedAdversarial probing of LLMs has piled up a sprawling toolkit over the past three years. Attack techniques with names like Tree of Attacks with Pruning, Crescendo, and Skeleton Key sit alongside hundreds of prompt transforms and scoring methods across open-source frameworks includ…HELPNETSECURITY.COM
21 MayFollow the CryptoEvery threat actor leaves a financial signature. Ransomware operators, state-sponsored hackers, fraud networks — they all need to move money, and when they do, the blockchain records it permanently. Jackie Burns Koven leads cyber threat intelligence at Chainalysis, where she tr…THECYBERWIRE.COM
21 MayCritical Drupal Vulnerability Could Leave Sites Open to CyberattackThe Drupal Security Team has issued a warning about a highly critical vulnerability affecting Drupal core, with a security release scheduled for May 20, 2026 (PSA-2026-05-18). The flaw carries a severity rating of 20/25, indicating a significant risk that attackers could compromi…GBHACKERS.COM
21 MayMini Shai-Hulud Hits @antv npm Packages, Targets CI/CD SecretsAn Active and sophisticated supply chain attack targeting the widely used @antv npm ecosystem, where a threat actor compromised a maintainer account and pushed malicious package updates designed to steal sensitive CI/CD credentials. The campaign, dubbed “Mini Shai-Hulud,” demonst…GBHACKERS.COM
21 MayAI becoming an SOC imperative for curtailing emerging cyber threatsThe cybersecurity profession is on the verge of a sea change, and security pros must begin to master AI tools to combat emerging threats by building more autonomous, real-time protections. Expert panelists at a recent DTX conference session in Manchester, titled “ Bot vs Bot: Sur…CSOONLINE.COM
21 MayTerra adds continuous network exploitation validation to its platformTerra Security has announced the public preview of continuous exploitation validation for network infrastructure, now available to all customers through the Terra Platform. The launch expands Terra’s offensive security capabilities from web applications to network infrastructure …HELPNETSECURITY.COM
21 MayIndian Student Data Weaponized in Phishing and Financial Fraud CampaignsA growing trend in India where student data is increasingly being exploited for cybercrime activities, including phishing, impersonation, social engineering, and financial fraud. As educational institutions rapidly adopt digital platforms for admissions, fee payments, examination…GBHACKERS.COM
21 MayASAPP expands adversarial testing for enterprise AI systemsASAPP has launched Continuous Red Teaming, a new capability that integrates adversarial AI testing directly into ASAPP’s model evaluation framework. The new capability is built on Promptfoo, an AI security platform that helps enterprises detect and address vulnerabilities i…HELPNETSECURITY.COM
21 MayNew NGINX 0-Day RCE “nginx-poolslip” Threatens Millions of ServersA newly discovered zero-day vulnerability in NGINX, dubbed “nginx-poolslip,” is raising serious concerns across the global cybersecurity community, as it exposes millions of servers to potential remote code execution (RCE) attacks. The vulnerability affects NGINX version 1.31.0, …GBHACKERS.COM
21 MayFake Invitation Phishing Campaign Steals Credentials From U.S. OrganizationsA large-scale phishing campaign leveraging fake event invitations is actively targeting U.S. organizations, combining credential theft, OTP interception, and remote access tool abuse into a single attack chain. The campaign stands out due to its repeatable phishing framework, whi…GBHACKERS.COM
21 MayA Hacker Group Is Poisoning Open Source Code at an Unprecedented ScaleGitHub is just the latest victim of TeamPCP, a gang that has carried out a spree of software supply chain attacks that has impacted hundreds of organizations.WIRED.COM
21 MayMicrosoft releases open-source tools to operationalize AI agent safetyMicrosoft has open-sourced two new tools aimed at bringing AI safety checks much earlier into the agent development lifecycle. The tools, called Rampart and Clarity, were announced this week as part of Microsoft’s broader push to operationalize safety engineering for agentic AI. …CSOONLINE.COM
21 MayApache OFBiz RCE Flaw Abuses Password-Change Restrictions for Authentication BypassA critical authentication bypass vulnerability in Apache OFBiz allows attackers to hijack forced password-change flows and achieve remote code execution (RCE) via a single HTTP request, affecting all versions before 24.09.06. Apache OFBiz RCE Flaw Apache OFBiz is an open-source E…GBHACKERS.COM
21 MayTenable One deepens third-party integrations with new Open Connector for unified risk visibilityThe days of rigid, vendor-locked security stacks are over. The Tenable One Open Connector amplifies Tenable One’s extensive capacity to ingest and consolidate third-party security data, giving you more complete visibility across your attack surface, so you can keep using your pre…TENABLE.COM
21 MayEuropol dismantles ‘First VPN’ service used by ransomware gangsEuropean law enforcement agencies have dismantled a long-running VPN service allegedly used by ransomware gangs and cybercriminals to conceal attacks, steal data, and evade investigators. The operation, coordinated by France and the Netherlands with support from Europol and Euroj…CYBERINSIDER.COM
21 MayThreatsDay Bulletin: Linux Rootkits, Router 0-Day, AI Intrusions, Scam Kits and 25 New StoriesThis week starts small. A token leaks. A bad package slips in. A login trick works. An old tool shows up again. At first, it feels like the usual mess. Then you see the pattern: attackers are not always breaking in. They are using the parts we already trust. That is what makes it…THEHACKERNEWS.COM
21 MaySelective HTTP Proxying in Linux, (Thu, May 21st)Recently, Rob wrote about a tool, Proxifier , that can intercept requests from specific processes. Proxifier is available for Windows, macOS, and Android. But I have not seen a generic Linux option yet. The advantage of a tool like Proxifier is the ability to target specific soft…ISC.SANS.EDU
21 MayReducing Phish-Prone Rates Without Training Fatigue: A Practical Playbook for Traditional OrganizationsPhishing remains the single biggest human-driven threat in most organizations. Yet many security leaders face a familiar problem: the stronger the push to run frequent training and simulations, the louder the employee backlash. Complaints range from “too many tests” to “training …KNOWBE4.COM
21 MayChinese APTs Share Linux Backdoor in Central Asia Telco Attacks"Showboat" doesn't show off, but clearly it doesn't need to, as it's long helped China spy on small market communications providers.DARKREADING.COM
21 MayContent Delivery Exploit Opens Websites to Brand HijackingThe Underminr domain-fronting attack allows threat actors to modify Web requests and leverage trusted websites to cloak malicious activity.DARKREADING.COM
21 MayQ1 2026 Threat Landscape Report: Zero-clicks, geopolitical tensions, and some wins for law enforcementThe first quarter of 2026 reinforced that attackers are moving faster, operating with greater coordination, and exploiting weaknesses before most organizations can respond effectively. From escalating geopolitical tensions to increasingly aggressive ransomware operations, the lat…RAPID7.COM
21 MayShowboat Linux Malware Hits Middle East Telecom with SOCKS5 Proxy BackdoorCybersecurity researchers have disclosed details of a new Linux malware dubbed Showboat that has been put to use in a campaign targeting a telecommunications provider in the Middle East since at least mid-2022. "Showboat is a modular post-exploitation framework designed for Linux…THEHACKERNEWS.COM
21 MayCybersecurity’s Hidden Communication RiskCybersecurity professionals often rely on acronyms and technical shorthand without realizing most people don’t understand them. The speaker connects this to a behavioral science concept called the “curse of experience” — experts naturally assume others share their knowledge. That…YOUTUBE.COM
21 MayUK plans for cybercrime law reform would protect almost no one, experts warnThe proposals would require researchers to cease activity the moment a vulnerability is identified, meaning they could not confirm it was real, assess its severity or determine its exploitability.THERECORD.MEDIA
21 MayAuthorities dismantle First VPN, used by ransomware actorsFirst VPN, a virtual private network service marketed to cybercriminals, promising anonymity for its users, was taken offline on May 19 and 20 as part of Operation Saffron. During the operation, French and Dutch authorities, with support from Europol and Eurojust, dismantled 33 s…HELPNETSECURITY.COM
21 May KEVCISA asks cybersecurity community to alert it to vulnerability exploitationThe agency wants to ensure that its public catalog of actively exploited flaws is as comprehensive as possible.CYBERSECURITYDIVE.COM
21 MayAttackers are bypassing MFA on SonicWall VPNs because something was wrong with previous fixAttackers bypassed MFA on patched SonicWall Gen6 VPNs because admins missed extra manual steps required to fully fix the flaw. There is a particular kind of security failure that is harder to catch than an unpatched system: a patched system where the patch did not actually work b…SECURITYAFFAIRS.COM
21 MaymacOS Kernel Memory Corruption ExploitA group used Anthropic’s Mythos AI model to help find a kernel memory corruption vulnerability and exploit on Apple’s M5. News article .SCHNEIER.COM
21 MayRobinhood Glitch Allowed Attackers to Send Phishing Emails to CustomersA phishing campaign exploited a glitch in Robinhood’s account creation process to send phishing emails from the investment platform’s own systems, SecurityWeek reports.KNOWBE4.COM
21 May KEVMicrosoft patches two actively exploited Defender vulnerabilities.Europol operation shutters First VPN. Ukrainian police identify suspected infostealer operator.THECYBERWIRE.COM
21 MayTrump Mobile exposes data of customers who ordered the T1 phoneTrump Mobile, the wireless carrier and smartphone brand tied to US President Donald Trump, is reportedly exposing sensitive customer information through an easily exploitable flaw on its website. That is according to claims made by YouTubers Coffeezilla and penguinz0, both of who…CYBERINSIDER.COM
21 MayMicrosoft open-sources tools for designing and testing AI agentsMicrosoft has open-sourced two tools aimed at bringing security discipline to AI agent development: Clarity, a structured design review tool, and RAMPART, a continuous testing framework. The release comes from Microsoft’s AI Red Team, the company’s internal unit that …HELPNETSECURITY.COM
21 MayCISA chief frets about open-source vulnerabilities, delayed security improvementsActing director Nick Andersen’s comments came as a wave of malware attacks hit tech that’s publicly available for collaboration. The post CISA chief frets about open-source vulnerabilities, delayed security improvements appeared first on CyberScoop .CYBERSCOOP.COM
21 MayThe art of being ungovernableIn this edition of the Threat Source newsletter, William explores the value of being "ungovernable" in a professional setting, sharing how challenging the status quo and seeking out the smartest people in the room can lead to a more fulfilling and successful career.TALOSINTELLIGENCE.COM
21 MayTrump postpones executive order focused on AI securityUnder a draft executive order, the NSA, Treasury Department and other federal agencies would get 90-days to test new models for cybersecurity and national security concerns. The post Trump postpones executive order focused on AI security appeared first on CyberScoop .CYBERSCOOP.COM
21 MayGlobal law enforcement operation takes First VPN offlinePolice seized First VPN in a global crackdown, exposed its cybercrime users, and shut down infrastructure tied to ransomware and data theft. A major international law enforcement operation has taken First VPN offline, a service that had become a quiet staple for ransomware crews,…SECURITYAFFAIRS.COM
21 MayLaw enforcement shuts down VPN service used by two dozen ransomware gangsFirst VPN promised hackers complete anonymity for their cyberattacks. But Europol said it was able to notify the service’s users that they have now been identified.TECHCRUNCH.COM
21 MayThat shield has cracks in it.Microsoft confirms active exploitation of two Defender flaws. Europol dismantles a VPN service tied to ransomware gangs. A nine-year-old Linux kernel bug exposes SSH keys and password hashes. Cisco patches a critical Secure Workload vulnerability, while Drupal fixes a highly crit…THECYBERWIRE.COM
21 May[Heads Up] GitHub Breach Shows Developer Tools Are Social Engineering TargetsGitHub disclosed that attackers accessed its internal repositories after compromising an employee device through a poisoned Visual Studio Code extension. The company said the activity appears limited to GitHub-owned internal repositories, with the attacker’s claim of roughly 3,80…KNOWBE4.COM
21 MayFCC, Github, MiniShai-hulud, Stated of Supply Chain, Itron, CRA, NIS2, and more!! - PSW #927In the security news this week: - FCC router bans and the hidden firmware update problem - Why extending support timelines actually improves security - Github supply chain concerns and the evolving SBOM ecosystem - CRA and NIS2 compliance deadlines are getting very real - The EU …YOUTUBE.COM
21 MayNew Verizon Report Reveals the Security Gap Attackers Are Exploiting MostVerizon’s 2026 DBIR shows vulnerability exploitation, AI-enabled attacks, third-party risk, and ransomware are reshaping cyber threats. The post New Verizon Report Reveals the Security Gap Attackers Are Exploiting Most appeared first on TechRepublic .TECHREPUBLIC.COM
21 May KEVEU’s 24-Hour Security DeadlineThe EU Cyber Resilience Act introduces a 24-hour disclosure requirement for actively exploited vulnerabilities affecting connected products sold in Europe. That includes hardware, firmware, submodules, and software dependencies. For many organizations, the challenge is not just p…YOUTUBE.COM
21 MayQuantifying 2026 Routinely Targeted Vulnerabilities (So Far)VulnCheck identified 25 CVEs disclosed in 2026 that have been routinely targeted by adversaries and researchers so far this year, drawing from a global body of exploit code and exploitation data.VULNCHECK.COM
20 MayWindows 11 BitLocker Zero-Day, TeamPCP Malware Leak, Iran Gas Station Hacks | Cybersecurity TodayA serious new Windows 11 BitLocker vulnerability, open-sourced offensive malware tools, a suspected Iranian cyber campaign targeting U.S. fuel infrastructure, and malware that appears designed to interfere with nuclear weapons simulation systems. Cybersecurity Today would like to…CYBERSECURITYTODAY.LIBSYN.COM
20 MayGitHub Investigating TeamPCP Claimed Breach of ~4,000 Internal RepositoriesGitHub on Tuesday said it's investigating unauthorized access to its internal repositories after the notorious threat actor known as TeamPCP listed the platform's source code and internal organizations for sale on a cybercrime forum. "While we currently have no evidence of impact…THEHACKERNEWS.COM
20 MayGrafana GitHub Breach Exposes Source Code via TanStack npm AttackGrafana Labs, on May 19, 2026, said an investigation into its recent breach found no evidence of customer production systems or operations being compromised. It said the scope of the incident is limited to the Grafana Labs GitHub environment, which includes public and private sou…THEHACKERNEWS.COM
20 MayPoC Exploit Released for DirtyDecrypt Linux Kernel VulnerabilityPoC exploit code for the DirtyDecrypt (DirtyCBC) Linux kernel vulnerability has been released publicly, turning a previously theoretical local privilege escalation into a practical, copy‑paste exploit path to root on specific Linux distributions. DirtyDecrypt (also called DirtyCB…GBHACKERS.COM
20 MayHackers Exploit MSHTA to Deploy LummaStealer and Amatera MalwareHackers are increasingly abusing the legacy Microsoft HTML Application Host (MSHTA) utility to deliver commodity malware such as LummaStealer and Amatera. Despite being tied to Internet Explorer, which was retired in 2022, MSHTA remains default in Windows, making it an attractive…GBHACKERS.COM
20 MayGitHub Source Code Reportedly Compromised, TeamPCP Claims BreachA threat actor group known as TeamPCP has claimed responsibility for a significant breach involving GitHub’s internal systems, alleging the theft of sensitive source code and proprietary organizational data. The group is currently offering the allegedly stolen dataset for sale on…GBHACKERS.COM
20 MayRisky Business #838 -- GitHub investigates possible breachOn this week’s show Patrick Gray, Adam Boileau and James Wilson discuss the week’s cybersecurity news. They cover: GitHub announced a possible breach CISA leaks important creds, keys in public repo Awful vulnerability in Bitlocker renders it useless without a PIN So. Many. Patche…RISKY.BIZ
20 MayNew NGINX Vulnerability Exposes Servers to Malicious Code ExecutionNGINX has disclosed a new high‑severity vulnerability in its JavaScript module that can allow remote attackers to crash servers and, in specific conditions, execute arbitrary code on vulnerable systems. F5 has published a security advisory (K000161307) describing a flaw in the NG…GBHACKERS.COM
20 MayAlleged Huawei zero-day blamed for the 2025 Luxembourg telecom crashA Huawei zero-day flaw reportedly caused Luxembourg’s 2025 nationwide outage, disrupting landline, 4G/5G, and emergency services On July 23, 2025, a nationwide telecom outage in Luxembourg was reportedly triggered by a previously undisclosed flaw in Huawei enterprise routers. The…SECURITYAFFAIRS.COM
20 MayInterpol's 'Operation Ramz' Pioneers Cross-Region Collabs in Middle EastWhile the numbers are modest, the crackdown on cybercrime involved 13 countries in the MENA region, the largest law enforcement collaboration to date.DARKREADING.COM
20 MayVerizon DBIR: Vulnerability Exploits Overtake Credentials as Top Access VectorVerizon DBIR finds 31% of data breaches began with software flaws last yearINFOSECURITY-MAGAZINE.COM
20 MayTeamPCP GitHub Breach: Internal GitHub Repositories Allegedly AccessedTeamPCP GitHub Breach: Internal GitHub Repositories Allegedly Accessed TeamPCP is back in the headlines, and this time the target is not a plugin, a CI/CD pipeline, or an open-source package. The group is claiming access to GitHub itself, one of the most critical pieces of infras…SOCRADAR.IO
20 MayShift to Prevention and Enforcement as We Repeat Security Mistakes With AI - Rob Allen - BSW #448Over the last decade, cybersecurity heavily invested in EDR, XDR, SIEM, telemetry, and SOC-driven operations. We stopped asking how to stop attacks and started asking how fast we could detect them. However, Mythos and frontier models have changed that paradigm. How do you detect …YOUTUBE.COM
20 MayGitHub confirms internal repository theft as TeamPCP claims attackGitHub disclosed that it is investigating unauthorized access to its internal repositories after attackers compromised an employee's device through a malicious Visual Studio Code extension. The company says there is currently no evidence that customer repositories or enterprise d…CYBERINSIDER.COM
20 MayTeamPCP breached GitHub’s internal codebase via poisoned VS Code extensionFollowing TeamPCP’s claim that they’ve breached GitHub’s own private code repositories, the Microsoft-owned company launched an investigation and confirmed the compromise. “Our current assessment is that the activity involved exfiltration of GitHub-interna…HELPNETSECURITY.COM
20 MaySHub Reaper impersonates Apple, Google, and Microsoft in one MacOS attack chainA newly disclosed macOS infostealer campaign is exploiting user trust in some of the biggest names in tech to slip past defenses. Researchers at SentinelOne have detailed a new variant of the SHub malware family, dubbed “Reaper,” that impersonates Apple, Google, and Microsoft at …CSOONLINE.COM
20 MayArmorCode gives security teams AI workers for exposure and remediationArmorCode has announced Anya Agents, a new agentic AI framework delivered on the patented ArmorCode Agentic AI Platform that enables organizations to operationalize AI-driven security workflows at enterprise scale. Built on ArmorCode’s Context Risk Graph, Anya Agents help securit…HELPNETSECURITY.COM
20 MayMicrosoft Open-Sources RAMPART and Clarity to Secure AI Agents During DevelopmentMicrosoft has unveiled two new open-source tools called RAMPART and Clarity to assist developers in better testing the security of artificial intelligence (AI) agents. RAMPART, short for Risk Assessment and Measurement Platform for Agentic Red Teaming, functions as a Pytest-nativ…THEHACKERNEWS.COM
20 MayGrafana GitHub Security Incident Reportedly Connected to TanStack npm RansomwareGrafana Labs has disclosed a targeted GitHub security incident linked to the ongoing TanStack npm supply chain ransomware campaign, raising concerns about software development pipeline security and token management practices. The company confirmed that attackers gained unauthoriz…GBHACKERS.COM
20 MayGremlin Stealer Hides C2 and Exfiltration Paths in Encrypted ResourcesA newly identified variant of the Gremlin stealer malware is leveraging advanced obfuscation techniques to conceal its command-and-control (C2) infrastructure and data exfiltration logic within encrypted .NET resource sections. This evolution highlights a significant shift toward…GBHACKERS.COM
20 MayOld Breaches Resold as New Corporate Data LeaksDark web data brokers are increasingly recycling old breach data and marketing it as fresh corporate leaks. The activity, largely observed in Chinese-language cybercrime forums and Telegram channels, is creating confusion among organizations and diverting security resources towar…GBHACKERS.COM
20 MayGitHub admits major source code leak after 3,800 internal repositories breachedMicrosoft’s GitHub has suffered what appears to be its biggest ever security breach after confirming that attackers exfiltrated code from around 3,800 of the company’s internal repositories. News of the incident first emerged on May 19, when GitHub said it was investigating “unau…CSOONLINE.COM
20 MayImplement agentic AI in cybersecurity with Tenable Hexa AI: Reduce cyber risk at machine speedAs frontier AI models collapse the traditional exploit window, Tenable Hexa AI transforms the security operating model from manual triage to agentic orchestration. See how you can automate vulnerability remediation and super-charge exposure management with Tenable Hexa AI. Key ta…TENABLE.COM
20 MayUkraine probes teen suspect in cyber theft scheme targeting California online shoppersThe investigation began after U.S. authorities informed their Ukrainian counterparts that hackers operating from Ukraine could be involved in attacks targeting users of American e-commerce platforms, Ukraine's Prosecutor General said.THERECORD.MEDIA
20 MayCompromised coding tool helped hackers breach thousands of GitHub repositoriesThe attack is the latest example of hackers’ intense focus on open-source packages.CYBERSECURITYDIVE.COM
20 MayCarding site B1ack’s Stash dumps 4.6 Million stolen cards for freeCarding forum B1ack’s Stash claims to have released millions of stolen CVV2 payment card records for free after suspending sellers. B1ack’s Stash, one of the most active stolen card marketplaces on the dark web, has released 4.6 million credit card records for free, n…SECURITYAFFAIRS.COM
20 MayPatch Now: Critical Flaw in OT Robot OS Gives Attackers ControlAn unauthenticated attacker can exploit the command injection vulnerability to gain remote access to robotic systems, causing significant disruption to the environment.DARKREADING.COM
20 MayVerizon DBIR: Vulnerability exploitation is the dominant initial access vectorVulnerability exploitation has overtaken stolen credentials as the most common way attackers gain initial access to target networks, according to the 2026 Verizon Data Breach Investigations Report. This is the first time credential theft has been knocked off the top spot in the r…HELPNETSECURITY.COM
20 MayNanoCo lands $12 million seed funding, launches enterprise assistant built on NanoClawNanoCo announced a $12 million seed round, alongside the commercial launch of a professional assistant built on its open-source agent framework NanoClaw. Valley Capital Partners led the round. Docker, Vercel, monday.com, Slow Ventures, Clutch Capital, Factorial Capital, and Huggi…HELPNETSECURITY.COM
20 MayOperationalizing CTEM Faster: Build Surface Command Dashboards in MinutesModern attack surfaces don’t sit still. Cloud expansion, SaaS sprawl, identity complexity, and shadow IT are continuously reshaping organizational risk. For security leaders, visibility isn’t the challenge anymore, but actually operationalizing that visibility is. Surface Command…RAPID7.COM
20 MayThe cost of trusting the extension ecosystem.GitHub confirms a breach tied to a malicious VS Code extension. Anthropic fights a Pentagon blacklist as the White House weighs new AI security rules. Drupal scrambles to patch a critical flaw. Cisco Talos tracks the evolution of BadIIS malware-for-hire. Signal adds anti-phishing…THECYBERWIRE.COM
20 MayGitHub Confirms Breach, 4K Internal Repos StolenOpen source software giant GitHub confirmed a data breach this week involving the theft of thousands of repos. One threat actor — TeamPCP — took credit.DARKREADING.COM
20 MayThe AI Kill Switch ProblemThe UK is discussing cybersecurity legislation that could include emergency shutdown mechanisms — “kill switches” — for advanced AI systems that threaten national security or human life. The speaker argues that emergency stop capabilities are reasonable at the system level. AI sy…YOUTUBE.COM
20 MayPinTheft: Another Linux Privilege Escalation, Another Working Exploit, This Time Targeting ArchPinTheft is a Linux LPE flaw in the RDS subsystem with public exploit code. Arch Linux users face the highest risk and should patch immediately. The wave of Linux local privilege escalation vulnerabilities showing up with working exploit code is not slowing down. The latest is Pi…SECURITYAFFAIRS.COM
20 MayFake Android Apps Commit Carrier Billing Fraud for Premium Svcs.The disguised apps use WebView automation, JavaScript injection, and OTP interception to avoid detection and complete fraudulent subscriptions.DARKREADING.COM
20 MayIntroducing RAMPART and Clarity: Open source tools to bring safety into Agent development workflowThe AI systems shipping inside enterprises today are fundamentally different from the ones we were building even two years ago, because they have moved well past answering questions and into accessing your email, retrieving records from your CRM, writing and executing code, and t…MICROSOFT.COM
19 MayCTT - 468,124 breached accountsIn April 2026, data allegedly obtained from CTT, Portugal's national postal service, was posted to a public hacking forum . The data included 468k unique email addresses along with names, phone numbers and parcel tracking numbers which can be used to retrieve the tracking history…HAVEIBEENPWNED.COM
19 MayGitHub Actions Supply Chain Attack Redirects Tags to Steal CI/CD CredentialsIn yet another software supply chain attack, threat actors have compromised the popular GitHub Actions workflow, actions-cool/issues-helper, to run malicious code that harvests sensitive credentials and exfiltrates them to an attacker-controlled server. "Every existing tag in the…THEHACKERNEWS.COM
19 MayCISA Admin Reportedly Exposes AWS GovCloud Credentials in Public GitHub RepositoryA significant security lapse involving the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has come to light after a contractor reportedly exposed highly sensitive AWS GovCloud credentials in a public GitHub repository. The incident, disclosed by security researchers…GBHACKERS.COM
19 MaySEPPmail Gateway Flaws Expose Organizations to RCE and Email Traffic InterceptionMultiple critical vulnerabilities in the SEPPmail Secure E-Mail Gateway are putting thousands of organizations at risk of remote code execution (RCE) and the interception of sensitive email. The flaws, tracked under several CVEs, impact widely deployed SEPPmail appliances used fo…GBHACKERS.COM
19 MayMythos Preview Automates PoC Exploit Creation for Vulnerability ResearchA new AI model from Anthropic is changing how security teams find and prove software vulnerabilities. It is raising hard questions about what happens when the same technology falls into the wrong hands. Cloudflare has published findings from its participation in Project Glasswing…GBHACKERS.COM
19 MayPublic Instagram posts provide raw material for AI phishing campaignsA handful of public Instagram posts can give attackers enough material to generate convincing phishing emails with GenAI. Research from the University of Texas at Arlington and Louisiana State University showed how public social media activity can be turned into phishing messages…HELPNETSECURITY.COM
19 MayEarbud sensors can authenticate users by their heartbeat, study findsResearchers built a continuous authentication system called AccLock that identifies a wearer by the tiny vibrations a heartbeat makes inside the ear canal. The signal comes from an accelerometer of the kind already sitting inside many wireless earbuds, so no extra hardware is nee…HELPNETSECURITY.COM
19 MayCompromised GitHub Action Steals Workflow CredentialsA widely used GitHub Action, actions-cool/issues-helper, has been compromised in a supply chain attack that exposes sensitive CI/CD secrets to an attacker-controlled domain. The attack hinges on a subtle but powerful manipulation of Git tags. Instead of altering the visible commi…GBHACKERS.COM
19 MayHackers Exploit Entra ID Accounts to Steal Microsoft 365, Azure DataHackers Abuse Microsoft Entra ID Accounts to Exfiltrate Microsoft 365 and Azure Data. A highly sophisticated cyberattack campaign carried out by a threat actor tracked as Storm-2949, targeting Microsoft Entra ID accounts to steal sensitive data from Microsoft 365 and Azure enviro…GBHACKERS.COM
19 MayProtecting the Neglected: Measuring County Cyber Risk with Dr. Ido Sivan SevillaIn this episode, host Caleb Tolin sits down with Dr. Ido Sivan Sevilla, an Assistant Professor at the Hebrew University School of Public Policy & Governance and the School of Computer Science and Engineering, to expose critical vulnerabilities within U.S. county governments. As t…THECYBERWIRE.COM
19 MayiProov brings identity verification to video meetings to reduce fraud risksiProov has launched iProov Verified Meetings, a new solution that enables organizations to verify the identity of video call participants without adding friction to the user experience. Video meetings have become a trusted and scalable communication channel, but attackers are inc…HELPNETSECURITY.COM
19 MayPostgreSQL Flaws Expose Databases to Remote Code Execution and SQL InjectionPostgreSQL has released critical security updates addressing multiple high-impact vulnerabilities that could allow remote code execution (RCE), SQL injection, and denial-of-service (DoS) attacks across widely deployed database environments. The PostgreSQL Global Development Group…GBHACKERS.COM
19 MayShai-Hulud worm copycats emerge after source code leakShai-Hulud worm copycats are already attacking NPM developers after its source code leaked, enabling fast supply chain exploitation. The first copycats of the Shai-Hulud worm have already started showing up online, only a few days after the malware’s source code was dumped on Git…SECURITYAFFAIRS.COM
19 May7 tips for accelerating cyber incident recoveryDespite strong and redundant defenses, enterprises remain vulnerable to a wide range of cyberattacks. And because attacks — and cyber incidents — are inevitable, developing an incident response and recovery process that’s quick, comprehensive, and coordinated is essential. Expedi…CSOONLINE.COM
19 MayGrafana Labs Confirms Hackers Stole Source CodeOpen source tool maker Grafana says hackers stole codebase via GitHub breachINFOSECURITY-MAGAZINE.COM
19 MaySEPPMail Secure E-Mail Gateway Vulnerabilities Enable RCE and Mail Traffic AccessCritical security vulnerabilities have been disclosed in SEPPMail Secure E-Mail Gateway, an enterprise-grade email security solution, that could be exploited to achieve remote code execution and enable an attacker to read arbitrary mails from the virtual appliance. "These vulnera…THEHACKERNEWS.COM
19 MayOperation Ramz Dismantles 53 Servers Used in Scam and Malware CampaignsA large-scale international cybercrime operation led by INTERPOL has resulted in 201 arrests and the takedown of 53 malicious servers linked to phishing, malware, and online scam campaigns across the Middle East and North Africa (MENA) region. Dubbed Operation Ramz, the init…GBHACKERS.COM
19 MayDrupal to Release Urgent Core Security Updates on May 20, Sites Told to PrepareDrupal has issued an alert stating that it intends to release a "core security release" for all supported branches on May 20, 2026, from 5-9 p.m. UTC. "The Drupal Security Team urges you to reserve time for core updates at that time because exploits might be developed within hour…THEHACKERNEWS.COM
19 MayUAC-0184 Uses Bitsadmin and HTA Files to Deliver Gated MalwareUAC-0184 uses a multi‑stage malware chain that abuses bitsadmin and HTA loaders to reach a heavily obfuscated payload bundle, ultimately hiding behind signed binaries such as VSLauncher.exe and PassMark Endpoint to gain stealthy network access on Ukrainian military networks. CERT…GBHACKERS.COM
19 MayAI Raises the Bar on Vulnerability Awareness and Secure-by-Design SoftwareAI-powered vulnerability scanning leaves no excuse for unpatched bugs as the EU Cyber Resilience Act pushes firms toward secure-by-design softwareINFOSECURITY-MAGAZINE.COM
19 MayPhishing Campaign Exploits Google AppSheets to Target Facebook AccountsResearchers at Guardo Labs are tracking a major phishing campaign that abused Google AppSheet as a relay to send phishing emails. The researchers identified more than 30,000 Facebook accounts that were compromised by this campaign. Since the emails are sent from Google’s legitima…KNOWBE4.COM
19 MayInternet Explorer may be dead, but its ghost still runs malwareMicrosoft’s aging “mshta.exe” utility, a leftover component from Internet Explorer, is still being actively abused in modern malware campaigns years after the browser itself was retired. According to new research from Bitdefender, attackers continue to abuse Microsoft HTML Applic…CSOONLINE.COM
19 MayPureLogs infostealer is stealing credentials worldwideA phishing campaign is smuggling the powerful PureLogs information stealer onto targets’ Windows machines by hiding encrypted malicious payloads inside cat photos, Fortinet researchers discovered. The attack The attack starts with a phishing email containing a TXZ archive a…HELPNETSECURITY.COM
19 MayHackers have compromised dozens of popular open source packages in an ongoing supply chain attackThe attacks are part of a wider campaign known as Mini Shai-Hulud, which has already compromised several open source projects and, in turn, developers and companies that use them.TECHCRUNCH.COM
19 MayGitHub scales back bug bounties, reminds users security is their responsibility tooFaced with the growing volume of submission to its bug bounty program, GitHub is replacing cash bounties with swag rewards for reports with low security impact — and asking researchers to stop submitting reports that are low quality or about things that aren’t its fault. The clou…CSOONLINE.COM
19 MayMini Shai-Hulud returns, compromising hundreds of npm packagesAnother malware wave is washing through open-source software repos, stealing publishing tokens, installing OS‑level backdoors and persisting in developer tools and CI pipelines. The post Mini Shai-Hulud returns, compromising hundreds of npm packages appeared first on CyberScoop .CYBERSCOOP.COM
19 MayPatch bypass allows hackers to exploit prior flaw in SonicWall SSL-VPNResearchers said a wave of attacks began in February targeting firewalls that appeared to be protected. CYBERSECURITYDIVE.COM
19 MayRapid7’s 2026 Global Cybersecurity Summit: Key Takeaways for Security LeadersSecurity teams are working in an environment where speed, scale, and complexity are all increasing at the same time. Across the Rapid7 2026 Global Cybersecurity Summit , the focus was not just on how the threat landscape is evolving, but on how teams are adapting their approach t…RAPID7.COM
19 MayTP-Link, Photoshop, OpenVPN, Norton VPN vulnerabilitiesCisco Talos’ Vulnerability Discovery & Research team recently disclosed eight vulnerabilities in TP-Link, and one each in Adobe Photoshop, OpenVPN, and Gen Digital's Norton VPN. The vulnerabilities mentioned in this blog post have been patched by their respective …TALOSINTELLIGENCE.COM
19 MayGoverning infrastructure as code using pattern-based policy as codeOrganizations often struggle to enforce security and compliance requirements consistently across their cloud infrastructure. In one environment, a workload might be deployed in an AWS Region that was never approved for that class of data. In another, a security group might allow …AWS.AMAZON.COM
19 MayTrapdoor Android Ad Fraud Scheme Hit 659 Million Daily Bid Requests Using 455 AppsCybersecurity researchers have disclosed details of a new ad fraud and malvertising operation dubbed Trapdoor targeting Android device users. The activity, per HUMAN's Satori Threat Intelligence and Research Team, encompassed 455 malicious Android apps and 183 threat actor-owned …THEHACKERNEWS.COM
19 MayMicrosoft dismantled malware-signing network Fox TempestMicrosoft disrupted Fox Tempest, a malware-signing-as-a-service (MSaaS) that allowed attackers to sign malware with fake trusted certificates. Microsoft said it disrupted a cybercrime operation run by a threat actor named Fox Tempest, which helped threat actors sign malware with …SECURITYAFFAIRS.COM
19 MayNews alert: Orchid Security study finds invisible identities now outnumber managed accountsNEW YORK, May 19, 2026, CyberNewswire— Orchid Security , the company solving identity at its core, today released its Identity Gap: 2026 Snapshot report, revealing that the majority of enterprise identity now exists outside the view of identity and access … (more…) The post…LASTWATCHDOG.COM
19 MayAntV data visualization tool the latest to be hit by ongoing npm supply chain attacksThe world’s largest open-source registry, node package manager (npm), has been hit by another fast-moving malware attack, this time targeting the widely-used AntV enterprise data visualization tool. Unlike last week’s high-profile npm attack on TanStack , which exploited a comple…CSOONLINE.COM
19 MayHuawei zero-day attack behind last year’s crash of Luxembourg's entire telecoms networkThere is no evidence that the incident has recurred, but the flaw remains unexplained and has not been publicly acknowledged by the company.THERECORD.MEDIA
19 MayCISA secrets left sitting on GitHub.A CISA contractor leaks GovCloud credentials on GitHub. INTERPOL cracks down on phishing infrastructure across the Middle East and North Africa. Microsoft patches a critical Authenticator flaw, while Poland moves officials off Signal after targeted phishing campaigns. A stealthie…THECYBERWIRE.COM
19 MayAttackers hit vulnerabilities hard last year, making exploits the top entry point for breachesVerizon’s annual Data Breach Investigations Report uncovered a surge of exploited vulnerabilities, and a growing lack of critical defect remediation industrywide. The post Attackers hit vulnerabilities hard last year, making exploits the top entry point for breaches appeared firs…CYBERSCOOP.COM
19 MayWindows Zero-Day Barrage Continues After Patch TuesdayYellowKey, GreenPlasma, and MiniPlasma add to the growing list of vulnerabilities a security researcher disclosed over the past six weeks.DARKREADING.COM
19 MayAI Spam Is Breaking Bug BountiesBug bounty programs created a structured way for security researchers to report vulnerabilities while helping software companies improve products without relying entirely on internal QA teams. The speaker argues that generative AI is now overwhelming some of these programs with l…YOUTUBE.COM
19 MayVerizon DBIR: Enterprises Face a Dangerous Vulnerability GlutVerizon's "2026 Data Breach Investigations Report" ("DBIR") finds that exploits are now involved in 31% of initial access for breaches, while patching lags too far behind the bad guys.DARKREADING.COM
19 MayMultiple Vulnerabilities in Mozilla Products Could Allow for Arbitrary Code ExecutionMultiple vulnerabilities have been discovered in Mozilla products, the most severe of which could allow for arbitrary code execution. Mozilla Firefox is a web browser used to access the Internet. Mozilla Firefox ESR is a version of the web browser intended to be deployed in large…CISECURITY.ORG
19 MaySN 1079: Daybreak and Codename MDASH - Microsoft's Edge Password BlunderOpenAI, Microsoft, and Google are racing to unleash next-gen AI that hunts for software vulnerabilities and hacks at scale. This episode explores how these advancements could shake up everything we thought we knew about cybersecurity. Microsoft rethinks Edge's "intended behavior"…TWIT.TV
18 MayThe Boring Stuff is Dangerous NowAI agents capable of discovering and exploiting obscure vulnerabilities are emerging alongside developers producing vast amounts of potentially flawed AI-generated code, forcing defenders to adapt accordingly.DARKREADING.COM
18 MayWhen ransomware hits, confidence doesn’t restore endpointsRansomware, supply chain vulnerabilities, insider threats, compliance failures, and software disruptions remain major concerns for security leaders, according to The Ransomware Reality: Zero Days to Recover report by Absolute Security. How CISOs currently ensure endpoint resilien…HELPNETSECURITY.COM
18 MayClaude Code Vulnerability Allows Attackers to Run Commands Through Crafted DeeplinksA recently disclosed flaw in Claude Code allowed attackers to execute arbitrary system commands using a single crafted deeplink URL, turning a convenience feature into a remote code execution (RCE) vector. The issue, documented by security researcher Joernchen, has been fixed in …GBHACKERS.COM
18 MayFormer CISA nominee Sean Plankey named US CEO of defense startupUFORCE, a London-based company founded by Ukrainians, is looking to make drones in America. The post Former CISA nominee Sean Plankey named US CEO of defense startup appeared first on CyberScoop .CYBERSCOOP.COM
18 MayCrafted JPEGs Could Trigger PHP Memory Bugs for ExploitationPHP, one of the most widely used web programming languages, is rarely viewed as a direct attack surface at its core level. Security focus typically shifts toward frameworks and third-party libraries. However, new research shows that PHP’s built-in functionality specifically the e…GBHACKERS.COM
18 MayResearchers Build First Public Apple M5 macOS Kernel Exploit with Mythos PreviewSecurity researchers have unveiled the first publicly known macOS kernel memory corruption exploit targeting Apple’s latest M5 silicon, marking a significant moment for both offensive security and Apple’s next-generation defenses. The exploit, developed in collaboration with Myth…GBHACKERS.COM
18 MayMalicious npm Packages Steal SSH Keys, Cloud Credentials, and Crypto WalletsA new supply chain attack campaign targeting developers has surfaced in the npm ecosystem, with four malicious packages discovered stealing sensitive data, including SSH keys, cloud credentials, and cryptocurrency wallets. The campaign, identified by OX Security within the past 2…GBHACKERS.COM
18 MayLyrie: Open-source autonomous pentesting agentPenetration testing has usually required weeks of manual work, specialized tooling, and teams with narrow skill sets. Lyrie, an open-source autonomous security agent built by OTT Cybersecurity, compresses that process into a command line tool and publishes the entire codebase. Th…HELPNETSECURITY.COM
18 MayAI shrinks vulnerability exploitation window to hoursTime has become organizations’ biggest vulnerability because the gap between vulnerability discovery and exploitation has narrowed to hours, according to Synack’s 2026 State of Vulnerabilities Report. Total vulnerabilities by severity (2022-2025) (Source: Synack) AI expands the a…HELPNETSECURITY.COM
18 MayCritical FunnelKit Vulnerability Puts 40,000+ WooCommerce Sites at RiskA critical security vulnerability in the Funnel Builder plugin by FunnelKit is actively being exploited, putting more than 40,000 WooCommerce websites at risk of payment data theft. The vulnerability affects all Funnel Builder versions prior to 3.15.0.3 and allows unauthenticated…GBHACKERS.COM
18 Mayn8n Security Flaws Could Let Attackers Achieve Remote Code ExecutionA set of critical vulnerabilities in the popular workflow automation platform n8n has raised serious security concerns, with researchers warning that attackers could chain multiple flaws to achieve full remote code execution (RCE) on affected systems. The issues, disclosed in mul…GBHACKERS.COM
18 May201 arrested in INTERPOL disruption of phishing and fraud networksOperation Ramz, a cybercrime initiative coordinated by INTERPOL across the MENA region, focused on disrupting phishing campaigns, malware activity, and cyber scams that caused substantial financial losses across the region. The operation resulted in the arrest of 201 individuals …HELPNETSECURITY.COM
18 MayWhy the best security investment a board can make in 2026 isn’t another toolThere is a conversation that happens in boardrooms every quarter that security leaders will recognize. The CISO presents the threat landscape. The board asks what the company needs. The answer, almost always, is another tool. Another platform, another module, another vendor to cl…CSOONLINE.COM
18 MayAI coding is fueling a secrets-sprawl crisis few CISOs are containingWhen Matt Schlicht built Moltbook, the social network where AI agents talk to one another, he didn’t write the code himself . He “just had a vision,” and vibe-coded it. The social network launched on Jan. 28, 2026, and within days, security researchers started to see serious secu…CSOONLINE.COM
18 MayAI Has a data problem, cascading breaches, and the weekly news - Dimitri Sirota - ESW #459### Interview with Dimitri Sirota from BigID Most organizations think AI risk lives in the model – or the identity. It doesn’t. It lives in the data. In this episode, BigID’s CEO reframes the conversation: why legacy access controls are breaking down, why visibility into sensitiv…YOUTUBE.COM
18 MaySecurity Researchers Find 47 Zero-Days at Pwn2Own BerlinThe research community was awarded $1.3m as it found dozens of novel vulnerabilities at Pwn2Own BerlinINFOSECURITY-MAGAZINE.COM
18 MayAttackers accessed, downloaded code from Grafana Labs’ GitHubA threat actor has managed to access Grafana Labs’ GitHub environment and download the company’s codebase, the open-source observability and data visualization firm announced on Sunday. The breach is significant given Grafana Labs’ widespread use across enterpri…HELPNETSECURITY.COM
18 MayMiniPlasma Windows 0-Day Enables SYSTEM Privilege Escalation on Fully Patched SystemsChaotic Eclipse, the security researcher behind the recently disclosed Windows flaws, YellowKey and GreenPlasma, has released a proof-of-concept (PoC) for a Windows privilege escalation zero-day flaw that grants attackers SYSTEM privileges on fully patched Windows systems. Codena…THEHACKERNEWS.COM
18 MayFour Malicious npm Packages Deliver Infostealers and Phantom Bot DDoS MalwareCybersecurity researchers have discovered four new npm packages containing information-stealing malware, one of which is a clone of the Shai-Hulud worm open-sourced by TeamPCP. The list of identified packages is below - chalk-tempalte (825 Downloads) @deadcode09284814/axios-util …THEHACKERNEWS.COM
18 MayZero-Day Exploit Against Windows BitLockerIt’s nasty , but it requires physical access to the computer: The exploit, named YellowKey, was published earlier this week by a researcher who goes by the alias Nightmare-Eclipse. It reliably bypasses default Windows 11 deployments of BitLocker, the full-volume encryption …SCHNEIER.COM
18 MayGremlin Stealer Hides Payloads in .NET Resources to Evade DetectionA newly discovered variant of the Gremlin Stealer is raising concerns among security researchers by adopting stealth-focused techniques that significantly reduce its detection footprint. Gremlin Stealer is an information-stealing malware actively sold on Telegram. It targets a wi…GBHACKERS.COM
18 MayNew image-based prompt injection attack targets multimodal AI modelsSecurity researchers have developed a new image-based prompt injection attack that can manipulate how multimodal AI systems interpret user instructions without modifying the original text prompt, potentially expanding security risks for AI agents and vision-language systems. In a…CSOONLINE.COM
18 MayOpen source tool maker Grafana Labs says hackers stole its code, refuses to pay ransomThe open source project said hackers stole its codebase and threatened to publish its source code if the company did not pay.TECHCRUNCH.COM
18 MayAI Security Shifts To Data ControlMost organizations today use commercial AI systems rather than hosting or training their own models. That includes platforms like OpenAI, Gemini, Microsoft Copilot, and Anthropic. This shift changes the security problem. Instead of focusing on testing model vulnerabilities, organ…YOUTUBE.COM
18 MayShinyHunters hack 7-Eleven: franchisee data and Salesforce records exposed7-Eleven confirmed a breach after ShinyHunters claimed theft of over 600,000 Salesforce records and franchisee data. 7-Eleven has confirmed a data breach after the ShinyHunters hacking group claimed it stole more than 600,000 Salesforce records containing personal and corporate i…SECURITYAFFAIRS.COM
18 May⚡ Weekly Recap: Exchange 0-Day, npm Worm, Fake AI Repo, Cisco Exploit and MoreMonday opens with a trust problem. A mail server flaw is under active use. A network control system was targeted. Trusted packages were poisoned. A fake model page pushed a stealer. Then came the familiar ransom claim: the data was returned and deleted. The pattern is clear. One …THEHACKERNEWS.COM
18 MayResearchers craft a kernel exploit on Apple's M5 chips, with help from Mythos.Santa Clara County files lawsuit against Meta over alleged advertising practices. IBM security executive eyed for CISA director.THECYBERWIRE.COM
18 May18th May – Threat Intelligence ReportFor the latest discoveries in cyber research for the week of 18th May, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Vodafone, a major international telecom, has sustained a source code leak claimed by the Lapsus$ extortion group. The company confirme…RESEARCH.CHECKPOINT.COM
18 MayMY TAKE: AI agents force a rethink of enterprise service lines as vendors move up the tech tackORLANDO — Companies are pulling AI agents into their daily operations through a dozen side doors. Related: SaaS and AI agents converge One of them was in focus at KB4-CON , KnowBe4’s annual customer conference at the Marriott World Center … (more…) The post MY TAKE: AI agen…LASTWATCHDOG.COM
18 MayAI cyberattackers are getting better fasterThe ability of AI models to perform end-to-end, multi-stage penetration tests that match the capabilities of humans undertaking the same tasks has improved dramatically in recent months, according to new benchmarks published by the UK government’s AI Security Institute (AISI). In…CSOONLINE.COM
18 MayMicrosoft: Edge 148 will stop loading cleartext passwords in memoryMicrosoft says it is changing how Edge handles saved passwords in memory following public criticism and the release of a proof-of-concept tool that demonstrated credentials could be extracted in cleartext from the browser’s process memory. Microsoft confirmed that future versions…CYBERINSIDER.COM
18 MayAI is drowning software maintainers in junk security reportsAI-assisted vulnerability research has exploded, unleashing a firehose of low-quality reports on overworked software maintainers who are wasting hours sifting through noise instead of fixing real problems. Linus Torvalds, the Linux kernel’s creator, says the flood has made …HELPNETSECURITY.COM
18 MayGame over for 74 suspected scammers after Dutch cops plastered their faces on billboardsThe Dutch police’s Game Over?! campaign, which publicly displays images of suspected fraudsters to encourage self-surrenders and gather public tips, is proving successful, with the identities of 74 of the 100 suspects shown already identified. A digital display promoting the Dutc…HELPNETSECURITY.COM
18 MayAI Ends Productivity GuessworkAI tools and LLM-based workflows are changing how work output is produced and evaluated. Unlike traditional office environments or early remote work, output can now be tracked more directly through generated results and activity. This shifts productivity measurement away from phy…YOUTUBE.COM
18 MayGrafana confirms GitHub token breach cybercrime group claims the attackGrafana confirmed a GitHub token breach that exposed source code, but said no customer data or systems were affected. Grafana Labs confirmed a security incident after the extortion group Coinbase Cartel listed it on a leak site and claimed data theft on May 15. The breach was tri…SECURITYAFFAIRS.COM
18 MayMicrosoft May security patch fails for some due to boot partition size glitch“Something didn’t go as planned. Undoing changes.” That’s all the clue some Windows 11 users will get when Microsoft’s May Security Update fails to install because of insufficient free space on the EFI System Partition (ESP), leaving their systems unprotected by the dozens of pat…CSOONLINE.COM
18 MayThe M5 just met its memory problem.Researchers crack Apple’s M5 memory protections with a kernel exploit. An IBM Security executive emerges as a possible CISA pick. Researchers uncover four malicious npm packages. AI-generated “slop” floods bug bounty programs. Major healthcare breaches hit the HHS tracker, 7-Elev…THECYBERWIRE.COM
18 MayAI might cut false positives, but it won’t stop the slopAnthropic and OpenAI promise their latest tools will find more vulnerabilities. Cybersecurity employees say they’re already flooded with AI-generated reports. The post AI might cut false positives, but it won’t stop the slop appeared first on CyberScoop .CYBERSCOOP.COM
18 MayShai-Hulud Worm Clones Spread After Code ReleaseThe release of Shai-Hulud source code spells trouble for software developers as researchers worry the self-replicating worm could scale.DARKREADING.COM
18 MayMultiple Vulnerabilities in NGINX Could Allow for Remote Code ExecutionMultiple vulnerabilities have been discovered in NGINX, the most severe of which could allow for remote code execution. NGINX is a software used for web serving, reverse proxying, caching, and load balancing. Successful exploitation of the most severe of these vulnerabilities may…CISECURITY.ORG
18 MayHow Storm-2949 turned a compromised identity into a cloud-wide breachStorm-2949 turned stolen credentials into a cloud-wide breach, moving from identity compromise to large-scale data theft without using malware. This incident shows how threat actors can exploit trusted systems to operate undetected. The post How Storm-2949 turned a compromised id…MICROSOFT.COM
17 MayPwn2Own Berlin 2026, Day Three: DEVCORE Crowned Master of Pwn, $1.298 Million TotalPwn2Own Berlin 2026 ended with 47 zero-days and $1.29M in payouts, as DEVCORE dominated the competition across all categories. Pwn2Own Berlin 2026 ended after three intense days, with participants discovering 47 unique zero-days, and earning $1,298,250 in total payouts. Pwn2Own B…SECURITYAFFAIRS.COM
17 MayGrafana GitHub Token Breach Led to Codebase Download and Extortion AttemptGrafana has disclosed that an "unauthorized party" obtained a token that granted them the ability to access the company's GitHub environment and download its codebase. "Our investigation has determined that no customer data or personal information was accessed during this inciden…THEHACKERNEWS.COM
17 MayWeek in review: Cisco patches SD-WAN 0-day, unpatched Microsoft Exchange Server flaw exploitedHere’s an overview of some of last week’s most interesting news, articles, interviews and videos: Review: Foundations of Cybersecurity, 2nd edition Jason Andress has refreshed his introductory security text for No Starch Press. He writes in the introduction that the term security…HELPNETSECURITY.COM
17 MayGitHub Actions Cache Poisoning is eating open sourcesubmitted by codeinabox to security 3 points | 0 comments https://neciudan.dev/github-actions-poisoningPROGRAMMING.DEV
17 MayPwn2Own Berlin 2026 concludes with $1.29 million paid for 47 zero-daysPwn2Own Berlin 2026 wrapped up with another string of successful enterprise-targeted exploits, bringing the contest’s final tally to $1,298,250 awarded for 47 unique zero-day vulnerabilities discovered over three days. DEVCORE secured the “Master of Pwn” title with 50.5 points an…CYBERINSIDER.COM
17 MaySecurity Affairs newsletter Round 577 by Pierluigi Paganini – INTERNATIONAL EDITIONA new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including the international press. Attackers exploit Funnel Buil…SECURITYAFFAIRS.COM
17 May KEVAttackers exploit Funnel Builder bug to inject e-skimmers into e-storesAttackers are exploiting a critical flaw in the WordPress Funnel Builder plugin to inject skimming code into WooCommerce checkout pages. A critical vulnerability in the WordPress Funnel Builder plugin is being actively exploited to inject malicious JavaScript into WooCommerce che…SECURITYAFFAIRS.COM
17 MayiodéOS review: Privacy-focused Android that doesn’t get in your wayiodéOS is a privacy-oriented Android operating system developed by the French company iodé, based on the Android Open Source Project (AOSP). The project focuses on reducing user tracking and dependence on Google services while still maintaining broad Android app compatibility and…CYBERINSIDER.COM
17 MayDebian 13.5 point release lands with security fixes, bug patchesDebian 13.5 is the fifth point release for the stable distribution “trixie.” The update folds in roughly 100 Debian Security Advisories and corrections for more than 130 source packages, covering everything from the Linux kernel and Apache HTTP Server to OpenSSH, sudo…HELPNETSECURITY.COM
16 MayInside CIRA: How Canada's .ca Registry Became a Global DNS & Cybersecurity ForceDavid Shipley interviews Jon Ferguson, VP at CIRA, about how the Canadian Internet Registration Authority evolved from early paper-based .ca registrations at UBC into a 142-person, member-based not-for-profit running .ca and authoritative Anycast DNS infrastructure now supporting…CYBERSECURITYTODAY.LIBSYN.COM
16 MayJDownloader Website Hack Exposes Windows and Linux Users to Malicious InstallersA popular open-source download manager trusted by millions suddenly became a malware delivery platform after attackers compromised its official website, replacing legitimate installers with trojanized versions targeting both Windows and Linux users. The incident, confirmed by JDo…GBHACKERS.COM
16 MayOpenAI and others deal with fallout from TanStack supply-chain attack.Disgruntled researcher discloses two Windows zero-days. Microsoft warns of critical zero-day in on-prem Exchange Servers.THECYBERWIRE.COM
16 MayOpenAI hit by supply chain attack linked to malicious TanStack packagesOpenAI said the TanStack supply chain attack compromised two employee devices and exposed credentials from code repositories. OpenAI confirmed that the recent TanStack supply chain attack compromised two employee devices and exposed credential material stored in internal source c…SECURITYAFFAIRS.COM
16 MayAI Broke Patch ManagementAI systems are now discovering software vulnerabilities at a pace that is forcing major vendors to rethink how they ship security updates. The speaker points to Mozilla fixes tied to Glasswing discoveries and Oracle shifting from quarterly to monthly patching cycles. That change …YOUTUBE.COM
16 MayFunnel Builder Flaw Under Active Exploitation Enables WooCommerce Checkout SkimmingA critical security vulnerability impacting the Funnel Builder plugin for WordPress has come under active exploitation in the wild to inject malicious JavaScript code into WooCommerce checkout pages with the goal of stealing payment data. Details of the activity were published by…THEHACKERNEWS.COM
15 MayHow a Google API Key Became an $8,000 AI Bill, Meta Scam Ads Lawsuit, and 73-Second Cyber AttacksGoogle Cloud customers are reporting shocking surprise bills after compromised or misused API keys were allegedly used to access expensive Gemini AI services. In one case, Rod Dinan says his monthly Google Cloud costs jumped from under $50 to nearly $8,000. Sydney developer Isuru…CYBERSECURITYTODAY.LIBSYN.COM
15 MayThe AI oversight paradox: Is the investment worth the cost of watching it?Unlike in 2025, when AI adoption and testing drove business strategies, organizations in 2026 want proven ROI before committing budgets, according to a report by Globalization Partners. How global executives characterize their organization’s approach to AI adoption (Source: Globa…HELPNETSECURITY.COM
15 MayHackers Exploit Scheduled Tasks for Persistence in FrostyNeighbor AttacksHackers linked to the long-running FrostyNeighbor cyber‑espionage group have intensified attacks against Ukrainian government organizations, deploying updated techniques that rely on scheduled tasks for stealthy persistence and server-side validation to evade detection. FrostyNei…GBHACKERS.COM
15 MayDell SupportAssist Update Forces Windows Systems Into BSOD LoopA faulty update to Dell’s SupportAssist Remediation service is triggering widespread system crashes, forcing thousands of Dell and Alienware devices into continuous Blue Screen of Death (BSOD) loops. Affected systems repeatedly crash with the “CRITICAL_PROCESS_DIED” error, often …GBHACKERS.COM
15 MaySoap Box: Where does AI fit into cloud security?In this sponsored soap box edition of the Risky Business podcast Patrick Gray chats with Toni de la Fuente, the founder of Prowler. Prowler started off as a bunch of scripts in a trenchcoat, then became an open source cloud security tool, and it’s now a venture-funded cloud secur…RISKY.BIZ
15 MayTeamPCP Hackers Exploit CI/CD Pipelines to Steal Cloud CredentialsA financially motivated threat group known as TeamPCP is aggressively targeting modern software supply chains, abusing trusted CI/CD pipelines to steal sensitive developer and cloud credentials at scale. TeamPCP’s core strategy is simple but highly effective: compromise trusted b…GBHACKERS.COM
15 MayPwn2Own Berlin 2026, Day One: $523,000 paid out, AI products fallPwn2Own Berlin 2026 day one saw 22 entries and 24 zero-days across major software, with researchers earning $523,000 in total rewards. Day one of Pwn2Own Berlin 2026 featured 22 entries targeting widely used technologies, including browsers, operating systems, AI platforms, and N…SECURITYAFFAIRS.COM
15 MayMultiple cPanel Vulnerabilities Could Lead to Sensitive Resource ExposureMultiple newly disclosed vulnerabilities in cPanel & WHM, including the critical CVE‑2026‑41940 authentication bypass bug and a cluster of May 2026 flaws, could allow attackers to access sensitive resources and hosting accounts if servers remain unpatched. Organizations runni…GBHACKERS.COM
15 MayChina-Linked Hackers Deploy New TencShell Malware Against Global ManufacturerA suspected China-linked threat actor targeted the Indian branch of a global manufacturer leveraging an open source offensive toolkitINFOSECURITY-MAGAZINE.COM
15 MayResearchers uncover YellowKey and GreenPlasma Windows Zero-DaysResearchers disclosed two new Windows zero-days named YellowKey and GreenPlasma affecting BitLocker and the CTFMON framework. A security researcher known as Chaotic Eclipse, also called Nightmare-Eclipse, disclosed two new Windows zero-day vulnerabilities named YellowKey and Gree…SECURITYAFFAIRS.COM
15 MayMicrosoft Edge, Windows 11, and LiteLLM Fall to Exploits at Pwn2Own Berlin 2026The world’s top ethical hackers wasted no time breaking into modern software and AI systems on the opening day of Pwn2Own Berlin 2026, exposing critical zero-day vulnerabilities in Microsoft Edge, Windows 11, LiteLLM, and NVIDIA platforms. On May 14, researchers demonstrated 24 u…GBHACKERS.COM
15 May KEVEU’s Cyber Resiliency Act will put IT leaders to the testUnlike most cyber security regulations, the EU’s Cyber Resilience Act is about product safety rather than processes or certification, extending the CE mark from the physical side of products to software, firmware, backend services, and anything with a network connection. It encod…CSOONLINE.COM
15 MayThe economics of ransomware 3.0The moment every boardroom dreads There is a moment in almost every ransomware negotiation — usually around 36 hours, when legal, IT and the CFO are all in the same room — when someone says it out loud: “Let’s just see what the insurance covers.” That instinct, understandable as …CSOONLINE.COM
15 MayRocky Linux launches opt-in security repository for urgent fixesRocky Linux has introduced a Security Repository that allows the distribution to ship urgent security fixes ahead of upstream Enterprise Linux when public exploit code exists and upstream patches are unavailable. “The repository is disabled by default. That’s intentio…HELPNETSECURITY.COM
15 MayMicrosoft Warns HPE Operations Agent Abused in Malware-Free AttacksMicrosoft has revealed a stealthy intrusion campaign where attackers bypassed traditional malware and exploits, instead abusing trusted enterprise tools to silently infiltrate networks. The technique highlights a growing shift in cyberattacks where adversaries rely on legitimate …GBHACKERS.COM
15 MayAutonomous systems are finally working. Security is nextWaymo recently crossed a major milestone: Over 170 million autonomous miles driven without a single serious crash or injury. For years, autonomous driving was treated as a promise that was always just out of reach — too complex, too risky and not ready for the real world. That ar…CSOONLINE.COM
15 MayGremlin Stealer's Evolved Tactics: Hiding in Plain Sight With Resource FilesUnit 42 analyzes the evolution of Gremlin stealer. This variant uses advanced obfuscation, crypto clipping and session hijacking to compromise data. The post Gremlin Stealer's Evolved Tactics: Hiding in Plain Sight With Resource Files appeared first on Unit 42 .UNIT42.PALOALTONETWORKS.COM
15 MayTanStack Supply Chain Attack Hits Two OpenAI Employee Devices, Forces macOS UpdatesOpenAI has disclosed that two of its employee devices in its corporate environment were impacted via the Mini Shai-Hulud supply chain attack on TanStack, but noted that no user data, production systems, or intellectual property were compromised or modified in an unauthorized mann…THEHACKERNEWS.COM
15 MayAkamai to acquire LayerX for $205 millionAkamai has entered into a definitive agreement to acquire LayerX, a provider of browser-based AI usage control and secure enterprise browser (SEB) technology. LayerX’s solutions will extend Akamai’s protection into the browser, where the majority of enterprise tasks now occur and…HELPNETSECURITY.COM
15 MayShai-Hulud Worm Steals Dev Secrets Across npm, GitHub, AWS & KubernetesShai-Hulud is a major cybersecurity threat targeting the open-source software supply chain. Security researchers are raising alarms over “Shai-Hulud,” a self-propagating npm worm designed to steal sensitive developer credentials from GitHub, AWS, Kubernetes, and local environment…GBHACKERS.COM
15 MayGoogle Project Zero Details Pixel 10 Zero-Click Exploit ChainA powerful zero-click exploit chain for the Pixel 10 that can take an attacker from a remote Dolby decoding bug to full kernel control through a single vulnerable video processing driver. The work shows both how quickly Google can now patch critical issues and how shallow mistake…GBHACKERS.COM
15 MayHackers Exploit OAuth Device Flow to Steal Microsoft 365 TokensHackers are rapidly weaponizing a little-known Microsoft authentication feature to hijack enterprise accounts, as device code phishing surges across the threat landscape. The spike in activity is closely tied to the public release of criminal toolkits and phishing-as-a-service (P…GBHACKERS.COM
15 MayMicrosoft Reports Severe Zero-Day Flaw in On-Prem Exchange ServersThe zero-day vulnerability affects on-premises installations for all versions of Exchange Server 2016, 2019 and Subscription EditionINFOSECURITY-MAGAZINE.COM
15 MayRedesigning Security Culture for the Agentic AgeThe launch of platforms like Moltbook , OpenClaw , and RentAHuman in early 2026 has provided an unsettling glimpse into the future. We are entering a phase of the digital workplace where AI agents no longer just assist us, they interact with one another, act autonomously in the p…KNOWBE4.COM
15 MayCISA orders all federal agencies to patch exploited bug in Cisco SD-WAN systems by SundayCisco released a patch for the vulnerability on Thursday, writing in an advisory that it could “allow an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges on an affected system.”THERECORD.MEDIA
15 MayResearchers claim the first macOS kernel exploit on Apple M5 chipsSecurity researchers have announced what they describe as the first public macOS kernel memory corruption exploit capable of bypassing Apple’s Memory Integrity Enforcement (MIE) protections on the latest M5 chip. The exploit chain, developed by researchers at Calif with assistanc…CYBERINSIDER.COM
15 MayHack One, Own Every MowerRobotic lawnmowers and similar IoT devices can become security risks when attackers gain firmware access or exploit weak credential practices. When devices share identical configurations or weak default credentials, compromising one unit can potentially expose entire fleets. In p…YOUTUBE.COM
15 MayCisco zero-day under ongoing attack by persistent threat groupThe threat group behind the attacks is also linked to a series of recently disclosed vulnerabilities in the vendor’s firewalls and SD-WAN systems. The post Cisco zero-day under ongoing attack by persistent threat group appeared first on CyberScoop .CYBERSCOOP.COM
15 MayFour OpenClaw Flaws Enable Data Theft, Privilege Escalation, and PersistenceCybersecurity researchers have disclosed a set of four security flaws in OpenClaw that could be chained to achieve data theft, privilege escalation, and persistence. The vulnerabilities, collectively dubbed Claw Chain by Cyera, can permit an attacker to establish a foothold, expo…THEHACKERNEWS.COM
15 MayUS orders travelers on Air Force One to throw away gifts, pins, and burner phones after China tripPeople who travelled to Beijing for a summit between the United States and China had to throw away items they received during the trip before boarding Air Force One, presumably for security reasons.TECHCRUNCH.COM
15 MayOpenAI impacted by TanStack supply-chain attack.Shai-Hulud code has been leaked. Microsoft warns of critical zero-day in on-prem Exchange Servers.THECYBERWIRE.COM
15 MayAttackers exploit critical flaw in Cisco Catalyst SD-WAN ControllerResearchers discovered the authentication bypass vulnerability while investigating a prior issue in the same service.CYBERSECURITYDIVE.COM
15 MayMullvad VPN exit IP patterns could enable user fingerprintingA researcher has disclosed a privacy weakness in Mullvad VPN that could allow users to be probabilistically identified across different VPN servers by correlating the exit IP addresses assigned to their WireGuard connections. The issue stems from how Mullvad deterministically ass…CYBERINSIDER.COM
15 MayHere’s how the FTC plans to enforce the Take It Down ActThe commission will dole out hefty fines and promises investigations for Take It Down Act violators. Experts say questions remain around the agency’s resources and priorities. The post Here’s how the FTC plans to enforce the Take It Down Act appeared first on CyberScoop .CYBERSCOOP.COM
15 MayA Vulnerability in Microsoft Exchange Server Could Allow for Arbitrary Code ExecutionA vulnerability has been discovered in Microsoft Exchange Server that could allow for arbitrary code execution. Microsoft Exchange Server is an enterprise-level email and collaboration platform developed by Microsoft that runs on Windows Server. Successful exploitation could allo…CISECURITY.ORG
15 MayOne email could be all it takes.Microsoft sounds the alarm on a critical Exchange zero-day, OpenAI and Mistral AI deal with fallout from a widening supply-chain attack campaign, and researchers uncover a thriving underground market for unlocking stolen iPhones. A stealthy macOS infostealer spreads through Click…THECYBERWIRE.COM
15 MayMicrosoft Exchange zero-day chain nets DEVCORE $200K at Pwn2OwnPwn2Own Berlin 2026 continued with another wave of successful zero-day demonstrations on Thursday, as security researchers earned $385,750 for 15 unique vulnerabilities targeting enterprise software, AI platforms, operating systems, and developer tools. The biggest payout of the …CYBERINSIDER.COM
15 MayExpired domain leads to supply chain attack on node-ipc npm packageA popular npm package called node-ipc has been compromised, with hackers publishing malicious versions that bundle credential stealing malware. The root cause of the compromise was an expired domain name that attackers managed to register in order to hijack a maintainer’s account…CSOONLINE.COM
15 MayCisco, Canvas, Microsoft, Exchange 0-Days, NPM Backdoors, GPT-5.5 and more... - SWN #581Cisco Catalyst, Canvas, Exchange 0-Days, BitLocker Bypass, Mini Shai Hulud, Node IPC, Patch Tuesday, GPT-5.5, Supply Chain Attacks, and More on the Security Weekly News Visit https://www.securityweekly.com/swn for all the latest episodes! Show Notes: https://securityweekly.com/sw…YOUTUBE.COM
15 MayPwn2Own Berlin 2026, Day Two: $385,750 more, Microsoft Exchange falls, and the running total crosses $900KDay two of Pwn2Own Berlin 2026 saw $385,750 earned for 15 zero-days, bringing the total to $908,750 and 39 vulnerabilities over two days. During the second day of Pwn2Own Berlin 2026, security researchers earned $385,750 after successfully demonstrating 15 unique zero-day vulnera…SECURITYAFFAIRS.COM
14 MayAmazon Quick Security Flaw Allowed Restricted Users to Access AI Chat AgentsA newly disclosed security flaw in Amazon’s AI-powered business intelligence platform has revealed how restricted users could quietly bypass controls and interact with AI chat agents, despite explicit administrative denial. The issue, discovered by Fog Security researcher Jason K…GBHACKERS.COM
14 MayGitLab Security Flaw Allows Cross-Site Scripting and Unauthenticated DoSGitLab has issued an urgent security update to neutralise a massive wave of vulnerabilities. Threat actors could exploit these newly disclosed flaws to silently hijack developer sessions or completely paralyze continuous integration pipelines with unauthenticated attacks. GitLab …GBHACKERS.COM
14 MayHackers Hijack HWMonitor to Sideload Malicious DLLHackers are once again exploiting user trust in legitimate software, this time abusing the popular CPUID HWMonitor utility to deliver a stealthy remote access trojan. The malicious archive mimics a legitimate installer, highlighting how trusted tools remain a powerful lure for in…GBHACKERS.COM
14 MayPoC Released for 18-Year-Old NGINX Flaw Allowing Remote Code ExecutionA critical vulnerability in NGINX’s source code, hidden since 2008, has finally been exposed, and a working exploit is already in the wild. Security researchers at depthfirst have publicly released a proof-of-concept (PoC) exploit demonstrating unauthenticated remote code e…GBHACKERS.COM
14 MayPackagist Warns: Update Composer Now After GitHub Actions Token LeakA sudden change in GitHub’s token format has triggered an unexpected security vulnerability in Composer, exposing sensitive authentication tokens in CI/CD logs and forcing Packagist to issue an urgent warning to PHP developers worldwide. The issue stems from a mismatch between Gi…GBHACKERS.COM
14 MayNew Exim BDAT GnuTLS Vulnerability Enables Code Execution AttacksA critical, stealthy vulnerability is lurking deep within Exim, the software powering a massive share of the world’s email infrastructure. Sitting exposed on the internet’s front lines, these message transfer agents are highly lucrative targets for ruthless threat act…GBHACKERS.COM
14 MayGentlemen RaaS Exploits Fortinet and Cisco Edge Devices for Initial AccessThe Gentlemen ransomware-as-a-service (RaaS) operation is turning exposed Fortinet and Cisco edge devices into a fast lane into enterprise networks and doing it at scale. What began as a rising RaaS brand in mid‑2025 has, by early 2026, evolved into one of the most active program…GBHACKERS.COM
14 MayAbrigo - 711,099 breached accountsIn April 2026, the fintech software company Abrigo was targeted in a "pay or leak" extortion attempt by the ShinyHunters group . Shortly after, data allegedly taken from the company's Salesforce instance was published publicly and contained over 700k unique email addresses belong…HAVEIBEENPWNED.COM
14 MayWhat CISOs need to land a board roleCybersecurity leaders often have complex relationships with their boards. Many boards lack cyber expertise, and CISOs can encounter roadblocks as a result when it comes to earning board approval. Other security leaders may not have a direct line to their board, or they may be vie…CSOONLINE.COM
14 MayDeepfake sextortion forces schools to remove student photos from websitesExperts are urging schools to take down identifiable photos of students, after AI deepfakes have led to sextortion cases at UK schools.MALWAREBYTES.COM
14 MayMy relationship status is “compromised.”This week, hosts of N2K CyberWire Maria Varmazis and Dave Bittner alongside …THECYBERWIRE.COM
14 MayCERN’s open source KiCad library gives the world 17,000 circuit board componentsCERN has released its complete KiCad component library under an open source license, making it available to hardware designers anywhere in the world. The library, maintained by CERN’s Design Office, contains more than 17,000 electronic components in the form of schematic sy…HELPNETSECURITY.COM
14 MayOver 70% of organizations hit by identity breachesAttackers rely on stolen credentials, compromised service accounts, and social engineering attacks targeting employees, according to Sophos’ The State of Identity Security 2026 survey. What do you estimate to be the overall cost to your organization to rectify the identity breach…HELPNETSECURITY.COM
14 MayMachine identities outnumber humans 109 to 1Organizations manage an average of 109 machine identities for every human identity. AI agents account for a growing share of those identities, with companies expecting AI agent growth of 85% over the next 12 months. Machine identities are projected to increase by 77%, and human i…HELPNETSECURITY.COM
14 MayWindows Zero-Days Expose BitLocker Bypasses And CTFMON Privilege EscalationAn anonymous cybersecurity researcher who disclosed three Microsoft Defender vulnerabilities has returned with two more zero-days involving a BitLocker bypass and a privilege escalation impacting Windows Collaborative Translation Framework (CTFMON). The security defects have been…THEHACKERNEWS.COM
14 MayMicrosoft turns Copilot Studio into an AI agent control centerThe Microsoft Copilot Studio April 2026 updates improve visibility and governance for admins and expand workflow capabilities for managing agents. Copilot surfaces agent status in the authoring experience, giving admins insight into each agent’s security and protection posture. C…HELPNETSECURITY.COM
14 MayNew Malware Framework Enables Screen Control and UAC BypassA sophisticated malware framework capable of screen control, browser artifact access, and User Account Control (UAC) bypass, highlighting how attackers are increasingly adapting open-source tools for real-world intrusions. The attack chain revealed a carefully staged operation de…GBHACKERS.COM
14 MayCanon MailSuite Security Flaw Allows Attackers to Execute Code RemotelyCanon has disclosed a critical security vulnerability in its GUARDIANWALL MailSuite product that could allow attackers to execute arbitrary code remotely, raising serious concerns for organizations relying on the platform for email security. The issue, officially announced on May…GBHACKERS.COM
14 MayHow AI Hallucinations Are Creating Real Security RisksAI hallucinations are introducing serious security risks into critical infrastructure decision-making by exploiting human trust through highly confident yet incorrect outputs. When an AI model lacks certainty, it doesn’t have a mechanism to recognize that. Instead, it generates t…THEHACKERNEWS.COM
14 MayChinese APT Exploits Microsoft Exchange to Breach Energy Sector NetworkChinese state-aligned hackers compromised a Microsoft Exchange server at a major energy firm. They repeatedly reused that same entry point to run a months‑long espionage operation, deploying the Deed RAT and Terndoor backdoors to maintain deep access across the network. The activ…GBHACKERS.COM
14 MayTeamPCP, BreachForums Launch $1K Supply-Chain Attack ContestA new cybercrime campaign is turning supply chain attacks into a public competition, as TeamPCP and BreachForums operators launch a $1,000 contest that encourages hackers to compromise open-source packages. The initiative, first highlighted by Dark Web Informer, signals an escala…GBHACKERS.COM
14 MayFlowerStorm phishing gang adopts virtual-machine obfuscation to evade email defensesA widely active phishing-as-a-service (PhaaS) operation known as FlowerStorm has begun using a browser-based virtual machine to conceal credential theft code, marking what researchers say is an escalation in phishing-kit sophistication that could make attacks harder for tradition…CSOONLINE.COM
14 MayFrontier AI models reap rapid discovery of security vulnerabilitiesSecurity teams have just a few months before AI-driven exploitation becomes the norm, researchers warn.CYBERSECURITYDIVE.COM
14 MayThreatsDay Bulletin: PAN-OS RCE, Mythos cURL Bug, AI Tokenizer Attacks, and 10+ StoriesEverything is still on fire. This week feels dumb in the worst way — bad links, weak checks, fake help desks, shady forum posts, and people turning supply chain attacks into some cursed little game for clout and cash. Half of it feels new. Half of it feels like crap we should hav…THEHACKERNEWS.COM
14 MayThe time of much patching is comingIn this week’s newsletter, Martin reflects on what the next iteration of AI tools means for vulnerability discovery and our ability to manage large-scale patch releases.TALOSINTELLIGENCE.COM
14 MayODNI taps officials to coordinate response to foreign election threatsDirector of National Intelligence Tulsi Gabbard has tapped two individuals to coordinate work across U.S. spy agencies to monitor threats to the 2026 elections, according to multiple sources familiar with the matter.THERECORD.MEDIA
14 MayRegional routing for AWS access portals: Implementing custom vanity domains for IAM Identity CenterAWS IAM Identity Center provides a web-based access portal that gives your workforce a single place to view their AWS accounts and applications. With the recent launch of IAM Identity Center multi-Region replication, customers can replicate their IAM Identity Center instance acro…AWS.AMAZON.COM
14 MayThe era of AI-powered attacks is here.Google says AI-powered cybercrime has gone industrial scale. Two new Windows zero-days emerge. Signal threatens to leave Canada over lawful access legislation. Pentagon-linked influence operations shift to paid ads. Linux admins scramble to patch a new root-level flaw. FamousSpar…THECYBERWIRE.COM
14 MayGoogle announces hackers are using AI to create zero days.Canvas pays hackers.THECYBERWIRE.COM
14 MayOpenAI asks macOS users to update after TanStack npm supply chain attackThe actions are being taken in light of an expanding supply chain campaign impacting the popular open-source library TanStack and additional npm and PyPI packages tied to several AI companies.THERECORD.MEDIA
14 May KEVMaximum Severity Cisco SD-WAN Bug Exploited in the WildThis is the second time this year a threat actor has leveraged a CVSS 10.0 vulnerability in Cisco's network control system.DARKREADING.COM
14 MayYou're not going to patch your way out of this - PSW #926This week: - New Yellowkey bitlocker bypass and what it means for you - Hackers can run you over with a robot lawnmower - FCC says new things about routers, again - Glitching with AI - almost no false positives - AI thought it was evil - DirtyFrag and the sad state of Linux LPEs …YOUTUBE.COM
14 MayBring out your dead: How agentic AI for cybersecurity helps you rid your cloud of forgotten, risky assetsTenable Hexa AI eliminates “zombie” cloud infrastructure, helping you reduce risk and make a “killing” on cost reduction. Key takeaways As AI accelerates cloud growth, zombie cloud assets multiply in your environment. You need agentic AI to prevent a cloud zombie apocalypse. Clou…TENABLE.COM
14 MayAI Just Hacked HardwareAn AI agent was used to autonomously execute a voltage fault injection attack against an ESP32 Secure Boot V1 system. It was given direct access to hardware interfaces and handled major parts of the attack chain, including tool configuration, exploit script generation, and firmwa…YOUTUBE.COM
14 MayThe First CVE Wave: Signs That AI-Assisted Vulnerability Discovery Is Reshaping Disclosure VolumesPublic CVE disclosure volumes are surging across major software suppliers and open source projects, and the evidence increasingly points to AI-assisted vulnerability discovery as the driving force.VULNCHECK.COM
14 MayOrBit (Re)turns: Tracking an open-source Linux rootkit across four years of forks and deploymentsExplore how OrBit, a two-stage malware, has changed over the last 4 years and why it matters for defenders. The post OrBit (Re)turns: Tracking an open-source Linux rootkit across four years of forks and deployments appeared first on Intezer .INTEZER.COM
13 MayCanvas Breach 'Deal' With ShinyHunters, AI Zero-Day Warning, Checkmarx Hit AgainCybersecurity Today examines a troubling set of new security developments affecting schools, software supply chains, and account security. Instructure says it reached an "agreement" with the ShinyHunters threat group after the massive Canvas breach that may have affected up to 27…CYBERSECURITYTODAY.LIBSYN.COM
13 MayResearchers open-source a Wi-Fi cyber range for security trainingWireless security training programs lean heavily on generic network labs, with Wi-Fi appearing as a checkbox alongside Bluetooth, Zigbee, and cellular. Hands-on environments dedicated to IEEE 802.11 are uncommon, even as Wi-Fi remains the default on-ramp to corporate networks and…HELPNETSECURITY.COM
13 MayRisky Business #837 -- GitHub Actions footgun claims TanStackOn this week’s show Patrick Gray, Adam Boileau and James Wilson discuss the week’s cybersecurity news. They cover: Mini Shai-Hulud and the TanStack compromise using Github Actions Instructure pays Canvas elearning platform data extortionists More Linux privilege escalation 0days!…RISKY.BIZ
13 MaySandyaa: Open-source autonomous security bug hunterSource code auditing has traditionally relied on static analyzers that flag long lists of potential issues, leaving engineers to sort bugs from noise. A new open-source project from offensive-security firm SecureLayer7 takes a different route, using LLMs to read a codebase, trace…HELPNETSECURITY.COM
13 MayClickFix Evolves Using Decade-Old Open-Source Python SOCKS5 ProxyA newly observed ClickFix campaign is pushing beyond simple user-triggered infections, introducing a more persistent and stealthy intrusion chain using PySoxy, a 10-year-old open-source Python SOCKS5 proxy. Unlike traditional ClickFix attacks that rely on a single PowerShell exec…GBHACKERS.COM
13 May KEV2026 CSO Award winners showcase business-enabling cyber innovationThe annual CSO Awards annually recognize security projects that demonstrate outstanding security leadership and business value. For this year’s program, CSO honors 64 security organizations whose hard work and innovative approaches have had a significant impact on how their enter…CSOONLINE.COM
13 MayGoogle entdeckt erstmals KI-basierten Zero-Day-ExploitWillkommen im neuen, KI-geschwängerten Bedrohungszeitalter. Gorodenkoff / Shutterstock Die Google Threat Intelligence Group (GTIG) warnt davor, dass kriminelle Hacker mittlerweile KI einsetzen – sowohl, um Schwachstellen aufzuspüren, als auch um anschließend Malware zu entwickeln…CSOONLINE.COM
13 MayNetSPI AI-powered Continuous Pentesting identifies high-impact vulnerabilitiesNetSPI launched AI-powered Continuous Pentesting offerings, designed to help organizations continuously identify, validate and reduce risk across dynamic external and cloud environments. Organizations are managing an expanding number of potential entry points as new internet-faci…HELPNETSECURITY.COM
13 MayReport: 4 in 10 UK Businesses Were Breached by Phishing Last Year43% of businesses in the UK reported a breach last year, with phishing driving the vast majority (85%) of these attacks, the Register reports. A survey by the British government found that attacks involving only phishing grew by six percent in 2025.KNOWBE4.COM
13 MayCISA’s AI SBOM guidance pushes software supply-chain oversight into new territoryThe US Cybersecurity and Infrastructure Security Agency (CISA) and its G7 cyber agency partners have released a list of minimum elements for an AI software bill of materials, a move that could help CISOs assess the security and provenance of AI systems entering enterprise environ…CSOONLINE.COM
13 MayBreaking things to keep them safe with Philippe LaulheretPhilippe shares his unique journey from French engineering school to the front lines of cybersecurity, explaining how his lifelong love for solving puzzles helps him uncover critical security flaws before they can be exploited.TALOSINTELLIGENCE.COM
13 MayClickFix finds a backup plan in PySoxy proxy chainsClickFix, a one-shot social engineering technique that tricks victims into executing malicious workflows disguised as fixes to technical issues in their systems, has got a persistence upgrade. In a one-off instance, ReliaQuest researchers have spotted an intrusion chain using sch…CSOONLINE.COM
13 MayMay 2026 Patch Tuesday: no zero-days but plenty to fixMay’s Patch Tuesday may not be the giant release many expected, but there are still plenty of important fixes that shouldn’t be ignored.MALWAREBYTES.COM
13 MayKDE gets over €1 million investment to strengthen security and core infrastructureEuropean governments and public institutions have been shifting away from proprietary software for years, and the financial infrastructure supporting open-source alternatives is growing to match. Germany’s Sovereign Tech Fund announced today that it is investing more than €…HELPNETSECURITY.COM
13 May KEVMay 2026 Patch Tuesday: 137 Vulnerabilities, No Zero-DaysMay 2026 Patch Tuesday: 137 Vulnerabilities, No Zero-Days Microsoft released its May 2026 Patch Tuesday security updates, resolving a total of 137 vulnerabilities across Windows and a broad range of Microsoft products and components. Unlike the previous several months, this relea…SOCRADAR.IO
13 MayMost Remediation Programs Never Confirm the Fix Actually WorkedSecurity teams have never had better visibility into their environments and never been worse at confirming what they fix stays fixed. Mandiant's M-Trends 2026 report puts the mean time to exploit at an estimated negative seven days. The Verizon 2025 DBIR puts median time to remed…THEHACKERNEWS.COM
13 MayMicrosoft Patches 138 Vulnerabilities, Including DNS and Netlogon RCE FlawsMicrosoft on Tuesday released patches for 138 security vulnerabilities spanning its product portfolio, although none of them have been listed as publicly known or under active attack. Of the 138 flaws, 30 are rated Critical, 104 are rated Important, three are rated Moderate, and …THEHACKERNEWS.COM
13 MayPalo Alto bets on identity security for autonomous AI with Idira launchPalo Alto Networks has launched Idira, a new identity security platform aimed at securing human users, machine identities, and AI agents amid the rising adoption of autonomous AI systems amongst enterprises. The company is positioning Idira as a next-generation identity security …CSOONLINE.COM
13 MaySecuring data centers in the agentic AI eraFind out how data center operators can protect critical building-management systems and cyber-physical infrastructure from AI-powered threats, as well as comply with evolving regulations. Key takeaways Data centers have evolved from simple storage hubs into critical national infr…TENABLE.COM
13 MayMicrosoft on pace to break annual vulnerability record as AI-driven patch wave takes holdFive months into 2026, Microsoft has already patched more than 500 vulnerabilities — although the exact monthly count varies depending on whether analysts include Edge, Chromium and fixes shipped earlier in the month.THERECORD.MEDIA
13 MayMicrosoft's MDASH AI System Finds 16 Windows Flaws Fixed in Patch TuesdayMicrosoft has unveiled a new multi-model artificial intelligence (AI)-driven system called MDASH to facilitate vulnerability discovery and remediation at scale, adding that it's being tested by some customers as part of a limited private preview. MDASH, short for multi-model agen…THEHACKERNEWS.COM
13 MayAzerbaijani Energy Firm Hit by Repeated Microsoft Exchange ExploitationA threat actor with affiliations to China has been linked to a "multi-wave intrusion" targeting an unnamed Azerbaijani oil and gas company between late December 2025 and late February 2026, marking an expansion of its targeting. The activity has been attributed by Bitdefender wit…THEHACKERNEWS.COM
13 MayWhat happens when China’s AI catches up to Mythos?The Trump-Xi summit opening in Beijing this week carries an agenda item unlike any in the history of US-China diplomacy: what to do about artificial intelligence that can autonomously find and exploit vulnerabilities in the world’s most critical software — and what happens when b…CSOONLINE.COM
13 MayHow to Identify and Exploit New VulnerabilitiesIn the ever-evolving world of cybersecurity, staying ahead of the curve is not just a goal—it’s a necessity. As new vulnerabilities emerge, the race to identify and mitigate them begins. But how do we, the guardians of the digital realm, rapidly pinpoint these threats as they bec…BLACKHILLSINFOSEC.COM
13 MayRapid7 Partner Academy: Driving Impact with Gold Stevie Award-Winning Partner Services CertificationsAt Rapid7, our commitment to our partners is built on the foundation of the PACT (Partnering with Accountability, Consistency, and Transparency) program. Central to this mission is the Rapid7 Partner Academy, which was recently honored with a Gold Stevie Award in the 2026 America…RAPID7.COM
13 MayMicrosoft Teams Vulnerability Allows Hackers to Perform Spoofing AttacksA newly discovered security flaw in Microsoft Teams for Android could allow attackers to carry out dangerous spoofing attacks. By exploiting improperly secured files, hackers can trick users and compromise sensitive corporate information. Microsoft has rapidly issued an official …GBHACKERS.COM
13 MayPatch Tuesday notes: Microsoft patches over a hundred flaws, none of which are zero-days.Foxconn confirms disruptive cyberattack as ransomware gang claims responsibility. Business news: Exaforce raises $125 million in Series B funding.THECYBERWIRE.COM
13 MayViral ‘RuView’ GitHub project uses Wi-Fi to track movement through wallsA new open-source project called “RuView” is drawing widespread attention online for demonstrating how ordinary Wi-Fi signals can be used to detect human movement, breathing patterns, and even body posture through walls without cameras or wearable devices. The project surged on G…CYBERINSIDER.COM
13 MayMicrosoft’s Patch Tuesday Update Targets 120 Security FlawsMicrosoft’s May Patch Tuesday fixes 120 flaws, including 31 remote code execution bugs, with no zero-days reported at release. The post Microsoft’s Patch Tuesday Update Targets 120 Security Flaws appeared first on TechRepublic .TECHREPUBLIC.COM
13 MayExaforce raises $125 million in Series B funding.Israeli security awareness training platform provider Frame Security emerges from stealth with $50 million.THECYBERWIRE.COM
13 MayDark Reading Celebrates 20 Years as a Leading Authority on Cybersecurity, Highlighting the People, Events, Ideas, and Technologies Shaping the Modern Risk LandscapeInforma TechTarget's flagship cybersecurity media brand launches a special content series to mark two decades as a trusted source for cybersecurity professionals.DARKREADING.COM
13 MayTables Turn on 'The Gentlemen' RaaS Gang With Data LeakAn OPSEC failure provides a window into what helped the ransomware group rise: a generous affiliate model, opportunistic TTPs, and an effective organizational structure.DARKREADING.COM
13 MayFired employee sought AI help to hide deletion of hosting firm’s customer dataThe apparent revenge deletion of US federal databases after the dismissal of twin brothers from an online hosting company is another reminder to IT and HR leaders that tough off-boarding procedures have to be implemented to prevent insider attacks. Destructive attacks either from…CSOONLINE.COM
13 MayBeyond Findings: Connecting Exploitable Risk to Cloud Context with Wiz and HackerOneSee proven, exploitable risk in the context of your full cloud environmentWIZ.IO
13 MayFragnesia: Linux Kernel Local Privilege Escalation via ESP-in-TCPA new page-cache corruption vulnerability in the Dirty Frag family enables unprivileged local attackers to achieve rootWIZ.IO
12 MayGoogle Warns Hackers Are Using AI to Build Working Zero-Day ExploitsArtificial intelligence has officially transitioned from an experimental hacking novelty into an industrial-scale weapon for cybercriminals. Google Threat Intelligence Group (GTIG) adversaries are now actively using generative AI models to discover vulnerabilities and engineer fu…GBHACKERS.COM
12 MayHEIDI: Free IDE security plugin for open-source vulnerability checksOpen-source dependencies make up a large percentage of the code in production applications, and most vulnerability checks still run late in the pipeline, inside CI/CD systems or after a release ships. Meterian is moving those checks earlier with HEIDI, a free plugin for Visual St…HELPNETSECURITY.COM
12 MayMagecart Hackers Exploit Google Tag Manager to Inject Credit Card SkimmersMagecart-style attackers are once again abusing trusted web services, this time weaponizing Google Tag Manager (GTM) to inject credit card skimmers into ecommerce websites stealthily. Because GTM is widely used and loaded from the trusted domain googletagmanager.com, malicious sc…GBHACKERS.COM
12 MayOpenAI Launches Daybreak for AI-Powered Vulnerability Detection and Patch ValidationOpenAI has launched Daybreak, a new cybersecurity initiative that brings together frontier artificial intelligence (AI) model capabilities and Codex Security to help organizations identify and patch vulnerabilities before attackers find a way in using the same issues. "Daybreak c…THEHACKERNEWS.COM
12 MayOpenAI Daybreak Automates Vulnerability Detection and PatchingThe relentless race against zero-day exploits and sophisticated cyberattacks requires a revolutionary approach to software security. Defenders are constantly overwhelmed by massive backlogs of alerts and the sheer volume of code requiring manual review. Enter OpenAI Daybreak, a f…GBHACKERS.COM
12 MayClaude Chrome Extension Flaw Lets Malicious Add-Ons Steal Gmail and Drive DataA critical vulnerability dubbed “ClaudeBleed” has compromised Anthropic’s trusted AI assistant, potentially turning it into a backdoor. This severe design flaw in the Claude Chrome extension allows malicious add-ons to hijack the AI secretly. Even extensions wit…GBHACKERS.COM
12 MayOpenAI’s Daybreak uses Codex Security to identify risky attack pathsOpenAI Daybreak is the company’s cybersecurity initiative focused on building AI-assisted software defense into the development process from the start. It combines OpenAI models, Codex Security, and cyber-focused GPT-5.5 variants to help organizations identify, validate, and prio…HELPNETSECURITY.COM
12 MayCISOs step into the AI spotlightServing in the military requires a precise, tactical mindset, and that’s exactly what Barry Hensley espoused during his 24 years in the US Army , where he rose to the rank of colonel. The military “is where you earn your stripes, showing your soldiers your willingness to jump int…CSOONLINE.COM
12 MayWhy Basic Security Practices Still Work - Rob Allen - ASW #382If you have to ditch your entire appsec strategy because you expect 2026 to bring more vulns more quickly, then you probably didn't have a good strategy in the first place. Rob Allen shares how the mentality of "assume breach" doesn't have to be a defeatist attitude and can inste…YOUTUBE.COM
12 MayDeveloper workstations are the new beachheadI spent the first week of April reading three separate threat intelligence reports that, on the surface, had nothing in common. One covered a North Korean campaign that had published over 1,700 malicious packages across five open-source ecosystems. Another detailed a malware oper…CSOONLINE.COM
12 MayWannaCry, the ransomware attack that changed the history of cybersecurityWannaCry showed how unpatched flaws and leaked cyber tools can cripple global systems, reshaping cybersecurity defenses worldwide. In memory of the day the digital world was shaken, but learned to fight back. The WannaCry ransomware attack represents one of the most significant e…SECURITYAFFAIRS.COM
12 MaySix new dnsmasq vulnerabilities open the door to DNS cache poisoning, local rootRecent disclosures have revealed that open-source networking tool dnsmasq is grappling with a serious set of vulnerabilities. The problems span memory safety and input validation, with researchers identifying heap buffer overflows, heap corruption, and code execution bugs among t…HELPNETSECURITY.COM
12 MayŠkoda confirms unauthorized access to its online shopCar manufacturer Škoda discovered that attackers had exploited a vulnerability in its online shop software and gained temporary unauthorized access to the system. What happened? After discovering the incident, the company took the shop offline as a precautionary measure, fixed th…HELPNETSECURITY.COM
12 MayOpen WebUI File Upload Vulnerability Enables 1-Click RCE AttackA critical, unpatched vulnerability is actively threatening Open WebUI users, turning a simple profile picture upload into a gateway for complete system compromise. Security researchers have publicly disclosed a severe stored Cross-Site Scripting (XSS) flaw that enables 1-click R…GBHACKERS.COM
12 MayFake Claude Code takes the IElevator to your browser secretsDevelopers looking for Anthropic’s increasingly popular Claude Code tool are now being lured into downloading malware. According to researchers at Ontinue, attackers are abusing a fake Claude Code installer to deliver a previously undocumented PowerShell payload. The malware is d…CSOONLINE.COM
12 MayGo fuzzing was missing half the toolkit. We forked the toolchain to fix it.Go’s native fuzzing is useful, but it stands far behind state-of-the-art tooling that the Rust, C, and C++ ecosystems offer with LibAFL and AFL++. Path constraints are hard to solve. Structured inputs usually need handmade parsing. It doesn’t even detect several common bug …TRAILOFBITS.COM
12 MayAttackers Combine ClickFix With PySoxy Proxying to Maintain PersistenceExploitation of open-source tools allows attackers to maintain persistent access after initial social engineering, warn ReliaQuest researchersINFOSECURITY-MAGAZINE.COM
12 MayCitrix moves secure access to a flexible, credit-based consumption modelCitrix has introduced Citrix Platform Flex, a secure access platform that combines software, management, and infrastructure to deliver managed desktops, enterprise browsing, and zero-trust access in a single offering. Built around workforce personas, Platform Flex replaces one-si…HELPNETSECURITY.COM
12 MayTop 10 Deep & Dark Web ForumsTop 10 Deep Web and Dark Web Forums in 2026 The top Deep Web and Dark Web Forums actively monitored in 2026 are XSS, Exploit.in, BHF, Dread, DarkForums, Altenen, CryptBB, Cracked, and DamageLib, based on how frequently they surface in threat intelligence investigations, court rec…SOCRADAR.IO
12 MayZoom Rooms and Workplace Flaws Expose Users to Elevated Access AttacksA newly disclosed batch of vulnerabilities in Zoom’s software suite could give attackers the leverage they need to hijack systems. Zoom has released critical security updates to patch three distinct flaws affecting its Windows and iOS applications. The most dangerous of the…GBHACKERS.COM
12 MayThreat Actors Abuse Vercel AI Tools to Mass-Produce Realistic Phishing SitesThreat actors are rapidly adopting generative AI platforms to scale phishing operations, and Vercel has emerged as a powerful enabler in this shift. Vercel is a cloud-based platform designed to help developers build and deploy modern web applications quickly. Its GenAI-powered to…GBHACKERS.COM
12 MaySAP Releases Patch for Critical SQL Injection Flaw in S/4HANAA severe vulnerability has struck the heart of enterprise resource planning systems this month, threatening organizations worldwide with potential data breaches. On May 12, 2026, the software giant released its monthly security patch update to address 15 newly discovered security…GBHACKERS.COM
12 MayOpenAI introduces Daybreak cyber platform, takes on Anthropic MythosOpenAI has unveiled Daybreak, its answer to Anthropic’s Claude Mythos, amid a growing market for frontier AI-powered cyber defense platforms. The initiative combines OpenAI’s large language models, Codex’s agentic capabilities, and integrations with the broader enterprise securit…CSOONLINE.COM
12 MayGoogle Says Hackers Used AI to Build Zero-Day ExploitGoogle says hackers used AI to help build a zero-day exploit targeting 2FA, raising concerns about AI-assisted hacking. The post Google Says Hackers Used AI to Build Zero-Day Exploit appeared first on TechRepublic .TECHREPUBLIC.COM
12 MayExaforce raises $125M Series B to build AI for catching and stopping cyberattacks as they happenThe round valued the three-year-old startup at $725 million.TECHCRUNCH.COM
12 MayThe world’s most “Dangerous” AI, Anthropic’s Mythos, found only one flaw in curlAnthropic’s AI found five vulnerabilities in curl, but only one low-severity issue proved to be a real vulnerability. In April, Anthropic made considerable noise announcing Mythos, a new artificial intelligence model described as so effective at identifying vulnerabilities in cod…SECURITYAFFAIRS.COM
12 MayMullvad shares workaround for Android 16 VPN leak that remains unfixedMullvad has warned that a recently disclosed Android 16 flaw can allow malicious applications to bypass VPN protections and leak a device’s real IP address, even when Android’s strictest VPN lockdown settings are enabled. The VPN provider says the issue impacts all VPN applicatio…CYBERINSIDER.COM
12 MayExaforce raises $125 million to respond to AI-powered attacksExaforce announced a $125 million Series B financing round, one of the largest ever in the emerging AI SOC space. The round includes participation from HarbourVest, Peak XV, Mayfield, Khosla Ventures, Seligman Ventures and AICONIC. The new capital will help Exaforce scale its AI-…HELPNETSECURITY.COM
12 MayAmazon Quick authorization bypass let users reach blocked AI chat agentsEnterprises running Amazon Quick, the AWS business intelligence and agentic AI service, rely on a feature called custom permissions to restrict who inside an account can use AI chat agents. Fog Security founder Jason Kao discovered that those restrictions were enforced only in th…HELPNETSECURITY.COM
12 MayGoogle launches new Android security feature to help uncover spyware attacksIntrusion Logging is a new part of Android’s Advanced Protection Mode, which aims to help protect human rights activists, journalists, and dissidents from government spyware attack and law enforcement forensic devices.TECHCRUNCH.COM
12 MayMistral AI SDK, TanStack Router hit in npm software supply chain attackThe TeamPCP threat group has pulled off another big supply chain attack which within a few hours this week was able to successfully compromise 170 Node Package Manager (npm) and PyPI packages. The attack affected the entire TanStack Router ecosystem (@tanstack) of 42 packages, a …CSOONLINE.COM
12 MayCritical Patches Issued for Microsoft Products, May 12, 2026Multiple vulnerabilities have been discovered in Microsoft products, the most severe of which could allow for remote code execution. Successful exploitation of the most severe of these vulnerabilities could result in an attacker gaining the same privileges as the logged-on user. …CISECURITY.ORG
12 MayMultiple Vulnerabilities in Apple Products Could Allow for Arbitrary Code ExecutionMultiple vulnerabilities have been discovered in Apple products, the most severe of which could allow for arbitrary code execution. Successful exploitation of the most severe of these vulnerabilities could allow for arbitrary code execution. Depending on the privileges associated…CISECURITY.ORG
12 MayMultiple Vulnerabilities in Adobe Products Could Allow for Arbitrary Code ExecutionMultiple vulnerabilities have been discovered in Adobe products, the most severe of which could allow for arbitrary code execution. Adobe After Effects is a digital effects, motion graphics, and compositing application. Adobe Commerce is a composable ecommerce solution that lets …CISECURITY.ORG
12 MayStop Chasing Individual CVEsMozilla shifted away from patching individual Firefox sandbox escape and JavaScript prototype vulnerabilities. Instead, they implemented an architectural change by freezing JavaScript prototypes. This move reduced entire classes of exploit paths rather than addressing each vulner…YOUTUBE.COM
12 May KEVWindows 11 security update fixes critical Bing and Azure flawsMicrosoft has released the May 2026 Patch Tuesday updates for Windows 11, fixing 97 security vulnerabilities across the Windows ecosystem. This month’s updates include fixes spanning Windows components, Microsoft Office, Azure services, SQL Server, SharePoint, Hyper-V, .NET, and …CYBERINSIDER.COM
12 MayMultiple Vulnerabilities in Fortinet Products Could Allow for Remote Code ExecutionMultiple vulnerabilities have been discovered in Fortinet products, the most severe of which could allow for remote code execution. * FortiAuthenticator is a centralized identity and access management (IAM) solution that secures network access by managing user identities, Multi-F…CISECURITY.ORG
12 MayHackers accessed BWH Hotels reservation system for monthsBWH Hotels says hackers accessed guest reservation data, including names and contacts, for over six months across multiple hotel brands. BWH Hotels disclosed a data breach, with threat actors having had access to guest reservation data for more than six months. The incident expos…SECURITYAFFAIRS.COM
12 MayAWS Security Agent full repository code scanning feature now available in previewToday, we’re excited to announce the preview release of full repository code review, a new capability in AWS Security Agent that performs deep, context-aware security analysis of your entire code base. AI-driven cybersecurity capabilities are advancing rapidly. AWS Security Agent…AWS.AMAZON.COM
12 May‘Mini Shai-Hulud’ malware compromises hundreds of open-source packages in sprawling supply-chain attackThe campaign hit major registries and hid behind legitimate-looking release signatures, showing how attackers can weaponize the software update process itself. The post ‘Mini Shai-Hulud’ malware compromises hundreds of open-source packages in sprawling supply-chain attack appeare…CYBERSCOOP.COM
12 MayIt's Patch Tuesday for Microsoft and Not a Zero-Day In SightIt's the first time in two years with no zero-days. But with 137 flaws to patch, including nine critical ones, admins still have plenty of work to do.DARKREADING.COM
12 MayAI-Written Exploits Are HereA reported AI-assisted exploit may be a preview of where cybercrime is heading next. In this clip, the hosts discuss claims that attackers used an LLM to help generate a Python exploit targeting a vulnerability tied to two-factor authentication in an open-source administration to…YOUTUBE.COM
12 MaySN 1078: DigiCert does it right - Hugging Face Under FireDigiCert's latest security mishap triggered not just a scramble behind the scenes, but a cascading crisis that briefly wiped trust from millions of Windows systems. Find out how a single support slip, followed by Microsoft's heavy-handed response, left critical infrastructures ex…TWIT.TV
12 MayIntroducing Wiz Audit History: Track Every Change Across your EnvironmentWiz Audit History is now GA, providing a continuous, cross-cloud timeline of changes to resource configurations and findings to accelerate incident response and simplify compliance.WIZ.IO
11 MayCanvas Breach Exposes 275M Accounts | AI Targets Water Systems | GM OnStar SettlementA massive cybersecurity week. On this episode of Cybersecurity Today, David Shipley breaks down the reported breach of Instructure's Canvas learning platform, where attacks linked to the ShinyHunters extortion group may have exposed data tied to up to 275 million user accounts ac…CYBERSECURITYTODAY.LIBSYN.COM
11 MayNew cPanel and WHM Vulnerabilities Expose Servers to Code Execution and DoS AttackscPanel and WebHost Manager (WHM) are critical administrative control panels used by hosting providers globally to manage servers, websites, and databases. Due to their widespread deployment, vulnerabilities in these platforms immediately become high-value targets for threat actor…GBHACKERS.COM
11 MayJDownloader Hack Spreads New Python RATThe official JDownloader website fell victim to a sophisticated supply-chain attack, resulting in malicious installers being distributed to users worldwide. Attackers exploited an unpatched vulnerability in the site’s content management system to redirect specific download …GBHACKERS.COM
11 MaySecurity teams are turning to AI to survive alert overloadThe World Economic Forum white paper “Empowering Defenders: AI for Cybersecurity” identified AI as the biggest driver of change in cybersecurity for 94% of survey respondents. The paper found that 77% of organizations already use AI in cybersecurity, with much of the activity foc…HELPNETSECURITY.COM
11 MaymacOS Malware Abuses Google Ads and Claude Shared Chats to Deliver PayloadsThreat actors are deploying a sophisticated malvertising campaign targeting macOS users by exploiting Google Ads and legitimate Anthropic Claude shared chats. Security researcher Berk Albayrak uncovered this novel attack chain on May 10, which distributes a variant of the MacSync…GBHACKERS.COM
11 MayODINI Malware Uses CPU Magnetic Signals to Exfiltrate Data from Air-Gapped SystemsAir-gapped systems and Faraday cages have long represented the gold standard for protecting critical infrastructure and sensitive military networks. However, a groundbreaking threat known as ODINI demonstrates that even these extreme isolation measures can be compromised. Researc…GBHACKERS.COM
11 MayRustinel: Open-source endpoint detection for Windows and LinuxOpen-source endpoint detection has long been split between Windows-focused tools built around Sysmon and Linux tools built around eBPF or auditd. Defenders running mixed environments have had to stitch together separate pipelines, separate rule sets, and separate maintenance burd…HELPNETSECURITY.COM
11 MayReview: Foundations of Cybersecurity, 2nd editionJason Andress has refreshed his introductory security text for No Starch Press. He writes in the introduction that the term security now extends past data center servers to cloud resources, mobile devices, the Internet of Things, and AI. About the author Jason Andress is an exper…HELPNETSECURITY.COM
11 MayWindows CreateFileW API Flaw Could Let Attackers Lock SMB Files at ScaleThe multi-billion-dollar ransomware defence industry operates on a fundamental assumption: to cause catastrophic operational damage, malicious actors must write corrupted data to a disk. However, a newly disclosed attack technique, GhostLock, completely invalidates this foundatio…GBHACKERS.COM
11 MayCrimenetwork Bust Reveals 22,000 Members and Over 100 Illicit VendorsLaw enforcement authorities have successfully dismantled the relaunched version of “Crimenetwork,” a prominent criminal online trading platform. A 35-year-old German citizen, suspected of operating the illicit platform, was apprehended at his residence in Mallorca, Sp…GBHACKERS.COM
11 MayShinyHunters Exploits Canvas LMS Free Teacher Accounts in New BreachIn early May 2026, ShinyHunters breached Instructure’s Canvas LMS by abusing the Free-For-Teacher (FFT) account program, triggering an active extortion campaign and exposing student and faculty data across thousands of schools worldwide. ShinyHunters claimed responsibility on 3 M…GBHACKERS.COM
11 MayMythos finds a curl vulnerabilitysubmitted by codeinabox to security 4 points | 1 comments https://daniel.haxx.se/blog/2026/05/11/mythos-finds-a-curl-vulnerability/ My personal conclusion can however not end up with anything else than that the big hype around this model so far was primarily marketing. I see no e…PROGRAMMING.DEV
11 May8 guiding principles for reskilling the SOC for agentic AIAt DXC Technology, global CISO Mike Baker has established one of the largest agentic security operation centers (SOCs) in the world. To upskill the workforce as part of this journey, he embedded experts from agentic SOC vendor 7AI within his security teams. When Damon McDougald ,…CSOONLINE.COM
11 MayThe scam economy has found its AI upgradeScam attempts continue to reach consumers via email, text messages, social media, online advertising, and phone calls. The volume of exposure has remained stable over the past year, with more than half of consumers encountering scam attempts at least monthly, according to the F-S…HELPNETSECURITY.COM
11 MayMicrosoft 365 Copilot Flaws Could Let Attackers Access Sensitive DataMicrosoft has disclosed a trio of critical information disclosure vulnerabilities affecting Microsoft 365 Copilot and Copilot Chat in Microsoft Edge. Released on May 7, 2026, these security flaws pose a substantial risk to enterprise data privacy and corporate confidentiality. If…GBHACKERS.COM
11 MayAI security is repeating endpoint security’s biggest mistakeThe security industry is experiencing déjà vu, and most teams haven’t recognized it yet. If you were in the trenches during the early 2000s, you remember the antivirus arms race. IT teams buried under signature updates. Configuration baselines checked obsessively. Patch cycles tr…CSOONLINE.COM
11 MayInstructure confirms Canvas user data exposed in cyberattackInstructure has confirmed that attackers gained unauthorized access to parts of its environment and exploited a vulnerability tied to the company’s Free for Teacher support ticket system. The company says Canvas is now fully operational and that core learning data, including cour…CYBERINSIDER.COM
11 MayYour Purple Team Isn't Purple — It's Just Red and Blue in the Same RoomDefending a network at 2 am looks a lot like this: an analyst copy-pasting a hash from a PDF into a SIEM query. A red team script is being rewritten by hand so the blue team can use it. A patch waiting on a change-approval window that's longer than the exploitation window itself.…THEHACKERNEWS.COM
11 MayPHP SOAP Extension Flaw Could Let Attackers Execute Code RemotelyRecently disclosed vulnerabilities in PHP, particularly within its widely used SOAP extension, have raised significant alarms across the cybersecurity community. Among the newly identified flaws is a high-severity vulnerability that could permit attackers to achieve Remote Code E…GBHACKERS.COM
11 MayMalicious Hugging Face model masquerading as OpenAI release hits 244K downloadsA malicious Hugging Face repository posing as an OpenAI release delivered infostealer malware to Windows systems and logged 244,000 downloads before being removed, raising fresh concerns about how enterprises source and validate AI models from public repositories. The repository,…CSOONLINE.COM
11 MayHackers Observed Using AI to Develop Zero-Day for the First TimeGoogle Threat Intelligence Group details how cybercriminals attempted to launch a campaign based around an AI-developed Zero-Day targeting open-source softwareINFOSECURITY-MAGAZINE.COM
11 MayHackers Use AI for Exploit Development, Attack AutomationCyber adversaries have long used AI, but now attackers are using large language models to develop exploits and orchestrate complex attacks.DARKREADING.COM
11 MayPolice take down relaunched criminal marketplace with 22,000 users, €3.6 million in revenueGerman authorities shut down a relaunched version of the criminal marketplace Crimenetwork and arrested its suspected operator. The domain seizure notice (Source: BKA) A special unit of the Spanish National Police arrested the suspected 35-year-old German operator at his residenc…HELPNETSECURITY.COM
11 Mayfsnotify Maintainer Access Change Sparks Supply Chain Security ConcernsA dispute over maintainer access in the widely used Go library fsnotify has triggered temporary supply chain concerns after contributors were removed from the project’s GitHub organization and recent releases came under scrutiny. While no evidence suggests that any version of fsn…GBHACKERS.COM
11 MayLyrie.ai Joins First Batch of Anthropic’s Cyber Verification ProgramDubai-founded OTT Cybersecurity LLC also unveils the Agent Trust Protocol (ATP), the first open cryptographic standard for AI agent identity, scope, and action verification — slated for IETF submission. OTT Cybersecurity LLC, the company behind Lyrie.ai, today announced two miles…CSOONLINE.COM
11 MayGoogle discovers weaponized zero-day exploits created with AIThe Google Threat Intelligence Group (GTIG) today released evidence of a zero-day exploit developed by a cybercriminal group with the help of AI. It marks the first time the security research group has identified what it believes to be an AI-crafted zero-day exploit in the wild. …CSOONLINE.COM
11 MayGTIG AI Threat Tracker: Adversaries Leverage AI for Vulnerability Exploitation, Augmented Operations, and Initial AccessExecutive Summary Since our February 2026 report on AI-related threat activity, Google Threat Intelligence Group (GTIG) has continued to track a maturing transition from nascent AI-enabled operations to the industrial-scale application of generative models within adversarial work…CLOUD.GOOGLE.COM
11 MayGoogle spotted an AI-developed zero-day before attackers could use itResearchers found artifacts in the code that proved AI was heavily involved. A prominent cybercrime group planned to exploit the zero-day en masse for financial gain. The post Google spotted an AI-developed zero-day before attackers could use it appeared first on CyberScoop .CYBERSCOOP.COM
11 MayGoogle researchers uncover criminal zero-day exploit likely built with AIGoogle’s threat intelligence researchers have linked a zero-day exploit to AI-assisted development by a criminal group. The exploit targeted a popular open-source web-based system administration tool. It allowed attackers to bypass two-factor authentication once they had va…HELPNETSECURITY.COM
11 MayWhy we use CAPTCHAs, (Mon, May 11th)A few months ago, I implemented Cloudflare&#;x26;#;39;s Turnstile CAPTCHA on some pages. The reason for implementing these CAPTCHAs is obvious: Bots make up a large percentage of traffic and affect site performance.
ISC.SANS.EDU
11 MayAI used to develop working zero-day exploit, researchers warnA report by GTIG shows threat groups are increasingly leveraging AI to scale attacks. The exploitation attempt was disclosed and patched, preventing a mass incident.CYBERSECURITYDIVE.COM
11 MayGoogle warns artificial intelligence is accelerating cyberattacks and zero-day exploitsGoogle says hackers now use AI to create exploits, automate attacks, evade defenses, and target AI supply chains at scale. Artificial intelligence is rapidly changing the cyber threat landscape, and a new report from the Google Cloud Threat Intelligence team highlights how attack…SECURITYAFFAIRS.COM
11 May'Dirty Frag' Exploit Poised to Blow Up on Enterprise Linux DistrosThe privilege escalation vulnerability, which is similar to other Linux flaws like Copy Fail and Dirty Pipe, may already be under limited exploitation.DARKREADING.COM
11 MayFinal Countdown: Last Chance to Join the Rapid7 Global Cybersecurity SummitThe Rapid7 2026 Global Cybersecurity Summit is just around the corner, and with it, a final opportunity to join the conversations shaping how security teams are adapting to a rapidly changing landscape. Over the past few weeks, we’ve shared a preview of what to expect, from the s…RAPID7.COM
11 MayHackers Used AI to Develop First Known Zero-Day 2FA Bypass for Mass ExploitationGoogle on Monday disclosed that it identified an unknown threat actor using a zero-day exploit that it said was likely developed with an artificial intelligence (AI) system, marking the first time the technology has been put to use in the wild in a malicious context for vulnerabi…THEHACKERNEWS.COM
11 MayIAM for MSSPs: The Hidden Risk of Blind Trust - Dustin Sachs - CSP #224Identity and access management is often sold as a technical problem, but real-world deployments tell a different story. For MSSPs managing access across multiple client environments, IAM becomes a test of trust, accountability, decision fatigue, and human behavior. In this episod…YOUTUBE.COM
11 MayRed Hat extends open source technology into spaceRed Hat and Voyager Technologies announced the successful deployment of Red Hat Enterprise Linux 10.1 and Red Hat Universal Base Image (UBI) to Voyager’s LEOcloud Space Edge IaaS Micro Datacenter aboard the International Space Station (ISS). This collaboration extends a container…HELPNETSECURITY.COM
11 MayIdentity security firm SailPoint discloses GitHub repository breachSailPoint disclosed a GitHub repository breach on April 20. The company contained the incident and said no customer data was affected. SailPoint is a cybersecurity company that provides identity security and identity governance solutions for enterprises. Its products help organiz…SECURITYAFFAIRS.COM
11 MayFCC Robocall Crackdown Raises Privacy Concerns Over Mandatory ID ChecksThe FCC’s proposed robocall crackdown could force carriers to verify customer identities, raising privacy concerns over anonymous phone use. The post FCC Robocall Crackdown Raises Privacy Concerns Over Mandatory ID Checks appeared first on TechRepublic .TECHREPUBLIC.COM
11 MayAI Isn’t Replacing CybersecurityThe speakers argue that AI in cybersecurity functions primarily as a force multiplier rather than a replacement. Experienced professionals can significantly increase their effectiveness using AI tools, but the technology is not yet replacing core human expertise. While AI has bee…YOUTUBE.COM
11 MayCalifornia hits GM with record $12.75M fine for selling driver location dataCalifornia Attorney General Rob Bonta and a coalition of state prosecutors have secured a $12.75 million settlement with General Motors over the automaker’s collection and sale of drivers’ location and behavior data. This marks the largest California Consumer Privacy Act (CCPA) p…CYBERINSIDER.COM
11 MayGoogle says cybercriminals used AI to develop zero-day exploitGoogle Threat Intelligence Group (GTIG) says it has identified what it believes is the first known case of cybercriminals using artificial intelligence to help develop a zero-day exploit intended for mass exploitation. According to Google, the exploit targeted a popular open-sour…CYBERINSIDER.COM
11 MayForeign routers get a longer lifeline.The FCC eases restrictions on foreign-made routers. Shiny Hunters hit Canvas and Zara. SailPoint discloses unauthorized access to its GitHub repositories. TrickMo Android banking malware has more tricks up its sleeve. Polish officials warn of increased targeting of ICS and public…THECYBERWIRE.COM
11 MayInside AD CS Escalation: Unpacking Advanced Misuse Techniques and ToolsUnit 42 analyzes AD CS exploitation through template misconfigurations and shadow credential misuse while offering behavioral detection for defenders. The post Inside AD CS Escalation: Unpacking Advanced Misuse Techniques and Tools appeared first on Unit 42 .UNIT42.PALOALTONETWORKS.COM
10 May KEVWeek in review: cPanel vulnerability actively exploited, DigiCert breach, LinkedIn job scamsHere’s an overview of some of last week’s most interesting news, articles, interviews and videos: Your work apps are quietly handing 19 data points to someone Office work in 2026 relies on mobile apps used alongside personal tools like banking and messaging. Ten widely used workp…HELPNETSECURITY.COM
10 MayOfficial JDownloader site served malware to Windows and Linux users between May 6 and May 7JDownloader website was hacked to distribute malicious Windows and Linux installers carrying a Python RAT between May 6–7, 2026. JDownloader official website was compromised in a supply chain attack that replaced legitimate Windows and Linux installers with malicious files betwee…SECURITYAFFAIRS.COM
10 MayNew cPanel vulnerabilities could allow file access and remote code executioncPanel fixed three flaws that could allow file reads, code execution, and privilege escalation. No active exploitation has been reported yet. cPanel has released security updates to fix three vulnerabilities affecting cPanel & WHM that could allow attackers to read files, exe…SECURITYAFFAIRS.COM
9 MayNVIDIA Confirms GeForce Data Breach Exposed Users’ Personal DataGFN Cloud Internet Services, operating as the regional NVIDIA GeForce NOW cloud gaming partner, GFN.AM has officially confirmed a significant data breach. The security incident exposed personal information of users registered on their streaming platform. While the company has now…GBHACKERS.COM
9 MayCybersecurity Today Month in Review: AI Coding Risks, Canvas Breach, QR Phishing SurgeThis week's panel dives into the cybersecurity stories that matter most for security leaders, IT teams, and anyone watching how AI is changing risk. Jim Love is joined by David Shipley (Beauceron Security), Laura Payne (White Tuque), and Jeff Williams (Contrast Security). Cyberse…CYBERSECURITYTODAY.LIBSYN.COM
9 MayVidar Infostealer Campaign Steals Passwords, Cookies, Crypto Wallets, and Device DataA highly evasive multi-stage malware campaign deploying the Vidar Infostealer. First discovered in late 2018 and built on the Arkei stealer source code, Vidar is notorious for aggressively harvesting user credentials, browser session cookies, cryptocurrency wallets, and detailed …GBHACKERS.COM
9 MayShinyHunters defaces Canvas portals during finals week.CISA orders Federal agencies to patch Ivanti zero-day by Sunday. Progress Software urges customers to patch critical MOVEit flaw.THECYBERWIRE.COM
8 MayBecome a millionaire by bug hunting on AndroidOver the past decade, Google has introduced a wide range of bug bounty programs for its software and services. The company has now announced that the reward for individuals who discover vulnerabilities in Android or the Chrome browser is being increased , bringing the maximum rew…CSOONLINE.COM
8 MayMeta allegedly made billions from scam advertising while online fraud explodes worldwide.In this special edition of Cybersecurity Today, David Shipley speaks with scam-fighting expert Erin West about the global fraud crisis, the rise of AI-powered scams, and why traditional law enforcement may be falling behind. Cybersecurity Today would like to thank Material Securi…CYBERSECURITYTODAY.LIBSYN.COM
8 MayNWHStealer Campaign Deploys Bun Loader, Anti-VM Evasion, and Encrypted C2A new distribution method for the NWHStealer infostealer that leverages the Bun JavaScript runtime, marking a significant evolution in the malware’s delivery infrastructure. The threat actors behind this Rust-based stealer are exploiting Bun’s relative newness and hig…GBHACKERS.COM
8 MayMultiple Critical Flaws Fixed in Next.js and React Server ComponentsVercel has released Next.js v16.2.6v16.2.6, fixing a large group of security flaws that affect modern web applications using Next.js and React Server Components. The update addresses high-, moderate-, and low-severity issues, including denial-of-service bugs, middleware bypasses,…GBHACKERS.COM
8 May423 Firefox Flaws Fixed as Browser Gains Support for Claude, Mythos, and MoreMozilla has successfully identified and patched 423 latent security vulnerabilities in Firefox using advanced artificial intelligence models, notably Claude Mythos Preview. Two weeks after initially announcing their AI-assisted security initiative, Firefox developers have shared …GBHACKERS.COM
8 MayMay 2026 Patch Tuesday forecast: AI starts driving security industry changesProject Glasswing. This is one of three major security industry changes I’ll cover today. The Anthropic Mythos vulnerability discovery model has already proven to be game changing in its ability to identify new vulnerabilities in software. Many of these vulnerabilities have exist…HELPNETSECURITY.COM
8 MayMental health apps are collecting more than emotional conversationsPeople use mental health apps to talk about depression, trauma and suicidal thoughts in moments they may not share with anyone else. Many users likely assume those conversations carry protections similar to therapy sessions. In reality, mental health apps operate without the same…HELPNETSECURITY.COM
8 MayProduct showcase: NetGuard open-source firewall for AndroidNetGuard is a free, open-source firewall for Android phones and tablets that provides users with a simple way to block internet access. Android does not allow VPN services to be chained, so the app uses the Android VPN service to route all internet traffic through itself. NetGuar…HELPNETSECURITY.COM
8 MaySnyk integrates Claude to advance AI-native application securitySnyk has announced it is leveraging Anthropic’s Claude models to advance software security. Snyk has integrated Claude into the Snyk AI Security Platform, enabling automated vulnerability discovery, prioritization, and developer-ready fixes across code, dependencies, containers, …HELPNETSECURITY.COM
8 MayFake Moustache Fools Age Checks, Sparks Online Safety Act FearsA critical gaps in age verification systems introduced under the Online Safety Act, with children easily bypassing safeguards using simple tricks including drawing fake facial hair to appear older on camera. The Online Safety Act, which came into force in July 2025, was designed …GBHACKERS.COM
8 MayTrellix Investigates RansomHouse Breach Claims Involving Source Code RepositoryLeading cybersecurity firm Trellix is actively investigating a potential security incident following claims made by the RansomHouse extortion group. The threat actors recently listed Trellix on their dark web leak site, alleging a successful cyberattack against the prominent secu…GBHACKERS.COM
8 MayPen tests show AI security flaws far more severe than legacy software bugsPenetration tests of AI-based systems are revealing a greater percentage of high-risk flaws than those discovered in legacy systems. Security consultancy Cobalt’s annual State of Pentesting Report reveals that 32% of all AI and large language model (LLM) findings are rated as hig…CSOONLINE.COM
8 MayHelping North Korean IT remote workers is becoming a fast track to prisonTwo U.S. nationals were sentenced to 18 months in prison for operating “laptop farms” that helped North Korean IT workers gain employment at nearly 70 American companies, generating more than $1.2 million for Pyongyang’s government. Although Matthew Issac Knoot of Nashville, Tenn…HELPNETSECURITY.COM
8 MayNew Linux PamDOORa Backdoor Uses PAM Modules to Steal SSH CredentialsCybersecurity researchers have disclosed details of a new Linux backdoor named PamDOORa that's being advertised on the Rehub Russian cybercrime forum for $1,600 by a threat actor called "darkworm." The backdoor is designed as a Pluggable Authentication Module (PAM)-based post-exp…THEHACKERNEWS.COM
8 MayCline Kanban WebSocket Vulnerability Enables Malicious Sites to Take Over AI Coding AgentsCline, a widely adopted open-source AI coding agent, has recently patched a severe vulnerability in its local Kanban server. Trusted by developers with deep access to source code, cloud credentials, and terminals, Cline automates complex coding tasks. However, researchers from Oa…GBHACKERS.COM
8 MayClaude in Chrome is taking orders from the wrong extensionsAnthropic Claude’s Chrome browser extension, known as Claude in Chrome, has a bug that can allow other malicious extensions to hijack it, compromising trusted AI workflows. Researchers at LayerX Security have warned that Claude’s overly trusted browser communication flows can be …CSOONLINE.COM
8 MayDirty Frag: A new Linux privilege escalation vulnerability is already in the wildDirty Frag: unpatched Linux kernel flaw grants root access on Ubuntu, RHEL and Fedora. A working exploit is already public. Security researchers have disclosed a new unpatched vulnerability in the Linux kernel, code-named Dirty Frag, that allows an unprivileged local user to gain…SECURITYAFFAIRS.COM
8 MayFrom Cyberwar to Cognitive Warfare: The Geopolitical Impact on Cybersecurity in AfricaWe’ve long defined cybersecurity as the technical discipline of protecting networks, data and systems. But when viewed through a geopolitical lens, then this definition is no longer sufficient. What we are dealing with today goes beyond protecting organisational data, to protecti…KNOWBE4.COM
8 MayPam Backdoor Targets Linux Systems to Steal SSH CredentialsA newly observed Linux backdoor technique, dubbed Pam, is exploiting the flexibility of Pluggable Authentication Modules (PAM) to capture SSH credentials and maintain persistence on compromised systems stealthily. Since its introduction in 1991 by Linus Torvalds, Linux has been d…GBHACKERS.COM
8 MayZero Chaos: Scaling Detection Engineering at the Speed of Software, with Detection As CodeEvery engineering team in your organization ships code through a pipeline. They branch, test, review, and deploy. If something breaks, they roll back. If someone asks "what changed?", the answer is in the commit history. This isn't heroic discipline to process; it's just how soft…RAPID7.COM
8 MayMFA Alone Won’t Save YouRob Allen describes a model where SaaS applications like Office 365, GitHub, or Salesforce only accept connections from approved IP addresses routed through a trusted app or secure tunnel. That means stolen credentials alone may no longer be enough for attackers. Even successful …YOUTUBE.COM
8 MayShinyHunters defaces Canvas portals during finals week.CISA orders Federal agencies to patch Ivanti zero-day by Sunday. Sri Lankan police shut down scam center.THECYBERWIRE.COM
8 MayMultiple universities forced to reschedule final exams after Canvas cyber incidentOn Thursday, dozens of students took to social media to say they saw a message from a cybercriminal group as they navigated through Canvas, an educational platform created by Instructure that hosts teaching materials, tests, readings and more.THERECORD.MEDIA
8 MayApple and Meta warn Canada’s Bill C-22 forces encryption backdoorsApple and Meta are publicly opposing portions of Canada’s proposed lawful access legislation, warning that Bill C-22 could weaken encryption protections, introduce systemic cybersecurity risks, and force technology companies to facilitate government surveillance capabilities. The…CYBERINSIDER.COM
8 MayInsider Betting on PolymarketInsider trading is rife on Polymarket: Analysis by the Anti-Corruption Data Collective, a non-profit research and advocacy group, found that long-shot bets—defined as wagers of $2,500 or more at odds of 35 percent or less—on the platform had an average win rate of a…SCHNEIER.COM
8 May KEVThe four-day race you don’t want to be in.CISA orders rapid patching of actively exploited Ivanti zero-day. Canvas gets hacked during finals week. Dirty Frag is a new Linux zero-day. Researchers document a serious Claude Chrome extension bug. Meta ends Instagram encryption. PCPJack malware clean house before moving in. A…THECYBERWIRE.COM
8 MayCanvas, Shai-Hulud, QuasarRat, 0Days, Anthropic, Aaran Leyland, and EU Compliance! - SWN #579Canvas, Shai-Hulud, QuasarRat, 0Days, Anthropic, Aaran Leyland, and EU Compliance and more! Visit https://www.securityweekly.com/swn for all the latest episodes! Show Notes: https://securityweekly.com/swn-579YOUTUBE.COM
8 MayA Framework for AI Threat ReadinessAI models now find and exploit zero-days autonomously. This 4-pillar framework accelerates patching, analysis, and threat response.WIZ.IO
7 MayMirai-Based xlabs_v1 Botnet Exploits ADB to Hijack IoT Devices for DDoS AttacksCybersecurity researchers have exposed a new Mirai-derived botnet that self-identifies as xlabs_v1 and targets internet-exposed devices running Android Debug Bridge (ADB) to enlist them in a network capable of carrying out distributed denial-of-service (DDoS) attacks. Hunt.io, wh…THEHACKERNEWS.COM
7 MayUS government agency to safety test frontier AI models before releaseThe Center for AI Standards and Innovation (CAISI), a division of the US Department of Commerce, has signed agreements with Google DeepMind, Microsoft, and xAI that would give the agency the ability to vet AI models from these organizations and others prior to their being made pu…CSOONLINE.COM
7 Mayvm2 Node.js Library Vulnerabilities Enable Sandbox Escape and Arbitrary Code ExecutionA dozen critical security vulnerabilities have been disclosed in the vm2 Node.js library that could be exploited by bad actors to break out of the sandbox and execute arbitrary code on susceptible systems. vm2 is an open-source library used to run untrusted JavaScript code inside…THEHACKERNEWS.COM
7 MayCybercriminals Exploit Microsoft Teams to Phish Login Credentials and Bypass MFAIranian state-sponsored threat actors linked to MuddyWater (Seedworm) have been caught hiding behind the Chaos ransomware brand to conduct sophisticated espionage operations, using Microsoft Teams as a phishing vector to steal credentials and manipulate multi-factor authenticatio…GBHACKERS.COM
7 MayDeepFake it till you make it.This week, hosts of N2K CyberWire Maria Varmazis and Dave Bittner alongside …THECYBERWIRE.COM
7 MayOpen-source MCP server monitoring for Python appsPythonic Model Context Protocol servers handle tool calls, session events, module imports, and subprocess activity. BlueRock has released MCP Python Hooks, an open source runtime sensor that gives developers a way to capture those signals without modifying application code. What …HELPNETSECURITY.COM
7 MayCritical vm2 Node.js Library Flaws Enable Arbitrary Code Execution AttacksMultiple critical sandbox-escape vulnerabilities have been disclosed in vm2, one of the most widely used Node.js sandboxing libraries, allowing attackers to escape the isolated execution environment and run arbitrary commands directly on the host system. Eleven advisories were pu…GBHACKERS.COM
7 MayUAT-8302 Targets Government Agencies With Custom Malware and Open-Source ToolsA new China-linked hacking group, tracked as UAT-8302, that is using custom malware and open-source tools to spy on government organizations in South America and southeastern Europe. The campaign focuses on long-term access and data theft, combining advanced backdoors like NetDra…GBHACKERS.COM
7 MayHackers Exploit Google Ads to Steal GoDaddy ManageWP LoginsHackers are abusing Google Ads to steal GoDaddy ManageWP credentials by placing a look‑alike phishing ad above the legitimate ManageWP result and proxying victims’ logins in real time via an adversary‑in‑the‑middle (AiTM) setup. The attackers purchase a sponsored Google ads that …GBHACKERS.COM
7 MayTen years later, has the GDPR fulfilled its purpose?This year marks the 10th anniversary of the EU’s adoption of the General Data Protection Regulation , which became mandatory for all companies beginning on May 25, 2018. The aim of the GDPR was simple, but important: to improve individuals’ control over their personal data. This …CSOONLINE.COM
7 MayResearchers Spot Uptick in Use of Vercel for Phishing CampaignsCofense has warned of a “significant” increase in phishing campaigns abusing Vercel platformINFOSECURITY-MAGAZINE.COM
7 MayCallPhantom Android scam reached 7.3 million downloads on Google PlayScams targeting Android users in India and across the Asia-Pacific region have grown around a long-standing curiosity gap: the desire to look up call records tied to a phone number. A cluster of 28 fraudulent apps on Google Play exploited that gap and pulled in more than 7.3 mill…HELPNETSECURITY.COM
7 MayScammers Exploit Disposable VoIP Numbers to Bypass Reputation BlockingNew tactics used by threat actors who embed phone numbers in scam emails as a key indicator of compromise (IOC), revealing how attackers exploit VoIP infrastructure to evade detection and scale fraud operations. Telephone-oriented attack delivery (TOAD) remains a dominant phishin…GBHACKERS.COM
7 MayCISOs: Align cyber risk communication with boardroom psychologyBy now, executive boards across industries understand that cyberattacks can be costly. What they often lack, however, is a clear view of which risks pose the biggest threat to their business and why certain investments need to rise to the top. Many security leaders lose traction …CSOONLINE.COM
7 MayThreatsDay Bulletin: Edge Plaintext Passwords, ICS 0-Days, Patch-or-Die Alerts and 25+ New StoriesBad week. Turns out the easiest way to get hacked in 2026 is still the same old garbage: shady packages, fake apps, forgotten DNS junk, scam ads, and stolen logins getting dumped into Discord channels like it’s normal. Some of these attack chains don’t even feel sophisticated any…THEHACKERNEWS.COM
7 MayClaude and SpaceX Join Forces to Enhance Large-Scale Compute CapacityAnthropic has officially announced a massive strategic partnership with SpaceX to expand its computing capabilities significantly. This collaboration aims to provide the necessary infrastructure to scale up the Claude artificial intelligence ecosystem. By securing dedicated compu…GBHACKERS.COM
7 MaySpring Vulnerabilities Open Door to Arbitrary File Access and GCP Secret LeaksSecurity researchers have identified four new vulnerabilities in the Spring Cloud Config Server, ranging from medium to critical severity. These newly disclosed flaws could allow attackers to access arbitrary files, leak Google Cloud Platform (GCP) secrets, and manipulate system …GBHACKERS.COM
7 MayThe AI-vs-AI battle is already happening. Watch it live at EXPOSURE 2026.Don’t singularly focus on the speed of AI attacks. You must also prepare for the shift AI is bringing to the threat landscape. Join Tenable at EXPOSURE 2026 to witness a live AI-vs-AI battle and get clarity to defend your organization against next-generation autonomous threats. K…TENABLE.COM
7 MayIf a fake moustache can fool age checks, is the Online Safety Act working?A UK report finds some progress since the Act came into force, but widespread workarounds, ongoing harm, and unresolved privacy concerns suggest the impact is still limited.MALWAREBYTES.COM
7 MayExploits and vulnerabilities in Q1 2026This report provides statistical data on published vulnerabilities and exploits we researched during Q1 2026. It also includes summary data on the use of C2 frameworks in APT attacks.SECURELIST.COM
7 MayOne House Democrat is pressing Commerce on the government’s spyware useRep. Summer Lee’s letter, first reported by CyberScoop, follows ICE confirmation of using spyware and news of a Trump ally becoming NSO Group’s executive chairman. The post One House Democrat is pressing Commerce on the government’s spyware use appeared first on CyberScoop .CYBERSCOOP.COM
7 MayHow Cloudflare responded to the “Copy Fail” Linux vulnerabilityWhen a critical Linux kernel privilege escalation was publicly disclosed, Cloudflare's security and engineering teams detected, investigated, and mitigated the threat across our global fleet, confirming zero customer impact and no malicious exploitation.CLOUDFLARE.COM
7 MayWhy Security in 2026 Requires Continuous Threat and Exposure Management (CTEM) at ScaleLet's be honest, the patching window just shrank to something no practitioner or organization can keep up with. Organizations now need to operate in an environment that must assume breach, which means fundamentals like attack surface management, micro-segmentation, identity manag…RAPID7.COM
7 MayBusinesses hide vast majority of ransomware attacks, report findsThe security firm BlackFog said the number of disclosed incidents it tracked in Q1 was roughly one-tenth of the number of undisclosed incidents.CYBERSECURITYDIVE.COM
7 MayPalo Alto Networks warns state-linked cluster behind zero-day exploitationA patch for the flaw, which hackers began targeting in early April, won’t be ready for another week.CYBERSECURITYDIVE.COM
7 MayCisco patches high-severity flaws enabling SSRF, code execution attacksCisco fixed several high‑severity flaws in its enterprise products, including SSRF bugs in Unity Connection that could enable code execution or service disruption. Cisco released patches for multiple high‑severity vulnerabilities affecting its enterprise products. Successful expl…SECURITYAFFAIRS.COM
7 MayMultiple Vulnerabilities in Mozilla Products Could Allow for Arbitrary Code ExecutionMultiple vulnerabilities have been discovered in Mozilla products, the most severe of which could allow for arbitrary code execution. Mozilla Firefox is a web browser used to access the Internet. Mozilla Firefox ESR is a version of the web browser intended to be deployed in large…CISECURITY.ORG
7 MayPCPJack Credential Stealer Exploits 5 CVEs to Spread Worm-Like Across Cloud SystemsCybersecurity researchers have disclosed details of a new credential theft framework dubbed PCPJack that targets exposed cloud infrastructure and ousts any artifacts linked to TeamPCP from the environments. "The toolset harvests credentials from cloud, container, developer, produ…THEHACKERNEWS.COM
7 MayICYMI: April 2026 @AWS SecurityRead all about the latest AWS security features, compliance updates, and hands-on resources in our new, monthly digest posts. You’ll find expert blog posts, new service capabilities, code samples, and workshops. AWS Security Blog posts This month’s AWS Security Blog posts covered…AWS.AMAZON.COM
7 MayLinkedIn illegally blocking free accounts from seeing ‘who’s viewed your profile’ data, group allegesA LinkedIn feature that allows paid subscribers to view a list of visitors to their profile should be made available to all EU users free of charge to comply with the region’s General Data Protection Regulation (GDPR), a legal complaint launched by the None of Your Business (NOYB…CSOONLINE.COM
7 MayGetting Rid of Your VPN - Rob Allen - PSW #925Rob Allen from Threatlocker joins us to discuss the risks associated with VPN appliances and how to implement better security solutions that don't leave you hanging out on the open Internet. The interview segment is sponsored by ThreatLocker. Visit https://securityweekly.com/thre…YOUTUBE.COM
7 May KEVIvanti customers confront yet another actively exploited zero-dayAttackers are hitting a frequent target in the network edge space, intruding victim networks through a defect in a widely used mobile endpoint security product. The post Ivanti customers confront yet another actively exploited zero-day appeared first on CyberScoop .CYBERSCOOP.COM
7 MayRapid7 and OpenAI: Helping Defenders Move at Machine SpeedWade Woolwine is Senior Director, Product Security at Rapid7. Announcing OpenAI's Trusted Access for Cyber program CIOs and CISOs are telling us the same thing in different ways: Advances in frontier AI are accelerating the threat environment and putting pressure on security oper…RAPID7.COM
6 MayWeekly Update 502Presently sponsored by: Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite It's a fascinating display of leverage: the ShinyHunters folks, with very limited resources and experience (their demographic will…TROYHUNT.COM
6 MayZero-Auth Vulnerability Enables Cross-Tenant Access at DoD ContractorA severe authorization vulnerability was recently discovered in Schemata, an AI-powered virtual training platform serving the United States Department of Defense. Security researcher Alex Schapiro, utilizing the open-source AI hacking agent Strix, identified a critical lack of AP…GBHACKERS.COM
6 MayMalicious OpenClaw Skill Targets Agentic AI Workflows to Deploy RATs and StealersOpenClaw’s agent “skill” ecosystem to deliver both Remcos RAT and a cross‑platform stealer called GhostLoader by hiding malware inside a deceptive DeepSeek integration called “DeepSeek‑Claw.” The campaign shows how agentic AI workflows with high local privileges can be quietly hi…GBHACKERS.COM
6 MayRansomware Gangs Escalate Attacks on Aviation and Aerospace SectorRansomware and data extortion groups are increasingly targeting the aviation and aerospace sector, exploiting interconnected systems, shared platforms, and identity-based access models to cause operational disruption and data compromise. Cyber risk across aviation has shifted bey…GBHACKERS.COM
6 MayRisky Business #836 -- You can't patch the bugpocalypseOn this week’s show, Patrick Gray and James Wilson are joined by special guest co-host Brad Arkin. They discuss the week’s cybersecurity news, including: The US Government says we just have to patch faster, but… Bugs in cPanel, MoveIt and all Linux distributions this week show th…RISKY.BIZ
6 MayRussia’s Forest Blizzard Is Abusing Home + Small Office Routers for Cred TheftThis week on the Microsoft Threat Intelligence Podcast, host Sherrod DeGrippo speaks with Danny Adamitis, Distinguished Engineer at Lumen Technologies’ Black Lotus Labs who break down how the Russian state-linked threat actor Forest Blizzard is exploiting home and small offi…THECYBERWIRE.COM
6 MayProofpoint Establishes Innovation Precedent for Source-Agnostic Modern Enterprise InvestigationsPROOFPOINT.COM
6 MayWindows Phone Link Exploited by CloudZ RAT to Steal Credentials and OTPsCybersecurity researchers have disclosed details of an intrusion that involved the use of a CloudZ remote access tool (RAT) and a previous undocumented plugin dubbed Pheno with the aim of facilitating credential theft. "According to the functionalities of the CloudZ RAT and Pheno…THEHACKERNEWS.COM
6 MaySalesforce Marketing Cloud Vulnerability Exposes Email Data RiskSalesforce Marketing Cloud (SFMC) recently patched a cluster of high‑impact vulnerabilities that could have allowed attackers to read and enumerate marketing emails and subscriber data across tenants, including Fortune 500 organizations. Modern enterprises rely on centralised mar…GBHACKERS.COM
6 MayPoisoned truth: The quiet security threat inside enterprise AIAs enterprises rush to deploy internal LLMs, AI copilots, and autonomous agents, most security conversations focus on familiar threats : prompt injection, jailbreaks, model abuse, and data exfiltration. But some security leaders argue a quieter risk deserves far more attention: w…CSOONLINE.COM
6 MayTrain like you fight: Why cyber operations teams need no-notice drillsSt. Michael’s Hospital in Toronto recently executed a full Code Orange simulation: A mass casualty emergency protocol requiring the activation of every clinical and operational team across the hospital. As a Level 1 trauma centre, it conducts large-scale exercises involving teams…CSOONLINE.COM
6 MayTeach to Sell and Two Interviews from RSAC 2026 from Dropzone AI and Microsoft - BSW #446As security leaders, we are continuously selling, maybe not as traditional sales folks, but as selling security across the organization. Whether you’re closing client deals, leading a team, running a business, or simply wanting your voice to be heard by other executives or the bo…YOUTUBE.COM
6 MayCloudZ RAT Exploits Microsoft Phone Link to Steal SMS OTPsCloudZ is a new modular remote access trojan that abuses Microsoft’s built‑in Phone Link feature to steal SMS one‑time passwords (OTPs) and other mobile notifications directly from Windows PCs, without infecting the phone itself. Microsoft Phone Link (formerly “Your Phone”) is in…GBHACKERS.COM
6 MayIntel 471 speeds threat hunting and remediation with Retroactive Threat DetectionsIntel 471 has announced Retroactive Threat Detections (RTD), a new capability within its Verity471 platform. RTD helps security teams quickly understand the impact of new threats on their environments. This transforms static intelligence reports into actionable answers within min…HELPNETSECURITY.COM
6 MayUiPath adds agentic AI capabilities to Automation Suite for government agenciesUiPath has announced the release of agentic AI capabilities on UiPath Automation Suite. The Automation Suite updates help government agencies and regulated industries accelerate agentic AI and automation adoption and are designed to address strict data sovereignty and compliance …HELPNETSECURITY.COM
6 MayNew Relic advances AI observability with new intelligence layerNew Relic has announced New Relic Knowledge, a new platform capability that integrates telemetry and knowledge sources to enhance issue detection and resolution. By combining real-time telemetry with historical incident data, system changes, and deep operational context, New Reli…HELPNETSECURITY.COM
6 MayServiceNow strengthens enterprise AI security with Autonomous Security & Risk platformServiceNow has launched Autonomous Security & Risk to govern every AI agent, identity, and connected asset. Armis delivers continuous asset intelligence across code, IT, OT, IoT, and connected assets, while Veza provides fine-grained visibility, intelligence, and governance …HELPNETSECURITY.COM
6 MayTaiwan High Speed Rail Hit by Spoofing Attack That Stops Three TrainsDuring the recent Qingming Festival holiday, the Taiwan High Speed Rail (THSR) experienced a severe cybersecurity incident that disrupted major transit operations. Three trains were suddenly forced into emergency stops, causing a 48-minute delay for passengers. Authorities have n…GBHACKERS.COM
6 MayNew malware turns Linux systems into P2P attack networksAttackers have found a new way to turn Linux systems into stealthy supply chain distribution hubs that are resistant to takedowns. Researchers from Trend Micro have disclosed a new malware framework, dubbed Quasar Linux or QLNX, describing it as a modular Linux remote access troj…CSOONLINE.COM
6 MayAttackers Continue to Pose as Help Desks in Social Engineering AttacksResearchers at Google’s Threat Intelligence Group (GTIG) are tracking a new threat actor that’s impersonating help desks to trick users into installing malware. The threat actor, which GTIG tracks as “UNC6692,” begins by sending a large volume of spam emails to the victim, then i…KNOWBE4.COM
6 MayPhishing Attack Weaponizes Calendar Invites to Steal Login CredentialsA new large-scale phishing campaign is abusing fake event invitations to compromise U.S. organizations, combining credential theft, OTP interception, and the deployment of remote monitoring and management (RMM) tools in a single operation. The campaign stands out because it blend…GBHACKERS.COM
6 MayMassive DDoS Attack Generates 2.45 Billion Requests Using 1.2 Million IP AddressesA distributed denial-of-service attack targeted a major user-generated content platform, generating an astonishing 2.45 billion malicious requests in just 5 hours. Security provider DataDome successfully intercepted the assault in real time, ensuring legitimate users experienced …GBHACKERS.COM
6 MayFEMITBOT Network Exploits Telegram Mini Apps to Spread Crypto Scams and Android MalwareA large-scale fraud and malware operation called FEMITBOT that abuses Telegram Mini Apps to steal cryptocurrency and infect Android devices. The campaign shows how trusted in-app web experiences can be turned into powerful tools for social engineering and credential theft. Telegr…GBHACKERS.COM
6 MayAnthropic’s CEO warns the “moment of danger” is real. But most are looking in the wrong place.Anthropic CEO Dario Amodei warns that AI’s rapid evolution is outpacing safety frameworks. Learn why the pace of vulnerability discovery isn't the real problem, why exposure management is now a strategic necessity, and how it can help you prioritize and remediate at scale. Key ta…TENABLE.COM
6 MayMuddying the Tracks: The State-Sponsored Shadow Behind Chaos RansomwareExecutive summary In early 2026, a sophisticated intrusion initially appearing to be a standard Chaos ransomware attack was assessed to be consistent with a targeted state-sponsored operation. While the threat actor operated under the banner of the Chaos ransomware-as-a-service (…RAPID7.COM
6 MayCloudZ Malware Abuses Phone Link to Steal SMS OTPsCisco Talos uncovers CloudZ RAT and Pheno plugin abusing Microsoft Phone Link to intercept SMS OTPsINFOSECURITY-MAGAZINE.COM
6 MayGrapheneOS fixes Android VPN leak Google refused to patchGrapheneOS has released a new update that fixes a recently disclosed Android VPN bypass vulnerability capable of leaking a user’s real IP address. The leak happens even when Android’s “Always-On VPN” and “Block connections without VPN” protections were enabled. The issue, disclos…CYBERINSIDER.COM
6 MayCISA warns of CopyFail exploitation.Attackers compromise installers for DAEMON Tools. New Linux RAT targets software developers.THECYBERWIRE.COM
6 MaySpeed, Not AI, Breaks YouThis clip argues that most enterprise breaches are driven by attack velocity, not advanced sophistication. Even AI-driven attack simulations can appear more effective than they are due to unrealistic conditions—like no defenders or penalties. Focusing too much on cutting-edge thr…YOUTUBE.COM
6 May KEVA critical Palo Alto PAN-OS zero-day is being exploited in the wildThe vendor hasn’t released a patch for the vulnerability or described the scope and objective of confirmed attacks. The post A critical Palo Alto PAN-OS zero-day is being exploited in the wild appeared first on CyberScoop .CYBERSCOOP.COM
6 MayA Vulnerability in Apache HTTP Server Could Allow for Remote Code ExecutionA vulnerability has been discovered in Apache HTTP Server with the HTTP/2 protocol that could allow for remote code execution. Apache is a free, open-source web server software that enables the delivery of web content over the internet. Successful exploitation could result in den…CISECURITY.ORG
6 MayThe exploit that writes its own story.CISA warns CopyFail is under active exploitation. Attackers compromise installers for a widely used disk imaging utility. MuddyWater masks cyberespionage as ransomware. Attackers spread malware through a fake OpenClaw plugin. Researchers ID a new Linux RAT. Vimeo blames a third p…THECYBERWIRE.COM
6 MayA Vulnerability in PAN-OS Could Allow for Remote Code ExecutionA vulnerability has been discovered in the PAN-OS Authentication Portal (aka Captive Portal) service that could allow for remote code execution. PAN-OS is the operating system that runs Palo Alto Networks next-generation firewalls. Successful exploitation could allow an unauthent…CISECURITY.ORG
5 MayAnthropic Mythos spurs White House to weigh pre-release reviews for high-risk AI modelsThe Trump administration is in early discussions about whether advanced AI models should be vetted before public release, according to reporting from the New York Times , the Wall Street Journal, and Axios . The conversations center on systems capable of facilitating cyberattacks…CSOONLINE.COM
5 MayMythbehavior under investigation.Welcome in! You’ve entered, Only Malware in the Building. Join us each month to sip tea and solve mysteries about today’s most interesting threats. Your host is Selena Larson, Proofpoint intelligence analyst and host of their podcast …THECYBERWIRE.COM
5 May174: Pacific RimFor six years, Sophos fought a secret cyber war against a state-backed hacking group targeting its firewalls. This forced Sophos to drastically change tactics to properly secure their firewalls. Was it ethical? Was it effective? They disrupted nine zero-day attacks, exposed who w…DARKNETDIARIES.COM
5 MayMicrosoft Details Phishing Campaign Targeting 35,000 Users Across 26 CountriesMicrosoft has disclosed details of a large-scale credential theft campaign that has leveraged a combination of code of conduct-themed lures and legitimate email services to direct users to attacker-controlled domains and steal authentication tokens. The multi-stage campaign, obse…THEHACKERNEWS.COM
5 MayThe Terrorist Designation: A New Red Line for Ransomware with Cynthia KaiserIn this episode, host Caleb Tolin explores the battlefield of enterprise defense, which has moved from simple data theft to ultra heinous crimes that put patient outcomes at risk. Guest Cynthia Kaiser shares Battlefield Stories from her time at the FBI and her current wor…THECYBERWIRE.COM
5 MayQualcomm Chipset Vulnerabilities Raise Alarm Over Remote Code Execution RiskQualcomm Technologies has released its May 2026 security bulletin, addressing a sweeping array of vulnerabilities across its proprietary and open-source software ecosystems. Threat actors could exploit these security gaps to compromise smartphones, automotive systems, and industr…GBHACKERS.COM
5 MayAttackers Exploit Amazon SES to Send Authenticated Phishing EmailsAttackers are increasingly abusing Amazon Simple Email Service (SES) to deliver highly convincing phishing emails that bypass traditional security controls, marking a growing trend in email-based threats. The primary goal of any phishing campaign is to evade detection while trick…GBHACKERS.COM
5 MayCritical Android Zero-Click Vulnerability Enables Remote Shell AccessGoogle has released the Android Security Bulletin for May 2026, addressing a highly critical vulnerability that allows attackers to execute code remotely without any user interaction. Published on May 4, 2026, the latest security update focuses heavily on a severe flaw located wi…GBHACKERS.COM
5 MayTrellix Reveals Unauthorized Access to Source CodeSecurity vendor Trellix has suffered a breach involving unauthorized accessINFOSECURITY-MAGAZINE.COM
5 MayCISOs step up to the security workforce challengeA robust cybersecurity program needs a range of skilled people, yet many CISOs continue to face an ongoing skills shortage — and the squeeze may only get worse as AI gains traction. Some 95% of cybersecurity practitioners and decision-makers noted at least one security skills gap…CSOONLINE.COM
5 MayKeeping Up With the OWASP GenAI Project - Scott Clinton - ASW #381Speed is the most common theme among developers and appsec teams working with LLMs and agents, from trying to keep up with patterns for deploying agents to dealing with more code faster to how the latest models impact code quality and security. The OWASP GenAI Project is helping …YOUTUBE.COM
5 MayNCSC Warns of an AI-Fuelled “Vulnerability Patch Wave”The UK's National Cyber Security Centre is urging organizations to prepare for glut of new software updatesINFOSECURITY-MAGAZINE.COM
5 MayDarkSword MalwareDarkSword is a sophisticated piece of malware —probably government designed—that targets iOS. Google Threat Intelligence Group (GTIG) has identified a new iOS full-chain exploit that leveraged multiple zero-day vulnerabilities to fully compromise devices. Based on too…SCHNEIER.COM
5 MayWhatsApp Security Flaw Enables Malicious URL Execution Through Instagram ReelsWhatsApp has recently patched two notable security vulnerabilities that could have allowed attackers to execute malicious links and disguise dangerous files. The most alarming discovery involves a flaw in how WhatsApp processes Instagram Reels. This vulnerability allows remote th…GBHACKERS.COM
5 MayEducation Sector Hit by Espionage, Phishing, and Supply Chain AttacksEducational institutions are now facing a coordinated mix of state espionage, spear‑phishing, and supply chain intrusions, even as classic ransomware and vulnerability volumes show signs of easing. Every attributed campaign was linked to state actors, with no financially motivate…GBHACKERS.COM
5 MayMicrosoft warns of global campaign stealing auth tokens from 35K usersMicrosoft revealed a phishing campaign hitting 35,000 users in 26 countries, stealing login tokens via fake code-of-conduct emails and legit services. Microsoft disclosed a major phishing campaign that targeted over 35,000 users across 26 countries in mid-April 2026. Attackers us…SECURITYAFFAIRS.COM
5 MayCloudZ malware hijacks Microsoft Phone Link to intercept SMS and OTPsA new malware campaign abuses Microsoft’s Phone Link app to intercept sensitive mobile data, including one-time passwords (OTPs), without compromising the phone itself. The attack centers on a modular malware toolkit called CloudZ RAT and a previously undocumented plugin for it, …CYBERINSIDER.COM
5 MayWe Scanned 1 Million Exposed AI Services. Here's How Bad the Security Actually IsWhile the software industry has made genuine strides over the past few decades to deliver products securely, the furious pace of AI adoption is putting that progress at risk. Businesses are moving fast to self-host LLM infrastructure, drawn by the promise of AI as a force multipl…THEHACKERNEWS.COM
5 MaySilver Fox Uses Fake Tax Notices to Drop ValleyRAT and ABCDoor BackdoorSilver Fox is running a tax‑themed phishing campaign that abuses fake notices from Indian and Russian tax authorities to drop ValleyRAT and a new Python backdoor dubbed ABCDoor, using a customized RustSL loader to evade detection and enforce strict geofencing controls. The campai…GBHACKERS.COM
5 MayCisco Acquisition of Astrix Security Signals to Strengthen on Non-Human Identity SecurityNetworking and security leader Cisco has announced its intent to acquire Astrix Security, a pioneer in Non-Human Identity (NHI) management. Announced in May 2026, this acquisition is designed to help enterprises secure the rapidly expanding “agentic workforce”, the gr…GBHACKERS.COM
5 MayStealthy malware abuses Microsoft Phone Link to siphon SMS OTPs from enterprise PCsA newly identified malware campaign is abusing Microsoft’s Phone Link feature to intercept SMS-based one-time passwords and other sensitive mobile data directly from Windows systems. The activity, first observed by Cisco Talos in January 2026, involves a remote access trojan dubb…CSOONLINE.COM
5 MayC/C++ checklist challenges, solvedWe recently added a C/C++ security checklist to the Testing Handbook and challenged readers to spot the bugs in two code samples : a deceptively simple Linux ping program and a Windows driver registry handler. If you found the inet_ntoa global buffer gotcha or the missing RTL_QUE…TRAILOFBITS.COM
5 MayUS-Targeted Phishing Campaign Exposes Credential and Remote Access Risks for CISOsA new large-scale phishing campaign is targeting U.S. organizations with fake event invitations that lead to credential theft, OTP interception, or RMM tool installation. ANY.RUN researchers found that the campaign uses a repeatable phishing framework to create event-themed lure …ANY.RUN
5 MayHow Far the US Went to Rescue Hostage Bowe BergdahlIn 2009, Bowe Bergdahl walked away from his Army post in eastern Afghanistan, only to be abducted and held hostage until 2014. He was captured by the Taliban and then handed to the Haqqani network, an aligned terrorist group. US officials said they kept Bergdahl locked in a metal…THECYBERWIRE.COM
5 MayPoC tool extracts cleartext passwords from Microsoft Edge memoryA newly released proof-of-concept (PoC) tool shows how Microsoft Edge handles saved credentials, demonstrating that passwords may be exposed in cleartext within browser process memory. The researcher behind the tool, Tom Jøran Sønstebyseter Rønning, claims the behavior is longsta…CYBERINSIDER.COM
5 MayA Walkthrough of the 2026 Global Cybersecurity Summit AgendaThe full agenda for the Rapid7 2026 Global Cybersecurity Summit is now live, and it gives a clearer sense of how the conversation around security operations is evolving. Across two days, the sessions progress from a shared understanding of how threats are changing into a more det…RAPID7.COM
5 MayFake SSA Emails Drive Venomous#Helper Phishing CampaignVenomous#Helper attackers impersonate the US Social Security Administration to deploy signed RMM software and maintain persistent access across US networksINFOSECURITY-MAGAZINE.COM
5 MayGoogle to pay up to $1.5 million for zero-click Pixel Titan M exploitsGoogle has revised its Android and Chrome Vulnerability Reward Programs (VRPs), which pay security researchers to report vulnerabilities in Android, Google hardware, and the Chrome browser. The update raises top bounties to $1.5 million and adjusts rewards for lower-complexity re…HELPNETSECURITY.COM
5 MayChina-Linked UAT-8302 Targets Governments Using Shared APT Malware Across RegionsA sophisticated China-nexus advanced persistent threat (APT) group has been attributed to attacks targeting government entities in South America since at least late 2024 and government agencies in southeastern Europe in 2025. The activity is being tracked by Cisco Talos under the…THEHACKERNEWS.COM
5 MayOracle will patch more often to counter AI cybersecurity threatOracle plans to issue security patches for its ERP, database, and other software on a monthly cycle, rather than quarterly, to respond to the increased pace of AI-enabled software vulnerability discovery. Other software vendors, notably Microsoft, SAP, and Adobe, already release …CSOONLINE.COM
5 MayTrellix investigating breach of source code repositoryThe cybersecurity company said there is no immediate evidence of code being exploited or released.CYBERSECURITYDIVE.COM
5 MayMicrosoft Edge Stores Passwords in Process Memory, Posing Enterprise RiskA proof-of-concept exploit (PoC) shows how someone with admin privileges can exploit the issue to steal passwords, and thus use them to engage in further malicious activity.DARKREADING.COM
5 MayUK's NCSC warns of AI-driven "patch wave."Google fixes critical Android vulnerability. Trellix discloses source code breach.THECYBERWIRE.COM
5 MayApple brings end-to-end encryption to RCS messaging in iOS 26.5Apple is preparing to roll out end-to-end encryption (E2EE) for RCS messaging in iOS 26.5, now in release candidate (RC) stage, marking a long-awaited step toward secure cross-platform communication between iPhone and Android users. The feature, currently in beta, ensures that me…CYBERINSIDER.COM
5 MayTanium Atlas aims to accelerate threat response in the AI eraTanium announced Tanium Atlas, an autonomous operating system (OS) that gives a single IT or security operator the data, guidance and reach to accomplish what once required an entire team – moving from intent to outcome in a single, governed experience. Tanium Atlas is built on a…HELPNETSECURITY.COM
5 MayCISA pushes critical infrastructure operators to prepare to work in isolationThe US Cybersecurity and Infrastructure Security Agency (CISA) has unveiled a new national initiative aimed at helping critical infrastructure operators withstand and recover from major cyberattacks by preparing to operate in isolation from the internet and third-party dependenci…CSOONLINE.COM
5 MayGoogle AppSheet Abuse Helped Phish 30,000 Facebook AccountsHackers abused Google AppSheet to send Meta phishing emails, compromising 30,000 Facebook business accounts across 50 countries. The post Google AppSheet Abuse Helped Phish 30,000 Facebook Accounts appeared first on TechRepublic .TECHREPUBLIC.COM
5 MayGoogle Update: Android Flaw Could Put Billions of Devices at RiskGoogle patched an Android zero-click RCE flaw affecting multiple versions. Here’s what IT teams should know and how to reduce mobile risk. The post Google Update: Android Flaw Could Put Billions of Devices at Risk appeared first on TechRepublic .TECHREPUBLIC.COM
5 MayEdge browser leaves passwords exposed in plain text, says researcherA Norwegian researcher has identified an issue with Microsoft Edge’s Password Manager that could be a serious concern for businesses. Tom Jøran Sønstebyseter Rønning found that passwords are being saved within the browser in plain text, with the effect that any PC, particularly a…CSOONLINE.COM
5 MayCVE Disclosures Become AI PromptsAI tools are already being used to discover vulnerabilities, including RCEs, through automated auditing and analysis. This raises the possibility that vulnerability disclosures could shift from detailed human-written reports to simple, reproducible AI prompts that generate the sa…YOUTUBE.COM
5 MayStrengthening cyber defense through policy and people.Markus Rauschecker, Executive Director of the University of Maryland Center for Cyber Health and Hazard Strategies, joins Dave Bittner on the CyberWire Daily podcast for a sponsored Industry Voices. He discusses why effective cybersecurity preparedness extends beyond technology, …THECYBERWIRE.COMHTTPS:
5 MayThe fixes keep coming.Brace for an AI-driven patch surge. Google fixes a critical Android flaw. Trellix confirms a source code breach. Apache Software Foundation ships urgent fixes. Data tied to Liberty Mutual leaks. CloudZ evolves to steal OTPs. Ouroboros persistence raises the stakes. A vishing susp…THECYBERWIRE.COM
5 MayTrellix Source Code Breach Highlights Growing Supply Chain ThreatsInfo is scant, but such breaches can reveal where a security product's controls are located and how detections are designed, giving attackers a leg up.DARKREADING.COM
5 May KEVPatch in 3 Days or BreakCISA is reportedly considering reducing remediation timelines for Known Exploited Vulnerabilities (KEV) from weeks down to just three days. Shorter deadlines reduce exposure to active threats—but dramatically increase operational pressure. Security teams may support the change, b…YOUTUBE.COM
5 MaySN 1077: A Browser AI API? - End of Bug Bounties?Google is sneaking a massive 4.7GB AI model into Chrome, and Mozilla is fighting back as the future of browsers threatens to turn into an AI arms race. Find out what's really happening behind this push and why it's setting off alarm bells across the web. Hackers AI-code a portal,…TWIT.TV
4 MaySpotting third-party cyber risk before attackers doIn this Help Net Security video, Jeffrey Wheatman, SVP and Cyber Strategist at Black Kite, discusses how organizations can identify and manage third-party cyber exposures before attackers exploit them. He argues that businesses should move beyond a data-loss mindset toward one ce…HELPNETSECURITY.COM
4 MayWhat researchers learned about building an LLM security workflowSecurity operations centers are running into the same wall everywhere. Detection tools generate more alerts than analysts can work through, and the early stages of any investigation involve pulling together logs from several sources to decide whether something is worth escalating…HELPNETSECURITY.COM
4 MayReborn Gaming - 126 breached accountsIn April 2026, the gaming community Reborn Gaming suffered a data breach due to a vulnerability in cPanel and WebHost Manager (WHM) . The breach exposed 126 unique email addresses along with IP addresses and Steam IDs. Reborn Gaming self-submitted the data to Have I Been Pwned.HAVEIBEENPWNED.COM
4 MayPipelock: Open-source AI agent firewallAI coding agents run with shell access, environment variables containing API keys, and unrestricted internet connectivity, creating a single point of failure where one compromised tool call can leak credentials to an attacker-controlled domain. Pipelock, an open-source security h…HELPNETSECURITY.COM
4 MayTrellix Source Code Breach Exposes Repository to Unauthorized AccessLeading cybersecurity firm Trellix has announced a security incident involving unauthorized access to a portion of its source code repository. The breach highlights a growing trend of threat actors targeting top-tier security vendors to uncover potential software vulnerabilities.…GBHACKERS.COM
4 MayTop 10 AI Pentest ToolsTop 10 AI Pentest Tools AI pentest tools are gaining popularity in offensive security workflows. These tools accelerate reconnaissance and automate workflows, but at the same time, enable less skilled actors to execute complex attacks. Now, security teams are forced to confront a…SOCRADAR.IO
4 MayAI-Powered Threat Actors Accelerate 0-Day Discovery at Machine SpeedThreat actors are already using AI models as autonomous operators to discover and exploit 0‑days in minutes, thereby collapsing the time and cost required to run complex intrusion campaigns. This shift, first clearly visible in late 2025 operations, is forcing defenders to rethin…GBHACKERS.COM
4 MayMOVEit Authentication Bypass Vulnerability Sparks Security ConcernsProgress Software has issued a critical security alert for its MOVEit Automation software. Two severe vulnerabilities have been discovered that could allow attackers to bypass authentication and escalate their privileges. Because of the critical nature of these flaws, administrat…GBHACKERS.COM
4 May KEVCISA Alert Highlights Active Exploitation of cPanel & WHM Security BugThe US Cybersecurity and Infrastructure Security Agency (CISA) has raised the alarm over a critical security vulnerability affecting WebPros cPanel & WebHost Manager (WHM) and WP2 (WordPress Squared). On April 30, 2026, CISA officially added this flaw to its Known Exploited V…GBHACKERS.COM
4 MayNew Apache MINA Vulnerabilities Open Door to Remote Code Execution AttacksThe Apache MINA project has issued urgent security updates to address two severe vulnerabilities. These security flaws could allow malicious actors to execute unauthorized code remotely. The development team has successfully patched these issues in the newly released Apache MINA …GBHACKERS.COM
4 MayThe fake IT worker problem CISOs can’t ignoreHiring fake IT workers has been a growing problem in recent years — but it’s often a problem very few want to admit to. From Fortune 500 companies down to smaller organizations, remote hiring practices have been exploited to grant trusted access to individuals who are not who the…CSOONLINE.COM
4 MayHow CISOs should utilize data security posture management to inform riskEvery CISO eventually faces the same tension: You know your security program needs to mature, but the budget and headcount to do it all aren’t there. That tension is especially sharp when it comes to data security posture management (DSPM) . Not every organization can afford, or …CSOONLINE.COM
4 MayPost Quantum Migration Struggles, AI Threats, and Modern Defenses - ESW #457Interview with Daniel dos Santos: Post-Quantum Cryptography and the Risks No One Is Talking About Post-quantum cryptography (PQC) is quickly shifting from theory to inevitability. In this segment, Daniel dos Santos, VP of Research at Forescout, explains why PQC isn’t the most imm…YOUTUBE.COM
4 MayClaude Security enters public beta with Opus 4.7 vulnerability scanning and patchingClaude Security, previously called Claude Code Security, is in public beta for Claude Enterprise customers. Available in Claude.ai, the capability scans codebases for security vulnerabilities and suggests targeted patches for review, helping teams identify and fix issues that mig…HELPNETSECURITY.COM
4 MayCritical cPanel Vulnerability Weaponized to Target Government and MSP NetworksA previously unknown threat actor has been observed targeting government and military entities in Southeast Asia, alongside a smaller cluster of managed service providers (MSPs) and hosting providers in the Philippines, Laos, Canada, South Africa, and the U.S., by exploiting the …THEHACKERNEWS.COM
4 May276 Arrested as Authorities Dismantle Crypto Scam Centers Targeting AmericansIn an unprecedented international law enforcement operation, authorities have dismantled at least nine overseas cryptocurrency scam centers, resulting in the arrest of 276 individuals. The coordinated effort, led by the FBI, Dubai Police, and the Chinese Ministry of Public Securi…GBHACKERS.COM
4 MayAI speeds flaw discovery, forcing rapid updates, UK NCSC warnsThe UK cyber agency NCSC warns AI is speeding up vulnerability discovery, likely causing a “patch wave” of urgent software updates to fix exposed flaws. The UK’s National Cyber Security Centre (NCSC) warns that AI is rapidly accelerating the discovery of software vulnerabilities,…SECURITYAFFAIRS.COM
4 MayDigiCert suffers breach, stolen certificates used to sign malwareDigiCert has disclosed a security incident in which attackers compromised internal support systems and abused stolen certificate issuance data to obtain valid EV code signing certificates. Some of the certificates were subsequently used to sign malware tied to the Zhong Stealer f…CYBERINSIDER.COM
4 MayStronger Cybersecurity, Stronger Business: NIST Celebrates 2026 National Small Business WeekHappy National Small Business Week! For over 60 years, the U.S. Small Business Administration has led this initiative to acknowledge the critical contributions of America’s entrepreneurs and small business owners. Part of the U.S. Department of Commerce, NIST’s mission is to driv…NIST.GOV
4 MayMalicious TanStack Package Abuses Postinstall Script to Steal Developer SecretsA malicious npm package named “tanstack” has been discovered deploying a stealthy data exfiltration campaign, targeting developers through a deceptive naming strategy and a hidden postinstall script. The package, impersonating the well-known TanStack ecosystem, was weaponized to …GBHACKERS.COM
4 MaySecurity agencies draw red lines around agentic AI deploymentsWith prompt injection and other attack pathways consistently surfacing across agentic AI deployments, security watchdogs have stepped in, collectively, to draw some hard boundaries. A joint advisory from the US Cybersecurity and Infrastructure Security Agency (CISA) and internati…CSOONLINE.COM
4 MayCisco Launches AI Provenance Tool to Strengthen Security and ComplianceArtificial intelligence models are integrated into countless enterprise applications, but knowing exactly where these models come from remains a major security hurdle. Cisco recently launched the Model Provenance Kit, an open-source tool for tracing the exact lineage of AI models…GBHACKERS.COM
4 MaySecurity for AI: A strategic framework for closing the AI exposure gapAs AI adoption accelerates, CISOs face a dual challenge: fueling innovation while mitigating the risks of a rapidly expanding attack surface. Tenable’s five-step framework for securing AI offers a systematic approach to reducing AI security risks as your organization races to ach…TENABLE.COM
4 May4th May – Threat Intelligence ReportFor the latest discoveries in cyber research for the week of 4th May, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Medtronic, a global medical device maker, has disclosed a cyberattack on its corporate IT systems. An unauthorized party accessed data,…RESEARCH.CHECKPOINT.COM
4 MayQ-Day Might Come SoonerIndustry timelines for quantum risk are tightening, with some projections pointing to 2029 for a cryptographically relevant quantum computer. If Q-Day arrives sooner than expected, organizations that delayed planning could be forced into rushed migrations under pressure. Advances…YOUTUBE.COM
4 MayOwl IRD enables one-way forensic data transfer for incident response teamsOwl Cyber Defense has announced the launch of its Incident Response Diode (IRD), a pocket-sized protocol filtering diode (PFD) designed for incident response and forensics teams. The Owl IRD was developed to help users securely move evidence from compromised endpoints into truste…HELPNETSECURITY.COM
4 May KEVTwo cybersecurity pros get prison time for helping ransomware gangTwo American cybersecurity professionals were sentenced to four years in prison for facilitating BlackCat ransomware attacks in 2023. They pleaded guilty in December 2025 to one count of conspiracy to obstruct, delay, or affect commerce, or the movement of any article or commodit…HELPNETSECURITY.COM
4 May⚡ Weekly Recap: AI-Powered Phishing, Android Spying Tool, Linux Exploit, GitHub RCE & MoreThis week, the shadows moved faster than the patches. While most teams were still triaging last month’s alerts, attackers had already turned control panels into kill switches, kernels into open doors, and open-source pipelines into silent delivery systems. The game has shifted fr…THEHACKERNEWS.COM
4 MayProgress Software urges customers to patch critical MOVEit flaw.Educational tech firm Instructure confirms breach. Sorry ransomware gang exploits recently disclosed cPanel vulnerability.THECYBERWIRE.COM
4 MayCritical vulnerability in cPanel leads to widespread exploitationResearchers warn that threat activity continues to surge, including brute force attacks and ransomware.CYBERSECURITYDIVE.COM
4 MayA Vulnerability in WHM cPanel and WP Squared Could Allow for Remote Code ExecutionA vulnerability has been discovered in WHM, cPanel, and WP Squared that could allow for remote code execution. WHM, cPanel, and WP Squared are Linux-based web hosting control panels for server and website management. While WHM provides server-level control, cPanel provides admini…CISECURITY.ORG
4 MayPhishing Campaign Hits 80+ Orgs Using SimpleHelp and ScreenConnect RMM ToolsAn active phishing campaign has been observed targeting multiple vectors since at least April 2025, with legitimate Remote Monitoring and Management (RMM) software as a way to establish persistent remote access to compromised hosts. The activity, codenamed VENOMOUS#HELPER, has im…THEHACKERNEWS.COM
4 MayHackers are still exploiting the cPanel bug to gain control of thousands of websitesDays after the disclosure of a critical vulnerability in popular web hosting software cPanel and WHM, hackers keep targeting and hacking websites.TECHCRUNCH.COM
4 MaySecurity without a login screen.Progress Software urges customers to patch a critical MOVEit authentication bypass. Washington worries about limited access to advanced AI tools. Paid influencers promote pro-American AI. CISA warns Copy Fail is under active exploitation. The Canvas educational platform suffers a…THECYBERWIRE.COM
4 MayExploit Cyber-Frenzy Threatens Millions via Critical cPanel VulnerabilityShortly after the authentication-bypass flaw was disclosed multiple proof-of-concept exploits appeared, and one researcher claims there's been zero-day activity for at least a month.DARKREADING.COM
4 May KEV‘Copy Fail’ is a real Linux security crisis wrapped in AI slopThe actively exploited defect could affect every mainstream Linux distribution built since 2017, but some researchers found Theori’s AI-generated disclosure unhelpful and lacking. The post ‘Copy Fail’ is a real Linux security crisis wrapped in AI slop appeared first o…CYBERSCOOP.COM
4 MayFrom Foundation to Force: Your Guide to Operationalizing Wiz at ScaleFollowing your foundation, operationalize Wiz across development, detection and response, and program maturity so your security program never stops getting stronger.WIZ.IO
3 MayWeek in review: High-severity LPE vulnerability in the Linux kernel, cPanel 0-day exploited for monthsHere’s an overview of some of last week’s most interesting news, articles, interviews and videos: The AI criminal mastermind is already hiring on gig platforms Labor-hire platforms let anyone with a credit card post a task and pay a stranger to complete it. The RentAHuman platfor…HELPNETSECURITY.COM
3 MayGoogle Revamps Bug Bounty Programs: Android Rewards Rise, Chrome Payouts Drop in the Age of AIGoogle revamps bug bounties: Android rewards rise to $1.5M, Chrome payouts drop, shifting focus to high-impact, AI-resistant vulnerabilities. Google has announced a major overhaul of its Vulnerability Reward Programs (VRP) for Android and Chrome, marking a strategic shift in how …SECURITYAFFAIRS.COM
2 MayConnected Cars Are Rolling Spy Networks — And They Can Be HackedConnected cars are no longer just vehicles — they are rolling networks of sensors, cameras, microphones, and constant data transmission. In this Cybersecurity Today Weekend Edition, David Shipley is joined by former CSIS intelligence officer Neil Bisson and cybersecurity expert F…CYBERSECURITYTODAY.LIBSYN.COM
2 MayDouble-edged threat.Today we are joined by Justin Albrecht, Principal Researcher at Lookout, discussing "Attackers Wielding DarkSword Threaten iOS Users." DarkSword is a highly sophisticated iOS exploit chain discovered by Lookout that targets iPhones (iOS 18.4–18.6.2), enabling near zero-click …THECYBERWIRE.COM
2 MayOpenAI and Anthropic brief Congress on cyber-capable AI models."Copy Fail" flaw leads to privilege escalation on Linux. FISA Section 702 gets another stopgap extension.THECYBERWIRE.COM
2 MayTrellix Confirms Source Code Breach With Unauthorized Repository AccessCybersecurity company Trellix has announced that it suffered a breach that enabled unauthorized access to a "portion" of its source code. It said it "recently identified" the compromise of its source code repository and that it began working with "leading forensic experts" to res…THEHACKERNEWS.COM
2 MayZenBusiness - 5,118,184 breached accountsIn March 2026, the hacker and extortion group "ShinyHunters" claimed to have obtained a substantial corpus of data from ZenBusiness , a business formation and compliance platform. The group claimed the data had been exfiltrated from platforms including Snowflake, Mixpanel and Sal…HAVEIBEENPWNED.COM
2 MayTrellix discloses the breach of a code repositoryTrellix disclosed a security breach affecting part of its source code repository, however, the company says there’s no sign of code misuse. Trellix revealed a breach that allowed unauthorized access to part of its source code repository. The company said it quickly launched an in…SECURITYAFFAIRS.COM
1 MaySnake Oilers: Ent AI, Spacewalk and MondooIn this edition of the Snake Oilers podcast three vendors stop by to pitch the audience on their products: Ent AI: Co-founder Brandon Dixon pitched Ent, an intent-aware, AI-powered endpoint security control. Spacewalk AI: Founders Chris Fuller and Tim Wenzlau pitch Spacewalk, an …RISKY.BIZ
1 MayNew infosec products of the month: April 2026Here’s a look at the most interesting products from the past month, featuring releases from Advenica, Aptori, Axonius, Broadcom, GlobalSign, Intruder, IP Fabric, Mallory, Secureframe, Siemens, Sitehop, and Virtue AI. Mallory brings contextual threat intelligence to security opera…HELPNETSECURITY.COM
1 MayFake CAPTCHA Scam Uses SMS Pumping to Inflate Phone BillsA newly uncovered cyber fraud campaign is abusing fake CAPTCHA pages to trick mobile users into sending large volumes of international SMS messages, resulting in unexpected phone bills and illicit profits for attackers. Unlike traditional malware campaigns, this operation does no…GBHACKERS.COM
1 MayAman - 215,563 breached accountsIn April 2026, the ultra-luxury hotel brand Aman was named by ShinyHunters as the target of a "pay or leak" extortion campaign , with the data allegedly obtained from their Salesforce CRM. The data was subsequently leaked publicly and contained over 200k unique email addresses. W…HAVEIBEENPWNED.COM
1 MayAI traffic is getting bigger, louder, and less predictableAI workflows need storage that supports repeated movement across the model lifecycle. Large datasets are ingested, transformed, exported for training, pulled back for evaluation, and refreshed as models evolve. Backblaze’s Q1 2026 Network Stats report says this creates a shift fr…HELPNETSECURITY.COM
1 MayClaude Security Enters Public Beta for Enterprise CustomersAnthropic has officially launched the public beta of Claude Security, an advanced vulnerability detection and remediation tool now available to Claude Enterprise customers. Powered by the highly capable Claude Opus 4.7 model, this platform shifts application security testing from…GBHACKERS.COM
1 MayOpen-source privacy proxy masks PII before prompts reach external AI servicesEnterprise developers routinely send prompts to external large language models that contain customer emails, support transcripts, and other identifying information, often without a sanitization layer between the application and the API. Dataiku has released Kiji Privacy Proxy, an…HELPNETSECURITY.COM
1 MayShadow AI risks deepen as 31% of users get no employer trainingBetween one-fifth and one-third of workers use AI outside the influence and governance of the IT function, according to a global survey of 6,000 full-time employees at enterprise organizations. Researchers found a widening gap between employee AI adoption and the controls organiz…HELPNETSECURITY.COM
1 MayChina-Aligned Hackers Deploy ShadowPad in Multi-Stage Espionage CampaignChina-aligned threat actors tracked as SHADOW-EARTH-053 are exploiting old but unpatched Microsoft Exchange and IIS vulnerabilities to run a stealthy, multi-stage espionage campaign across Asian governments, critical infrastructure, and one NATO member state. The group primarily …GBHACKERS.COM
1 MayMultiple Wireshark Vulnerabilities Allow Arbitrary Code Execution via Malformed PacketsThe Wireshark Foundation has released version 4.6.5 of its widely used network protocol analyzer, addressing a massive wave of security vulnerabilities. This urgent update patches over 40 distinct security flaws, driven by a recent surge in AI-assisted vulnerability reports. The …GBHACKERS.COM
1 MayAI-Powered Ransomware Surge Hits 7,831 Victims WorldwideRansomware attacks surged dramatically in 2025, with global victims reaching 7,831. The sharp rise highlights how cybercrime has evolved into a highly organized, AI-driven ecosystem in which attackers operate at speed, with automation and scale. This surge is largely fueled by th…GBHACKERS.COM
1 MayDDoS Malware Targets Jenkins to Hit Valve Game ServersA new DDoS botnet that abuses exposed Jenkins servers to launch powerful attacks against Valve Source Engine game infrastructure, including servers hosting titles like Counter‑Strike and Team Fortress 2. The campaign shows how a single misconfigured CI server can be turned into a…GBHACKERS.COM
1 MayPoisoned Ruby Gems and Go Modules Exploit CI Pipelines for Credential TheftA new software supply chain attack campaign has been observed using sleeper packages as a conduit to subsequently push malicious payloads that enabled credential theft, GitHub Actions tampering, and SSH persistence. The activity has been attributed to the GitHub account "BufferZo…THEHACKERNEWS.COM
1 MayJust 34% of cyber pros plan to stick with their current employerDeclining job satisfaction means that only one in three (34%) cybersecurity professionals plan to stay with their current employer, increasing the pressure on CISOs’ talent retention strategies. And according to a survey of 500 cybersecurity professionals by IANS and Artico Searc…CSOONLINE.COM
1 MayManaging OT risk at scale: Why OT cyber decisions are leadership decisionsThe first time I approached an OT environment, I assumed that the strategies effective in IT cybersecurity would be equally applicable. I was wrong. The experience revealed a fundamental difference, highlighting the need for a distinct approach to OT cyber risk management. The mi…CSOONLINE.COM
1 MayHuman-centric failures: Why BEC continues to work despite MFABusiness email compromise (BEC) is still thriving even in organizations that have implemented multi-factor authentication (MFA). As security professionals, we often assume that MFA is the silver bullet for email security, but real-world incidents suggest otherwise. Attackers expl…CSOONLINE.COM
1 May KEVActively exploited cPanel bug exposes millions of websites to takeoverA vulnerability in the cPanel/WHM admin interface lets attackers access websites without a username and password.MALWAREBYTES.COM
1 MayNine-Year-Old Zero-Day Flaw in Linux Kernel Discovered by AI-Equipped Security ResearcherA researcher from offensive security firm Theori has found a nine-year-old flaw in the Linux kernel with the help of AIINFOSECURITY-MAGAZINE.COM
1 MayAnthropic launches Claude Security to counter rapid AI-Powered exploitsAnthropic launched Claude Security to counter faster AI-driven cyberattacks, as tools like Mythos enable near-instant exploitation by threat actors. Anthropic introduced Claude Security to help defenders keep up with a surge in AI-powered cyberattacks. As models like Mythos drast…SECURITYAFFAIRS.COM
1 MayUtah becomes first US state to require age verification for VPN useUtah is set to implement a first-of-its-kind law targeting VPN use to enforce online age verification, raising concerns about privacy, free speech, and technical feasibility. The measure, which takes effect on May 6, 2026, shifts liability onto websites and restricts how they can…CYBERINSIDER.COM
1 MayMozilla warns Chrome’s Prompt API threatens web neutralityMozilla has reiterated strong opposition to Google’s proposed Prompt API for Chrome, warning that it could fragment the web, lock developers into model-specific behavior, and introduce problematic policy enforcement at the browser level. The Prompt API aims to provide web develop…CYBERINSIDER.COM
1 MayAnthropic Rolls Out Claude Security for AI Vulnerability ScanningClaude Security enters public beta, giving enterprises AI driven code scanning with no API integration or custom agents requiredINFOSECURITY-MAGAZINE.COM
1 MayVulnerability remediation: Match CVEs to asset owners in seconds with Tenable Hexa AIDetecting a vulnerability is easy. Finding the person responsible for fixing it is where remediation programs often break down. See how Tenable Hexa AI uses MCP to connect your exposure data to your identity provider — automating the hunt for asset owners in seconds. Key takeaway…TENABLE.COM
1 MayBritish cyber agency warns of looming ‘patch wave’ as AI speeds flaw discoveryBritain’s cyber agency warned that organizations should prepare for a surge of urgent software updates as artificial intelligence accelerates the discovery of security flaws, raising the risk of widespread exploitation.THERECORD.MEDIA
1 MayChina-Linked Hackers Target Asian Governments, NATO State, Journalists, and ActivistsCybersecurity researchers have disclosed details of a new China-aligned espionage campaign targeting government and defense sectors across South, East, and Southeast Asia, along with one European government belonging to NATO. Trend Micro has attributed the activity to a threat ac…THEHACKERNEWS.COM
1 MayA Medicare database leaked Social Security numbers.FISA Section 702 gets another stopgap extension. "Mini Shai Hulud" campaign spreads through the open-source supply chain.THECYBERWIRE.COM
1 MayTCP Packet Walks Into a BarHacker culture often uses humor rooted in programming, networking, and system behavior—like TCP reliability, source code access, and deployment frustrations. These jokes aren’t just comedy; they reflect shared experiences in software and infrastructure work. Concepts like packet …YOUTUBE.COM
1 MayYour KnowBe4 Fresh Content Updates from April 2026John N Just, Ed.D. - Chief Learning Officer What's New: Celebrating World Password Day and Beyond Happy May! This month, we are putting a major spotlight on World Password Day (May 7) . While the "traditional" password might be evolving into passkeys and biometrics, the human ele…KNOWBE4.COM
1 MayThink before you deploy the agent.Five Eyes agencies issue agentic AI guidance. A federal database leaks Social Security numbers. A stealthy worm poisons open source packages. OT firms are sidelined from frontier cyber models. The FBI warns of a surge in cyber-enabled cargo theft. Officials flag likely election i…THECYBERWIRE.COM
1 MayHidden Risk QR Code PhishingQR code phishing attacks more than doubled in early 2026, making them one of the fastest-growing email-based attack vectors. Attackers exploit a simple trust gap: users are trained to inspect links, but QR codes hide the destination entirely. This removes visibility and makes tra…YOUTUBE.COM
1 MayAI agents can bypass guardrails and put credentials at risk, Okta study findsAn AI agent that revealed sensitive data without being asked. An agent that overruled its own guardrails. Another that sent credentials to an attacker via Telegram, because it forgot it wasn’t supposed to do so after a reset. It’s no secret that AI agents have huge potential, bal…CSOONLINE.COM
1 MayEssential Data Sources for Detection Beyond the EndpointUnit 42 highlights the need for a comprehensive security strategy that spans every IT zone. Explore the full details here. The post Essential Data Sources for Detection Beyond the Endpoint appeared first on Unit 42 .UNIT42.PALOALTONETWORKS.COM
30 AprAmazon Layoffs Hit Thousands Across Multiple States as Fresh Stores CloseAmazon layoffs are hitting workers across several states as Fresh closures, AI investments, and post-pandemic restructuring reshape its workforce. The post Amazon Layoffs Hit Thousands Across Multiple States as Fresh Stores Close appeared first on TechRepublic .TECHREPUBLIC.COM
30 AprMicrosoft Confirms Windows Flaw Is Being Exploited After Incomplete PatchMicrosoft confirmed a Windows zero-click flaw tied to an incomplete patch is being exploited, putting credentials at risk for unpatched users. The post Microsoft Confirms Windows Flaw Is Being Exploited After Incomplete Patch appeared first on TechRepublic .TECHREPUBLIC.COM
30 AprResearchers unearth industrial sabotage malware that predated Stuxnet by 5 yearsDesigned to cripple Iran’s nuclear enrichment program, the 2010 Stuxnet worm set a cybersecurity precedent as the first time a nation escalated its activities from strategic espionage to sabotage in cyberspace. Now, a new discovery suggests such operations were in full swing year…CSOONLINE.COM
30 AprSonicWall SonicOS Flaw Lets Attackers Bypass Access Controls and Crash FirewallsSonicWall has released a security advisory detailing three new vulnerabilities affecting its SonicOS software. Disclosed on April 29, 2026, under advisory ID SNWLID-2026-0004, these security flaws open the door for attackers to bypass access controls, manipulate restricted files,…GBHACKERS.COM
30 AprA game of loans.This week, while Maria is on vacation, Dave Bittner and Joe Carrigan are joined by Michele Kellerman as they discuss the latest in social eng…THECYBERWIRE.COM
30 AprGoogle Fixes CVSS 10 Gemini CLI CI RCE and Cursor Flaws Enable Code ExecutionGoogle has addressed a maximum severity security flaw in Gemini CLI -- the "@google/gemini-cli" npm package and the "google-github-actions/run-gemini-cli" GitHub Actions workflow -- that could have allowed attackers to execute arbitrary commands on host systems. "The vulnerabilit…THEHACKERNEWS.COM
30 Apr KEVQinglong Task Scheduler RCE Flaws Exploited in the WildHackers are actively exploiting two severe authentication bypass vulnerabilities in Qinglong, a popular open-source task scheduling platform. These flaws allow attackers to execute arbitrary code and deploy resource-draining cryptomining malware on vulnerable servers. Qinglong is…GBHACKERS.COM
30 AprJenkins Plugin Updates Fix Path Traversal and Stored XSS BugsThe Jenkins project released a critical security advisory addressing seven vulnerabilities across multiple widely used plugins. The disclosed flaws include high-severity path traversal and stored cross-site scripting (XSS) vulnerabilities that could allow threat actors to execute…GBHACKERS.COM
30 AprSAP npm package attack highlights risks in developer tools and CI/CD pipelinesA supply chain attack on SAP-related npm packages has put fresh scrutiny on the developer tools and build workflows that enterprises rely on to produce software. The campaign, referred to as “mini Shai-Hulud,” affected packages used in SAP’s JavaScript and cloud application devel…CSOONLINE.COM
30 AprStopping the quiet drift toward excessive agency with re-permissioningIn their infancy, LLM models were not difficult to contain. You gave a prompt; they responded, and if something was wrong it was usually “just text.” This could take the form of a summary that missed the best bits, a tone-deaf line or a wordy sentence. But then, agents were co-op…CSOONLINE.COM
30 AprODNI to CISOs on threat assessments: You’re on your ownEvery year, CISOs, CSOs, and chief risk officers pore over the Office of the Director of National Intelligence (ODNI)’s Annual Threat Assessment (ATA) for insights on emerging threats they may soon face. This year, however, structural changes to the report itself underscore a fou…CSOONLINE.COM
30 AprMax-severity RCE flaw found in Google Gemini CLISecurity researchers are warning about a max severity vulnerability in Google Gemini CLI that could allow remote code execution (RCE) in environments where the tool processes untrusted inputs. The issue was disclosed by Novee Security researchers and affects the @google/gemini-cl…CSOONLINE.COM
30 AprNew Python Backdoor Uses Tunneling Service to Steal Browser and Cloud CredentialsCybersecurity researchers have disclosed details of a stealthy Python-based backdoor framework called DEEP#DOOR that comes with capabilities to establish persistent access and harvest a wide range of sensitive information from compromised hosts. "The intrusion chain begins with e…THEHACKERNEWS.COM
30 AprDismantle implicit trust in OT networks, CISA tells critical infrastructure operatorsThe US Cybersecurity and Infrastructure Security Agency (CISA) has asked owners and operators of operational technology to stop assuming their networks are safe, and has released joint guidance to adapt zero trust principles for industrial systems that support US power, water, tr…CSOONLINE.COM
30 AprCisco releases open-source toolkit for verifying AI model lineageEnterprises pulling models from Hugging Face and other open repositories rarely keep records of how those models are altered after download, leaving organizations with little ability to confirm what they are running in production. The State of AI Security 2026 from Cisco places t…HELPNETSECURITY.COM
30 AprMet Police face criticism for using AI to spy on their own officersLondon police officers have been warned by the Metropolitan Police Federation to watch their backs after the force deployed controversial AI software to investigate misconduct. The staff association, representing more than 30,000 officers in London, reported it had not been infor…HELPNETSECURITY.COM
30 AprHackers arrested for stealing and reselling 600,000 Roblox accountsUkrainian police detained three suspects accused of hacking into Roblox accounts and reselling the data on Russian websites, with payments made in cryptocurrency. Police raid (Source: The Prosecutor General’s Office of Ukraine) “Prosecutors of the Lviv region, togethe…HELPNETSECURITY.COM
30 AprAI Is Scaling Cyber AttacksA recent report details how attackers are using AI tools to automate reconnaissance, target selection, and vulnerability discovery during cyber attacks. This significantly lowers the cost and effort required to launch attacks while increasing their scale and effectiveness. As a r…YOUTUBE.COM
30 AprArbitrary code execution and Claude Code CLI: How Claude executed code before you click 'trust'submitted by codeinabox to security 2 points | 0 comments https://www.sonarsource.com/blog/claude-arbitrary-code-executionPROGRAMMING.DEV
30 Apr"Copy Fail" flaw leads to privilege escalation on Linux.US House votes to extend FISA Section 702, though Senate passage is unlikely. OpenSSH flaw can lead to root shell access.THECYBERWIRE.COM
30 AprAgent’s claims on WhatsApp access spark security concernsA US agent claimed WhatsApp encryption is fake and Meta can access messages; the probe was abruptly shut, raising security concerns. A US agent claimed WhatsApp encryption is fake, alleging Meta accesses all unencrypted messages, but Commerce Department abruptly shut the probe, l…SECURITYAFFAIRS.COM
30 AprHackers are actively exploiting a bug in cPanel, used by millions of websitesWeb hosts are scrambling to fix the bug under active attack by hackers. One company said hackers have been abusing the bug for months.TECHCRUNCH.COM
30 AprBridging the gap: How to integrate Claude Security into the Tenable One Exposure Management PlatformBridge the gap between AI-driven vulnerability discovery and prioritized remediation. Learn how to integrate Claude Security’s deep-logic analysis into Tenable One to unify your attack surface, eliminate noise, and focus on the risks that matter most. Key takeaways As frontier AI…TENABLE.COM
30 AprAnother AI-Assisted Software Scan Yields 9-Year-Old Linux BugThe proof-of-concept exploit code runs only 10 lines long, but luckily, a patch is already available.DARKREADING.COM
30 AprFIRESTARTER - PSW #924This week in the security news: - Are you a FIRESTARTER? - Eavesdropping via fiber-optic cables - Copy Fail - more Linux LPE - Github RCE - Running Linux on a PS5 - BadUSB tricks - SilentGlass and HDMI threats - Sonicwall and vague details - Universities are for porn? - The Bansh…YOUTUBE.COM
30 AprWhen Trusted Sites Turn MaliciousAttackers have long exploited trusted domains—like university websites—by injecting malicious code that redirects traffic or hosts spam content, leveraging the site’s reputation to boost visibility. This “reputation theft” not only helps attackers rank higher in search results, b…YOUTUBE.COM
30 AprThat AI Extension Helping You Write Emails? It’s Reading Them FirstUnit 42 uncovers high-risk AI browser extensions. Disguised as productivity tools, they steal data, intercept prompts, and exfiltrate passwords. Protect your browser. The post That AI Extension Helping You Write Emails? It’s Reading Them First appeared first on Unit 42 .UNIT42.PALOALTONETWORKS.COM
30 AprBank regulator sounds warning over cybersecurity threat posed by AI modelsFrontier AI models inspired by Anthropic’s Claude Mythos could arm attackers with advanced capabilities that the banking sector is ill equipped to cope with, Australia’s financial regulator, the Australian Prudential Regulation Authority (APRA), has warned. In a letter addressed …CSOONLINE.COM
29 AprCI/CD pipeline abuse: the problem no one is watchingHow we built an open-source, drop-in CI template that uses signal extraction and LLM reasoning to catch CI/CD abuse in GitHub Actions, GitLab CI, and Azure DevOps pipelines.ELASTIC.CO
29 AprMore fake extensions linked to GlassWorm found in Open VSX code marketplaceThe threat actor seeding the Open VSX code marketplace with fraudulent extensions that download the GlassWorm malware has uploaded 73 more impersonated links, as its attempt to infect software supply chains continues. Philipp Burckhardt , head of threat intelligence at Socket, wh…CSOONLINE.COM
29 AprProduct showcase: SimpleX Chat removes user identifiers from messagingSimpleX Chat is a free, private, open-source messenger that uses encryption and does not require user identifiers. It is available on mobile and desktop platforms, including iOS, Android, Windows, macOS, and Linux. After downloading the app, the user creates a profile by entering…HELPNETSECURITY.COM
29 AprMassive Python Supply Chain Hack, $2.1B Scam Losses, North Korea Targets Crypto ExecsA major open source Python tool was hijacked in a supply chain attack, exposing developer credentials, cloud secrets, and crypto wallets. Meanwhile, the FTC says Americans lost more than $2.1 billion to scams that began on social media, with Facebook leading reported losses. Cybe…CYBERSECURITYTODAY.LIBSYN.COM
29 AprcPanel Releases Emergency Patch for Critical Authentication FlawWeb hosting administrators must take immediate action, as cPanel has rolled out an emergency security update to address a critical vulnerability. Disclosed on April 28, 2026, this flaw impacts various authentication paths within the cPanel and WebHost Manager (WHM) ecosystem. Con…GBHACKERS.COM
29 AprRisky Business #835 -- Why the Fast16 malware is badassOn this week’s show, Patrick Gray and James Wilson are joined by special guest-host Dmitri Alperovitch. They discuss the week’s cybersecurity news, including: The US government is mad as hell about Chinese firms stealing American AI technology Dmitri has an opinion or two about t…RISKY.BIZ
29 AprVimeo Confirms Data Breach After Hackers Access User DatabaseVimeo has officially confirmed a data breach affecting its user database. The security incident did not originate with Vimeo, but rather with Anodot, a third-party analytics vendor used by the video hosting platform. This event highlights the ongoing risks associated with softwar…GBHACKERS.COM
29 AprShinyHunters exploit Anodot incident to target VimeoThe video platform Vimeo confirmed a security breach via Anodot that exposed metadata, video titles, and some user emails. Vimeo said some user data was accessed after a breach at Anodot. Anodot is a company that provides AI-driven data analytics and anomaly detection tools. Most…SECURITYAFFAIRS.COM
29 AprVirtue AI PolicyGuard turns AI policies into enforceable runtime guardrailsVirtue AI has announced PolicyGuard, a system that enables enterprises to define, edit, and enforce custom AI runtime protection guardrails across models, agents, and applications. Most organizations have “AI acceptable use policies.” When they need to enforce those p…HELPNETSECURITY.COM
29 AprSLOTAGENT Malware Hides API Calls and Strings to Thwart AnalysisA previously unknown remote access trojan (RAT), dubbed SLOTAGENT, after analyzing a suspicious ZIP archive uploaded from Japan to a public malware repository in early 2026. The malware demonstrates advanced evasion techniques and flexible post-exploitation capabilities, making i…GBHACKERS.COM
29 AprDigitalOcean AI-Native Cloud unifies infrastructure, inference, and agents for production AIDigitalOcean has introduced the AI-Native Cloud, an end-to-end platform built for the inference and agentic era. Spanning infrastructure, core cloud, inference, data, and managed agents, it already supports production workloads at Higgsfield AI, Hippocratic AI, ISMG, Bright Data,…HELPNETSECURITY.COM
29 AprClaude Mythos Has Found 271 Zero-Days in FirefoxThat’s a lot . No, it’s an extraordinary number: Since February, the Firefox team has been working around the clock using frontier AI models to find and fix latent security vulnerabilities in the browser. We wrote previously about our collaboration with Anthropic to s…SCHNEIER.COM
29 AprCritical cPanel Authentication Vulnerability Identified — Update Your Server ImmediatelycPanel has released security updates to address a security issue impacting various authentication paths that could allow an attacker to obtain access to the control panel software. The problem affects all currently supported versions, according to an alert released by cPanel on T…THEHACKERNEWS.COM
29 AprAWS leans on prior ingenuity to face future AI and quantum threatsAs Amazon celebrates the 20th anniversary of its AWS cloud this year, the world’s biggest cloud computing provider now faces two giant cybersecurity threats — AI and quantum. How the company will navigate these emerging issues to ensure the security and resilience of systems used…CSOONLINE.COM
29 AprThe Next Frontier: Autonomous Security and RSAC Interviews from Quantro & SandboxAQ - BSW #445Attackers are increasingly weaponizing frontier models to accelerate the entire attack lifecycle, with current and emerging models reducing the time and expertise needed to start disruptive attacks. As offensive capabilities become more automated and agentic, organizations will n…YOUTUBE.COM
29 AprCursor AI Coding Agent Vulnerability Lets Attackers Run Code on Developers’ MachinesA newly disclosed high-severity vulnerability in the Cursor AI-powered coding environment could allow attackers to execute arbitrary code on a developer’s machine, raising fresh concerns about the security of AI-assisted development workflows. The vulnerability was officially pub…GBHACKERS.COM
29 AprU.S. Charges Suspected Scattered Spider Member Over Cyber IntrusionsFederal authorities have charged 19-year-old Peter Stokes, known online as “Bouquet,” for his alleged role in the notorious cybercriminal group Scattered Spider. Law enforcement arrested the dual U.S. and Estonian citizen earlier this month in Helsinki as he attempted…GBHACKERS.COM
29 AprExtending Ruzzy with LibAFLLibAFL is all the rage in the fuzzing community these days, especially with LLVM’s libFuzzer being placed in maintenance mode . Written in Rust, LibAFL claims improved performance, modularity, state-of-the-art fuzzing techniques, and libFuzzer compatibility . For these reasons, I…TRAILOFBITS.COM
29 AprCursor AI Extension Flaw Exposes Developer Tokens to Credential TheftSecurity researchers at LayerX have uncovered a high-severity vulnerability in the popular AI-powered development environment, Cursor. Dubbed “CursorJacking,” this flaw carries a CVSS score of 8.2 and exposes developers to immediate credential theft. Any installed ext…GBHACKERS.COM
29 AprMastering agentic AI security through exposure managementAs AI tools evolve from siloed chatbots to autonomous, hyperconnected systems, they create a vast new attack surface. Discover how to manage this risk by focusing on visibility, agency, and semantic security to protect your organization’s increasingly complex landscape of agentic…TENABLE.COM
29 AprExperts on Experts: The 2026 Threat Landscape is Moving Faster than Defenders ExpectThis week on Experts on Experts, I’m joined by Christiaan Beek, Rapid7’s VP of Threat Analytics, to talk through what we’re seeing in the 2026 threat landscape and how it connects to recent research coming out of Rapid7 Labs. We start with the report, but quickly move into what’s…RAPID7.COM
29 AprMicrosoft won’t patch PhantomRPC: Feature or bug?A researcher has detailed five ways to exploit PhantomRPC, which Microsoft rates “moderate” and does not plan to fix.MALWAREBYTES.COM
29 AprAll supported cPanel versions hit by critical auth bug, now patchedcPanel fixed a critical authentication flaw that could let attackers access servers. The issue affects all supported versions. cPanel released security updates to address a critical authentication vulnerability that could allow attackers to gain unauthorized access to its control…SECURITYAFFAIRS.COM
29 AprSwiss police arrest 10 suspected members of Nigeria-linked crime group Black AxeSwiss and German law enforcement have arrested 10 suspected members of the Nigerian criminal network Black Axe, including a regional leader believed to oversee operations in Southern Europe.THERECORD.MEDIA
29 AprAI Speeds Up Cyber AttacksAI is accelerating existing attack patterns rather than replacing them. Identity-based attacks account for the majority of cloud compromises, with human and system failures still the root cause. The real shift isn’t new tactics—it’s speed and scale. Attackers can move faster, aut…YOUTUBE.COM
29 AprAI Finds 38 Security Flaws in Electronic Health Record PlatformFlaws in OpenEMR's platform — used by more than 100,000 healthcare providers — enabled database compromise, remote code execution, and data theft.DARKREADING.COM
29 AprWhat It Takes to Run Marketing Solo with Sara Ceballos, Director of Marketing at BreachRxRunning marketing as a team of one means you’re responsible for everything, from attribution to brand to pipeline. Sara Ceballos, Director of Marketing, joins the show to talk through her time at Inspectiv, where she was brought in to support two new product launches, rethink the…THECYBERWIRE.COM
29 AprA wake-up call on frontier AI.OpenAI and Anthropic brief Congress on cyber-capable AI. The GAO flags improper DOGE access to Treasury payment systems. Greece moves to end online anonymity. CISA orders agencies to patch an exploited Windows zero-day. Researchers uncover ransomware that destroys data instead of…THECYBERWIRE.COM
29 AprReverse Engineering With AI Unearths High-Severity GitHub BugWiz used an AI reverse-engineering tool to pinpoint a vulnerability that previously would have been too costly and time-consuming to undertake.DARKREADING.COM
29 AprFive Things we Took Away from Gartner SRM Sydney 2026At this year's Gartner Security and Risk Management Summit in Sydney, Rapid7 CISO Brian Castagna joined industry CISO Nigel Hedges for a fireside chat on the decisions security leaders are actually making right now. They discussed the real decisions being made right now about bud…RAPID7.COM
29 AprModern Defensible Architecture: Resilience for the Australian Federal GovernmentHow Wiz enables Australian government agencies to operationalise MDA with real-time context, zero trust enforcement, and end-to-end cloud visibility.WIZ.IO
28 AprMicrosoft Patches Entra ID Role Flaw That Enabled Service Principal TakeoverAn administrative role meant for artificial intelligence (AI) agents within Microsoft Entra ID could enable privilege escalation and identity takeover attacks, according to new findings from Silverfort. Agent ID Administrator is a privileged built-in role introduced by Microsoft …THEHACKERNEWS.COM
28 AprClickUp Security Flaw Exposes 959 Emails Linked to Major Fortune 500 FirmsA major security flaw in the popular productivity platform ClickUp has exposed sensitive data, including 959 email addresses tied to Fortune 500 companies and government agencies. The primary vulnerability stems from a hardcoded Split.io SDK token left inside ClickUp’s production…GBHACKERS.COM
28 AprClaude Opus 4.6-Powered AI Coding Agent Wipes Production Database in 9 SecondsA Claude Opus 4.6-powered AI coding agent operating through the Cursor editor autonomously deleted the production database and backups of SaaS startup PocketOS in just nine seconds. The incident highlights critical security failures in AI guardrails and infrastructure access cont…GBHACKERS.COM
28 AprWhat CISOs need to get right as identity enters the agentic eraIdentity has always been central to security, but the proliferation of AI agents is rapidly changing the challenge of managing and securing identity, spurring CISOs to rethink their identity strategies — even how it is defined. “Identity is now both a control surface and an attac…CSOONLINE.COM
28 AprStopping AiTM attacks: The defenses that actually work after authentication succeedsThe security industry has spent years building better authentication. Longer passwords, second factors, hardware tokens. And attackers responded by moving past authentication entirely. Adversary-in-the-middle (AiTM) phishing does not steal credentials and replay them. It sits bet…CSOONLINE.COM
28 AprTop 10 Web Hacking Techniques of 2025 and a Hint for 2026 - James Kettle - ASW #380Portswigger's list of web hacking techniques is a long-running celebration of curiosity and research from the web hacking community. James Kettle shares his thoughts on the entries from 2025 and how he expects LLMs and agents to influence what the list will look like for next yea…YOUTUBE.COM
28 AprBuilding Resilience in a World of Constant ThreatsMegan Stifel, Chief Strategy Officer at the Institute for Security and Technology, joins Ann on this week’s episode of Afternoon Cyber Tea to discuss why cybersecurity must be treated as a shared governance responsibility, not just an IT issue. They explore how boardroom misalign…THECYBERWIRE.COM
28 AprVimeo suffers 3rd-party breach exposing user data, hackers threaten leakVimeo has disclosed a security incident stemming from a breach at third-party analytics provider Anodot, which resulted in unauthorized access to certain user and customer data. The company states that no video content, login credentials, or payment information were exposed, thou…CYBERINSIDER.COM
28 AprMDR Selection is a Partnership DecisionManaged Detection and Response (MDR) is a cybersecurity service that combines human expertise and technology to detect, investigate, and respond to threats 24/7. I write this as a Field CISO at Rapid7, but also as someone who has had to live with the operational reality of MDR on…RAPID7.COM
28 AprAfter Mythos: New Playbooks For a Zero-Window EraWhen patching isn’t fast enough, NDR helps contain the next era of threats. If you’ve been tracking advancements in AI, you know the exploit window, the short buffer that organizations relied on to patch and protect after a vulnerability disclosure, is closing fast. Anthropic’s n…THEHACKERNEWS.COM
28 AprSecuring RAG pipelines in enterprise SaaSIn the enterprise SaaS space, AI agents are becoming an integral part of the SaaS product. To make these intelligent agents truly useful, they need contextual, customer-specific knowledge, something standard Large Language Models (LLMs), open source or otherwise, inherently lack …CSOONLINE.COM
28 AprWhat Anthropic’s Mythos Means for the Future of CybersecurityTwo weeks ago, Anthropic announced that its new model, Claude Mythos Preview, can autonomously find and weaponize software vulnerabilities, turning them into working exploits without expert guidance. These were vulnerabilities in key software like operating systems and internet i…SCHNEIER.COM
28 AprMicrosoft fixes Entra ID flaw enabling privilege escalationMicrosoft fixed a Microsoft Entra ID flaw where the Agent ID Administrator role could enable privilege escalation and account takeover. Microsoft addressed a flaw in Microsoft Entra ID that could let attackers take over service accounts. The issue involved the Agent ID Administra…SECURITYAFFAIRS.COM
28 AprHTTP Requests with X-Vercel-Set-Bypass-Cookie Header, (Tue, Apr 28th)This weekend, we saw a few requests to our honeypot that included an "X-Vercel-Set-Bypass-Cookie" header. A sample request:
ISC.SANS.EDU
28 AprSecuring the git push pipeline: Responding to a critical remote code execution vulnerabilityHow we validated, fixed, and investigated a critical vulnerability in under two hours, and confirmed no exploitation. The post Securing the git push pipeline: Responding to a critical remote code execution vulnerability appeared first on The GitHub Blog .GITHUB.BLOG
28 AprSignal Phishing Campaign Targets German Officials in Suspected Russian OperationSuspected Russian phishing via Signal targeted German officials, exploiting trust to access accounts and sensitive political communications. A new wave of cyber operations targeting European political leadership is once again highlighting how modern espionage increasingly relies …SECURITYAFFAIRS.COM
28 AprGet Motivated: What to Expect from Our Keynote at Rapid7's Global Cybersecurity SummitSecurity teams prepare for incidents every day. Alerts are tuned, playbooks are built, and processes are tested. But when something actually happens, the challenge shifts. It becomes not just about making decisions under pressure, but how well that preparation has set teams up to…RAPID7.COM
28 AprAccess control with IAM Identity Center session tagsAs organizations expand their Amazon Web Services (AWS) footprint, managing secure, scalable, and cost-efficient access across multiple accounts becomes increasingly important. AWS IAM Identity Center offers a centralized, unified solution for managing workforce access to AWS acc…AWS.AMAZON.COM
28 AprA Vulnerability in OpenSSH Could Allow for Authentication BypassA vulnerability has been discovered in OpenSSH which could allow for authentication bypass. OpenSSH (Open Secdure Shell) is an open-source suite of secure networking utilities based on the SSH protocol. It provides encrypted communication sessions over unsecured networks in a cli…CISECURITY.ORG
28 AprWhy Sharing a Screenshot Can Get You Jailed in the UAEThe war in Iran has drawn attention to arrests in the United Arab Emirates over online content, but the legal framework behind that enforcement has existed for years.WIRED.COM
28 AprPitney Bowes confirms Salesforce breach after hacker leaks 25 million recordsPitney Bowes has confirmed to CyberInsider that it suffered a cybersecurity incident involving unauthorized access to customer data stored in its Salesforce environment. This admission follows claims by the ShinyHunters extortion group that it has stolen over 25 million records. …CYBERINSIDER.COM
28 AprMultiple Vulnerabilities in Mozilla Products Could Allow for Arbitrary Code ExecutionMultiple vulnerabilities have been discovered in Mozilla products, the most severe of which could allow for arbitrary code execution. Mozilla Firefox is a web browser used to access the Internet. Mozilla Firefox ESR is a version of the web browser intended to be deployed in large…CISECURITY.ORG
28 AprOracle Quarterly Critical Patches Issued April 21, 2026Multiple vulnerabilities have been discovered in Oracle products, the most severe of which could allow for remote code execution. Successful exploitation of the most severe of these vulnerabilities could result in an attacker gaining the same privileges as the logged-on user. Dep…CISECURITY.ORG
28 AprVidar Rises to Top of Chaotic Infostealer MarketThe malware has filled the gap created by last year's law enforcement takedowns of Lumma and Rhadamanthys.DARKREADING.COM
28 AprSpy agency officials say job loss anxiety, moving fast ‘safely’ among top challenges in AI workforce overhaulWhile tech leaders think about how to strategically deploy AI tools to support human intelligence needs, rank and filers express concerns about their livelihoods. The post Spy agency officials say job loss anxiety, moving fast ‘safely’ among top challenges in AI workforce overhau…CYBERSCOOP.COM
27 AprFake CAPTCHA IRSF Scam and 120 Keitaro Campaigns Drive Global SMS, Crypto FraudCybersecurity researchers have disclosed details of a telecommunications fraud campaign that uses fake CAPTCHA verification tricks to dupe unsuspecting users into sending international text messages that incur charges on their mobile bills, generating illicit revenue for the thre…THEHACKERNEWS.COM
27 AprCritical Gemini CLI Flaw Raises Supply Chain Security ConcernsGoogle has rolled out urgent security updates for its Gemini CLI and the accompanying GitHub Action to address a critical vulnerability. Tracked as GHSA-wpqr-6v78-jr5g, this flaw exposes continuous integration and continuous deployment (CI/CD) pipelines to Remote Code Execution (…GBHACKERS.COM
27 AprAttackers Chain CODESYS Vulnerabilities to Backdoor ApplicationsNozomi Networks Labs published critical research detailing three new vulnerabilities in the CODESYS Control runtime. When chained together, these security flaws allow an authenticated attacker with low-level privileges to replace a legitimate industrial control application with a…GBHACKERS.COM
27 AprADT - 5,488,888 breached accountsIn April 2026, home security firm ADT confirmed a data breach by ShinyHunters , which listed the company on its website as part of a "pay or leak" extortion attempt. The breach impacted 5.5M unique email addresses along with names, phone numbers and physical addresses. ADT also a…HAVEIBEENPWNED.COM
27 AprU.S. utility giant Itron discloses a security breachItron detected unauthorized access to part of its IT environment on April 13, 2026, and launched incident response and notified authorities. Itron disclosed a cyber incident involving unauthorized access to part of its internal IT systems, detected on April 13, 2026. The company …SECURITYAFFAIRS.COM
27 Apr25 open-source cybersecurity tools that don’t care about your budgetRegardless of the operating system you use, managing secrets, apps, cloud, compliance, and security operations can be overwhelming. The free, open-source tools presented in this article can help you detect threats, increase visibility, enforce controls, and investigate and respon…HELPNETSECURITY.COM
27 AprProduct showcase: LuLu reveals unauthorized outbound connections from Mac appsLuLu is a free, open-source firewall for macOS that lets you control which apps are allowed to send data from your computer. macOS includes a built-in firewall, but it mainly handles incoming connections. LuLu also monitors outgoing traffic. Installing and setting Up LuLu After d…HELPNETSECURITY.COM
27 AprOpenClaw Flaws Expose Systems to Policy Bypass AttacksOpenClaw, a rapidly adopted open-source autonomous AI agent framework, has released critical security updates to address three moderate-severity vulnerabilities. Found in npm package versions before 2026.4.20, these complex flaws expose systems to severe policy bypasses, unauthor…GBHACKERS.COM
27 AprThe ‘manager of agents’: How AI evolves the SOC analyst roleEvery SOC analyst has heard it by now: “AI is coming for your job”. I hear it in conversations with SOC teams. I see it in the hesitation during evaluations. And increasingly, I feel it as a source of resistance — especially from the very people AI is supposed to help. But the re…CSOONLINE.COM
27 AprRethinking Security from the OS Up in the Age of AI and more RSAC 2026 Interviews - ESW #456Rethinking Security from the OS Up in the Age of AI Karen Heart discusses a file-system–first approach to security, arguing that most modern attacks—including ransomware and supply chain compromises—succeed because they inherit user permissions and operate inside overly trusted s…YOUTUBE.COM
27 AprFake Income Tax Notices Used to Spread MalwareCybercriminals are exploiting India’s tax season by launching sophisticated phishing campaigns that impersonate the Income Tax Department to deliver dangerous malware to unsuspecting taxpayers. The malicious operation uses fake assessment notices and tax compliance warnings…GBHACKERS.COM
27 AprItron Discloses Data Breach After Hackers Access Internal SystemsItron, Inc., a leading smart metering and energy infrastructure technology company, has disclosed a cybersecurity incident after an unauthorized third party gained access to certain of its internal systems, according to a Form 8-K filing submitted to the U.S. Securities and Excha…GBHACKERS.COM
27 AprMythos Changed the Math on Vulnerability Discovery. Most Teams Aren't Ready for the Remediation SideAnthropic’s Claude Mythos Preview has dominated security discussions since its April 7 announcement. Early reporting describes a powerful cybersecurity-focused AI system capable of identifying vulnerabilities at scale and raising serious questions about how quickly organizations …THEHACKERNEWS.COM
27 AprPhantomCore Exploits TrueConf Vulnerabilities to Breach Russian NetworksA pro-Ukrainian hacktivist group called PhantomCore has been attributed to attacks actively targeting servers running TrueConf video conferencing software in Russia since September 2025. That's according to a report published by Positive Technologies, which found the threat actor…THEHACKERNEWS.COM
27 AprMicrosoft patched an ‘agent-only’ role that was notAn administrative role meant for AI agents within Microsoft’s Entra ID ecosystem could allow privilege escalation and tenant takeover attacks, as it had privileges over more than agent-related objects. Researchers at Silverfort found that users assigned to Microsoft’s “Agent ID A…CSOONLINE.COM
27 Apr27th April – Threat Intelligence ReportFor the latest discoveries in cyber research for the week of 27th April, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Vercel, a frontend cloud platform, has disclosed a security incident linked to a compromise at Context.ai, where stolen OAuth tokens…RESEARCH.CHECKPOINT.COM
27 AprEU Proposes Forcing Google to Share Search Data With Rivals Under DMAThe European Commission has proposed new measures that could force Google to share key search engine data with rival platforms under the Digital Markets Act, or DMA. The move is part of the EU’s wider push to reduce the market power of major technology companies and create fairer…GBHACKERS.COM
27 AprUS, UK authorities warn that Firestarter backdoor malware survives patchingA federal agency was impacted by a hacking campaign that exploited flaws in Cisco devices.CYBERSECURITYDIVE.COM
27 AprMedical device giant Medtronic confirms data breach incidentMedtronic has disclosed that an unauthorized party accessed portions of its corporate IT environment, while stating there is currently no evidence of disruption to medical devices, patient care, or core operations. The healthcare technology giant revealed the incident in a public…CYBERINSIDER.COM
27 AprCheckmarx Confirms GitHub Repository Data Posted on Dark Web After March 23 AttackCheckmarx has disclosed that its ongoing investigation tied to the supply chain security incident has revealed that a cybercriminal group published data related to the company on the dark web. "Based on current evidence, we believe this data originated from Checkmarx's GitHub rep…THEHACKERNEWS.COM
27 AprUnpatched 'PhantomRPC' Flaw in Windows Enables Privilege EscalationA researcher discovered five different exploit paths that stem from an architectural weakness in how Windows' Remote Procedure Call (RPC) mechanism handles connections to unavailable services.DARKREADING.COM
27 AprOptimize security operations through an AWS Security Hub POCApril 27, 2026: This post was first published in September 2025 when the enhanced AWS Security Hub was in public preview. It has since been updated to reflect the general availability of Security Hub. This revision also provides a more detailed, step-by-step framework for plannin…AWS.AMAZON.COM
27 AprOpen source package with 1 million monthly downloads stole user credentialssubmitted by schnurrito to security 5 points | 1 comments https://arstechnica.com/security/2026/04/open-source-package-with-1-million-monthly-downloads-stole-user-credentials/PROGRAMMING.DEV
26 AprWeek in review: Claude Mythos finds 271 Firefox flaws, Vercel breachHere’s an overview of some of last week’s most interesting news, articles, interviews and videos: SmokedMeat: Open-source tool shows what attackers do inside CI/CD pipelines Boost Security has released SmokedMeat, an open-source framework that runs attack chains against CI/CD inf…HELPNETSECURITY.COM
25 AprThe Patch Gap Is the ProblemMultiple public exploits are targeting Microsoft Defender’s internal privilege workflows, with confirmed use in active attacks. Some vulnerabilities have been patched, while others remain exposed. Security tools themselves can become attack surfaces. The delay between exploit rel…YOUTUBE.COM
25 AprGovernments and industry race to harness AI for vulnerability discovery.FIRESTARTER malware remained on Cisco devices after patches were applied. Cloud development platform Vercel confirms breach.THECYBERWIRE.COM
25 AprFirefox is quietly experimenting with Brave’s ad-blocking engineMozilla has quietly begun experimenting with Brave’s Rust-based ad-blocking engine in Firefox, signaling a potential shift in how the browser handles ads and trackers. The change was first spotted in Firefox 149 under Bugzilla entry 2013888, where Mozilla engineers introduced adb…CYBERINSIDER.COM
24 AprInside The Vercel Supply Chain ExploitInside the Vercel Breach: Highlighting OAuth Token Risk In a special edition of Cybersecurity Today, host Jim Love and guest Jamie Blasco (CTO, Nudge Security) discuss Vercel, a major developer hosting platform, and a breach tied to OAuth grants and shadow AI. Reporting shared by…CYBERSECURITYTODAY.LIBSYN.COM
24 AprHackers Exploit SS7 and Diameter Flaws to Track Mobile Users GloballyA recent investigation by Citizen Lab has uncovered sophisticated, multi-year surveillance campaigns exploiting foundational vulnerabilities in global mobile networks. The report, titled “Bad Connection,” reveals how suspected commercial surveillance vendors (CSVs) we…GBHACKERS.COM
24 AprPhantomRPC: A new privilege escalation technique in Windows RPCKaspersky researcher discovered a vulnerability in RPC architecture that enables an attacker to create a fake RPC server and escalate their privileges.SECURELIST.COM
24 AprTropic Trooper Uses Trojanized SumatraPDF and GitHub to Deploy AdaptixC2Chinese-speaking individuals are the target of a new campaign that uses a trojanized version of SumatraPDF reader to deploy the AdaptixC2 Beacon post-exploitation agent and ultimately facilitate the abuse of Microsoft Visual Studio Code (VS Code) tunnels for remote access. Zscale…THEHACKERNEWS.COM
24 AprXiongmai IP Camera Flaw Lets Attackers Bypass AuthenticationA critical security vulnerability has been identified in Hangzhou Xiongmai Technology’s XM530 IP Cameras, putting countless commercial facilities at risk. This severe flaw allows remote attackers to bypass authentication protocols and access sensitive device information eas…GBHACKERS.COM
24 AprHackers Exploit Pastebin PowerShell Script to Hijack Telegram SessionsHackers are experimenting with a new Telegram‑focused session stealer that hides in a Pastebin‑hosted PowerShell script posing as a Windows telemetry update, giving defenders a rare view into how such tools are built and tested. The script does not attempt to grab passwords or br…GBHACKERS.COM
24 AprFirefox flaw enables cross-site tracking, undermines Tor Browser defensesA newly disclosed vulnerability in Firefox and Tor Browser allowed websites to generate a stable, process-level identifier using IndexedDB, undermining private browsing protections and cross-site isolation. The issue has been fixed in recent Firefox releases following responsible…CYBERINSIDER.COM
24 AprHackers Exploit Agent ID Administrator Role to Hijack Service PrincipalsA severe scoping vulnerability was recently discovered in Microsoft Entra ID’s new Agent Identity Platform. The security flaw allowed users assigned the Agent ID Administrator role to hijack arbitrary service principals across an organization’s tenant, leading to pote…GBHACKERS.COM
24 AprUK Biobank Data Breach: Health Data of 500,000 Listed for Sale in ChinaUK government Minister confirms that breached health records of UK Biobank volunteers were up for sale on Chinese ecommerce platforms before being removedINFOSECURITY-MAGAZINE.COM
24 Apr3 Reasons to Attend our Global Cybersecurity Summit if you’re Focused on AI, Threats, and CTEMSecurity teams are dealing with a different kind of pressure now. It is not just the volume of alerts or the pace of attacks, but also the gap between what teams can see and what they can act on with confidence. That gap shows up in different ways. Threats move across identity an…RAPID7.COM
24 AprCIS Control Becomes LawRegulators such as NYDFS are requiring financial institutions to formally attest to MFA adoption and maintain accurate inventories of their IT assets, aligning directly with CIS Control 1. These are considered foundational cybersecurity practices, yet they are still not universal…YOUTUBE.COM
24 AprFIRESTARTER malware remained on Cisco devices after patches were applied.Open-source AI models may match Mythos's capabilities. White House moves to fight foreign extraction of US AI capabilities.THECYBERWIRE.COM
24 AprMeta’s Biggest Layoff of 2026 Is Confirmed to Start Next MonthMeta will cut 10% of its workforce, impacting about 8,000 employees, as it shifts resources to AI and reduces costs amid ongoing restructuring efforts. The post Meta’s Biggest Layoff of 2026 Is Confirmed to Start Next Month appeared first on TechRepublic .TECHREPUBLIC.COM
24 AprCISA last in line for access to Anthropic MythosThe US Cybersecurity and Infrastructure Security Agency (CISA) does not yet have access to Anthropic’s bug-hunting AI model, Claude Mythos, even though other government agencies do, Axios reported earlier this week . As if that weren’t a big enough slap in the face for the nation…CSOONLINE.COM
24 AprNew US House privacy bills raise hard questions about enterprise data collectionUS House Republicans have introduced two major privacy proposals that would reshape how US companies collect, process, and retain consumer data: the SECURE Data Act for general consumer privacy and the GUARD Financial Data Act for financial institutions. The bills would create na…CSOONLINE.COM
24 AprWhen Updates Turn Into MalwareThe “Canister Worm” attack compromises legitimate NPM publishers and replaces package contents with malware that executes during installation or updates. Developers can unknowingly pull malicious code directly into their environments. Because the source appears trusted, tradition…YOUTUBE.COM
📋 SECURITY BULLETINS 62[+]
22 JulOracle Patches Over 1,400 Vulnerabilities With Quarterly Security UpdatesMany of the vulnerabilities fixed with the July 2026 Critical Patch Update were likely discovered by AI. The post Oracle Patches Over 1,400 Vulnerabilities With Quarterly Security Updates appeared first on SecurityWeek .SECURITYWEEK.COM
22 JulMicrosoft to stop Exchange 2016 / 2019 security updates in OctoberMicrosoft has reminded customers that it will stop shipping security updates for Exchange 2016 and 2019 through the Extended Security Update (ESU) program in October. [...]BLEEPINGCOMPUTER.COM
22 JulEclypsium Launches InfraTrust to Centralize Enterprise Hardware Security RisksNew global infrastructure security intelligence database debuts alongside monthly advisory delivering actionable risk data to protect critical enterprise hardware infrastructure. Portland, OR – July 22, 2026 – Eclypsium, the infrastructure assurance company, today announced the l…ECLYPSIUM.COM
20 JulWindows KB5121767 OOB update fixes shutdowns on some Dell PCsMicrosoft has released emergency updates to fix a known issue causing some Dell PCs to shut down after installing the July 2026 Windows 11 security updates. [...]BLEEPINGCOMPUTER.COM
17 JulWindows Server 2022 reach end of mainstream support in 90 daysMicrosoft announced that Windows Server 2022 will reach the mainstream end date in October 2026, but will switch to extended support and continue receiving security updates for five more years. [...]BLEEPINGCOMPUTER.COM
16 JulSecurity updates available for Adobe, Chrome, Firefox, VMWare, and ZoomSeveral updates have been made available including those for Adobe, Chrome, Firefox, VMWare, and Zoom.MALWAREBYTES.COM
15 JulMicrosoft: Some Dell PCs shut down after recent Windows updatesMicrosoft is blocking this month's Windows 11 security updates on some Dell devices because they are causing shutdowns and performance issues. [...]BLEEPINGCOMPUTER.COM
15 JulFreeRDP 3.29.0 security update resolves 22 advisoriesFreeRDP is a free implementation of the Remote Desktop Protocol, released under the Apache license, and it runs on a large share of workstations and servers through the many tools built on it. The 3.29.0 version is a security, bugfix, and maintenance update that resolves 22 advis…HELPNETSECURITY.COM
15 JulICS Patch Tuesday: Vulnerabilities Fixed by Siemens, Schneider, RockwellThe industrial giants fixed dozens of vulnerabilities across their ICS products, with advisories also released by CISA and VDE CERT. The post ICS Patch Tuesday: Vulnerabilities Fixed by Siemens, Schneider, Rockwell appeared first on SecurityWeek .SECURITYWEEK.COM
15 JulMicrosoft patches record number of security vulnerabilities, citing its use of AIMicrosoft's monthly release of security fixes, dubbed Patch Tuesday, resolved a record 570 security vulnerabilities across the company's product line, thanks to discoveries with AI.TECHCRUNCH.COM
14 JulMicrosoft releases Windows 10 KB5099539 extended security updateMicrosoft has released the Windows 10 KB5099539 extended security update, which includes the July 2026 Patch Tuesday security updates for 570 vulnerabilities, along with additional security fixes. [...]BLEEPINGCOMPUTER.COM
13 JulMicrosoft demystifies how Windows updates workMicrosoft has published a guide explaining the Windows servicing model, outlining the purpose of monthly security updates, optional preview releases, hotpatch updates, and the mechanisms used to deliver new features throughout the year. “Most individuals and organizations regular…HELPNETSECURITY.COM
13 JulMicrosoft Entra ID security updates: Passkeys are the default authentication method in Entra IDMicrosoft Entra ID makes passkeys the default sign-in experience and introduces a new model for SMS and voice authentication. Read about how to prepare. The post Microsoft Entra ID security updates: Passkeys are the default authentication method in Entra ID appeared first on Micr…MICROSOFT.COM
12 JulDebian 13.6 security update patches over a hundred advisories in trixieMost PCs still run with a UEFI Secure Boot certificate authority, installed by default since 2013, that has now expired. That certificate signed the bootloaders letting machines start with Secure Boot turned on. Its expiry sits at the center of the sixth update to Debian 13, code…HELPNETSECURITY.COM
10 JulJuly 2026 Patch Tuesday forecast: Is CVE tracking still practical?I was off by a month in my forecast of record-setting CVE releases from Microsoft. In June, we saw the deluge of over 200 reported CVEs that I expected in May. There were 116 CVEs for Windows 11 and 104 for Windows 10. In addition, we saw large numbers in both common applications…HELPNETSECURITY.COM
10 JulMicrosoft Warns of Increase in Number of Security UpdatesMicrosoft has said the volume of Windows security updates is set to grow as it uses AI to find new bugsINFOSECURITY-MAGAZINE.COM
9 JulMicrosoft expects more Windows security updates from AI-discovered flawsMicrosoft says Windows users should expect to see an increase in security updates as the company increasingly relies on artificial intelligence to discover vulnerabilities in its codebase. [...]BLEEPINGCOMPUTER.COM
4 JulFBI: TeamPCP Compromised Dev Tools to Steal Cloud CredentialsFBI says TeamPCP poisoned trusted developer tools to steal cloud credentials, spread malware through software updates, and extort victims. On July 2, 2026, the FBI published a FLASH alert identifying the criminal group called TeamPCP and detailing how it compromised widely used d…SECURITYAFFAIRS.COM
2 JulIt’s 37oC, And All We Can Think About Is ColdFusion (Adobe ColdFusion Security Bulletin APSB26-68 CVE Bonanza)We’re back, melting - we’ve tried shouting, screaming, and throwing things at the Sun, and it is just not working. Before we begin our analysis, we want to be clear - given the number of vulnerabilities fixed (and some not mentioned..), we’ve struggled to hav…LABS.WATCHTOWR.COM
30 JunApple Fixes WebKit Flaws in iOS and macOS, With Help From AI ToolsApple released updates for iOS, iPadOS, macOS, and Safari, fixing WebKit flaws, four of which were found using AI tools like Claude and Codex Apple pushed out security updates for iOS, iPadOS, macOS, and Safari on Monday, and this round comes with a twist worth noticing. Four of …SECURITYAFFAIRS.COM
26 JunMicrosoft gives Windows 10 users an unexpected extra year of free security updatesMicrosoft has given Windows 10 users another year of free security updates, extending its consumer Extended Security Updates (ESU) program until October 12, 2027. “Windows 10 support has ended. You can enroll in ESU any time until the program ends on October 12, 2027. If you’re a…HELPNETSECURITY.COM
25 JunMicrosoft quietly extends free Windows 10 ESU support to October 2027Microsoft has quietly extended its free Windows 10 Extended Security Updates (ESU) program for consumers by an additional year, allowing enrolled devices to continue receiving security updates until October 12, 2027. [...]BLEEPINGCOMPUTER.COM
23 JunSN 1084: The Residential Proxy Threat - Malicious Proxies in Your Living RoomA flood of everyday gadgets, from cheap streaming boxes to digital photo frames, are being secretly conscripted into global proxy networks and used to mask major cyberattacks—possibly even targeting your own home network. Worries of AI-power cyberattacks are spreading. Mythos "mi…TWIT.TV
22 JunThousands of D-Link routers under control of AryStinger botnetThousands of outdated D-Link routers have been absorbed into the AryStinger botnet, with no future security updates available to protect them.MALWAREBYTES.COM
19 JunMicrosoft broke some OLE automations with latest Windows updateMicrosoft Office users may find that some of their applications are failing to open when called on by third-party applications. It’s an issue that has emerged after the latest round of Microsoft updates . The problem affects Word, Excel, and other Office applications opened from …CSOONLINE.COM
18 JunMicrosoft fixes Windows Server 2016 security update failuresMicrosoft has fixed a known issue causing the June 2026 security updates to fail on Windows Server 2016 systems that weren't up to date. [...]BLEEPINGCOMPUTER.COM
18 JunF5 issues out-of-band patches for critical NGINX vulnerabilitiesCybersecurity company F5 has released out-of-band security updates to address multiple NGINX web server vulnerabilities, including two critical-severity flaws that could allow attackers to execute code on vulnerable systems. [...]BLEEPINGCOMPUTER.COM
18 JunApple fixes Beats Studio Buds flaw that let hackers spy on conversationsApple has released security updates to patch a high-severity flaw affecting the Beats Studio Buds wireless earbuds that could allow attackers in Bluetooth range to spy on users' conversations. [...]BLEEPINGCOMPUTER.COM
17 JunOracle’s Second Monthly Security Updates Deliver 245 PatchesOracle has released its June 2026 Critical Security Patch Update to fix vulnerabilities in Communications, EBS, Enterprise Manager and other products. The post Oracle’s Second Monthly Security Updates Deliver 245 Patches appeared first on SecurityWeek .SECURITYWEEK.COM
11 JunMicrosoft fixes BitLocker recovery bug on Windows Server 2025Microsoft has resolved a known issue causing some Windows Server 2025 devices to boot into BitLocker recovery after installing the April 2026 security update. [...]BLEEPINGCOMPUTER.COM
10 JunICS Patch Tuesday: Vulnerabilities Fixed by Siemens, Schneider, Phoenix ContactIn addition, Rockwell Automation announced some enhancements to its SecureOT cybersecurity solution for OT. The post ICS Patch Tuesday: Vulnerabilities Fixed by Siemens, Schneider, Phoenix Contact appeared first on SecurityWeek .SECURITYWEEK.COM
9 JunMicrosoft releases Windows 10 KB5094127 extended security updateMicrosoft has released the Windows 10 KB5094127 extended security update, which fixes the June 2026 Patch Tuesday vulnerabilities and adds new functionality to monitor the rollout of updated Secure Boot certificates that replace those expiring this month. [...]BLEEPINGCOMPUTER.COM
9 JunMicrosoft breaks Patch Tuesday record with 206 vulnerabilitiesFears and warnings about a roaring flood of error-riddled software have materialized. And the disease is spreading. The post Microsoft breaks Patch Tuesday record with 206 vulnerabilities appeared first on CyberScoop .CYBERSCOOP.COM
9 JunMicrosoft Patch Tuesday for June 2026 — Snort rules and prominent vulnerabilitiesMicrosoft Patch Tuesday details for June 2026.TALOSINTELLIGENCE.COM
8 JunMicrosoft changes how Defender for Endpoint EDR updates are delivered on WindowsMicrosoft will distribute Defender for Endpoint EDR updates through Microsoft Update, enabling EDR security improvements to be released independently of monthly Windows operating system updates. The rollout started for Windows 10 devices in late May 2026 and will expand to Window…HELPNETSECURITY.COM
5 JunJune 2026 Patch Tuesday forecast: Where are the CVEs?My forecast from last month was only partly right. After the Anthropic Mythos announcements and the deluge of newly discovered vulnerabilities from vendors like Mozilla, Microsoft’s updates were standard fare, 65 CVEs reported in Windows 11 and 58 in Windows 10. The Microsoft Off…HELPNETSECURITY.COM
1 JunMicrosoft fixes KB5089549 Windows security update install issuesMicrosoft has resolved a known issue causing installation failures and 0x800f0922 errors when deploying the May 2026 Windows 11 security update (KB5089549). [...]BLEEPINGCOMPUTER.COM
26 MayMicrosoft: Domain Controller lookup may fail on Windows Server 2016Microsoft has confirmed a new known issue affecting Windows Server 2016 systems that causes domain controller lookups to fail after installing the KB5087537 May 2026 security update. [...]BLEEPINGCOMPUTER.COM
21 MayGoogle Chrome Security Flaws Could Let Attackers Execute Code RemotelyGoogle has released a critical security update for its Chrome browser, addressing multiple vulnerabilities that could allow attackers to execute arbitrary code on affected systems. The update, now rolling out to users globally, upgrades Chrome to version 148.0.7778.178/179 for Wi…GBHACKERS.COM
20 MaySmashing Security podcast #468: High-speed train hacks and homicidal lawnmowersA 23-year-old radio enthusiast spent £300 on a piece of kit from the internet, and used it to bring four packed high-speed trains to a screeching halt. His defence in court? Possibly the most creative excuse we've heard all year. Meanwhile, owners of $4,000 robot lawnmowers are d…GRAHAMCLULEY.COM
19 MaymacOS Malware Abuses Fake Google Update for PersistenceA newly observed variant of the SHub macOS infostealer, dubbed “Reaper,” is expanding its capabilities with stealthier delivery, enhanced data theft, and a persistence mechanism disguised as a legitimate Google software update. The Reaper variant continues SHub’s use of fake appl…GBHACKERS.COM
19 MayDrupal is rolling out an emergency security update on May 20. You cannot miss itDrupal Is Pushing an Emergency Security Update Tomorrow. If You Run a Drupal Site, This Is Not One to Miss. Something significant is coming out of the Drupal project tomorrow, and the way the announcement is worded should be enough to get any site administrator’s attention.…SECURITYAFFAIRS.COM
15 MayGoogle Patches 79 Chrome Security Vulnerabilities, 14 Rated CriticalGoogle has rolled out a major Chrome security update, fixing 79 vulnerabilities in the Stable channel, including 14 critical flaws that could allow attackers to execute arbitrary code or crash systems. The update, now available as version 148.0.7778.167/168 for Windows and Mac an…GBHACKERS.COM
13 MayMicrosoft Fixes 17 Critical Flaws in May Patch TuesdayMicrosoft has patched 120 vulnerabilities in this month’s security update roundINFOSECURITY-MAGAZINE.COM
13 MayMicrosoft Releases Cumulative Update for Windows 11, Version 25H2 and 24H2Microsoft has officially released its May 2026 Patch Tuesday updates, delivering critical security fixes and system improvements for multiple Windows 11 versions. According to Microsoft release notes, the deployment includes cumulative update KB5089549 for Windows 11 versions 25H…GBHACKERS.COM
13 MayGoogle Launches New Android Security Features to Fight Scams, TheftGoogle detailed Android security updates for 2026, including verified bank calls, stronger theft protection, OTP hiding, and spyware forensics. The post Google Launches New Android Security Features to Fight Scams, Theft appeared first on TechRepublic .TECHREPUBLIC.COM
13 MayMicrosoft Patch Tuesday for May 2026 fix 138 bugs, some of them are alarmingMicrosoft’s May 2026 Patch Tuesday fixed 138 flaws, including 30 critical bugs, across Windows, Office, Azure, Edge, SQL Server, and more. Microsoft’s May 2026 Patch Tuesday patched 138 vulnerabilities in a single release. That is a number that gives pause even for people a…SECURITYAFFAIRS.COM
13 MayEvery layer needs a patch now.Patch Tuesday. Global agencies update SBOM guidance. Iran-linked espionage group Seedworm breached a major South Korean electronics manufacturer. A telehealth platform breach affects 716,000. Foxconn confirms a cyberattack. Maria Varmazis has an update on orbital data centers. A …THECYBERWIRE.COM
12 MayMicrosoft May 2026 Patch Tuesday, (Tue, May 12th)Today&#;x26;#;39;s Microsoft patch Tuesday fixes 137 different vulnerabilities. In addition, the update addresses 137 Chromium-related issues affecting Microsoft Edge.
ISC.SANS.EDU
12 MayiOS 26.5 Updates RCS Messaging, Apple Maps, and iPhone WallpapersApple’s iOS 26.5 update adds encrypted RCS, new wallpapers, Maps suggestions, and security updates for older devices. The post iOS 26.5 Updates RCS Messaging, Apple Maps, and iPhone Wallpapers appeared first on TechRepublic .TECHREPUBLIC.COM
12 MayPatch Tuesday, May 2026 EditionArtificial intelligence platforms may be just as susceptible to social engineering as human beings, but they are proving remarkably good at finding security vulnerabilities in human-made computer code. That reality is on full display this month with some of the more widely-used s…KREBSONSECURITY.COM
12 MayMicrosoft Patch Tuesday for May 2026 — Snort rules and prominent vulnerabilitiesMicrosoft has released its monthly security update for May 2026, which includes 112 vulnerabilities affecting a range of products, including 16 that Microsoft marked as “critical”.TALOSINTELLIGENCE.COM
12 MayMicrosoft addresses 137 vulnerabilities in May’s Patch Tuesday, including 13 rated criticalThe high volume of vulnerabilities reflects a growing trend researchers have been anticipating as artificial intelligence models are deployed to find previously uncovered defects in code. The post Microsoft addresses 137 vulnerabilities in May’s Patch Tuesday, including 13 rated …CYBERSCOOP.COM
11 MayUS: FCC Relaxes Foreign-Made Router Ban to Allow for Security UpdatesThe same extension applies to security updates shipped to US-based users of foreign-made dronesINFOSECURITY-MAGAZINE.COM
11 MayFCC pushes ban on security updates for foreign-made routers, drones to 2029The router deadline, originally slated for March 1, 2027, has been pushed back to at least January 1, 2029, according to the announcement from the FCC’s Office of Engineering and Technology (OET).THERECORD.MEDIA
7 MayGoogle pushes massive Chrome security update to patch 127 flawsGoogle has released Chrome 148 to the stable channel with one of the largest security update batches in the browser’s history, patching 127 vulnerabilities across Windows, macOS, and Linux systems. The update includes three critical flaws and dozens of high-severity memory safety…CYBERINSIDER.COM
5 MayOracle rolls out monthly security patch updatesOracle is changing how its security fixes are delivered: starting in May 2026, there will be a monthly Critical Security Patch Update. “Each [monthly] CSPU is smaller and more focused, making it easier to apply critical fixes quickly [to customer-managed deployments],”…HELPNETSECURITY.COM
1 MayMicrosoft Windows 11 April 2026 Security Update Disrupts Third-Party Backup ToolsThe April 2026 security update for Windows 11, designated as KB5083769, is causing severe disruptions for users relying on third-party backup solutions. Deployed for Windows 11 versions 24H2 and 25H2, this patch introduces a critical flaw that breaks the Microsoft Volume Shadow C…GBHACKERS.COM
1 MaySonicWall patches three SonicOS flaws in Gen 6, 7 and 8 firewalls. Patch them nowSonicWall patches three SonicOS flaws in Gen 6, 7 and 8 firewalls. The company released firmware updates to block bypass attacks and unauthorized access. SonicWall released urgent firmware updates to fix three SonicOS vulnerabilities affecting Gen 6, Gen 7, and Gen 8 firewalls. T…SECURITYAFFAIRS.COM
29 AprMicrosoft Confirms Remote Desktop Warning Issue After April UpdateMicrosoft has officially confirmed a known issue affecting Remote Desktop Protocol (RDP) connections following the April 14, 2026, Patch Tuesday updates. Specifically impacting Windows 11 version 26H1 (KB5083768, OS Build 28000.1836), the update was intended to harden systems aga…GBHACKERS.COM
28 AprFake Tax Audits and Updates Fuel Silver Fox Malware CampaignA China-linked threat group known as Silver Fox is running a new wave of cyber campaigns using fake tax audit notifications and software update lures to deliver malware across Asia. Active since at least 2022, the group initially focused on financially motivated attacks but, sinc…GBHACKERS.COM
27 AprMicrosoft Releases Enterprise Policy Option to Disable Windows 11 CopilotMicrosoft has introduced a new enterprise policy setting that allows IT administrators to silently uninstall the Microsoft Copilot app from managed Windows 11 devices, marking a significant shift in how organizations can control AI tool deployment across their fleets. The new Rem…GBHACKERS.COM
📢 SECURITY ADVISORIES 627[+]
23 JulUS Warns of Iranian Hackers Targeting Siemens, Schneider, and Rockwell ICS DevicesAn updated advisory from federal agencies provides information on the techniques used to hack programmable logic controllers. The post US Warns of Iranian Hackers Targeting Siemens, Schneider, and Rockwell ICS Devices appeared first on SecurityWeek .SECURITYWEEK.COM
23 JulANCHOR-CI could fix 20 years of broken government-industry collaborationThe government spent the past two decades learning what private sector partners have always known: cyber resilience requires everyone in the room. ANCHOR-CI is proof that the lessons may finally stick. The post ANCHOR-CI could fix 20 years of broken government-industry collaborat…CYBERSCOOP.COM
23 JulIranian Hackers Target Siemens and Schneider Industrial Systems, CISA WarnsUS government agencies have warned that Iranian cyber actors are targeting US-based Siemens and Schneider industrial equipmentINFOSECURITY-MAGAZINE.COM
23 JulGAO report details scope of cybersecurity regulation overlapA morass of rules is forcing companies to report the same information multiple times — and sometimes, those rules conflict.CYBERSECURITYDIVE.COM
23 JulRubio restricts visas for sextortionists, cyber scammersThe move stems from a Trump executive order as the administration continues to pursue cyber-enabled fraud and other crimes. The post Rubio restricts visas for sextortionists, cyber scammers appeared first on CyberScoop .CYBERSCOOP.COM
22 JulStates Want ICE Agents to Show Their Faces. The Trump Administration Is Blocking ThemFederal lawyers say anti-mask laws would endanger immigration agents, citing an ICE face-recognition art project that doesn’t actually work.WIRED.COM
22 JulEU Financial Institutions Leak Data Through Cookie TrackersEuropean banks inadvertently transmitted customer data to ad platforms via tracking pixels, raising serious compliance, security, and privacy concerns.DARKREADING.COM
22 JulFederal agencies broaden alert on Iran-linked OT attacksThe observed incidents include “malicious project file interactions and manipulation of data on human machine interface (HMI) and supervisory control and data acquisition (SCADA) displays,” the advisory says.THERECORD.MEDIA
22 JulExtension of CISA 2015 info-sharing protections passes as part of House’s defense billA 10-year renewal of the cybersecurity information-sharing law known as CISA 2015 passed as part of the House's fiscal 2027 defense authorization bill.THERECORD.MEDIA
22 JulMost federal cybersecurity reporting rules are duplicative, study findsThe Government Accountability Office looked at 117 rules across 37 agencies and found 70% had reporting requirements that were overlapping. The post Most federal cybersecurity reporting rules are duplicative, study finds appeared first on CyberScoop .CYBERSCOOP.COM
21 JulMicrosoft shares manual fix for WSUS sync delays and timeoutsMicrosoft has shared manual mitigations to help IT administrators fix Windows Server Update Services (WSUS) servers affected by a known issue that causes Windows Update scans to fail or time out. [...]BLEEPINGCOMPUTER.COM
21 JulShufti simplifies cross-border compliance with the Glocal PlatformShufti has launched the Shufti Glocal Platform, a compliance lifecycle management solution designed to help organizations manage identity verification, fraud prevention, risk assessment, and regulatory compliance through a single platform across every industry, every region, and …HELPNETSECURITY.COM
21 JulThe Trump administration's AI czar resigns.Extortion group wipes Romania's land registry database. FBI warns of impersonators targeting scam victims.THECYBERWIRE.COM
21 JulHouse intel bill includes provisions on state and local threat intelligence, election security, AIThe House Intelligence Committee advanced its fiscal 2027 authorization legislation Monday. The post House intel bill includes provisions on state and local threat intelligence, election security, AI appeared first on CyberScoop .CYBERSCOOP.COM
21 JulWhere’s the Trump administration line on AI regulation?The messy approach to U.S. AI regulation reflects both the rapid speed of model cyber capabilities and the White House’s “education” over the past two years, experts said. The post Where’s the Trump administration line on AI regulation? appeared first on CyberScoop .CYBERSCOOP.COM
21 JulTrump Orders Defense Contractors to Map Software, Suppliers Across Critical Supply ChainsNew executive order calls for end-to-end visibility into defense supply chains, including software dependencies, foreign ownership and cyber-related supplier risks. The post Trump Orders Defense Contractors to Map Software, Suppliers Across Critical Supply Chains appeared first o…SECURITYWEEK.COM
20 JulRussian Intelligence Hacks IP Cameras to Spy on Military Logistics Across NATO States and UkraineAt least one Russian intelligence service is systematically hijacking internet-connected security cameras across Europe and Ukraine, using the feeds to watch military transport routes, weapons shipments bound for Kyiv, and the locations of Ukrainian troops. That is the finding of…THEHACKERNEWS.COM
20 JulBanning AI Won't Stop ItHighly regulated industries have often been slower to adopt AI because regulations and risk concerns create uncertainty. But organizations are increasingly realizing they can't delay forever. Cybersecurity and risk teams are shifting from acting solely as gatekeepers to becoming …YOUTUBE.COM
20 JulDutch Intelligence Warns Russia Uses Hacked IP Cameras for Military EspionageDutch intelligence says Russia hacks IP cameras to monitor NATO military logistics and weapons shipments to Ukraine. The Netherlands’ AIVD and MIVD, the civilian and military intelligence services, published a joint advisory on July 10 confirming that at least one Russian i…SECURITYAFFAIRS.COM
20 JulHackers were inside South Korea's diplomat training system for 9 monthsUnidentified hackers compromised an online education system used by South Korea's diplomatic academy, stealing personal information belonging to former and current employees of the country's Ministry of Foreign Affairs.THERECORD.MEDIA
18 JulThe Future of Age Verification: Your Face Never Leaves Your DeviceAs age verification laws expand worldwide, organizations face growing pressure to protect users' privacy while meeting regulatory requirements. Incode explains how on-device age estimation verifies age without transmitting or storing facial images, reducing biometric privacy risk…BLEEPINGCOMPUTER.COM
17 JulThe five step plan that cuts security budget wasteIn this Help Net Security video, Viktor Bulanek, CTO of Penetrify, explains where security budget waste comes from. Budgets get built around vendor categories, compliance checkboxes, and last year’s headlines. Attackers work along attack paths, and that mismatch is where th…HELPNETSECURITY.COM
17 JulSenior executives are killing your shadow AI strategyShadow IT has long been a major problem for CISOs, but the biggest problem may be coming from the executive suite’s hunger for unsanctioned AI. Nearly two-thirds of senior decision-makers admit to using unapproved AI tools , compared to just 31% of lower-level employees, accordin…CSOONLINE.COM
17 JulZelensky appoints Ukraine's acting security service chief as acting defense ministerYevhenii Khmara, a major general with deep experience in intelligence, counterterrorism and long-range strikes against Russia, is Ukraine's new acting defense minister.THERECORD.MEDIA
17 JulPodcast: Broken Governance, Agentic AI, and the MindStone Agent Exclusive(Video) Artificial intelligence is transforming cybersecurity, but are governance, compliance, and security practices evolving fast enough to keep up? The post Podcast: Broken Governance, Agentic AI, and the MindStone Agent Exclusive appeared first on SecurityWeek .SECURITYWEEK.COM
17 JulState officials, election experts pan Trump speech: ‘This is what desperation looks like’The president’s speech re-hashed debunked conspiracies around U.S. elections. Critics say the administration’s 18-month investigation into voter fraud has been a total failure. The post State officials, election experts pan Trump speech: ‘This is what desperation looks like’ appe…CYBERSCOOP.COM
16 JulWho governs your AI agents?Your team spent a decade maturing privileged access management. Then AI agents arrived and they don’t log in like humans. Now your biggest insider threat is an AI agent that lacks the access it needs, and then it goes to get it. In this episode Sundari Parekh, VP of AI Security a…THECYBERWIRE.COM
16 JulRomania’s land registry hit by cyber attack, data allegedly for saleRomania’s National Agency for Cadastre and Land Registration (ANCPI) suffered a major disruption on Tuesday, July 14, when its e-Terra cadastre and land registry app became unavailable to users. What was first declared to be a “major technical incident” has now …HELPNETSECURITY.COM
16 JulUkrainians rally against dismissal of tech-minded defense minister FedorovUkraine President Volodymyr Zelensky dismissed Defense Minister Mykhailo Fedorov, who championed the push to integrate drone technology and digital innovation into the military.THERECORD.MEDIA
16 JulSenator calls on Rubio, Blanche to push back against Canadian surveillance legislationDemocratic Sen. Ron Wyden says the Trump administration should pressure Canada not to enact a proposal that would "weaponize American technology infrastructure" for surveillance purposes.THERECORD.MEDIA
15 JulMicrosoft is forcing an enterprise transition to passkeysPasskeys have been around for some time, but enterprise-wide adoption to this point has been slow for a number of reasons. But soon, many Microsoft customers won’t have a choice. Starting September 1, Microsoft will roll out passkeys as the default authentication method in its cl…CSOONLINE.COM
15 JulProduct showcase: Trust Chain TPRM turns vendor compliance evidence into verified assuranceTrust Chain is an AI-native third-party risk management (TPRM) solution by Strike Graph that replaces the security questionnaire model with validated evidence of compliance. Rather than asking vendors to self-report their security posture, Trust Chain requires vendors to submit e…HELPNETSECURITY.COM
15 JulWhen 80,000 fans log on at once: The 2026 World Cup’s unique cybersecurity issuesWith the World Cup in full swing, stadiums across North America are currently accommodating thousands of fans every match day. That said, the stadiums’ biggest security challenge isn’t of a physical nature. It is not hyperbolic to say that football stadiums are some of the most c…CSOONLINE.COM
15 JulTrump administration unveils AI-supported clearinghouse for cyber vulnerabilitiesThe Gold Eagle program will allowe industry, critical infrastructure operators and the government to use artificial intelligence to rapidly detect, prioritize and patch cybersecurity vulnerabilities, officials said.THERECORD.MEDIA
14 JulUS authorities warn of Russian attacks on critical infrastructureThe US authorities NSA, FBI, and CISA warn that Russian hackers have recently carried out a number of attacks on critical infrastructure in North America and Europe. Hackers are reportedly breaking into networks using vulnerable and misconfigured routers, making it extra importan…CSOONLINE.COM
14 JulShifting Security and Protecting the Pharma Supply Chain with Andy HillisHost Caleb Tolin sits down with Andy Hillis to discuss the evolution of information security from a late stage deployment checklist to a core prerequisite within global pharmaceutical infrastructure. The conversation reviews the operational challenges of managing over 200 annual …THECYBERWIRE.COM
14 JulNATO logistics, Ukrainian troops are top subjects of Russian camera hacks, advisory saysDutch intelligence officials report that at least one Russian agency is compromising internet-connected cameras across Europe to spy on military logistics and Ukrainian personnel.THERECORD.MEDIA
14 JulTreasury sanctions First VPN Service, others for abetting ransomware gangsThe designations hit 1VPNS, its alleged Ukrainian administrator and a Belarusian who allegedly sold “cryptors” to disguise ransomware and other malware. The post Treasury sanctions First VPN Service, others for abetting ransomware gangs appeared first on CyberScoop .CYBERSCOOP.COM
13 JulWhy SBOMs, signing, and provenance still don’t tell you if software is safeWe have made real progress in software supply chain security, improving visibility into software components, authenticity and build integrity. Much of this progress traces back to Executive Order 14028, which pushed agencies, contractors and enterprises to invest in SBOMs, signin…HELPNETSECURITY.COM
13 JulRussian State Hackers Target Vulnerable Routers Worldwide, Joint Advisory WarnsCybersecurity agencies from 12 countries have warned that Russian state-backed hackers are actively targeting vulnerable routers using weak SNMP credentialsINFOSECURITY-MAGAZINE.COM
13 JulNew compliance guidance available: HITRUST i1 on AWSWe are pleased to announce the publication of a new AWS compliance implementation guidance: HITRUST i1 Compliance on AWS: Customer Implementation Guidance with an Illustrative Healthcare Platform. Healthcare organizations seeking HITRUST i1 certification increasingly rely on Amaz…AWS.AMAZON.COM
13 JulLessons Learned from CISA’s Recent GitHub LeakThe Cybersecurity and Infrastructure Security Agency (CISA) has issued a postmortem on a data leak in which a contractor published dozens of internal CISA credentials -- including AWS Govcloud keys -- in a public GitHub repository for almost six months before being notified by Kr…KREBSONSECURITY.COM
13 JulOfficials once again warn defenders that Russian hackers are targeting network devicesState-sponsored attackers are targeting critical infrastructure networks in defense, communications, energy, finance, government and health care. The post Officials once again warn defenders that Russian hackers are targeting network devices appeared first on CyberScoop .CYBERSCOOP.COM
13 JulVPN service favored by ransomware groups is sanctioned by USThe U.S. Treasury Department announced sanctions against First VPN Service (1VPNS) and its Ukrainian administrator for aiding ransomware groups. Separately, a Belarusian man was sanctioned for malware "cryptors."THERECORD.MEDIA
13 JulAI Cannot Govern AloneAI can help organizations create stronger policies and improve security decision-making, but current AI systems are not perfectly precise. Because AI is non-deterministic, security teams still need humans involved in important decisions. Better outcomes require combining AI capab…YOUTUBE.COM
13 JulStates are building their own election defense networks as federal support evaporatesElection officials are facing an impossible choice: follow federal directives they don’t trust, or risk becoming targets of a criminal investigation. The post States are building their own election defense networks as federal support evaporates appeared first on CyberScoop .CYBERSCOOP.COM
11 JulUS cyber agency CISA had to build its incident playbook during the incident, agency revealsCISA said it "missed" an opportunity to get ahead of the security incident by not creating a response plan ahead of time.TECHCRUNCH.COM
10 JulMicrosoft uncovers GigaWiper, a backdoor designed for destruction on demandMicrosoft is warning defenders about a new backdoor that blurs the line between espionage malware and wipers. In a technical analysis published on Thursday, Microsoft Threat Intelligence detailed GigaWiper, a Golang-based implant first observed in October 2025 intrusions that com…CSOONLINE.COM
10 JulCISA details security lapses that led to GitHub leak of passwords, cloud access keysThe agency’s blog post came as lawmakers pressed the agency for answers.CYBERSECURITYDIVE.COM
10 JulCISA Details Incident Response to Exposed AWS GovCloud KeysCISA reveals how it responded after sensitive AWS GovCloud credentials and internal data were exposed in a public GitHub repositoryINFOSECURITY-MAGAZINE.COM
10 JulMore Countries Jump on the Social Media Ban WagonAge restrictions on accounts may be more of a ban(d) aid, because industry compliance is already falling short. Tech giants are struggling to follow the laws without affecting users.DARKREADING.COM
10 JulCISA looks to remedy ailments from big May credential leakA major credential leak spurred the Cybersecurity and Infrastructure Security Agency to strengthen protections for its sensitive materials, improve how researchers can report agency vulnerabilities and develop plans for similar incidents, the agency said in a forensic report rele…CYBERSCOOP.COM
10 JulAttackers Have the Advantage NowThe pace of cyberattacks has accelerated dramatically. Techniques that once required weeks can now happen in minutes, hours, or days, making it increasingly difficult for defenders to respond using traditional security processes. The concern isn't that attackers will always have …YOUTUBE.COM
9 Jul75% CISOs Fear Executives Don’t Understand Cybersecurity Risks Employees FaceSurvey of cybersecurity leaders by MetaCompliance finds that many feel boards are uninterested in ever-evolving cyber risksINFOSECURITY-MAGAZINE.COM
9 JulWhy we cannot wait for better post-quantum signature algorithmsNIST is advancing nine new post-quantum signature algorithms as potential candidates for future standardization. We take a closer look at all of them, and argue that while they are in the works and show great potential, we should use ML-DSA for now — the best one currently availa…CLOUDFLARE.COM
9 JulEU Parliament voted to restore private communications scanningThe European Parliament has approved legislation that restores the temporary legal framework allowing online platforms to voluntarily scan private communications for child sexual abuse material (CSAM). This vote effectively revives a regime that expired in April after the EU Parl…CYBERINSIDER.COM
8 JulNCSC Touts National Scale, AI-Powered “Cyber Shield” for DefenseThe National Cyber Security Centre wants to work with AI partners to build a new “Cyber Shield” to defend the UKINFOSECURITY-MAGAZINE.COM
8 JulEU now one step away from reviving private message scanning rulesThe European Parliament has approved an urgent procedure to fast-track legislation that would revive the EU's expired “Chat Control 1.0” rules. This development sets up a decisive vote on July 9 over whether online platforms may once again be allowed to voluntarily sc…CYBERINSIDER.COM
8 JulFormer UK privacy chief preparing legal action against woman who reported him, minister saysLiz Kendall, the secretary of state for science, innovation and technology, said she was “absolutely appalled” at the findings of “sexual harassment and bullying” made by an independent investigation at the Information Commissioner’s Office (ICO).THERECORD.MEDIA
8 JulGreek victims file lawsuit against Intellexa over Predator spywareThe use of the spyware came to light in 2022, with traces of Predator found on dozens of phones. The scandal led to the resignation of Greece’s intelligence service chief and the prime minister’s chief of staff.THERECORD.MEDIA
7 JulIran-Linked Hackers Use New Cavern C2 Framework to Target Israeli OrganizationsAn Iranian hacking group affiliated with Iran's Ministry of Intelligence and Security (MOIS) has been wielding a previously undocumented modular command-and-control (C2) framework dubbed Cavern (aka Cav3rn) targeting Israeli organizations. The activity, which has primarily single…THEHACKERNEWS.COM
7 JulRadware updates Agentic AI Protection with AI governance and compliance capabilitiesRadware has announced enhancements to its Agentic AI Protection solution to help organizations govern and secure AI agents across enterprise environments. The release adds compliance reporting to support alignment with leading global AI standards, enhanced visibility into agent e…HELPNETSECURITY.COM
7 JulUK cyber pledge draws only a handful of top firms despite ministerial appealThose that did sign include large firms such as Aviva, the London Stock Exchange Group and Marks & Spencer, which lost hundreds of millions of pounds in a cyberattack last year, as well as small cybersecurity consultancies.THERECORD.MEDIA
7 JulCISA Reportedly Using Anthropic’s Mythos to Scan Government Software for FlawsThe audits are reportedly being spearheaded by CISA’s Attack Surface Evaluation team, a specialized unit tasked with conducting digital defense assessments and simulated hacking exercises. The post CISA Reportedly Using Anthropic’s Mythos to Scan Government Software for Flaws app…SECURITYWEEK.COM
7 JulBritain plans to build autonomous AI 'Cyber Shield' to defend nationThe capability, called Cyber Shield, is designed to counter a threat the National Cyber Security Centre (NCSC) said could see attackers “move at machine speed and greater scale, reducing opportunities for detection and response.”THERECORD.MEDIA
7 JulHidden backdoor in Tenda router firmware grants admin accessA hidden authentication backdoor has been found in multiple Tenda router firmware versions, potentially allowing an attacker to gain administrative access to the device's web management panel. [...]BLEEPINGCOMPUTER.COM
6 JulCavern Manticore: Exposing Iran-Linked Modular C2 FrameworkKey Points Introduction Since early 2026, Check Point Research (CPR) has tracked a new modular command-and-control framework used by Cavern Manticore, an Iran-nexus APT group primarily targeting Israeli organizations, with a focus on IT providers, and government sectors. Cavern M…RESEARCH.CHECKPOINT.COM
6 JulOperationalizing Agentic AI: from assisted to autonomousEver since ChatGPT made its public debut nearly four years ago, governance and security have largely lagged behind AI adoption. Eager to experiment with AI tools and find ways to improve their work and personal lives, users have uploaded corporate data, financial records, and eve…CSOONLINE.COM
6 JulKYC : Bypass age verification using generative video modelsHistorically reserved for the banking sector, the KYC (Know Your Customer) process is now making its way into many online services, driven by increasingly strict legislation on anonymity and age verification. To comply, platforms deploy significant measures aimed at guaranteeing …SYNACKTIV.COM
6 Jul5 insights from Frost & Sullivan’s 2025 Frost Radar™ for Cloud Security Posture ManagementRead five key learnings from the Frost & Sullivan 2025 Frost Radar™ for CSPM to learn how CSPM is evolving from point-in-time compliance to continuous risk management. The post 5 insights from Frost & Sullivan’s 2025 Frost Radar™ for Cloud Security Posture Management app…MICROSOFT.COM
6 JulAI Needs an Identity TooAI is transforming identity security in two directions. Organizations are using AI to automate identity management, while AI agents themselves are becoming identities that require permissions, monitoring, and governance. As AI agents access sensitive data and perform actions on b…YOUTUBE.COM
6 JulEFF-led coalition urges FTC to reject X’s bid to end privacy oversightA coalition of 15 public-interest organizations is urging the U.S. Federal Trade Commission (FTC) to reject X Corp.'s request to terminate or weaken a 2022 privacy order requiring the company to undergo regular compliance reviews after it repeatedly violated users' privacy. The g…CYBERINSIDER.COM
2 JulReview: CTRL+ALT+PWNHacking gear that once sat in well-funded labs now ships to anyone with a credit card and a video tutorial. Frank Riccardi builds his consumer guide, CTRL+ALT+PWN: The Hacker’s Playbook (And How to Beat It), on that one condition. He spent twenty-five years in healthcare co…HELPNETSECURITY.COM
2 JulNCSC Shares Tips on How to Make a Pen Tester’s Job HarderThe NCSC has shared best practice advice from pen testers which could help improve system resilienceINFOSECURITY-MAGAZINE.COM
2 JulTrump Administration Lifts Restrictions on Anthropic’s Claude Models After Cybersecurity AlarmAnthropic said Tuesday night that its AI model called Claude Fable 5 is now widely available. The post Trump Administration Lifts Restrictions on Anthropic’s Claude Models After Cybersecurity Alarm appeared first on SecurityWeek .SECURITYWEEK.COM
2 JulCybersecurity Mission Creep in the USInteresting paper: “ Cybersecurity Mission Creep .” Abstract: Cybersecurity is experiencing mission creep. Policymakers are casting more and more problems as issues of cybersecurity. So reframed, wildly different policy issues, from misinformation, to child social med…SCHNEIER.COM
2 JulAussies Face Reduced Cybercrime Risk, as Pressure Shifts to SMBsImproved institutional safeguards and stricter regulations have pushed the burdens of protection and risk reduction on to Australian businesses.DARKREADING.COM
1 JulAI-generated code risks reach security, legal, and compliance teamsMost engineering organizations write code with AI, and a good number of them keep that code away from customers. A Flux survey of engineering leaders and practitioners found that nearly half run AI-generated code in production. Almost every company in the sample uses AI somewhere…HELPNETSECURITY.COM
30 JunHalf the defense base still builds security around complianceCMMC requirements are appearing in defense contracts and moving down through supplier networks to thousands of companies new to this kind of compliance work. Many run on limited budgets with lean security teams. The picture comes from nearly 900 defense contractors, C3PAOs, feder…HELPNETSECURITY.COM
30 JunNew Controller Flaws Expose Highway Signs and Billboards to Remote HackingCISA has published an advisory to inform organizations about three vulnerabilities found by a researcher in Daktronics controllers. The post New Controller Flaws Expose Highway Signs and Billboards to Remote Hacking appeared first on SecurityWeek .SECURITYWEEK.COM
30 JunCompleting Compliance with Evidence : A Bottom-Up Approach to NIS2, DORA, and the Cyber Resilience ActGRC (Governance, Risks and Compliance) as it is most often practiced works top-down, you read a piece of regulation, draft a policy, declare coverage, and archive a documentary record. This approach has value, it structures, it documents, it meets an auditor's formal expectations…SYNACKTIV.COM
30 JunCequence Platform 9.0 uses AI to simplify API security and complianceCequence Security has announced general availability of Cequence Platform 9.0, an AI-native release that changes how users interact with API security tools. Platform 9.0 ships with a built-in AI Assistant, an open Model Context Protocol (MCP) server that exposes every platform ca…HELPNETSECURITY.COM
30 JunDHS proposes new framework for public-private infrastructure security collaborationThe Trump administration eliminated the previous system in 2025, sparking a backlash from experts and infrastructure operators.CYBERSECURITYDIVE.COM
30 JunDHS to unveil replacement council for critical infrastructure cybersecurityThe Department of Homeland Security is bringing back a key cybersecurity information sharing effort with critical infrastructure, more than a year after the Trump administration shuttered an existing nerve center between government and private sector. The Alliance of National Cou…CYBERSCOOP.COM
30 JunHouse passes kids’ online safety bill, but Senate approval unlikelyThe Kids Internet and Digital Safety (KIDS) Act passed with bipartisan support by a 267-117 margin, winning the two-thirds majority needed to greenlight the legislation under a process that speeds up a bill’s path to a vote but requires more than a simple majority.THERECORD.MEDIA
30 JunTrump budget boss Russell Vought open to re-staffing CISADHS Secretary Markwayne Mullin has been floating the idea of adding back 600 CISA personnel after deep Trump administration cuts. The post Trump budget boss Russell Vought open to re-staffing CISA appeared first on CyberScoop .CYBERSCOOP.COM
29 JunWhat the post-quantum executive order really demands of CISOsith federal PQC deadlines set for 2030 and 2031, CISOs face a multi-year transformation program that most organizations have not yet started. The window for orderly execution is narrowing fast. The post What the post-quantum executive order really demands of CISOs appeared first …CYBERSCOOP.COM
29 JunOpenAI and Anthropic Limit New AI Models to Trump-Approved Customers During Cybersecurity ReviewChatGPT maker OpenAI said Friday it is restricting the release of its new artificial intelligence model at the request of President Donald Trump’s administration. The post OpenAI and Anthropic Limit New AI Models to Trump-Approved Customers During Cybersecurity Review appeared fi…SECURITYWEEK.COM
29 JunMustang Panda Uses Zoho WorkDrive as Command Channel in Indian Government AttacksThe China-aligned espionage group Mustang Panda is running two campaigns against the Indian government and hydropower targets, deploying new malware and turning a legitimate cloud service into its command channel. Acronis Threat Research Unit found active compromis…THEHACKERNEWS.COM
27 JunFBI Warns Russian Intelligence Hackers Target Signal Backup Recovery KeysThe FBI and CISA have updated their March warning about Russian intelligence phishing Signal accounts, and the operators have added a step: they now coax targets into handing over their Signal Backup Recovery Key. Hand it over once, and the attacker can restore the acco…THEHACKERNEWS.COM
27 JunAWS Forensics : What you need to knowNowadays, it is rare to find a company whose IT system does not rely, at least in part, on cloud technologies. These solutions offer numerous benefits, particularly in terms of the rapid deployment of services and infrastructure. However, those technologies require specific skill…SYNACKTIV.COM
27 JunActivID administrator account takeover : the story behind HID-PSA-2025-002In September 2025, we were asked by one of our clients to focus on a specific product: ActivID Appliance by HID. According to the vendor, this product is used worldwide to secure access to critical infrastructure and data. It supports a wide range of authentication methods includ…SYNACKTIV.COM
27 JunWhat Counts as a Crypto Security?The SEC has introduced a five-part framework to clarify when a crypto asset should be treated as a security. Under the guidance, assets such as Bitcoin, Ethereum, meme coins, and utility tokens are generally not classified as securities, while stablecoins fall under separate legi…YOUTUBE.COM
27 JunNew FBI Alert: Russian Intelligence Uses Signal Recovery Keys to Access MessagesFBI warns Russian spies now target Signal Backup Recovery Keys, enabling access to message history and long-term account takeover. The FBI and CISA updated their March 2026 warning about Russian intelligence phishing campaigns, and the new advisory adds a detail that wasn’t…SECURITYAFFAIRS.COM
26 JunZeroTier Quantum RC2 brings post-quantum security closer to general availabilityZeroTier has announced the release candidate 2 (RC2) for ZeroTier Quantum, its end-to-end quantum-secure networking platform. This milestone marks the final testing phase, positioning the platform one step away from general availability (GA). ZeroTier Quantum addresses the loomin…HELPNETSECURITY.COM
26 JunFBI: Russian hackers now target Signal backup recovery keysThe FBI and CISA are warning that a phishing campaign targeting Signal users tied to Russian intelligence services has evolved to steal Signal Backup Recovery Keys, allowing attackers to access victims' historical messages. [...]BLEEPINGCOMPUTER.COM
25 JunDHS chief says president has met with potential CISA nominee; agency plans to hire 600Once a new CISA director is in place, the agency will ramp up hiring efforts, Homeland Security Secretary Markwayne Mullin told lawmakers. The White House has not yet announced a nominee.THERECORD.MEDIA
25 JunFCC passes new cybersecurity rules for emergency systems, undersea cablesThe new rules would overhaul national emergency systems to protect against hijacking and update federal security review rules for undersea cables providers The post FCC passes new cybersecurity rules for emergency systems, undersea cables appeared first on CyberScoop .CYBERSCOOP.COM
25 JunFederal court rules Trump election-focused executive order illegalProvisions setting up federal voter lists for each state and restricting mail ballots through USPS were declared unconstitutional. The post Federal court rules Trump election-focused executive order illegal appeared first on CyberScoop .CYBERSCOOP.COM
25 JunNIST offers security guidance for water utilities using remote-access toolsThe technology is one of the water sector’s biggest cybersecurity weaknesses.CYBERSECURITYDIVE.COM
25 JunNew CISA Guide Helps Agencies Adopt SASE For Zero TrustNew CISA guidance shows federal agencies how to use SASE to move from legacy TIC 2.0 to zero trustINFOSECURITY-MAGAZINE.COM
24 JunWhere IT meets OT and railway cybersecurity gets harderIn this interview with Help Net Security, Jorge Aldegunde, Global Head of Railway Services at DNV, talks through what happens when old operational technology meets newer IT in monorail systems. He explains why open networks widened the attack surface, how teams decide whether to …HELPNETSECURITY.COM
24 JunGoogle Workspace expands password reset alerts to all adminsGoogle’s Alert Center, a dashboard in the Google Admin console that displays security and administrative alerts and helps administrators identify, investigate, and respond to issues affecting their organization, is expanding the “Super Admin password reset” alert into…HELPNETSECURITY.COM
24 JunWhite House’s state infrastructure cybersecurity initiative stalledThe Trump administration says it wants to help states implement innovative defenses. Most states are still waiting for the call to participate.CYBERSECURITYDIVE.COM
24 JunAnthropic’s Claude Tag gives AI agents independent identitiesAnthropic introduced an agent identity model for Claude Tag, its AI assistant designed for team collaboration in shared workspaces. The model gives Claude its own identity, permissions, and tool access, configured by administrators and tied to a workspace or channel. Because Clau…HELPNETSECURITY.COM
24 JunAdvancing Product Security: New IoT Guidance and New EngagementIt may be summertime, but the NIST Cybersecurity for the Internet of Things (IoT) Program isn’t hitting the hammock! Organizations are managing growing device complexity, evolving threats, and pressure to turn guidance into operational decisions…so we remain focused on helping st…NIST.GOV
24 JunSecurity Awareness Training FailedSecurity awareness training has existed for decades, yet credential theft and phishing attacks still dominate breach reports. In this episode of Business Security Weekly, Robert Siciliano explains why many awareness programs fail to create lasting behavioral change. Instead of he…YOUTUBE.COM
24 JunBe on the lookout for Mistic, a new backdoor used by ransomware brokerResearchers have identified a new backdoor program that has been used in enterprise intrusions since April and appears to be linked to an initial access broker that sells network footholds to ransomware gangs. Dubbed Mistic by researchers from Symantec , the malware program has b…CSOONLINE.COM
23 JunTrump Signs Executive Order Accelerating Post-Quantum Cryptography MigrationFederal agencies are required to transition high-value assets and high-impact systems to use PQC by the end of 2030 and 2031. The post Trump Signs Executive Order Accelerating Post-Quantum Cryptography Migration appeared first on SecurityWeek .SECURITYWEEK.COM
23 JunOmada Identity Sovereign targets Europe’s growing digital sovereignty demandsOmada has introduced Omada Identity Sovereign, a new solution that enables organizations to take direct control over where and how their identity governance is deployed. The solution addresses the digital sovereignty requirements, including data, operational, and jurisdictional c…HELPNETSECURITY.COM
23 JunGIGABYTE confirms UEFI password bypass possible, calls it a design issueA security issue in the Microsoft Windows Recovery Environment (WinRE) could allow attackers to bypass administrator-configured UEFI or BIOS passwords on GIGABYTE motherboards, potentially undermining firmware security controls and enabling unauthorized access to data. The issue …CYBERINSIDER.COM
23 JunTrump Issues Executive Order to Fast-Track Post-Quantum MigrationAll US federal agencies will have to complete their post-quantum cryptography transition by 2031, according to a new Trump Executive OrderINFOSECURITY-MAGAZINE.COM
23 JunTrump Order Sets 2030 Deadline for Federal Post-Quantum Crypto MigrationPresident Trump signed an executive order on June 22 setting hard deadlines for federal agencies to move high-value assets and high-impact systems to post-quantum cryptography. Key establishment must move by December 31, 2030; digital signatures by December 31, 2031. EO…THEHACKERNEWS.COM
23 JunTrump directs federal agencies to protect US data from quantum threatsAn executive order signed Monday aims to accelerate the government's transition to post-quantum cryptography (PQC), a new generation of encryption designed to protect data from the powerful quantum computers expected in the future.THERECORD.MEDIA
23 JunThe post-quantum EO is an important milestone. Now it’s time to get to workThe new post-quantum executive order sets a 2030 migration deadline and establishes a powerful foundation for post-quantum resilience. We look at what it gets right, where it can go further, and our migration playbook for government and industry.CLOUDFLARE.COM
22 JunNCSC Urges Fortinet Customers to Tackle FortiBleed FalloutThe NCSC has released guidance for Fortinet customers impacted by the FortiBleed threat campaignINFOSECURITY-MAGAZINE.COM
22 JunCISA urges device hardening after thousands of Fortinet credentials compromisedSecurity researchers warn of a months-long FortiBleed campaign targeting western organizations.CYBERSECURITYDIVE.COM
22 JunCourt rules SAVE database illegal, orders it dismantledA judge said the administration’s database violates the Privacy Act, the Social Security Act and the Administrative Procedures Act. The post Court rules SAVE database illegal, orders it dismantled appeared first on CyberScoop .CYBERSCOOP.COM
20 JunFrench President Urges US to Share Cutting-Edge AI and Democracies to Cooperate on RegulationFrench President Emmanuel Macron urged the world’s wealthy democracies to work together on regulating advanced AI systems. The post French President Urges US to Share Cutting-Edge AI and Democracies to Cooperate on Regulation appeared first on SecurityWeek .SECURITYWEEK.COM
19 JunFortiBleed Emergency: 74,000 Fortinet Logins ExposedA special crossover episode of Cybersecurity Today and Hashtag Trending for June 19, 2026. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent warning after security researchers uncovered the FortiBleed dataset, exposing credentials tied to appro…CYBERSECURITYTODAY.LIBSYN.COM
19 JunCISA Warns Fortinet Customers as FortiBleed Hits 86,644 FortiGate DevicesThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday urged Fortinet customers with FortiGate appliances to take steps to secure against ongoing malicious activity aimed at thousands of internet-accessible devices. The sweeping campaign, believed to be the …THEHACKERNEWS.COM
19 JunFortiBleed Campaign Exposing Credentials for 73,932 FortiGate SystemsA dataset containing valid administrative and VPN credentials for tens of thousands of Fortinet FortiGate firewalls.RECORDEDFUTURE.COM
19 JunCISA warns Fortinet users to secure devices after FortiBleed leakThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) urged Fortinet customers to secure their devices after nearly 74,000 firewall and VPN credentials were exposed in a data leak dubbed "FortiBleed." [...]BLEEPINGCOMPUTER.COM
18 JunCFGI - 248,235 breached accountsIn March 2026, the financial consulting and advisory firm CFGI was the target of a ShinyHunters "pay-or-leak" extortion campaign . The group subsequently publicised data allegedly obtained from CFGI comprising corporate contact information, including 243k unique email addresses, …HAVEIBEENPWNED.COM
18 JunHostile States Behind 75% of Cyber-Attacks on UK Critical Infrastructure, NCSC WarnsRichard Horne, the NCSC CEO, said three-quarters of cyber-attacks targeting UK critical infrastructure came from nation-state actorsINFOSECURITY-MAGAZINE.COM
18 JunOrphaned AI Agents: How to Find Hidden Access Risks Inside Your NetworkIf an autonomous AI agent interacts with your company's core intellectual property today, can your security team instantly name the person who authorized it? For most enterprises, the answer is a simple no. The rush to adopt internal AI tools has left a massive trail of administr…THEHACKERNEWS.COM
18 JunFortiBleed exposed admin credentials for 75,000 Fortinet firewalls worldwideA newly uncovered cybercrime operation dubbed FortiBleed has exposed administrative credentials for approximately 75,000 Fortinet FortiGate firewalls, potentially giving attackers direct access to corporate networks around the world. The data appears to be recent, affecting organ…CYBERINSIDER.COM
18 JunOperation Escaneo Signals Shift in LatAm Threat LandscapeThe threat group's curious business model may combine opportunistic monetization alongside intel collection, without much coordination between the two.DARKREADING.COM
17 JunThe checklist problem behind critical infrastructure cyber safetyAn asset owner can meet major federal cyber compliance standards and still run equipment that lacks the engineering to withstand an attack or a failure. New research from George Mason University examines how United States cyber policy defines reasonable care for systems that cont…HELPNETSECURITY.COM
17 JunUkraine can now tap EU cyber support during major attacksUkraine can now call on emergency cyber support from the European Union during large-scale cybersecurity incidents. The move follows a decision by the Council of the European Union to add the country to the EU Cybersecurity Reserve. The Reserve operates under ENISA, the European …HELPNETSECURITY.COM
17 JunWarner warns of CISA cuts, staffing gaps in letter to acting chiefWarner on Tuesday also wrote a letter to DHS Secretary Markwayne Mullin, underscoring that DHS must prioritize CISA and pay for the MS-ISAC.THERECORD.MEDIA
17 JunEstonia plans government IDs giving AI agents rights and responsibilitiesThere’s no shortage of agentic AI tools out there that offer to perform online tasks on your behalf, if only you’ll give them all your passwords and credit card details. The trouble starts when those agents don’t know when to stop — or when others don’t know to stop them. In Esto…CSOONLINE.COM
17 JunSupply-chain attack injects backdoor on ShapedPlugin WordPress softwareA supply-chain attack targeted ShapedPlugin, a WordPress plugin developer with more than 400,000 active installations across its free products. The backdoored premium plugin releases were distributed through the company's official update infrastructure. The malware provided attac…CYBERINSIDER.COM
17 JunMajor critical infrastructure disruptions are inevitable, acting CISA chief saysIn recent years, the U.S. government has reoriented its cybersecurity strategy away from prevention and toward resilience.CYBERSECURITYDIVE.COM
17 JunHostile states behind three-quarters of attacks on Britain's critical infrastructure, cyber chief warnsNCSC CEO Richard Horne warned that “kinetic targeting in any conflict tomorrow will be based on intelligence gathered today” and that nation-state adversaries were “prepositioning” throughout British critical infrastructure.THERECORD.MEDIA
17 JunThe nominee in limbo.President Trump halts a key intelligence nomination. The FBI warns of a new Microsoft 365 phishing threat. France cuts ties with Palantir. A new Android banking trojan emerges. Fortinet firewalls come under attack. CISA orders emergency Joomla patching. Plus, Madison Square Garde…THECYBERWIRE.COM
16 JunEU Cybersecurity Act 2.0: When good regulation goes badOver recent years we’ve witnessed the EU becoming increasingly serious about cybersecurity. After years of watching high profile breaches, many resulting from supply chain attacks targeting our critical infrastructure, that seriousness is welcome. But good intentions and good pol…HELPNETSECURITY.COM
16 JunCybersecurity Executives Urge the Trump Administration to Ease Restrictions on Anthropic AI ModelsA group of cybersecurity executives and experts is asking the Trump administration to lift its directive preventing the use of Anthropic’s latest artificial intelligence models by foreign nationals. The post Cybersecurity Executives Urge the Trump Administration to Ease Restricti…SECURITYWEEK.COM
16 JunTricked and Extradited: Inside the First FBI Operation to Lure a Chinese Spy to the USThe FBI won’t discuss exactly how Chinese spy Xu Yanjun came to the attention of special agents. Xu was handling a GE Aviation engineer in Ohio who specialized in composite fan-blade technology. That engineer, David Zheng, had been approached by an official from Nanjing Universit…THECYBERWIRE.COM
16 JunKeep up with HIPAA Expectations amid Growing Cyber ThreatsHealthcare organizations can satisfy cybersecurity and HIPAA compliance obligations while upholding patient safety. Read on to learn how.CISECURITY.ORG
16 JunLawmakers leary about Trump administration’s Anthropic orderSome panned it, some said they needed more information, but caution figured into all of the responses. The post Lawmakers leary about Trump administration’s Anthropic order appeared first on CyberScoop .CYBERSCOOP.COM
15 JunPopular WordPress Plugin Scripts Tampered to Plant Hidden Backdoors on SitesAn attacker tampered with trusted JavaScript files used by WordPress sites running PushEngage, OptinMonster, and TrustPulse, turning those files into a way to break into the sites. When a site administrator was logged in as the file loaded, the code created an admin account under…THEHACKERNEWS.COM
15 JunCybersecurity Experts Urge US to Lift Ban on Anthropic's Frontier AI ModelsAccess to two Anthropic large language models, Mythos 5 and Fable 5, has effectively been banned to any non-US nationals by the Trump administrationINFOSECURITY-MAGAZINE.COM
15 JunSupply-chain attack hits OptinMonster plugin used in 1.2 million WordPress sitesA supply-chain attack targeting the WordPress plugins OptinMonster, TrustPulse, and PushEngage exposed more than 1.2 million websites to potential compromise after attackers injected malicious JavaScript into files distributed through official CDN infrastructure. The malware crea…CYBERINSIDER.COM
15 JunTrust3 AI’s AgentDOS monitors AI agent activity, data access, and token consumptionTrust3 AI has announced AgentDOS, an enterprise control plane that provides visibility into AI agents, including real-time token consumption monitoring across platforms such as Databricks Agent Bricks and Microsoft Copilot Studio. As enterprises rapidly scale AI adoption, a new c…HELPNETSECURITY.COM
15 JunOmada Agent Governance helps organizations manage AI agent access, risk, and complianceOmada has announced Omada Agent Governance, a new solution designed to help organizations bring the same governance discipline to AI agents and non-human identities that they already apply to people. AI agents are rapidly becoming a new class of digital actor inside enterprises. …HELPNETSECURITY.COM
13 JunAnthropic Says It Has Taken Its Latest AI Models Offline to Comply With New Export ControlsAnthropic takes Fable 5 and Mythos 5 offline to comply with a directive from the Trump administration to prevent use by foreign nationals. The post Anthropic Says It Has Taken Its Latest AI Models Offline to Comply With New Export Controls appeared first on SecurityWeek .SECURITYWEEK.COM
13 JunChinese hackers hijack auth flow, spy on isolated network for a decadeChinese hackers took control of a target organization's authentication stack and maintained persistence for 10 years, with full visibility into the administrative activity. [...]BLEEPINGCOMPUTER.COM
12 JunHow to use NIST and ISO frameworks to govern AI agentsSecurity leaders no longer need convincing that AI agents introduce risk. What’s missing is how to govern them once they move into production and begin operating autonomously across enterprise environments. AI agents already read sensitive documents, invoke internal APIs, trigger…HELPNETSECURITY.COM
12 JunINTERPOL Operation Takes Down Sniper Dz Phishing Platform, Arrests AdministratorAn INTERPOL-led operation last month resulted in the disruption of Sniper Dz, a decade-long phishing-as-a-service (PhaaS) platform, Group-IB said Thursday. The effort, codenamed Operation Ramz, took place between October 2025 and February 2026, and saw authorities from 13 countri…THEHACKERNEWS.COM
12 JunFrench government’s secure messaging system breachedAn intruder has breached the French government’s encrypted messaging service, Tchap, showing once again that human error is a weak spot in any security system. Tchap was developed in France as an example of national sovereignty and was designed to be a more secure option than Wha…CSOONLINE.COM
12 JunWarrantless wiretaps cut off for a week following US Congress voteLawmakers have failed to extend a surveillance law that allows US intelligence agencies to monitor targets abroad without a warrant. Congress rejected a vote to extend Section 702 of the Foreign Intelligence Surveillance Act to July 2, which means, for a few days at least, some s…CSOONLINE.COM
11 JunTrump’s AI pivot.This week, Dave and Ben sit down with N2K's lead analyst Ethan Cook to examine President Trump's recent Executive Order centered on AI. With this order, the Trump administration is looking to increase its oversight of new AI models to better account for potential security vulnera…THECYBERWIRE.COM
11 JunCISA Orders Agencies to Patch by Risk, Not SeverityNew CISA directive tells federal agencies to patch by real-world risk, not CVSS severity scoresINFOSECURITY-MAGAZINE.COM
10 JunCISA, researchers warn of escalating attacks using Cisco Catalyst SD-WAN flawsMultiple vulnerabilities are being chained together to gain additional access to systems.CYBERSECURITYDIVE.COM
10 JunCISA to require federal agencies to patch some cyber vulnerabilities within 3 daysCISA is giving agencies 180 days to adopt the new patching time frame, according to a directive released Wednesday.THERECORD.MEDIA
10 JunCISA Tells US Agencies to Fix Security Bugs in as Little as 3 Days Thanks to AI Threats“Defenders cannot afford to take weeks to patch,” one Cybersecurity and Infrastructure Security Agency official warned on Wednesday.WIRED.COM
10 JunCISA Rewrites Federal Patching Requirements for AI Threat EraThe new directive gives federal agencies three days to fix the most dangerous flaws, while less severe issues can be deferred.DARKREADING.COM
9 JunFrench government confirms breach at secure messaging platform TchapFrance's Interministerial Directorate for Digital Affairs (DINUM) has confirmed a security incident affecting Tchap, the encrypted messaging platform used across French government agencies. The disclosure comes after a threat actor attempted to sell or leak data allegedly stolen …CYBERINSIDER.COM
9 Jun75% of Firms Deploy Vulnerable Code Amid Pressure on CISOs, Report FindsCheckmarx report warns that business pressure is among the reason security leaders let security compliance slipINFOSECURITY-MAGAZINE.COM
9 JunCISA to transform how it assesses cyber vulnerabilities and risks, Andersen saysA binding operational directive being released Wednesday will direct federal agencies to change the way they address vulnerabilities by elevating some while putting others to the side.THERECORD.MEDIA
8 JunUkraine’s foreign minister offer recipe for improved resilienceCybersecurity professionals were offered lessons of resilience in the most extreme circumstances from Ukraine’s former minister of foreign affairs. Dmytro Kuleba, who served as Ukraine’s Minister of Foreign Affairs between 2020 and 2024, told Infosecurity Europe delegates that th…CSOONLINE.COM
8 JunThe AI security race needs accountability, not overregulationPartnership between policymakers and tech companies, not government oversight, offers the best path forward for responsible AI innovation. The post The AI security race needs accountability, not overregulation appeared first on CyberScoop .CYBERSCOOP.COM
8 JunRussia upgrades rules for its digital spy system to better track citizens onlineNew regulations published by Russia's Ministry of Digital Development at the end of May updated the technical standards governing SORM, formally known as the System for Operative Investigative Activities.THERECORD.MEDIA
8 Jun8th June – Threat Intelligence ReportFor the latest discoveries in cyber research for the week of 1st June, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES DentaQuest, a U.S. dental benefits administrator owned by Sun Life, has suffered a data breach after threat group ShinyHunters leaked …RESEARCH.CHECKPOINT.COM
8 JunMeta’s recovery plan needed recovery.Meta exposes 20,000 Instagram accounts through a support tool bug. CISA warns of active attacks on SolarWinds Serv-U. WordPress sites face takeover through a widely used plugin. A new Gafgyt variant broadens its reach. Pink extortionists steal cloud data with vishing and legitima…THECYBERWIRE.COM
8 JunUK gives big tech 3 months to create device controls to block nude images of kidsThe companies “must activate built-in features or implement technical solutions on smartphones and tablets to detect and block nude images for children,” according to a press release from the Home Office. Prime Minister Keir Starmer announced the measure in a speech at London Tec…THERECORD.MEDIA
5 JunIndustry Reactions to New Trump AI Cybersecurity Executive Order: Feedback FridayExperts commented on the EO’s voluntary nature, the balance between innovation and security, and potential implementation gaps. The post Industry Reactions to New Trump AI Cybersecurity Executive Order: Feedback Friday appeared first on SecurityWeek .SECURITYWEEK.COM
5 JunHackers Leak DentaQuest Information Impacting 2.6 MillionThe ShinyHunters extortion group leaked roughly 234 GB of data allegedly stolen from the dental benefits administrator. The post Hackers Leak DentaQuest Information Impacting 2.6 Million appeared first on SecurityWeek .SECURITYWEEK.COM
5 JunMicrosoft Outlook leaves email connections unencrypted despite SSL/TLS settingA server upgrade that introduced stricter email security checks has uncovered what appears to be a long-standing Outlook issue that may have caused some users to retrieve email over unencrypted connections despite having SSL/TLS enabled in their account settings. The discovery wa…CYBERINSIDER.COM
5 JunNorway fines largest electronics retailer $2.1M for client data violationsNorway’s Data Protection Authority (Datatilsynet) has imposed a NOK 20 million (approximately $2.1 million) administrative fine on electronics retail giant Elkjøp for multiple GDPR violations tied to its customer club, targeted marketing activities, and handling of customer priva…CYBERINSIDER.COM
5 JunTrump AI Order Seeks Voluntary Frontier Model TestingThe White House's executive order establishes voluntary framework for early government access to frontier models while investing in federal security.DARKREADING.COM
5 JunThe NSA gets an AI upgrade.Anthropic brings Mythos to the NSA. A Palantir executive emerges as a possible CISA pick. A Linux flaw is under active attack. Minecraft malware goes commercial. An npm package gets caught in the Miasma worm campaign. Researchers document the first AI-driven container escape. A b…THECYBERWIRE.COM
4 JunInfosecurity Europe: Ukraine’s Experience Highlights the Need for Preparation and Resilience in CybersecurityFormer Ukrainian foreign minister, Dmytro Kuleba, urges Infosecurity Europe attendees to fight the good fightINFOSECURITY-MAGAZINE.COM
4 JunPakistan Spies on Afghan Finance Ministry With Xeno RATDespite broadly connected digital infrastructure, standard fare TTPs are enough to cause trouble for Afghanistan's porous cybersecurity.DARKREADING.COM
4 JunSpotless compliance evidence can still hide a broken controlIn this interview with Help Net Security, Marc Rubbinaccio, Head of Cybersecurity and Compliance at Secureframe, explains where security teams go wrong when preparing for CMMC and FedRAMP 20x. The conversation covers how organizations check the 110 requirements but miss the 320 a…HELPNETSECURITY.COM
4 JunInfosecurity Europe: How Businesses Can Prepare for a Cybersecurity Crisis with Effective PlansCybersecurity and business leaders with experience of dealing with major incidents from within the NCSC and at JLR detail what you need to prioritize if your organization is hit by a cyber-attackINFOSECURITY-MAGAZINE.COM
4 JunChinese spies are using LinkedIn to lure Westerners into sharing sensitive informationThe advisory warns that Chinese spies are using public job search platforms to recruit people with access to non-public information.TECHCRUNCH.COM
4 JunFive Eyes allies issue advisory on Chinese intelligence operations.Researchers track versatile China-based cybercrime group. Cisco fixes critical flaw affecting Unified CM.THECYBERWIRE.COM
4 JunCISA chief says Trump AI EO implementation will start soonThe agency, depleted after several rounds of cuts imposed by the White House, insists it can handle its new AI security responsibilities.CYBERSECURITYDIVE.COM
4 JunSupreme Court rules FCC fines punishing telecom giants for sharing location data were legalThe Trump administration had backed the FCC’s position and, apart from Justice Clarence Thomas, the high court agreed.THERECORD.MEDIA
4 JunDentaQuest data breach exposed info of 2.6 million accountsA data breach at the dental benefits administrator DentaQuest has reportedly exposed the sensitive data of 2.6 million accounts. [...]BLEEPINGCOMPUTER.COM
4 JunHill Dems hammer GOP for $250M CISA budget cutA House Appropriations subcommittee is set to mark up fiscal 2027 DHS funding legislation Friday. The post Hill Dems hammer GOP for $250M CISA budget cut appeared first on CyberScoop .CYBERSCOOP.COM
3 JunTrump Signs Order Inviting Voluntary Review of Frontier AI ModelsTrump's executive order invites voluntary pre-release review of frontier AI modelsINFOSECURITY-MAGAZINE.COM
3 JunCitizen Lab urges Canada to withdraw parts of Bill C-22 over privacy concernsCitizen Lab and the Canadian Civil Liberties Association (CCLA) are urging lawmakers to withdraw key provisions of Canada's proposed lawful access legislation, Bill C-22, warning that it would create sweeping surveillance powers, undermine privacy rights, and pose significant cyb…CYBERINSIDER.COM
3 JunCISA, FBI warn that hackers are targeting systems used to monitor industrial fluidsAutomatic tank gauge systems are widely used across multiple industries, including energy, agriculture and transportation.CYBERSECURITYDIVE.COM
3 JunDentaQuest - 2,553,599 breached accountsIn May 2026, the dental benefits administrator DentaQuest was the target of a ShinyHunters "pay or leak" extortion campaign that resulted in the group publicly publishing hundreds of gigabytes of data allegedly obtained from the company. The data included 2.6M unique email addres…HAVEIBEENPWNED.COM
3 JunDHS chief signals efforts to reshape CISAIn his first appearance before the panel since being confirmed in March, Mullin said that CISA probably needs “somewhere around” 2,800 employees, despite its ability to hire up to 3,400.THERECORD.MEDIA
3 JunDHS Secretary Markwayne Mullin pinpoints optimal CISA staffing levelsHe told lawmakers that he wants approximately 600 more people than it has now, which would still be well below personnel numbers prior to Trump’s second term. The post DHS Secretary Markwayne Mullin pinpoints optimal CISA staffing levels appeared first on CyberScoop .CYBERSCOOP.COM
3 JunCISA warns of cyberattacks targeting fuel tank monitoring systemsCISA, the FBI, the NSA, the Department of Energy, and other US government partners are warning that hackers are targeting internet-exposed automatic tank gauge (ATG) systems used to monitor fuel and liquid storage tanks across various critical infrastructure sectors. [...]BLEEPINGCOMPUTER.COM
2 JunSensitive government personnel data posted online, Spanish police arrest suspectThe Spanish National Police arrested a man in Granada for allegedly leaking personal data belonging to members of several sensitive state institutions. According to police, the suspect published the information on multiple online platforms, exposing personnel associated with orga…HELPNETSECURITY.COM
2 JunInfosecurity Europe: NCSC Urges Immediate Action to Boost Resilience as Uncertainty PersistsNCSC director of operations, Paul Chichester, says it’s time to future-proof cybersecurity todayINFOSECURITY-MAGAZINE.COM
2 JunTrump administration releases scaled-back AI executive orderThe order – which Trump refrained from signing at the last minute, appears to make significant concessions to industry compared to earlier drafts. The post Trump administration releases scaled-back AI executive order appeared first on CyberScoop .CYBERSCOOP.COM
2 JunDOD wants to integrate cyber in all operations, and integrate security into AITop Pentagon cyber policy official Katherine Sutton said recent conflicts have emphasized the importance of cyber, and that the department can’t make old mistakes with AI security. The post DOD wants to integrate cyber in all operations, and integrate security into AI appeared fi…CYBERSCOOP.COM
2 JunTrump signs EO seeking early government access to powerful AI modelsThe directive represents an about-face for an administration that previously repudiated government AI reviews.CYBERSECURITYDIVE.COM
2 JunIdentify unused AWS KMS keys and prevent accidental key deletionsAs you scale your use of Amazon Web Services (AWS), managing KMS keys becomes increasingly important. Whether you manage a handful of keys or thousands across multiple AWS accounts and AWS Regions, there’s often a need to audit key usage to help you meet compliance requirements, …AWS.AMAZON.COM
2 JunWhite House unveils pared-back AI executive orderThe order notes that federal access to the models should be subject to “appropriate confidentiality, cybersecurity, insider-risk, and intellectual-property protection, use, and nondisclosure requirements.”THERECORD.MEDIA
2 JunTrump Signs Executive Order That Invites Vetting of Top AI Models for National Security RisksThe order establishes a framework for the federal government to vet the national security risks of the most advanced AI systems for up to a month before their public release. The post Trump Signs Executive Order That Invites Vetting of Top AI Models for National Security Risks ap…SECURITYWEEK.COM
1 JunEU organizations buckle under rising compliance pressureCybersecurity governance in the EU is shifting under expanding frameworks such as NIS2 and DORA, while AI raises new questions for security teams. What the future brings is hard to predict, and organizations must find a way to cope. Antonija Vojnović, Governance, Risk and Complia…HELPNETSECURITY.COM
1 JunData discovery gaps that catch enterprises off guardIn this interview with Help Net Security, Avani Desai, CEO at Schellman, talks about the gap between what organizations think they know about their data and what discovery scans turn up. She shares stories of shadow data in abandoned cloud storage, post-merger surprises where dup…HELPNETSECURITY.COM
1 Jun1,000 Data Breaches Later, the Disclosure Lag is Worse Than EverPresently sponsored by: Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite Today, I loaded the 1,000th data breach into Have I Been Pwned . Reflecting on that milestone number, I pondered how to mark the occasi…TROYHUNT.COM
1 JunThe Security Growth Platform: Why MSPs Are Moving Beyond vCISO ToolsThree years ago, the practical question for an MSP building a cybersecurity practice was which "vCISO platform" to buy. The term was good shorthand for the work at the time: assessments, advisory, reporting, maybe a compliance module bolted on the side. The work has since outgrow…THEHACKERNEWS.COM
1 JunAs the Pentagon Pushes for Battlefield AI, Some Military Leaders Urge CautionAI’s use in the military is part of the administration’s larger push to grow the capability it sees as a unique American advantage. The post As the Pentagon Pushes for Battlefield AI, Some Military Leaders Urge Caution appeared first on SecurityWeek .SECURITYWEEK.COM
1 JunMullvad VPN on Android passes Google-backed MASA security auditMullvad has announced that its Android VPN application has successfully passed the Mobile Application Security Assessment (MASA) for a second consecutive year. The assessment identified several minor issues, all of which were addressed in a subsequent release, resulting in a succ…CYBERINSIDER.COM
1 JunUSPS moving forward with mail-in ballot changes as courts weigh Trump’s election orderA judge said Democrats and civil groups filed the lawsuit too early to demonstrate harm, but that could change after newly proposed postal regulations. The post USPS moving forward with mail-in ballot changes as courts weigh Trump’s election order appeared first on CyberScoop .CYBERSCOOP.COM
1 JunAI joins the chain of command.Battlefield AI sparks debate. Election cyber threats rise. A critical Windows flaw is under active attack. CISA weighs new reporting rules. Russian targets face a stealthy hacking campaign. A 19-year-old Linux bug gets its day in the sun. Today’s business update. Our guest is Hea…THECYBERWIRE.COM
1 JunAnthropic to Open Mythos AI to EU's ENISAThe European security agency's entry to Project Glasswing is the result of "strong bilateral cooperation" between the European Commission and Anthropic.DARKREADING.COM
31 MayCyberWire Daily at 10: The evolution of ransomware.In this special edition of CyberWire Daily’s 10th anniversary series, N2K CyberWire's Maria Varmazis and Dave Bittner consider the tactics, trends, and turning points that shaped the threat landscape over the last decade of ransomware. Ransomware has evolved from small-scale exto…THECYBERWIRE.COM
31 MayDutch Authorities Dismantle Botnet Linked to 17 Million Infected DevicesDutch authorities have announced the takedown of a botnet that enslaved millions of infected devices, including computers, tablets, smartphones, and IoT devices, to carry out malicious attacks. The bot network, per the Dutch Politie and the National Cyber Security Center (NCSC), …THEHACKERNEWS.COM
30 MayAI Sees Trees, Humans See ForestsAI systems are becoming extremely effective at processing security logs, compliance data, and operational telemetry at massive scale. In cybersecurity environments, that creates major efficiency gains for analysis, monitoring, and identifying patterns humans might miss manually. …YOUTUBE.COM
29 MayNetskope extends data localization capabilities with NewEdge updatesNetskope has enhanced its NewEdge Network infrastructure, expanding data sovereignty capabilities to more regions than any other SASE cloud provider. The NewEdge Network architecture provides national data localization features that address requirements for network transport, dat…HELPNETSECURITY.COM
29 MayChilling EffectsYounger Americans have soured on the second Donald Trump presidency , but they are not protesting it. Despite an unpopular Iran war and an even more unpopular Trump administration , college campus protests nationwide have gone silent . And at many schools, student activism is vir…SCHNEIER.COM
29 MayCISA urges security teams to check for software development compromisesThe agency warned about a wave of attacks targeting credentials and other secrets across critical supply chains.CYBERSECURITYDIVE.COM
29 MayIn Other News: Trump Mobile Data Breach, FIFA World Cup Phishing, CISA Responds to Supply Chain AttacksNoteworthy stories that might have slipped under the radar: Trump Mobile exposes customer data, phishers target the 2026 FIFA World Cup, CISA responds to recent supply chain attacks. The post In Other News: Trump Mobile Data Breach, FIFA World Cup Phishing, CISA Responds to Suppl…SECURITYWEEK.COM
29 MayThe White House’s Aliens.gov Site Brags That ICE Arrested More Than 700 US CitizensThe website, which compares human beings to extraterrestrials, touts arrest numbers from the Trump administration’s sweeping immigration crackdown. But some of its details are really out there.WIRED.COM
28 MaySextortionist sentenced to 33 years for targeting 145 childrenA Canadian man was sentenced to 33 years in prison after pleading guilty to targeting more than 145 children across the United States, some as young as 6 years old, in an eight-year-long sextortion scheme. [...]BLEEPINGCOMPUTER.COM
28 MayExperts on Experts: Why Compliance is becoming ContinuousThis week on Experts on Experts, I’m joined by Sergio Alonso – Rapid7’s Director of Trust, Risk, and Compliance – to talk about how compliance is changing and why many security teams are rethinking the way they approach readiness, reporting, and operational risk. One of the bigge…RAPID7.COM
28 MayNew Cyber Command chief commissions MITRE to review modernization efforts.CISA orders US agencies to patch maximum-severity cPanel flaw by tomorrow. Carnival confirms breach affecting just under six million people.THECYBERWIRE.COM
28 MaySimplifying policy management with URL and Domain Category filtering on AWS Network FirewallNetwork administrators face a persistent challenge: maintaining domain blocklists and allowlists that keep pace with the internet. New websites and services emerge daily, and keeping these lists current requires constant manual updates that leave gaps in coverage. This challenge …AWS.AMAZON.COM
27 MayIranian intelligence service behind hack of LA transit system, researchers sayThe hacking group claimed to be a standalone hacktivist crew but actually has ties to the Ministry of Intelligence of the Islamic Republic of Iran (MOIS), researchers at Gambit Security said in a report published Tuesday.THERECORD.MEDIA
27 MayPing Identity advances agentic security with AI governance and trusted accessPing Identity announced new capabilities that extend the Ping Identity Platform for the agentic enterprise, where AI agents, automation, and developers increasingly shape how access is managed, governed, and secured across organizations. AI agents are changing both sides of the i…HELPNETSECURITY.COM
27 MayFBI warns extortion hackers are visiting US law firms to steal dataIn a public advisory issued Tuesday the FBI said a hacking group has targeted law firms using social engineering schemes to gain remote access to corporate systems and exfiltrate data.THERECORD.MEDIA
27 MayBreaking the GlassWorm.A major takedown disrupts the GlassWorm botnet. The White House rewrites federal cyber logging rules as CISA faces cuts amid rising AI threats. Federal agencies ramp up scrutiny of so-called anti-tech extremism. GCHQ warns Russia is targeting UK infrastructure. Researchers uncove…THECYBERWIRE.COM
26 MayHow Varonis Atlas integrates Claude Compliance API for AI governanceAI governance requires visibility into how AI tools interact with enterprise data. Varonis explains how its Atlas platform uses Claude Compliance API data to help monitor usage, investigate risk, and support compliance. [...]BLEEPINGCOMPUTER.COM
26 MayFBI warns of Kali365 phishing kit targeting Microsoft 365 accountsThe FBI has issued a warning about a phishing-as-a-service (PhaaS) platform known as “Kali365” that is being used to compromise Microsoft 365 accounts through sophisticated phishing and adversary-in-the-middle (AiTM) attacks. According to a public advisory published by the FBI’s …CYBERINSIDER.COM
26 MayWhite House charts new course for federal agencies and cybersecurity loggingA Trump administration memo published last week replaces one from its predecessor, with at least one analyst fearful of potential harmful results. The post White House charts new course for federal agencies and cybersecurity logging appeared first on CyberScoop .CYBERSCOOP.COM
25 MayAnthropic adds 28 security and compliance integrations for ClaudeAI tools are becoming part of everyday work in organizations, creating new security and oversight requirements as usage grows. To address that, Anthropic introduced 28 integrations with security and compliance tools that allow IT and security teams to manage Claude in the same wa…HELPNETSECURITY.COM
23 MayResearcher Finds Public GitHub Repo Exposing Sensitive CISA CredentialsThe episode recounts how GitGuardian security researcher Guillaume Valadon, while monitoring public GitHub for leaked secrets, discovered a publicly accessible repository labeled "CISA-Private" containing highly sensitive CISA materials, including internal DHS/CISA credentials, c…CYBERSECURITYTODAY.LIBSYN.COM
22 MaySuspected KimWolf botnet admin arrested over DDoS-for-hire operationU.S. and Canadian authorities arrested and charged a Canadian man accused of operating the KimWolf DDoS botnet, a service linked to attacks that infected more than one million devices worldwide. Jacob Butler, 23, of Ottawa, Canada, also known online as “Dort,” was arr…HELPNETSECURITY.COM
22 MayVersa extends zero trust principles to AI agents and MCP workflowsVersa has introduced a patent-pending zero trust architecture for the Model Context Protocol (MCP), applying zero trust principles to AI execution. The company said every AI-generated action is validated against user identity, role-based access controls, and system policies befor…HELPNETSECURITY.COM
22 MayCISA Security LeakCrazy story : Until this past weekend, a contractor for the Cybersecurity & Infrastructure Security Agency (CISA) maintained a public GitHub repository that exposed credentials to several highly privileged AWS GovCloud accounts and a large number of internal CISA systems. Se…SCHNEIER.COM
22 MayMicrosoft says it’s making AI ‘safe for work’ in your browserMicrosoft is testing the addition of agentic AI to its corporate browser, Edge for Business . A new version, currently available in a limited preview, will help perform routine tasks more efficiently, according to Microsoft’s partner product manager for Edge, Lindsay Kubasik. Age…CSOONLINE.COM
22 MayLawmakers Demand Answers as CISA Tries to Contain Data LeakLawmakers in both houses of Congress are demanding answers from the U.S. Cybersecurity & Infrastructure Security Agency (CISA) after KrebsOnSecurity reported this week that a CISA contractor intentionally published AWS GovCloud keys and a vast trove of other agency secrets o…KREBSONSECURITY.COM
22 MayProton VPN vows to resist Canadian surveillance demands under Bill C-22Proton VPN General Manager David Peterson said the Swiss-based VPN provider will not comply with any Canadian surveillance demands stemming from the country’s proposed lawful access legislation, Bill C-22, pledging to challenge the law “by every means available.” In a statement p…CYBERINSIDER.COM
22 MayToo many cooks in the algorithm.Trump hits pause on an AI executive order. Lawmakers sound alarms over CISA cuts. A sophisticated scareware campaign traps users in fake tech support scams. Ubiquiti patches critical UniFi flaws. The U.S. pours billions into quantum computing. Researchers uncover delayed Google A…THECYBERWIRE.COM
21 MayMullvad confirms VPN fingerprinting flaw, says fix is on the wayMullvad has published an official advisory confirming a fingerprinting issue in its VPN infrastructure that could allow online services to probabilistically correlate users as they switch between VPN servers. The company says the flaw does not expose a user’s identity, but it can…CYBERINSIDER.COM
21 MayEuropean authorities take down prolific cybercrime VPN serviceOfficials arrested the alleged administrator of First VPN, seized its servers and domains. Europol said the service appeared in almost every major recent cybercrime investigation. The post European authorities take down prolific cybercrime VPN service appeared first on CyberScoop…CYBERSCOOP.COM
21 MayProofpoint Integrates with the Claude Compliance API to Extend Data Security and Governance to ClaudePROOFPOINT.COM
21 MayDC court could provide potential resolution to Anthropic’s lawsuit.Poland adopts new cryptocurrency regulations.THECYBERWIRE.COM
21 MayLawmakers from both parties say CISA cuts have gone too farReps. Don Bacon, R-Neb., and James Walkinshaw, D-Va., found rare bipartisan agreement that the agency tasked with defending civilian networks has been diminished at a moment when threats from China and others are growing. The post Lawmakers from both parties say CISA cuts have go…CYBERSCOOP.COM
21 MayAlleged leader of Kimwolf, a sweeping botnet for cybercriminals, arrested in CanadaJacob Butler, a 23-year-old from Ottawa, awaits extradition to the United States and faces up to 10 years in prison. The post Alleged leader of Kimwolf, a sweeping botnet for cybercriminals, arrested in Canada appeared first on CyberScoop .CYBERSCOOP.COM
21 MayClaude Enterprise Meets the Security Graph: Wiz Integrates with Anthropic's Compliance APISecurity and compliance teams can now monitor Claude activity directly in Wiz, extending the workflows they already rely on to AIWIZ.IO
20 MayWhy Policy in Amazon Bedrock AgentCore chose Cedar for securing agentic workflowsAgents have agency: they adapt and find multiple ways to solve problems. This autonomy creates a fundamental security challenge: the large language model (LLM) at the heart of the agent is non-deterministic, and its decisions can’t be predicted or guaranteed in advance. It can ha…AWS.AMAZON.COM
19 MayCybersecurity jobs available right now: May 19, 2026CISO DataFence | Israel | Hybrid – View job details As a CISO, you will develop security roadmaps, compliance plans, risk registers, policies, and control implementation plans while leading audit and regulatory compliance activities. You will manage client project…HELPNETSECURITY.COM
19 MayAI infrastructure is cracking under sovereignty demandsAI deployments are moving into environments with tighter controls around data, infrastructure, and system operations. Organizations are building AI systems across multiple providers, platforms, and computing environments while managing governance, security, and compliance obligat…HELPNETSECURITY.COM
19 MayKimsuky Uses LNK, JSE Lures to Target Recruiters, Crypto Users, Defense OfficialsKimsuky Hackers Use LNK and JSE Lures to Target Recruiters, Crypto Users, and Defense Officials. North Korea-linked threat group Kimsuky has launched at least four distinct spear-phishing campaigns in early 2026, targeting recruiters, cryptocurrency users, developers, defense per…GBHACKERS.COM
19 MayUS cyber agency CISA exposed reams of passwords and cloud keys to the open webThe federal cybersecurity agency left plaintext passwords in a spreadsheet uploaded to a public GitHub repository, per a report by independent journalist Brian Krebs.TECHCRUNCH.COM
19 MayCISA contractor exposed AWS GovCloud keys on GitHub.Microsoft fixes critical Authenticator flaw. INTERPOL operation nabs 200 suspected cybercriminals.THECYBERWIRE.COM
19 MayCISA Exposes Secrets, Credentials in 'Private' RepoThe agency's GitHub repository, publicly available since November 2025, was ironically named "Private-CISA."DARKREADING.COM
19 MayCISA credential leak raises alarms, and Capitol Hill demands answersA researcher who found a repository that leaked on GitHub said it was one of the worst he’s witnessed. The post CISA credential leak raises alarms, and Capitol Hill demands answers appeared first on CyberScoop .CYBERSCOOP.COM
18 MayCan Laws Stop Deepfakes? South Korea Aims to Find OutSouth Korea's local elections next month will be a test bed for how effective regulations might be to stymie the flow of deepfakes.DARKREADING.COM
18 MayMicrosoft Acknowledges Windows 11 Update Failure Linked to Error 0x800f0922Microsoft has acknowledged a growing issue affecting Windows 11 users: the May 2026 cumulative update (KB5089549) fails to install, resulting in error code 0x800f0922. The problem is affecting systems running Windows 11 versions 24H2 and 25H2, raising concerns among enterprise ad…GBHACKERS.COM
18 MayNCSC Publishes Guidance on Securing Agentic AI UseThe UK’s National Cyber Security Centre is helping organizations to understand agentic AI security risksINFOSECURITY-MAGAZINE.COM
18 MayCISA Admin Leaked AWS GovCloud Keys on GithubUntil this past weekend, a contractor for the Cybersecurity & Infrastructure Security Agency (CISA) maintained a public GitHub repository that exposed credentials to several highly privileged AWS GovCloud accounts and a large number of internal CISA systems. Security experts…KREBSONSECURITY.COM
15 MaySignal threatens to leave Canada over proposed lawful access billEncrypted messaging platform Signal says it would withdraw from the Canadian market rather than comply with provisions in Ottawa’s proposed lawful access legislation that it believes could undermine encryption and introduce dangerous security vulnerabilities. In an interview with…CYBERINSIDER.COM
15 MayWhat 45 Days of Watching Your Own Tools Will Tell You About Your Real Attack SurfaceIn Your Biggest Security Risk Isn't Malware — It's What You Already Trust, we made a simple argument: the most dangerous activity inside most organizations no longer looks like an attack. It looks like administration. PowerShell, WMIC, netsh, Certutil, MSBuild — the same trusted …THEHACKERNEWS.COM
15 MayTurla Turns Kazuar Backdoor Into Modular P2P Botnet for Persistent AccessThe Russian state-sponsored hacking group known as Turla has transformed its custom backdoor Kazuar into a modular peer-to-peer (P2P) botnet that's engineered for stealth and persistent access to compromised hosts. Turla, per the U.S. Cybersecurity and Infrastructure Security Age…THEHACKERNEWS.COM
14 MayThe Human Side of Threat IntelligenceIngrid Parker, Director of Intel Response at Unit 42, has a background that doesn't fit the mold: art student, Army linguist, systems administrator deployed to Afghanistan, co-author of 11 Strategies of a World-Class Cybersecurity Operations Center. In this conversation, she and …THECYBERWIRE.COM
14 MaySony's failed attempt to stop piracy.This week, Dave and Ben sit down to discuss how Sony's failed lawsuit could have major impacts on other copyright lawsuits alongside how the EU's AI approach might be grounded in nuclear deterrence strategies. Additionally, our team sits down with Dr. Liz James, a managing securi…THECYBERWIRE.COM
14 MayHYCU aiR detects insider risk and AI activity from backupsHYCU has announced HYCU aiR (AI Resilience), an AI-native solution that turns backup data across dozens of applications into a live and actionable intelligence for security, compliance, and IT teams. aiR lets organizations search, query, and run purpose-built agents to surface in…HELPNETSECURITY.COM
14 MayPentagon cyber official calls advanced AI ‘revolutionary warfare’Paul Lyons, principal deputy assistant secretary for cyber policy, also discussed the importance of cyber offense. The post Pentagon cyber official calls advanced AI ‘revolutionary warfare’ appeared first on CyberScoop .CYBERSCOOP.COM
13 MayVersa CSPM brings continuous visibility to cloud risk and compliance exposureVersa has announced Versa Cloud Security Posture Management (CSPM), extending the VersaONE Universal SASE Platform to provide continuous visibility, prioritization, and remediation of cloud risk across environments. With CSPM, Versa combines secure access protection and cloud pos…HELPNETSECURITY.COM
13 MayApricorn hardens ASK3 encrypted USB drive for extreme conditionsApricorn has announced enhancements to its Aegis Secure Key 3.0 (ASK3), delivering faster performance and new environmental protection capabilities designed to secure the device and its data in the most demanding physical circumstances. The ASK3 was updated to meet and exceed the…HELPNETSECURITY.COM
13 MaySignal responds to phishing attacks with new in-app security warningsSignal is adding new protections for users following recent phishing and social engineering attacks. In March, the FBI and CISA issued a warning stating that Signal had become a primary target of Russian intelligence-linked hackers. Dutch and German security authorities were amon…HELPNETSECURITY.COM
13 MayNavigating the Cybersecurity Landscape in India Empowering Human and AI AgentsIntroduction The Asia-Pacific and Japan (APJ) region, with its dynamic economic growth and technological advancements, presents unique challenges and opportunities in the realm of human risk management and agentic risk management, particularly within the financial services sector…KNOWBE4.COM
13 MayPCI PIN and P2PE compliance packages for AWS Payment Cryptography are now availableAmazon Web Services (AWS) is pleased to announce the successful completion of Payment Card Industry Personal Identification Number (PCI PIN) and PCI Point-to-Point Encryption (PCI P2PE) assessments for the AWS Payment Cryptography service. This assessment expands the AWS Payment …AWS.AMAZON.COM
13 MayIntroducing the updated AWS User Guide to Governance, Risk, and Compliance for Responsible AI AdoptionThe financial services industry (FSI) is using AI to transform how financial institutions serve their customers. AI solutions can help proactively manage portfolios, automatically refinance mortgages when rates decrease, and negotiate insurance premiums for customers. However, th…AWS.AMAZON.COM
13 MayCheckbox Assessments Aren't Fit to Measure to RiskSecurity governance needs to be more than an annual compliance exercise. New companies are emerging to address risk-management gaps in current audit tools.DARKREADING.COM
12 MayNavigating Human and Agentic Risks for Financial Institutions in the APJ RegionIntroduction The Asia-Pacific and Japan (APJ) region, with its dynamic economic growth and technological advancements, presents unique challenges and opportunities in the realm of human risk management and agentic risk management, particularly within the financial services sector…KNOWBE4.COM
12 MayMajor world economies spell out key elements of AI ‘ingredients list’Experts on the topic say the G7 guidance is good, but could still use some improvements. The post Major world economies spell out key elements of AI ‘ingredients list’ appeared first on CyberScoop .CYBERSCOOP.COM
11 MayPolice Shut Relaunched Crimenetwork Dark Web MarketplaceSpanish police have arrested the suspected administrator of German dark web marketplace CrimenetworkINFOSECURITY-MAGAZINE.COM
11 MayDirty Frag: Linux kernel hit by second major security flaw in two weeksThe issue was found in the same area of the Linux kernel that produced last month’s Copy Fail bug, and also allows anyone with a basic account on an affected computer to seize full administrative control.THERECORD.MEDIA
11 MayAlation AI Governance creates a system of record for AI oversightAlation has introduced Alation AI Governance, a new offering that gives enterprises the system of record they are missing for AI compliance. Enterprises are deploying AI models, agents, and tools faster than they can govern them. As a result, when a board or regulator asks about …HELPNETSECURITY.COM
11 MayWhen Ransomware Negotiators Flip SidesA ransomware negotiator pleaded guilty to conspiracy involving ransomware deployment and extortion against U.S. victims. The speaker also notes this is reportedly the third case involving someone connected to ransomware negotiations. Ransomware negotiators often sit in a uniquely…YOUTUBE.COM
9 MayHackable Robot Lawn Mower Unlocks a New NightmarePlus: Meta officially kills encrypted Instagram DMs, the Trump administration targets “violent left wing extremists,” leaked documents reveal Russia's school for elite hackers, and more.WIRED.COM
8 MayEU calls VPNs “a loophole that needs closing” in age verification pushThe European Parliamentary Research Service (EPRS) has warned that virtual private networks (VPNs) are increasingly being used to bypass online age-verification systems, describing the trend as “a loophole in the legislation that needs closing.” The warning comes as governments a…CYBERINSIDER.COM
8 MayKingdom Market administrator given 16-year sentenceSlovakian national Alan Bill, 33, pleaded guilty in January to a conspiracy to distribute controlled substances charge after admitting to his role in running Kingdom Market — a platform used by drug dealers and cybercriminals between March 2021 and December 2023.THERECORD.MEDIA
7 MayTrump’s AI Preemption Playbook.This week, Dave and Ben look at how the Trump administration is reshaping federalism through AI policy alongside looking at a lawsuit filed by a college student against a dating app for using her image without permission. Afterwards, Ben sits down with Jen Sovada, Claroty’s Publi…THECYBERWIRE.COM
7 MayKloudfuse 4.0 delivers AI-governed observability and scalable workload isolationKloudfuse has announced the general availability of Kloudfuse 4.0. The release helps enterprises meet rising compliance requirements, adopt AI-driven observability with production-grade governance, and scale their observability infrastructure without platform bottlenecks, while k…HELPNETSECURITY.COM
7 MayBots in translation: Can AI really fix SIEM rule sprawl across vendors?Enterprises migrating between SIEM platforms often have to manually rewrite detection rules because vendors such as Splunk, Microsoft Sentinel, IBM QRadar, and Google Chronicle use different query languages and data models. Researchers now say AI may be able to automate much of t…CSOONLINE.COM
7 MayNew CISA initiative aims to help critical infrastructure operators prepare for disruptions.Taiwanese police arrest student for allegedly hacking train systems. Scam apps offer fake phone call records.THECYBERWIRE.COM
7 MayHas CISA Finally Found Its New Leader in Tom Parker?Dark Reading investigates rumors that Tom Parker, a board room 'operator' and longtime cyber exec, could be next in line to take over CISA.DARKREADING.COM
7 MayPentagon reaches deals with seven AI providers.Trump administration considering pivot on AI oversight requirements.THECYBERWIRE.COM
7 MayTrump officials are steering a cybersecurity scholarship program toward AIThe latest development has thrown scholars for a curveball, and has some worried about being “left out to dry” when it comes to job positions. The post Trump officials are steering a cybersecurity scholarship program toward AI appeared first on CyberScoop .CYBERSCOOP.COM
7 MayThe backup plan needs a backup plan.CISA pushes critical infrastructure to prepare for offline operations during cyberattacks. Questions grow over a shared U.S.-China AI threat. A Russian university is accused of feeding talent into GRU cyber units. Researchers warn poisoned data could quietly corrupt enterprise AI…THECYBERWIRE.COM
7 MayIranian government hackers using Chaos ransomware as cover, researchers sayIncident responders from cybersecurity firm Rapid7 published a report about a recent intrusion that initially appeared to be a Chaos ransomware attack but was later discovered to be an attack attributed to MuddyWater, an Iranian APT group tied to the country’s Ministry of Intelli…THERECORD.MEDIA
6 MayIran-Linked Hackers Target Oman Ministries in Webshell and Data Theft CampaignIran-linked operators have mounted a broad espionage operation against multiple Omani ministries, abusing exposed webshells, SQL escalation scripts, and a poorly secured C2 server to steal judicial and identity data at scale. Attacker’s own open directory strongly suggests a Mini…GBHACKERS.COM
6 MayAttackers Bypass Azure AD Conditional Access Using Phantom Device RegistrationA recent authorized red team operation by Howler Cell has demonstrated a critical attack path that completely bypasses Microsoft Entra ID (Azure AD) Conditional Access. Azure Conditional Access acts as the primary gatekeeper for cloud identity security, enforcing access rules bas…GBHACKERS.COM
6 MayHow CISOs Reduce Cyber Risk with MITRE ATT&CKNowadays CISOs face escalating threats that outpace traditional defenses. The strategy is evolving from compliance-driven checklists to a threat-informed approach. MITRE ATT&CK provides a globally accessible knowledge base of real-world adversary tactics, techniques…ANY.RUN
6 MayCISA Urges Critical Infrastructure Providers to Make Plans to Remain Operational if hit by Cyber-AttackCISA’s CI Fortify initiative aim for critical infrastructure operators to build isolation & recoveryINFOSECURITY-MAGAZINE.COM
6 MayNIST will test three major tech firms’ frontier AI models for cybersecurity risksAfter Anthropic’s announcement of Claude Mythos, agencies across the government are racing to get ahead of new AI models’ potential dangers.CYBERSECURITYDIVE.COM
6 MayIranian state-backed spies pose as ransomware slingers in false flag attacksAn Iranian state-sponsored espionage group is pretending to be a regular ransomware gang in a new wave of ransomware attacks targeting enterprises. APT group MuddyWater (aka Seedworm) is masquerading as the Chaos ransomware-as-a-service group to confuse incident response and mask…CSOONLINE.COM
6 MayNew CISA initiative aims for critical infrastructure to operate offline during cyberattacksThe initiative, named CI Fortify, focuses on isolation and recovery efforts that would see critical infrastructure organizations proactively disconnect from third-party dependencies and find ways to operate without reliable telecommunications and internet.THERECORD.MEDIA
6 MayNew compliance guide available: ISO/IEC 42001:2023 on AWSWe have released our latest compliance guide, ISO/IEC 42001:2023 on AWS, which provides practical guidance for organizations designing and operating an Artificial Intelligence Management System (AIMS) using AWS services. As organizations deploy AI and generative AI workloads in t…AWS.AMAZON.COM
5 MayDownload: Secure Foundations for AI Workloads on AWSCenter for Internet Security helps organizations deploy AI and high-performance compute environments from a trusted, hardened operating system baseline. CIS Hardened Images help teams reduce misconfiguration risk, support compliance efforts, and move faster in AWS. What are AI-op…HELPNETSECURITY.COM
5 MayMicrosoft: Phishing campaign used fake compliance notices to compromise employee accountsPhishers have been using fake workplace compliance notices to try to trick Microsoft account owners into signing in via a fake sign-in page, says the company’s Defender Research team. The email campaign targeted more than 35,000 users across 13,000 organizations in 26 count…HELPNETSECURITY.COM
5 MayLuxSci Launches Enterprise-Grade HIPAA-Compliant Email Security for Mid-Sized Healthcare OrganizationsCambridge, MA, May 5th, 2026, CyberNewswire New right-sized offering brings advanced encryption, easy API integration, and HITRUST-certified compliance to the most underserved segment in healthcare email — with pricing starting at $99/month LuxSci, a leading provider of HIPAA com…GBHACKERS.COM
5 MayCISA urges critical infrastructure firms to ‘fortify’ now before it’s too lateAs concerns mount about potential cyber sabotage by the Chinese government, the U.S. is warning infrastructure operators to practice maintaining services in a degraded state.CYBERSECURITYDIVE.COM
5 MayMicrosoft Flags Mass Phishing Campaign Using Fake Compliance EmailsMicrosoft researchers warn of a large-scale phishing campaign using fake compliance emails to steal credentials, targeting 35,000 users across 13,000 organizations worldwideINFOSECURITY-MAGAZINE.COM
5 MayCISA boasts AI automation improvements to threat analysis, mission supportCybersecurity and Infrastructure Security Agency officials said it’s proven a boon in numerous areas, but there are some hurdles to adoption, still. The post CISA boasts AI automation improvements to threat analysis, mission support appeared first on CyberScoop .CYBERSCOOP.COM
5 MaySupply-chain attacks take aim at your AI coding agentsAttackers too are looking to cash in on the AI coding craze, adapting their supply-chain techniques to target coding agents themselves. Many AI agents autonomously scan package registries such as NPM and PyPI for components to integrate into their coding projects, and attackers a…CSOONLINE.COM
5 May KEVZino, 0auth, VSS, Mental Health Hackers, 3 Days of KEV, Copy/Fail, AI, Aaran Leyland - SWN #578Zino of Citium, 0auth, VSS, Mental Health Hackers, 3 Days of the CISA, Copy/Fail, AI Gone Wild, Aaran Leyland, and More on the Security Weekly News. Visit https://www.securityweekly.com/swn for all the latest episodes! Show Notes: https://securityweekly.com/swn-578YOUTUBE.COM
5 MayCISA wants critical infrastructure to operate ‘weeks to months’ in isolation during conflictThe agency will begin targeted assessments meant to help critical infrastructure entities operate while disconnecting OT networks from IT and third-party vendors. The post CISA wants critical infrastructure to operate ‘weeks to months’ in isolation during conflict appeared first …CYBERSCOOP.COM
4 MayGlobal Crackdown Arrests 276, Shuts 9 Crypto Scam Centers, Seizes $701MA coordinated international operation involving U.S. and Chinese authorities has arrested at least 276 suspects and shut down nine scam centers used for cryptocurrency investment fraud schemes targeting Americans, resulting in millions of dollars in losses. The crackdown was led …THEHACKERNEWS.COM
4 MayDigiCert Root Certificates Incorrectly Detected as Malware by Microsoft DefenderOn May 3, 2026, system administrators and everyday users worldwide experienced a sudden, massive spike in severe security alerts from Microsoft Defender. The native Windows security platform began aggressively flagging system files as “Trojan:Win32/Cerdigent.A!dha.” T…GBHACKERS.COM
4 MayPenske Logistics launches platform for real-time supply chain visibilityPenske Logistics has announced the launch of Supply Chain Insight, a secure technology platform and mobile application that provides customers with a real-time view of their supply chain operations across transportation and warehousing. Supply chain leaders are under increased pr…HELPNETSECURITY.COM
4 MayUS government warns of severe CopyFail bug affecting major versions of LinuxU.S. cybersecurity agency CISA says the CopyFail bug is being actively used in hacking campaigns, and poses a major risk to servers and data centers that rely on Linux.TECHCRUNCH.COM
1 MayMultiple Exim Mail Server Vulnerabilities Could Trigger Crashes via Malicious DNS DataThe developers of the Exim mail server have officially rolled out version 4.99.2 to address four newly discovered security vulnerabilities. This critical update patches multiple software flaws that could allow attackers to crash server connections, corrupt memory heaps, or potent…GBHACKERS.COM
1 MayEtherRAT Uses SEO Poisoning and Fake GitHub Pages to Target Enterprise AdminsA newly uncovered cyber campaign dubbed “EtherRAT” is raising concerns across enterprise environments, as attackers combine SEO poisoning, GitHub abuse, and blockchain-based infrastructure to target high-privilege IT professionals. Instead of broadly targeting users, the attacker…GBHACKERS.COM
1 MayNearly every Linux system built since 2017 vulnerable to ‘Copy Fail’ flawSecurity researchers and European cybersecurity officials are urging administrators to address the risk posed by a newly discovered security flaw that has been hiding in the Linux operating system for nearly a decade.THERECORD.MEDIA
1 MayUK Tech Ministers Opposing Government Plans to Align with EU AI RulesUK technology ministers are briefing against government plans to adopt EU regulations, arguing that it could restrict the growth of Britain’s tech and AI sector. The post UK Tech Ministers Opposing Government Plans to Align with EU AI Rules appeared first on TechRepublic .TECHREPUBLIC.COM
1 MayUS government, allies publish guidance on how to safely deploy AI agentsThe guidance warns that agents capable of taking real-world actions on networks are already inside critical infrastructure, and most organizations are granting them far more access than they can safely monitor or control. The post US government, allies publish guidance on how to …CYBERSCOOP.COM
1 MayAnnouncing the ISO 31000:2018 Risk Management on AWS Compliance GuideAWS Security Assurance Services is announcing the release of our latest compliance guide, ISO 31000:2018 Risk Management on AWS, which provides practical guidance for organizations establishing and operating a risk management program in AWS environments using ISO 31000:2018 princ…AWS.AMAZON.COM
30 AprEtherRAT Distribution Spoofing Administrative Tools via GitHub FacadesIntro A sophisticated, high-resilience malicious campaign was identified by Atos Threat Research Center (TRC) in March 2026. This operation specifically targets the high-privilege professional accounts of enterprise administrators, DevOps engineers, and security analysts by imper…THEHACKERNEWS.COM
30 AprCISA and Partners Publish Zero Trust Guidance For OT SecurityA new CISA‑led guide explains how zero‑trust security can be applied to operational technology, balancing cyber defence with safety and system availabilityINFOSECURITY-MAGAZINE.COM
30 AprZambia cancels global digital freedoms conference days before startOn Tuesday, Zambia’s Minister of Technology and Science offered the first hint that the conference would be cancelled, telling a Zambian news outlet that participants’ security clearances were incomplete and that the government has concerns about the conference’s “dialogue.”THERECORD.MEDIA
30 AprHackers earning millions from hijacked cargo, FBI saysIn an advisory this week, FBI officials said cyber actors have spent the last two years breaking into the systems of brokers and carriers — allowing them to pose as victim companies and post fraudulent listings on freight delivery message boards.THERECORD.MEDIA
29 Apramazee.ai’s amazeeClaw simplifies production deployment of AI agents with regional controlamazee.ai has announced the launch of amazeeClaw, a managed OpenClaw hosting platform that enables developers and enterprises to deploy production-ready AI agents with data sovereignty and regional control without having to set up their own infrastructure. As adoption of AI agent…HELPNETSECURITY.COM
29 AprAlleged Silk Typhoon hacker extradited to the United States to face chargesA man accused of working as a hacker for China's Ministry of State Security has been extradited to the USA from Italy, and faces - if found guilty - the prospect of decades behind bars. Read more in my article on the Hot for Security blog.BITDEFENDER.COM
29 AprSri Lanka discloses another missing payment, days after hackers stole $2.5M from its finance ministryThe government of Sri Lanka has lost more than $3 million in two recent, separate cybersecurity incidents as the country continues to recover from its 2022 debt crisis.TECHCRUNCH.COM
28 AprFrench police arrest 21-year-old “HexDex” hacker over 100 alleged data breachesA 21-year-old man suspected of conducting approximately 100 data breaches since late 2025 - including a hack of the French Ministry of National Education that exposed records on almost a quarter of a million employees - has been arrested at his home in western France. Read more i…BITDEFENDER.COM
28 AprNo Metrics Are Better Than Bad Metrics in the SOC, Says NCSCThe National Cyber Security Centre has warned against measuring SOCs with ticket-based metricsINFOSECURITY-MAGAZINE.COM
28 AprNCSC launches SilentGlass, a plug-in device to secure HDMI and DisplayPort linksNCSC’s SilentGlass blocks malicious HDMI/DisplayPort links, protecting monitors from hardware attacks. Now commercialized for global use. The UK’s National Cyber Security Centre (NCSC) has launched SilentGlass, a new device to protect one of the most overlooked parts of modern IT…SECURITYAFFAIRS.COM
28 AprSignal to roll out anti-phishing safeguards following account takeoversSignal says recent reports describing attacks against its users do not reflect a breach of its platform, while also announcing plans to introduce new protections aimed at stopping similar phishing campaigns in the future. The clarification follows a joint advisory issued earlier …CYBERINSIDER.COM
28 AprWar hits where it hurts.Conflict in the Middle East disrupts the circuit board supply chain. The Supreme Court considers arguments on geofence searches. A new report highlights Chinese digital transnational repression. The NCSC protects HDMI and DisplayPort links. Tennessee bans cryptocurrency ATMs. Res…THECYBERWIRE.COM
27 AprTLS Connect gives SMBs a right-sized automated tool to manage TLS certificatesGMO GlobalSign today launched TLS Connect, a Certificate Lifecycle Management (CLM) tool designed specifically for SMBs. TLS Connect automates public trust TLS certificate deployment and renewal, allowing SMBs to strengthen security, maintain regulatory compliance and reduce busi…HELPNETSECURITY.COM
25 AprCISA reports persistent FIRESTARTER backdoor on Cisco ASA device in federal networkCISA said a federal Cisco Firepower ASA device was infected with the FIRESTARTER backdoor in Sept 2025, and it survived security patches. CISA revealed that a U.S. federal civilian agency’s Cisco Firepower device running ASA software was compromised in September 2025 by the FIRES…SECURITYAFFAIRS.COM
24 AprChinese attackers are pwning your infrastructure to use in attacks, 10 countries warnsubmitted by Sepia to cybersecurity 1 points | 0 comments https://www.theregister.com/2026/04/23/china_covert_networks/ Here is the report, Defending against China-nexus covert networks of compromised devices (pdf) . A majority of China-linked threat actors are using compromised …SH.ITJUST.WORKS
24 AprChinese attackers are pwning your infrastructure to use in attacks, 10 countries warnsubmitted by Sepia to cybersecurity 5 points | 1 comments https://www.theregister.com/2026/04/23/china_covert_networks/ cross-posted from: mander.xyz/post/50988211 Here is the report, Defending against China-nexus covert networks of compromised devices (pdf) . A majority of China…INFOSEC.PUB
24 AprChina-linked threat actors use consumer device botnets to evade detection, warn UK and partnersUK National Cyber Security Centre (NCSC) warns China-linked hackers use hijacked devices as proxy networks to hide activity and evade detection. UK National Cyber Security Centre (NCSC) and global partners warn that China-linked threat actors now rely on large proxy networks buil…SECURITYAFFAIRS.COM
24 AprCompromised everyday devices power Chinese cyber espionage operationsChina-linked threat actors have shifted from individually procured infrastructure to large-scale covert networks, botnets built from compromised routers and other edge devices, the National Cyber Security Centre (NCSC) warns. To help organizations address this threat, the NCSC, t…HELPNETSECURITY.COM
24 AprNew Cisco firewall malware can only be killed by pulling the plugSuspected state-sponsored attackers are using a custom backdoor to persistently compromise Cisco security devices (firewalls), the US CISA and the UK National Cyber Security Centre warned on Thusday. “The [Firestarter] malware (…) is relevant for both Cisco Firepower …HELPNETSECURITY.COM
24 AprNorway's prime minister proposes ban on social media access for young teensAn upcoming proposed bill will include language that holds big tech accountable for using age verification tools to block young users.THERECORD.MEDIA
24 AprNASA Employees Duped in Chinese Phishing Scheme Targeting U.S. Defense SoftwareThe Office of Inspector General (OIG) of the U.S. National Aeronautics and Space Administration (NASA) has revealed how a Chinese national posed as a U.S. researcher as part of a spear-phishing campaign to obtain sensitive information from the space agency, as well as from govern…THEHACKERNEWS.COM
24 AprFIRESTARTER Backdoor Hit Federal Cisco Firepower Device, Survives Security PatchesThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) has revealed that an unnamed federal civilian agency's Cisco Firepower device running Adaptive Security Appliance (ASA) software was compromised in September 2025 with malware called FIRESTARTER. FIRESTARTER, per CI…THEHACKERNEWS.COM
24 AprIran’s cyber threat may be less ‘shock and awe’ than ‘low and slow,’ officials sayOfficials and experts believe the most likely threat from Iranian hackers is not a digital shock-and-awe campaign, but something quieter: opportunistic intrusions, dressed up to look bigger than they are.THERECORD.MEDIA
24 AprA digital battlefield in practice.Locked Shields wraps another year. Open models challenge Mythos. CISA tracks FIRESTARTER inside a federal agency. The White House targets foreign AI model extraction. Microsoft lets admins remove Copilot. Treasury sanctions a Cambodian scam-compound senator. Breeze Cache rushes a…THECYBERWIRE.COM
24 AprLatest spy power reauthorization bill leaves critics unimpressedAn April 30 deadline is looming to extend expiring Section 702 powers, and the newest legislation to re-up it is drawing fire from the left and right. The post Latest spy power reauthorization bill leaves critics unimpressed appeared first on CyberScoop .CYBERSCOOP.COM
🔥 INCIDENT REPORTING 912[−]
23 JulRansomware Attack Puts a Chill On Japanese Frozen-Food ChainA cyberattack on a food and logistics firm disrupts the supply of frozen food to thousands of clients, including major franchises like Kentucky Fried Chicken.DARKREADING.COM
23 JulTwo-Thirds of Ransomware Victims Say AI Boosted Attack EffectivenessA new study of organizations which have fallen victim to ransomware suggests the rise of AI-tools being used by hackers is making life harder for defendersINFOSECURITY-MAGAZINE.COM
23 JulSwiss rail manufacturer Stadler refuses to pay $12.3 million ransom after cyberattackCybercriminal group Everest is demanding 10 million Swiss francs ($12.3 million) from Swiss rail vehicle manufacturer Stadler after breaching a data exchange platform shared with one of its suppliers through compromised credentials. Stadler operates 16 production and component pl…HELPNETSECURITY.COM
23 JulNew msaRAT malware uses Chrome, Edge browsers to route C2 trafficThe Chaos ransomware gang is using a new backdoor dubbed msaRAT that hides command-and-control (C2) communication by routing it through the Chrome or Edge browsers. [...]BLEEPINGCOMPUTER.COM
23 JulPyPI hardens package security with new upload restrictionsThe Python Package Index (PyPI) now rejects uploads of new files to releases older than 14 days to prevent attackers from poisoning long-stable releases if a project’s publishing tokens or release workflows are compromised. “This change will protect Python users and reduce …HELPNETSECURITY.COM
23 JulChaos ransomware's msaRAT: Living off the browser to build a covert C2 channelThe Chaos ransomware group uses new malware "msaRAT" that hijacks browsers. The malware doesn't communicate directly with C2 but connects through the browser. It enables arbitrary command execution while hiding the attacker's IP from victims via WebRTC over TURN.TALOSINTELLIGENCE.COM
23 JulUpbound Group Says Data Breach Led to $13 Million in Fraudulent Contract LossesHackers recently obtained non-sensitive customer information and other documents from the company. The post Upbound Group Says Data Breach Led to $13 Million in Fraudulent Contract Losses appeared first on SecurityWeek .SECURITYWEEK.COM
23 JulChaos ransomware msaRAT hides its C2 channel inside a legitimate browser processCisco Talos has identified a Rust-based remote access trojan it attributes to the Chaos ransomware group, named msaRAT after four of the binding names left in the binary. The tool starts its own instance of Chrome or Edge on the victim machine and controls it through Chrome DevTo…HELPNETSECURITY.COM
23 JulAttackers Weaponize GitHub Actions Runners to Target cPanel and WHM ServersCybersecurity researchers have shed light on a large-scale campaign that has turned compromised GitHub repositories into distributed attack infrastructure designed to target cPanel and WebHost Manager (WHM) instances. The activity involves malicious Packagist development versions…THEHACKERNEWS.COM
23 JulWhen the "Autonomous Attacker" Is Your Own AI Model, (Thu, Jul 23rd)Two disclosures, five days apart, described the same intrusion from opposite ends —
one from the victim, one from the party that turned out to be responsible — and
together they make one of the more instructive incidents of th…ISC.SANS.EDU
23 JulMajor Australian energy supplier confirms customer data compromisedOrigin Energy said it was working to figure out how many Australians were affected by a recent data breach.THERECORD.MEDIA
23 JulChaos Ransomware Uses msaRAT to Route C2 Traffic Through Headless Chrome and EdgeThe Chaos ransomware group ran its command-and-control through the victim's own browser. Cisco Talos on Thursday detailed msaRAT, the Rust implant behind it, found on a compromised Windows machine ahead of the encryptor. The implant never opens an outbound connection of its own. …THEHACKERNEWS.COM
23 JulAustralian energy provider Origin says data breach exposes client dataOrigin Energy has confirmed that an unauthorized party accessed and subsequently leaked customer data online, exposing sensitive personally identifiable information (PII), among others. [...]BLEEPINGCOMPUTER.COM
22 JulRisky Business #845 -- OpenAI's Skynet momentOn this week’s show special guest co-host Chris Krebs joins Patrick Gray and James Wilson to discuss the week’s cybersecurity news. They cover: Oopsie daisy! OpenAI agents went rogue and hacked Hugging Face US and China trade AI model ban threats Iran has been using SS7 queries t…RISKY.BIZ
22 JulOpenAI says its AI models hacked Hugging Face during testingOpenAI says its AI models, including GPT‑5.6 Sol and a pre-release model, hacked into the Hugging Face artificial intelligence repository while being tested in a sandboxed testing environment. [...]BLEEPINGCOMPUTER.COM
22 JulOpenAI Says Its AI Models Escaped Sandbox, Targeted Hugging Face to Cheat BenchmarkOpenAI on Tuesday said a combination of its artificial intelligence (AI) models, including GPT-5.6 Sol and an "even more capable pre-release model," was behind the security incident that targeted Hugging Face's production infrastructure last week. The AI company said the models w…THEHACKERNEWS.COM
22 JulChick-fil-A discloses data breach after credential stuffing attacksAmerican fast food restaurant chain Chick-fil-A is notifying customers of a data breach after their accounts were hacked in a wave of recent credential stuffing attacks. [...]BLEEPINGCOMPUTER.COM
22 JulProofpoint Research Finds 65% of Organizations Affected by Ransomware Say AI Made Attacks More EffectivePROOFPOINT.COM
22 JulRansomware Group Threatening to Leak Data Stolen From Coca-Cola’s FairlifeThe Anubis ransomware group claims to have stolen 1 TB of confidential data from the Coca-Cola subsidiary. The post Ransomware Group Threatening to Leak Data Stolen From Coca-Cola’s Fairlife appeared first on SecurityWeek .SECURITYWEEK.COM
22 JulOpenAI confirms its AI agent autonomously breached Hugging FaceOpenAI has revealed that an autonomous AI agent powered by GPT-5.6 Sol and a more capable unreleased model escaped its intended testing environment, gained internet access, and compromised parts of Hugging Face's production infrastructure while attempting to obtain benchmark answ…CYBERINSIDER.COM
22 JulPaidwork breach exposes data of 23 million users: Check if you’re affectedA reported breach at microtask platform Paidwork exposed personal and financial data of more than 23 million users. Here's how to check if you're affected.MALWAREBYTES.COM
22 JulOpenAI models behind breach of Hugging Face systems, companies sayOpenAI announced that its models were behind a breach of the AI platform Hugging Face, which had earlier detected an attack carried out by "by an autonomous AI agent."THERECORD.MEDIA
22 JulSuno, Paidwork Data Breaches Affect Tens of Millions of AccountsHackers leaked names, email addresses, phone numbers, passwords, and financial information stolen from the two platforms. The post Suno, Paidwork Data Breaches Affect Tens of Millions of Accounts appeared first on SecurityWeek .SECURITYWEEK.COM
22 JulFlaw in Adobe Extension With 300M Installs Enabled WhatsApp Data TheftAn attacker only needed to convince the targeted user to visit a malicious website to exfiltrate WhatsApp messages and contacts. The post Flaw in Adobe Extension With 300M Installs Enabled WhatsApp Data Theft appeared first on SecurityWeek .SECURITYWEEK.COM
22 JulJapanese food logistics giant recovers as extortion group claims cyberattackNichirei Logistics Group said warehouse operations and frozen food shipments are returning to normal. A cybercrime gang said it caused the disruption.THERECORD.MEDIA
22 JulOpenAI models escaped containment and hacked a major AI application libraryThe attack is the first known instance of frontier models autonomously breaking out of a testing environment and into another company’s servers.CYBERSECURITYDIVE.COM
22 JulHow enterprise GenAI can amplify ransomware risk — and how to contain itEnterprise AI can accelerate ransomware attacks when AI assistants and agents inherit excessive permissions or compromised identities. Acronis explains how identity controls, governance, and least-privilege access help reduce AI-enabled ransomware risk while supporting secure AI …BLEEPINGCOMPUTER.COM
22 JulNew Kimsuky campaign compromised South Korean software vendorsA North Korean advanced persistent threat (APT) group recently targeted vendors of collaborative-work software, South Korean researchers said.THERECORD.MEDIA
22 JulSwiss rail giant Stadler rejects $12.3M ransom demand after cyberattackSwiss rail vehicle manufacturer Stadler Rail says the Everest ransomware gang demanded about $12.3 million after breaching a data exchange platform shared with one of its suppliers. [...]BLEEPINGCOMPUTER.COM
22 JulReal world incident response: Microsoft and AXA XL strengthen cyber resilienceOur collaboration with AXA XL brings Microsoft Incident Response services directly to cyber insurance policyholders, helping organizations coordinate technical, business, and insurance decisions. The post Real world incident response: Microsoft and AXA XL strengthen cyber resilie…MICROSOFT.COM
21 JulPR3TACK preemptive framework maps threats before attackers use themDefensive frameworks in cybersecurity record what attackers have already done. Analysts study a breach, document the method, and build detections around confirmed activity. This cycle leaves a gap between the moment an attacker invents a technique and the moment defenders learn t…HELPNETSECURITY.COM
21 JulThe air gap is a myth and other OT security truthsBenjamin Bachmann, Director Group Information Security at Bilfinger, speaks with Help Net Security about defending industrial plants. He explains why attackers want to control operations instead of stealing data, and why the air gap is mostly a myth. Bachmann covers how containme…HELPNETSECURITY.COM
21 JulData breach at AI music service Suno exposed 55 million accountsAI music generation platform Suno suffered a data breach that exposed the personal information of more than 55 million users, according to Have I Been Pwned (HIBP). The incident exposed phone numbers and tens of thousands of Stripe purchase records containing customer names, phys…CYBERINSIDER.COM
21 JulUkraine warns fake CAPTCHAs are being used to make you hack yourselfUkraine's computer emergency response team, CERT-UA, has warned that the Kremlin-backed Sandworm hacking group is leveraging fake CAPTCHA checks on compromised websites that persuade users to run malicious code. Read more in my article on the Hot for Security blog.BITDEFENDER.COM
21 JulA Device Hidden in Cars Across the US Leaves Them Vulnerable to Hacking and Paralysis. Patch It NowDealerships installed alarms in millions of vehicles—and left them in even if the buyer didn’t want them. Now researchers warn they can be hacked to unlock, track, and disable cars.WIRED.COM
21 JulClover Health Investments Discloses Data BreachUsing social engineering, hackers compromised employee accounts with access to personal and health information. The post Clover Health Investments Discloses Data Breach appeared first on SecurityWeek .SECURITYWEEK.COM
21 JulNew HollowGraph Malware Abuses Microsoft 365 Calendar for C&C CommunicationPart of a larger toolkit, HollowGraph uses a compromised 365 account’s calendar as a two-way dead-drop. The post New HollowGraph Malware Abuses Microsoft 365 Calendar for C&C Communication appeared first on SecurityWeek .SECURITYWEEK.COM
21 JulKenya probes hack of president's website after bitcoin ransom demandThe website was hacked on Saturday, when its homepage was replaced with a message displaying a cryptocurrency wallet address and threatening to publish unspecified information about President William Ruto unless the ransom was paid.THERECORD.MEDIA
21 JulA New Ransomware Threat Actor Emerges Every Week, Warns ReportAnalysis by Black Kite warns that ransomware ecosystem is becoming bigger and more fragmentedINFOSECURITY-MAGAZINE.COM
21 JulClosing the Identity Gaps in Critical Infrastructure SecurityCritical infrastructure attacks often begin with stolen credentials, compromised devices, or trusted accounts. Specops Software explains why Zero Trust should verify both user identities and device trust before granting access to critical systems. [...]BLEEPINGCOMPUTER.COM
21 JulJadePuffer returns with ransomware built to target AI models and infrastructureJadePuffer, the threat actor behind the recently documented extortion operation executed end-to-end by an AI agent, is now attempting to leverage ENCFORGE, novel ransomware created to target AI and machine learning (ML) infrastructure. The extortion contact embedded in the ransom…HELPNETSECURITY.COM
21 JulAI music generator Suno breach affects 55M users, per Have I Been PwnedA hacker took names, phone numbers, and physical addresses of millions of customers who used AI music generator Suno.TECHCRUNCH.COM
21 JulRansomware victims fail to fix flaws that exposed themMany organizations still aren’t securing their email or patching vulnerabilities after recovering from attacks, a new report found.CYBERSECURITYDIVE.COM
21 JulSpain fines 23andMe nearly $3 million for cybersecurity failings enabling 2023 hackThe Agencia Española de Protección de Datos (AEPD) announced the fine on Friday, saying in its decision that more than 2,600 Spaniards were impacted by a breach affecting 6.9 million people worldwide.THERECORD.MEDIA
21 JulAnubis ransomware claims Coca-Cola Fairlife attack, threatens data leakThe Anubis ransomware gang has claimed responsibility for the cyberattack on Coca-Cola's Fairlife dairy subsidiary, threatening to publish allegedly stolen corporate data unless the company pays a ransom. [...]BLEEPINGCOMPUTER.COM
21 JulThe defense against the AI arts.Trump's latest AI leader resigns. The Army burns through its AI tokens. Scammers impersonate IC3 personnel.HollowGraph malware uses a compromised Microsoft 365 calendar for C2. Qilin ransomware targets a critical Palo Alto Networks flaw. A North Korean campaign targets Web3 and c…THECYBERWIRE.COM
21 JulRansomware Is Accelerating, But It's Not Because of AIResearchers pointed to fragmentation of the ransomware ecosystem, the emergence of new attackers, and expansion of attacks on less defended organizations.DARKREADING.COM
21 JulOpenAI says model test was behind Hugging Face hackAt the time, Hugging Face said it wasn’t clear which LLM was used in the attack. OpenAI confirmed it was one of their models being tested for “maximal” cyber capabilities. The post OpenAI says model test was behind Hugging Face hack appeared first on CyberScoop .CYBERSCOOP.COM
20 JulMore alerts are making your team slower, and an outcome-based SOC fixes thatIn this Help Net Security video, Thom Langford, EMEA CTO, Rapid7, explains why piling on more security alerts makes a SOC slower to respond. Attackers log in with stolen credentials and use trusted tools like PowerShell instead of custom malware. He shares a case where attackers …HELPNETSECURITY.COM
20 JulHugging Face Hacked in Autonomous AI AttackTargeting production infrastructure, the attack compromised internal datasets and service credentials. The post Hugging Face Hacked in Autonomous AI Attack appeared first on SecurityWeek .SECURITYWEEK.COM
20 JulErnst & Young Data Breach Affects Personal, Financial InformationHackers stole names, addresses, Social Security numbers, credit/debit card numbers, and other information from a third-party management platform. The post Ernst & Young Data Breach Affects Personal, Financial Information appeared first on SecurityWeek .SECURITYWEEK.COM
20 JulHugging Face confirms breach affected internal datasets and credentials, urges users to take actionHugging Face is urging users to rotate any access tokens stored on the platform and review account activity.TECHCRUNCH.COM
20 JulSoftware provider to more than 2,000 US hospitals says hackers stole employee and customer dataCraneware, which is headquartered in Edinburgh and listed on London's AIM market, told investors it detected unauthorized access to a “subset” of its data environment and has since brought in outside forensic investigators.THERECORD.MEDIA
20 JulJadePuffer Returns With Ransomware Designed to Wipe AI ModelsJadePuffer follow-up campaign deployed ENCFORGE locker built to destroy AI model artifactsINFOSECURITY-MAGAZINE.COM
20 JulHackers stole ‘significant’ amount of data from tech firm relied on by thousands of US hospitals and pharmaciesEdinburgh-based tech firm Craneware said customer data was stolen during a cyberattack. The company makes software that thousands of U.S. hospitals, pharmacies, and clinics rely on for billing patients, potentially exposing health data.TECHCRUNCH.COM
20 JulHealthcare giant Abbott probes two cyber incidents amid extortion claimsExtortion groups ShinyHunters and ShadowByt3$ claim they stole vast amounts of patient data. Those allegations have not been verified.MALWAREBYTES.COM
20 JulRomania races to restore land registry after cyberattack disrupts property marketRomania's land registry agency is still recovering from a cyberattack it called "the most serious technical incident in the institution's history."THERECORD.MEDIA
20 JulPaidwork breach exposes sensitive data of 23 million userData belonging to more than 23 million users has been exposed following a breach at Paidwork, a platform that pays people for completing online microtasks. Paidwork markets itself as a way to earn money through simple tasks like watching ads, testing apps, and completing surveys,…HELPNETSECURITY.COM
20 JulHollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050A newly discovered espionage implant has been using a hijacked Microsoft 365 calendar as its command channel, planting operator instructions and smuggling out stolen files as attachments on calendar events dated to the year 2050. Group-IB, which named the malware HollowGraph, say…THEHACKERNEWS.COM
20 JulHugging Face discloses an autonomous agentic breach.Abbott Laboratories investigates another alleged breach. FBI arrests a Florida man accused of spreading malware through video games.THECYBERWIRE.COM
20 JulHackers steal customer data from major hospital software vendorThe breach is another reminder of how vulnerable the healthcare industry is to supply-chain attacks.CYBERSECURITYDIVE.COM
20 JulNew HollowGraph malware uses Microsoft Graph for stealthy C2 commsA malicious component dubbed HollowGraph uses the calendar feature in compromised Microsoft 365 mailboxes as a command-and-control channel to receive attacker commands and exfiltrate stolen data. [...]BLEEPINGCOMPUTER.COM
20 JulSuno - 55,282,226 breached accountsIn November 2025, AI music generation tool Suno suffered a data breach that later came to light in July the following year . The data contained over 55M unique email addresses. Phone numbers were also present where they had been used as the sign-up method. Although representing a…HAVEIBEENPWNED.COM
20 JulJadePuffer agentic attacks now target AI model data with ransomwareThe JadePuffer autonomous AI agent has upgraded with custom malware called EncForge that focuses on encrypting AI assets, such as training datasets, vector databases, and model checkpoints. [...]BLEEPINGCOMPUTER.COM
19 JulSECURITY AFFAIRS MALWARE NEWSLETTER ROUND 106Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter CrashStealer: C++ macOS infostealer posing as crash reporter Lucide Proxy: Turning Student Web Proxies into DDoS Bots …SECURITYAFFAIRS.COM
19 JulPaidwork - 23,272,765 breached accountsIn March 2026, hackers claimed they had obtained data from the gig economy platform Paidwork which they then listed for sale . Almost 11GB of data allegedly obtained from the platform was subsequently posted publicly in July and contained over 23M unique email addresses. The brea…HAVEIBEENPWNED.COM
18 JulWhen trusted sites turn.Lauren Fievisohn, Ph.D, Senior Threat Researcher from Silent Push, is sharing their work on "Meet DriveSurge: A New Threat Actor Using ClickFix and Fake Update Drive-By Attacks in Thousands of Compromised Sites." Silent Push researchers have identified a newly named threat act…THECYBERWIRE.COM
18 JulYour Period Tracker Is (Probably) Spying on YouPlus: Russian cyberspies turn to infrastructure hacking, DHS repeatedly fails to realize it’d been hacked, a breach exposes an AI music generator’s scraping ways, and more.WIRED.COM
18 JulDaxin: 13-Year-Old China-Linked Malware Found Still Active on Manufacturer’s NetworkResearchers found China’s Daxin rootkit and a new Stupig backdoor on a Taiwan firm’s network, suggesting a stealthy intrusion dating back to 2013. Symantec’s Threat Hunter Team found Daxin running on a compromised host at a Taiwan-based subsidiary of a multinati…SECURITYAFFAIRS.COM
17 JulCoca-Cola Suspends US Fairlife Production Due to Ransomware AttackThe company says the incident has not affected product quality and safety, nor Fairlife’s Canada production. The post Coca-Cola Suspends US Fairlife Production Due to Ransomware Attack appeared first on SecurityWeek .SECURITYWEEK.COM
17 JulThe Gentlemen Overtakes Qilin as Most Prolific Ransomware ThreatAnalysis of ransomware incidents by ReliaQuest indicates a shift in the ransomware landscapeINFOSECURITY-MAGAZINE.COM
17 JulCyberattack Disrupts Operations of Japanese Frozen Food Giant NichireiThe company disconnected its systems on July 13 and is starting to gradually restore operations. The post Cyberattack Disrupts Operations of Japanese Frozen Food Giant Nichirei appeared first on SecurityWeek .SECURITYWEEK.COM
17 JulNew GoSerpent Malware Targets Southeast Asian Governments and Diplomats for EspionageCybersecurity researchers have discovered a previously undocumented malware called GoSerpent that has been put to use in cyber attacks targeting entities in Southeast Asia since late 2025 with a focus on long-term access and intelligence gathering. Russian cybersecurity company K…THEHACKERNEWS.COM
17 JulEY says client tax data exposed in third-party IT software breachErnst & Young (EY) is notifying affected individuals that personal and financial information was exposed after attackers breached a third-party IT service management platform used by the firm's tax practice. The professional services giant says the incident resulted in unaut…CYBERINSIDER.COM
17 JulArmenia Detains Russian Tourist on U.S. Warrant for REvil Hacker, Lawyers Say Wrong ManArmenia has held a Russian tourist named Aleksandr Ermakov in a detention center since June 28, on a U.S. extradition request for a REvil ransomware suspect named Aleksandr Ermakov. His wife, Maria Yurova, told REN TV that border officers pulled him out of the departure hall at Y…THEHACKERNEWS.COM
17 JulShark vacuum flaw exposes cameras, home maps and Wi-Fi passwordsOne compromised Shark robot vacuum could unlock remote access to many others.MALWAREBYTES.COM
17 JulSpirals ransomware locks down victim systems in under 24 hoursA previously unknown ransomware strain called Spirals was used last month in an attack against an IT services company in South Asia, where attackers went from initial access to data theft and encrypting the network in less than 24 hours, according to Symantec’s Threat Hunte…HELPNETSECURITY.COM
17 JulDairy company Fairlife suspends production in US after cyber incidentFairlife’s U.S. operation includes plants in Michigan, New York and Arizona, and the company's retail sales passed $1 billion in 2022.THERECORD.MEDIA
17 JulWhen Patching Is Already Too LateThe discussion makes a bold claim: many organizations no longer have enough time to patch before attackers compromise vulnerable systems. Instead of treating prevention as the primary strategy, the emphasis shifts toward detecting intrusions quickly and responding before attacker…YOUTUBE.COM
17 JulGovernment Agencies Falling Victim to Ransomware Daily, Warns StudyGovernment organizations are targeted by attackers who know agencies cannot afford disruption to public servicesINFOSECURITY-MAGAZINE.COM
17 Jul23andMe Faces New Security Mandates in $18m Data Breach Settlement23andMe has agreed to an $18m settlement with 42 US attorneys general over its 2023 data breach, including enhanced data protection requirementsINFOSECURITY-MAGAZINE.COM
17 JulErnst & Young discloses data breach after support system hackErnst & Young is notifying customers of a data breach caused by the compromise of a third-party support ticket system used by its IT personnel. [...]BLEEPINGCOMPUTER.COM
17 JulAbbott discloses cyberattack on cancer diagnostics businessThe cyberattack follows Abbott’s recent $21 billion purchase of Exact Sciences. Abbott did not disclose what kind of information was accessed.CYBERSECURITYDIVE.COM
17 JulGoldenEyeDog Subgroup Linked to DigiCert Breach and Code-Signing Certificate TheftCybersecurity researchers have attributed the April 2026 DigiCert security incident to a threat activity cluster dubbed CylindricalCanine. Expel, which shared technical details of the event, described the threat actor as a sub-group of GoldenEyeDog (aka APT-Q-27, Dragon Breath, a…THEHACKERNEWS.COM
17 JulA cyberattack hit Nichirei, one of Japan’s largest food companiesA cyberattack hit one of Japan’s largest food companies, Nichirei, disrupting logistics and shipments. The company is gradually restoring operations. Nichirei is one of Japan’s largest food companies, best known for its frozen food business. Founded in 1942 and headqu…SECURITYAFFAIRS.COM
17 JulAbbott Laboratories probes two cyber incidents amid extortion claimsAbbott Laboratories is investigating two separate cybersecurity incidents after confirming unauthorized access to internal legacy Exact Sciences systems in its Cancer Diagnostics business, while also investigating a separate claim that attackers breached its LabCentral portal and…BLEEPINGCOMPUTER.COM
17 JulAI Becomes The Supply ChainAI tools are increasingly being used to recommend code, libraries, and scripts. The clip explores the possibility that a compromised AI system could influence those recommendations. Software supply chains already depend on trust between developers, tools, and dependencies. Adding…YOUTUBE.COM
16 JulUnpacking the AsyncAPI npm supply chain compromise and import-time payload deliveryThreat actors compromised AsyncAPI packages and weaponized trusted CI/CD workflows to distribute malware through npm. This analysis breaks down the attack chain, payload delivery, and recommended defenses. The post Unpacking the AsyncAPI npm supply chain compromise and import-tim…MICROSOFT.COM
16 JulRansom demands are down, email is the top way attackers get inAn employee opens an email that looks like any other, clicks a link, and gives up a password without noticing. A stolen login opens a door deeper in the network. Files stop opening a few days later. That chain now sits at the front of most ransomware cases. Malicious email and ph…HELPNETSECURITY.COM
16 JulPolice Disrupt a €140M Cyber Fraud Ring in SpainIberian hackers carried out a variety of cyberattacks and laundered the winnings through complex financial networks.DARKREADING.COM
16 JulClaude Code and DeepSeek Powered Chinese Cyber Espionage CampaignChinese actors used Claude Code and DeepSeek to automate attacks that breached government systems and targeted financial firms. Hunt.io researchers stumbled onto an active intrusion campaign in June 2026 while pivoting on known TencShell command-and-control infrastructure. A sing…SECURITYAFFAIRS.COM
16 JulNew Spirals ransomware encrypts victim network in under 24 hoursA new ransomware actor called Spirals completed a corporate intrusion, from initial access to data theft and encryption, in less than 24 hours. [...]BLEEPINGCOMPUTER.COM
16 JulGoSerpent: a persistent threat evolves with sophisticated data collection and exfiltrationTwo-phase attacks with the GoSerpent backdoor, Stowaway RAT, ThumbcacheService and other tools aim to steal data from government entities in Southeast Asia.SECURELIST.COM
16 JulScattered Spider hackers sentenced to 5.5 years over £29 million Transport for London hackTwo leading members of the Scattered Spider cybercrime collective have been sentenced to more than five years in prison for carrying out the 2024 cyberattack against Transport for London (TfL).THERECORD.MEDIA
16 Jul23andMe to pay $18 million in new genetics data breach settlementGenetic testing company 23andMe has agreed to pay $18 million to settle claims from a coalition of 43 attorneys general that it failed to protect customers' genetic data. [...]BLEEPINGCOMPUTER.COM
16 JulTwo Scattered Spider Hackers Sentenced to Jail in UKThalha Jubair and Owen Flowers were prosecuted over a 2024 cyberattack targeting Transport for London (TfL). The post Two Scattered Spider Hackers Sentenced to Jail in UK appeared first on SecurityWeek .SECURITYWEEK.COM
16 JulScattered Spider members jailed over Transport for London hack that cost £29 millionTwo members of the notorious “Scattered Spider” hacking collective have been sentenced to five years and six months in prison each for a cyberattack on Transport for London (TfL) that disrupted services for thousands of commuters and cost the transport authority an es…HELPNETSECURITY.COM
16 JulThreatsDay: Game Cheat Spyware, 24-Hour Ransomware, Chrome Sync Stalking + 12 More StoriesA lot of this week’s trouble starts with something that looks close enough. A familiar repo. A useful installer. A harmless sync setting. Then the handoff goes bad, the box starts talking to someone else, and the damage moves faster than the explanation. Old bugs are back, weak d…THEHACKERNEWS.COM
16 Jul23andMe agrees to a $18 million settlement over 2023 data breachA bipartisan coalition of 43 attorneys general has secured an $18 million settlement with genetic testing company 23andMe over its failure to adequately protect customer data before the company's 2023 breach. The agreement also requires new cybersecurity and governance measures f…CYBERINSIDER.COM
16 JulRussian trio indicted for allegedly running bulletproof hosting providers that spurred cybercrimeOfficials accused three Russian nationals, Media Land and ML.Cloud of supporting cyberattacks spanning 21 U.S. states and other countries, resulting in losses surpassing $62 million. The post Russian trio indicted for allegedly running bulletproof hosting providers that spurred c…CYBERSCOOP.COM
16 JulTwo Scattered Spider Members Sentenced to Prison Over £29 Million TfL CyberattackTwo members of the Scattered Spider cybercrime group received jail sentences in the UK for the 2024 cyberattack on Transport for London. A UK court sentenced two Scattered Spider members, Thalha Jubair (20) and Owen Flowers (18), for their role in the 2024 cyberattack on Transpor…SECURITYAFFAIRS.COM
16 JulCoca-Cola suspended production at its Fairlife dairy after a ransomware attackCoca Cola said dairy production at its Fairlife unit will "remain suspended" in the United States following a hack.TECHCRUNCH.COM
16 JulAnubis ransomware: what you need to knowThe Anubis ransomware-as-a-service (RaaS) operation has hit some healthcare organisations hard - but they are not the only ones at risk. Read more in my article on the Fortra blog.FORTRA.COM
16 JulAI, Automation and Attacks: Unpacking the Unit 42 2026 Global Incident Response ReportExplore Unit 42's perspectives on AI's impact on cybersecurity, including key updates since the 2026 Incident Response Report. The post AI, Automation and Attacks: Unpacking the Unit 42 2026 Global Incident Response Report appeared first on Unit 42 .UNIT42.PALOALTONETWORKS.COM
15 JulWeekly Update 512: IoT Lockout FailPresently sponsored by: Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite "Build a smart home", they said. "It'll make life so much better", they said. Well, life wasn't very bloo…TROYHUNT.COM
15 JulBehind the Book: Threat-Driven Software DevelopmentIn this episode of the Microsoft Threat Intelligence Podcast, host Sherrod DeGrippo is joined by co-authors Michael Howard, Lee Holmes, and Shawn Hernan for a discussion on their new book, Threat-Driven Software Development: Defending Online Services from Modern Threat Acto…THECYBERWIRE.COM
15 JulUS charges alleged operators of Russian bulletproof hosting serviceU.S. federal prosecutors have unsealed charges against three Russian nationals, accusing them of providing bulletproof hosting (BPH) services to ransomware gangs that caused over $62 million in damages to victims worldwide. [...]BLEEPINGCOMPUTER.COM
15 JulFluke - 821,100 breached accountsIn July 2026, electronic test and measurement equipment company Fluke was targeted in a ShinyHunters "pay or leak" extortion campaign . The group subsequently published more than 100GB of data allegedly taken from the company. The corpus contained largely corporate contact inform…HAVEIBEENPWNED.COM
15 JulOkoBot: new sophisticated malware framework targets cryptocurrency usersKaspersky GReAT experts dissect the new OkoBot campaign targeting cryptocurrency users. This complex framework employs TookPS, exfiltrates seed phrases, monitors Chromium-based browsers, and installs various malware strains, including the Rilide stealer.SECURELIST.COM
15 JulGoose Creek data breach exposes 6.6 million customer recordsGoose Creek Candle Company has suffered a data breach exposing the personal information of 6.6 million customers, according to a new entry published by Have I Been Pwned (HIBP). The breach was added to the service earlier today after HIBP received a copy of the dataset from the p…CYBERINSIDER.COM
15 JulUS charges Russian ‘bulletproof’ web hosts over cyberattacks that netted $62M from cybercrime victimsThe 2024 indictment, now unsealed, accuses three Russians and two web hosts of aiding hackers and profiting from cybercrime.TECHCRUNCH.COM
15 Jul23andMe reaches $18 million settlement with states for massive breachA coalition of 42 state attorneys general reached an $18 million settlement with 23andMe for cybersecurity failings that led to a data breach.THERECORD.MEDIA
14 JulYour vendor’s vendor might be the real breach riskIn this Help Net Security video, Chris Boehm, Field CTO, Zero Networks, breaks down how a vendor breach can become your breach. He explains that attackers now target the subcontractors behind your trusted vendors. A compromised credential at a company you have never heard of can …HELPNETSECURITY.COM
14 JulThe ransomware negotiator who was working for the other sideWhen a company falls victim to a ransomware attack, it is not uncommon for it to turn to experts for help. Specialist ransomware negotiation firms handle communications with criminal gangs on a victim's behalf. What victims don't expect is that their trusted negotiator might be s…BITDEFENDER.COM
14 JulU.S. Sanctions First VPN Service and Malware Cryptor Seller Over Ransomware SupportThe U.S. Treasury Department's Office of Foreign Assets Control (OFAC) has designated two individuals and a VPN service provider for enabling ransomware actors' and other cybercriminals' malicious activities, including ransomware attacks against Americans. The VPN, named First VP…THEHACKERNEWS.COM
14 JulCrashStealer: New macOS Infostealer Uses Signed Apps to Evade GatekeeperNew macOS infostealer CrashStealer uses a signed app to bypass Gatekeeper, steals credentials and wallets, then AES-encrypts stolen data. Jamf Threat Labs first spotted CrashStealer in early May 2026 as a suspicious macOS sample uploaded to VirusTotal. By early July, in-the-wild …SECURITYAFFAIRS.COM
14 JulPhishing for dummies: Forg365 lowers barrier to M365 account takeoversA newly documented phishing-as-a-service platform distributed through Telegram is lowering the technical barrier to Microsoft 365 account takeovers by giving less-skilled attackers automated tools to evade some authentication controls and retain access after compromise. The platf…CSOONLINE.COM
14 JulLidl Notifies Customers of Third-Party Data BreachSupermarket giant Lidl has revealed details of a supplier breach impacting customer dataINFOSECURITY-MAGAZINE.COM
14 JulUS sanctions VPN, malware providers for enabling ransomware attacksThe U.S. Treasury Department's Office of Foreign Assets Control (OFAC) sanctioned two individuals and one entity for enabling ransomware attacks against U.S. organizations. [...]BLEEPINGCOMPUTER.COM
14 JulUS, Allies Warn of Russian Cyberattacks Targeting Critical Infrastructure RoutersMultiple state-sponsored APTs are compromising poorly secured devices across critical infrastructure sector networks. The post US, Allies Warn of Russian Cyberattacks Targeting Critical Infrastructure Routers appeared first on SecurityWeek .SECURITYWEEK.COM
14 JulAttacker Used AI to Build Custom PowerShell Recon MalwareHuntress found an AI-generated PowerShell script used for AD reconnaissance, showing attackers are using AI to create custom, evasive tools. During an incident response investigation on June 3, 2026, Huntress analyst Jevon Ang recovered a PowerShell script from a compromised Wind…SECURITYAFFAIRS.COM
14 JulPentagon suspends CMMC Phase II requirements.US Treasury Department sanctions VPN provider that allegedly assisted criminals. Lidl discloses breach affecting customer information.THECYBERWIRE.COM
14 JulHealthcare sector faces persistent supply-chain security, identity management challengesA new report says doctors and nurses should train for cyberattacks the way firefighters train for major blazes — even if they expect them to be rare.CYBERSECURITYDIVE.COM
14 JulCanada’s Electronic Spy Agency Conducted Cyberattacks on Criminals Brokering Fentanyl Ingredients, Report SaysResearch fellow Bill Robinson speaks with The Globe and Mail about CSE spending. The post Canada’s Electronic Spy Agency Conducted Cyberattacks on Criminals Brokering Fentanyl Ingredients, Report Says appeared first on The Citizen Lab .CITIZENLAB.CA
14 JulCyberattack at KFC Japan impacting online orders and deliveriesKFC Japan has announced that a cyberattack affecting one of its third-party logistics providers is disrupting food deliveries to restaurants nationwide, raising the possibility of product shortages, reduced operating hours, and temporary store closures. The company has suspended …CYBERINSIDER.COM
14 JulFinland issues wanted notice for hacker behind massive psychotherapy data breachThe defendant's lawyer told Finnish media that he does not know where his client is but believes Kivimäki is outside Finland.THERECORD.MEDIA
14 JulSynopsys Finds No Evidence of Data Breach Amid Bosch Hack ClaimsThe D1R cybercrime group claimed to have stolen valuable data from Synopsys and Bosch, threatening to leak it unless a ransom is paid. The post Synopsys Finds No Evidence of Data Breach Amid Bosch Hack Claims appeared first on SecurityWeek .SECURITYWEEK.COM
14 JulU.S. Treasury Sanctions VPN Provider and Cryptor Seller Behind Billions in Ransomware LossesU.S. sanctions hit VPN provider 1VPNS and a cryptor seller for enabling ransomware gangs behind billions in losses to critical infrastructure. The U.S. Treasury’s Office of Foreign Assets Control sanctioned two individuals and one entity on July 13 for supplying tools and i…SECURITYAFFAIRS.COM
14 JulWhen the Negotiator Helps HackersA ransomware negotiator was sentenced to federal prison after prosecutors said he secretly worked with the BlackCat ransomware group while negotiating on behalf of victims. According to court filings, he shared insurance limits, negotiating positions, and internal settlement thre…YOUTUBE.COM
13 JulCenters Laboratory Data Breach Affects 540,000 IndividualsThe WorldLeaks extortion group claimed to have stolen 720 GB of data from the healthcare testing and laboratory services provider. The post Centers Laboratory Data Breach Affects 540,000 Individuals appeared first on SecurityWeek .SECURITYWEEK.COM
13 JulHacker Extradited from Ukraine Pleads Guilty to Ryuk Ransomware ChargesAn Armenian man has pleaded guilty to his role in the infamous Ryuk ransomware operationINFOSECURITY-MAGAZINE.COM
13 JulFastNetMon eliminates third-party bgp lookups with NetomicsFastNetMon is introducing Netomics, a self-hosted BGP routing intelligence platform that combines live routing data, registry information, RPKI validation, routing history and AI-assisted querying into a single application. Built for internet service providers (ISPs), cloud provi…HELPNETSECURITY.COM
13 JulDutch Nationals Suspected in Odido Hack That Exposed Six Million CustomersDutch police suspect local hackers behind the Odido breach that exposed 6M customers after a phishing attack and seek public help identifying them. Dutch police have identified strong indications that Dutch nationals were involved in the February 2026 cyberattack on telecom provi…SECURITYAFFAIRS.COM
13 JulEU sanctions Russian GRU military hackers over cyberattacksThe European Union and the United Kingdom jointly sanctioned dozens of Russian individuals and entities and accused Russia of coordinating a network of hacking groups responsible for attacks across Europe. [...]BLEEPINGCOMPUTER.COM
13 JulBreach at the Beach: Play the Ultimate Entra ID CTFLearn how attackers abuse Entra ID through a free hands-on Capture the Flag. Varonis created the Breach at the Beach CTF to teach defenders how to investigate Entra ID attack techniques using realistic scenarios. [...]BLEEPINGCOMPUTER.COM
13 JulLidl discloses online shop breach after service provider hackGerman discount supermarket chain Lidl notified customers in Germany, Belgium, and the Netherlands that attackers stole their personal information in a breach at a service provider. [...]BLEEPINGCOMPUTER.COM
13 Jul⚡ Weekly Recap: ShareFile Threat, Citrix Bleed 2 Ransomware, AI Coding Attacks, and MoreSomewhere right now, a security tool is quietly finding bugs faster than any human can fix them. That's supposed to be the good news. The catch is that the attackers have the same tools, pointed the other way, and they don't file tickets. That's the shape of this week. Trusted co…THEHACKERNEWS.COM
13 JulEurope strikes out against Russia’s Turla over espionage, ‘destructive attacks’The EU, its members and the U.K. took action against Russian government officials and others while attributing the winter cyberattacks against Poland’s energy grid to the FSB. The post Europe strikes out against Russia’s Turla over espionage, ‘destructive attacks’ appeared first …CYBERSCOOP.COM
13 JulHackers breach Lidl’s IT service provider, steal customer dataGerman discount supermarket chain Lidl has notified customers in Germany, Belgium, and the Netherlands that customer data was stolen after attackers breached one of its IT service providers. In notices published on its support websites in Belgium and the Netherlands, Lidl said it…HELPNETSECURITY.COM
13 JulCrashStealer macOS Malware Uses Notarized Dropper to Pass Gatekeeper ChecksCybersecurity researchers have flagged a new macOS information stealer called CrashStealer that's capable of harvesting sensitive data from compromised systems. Unlike other information stealers that are built on AppleScript droppers or Objective-C-based wrappers, CrashStealer is…THEHACKERNEWS.COM
13 JulRussian celebrity journalist Ksenia Sobchak says hackers accessed Telegram channels via email breachFollowing the breach of several of her Telegram channels, controversial Russian journalist Ksenia Sobchak claimed published screenshots of her correspondence with political figures were fake.THERECORD.MEDIA
13 JulState of the router.The U.S. and its allies warn of Russian cyber threats targeting critical infrastructure as Europe rolls out new sanctions. Apple sues OpenAI over alleged trade secret theft. Progress investigates a potential ShareFile security incident, Zimbra patches a critical flaw, and researc…THECYBERWIRE.COM
13 JulJapan's largest taxi operator shuts systems after cyberattackJapan's largest taxi operator, Nihon Kotsu, announced that its systems were compromised in a cyberattack, forcing the company to shut down part of its infrastructure. [...]BLEEPINGCOMPUTER.COM
13 JulWeak Security Continues to Fuel Russian CyberattacksIn a first, the UK and the EU jointly impose sanctions on Russian individuals and entities for cyberattacks and disinformation campaigns in the region.DARKREADING.COM
12 JulRyuk Ransomware Member Pleads Guilty Over Attacks on U.S. OrganizationsAn alleged Ryuk ransomware member pleaded guilty in the U.S. for helping deploy attacks on American companies and faces up to 15 years in prison. Armenian national Karen Serobovich Vardanyan (34) pleaded guilty in the U.S. for his role in Ryuk ransomware attacks targeting America…SECURITYAFFAIRS.COM
11 JulConti-versal opinions.Today we are joined by Geoff White, host of Cyber Hack and BBC journalist, taking a deep dive into the Conti ransomware gang. Geoff explores an in-depth investigation into the notorious Conti ransomware gang, drawing from thousands of leaked internal messages to reveal how th…THECYBERWIRE.COM
11 JulGlendale Community College - 793,925 breached accountsIn June 2026, Glendale Community College was the target of a ShinyHunters "pay or leak" extortion campaign . Data allegedly obtained from Glendale was later published online and included almost 800k unique email addresses along with various other data fields, including names, add…HAVEIBEENPWNED.COM
11 JulCompromised jscrambler 8.14.0 npm Release Drops Rust Infostealer During InstallVersion 8.14.0 of the jscrambler npm package shipped with a malicious preinstall hook that silently drops and runs a native infostealer during installation, one build each for Windows, macOS, and Linux. Published on July 11, 2026, it needs no import and no CLI…THEHACKERNEWS.COM
10 JulDormant GitHub Accounts Help Attackers Blend In While Mapping Corporate OrgsDatadog Security Labs is warning of "several overlapping campaigns" that are systematically enumerating corporate GitHub organizations, repositories, and user accounts through the GitHub API. "Operators rely on automated scraping tooling with custom or legitimate-sounding us…THEHACKERNEWS.COM
10 JulRisky Bulletin: NSA Tailored Access Operations is backThe NSA’s Tailored Access Operations team is back, India bans an app used to hack e-rickshaws, Accenture has another data breach, and a leak exposes a suspected Chinese cyber contractor. The Risky Bulletin newsletter and podcast will be on an editorial break until July 20.RISKY.BIZ
10 JulNHS Warns Staff Over Unauthorized Access to Patient DataNHS tells staff they could face prison for “inappropriate” access to patients’ medical recordsINFOSECURITY-MAGAZINE.COM
10 JulFormer ransomware negotiator gets 4 years for BlackCat attacksA former employee of cybersecurity incident response company DigitalMint was sentenced to 70 months in prison for targeting U.S. companies in BlackCat (ALPHV) ransomware attacks. [...]BLEEPINGCOMPUTER.COM
10 JulRansomware Negotiator Gets 70 Months in Prison for Aiding BlackCat AttacksA 41-year-old former ransomware negotiator has been sentenced to nearly six years (i.e., 70 months) in prison in the U.S. for their role in conspiring with the now-defunct BlackCat ransomware operators to extort multiple victims and working with two other cybersecurity profession…THEHACKERNEWS.COM
10 JulGigaWiper Combines Multiple Malware for System-Level SabotageThe backdoor’s destructive capabilities include a standalone wiper, ransomware encryption, and a multi-pass wiping command. The post GigaWiper Combines Multiple Malware for System-Level Sabotage appeared first on SecurityWeek .SECURITYWEEK.COM
10 JulGigaWiper Merges Three Malware Families Into One Destructive BackdoorMicrosoft uncovered GigaWiper, a modular Go backdoor combining three malware families with espionage, remote control, and destructive wiping features. In October 2025, Microsoft’s threat intelligence team identified destructive wiping activity inside compromised environment…SECURITYAFFAIRS.COM
10 JulFormer Ransomware Negotiator Sentenced to 70 Months in Prison for Secretly Helping BlackCat GangA former ransomware negotiator was sentenced to nearly six years for secretly helping BlackCat extort victims while betraying his clients. A U.S. court sentenced former ransomware negotiator Angelo Martino, 41, to 70 months in prison for conspiring with the BlackCat ransomware ga…SECURITYAFFAIRS.COM
10 JulThird US Security Expert Sentenced to Prison for Helping Ransomware GangAngelo Martino, a former ransomware negotiator, was sentenced to 70 months for helping the BlackCat/Alphv group. The post Third US Security Expert Sentenced to Prison for Helping Ransomware Gang appeared first on SecurityWeek .SECURITYWEEK.COM
10 JulRansomware Never Stopped: Over 9,000 Confirmed Attacks Since 2018Ransomware remains above 1,400 attacks yearly since 2023. Qilin leads in 2026, while the U.S. remains the main target. Ransomnews has independently confirmed 9,291 ransomware attacks worldwide between January 2018 and July 2026, tracking incidents only when verified through victi…SECURITYAFFAIRS.COM
10 JulFlorida ransomware negotiator convicted for helping ransomware gang extort US companiesA third ransomware negotiator has been jailed for helping a notorious ransomware group extort American victim companies into paying the hackers.TECHCRUNCH.COM
10 JulIn Other News: DHS Database Hacked, Adobe Boosts Patch Cadence, Canada Disrupts Ransomware OpsOther noteworthy stories that might have slipped under the radar: Abnormal AI sued by Anthropic, AssuranceAmerica data breach affects 7 million people, NSA brings back TAO. The post In Other News: DHS Database Hacked, Adobe Boosts Patch Cadence, Canada Disrupts Ransomware Ops app…SECURITYWEEK.COM
10 JulPolice suspects Dutch hackers were involved in Odido breachThe Dutch National Police (Politie) says it has found "strong indications" that Dutch hackers have been involved in a February breach at the telecommunications provider Odido. [...]BLEEPINGCOMPUTER.COM
10 JulCybercriminals Flock to Healthcare Businesses as Attacks SurgeWhile cyberattacks against hospitals and clinics grew modestly in the first half of 2026, attacks on service providers and other healthcare businesses more than doubled.DARKREADING.COM
10 JulInjective Labs GitHub Compromise Pushes Wallet-Key-Stealing npm PackagesUnknown threat actors compromised the Injective Labs SDK project's GitHub repository and leveraged it to publish a malicious package on the npm registry to steal cryptocurrency wallet private keys and mnemonic seed phrases. The compromised version, @injectivelabs/sdk-ts@1.20.21, …THEHACKERNEWS.COM
10 JulRyuk operator pleads guilty; Blackcat/AlphV conspirator gets nearly 6-year sentenceOne man accused of deploying Ryuk ransomware pleaded guilty Wednesday in an Oregon federal court to conspiracy and computer fraud, while another man received a 70-month federal prison sentence in a Florida court for helping the Blackcat/AlphV gang extort multiple victims.THERECORD.MEDIA
10 JulRyuk ransomware member pleads guilty in the US, faces 15 years in prisonA 34-year-old Armenian man has pleaded guilty to hacking U.S. companies and deploying the infamous Ryuk ransomware to encrypt their systems. [...]BLEEPINGCOMPUTER.COM
10 JulArmenian national pleads guilty to Ryuk ransomware attacksKaren Vardanyan faces up to 15 years in federal prison and agreed to pay nearly $1.2 million in restitution. The post Armenian national pleads guilty to Ryuk ransomware attacks appeared first on CyberScoop .CYBERSCOOP.COM
10 JulNo Manners Here: The Ruthless Rise of The Gentlemen RansomwareUnit 42 explores The Gentlemen ransomware operations, revealing the affiliate model driving its rapid growth. Learn more here. The post No Manners Here: The Ruthless Rise of The Gentlemen Ransomware appeared first on Unit 42 .UNIT42.PALOALTONETWORKS.COM
9 Jul'GodDamn' Ransomware Uses BYOVD to Smite US CompaniesMicrosoft co-signed a malicious kernel driver, and now it's being used to kill security software in ransomware attacks.DARKREADING.COM
9 JulThe Language of AI Could Change How Humans SpeakLast week, national security agencies from the Five Eyes—that’s the rich, English-language-speaking countries club—jointly released a statement warning of the increasing cyber risks of AI models: in particular, their ability to autonomously hack into systems and…SCHNEIER.COM
9 JulMount Royal University Confirms Data Stolen in Ransomware AttackHackers accessed the institution’s internal network and deleted two drives containing employee, student, and university data. The post Mount Royal University Confirms Data Stolen in Ransomware Attack appeared first on SecurityWeek .SECURITYWEEK.COM
9 JulGodDamn Ransomware Uses PoisonX Driver to Disable Endpoint DefensesCybersecurity researchers have flagged a new ransomware family called GodDamn that employs the PoisonX kernel driver to neutralize security software as part of its defense evasion strategy. According to a new report published by the Threat Hunter Team from Symantec, the ransomwar…THEHACKERNEWS.COM
9 JulAI Gateways Offer Attackers the Keys to the KingdomA cryptomining incident highlights how AI gateways can provide access to AI models, cloud infrastructure, and identity and access management (IAM) data.DARKREADING.COM
9 JulAssuranceAmerica Breach Exposes 7 Million Driver’s Licenses After Employee Account HackAssuranceAmerica confirmed a breach exposing nearly 7 million driver’s licenses after hackers compromised an employee account and stole customer data. U.S. auto insurer AssuranceAmerica has confirmed a data breach affecting nearly 7 million people, making it the largest kno…SECURITYAFFAIRS.COM
9 JulLatvian forestry company still restoring systems weeks after ransomware attackA foreign, financially motivated group was responsible for a cyberattack on state-owned forestry company Latvijas Valsts Mezi (LVM), officials said.THERECORD.MEDIA
9 JulData breach hits car insurance providerHackers gained access to more than 6.9 million records at AssuranceAmerica by targeting a company employee.CYBERSECURITYDIVE.COM
9 JulRansomware ecosystem grows, but ‘four-headed monster’ dominatesAI is helping hackers, a new report finds, but mostly by automating very human behaviors.CYBERSECURITYDIVE.COM
9 JulGigaWiper: Anatomy of a destructive backdoor assembled from multiple malwareGigaWiper is a destructive backdoor that combines multiple wiping and ransomware-like capabilities into a single operational platform. This blog analyzes how the malware incorporates code from several previously separate malware families and provides guidance to help defenders de…MICROSOFT.COM
9 JulNew GigaWiper Windows Backdoor Bundles Disk Wiping, Fake Ransomware, and SpywareMicrosoft has taken apart a destructive Windows backdoor it calls GigaWiper. What stands out is how it is built: not one tool but three older destructive programs bolted into one, offered as commands the operator can choose from. Each is a different way to break a machine: wipe t…THEHACKERNEWS.COM
9 JulGodDamn Ransomware Uses PoisonX to Blind Security SoftwareGodDamn ransomware uses the signed PoisonX driver to disable security tools, marking a more advanced version of the Beast ransomware family. Symantec’s Threat Hunter Team found a new ransomware family called GodDamn that first appeared in the wild on May 21, 2026, and analy…SECURITYAFFAIRS.COM
9 JulInjective SDK on npm infected with cryptocurrency wallet stealerHackers compromised the Injective Labs SDK project's GitHub repository and used it to publish a malicious package on the Node Package Manager (npm) that stole cryptocurrency wallet private keys and mnemonic seed phrases. [...]BLEEPINGCOMPUTER.COM
8 JulOrbia CISO Miranda Ritchie on building security into sustainable infrastructureIn this interview with Help Net Security, industrial cybersecurity, CISO at Orbia, talks about protecting industrial systems where software runs water, chemical and manufacturing processes. She explains why a cyber incident in these settings can harm people, equipment and the env…HELPNETSECURITY.COM
8 JulOnlyFans Models Are Accidentally Making Hacked Government Websites DisappearScammers are hijacking government websites to upload ads for “leaked” OnlyFans content. Thousands of copyright complaints from adult creators are helping people avoid malicious links.WIRED.COM
8 JulCybersecurity and the Gap Between Skill and AbilityLast week, national security agencies from the Five Eyes—that’s the rich, English-language-speaking countries club—jointly released a statement warning of the increasing cyber risks of AI models: in particular, their ability to autonomously hack into systems and…SCHNEIER.COM
8 JulTelco giant KDDI says data breach affects over 12 million peopleJapanese telecommunications giant KDDI says that millions of people had their email addresses and passwords exposed after attackers breached an email platform used by five internet service providers (ISPs) in the country. [...]BLEEPINGCOMPUTER.COM
8 JulWeekly Update 511: Live from my Riad in MarrakechPresently sponsored by: Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite How's this for a location?! I mean, last week was nice with Scott in Mallorca, but Marrakech is, well, wow 😮 Anyway, about…TROYHUNT.COM
8 JulAccenture confirms a data breach.Australian telecom outage attributed to software bug. Business news: Keyfactor secures more than $1 billion in a growth funding round.THECYBERWIRE.COM
8 JulAnother massive data breach exposed millions of driver’s license numbersThe cyberattack targeting a U.S. insurance giant is the largest known breach of driver's license numbers so far in 2026.TECHCRUNCH.COM
8 JulMount Royal University confirms breach as hackers claim attackMount Royal University in Calgary says hackers stole and then deleted data from its file storage systems after breaching the university's network. [...]BLEEPINGCOMPUTER.COM
8 JulSmashing Security podcast #475: JadePuffer – the AI that ran a ransomware attack all by itselfA 15-year-old boy asked a chatbot for help - and cancelled nearly 47,000 anime streaming subscriptions in under four hours. Meanwhile, researchers have documented the first fully autonomous, agentic AI-driven ransomware attack, "JadePuffer". What does this tell us about the futur…GRAHAMCLULEY.COM
7 JulNothing left to StealC.Welcome in! You’ve entered, Only Malware in the Building. Join us each month to sip tea and solve mysteries about today’s most interesting threats. Your host is Selena Larson, Proofpoint intelligence analyst and host of their podcas…THECYBERWIRE.COM
7 JulIran-Linked Hackers Using Modular C&C Framework in CyberattacksResearchers say the Iran-linked threat actor used an adaptable modular malware framework and compromised IT service providers to reach high-value targets in Israel. The post Iran-Linked Hackers Using Modular C&C Framework in Cyberattacks appeared first on SecurityWeek .SECURITYWEEK.COM
7 JulHacktivists call out Trump by hacking and defacing US Army websitesThe U.S. Army has fixed two of its websites that were hacked to display messages calling President Trump a "pedophile" and a "thief."TECHCRUNCH.COM
7 JulMajor Japanese telco says cyberattack exposed 12 million emailsThe company said the breach affected an email system used to manage customer email accounts, webmail services and email storage for five Japanese internet service providers.THERECORD.MEDIA
7 JulCounty Government Reportedly Paid $1 Million to Cyber Extortion GroupThe alleged victim, believed to be a small Ohio county, reportedly paid the extortion group to prevent the public release of sensitive stolen data. The post County Government Reportedly Paid $1 Million to Cyber Extortion Group appeared first on SecurityWeek .SECURITYWEEK.COM
6 JulHow to prioritize AI agent security by business impactYour CEO calls about an AI agent security incident in finance. He wants to know whether money moved, whether financial data was exposed, who owned the agent and why it had this level of access. The agent was connected to a spend management application to reconcile invoices, summa…HELPNETSECURITY.COM
6 JulResearchers Claim First Fully Agentic Ransomware: JadePufferResearchers have revealed JadePuffer, the first agentic AI-powered ransomware campaign, highlighting how autonomous agents can automate cyber-attacksINFOSECURITY-MAGAZINE.COM
6 JulICE’s Internal Watchdog Is Now Investigating Online CriticsThe Office of Professional Responsibility has opened more than 100 cases over what ICE officials call “incidents of doxing and threats” against ICE employees.WIRED.COM
6 JulSuspected China-Nexus Hackers Use Fake Indian Tax Filing Utility to Deploy DcRATA suspected China-nexus threat activity cluster has been observed targeting Indian taxpayers, tax professionals, and corporate finance teams to deliver a remote access trojan designed to steal sensitive data from compromised hosts. The multi-stage campaign, codenamed Operation Dr…THEHACKERNEWS.COM
6 Jul6th July – Threat Intelligence ReportFor the latest discoveries in cyber research for the week of 6th July, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES River Bank & Trust, a US financial institution, has experienced a ransomware incident after an unauthorized actor accessed the net…RESEARCH.CHECKPOINT.COM
6 JulFBI disrupts residential proxy network used by botnet.New macOS infostealer poses as a clipboard manager. AdaptHealth discloses data breach affecting patient information.THECYBERWIRE.COM
6 JulSysdig clocks first documented case of agentic ransomwareThe AI agent didn’t accomplish every step in the late June 2026 attack, but it allowed the threat actor to significantly reduce complexity, speed up the tempo and gain operational advantages. The post Sysdig clocks first documented case of agentic ransomware appeared first on Cyb…CYBERSCOOP.COM
6 JulMajor medical device manufacturer notifies nearly 4 million of breachInformation like Social Security numbers and health-related data was accessed, but the company said it had “no evidence that impacted information has been publicly posted or exposed on the internet.”THERECORD.MEDIA
6 JulBlogspot-Hosted Payloads Delivered in ‘Veil#Drop’ AttacksSecuronix says the sophisticated framework abuses compromised websites, Blogspot, PowerShell, and fileless techniques to evade detection and deploy the PureLog information stealer. The post Blogspot-Hosted Payloads Delivered in ‘Veil#Drop’ Attacks appeared first on Se…SECURITYWEEK.COM
6 JulCanadian spy agency reports hacking three criminal groups in 2025A ransomware-as-a-service gang, an online foreign extremist group and drug traffickers were separately the targets of offensive operations in 2025, according to Canada's Communications Security Establishment.THERECORD.MEDIA
6 JulThe ‘first’ AI-run ransomware attack still needed a humanAn AI agent carried out the technical execution of a real-world ransomware attack for the first known time, but new details show a human still chose the victim, set up the infrastructure, and supplied stolen credentials — meaning it wasn't quite the fully autonomous cybercrime de…TECHCRUNCH.COM
5 JulSecurity Affairs newsletter Round 584 by Pierluigi Paganini – INTERNATIONAL EDITIONA new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including the international press. U.S. Government Agency Paid $…SECURITYAFFAIRS.COM
5 JulMedtronic Notifies 3.8 Million After ShinyHunters Data BreachMedtronic says a ShinyHunters attack exposed the personal and medical data of over 3.8 million people. Products and operations were unaffected. Medtronic is notifying 3,834,294 individuals after a cyberattack by the ShinyHunters extortion group exposed personal and medical inform…SECURITYAFFAIRS.COM
4 JulNew Avalon Malware Framework Packs CrownX Ransomware CapabilitiesCybersecurity researchers have discovered a previously undocumented modular malware framework codenamed Avalon that's distributed by means of a multi-stage phishing chain capable of bypassing traditional security controls. Avalon combines credential collection, lateral movement, …THEHACKERNEWS.COM
4 JulU.S. Government Entity Paid Kairos $1 Million in Data-Theft Extortion CaseA U.S. government entity paid about $1 million to keep stolen files from being leaked, according to a new case study by Rakesh Krishnan for Ransom-ISAC, built on a leaked negotiation chat and the blockchain trail the payment left. The odd part: the group that took the money …THEHACKERNEWS.COM
4 JulJadePuffer ransomware used AI agent to automate entire attackResearchers identified what they believe is the first documented case of a ransomware operation, JadePuffer, conducted entirely by a large language model (LLM) agent. [...]BLEEPINGCOMPUTER.COM
4 JulU.S. Government Agency Paid $1M to Data Extortion Group KairosA U.S. government agency paid $1M to Kairos, a group focused on data theft and extortion rather than ransomware, Ransom-ISAC reports. A new case study from Ransom-ISAC reconstructs a complete data-extortion incident involving a U.S. government body and a threat actor called Kairo…SECURITYAFFAIRS.COM
3 JulCyberWire Daily at 10: The vulnerabilities, zero‑days, and hardware flaws over the last decade.In this special edition of CyberWire Daily’s 10th anniversary series, N2K CyberWire's Maria Varmazis and Dave Bittner discuss 10 years of vulnerabilities, zero‑days, and hardware flaws. Together they reflect on the last decade of cybersecurity vulnerabilities, exploring key s…THECYBERWIRE.COM
3 JulRisky Bulletin: FatFs bugs enable physical access attacks on a load of devicesFatFs bugs enable physical access attacks on industrial equipment, a clever password spraying attack bypasses M365 MFA, an AI agent is deploying ransomware in live attacks, and a webinar platform sues two security firms over bad IOCs.RISKY.BIZ
3 JulPolitician who investigated spyware abuses had his phone hacked with Pegasus spywareA government customer of NSO Group used the company's Pegasus spyware to hack into the phone of a European politician, who at the time was serving on an EU committee tasked with investigating the spyware industry.TECHCRUNCH.COM
3 JulSwimming Pools, Pee, and Trying to Delete Your Data From the InternetPresently sponsored by: Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite I can't recall if someone else originally came up with this saying or if I said it in some off-the-cuff comment and it just propag…TROYHUNT.COM
3 JulMedtronic Data Breach Impacts 3.8 Million PeopleMedical technology giant Medtronic is notifying more than 3.8 million individuals that their personal and medical information was compromised in a recent data breach. The incident occurred in April 2026, when the infamous extortion group ShinyHunters accessed the company’s corpor…SECURITYWEEK.COM
3 JulGoogle, FBI Disrupt NetNut Residential Proxy Network Powered by Millions of DevicesNetNut rented access to millions of compromised devices, allowing cybercriminals and nation-state actors to mask their identities during attacks. The post Google, FBI Disrupt NetNut Residential Proxy Network Powered by Millions of Devices appeared first on SecurityWeek .SECURITYWEEK.COM
3 JulEuropean Parliament Member Investigating Spyware Was Hacked With PegasusA new report from the Citizen Lab has revealed that former Member of the European Parliament Stelios Kouloglou had his mobile device repeatedly hacked with the notorious Pegasus spyware while serving on a committee that was tasked with investigating the abuse of such commercial s…THEHACKERNEWS.COM
3 JulWarning Over “Industrialized” Cyber-Attacks After Ransomware Gang Partners With TeamPCPResearchers warn that collaboration could lead to “unprecedented” ransomware attacks, as FBI also issues warningINFOSECURITY-MAGAZINE.COM
3 JulQilin Dominates Ransomware Market Amid Growing Cybercrime ConsolidationThe ransomware landscape is reconsolidating around major players, with Qilin emerging as the leading RaaS operation, researchers sayINFOSECURITY-MAGAZINE.COM
3 JulArmored Likho Targets Government Agencies, Power Sector with BusySnake StealerA previously undocumented threat actor known as Armored Likho has been attributed to cyber attacks targeting government agencies and the electric power sector across Russia, Brazil, and Kazakhstan. "Armored Likho blends financially motivated campaigns targeting private individual…THEHACKERNEWS.COM
3 JulNew macOS malware PamStealer uses PAM to validate stolen dataA previously undocumented macOS infostealer dubbed PamStealer validates victims' macOS passwords through the OS’s Pluggable Authentication Modules (PAM) before stealing them. Jamf Threat Labs researchers, who analyzed a two-stage attack chain combining AppleScript, JavaScript for…CYBERINSIDER.COM
3 JulNetNut proxy network disrupted, 2 million infected devices cut offA joint operation involving Google has disrupted NetNut, a residential proxy network that gave access to millions of compromised Android devices, including smart TVs and streaming boxes. [...]BLEEPINGCOMPUTER.COM
3 JulMoody Bible Institute - 2,303,416 breached accountsIn June 2026, Moody Bible Institute was targeted by a ShinyHunters "pay or leak" extortion campaign . Over 2.3M unique email addresses and other personal data were later published publicly, including names, physical addresses, phone numbers, dates of birth and other information r…HAVEIBEENPWNED.COM
3 JulPegasus Used Against MEP Investigating Pegasus, Citizen Lab FindsA former EU lawmaker was hacked with Pegasus spyware while investigating its use, according to Citizen Lab. The Citizen Lab published a report documenting one of the more darkly ironic findings in recent surveillance research: former Member of the European Parliament Stelios Koul…SECURITYAFFAIRS.COM
2 JulMedtronic notifies customers impacted by ShinyHunters data breachHealthcare device firm Medtronic is notifying affected customers about a data breach that exposed their personal data to an unauthorized third party. [...]BLEEPINGCOMPUTER.COM
2 JulCatching ransomware on the wire before it locks the file serverCorporate networks keep sensitive files off individual workstations and store them on shared servers that staff reach through mapped network drives. That arrangement hands ransomware operators a target worth chasing. A single compromised laptop can begin encrypting files that liv…HELPNETSECURITY.COM
2 JulThe endpoint recovery gap many teams discover during an incidentIn this interview with Help Net Security, IGEL CTO Matthias Haas explains why backups alone do not equal recovery. He makes the case that endpoint recovery is often overlooked, leaving organizations exposed when thousands of devices go down at once. Haas walks through what a well…HELPNETSECURITY.COM
2 JulOpera blocks ClickFix attacks with new clipboard protection featureOpera has launched Paste Protect, a clipboard protection feature designed to prevent clipboard-based attacks such as hijacking and pastejacking. Paste Protect includes built-in protection and warnings against ClickFix-based cyberattacks, which accounted for more than half of malw…HELPNETSECURITY.COM
2 JulAlleged Scattered Spider Hacker Extradited to U.S. to Face Cybercrime ChargesAlleged Scattered Spider member Peter Stokes, 19, was extradited from Finland to the U.S. over hacking, fraud, and extortion charges. Peter Stokes, 19, an alleged Scattered Spider member known online as “Bouquet,” has been extradited from Finland to the U.S. to face h…SECURITYAFFAIRS.COM
2 JulMissed incidents, persistent threats, and response gaps: Insights from compromise assessment projectsKaspersky Compromise Assessment specialists analyze trends from the service's 2025 projects and provide tips on how to enhance your organization's security.SECURELIST.COM
2 JulFortiBleed Credential Theft Linked to INC and Lynx Ransomware OperationsThe recently discovered financially-motivated FortiBleed campaign has been attributed to INC and Lynx ransomware operations, indicating that the verified, stolen credentials were intended for follow-on intrusions. "An operator tied to FortiBleed's infrastructure was found activel…THEHACKERNEWS.COM
2 Jul‘BioShocking’ Attack Tricks AI Browsers Into Stealing CredentialsResearchers show how context manipulation can cause agentic browsers to abandon safety guardrails and exfiltrate sensitive credentials. The post ‘BioShocking’ Attack Tricks AI Browsers Into Stealing Credentials appeared first on SecurityWeek .SECURITYWEEK.COM
2 Jul430,000 FortiGate Devices Exposed in FortiBleed Ransomware LinkFortiBleed exposed 430,000 FortiGate firewalls, linked to INC Ransom and Lynx, enabling domain compromise and at least 12 ransomware attacks. SOCRadar’s Threat Research Unit has connected FortiBleed, a large-scale campaign that harvested credentials from over 430,000 FortiG…SECURITYAFFAIRS.COM
2 JulCybercriminals Pose as Interpol in Phishing Emails to Infect Victims With RansomwareBitdefender researchers warned of curious ransomware campaign which has targeted businesses around the worldINFOSECURITY-MAGAZINE.COM
2 JulFortiBleed Campaign Linked to INC, Lynx Ransomware AttacksResearchers say credentials harvested from hundreds of thousands of FortiGate firewalls are being used to facilitate ransomware attacks by the INC and Lynx operations. The post FortiBleed Campaign Linked to INC, Lynx Ransomware Attacks appeared first on SecurityWeek .SECURITYWEEK.COM
2 JulScattered Spider suspect extradited over $8 million ransom schemeA suspected Scattered Spider member has been extradited to the United States to face charges linked to cyberattacks against U.S. companies, including the breach of a luxury jewelry retailer that led to an $8 million cryptocurrency ransom demand after attackers stole company data.…HELPNETSECURITY.COM
2 JulUS government says it got hacked — againA top Democrat on the Senate's Intelligence Committee warned that the information accessed on a Homeland Security intelligence-sharing network may risk national security.TECHCRUNCH.COM
2 JulMost cybersecurity workers have been told to conceal a breach, report findsThe security firm Bitdefender’s annual survey also found that U.S. companies were simultaneously more confident and more strained on cyber defense than foreign peers.CYBERSECURITYDIVE.COM
2 JulThreatsDay: AI Compute Hijacking, Apple Email Flaw, BlueHammer Ransomware + 14 StoriesThis week’s security news is mostly about weak spots. Browsers, bots, sandboxes, AI systems, and email flows all show the same problem in different ways. Everything looks normal until someone tests a small gap and finds a way through. This is not one big break. It is small permis…THEHACKERNEWS.COM
2 JulThe Gentlemen ransomware: what you need to knowWho Are The Gentlemen? Despite the impeccably polite name, there is nothing polite or refined about this particular gang of cybercriminals. Read more in my article on the Fortra blog.FORTRA.COM
2 JulRansomware Thugs Masquerade as Interpol to Entice Small BizThe ransomware campaign relies on basic social engineering and stretches across multiple regions, including the US, Europe, Middle East, and elsewhere.DARKREADING.COM
2 JulFBI Seizes NetNut Proxy Platform, Popa BotnetThe Federal Bureau of Investigation (FBI) said today it worked with industry partners to seize hundreds of domains associated with NetNut, a sprawling residential proxy service operated by the publicly-traded Israeli company Alarum Technologies [NASDAQ: ALAR]. The action comes ro…KREBSONSECURITY.COM
1 JulChina-Linked Group Targets Southeast Asia Critical SystemsThe group compromised at least 10 regional organizations, including two state-owned entities, and deployed a new backdoor.DARKREADING.COM
1 JulUS puts $10m bounty on Russian hackers, new phish hunts hotels, Supreme Court reins in geofencingUS Puts $10M Bounty on Russian Hackers, Supreme Court Limits Geofence Warrants, New phishing campaign targets hotels, AI Coding Agents Tricked into Malware and Canada's Electronic Spies Go After Ransomware Gangs. The episode covers the US State Department's up to $10 million rewa…CYBERSECURITYTODAY.LIBSYN.COM
1 JulWhy Ask Credentials If There Are Secret Codes?, (Wed, Jul 1st)This morning, an interesting phishing email hit my mailbox. It targets Metamask[ 1 ], a cryptocurrency wallet, available as a browser extension and a mobile app, that lets users store, send, and receive crypto money. It's pretty popular, so a juicy target for crimin…ISC.SANS.EDU
1 JulInsurance Giant Aflac Discloses Data Breach Impacting MillionsAflac Japan has notified regulators that policy details and personal and banking information have been compromisedINFOSECURITY-MAGAZINE.COM
1 JulBrowser-Only Ransomware: From LLM Hallucinations to a Practical Attack TechniqueResearch by: Alexey Bukhteyev Key Takeaways Introduction Over the past several years, large language models have reshaped software development, and malware development has followed the same path. Check Point Research has documented this trend from early experiments showing t…RESEARCH.CHECKPOINT.COM
1 JulARToken: Inside an EvilTokens affiliate panel targeting Microsoft 365Talos has identified "ARToken," a phishing-as-a-service platform that targets Microsoft 365. The ARToken panel exposes 80+ API endpoints for device code phishing, Primary Refresh Token persistence, email access, BEC operations, and SharePoint exfiltration.TALOSINTELLIGENCE.COM
1 JulThe SOC Files: ScreenConnect masked as freeware. An inside look at a large-scale campaignKaspersky experts have uncovered a malicious network infrastructure for delivering AsyncRAT. The Trojan is dropped via compromised ScreenConnect software. In this post, we break down the infection chain and analyze the C2 infrastructure.SECURELIST.COM
1 JulJapanese insurer, brewer, manufacturer and telecom disclose cyber breachesAflac's Tokyo arm and brewer Sapporo are among the major Japanese companies to recently notify the public about data breaches.THERECORD.MEDIA
1 JulAI-Generated Browser Ransomware Abuses Chromium API on Windows and AndroidCybersecurity researchers have flagged a new malware artifact generated using DeepSeek that constructed a novel attack path combining "unrealistic browser-malware concepts with a real browser capability" to turn it into a working ransomware technique that runs entirely inside the…THEHACKERNEWS.COM
1 JulAzure CLI Targeted in LSHIY Password Spray Campaign Across 64 Orgs81 Million Login Attempts, 78 Compromised Accounts: The LSHIY Password Spray Hitting Azure CLI Huntress researchers have been tracking a massive automated password spray campaign against Microsoft Azure CLI environments since June 12, 2026. A password spray attack is when attacke…SECURITYAFFAIRS.COM
1 JulFake Interpol investigation emails deliver custom ransomware worldwideThreat actors impersonate Interpol to trick small businesses into launching ransomware disguised as evidence in a fake cybercrime investigation. The campaign has targeted organizations across Europe, Asia, the Middle East, and the United States, relying on convincing social engin…CYBERINSIDER.COM
1 JulDHS confirms hackers breached HSIN info-sharing platformThe Department of Homeland Security is investigating a cyberattack that compromised the Homeland Security Information Network (HSIN), a sensitive information-sharing platform used by federal, state, local, and private-sector partners. [...]BLEEPINGCOMPUTER.COM
1 JulTeen suspect in Scattered Spider hacks is extradited to USA complaint unsealed this week accuses a 19-year-old of participating in incidents including a breach of a "luxury-jewelry retailer" in 2025.THERECORD.MEDIA
1 JulFortiBleed credential-theft campaign linked to Lynx ransomwareThe massive FortiBleed credential theft campaign has been linked to the INC and Lynx ransomware operations, suggesting the stolen Fortinet credentials were intended to fuel future network intrusions. [...]BLEEPINGCOMPUTER.COM
30 JunProduct showcase: Scam calls, phishing, and data breaches? Meet AVG Mobile SecurityAVG Mobile Security for iOS helps protect users against online threats with features including Web Guard, VPN, Scam Guardian Pro, Hack Alerts, and Photo Vault. It also identifies suspicious calls and scam text messages and helps keep personal information private while using Wi-Fi…HELPNETSECURITY.COM
30 JunOver 300 UK Firms Hit by Ransomware in a YearReport Fraud data reveals that more than half of 323 UK ransomware victims last year were SMEsINFOSECURITY-MAGAZINE.COM
30 JunBlackfield ransomware asks Nidec Corporation for $2 million ransomThe Blackfield ransomware gang is asking for a $2 million ransom from Nidec Corporation, a large Japanese manufacturer of electronic components for automotive and computing applications. [...]BLEEPINGCOMPUTER.COM
30 JunNissan Employee Data Breached in Oracle PeopleSoft HackOnly a handful of the 100 organizations targeted in the PeopleSoft campaign have been confirmed. The post Nissan Employee Data Breached in Oracle PeopleSoft Hack appeared first on SecurityWeek .SECURITYWEEK.COM
30 JunAflac Japan Data Breach Impacts 4.38 MillionHackers accessed the insurance giant’s policyholder portal multiple times between June 15 and June 25. The post Aflac Japan Data Breach Impacts 4.38 Million appeared first on SecurityWeek .SECURITYWEEK.COM
30 JunLessons from the Underground: How to Combat Business Email CompromiseBusiness Email Compromise is more than an email scam. It's a coordinated operation involving compromised accounts, financial research, and cash-out networks. Flare explores how underground forums reveal how BEC attacks are planned and executed. [...]BLEEPINGCOMPUTER.COM
30 JunStop Policing AI PromptsAI security is changing. Instead of focusing only on preventing bad responses or prompt abuse, organizations increasingly need to control what AI agents are actually allowed to do inside real systems. As AI agents gain access to identities, applications, and workflows, the bigges…YOUTUBE.COM
30 JunWeekly Update 510: Live From Mallorca with Scott HelmePresently sponsored by: Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite How's the view?! Back to business, it's now 8 years ago that Scott and I thought it would be a cool idea to build Why no HTTP…TROYHUNT.COM
30 JunMicrosoft Warns Poisoned MCP Tool Descriptions Can Make AI Agents Leak DataNew Microsoft research shows how attackers can hijack AI agents that act on a user's behalf, using nothing more than a poisoned tool description to make the agent quietly hand over company data to an outsider. The trick is that the agent never breaks a rule. Every step …THEHACKERNEWS.COM
30 JunMalicious PyPI packages give hackers control of Telegram bot serversA campaign active since last November has been targeting Python developers building Telegram bots with trojanized Pyrogram forks that allow attackers to read arbitrary files on compromised servers. [...]BLEEPINGCOMPUTER.COM
29 JunSycophantic chatbots and the harms that build over many chatsPeople use AI chatbots for company, advice, and emotional support, and these systems answer in ways meant to hold their attention. Researchers describe the resulting risks as affective safety, a class of harm that exists because humans are emotional beings and because the systems…HELPNETSECURITY.COM
29 JunHijacked npm and Go Packages Use VS Code Tasks to Deploy Python InfostealerCybersecurity researchers have uncovered two hijacked npm packages and a cluster of Go packages that are designed to deploy a Python-based information stealer on compromised Windows, Linux, and macOS hosts. "This attack avoids the most common npm execution paths through lifecycle…THEHACKERNEWS.COM
29 JunThe Gentlemen are knocking: сustom backdoors and evolving tacticsKaspersky researchers analyze incidents related to The Gentlemen RaaS group, disclose their tools and TTPs, and find a new ransomware variant.SECURELIST.COM
29 JunTop Google Security Staff Warn Search Data Could Be Hacked if EU Rules ChangeEurope’s pro-competition proposals could see Google Search and Android systems opened up. The company claims there are serious privacy flaws.WIRED.COM
29 JunRussian Hackers Accused of Destructive Cyber-Attack on Jaguar Land RoverExperts warn the Jaguar Land Rover breach bears hallmarks of Kremlin-backed hackers, citing novel ransomware, strategic timing and efforts to obscure attributionINFOSECURITY-MAGAZINE.COM
29 JunPrivacyHawk Enterprise helps organizations find shadow IT and minimize third-party cyber riskPrivacyHawk has announced the general availability of PrivacyHawk Enterprise, a solution that identifies and eliminates the shadow IT accounts, abandoned SaaS subscriptions, and forgotten third-party services quietly exposing organizations to breach risk. Every organization has a…HELPNETSECURITY.COM
29 Jun29th June – Threat Intelligence ReportFor the latest discoveries in cyber research for the week of 29th June, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Polymarket, a large cryptocurrency-based prediction market, has confirmed a supply chain attack after a third-party frontend vendor b…RESEARCH.CHECKPOINT.COM
29 JunFrom Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver AkiraKey Takeaways This case was first reported to customers in a threat brief released in July 2025 and in a public flash alert in August 2025 in partnership with Swisscom B2B CSIRT, which observed another intrusion tied to the same campaign. This report contains data from both intru…THEDFIRREPORT.COM
29 JunWhite House eases restrictions on Mythos.FBI issues updated warning on Russian phishing attacks targeting messaging apps. Japanese telecommunications giant discloses breach.THECYBERWIRE.COM
29 JunInsurance body confirms hackers posted Oracle PeopleSoft breach dataNAIC warned that some ratings agencies have suspended data feeds as a precaution. CYBERSECURITYDIVE.COM
29 JunOne Hack, Fifty VictimsA single breach can trigger many others when attackers compromise widely used software, infrastructure, or suppliers. The speakers describe this as a cascading breach, while also comparing it to hack amplification. Rather than attacking companies one by one, attackers may focus o…YOUTUBE.COM
29 JunWhat the June 2026 Threat Technique Catalog update means for your AWS environmentThe AWS Customer Incident Response Team (AWS CIRT) encounters patterns that repeat across engagements when helping customers respond to security incidents. We’re passionate about making sure that information is accessible so that everyone can improve their security posture and th…AWS.AMAZON.COM
29 JunIran, Russia, China Target Water Systems for SabotageNation-state attackers breach water systems through weak passwords, exposed PLCs, and poor segmentation — not sophisticated malware.DARKREADING.COM
28 JunSECURITY AFFAIRS MALWARE NEWSLETTER ROUND 103Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter More Than 4,000 Legacy Routers Compromised by AryStinger, Turned into Global Attack Proxies for Hackers A VBScript …SECURITYAFFAIRS.COM
27 JunKubernetes forensics 1/3: what the container ?In 2025, Synacktiv CSIRT observed a significant rise in attacks and compromises targeting Kubernetes environments. The consensus is that these attacks are bound to keep expanding as much as the technology itself. To better understand how a Kubernetes cluster works and how to inve…SYNACKTIV.COM
27 JunOSX/MacRansom; analyzing the latest ransomware to target macsLooks like somebody on the 'dark web' is offering 'Ransomware as a Service'...that's designed to infect Macs!OBJECTIVE-SEE.ORG
27 JunHandBrake Hacked! OSX/Proton (re)AppearsThe website of a popular application was hacked, and the application trojaned with a new variant of osx/proton.OBJECTIVE-SEE.ORG
27 JunTowards Generic Ransomware DetectionBy monitoring file I/O events and detecting the rapid creation of encrypted files by untrusted processes, can ransomware be generically detected?OBJECTIVE-SEE.ORG
27 JunThird-Party Breaches Teach Education Sector a Costly Lesson in Vendor RiskRising threats from third-party actors are forcing institutions to play defense to protect student data from ransomware and other attacks.DARKREADING.COM
27 JunHospitality Sector Hit by Phishing Campaign Using Fake Guest Complaint EmailsMicrosoft warns of a phishing campaign targeting the hospitality sector with fake guest emails that install TonRAT using resilient persistence. Microsoft Threat Intelligence published a detailed analysis on an ongoing hacking campaign against hospitality organizations that has be…SECURITYAFFAIRS.COM
27 JunUkraine Says Russian Intelligence Used Fake Support Texts to Steal Messaging CredentialsThe Security Service of Ukraine (SSU) said it, together with the U.S. Federal Bureau of Investigation (FBI), uncovered a long-running campaign orchestrated by Russian intelligence services to break into the messaging accounts of government officials, military personnel, politicia…THEHACKERNEWS.COM
26 JunAmerican Tower - 216,601 breached accountsIn June 2026, telecommunications tower infrastructure company American Tower was the target of a ShinyHunters "pay or leak" extortion campaign . The group subsequently published data allegedly taken from the company containing more than 200k unique email addresses belonging to em…HAVEIBEENPWNED.COM
26 JunCMC Releases Analysis and Guidance for Education Sector After Canvas Data BreachThe UK Cyber Monitoring Centre reviews the Canvas breach affecting 160 UK universities, highlighting data theft risks and financial impacts of cyber incidentsINFOSECURITY-MAGAZINE.COM
26 JunSIM-swapping gang busted in international police operationOfficers from Poland’s Central Bureau for Combating Cybercrime (CBZC) arrested four suspected members of an organized cybercrime group accused of SIM swap attacks, cryptocurrency theft, and money laundering. The operation involved agents from the U.S. Federal Bureau of Inve…HELPNETSECURITY.COM
26 JunHealthcare leaders see a fatal cyber incident as inevitableHealthcare practices run on a chain of outside vendors. An EMR system holds clinical records, a billing platform processes claims, a telehealth tool supports remote visits, and a cloud provider stores data. Every one of those connections gives an outside company a path into the p…HELPNETSECURITY.COM
26 JunOne Million Passports Leaked OnlineA database of almost a million passports from around the world was leaked online. Note what happened. A high-value credential—a passport—was used in an ancillary low-value authentication system: ID verification for cannabis dispensaries. And it’s the low-value s…SCHNEIER.COM
26 JunMiasma Malware Targets npm Packages and GitHub Actions in Supply Chain AttackCybersecurity researchers have flagged yet another evolution of the supply chain attack linked to the Mini Shai-Hulud, Miasma, and Hades malware family that has compromised a new set of npm packages, even as it has propagated to the Go ecosystem. "The latest activity includes mal…THEHACKERNEWS.COM
26 JunPolymarket suffers supply chain attack leading to $3 million crypto theftPolymarket says it has contained a supply chain attack that injected malicious code into its website after a compromised third-party vendor exposed some users to a phishing campaign. This resulted in roughly $3 million in cryptocurrency theft, which the company says will be fully…CYBERINSIDER.COM
26 JunMystery hackers use novel SharkLoader dropper against governments, software devsKaspersky researchers have uncovered a previously unknown cyberattack campaign that has compromised government organizations and software development companies in multiple countries. They first stumbled onto the campaign while investigating an attack on a diplomatic organization …HELPNETSECURITY.COM
26 JunRussia used social engineering to breach prominent messaging accounts, Ukraine saysUkraine's SBU described a long-running Russian operation that used fake tech-support workers to persuade people to hand over credentials to their messaging apps.THERECORD.MEDIA
26 JunIn Other News: Chinese Mythos-Like AI, Tata Electronics Breach, Snyk LayoffsOther noteworthy stories that might have slipped under the radar: Russia used Cellebrite to hack activist’s phone, Five Eyes issue urgent AI threat warning, macOS Gaslight backdoor, Scattered Spider guilty pleas. The post In Other News: Chinese Mythos-Like AI, Tata Electronics Br…SECURITYWEEK.COM
26 JunChinese-Speaking APT Deploys New TinyRCT Backdoor in Southeast Asia CampaignA Chinese-speaking advanced persistent threat (APT) actor has been linked to a new custom backdoor called TinyRCT as part of cyber attacks aimed at government entities and critical infrastructure in Southeast Asia. The activity, particularly aimed at state-owned enterprises in th…THEHACKERNEWS.COM
26 JunNew SharkLoader Malware Deploys Cobalt Strike in StrikeShark CyberattacksA newly discovered cyber attack campaign has been observed delivering a previously undocumented malware family called SharkLoader that acts as a loader for deploying Cobalt Strike Beacon on compromised hosts. Kaspersky, which is tracking the activity under the moniker StrikeShark…THEHACKERNEWS.COM
26 JunPolymarket customers lose $3 million in supply-chain attackPolymarket says it will fully reimburse customers who lost an estimated $3 million after hackers injected a malicious script into the platform's frontend following a breach at a third-party vendor. [...]BLEEPINGCOMPUTER.COM
25 JunSurviving the Mythos Era: Richard Bejtlich on the Case for NDRDespite the abundance of telemetry at analysts’ disposal, many security operations teams struggle to answer a few basic questions during incident investigation: What happened? What evidence do we have? How do we know we’re seeing it all, in context? Answering these questions requ…THEHACKERNEWS.COM
25 JunPolymarket says hackers stole users’ fundsThe prediction market giant Polymarket said it's refunding users who had funds stolen due to a third-party breach.TECHCRUNCH.COM
25 JunHacked Klue says criminals are deleting stolen customer data, but now other hackers are making threatsMarket research company Klue told customers that it believes the hacking group that stole their data is now deleting it. The company, however, warned about a second group of hackers wanting ransom.TECHCRUNCH.COM
25 JunCellebrite said it cut off Russia, but Russia used its tools anywaySecurity researchers found evidence that Russian authorities hacked the iPhone of a political opponent using a phone-unlocking device made by Cellebrite, even after the company said it would stop selling to Putin’s government.TECHCRUNCH.COM
25 JunGamaredon in 2025: Leveraging tunnels, workers, dead drops, and new alliancesESET Research analyzes Gamaredon’s new toolset and the group’s growing reliance on legitimate online services to hide its C&C infrastructure and exfiltrate stolen dataWELIVESECURITY.COM
25 JunEvaluating Mexico’s New Cybersecurity PlanExplore an analysis of Mexico’s 2025–2030 National Cybersecurity Plan. Discover how Mexico is addressing critical threats like ransomware, organized crime, and AI-driven attacks while preparing its digital infrastructure for the 2026 FIFA World Cup and beyondRECORDEDFUTURE.COM
25 JunElite network says it was hacked after members’ personal data was left exposedPersonal data belonging to politicians, military leaders, and executives was left publicly accessible in what looks like a security misconfiguration.MALWAREBYTES.COM
25 JunGone with the command.International operation disrupts Amadey and StealC malware infrastructure. Australian spy chief warns nation-state hackers are prepositioning for future sabotage. Stealthy new backdoor may be tied to initial access broker. Researchers uncover "Cordyceps" supply chain flaw. Iran-l…THECYBERWIRE.COM
25 JunAnother Russian dairy company reportedly disrupted by cyberattackA dairy products manufacturer in Russia's republic of Bashkortostan is the latest such company to have its operations snarled by a cyberattack.THERECORD.MEDIA
25 JunUkraine's state postal operator reports app disruption after cyberattackUkraine's state-owned postal operator said it was experiencing disruptions to some of its app services due to a suspected cyberattack, but did not say who was behind it.THERECORD.MEDIA
25 JunMinnesota man known as ‘Snoopy’ sentenced in DraftKings hackNathan Austad, who sold access to compromised accounts through a criminal storefront, is the third and final defendant sentenced in the 2022 breach The post Minnesota man known as ‘Snoopy’ sentenced in DraftKings hack appeared first on CyberScoop .CYBERSCOOP.COM
25 JunMajor Increase in Ransomware Attacks Targeting Europe, Warns New ReportAnalysis of ransomware incidents by researchers at Black Kite found that attacks have risen by over 50% in the last year, with supply chain attacks increasingINFOSECURITY-MAGAZINE.COM
25 JunPoland busts SIM-swapping gang tied to millions in crypto theftAuthorities in Poland have arrested four members of an organized cybercrime group accused of breaching telecommunications partners and hijacking email accounts to carry out SIM-swapping attacks. [...]BLEEPINGCOMPUTER.COM
25 JunWebinar: Why account takeovers remain one of the hardest threats to stopAccount takeover attacks continue to challenge security teams because attackers often operate through legitimate accounts and trusted services. This webinar explores how behavioral AI can help organizations identify compromised accounts faster and automate response workflows. [..…BLEEPINGCOMPUTER.COM
25 JunEurope Evolves Into Ransomware's Favorite RegionAfter a global lull, ransomware gangs are setting sights on a rich new arena: attacking EU organizations and their suppliers.DARKREADING.COM
25 JunStealthy new backdoor surfaces in attacks on multiple sectorsA relatively new backdoor called Mistic has been deployed in multiple attacks since April 2026 targeting organizations in the insurance, education, IT, and professional services sectors, according to Symantec. The malware appears to be associated with Woodgnat, also known as Kong…HELPNETSECURITY.COM
24 JunFortiBleed: Fortinet Says It's Not a BugFortinet finally weighs in on FortiBleed - it's not a bug. Plus a healthcare AI firm loses 1.4 million people's data to a single phishing email, a trading bot built to prey on others gets played for $15 million, and LastPass lands back on a breach list it didn't cause. 00:00 Head…CYBERSECURITYTODAY.LIBSYN.COM
24 JunWeekly Update 509Presently sponsored by: Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite I know enough about home cinema audiovisual to know there's a lot I don't know. It's conscious incompetence, if you like…TROYHUNT.COM
24 JunStealthy Mistic backdoor linked to ransomware access broker KongTukeA new backdoor dubbed Mistic has been observed in financially motivated attacks targeting organizations in the insurance, education, IT, and professional services sectors. [...]BLEEPINGCOMPUTER.COM
24 JunIran-Linked MuddyWater Poses as Ransomware Gang to Mask Cyber EspionageAn NCC Group report warns state-backed hackers are attempting to hide activity by posing as ransomware groups and deploying commercially available malwareINFOSECURITY-MAGAZINE.COM
24 JunNew ‘Mistic’ RAT Opens Door to Several Ransomware FamiliesMistic is used by Woodgnat, an initial access broker working with Qilin, Interlock, Rhysida, Akira, 8Base, and Black Basta. The post New ‘Mistic’ RAT Opens Door to Several Ransomware Families appeared first on SecurityWeek .SECURITYWEEK.COM
24 JunKDDI Breach Affects Six Japanese ISPs, Exposes 14.2 Email CredentialsCustomers of the affected Japanese email services are “strongly advised” to change their email passwordsINFOSECURITY-MAGAZINE.COM
24 JunPhishing attack on healthcare firm Xsolis impacts 1.4 million peopleHealthcare technology company Xsolis confirmed that a phishing attack resulted in unauthorized access to its network. The company develops AI-powered software for hospitals, health systems, and health plans and serves more than 600 hospitals and health insurers. “On January…HELPNETSECURITY.COM
24 JunIndian auto giant Bajaj Auto hit by ransomware incidentThe company said in a regulatory filing that it became aware of the incident on Tuesday morning and had taken precautionary measures to contain its impact.THERECORD.MEDIA
24 JunMadison Square Garden Sports - 9,796,738 breached accountsIn June 2026, the sports and entertainment company Madison Square Garden Sports was the target of a ShinyHunters "pay or leak" extortion campaign . The group later published the alleged data, which included almost 10M unique email addresses spanning staff and customers, along wit…HAVEIBEENPWNED.COM
24 JunAmadey, StealC malware operations disrupted in Operation Endgame actionMicrosoft, Europol, and international partners have disrupted infrastructure used by the Amadey and StealC malware operations as part of Operation Endgame, which targets cybercriminal services and ransomware gangs. [...]BLEEPINGCOMPUTER.COM
24 JunRansomware attacks grew in 2025 as traditional data breaches fell, Bitsight saysIn a new report, the company also charted a massive surge in internet-exposed AI services.CYBERSECURITYDIVE.COM
24 JunMicrosoft, Europol lead global takedown of infostealer malwareCybercriminals used Amadey and StealC to infect thousands of computers worldwide, leading to ransomware and other digital crimes.CYBERSECURITYDIVE.COM
24 JunSmashing Security podcast #473: How a hacker could have Rickrolled the entire World CupA polite caller from your bank says there is a problem with your account. Don't worry - they'll send someone round to help. They'll even take your cards away to keep them safe. The scam has run rampant, until Dutch police plastered blurred photos of 100 suspects across billboards…GRAHAMCLULEY.COM
24 JunDraftKings hacker 'Snoopy' sentenced to 18 months in prisonA 21-year-old using the alias "Snoopy" was sentenced to 18 months in prison for his role in hacking DraftKings accounts in the November 2022 cyberattack. [...]BLEEPINGCOMPUTER.COM
24 JunMalicious Edge extension abuses Native Messaging as bridge to malwareA malicious Microsoft Edge extension dubbed 'Edgecution' has been used in a ransomware attack to escape the browser sandbox and deploy a Python-based backdoor. [...]BLEEPINGCOMPUTER.COM
23 JunXsolis Data Breach Affects 1.4 Million IndividualsThreat actors gained access to personal and protected health information that Xsolis received from its clients. The post Xsolis Data Breach Affects 1.4 Million Individuals appeared first on SecurityWeek .SECURITYWEEK.COM
23 JunCanadian Electricity Provider London Hydro Discloses Data BreachHackers stole customers’ names, addresses, email addresses, phone numbers, and account information. The post Canadian Electricity Provider London Hydro Discloses Data Breach appeared first on SecurityWeek .SECURITYWEEK.COM
23 JunHackers steal passport and driver’s license data of 3 million TexansA breach at a Texas Parks and Wildlife Department vendor exposed personal information belonging to more than three million Texans.MALWAREBYTES.COM
23 JunTwo Scattered Spider hackers plead guilty over Transport for London cyberattackTwo members of the notorious hacker group Scattered Spider have pleaded guilty to charges related to a 2024 cyberattack on Transport for London (TfL) that resulted in £29 million in loss and recovery costs. Thalha Jubair, 20, from London, and Owen Flowers, 18, from Walsall, plead…HELPNETSECURITY.COM
23 JunAnthropic’s Fable 5 Model Jailbroken Within DaysFable 5 is the supposed safe version of Anthropic’s Mythos Preview, with guardrails to ensure that it can’t be used to create cyberattacks. Well, that restriction was bypassed within days.SCHNEIER.COM
23 JunTwo Scattered Spider members plead guilty over cyberattack that crippled London transitA 20-year-old and an 18-year-old admitted to infiltrating the network of Transport for London in 2024, disrupting public transportation services for months.THERECORD.MEDIA
23 JunPassword manager maker LastPass says hackers stole customer support case data during Klue breachThis is the second data breach to affect LastPass customers in recent years, after one of the password manager's tech partners was recently breached.TECHCRUNCH.COM
23 JunScattered Spider Hackers Plead Guilty on Day 1 of TrialTwo men pleaded guilty in the United Kingdom this week to criminal charges stemming from an August 2024 cyberattack that crippled Transport for London, the entity responsible for the public transport network in the Greater London area. The duo were key members of a prolific cyber…KREBSONSECURITY.COM
23 JunTata Electronics confirms cybersecurity incident after World Leaks dumps Apple dataTata Electronics has confirmed that it recently experienced a cybersecurity incident after the World Leaks extortion group listed the company on its leak portal and published what it claims is stolen corporate data. The company says it detected the incident weeks ago and that its…CYBERINSIDER.COM
23 JunKlue says hackers stole credential from 2022 that led to customer data breachesIt's unclear why Klue had not revoked the credential after the limited pilot, which hackers then used to breach a system holding keys for accessing customers' data.TECHCRUNCH.COM
23 JunDialog Claims It Was Hacked. A Misconfigured Website Left Its Members ExposedThe private events group, cofounded by Peter Thiel, says a “criminal” hacker is behind a breach that exposed members’ personal details. WIRED found no evidence a break-in was needed to access the files.WIRED.COM
23 JunHealthtech firm Xolis suffers data breach impacting 1.4 million peopleHealthcare technology company Xsolis says that sensitive data belonging to nearly 1.4 million individuals was compromised in a phishing attack that gave attackers access to its network. [...]BLEEPINGCOMPUTER.COM
23 JunYour Breach Plan Is DelusionalCybersecurity teams often repeat the phrase: “It’s not if, it’s when.” But according to this conversation, many organizations still behave as if breaches are completely preventable. Budgets continue flowing into detection tools, dashboards, and perimeter defenses while resilience…YOUTUBE.COM
23 JunTata Electronics confirms cyberattack as hackers leak dataTata Electronics has confirmed in a statement to BleepingComputer that it was the target of a cyberattack that impacted parts of its IT infrastructure. [...]BLEEPINGCOMPUTER.COM
22 JunTexas Parks & Wildlife Data Breach Affects 3 Million IndividualsHackers stole personal information after breaching the systems of a third-party license vendor serving TPWD. The post Texas Parks & Wildlife Data Breach Affects 3 Million Individuals appeared first on SecurityWeek .SECURITYWEEK.COM
22 JunINTERPOL Warns Phishing, Ransomware, and AI Scams Are Rising Across Asia-PacificA new report from INTERPOL has revealed a "dramatic increase" in cybercrime in Asia and the South Pacific, fueled by rapid digitalization, internet penetration, new technologies, organized criminal networks, and a disparity in cybersecurity maturity. According to INTERPOL's 2025/…THEHACKERNEWS.COM
22 JunInfrastructure downtime has a $50k-per-hour price tag. It’s time to turn hours into minutes.Threats move at machine speed. Network incident response still doesn't. What’s standing in the way?CYBERSECURITYDIVE.COM
22 JunWhatsApp users targeted by ongoing VBScript malware campaignKaspersky researchers have uncovered an ongoing malware campaign that uses compromised WhatsApp accounts to distribute malicious VBScript attachments. The attachments install ManageEngine Endpoint Central, a legitimate remote management tool that can provide attackers with remote…CYBERINSIDER.COM
22 Jun⚡ Weekly Recap: Browser Bugs, EDR Killers, TV Botnet, OpenBSD Flaw, Android Trojan, and MoreIt’s Monday again. This week’s threat list looks painfully familiar: abused integrations, fake tools, poisoned websites, ransomware crews trying to shut down security tools, and mobile malware asking for way too much control. The annoying part is how little of this feels new. Wea…THEHACKERNEWS.COM
22 JunKlue hack results in data breach at several cybersecurity firmsHuntress, HackerOne, Jamf, Recorded Future, and Tanium are among the cybersecurity companies that had data stolen following an earlier breach at market research firm Klue.TECHCRUNCH.COM
22 JunSuspected cyberattack triggers false emergency alerts across parts of BrazilThe incident occurred early Saturday when at least a dozen unauthorized alerts were sent through Brazil's Civil Defense Alert system, a platform designed to warn residents about imminent threats such as floods, landslides and other natural disasters.THERECORD.MEDIA
22 JunGentleKiller Framework Disables Victims' Security SoftwareESET details GentleKiller, the EDR-killer framework the Gentlemen ransomware gang gives affiliatesINFOSECURITY-MAGAZINE.COM
22 JunPrevent data exfiltration: AWS egress controls for cloud workloadsWhen securing an Amazon Web Services (AWS) environment, teams naturally prioritize inbound controls, firewalls, WAFs, and access policies, because that’s where the most visible threats originate. Outbound traffic, on the other hand, tends to get less attention. It’s often left op…AWS.AMAZON.COM
22 JunKlue supply-chain attack impacts cybersecurity firms.Brand-new Prinz Eugen ransomware is surprisingly polished. Brazil investigates suspected hack of emergency alert system. Texas data breach affects hunting and fishing licensees.THECYBERWIRE.COM
22 Jun22nd June – Threat Intelligence ReportFor the latest discoveries in cyber research for the week of 22nd June, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Texas Parks and Wildlife Department has been affected by a third-party data breach involving its license system vendor. The incident …RESEARCH.CHECKPOINT.COM
22 JunOne intrusion, two cyberattackers: Uncovering parallel threat activityRansomware case reveals two parallel threat actors, blending tactics and evasion—showing why isolated signals can often miss modern, overlapping cyberattacks. The post One intrusion, two cyberattackers: Uncovering parallel threat activity appeared first on Microsoft Security Blog…MICROSOFT.COM
22 JunShapedPlugin WordPress Pro Plugins Backdoored in Supply Chain AttackMultiple WordPress plugins from ShapedPlugin were compromised in a supply chain attack after unknown threat actors managed to tamper with the official release channels and push backdoor code. "Attackers compromised the vendor's build and distribution pipeline, injecting backdoor …THEHACKERNEWS.COM
22 JunTata Electronics, a major tech supplier to Apple and Tesla, confirms data breachThe incident comes as Tata Electronics expands its role in global technology supply chains.TECHCRUNCH.COM
22 JunFortiBleed campaign used custom FortiGate sniffer to steal credentialsSecurity firm SOCRadar says the large-scale FortiBleed campaign targeting Fortinet FortiGate devices used custom sniffers to harvest authentication secrets from compromised firewalls and steal credentials. [...]BLEEPINGCOMPUTER.COM
22 JunThe Klue is in the data trail.Klue supply-chain attack impacts cybersecurity firms. Brand-new Prinz Eugen ransomware is surprisingly polished. ShinyHunters leak exposes sensitive data of 10,000 Council of Europe employees. Security agencies sound alarm over FortiBleed credential harvesting operation. Texas da…THECYBERWIRE.COM
22 JunJaredFromSubway MEV bot hacked in $15 million crypto theftThe JaredFromSubway Ethereum MEV (Maximal Extractable Value) bot suffered a $15 million loss after an attacker manipulated the opportunity-detection logic by creating fake cryptocurrency trading opportunities. [...]BLEEPINGCOMPUTER.COM
21 JunAryStinger botnet infected thousands of D-Link routers worldwideA previously undocumented malware botnet named AryStinger has compromised more than 4,000 outdated routers to turn them into proxies for malicious traffic. [...]BLEEPINGCOMPUTER.COM
20 JunThe Gentlemen RaaS Uses GentleKiller EDR Framework Targeting 400 Security ProcessesThe Gentlemen ransomware-as-a-service (RaaS) operation is actively developing and maintaining a suite of endpoint detection and response (EDR) killers that it hands out to affiliates for impairing system defenses before deploying the encryptor. This mature portfolio of EDR-termin…THEHACKERNEWS.COM
20 JunYou Don’t Need Perfect SecurityThis clip compares cybersecurity deterrence to choosing between two identical Ferraris — except one has a rabid pit bull in the back seat. The point is simple: attackers often look for the easiest target, not necessarily a perfect target. The conversation also references the clas…YOUTUBE.COM
20 JunMicrosoft links Mastra AI supply chain attack to North Korean hackersMicrosoft has attributed a recent Mastra AI supply chain attack that compromised more than 140 npm packages to the North Korean hacking group Sapphire Sleet, also known as BlueNoroff. [...]BLEEPINGCOMPUTER.COM
20 JunNew Prinz Eugen ransomware prioritizes recent files for encryptionA new ransomware operation named 'Prinz Eugen' prioritizes recently modified files for encryption and leaves no ransom note on the system. [...]BLEEPINGCOMPUTER.COM
19 JunFrom Assistive to Agentic: The AI Shift That's Redefining Threat ManagementIntroduction The average enterprise security team has 40 or more security tools, giving a lot of visibility into internal telemetry and asset data. But often, these tools are working in siloes, generating (overlapping) alerts and data. And yet, breach dwell times remain stubbornl…THEHACKERNEWS.COM
19 JunOperation Endgame Disrupts Malware Network Linked to Major Ransomware GangSocGholish malware has been removed from 15,000 sites associated with Evil Corp hackersINFOSECURITY-MAGAZINE.COM
19 JunWebinar: How attackers bypass MFA and how defenders can respondModern phishing attacks, including Device Code phishing, can undermine MFA protections and grant attackers access to corporate accounts without stealing passwords. This webinar explores how behavioral AI can help security teams detect compromised accounts faster and automate resp…BLEEPINGCOMPUTER.COM
19 JunFortiBleed: 86,000 Fortinet Device Credentials CompromisedThe large-scale credential theft campaign hit roughly half of the internet-accessible Fortinet firewalls and VPNs. The post FortiBleed: 86,000 Fortinet Device Credentials Compromised appeared first on SecurityWeek .SECURITYWEEK.COM
18 JunHow security teams are getting credential visibility into developer endpointsAs we noted in our earlier analysis, attackers already know secrets are on your developers’ machines, the only question is whether security teams do. The supply chain attack calendar of 2026 has been relentless. Megalodon backdoored 5,500 GitHub repositories in six hours. T…HELPNETSECURITY.COM
18 JunKodak Admits Data Breach After ShinyHunters Hack ClaimsKodak told SecurityWeek it believes there is no threat to its systems or operations as a result of the cybersecurity incident. The post Kodak Admits Data Breach After ShinyHunters Hack Claims appeared first on SecurityWeek .SECURITYWEEK.COM
18 Jun5 new security operations roles the AI-SOC will createFor years we’ve heard the frightening prediction that AI will take jobs away from people. It will and it already is , but that doesn’t mean it won’t also create new jobs and skills demands — like every other labor trend driven by technology advances. Take security operations for …CSOONLINE.COM
18 JunGentleKiller targets more than 400 security processes across 48 productsMost ransomware operations leave the work of disabling endpoint security software to their affiliates. The ransomware-as-a-service gang Gentlemen runs a different model. Its operators develop and maintain a set of tools for shutting down endpoint detection and response (EDR) prod…HELPNETSECURITY.COM
18 JunKodak confirms breach as ShinyHunters’ leak threat reaches deadlineThe photography giant confirmed a data breach after ShinyHunters claimed it stole 2.2 million records and threatened to leak them.MALWAREBYTES.COM
18 JunMoody Bible Institute investigates potential data breach incidentMoody Bible Institute (MBI) says it is investigating claims that its systems were breached after the institution appeared on the dark web extortion site operated by the ShinyHunters threat group, which alleges it stole more than 23 GB of sensitive data from the Chicago-based Chri…CYBERINSIDER.COM
18 JunShapedPlugin update flow hacked to infect WordPress sitesMultiple WordPress plugins from ShapedPlugin were compromised in a supply chain attack that distributed infected releases to paying customers via the vendor's official update system. [...]BLEEPINGCOMPUTER.COM
18 JunAL26-014 – FortiBleed leak of thousands of compromised credentials impacting Fortinet devicesCYBER.GC.CA
18 JunINC Ransomware Emerges as Major RaaS Threat in 2026 with 830+ Victims Since 2023Cybersecurity researchers have charted the evolution of INC from an nascent ransomware-as-a-service (RaaS) operation to one of the most prolific cybercrime groups in 2026, claiming no less than 830 victims since August 2023. "The disruption of LockBit and the shutdown of BlackCat…THEHACKERNEWS.COM
18 JunAustralian sugar producer works to restore operations as ransomware group claims attackMackay Sugar said it was "working urgently" to verify claims that a highly active ransomware group was behind a cyberattack that shut down harvesting and milling operations.THERECORD.MEDIA
18 JunICO Cautions Healthcare Worker After Princess of Wales IncidentHospital insider escapes criminal prosecution after attempting to sell royal’s medical recordsINFOSECURITY-MAGAZINE.COM
18 JunTexas government data breach allowed hackers to steal 3 million driver’s licenses and passportsA data breach involving government-issued ID documents affects over three million people in Texas.TECHCRUNCH.COM
18 JunNintendo confirms data stolen in WebMD subsidiary cyberattackNintendo of America has confirmed to BleepingComputer that threat actors stole survey data from the third-party TinyPulse service used internally, but its systems were not compromised. [...]BLEEPINGCOMPUTER.COM
18 JunNovo Nordisk Breach Exposes Software Development Pipeline RiskA leaked GitHub token underscores what most organizations get wrong: Treating secrets management as a tooling problem rather than an identity problem.DARKREADING.COM
18 JunCybersecurity Focused On The Wrong ThingTraditional cybersecurity frameworks often prioritize confidentiality — protecting sensitive information from unauthorized access. But attacks against critical infrastructure introduce a different kind of risk. In many scenarios, the bigger danger is not stolen data, but failures…YOUTUBE.COM
18 JunGentlemen ransomware uses multiple EDR killers to disable defensesThe Gentlemen ransomware-as-a-service (RaaS) is actively developing and maintaining a suite of endpoint detection and response (EDR) killers to help affiliates evade detection in attacks. [...]BLEEPINGCOMPUTER.COM
17 JunNavigating SEC, NIS2, and DORA incident disclosure timelines under pressureIn this Help Net Security video, Rick Goud, Global Field CTO at Kiteworks, discusses how to handle SEC, NIS2, and DORA disclosure timelines during a security incident. He opens with a 3.47 a.m. call: the team cannot confirm whether customer data left the environment, yet three re…HELPNETSECURITY.COM
17 Jun3 Recently Patched Fortinet FortiSandbox Vulnerabilities in Hacker CrosshairsSOCRadar has detected 30,000 compromised Fortinet firewalls that expose networks to hacking. The post 3 Recently Patched Fortinet FortiSandbox Vulnerabilities in Hacker Crosshairs appeared first on SecurityWeek .SECURITYWEEK.COM
17 JunKodak confirms data breach claimed by ShinyHunters extortion gangKodak has confirmed that it's working with external cybersecurity experts to investigate a security breach after hackers gained access to some of the company's data. [...]BLEEPINGCOMPUTER.COM
17 JunMalicious JetBrains Plugins Steal AI API Keys as Chrome Extensions Capture Chatbot ChatsCybersecurity researchers have flagged a "coordinated malware campaign" on the JetBrains Marketplace that has published no less than 15 malicious plugins capable of exfiltrating artificial intelligence (AI) provider keys. "Every plugin poses as an AI coding assistant built on Dee…THEHACKERNEWS.COM
17 JunEU Security Experts to Support Ukrainian Organizations in Case of Cyber-AttacksUkraine has been added to the EU Cybersecurity Reserve, which provides incident response services against large-scale incidentsINFOSECURITY-MAGAZINE.COM
17 JunVelocityEHS uses QR codes to speed up incident reporting and risk responseVelocityEHS has announced the launch of QR Codes for Incident Management, a new feature designed to eliminate friction in safety reporting and help organizations surface incidents and near misses, identify risks, and take action. By enabling instant, mobile access to reporting to…HELPNETSECURITY.COM
17 JunSweeping Credential-Harvesting Heist Compromises +30K Fortinet DevicesAttackers actively are targeting various sectors across nearly 200 countries and have already compiled a list of working credentials for tens of thousands of compromised devicesDARKREADING.COM
17 JunWebinar Today: How Modern Breaches Bypass MFA and Evade DetectionAttendees will learn how attackers evade conventional detection methods, why legacy MFA alone is no longer sufficient, and how organizations can strengthen their defenses. The post Webinar Today: How Modern Breaches Bypass MFA and Evade Detection appeared first on SecurityWeek .SECURITYWEEK.COM
17 JunCalifornia water utility probes breach claim by Iran-linked actorThe group Handala said it attacked one of the nation’s largest water companies.CYBERSECURITYDIVE.COM
17 JunCanada introduces privacy law with GDPR-like penalties for data breachesThe Canadian government has introduced Bill C-36, a major privacy reform package that would recognize privacy as a fundamental right, expand consumer control over personal information, strengthen protections for children's data, and create a new regulator with the power to impose…CYBERINSIDER.COM
17 JunLow-skilled attacker used Claude, Codex to breach 14 companiesResearchers have long warned that AI agents could lower the skill floor for offensive cyber operations, and a recent report by OALABS (Open Analysis) researchers bears that out. After recovering and analyzing over 1,000 agent sessions from a compromised server on which an attacke…HELPNETSECURITY.COM
17 JunEU grants Ukraine access to cybersecurity reserve for major attacksAs Kyiv takes steps toward formal accession to the EU, the bloc is integrating Ukraine with its pool of pre-approved cybersecurity incident response companies.THERECORD.MEDIA
17 JunCybercriminals allegedly hacked tens of thousands of Fortinet firewalls used by major companies all over the worldAn alleged Russian-speaking group of cybercriminals is reportedly compromising and targeting several major companies that use Fortinet Firewalls and VPNs through previously known passwords.TECHCRUNCH.COM
17 JunAI is accelerating cyberattacks—here’s how to stay aheadSee how Microsoft unifies identity and security signals to help teams prevent, detect, and respond to AI-accelerated attacks faster. The post AI is accelerating cyberattacks—here’s how to stay ahead appeared first on Microsoft Security Blog .TECHCOMMUNITY.MICROSOFT.COM
17 JunINC Ransomware Thrives by Mastering the BasicsAnd one of those basics is focusing on sectors where a ransomware disruption creates immediate pressure to pay up, like with healthcare.DARKREADING.COM
16 JunChinese Hackers Abused Google Workspace Rules to Steal Research and Defense EmailsA China-linked espionage group hid inside North American medical, academic, and military research networks for more than a year, quietly stealing sensitive research and defense email. The way in was a backdoor on their REDCap research servers that stole login credentials. The exf…THEHACKERNEWS.COM
16 JunSurvey: 94% of Incidents Involve Anonymized Infrastructure. Teams Are Still ReactiveSecurity teams have never had more IP data at their disposal. Every day, analysts ingest enrichment feeds, geolocation data, reputation scores, telemetry, and threat intelligence from a growing ecosystem of vendors and platforms. Yet despite this abundance of information, many or…THEHACKERNEWS.COM
16 JunImaging giant Kodak confirms hackers breached systems and stole dataKodak says it is investigating a cybersecurity incident after the ShinyHunters extortion group claimed to have stolen more than 2.2 million records containing customer personally identifiable information (PII) and internal corporate data. The company confirmed that an unauthorize…CYBERINSIDER.COM
16 JunUK to require ID or face scan before you can make social media accountsOpening a new social media account in the UK will soon mean proving you're over 16 with an ID upload or a facial age scan, under a government ban on under-16s taking effect in spring 2027. Security experts warn the age checks are easy to circumvent and create new data-breach risk…BLEEPINGCOMPUTER.COM
16 Jun'Lorem Ipsum' Malware Pivots to ClickFix DeliveryNew analysis shows the campaign, which uses compromised WordPress sites, may be linked to the ransomware and data extortion group Vice Society.DARKREADING.COM
16 JunAI adoption correlates with incident frequency, underscoring need for governanceEven organizations that haven’t yet been breached expect an AI-related incident in the near future, a new survey found.CYBERSECURITYDIVE.COM
16 JuniRhythm Confirms Data Stolen in HackThe digital health company said it learned of the breach on June 8 and the attackers demanded a ransom. The post iRhythm Confirms Data Stolen in Hack appeared first on SecurityWeek .SECURITYWEEK.COM
15 JunWeekly Update 508Presently sponsored by: Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite Light switches. How on earth is it so hard to find decent light switches?! It sounds ridiculous until you actually spend enough time lo…TROYHUNT.COM
15 JunOne-Click Microsoft 365 Copilot Flaw Could Have Let Attackers Steal Emails, Files, and MFA CodesA single click on a trusted Microsoft link could have let an attacker pull emails, calendar details, and indexed files out of Microsoft 365 Copilot Enterprise Search. Researchers at Varonis Threat Labs chained three bugs into a one-click exfiltration path they call SearchLeak. Be…THEHACKERNEWS.COM
15 JunInfinite Campus - 137,123 breached accountsIn March 2026, the student information system Infinite Campus was targeted in a ShinyHunters "pay or leak" extortion campaign . The group subsequently published data they alleged was taken from Infinite Campus, containing 137k unique email addresses along with names, phone number…HAVEIBEENPWNED.COM
15 JunAnthropic suspends Fable and Mythos over US national security concerns.US state attorneys general open an investigation into OpenAI. Maine takes its breach reporting database offline.THECYBERWIRE.COM
15 JunMaine closes data breach portal to the public after fake reportsMaine is still allowing companies to report breaches, but won’t make the portal easily available to the public until after it completes an audit of its procedures to stop such incidents, according to a press release from the Maine attorney general’s office.THERECORD.MEDIA
15 JunAdriatic Port Cyber-Attack by Anubis Sparks Warning Over Maritime Security RisksHow the Anubis ransomware group stole and leaked an Italian Adriatic port authority's dataINFOSECURITY-MAGAZINE.COM
15 JunMaine Takes Breach Reporting Portal Offline After Fake EntriesThe Office of the Maine Attorney General has suspended its breach reporting portalINFOSECURITY-MAGAZINE.COM
15 Jun15th June – Threat Intelligence ReportFor the latest discoveries in cyber research for the week of 15th June, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES The University of Nottingham, a UK research university, has suffered a data breach after ShinyHunters accessed its student records sy…RESEARCH.CHECKPOINT.COM
15 JunAkira ransomware spotted using LimeWire service for data theftAn Akira ransomware affiliate used Easyupload.io, a file-sharing service operated by LimeWire, to exfiltrate stolen data during a recent attack. The incident was detected on May 29 after Huntress' SOC identified unauthorized remote access to a domain controller. Although the init…CYBERINSIDER.COM
15 JunOptinMonster WordPress plugin hacked in CDN supply-chain attackWordPress plugins OptinMonster, TrustPulse, and PushEngage have been compromised in a supply-chain attack impacting Awesome Motive-s content distribution network (CDN). [...]BLEEPINGCOMPUTER.COM
15 JunCouncil of Europe investigates ShinyHunters data breach claimsThe Council of Europe, the continent's oldest intergovernmental body, is probing claims of a data breach made by the ShinyHunters extortion group over the weekend. [...]BLEEPINGCOMPUTER.COM
15 JunChinese hackers breach REDCap servers, steal medical researchA China-linked espionage campaign targeted exposed REDCap servers to deploy the InfiniteRed malware and steal sensitive data from a medical institution in North America. [...]BLEEPINGCOMPUTER.COM
15 JunRansomware Attack Shuts Down Mills of Australia’s Second-Largest Sugar ProducerMackay Sugar was targeted in a cyberattack carried out by a threat group known as The Gentlemen. The post Ransomware Attack Shuts Down Mills of Australia’s Second-Largest Sugar Producer appeared first on SecurityWeek .SECURITYWEEK.COM
15 JunUkrainian Man Pleads Guilty in US to Conti Ransomware ChargesOleksii Oleksiyovych Lytvynenko admitted to working on the development of a loader for the Conti gang. The post Ukrainian Man Pleads Guilty in US to Conti Ransomware Charges appeared first on SecurityWeek .SECURITYWEEK.COM
15 JunOzempic Maker Novo Nordisk Says Hackers Breached IT SystemsThe pharmaceutical giant says the attackers gained access to personal data stored on the compromised systems. The post Ozempic Maker Novo Nordisk Says Hackers Breached IT Systems appeared first on SecurityWeek .SECURITYWEEK.COM
15 JunFrench Government Messaging Platform Breached by Mysterious ‘Misere’ HackerFrench officials say roughly 73,000 government accounts were affected, while the threat actor claims to have stolen messages and user data from the sovereign Tchap platform. The post French Government Messaging Platform Breached by Mysterious ‘Misere’ Hacker appeared first on Sec…SECURITYWEEK.COM
15 JunMaine Disables Data Breach Portal Due to Fake SubmissionsSomeone posted fake VRChat and Discord data breach reports on the system, prompting the Maine AG to take action. The post Maine Disables Data Breach Portal Due to Fake Submissions appeared first on SecurityWeek .SECURITYWEEK.COM
15 JunChina-Nexus Actor Spy on US Researchers Undetected for a YearGoogle discovered and disrupted the sprawling campaign, which stole RedCAP credentials to target numerous institutions and exfiltrate sensitive data.DARKREADING.COM
15 JunThe Beginning of the End of Social EngineeringAI-native operating systems are shifting the responsibility to stay vigilant against social engineering cyberattacks from the user onto the system itself.DARKREADING.COM
15 JunUkrainian national pleads guilty in connection with Conti ransomwareA Ukrainian national pleaded guilty to conspiracy to commit wire fraud in connection with the deployment of Conti ransomware, which targeted more than 1,000 victims worldwide. According to the U.S. Department of Justice, 44-year-old Oleksii Oleksiyovych Lytvynenko joined the Cont…HELPNETSECURITY.COM
15 JunInside the Modern SOC: The 72-Minute RaceAttackers can move from access to exfiltration in 72 minutes. Learn how modern SOC teams close the speed gap with Unit 42's AI-driven automation, threat hunting, MDR and Managed XSIAM. The post Inside the Modern SOC: The 72-Minute Race appeared first on Unit 42 .UNIT42.PALOALTONETWORKS.COM
13 JunCyberTitan Champions: Inside Canada's National High School Cybersecurity Competition (and CyberPatriot)Cybersecurity Today on the Weekend interviews the winning Canadian CyberTitan team ("S-ores"/a regex-based name) along with coach Phil, educator Tim, and CyberTitan manager Sheena to explain how CyberTitan (run by ICTC) connects to the international CyberPatriot program. They des…CYBERSECURITYTODAY.LIBSYN.COM
13 JunThe FBI built its own replica small town to simulate real-world cyberattacksHidden inside a building in Alabama, the FBI has created its own small town as a dedicated cyber training ground for simulating cyberattacks.TECHCRUNCH.COM
13 JunEx-school district employee jailed for hacks on former employerA former IT employee at an Iowa school district was sentenced to 21 months in prison after conducting a prolonged cyberattack against the former employer that disrupted classroom operations, deleted accounts, and caused tens of thousands of dollars in damages. [...]BLEEPINGCOMPUTER.COM
12 JunEuropol Disrupts AudiA6 Crypto Laundering Service Used by Ransomware GangsAuthorities in Europe have disrupted AudiA6, a cryptocurrency laundering service used by ransomware gangs and cybercriminal networks. Europol, in a statement issued Thursday, said the dismantling of AudiA6 cut off a "key financial pipeline used to wash hundreds of millions in ill…THEHACKERNEWS.COM
12 JunOver 73,000 French govt employees affected in Tchap messenger breachThe French government revealed that a recent breach of its Tchap encrypted messaging platform affects the accounts of over 73,000 employees in the French public sector. [...]BLEEPINGCOMPUTER.COM
12 JunRansomware Payment Crypto Laundering Platform Taken Out by FBI and EuropolDomain of dark web money laundering platform AudiA6 seized and suspects arrested in joint operation by the FBI, Europol and othersINFOSECURITY-MAGAZINE.COM
12 JunSouth Korea hits Coupang with record $409 million fine over data breachThe penalty is the largest ever issued by the commission for a personal data breach, surpassing the record 134.8 billion won ($88.8 million) fine levied against SK Telecom earlier this year.THERECORD.MEDIA
12 JunAgentic AI surges in financial sector even as many firms fail to manage security risksOne-fifth of firms aren’t even sure if they’ve been hacked through their AI tools, according to a new report.CYBERSECURITYDIVE.COM
12 JunIn Other News: Google Security Layoffs, AudiA6 Takedown, $400 Million Coupang FineOther noteworthy stories that might have slipped under the radar: ICS device exposure remains flat as attack surface widens, Microsoft issues incident response playbook for AI, IBM and AT&T accused of hack cover-ups. The post In Other News: Google Security Layoffs, AudiA6 Ta…SECURITYWEEK.COM
12 JunBankruptcy admin approves settlement fund of $47 million for 23andMe data breach victimsAbout 7 million customers of the genetics testing company had their data stolen by hackers starting in April 2023, and many had their information posted on the dark web.THERECORD.MEDIA
12 JunConti ransomware group member pleads guilty, faces up to 20 years in prisonOleksii Lytvynenko, a 44-year-old Ukrainian national, admitted to joining the prolific cybercrime group in 2021. Officials said he engaged in cybercrime up until his arrest in Ireland in 2023. The post Conti ransomware group member pleads guilty, faces up to 20 years in prison ap…CYBERSCOOP.COM
12 JunUkrainian national pleads guilty to role in Conti ransomware operationA Ukrainian national extradited from Ireland to the United States last year has pleaded guilty to conspiracy charges tied to the Conti ransomware operation. [...]BLEEPINGCOMPUTER.COM
12 JunOver 400 Arch Linux packages compromised to push rootkit, infostealerMore than 400 packages in the Arch User Repository (AUR) are distributing a Linux rootkit and infostealer malware targeting credentials and access tokens. [...]BLEEPINGCOMPUTER.COM
12 JunMaine disables data breach notification portal after fake disclosuresMaine has taken its public data breach reporting portal offline after fraudulent breach disclosures were published on the state's website, prompting a review of procedures to prevent abuse in the future. [...]BLEEPINGCOMPUTER.COM
11 JunPrompt injection still drives most agentic AI security failures in productionA backdoor sat on PyPI for three hours in March 2026. Nearly 47,000 downloads occurred during the window. The compromised package, LiteLLM, serves as the language-model gateway for CrewAI, DSPy, Microsoft GraphRAG, and dozens of other AI agent frameworks. Anyone pulling an update…HELPNETSECURITY.COM
11 JunNottingham University data breach affects over 450,000 studentsThe University of Nottingham confirmed on Wednesday that a hacking group gained access to its student records system in a breach affecting both current students and alums. [...]BLEEPINGCOMPUTER.COM
11 JunUniversity of Nottingham Confirms Breach After Hackers Leak DataThe ShinyHunters hacker group has taken credit for the attack, leaking more than 450,000 email addresses and other information. The post University of Nottingham Confirms Breach After Hackers Leak Data appeared first on SecurityWeek .SECURITYWEEK.COM
11 JunExtortion-Only Attacks Increase, With Data Theft Dominating Ransomware ClaimsExtortion-only attacks are increasing as data theft drives most ransomware claims, with many organizations unable to stop stolen data from being exposedINFOSECURITY-MAGAZINE.COM
11 JunCybersecurity Stars Awards 2026: Winners Announced Across 95 CategoriesMost good security work is invisible by design. Today is the exception. The 2026 Cybersecurity Stars Awards winners are announced across 95 subcategories in four main award categories. The reason is simple. Cybersecurity is full of work that deserves recognition and rarely gets i…THEHACKERNEWS.COM
11 JunSouth Korea hits Coupang with $400M+ fine for data breach that affected millionsSouth Korean authorities issued the record-breaking fine following a data breach that affected over 30 million customers.TECHCRUNCH.COM
11 JunUniversity of Nottingham confirms cyber incident as Shiny Hunters group claims data theftAccording to the university’s statement, it is still working to understand what data has been accessed and said it had already directly contacted affected students and alumni, potentially including those in its foreign campuses in Malaysia and China as well as in Nottingham.THERECORD.MEDIA
11 JunAI Is Upgrading Hackers FastAI is rapidly increasing the effectiveness of cyber attackers at every level. Tasks that once required deeper expertise can now be automated, accelerated, or simplified with AI-assisted tooling. That shift compresses the gap between inexperienced, mid-tier, and highly advanced th…YOUTUBE.COM
11 JunGerman court holds Google liable for AI-generated claims.OpenAI disrupts two China-linked influence operations. Cyberattack disrupts Australian sugar mills.THECYBERWIRE.COM
11 JunBritish high school sends students home following cyberattackGreat Marlow School, which has 1,428 pupils according to the Department for Education (DfE), said it was set to remain closed while it works with specialist IT and cybersecurity professionals to resolve the issue.THERECORD.MEDIA
11 JunRussian national charged in connection with Void Blizzard espionage campaignDenis Obrezko accused of orchestrating cyberattacks that compromised at least 11 U.S. companies as part of the Kremlin-linked group's sprawling espionage operation.\ The post Russian national charged in connection with Void Blizzard espionage campaign appeared first on CyberScoop…CYBERSCOOP.COM
11 JunThe court calls Google’s bluff.Google faces liability for AI-generated claims. Washington pauses public AI model assessments. Anthropic ships a safer AI model. OpenAI disrupts influence operations. Ransomware operators get a powerful new backdoor. Urgent patches land for Ivanti and Veeam. PyPI supply chain att…THECYBERWIRE.COM
11 JunMaine breach portal abused to publish fake data breach disclosuresIn an unusual misinformation campaign, fraudulent data breach disclosures were submitted to Maine's official breach portal and publicly posted before their legitimacy could be verified, prompting companies to deny the claims. [...]BLEEPINGCOMPUTER.COM
10 JunWeekly Update 507Presently sponsored by: Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite 1,000 breaches is one hell of a milestone. It's not just the process of getting data, verifying it, loading it, sending notificati…TROYHUNT.COM
10 JunOver a Quarter of Identity Crime Victims Hit by Multiple Incidents, ITRC Data ShowsNearly 26% of identity crime victims faced multiple incidents in the past year, as ITRC warns of a growing "multi-layered crisis"INFOSECURITY-MAGAZINE.COM
10 JunWhy schools remain one of cybercriminals’ favourite targetsSchools on both sides of the Atlantic have been revealed in recent days to have been hit by hackers, reminding all of us that ransomware gangs see educational instituions as targets all year round. Read more in my article on the Hot for Security blog.BITDEFENDER.COM
10 JunCyberattack shuts down major Australian sugar mills, disrupting harvestAustralia's second-largest sugar producer said on Wednesday that it was responding to a cybersecurity incident affecting parts of its operations and had engaged cybersecurity experts and local authorities to investigate the attack and restore its systems safely.THERECORD.MEDIA
10 JunUniversity of Nottingham confirms hackers accessed student dataThe University of Nottingham has confirmed to CyberInsider in a statement that it suffered a cyber incident resulting in unauthorized access to data stored in its student record system. The disclosure comes after ShinyHunters listed the university on its leak site, alleging it ha…CYBERINSIDER.COM
10 JunOracle PeopleSoft servers hacked in ShinyHunters data theft attacksOracle PeopleSoft servers are being targeted in ongoing data theft attacks by the ShinyHunters extortion gang, which claims to have stolen data from over 100 organizations. [...]BLEEPINGCOMPUTER.COM
10 JunBug Bounty Research Triggers ServiceNow Security AlertBug bounty research inadvertently led organizations to believe they were being breached through their ServiceNow instances.DARKREADING.COM
10 JunCybercriminals claim breach of Oracle PeopleSoft servers at 100-plus organizationsThe ShinyHunters hacking gang claims to have compromised the Oracle PeopleSoft servers of more than 100 organizations, including many universities.TECHCRUNCH.COM
10 JunUniversity of Nottingham - 454,635 breached accountsIn June 2026, the University of Nottingham was the target of a cyber attack , later linked to a ShinyHunters "pay or leak" extortion campaign. Tens of gigabytes of data were subsequently published online and included 455k unique email addresses along with extensive personal infor…HAVEIBEENPWNED.COM
9 JunOpenAI’s Lockdown Mode is trying to solve the problem that it createdOpenAI’s move to implement a Lockdown Mode that tries to limit data exfiltration by shutting down external capabilities is being seen as making the best out of a bad situation. But Lockdown Mode doesn’t block exfiltration as much as it slightly reduces it, and the reality of ente…CSOONLINE.COM
9 JunCybersecurity jobs available right now: June 9, 2026Application Security Architect INTENSITY Global Group | Israel | Hybrid – View job details As an Application Security Architect, you will design secure application architectures, perform threat modeling and security assessments, define security standards and contr…HELPNETSECURITY.COM
9 JunHades PyPI Attack: 19 Packages Poisoned to Auto-Run Bun Credential StealerThe Miasma supply chain campaign has sparked a fresh attack wave called Hades, this time involving 37 malicious wheel artifacts across 19 packages in the Python Package Index (PyPI) registry, as the Mini Shai-Hulud-style attacks continue to be refined and splintered to target spe…THEHACKERNEWS.COM
9 JunFrench govt messaging service breached in account hijacking attackDINUM, the digital affairs directorate of the French government, warned that hackers used a hijacked user account to breach Tchap, the French government's encrypted messaging platform. [...]BLEEPINGCOMPUTER.COM
9 JunElastic brings AI-driven incident investigation to Kubernetes and observability toolsElastic has introduced an agentic Kubernetes investigation workflow and MCP-based observability skills that diagnose incidents the moment an alert fires. By the time an SRE opens the alert, the root cause has already been identified, evidence has been assembled, and recommended n…HELPNETSECURITY.COM
9 JunAnthropic Offers Mythos Upgrade for Cyber Partners and a ‘Safe’ Version for the Rest of YouAnthropic is releasing Claude Mythos 5 to trusted organizations and Claude Fable 5 to the public, a version it says can’t be used for cyberattacks.WIRED.COM
9 JunMiasma Supply Chain Worm Burrows Into 73 Microsoft RepositoriesThe attacks stemmed from a GitHub account that was also compromised in a previous Miasmi attack on Microsoft last month.DARKREADING.COM
8 JunClaude Outage Data Leak, Microsoft GitHub Worm, IBM Hack, M Instagram Takeovers, Canada's Bill C-8TClaude Outage Data Leak Fears, Microsoft GitHub Worm, IBM Hack Allegations, Meta AI Instagram Takeovers, and Canada's Bill C-8 David Shipley reports that Anthropic's Claude suffered a roughly two-hour outage affecting models including Opus, during which a user alleged receiving …CYBERSECURITYTODAY.LIBSYN.COM
8 JunCybercriminals create 19,000 FIFA-themed domains ahead of 2026 World CupFans looking for tickets, accommodation and match broadcasts are already encountering scams tied to the 2026 FIFA World Cup. The 2026 FIFA World Cup will bring millions of visitors and an estimated 6 billion spectators to a tournament spread across 16 host cities in the United St…HELPNETSECURITY.COM
8 JunOver 20,000 Instagram accounts stolen in Meta AI support hackMeta has revealed that over 20,000 Instagram users had their accounts hijacked in a recent incident where attackers used Meta's AI-powered support system to reset passwords. [...]BLEEPINGCOMPUTER.COM
8 JunWhen attacks spread too far: Lessons from real cyber attack case studiesIn this Help Net Security video, Michael Adjei, Director, Systems Engineering at Illumio, explains three real world cyber attacks and what went wrong during detection. Adjei walks through a collaboration tool scam that copied Microsoft Teams, an identity phishing case used for pa…HELPNETSECURITY.COM
8 JunMeta Says 20,000 Instagram Accounts Hacked via AI Tool AbuseThe social media giant has informed authorities about the impact of the recent attack involving an account recovery support tool. The post Meta Says 20,000 Instagram Accounts Hacked via AI Tool Abuse appeared first on SecurityWeek .SECURITYWEEK.COM
8 JunSilent Ransom Group Uses DNS Fast Flux in AttacksFocusing on hacking law firms in the US, the ransomware group relies on fast flux to hide its C&C infrastructure. The post Silent Ransom Group Uses DNS Fast Flux in Attacks appeared first on SecurityWeek .SECURITYWEEK.COM
8 Jun174,000 Impacted by Lansing Community College Data BreachHackers accessed personal information stored on certain Lansing Community College systems in February 2025. The post 174,000 Impacted by Lansing Community College Data Breach appeared first on SecurityWeek .SECURITYWEEK.COM
8 JunNew Shai-Hulud attack trojanizes 19 science-focused PyPI packagesHackers compromised 19 packages on the PyPI, collectively downloaded hundreds of thousands of times, in a new Shai-Hulud supply-chain attack that delivered malware designed to steal developer secrets. [...]BLEEPINGCOMPUTER.COM
8 JunSoFi confirms third-party data breach at Hong Kong subsidiarySoFi Hong Kong is warning that it suffered a data breach after hackers gained access to a database at a third-party vendor containing customer information. [...]BLEEPINGCOMPUTER.COM
8 JunNew Apple feature automatically changes your compromised passwordsAt WWDC 26, Apple announced an Apple Intelligence-powered feature that can automatically fix weak and compromised passwords. This works in Safari, and it's rolling out with iOS 27. [...]BLEEPINGCOMPUTER.COM
6 JunNew ChatGPT Lockdown Mode Limits Tools That Could Enable Data ExfiltrationOpenAI has begun rolling out a new Lockdown Mode to ChatGPT for eligible personal accounts to reduce the risk of data exfiltration arising from prompt injection attacks. The feature is primarily designed for people and organizations that handle sensitive data and require stricter…THEHACKERNEWS.COM
5 JunPCPJack Hijacks 230 AWS, Google Cloud, and Azure Servers for Covert SMTP Relay NetworkThe threat actor known as PCPJack has hijacked cloud servers associated with Amazon Web Services (AWS), Google Cloud, and Microsoft Azure to create a covert SMTP email relay network. "Compromised business servers across the U.S., Europe, and Asia were quietly converted into SMTP …THEHACKERNEWS.COM
5 JunBCD Travel - 396,313 breached accountsIn May 2026, the corporate travel management company BCD Travel was claimed as a victim of the ShinyHunters "pay or leak" extortion campaign . Data allegedly obtained from BCD was subsequently published publicly in early June and contained 396k unique email addresses. Other expos…HAVEIBEENPWNED.COM
5 JunNightclub Giant RCI Says Data Breach Affects 40,000 IndividualsThe company detected a network intrusion in March and an investigation showed that some files were stolen during the attack. The post Nightclub Giant RCI Says Data Breach Affects 40,000 Individuals appeared first on SecurityWeek .SECURITYWEEK.COM
5 JunAI is helping low-skill hackers pull off advanced cyberattacksAnthropic has published an analysis of cyber-related misuse of its AI systems, examining 832 accounts that were banned for malicious cyber activity between March 2025 and March 2026. The company mapped the observed behavior to the MITRE ATT&CK framework, which documents tact…HELPNETSECURITY.COM
5 JunNSA said to be readying Anthropic’s Mythos for use in cyber operationsThe U.S. eavesdropping agency is reportedly preparing Anthropic's Mythos for use in cyberattacks, despite a federal ban on using the AI model maker.TECHCRUNCH.COM
5 JunGoogle and FBI warn of ransomware group that sends fake IT workers to hack victims in personCybercriminals, part of a gang known as Silent Ransom Group, have sent people pretending to be IT support employees to law firms' offices, where the criminals have stolen data using USB drives or remote access tools.TECHCRUNCH.COM
5 JunMicrosoft identifies seven new ways AI agents can be hackedMicrosoft has identified seven new failure modes in agentic AI systems, in addition to those it identified last year in its first Taxonomy of Failure Modes in Agentic AI Systems . Four things contributed to the growing list of ways agentic AI can go wrong : the speed at which the…CSOONLINE.COM
5 JunChinese APT deploys new malware to keep access to hacked networksA Chinese espionage group tracked as UNC5221 has been accessing Microsoft 365 environments using the Brickstorm backdoor and previously undocumented malware named Plenet and AgentPSD. [...]BLEEPINGCOMPUTER.COM
5 JunFormer cyber executive turned whistleblower accuses IBM of covering up several data breachesIBM and two of its subsidiary companies were allegedly breached during the mid-2010s, which a lawsuit filed by a former cybersecurity executive accuses IBM of not disclosing and actively covering up.TECHCRUNCH.COM
5 JunExposed Fuel Tank Gauges Under Attack in the USThreat actors are taking advantage of Internet-exposed tank gauges by breaching gas stations, opening the door to disruption.DARKREADING.COM
4 JunDentaQuest data breach exposed sensitive info of 2.6 million peopleDentaQuest says it is investigating a cybersecurity incident involving unauthorized access to part of its network, following the ShinyHunters extortion group's public leak of data allegedly stolen from the company. The breach has since been added to Have I Been Pwned (HIBP), whic…CYBERINSIDER.COM
4 JunUN food agency investigates breach exposing data of Gaza aid recipientsIn a message sent to aid recipients via Telegram over the weekend, the World Food Programme (WFP) said that "unauthorized parties" had accessed data stored in its self-registration application in Gaza.THERECORD.MEDIA
4 JunSecurity Tools Don’t Reduce RiskThe Peltzman effect describes how people often feel safer once protections are in place, even when the underlying risk has not meaningfully changed. In cybersecurity, organizations may assume firewalls, MSSPs, or security tools automatically make incidents less likely. That assum…YOUTUBE.COM
4 JunHola Browser supply chain breach delivered crypto-miner to usersA supply chain compromise resulted in a crypto-mining executable being distributed alongside certain installations of Hola Browser for Windows. The unexpected component, named me.exe, was discovered by Sophos X-Ops during a software certification test and was not part of the brow…CYBERINSIDER.COM
4 JunUN food agency discloses breach affecting 600,000 Gaza householdsThe United Nations' World Food Programme (WFP), the world's largest humanitarian organization, revealed over the weekend that its self-registration application (SRA) for Palestine was breached. [...]BLEEPINGCOMPUTER.COM
4 JunAgentic AI Is Transforming Defense, But Only Secure IT Infrastructure Will Maximize ItOver the past several weeks, the cybersecurity community has been reminded how quickly frontier and agentic AI in defense networks can challenge our assumptions. When Anthropic's Claude Mythos model was made available to a limited set of organizations as a technical preview, it w…THEHACKERNEWS.COM
4 JunRussia seeks to label two anti-Kremlin hacker groups as ‘extremist’The groups have previously claimed responsibility for cyberattacks targeting critical infrastructure and government institutions in Russia and Belarus.THERECORD.MEDIA
4 JunEU fines Temu 200 million Euros for breaching the DSA.Trump signs new EO focused on AI.THECYBERWIRE.COM
4 JunCredit card theft campaign abuses Stripe to host stolen payment infoA new Magecart campaign is using Stripe's API infrastructure to host the credit card-stealing payload and the data exfiltrated from checkout pages. [...]BLEEPINGCOMPUTER.COM
4 JunVerdantBamboo: Just Another BRICKSTORM in the FirewallIn September 2025, Volexity conducted an incident response engagement that began after suspicious network traffic was observed from a Linux-based virtual machine appliance on a customer’s network. The virtual machine […] The post VerdantBamboo: Just Another BRICKSTORM in th…VOLEXITY.COM
4 JunHola Browser for Windows compromised to deliver cryptominerThe Windows version of the Hola Browser has been compromised in a supply chain attack that delivered an undeclared executable identified by researchers as a cryptocurrency miner. [...]BLEEPINGCOMPUTER.COM
3 JunWelcoming the Philippine Government to Have I Been PwnedPresently sponsored by: Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite Today, we welcome the 46th government onboarded to Have I Been Pwned’s free gov service: the Philippines. The Philippines’…TROYHUNT.COM
3 JunA small Slovenian team handles 6,000 cyber incidents a yearOnline fraud complaints, ransomware cases, and phishing tips reach Slovenia’s national cyber response center in steady volume, and a team of around a dozen analysts sorts through them. Gorazd Božič, who manages SI-CERT at the public agency ARNES, described that work in an i…HELPNETSECURITY.COM
3 JunPreinstall to persistence: Inside the Red Hat npm Miasma credential-stealing campaignA large-scale npm supply chain attack compromised over 90 versions of @redhat-cloud-services packages, silently infecting CI/CD environments and developer systems. The malicious code steals credentials from GitHub, cloud platforms, and local machines, then spreads like a worm by …MICROSOFT.COM
3 JunSecurity of 100 AI Agents Tested and Ranked – What You Need to KnowThe AI Risk Quadrant evaluates AI agents based on three factors: how vulnerable they are to compromise, the potential impact of a breach, and the strength of their security defenses. The post Security of 100 AI Agents Tested and Ranked – What You Need to Know appeared first on Se…SECURITYWEEK.COM
3 JunHackers Target Global Stock Exchange in Espionage OperationThe attackers had access to a senior executive’s email account for 150 days and exfiltrated data for months. The post Hackers Target Global Stock Exchange in Espionage Operation appeared first on SecurityWeek .SECURITYWEEK.COM
3 JunIMA Diligence Services Data Breach Impacts 525,000 PeopleThe affected individuals’ personal information was stolen from a legacy server managed by a third party. The post IMA Diligence Services Data Breach Impacts 525,000 People appeared first on SecurityWeek .SECURITYWEEK.COM
3 JunThe worst hacks and breaches of 2026 (so far)From a massive DOGE data breach and the hacking of critical energy and water systems to the hack of an FBI surveillance system, here are the most damaging security incidents and data breaches of 2026.TECHCRUNCH.COM
3 JunUltrahuman says hackers accessed customers’ wellness data via internal toolThe breach at wearable ring maker Ultrahuman stemmed from credentials stolen from a malware-infected employee laptop.TECHCRUNCH.COM
3 JunChinese hackers use new Atlas RAT malware in European cyberattacksA Chinese-speaking cybercrime group has expanded its targeting to the European space, deploying previously undocumented malware and the Atlas backdoor. [...]BLEEPINGCOMPUTER.COM
3 JunU.S. sanctions Nobitex crypto exchange used by Iranian ransomware actorsThe U.S. Treasury's Office of Foreign Assets Control (OFAC) has announced sanctions against Nobitex, Iran's largest cryptocurrency exchange, for facilitating payments related to terrorist activities. [...]BLEEPINGCOMPUTER.COM
2 JunThe Intersection of Encryption and AIAs part of their 20th Anniversary celebration, Dark Reading asked five cybersecurity industry leaders who wrote blogs or columns for them over the years to select their favorite piece and share their reflections on the topic today. This is my section. Renowned technologist and au…SCHNEIER.COM
2 JunBeyond Assume-Breach: How AI-Native Security Will Reshape Enterprise DefenseTwenty years after Dark Reading launched, we're looking ahead at what's next for enterprise security. Spoiler: It's hyper-segmented, AI-orchestrated, and way more sophisticated than your dad's firewall.DARKREADING.COM
2 JunRed Hat removes tainted packages after software pipeline compromiseAccording to the company’s preliminary analysis, a compromised GitHub account was used to push the malicious code out to customers, hitting 32 packages downloaded roughly 117,000 times a week.THERECORD.MEDIA
2 Jun64,000 accounts exposed in breach of GTA V cheat service Atlas MenuAtlas Menu, a cheat service for Grand Theft Auto V and Counter-Strike 2, has been added to the Have I Been Pwned database following a data breach that exposed tens of thousands of user records. The incident exposed approximately 64,000 accounts, including email addresses, usernam…HELPNETSECURITY.COM
2 JunRussia claims foreign spy agencies hacked officials' phonesIn a statement, Russia's Federal Security Service (FSB) said it had uncovered what it described as a "large-scale operation" involving malicious software installed on the mobile devices of senior Russian officials.THERECORD.MEDIA
2 JunAI-built ransomware toolkit automates EDR evasion, AD discoveryA threat actor is using an AI-built attack toolkit that automates Active Directory discovery and helps evade endpoint detection and response (EDR) solutions. [...]BLEEPINGCOMPUTER.COM
2 JunChina Uses Dual-Method Cyberattack on Czech OrgsChina is stealing data from high-value targets via a sneaky, double-layer spear-phishing campaign that includes the Azureveil malware.DARKREADING.COM
2 JunOne Account, Total BreachA single account can serve as an entry point into interconnected systems. With technologies like single sign-on and widespread SaaS adoption, one compromised credential may provide access to multiple services and environments. The impact of identity compromise is no longer isolat…YOUTUBE.COM
1 JunWeekly Update 506Presently sponsored by: Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite I'm finding it quite fascinating to watch the current spate of ShinyHunters breaches and dumps. There's the obvious criminali…TROYHUNT.COM
1 JunEdmunds - 177,860 breached accountsIn January 2026, the automotive research and car-shopping platform Edmunds was listed by the ShinyHunters hacking group as having been breached . Data purportedly obtained in the incident was later published publicly and included 178k unique email addresses, usernames, passwords,…HAVEIBEENPWNED.COM
1 JunMicrosoft confirms outage affecting MFA, My Sign-Ins platformMicrosoft is working to address an ongoing incident preventing customers from setting up multi-factor authentication (MFA) or accessing the My Sign-Ins platform. [...]BLEEPINGCOMPUTER.COM
1 JunInfosecurity Europe: Tabletop Exercise to Test How CISOs Respond to Major Supermarket Cyber-AttackSemperis is set to bring ‘Enter the War Room: A Tabletop Experience’ to Infosecurity Europe to help cybersecurity leaders prepare to face real incidentsINFOSECURITY-MAGAZINE.COM
1 JunWebinar tomorrow: From alert to resolution in network incident responseNetwork incidents are often detected quickly, but investigations and coordination can delay resolution. Join our webinar tomorrow to learn how automation and AI-assisted workflows can help IT teams accelerate incident response. [...]BLEEPINGCOMPUTER.COM
1 JunMicrosoft fixes outage affecting MFA setup, MySignIn serviceMicrosoft is working to address an ongoing incident preventing customers from setting up multi-factor authentication (MFA) or accessing the My Sign-Ins platform. [...]BLEEPINGCOMPUTER.COM
1 Jun1st June – Threat Intelligence ReportFor the latest discoveries in cyber research for the week of 1st June, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Carnival Corporation, a global cruise line operator, has confirmed a data breach affecting nearly 6 million people after attackers use…RESEARCH.CHECKPOINT.COM
1 JunMicrosoft investigates Office Apps, Teams file access issuesMicrosoft says an ongoing incident is preventing users of its Teams collaboration platform and Office for the web cloud-based productivity suite from opening files. [...]BLEEPINGCOMPUTER.COM
1 JunGrand Theft Auto V cheat service gets hacked, exposing thousands of gamersHackers stole usernames, hashed passwords, and other data from a service that allowed players to cheat in Grand Theft Auto V.TECHCRUNCH.COM
1 JunMiasma Supply Chain Attack Compromises Red Hat npm Packages with Credential-Stealing WormA new Mini Shai-Hulud supply chain attack campaign, codenamed Miasma, has compromised @redhat-cloud-services packages to steal credentials and secrets from developer machines and deliver a self-propagating worm. "This is effectively a Mini Shai-Hulud campaign: it uses the same co…THEHACKERNEWS.COM
1 JunHackers hijacked Instagram accounts by tricking Meta AI support chatbot into granting accessSeveral users on social media reported having their Instagram accounts hacked over the weekend. Meta's own support chatbot was blamed for allowing hackers to hijack accounts.TECHCRUNCH.COM
1 JunTina Peters, convicted in election-security breach, emerges defiant and vows legal fightThe former Colorado election clerk struck an unrepentant pose in her first interview after her prison sentence was commuted by Colorado Governor Jared Polis. The post Tina Peters, convicted in election-security breach, emerges defiant and vows legal fight appeared first on CyberS…CYBERSCOOP.COM
1 JunRed Hat npm packages compromised to steal developer credentialsMore than 30 npm packages under Red Hat's '@redhat-cloud-services' namespace were compromised in a supply-chain attack that distributed a new variant of the Shai-Hulud credential-stealing malware, dubbed "Miasma." [...]BLEEPINGCOMPUTER.COM
1 JunHackers hijack thousands of sites for ClickFix and FakeUpdate attacksA threat actor tracked as DriveSurge has been operating large-scale malware distribution campaigns using ClickFix and FakeUpdates techniques on compromised sites. [...]BLEEPINGCOMPUTER.COM
30 MayRussia-aligned crime group Greyvibe extensively uses AI in attacksResearchers have uncovered a previously undocumented Russian group that makes extensive use of large language models (LLMs) in its attacks against private, government, and military organizations in Ukraine. It uses a variety of attack vectors along with custom malware, with the g…CSOONLINE.COM
30 MayCybercrime Crew Claims It Hacked Mike Lindell’s MyPillowPlus: A ransomware group is now stealing data in person, BusPatrol wants to hand its license plate surveillance data to the cops, and more.WIRED.COM
30 MayAtlas Menu - 63,926 breached accountsIn May 2026, the GTA V and CS2 cheat service Atlas Menu suffered a data breach. An attacker claimed to have gained access to all Atlas systems and published the service's database to a public GitHub repository. The incident exposed 64k unique email addresses along with usernames,…HAVEIBEENPWNED.COM
29 MayProduct showcase: TotalAV helps iOS users clean up their digital messTotalAV Mobile Security helps protect devices from malicious websites, SMS scams, unsafe public Wi-Fi networks, and exposed credentials. The app is available for Windows, Android, macOS, and iOS devices. After downloading the app from the App Store, users provide an email address…HELPNETSECURITY.COM
29 MayKimsuky Deploys HTTPSpy, Expands Arsenal with HelloDoor and VS Code TunnelsThe North Korean state-sponsored threat actor known as Kimsuky (aka Velvet Chollima) has been attributed to a fresh set of cyber attacks targeting South Korean military and corporate entities through March and April 2026. "Kimsuky employed a range of tailored social engineering t…THEHACKERNEWS.COM
29 MayHumanix expands detection to identify live violations of security proceduresHumanix has announced a capability to identify live violations of organization-defined procedures governing IT support workflows. Designed to prevent unauthorized access, these procedures typically require help desk and service desk agents to follow identity verification steps be…HELPNETSECURITY.COM
29 MayCharter Communications data breach affects 4.9 million accountsThe ShinyHunters extortion gang stole personal information from 4.9 million accounts after hacking the U.S. telecom giant Charter Communications in early April, according to data breach notification service Have I Been Pwned. [...]BLEEPINGCOMPUTER.COM
29 MayMalicious Sicoob NuGet Steals Banking Credentials as npm Packages Target Cloud SecretsCybersecurity researchers have discovered a malicious NuGet package that masquerades as a C# software development kit for Sicoob, one of Brazil's largest cooperative financial systems, to siphon client IDs and PFX certificates. According to Socket, versions 2.0.0 through 2.0.4 of…THEHACKERNEWS.COM
29 MayCalifornia Sues 23andMe, Alleging It Failed to Protect User Data in 2023 BreachAttorney General Rob Bonta filed the lawsuit against Chrome Holding Co., which 23andMe rebranded under after filing for bankruptcy last March. The post California Sues 23andMe, Alleging It Failed to Protect User Data in 2023 Breach appeared first on SecurityWeek .SECURITYWEEK.COM
29 MayNew Russian-Linked GREYVIBE Targets Ukraine with AI-Powered CyberattacksA previously undocumented threat actor dubbed GREYVIBE has been attributed to ongoing and persistent attacks targeting Ukraine and Ukraine-related entities since at least August 2025. GREYVIBE, per WithSecure, is assessed to be a Russian-speaking group operating broadly in the Ru…THEHACKERNEWS.COM
29 MaySilent Ransom Group Uses In-Person IT Impersonation to Breach SystemsThreat actors from the Silent Ransom Group, aka Luna Moth, are escalating attacks by impersonating IT staff in phone calls and even showing up in person to gain direct access to victim systemsINFOSECURITY-MAGAZINE.COM
29 MayCharter Communications Data Breach Could Impact Nearly 5 MillionThe notorious ShinyHunters extortion group leaked over 42 million records allegedly stolen from Charter in April. The post Charter Communications Data Breach Could Impact Nearly 5 Million appeared first on SecurityWeek .SECURITYWEEK.COM
29 MayMokN Raises $15 Million for Phish-Back PlatformMokN's platform deploys realistic decoy access points to lure attackers into revealing compromised credentials, enabling organizations to respond before abuse occurs. The post MokN Raises $15 Million for Phish-Back Platform appeared first on SecurityWeek .SECURITYWEEK.COM
29 MayCalifornia AG sues 23andMe over 2023 breach exposing health dataCalifornia Attorney General Rob Bonta filed a lawsuit against 23andMe, now Chrome Holding Co., over the company's failure to protect sensitive customer genetic and personal information. [...]BLEEPINGCOMPUTER.COM
28 MayThe CISO selling confidence in a market full of breach headlinesEngineering teams across enterprise IT are writing their own software with AI coding assistants, spinning up agents that act on their behalf, and assigning those agents the same access privileges their human creators hold. The shift has pulled the role of the chief information se…HELPNETSECURITY.COM
28 MayNordic CISOs Handle Rising Cyber Threats Remarkably WellArtificial intelligence notwithstanding, the vast majority of CISOs in northern Europe say they're facing no more serious cyberattacks than they did two years ago.DARKREADING.COM
28 MayXM Cyber enhances identity risk visibility with continuous exposure management capabilitiesXM Cyber has announced platform enhancements aimed at helping organizations reduce identity risk, compounded by AI-enabled attackers. According to Gartner, “By 2028, 70% of CISOs will use identity visibility and intelligence capabilities to shrink the IAM attack surface, reducing…HELPNETSECURITY.COM
28 MayPolice arrest suspect in Ajax football club hack that exposed 300,000 fan recordsThe Dutch National Police arrested a man suspected of hacking into the computer systems of AFC Ajax, a football club from Amsterdam. “On the morning of Tuesday, May 26, detectives arrested a 35-year-old man from the municipality of Buren for computer intrusion at the Amsterdam fo…HELPNETSECURITY.COM
28 MayGoogle Unveils AI Threat Defense Platform to Fight AI-Powered CyberattacksNew AI Threat Defense platform combines capabilities from Mandiant, Wiz and Gemini to help customers fight AI with AI. The post Google Unveils AI Threat Defense Platform to Fight AI-Powered Cyberattacks appeared first on SecurityWeek .SECURITYWEEK.COM
28 MayInfosecurity Europe: Cybersecurity Staff Prefer CISOs With Real Attack Response Experience, Study RevealsISC2 survey of cybersecurity professionals suggests that staff want their information security leaders to have experienced reacting to a significant cyber incidentINFOSECURITY-MAGAZINE.COM
28 May2026 World Cup: Discussing The World’s Biggest Game’s Attack SurfaceThe 2026 World Cup presents major cyber risks from ransomware groups, state-aligned actors, and other groups targeting critical infrastructure. Learn more here. The post 2026 World Cup: Discussing The World’s Biggest Game’s Attack Surface appeared first on Unit 42 .UNIT42.PALOALTONETWORKS.COM
28 MayCarnival Cruise confirms data breach affecting nearly 6 million peopleCarnival Corporation, the world's largest cruise line operator, has confirmed a data breach affecting nearly 6 million people claimed by the ShinyHunters extortion gang in April 2026. [...]BLEEPINGCOMPUTER.COM
28 MayCarnival confirms data breach impacting nearly 6 millionCruise giant Carnival has suffered yet another data breach, with ShinyHunters claiming to have stolen personal data affecting nearly 6 million people.MALWAREBYTES.COM
28 MayRomanian gets 5 years in prison for hacking Oregon govt networkA Romanian national was sentenced this week to 56 months in federal prison for breaking into an Oregon state government computer network and fr cyberattacks targeting dozens of other U.S. victims. [...]BLEEPINGCOMPUTER.COM
28 MayWebinar: Why network incidents take too long to resolveMany organizations can detect network issues quickly, but investigations and coordination often slow incident resolution. This webinar explores how automation and AI-assisted workflows can help IT teams reduce delays and improve response times. [...]BLEEPINGCOMPUTER.COM
28 MayMyPillow listed on ransomware gang’s leak site, but denies it has been breachedA notorious ransomware gang claims to have stolen MyPillow's private data, but CEO Mike Lindell calls it a politically motivated "hit job." With the countdown ticking toward a massive dark web leak, who is telling the truth? Read more in my article on the Hot for Security blog.BITDEFENDER.COM
28 MayNew BTMOB Android Malware Enables Full Device TakeoverDelivered via phishing lures, the malware combines financial theft with data exfiltration and remote access. The post New BTMOB Android Malware Enables Full Device Takeover appeared first on SecurityWeek .SECURITYWEEK.COM
28 MayCruise giant Carnival confirms data breach affecting nearly 6 million peopleThe company said the threat actor gained access to a limited portion of its IT environment last month after compromising an employee account. By the end of April, Carnival determined that the attacker had copied personal information from its systems.THERECORD.MEDIA
28 MayCarnival begins notifying 6 million people of a data breachCarnival Corporation has begun notifying roughly six million individuals that their personal information was stolen in the cyberattack claimed by the ShinyHunters extortion group earlier this year. The disclosure follows the public leak of data allegedly containing 8.7 million re…CYBERINSIDER.COM
28 MayCarnival Data Breach Exposed 6 Million PeopleData breach leaves nearly 6 million Carnival customers navigating identity theft risks. The post Carnival Data Breach Exposed 6 Million People appeared first on SecurityWeek .SECURITYWEEK.COM
28 MayCybercriminals sail away with data from 6 million Carnival customersCarnival Corporation, one of the world’s largest cruise operators, confirmed a data breach weeks after the ShinyHunters hacking group claimed it had stolen millions of customer records. Carnival acknowledged a phishing incident involving a single employee account and stated that …HELPNETSECURITY.COM
28 MayThe Gentlemen ransomware: Dissecting a self-propagating Go encryptorMicrosoft Threat Intelligence presents a comprehensive analysis of The Gentlemen, a Go-based ransomware deployed by affiliates of Storm-2697 that combines per-file ephemeral key encryption with an aggressive self-propagation module to deploy itself across an entire network using …MICROSOFT.COM
28 MayRussia-Linked ‘GreyVibe’ Attackers Use AI to Supercharge CyberattacksResearchers warn GreyVibe’s extensive use of ChatGPT, Gemini, and other AI tools offers a glimpse into how future cybercriminal and state-aligned groups will operate. The post Russia-Linked ‘GreyVibe’ Attackers Use AI to Supercharge Cyberattacks appeared first on SecurityWeek .SECURITYWEEK.COM
28 MayCharter - 4,851,517 breached accountsIn May 2026, the telecommunications company Charter Communications (the parent company behind the consumer broadband and cable brand Spectrum) was named by the ShinyHunters group in a "pay or leak" extortion campaign . The group later published the data, which exposed 4.9M unique…HAVEIBEENPWNED.COM
28 MayGreyVibe hackers use ChatGPT, Gemini to power cyberattacksA likely Russian threat cluster tracked as GreyVibe has been targeting Ukrainian entities with AI-generated lures and a rich set of custom malware tools. [...]BLEEPINGCOMPUTER.COM
27 MayLA Metro Cyberattack Linked to Iranian State-Sponsored HackersThe attack was claimed by a hacktivist group, but evidence showed it used infrastructure linked to Iranian government threat actors. The post LA Metro Cyberattack Linked to Iranian State-Sponsored Hackers appeared first on SecurityWeek .SECURITYWEEK.COM
27 May3 SOC Steps that Shut Down Incident Risks EarlyMost organizations still picture cyber defense as a fortress problem: build stronger walls, add more guards, buy another detection engine. But modern incidents rarely crash through the front gate. They drift in disguised as routine activity, hide inside legitimate processes, and …THEHACKERNEWS.COM
27 MayCrowdStrike shuts down the Glassworm botnet.Extortion group sends individuals to infiltrate organizations in person. Lithuania investigates breach of the Centre of Registers. Business news: Zscaler to acquire Symmetry Systems.THECYBERWIRE.COM
27 MayLatin American Cybercriminals Hoover Up Government DataA purported leak exposing 5.8 million records of Uruguayan citizens is the latest incident where cybercriminals targeted government agencies to monetize citizen data.DARKREADING.COM
27 MayThe Small Model CliffCASI Leaderboard, Bias Jailbreak, and Three Coordinated Supply Chain IncidentsF5.COM
27 MayRansomware Actors Show Up In Person to Steal Law Firm DataThe FBI warned that the extortion gang Silent Ransom Group is targeting law firms and socially engineering its way into servers and databases.DARKREADING.COM
26 MayProduct showcase: F-Secure Internet Security blocks phishing sites, fake stores, and SMS scamsF-Secure Internet Security protects against viruses, ransomware, spyware, infected email attachments, and other cyber threats. It focuses on securing devices and online activity through malware protection, scam prevention, safe browsing, and banking safeguards. The platform suppo…HELPNETSECURITY.COM
26 May7-Eleven data breach exposes personal information of 185,000 peopleThe ShinyHunters extortion gang stole the personal information of over 183,000 people after hacking the systems of convenience store chain giant 7-Eleven in April, according to data breach notification service Have I Been Pwned. [...]BLEEPINGCOMPUTER.COM
26 MayWatch on Demand: Threat Detection & Incident Response Summit – All Sessions AvailableRegister to enjoy free access and explore the tools, strategies, and frameworks needed to build a resilient security program for a world where every minute counts. The post Watch on Demand: Threat Detection & Incident Response Summit – All Sessions Available appeared fi…SECURITYWEEK.COM
26 May185,000 Likely Impacted by 7-Eleven Data BreachThe allegedly stolen information leaked by ShinyHunters contains email addresses, names, addresses, and dates of birth. The post 185,000 Likely Impacted by 7-Eleven Data Breach appeared first on SecurityWeek .SECURITYWEEK.COM
26 MayPersonal information of 185,000 people exposed after cyberattack on 7-ElevenData belonging to about 185,000 people was exposed following a cyberattack on convenience store chain 7-Eleven that was later claimed by the ShinyHunters extortion gang, according to Have I Been Pwned. The exposed information includes email addresses, names, physical addresses, d…HELPNETSECURITY.COM
26 MayMicrosoft Defender can now automatically isolate hacked endpointsMicrosoft is testing a new Defender for Endpoint capability that will automatically isolate compromised endpoints to thwart attackers' attempts to move laterally across the network. [...]BLEEPINGCOMPUTER.COM
26 MayWebinar: Too many tools are slowing network incident responseIT teams often need to jump between monitoring dashboards, infrastructure tools, ticketing systems, and communication platforms during network incidents. This webinar explores how automation and AI-assisted workflows can help reduce manual coordination and improve incident respon…BLEEPINGCOMPUTER.COM
26 May7-Eleven data breach affects over 185,000 people’s personal dataThe data breach included names, dates-of-birth, postal addresses, and Social Security numbers, according to a state government listing.TECHCRUNCH.COM
26 MayLithuania investigates theft of 600,000 state registry records by foreign actorThe Lithuanian Prosecutor General’s Office said Friday that attackers gained unauthorized access to more than 600,000 records managed by the Centre of Registers, the state agency responsible for handling property and legal entity records.THERECORD.MEDIA
26 MayIranian hackers blamed for breach of Los Angeles transit system that took weeks to recoverAn Israeli cybersecurity firm said Iran’s government is behind Ababil of Minab, a fake hacktivist persona that has claimed a series of data breaches after the start of the war in Iran.TECHCRUNCH.COM
26 MayIranian government, not hacktivist group, breached LA Metro system, security firm saysA report by Israel-based Gambit Security dismisses the hackers’ claims of being patriotic but unaffiliated activists.CYBERSECURITYDIVE.COM
26 MayCharter confirms data breach after ShinyHunters extortion threatU.S. telecommunications giant Charter Communications has confirmed it suffered a data breach after the ShinyHunters extortion group threatened to leak stolen data unless a ransom is paid. [...]BLEEPINGCOMPUTER.COM
25 MayLessons for organizations from the Verizon 2026 Data Breach Investigations ReportThis is my favourite time of the year, not just because spring is here and the promise of summer is on the way. But also, because one of my must reads each year gets published. There are a few must read reports that I have on my reading list for each year and the Verizon Data Bre…HELPNETSECURITY.COM
25 MayDocketWise Data Breach Impacts 143,000Hackers accessed names, addresses, Social Security numbers, financial information, and medical data from third-party partner repositories. The post DocketWise Data Breach Impacts 143,000 appeared first on SecurityWeek .SECURITYWEEK.COM
25 MayLaravel-Lang Packages Poisoned for Malware DeliveryPublished within a 15-minute window, the malicious tags introduced backdoors to exfiltrate CI secrets. The post Laravel-Lang Packages Poisoned for Malware Delivery appeared first on SecurityWeek .SECURITYWEEK.COM
25 May266,000 Affected by Data Breach at Radiology Associates of RichmondThreat actors stole files containing names and protected health information from the healthcare organization’s systems. The post 266,000 Affected by Data Breach at Radiology Associates of Richmond appeared first on SecurityWeek .SECURITYWEEK.COM
25 MayOncology Institute Discloses Data BreachThe affected third-party vendor has not been named, but one possible candidate is TriZetto. The post Oncology Institute Discloses Data Breach appeared first on SecurityWeek .SECURITYWEEK.COM
25 MayNetherlands Seizes 800 Servers, Arrests 2 for Aiding CyberattacksAuthorities in the Netherlands have arrested the co-owners of two related Internet hosting companies for operating IT infrastructure used by Russia to carry out cyberattacks, influence operations and disinformation campaigns inside the European Union. The two men were the focus o…KREBSONSECURITY.COM
25 MayWelcoming the Bhutanese Government to Have I Been PwnedPresently sponsored by: Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite Today, we welcome the 45th government onboarded to Have I Been Pwned’s free gov service: Bhutan. The Bhutan Computer Incident Re…TROYHUNT.COM
24 MayWeekly Update 505Presently sponsored by: Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite Well, that didn't last long! Recording this on Saturday morning my time, I observed ShinyHunters having gone quiet since the massi…TROYHUNT.COM
24 May7-Eleven - 185,256 breached accountsIn April 2026, 7-Eleven was the victim of a "pay or leak" extortion campaign by ShinyHunters , with the data later published that month. The incident exposed 185k unique email addresses, along with names, physical addresses, dates of birth and phone numbers. A small number of rec…HAVEIBEENPWNED.COM
23 MayLaravel-Lang PHP Packages Compromised to Deliver Cross-Platform Credential StealerCybersecurity researchers have flagged a fresh software supply chain attack campaign that has targeted multiple PHP packages belonging to Laravel-Lang to deliver a comprehensive credential-stealing framework. The affected packages include - laravel-lang/lang laravel-lang/http-sta…THEHACKERNEWS.COM
23 MayCharter Communications confirms data breach as hackers threaten leak of 42 million recordsCharter Communications has confirmed a cybersecurity incident after the ShinyHunters extortion group claimed it breached the telecommunications giant and stole data belonging to more than 42 million customers. The threat actor added Charter Communications to its leak site this we…CYBERINSIDER.COM
22 MayAuthorities Take Down “First VPN” Service Used in Ransomware AttacksAuthorities in Europe have dismantled a major criminal VPN service known as “First VPN,” which was widely used by ransomware operators and cybercriminal groups to conceal their activities. The coordinated operation, led by French and Dutch authorities with support from Eurojust a…GBHACKERS.COM
22 MayHackers Abuse Hugging Face to Deliver npm MalwareA newly uncovered supply chain attack targeting the npm ecosystem has been linked to North Korean (DPRK)-aligned threat actors. The campaign centers around a malicious npm package named terminal-logger-utils, which embeds a sophisticated multi-stage malware capable of keylogging,…GBHACKERS.COM
22 MayOperation Dragon Whistle Targets Changzhou University with Malicious LNK FilesA recent phishing campaign dubbed “Operation Dragon Whistle” highlights an evolving trend in cyberattacks: threat actors abusing legitimate developer tools and cloud services to maintain stealth and persistence. Although initially linked to targeting academic environments such as…GBHACKERS.COM
22 MayGoogle API Key Issue Allows Deleted Keys to Retain Access to Cloud ServicesGoogle Cloud API keys may continue functioning for up to 23 minutes after deletion, exposing a significant security gap that could allow attackers to retain unauthorized access to cloud services even after credentials are revoked. Google API Deleted Keys to Retain Access Security…GBHACKERS.COM
22 MayCloud Atlas activity in the second half of 2025 and early 2026: new tools and a new payloadThe experienced Cloud Atlas group remains active, continuing to target government sectors and diplomatic entities in Russia and Belarus, employing both new and established techniques to maintain persistence in compromised systems.SECURELIST.COM
22 MayKeepnet contributes voice and SMS phishing data to the 2026 Verizon DBIRKeepnet, an Extended Human Risk Management (xHRM) platform, today announced that its voice and SMS phishing simulation data contributed to the 2026 Verizon Data Breach Investigations Report (DBIR). The 2026 edition is the first to include voice and SMS phishing simulation data at…HELPNETSECURITY.COM
22 MayAI Alone Won’t Stop the Breach: Why Email Security Needs Humans-on-the-Loop2026 has officially become the year of speed, scale and support. The delta between a phishing email landing and a full organizational compromise has shrunk to mere seconds. KNOWBE4.COM
22 MayVerizon DBIR: Healthcare Fends Off Increased Social Engineering AttacksRansomware and vendor breaches persist, but the 2026 Data Breach Investigations Report (DBIR) highlights how evolving social engineering tactics make the sector more vulnerable.DARKREADING.COM
22 MayFast and Furious – Nimbus Manticore Operations During the Iranian ConflictKey Findings Introduction During the recent geopolitical tensions in the Middle East, we reported on multiple Iran-nexus threat actors advancing Iran’s strategic objectives through cyber operations. These activities included targeting internet-connected cameras, co…RESEARCH.CHECKPOINT.COM
22 MayKash Patel’s clothing brand website shut down after reports it was hackedAccording to users on X, the website was hijacked by hackers in an attempt to trick visitors into installing malware.TECHCRUNCH.COM
22 MayMcDonald’s France resets accounts after customer data breachMcDonald’s France has confirmed that attackers accessed customer loyalty account information after a breach affecting partners tied to its McDo+ rewards program. The incident led to widespread fraud in which stolen loyalty points were reportedly used to place unauthorized food or…CYBERINSIDER.COM
22 MayNetherlands seizes 800 servers of hosting firm enabling cyberattacksFinancial crime investigators in the Netherlands (FIOD) arrested two men and seized 800 servers linked to a web hosting company that enabled cyberattacks, interference operations, and disinformation campaigns. [...]BLEEPINGCOMPUTER.COM
22 MayFirst VPN Dismantled in Global Takedown Over Use by 25 Ransomware GroupsAuthorities in Europe and North America have announced the dismantling of a criminal virtual private network (VPN) service used by criminal actors to obscure the origins of ransomware attacks, data theft, scanning, and denial-of-service attacks. The disruption of First VPN Servic…THEHACKERNEWS.COM
21 MayGitHub Internal Repositories Breached via Malicious Nx Console VS Code ExtensionGitHub on Wednesday officially confirmed that the breach of its internal repositories was the result of a compromise of an employee device involving a poisoned version of the Nx Console Microsoft Visual Studio Code (VS Code) extension. The development comes as the Nx team r…THEHACKERNEWS.COM
21 MayDragonica Lunaris - 126,293 breached accountsIn December 2025, the European Dragonica private server Dragonica Lunaris suffered a data breach. The incident exposed 126k email addresses, usernames, dates of birth and bcrypt password hashes. The service operator confirmed the breach and advised it has since been fixed.HAVEIBEENPWNED.COM
21 MayGrafana Labs Says Code Breach Stemmed from TanStack AttackGrafana Labs has confirmed a recent data breach was caused by the TanStack supply chain attackINFOSECURITY-MAGAZINE.COM
21 MayGitHub, Grafana Labs breaches traced back to TanStack supply chain compromiseGitHub CISO Alexis Wales has named the malicious VS Code extension behind the breach they suffered at the hands of the threat group TeamPCP: Nx Console, a popular developer tool with 2.2 million installs. A malicious version of the otherwise benign extension was used to steal sec…HELPNETSECURITY.COM
21 MayGitHub Breach Traced to Malicious 'Nx Console' VS Code ExtensionA threat actor compromised an Nx developer and posed as a legitimate maintainer to publish a malicious extension on Visual Studio MarketplaceINFOSECURITY-MAGAZINE.COM
21 MayGrafana Labs links GitHub environment breach to TanStack npm supply chain attackThe company behind the widely used observability platform refused an extortion demand and has since taken steps to harden its security.CYBERSECURITYDIVE.COM
21 MayCybercriminal VPN Dismantled in Europol CrackdownFirst VPN, a service used by ransomware actors and fraudsters, was dismantled by EuropolINFOSECURITY-MAGAZINE.COM
21 MayDefenders fall behind, as AI rewrites the rules of a data breachFor almost 20 years, stolen credentials have been the most common route for attackers into organizations, according to the Verizon Data Breach Investigations Report (DBIR). But that's no longer the case. Read more in my article on the Fortra blog.FORTRA.COM
20 MayMicrosoft disrupts malware code-signing service used by ransomware gangsMicrosoft has disrupted the infrastructure powering the largest malware code-signing service used to help ransomware groups and other cybercriminals make malicious programs harder to detect on Windows. The threat actors behind the service used stolen identities and impersonated l…CSOONLINE.COM
20 MayWhat happens when your identity provider becomes the kill chainIn this Help Net Security video, Colin Constable, CTO at Atsign, explains why your identity provider (IdP) has become the kill chain in cyberattacks. Attackers steal session cookies, tokens, or consent grants you’ve already issued and walk in behind you. Constable breaks do…HELPNETSECURITY.COM
20 MayFBI warns students and staff that ShinyHunters may come knocking after Canvas breachHaving receive a ransom payment for its attack on Canvas, ShinyHunters and other extortion gangs are only likely to be further incentivised to launch similar attacks in future. Read more in my article on the Hot for Security blog.BITDEFENDER.COM
20 MayA malicious VS code extension just breached GitHub ‘s internal repositoriesOne employee installed a trojanized VS Code extension. Result: ~3,800 GitHub internal repositories exfiltrated. TeamPCP claims credit, wants $50K. There is something almost ironic about GitHub, the platform that hosts the code for most of the world’s software, getting breac…SECURITYAFFAIRS.COM
20 MayEncryption Consulting launches CertSecure Manager v3.3 with zero-touch certificate renewalsEncryption Consulting has released CertSecure Manager v3.3, which automates zero-touch certificate renewal across all major enterprise server platforms and extends CA support to 11 providers, including Google Public CA and AWS. Certificate-related outages can cost enterprises mil…HELPNETSECURITY.COM
20 MayGitHub Confirms Breach of Internal Repositories Via Malicious VS Code ExtensionThe prolific threat group TeamPCP has claimed a hack into GitHub’s internal repositoriesINFOSECURITY-MAGAZINE.COM
20 MayFox Tempest Linked to Malware-Signing Service Abusing Microsoft Artifact SigningFox Tempest, a financially motivated threat actor, has been linked to a large-scale malware-signing-as-a-service (MSaaS) operation that abused Microsoft’s Artefact Signing platform to enable cybercriminals to distribute malicious software that appeared to be trusted. According to…GBHACKERS.COM
20 MayMicrosoft Takes Down Malware-Signing Service Behind Ransomware AttacksMicrosoft on Tuesday said it disrupted a malware-signing-as-a-service (MSaaS) operation that weaponized the company's Artifact Signing system to deliver malicious code and conduct ransomware and other attacks, compromising thousands of machines and networks across the world. The …THEHACKERNEWS.COM
20 MayMicrosoft DurableTask Python Client Targeted in TeamPCP CyberattackThe ongoing TeamPCP software supply chain campaign has compromised the official Microsoft DurableTask Python client, a widely used package for orchestrating workflows in Python applications. Three versions of the durabletask package on PyPI, 1.4.1, 1.4.2, and 1.4.3, were identifi…GBHACKERS.COM
20 MayCustomers say Trump Mobile is leaking their personal informationTrump Mobile is leaking customers’ email and home addresses but has not responded to people alerting the company of the data exposure, according to two YouTubers who said they verified that their leaked data is authentic.TECHCRUNCH.COM
20 MayGitHub says hackers stole data from thousands of internal repositoriesThe code hosting giant GitHub said it was investigating a breach, but said there was no evidence of customer data theft.TECHCRUNCH.COM
20 MayGitHub discloses breach of 3,800 internal code repositories.Microsoft disrupts malware signing service. Business news: Akamai to acquire LayerX for $205 million.THECYBERWIRE.COM
20 May7-Eleven confirms breach after ShinyHunters claimsThe breach notification letters say 7-Eleven discovered the breach on April 8 and, after an investigation, determined that the cybercriminals gained access to “certain 7-Eleven systems used to store franchisee documents.”THERECORD.MEDIA
20 MayGitHub says internal repositories were impacted in poisoned VS Code extension attackGitHub said late Tuesday that internal repositories were exfiltrated after an employee device was compromised through a poisoned Visual Studio Code extension, an incident that underscores the growing risks facing software development platforms and the ecosystems built around thir…CYBERSCOOP.COM
20 May7-Eleven hit by data breachThe retailer confirmed that an unauthorized third party gained access to certain systems used to store franchisee documents earlier this spring.CYBERSECURITYDIVE.COM
20 MayMicrosoft disrupts cybercrime operation that hid behind legitimate softwareThe Fox Tempest malware-signing-as-a-service operation was linked to numerous ransomware attacks.CYBERSECURITYDIVE.COM
20 MayMeet Rampart and Clarity, Microsoft’s new red team combo AI agentsMicrosoft’s AI red team lead talked to CyberScoop about the goals behind open sourcing a pair of security tools meant for developers and incident responders. The post Meet Rampart and Clarity, Microsoft’s new red team combo AI agents appeared first on CyberScoop .CYBERSCOOP.COM
20 MayProcesses and Culture Top Reasons Behind Data BreachesGovernment leaders revealed that, in spite of state laws meant to improve cyber hygiene, an analysis of incidents showed issues persist and visibility falls short.DARKREADING.COM
20 MayInvestigating unauthorized access to GitHub’s internal repositoriesIf any impact is discovered, customers will be notified via established incident response and notification channels. The post Investigating unauthorized access to GitHub’s internal repositories appeared first on The GitHub Blog .GITHUB.BLOG
20 MayMini Shai Hulud: Compromised @antv npm packages enable CI/CD credential theftCompromised @antv npm packages deploy the Mini Shai-Hulud payload to steal CI/CD secrets from Linux-based automation environments. The malware executes during npm install and targets credentials across GitHub, AWS, Kubernetes, Vault, npm, and 1Password platforms. The post Mini Sh…MICROSOFT.COM
19 MayMini Shai-Hulud Pushes Malicious AntV npm Packages via Compromised Maintainer AccountCybersecurity researchers have discovered a fresh software supply chain attack campaign that has compromised various npm packages associated with the @antv ecosystem as part of the ongoing Mini Shai-Hulud attack wave. "The attack affects packages tied to the npm maintainer accoun…THEHACKERNEWS.COM
19 MayCompromised Nx Console VS Code Extension Steals Developer and Cloud SecretsNx Console’s popular VS Code extension was briefly weaponized into a credential-stealing tool that can leak developer and cloud secrets and plant a persistent backdoor. Anyone who installed v18.95.0 should treat their environment as fully compromised. On May 18, 2026, a malicious…GBHACKERS.COM
19 MayMini Shai-Hulud Attack Hits @antv npm PackagesA large-scale npm supply chain attack has compromised multiple widely used packages within the @antv ecosystem, to investigate what appears to be an active and rapidly evolving campaign linked to the Mini Shai-Hulud malware family. The attack centers on the compromise of the npm …GBHACKERS.COM
19 MayCompromised Nx Console 18.95.0 Targeted VS Code Developers with Credential StealerCybersecurity researchers have flagged a compromised version of the Nx Console extension that was published to the Microsoft Visual Studio Code (VS Code) Marketplace. The extension in question is rwl.angular-console (version 18.95.0), a popular user interface and plugin for code …THEHACKERNEWS.COM
19 MayGentlemen Ransomware Targets Windows, Linux, NAS, BSD, and ESXi SystemsThe Gentlemen ransomware operation has rapidly emerged as one of the most active and scalable cybercrime threats since its public appearance in the second half of 2025. The Gentlemen stands out for its ability to target a wide range of enterprise systems, including Windows, Linux…GBHACKERS.COM
19 MayPoland shifts away from Signal following cyberattacks on officials’ accountsPoland told officials to stop using the popular instant messaging app Signal after cyberattacks targeted government accounts. Poland has instructed government officials to stop using Signal for sensitive communications and move to a state-developed alternative. The decision follo…SECURITYAFFAIRS.COM
19 MayShinyHunters Takes Responsibility for Attack on Learning Management PlatformA cyberattack linked to the notorious threat group ShinyHunters has disrupted a widely used Learning Management System (LMS), impacting educational institutions and students across the United States. According to a Public Service Announcement (PSA) issued by the FBI on May 15, 20…GBHACKERS.COM
19 MayThe New Phishing Click: How OAuth Consent Bypasses MFAIn February 2026, a phishing-as-a-service (PhaaS) platform called EvilTokens went live. Within five weeks, it had compromised more than 340 Microsoft 365 organizations across five countries. The targets of the platform received a message asking them to enter a short code at…THEHACKERNEWS.COM
19 MayCyberheistNews Vol 16 #20 [Heads Up] Today You Have Only 60 Seconds to Stop That Breach. Are You Ready?KNOWBE4.COM
19 MayLooking Back, Looking Forward: Digesting a Dynamic Bouillabaisse of Cyber EvolutionDark Reading editors reflect on two decades of dramatic change — from perimeter defense to assume-breach strategies — and warn that while AI, cloud, and COVID-19 have transformed the threat landscape, organizations are still failing at fundamental security hygiene that could stop…DARKREADING.COM
19 MaySelector extends AI-driven observability into multi-cloud environmentsSelector has announced the expansion of its platform with AI-powered multi-cloud observability capabilities. The extension of Selector’s AI-driven observability approach into multi-cloud environments enables organizations to correlate signals across the full hybrid path. By…HELPNETSECURITY.COM
19 MayWhen AI Starts Acting MaliciousKeith Hoodlet defines AI misalignment through observable security behavior: agents taking actions that resemble malicious hacking activity even when they were not instructed to perform offensive tasks. In this example, the AI was given benign objectives but reacted to surrounding…YOUTUBE.COM
19 MayMicrosoft Takes Down Fox Tempest for Providing Ransomware-Enabling Signing ToolMicrosoft’s Digital Crimes Unit has taken down the infrastructure of Fox Tempest, a prolific cybercrime-enabling threat groupINFOSECURITY-MAGAZINE.COM
19 MayMicrosoft disrupts cybercrime service that abused software verification systems en masseFox Tempest, a financially-motivated threat group, allowed ransomware operators and other cybercriminals to slip malware-laced software past security controls. The post Microsoft disrupts cybercrime service that abused software verification systems en masse appeared first on Cybe…CYBERSCOOP.COM
19 MayBiometrics, diagnoses, and bank details exposed in major healthcare breachNYC Health + Hospitals says attackers accessed its systems for months through a third-party vendor compromise, affecting at least 1.8 million people.MALWAREBYTES.COM
19 MayMicrosoft disrupts Fox Tempest malware-signing-as-a-service platform tied to ransomware gangsThe company unsealed a legal case in U.S. District Court on Tuesday detailing the disruption of Fox Tempest — a popular service that has operated since May 2025 and provides cybercriminals with code signing tools.THERECORD.MEDIA
19 MayCIRT insights: How to help prevent unauthorized account removals from AWS OrganizationsThe AWS Customer Incident Response Team works with customers to help them recover from active security incidents. As part of this work, the team often uncovers new or trending tactics used by various threat actors that take advantage of specific customer configurations and design…AWS.AMAZON.COM
19 MayExposing Fox Tempest: A malware-signing service operationFox Tempest is a financially motivated threat actor operating a malware‑signing‑as‑a‑service (MSaaS) used by other cybercriminals, including Vanilla Tempest and Storm groups, to more effectively distribute malicious code, including ransomware. The post Exposing Fox Tempest: A mal…MICROSOFT.COM
18 MayWeekly Update 504Presently sponsored by: Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite It's a hot topic, the old "pay or don't pay" for hackers not to leak your data. Since recording this a few days ago…TROYHUNT.COM
18 MayGrafana Labs Confirms Security Incident Involving GitHub Codebase AccessGrafana Labs has confirmed a security incident involving unauthorized access to its internal GitHub environment, after a threat actor obtained a compromised access token and downloaded portions of the company’s codebase. The disclosure, made via an official statement on May 17, 2…GBHACKERS.COM
18 MayHackers Abuse Cloudflare Storage to Exfiltrate Network FilesA sophisticated cyber espionage campaign targeting multiple Malaysian organizations has been uncovered, revealing a highly structured attack chain that blends custom tooling, cloud infrastructure, and stealthy data exfiltration. At the center of the operation is an Azure virtual …GBHACKERS.COM
18 MayPaper Werewolf APT Spreads EchoGather RAT via Fake Adobe InstallerA sophisticated Russian-language threat cluster known as Paper Werewolf (also tracked as GOFFEE) has launched a fresh wave of targeted cyberattacks against Russian industrial, financial, and transport organizations between March and April 2026. The attack begins with a …GBHACKERS.COM
18 MayThe Canvas breach proved that prevention is no longer enoughCybercriminals brought down the most widely used learning platform in North America. The Canvas breach is a blueprint for how SaaS attacks now work — and a warning about how unprepared most organizations still are. The post The Canvas breach proved that prevention is no longer en…CYBERSCOOP.COM
18 MayNYC Health and Hospitals says hackers stole medical data and fingerprints during breach affecting at least 1.8 million peopleThe New York public healthcare system said hackers stole personal and medical data, and scans of biometrics — including fingerprints — in one of the largest recorded breaches of 2026.TECHCRUNCH.COM
18 MayFuel Tank Breaches Expand Scope of Iran's Cyber OffensiveSecurity experts have long warned that insecure automatic tank gauge (ATG) systems exposed on the Internet can be tampered with by threat actors.DARKREADING.COM
18 MayGrafana refuses to pay ransom after codebase theftOn Saturday night, the company released a statement confirming the incident and outlining their decision not to pay a ransom issued by the hackers behind the attack.THERECORD.MEDIA
18 MayMore than 200 arrested in cyber raids aimed at Middle East scam networksInvestigators found hundreds of compromised devices that were used as part of the cybercriminal operation and notified device owners as part of the raids.THERECORD.MEDIA
18 MayAddi - 34,532,941 breached accountsIn March 2026, the Colombian fintech company Addi identified unauthorised activity on its platform and advised customers that "it is possible that your personal information may have been compromised". The "pay or leak" extortion group ShinyHunters subsequently claimed responsibil…HAVEIBEENPWNED.COM
16 MayCybercriminal Twins Caught After They Forgot to Turn Off Microsoft Teams RecordingPlus: Instructure’s Canvas ransomware debacle comes to a close, an alleged dark net market kingpin gets arrested, OpenAI workers fall victim to a supply chain attack, and more.WIRED.COM
16 MayRussian APT Turla builds long-term access tool with Kazuar Botnet evolutionRussia-linked APT group Turla turned its Kazuar malware into a stealthy P2P botnet for long-term access to compromised systems. Russia-linked APT group Turla upgraded its Kazuar backdoor into a modular peer-to-peer botnet designed for stealth and persistent access to infected sys…SECURITYAFFAIRS.COM
15 MayTaiwan Incident Highlights Cybersecurity Gaps in Rail SystemsA Taiwanese student experimenting with software-defined radio technology shut down three bullet trains for nearly an hour, leading to an anti-terrorism response.DARKREADING.COM
15 MayWindows 11 and NVIDIA hacked on the first day of Pwn2Own Berlin 2026Researchers earned more than half a million dollars on the opening day of Pwn2Own Berlin 2026 after successfully demonstrating 24 previously unknown vulnerabilities across AI platforms, NVIDIA software, Windows 11, Linux systems, and developer tools. The first day of the hacking …CYBERINSIDER.COM
15 MayOpenAI confirms exposure in recent ‘Shai-Hulud’ supply-chain attackOpenAI says a recent software supply-chain attack tied to the “Mini Shai-Hulud” malware campaign impacted two employee devices and exposed limited internal credentials, prompting the company to rotate code-signing certificates for its desktop applications. The company said it fou…CYBERINSIDER.COM
15 MayInside The Gentlemen Ransomware Leak: When the Hunter Becomes the HuntedInside The Gentlemen Ransomware Leak: When the Hunter Becomes the Hunted Ransomware groups spend their days breaking into networks, stealing data, and pressuring victims into paying. They rarely find themselves on the other side of that equation. But in early May 2026, one of the…SOCRADAR.IO
15 MayGunra Ransomware Expands RaaS After Conti Locker ShiftGunra ransomware is rapidly evolving into a more structured and dangerous cybercrime operation after shifting from a Conti-based locker to its own Ransomware-as-a-Service (RaaS) model. First discovered in April 2025, the group initially targeted a small number of victims, but its…GBHACKERS.COM
15 MayAttackers replaced JDownloader installer downloads with malwareThe JDownloader website was compromised and installer download links served malware for several days.MALWAREBYTES.COM
15 MayMore than $10 million stolen from crypto platform THORChainTHORChain officials said the investigation into the incident is ongoing but explained that one of their six vaults was compromised, leading to a loss of about $10.7 million.THERECORD.MEDIA
15 MayYour NPM Package Is Stealing SecretsMalicious versions of the Node IPC NPM package contained heavily obfuscated payloads designed to steal developer and cloud credentials. The malware targeted AWS, Azure, GCP, GitHub, Kubernetes, Terraform, SSH keys, and dozens of other secret categories while disguising outbound t…YOUTUBE.COM
14 MayWelcoming the Bahamian Government to Have I Been PwnedPresently sponsored by: Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite Today, we welcome the 44th government onboarded to Have I Been Pwned’s free gov service: The Bahamas. The National Computer Inci…TROYHUNT.COM
14 MayWhen ransomware gets physical: cybercriminals turn to threats of violencePay up, or we'll pay someone to pay you a visit. Cybercrime gangs are increasingly turning to real-world threats - and even hiring local muscle to deliver the message. Read more in my article on the Hot for Security blog.BITDEFENDER.COM
14 MayFamousSparrow targets Azerbaijani energy sector in multi-wave espionage campaignChinese-linked FamousSparrow repeatedly targeted an Azerbaijani oil and gas company, reusing the same entry point in three intrusions from Dec 2025 to Feb 2026. Chinese-linked threat actor FamousSparrow has conducted a sustained intrusion campaign against an Azerbaijani oil and g…SECURITYAFFAIRS.COM
14 MayNitrogen Ransomware claims massive data theft from FoxconnFoxconn confirmed a cyberattack on some North American factories. The Nitrogen ransomware group claims it stole 8TB of data from the firm. Foxconn confirmed that several of its North American factories were affected by a cyberattack. The manufacturer confirmed it was targeted by …SECURITYAFFAIRS.COM
14 MayBreachForums & TeamPCP Promote Supply Chain Competition as Cybercrime Gets GamifiedBreachForums & TeamPCP Promote Supply Chain Competition as Cybercrime Gets Gamified Underground cybercrime communities are increasingly borrowing ideas from legitimate tech ecosystems: branding, public challenges, shared tools, reputation building, and even prize-based compet…SOCRADAR.IO
14 MayMicrosoft Research: AI Can Generate Realistic Command-Line and Process TelemetryA new approach showing how artificial intelligence can generate highly realistic command-line data and process telemetry potentially transforming how security teams build and test threat detection systems. Logs and telemetry form modern cybersecurity risk, powering threat detecti…GBHACKERS.COM
14 MayLATAM Under Siege: Agent Tesla’s 18-Month Credential Theft Campaign Against Chilean EnterprisesCredential theft malware rarely announces itself with ransomware-level noise. Instead, it operates like a silent siphon hidden inside everyday business workflows: invoices, payroll files, purchase orders, procurement requests. Agent Tesla campaigns are especia…ANY.RUN
14 MayFoxconn Attack Highlights Manufacturing's Cyber CrisisA Nitrogen ransomware attack on Foxconn's North American facilities is one of 600 hits on manufacturers this year, as gangs increasingly target the sector for its low tolerance for downtime.DARKREADING.COM
14 MayTop 5 Surface Web Hacker Forums in 2026Top 5 Hacker Forums on the Surface Web Security teams often associate cybercrime forums exclusively with the Dark Web and Tor. However, several of the most active underground communities now operate openly on the surface web, accessible via standard browsers and indexed infrastru…SOCRADAR.IO
14 MaySandworm Hackers Shift From IT Breaches to Critical OT TargetsA new wave of cyber activity linked to the notorious Sandworm group is raising fresh alarms across global critical infrastructure. Security researchers warn that the Russian state-backed threat actor is no longer just infiltrating IT networks it is actively pivoting into operatio…GBHACKERS.COM
14 MayLABScon25 Replay | Breach Alpha: Trading on Cyber FalloutMick Baccio and Scott Roberts examine whether public breach signals and market timing models can turn cyber incidents into actionable trading opportunities.SENTINELONE.COM
14 MayWhen Nobody Reports the ThreatSecurity teams often depend on users or employees to report suspicious behavior, anomalies, or identity-related issues. But humans naturally assume another person will step in first. That creates a dangerous reporting gap. If everyone ignores unusual activity because they expect …YOUTUBE.COM
14 MayMajor tech manufacturer Foxconn confirms cyberattack hit North American factoriesThe ransomware group Nitrogen claimed responsibility for the attack and said it stole 8 terabytes of data spanning more than 11 million files belonging to the company’s top customers. The post Major tech manufacturer Foxconn confirms cyberattack hit North American factories appea…CYBERSCOOP.COM
14 MayWest Pharmaceutical starts restoring operations after ransomware attackThe company confirmed data was stolen and encrypted by the attackers.CYBERSECURITYDIVE.COM
14 MayFighting AI-Assisted Ransomware ThreatsThis Anti-Ransomware Day, it's important to recognize the ever-changing landscape of cyber threats and how organizations can fortify their defenses. The evolution from traditional ransomware to cyber extortion over the last few years reflects a professionalized, decentralized eco…KNOWBE4.COM
13 MayGemStuffer Abuses 150+ RubyGems to Exfiltrate Scraped U.K. Council Portal DataCybersecurity researchers are calling attention to a new campaign dubbed GemStuffer that has targeted the RubyGems repository with more than 150 gems that use the registry as a data exfiltration channel rather than for malware distribution. "The packages do not appear designed fo…THEHACKERNEWS.COM
13 MayRansomware Gangs Use BYOVD and EDR Killers to Disable Security ToolsRansomware is evolving faster than many defenses can keep up. In 2026, attackers are no longer just encrypting files they are systematically dismantling security tools, stealing sensitive data, and even preparing for a post-quantum future. Despite a slight global decline in ranso…GBHACKERS.COM
13 MayInfostealer Malware Fuels Corporate Breaches From Personal DevicesInfostealer malware is no longer just a consumer nuisance it has become a direct bridge between personal device infections and full-scale enterprise breaches. Once these credentials are harvested and posted on dark web forums, attackers gain immediate footholds into corporate env…GBHACKERS.COM
13 MayQ1 2026 Ransomware Attacks Hits 2,122 Orgs Amid Fewer, More Impactful GroupsRansomware activity remained elevated in Q1 2026, continuing the trend established over the past year. The latest State of Ransomware Q1 2026 report reveals that 2,122 organizations were listed on ransomware data leak sites (DLS), marking the second-highest Q1 total on record. Wh…GBHACKERS.COM
13 MayCanada Life - 237,810 breached accountsIn April 2026, Canada Life was the victim of a "pay or leak" extortion campaign by the ShinyHunters group . The group subsequently published the data which contained over 200k unique email addresses along with names, phone numbers, physical addresses and, in some cases, customer …HAVEIBEENPWNED.COM
13 MayOptimize Legal Operations as the CISO Role Changes to Address Skills Gaps and AI - BSW #447Legal departments are under continual pressure to solve problems effectively and integrate innovative technology all while reducing costs and complexity. Enter cybersecurity, a complex and potentially costly risk. How should legal departments prepare? Walter Wilkens, Head of Deli…YOUTUBE.COM
13 MayNew SOC-Ready Reporting for Faster Triage, Escalation, and Incident Response with ANY.RUNSuccessful SOC operations require more than accurate detections. Instant access to context, clear conclusions, and operationally relevant insights allow incidents to move across workflows without delays: Making ANY.RUN’…ANY.RUN
13 MayInstructure settles with hackers following massive student data theftEducational tech firm Instructure reached a deal with hackers after a major Canvas breach exposed data stolen from schools and universities. Educational tech firm Instructure says it reached an agreement with the cybercrime group behind a major Canvas data theft, after attackers …SECURITYAFFAIRS.COM
13 MayRansomware: Over Half of CISOs Would Consider Paying Ransom to HackersSurvey of cybersecurity leaders suggests that majority would strongly consider paying cybercriminals, if that’s what it took to help restore encrypted systemsINFOSECURITY-MAGAZINE.COM
13 MayCanvas owner reaches ‘agreement’ with threat actors after data breachCybersecurity experts suggest that Instructure appears to have made a ransomware payment, which the FBI highly discourages.CYBERSECURITYDIVE.COM
13 MayThus Spoke…The GentlemenKey Points Introduction The Gentlemen ransomware‑as‑a‑service (RaaS) operation is a relatively new group that emerged around mid‑2025. Its operators advertise the service across multiple underground forums, promoting their ransomware platform and inviting penetration testers and …RESEARCH.CHECKPOINT.COM
13 MayTuskira’s Kairo exposes hidden AI-driven breach pathsTuskira has announced the launch of Kairo, a breach modeling capability that detects deep, hidden breach paths by leveraging its security data mesh and digital twin technology. Kairo helps security teams improve breach resilience by modeling how attackers can leverage new AI mode…HELPNETSECURITY.COM
13 MayUS lawmakers demand answers from Instructure after Canvas data breachesU.S. House lawmakers want to know how hackers broke into education tech giant Instructure twice, and stole reams of data from students who use the company's flagship student data software Canvas.TECHCRUNCH.COM
13 MayThe Real Work Starts After BreachAfter a cyberattack, the first priority is containment and forensic analysis. But according to Walter Wilkens, another major phase begins immediately after: data mining the breached environment to determine what sensitive information was exposed. That includes identifying PII (pe…YOUTUBE.COM
13 MayCanvas Owner Reaches Agreement With Cybercriminals After Ransomware AttackInstructure says it reached an agreement with ShinyHunters over the Canvas breach dataINFOSECURITY-MAGAZINE.COM
13 MayRansomware hackers claim breach at Foxconn, a major electronics manufacturer for Apple, Google, and NvidiaA ransomware group has claimed responsibility for hacking the electronics manufacturing giant Foxconn, and is attempting to extort the company.TECHCRUNCH.COM
13 MayHackers Claim 11M Files Stolen From Foxconn, Supplier to Apple and NvidiaFoxconn confirmed a North American cyberattack after Nitrogen claimed it had stolen 11M files tied to major tech customer projects. The post Hackers Claim 11M Files Stolen From Foxconn, Supplier to Apple and Nvidia appeared first on TechRepublic .TECHREPUBLIC.COM
13 MayCanvas Breach Hackers Reach Deal After Claiming 275M Records StolenInstructure reached a deal with the Canvas hackers after they claimed to have stolen data tied to nearly 9,000 schools and 275 million people. The post Canvas Breach Hackers Reach Deal After Claiming 275M Records Stolen appeared first on TechRepublic .TECHREPUBLIC.COM
13 MayGoogle Enhances Android Mobile Security with New AI-powered ProtectionsMobile devices have become ground zero for a ruthless wave of cyberattacks, with invisible threat actors draining bank accounts and hijacking digital identities before victims even realize they’ve been compromised. Now, Google is striking back with a massive counteroffensiv…GBHACKERS.COM
13 MayFoxconn confirms cyberattack affecting some North American facilitiesA ransomware group has claimed a major attack against the electronics manufacturer.CYBERSECURITYDIVE.COM
13 MayStudent Messages Were the Real TargetMost breach headlines focus on passwords, credit cards, or government IDs. This breach hit somewhere more personal. Attackers reportedly breached Canvas — a learning platform used across colleges and universities — and may have accessed billions of private inbox messages exchange…YOUTUBE.COM
13 MayOpenLoop Health confirms January 2026 Data breach affecting 716,000In January 2026, telehealth infrastructure firm OpenLoop Health suffered a security breach that exposed information of 716,000 people. OpenLoop Health confirmed a January 2026 cyberattack that exposed personal information of 716,000 individuals using its telehealth services. The …SECURITYAFFAIRS.COM
13 MaySmashing Security podcast #467: How ShinyHunters hacked the world’s biggest universitiesWelcome to the largest educational data breach in history - affecting nearly 9,000 institutions, every Ivy League university, and 30 million students mid-finals. When Canvas's parent company refused to pay and announced they had deployed "security patches" instead, the hackers we…GRAHAMCLULEY.COM
12 MayCheckmarx Jenkins AST Plugin Compromised in KICS Supply Chain AttackSupply chain campaign has now extended to Checkmarx’s Jenkins ecosystem, with attackers pushing a malicious Checkmarx Jenkins AST plugin to the official Jenkins Marketplace as part of the ongoing KICS/Trivy-linked compromise. The rogue release is identified as version 2026.5.09 a…GBHACKERS.COM
12 May84 npm Packages Linked to TanStack Hit by Supply-Chain BreachA massive supply chain breach affecting 84 npm packages within the widely used TanStack ecosystem. Malicious actors compromised these packages by injecting a sophisticated credential-stealing tool designed to target continuous integration environments such as GitHub Actions. Pack…GBHACKERS.COM
12 MayInstructure Reaches Ransom Agreement with ShinyHunters to Stop 3.65TB Canvas LeakAmerican educational technology company Instructure, the parent company of Canvas, said it reached an "agreement" with a decentralized cybercrime extortion group after it breached its network and threatened to leak stolen information from thousands of schools and universities. In…THEHACKERNEWS.COM
12 MayState of ransomware in 2026Kaspersky researchers are sharing insights into the main ransomware trends for 2026: EDR killers on the rise, switching from data encryption to data leaks, and more.SECURELIST.COM
12 MayMicrosoft Warns: MistralAI PyPI Package Compromised with MalwareMistral’s official Python client on PyPI has been pulled into the ongoing wave of AI supply‑chain attacks, with Microsoft warning that version 2.4.6 of the mistralai package was backdoored to silently deploy a credential‑stealing payload on Linux systems. The logic is designed to…GBHACKERS.COM
12 MayStolen Canvas data was “returned” after hacker agreement, Instructure saysInstructure says the stolen Canvas data impacting millions of students and staff was “returned.” That’s not how breaches work.MALWAREBYTES.COM
12 MaySouth Staffordshire Water Fined £1m After Data BreachThe ICO has fined South Staffordshire Water nearly £1m for a series of data protection failingsINFOSECURITY-MAGAZINE.COM
12 MayCushman & Wakefield - 310,431 breached accountsIn May 2026, the real estate services firm Cushman & Wakefield was the target of a "pay or leak" extortion campaign by the ShinyHunters group . Following the threat, the group publicly published data they alleged had been obtained from the firm, consisting mostly of C&W email…HAVEIBEENPWNED.COM
12 MayState-sponsored actors, better known as the friends you don’t wantResponding to a state-sponsored threat is nothing like responding to ransomware, and the differences can make or break the outcome. Learn why your IR plan might need revisiting, and the factors you should consider.TALOSINTELLIGENCE.COM
12 MayNew ‘Shai-Hulud’ attack breached hundreds of npm and PyPI packagesA rapidly expanding supply-chain attack tied to the “Mini Shai-Hulud” malware campaign has compromised more than 400 package artifacts across npm, PyPI, and Composer repositories. The breached projects include widely used libraries from TanStack, Mistral AI, UiPath, OpenSearch, a…CYBERINSIDER.COM
12 MayHackers Hijack Microsoft Teams Accounts to Spread ModeloRAT MalwareHackers are now abusing hijacked Microsoft Teams accounts and fake IT helpdesk chats to push a new, undocumented version of the Python‑based ModeloRAT into corporate environments. Instead, they use compromised or newly created Microsoft Teams accounts that impersonate internal IT…GBHACKERS.COM
12 MayANY.RUN & Elastic Security: Bring Threat Intelligence into Detection and Investigation WorkflowsSecurity teams don’t lack data. They lack timely, usable intelligence. Analysts spend too much time validating indicators, switching between tools, and figuring out what actually matters. This introduces delays and puts organizations at risk of a mis…ANY.RUN
12 MayCushman and Wakefield Confirms Data Breach Impacting Over 310,000 AccountsGlobal real estate powerhouse Cushman & Wakefield is the latest casualty in an escalating war of corporate extortion. Following a tense “pay or leak” standoff, the notorious ShinyHunters threat syndicate has carried out its threat, dumping hundreds of thousands of…GBHACKERS.COM
12 MayInstructure strikes deal with hackers who breached it twiceThe maker of the Canvas school software said it "reached an agreement" with the hackers, but provided no guarantees that the hackers would not release the data or keep their word.TECHCRUNCH.COM
12 MayInstructure pays ransom after Canvas incident as Congress announces investigationThe company said its agreement with the hackers involved their data being “returned” to them and digital confirmation of data destruction.THERECORD.MEDIA
12 MayCanvas owner reaches agreement with ShinyHunters, says user data was deletedInstructure says it reached an agreement with the threat actors behind the recent cyberattack targeting its Canvas learning platform. The company stated that stolen data was returned and that the attackers provided “digital confirmation of data destruction.” The attack was previo…CYBERINSIDER.COM
12 MayInstructure took a risky approach to recover stolen Canvas dataInstructure, the company behind the online learning platform Canvas, said it reached an agreement with the extortion group ShinyHunters to prevent data stolen in a recent breach from being leaked online. According to the company’s website, Canvas has more than 30 million active u…HELPNETSECURITY.COM
12 MayIdentity takes center stage as a leading factor in enterprise cyberattacksA new report shows two-thirds of ransomware attacks began with an identity-related breach.CYBERSECURITYDIVE.COM
12 MayHugging Face Packages Weaponized With a Single File TweakA tokenizer library file present in Hugging Face AI models can be manipulated to hijack the model's outputs and exfiltrate data.DARKREADING.COM
12 MayReport: Most Phishing Attacks Abuse Trusted ServicesPhishing attacks are increasingly abusing trusted services to evade security filters, according to VIPRE’s Email Threat Trends Report for Q1 2026. The two primary methods of delivery were compromised accounts at 33% and free email services 32%. Additionally, just under 90% of att…KNOWBE4.COM
12 MayWest Pharmaceutical warns of ransomware attack impacting business operationsWest Pharmaceutical Services filed a report with the Securities and Exchange Commission (SEC) on Monday evening warning customers that a hacker breached the company network on May 4, stole data and encrypted systems.THERECORD.MEDIA
12 MayFoxconn confirms cyberattack impacting North American factoriesA spokesperson for the company confirmed the incident but declined to provide specifics on how many factories in North America were impacted. Foxconn has factories in Wisconsin, Ohio, Texas, Virginia, Indiana and several across Mexico.THERECORD.MEDIA
12 MayFoxconn Ransomware Attack Shows Nothing Is Safe ForeverFamous for helping build Apple's iPhones, Foxconn just suffered another cyberattack, highlighting the perils of warehousing some of the world's most valuable data.WIRED.COM
12 MayMini Shai-Hulud Strikes Again: TanStack + more npm Packages CompromisedDetect and mitigate malicious npm packages linked to the latest Mini Shai-Hulud supply chain campaign targeting high-value developer tooling.WIZ.IO
11 MayWelcoming the Costa Rican Government to Have I Been PwnedPresently sponsored by: Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite Today, we welcome the 42nd government onboarded to Have I Been Pwned’s free gov service: Costa Rica. The CSIRT of the Government…TROYHUNT.COM
11 MayWeaponized JPEG file Drops Trojanized ScreenConnect MalwareHackers are abusing a weaponized JPEG file to quietly install a trojanized version of the ConnectWise ScreenConnect remote‑access tool on Windows systems, enabling full surveillance, credential theft, and long‑term control over compromised networks. The campaign shows how a simpl…GBHACKERS.COM
11 MayZara Data Breach Impacts Nearly 200,000 CustomersShinyHunters gets away with emails and other data on 200,000 Zara customersINFOSECURITY-MAGAZINE.COM
11 MayThe State of Ransomware – Q1 2026Key Findings Ransomware in Q1 2026: Consolidation at Scale During the first quarter of 2026, we monitored more than 70 active data leak sites (DLS) that collectively listed 2,122 new victims. This figure represents a 12.2% decline from the Q4 2025 all-time record of 2,416 victims…RESEARCH.CHECKPOINT.COM
11 MayShinyHunters Escalates Canvas Extortion with School by School Ransom CampaignShinyHunters has escalated its Canvas extortion campaign, defacing hundreds of school login pages and threatening to leak stolen data unless institutions negotiateINFOSECURITY-MAGAZINE.COM
11 MayUK water company allowed hackers to lurk undetected for nearly two years, regulator findsThe Information Commissioner's Office (ICO) fined South Staffordshire Water £963,900 ($1.3 million) on Monday over an attack by the Cl0p ransomware group that led to the personal data of 633,887 customers and employees being published in August 2022.THERECORD.MEDIA
11 May11th May – Threat Intelligence ReportFor the latest discoveries in cyber research for the week of 11th May, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Instructure, the US education technology company behind the Canvas learning platform, has confirmed a major data breach affecting its …RESEARCH.CHECKPOINT.COM
11 MayCyber Espionage Group Targets Aviation Firms to Steal Map DataThe campaign quietly compromises aerospace and drone operators to exfiltrate GIS files, terrain models, and GPS data and gain a clear picture of adversaries' world view.DARKREADING.COM
11 MayA 2nd Canvas data breach causes major disruptions for schools, collegesThe Instructure-owned learning management system went offline on May 7 after a threat actor once again gained unauthorized access.CYBERSECURITYDIVE.COM
11 MayPoor security left hackers inside water company network for nearly two yearsThe UK’s data protection regulator, the Information Commissioner’s Office (ICO), fined South Staffordshire Water’s parent company £963,900 over security failures linked to a cyberattack that exposed the personal data of 633,887 people. According to the ICO, the South Staffordshir…HELPNETSECURITY.COM
11 MayZimperium Mobile App Response Agent helps security teams counter mobile attacksZimperium launched Mobile App Response Agent, enabling security teams to respond faster than ever before to fraud and security threats. Leveraging Zimperium’s expertise in mobile security, Mobile App Response Agent is part of Zimperium’s Mobile App Protection Suite (MAPS), empowe…HELPNETSECURITY.COM
11 MayWelcoming the Bangladesh Government to Have I Been PwnedPresently sponsored by: Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite Today, we welcome the 43rd government onboarded to Have I Been Pwned's free gov service, Bangladesh. The BGD e-GOV CIRT department…TROYHUNT.COM
10 MayCyberWire Daily at 10: The evolution of geopolitics and warfare.In this special edition of CyberWire Daily’s 10th anniversary series, N2K CyberWire's Maria Varmazis and Dave Bittner discuss cybersecurity geopolitics and warfare that have been in the news over the past 10 years. Our conversation treks around the globe beginning with the su…THECYBERWIRE.COM
10 MaySecurity Affairs newsletter Round 576 by Pierluigi Paganini – INTERNATIONAL EDITIONA new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including the international press. Quasar Linux RAT (QLNX): A Fi…SECURITYAFFAIRS.COM
10 MayWeekly Update 503Presently sponsored by: Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite Well, it's the day before the Instructure "pay or leak" deadline (at least by my Aussie watch), and the company remains …TROYHUNT.COM
9 MayBraintrust security incident raises concerns over AI supply chain risksBraintrust warned customers to rotate API keys after hackers breached an AWS account, exposing secrets tied to cloud-based AI models. AI observability startup Braintrust warned customers to rotate API keys after attackers gained unauthorized access to one of the company’s AWS acc…SECURITYAFFAIRS.COM
8 MayCanvas Breach Disrupts Schools & Colleges NationwideAn ongoing data extortion attack targeting the widely-used education technology platform Canvas disrupted classes and coursework at school districts and universities across the United States today, after a cybercrime group defaced the service's login page with a ransom demand tha…KREBSONSECURITY.COM
8 MayThe Canvas Hack Is a New Kind of Ransomware DebacleThousands of schools around the US were paralyzed on Thursday after education tech firm Instructure shut down access to its Canvas platform following a breach by hackers going by the name ShinyHunters.WIRED.COM
8 MayHackers Use Morse Code to Trick Grok and Bankrbot, Steal $200K in Crypto TokensThreat actors have successfully executed a novel prompt injection attack against artificial intelligence agents, draining approximately $200,000 in cryptocurrency. By using Morse code to bypass standard AI safety filters, an attacker tricked the Grok AI model and an autonomous wa…GBHACKERS.COM
8 MayZara - 197,376 breached accountsIn April 2026, the fashion brand Zara was among a number of organisations targeted by the ShinyHunters extortion group as part of their "pay or leak" campaign. The group claimed the breach was related to a compromise of the Anodot analytics platform and subsequently published a t…HAVEIBEENPWNED.COM
8 MayPCPJack Campaign Boots TeamPCP Off Compromised MachinesSentinelOne believes the PCPJack campaign may be the brainchild of a former TeamPCP memberINFOSECURITY-MAGAZINE.COM
8 MayCanvas outage hits thousands of universities as ShinyHunters threatens leakA major outage impacting Canvas, one of the world’s most widely used learning management systems, disrupted universities and school districts across the United States and worldwide. The disruption came after threat actors linked to the ShinyHunters extortion group breached the pa…CYBERINSIDER.COM
8 MayAvantra’s new AI can diagnose SAP failures in secondsAvantra launched Avantra 26, an advancement in AI-driven operations, strengthening native integration with SAP Cloud ALM, and delivering automated visibility across SAP Business Technology Platform (BTP). Avantra also announced Avantra AIR Root Cause Analyzer, an AI-powered intel…HELPNETSECURITY.COM
8 MayFormer IT contractor convicted for wiping 96 US government databasesA federal jury has convicted a Virginia man for his role in a retaliatory cyberattack that wiped dozens of US government databases after he and his twin brother were fired from a federal contractor in 2025. Prosecutors said the attack affected systems used by more than 45 federal…CYBERINSIDER.COM
8 MayMicrosoft says Edge’s plaintext password behavior is “by design”A researcher found Edge loads saved passwords into computer memory when it starts, making them easier to steal if a device is already compromised.MALWAREBYTES.COM
8 MayYou Have 60 Seconds to Stop the Breach. Are You Ready?2026 has officially become the year of speed, scale and support The delta between a phishing email landing and a full organizational compromise has shrunk to mere seconds.KNOWBE4.COM
8 MayPro-Ukraine BO Team and Head Mare hackers appear to team up in attacks against RussiaResearchers at Moscow-based cybersecurity firm Kaspersky said they identified overlapping infrastructure and tools used by both groups — including command-and-control systems operating on the same compromised host — suggesting some coordination.THERECORD.MEDIA
8 MayShinyHunters claims nearly 9,000 schools affected by Canvas data breachThe group that stole data from Instructure users claims that it will release the data of students from nearly 9,000 education institutions around the country. The post ShinyHunters claims nearly 9,000 schools affected by Canvas data breach appeared first on CyberScoop .EDSCOOP.COM
8 MayInstructure confirms cybersecurity incidentThe ed tech company that operates Canvas said information impacted by the data breach includes messages, names, email addresses and student ID numbers.CYBERSECURITYDIVE.COM
8 MayAnthropic’s Claude used in attempted compromise of Mexican water utilityResearchers warn the incident highlights how AI tools can help untrained threat actors develop complex cyberattack capabilities.CYBERSECURITYDIVE.COM
8 MayZara Data Breach: 197,000 Customers Exposed in Third-Party Security IncidentNearly 200,000 Zara customers were exposed in a third-party breach linked to ShinyHunters, revealing emails, purchase history, and support data. Personal data belonging to nearly 197,000 Zara customers has been compromised following a cyberattack on a former technology provider u…SECURITYAFFAIRS.COM
8 MayPoland says hackers breached water treatment plants, and the U.S. is facing the same threatA report by Poland’s top intelligence agency accused Russia of sabotage and hacking activities against the country’s military and civilian infrastructure.TECHCRUNCH.COM
8 MayCyberattacks on Poland’s Water Plants: A Blueprint for Hybrid WarfarePoland’s ABW confirmed hackers breached ICS at five water plants, gaining ability to alter equipment settings. Russia-linked APT groups suspected. Poland’s Internal Security Agency (ABW) has published a detailed account of a sustained campaign targeting the country’s water …SECURITYAFFAIRS.COM
8 MayRansomHouse says it breached Trellix and exposes internal systemsRansomHouse claimed responsibility for the Trellix breach, adding the security firm to its Tor data leak site and sharing screenshots of internal systems. The RansomHouse ransomware group has claimed responsibility for the recent cyberattack on cybersecurity firm Trellix. To supp…SECURITYAFFAIRS.COM
8 MayDevelopers Are the New TargetA Linux RAT known as Quasar is reportedly targeting developers instead of end users. The malware focuses on stealing Git credentials, NPM tokens, PyPI credentials, and other secrets tied to software repositories. Once attackers gain access to developer accounts, they may be able …YOUTUBE.COM
7 MayWoflow - 447,593 breached accountsIn March 2026, the AI-driven merchant data platform Woflow was named as a victim by the ShinyHunters data extortion group . The group subsequently published tens of thousands of files allegedly obtained from the company, comprising more than 2TB of data. The trove included hundre…HAVEIBEENPWNED.COM
7 MayDay Zero Readiness: The Operational Gaps That Break Incident ResponseHaving an incident response retainer, or even a pre-approved external incident response firm, is not the same as being ready for an incident. A retainer means someone will answer the phone. Operational readiness determines whether that team can do meaningful work the moment they …THEHACKERNEWS.COM
7 MayPolish intelligence warns hackers attacked water treatment control systemsThe agency did not publicly attribute the incidents to a specific group or country but said Poland faced intensified hostile cyber activity in 2024 and 2025, “with particular emphasis on the special services of the Russian Federation.”THERECORD.MEDIA
7 MayWorld's First AI-Driven Cyberattack Couldn't Breach OT SystemsThe most sophisticated AI-integrated campaign to date hit a brick wall in the form of a SCADA login screen.DARKREADING.COM
7 MayOne Click, Total Shutdown: The "Patient Zero" Webinar on Killing Stealth BreachesThe hardest part of cybersecurity isn't the technology, it’s the people. Every major breach you’ve read about lately usually starts the same way: one employee, one clever email, and one "Patient Zero" infection. In 2026, hackers are using AI to make these "first clicks" nearly im…THEHACKERNEWS.COM
7 MayNorth Carolina man pleads guilty to doxxing Supreme Court justicesThe incident underscores the dangers public officials face from doxxing, as well as how easy it has become to find sensitive information online.THERECORD.MEDIA
7 MayHackers hack victims hacked by other hackersAn unknown group of hackers is breaking into systems previously breached by the cybercrime group TeamPCP. Once inside, the hackers immediately kick out TeamPCP and remove its hacking tools from the victims’ systems.TECHCRUNCH.COM
7 MayUnplug your way to better codeCybersecurity concepts — logs, packets, DNS exfiltration, and more — are usually intangible, and its practitioners are prone to mental fatigue, Amy takes a second to yell at you to go touch grass.TALOSINTELLIGENCE.COM
7 May“ClaudeBleed” allows any Chrome extension to control Anthropic’s AI assistantA critical flaw in Anthropic’s “Claude in Chrome” browser extension allows any Chrome extension, even one with zero permissions, to hijack Claude’s AI capabilities and perform sensitive actions on behalf of users. The issue, discovered by LayerX and dubbed “ClaudeBleed,” could en…CYBERINSIDER.COM
7 MayHackers deface school login pages after claiming another Instructure hackThe cybercrime group ShinyHunters claimed to have hacked Instructure again, defacing the login pages of several Instructure customer schools with an extortion message.TECHCRUNCH.COM
7 MayVPN Access Without Open PortsThreatLocker is adding remote-access functionality directly into its existing endpoint agent. The idea is similar to tools like Tailscale, WireGuard, or Cloudflare Tunnel: create secure connections to devices without exposing ports to the public internet. That changes the traditi…YOUTUBE.COM
6 MayQLNX Targets Developers in Supply Chain Credential Theft CampaignQLNX is a newly documented Linux remote access trojan (RAT) that targets the theft on developers’ and DevOps credentials to hijack software supply chains. Recent attacks against popular projects like LiteLLM on PyPI and the Axios npm package have shown how a single compromised ma…GBHACKERS.COM
6 MayRansomware Gang Member Linked to Russian Cybercrime Group Sentenced to PrisonA Latvian national operating from Moscow has been sentenced to 102 months in federal prison for his role as a key negotiator within a prolific Russian ransomware network. Deniss Zolotarjovs, 35, participated in a cybercrime syndicate that orchestrated data theft and extortion cam…GBHACKERS.COM
6 MayVimeo Confirms Breach Exposing 119,000 Unique User Email AddressesVideo hosting platform Vimeo has confirmed a data breach that exposed approximately 119,000 unique user email addresses, attributing the incident to a security compromise at Anodot, a third-party analytics vendor integrated with its systems. The breach came to light after the Shi…GBHACKERS.COM
6 MayMiddle East Cyber Battle Field Broadens — Especially in UAEAs the war with Iran continues, breach attempts targeting the United Arab Emirates tripled in a few weeks — many targeting critical infrastructure.DARKREADING.COM
6 MayLegionProxy - 10,144 breached accountsIn April 2026, the commercial residential and ISP proxy network LegionProxy suffered a data breach . The incident exposed 10k email addresses, bcrypt password hashes, names and purchases.HAVEIBEENPWNED.COM
6 MayMillions of students’ personal data stolen in major education breachShinyHunters claims it stole personal data from 275 million users on Instructure’s Canvas platform across schools and education providers.MALWAREBYTES.COM
6 MayIran-Linked APT Posed as Chaos Ransomware Member in Espionage CampaignRapid7 reveals an Iranian false flag operation masquerading as a Chaos ransomware attackINFOSECURITY-MAGAZINE.COM
6 MayMuddyWater Uses Microsoft Teams to Steal Credentials in False Flag Ransomware AttackThe Iranian state-sponsored hacking group known as MuddyWater (aka Mango Sandstorm, Seedworm, and Static Kitten) has been attributed to a ransomware attack in what has been described as a "false flag" operation. The attack, observed by Rapid7 in early 2026, has been found to leve…THEHACKERNEWS.COM
6 MayIran-sponsored threat group behind false flag social engineering campaignThe state-linked actor has been masquerading as a criminal ransomware group in attacks targeting U.S. organizations.CYBERSECURITYDIVE.COM
6 MayCybercriminals Are Complaining About AI Slop Flooding Their ForumsIt's not just you. Hackers and other cybercriminals are complaining about “AI shit” flooding platforms where they discuss cyberattacks and other illegal activity.WIRED.COM
6 MayIranian cyber espionage disguised as a Chaos Ransomware attackIran-linked APT MuddyWater used ransomware-style tactics to mask espionage, combining phishing, credential theft, data exfiltration, and extortion without encryption. A newly discovered cyber intrusion attributed to the Iran-linked APT MuddyWater (aka SeedWorm, TEMP.Zagros, Mango…SECURITYAFFAIRS.COM
6 MayDOJ says ransomware gang tapped into Russian government databasesU.S. prosecutors said a ransomware gang fueled Russian government corruption, and allowed the gang's leaders to avoid paying taxes and dodge the country's military draft.TECHCRUNCH.COM
6 MayAI evaluation startup Braintrust confirms breach, tells every customer to rotate sensitive keysBraintrust, a startup that makes an “operating system for engineers building AI software,” notified customers that hackers broke into one of its Amazon cloud environments, and is asking customers to rotate their API keys.TECHCRUNCH.COM
6 MayInstructure Breach Exposes Schools' Vendor DependenceShinyHunters' attack on Instructure, which owns the widely used Canvas learning management system (LMS), carries big questions about the trust educational institutions put into their vendors.DARKREADING.COM
5 MayVimeo - 119,167 breached accountsIn April 2026, the ShinyHunters extortion group listed Vimeo on their extortion portal as part of their "pay or leak" campaign . They subsequently published hundreds of gigabytes of data, predominantly consisting of video titles, technical data and metadata. The data also include…HAVEIBEENPWNED.COM
5 MayDigiCert Hacked in Screensaver-Based Attack to Fraudulently Obtain EV Code Signing CertificatesDigiCert, a major Certificate Authority, recently suffered a significant security breach where hackers used a malicious screensaver file to steal 60 Extended Validation (EV) Code Signing certificates. These highly trusted certificates were subsequently used to sign the “Zho…GBHACKERS.COM
5 MayEducational tech firm Instructure data breach may have impacted 9,000 schoolsInstructure, maker of the Canvas learning platform, is investigating a cyber incident that exposed users’ personal data. Instructure is a U.S.-based educational technology company best known for developing Canvas, one of the world’s most widely used learning management systems (L…SECURITYAFFAIRS.COM
5 MayScarCruft Hacks Gaming Platform to Deploy BirdCall Malware on Android and WindowsThe North Korea-aligned state-sponsored hacking group known as ScarCruft has compromised a video game platform in a supply chain espionage attack, trojanizing its components with a backdoor called BirdCallto likely target ethnic Koreans residing in China. While prior versions of …THEHACKERNEWS.COM
5 MayAPT37 hacks gaming platform to spread new BirdCall Android spywareNorth Korean hackers compromised a gaming platform in a supply-chain attack, using trojanized Windows and Android games to deploy a previously undocumented mobile variant of its BirdCall spyware. Security researchers at ESET detailed the operation in a recent report, describing h…CYBERINSIDER.COM
5 MayAustralia launches cyber review board modeled on version disbanded in USThe Cyber Incident Review Board will carry out no-fault, post-incident reviews of significant cyberattacks on Australian government and industry, focusing on systemic lessons rather than individual or corporate culpability.THERECORD.MEDIA
5 MayConti ransomware gang member sentenced to 102 months in prisonA Latvian national who was part of a major Russian ransomware organization that stole from and extorted more than 54 companies has been sentenced to 102 months in prison. Deniss Zolotarjovs, 35, of Moscow, Russia, was part of a group linked to former members of the Conti ransomwa…HELPNETSECURITY.COM
5 MayIntroducing the New AI-Native KnowBe4 SATCybercriminals are getting smarter and faster. Social engineering attacks are evolving rapidly, and AI is making them more convincing than ever. According to the 2025 Verizon Data Breach Investigations Report, up to 68% of cyberattacks involve some form of social engineering. Mea…KNOWBE4.COM
5 MayScarCruft Targets Gaming Platform With Windows, Android BackdoorsA sophisticated multiplatform supply-chain attack orchestrated by the North Korea-aligned APT group ScarCruft, targeting ethnic Koreans in China’s Yanbian region through a compromised gaming platform. The attack, believed to have been ongoing since late 2024, weaponized bot…GBHACKERS.COM
5 MayHackers Abuse DAEMON Tools Distribution Channel to Deliver Malicious PayloadsA sophisticated supply-chain attack has compromised the official distribution channel for DAEMON Tools, delivering multi-stage malware to users worldwide. Since April 8, 2026, threat actors have distributed trojanized installers signed with legitimate digital certificates to cond…GBHACKERS.COM
5 MayHackers steal students’ data during breach at education tech giant InstructureThe data breach at education tech giant Instructure includes students' private data, according to a sample of the allegedly stolen data seen by TechCrunch.TECHCRUNCH.COM
5 MayNorth Korean APT Targets Yanbian Gamers via Trojanized PlatformESET warns that North Korean hackers compromised a Yanbian gaming site in a supply‑chain attack, trojanizing Windows and Android software to spy on usersINFOSECURITY-MAGAZINE.COM
5 MayDAEMON Tools Supply Chain Attack Compromises Official Installers with MalwareA newly identified supply chain attack targeting DAEMON Tools software has compromised its installers to serve a malicious payload, according to findings from Kaspersky. "These installers are distributed from the legitimate website of DAEMON Tools and are signed with digital cert…THEHACKERNEWS.COM
5 MayLatvian national sentenced for ransomware attacks run by former Conti leadersDeniss Zolotarjovs was mostly tasked with putting pressure on the Russia-based crew’s victims, in one case leaking hundreds of children’s health records. The post Latvian national sentenced for ransomware attacks run by former Conti leaders appeared first on CyberScoop .CYBERSCOOP.COM
5 MayConti, Akira ransomware affiliate given 8-year sentenceDeniss Zolotarjovs pleaded guilty in July 2025 to money laundering and wire fraud charges after being arrested in the country of Georgia.THERECORD.MEDIA
5 MayVimeo confirms breach via third-party vendor impacts 119K usersHackers stole data of 119,000 Vimeo users in April. The breach, linked to a third‑party vendor, exposed personal details. Vimeo confirmed a data breach after the ShinyHunters gang stole personal information of 119,000 users in April 2026. According to Have I Been Pwned, the attac…SECURITYAFFAIRS.COM
5 MayU.S. court sentences Karakurt ransomware negotiator to 8.5 yearsDeniss Zolotarjovs was sentenced to 8.5 years in the U.S. after pleading guilty to money laundering and fraud tied to ransomware. Deniss Zolotarjovs, a Latvian national linked to the Karakurt ransomware gang, has been sentenced to 8.5 years in U.S. prison, marking a significant s…SECURITYAFFAIRS.COM
4 May15-year-old detained over massive data breach at French government agencyFrench authorities have detained a 15-year-old suspected of involvement in a data breach at France Titres, the government agency responsible for issuing official documents. “Between 12 and 18 million data records were reportedly being offered for sale on cybercriminal forum…HELPNETSECURITY.COM
4 May KEVDOJ Sentences Two Americans for ALPHV BlackCat Ransomware AttacksThe U.S. Department of Justice (DOJ) has sentenced two American cybersecurity professionals to prison for their involvement in ALPHV BlackCat ransomware attacks that targeted multiple U.S. organizations in 2023. The case highlights the growing threat of insider expertise being mi…GBHACKERS.COM
4 May2026: The Year of AI-Assisted AttacksOn December 4, 2025, a 17-year-old was arrested in Osaka under Japan’s Unauthorized Access Prohibition Act. The young man had run malicious code to extract the personal data of over 7 million users of Kaikatsu Club, Japan's largest internet cafe chain. When asked, the young man s…THEHACKERNEWS.COM
4 MayBluekit Phishing Kit Streamlines Domains, 2FA Lures, and Session HijackingA newly discovered phishing kit called “Bluekit” is reshaping how cybercriminals run phishing campaigns by combining multiple attack stages into a single, centralized platform. Instead, Bluekit integrates these capabilities into one operator panel, streamlining the entire attack …GBHACKERS.COM
4 MayCanvas Confirms Data Breach Following ShinyHunters ClaimInstructure, the educational technology company behind the widely used Canvas Learning Management System (LMS), has officially confirmed a major data breach. This confirmation directly follows recent claims made by the notorious threat actor group known as ShinyHunters. Canvas is…GBHACKERS.COM
4 MayDigiCert breached via malicious screensaver fileA targeted social engineering attack against DigiCert’s support channel led to the compromise of internal systems and the unauthorized issuance of EV Code Signing certificates. DigiCert is a global Certificate Authority (CA) providing digital trust services, specializing in TLS/S…HELPNETSECURITY.COM
4 MayCyberattacks are raising your prices (Lock and Code S07E09)This week on the Lock and Code podcast, we speak with Eva Velasquez about small business cyberattacks and the "cyber tax" coming for us all.MALWAREBYTES.COM
4 MayRansomware group claims breach of pro-Orbán Hungarian media firmMediaworks confirmed the incident on Friday, warning that “a significant amount of illegally obtained data may have come into the possession of unauthorized persons."THERECORD.MEDIA
4 MayEducational company Infrastructure reports cyber incidentBy Saturday, Infrastructure’s chief information security officer Steve Proud confirmed that the hackers gained access to information about users at some educational institutions, including names, email addresses, student ID numbers and messages between users.THERECORD.MEDIA
3 MaySecurity Affairs newsletter Round 575 by Pierluigi Paganini – INTERNATIONAL EDITIONA new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including the international press. Two US cybersecurity experts …SECURITYAFFAIRS.COM
3 MaySalt Typhoon breach IBM subsidiary in Italy: a warning for Europe’s digital defensesApril 2026 breach at Sistemi Informativi (IBM Italy) raises concerns over Chinese-linked cyber ops in Europe, including Salt Typhoon. In late April 2026, the Italian cybersecurity landscape was shaken by a significant breach targeting Sistemi Informativi, a company wholly owned b…SECURITYAFFAIRS.COM
3 MayMarcus & Millichap - 1,837,078 breached accountsIn April 2026, the commercial real estate brokerage firm Marcus & Millichap was named as one of multiple alleged victims of the ShinyHunters hacking and extortion group . Data alleged to have been obtained from the company was subsequently released publicly and included 1.8M uniq…HAVEIBEENPWNED.COM
2 MayMassive Facebook Phishing Operation Leverages AppSheet, Netlify, and TelegramCybersecurity researchers at Guardio Labs have uncovered a massive phishing operation dubbed AccountDumpling that has compromised more than 30,000 Facebook accounts worldwide. Unlike conventional phishing campaigns that rely on spoofed domains or compromised SMTP servers, this Vi…GBHACKERS.COM
2 MayNew Deep#Door RAT uses stealth and persistence to target WindowsDeep#Door hides a Python RAT inside a batch file, kills Windows defenses, survives via multiple persistence methods, and exfiltrates data through a public TCP tunnel. Security researchers at Securonix uncovered a sophisticated malware campaign called Deep#Door. Threat actors empl…SECURITYAFFAIRS.COM
2 May KEVTwo US cybersecurity experts sentenced in ransomware case, third awaits July rulingTwo US security experts were sentenced to 4 years for helping ransomware attacks. A third accomplice pleaded guilty and awaits sentencing. Two US cybersecurity professionals, Ryan Goldberg and Kevin Martin, were sentenced to four years in prison for their role in supporting ranso…SECURITYAFFAIRS.COM
1 MayA Ransomware Negotiator Was Working for a Ransomware GangSomeone pleaded guilty to secretly working for a ransomware gang as he negotiated ransomware payments for clients.SCHNEIER.COM
1 May KEVTwo Cybersecurity Professionals Get 4-Year Sentences in BlackCat Ransomware AttacksThe U.S. Department of Justice (DoJ) on Thursday announced the sentencing of two cybersecurity professionals to four years each in prison for their role in facilitating BlackCat ransomware attacks in 2023. Ryan Goldberg, 40, of Georgia, and Kevin Martin, 36, of Texas, were accuse…THEHACKERNEWS.COM
1 MayTwo American Cybersecurity Workers Jailed for BlackCat Ransomware AttacksThe cybersecurity workers used their knowledge and skills to conduct ransomware attacks for notorious gang, rather than protect victims against themINFOSECURITY-MAGAZINE.COM
1 MayCyber incident responders who carried out ransomware attacks given 4-year sentencesTwo cybersecurity incident responders who abused their positions to carry out covert ransomware attacks were sentenced to four years in prison.THERECORD.MEDIA
1 May30,000 Facebook Accounts Hacked via Google AppSheet Phishing CampaignA newly discovered Vietnamese-linked operation has been observed using a Google AppSheet as a "phishing relay" to distribute phishing emails with an aim to compromise Facebook accounts. The activity has been codenamed AccountDumpling by Guardio, with the scheme selling the stolen…THEHACKERNEWS.COM
1 MayThe new speed of cyber defense with Andrew Carr from Booz AllenAndrew Carr, Managing Director and head of Threat Detection and Response at Booz Allen, joins Dave Bittner on the CyberWire Daily podcast for a sponsored Industry Voices. Drawing on years of incident response and ransomware negotiation experience, he explains how AI is compressin…THECYBERWIRE.COMHTTPS:
30 AprCompromised SAP npm Packages Found Harvesting Developer and CI/CD SecretsSecurity researchers have identified a severe supply chain attack targeting the SAP developer ecosystem. A threat group identified as TeamPCP has compromised multiple legitimate SAP npm packages in a new campaign named Mini Shai Hulud. The operation relies on injecting malicious …GBHACKERS.COM
30 AprOperation Winter SHIELD: What the FBI Wants Industry to Do NowThe FBI sees every breach. You see yours. Adam Maddock, Section Chief of the FBI's Cyber Technical Analytics and Operations Section, and Jarrod Schlenker, Assistant Section Chief leading the FBI Cyber Division's private-sector engagement, join David Moulton to walk through …THECYBERWIRE.COM
30 AprMeta accused of violating DSA by failing to safeguard minorsThe European Commission accuses Meta of failing to protect children, allowing users under 13 on Instagram and Facebook, in breach of the DSA rules. The European Commission has accused Meta of violating child safety rules. Instagram and Facebook allegedly failed to prevent childre…SECURITYAFFAIRS.COM
30 AprWhy Your Email Security Needs a Global Human Network to Close the Detection GapThe biggest challenge in email security today isn’t just detecting a threat; it’s the speed of response across a global landscape. As we head into the second half of 2026, the stakes with speed have gotten higher. According to SQ Magazine, AI-generated phishing attempts are 68% h…KNOWBE4.COM
30 AprMoldova’s health insurance agency reports possible data leak after cyberattackThe agency said the incident occurred several weeks ago and that technical assessments indicated a possible theft of limited information.THERECORD.MEDIA
30 AprUK: Education Sector Faces Surge in Cyber Breaches Despite Stable National Threat LevelsThe British public education sector has faced the nation’s most dramatic increase in cyber breach prevalence over the past yearINFOSECURITY-MAGAZINE.COM
30 AprAnti-DDoS Firm Heaped Attacks on Brazilian ISPsA Brazilian tech firm that specializes in protecting networks from distributed denial-of-service (DDoS) attacks has been enabling a botnet responsible for an extended campaign of massive DDoS attacks against other network operators in Brazil, KrebsOnSecurity has learned. The firm…KREBSONSECURITY.COM
30 AprFrance investigates 15-year-old over alleged hack of national ID agencyThe minor was taken into police custody on April 25 on suspicion of involvement in a data breach affecting the National Agency for Secure Documents (ANTS), which processes applications for passports, national identity cards, residence permits and driver’s licenses.THERECORD.MEDIA
30 AprFrance arrests 15-year-old hacker who stole data of 11.7 million peopleFrench authorities have detained a 15-year-old suspect in connection with the recent ANTS data breach, which exposed millions of sensitive user records on cybercrime forums. According to a statement published earlier today by Paris public prosecutor Laure Beccuau, the minor was t…CYBERINSIDER.COM
30 AprPyTorch Lightning Compromised in PyPI Supply Chain Attack to Steal CredentialsIn yet another software supply chain attack, threat actors have managed to compromise the popular Python package Lightning to push two malicious versions to conduct credential theft. According to Aikido Security, Socket, and StepSecurity, the two malicious versions are versions 2…THEHACKERNEWS.COM
30 AprTeamPCP Hits SAP Packages With 'Mini Shai-Hulud' AttackSeveral npm packages for SAP's cloud application development ecosystem have been compromised as TeamPCP's supply chain attacks broaden.DARKREADING.COM
30 Apr KEVFormer incident responders sentenced to 4 years in prison for committing ransomware attacksRyan Goldberg and Kevin Martin attacked five companies in 2023 and extorted nearly $1.3 million from one of their victims. The post Former incident responders sentenced to 4 years in prison for committing ransomware attacks appeared first on CyberScoop .CYBERSCOOP.COM
29 AprBlueNoroff Deploys Fileless PowerShell in AI-Generated Zoom Lure CampaignA sophisticated BlueNoroff campaign targeting cryptocurrency executives through fake Zoom meetings enhanced with AI-generated deepfakes and fileless PowerShell malware. The North Korean state-sponsored group successfully compromised a North American Web3 company in January 2026, …GBHACKERS.COM
29 AprVect 2.0 RaaS Expands Attacks Across Windows, Linux, and ESXiVect 2.0 Ransomware‑as‑a‑Service (RaaS) operation is rapidly evolving into a multi‑platform threat that can encrypt Windows, Linux, and VMware ESXi environments across modern hybrid infrastructures. The group runs a classic affiliate model, renting out its ransomware and TOR‑base…GBHACKERS.COM
29 AprLofyStealer Targets Minecraft Players via Node.js Loader and Browser InjectionMinecraft players are being lured with a fake hacking tool called “Slinky” that secretly installs a powerful infostealer dubbed LofyStealer (also tracked as GrabBot), linked to the Brazilian cybercrime group LofyGang. The malware uses a Node. js-based loader and an in-memory C++ …GBHACKERS.COM
29 AprVECT 2.0 Ransomware Wipes Large Files Across Windows, Linux & ESXiThe “new” VECT 2.0 ransomware is essentially a cross‑platform data wiper that permanently destroys most enterprise files rather than encrypting them for recovery. For any file larger than 131,072 bytes (128 KB), VECT processes four separate chunks using four different randomly ge…GBHACKERS.COM
29 AprCritical Flaw Turns Vect Ransomware into Data Destroying WiperThe Vect 2.0 ransomware wipes large files instead of merely encrypting them, making recovery impossible – even for the attackersINFOSECURITY-MAGAZINE.COM
29 AprResearchers Track 2.9 Billion Compromised CredentialsKELA claims infostealers remained the primary access vector for attacks in 2025INFOSECURITY-MAGAZINE.COM
29 AprOpenAI and Anthropic brief Congress on cyber-capable AI models.Rival ransomware gangs list each other as victims. Business news: Silverfort will acquire Fabrix Security.THECYBERWIRE.COM
29 AprEuropean Commission accuses Meta of breaching child safety rulesThe platforms allegedly flouted the bloc’s Digital Services Act (DSA) by “failing to diligently identify, assess and mitigate the risks of minors under 13 years old accessing their services,” the commission said.THERECORD.MEDIA
29 AprVect 2.0 Ransomware Acts as Wiper, Thanks to Design ErrorThe emerging ransomware has been deployed against victims of the TeamPCP supply chain attacks, but organizations should think twice before paying for a decryptor.DARKREADING.COM
29 AprSAP npm Packages Compromised by “Mini Shai-Hulud” Credential-Stealing MalwareCybersecurity researchers are sounding the alarm about a new supply chain attack campaign targeting SAP-related npm Packages with credential-stealing malware. According to reports from Aikido Security, SafeDep, Socket, StepSecurity, and Google-owned Wiz, the campaign – calling it…THEHACKERNEWS.COM
29 AprGoogle AppSheet abused to compromise 30,000 Facebook accountsA large-scale phishing operation abusing Google’s AppSheet platform has compromised at least 30,000 Facebook accounts, using fully authenticated emails that bypass traditional security checks. Guardio Labs uncovered the campaign while investigating a wave of phishing emails sent …CYBERINSIDER.COM
29 AprSmashing Security podcast #465: This developer wanted to cheat at Roblox. It cost millionsA developer at an AI startup wanted to cheat at Roblox. They downloaded a dodgy script on their work laptop. That one decision triggered a cascade of failures that ended with a $2 million data breach affecting hundreds of thousands of organisations. All for some free in-game curr…GRAHAMCLULEY.COM
28 AprWeekly Update 501Presently sponsored by: Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite This is so "peak 2026" - writing an equality policy to ensure people treat our AI bot with the same respect as they do their …TROYHUNT.COM
28 AprChinese Silk Typhoon Hacker Extradited to U.S. Over COVID Research CyberattacksA Chinese national accused of being a member of the Silk Typhoon hacking group has been extradited to the U.S. from Italy. Xu Zewei, 34, was arrested in July 2025 by Italian authorities for his alleged links to the Chinese state-sponsored threat group and for orchestrating …THEHACKERNEWS.COM
28 AprProofpoint Research Reveals Half of Global Organizations Experienced AI Incidents Despite Having AI Security Controls in PlacePROOFPOINT.COM
28 AprCheckmarx Confirms Security Incident Involving GitHub Repository ExposureApplication security provider Checkmarx has officially confirmed a new security incident involving the exposure of its internal GitHub repository. On April 27, 2026, Udi-Yehuda Tamar, the company’s VP of Platform Engineering and Global CISO, revealed that a cybercriminal gr…GBHACKERS.COM
28 AprRansomware Turf War as 0APT and KryBit Groups Trade BlowsRansomware groups 0APT and KryBit have doxxed each other onlineINFOSECURITY-MAGAZINE.COM
28 AprVECT 2.0 Ransomware Irreversibly Destroys Files Over 131KB on Windows, Linux, ESXiThreat hunters are warning that the cybercriminal operation known as VECT 2.0 acts more like a wiper than a ransomware due to a critical flaw in its encryption implementation across Windows, Linux, and ESXi variants that renders recovery impossible even for the threat actors. The…THEHACKERNEWS.COM
28 AprIran war updates.US Supreme Court leans toward requiring warrants for geofencing searches. ShinyHunters claims responsibility for Pitney Bowes breach.THECYBERWIRE.COM
28 AprMedtronic Confirms Data Breach After ShinyHunters ClaimsMedtronic confirms IT breach as ShinyHunters claims millions of records accessedaINFOSECURITY-MAGAZINE.COM
28 AprVECT: Ransomware by design, Wiper by accidentKey Takeaways Background VECT Ransomware is a Ransomware-as-a-Service (RaaS) program that made its first appearance in December 2025 on a Russian-language cybercrime forum. After claiming their first two victims in January 2026, the group got back into the public eye due to an an…RESEARCH.CHECKPOINT.COM
28 AprVideo site Vimeo blames security incident on Anodot breachThe hackers did not access video content, user logins or payment card information, and there was no disruption to Vimeo’s services,THERECORD.MEDIA
28 AprADT Confirms Major Data Breach Exposing Millions of Names, Partial SSNsADT confirmed a data breach exposing customer names, addresses, phone numbers, and partial SSNs, with millions of records reportedly affected. The post ADT Confirms Major Data Breach Exposing Millions of Names, Partial SSNs appeared first on TechRepublic .TECHREPUBLIC.COM
28 AprWhat the March 2026 Threat Technique Catalog update means for your AWS environmentThe AWS Customer Incident Response Team (AWS CIRT) regularly encounters patterns that repeat across their engagements when helping customers respond to security incidents. We’re passionate about making sure that information is widely accessible so that everyone can improve their …AWS.AMAZON.COM
28 AprFeuding Ransomware Groups Leak Each Other's DataWhen 0APT and KryBit attacked each other, they exposed infrastructure and operational data, giving defenders rare insight into ransomware operations.DARKREADING.COM
27 AprCyber Weapon in Toronto, Grid Attack, Stuxnet Lie ExposedA rogue cyber weapon drove through Toronto blasting scam texts to thousands of phones. A major U.S. critical infrastructure provider confirms a cyberattack. And researchers reveal that Stuxnet may not have been the first cyber weapon after all. In today's Cybersecurity Today with…CYBERSECURITYTODAY.LIBSYN.COM
27 AprCritical infrastructure giant Itron says it was hackedThe American technology giant provides water and energy monitoring and utility meters to hundreds of millions of homes and businesses.TECHCRUNCH.COM
27 AprHackers impersonate Microsoft Teams help desk to breach corporate networksHackers are impersonating Microsoft Teams help desk workers to trick victims into installing data-stealing malware, researchers found.THERECORD.MEDIA
27 AprUtilities Tech Supplier Itron Discloses Cyber-Attack, Operations UnaffectedItron confirmed a cyber incident but does not believe it is likely to have a material impact on the companyINFOSECURITY-MAGAZINE.COM
27 AprLINKEDIN BROWSERGATEBrowserGate claims LinkedIn secretly fingerprints users via extensions and device data, sending encrypted results to third parties for tracking. BrowserGate is an investigation conducted by Fairlinked (https://browsergate.eu/), an association of commercial LinkedIn users, which d…SECURITYAFFAIRS.COM
27 AprFIRESIDE CHAT: Leaked secrets are now the go-to attack vector — and AI is accelerating exposuresA consequential shift is underway in how enterprise breaches begin. The leaked credential — once treated as a hygiene problem — has become the primary on-ramp. Related: No easy fixes for AI risk Last August’s Salesloft campaign was the pattern … (more…) The post FIRESIDE CH…LASTWATCHDOG.COM
27 AprRansomware Uses Your Own PermissionsRansomware operates using the same permissions as the infected user. If your account can access and modify files, so can the malware running under it. This turns the permission system into a liability. Instead of blocking malicious activity, it enables it—because the system assum…YOUTUBE.COM
27 AprMajor critical infrastructure supplier reports cyberattackItron, which makes devices that measure energy and water use, said its operations were continuing, despite the intrusion.CYBERSECURITYDIVE.COM
27 AprSenators seek answers about hackers obtaining sensitive student data from ostensibly anonymous tip lineSens. Maggie Hassan and Jim Banks wrote to Navigate360 after a hacker claimed to compromise the school safety tool. The post Senators seek answers about hackers obtaining sensitive student data from ostensibly anonymous tip line appeared first on CyberScoop .CYBERSCOOP.COM
27 AprHacker who allegedly carried out cyberattacks for China is extradited to U.S.Xu Zewei is accused of participating in a Chinese government hacking group that broke into thousands of U.S. organizations and stole COVID-19-related research.TECHCRUNCH.COM
27 AprSimplicity Stops Data ExfiltrationThis approach limits both file access and network connectivity using allowlisting—only approved actions are permitted, reducing the attack surface. By controlling sockets (network access) and files together, it becomes much harder for attackers to exfiltrate data or pull down mal…YOUTUBE.COM
27 AprMedtronic discloses security incident after ShinyHunters claimed theft of 9M+ recordsMedtronic confirmed a breach of its IT systems after ShinyHunters claimed the theft of over 9 million records. Medtronic confirmed a cyberattack on its corporate IT systems after the hacker group ShinyHunters claimed to have stolen over 9 million records. The company did not shar…SECURITYAFFAIRS.COM
27 AprThe Supreme Court sits on the geofence.The Supreme Court weighs geofence warrants. Iran leans toward quieter cyber ops. Researchers unpack Fast16 sabotage malware. Microsoft tracks an Outlook outage. Snow malware moves deep inside networks. Itron reports a breach. SMS blasters hit Canada. Italy extradites an accused h…THECYBERWIRE.COM
27 AprPitney Bowes - 8,243,989 breached accountsIn April 2026, the hacking collective ShinyHunters claimed to have obtained data from Pitney Bowes as part of a broader extortion campaign that also named several other organisations. After negotiations allegedly failed, the group publicly released the data which included 8.2M un…HAVEIBEENPWNED.COM
26 AprTrigona ransomware adopts custom tool to steal data and evade detectionTrigona ransomware now uses a custom command-line tool to steal data faster and evade detection, replacing tools like Rclone and MegaSync. Symantec researchers report that recent Trigona ransomware attacks used a custom-built data exfiltration tool instead of common utilities lik…SECURITYAFFAIRS.COM
26 AprUdemy - 1,401,259 breached accountsIn April 2026, online training company Udemy was the victim of a “pay or leak” extortion attempt perpetrated by the ShinyHunters group. The data was subsequently leaked publicly and contained 1.4M unique email addresses belonging to customers and instructors. The data also includ…HAVEIBEENPWNED.COM
25 AprDiscord Sleuths Gained Unauthorized Access to Anthropic’s MythosPlus: Spy firms tap into a global telecom weakness to track targets, 500,000 UK health records go up for sale on Alibaba, Apple patches a revealing notification bug, and more.WIRED.COM
24 AprBitwarden CLI Compromised in Ongoing Checkmarx Supply Chain Attacksubmitted by cm0002 to cybersecurity 4 points | 0 comments https://socket.dev/blog/bitwarden-cli-compromisedINFOSEC.PUB
24 AprCarnival - 7,531,359 breached accountsIn April 2026, the notorious hacking collective ShinyHunters claimed they had obtained a substantial volume of data belonging to the Carnival cruise operator and attempted to extort the organisation to prevent the data from being leaked. The following week, the group published th…HAVEIBEENPWNED.COM
24 AprRansomware Gang Unveils Custom Data-Theft ToolRansomware operators introduced a custom-built data exfiltration tool, signaling a notable evolution in attack techniques. Unlike most ransomware groups that rely on publicly available utilities such as Rclone or MegaSync, Trigona affiliates are now using a proprietary tool to st…GBHACKERS.COM
24 AprHackers Impersonate IT Helpdesk Staff to Breach Firms via Microsoft TeamsA newly identified cyber threat group, UNC6692, is using a clever mix of social engineering and custom malware to infiltrate corporate networks. By impersonating IT helpdesk personnel on Microsoft Teams, these hackers trick employees into downloading a sophisticated malware suite…GBHACKERS.COM
24 AprBitwarden CLI Compromised After Malicious GitHub Actions WorkflowCybersecurity researchers at Socket have uncovered a major supply chain compromise affecting the Bitwarden CLI. Attackers successfully abused a GitHub Action in Bitwarden’s CI/CD pipeline to inject malicious code into the popular password manager’s npm package. This breach …GBHACKERS.COM
24 AprChina-Linked Hackers Hide Behind Compromised RoutersHackers linked to China are increasingly abusing compromised routers and edge devices to build covert networks, enabling stealthy cyber operations that are harder to detect and block. Instead of relying on dedicated servers or purchased hosting, threat actors are now leveraging l…GBHACKERS.COM
24 AprAI is speeding up nation-state cyber programsIn this Help Net Security interview, Kaja Ciglic, Senior Director, Cybersecurity Policy and Diplomacy at Microsoft, discusses how nation-state cyber programs have changed over three years. Cyber has become a core instrument of state power, integrated with military, economic, and …HELPNETSECURITY.COM
24 AprCheckmarx supply chain attack impacts Bitwarden npm distribution pathBitwarden CLI was hit by the Checkmarx supply chain attack. Version 2026.4.0 shipped malicious code in bw1.js via a compromised GitHub Action. Bitwarden CLI has been compromised as part of the ongoing Checkmarx supply chain campaign, researchers warn. The affected version, @bitwa…SECURITYAFFAIRS.COM
24 AprAI Phishing Is No. 1 With a Bullet for CyberattackersIn the last six months, companies have seen a significant influx of AI-powered phishing, as cyberattackers progress from small campaigns to 1-to-1 personalized attacks.DARKREADING.COM
24 AprSignal phishing campaign targets Germany’s Bundestag President Julia KlöcknerGermany’s Bundestag President Klöckner was targeted in a Signal phishing attack via a fake CDU group chat. Germany’s Bundestag President Julia Klöckner has reportedly become the latest European political figure targeted through a Signal-based phishing attack, reported Der Spiegel…SECURITYAFFAIRS.COM
24 AprHasbro expects March cyberattack to impact second-quarter revenueThe toy maker is reviewing files and working to fully bring certain systems back online. The company will incur some costs related to the investigation.CYBERSECURITYDIVE.COM
24 AprScattered Spider co-conspirator pleads guiltyAnother member of the notorious Scattered Spider gang of cyber criminals has pleaded guilty in a US court, and will be sentenced later this year. Tyler Buchanan pleaded guilty in a Florida court to conspiring with others to hack into companies’ computer systems with the intent of…CSOONLINE.COM
24 AprADT says customer data stolen in cyber intrusionThe home security company ADT said cybercriminals breached company systems on Monday and stole a “limited set” of customer and prospective customer information.THERECORD.MEDIA
24 AprADT confirms data breach after hacker claims 10 million records stolenThe American security company ADT has confirmed via a statement to CyberInsider a cybersecurity incident involving unauthorized access to a subset of customer data. The admission follows claims by the ShinyHunters extortion group that it breached the company and stole over 10 mil…CYBERINSIDER.COM
🕵️ THREAT INTELLIGENCE 1505[+]
23 JulISC Stormcast For Thursday, July 23rd, 2026 https://isc.sans.edu/podcastdetail/10020, (Thu, Jul 23rd)(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.ISC.SANS.EDU
23 JulThe AI code vulnerabilities that grow with your appTheori built 28 apps with AI coding agents and scanned each one through its pentesting platform. Five models did the building, split between Anthropic and OpenAI, across apps written from a spec, thrown together from a casual prompt, and rewritten from an aging PHP codebase. The …HELPNETSECURITY.COM
23 JulShadow AI is becoming enterprise security’s biggest blind spotArtificial intelligence has moved from experimentation to everyday business operations with remarkable speed. Employees are using it to summarize documents, draft communications, analyze spreadsheets, write code, build automations, and create AI-powered workflows across nearly ev…HELPNETSECURITY.COM
23 JulProduct Showcase: AppViewX Agent Identity SecurityAI is multiplying enterprise identities as quantum computing reshapes the cryptographic trust that secures them, and enterprises need to solve both together. Traditional identity security was built for people with predictable, auditable access, not autonomous, short-lived agents …HELPNETSECURITY.COM
23 JulAxonius expands Asset Cloud with Cyber Assets and Exposures enhancementsAxonius has announced new capabilities across the Axonius Asset Cloud to better address asset intelligence and exposure management use cases. The enhancements make it easier than ever to address CMDB visibility gaps and respond to vulnerabilities, while extending asset intelligen…HELPNETSECURITY.COM
23 JulAssaf Keren Appointed New CISO of MetaHe replaces Guy Rosen, who announced his retirement from the company after 13 years. The post Assaf Keren Appointed New CISO of Meta appeared first on SecurityWeek .SECURITYWEEK.COM
23 JulNew Dolphin X infostealer uses AI to identify high-value victimsA newly identified Windows malware called Dolphin X combines information-stealing capabilities with remote access features while targeting credentials from more than 300 applications. The malware also includes an AI-powered profiler that automatically ranks infected users, helpin…CYBERINSIDER.COM
23 JulNuclear-Sabotage Malware Benchmark Trips Up Most Frontier AI ModelsSentinelOne’s new benchmark, built on the Fast16 case, shows which AI models can sustain a malware investigation and which cannot. The post Nuclear-Sabotage Malware Benchmark Trips Up Most Frontier AI Models appeared first on SecurityWeek .SECURITYWEEK.COM
23 JulClick. Click. Fake it until they make it… insideTL;DR The Problem In this online world it’s been easier than ever to order what you need, when you need and to the exact specifications you want… mostly. The clothing world, alongside many other sectors, is plagued by fakes to t…PENTESTPARTNERS.COM
23 JulMozilla releases Thunderbird 153 with native Microsoft Exchange supportThunderbird 153 “Meadow” has been released, introducing native Microsoft Exchange support alongside a redesigned account setup experience, user interface improvements, and security fixes. The update marks the first time Exchange accounts can be configured directly in …CYBERINSIDER.COM
23 JulAbstract Raises $25 Million to Expand Composable Security Operations PlatformThe latest investment round brings the total raised by Abstract to nearly $50 million. The post Abstract Raises $25 Million to Expand Composable Security Operations Platform appeared first on SecurityWeek .SECURITYWEEK.COM
23 JulRussian Global Webmail EspionageUnit 42 details a Russian cyberespionage campaign targeting Zimbra webmail servers using JavaScript injection to steal credentials. The post Russian Global Webmail Espionage appeared first on Unit 42 .UNIT42.PALOALTONETWORKS.COM
23 JulChick-fil-A Accounts Get Fried in Credential Stuffing AttackThreat actors used credentials obtained from other companies to hack into Chick-fil-A One accounts. The post Chick-fil-A Accounts Get Fried in Credential Stuffing Attack appeared first on SecurityWeek .SECURITYWEEK.COM
23 JulThe case for a cooldown: Why Dependabot now waits before issuing version updatesA new default three-day cooldown delays version update pull requests so maintainers and security researchers can address findings in a release before it gets into your code. The post The case for a cooldown: Why Dependabot now waits before issuing version updates appeared first o…GITHUB.BLOG
23 JulOpenAI Fixes ChatGPT Agent Flaw That Could Let Attackers Forge an AI InsiderAgentForger allows an attacker to create, insert and remotely control an invisible autonomous AI agent inside a victim organization. The post OpenAI Fixes ChatGPT Agent Flaw That Could Let Attackers Forge an AI Insider appeared first on SecurityWeek .SECURITYWEEK.COM
23 JulEmail threat landscape: Q2 2026 trends and insightsIn the second quarter of 2026, the continuing effects of Microsoft’s disruption of the Tycoon2FA phishing platform contributed to sustained declines in several major phishing techniques, while threat actors expanded into Teams-based social engineering and employed increasingly au…MICROSOFT.COM
22 JulISC Stormcast For Wednesday, July 22nd, 2026 https://isc.sans.edu/podcastdetail/10018, (Wed, Jul 22nd)(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.ISC.SANS.EDU
22 JulSmall teams are the heaviest users of AI coding agentsThe pull request arrives with the tests already run and the description already written, the work of an agent that handled the whole thing on its own. Somebody still has to read it. On GitHub that somebody is usually one developer sitting alone with the diff, and the rest of the …HELPNETSECURITY.COM
22 JulAI's Disruption as Cybersecurity’s Economics Are Broken, Compounding Security Debt - BSW #457America has lived through technological and economic upheaval before. Farm workers moved to factories. Factory workers moved into services. New industries replaced old ones. Productivity rose. Living standards improved. But are we ready for the greatest disruption in American his…YOUTUBE.COM
22 JulAI models cheat on cybersecurity evaluations, then fail to admit itFrontier AI models will take just about any route to finish a task, cheating included, according to new cybersecurity evaluations from the UK government’s AI Security Institute (AISI). AISI defines cheating as a model doing something outside the bounds of what a task allows…HELPNETSECURITY.COM
22 JulFirst-Person Identity Theft StoryHarrowing story of an identity theft victim. Yes, the person made a mistake—they gave the scammer a two-factor authentication code that allowed the scammer to take over their email address. But the real story here is how, for many of us, the security of most of our accounts…SCHNEIER.COM
22 JulBox expands enterprise AI governance with new agent security featuresoxBox has announced new security capabilities designed to give organizations greater control over AI agents working with enterprise content. With new agent guardrails, third-party agent activity oversight, prompt injection detection, agent classification-based access policies, and …HELPNETSECURITY.COM
22 JulArista adds AI-driven zero trust to VeloCloud SD-WANArista Networks has announced the launch of its new AI-driven Edge Threat Management (ETM) for VeloCloud SD-WAN, delivering integrated zero trust security for enterprise branch offices. Customers can leverage this integration to simplify the branch, collapsing multiple disparate …HELPNETSECURITY.COM
22 JulWhy Modern SOCs Need Multi-Layered DetectionsThe cycle is over. For years, cybersecurity followed a familiar pattern: defenses improved, attackers adapted, and the back-and-forth continued. Today, AI-equipped attackers are simply outpacing defenses. Most intrusions now bypass endpoint and malware-based detection entirely. T…THEHACKERNEWS.COM
22 JulGlow exits stealth with $180 million to secure the AI-enabled endpointGlow has emerged from stealth with $180 million in funding at a $1.2 billion valuation to advance a prevention-first approach to endpoint security. The funding round was led by Sequoia, Cyberstarts, Greenoaks, and Redpoint Ventures, with participation from Index Ventures, Swish V…HELPNETSECURITY.COM
22 JulStrongestLayer Raises $4.1 Million in Seed Funding ExtensionThe startup will use the fresh investment to accelerate its go-to-market strategy and to expand its platform. The post StrongestLayer Raises $4.1 Million in Seed Funding Extension appeared first on SecurityWeek .SECURITYWEEK.COM
22 JulWhen Identity Verification Fails: Lessons from a Real-World SIM Swap and Near Account TakeoverIdentity confidence changes throughout every interaction and should be reassessed continuously as new risk signals emerge. The post When Identity Verification Fails: Lessons from a Real-World SIM Swap and Near Account Takeover appeared first on SecurityWeek .SECURITYWEEK.COM
22 JulThreatDown expands security visibility to AI tools and machine identitiesThreatDown has announced a synchronized expansion of its AI and identity security capabilities to protect organizations from emerging, unmanaged risks. The company launched AI visibility, giving security and managed service provider (MSP) teams a full inventory of the AI tools ru…HELPNETSECURITY.COM
22 JulSwimlane AI SOC automates security operations for MSSPsSwimlane has announced the launch of Swimlane AI SOC for MSSPs, which the company says is designed to empower managed security service providers through agentic AI automation rather than compete for their customers. Some AI SOC providers are moving into managed services, turning …HELPNETSECURITY.COM
22 JulPalo Alto Networks to Acquire Observability Platform Provider EmbraceAcquisition follows January's Chronosphere deal, deepening Palo Alto Networks' push beyond core security into observability. The post Palo Alto Networks to Acquire Observability Platform Provider Embrace appeared first on SecurityWeek .SECURITYWEEK.COM
22 JulNext chapter: Restructuring GitHub’s bug bounty programGitHub is making some significant changes to its bug bounty program, shifting its focus to give researchers a better experience working with the GitHub team. The post Next chapter: Restructuring GitHub’s bug bounty program appeared first on The GitHub Blog .GITHUB.BLOG
22 JulYou Can't Ban Attacker AIAI capabilities are becoming widely accessible. The discussion is shifting from whether attackers will use AI to how defenders can use similar technology to identify weaknesses in their own environments. If organizations focus only on restricting AI instead of adopting effective …YOUTUBE.COM
22 JulWhite House accuses Chinese company of distilling Anthropic’s FableWhile distillation attacks by foreign governments and companies have real national security implications, questions around who ultimately owns the data in AI systems are fraught. The post White House accuses Chinese company of distilling Anthropic’s Fable appeared first on CyberS…CYBERSCOOP.COM
22 JulMalware is targeting AI tools in software development environmentsThe worm blends in with thousands of other commands occurring daily in any given environment, yet its intent and origins remain unknown. The post Malware is targeting AI tools in software development environments appeared first on CyberScoop .CYBERSCOOP.COM
21 JulISC Stormcast For Tuesday, July 21st, 2026 https://isc.sans.edu/podcastdetail/10016, (Tue, Jul 21st)(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.ISC.SANS.EDU
21 JulCybersecurity jobs available right now: July 21, 2026Application Security Analyst Stellantis | USA | On-site – View job details As an Application Security Analyst, you will perform application security testing using SAST, DAST, IAST, and other assessment tools to identify vulnerabilities and support remediation effo…HELPNETSECURITY.COM
21 JulAI agents are still logging in as humansMost large companies run more than one AI platform at the same time. Developers pull up coding assistants, marketing teams lean on writing tools, and analysts query enterprise search across separate vendors. Single-provider setups keep giving way to mixed stacks as companies keep…HELPNETSECURITY.COM
21 JulNobody was checking the drives that encrypt your laptopA drive ships with a label promising hardware encryption. You plug it in, set a password, and trust the chip inside to handle the rest. Millions of laptops and workstations run this way, on solid-state drives built to the TCG Opal2 standard. Milan Brož and three colleagues bought…HELPNETSECURITY.COM
21 JulZimbra Update Patches Critical VulnerabilitiesThe latest Zimbra refresh resolves command injection, XSS, restriction bypass, and SSRF security defects. The post Zimbra Update Patches Critical Vulnerabilities appeared first on SecurityWeek .SECURITYWEEK.COM
21 JulWhat the World Cup can teach us about cybersecurity resilienceFuture major events can’t rely on yesterday's playbook. Lessons from the World Cup show why true cyber resilience starts months before kickoff and extends far beyond stadium perimeters. The post What the World Cup can teach us about cybersecurity resilience appeared first on Cybe…CYBERSCOOP.COM
21 JulResearchers Uncover North Korean 'ClickFake' Campaign Targeting Web3 ProsIn a new campaign, North Korean hacking group Famous Chollima targeted crypto professionals through ClickFix lures to deliver Windows and macOS trojansINFOSECURITY-MAGAZINE.COM
21 JulAWS wants GuardDuty to automate the first steps of threat investigationsAmazon GuardDuty investigation agent is now in public preview. The feature provides AI-powered investigations of GuardDuty findings, AWS accounts and AWS organizations, helping security teams reduce investigation time. During the public preview, the investigation agent is availab…HELPNETSECURITY.COM
21 JulFake FBI agents target people who already got scammedScammers are impersonating FBI personnel who supposedly handle Internet Crime Complaint Center (IC3) complaints, using that disguise to deceive and revictimize people who already lost money once. The IC3 published the update on July 20, 2026, building on an earlier alert from Apr…HELPNETSECURITY.COM
21 JulMIT to Become Hotbed of AI Video SurveillanceIt’s a lot : According to information obtained by The Tech , MIT is spending over $3 million on more than 500 AI surveillance cameras in academic buildings, residence halls, and outdoor areas along Memorial Drive. Installation of the new cameras, along with the wiring and i…SCHNEIER.COM
21 JulCISO Conversations: Andreas Gaetje – From Economics to CISO at Körber AGGaetje’s story shows that you don’t need to be a ‘deep bit-crawler’ to become a Chief Information Security Officer. The post CISO Conversations: Andreas Gaetje – From Economics to CISO at Körber AG appeared first on SecurityWeek .SECURITYWEEK.COM
21 JulA new extortion cocktail: office printers, small ransoms, and BitLockerWe cover two recent cases of BitLocker extortion using RDP, MSSQL, RMM tools, web shells, and printers. The story includes TTPs and recommendations.SECURELIST.COM
21 JulEmpirical Security Raises $25 Million in Series A FundingThe startup will use the investment to accelerate the development of its threat prediction and discovery products. The post Empirical Security Raises $25 Million in Series A Funding appeared first on SecurityWeek .SECURITYWEEK.COM
21 JulSecurityWeek Launches Critical Impact Awards to Recognize Excellence in Industrial CybersecurityIndependently judged and sponsor-neutral, the new awards program honors the people, organizations, and technologies delivering proven impact in industrial cybersecurity; winners to be announced live at the 2026 ICS Cybersecurity Conference in Nashville The post SecurityWeek Launc…SECURITYWEEK.COM
21 JulLoop engineering comes to the SOC: Introducing the Intezer Org BrainOrganizational context in an AI SOC is table stakes. Org Brain is very different. It learns, it recalls, it fetches what it's missing, and it gets sharper with every alert it touches, all autonomously. The post Loop engineering comes to the SOC: Introducing the Intezer Org Brain …INTEZER.COM
21 JulCaptive Portal Detection, (Tue, Jul 21st)Not everything our honeypots detect is an attack. Sometimes it is just "odd traffic", and this is one example: Our "First Seen" list currently includes "http://detectportal.firefox.co
m/success.txt" as one of the new URLs detected by our honeypots. The hostname "detectporta…ISC.SANS.EDU
21 JulRussian Hacker Turns Jailbroken Claude Into Pentest PlatformRussian-speaking actor Trim built a commercial offensive AI pentest tool on jailbroken Claude modelsINFOSECURITY-MAGAZINE.COM
21 JulDruva brings backup, recovery and governance to AI workloadsDruva has announced Druva AI Resilience, a new approach that helps organizations recover, govern, and defend the systems, activity, and context behind AI-powered work. The launch introduces new and expanded capabilities for Microsoft Copilot, Claude Code, Druva Model Context Prot…HELPNETSECURITY.COM
21 JulArgon2 algorithm dramatically slows password cracking by high-end GPUsA new study shows that the Argon2id password hashing algorithm dramatically increases the cost of offline password cracking by neutralizing much of the advantage offered by modern GPUs. The study by Specops researcher David Ketler examines how Argon2id performs against modern pas…CYBERINSIDER.COM
21 JulTeleport enhances Identity Security platform with new AI agent behavior controlsTeleport has expanded its Identity Security platform with three new capabilities designed to ensure that agent behavior remains within defined boundaries: Beams Session Summaries, Agentic Classifiers, and Risk Scoring. They give enterprises a foundational harness for identifying …HELPNETSECURITY.COM
21 JulNorth Korea’s IT worker scheme funds Russia’s war effortDTEX researchers found a series of transactions in a payment wallet showing North Korean IT worker salaries flowing into sanctioned entities that support the regime’s military programs. The post North Korea’s IT worker scheme funds Russia’s war effort appeared first o…CYBERSCOOP.COM
21 JulIgnore Apple, Pay the PricePatrick Wardle shares the biggest lesson he learned after years of building macOS security tools: follow Apple's recommended development practices whenever possible. Choosing unsupported techniques may seem like the better engineering decision at first, but platform changes often…YOUTUBE.COM
21 JulFirefox 153 adds built-in Containers for easy account isolationMozilla has released Firefox 153, introducing built-in Containers as a native browser feature alongside HDR video playback on Windows, new PDF editing capabilities, and several security improvements. Firefox 153 is now rolling out to users on the browser's Release channel. The up…CYBERINSIDER.COM
21 JulDon't Overbuild Your AI WorkflowLarge codebases don't fit into a single LLM prompt. As projects grow, developers often need to split work into smaller pieces and guide the model with structured workflows. That doesn't mean you should build an elaborate AI harness from day one. A simple workflow often delivers t…YOUTUBE.COM
21 JulAI models keep getting caught cheatingNew research from the UK shows how nearly every model tested tried to cheat, scam or cut corners on its way to solving problems. The post AI models keep getting caught cheating appeared first on CyberScoop .CYBERSCOOP.COM
21 JulEvery Browser Extension Is a TradeoffNot all browser extensions present the same level of risk. Security teams evaluate whether an extension supports a legitimate business need and what permissions it requests before deciding whether to allow it. An extension that enables essential work may be acceptable when paired…YOUTUBE.COM
20 JulISC Stormcast For Monday, July 20th, 2026 https://isc.sans.edu/podcastdetail/10014, (Mon, Jul 20th)(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.ISC.SANS.EDU
20 JulA forensic tool for backdoored code completions in AI assistantsDevelopers lean on AI coding assistants for a growing share of their daily work, letting the tools predict the next few lines and accepting many suggestions with a quick glance. Those tools learn from large collections of code, and some of that code can be tampered with before tr…HELPNETSECURITY.COM
20 JulProduct showcase: ZoneAlarm Mobile Security adds customizable content filtering to mobile securityZoneAlarm Mobile Security is a security app from Check Point designed to protect mobile devices against phishing, malicious websites, unsafe networks, and fraudulent links. It is available for iPhone, iPad, Android, and can run on Apple silicon Macs through the App Store. Getting…HELPNETSECURITY.COM
20 JulOn Flock License Plate Tracking CamerasA recent story of a writer who was mistakenly identified, tracked, and arrested using data from Flock cameras has gone viral. The New Jersey plates that were allegedly stolen from the LA dealer were 34 03 DTM , not 34 10 DTM . But when the police report was created and the plate …SCHNEIER.COM
20 JulWhy blocking AI models won’t stop the cyber threats they createAI companies can find vulnerabilities and write patches. But only the government can build the long-term defense strategy America needs. The post Why blocking AI models won’t stop the cyber threats they create appeared first on CyberScoop .CYBERSCOOP.COM
20 JulNeo Emerges From Stealth With $100M to Control and Secure Enterprise AI SoftwareNeo raised money across seed and Series A funding rounds from Andreessen Horowitz, Bessemer Venture Partners, and others. The post Neo Emerges From Stealth With $100M to Control and Secure Enterprise AI Software appeared first on SecurityWeek .SECURITYWEEK.COM
20 JulHOLLOWGRAPH malware turns Microsoft 365 calendars into an espionage channelMicrosoft 365 calendars have become a hiding place for espionage malware, with commands and stolen files stashed inside appointments dated to the year 2050, researchers from Group-IB discovered. Targeted campaign tied to Iranian espionage activity The malware, which Group-IB call…HELPNETSECURITY.COM
20 JulThe Odyssey piracy scams surface hours after its theatrical debutChristopher Nolan’s The Odyssey had barely reached theaters before scammers began targeting people searching for pirated copies, according to Malwarebytes. Within hours of the film’s release, researchers found two separate scams running on cloned piracy sites: fake br…HELPNETSECURITY.COM
19 JulUAC-0145 Uses ClickFix CAPTCHAs to Infect Ukrainian Devices wih MalwareRussian state-sponsored threat actors have been observed leveraging the infamous ClickFix strategy to trick Ukrainian targets into infecting their own machines with data-stealing malware. According to the Computer Emergency Response Team of Ukraine (CERT-UA), the activity has bee…THEHACKERNEWS.COM
19 JulHackers abuse ViPNet software to target Russian govt agenciesAn advanced threat actor is abusing the update mechanism for the ViPNet private networking product suite to target Russian organizations, including government agencies. [...]BLEEPINGCOMPUTER.COM
19 JulScans for Hikvision Intelligent Security API, (Sun, Jul 19th)We have been following issues with Hikvision cameras for a long, long time . Like many similar products, Hikvision cameras have a long history of vulnerabilities and are often targeted by internet-wide scans that our honeypot network detects.
ISC.SANS.EDU
18 JulNew North Korean campaign uses fake coding interviews to steal developer credentialsDPRK-aligned hackers hid malware inside SVG flag images to backdoor developer job interview coding tests. Not one antivirus vendor caught it.ELASTIC.CO
18 JulVoting Works Like AuthenticationThe voting process described uses identity verification, authorization checks, machine scanning, voter confirmation, and stored paper records. Security is not only about preventing digital attacks. Physical processes also rely on layered controls to verify who can participate and…YOUTUBE.COM
17 JulISC Stormcast For Friday, July 17th, 2026 https://isc.sans.edu/podcastdetail/10012, (Fri, Jul 17th)(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.ISC.SANS.EDU
17 JulNew infosec products of the week: July 17, 2026Here’s a look at the most interesting products from the past week, featuring releases from Cloudflare, Lineation.ai, Nudge Security, and Polygraf AI. Polygraf AI Meeting Guard delivers real-time deepfake detection for enterprise meetings Polygraf AI has announced Meeting Guard, a…HELPNETSECURITY.COM
17 JulA hard drive reliability check on 341,263 drives, from 4TB to past 20TBLarge cloud storage operators track their hard drives every day, recording which units keep running and which ones drop off the racks. Backblaze does this at scale, and its Q1 2026 report covers a fleet built for continuous use. The analysis covered 341,263 hard drives, after boo…HELPNETSECURITY.COM
17 JulPrompt injection is becoming the XSS of the web agent eraAutonomous web agents read whatever a page displays, and much of that content comes from strangers. Product reviews, seller listings, and advertisements sit beside trusted site menus on a single page. An agent that reads all of that text as instructions can be steered by any of i…HELPNETSECURITY.COM
17 JulThe script, not the voice, is what makes AI voice phishing workThe call comes in at 4:40 on a Friday. The voice belongs to a senior manager, or sounds close enough, and she needs a password reset before a flight. She is polite, she is in a hurry, and she has the last four of the badge number. Researchers at Harvard Kennedy School, Meta and e…HELPNETSECURITY.COM
17 JulRisk Ledger Raises $32 Million in Series B FundingThe British firm has built a collaborative platform to help organizations address supply chain security risks. The post Risk Ledger Raises $32 Million in Series B Funding appeared first on SecurityWeek .SECURITYWEEK.COM
17 JulScammers weaponize FaceTime in attempt to drain bank accountsApple is warning iPhone and iPad users that scammers are using FaceTime calls to trick them into handing over money and account details. The company says scammers use social engineering, posing as representatives of a trusted company or entity, and contacting people by phone or o…HELPNETSECURITY.COM
17 JulClaude can now sign into websites with 1Password without exposing your credentials1Password has introduced 1Password for Claude, a beta integration that lets Anthropic’s AI assistant complete browser tasks requiring authentication without accessing users’ passwords or other secrets. The integration is available to paid Claude subscribers (Pro, Max,…HELPNETSECURITY.COM
17 JulNew Russian Campaign Uses Fake Webex and Zoom Installers to Deploy Starland RATRussian-speaking UAT-11795 spreads trojanized Zoom, Webex, and MobaXterm installers to deliver Starland RAT and the WLDR memory-only implant. Cisco Talos researchers published a detailed technical report on July 16 disclosing UAT-11795, a financially motivated, Russian-speaking t…SECURITYAFFAIRS.COM
17 JulDetails of Alan Turing’s Voice Encryption SystemReally interesting piece of cryptographic history : In November 2023, a large cache of his wartime papers—nicknamed the “Bayley papers”—was auctioned in London for almost half a million U.S. dollars. The previously unknown cache contains many sheets in Tur…SCHNEIER.COM
17 JulBeacon Security Raises $13 Million for Security Data PlatformThe startup helps organizations detect, hunt, and protect their assets across environments at machine speed. The post Beacon Security Raises $13 Million for Security Data Platform appeared first on SecurityWeek .SECURITYWEEK.COM
17 JulIndustry Reactions to Pentagon Suspending CMMC Phase 2: Feedback FridayIndustry professionals broadly agree that the suspension pauses third-party CMMC audits but not the underlying legal obligation to protect CUI. The post Industry Reactions to Pentagon Suspending CMMC Phase 2: Feedback Friday appeared first on SecurityWeek .SECURITYWEEK.COM
17 JulFake Coding Tests Deliver OtterCookie-Aligned Malware Hidden in SVG Flag ImagesNorth Korean threat actors linked to the Contagious Interview campaign have been observed employing steganography in SVG image files to conceal malicious payloads as part of a campaign using fake job postings and coding challenges. "Any user who ran the project ended up with a fo…THEHACKERNEWS.COM
17 JulGoogle must open Android to rival AI agents, EU ordersThe European Union is stepping up its actions against US tech giants under the Digital Markets Act, which is intended to ensure fair competition between digital platforms. On Thursday, the European Commission issued two rulings to limit Google’s dominance . The Commission ordered…CSOONLINE.COM
17 JulLeading members of Scattered Spider sentenced in UK to 66 months in jailThalha Jubair and Owen Flowers led and directed many attacks attributed to the hacker subset of The Com. U.S. authorities previously accused Jubair of participating in at least 120 attacks. The post Leading members of Scattered Spider sentenced in UK to 66 months in jail appeared…CYBERSCOOP.COM
17 JulMozilla study ranks Euki as the most private period trackerA Mozilla privacy investigation into six popular period-tracking apps found that some services expose device identifiers, usage details, or sensitive logs to analytics and advertising systems. Euki earned the study’s only perfect score because it stores health information locally…CYBERINSIDER.COM
17 JulMicrosoft at Black Hat USA 2026: Defending trust in the age of AI and supply chain attacksJoin Microsoft Security at Black Hat USA 2026 for supply chain research, hands-on security experiences, expert conversations, and our reception. The post Microsoft at Black Hat USA 2026: Defending trust in the age of AI and supply chain attacks appeared first on Microsoft Securit…MICROSOFT.COM
17 JulFriday Squid Blogging: Squid Washing Up on Cape Cod BeachLots of articles about this . As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered. Blog moderation policy.SCHNEIER.COM
17 JulM. Thénardier, LastPass, GitHub, EBS, Spirals, Pegasus, Shaft, Josh Marpet, and More - SWN #599M. Thénardier, LastPass, GitHub, EBS, Spirals, Pegasus, Shaft, Josh Marpet, and More on this episode of the Security Weekly News. Visit https://www.securityweekly.com/swn for all the latest episodes! Show Notes: https://securityweekly.com/swn-599YOUTUBE.COM
16 JulISC Stormcast For Thursday, July 16th, 2026 https://isc.sans.edu/podcastdetail/10010, (Thu, Jul 16th)(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.ISC.SANS.EDU
16 JulTrend Micro, Tanium, ESET and Tenable Patch Severe Product VulnerabilitiesThe cybersecurity companies patched critical and high-severity vulnerabilities in some of their products. The post Trend Micro, Tanium, ESET and Tenable Patch Severe Product Vulnerabilities appeared first on SecurityWeek .SECURITYWEEK.COM
16 JulOld UEFI Shims Expose Systems to Secure Boot BypassSigned by Microsoft, the vulnerable UEFI shim bootloaders could be abused on any system, regardless of the OS. The post Old UEFI Shims Expose Systems to Secure Boot Bypass appeared first on SecurityWeek .SECURITYWEEK.COM
16 JulVS Code agent host runs Copilot, Claude, and Codex in a dedicated processDevelopers who lean on AI coding agents often keep several editor windows open at once, each tied to its own session. The 1.129 release of Visual Studio Code reworks that setup with a dedicated agent host. A dedicated process for agent sessions The agent host is a separate proces…HELPNETSECURITY.COM
16 JulChina’s Top Cybersecurity Firms Hit by Mounting Military Procurement BansChinese cybersecurity firms are facing action from the country’s military, but it’s not due to product or technical failures. The post China’s Top Cybersecurity Firms Hit by Mounting Military Procurement Bans appeared first on SecurityWeek .SECURITYWEEK.COM
16 JulPolice take down investment fraud network that stole €100 million a monthDutch police, working alongside Belgian authorities and Europol, have dismantled a major criminal network accused of operating a global investment fraud scheme through dozens of fraudulent call centers. Investigators estimate the organization generated more than €100 million a mo…HELPNETSECURITY.COM
16 JulLineation.ai focuses on runtime security for autonomous AI agentsLineation.ai has announced the public launch of its comprehensive agentic security platform. Delivering a solution at the intersection of genAI application security and runtime defense, lineation introduces a zero trust unified control plane and a lightweight endpoint daemon that…HELPNETSECURITY.COM
16 JulEFF: Apple the only major wearable vendor offering E2EE for health dataThe Electronic Frontier Foundation (EFF) says Apple is the only major wearable manufacturer among ten leading brands it examined that offers end-to-end encryption for users' cloud-synchronized health data. The privacy group's review also found that transparency around government …CYBERINSIDER.COM
16 JulRussian hackers trojanize WebEx, Zoom apps to push Starland malwareA financially motivated Russian threat actor tracked as UAT-11795 is using trojanized software to steal credentials and cryptocurrency by deploying a new backdoor called Starland RAT. [...]BLEEPINGCOMPUTER.COM
16 JulSplunk, Zoom Patch Critical VulnerabilitiesThe flaws could allow attackers to access credentials and data, take over accounts, and escalate their privileges. The post Splunk, Zoom Patch Critical Vulnerabilities appeared first on SecurityWeek .SECURITYWEEK.COM
16 JulOak Emerges From Stealth Mode With $60 Million in FundingThe startup has built an AI-powered Identity Operating System that governs all identities across an organization’s environment. The post Oak Emerges From Stealth Mode With $60 Million in Funding appeared first on SecurityWeek .SECURITYWEEK.COM
16 JulIntruder brings AI-powered, on-demand penetration testing to web applicationsIntruder has announced the launch of AI Pentesting for web applications, providing on-demand penetration testing. Following its initial release of issue-level investigations last quarter, the platform now allows organizations to securely connect their codebases via GitHub or GitL…HELPNETSECURITY.COM
16 Jul20+ Hijacked Government Websites Became
an Attack ChannelMore than 20 Brazilian government websites were hijacked and turned into malware delivery channels in an active PhantomEnigma campaign uncovered by ANY.RUN, a leading provider of interactive malware analysis and threat intelligence solutions. The investigation revealed previously…THEHACKERNEWS.COM
16 JulDaxin Resurfaces in Taiwan Alongside Stupig Pre-Login SYSTEM BackdoorAn advanced malware previously attributed to a China-linked threat actor has resurfaced after more than four years within a Taiwan manufacturing firm, along with a previously unreported backdoor dubbed Stupig. Daxin ("srt64.sys"), as the kernel-mode rootkit is referred to, was fi…THEHACKERNEWS.COM
16 JulAI Data Centers Are Being Built Faster Than They Can Be SecuredAI infrastructure introduces new security risks that traditional data center designs were never built to handle. The post AI Data Centers Are Being Built Faster Than They Can Be Secured appeared first on SecurityWeek .SECURITYWEEK.COM
16 Jul‘ClickLock Stealer’ Bypasses macOS Security With Social Engineering, Process KillingThe new macOS malware has targeted at least 100 users to steal their passwords and cryptocurrency. The post ‘ClickLock Stealer’ Bypasses macOS Security With Social Engineering, Process Killing appeared first on SecurityWeek .SECURITYWEEK.COM
16 JulAI Governance Is Everyone's ProblemAI adoption impacts nearly every part of an organization. Security teams must evaluate risks around data, access, and technology, but they cannot manage AI governance alone. A successful AI governance program requires shared ownership across security, IT, legal, privacy, finance,…YOUTUBE.COM
16 JulSandworm hackers have a CAPTCHA trick for UkrainiansRather than verifying they are human, the CAPTCHA users are instructed to copy and paste a PowerShell command into their Windows computers.THERECORD.MEDIA
16 JulAdaptiva simplifies secure patch management for air-gapped networksAdaptiva has announced AirGap for OneSite Patch, a new capability that extends autonomous patch management to air-gapped environments. Developed in response to growing demand from government agencies, critical infrastructure operators, and large enterprises managing highly secure…HELPNETSECURITY.COM
16 JulProtecting Privacy in an AI EraDaniel Solove argues in the Wall Street Journal (alternate link ) that giving people control of their personal data is not an effective way to regulate privacy in this era. Instead, we need to hold companies accountable for their actions, similar to what we do with food and drug …SCHNEIER.COM
16 JulIran-nexus actors using AI to enhance cyber playbookA report shows state-linked and hacktivist groups have used ChatGPT and other tools for malware development, phishing and mapping out industrial sites.CYBERSECURITYDIVE.COM
16 JulGaps in network security, oversight strategy hamper US’s aviation cybersecurity regulatorsA new government audit identified several weaknesses at the two agencies that protect air travel from hackers.CYBERSECURITYDIVE.COM
16 JulLeast privilege for AI agents: Identity, access, and tool bindingAs AI agents become more autonomous, strong identity, access, and auditing controls are critical to keeping them secure. The post Least privilege for AI agents: Identity, access, and tool binding appeared first on Microsoft Security Blog .MICROSOFT.COM
16 JulThe BIOS Password MistakeNot every "BIOS password" is actually the same thing. In this conversation, the distinction is made between a BIOS setup password, a boot password, a hard drive password, and a BitLocker recovery key. Each protects a different layer of the system. Confusing these terms can lead t…YOUTUBE.COM
16 JulACR Stealer: Two observed intrusion chains amid increased threat activityFrom late April 2026 to mid-June 2026, Microsoft Defender Experts observed increased ACR Stealer activity across customer environments. These campaigns are successfully using ClickFix lures to steal browser credentials, authentication tokens, and sensitive documents from enterpri…MICROSOFT.COM
15 JulInside the Media Mind of Sasha Ingber: SpyCast PodcastOn this episode of #IMM, Christine and Madison sit down with Sasha Ingber the host of SpyCast, the International Spy Museum's flagship podcast on global intelligence, espionage and covert operationsTHECYBERWIRE.COM
15 JulISC Stormcast For Wednesday, July 15th, 2026 https://isc.sans.edu/podcastdetail/10008, (Wed, Jul 15th)(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.ISC.SANS.EDU
15 JulRecent DShield SIEM Update, (Tue, Jul 14th)The last update to the DShield SIEM [ 4 ] was in Sep 2025 which contained some minor tweaks. This update currently is using ELK stack version 8.19.15, contains some additional dashboards and new logs.
ISC.SANS.EDU
15 JulAn AI overthinking attack can tie a robot up for over a minuteRobots that read the world through cameras now lean on large vision-language models to interpret what they see and decide what to do next. These models handle images and text together, so any words that fall inside the camera frame become part of the input. A stop sign, a street …HELPNETSECURITY.COM
15 JulAWS retools Security Hub for AI and multicloud threatsAWS added AI workload protection and Microsoft Azure security monitoring to Security Hub, its centralized security platform for collecting and prioritizing security findings across cloud environments. Support for additional cloud platforms will follow. “Collecting findings …HELPNETSECURITY.COM
15 JulTuxBot v3: Inside an IoT Botnet Framework With LLM-Assisted DevelopmentTuxBot v3 Evolution, an IoT botnet framework built with LLMs. Read our analysis of its cross-compiled binaries, C2 architecture and bugs. The post TuxBot v3: Inside an IoT Botnet Framework With LLM-Assisted Development appeared first on Unit 42 .UNIT42.PALOALTONETWORKS.COM
15 JulVulnerabilities Patched by Fortinet, Ivanti, ServiceNowA critical security defect in the ServiceNow AI platform could allow remote attackers to execute arbitrary code. The post Vulnerabilities Patched by Fortinet, Ivanti, ServiceNow appeared first on SecurityWeek .SECURITYWEEK.COM
15 JulA Video Screen That Is Also a CameraAmazing : Researchers from ETH Zurich in Switzerland, however, managed to create a new type of pixel that can simultaneously do both. This hypercharged pixel, called a Fourier pixel, can generate and sense arbitrary light fields and tap into a pixel’s full potential for car…SCHNEIER.COM
15 JulUS Charges Russian Individuals and Firms for Running Cybercrime ServicesThe suspects and their companies were previously sanctioned by the United States and its allies. The post US Charges Russian Individuals and Firms for Running Cybercrime Services appeared first on SecurityWeek .SECURITYWEEK.COM
15 JulSpanish police dismantle €140 million cybercrime networkSpanish National Police have dismantled a cybercrime network accused of stealing and laundering about €140 million through fake investment platforms, CEO fraud, invoice fraud, and man-in-the-middle attacks. Four people were arrested as part of the operation: two in Portugal, one …HELPNETSECURITY.COM
15 JulNudge Security automates detection of risky OAuth grants and browser extensionsNudge Security has announced new agentic capabilities to help security and IT teams find and remediate malicious and high-risk OAuth grants and browser extensions, two of the fastest-growing and hardest to manage attack surfaces in the enterprise. The new agents continuously anal…HELPNETSECURITY.COM
15 JulBinary Defense’s NightBeacon CMD helps enterprise SOC teams automate threat investigationsBinary Defense has announced NightBeacon CMD, a standalone AI-driven SOC workbench that enterprise security teams can deploy in their own environments. Built and hardened inside Binary Defense’s live 24/7 Security Operations Center (SOC), NightBeacon CMD gives customers the…HELPNETSECURITY.COM
15 JulWindows Bind Link Attacks Can Hide Malware From EDR ToolsBitdefender researchers show how Windows bind links can create conflicting filesystem views to hide malware from endpoint security products. The post Windows Bind Link Attacks Can Hide Malware From EDR Tools appeared first on SecurityWeek .SECURITYWEEK.COM
15 JulVirtual Event Today: Cloud & Data Security SummitAttendees will be able to interact with leading solution providers and other end users facing similar challenges in securing a variety of cloud deployments. The post Virtual Event Today: Cloud & Data Security Summit appeared first on SecurityWeek .SECURITYWEEK.COM
15 JulRadware adds cloud intelligence to DefensePro X for web DDoS defenseRadware has announced a new cloud-augmented protection architecture for DefensePro X, extending the platform with new AI-powered cloud algorithms while keeping traffic inspection and mitigation locally within customer premises. The first such service released is Cloud Web DDoS Pr…HELPNETSECURITY.COM
15 JulLatticeFlow AI connects governance frameworks with continuous AI risk monitoringLatticeFlow AI has announced a platform for managing AI risk across agentic systems. Organizations are deploying autonomous AI in critical business processes, while governance approaches based on documentation and point-in-time assessments struggle to keep up with evolving risks.…HELPNETSECURITY.COM
15 JulThreat actor impersonated hundreds of brands on GitHub to push infostealer malwareA financially motivated threat actor is impersonating hundreds of brands on GitHub and pushing a smash-and-grab infostealer masquerading as legitimate downloads of popular software, Arctic Wolf threat researchers have warned. “The 292 impersonated repositories span security…HELPNETSECURITY.COM
15 JulSocure rolls out Remote Verifier for higher-risk identity checksSocure has launched Remote Verifier in RiskOS, a new identity verification tool that helps organizations verify identities requiring additional review while reducing manual effort. Socure’s AI-powered document verification solution instantly verifies more than 99% of identities o…HELPNETSECURITY.COM
15 JulXint Pulse offers on-demand black-box penetration testing for web applicationsXint.io has launched Xint Pulse, a black-box autonomous penetration testing tool that provides product security teams with on-demand security assessments of their applications. Unlike the company’s enterprise platform, which is designed for continuous testing, Xint Pulse is…HELPNETSECURITY.COM
15 JulLabubaRAT malware infiltrates Windows systems while posing as NVIDIA softwareLabubaRAT, a previously undocumented Rust-based remote access tool (RAT) masquerading as NVIDIA software that enables post-compromise operations on Windows systems, has been uncovered by Blackpoint Cyber. According to researchers, LabubaRAT creates “a reusable foothold for …HELPNETSECURITY.COM
15 JulForget the model. When it comes to cybersecurity, it’s all about the harnessIndustry has quickly developed tools meant to guide and direct frontier LLMs in cybersecurity. Attackers aren’t far behind. The post Forget the model. When it comes to cybersecurity, it’s all about the harness appeared first on CyberScoop .CYBERSCOOP.COM
15 JulProton says it rejected all 47 data requests targeting VPN users in 2026Proton has updated its Proton VPN transparency report, revealing that it received 47 legally binding requests for user information during the first half of 2026. According to the company, all 47 requests were denied because Proton VPN's no-logs policy meant it had no data capable…CYBERINSIDER.COM
15 JulTurning threat intelligence into decisive action with Defender ExpertsSecurity teams have never had more visibility, yet rarely have they felt more uncertain. Signal pours in from endpoints, identities, cloud workloads, and a sprawling mix of third-party tools. The post Turning threat intelligence into decisive action with Defender Experts appeared…MICROSOFT.COM
15 JulDems press DNI nominee Jay Clayton on election security questions, but leave dismayedClayton maintained he was not an “election denier” but wouldn’t directly answer a number of questions about the 2020 race, his predecessor’s appearance at a January election office raid and more. The post Dems press DNI nominee Jay Clayton on election security questions, but leav…CYBERSCOOP.COM
15 JulStop Treating AI Like CoworkersSome organizations are giving AI agents names, titles, and workplace roles to encourage adoption. An MIT article argues that AI agents are not coworkers, despite how they're often presented. Anthropomorphism—the tendency to assign human qualities to non-human things—can influence…YOUTUBE.COM
14 JulISC Stormcast For Tuesday, July 14th, 2026 https://isc.sans.edu/podcastdetail/10006, (Tue, Jul 14th)(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.ISC.SANS.EDU
14 JulCybersecurity jobs available right now: July 14, 2026Cyber Network Engineer Fiserv | USA | On-site – View job details As a Cyber Network Engineer, you will lead the design, governance, and security review of enterprise network architectures across on-premises and cloud environments. You will provide expertise in net…HELPNETSECURITY.COM
14 JulTelegram’s t.me domain suspended at the registry level, breaking links worldwideTelegram's t.me domain was temporarily placed on serverHold status at the registry level on Tuesday, causing all t.me links to stop resolving through the global Domain Name System (DNS). While the messaging platform itself remained operational, users were unable to access public …CYBERINSIDER.COM
14 JulMultiple Jscrambler Packages Impacted by Supply Chain AttackA threat actor poisoned several Jscrambler NPM package versions to drop a cross-platform credential stealer. The post Multiple Jscrambler Packages Impacted by Supply Chain Attack appeared first on SecurityWeek .SECURITYWEEK.COM
14 JulMicrosoft Entra ID authentication overhaul to start in September 2026Microsoft will begin rolling out passkeys as the default authentication experience for Microsoft Entra ID in the public cloud on September 1, 2026. Organizations with SMS or voice authentication enabled will automatically be enabled for passkeys. The next time users complete MFA,…HELPNETSECURITY.COM
14 JulValarian Raises $50 Million for Sovereign Infrastructure Control LayerUK-based cybersecurity firm Valarian has raised a total of $70 million for its ACRA technology. The post Valarian Raises $50 Million for Sovereign Infrastructure Control Layer appeared first on SecurityWeek .SECURITYWEEK.COM
14 JulUK charges five persons linked to fraud platform behind more than a million scam callsFive people have been charged in the UK following a National Crime Agency (NCA) investigation into Russian Coms, a caller ID spoofing service used by fraudsters. Ayoub Sehailia, 28, Zakkaria Sehailia, 30, Usman Din, 30, Denis Ozmus, 29, and Fadila Salem, 53, all of London, are ch…HELPNETSECURITY.COM
14 Jul[Video] Where protection starts: Cisco Talos Intelligence IntegrationsEvery day, defenders make high-consequence decisions with incomplete information. Learn how Cisco Talos Intelligence Integrations help reduce uncertainty by turning the latest threat intelligence into proactive protections across Cisco technologies.TALOSINTELLIGENCE.COM
14 JulNo one knows how many old shims can still bypass UEFI Secure BootThe vast majority of UEFI computers carry a Microsoft certificate that will trust a small first-stage loader called a shim, a program Microsoft signs so that Linux and assorted boot tools can run with Secure Boot on. Eleven of those signed shims turned out to be old enough to und…HELPNETSECURITY.COM
14 JulLastPass warns users of active campaign targeting master passwordsLastPass is warning customers about an active phishing campaign that uses lookalike domains and fake security notifications to trick users into revealing their master passwords or downloading malicious software. The company says the activity has no impact on LastPass's own system…CYBERINSIDER.COM
14 JulDownload: The ultimate guide to network operations managementModern network operations are too manual. Today’s IT and security teams are managing growing complexity across networks, infrastructure, tools, and workflows. The result? Slower response, duplicated effort, and operational friction. This guide explores how intelligent workflows h…HELPNETSECURITY.COM
14 JulHow Pentera Turns AI Security Workflows into Validation EnginesAI security agents are starting to influence real security decisions. They summarize findings, prioritize remediation, recommend next steps, and help teams move faster. But most still rely on fragmented risk signals: scanner output, severity scores, threat intelligence, configura…THEHACKERNEWS.COM
14 JulOAuth Client ID Spoofing Lets Attackers Validate Stolen Microsoft Entra CredentialsAt least two distinct threat actors are weaponizing a novel evasion technique called OAuth client ID spoofing in cloud campaigns, while slipping past telemetry. The activity allows users to enumerate user accounts and validate stolen credentials in Microsoft Entra ID environments…THEHACKERNEWS.COM
14 JulNew macOS malware steals passwords by posing as Apple’s crash-reporting toolJamf Threat Labs has uncovered a new macOS infostealer named CrashStealer that disguises itself as Apple’s crash-reporting tool to steal passwords, Keychain data, and cryptocurrency wallets. The malware was first spotted in May while it was still under development. By early…HELPNETSECURITY.COM
14 JulAI's Hidden Security LayerAI security is changing. The biggest risk is no longer simply whether employees are using AI—it's what they're asking AI to process. Sensitive prompts can expose confidential information in ways traditional security tools weren't built to observe. EDR, antivirus, and network moni…YOUTUBE.COM
14 JulSharp rise in AI adoption for cyber defense exposes major governance gapA report by the SANS Institute indicates a split between senior security leaders and frontline practitioners. CYBERSECURITYDIVE.COM
14 JulUpcoming Speaking EngagementsThis is a current list of where and when I am scheduled to speak: I’m speaking (virtually) at the Policy-Relevant Privacy Research Workshop in Calgary, Canada, on Monday, July 20, 2026. I’m speaking at Boston Leadership Exchange in Boston, Massachusetts, USA, on Wednesday, July 2…SCHNEIER.COM
14 JulAdobe Patches Critical ColdFusion VulnerabilitiesThe ColdFusion security defects could allow attackers to execute arbitrary code or elevate their privileges. The post Adobe Patches Critical ColdFusion Vulnerabilities appeared first on SecurityWeek .SECURITYWEEK.COM
14 JulStop Securing AI in SilosAI application security includes many protections—input validation, output sanitization, infrastructure controls, and more. Too often, they're evaluated independently instead of as parts of a larger system. A holistic approach allows security controls to inform each other, more c…YOUTUBE.COM
14 JulNearly 300 GitHub repos pose as legit software to push malwareA threat actor has published hundreds of fake GitHub repositories impersonating legitimate software and security projects to distribute infostealer malware. [...]BLEEPINGCOMPUTER.COM
14 JulMr. Data, Joomla Babooa, 1VPNS, RabbitMQ, UEFI, Center 16, Sextortion, Aaran Leyland - SWN #598Mr. Data, Joomla Babooa, 1VPNS, RabbitMQ, UEFI, Center 16, Sextortion, Aaran Leyland, and More on the Security Weekly News. Visit https://www.securityweekly.com/swn for all the latest episodes! Show Notes: https://securityweekly.com/swn-598YOUTUBE.COM
14 JulWhite House details ‘Gold Eagle’ clearinghouse for AI cyber threatsThe White House said the clearinghouse has already started to receive intelligence on vulnerabilities and prioritize patches. The post White House details ‘Gold Eagle’ clearinghouse for AI cyber threats appeared first on CyberScoop .CYBERSCOOP.COM
13 JulISC Stormcast For Monday, July 13th, 2026 https://isc.sans.edu/podcastdetail/10004, (Mon, Jul 13th)(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.ISC.SANS.EDU
13 JulEnterprises are rethinking where their AI applications runGrowing demand for compute capacity, power, cooling and low-latency connectivity is prompting organizations to reassess where AI applications run, according to CoreSite. Public cloud continues to support experimentation and rapid deployment, while colocation is increasingly used …HELPNETSECURITY.COM
13 JulA hardware security AI assistant that checks chips for hidden backdoorsChip designers license blocks of circuitry from outside vendors and drop them into larger products. A single processor can carry components from a range of suppliers, each written by a company the buyer may never deal with directly. A malicious supplier can bury a hidden circuit …HELPNETSECURITY.COM
13 JulAI-generated code has made security debt a governance problemMoving from tool approval to true governance is the only way for CISOs to keep pace with the accelerating velocity of software risk. The post AI-generated code has made security debt a governance problem appeared first on CyberScoop .CYBERSCOOP.COM
13 JulProgress Prompts ShareFile Storage Zone Controller Shutdown Amid Security ConcernsThe company notified customers to manually shut down their servers while it is investigating a credible threat. The post Progress Prompts ShareFile Storage Zone Controller Shutdown Amid Security Concerns appeared first on SecurityWeek .SECURITYWEEK.COM
13 JulClaude Code users keep 50% higher limits until July 19Anthropic has extended a limited-time promotion that increases weekly usage limits in Claude Code by 50% through July 19, 2026, at 11:59 PM PT. When the promotion ends, weekly usage limits will return to their standard levels without any changes to users’ plans or billing. …HELPNETSECURITY.COM
13 JulAI Data Centers and the Concentration of WealthThis essay was written with Nathan E. Sanders, and originally appeared in The Guardian . Opposition to AI data centers has emerged as a primary theme in US politics, one that—surprisingly—doesn’t fall along party lines. We applaud people coming together for cons…SCHNEIER.COM
13 JulEU Targets Russian Intelligence Officers Accused of Running a Yearslong Cyber Spying CampaignThe move targeted people and entities accused of links to an online spying network that the EU claims targeted governments and carried out sabotage operations against critical infrastructure. The post EU Targets Russian Intelligence Officers Accused of Running a Yearslong Cyber S…SECURITYWEEK.COM
13 JulRust-proof your code with our new Testing Handbook chapterWe’ve added a new chapter to our Testing Handbook : a comprehensive guide to security testing Rust programs. This chapter covers the tools and techniques we use at Trail of Bits to validate the security of Rust programs and systems. fn main () {( | f: & dyn Fn ( u128 )-> B…TRAILOFBITS.COM
13 JulSecurity threat prompts Progress to disable ShareFile accounts, tell customers to shut down serversA “credible external security threat” targeting Progress Software’s ShareFile Storage Zone Controllers (SZC) – the on-premises, customer-managed server components where organizations store files shared via this popular enterprise platform – has spurr…HELPNETSECURITY.COM
13 JulAttacker Uses Suspected AI-Generated PowerShell Script to Map Active DirectoryCybersecurity researchers have flagged an intrusion in which an unknown threat actor leveraged a vibe-coded PowerShell script for Active Directory (AD) enumeration. "The script looked for the Domain Controller (DC) and mapped users, computers, and domains, before creating a direc…THEHACKERNEWS.COM
13 JulCybersecurity M&A Roundup: 37 Deals Announced in June 2026Significant cybersecurity M&A deals announced by 1Password, Accenture, Cisco, F5, Rubrik, and SailPoint. The post Cybersecurity M&A Roundup: 37 Deals Announced in June 2026 appeared first on SecurityWeek .SECURITYWEEK.COM
13 JulFake OAuth client IDs are helping attackers slip past sign-in logsAttackers running account enumeration against Microsoft cloud tenants have added a step that keeps their probing out of the usual telemetry. They spoof the OAuth client ID, the globally unique identifier assigned to an application and passed as client_id in an authentication requ…HELPNETSECURITY.COM
13 JulCloudflare Precursor uses continuous behavioral analysis to stop advanced botsCloudflare has announced the general availability of Precursor, a next-generation, continuous behavioral validation engine for bot management. Precursor runs seamlessly inside web browsers to monitor entire user sessions in order to detect bot automation. Unlike static CAPTCHAs, …HELPNETSECURITY.COM
13 JulLumen expands managed detection and response with Cortex XSIAM integrationLumen Technologies has announced Lumen Defender Advanced Managed Detection and Response (AMDR) for Palo Alto Networks Cortex XSIAM. Attackers are increasingly operating earlier in the lifecycle while AI is accelerating threat speed. This expanded service will bring together Lumen…HELPNETSECURITY.COM
13 JulEU Targets FSB-Linked Hackers in New Sanctions Over Cyber SabotageEU sanctions target nine people and four entities tied to Russia’s FSB over a 15-year cyberespionage and critical infrastructure sabotage campaign. The European Union imposed sanctions on Monday targeting nine individuals and four entities linked to a Russian cyberespionage…SECURITYAFFAIRS.COM
13 JulYour CI Pipeline Becomes the AttackDependency pinning helps ensure consistent builds, but it doesn't protect a CI/CD pipeline if an attacker can modify the workflow itself. A workflow is ultimately executable code, often defined in a YAML file, running on infrastructure that may have access to cloud credentials or…YOUTUBE.COM
13 JulHacker Conversations: Jesse McGraw (GhostExodus), From Blackhat Hacker to RedemptionOnce a notorious blackhat hacker, McGraw shares his journey from high school hacking and prison to redemption as a cybersecurity advocate. The post Hacker Conversations: Jesse McGraw (GhostExodus), From Blackhat Hacker to Redemption appeared first on SecurityWeek .SECURITYWEEK.COM
13 JulEU and UK blacklist Russia’s cyber operators over efforts to destabilize EuropeThe EU and the UK jointly sanctioned dozens of Russian individuals and entities, accusing Moscow of coordinating a malicious cyber ecosystem targeting Europe, its member states, and international partners. The UK sanctioned 24 individuals and entities, while the EU imposed restri…HELPNETSECURITY.COM
13 JulWestern intelligence agencies warn of Russian hackers targeting critical infrastructure.Progress Software tells ShareFile admins to shut down servers immediately. Researchers identify a new macOS infostealer.THECYBERWIRE.COM
13 JulHackers find a new trick to collect Microsoft Entra user data without raising red flagsOrganizations should check their logs for signs of an increasingly popular obfuscation technique, Proofpoint said.CYBERSECURITYDIVE.COM
13 JulCloudflare expands behavioral tracking to fight AI bots, says user privacy protectedCloudflare has introduced Precursor, a new bot detection system that continuously monitors visitor behavior throughout an entire browsing session instead of relying solely on CAPTCHAs or isolated verification points. While the company says the technology is designed to combat inc…CYBERINSIDER.COM
13 JulGigaWiper Lets Threat Actors Choose Their Own Destructive AttackA modular implant borrows from various malware families to combine both backdoor and wiper activities to maximize impact and minimize operational output.DARKREADING.COM
13 JulLiving on the Edge: How Threat Actors Use Network Infrastructure Against YouThe post Living on the Edge: How Threat Actors Use Network Infrastructure Against You appeared first on Eclypsium | Supply Chain Security for the Modern Enterprise .ECLYPSIUM.COM
13 JulDefending SaaS-based applications against ShinyHunters OAuth abuseMicrosoft Threat Intelligence identified threat actor activity with overlapping tradecraft commonly associated with ShinyHunters, including voice phishing (vishing), supply-chain compromise, and misconfigured guest access targeting SaaS-based applications. The post Defending SaaS…MICROSOFT.COM
11 JulWireshark 4.6.7 Released, (Sat, Jul 11th)Wireshark release 4.6.7 fixes 12 vulnerabilities and 16 bugs.
ISC.SANS.EDU
11 JulGhost Accounts Abuse GitHub API in Mass Recon CampaignMultiple campaigns are using ghost accounts to map GitHub organizations, including their repositories and members. The post Ghost Accounts Abuse GitHub API in Mass Recon Campaign appeared first on SecurityWeek .SECURITYWEEK.COM
10 JulISC Stormcast For Friday, July 10th, 2026 https://isc.sans.edu/podcastdetail/10002, (Fri, Jul 10th)(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.ISC.SANS.EDU
10 JulNew infosec products of the week: July 10, 2026Here’s a look at the most interesting products from the past week, featuring releases from Attestiv, Automox, Codenotary, and First Recon AI. Codenotary launches AI security platform that learns from AI agent behavior Codenotary has announced AgentMon 3, the latest generation of …HELPNETSECURITY.COM
10 JulAWS gives its ERP agent deny-by-default rules and a separate identityAccounts receivable teams at large companies spend hours each day matching incoming bank payments to invoices by hand. When those payments sit unmatched for days, cash flow suffers and days sales outstanding climbs. The same pattern repeats across blocked invoices, purchase order…HELPNETSECURITY.COM
10 JulMost data brokers won’t tell you what happened to your deletion requestData brokers collect personal details on most adults in the United States and sell them to buyers that include employers, landlords, insurance companies, and government agencies. California gives residents a way to push back. You can ask a broker to delete your records, or to sto…HELPNETSECURITY.COM
10 JulNetwork of 200 GitHub Repositories Used for Malware InfectionA Go module is used to load PowerShell code that fetches a resolver from public dead drops to execute Windows malware. The post Network of 200 GitHub Repositories Used for Malware Infection appeared first on SecurityWeek .SECURITYWEEK.COM
10 JulMeta automatically opts public Instagram accounts into AI image generationMeta has launched Muse Image, a new AI image-generation model that lets users incorporate photos from public Instagram accounts into AI-generated images by simply tagging a username in a prompt. The feature has sparked privacy concerns because public Instagram accounts are enroll…CYBERINSIDER.COM
10 JulFlying with the Flipper ZeroWhy is the world so alarmed about taking the Flipper on board planes? Is it just poorly educated armchair cyber commentators of the ‘don’t use open Wi-Fi / USB juicejacking’ style of fearmongering, or is there something to it? TL;DR Why are people worried? …PENTESTPARTNERS.COM
10 JulLineageOS adds browser-based flashing tool for older Android devicesLineageOS has introduced a browser-based flashing tool that significantly lowers the barrier to installing the popular aftermarket Android operating system. The new feature makes it easier for users to install LineageOS on supported devices, helping extend the life of smartphones…CYBERINSIDER.COM
10 JulHackers Use Fake Microsoft Entra Passkey Enrollment to Gain Microsoft 365 AccessA threat actor has been targeting organizations spanning multiple sectors with voice-based fake security requests that prompt Microsoft 365 users to enroll a new Entra passkey with an aim to carry out data extortion attacks. The threat actor, tracked by Okta under the moniker O-U…THEHACKERNEWS.COM
10 JulOkta Warns of Vishing Attacks Targeting Microsoft 365 CustomersThe attackers call victims to direct them to phishing websites mirroring Microsoft Entra ID login pages. The post Okta Warns of Vishing Attacks Targeting Microsoft 365 Customers appeared first on SecurityWeek .SECURITYWEEK.COM
10 JulZimbra patches a critical flaw in its Classic Web Client.GigaWiper combines espionage capabilities with destructive payloads. Helix extortion gang conducts device-code phishing attacks.THECYBERWIRE.COM
10 JulMicrosoft Warns New 'GigaWiper' Malware Combines Espionage and Destructive CapabilitiesA new multi-purpose backdoor allows cyber threat actors to conduct both quiet espionage activity and destructive wiping operationsINFOSECURITY-MAGAZINE.COM
10 JulSecuring our future: July 2026 progress report on Microsoft’s Secure Future InitiativeMicrosoft’s latest Secure Future Initiative report outlines progress on secure foundations, AI-powered defense, and future-ready cybersecurity. The post Securing our future: July 2026 progress report on Microsoft’s Secure Future Initiative appeared first on Microsoft Securi…MICROSOFT.COM
10 JulBorg, GitLost, ColdFusion, GodDamn, GhostApproval, OWA, Epaphroditus, Josh Marpet & More - SWN #597Borg, GitLost, ColdFusion, GodDamn, GhostApproval, OWA, Epaphroditus, Locutus, Josh Marpet, and More on this episode of the Security Weekly News. Visit https://www.securityweekly.com/swn for all the latest episodes! Show Notes: https://securityweekly.com/swn-597YOUTUBE.COM
9 JulISC Stormcast For Thursday, July 9th, 2026 https://isc.sans.edu/podcastdetail/10000, (Thu, Jul 9th)(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.ISC.SANS.EDU
9 Jul_HELP_ME_ESCAPE_FROM_BELARUS_PLEASE_ [Guest Diary], (Tue, Jul 7th)[This is a Guest Diary by Jason Callahan, an ISC intern as part of the SANS.edu BACS program]
ISC.SANS.EDU
9 JulA single malware file can outweigh an entire AI datasetAntivirus vendors and security startups keep shipping AI features that promise to read malware the way a seasoned analyst would. The results inside security teams tell a quieter story. A new paper argues that static analysis of software, the job of deciding whether a program is m…HELPNETSECURITY.COM
9 JulProduct showcase: Protect your iPhone with McAfee Mobile SecurityMcAfee Mobile Security for iOS combines scam protection, web protection, VPN, Wi-Fi security, and device security checks in a single app. It is also available for Android. After downloading the app from the App Store, I created an account and completed a short onboarding process.…HELPNETSECURITY.COM
9 JulWireshark 4.6.7 patches a dozen security flawsNetwork analysts who open packet captures in Wireshark push untrusted data through a large set of protocol dissectors, and each parser is a spot where a malformed frame can trip up the software. The 4.6.7 maintenance release closes twelve of those weak points. The fixes reach fro…HELPNETSECURITY.COM
9 JulMessaging fraud trends point to smarter attacks, stronger blockingFraudsters spent 2025 investing in scale. New routes, new tools, and higher message volumes moved through the SMS, voice, and chat channels that businesses rely on to reach customers. Money follows that activity. The Communications Fraud Control Association puts global telecom fr…HELPNETSECURITY.COM
9 JulMalicious AI agent skills can slip past the scanners built to stop themDevelopers who build with AI coding agents grab capabilities off public marketplaces the same way they grab packages from npm or PyPI. The add-ons are called agent skills. Each one is a little bundle of plain-English instructions, scripts, and files that a tool such as Claude Cod…HELPNETSECURITY.COM
9 JulThe fake report message that ends with a stolen Reddit accountA direct message arrives on Reddit from a stranger, and it invites a reply. That reply is the point. This scheme runs on social engineering, with no malware and no malicious links, and it has spread across Reddit, Discord, and similar platforms. The goal is a single piece of info…HELPNETSECURITY.COM
9 Jul8Layers Raises $2.9 Million for Identity Security PlatformThe Spanish startup has closed an extended pre-seed funding round two months after launching its digital identity protection platform. The post 8Layers Raises $2.9 Million for Identity Security Platform appeared first on SecurityWeek .SECURITYWEEK.COM
9 JulDetection engineering in the AI eraAI is lowering the barrier to sophisticated attacks. Explore why detection engineering matters and where most programs fall short. The post Detection engineering in the AI era appeared first on Intezer .INTEZER.COM
9 JulAWS centralizes access, spending, and governance for ClaudeClaude apps gateway for AWS is a self-hosted control plane that gives organizations a single point of control over access, costs, and policies for Claude Code and Claude Desktop. It replaces per-developer cloud credentials, manual distribution of managed settings to developer lap…HELPNETSECURITY.COM
9 JulNetSPI pairs AI pentesting with expert-validated security findingsNetSPI has announced the expansion of its AI-powered continuous pentesting platform, broadening the suite of services that organizations can use to ensure critical assets are always protected. The new services comprise continuous web application penetration testing, continuous AI…HELPNETSECURITY.COM
9 JulYour coding agent says no in chat and yes in the codeMillions of developers share their keyboard with GitHub Copilot. Inside Visual Studio Code, it opens their files, writes and edits code, runs scripts, and reworks its own output across many turns. The safety testing that vets these agents still runs on chatbot rules: one harmful …HELPNETSECURITY.COM
9 JulThe Two BIOS Passwords Everyone ConfusesTL;DR: The setup password and the boot password are different controls that protect different things; vendors give them half a dozen different names, and mixing them up leaves real gaps below the OS. Two Passwords, Two Different Jobs When someone tells me “we set the BIOS p…ECLYPSIUM.COM
9 JulVibe-Coded Malware Caught in Active Directory AttackHuntress found a threat actor using vibe-coded PowerShell to map an Active Directory networkINFOSECURITY-MAGAZINE.COM
9 JulCitrix launches MCP Gateway to secure enterprise AI agentsCitrix has announced updates to its high-performance application delivery and security platform NetScaler, introducing MCP Gateway functionality to allow enterprises to securely route, govern and observe agent traffic to backend Model Context Protocol (MCP) servers. In addition, …HELPNETSECURITY.COM
9 JulVectogate debuts platform to secure and govern autonomous AI agentsVectogate has launched an AI governance platform designed to give organizations centralized control over AI agents as they increasingly take on autonomous tasks with access to sensitive data and internal business systems. The company aims to address one of the key governance chal…HELPNETSECURITY.COM
9 JulQIZ Security Raises $17 Million for Cryptographic Governance PlatformThe Israeli company has developed a cryptographic posture and post-quantum cryptography management platform. The post QIZ Security Raises $17 Million for Cryptographic Governance Platform appeared first on SecurityWeek .SECURITYWEEK.COM
9 JulUK Government Rolls Out Agentic AI Defense Plan Alongside Industry PledgeTwo announcements on July 7, 2026, demonstrate the government’s determination to improve the level of cybersecurity within the UK. The post UK Government Rolls Out Agentic AI Defense Plan Alongside Industry Pledge appeared first on SecurityWeek .SECURITYWEEK.COM
9 JulExtortion crew hijacks Microsoft 365 accounts via fake passkey setupThe Pink cyber extortion crew is tricking employees into giving them access to their Microsoft 365 accounts by faking Entra passkey enrollment requests. The attack The attack starts with a vishing call to an employee. The caller poses as IT and says it’s time to set up a pa…HELPNETSECURITY.COM
9 JulHow GitHub gave every repository a durable ownerGitHub had over 14,000 repositories. Fewer than half had clear ownership. Here's how we gave every active repository a validated owner in under 45 days, archived the rest, and made ownership the foundation for everything that followed. The post How GitHub gave every repository a …GITHUB.BLOG
9 JulInterpol cybercrime crackdown nets 5,800 arrests across 97 countriesThe anti-fraud crackdown, dubbed Operation First Light, identified more than 142,000 victims of various social-engineering scams. The post Interpol cybercrime crackdown nets 5,800 arrests across 97 countries appeared first on CyberScoop .CYBERSCOOP.COM
8 JulISC Stormcast For Wednesday, July 8th, 2026 https://isc.sans.edu/podcastdetail/9998, (Wed, Jul 8th)(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.ISC.SANS.EDU
8 JulOpenAI and Anthropic are pulling in different directionsCompanies are handing routine operational decisions to AI agents that plan, remember, and act on their behalf. These agents run on statistical models, and their behavior can drift across weeks and months. That drift opens a security gap outside the reach of standard monitoring to…HELPNETSECURITY.COM
8 JulmacOS is becoming a proving ground for AI agentsSomewhere right now, a Mac Mini is sitting on a shelf doing someone’s chores. Nobody’s watching it. It reads a version number out of Terminal, hops over to Safari, digs up a release year, then quietly files a reminder, the kind of dull three-app errand a human would g…HELPNETSECURITY.COM
8 JulHow to implement a continuous offensive security testing programThe hard part was never finding the exposure. It was deciding what to do about it: whether to patch, mitigate, monitor, or accept, and banking that that decision would still hold tomorrow. A penetration test answers this question for the day it runs, then quietly expires. The env…HELPNETSECURITY.COM
8 JulClaude Cowork turns your phone into a remote control for AI workAnthropic started rolling out Claude Cowork, an AI agent that completes multi-step tasks, in beta for Max users on mobile and the web. They describe a goal, and Claude plans the work, uses the required tools, and produces outputs such as documents, spreadsheets, presentations, an…HELPNETSECURITY.COM
8 JulThousands of malicious AI skills found capable of stealing data, running malwareAI agents can browse the web, use external tools, execute commands, and perform tasks on behalf of users. Many rely on skills that define how they interact with services and data. Malicious skills can abuse those capabilities to steal data, execute malware, or manipulate an agent…HELPNETSECURITY.COM
8 JulScienceLogic adds geographic service visibility to Skylar OneScienceLogic has released the “Kyoto” update for Skylar One, the core observability offering in its AI Platform. The release adds geographic service visibility, simplified location and device management, enhanced relationship mapping, and platform updates aimed at imp…HELPNETSECURITY.COM
8 JulCodenotary launches AI security platform that learns from AI agent behaviorCodenotary has announced AgentMon 3, the latest generation of its enterprise AI security platform, introducing adaptive runtime security policies. These continuously evolve as AI agents operate across an organization by learning from customer-specific workflows, observed behavior…HELPNETSECURITY.COM
8 JulChina-Linked UAT-7810 Expands ORB Network With New LONGLEASH MalwareA Chinese threat actor tracked as UAT-7810 is actively refining its bespoke malware to expand its Operational Relay Box (ORB) network by breaking into internet-facing networking devices. According to findings from Cisco Talos, UAT-7810 is an advanced persistent threat (APT) actor…THEHACKERNEWS.COM
8 JulWhat Happens if China Hacks the US Water Supply? I Went to a Secret War Game to Find OutBurst water mains. Evacuated hospitals. In a closed-door simulation, insurers played out their response to a mass disruption by China’s Volt Typhoon hackers—and found a nightmare scenario.WIRED.COM
8 JulAutomox MCP Server adds visual reviews and AI-driven patch policy creationAutomox has released Automox MCP Server 2.2, adding interactive review surfaces, first-class Patch by Severity policy creation, and live capability discovery to its governed agentic interface for endpoint operations. The release advances Automox MCP beyond natural-language access…HELPNETSECURITY.COM
8 JulNew Malicious Campaign Delivers Vidar Infostealer and Monero Crypto MinerCyber threat actors are infecting victims with the Vidar stealer and the XMRig cryptocurrency miner in a new malicious campaignINFOSECURITY-MAGAZINE.COM
8 JulTelegram-Hosted RedWing Malware Lets Anyone Rent Android Spyware ToolsRedWing: The Android Banking Trojan You Can Rent on Telegram for Less Than a Coffee Subscription Zimperium’s zLabs team has uncovered RedWing, an Android spyware operation sold as a subscription service through Telegram, with links to Russian threat actors and apparent root…SECURITYAFFAIRS.COM
8 JulThreat Actors Uses Agentic AI to Rapidly Compromise Cloud TargetSygnia report details how agentic AI accelerated weeks-long attack to just 72 hoursINFOSECURITY-MAGAZINE.COM
8 JulDNSFilter makes its DNS threat protection available to OEM partnersDNSFilter has launched an Original Equipment Manufacturing (OEM) program that lets external ISPs, cybersecurity firms, device makers, and other consumer app developers to embed their DNS threat protection, domain analysis, and privacy solutions into their own platforms and soluti…HELPNETSECURITY.COM
8 JulAttestiv DeepScan combines AI and forensic analysis for file validationAttestiv announced the launch of DeepScan, a new platform built to help organizations automatically validate submitted files before they drive critical business decisions. DeepScan represents a major architectural shift for Attestiv and its customers: moving from detecting fake o…HELPNETSECURITY.COM
8 JulWebinar Today: Why Email Security Keeps FailingJoin the webinar as we break down why email-layer defenses alone can’t keep pace with the modern phishing ecosystem. The post Webinar Today: Why Email Security Keeps Failing appeared first on SecurityWeek .SECURITYWEEK.COM
8 JulCensys Internet Map links real-time DNS data to internet infrastructureCensys has announced the expansion of the Censys Internet Map to include real-time DNS visibility. Security teams can now seamlessly pivot between domains, names, and the Internet infrastructure behind them on the Censys Platform. With active DNS data now part of the Internet Map…HELPNETSECURITY.COM
8 JulBlackpoint AI SOC Agent autonomously contains identity-based attacksBlackpoint Cyber has unveiled the generally available autonomous response capability, Blackpoint AI SOC Agent for identity threat detection and response (ITDR). Using an AI + human hybrid model, the AI SOC Agent acts on high-confidence threats targeting Microsoft 365 and Google W…HELPNETSECURITY.COM
8 JulFirst Recon AI Security Runtime helps enterprises govern AI with audit-ready evidenceFirst Recon AI has announced the public launch and general availability of First Recon’s AI Security Runtime, a security platform that both governs and secures how enterprises use artificial intelligence across an organization. First Recon’s runtime inspects every AI …HELPNETSECURITY.COM
8 JulFalconStor Cloud Clean Room enables validated recovery without dedicated infrastructureFalconStor has announced FalconStor Cloud Clean Room, an on-demand infrastructure platform designed to let organizations perform validated recovery testing in a persistent secure enclave. Each test starts from a known state, reducing the risk of carrying issues over from previous…HELPNETSECURITY.COM
8 JulSCMBANKER Malware Uses ClickFix Lures to Target Mexican Banking UsersA new banking fraudulent operation is targeting customers of Mexican banks, fintech, payment processors, and cryptocurrency exchanges using ClickFix lures. The activity cluster, tracked by Elastic Security Labs under the moniker REF6045, involves infecting victims through fake CA…THEHACKERNEWS.COM
8 JulChina-Linked APT Expands Proxy Network With New MalwareCisco Talos said China-linked APT UAT-7810 is growing its proxy relay network with new malwareINFOSECURITY-MAGAZINE.COM
8 JulUS enterprises incorporate cyber risk into larger strategic focusThe rapid adoption of AI and cloud is forcing significant shifts toward business resilience and financial impact.CYBERSECURITYDIVE.COM
8 JulTrojanized LetsVPN installer gives attackers remote access to Windows PCsA malicious Windows installer masquerading as LetsVPN deploys a remote access trojan (RAT) alongside the legitimate VPN software. The malware, dubbed GoodPersonRAT, grants attackers full control over infected systems and employs multiple stealth techniques to evade detection. The…CYBERINSIDER.COM
8 JulDuckDuckGo browser adds built-in YouTube ad blocking systemDuckDuckGo has added built-in YouTube ad blocking to its privacy-focused browser, allowing users to watch most YouTube videos without pre-roll or mid-roll advertisements. The feature is now enabled by default on Windows, macOS, and iPhone, while Android users can enable it manual…CYBERINSIDER.COM
8 JulChina-Linked APT Expands Arsenal With New ‘Leash’ BackdoorsCisco says the threat actor behind the LapDogs campaign has expanded its SOHO router malware toolkit with LongLeash, DogLeash, and JarLeash backdoors. The post China-Linked APT Expands Arsenal With New ‘Leash’ Backdoors appeared first on SecurityWeek .SECURITYWEEK.COM
8 JulAI Surveillance Is Being Supercharged–And It Will Chill Social ProgressSenior research fellow Jon Penney and co-author Bruce Schneier argue that widely deploying AI surveillance could be corrosive to democracy. The post AI Surveillance Is Being Supercharged–And It Will Chill Social Progress appeared first on The Citizen Lab .CITIZENLAB.CA
8 JulTaiwan charges two businessmen over alleged role in Chinese espionage campaignA company based in Taiwan was leasing out accounts on the popular LINE messaging app to Chinese spies, according to prosecutors, who charged two men in the alleged scheme.THERECORD.MEDIA
8 JulEntra passkey enrollment vishing targets Microsoft 365 usersA threat actor has been targeting organizations across multiple sectors with voice-based fake security requests that ask Microsoft 365 users to enroll a new Entra passkey. [...]BLEEPINGCOMPUTER.COM
8 JulProtecting Microsoft at AI speed: How SFI proactively hardens our cloudAt Microsoft we encompass these security requirements, along with threat knowledge, and operational frameworks in our Secure Future Initiative (SFI), to guide what a well-defended cloud service looks like. But defining the requirements is only the start. Meeting the requirements …MICROSOFT.COM
8 JulFrench nonprofit starts global intelligence and research hub for AI cyber threatsOne of the project’s top goals is stitching together an international, quick response coalition of governments, businesses and civil experts for AI-related threats. The post French nonprofit starts global intelligence and research hub for AI cyber threats appeared first on CyberS…CYBERSCOOP.COM
8 JulAI Could Shrink Leadership PipelinesMany discussions about AI focus on entry-level jobs. But organizational changes don't stop there. If AI reduces the need for some entry-level and middle-management roles, it could also shrink the pipeline of employees who traditionally develop into senior leaders. Fewer opportuni…YOUTUBE.COM
7 JulISC Stormcast For Tuesday, July 7th, 2026 https://isc.sans.edu/podcastdetail/9996, (Tue, Jul 7th)(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.ISC.SANS.EDU
7 JulReview: Building Machine Learning Systems with a Feature StoreMany people come to machine learning by training a model on a tidy dataset, and then meet a harder problem: making that model work for real users, on fresh data, every day. Jim Dowling’s O’Reilly book, Building Machine Learning Systems with a Feature Store, is written…HELPNETSECURITY.COM
7 JulYour company already adopted AI and nobody is governing accessIn this Help Net Security video, Antoine Berton, CTO at Elba Security, breaks down the AI attack surface. Your company already adopted AI, and every adoption creates access that nobody governs. A quick click on a Friday afternoon connects a free AI tool to your Google Workspace, …HELPNETSECURITY.COM
7 JulResearchers make the case for a cybersecurity AI scientistAutonomous AI agents have started doing real security work. Language-model agents probe software for flaws, run penetration tests, and chain together attack steps that once needed a human operator. Research about security has stayed slower and more manual, built around expert sca…HELPNETSECURITY.COM
7 JulKeyfactor Scores $1 Billion+ Investment for AI, Post-Quantum SecurityThe investment will accelerate Keyfactor's machine identity, PKI, and cryptographic security platform as enterprises prepare for AI-driven and post-quantum threats. The post Keyfactor Scores $1 Billion+ Investment for AI, Post-Quantum Security appeared first on SecurityWeek .SECURITYWEEK.COM
7 JulAI-Generated Malware Powers New Armored Likho APT CampaignArmored Likho APT uses AI-generated malware, phishing, and BusySnake Stealer to target governments and power grids in Russia, Kazakhstan, and Brazil. Kaspersky’s threat research team has documented a previously unknown APT group they’re calling Armored Likho, also tra…SECURITYAFFAIRS.COM
7 JulGoogle Is Suing Chinese Scammers Who Are Using GeminiNot sure this will have any effect, but I support the effort: According to Google’s legal filing, Outsider Enterprise operates through Telegram. The group offers phishing-as-a-service to individuals who may not be technically savvy enough to set up fraudulent websites and t…SCHNEIER.COM
7 JulUAT-7810 continues building ORB networks using new malwareTalos’ latest findings on UAT-7810 indicate that the threat actor continues to develop their custom-made malware.TALOSINTELLIGENCE.COM
7 JulThe Navy Spy who Sold Secrets for $377 a YearYou may have heard of the long-running TV show NCIS, based on the real work of the Naval Criminal Investigative Service. But you may never have heard of a unit inside it, called the Office of Special Projects, where staff work on espionage cases that originate inside the U.S. Nav…THECYBERWIRE.COM
7 JulCISO Conversations: Tarah Wheeler, Cybersecurity Leader, Thought Leader and Original ThinkerTarah Wheeler is CISO at TPO Group, a firm that provides cybersecurity consultancy for high-stakes organizations. But despite this elevated position, her journey was far from typical. The post CISO Conversations: Tarah Wheeler, Cybersecurity Leader, Thought Leader and Original Th…SECURITYWEEK.COM
7 JulBarracuda adds PAM and identity protection with Evo Security acquisitionBarracuda Networks has acquired Evo Security. The acquisition expands the BarracudaONE platform’s identity security capabilities by adding privileged access management (PAM), access control, identity protection, and identity threat detection and response. By combining Evo S…HELPNETSECURITY.COM
7 JulCyberProof Agentic MXDR Service brings AI agents to managed detection and responseCyberProof has announced the launch of the CyberProof Agentic MXDR Service which connects AI agents with human expertise and presents quantifiable security outcomes with CyberProof’s Reveal360. CyberProof modernizes managed detection and response by shifting security operat…HELPNETSECURITY.COM
7 JulPost-Mythos Cybersecurity: Can You Automate Infrastructure Assurance with AI?TL;DR: Security leaders should absolutely reassess their cybersecurity programs in light of Mythos, Daybreak, and other frontier AI models. AI will make some workflows easier to automate, some internal tools easier to build, and some vendor spend harder to justify. But the risk-r…ECLYPSIUM.COM
7 JulSecurity or Privacy: Which Comes First?Security and privacy don't always point in the same direction. Many modern applications rely on stronger verification or deeper system access to reduce fraud, cheating, and abuse. Those protections can also increase privacy concerns. Whether it's kernel-level anti-cheat software …YOUTUBE.COM
7 JulBusinesses modernizing networks for AI fear expanding attack surface, limited visibilityIT leaders are worried that security controls aren’t keeping pace with threats to AI systems.CYBERSECURITYDIVE.COM
7 JulRedWing MaaS Packages Android Bank Fraud as a Telegram Rental ServiceA new Android malware operation called RedWing is being rented out on Telegram as a ready-made bank-fraud service. It lets even low-skill criminals take over a victim's phone, steal their banking logins, and capture the one-time codes that protect their accounts. Zimperium's zLab…THEHACKERNEWS.COM
7 JulMicrosoft Windows telemetry identified hacker despite VPN useMicrosoft identified an alleged Scattered Spider member through Windows telemetry despite the suspect using a VPN to mask his IP address. The details appear in the superseding criminal complaint against Peter Stokes, whose extradition to the United States we covered last week. A …CYBERINSIDER.COM
7 JulMore Odd DNS Records: NIMLOC, (Tue, Jul 7th)Yesterday, I talked about NAPTR records and how they are related to RCS. But there is another "odd" record that shows up in my DNS logs. This one isn&#;x26;#;39;t new, but I don&#;x26;#;39;t think I ever covered it: NIMLOC. …ISC.SANS.EDU
7 JulWireVPN service linked to years-long residential proxy operationA VPN service with more than one million Android downloads is at the center of a long-running operation that allegedly recruits victims' devices into a residential proxy network. The Infoblox investigation began after researchers analyzed the infrastructure behind a malicious ins…CYBERINSIDER.COM
7 JulSpanish Police Arrest Man Linked to CARR, Z-Pentest, and NoName057(16)Spain arrested a suspected CARR and Z-Pentest collaborator in an FBI-led probe for aiding pro-Russian hackers, coordinating attacks, and using crypto. Spanish National Police arrested a man in Palencia last March on charges of membership in and collaboration with a terrorist orga…SECURITYAFFAIRS.COM
7 JulDeepfake CSAM lawsuit against xAI, Grok expandsTwo new alleged victims detailed how Grok was used by friends and family to generate sexual images of them as minors. The suit also adds Stability AI as a defendant. The post Deepfake CSAM lawsuit against xAI, Grok expands appeared first on CyberScoop .CYBERSCOOP.COM
7 JulWatch out for fake support calls in Microsoft TeamsPalo Alto Networks’ security division, Unit 42, is warning of yet another campaign targeting Microsoft Teams users . The new campaign begins with Teams users receiving an email asking if they would like to participate in a survey. If they open the attached PDF file, they will sho…CSOONLINE.COM
7 JulDune References, FAT, Claude, ZhiPu, PolinRider, RentaBot, Sony, Aaran Leyland & More - SWN #596Dune References, FAT, Claude, ZhiPu, PolinRider, RentaBot, Sony, Aaran Leyland, and More on the Security Weekly News. Visit https://www.securityweekly.com/swn for all the latest episodes! Show Notes: https://securityweekly.com/swn-596YOUTUBE.COM
7 JulSpain arrests suspected hacker linked to Russian hacktivist campaignAuthorities didn’t name the man or file formal charges, but accuse him of participating in attacks linked to Cyber Army of Russia Reborn and NoName. The post Spain arrests suspected hacker linked to Russian hacktivist campaign appeared first on CyberScoop .CYBERSCOOP.COM
7 JulVidar Stealer Unmasked: Code Signing Abuse, Go Loaders and File InflationA cybercrime campaign combined a loader-as-a-service framework and DLL sideloading via a Go-compiled fake MpClient.dll, a novel evasion layer combination. The post Vidar Stealer Unmasked: Code Signing Abuse, Go Loaders and File Inflation appeared first on Unit 42 .UNIT42.PALOALTONETWORKS.COM
7 JulGitHub's Joke Backfired FastGitHub appeared to poke fun at Sony's decision to move away from optical media by offering developers CD-ROM copies of their public repositories. The offer included a real request form, and enough people treated it seriously that GitHub removed it early. Whether it began as a mar…YOUTUBE.COM
6 JulProduct showcase: Is that text a scam? Malwarebytes Mobile Security can help you find outMalwarebytes Mobile Security for iPhone combines scam prevention, privacy protection, and identity monitoring in a single app. It evaluates a device’s security posture, provides recommendations to improve protection, and is available for Windows, macOS, Android, iOS, and Ch…HELPNETSECURITY.COM
6 JulOAuth, guest accounts, and weak MFA drive SaaS riskOrganizations often create guest accounts to give contractors, suppliers, and partners temporary access to files and SaaS applications. Many of these accounts remain active long after they are needed, creating overlooked access paths to corporate data. Guest accounts accounted fo…HELPNETSECURITY.COM
6 JulWhen checking the URL isn’t enough: a Device Code Phishing attack via a Microsoft websiteThe OAuth 2.0 Device Authorization Grant specification was designed to streamline authentication for Smart TVs, IoT devices, and printers. Today, threat actors are weaponizing it.SECURELIST.COM
6 JulISC Stormcast For Monday, July 6th, 2026 https://isc.sans.edu/podcastdetail/9994, (Mon, Jul 6th)(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.ISC.SANS.EDU
6 JulRCS and DNS: The NAPTR Record, (Mon, Jul 6th)Over the last year, with recent updates to iOS and Android, RCS (Rich Communication Services) has become an increasingly used protocol [1]. RCS is supposed to eventually replace SMS, and in addition to richer formatting, provides added (but optional) security. RCS messa…ISC.SANS.EDU
6 JulUkrainian media outlets now among 'priority targets' for Russian hackersA top Ukrainian security official described two previously unreported attacks on TV media organizations and said Russia has ramped up hacking activities against the industry.THERECORD.MEDIA
6 JulOpenSSH 10.4 arrives with security fixes and a post-quantum signature optionOperators who manage remote access to Unix and Linux systems keep a close watch on OpenSSH, the software that carries most SSH traffic across the internet. The project released version 10.4 with eight security fixes, a set of bug corrections, and a couple of new features. What th…HELPNETSECURITY.COM
6 JulCheap AI Will Handle Most TasksFuture AI systems are expected to split work between lightweight local models and larger cloud-based foundation models. Simple tasks can be completed by inexpensive models, while advanced reasoning is reserved for more capable—and more expensive—AI. This hybrid approach could low…YOUTUBE.COM
6 JulAlleged member of Scattered Spider extradited to USA man with dual US-Estonian citizenship was charged in connection to the hack of a luxury jewelry retailer.CYBERSECURITYDIVE.COM
6 JulThe Shift Toward Business-Aligned Risk ManagementMoving from isolated, technical data to a continuous risk lifecycle can help organizations align security controls with actual business consequences. The post The Shift Toward Business-Aligned Risk Management appeared first on SecurityWeek .SECURITYWEEK.COM
6 JulArmored Likho APT Targeting Government, Electric Power EntitiesThe threat actor uses modular RATs and information stealers in financially motivated and cyber espionage campaigns. The post Armored Likho APT Targeting Government, Electric Power Entities appeared first on SecurityWeek .SECURITYWEEK.COM
6 JulUS Army websites defaced with pro-Kurdish sentiments, insults to TrumpAt least two websites appear to be victim to 404 hijacking attacks. Army officials took the sites down after being contacted by CyberScoop. The post US Army websites defaced with pro-Kurdish sentiments, insults to Trump appeared first on CyberScoop .CYBERSCOOP.COM
6 JulExpressVPN adds passkeys on password manager, passes security auditExpressVPN has announced a major update to its standalone ExpressKeys password manager, adding passkey support, secure credential sharing, and direct vault imports. Alongside the release, the company published a new independent security assessment by Cure53, which found no severe…CYBERINSIDER.COM
6 JulFake IT support calls on Microsoft Teams push EtherRAT malwareThreat actors are abusing Microsoft Teams voice calls by impersonating corporate IT support staff to trick employees into installing the EtherRAT malware, giving attackers initial access to corporate networks. [...]BLEEPINGCOMPUTER.COM
6 JuluBlock Origin Chrome extension now blocks known ClickFix sitesuBlock Origin has quietly added protections against ClickFix attacks to its built-in badware filter list, helping block access to websites that attempt to trick users into copying and executing malicious commands. The capability came to light through a user discussion on Mastodon…CYBERINSIDER.COM
5 JulSECURITY AFFAIRS MALWARE NEWSLETTER ROUND 104Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter Hijacked npm Packages Use Novel VSCode Autorun and Blockchain Dead Drops to Deploy a Credential/Crypto Stealer Buil…SECURITYAFFAIRS.COM
4 JulNorth Korean Hackers Publish 108 Malicious Packages and Extensions in PolinRider CampaignThe North Korean threat actors linked to the Contagious Interview campaign have been observed publishing 108 unique packages and web browser extensions spanning npm, Packagist, Go, and Google Chrome as part of an ongoing activity referred to as PolinRider. "The campaign remains a…THEHACKERNEWS.COM
4 JulAI Tested Against Cyber ExpertsCybersecurity platforms like Hack The Box are being used to benchmark both human practitioners and AI models in the same realistic lab environments. Government AI security institutes have also used these systems to evaluate advanced models. This creates one of the clearest real-w…YOUTUBE.COM
3 JulGoogle Disrupts NetNut Residential Proxy Network Spanning 2 Million Home DevicesGoogle has significantly degraded NetNut, one of the biggest networks that turns home devices into rented relays for other people's traffic. Working with the FBI, Lumen, and others, Google's Threat Intelligence Group (GTIG) said this week it had reduced the network's po…THEHACKERNEWS.COM
3 JulNew infosec products of the week: July 3, 2026Here’s a look at the most interesting products from the past week, featuring releases from Digi International, iboss, Jamf, and Netzilo. Digi International’s DANI automates network diagnostics and device management Digi International has announced the launch of DANI, the Digi Art…HELPNETSECURITY.COM
3 JulSomeone infected a spyware probe overseer with spywareCitizen Lab says the phone of a member of Europe’s PEGA Committee was infected twice with Pegasus, the NSO Group spyware that gave the panel its name. The post Someone infected a spyware probe overseer with spyware appeared first on CyberScoop .CYBERSCOOP.COM
3 JulGeopolitical cyber threats are turning HR into a security front lineIn this Help Net Security video, Roman Sannikov, Global Research Coordinator at iCOUNTER, explains why geopolitics belongs in every security team’s threat model. With open and simmering conflicts around the world, attacks can come from actors that would never have targeted …HELPNETSECURITY.COM
3 JulNon-interactive SSH attacks dominate after loginAnyone who runs a server with SSH exposed to the internet sees the same pattern in the logs. A steady stream of automated scanners tries to log in, hour after hour, from addresses all over the world. The common picture of what comes next has an attacker landing a shell, looking a…HELPNETSECURITY.COM
3 JulIntezer helps SOC teams automate custom security tasksIntezer has announced Custom Agents, a new capability that lets security teams build their own AI agents directly inside the Intezer platform. The launch builds on Intezer’s core approach, that lets autonomous agents do the security work and humans supervise it. Security teams ca…HELPNETSECURITY.COM
3 JulArmored Likho digging a snake pit: inside the covert BusySnake Stealer campaignAn inside look at the active Armored Likho APT campaign. The attackers are using spear-phishing, AI-generated loaders, and a new Python-based tool, BusySnake Stealer, to target organizations in Russia, Kazakhstan, and Brazil.SECURELIST.COM
3 JulFBI, Google Take Down NetNut Proxy Network Used by Cyber Threat ActorsThe NetNut proxy network and the ‘Popa’ botnet are known to have infected devices with variants of Mirai DDoS botnetsINFOSECURITY-MAGAZINE.COM
3 JulAlleged Scattered Spider Hacker Extradited to USProsecutors say 19-year-old Peter Stokes was a member of Scattered Spider, the hacking group linked to more than 100 network intrusions and over $100 million in ransom payments. The post Alleged Scattered Spider Hacker Extradited to US appeared first on SecurityWeek .SECURITYWEEK.COM
3 JulEN 303 645 is the baseline, not the finish line for IoT securityTL;DR Why EN 303 645 matters ETSI EN 303 645 has given consumer IoT security a much-needed baseline. It gives manufacturers, assessors, and product teams a shared view of reasonable IoT security and something concrete to work against. But after years of assessing prod…PENTESTPARTNERS.COM
3 JulNorth Korea-Linked npm Packages Mimic Rollup Polyfills to Steal Developer SecretsThreat actors with ties to North Korea have been linked to a fresh set of malicious npm packages that masquerade as Rollup polyfill tooling to facilitate remote access and data theft. According to JFrog, the packages "rollup-packages-polyfill-core" and "rollup-runtime-polyfill-co…THEHACKERNEWS.COM
3 JulApple AirDrop and Android Quick Share flaws expose users to wireless attacksSecurity researchers have identified six previously undocumented vulnerabilities in Apple AirDrop and Google/Samsung Quick Share after conducting the first comprehensive reverse engineering and security analysis of both proprietary proximity file-sharing protocols. While the flaw…CYBERINSIDER.COM
3 JulBeyond the AI Hype, Cyber Readiness in the Age of AI - Gibb Witham - SWN #595I talk to Gibb Witham, President of Hack The Box, about cyber readiness, hands-on security training, Hack The Box, and AI in cybersecurity. Visit https://www.securityweekly.com/swn for all the latest episodes! Show Notes: https://securityweekly.com/swn-595YOUTUBE.COM
3 JulAI Becomes Cybersecurity Operating SystemAI is being used in cybersecurity to automate low-level tasks and accelerate operational workflows, particularly in offensive contexts. Rather than replacing human operators, AI is acting as an “operating system” for cybersecurity work. It improves speed in both defensive and off…YOUTUBE.COM
2 JulISC Stormcast For Thursday, July 2nd, 2026 https://isc.sans.edu/podcastdetail/9992, (Thu, Jul 2nd)(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.ISC.SANS.EDU
2 JulIs the next frontier model your biggest threat or your best defender?If you think the recent wave of AI-discovered vulnerabilities is a problem, Rob Bair of Anthropic has a reframe for you. Discovery is the easy part. Closing the remediation gap is now the defining security challenge. Drawing on his experience in the Navy, in national security, an…THECYBERWIRE.COM
2 JulSrsly Risky Biz: America won't beat the distillation ecosystemTom Uren and James Wilson talk about Chinese AI labs stealing the special sauce of American AI models in ‘distillation attacks’. These attacks are fed by a grey market in which Chinese consumers buy access to American models, where one of the byproducts is logs of user requests a…RISKY.BIZ
2 JulOpera introduces Paste Protect feature to block ClickFix attacksOpera has introduced a new browser security feature called Paste Protect, designed to stop clipboard-based attacks such as ClickFix before users can execute malicious commands. The feature is enabled by default in Opera's desktop browser, and the company says it is the first majo…CYBERINSIDER.COM
2 JulCloudflare changes AI crawler access rulesCloudflare introduced new controls that let website owners manage AI traffic across three categories: Search, Agent, and Training. The feature is available to all Cloudflare customers, including those on the Free plan, and gives website owners more control over how different type…HELPNETSECURITY.COM
2 JulIntroducing Custom Agents: Automate your SOC, your wayAdd your own agents and automations on top of the ones Intezer runs out of the box, take more of the manual work off your analysts, and tailor AI SOC to the way your team actually operates. The post Introducing Custom Agents: Automate your SOC, your way appeared first on Intezer …INTEZER.COM
2 JulToddyCat-Linked Umbrij Malware Abuses OAuth to Access Gmail via Google APIThe threat actor known as ToddyCat has been attributed to a new malware called Umbrij that's designed to gain surreptitious access to a victim's email correspondence via the Google API. "In this campaign, the attackers focused their attention on corporate email communications hos…THEHACKERNEWS.COM
2 JulYou Ruled Yourself Out Too SoonEarly interest in technology and cybersecurity didn’t automatically turn into confidence. At eighteen, the assumption was that a career in cyber “probably wasn’t in the cards,” despite the interest already being there. That mindset is common across industries. People often elimin…YOUTUBE.COM
2 JulHow to Conduct a Successful Audit of AI-Driven Software DevelopmentAs AI-generated code becomes commonplace, CISOs need new audit strategies to measure developer practices, govern AI tool usage, and identify software risks before they reach production. The post How to Conduct a Successful Audit of AI-Driven Software Development appeared first on…SECURITYWEEK.COM
2 JulHow GitHub used secret scanning to reach inbox zeroGitHub had 20,000+ secret scanning alerts across 15,000 repositories. Here's how we separated signal from noise, built remediation workflows, and reached inbox zero in nine months. The post How GitHub used secret scanning to reach inbox zero appeared first on The GitHub Blog .GITHUB.BLOG
2 JulAlleged longstanding member of Scattered Spider extradited to USPeter Stokes boasted on social media about the luxurious globetrotting life he enjoyed while he was still a child. The post Alleged longstanding member of Scattered Spider extradited to US appeared first on CyberScoop .CYBERSCOOP.COM
2 JulScattered Spider member extradited to the U.S. facing cybercrime chargesThe U.S. Department of Justice has announced the arrest and extradition of an alleged member of the notorious cybercrime group Scattered Spider. According to the Justice Department, Scattered Spider has been involved in more than 100 network intrusions, resulting in over $100 mil…CYBERINSIDER.COM
2 JulGoogle loses final appeal against €4.1 billion Android antitrust fineThe European Union's highest court has upheld a €4.125 billion ($4.8 billion) antitrust fine against Google, bringing to an end the company's appeal over allegations that it abused Android's dominant market position to strengthen its search business. The ruling confirms that Goog…CYBERINSIDER.COM
2 JulImproving security posture across the Microsoft partner ecosystemRead how Microsoft strengthens partner ecosystem security with CSP vetting, least privilege access, monitoring, and risk management best practices. The post Improving security posture across the Microsoft partner ecosystem appeared first on Microsoft Security Blog .MICROSOFT.COM
2 JulBrave browser introduces Containers for secure account isolationBrave has released version 1.92 of its privacy-focused browser, introducing built-in Containers that let users isolate browser tabs into separate identities for improved workflow and account management. While similar functionality has been available through extensions, Brave’s na…CYBERINSIDER.COM
2 JulTechnical Blueprint: Hardware Security for AI InfrastructureDownload the PDF > Executive Summary This document details the necessary effort to implement the Eclypsium Hardware Supply Chain Security Platform to address critical hardware supply chain vulnerabilities, infrastructure integrity, and component-level security gaps within Departm…ECLYPSIUM.COM
2 JulHow We Added WebAuthn to a Browser-Based RDP ClientA look inside the reverse-engineering journey of building the first RDP client outside of Windows to support WebAuthn redirection. The post How We Added WebAuthn to a Browser-Based RDP Client appeared first on Unit 42 .UNIT42.PALOALTONETWORKS.COM
1 JulISC Stormcast For Wednesday, July 1st, 2026 https://isc.sans.edu/podcastdetail/9990, (Wed, Jul 1st)(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.ISC.SANS.EDU
1 JulGetting boards to fund ERM means speaking their currencyIn this Help Net Security video, Greg Young, VP Cybersecurity and Corporate Development at TrendAI, explains how to build Enterprise Risk Management that a board will pay for. Drawing on nearly four decades in cybersecurity, including time as a CISO and 14 years as a Gartner anal…HELPNETSECURITY.COM
1 JulThis supercomputer encrypts your data even while it’s running itMost people who handle sensitive data already encrypt it in two places. They lock it down when it sits on a hard drive, and they lock it down when it moves across a network. There has always been a third moment that stayed open. The instant a computer pulls that data into memory …HELPNETSECURITY.COM
1 JulRisky Business #844 -- China closes AI vulndev gap as USA lifts Fable banOn this week’s show Patrick Gray, Adam Boileau and James Wilson discuss the week’s cybersecurity news. They cover: Anthropic’s Fable 5 returning while OpenAI’s GPT-5.6 gets thrown in model jail Distillation, cheap tokens, and AI chat harvesting is an industry in China Edge become…RISKY.BIZ
1 JulGoogle Patches 382 Chrome VulnerabilitiesFifteen of the newly patched flaws have been rated ‘critical’ and 67 have been rated ‘high severity’. The post Google Patches 382 Chrome Vulnerabilities appeared first on SecurityWeek .SECURITYWEEK.COM
1 JulWhat a financial planner taught me about cybersecurityWhen I spoke at a recent cybersecurity awareness event for financial planners and tax advisors, the audience really engaged with the subject. As happens at conferences the world over, people often come up to speakers to ask follow-up questions, or just give their feedback about p…HELPNETSECURITY.COM
1 JulMassive Password Spray Campaign Targeting Azure CLIHackers were seen making over 81 million login attempts originating from systems associated with hosting provider LSHIY. The post Massive Password Spray Campaign Targeting Azure CLI appeared first on SecurityWeek .SECURITYWEEK.COM
1 JulDawnguard Raises $6.3 Million for Security Architecture Automation PlatformThe company has publicly launched its solution to help organizations design, build, and operate secure cloud systems. The post Dawnguard Raises $6.3 Million for Security Architecture Automation Platform appeared first on SecurityWeek .SECURITYWEEK.COM
1 JulThis phishing kit looks more like BEC-as-a-serviceCisco Talos’ research on ARToken builds on what’s known about the related EvilTokens phishing-as-a-service. The post This phishing kit looks more like BEC-as-a-service appeared first on CyberScoop .CYBERSCOOP.COM
1 JulFrontier AI: Six Questions Every Enterprise Should Ask Security VendorsFrom model selection and automation to validation and measurable results, the right questions can help enterprises separate genuine AI capabilities from marketing hype. The post Frontier AI: Six Questions Every Enterprise Should Ask Security Vendors appeared first on SecurityWeek…SECURITYWEEK.COM
1 JulApple Patches Dozens of Vulnerabilities Across iOS, macOS, and SafariThe updates fix vulnerabilities in WebKit, the kernel, WebRTC, Web Extensions, and other components affecting iPhone, iPad, Mac, and Safari users. The post Apple Patches Dozens of Vulnerabilities Across iOS, macOS, and Safari appeared first on SecurityWeek .SECURITYWEEK.COM
1 JulPapa Johns Surveillance-Based AdvertisingPapa Johns is spying on people’s buying activities to predict when they are low on food: The pizza chain recently tapped NBCUniversal, Instacart and the dentsu-owned media agency Carat for help reaching consumers when they’re low on groceries—and thus more likel…SCHNEIER.COM
1 JulThe ARToken phishing panel targets Microsoft 365 accountsAccounts-payable staff at U.S. companies keep receiving invoice emails that look like they come from vendors they already work with. One landed at a life-sciences company in April 2026, addressed to the person who handles payments and written in the voice of a Wisconsin contracto…HELPNETSECURITY.COM
1 JulAdobe Patches Critical ColdFusion, Campaign Classic VulnerabilitiesSeven of the security defects have a maximum severity rating of 10/10 and could lead to arbitrary code execution. The post Adobe Patches Critical ColdFusion, Campaign Classic Vulnerabilities appeared first on SecurityWeek .SECURITYWEEK.COM
1 JulCitrix Patches NetScaler Vulnerabilities, Including New ‘HTTP/2 Bomb’ AttackCitrix urges customers to patch NetScaler after fixing six vulnerabilities, including the HTTP/2 Bomb flaw and a high-severity CitrixBleed-style information disclosure bug. The post Citrix Patches NetScaler Vulnerabilities, Including New ‘HTTP/2 Bomb’ Attack appeared first on Sec…SECURITYWEEK.COM
1 JulDawnguard launches platform to automate secure cloud architectureDawnguard announced the public launch of its security architecture automation platform, making it available to organizations looking to design, build, and operate secure cloud-native systems from day zero through production. The launch marks the company’s move from enterprise des…HELPNETSECURITY.COM
1 JulSafe Events Start With Threat Intel and Digital SecurityPlanning ahead to defend against cyber threats is the work that keeps events uneventful.DARKREADING.COM
1 JulEmpowering Too Soon BackfiresEmpowerment isn't binary. It's a dial that leaders should adjust based on operational clarity, individual capability, and team maturity. Granting full autonomy before a team is ready can increase mistakes, confusion, and inconsistency. On the other hand, withholding autonomy from…YOUTUBE.COM
1 JulTurning Indicators into Intelligence in OpenCTI with Criminal IPThreat intelligence is only as useful as the context behind it. Criminal IP explains how its integration enriches threat indicators in OpenCTI with risk scoring, infrastructure intelligence, and phishing analysis. [...]BLEEPINGCOMPUTER.COM
1 Jul6 security settings every GitHub maintainer should enable this weekThese six free settings will not make your project unhackable. Nothing will. What they will do is close the easy doors. Turn these on, and your project will be meaningfully harder to attack than it was before. The post 6 security settings every GitHub maintainer should enable thi…GITHUB.BLOG
1 JulAnthropic reactivates Fable, Mythos after securing government approvalThe company’s powerful frontier models are back, but vetting issues remain unresolved.CYBERSECURITYDIVE.COM
1 JulTor releases Arti 2.5.0 with stable CGO encryption and security fixesThe Tor Project has released Arti 2.5.0, promoting its next-generation Counter Galois Onion (CGO) encryption scheme to stable status while also patching two denial-of-service (DoS) vulnerabilities affecting the Rust-based Tor implementation. The release marks a significant milest…CYBERINSIDER.COM
1 JulMicrosoft named a leader in the Frost Radar for cloud and application runtime securityFrost & Sullivan names Microsoft a leader as cloud and application security converge into unified, runtime risk reduction. The post Microsoft named a leader in the Frost Radar for cloud and application runtime security appeared first on Microsoft Security Blog .MICROSOFT.COM
1 JulWaiting for Quantum Is a MistakeQuantum computing is still in its early stages, but major technology platforms are already investing in the technology. While commercial-scale systems aren't available yet, development continues to accelerate. Organizations that wait for quantum computing to become commonplace ma…YOUTUBE.COM
1 JulSEO-Poisoned Software Sites Abuse ScreenConnect to Deploy AsyncRATUnknown threat actors are leveraging the ScreenConnect remote access tool as a way to deploy and execute AsyncRAT. Kaspersky said the activity is part of a "massive, multi-domain, multi-language" campaign that distributes malicious installer archives hosted on spoofed websites. T…THEHACKERNEWS.COM
1 JulMicrosoft Adds New Teams Controls to Block Unauthorized AI Bots From MeetingsMicrosoft's new Teams admin policy requires organizer approval for external AI bots, giving organizations greater visibility and control over automated participants in sensitive meetings. The post Microsoft Adds New Teams Controls to Block Unauthorized AI Bots From Meetings appea…SECURITYWEEK.COM
1 JulMicrosoft accelerates quantum cryptography rollout, targets 2029 transitionMicrosoft has announced that it is accelerating its transition to post-quantum cryptography (PQC) amid growing concerns that cryptographically relevant quantum computers could arrive sooner than previously anticipated. The company now aims to transition critical products and serv…CYBERINSIDER.COM
1 JulCrafty Phishing Campaigns Auto-Adapt to Victim's Device, OSAttackers fingerprint victims through user-agent data to deliver OS-specific payloads, increasing compromise rates and campaign profitability.DARKREADING.COM
1 JulFake Values Kill Company TrustCore values only build trust when they're reflected in everyday decisions. A company that claims to be "people first" but consistently acts otherwise creates a gap between its messaging and reality. That disconnect weakens credibility with employees, leaders, and candidates. Orga…YOUTUBE.COM
30 JunISC Stormcast For Tuesday, June 30th, 2026 https://isc.sans.edu/podcastdetail/9988, (Tue, Jun 30th)(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.ISC.SANS.EDU
30 JunWSL containers now build and run Linux workloads on WindowsContainers power a large share of cloud-native applications, AI workloads, and testing and deployment pipelines. Developers working on Windows have long pulled in third-party software to build and run them. That step becomes optional with WSL containers, a feature that arrived at…HELPNETSECURITY.COM
30 JunQuantifind Raises $200 Million for AI-Native Risk IntelligenceQuantifind will accelerate international expansion and extend its platform’s localized risk intelligence capabilities. The post Quantifind Raises $200 Million for AI-Native Risk Intelligence appeared first on SecurityWeek .SECURITYWEEK.COM
30 JunAirDrop and Quick Share vulnerabilities affect protocols on five billion devices as fixes beginPhones and laptops ship with a feature that sends files to nearby devices over the air, with no cables, accounts, or prior pairing. Apple calls its version AirDrop. Google and Samsung call theirs Quick Share. Both run inside privileged background services that wake when another d…HELPNETSECURITY.COM
30 JunKali Linux 2026.2 trims VM boot times, refreshes its desktopsPenetration testers who run Kali Linux inside virtual machines boot their systems faster after the 2026.2 release. The change comes from a decision about graphics firmware, the code that drives NVIDIA, AMD, and Intel GPUs. That firmware has grown large enough to slow the early st…HELPNETSECURITY.COM
30 JunToddyCat: your hidden email assistant. Part 2An in-depth analysis of Umbrij, a new tool used by the ToddyCat APT group to compromise corporate email communications in Gmail. The attack targeted OAuth authorization tokens, allowing threat actors to gain access to Google services.SECURELIST.COM
30 JunThe AI Token Costs That Can Break CybersecurityAs cybersecurity platforms embrace agentic AI, organizations must balance detection performance against the escalating costs of token consumption, deployment architecture, and AI credits. The post The AI Token Costs That Can Break Cybersecurity appeared first on SecurityWeek .SECURITYWEEK.COM
30 JunAirDrop and Quick Share Flaws Let Nearby Attackers Trigger Crashes and Bypass ChecksTwo researchers have found six security flaws in AirDrop and Quick Share, the wireless features that beam files between nearby devices with no cables or shared network. An attacker within wireless range, with just a laptop and no prior connection, can crash the sharing service on…THEHACKERNEWS.COM
30 JunSupreme Court Rules Constitutional Privacy Protections Apply to Cellphone Users’ Location HistoryThe ruling was made in the case of a bank robber whose identity was discovered through a geofence warrant. The post Supreme Court Rules Constitutional Privacy Protections Apply to Cellphone Users’ Location History appeared first on SecurityWeek .SECURITYWEEK.COM
30 JunThe Realities of AI Video SurveillanceThe Financial Times has a good article on how AI is changing the capabilities of video surveillance, with information from both Israel/Iran and Russia. I wrote about this sort of thing a few years ago, how AI enables mass spying in the way that computers and networks enabled mass…SCHNEIER.COM
30 JunMozilla tightens rules for certificate authorities to improve web securityMozilla has released version 3.1 of its Mozilla Root Store Policy (MRSP), introducing new requirements aimed at improving transparency and oversight across the public Web PKI. The updated policy, which takes effect on July 1, 2026, focuses on stronger Certification Authority (CA)…CYBERINSIDER.COM
30 JunWhat the Numbers Say About FIFA 2026 Cyber RiskThe FIFA World Cup 2026 opened on June 11. By that date, according to Check Point Research, the fraud infrastructure targeting it had already been built, staged, and partially deployed. Threat actor activity was pre-planned, months out, across three sectors and at least ten langu…THEHACKERNEWS.COM
30 JunDigi International’s DANI automates network diagnostics and device managementDigi International has announced the launch of DANI, the Digi Artificial Network Intelligence agent, a purpose-built AI network operations agent natively embedded in a networking device management platform, Digi Remote Manager (DRM). Embedded directly within DRM as a value-added …HELPNETSECURITY.COM
30 JunOpenMatter Network brings verifiable trust to AI governanceOpenMatter Network has announced the launch of its cryptographically verifiable platform for secure collaboration and AI governance, built on a simple premise: Don’t Trust Data. Prove It. For decades, organizations have relied on trust-based assumptions to secure data, exec…HELPNETSECURITY.COM
30 JunChrome and Firefox Free VPN extensions caught stealing clipboard dataTwo browser extensions masquerading as free VPN services were transformed into clipboard stealers through malicious updates. The Chrome and Firefox add-ons retained working proxy functionality to appear legitimate while secretly monitoring copied data and transmitting it to attac…CYBERINSIDER.COM
30 JunProton launches Lumo 2.0 with advanced reasoning and image generationProton has announced Lumo 2.0, a major upgrade that significantly expands the assistant's capabilities while maintaining the privacy protections that distinguish it from mainstream AI platforms. The new release introduces stronger reasoning models, image recognition and generatio…CYBERINSIDER.COM
30 JunWhat’s new in Microsoft Security: June 2026This month’s updates help security and IT teams strengthen identity and multicloud foundations, protect data wherever it lives, and secure the developer workflows powering AI innovation. The post What’s new in Microsoft Security: June 2026 appeared first on Microsoft Security B…MICROSOFT.COM
30 JunSecuring AI agents: When AI tools move from reading to actingMCP tool poisoning turns trusted AI agents into a control plane for data loss. Learn how threat actors manipulate tool descriptions to trigger unauthorized actions, and how to detect, contain, and prevent it. The post Securing AI agents: When AI tools move from reading to acting …MICROSOFT.COM
30 JunNew Gartner® Report on Preemptive Exposure ManagementThe 2026 Gartner report titled Emerging Tech: Top Funded Startups for Preemptive Exposure Management, that names Eclypsium in the Domain Specific Exposure Management category, was published in April. While this is only a small part of what the Eclypsium Hardware Supply Chain Secu…ECLYPSIUM.COM
30 JunBTS #77 - FortiBleed Uncovered: How Attackers Harvest Credentials from Fortinet DevicesPaul Asadoorian is joined by Chase Snyder and Vlad Babkin to unpack FortiBleed, a large-scale Fortinet credential-harvesting campaign, and what it reveals about network edge security. Welcome to episode 77 of Below the Surface. Paul Asadoorian sits down with Chase Snyder and Vlad…ECLYPSIUM.COM
30 JunWhen AI Chooses Your VendorTyler Shields argues that companies are beginning to publish pricing specifically for AI agents, making it easier for software—not just people—to compare services automatically. As agents evaluate cost, security, and available integrations, support for MCP could become increasing…YOUTUBE.COM
30 JunAccelerating the quantum-safe timelineWe’re accelerating quantum-safe readiness—and sharing what organizations can do now to transition earlier and with confidence. The post Accelerating the quantum-safe timeline appeared first on Microsoft Security Blog .MICROSOFT.COM
30 JunAI Cocaine Recipes, Russian Hack, Scattered Spider, Cisco, Amazon Q – Aaran Leyland - SWN #594AI Cocaine Recipes, Green Shirt Jailbreak, JLR Russia Hack, Scattered Spider, Cisco Root, Amazon Q Pwned – Aaran Leyland – SWN #594 Visit https://www.securityweekly.com/swn for all the latest episodes! Show Notes: https://securityweekly.com/swn-594YOUTUBE.COM
30 JunProton’s pitch for Lumo 2.0: Frontier AI without the data grabProton has unveiled Lumo 2.0, a major upgrade to its zero-access encrypted AI assistant. Built on a new architecture, the release brings the assistant closer to frontier AI models with new AI models, multimodal capabilities, Memory, improved web search, and enterprise features. T…HELPNETSECURITY.COM
29 JunISC Stormcast For Monday, June 29th, 2026 https://isc.sans.edu/podcastdetail/9986, (Mon, Jun 29th)(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.ISC.SANS.EDU
29 JunRisky Bulletin: White House asks OpenAI to restrict GPT 5.6The White House asks OpenAI to keep a tight grip on ChatGPT 5.6, the US Secret Service made some appalling OpSec mistakes, AMD has reintroduced a CPU security feature after consumer backlash, and an Iranian APT operator has been arrested in Montenegro.RISKY.BIZ
29 JunMost teams accept higher risk for faster AI database workDatabase professionals are using AI for everyday work like writing queries, building schemas, and reviewing code, and a growing share rely on autonomous tools that act on the database itself. The use of AI in database management has almost tripled in a year, climbing from 15% to …HELPNETSECURITY.COM
29 JunCompanies keep bolting AI onto their products, and the security bill is coming dueCompanies keep bolting AI and LLM features onto their products, and the security results are starting to show a pattern. The vulnerabilities those features create get rated high risk far more often than anything else, and they get fixed slower than anything else. The figures come…HELPNETSECURITY.COM
29 JunOpenAI Unveils GPT-5.6 Sol as Its Most Advanced Cybersecurity AIThe company says Sol matches competing systems like Mythos Preview while using only a third of the output tokens. The post OpenAI Unveils GPT-5.6 Sol as Its Most Advanced Cybersecurity AI appeared first on SecurityWeek .SECURITYWEEK.COM
29 JunMicrosoft Removes 119 Edge Extensions That Hid Malware in Images and FontsMicrosoft has shut down a long-running malicious extension operation on the Edge Add-ons store that hid its payloads inside ordinary image and font files, then woke up days after install to steal credentials and run ad fraud. The company calls it StegoAd, a mash-up of stegan…THEHACKERNEWS.COM
29 JunUS Offers $10 Million Bounty for Russian State Hackers as Messaging App Attacks EvolveUNC5792 and UNC4221 have been targeting US government officials, military leaders, and allied personnel. The post US Offers $10 Million Bounty for Russian State Hackers as Messaging App Attacks Evolve appeared first on SecurityWeek .SECURITYWEEK.COM
29 JunGPT-5.6 gets better at cybersecurityOpenAI has started rolling out the GPT-5.6 series models in limited preview to a small group of trusted partners through the API and Codex. The series includes Sol as the flagship model, Terra as a balanced option, and Luna as the fastest and most cost-efficient model. The rollou…HELPNETSECURITY.COM
29 JunSSU and FBI Uncover Russian Cyber Espionage Operation Against Officials and Military PersonnelUkraine’s SSU and the FBI Just Confirmed Russian Intelligence Has Been Systematically Hacking Messenger Accounts for Years. The Security Service of Ukraine (SSU), working jointly with the FBI, has formally exposed a sustained Russian intelligence campaign targeting the mess…SECURITYAFFAIRS.COM
29 JunWhy Post-Quantum Cryptography Starts With CredentialsToday’s encrypted data, such as credentials, may no longer remain confidential in the future because the public-key cryptography protecting it will soon be broken by quantum computers. Although no machine today can break elliptic curve cryptography or RSA, quantum hardware is adv…THEHACKERNEWS.COM
29 JunGamaredon Expands Ukraine Attacks with New Malware and Cloud Service AbuseA Russian advanced persistent threat (APT) group has continued to evolve and expand its malware arsenal as part of its ongoing cyber onslaught against Ukraine throughout 2025. Slovakian cybersecurity company ESET said it observed 35 distinct spear-phishing campaigns mounted by Ga…THEHACKERNEWS.COM
29 JunInsurance Regulators Group NAIC Hit in Oracle PeopleSoft HackThe ShinyHunters extortion group claims to have stolen 3.1 TB of data from the organization. The post Insurance Regulators Group NAIC Hit in Oracle PeopleSoft Hack appeared first on SecurityWeek .SECURITYWEEK.COM
29 JunOpenAI voluntarily limits new AI models at government’s requestThe company said it was working with the government on a more formal process for reviewing model releases.CYBERSECURITYDIVE.COM
29 JunResearchers Demo New Claude Code Attack Using Harmless-Looking Repositories to Hijack Developer MachinesIndirect prompts hidden in a repository can lead to Claude Code spawning a reverse shell on the developer’s machine. The post Researchers Demo New Claude Code Attack Using Harmless-Looking Repositories to Hijack Developer Machines appeared first on SecurityWeek .SECURITYWEEK.COM
29 JunStraiker Raises $64 Million for AI Security PlatformThe startup’s platform can identify AI agents and provide visibility into their access, behavior, and risks. The post Straiker Raises $64 Million for AI Security Platform appeared first on SecurityWeek .SECURITYWEEK.COM
29 JunWhatsApp Rolling Out Username Feature to Bolster Phone Number PrivacyAn optional ‘username key’ adds another layer by requiring a secondary credential before someone can message users. The post WhatsApp Rolling Out Username Feature to Bolster Phone Number Privacy appeared first on SecurityWeek .SECURITYWEEK.COM
29 JunSupreme Court approves mail-in ballots that arrive after Election DayThe ruling is a victory for election advocates who say the evidence overwhelmingly shows that voter fraud is rare and not tied to mail voting in general. The post Supreme Court approves mail-in ballots that arrive after Election Day appeared first on CyberScoop .CYBERSCOOP.COM
29 JunSupreme Court delivers ‘major win’ for tech privacy in Chatrie rulingDissenting justices who criticized the ruling said it would have “seismic” implications for the Fourth Amendment. The post Supreme Court delivers ‘major win’ for tech privacy in Chatrie ruling appeared first on CyberScoop .CYBERSCOOP.COM
29 JunChrome extension Adblock for YouTube with 11 million users could be silently weaponizedThe operators of the popular “Adblock for YouTube” Chrome extension could remotely execute JavaScript on websites visited by users through a server-side configuration change. Island researchers who discovered this found no evidence that the architectural weakness has …CYBERINSIDER.COM
29 JunUS offers $10 million for info on Russian hackers targeting Signal accountsThe U.S. Department of State has announced a reward of up to $10 million for information leading to the identification or location of members of UNC5792. This is a Russian state-linked hacking group accused of targeting Signal and WhatsApp accounts belonging to U.S. government of…CYBERINSIDER.COM
29 JunChromium extension uses AI‑related branding to redirect browser searchA malicious Chromium-based extension that spoofs the AI-powered answer engine Perplexity AI redirects browser search traffic using MV3 APIs and intermediary infrastructure. The post Chromium extension uses AI‑related branding to redirect browser search appeared first on Microsoft…MICROSOFT.COM
29 JunWarner bill would create federally vetted list for secure, trustworthy AI agentsThe bill empowers the FTC to create a registry for sellers of AI agent software certifying their privacy and cybersecurity protections. The post Warner bill would create federally vetted list for secure, trustworthy AI agents appeared first on CyberScoop .CYBERSCOOP.COM
29 JunWhatsApp opens username reservations ahead of feature rolloutMeta has announced that WhatsApp users can now reserve usernames ahead of a broader launch planned for later this year, introducing a long-awaited privacy feature that allows people to connect without sharing their phone numbers. The company says the feature is designed to give u…CYBERINSIDER.COM
29 JunU.S. Targets Russian Cyber Spies With $10M Bounty Over Messaging App AttacksThe U.S. offers up to $10M for information on Russian hackers targeting Signal and WhatsApp accounts of officials and journalists. The U.S. government is offering rewards of up to $10 million for information leading to the identification of members of the Russian-linked groups UN…SECURITYAFFAIRS.COM
28 JunYARA-X 1.18.0 and 1.19.0 Release, (Sun, Jun 28th)YARA-X&#;x26;#;39;s 1.18.0 release brings 3 improvements and 2 bugfixes.
ISC.SANS.EDU
27 JunThe Dacls RAT ...now on macOS!A sophisticated Lazarus Group implant has arrived on macOS. In this post, we deconstruct the Mac variant of a OSX.Dacls, detailing its install logic, persistence, and capabilities.OBJECTIVE-SEE.ORG
27 JunWeaponizing a Lazarus Group ImplantThe Lazarus group's latest implant/loader supports in-memory loading of 2nd-stage payloads. In this post we describe exactly how to repurposing this 1st-stage loader to execute *our* custom 'fileless' payloads!OBJECTIVE-SEE.ORG
27 JunLazarus Group Goes 'Fileless'The rather infamous APT group, "Lazarus", continues to evolve their macOS capabilities. Today, we tear apart their latest 1st-stage implant that supports remote download & in-memory execution of secondary payloads!OBJECTIVE-SEE.ORG
27 JunPass the AppleJeusA new macOS backdoor written by the infamous Lazarus APT group needs analyzing. Here, we examine it's infection vector, method of persistence, capabilities, and more!OBJECTIVE-SEE.ORG
27 JunMiddle East Cyber-Espionage (part two)The APT group WindShift has been targeting Middle Eastern governments with Mac implants. Let's (continue to) analyze their 1st-stage macOS implant: OSX.WindTail!OBJECTIVE-SEE.ORG
27 JunMiddle East Cyber-EspionageThe APT group WindShift has been targeting Middle Eastern governments with Mac implants. Let's analyze their 1st-stage macOS implant: OSX.WindTail!OBJECTIVE-SEE.ORG
27 JunWho Moved My Pixels?!In this guest blog post my friend Mikhail Sosonkin reverses Apple's screencapture utility, discusses Mac malware that captures desktop images, and suggests methods for screen-capture detection!OBJECTIVE-SEE.ORG
27 JunChinese Framework Powers 200,000 Scam SitesThreat actors are selling investment scam templates created using the legitimate DCloud Uni-App toolkit. The post Chinese Framework Powers 200,000 Scam Sites appeared first on SecurityWeek .SECURITYWEEK.COM
26 JunGoogle Details Turla's New STOCKSTAY Backdoor Used in Ukraine Espionage AttacksThe Russian state-sponsored threat actor known as Turla has been attributed to a previously undocumented .NET backdoor called STOCKSTAY that has been deployed against government and military organizations in Ukraine, and entities that have an interest in Italian foreign policy. D…THEHACKERNEWS.COM
26 JunRussian APT Deploys ‘StockStay’ Backdoor Against Ukrainian TargetsTurla has been using the backdoor against government and military organizations in Ukraine for espionage. The post Russian APT Deploys ‘StockStay’ Backdoor Against Ukrainian Targets appeared first on SecurityWeek .SECURITYWEEK.COM
26 JunNew Enterprise-Ready MCP Specification Brings New Security ChallengesA major overhaul of the Model Context Protocol shifts critical security responsibilities from the protocol itself to developers and platform operators. The post New Enterprise-Ready MCP Specification Brings New Security Challenges appeared first on SecurityWeek .SECURITYWEEK.COM
26 JunPhilip Martin Joins Uber as Chief Information Security OfficerMartin brings experience from Coinbase, Palantir, Amazon, and the U.S. Army to lead Uber's cybersecurity and enterprise security organization. The post Philip Martin Joins Uber as Chief Information Security Officer appeared first on SecurityWeek .SECURITYWEEK.COM
26 JunThreatModeler introduces Nexus to automate threat modeling with AI governanceThreatModeler has announced the general availability of ThreatModeler Nexus, an agentic threat modeling platform that brings governed, architecture-aware security to the way modern software is actually built. As AI writes a growing share of production code, the question is no lon…HELPNETSECURITY.COM
26 JunA privacy-first take on local malware analysisSubmitting a suspicious file to VirusTotal or MalwareBazaar places a copy of that file on a platform other people can search. Analysts across the industry rely on these services to get a quick verdict on whether a binary is dangerous. The convenience carries a condition many over…HELPNETSECURITY.COM
26 JunTwo CEOs on why security and AI readiness belong togetherSuperOps and Guardz are bundling PSA, RMM, MDM, and agentic SecOps into one offering for MSPs. In this Help Net Security Q&A, SuperOps CEO Arvind Parthiban and Guardz CEO Dor Eisner explain how a connected stack cuts the time and context lost to tool-switching, lowers costs …HELPNETSECURITY.COM
26 JunMicrosoft Warns of Photo ZIP Phishing Campaign Targeting Hotels with Node.js ImplantAn active phishing campaign has been targeting hotel and other hospitality organizations across Europe and Asia since April 2026, using photo-themed ZIP files to drop a Node.js implant and dig into front-desk machines, Microsoft says. The company has not attributed the …THEHACKERNEWS.COM
26 Jun$3 Million Reportedly Stolen in Polymarket HackThe decentralized prediction market said hackers targeted some of its users through a compromise of a third-party vendor. The post $3 Million Reportedly Stolen in Polymarket Hack appeared first on SecurityWeek .SECURITYWEEK.COM
26 JunMirage2FA phishing kit uses HTML smuggling to steal Microsoft 365 credentialsMirage2FA, a phishing kit that combines short-lived HTML smuggling with obfuscated JavaScript loaders to deliver fake Microsoft 365 login pages and steal credentials during MFA prompts, has been identified by researchers at Fortra. Fortra based its analysis on a suspicious HTML a…HELPNETSECURITY.COM
26 JunAWS unveils agent security, data access toolsThe updates reflect Anthropic's Mythos model and the speed at which vulnerabilities can be surfaced.CYBERSECURITYDIVE.COM
26 JunNebulock Raises $25 Million for AI-Native Contextual SecurityThe cybersecurity startup provides threat hunting, proactive detection, and behavioral security analytics. The post Nebulock Raises $25 Million for AI-Native Contextual Security appeared first on SecurityWeek .SECURITYWEEK.COM
26 JunProof’s x401 establishes an open protocol for AI agent identity and authorizationProof has launched x401, an open, issuer-neutral protocol that lets any website or API ask for and verify the identity behind agents. With x401, a service can ask for the proof it requires: verified identity, age, membership, organizational affiliation, signing authority, proof o…HELPNETSECURITY.COM
26 JunTurla group adds more malware to Russia’s espionage efforts against UkraineThreat intelligence researchers at Google described StockStay, the latest malware developed by the Russian cyber-espionage group known as Turla.THERECORD.MEDIA
26 JunFCC requires emergency-alert distributors to secure their systemsMore than a decade after a high-profile hacking campaign, the commission is moving from recommending basic security protocols to requiring them.CYBERSECURITYDIVE.COM
26 JunNew Millenium RAT version infects 62,000 Windows systems worldwideA major evolution of the Millenium remote access trojan (RAT) has infected more than 62,000 Windows devices across over 160 countries while continuing to use Telegram bots for command-and-control. Group-IB examined Millenium RAT version 4.*, which it says represents a significant…CYBERINSIDER.COM
26 JunMeta Is Testing Facial Recognition for Police and MilitaryWe know that ICE wants to deploy eyeglasses with facial recognition that can identify people in real time. Turns out Meta is prototyping the feature with a Pentagon supplier. (Alternate news story.)SCHNEIER.COM
26 JunRussian hackers were behind $2.5 billion hack of Jaguar Land Rover: ReportThe hack on car giant Jaguar Land Rover last year was one the most disrupting, damaging, and costly hacks of the last few years.TECHCRUNCH.COM
26 JunCybersecurity firms targeted by fraudulent OpenAI organization invitesThreat actors are creating OpenAI tenants that impersonate legitimate companies and inviting employees to join them, in what appears to be a ploy to trick targets into submitting sensitive company information in chats and projects. [...]BLEEPINGCOMPUTER.COM
26 JunATF cancels controversial commercial geolocation contractThe agency told CyberScoop the tool was a pilot that didn’t meet their needs. Members of Congress say it was accessed for hundreds of active cases. The post ATF cancels controversial commercial geolocation contract appeared first on CyberScoop .CYBERSCOOP.COM
26 JunAI Brain Harvest, Fortibleed, Win 10, Blacksite, Windchill, Cisco, BB-8, Josh Marpet - SWN #593AI Brain Harvest, Fortibleed, Win 10, Blacksite, Windchill, Cisco, BB-8 Sidewalk Bots, Josh Marpet, and More on this episode of the Security Weekly News. Visit https://www.securityweekly.com/swn for all the latest episodes! Show Notes: https://securityweekly.com/swn-593YOUTUBE.COM
26 JunMFA Won't Stop This Phishing KitThe Black Site phishing kit pairs with an evasion tool called Cloaked.gg to perform adversary-in-the-middle attacks. By acting as a reverse proxy between the victim and the legitimate website, it can capture credentials and authenticated session data during the login process. Thi…YOUTUBE.COM
25 JunAI and LiabilityEarlier this month, a German court ruled that Google is liable for its AI search summaries. Rejecting defenses like “users can check for themselves,” and that they generally know “that information generated with AI should not be blindly trusted,” the court…SCHNEIER.COM
25 JunWhat do Ports Hear When Nobody's Listening? An Assessment of Automated Cybercrime [Guest Diary], (Wed, Jun 24th)[This is a Guest Diary by Nicole Phillips, an ISC intern as part of the SANS.edu BACS program]
ISC.SANS.EDU
25 JunIntroduction to COM usage by Windows threatsComponent Object Model (COM) is a fundamental Windows technology used by legitimate applications for object activation, inter-process communication, automation and language-independent component reuse. Those same qualities make it useful to threat actors.TALOSINTELLIGENCE.COM
25 JunWhere Expertise Meets Algorithm: The Insikt Group® Intelligence EdgeDiscover how Recorded Future’s Insikt Group combines human expertise with automated analysis to turn raw data into actionable, industry-leading threat intelligence.RECORDEDFUTURE.COM
25 JunRussia uses Cellebrite to break into human rights activist’s phone, even after cancellation of contractThe phone-cracking firm broke off from its deal with Russia, but Citizen Lab said that didn’t stop authorities from surveilling Andrey Pivovarov. The post Russia uses Cellebrite to break into human rights activist’s phone, even after cancellation of contract appeared first on Cyb…CYBERSCOOP.COM
25 JunAs cyber risk evolves, the insurance industry tightens guardrailsC-suite executives are concerned about resilience, but claims are increasingly tied to strict underwriting standards.CYBERSECURITYDIVE.COM
25 JunCL-STA-1062 Targets Southeast Asian Governments and Critical InfrastructureGovernment entities and critical infrastructure were targeted for espionage in SE Asia by attackers using a hybrid toolkit, including custom TinyRCT backdoor. The post CL-STA-1062 Targets Southeast Asian Governments and Critical Infrastructure appeared first on Unit 42 .UNIT42.PALOALTONETWORKS.COM
25 JunWhatsApp is now warning users attempting to message unknown numbersWhatsApp has introduced a new security feature designed to make users think twice before starting conversations with unfamiliar phone numbers. The new “trust warning,” first spotted by WABetaInfo, appears before a chat is opened and provides contextual information tha…CYBERINSIDER.COM
25 JunGrapheneOS cites Hyundai, KIA as it pressures Volkswagen over app blockGrapheneOS is calling on Volkswagen customers to pressure the automaker into restoring compatibility with its mobile app after users reported last week that the app no longer works on the privacy-focused Android operating system. The project pointed to Hyundai and Kia, which it s…CYBERINSIDER.COM
25 JunOrder-tracking app Shop abused to push callback phishing attacksThreat actors are increasingly abusing Shop, the order-tracking app from Shopify, by adding fake purchase receipts in users' order histories to trick them into providing sensitive data or installing remote access software. [...]BLEEPINGCOMPUTER.COM
25 JunRunlayer Raises $30 Million in Series A FundingThe startup’s platform functions as a secure control layer, aiming to secure AI tools across enterprises. The post Runlayer Raises $30 Million in Series A Funding appeared first on SecurityWeek .SECURITYWEEK.COM
25 JunGitLab Patches Code Execution, Information Disclosure VulnerabilitiesThe latest GitLab CE/EE updates address 13 vulnerabilities, including three high-severity defects. The post GitLab Patches Code Execution, Information Disclosure Vulnerabilities appeared first on SecurityWeek .SECURITYWEEK.COM
25 JunSecurityWeek ICS Cybersecurity Conference Heads to Nashville for Special 25-Year Anniversary EditionThe 2026 Industrial Control Systems (ICS) Cybersecurity Conference takes place October 6-8, 2026, at the W Nashville. The post SecurityWeek ICS Cybersecurity Conference Heads to Nashville for Special 25-Year Anniversary Edition appeared first on SecurityWeek .SECURITYWEEK.COM
25 JunRussian APT 'Gamaredon' Upgrades Its Arsenal, Requiring New DefensesThe FSB state-sponsored operation has gotten a lot better at loading its malware and hiding its servers.DARKREADING.COM
25 JunPhoto ZIP campaign targeting hospitality industry delivers Node.js implant for persistent accessMicrosoft Threat Intelligence identified an active multi-stage intrusion campaign targeting hospitality organizations in Europe and Asia. The campaign uses photo-themed ZIP archives and fake image shortcut files to deliver a persistent Node.js implant and evade detection. The pos…MICROSOFT.COM
25 JunMicrosoft a Leader in The Forrester Wave™ for Endpoint Management PlatformsMicrosoft named a Leader in the Forrester Wave™: Endpoint Management Platforms, Q2 2026, with the highest scores in the current offering and strategy categories. The post Microsoft a Leader in The Forrester Wave™ for Endpoint Management Platforms appeared first on Microsoft Secur…MICROSOFT.COM
24 JunISC Stormcast For Wednesday, June 24th, 2026 https://isc.sans.edu/podcastdetail/9984, (Wed, Jun 24th)(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.ISC.SANS.EDU
24 JunProduct showcase: How to evaluate AI SOC platforms and where Prophet AI leadsThe Agentic SOC market is loud. Dozens of vendors promise to take alert triage, investigation, and response off your analysts’ plates, but most claims have never been tested in production. The hard part is separating operational improvement from this marketing noise. Gartne…HELPNETSECURITY.COM
24 JunSecurity testing was built for a slower worldSoftware teams are pushing code into production faster than security testing can keep up. AI is accelerating development cycles and adding pressure to security programs that rely on periodic validation and manual penetration testing. The 2026 State of AI Security Testing report f…HELPNETSECURITY.COM
24 JunLinux Process Name Masquerading, (Wed, Jun 24th)In a previous diary, I talked about stack strings&#;x26;#;x5b; 1 &#;x26;#;x5d; with a practical example of them. Since my SEC670 class, I&#;x26;#;xe2;&#;x26;#;x80;&…ISC.SANS.EDU
24 JunQodo expands platform to help teams govern AI-generated code and engineering standardsQodo has announced three new platform capabilities: Cross-Repo Code Review, Custom Rules Miner, and Skill Review Standards. These new capabilities address a set of governance gaps that have emerged as AI-generated code reaches enterprise scale. AI agents have fundamentally change…HELPNETSECURITY.COM
24 JunCequence introduces behavioral bot detection and biometric verification without CAPTCHAsCequence Security has announced the launch of Intent Graph and Biometric Check, two new capabilities that extend the behavioral architecture Cequence has built since its inception. They provide enterprises with bot defense that works across web, mobile, API, and agentic AI traffi…HELPNETSECURITY.COM
24 JunNew Secure Code Warrior framework helps CISOs govern AI-driven software developmentSecure Code Warrior has introduced its new SCW AI Adoption Model, a practical framework that maps the progression of AI use in software development, from minimal AI assistance to fully autonomous agentic orchestration. The framework helps CISOs assess their organization’s l…HELPNETSECURITY.COM
24 JunDigiCert brings independent trust validation to confidential computing environmentsDigiCert has announced it is bringing independent trust validation to confidential computing environments, in collaboration with Google Cloud. By applying the proven principles of Public Key Infrastructure (PKI) to cloud infrastructure, DigiCert will provide cryptographic verific…HELPNETSECURITY.COM
24 JunEmbedding Forbidden Text in Spyware to Discourage AI AnalysisAt least one malware developer is adding text about nuclear and biological weapons to their spyware, in an effort to stop automatic AI analysis. Details : The _index.js payload begins with a large JavaScript block comment containing fake system instructions and policy-triggering …SCHNEIER.COM
24 JunAgentic AI Security: Wrong Context, Wrong Decisions at Machine SpeedContext is the central plank of AI in general, and agentic AI in particular. If an AI system doesn’t have the correct context, it cannot make the correct decisions. The post Agentic AI Security: Wrong Context, Wrong Decisions at Machine Speed appeared first on SecurityWeek .SECURITYWEEK.COM
24 JunThird DraftKings Hacker Sentenced to 18 Months in PrisonNathan Austad has been ordered to pay roughly $1.8 million in forfeiture and restitution, and the sentence also includes 3 years of supervised release. The post Third DraftKings Hacker Sentenced to 18 Months in Prison appeared first on SecurityWeek .SECURITYWEEK.COM
24 JunCritical Ubiquiti Vulnerabilities in Attackers’ CrosshairsThe flaws allow remote, unauthenticated attackers to make system changes, access underlying accounts, and inject commands. The post Critical Ubiquiti Vulnerabilities in Attackers’ Crosshairs appeared first on SecurityWeek .SECURITYWEEK.COM
24 JunSuperOps and Guardz bundle IT operations and security into one product for MSPsSuperOps and Guardz announced a strategic partnership, combining their platforms into a single bundled offering for managed service providers (MSPs). The package brings professional services automation (PSA), remote monitoring and management (RMM), mobile device management (MDM),…HELPNETSECURITY.COM
24 JunmacOS Backdoor Uses Prompt Injection to Evade AI TriageSentinelLabs found a North Korea-linked macOS backdoor using prompt injection on AI triage toolsINFOSECURITY-MAGAZINE.COM
24 JunExclusive: Meet AIVEX, a New Triage Model Built to Reduce Supply Chain Threat and RiskThe new framework seeks to help security teams identify which software supply chain vulnerabilities pose the greatest operational, safety, and business risks in AI-driven environments. The post Exclusive: Meet AIVEX, a New Triage Model Built to Reduce Supply Chain Threat and Risk…SECURITYWEEK.COM
24 JunAlgerian national accused of running cybercrime marketplaces extradited to USAn Algerian national accused of running online marketplaces that sold phishing kits and fraud tools has been extradited from Spain to the United States to face bank fraud conspiracy charges. The post Algerian national accused of running cybercrime marketplaces extradited to US ap…HELPNETSECURITY.COM
24 JunStealC and Amadey: Breaking down infostealers and the cybercrime services that deliver themOn June 24, 2026, Microsoft’s Digital Crimes Unit (DCU) facilitated the takedown, suspension, and blocking of domains that formed the backbone of the StealC and Amadey infrastructure. This blog is a technical breakdown of StealC and Amadey. The post StealC and Amadey: Breaking do…MICROSOFT.COM
24 JunMozilla proposes privacy-preserving alternative to CAPTCHAsMozilla has unveiled a new proposal called PACT (Private Access Control Tokens), a framework designed to help websites distinguish legitimate users from abusive bots without relying on invasive tracking, hardware attestation, or repeated CAPTCHA challenges. According to Mozilla, …CYBERINSIDER.COM
24 JunTor Project to disable support for Tor 0.4.8 on September 1The Tor Project has announced plans to stop supporting Tor 0.4.8 and earlier releases on September 1, 2026, as it prepares the network for the deployment of Arti, its Rust-based implementation of Tor. The announcement concerns the underlying Tor software used by relays, onion ser…CYBERINSIDER.COM
24 JunAI Can Create Infinite BugsAI-assisted coding is changing how software gets built, but faster code generation does not automatically mean better engineering. In this conversation, the panel explores the growing risk of developers relying too heavily on AI-generated code without understanding the logic behi…YOUTUBE.COM
23 JunISC Stormcast For Tuesday, June 23rd, 2026 https://isc.sans.edu/podcastdetail/9982, (Tue, Jun 23rd)(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.ISC.SANS.EDU
23 JunOnly 7% of companies are ready for the AI agents they deployedMost organizations now run or pilot AI agents that operate on company data with limited human direction at each step, a share that reaches 88% in Veeam Software’s Data and AI Trust Gap report. The systems that are supposed to keep an eye on them have not caught up. That gap…HELPNETSECURITY.COM
23 JunF5 launches AI Security Platform to uncover and secure shadow AIF5 has introduced the F5 AI Security Platform to give CISOs continuous visibility, governance, and protection across enterprise AI applications, models, agents, and the APIs connecting them. F5 also announced the acquisition of SurePath AI, as a key component in the launch of the…HELPNETSECURITY.COM
23 JunMavenir turns NOC knowledge into automation for autonomous networksMavenir has announced its Agentic Service Assurance Framework, a TM Forum IG1251/IG1453-aligned, multi-agent system that automates complex network operations across multiple domains without replacing existing systems. The framework pairs an Intent Orchestrator with a multi-layer …HELPNETSECURITY.COM
23 Jun50% of LG and Samsung smart TV apps embed residential proxiesThousands of smart TV applications available on LG and Samsung platforms contain software that turns devices into residential proxy nodes. Researchers at Spur Intelligence identified proxy SDKs in 2,058 of the 6,038 webOS and Tizen apps they analyzed. Spur's Trevor Sutter downloa…CYBERINSIDER.COM
23 JunRussian Initial Access Broker Behind FortiBleed CampaignUsing a custom sniffer, the threat actor has captured over 110 million credentials since at least February 2026. The post Russian Initial Access Broker Behind FortiBleed Campaign appeared first on SecurityWeek .SECURITYWEEK.COM
23 JunGTA 6 early access offers are taking gamers’ cryptoScam websites are circulating across the internet with a pitch aimed at millions of gamers: a way to play Grand Theft Auto VI before its release. The pages promise early access for a few hundred dollars in cryptocurrency, ask buyers to enter a payment code, and claim the game wil…HELPNETSECURITY.COM
23 JunOpenAI Refocuses Cybersecurity Efforts on Patching Over DiscoveryOpenAI has expanded its Daybreak cybersecurity initiative with a new suite of tools and partnerships. The post OpenAI Refocuses Cybersecurity Efforts on Patching Over Discovery appeared first on SecurityWeek .SECURITYWEEK.COM
23 JunCISO Conversations: Carl Froggett – Combining CISO and CIO at Deep InstinctCarl Froggett combines CISO and CIO. He currently occupies both positions at Deep Instinct. Before then, he was CISO at Citi for almost 17 years. The post CISO Conversations: Carl Froggett – Combining CISO and CIO at Deep Instinct appeared first on SecurityWeek .SECURITYWEEK.COM
23 JunFortiBleed Attackers Turn Firewalls Into Credentials Stealers as Heist PersistsThe threat actors engineered a Golang-based sniffer to target 430,000 FortiGate firewalls and identify 110 million credentials in the ongoing global campaign.DARKREADING.COM
23 JunNew N-able feature gives IT teams visibility into AI usage across endpoints and networksN-able has announced the availability of Shadow AI Visibility across its Unified Endpoint Management (UEM) solutions, N‑central and N‑sight, and its Security Operations platform, Adlumin. The new capability helps organizations identify, classify, and monitor AI tool usage across …HELPNETSECURITY.COM
23 JunDragos unveils OT-native AI to help critical infrastructure teams prioritize threats fasterDragos has announced the release of EmberAI, an OT-native AI built on the Dragos Intelligence Fabric. EmberAI gives every analyst immediate access to Dragos’s OT-specific intelligence, gained from more than a decade of OT operations, activity, and expertise. Putting histori…HELPNETSECURITY.COM
23 JunSecurity Teams Must Become EngineersSecurity teams are becoming deeply technical because modern infrastructure complexity keeps increasing. In this clip, Ev explains why many organizations are restructuring cybersecurity around engineering instead of traditional IT operations. This changes more than job titles. Som…YOUTUBE.COM
23 JunAlgerian man charged with running two cybercrime marketplacesAbdellah Belmili allegedly ran two black-market websites selling stolen financial credentials and custom-built phishing kits targeting major American banks, federal prosecutors say. The post Algerian man charged with running two cybercrime marketplaces appeared first on CyberScoo…CYBERSCOOP.COM
23 JunWhat the Fortibleed campaign means for organizations running FortiGate firewallsA massive credential-harvesting campaign targeting FortiGate firewalls has exposed thousands of organizations to potential network compromise, and a trove of attacker tools, scripts, and credentials left inadvertently exposed on a server has given researchers an unusually detaile…HELPNETSECURITY.COM
23 JunTrump sets new deadlines for agencies and contractors to adopt post-quantum cryptographyThe president also launched new efforts to research the scientific benefits of quantum computers — and protect that research from adversaries.CYBERSECURITYDIVE.COM
23 JunLooming AI-fueled threats require urgent cybersecurity improvements, Five Eyes members sayThe intelligence-sharing alliance said advanced AI models will surpass expectations in a matter of months.CYBERSECURITYDIVE.COM
23 JunData Exposure Flaws Threaten Dify AI Platform Used by 1 Million AppsAttackers could abuse Dify's multi-tenant cloud service to read private chats, preview other tenants' documents, and reach internal APIs. The post Data Exposure Flaws Threaten Dify AI Platform Used by 1 Million Apps appeared first on SecurityWeek .SECURITYWEEK.COM
23 JunDragos Unveils AI for OT SecurityNamed EmberAI, the new capability is built on Dragos’ massive operational technology cybersecurity dataset. The post Dragos Unveils AI for OT Security appeared first on SecurityWeek .SECURITYWEEK.COM
23 JunJustice Department seizes infrastructure used by cyber scam and criminal marketplacelso Tuesday, the Treasury Department took action against the same Cambodian company, Huione Group, and affiliates. The post Justice Department seizes infrastructure used by cyber scam and criminal marketplace appeared first on CyberScoop .CYBERSCOOP.COM
23 JunAI Killed the 5-Year RoadmapTraditional identity and security programs were built around long planning cycles. In this clip, the speaker argues that agentic AI has broken that model because organizations can no longer reliably predict how systems and AI-driven workflows will evolve. Instead of static roadma…YOUTUBE.COM
23 JunOpenClaw’s Skill Marketplace and the Emerging AI Supply Chain ThreatUnit 42's analysis of ClawHub revealed evasive malicious skills bypassing automated scanners to deploy infostealers and execute agentic financial fraud. The post OpenClaw’s Skill Marketplace and the Emerging AI Supply Chain Threat appeared first on Unit 42 .UNIT42.PALOALTONETWORKS.COM
22 JunISC Stormcast For Monday, June 22nd, 2026 https://isc.sans.edu/podcastdetail/9980, (Mon, Jun 22nd)(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.ISC.SANS.EDU
22 JunProduct showcase: Avira Security for iOS blends security, privacy, and device optimizationAvira Mobile Security for iOS combines security, privacy, and device optimization tools in a single application. The app is also available for Android, macOS, and Windows devices. After downloading the application from the App Store users are guided through a short onboarding pro…HELPNETSECURITY.COM
22 JunWho pays when you gate cyber-capable AI models?In this interview with Help Net Security, Jaya Baloo, COO & CISO at Aisle, examines the debate over restricting access to cyber-capable AI models. She lays out the strongest argument for gating these tools, then explains where it breaks down for security teams who depend on …HELPNETSECURITY.COM
22 JunEncrypted DNS still tells an eavesdropper where to lookEncrypted DNS runs across much of the Internet. DNS over TLS, HTTPS, and QUIC keep the contents of a query away from anyone watching a network link. The encryption covers the message inside each packet. The packet still carries plaintext headers, and those values mark a flow as D…HELPNETSECURITY.COM
22 Jun23 ClawHub plugins squatting official scopes expose AI registry security gapsPlugin registries for AI agents use npm-style scopes like @openclaw/ and @clawhub/ to signal who published a package. But on ClawHub, a registry whose plugins run with Claude, OpenClaw, and other agents, those official scopes weren’t reserved to their owners for every packa…HELPNETSECURITY.COM
22 JunFortinet Responds to FortiBleed CampaignA database of over 86,000 confirmed working credentials was created during the credential-harvesting campaign. The post Fortinet Responds to FortiBleed Campaign appeared first on SecurityWeek .SECURITYWEEK.COM
22 JunMore Cybersecurity Firms Disclose Impact From Klue HackHackerOne, Huntress, Jamf, OneTrust, Recorded Future, Snyk, and Tanium are among the affected Klue customers. The post More Cybersecurity Firms Disclose Impact From Klue Hack appeared first on SecurityWeek .SECURITYWEEK.COM
22 JunAnthropic to introduce age and ID checks for Claude users on July 8Anthropic has updated its privacy policy to disclose that Claude users may be asked to verify their age or identity beginning July 8, a change that could require submitting government-issued identification documents and biometric data. The updated policy states that, in certain c…CYBERINSIDER.COM
22 JunProfessional Athletes and WearablesI haven’t thought about the privacy issues surrounding professional athletes and wearables. Wearables present serious privacy issues for “Average Joe” consumers, who are entrusting tech companies to safely store and protect their biometric data. Imagine the stak…SCHNEIER.COM
22 JunMicrosoft Attributes Mastra AI Supply Chain Attack to North KoreaNorth Korean threat actor Sapphire Sleet has been linked to a supply chain attack targeting Mastra, according to Microsoft security researchersINFOSECURITY-MAGAZINE.COM
22 JunNorth Korean Hackers Blamed for Mastra NPM Supply Chain AttackA malicious dependency the attackers added to over 140 Mastra packages fetches a payload targeting cryptocurrency extensions. The post North Korean Hackers Blamed for Mastra NPM Supply Chain Attack appeared first on SecurityWeek .SECURITYWEEK.COM
22 JunWebshells Remain Popular, (Mon, Jun 22nd)Webshells have been popular for a long time. We already covered this topic across multiple diaries[ 1 ][ 2 ]. I spent some time to track them[ 3 ] and slighly paid less attention to them but today I found another one. It seems to be a new player (pus…ISC.SANS.EDU
22 JunIntel agencies: Frontier AI models will reshape cybersecurity faster than expectedThe joint warning from Five Eyes countries mirrors what many cybersecurity and AI experts have been saying for the past year. The post Intel agencies: Frontier AI models will reshape cybersecurity faster than expected appeared first on CyberScoop .CYBERSCOOP.COM
22 JunInterpol, Europol renew agreement to combat hackers and other criminalsExperts say international partnerships are key to taking down sprawling cybercriminal operations.CYBERSECURITYDIVE.COM
22 JunAI-Powered Attacks Are Now a Commodity with Mike Britton, CIO of Abnormal AIMike Britton, CIO at Abnormal AI, joins Dave Bittner on the CyberWire Daily podcast to discuss how AI-powered attacks have evolved from simple phishing assistance into fully productized cybercrime platforms. Drawing on recent research into platforms like VENOM and EvilTokens, as …THECYBERWIRE.COMHTTPS:
22 JunGuarding AI memoryWhat happens when threat actors target what AI remembers? Microsoft breaks down the risks and the defenses. The post Guarding AI memory appeared first on Microsoft Security Blog .MICROSOFT.COM
21 JunThe systemd 261 release brings a software TPM, new OS installerLinux distributions that ship systemd as their init system now have a new version to track. The systemd 261 update adds a cloud metadata subsystem, carries process state through kexec reboots, and continues a long-running effort to load external libraries on demand. Cloud metadat…HELPNETSECURITY.COM
20 JunThreat Brief: Mitigating Large-Scale Credential AttacksWe provide guidance for preparing for and mitigating large-scale credential attacks, focusing on recent campaigns targeting security vendors' devices. The post Threat Brief: Mitigating Large-Scale Credential Attacks appeared first on Unit 42 .UNIT42.PALOALTONETWORKS.COM
19 JunAnthropic’s Fable and the State of AIOn June 9th, Anthropic released its Fable generative AI model. Three days later, the US government classified it as a dangerous munition, and used its export-control authority to prohibit any foreign nationals from accessing it. Unable to differentiate between Americans and forei…SCHNEIER.COM
19 JunAI Phishing Looks Too RealAI-assisted phishing campaigns can now incorporate publicly available information such as conference schedules, speaker lists, and organizational roles. In this case, a message referencing Zero Trust World used a SharePoint link and appeared to come from an event organizer. Recip…YOUTUBE.COM
19 JunProton VPN passes no-logs audit that found no user activity retentionProton VPN has passed the fifth consecutive independent audit of its no-logs policy, with European security firm Securitum concluding that the VPN provider's infrastructure does not retain browsing activity, DNS queries, connection metadata, or records that could link users to sp…CYBERINSIDER.COM
19 JunCisco to Acquire WideField Security to Boost Splunk’s Agentic SOCWideField will accelerate Agentic SOC capabilities by expanding the lens on threat investigation to include identity, credentials, sessions, and blast radius. The post Cisco to Acquire WideField Security to Boost Splunk’s Agentic SOC appeared first on SecurityWeek .SECURITYWEEK.COM
19 JunCybercriminals abused GitHub, YouTube and VirusTotal to push crypto-stealing malwareA cryptocurrency-stealing malware campaign used inflated GitHub activity, software reviews, YouTube tutorials and favorable VirusTotal comments to make malicious trading and gambling tools appear trustworthy, Check Point researchers found. According to the researchers, the attack…HELPNETSECURITY.COM
19 JunForget traffic lights, Google’s reCAPTCHA may ask for hand gesturesGoogle has introduced hand gesture verification for reCAPTCHA, a new method for verifying that a user is human. Google’s reCAPTCHA is part of Google Cloud Fraud Defense, a fraud and abuse prevention platform for bot, account, and transaction protection. It uses risk analysi…HELPNETSECURITY.COM
19 JunAccenture to buy Dragos, runZero, and NetRise in $4.2 billion cybersecurity dealAccenture is expanding its position with the acquisition of a majority stake in Dragos and all of runZero and NetRise to deliver end-to-end operational technology (OT) security for the critical infrastructure and industrial operations underpinning power grids, pipelines, manufact…HELPNETSECURITY.COM
19 JunBlackFog brings shadow AI visibility to macOS endpoints with ADX VisionBlackFog has announced the general availability of ADX Vision for macOS, extending its shadow AI detection, governance, and prevention platform to Apple endpoints. With this release, enterprises can now apply a single, consistent AI data-loss policy across Windows and macOS devic…HELPNETSECURITY.COM
19 JunYour browser tab could become encrypted storage for someone else’s filesDecentralized storage networks already hand pieces of people’s data to strangers’ machines. The lasting question across these networks is whether the machine holding the data can read it. A research paper by Gregory Magarshak, a professor at IENYC, describes a system …HELPNETSECURITY.COM
18 JunISC Stormcast For Thursday, June 18th, 2026 https://isc.sans.edu/podcastdetail/9978, (Thu, Jun 18th)(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.ISC.SANS.EDU
18 JunWhat happens to oversight when AI agents write a lab’s own codeInside the labs building frontier AI, a growing share of the coding gets done by the AI itself. These agents write, edit, and run software with light human oversight between steps, and they reach into production infrastructure, research pipelines, and potentially the systems that…HELPNETSECURITY.COM
18 JunHomebrew tightens tap security, begins work on its interfaceAnyone who installs software through a third-party Homebrew tap runs Ruby code written by people outside the project, and that code runs without a sandbox. That risk sits at the center of Homebrew 6.0.0. Tap trust Homebrew now requires a tap, along with any tap-qualified formula …HELPNETSECURITY.COM
18 JunFrom package to postinstall payload: Inside the Mastra npm supply chain compromiseA poisoned npm package infected 140+ projects with a hidden payload. This report highlights how to detect, hunt, and defend against supply chain attacks using Microsoft Defender and actionable threat intelligence. The post From package to postinstall payload: Inside the Mastra np…MICROSOFT.COM
18 JunSecuring digital keys when your phone unlocks the carIn this interview with Help Net Security, Alysia Johnson, President of the Car Connectivity Consortium (CCC), explains how the CCC Digital Key has grown from a single-brand feature into a standard meant to work across phones, automakers, and suppliers. She talks through what chan…HELPNETSECURITY.COM
18 JunBarracuda introduces AI-powered email security with automated threat responseBarracuda Networks has unveiled Barracuda Integrated Email Protection, an Integrated Cloud Email Security (ICES) solution delivering protection against evolving AI-driven threats. Powered by AI, the solution continuously and autonomously detects and remediates threats across the …HELPNETSECURITY.COM
18 JunNew 42Crunch plugin helps developers find and fix API vulnerabilities in GitHub Copilot42Crunch has announced the availability of the 42Crunch API Security Testing Plugin for GitHub Copilot. This latest advance enables developers to continuously audit, test, remediate and validate API security vulnerabilities directly within AI-assisted development workflows. Organ…HELPNETSECURITY.COM
18 JunBlue Planet helps service providers reduce risk with unified network change governanceBlue Planet is closing the governance gap in network operations by unveiling Blue Planet Configuration and Change Management (CCM), unifying device configuration, change, and lifecycle management across multi-vendor networks. Backed by Blue Planet’s deep Operations Support System…HELPNETSECURITY.COM
18 JunSailPoint to Acquire Entro in Reported $200 Million DealIsrael-based Entro specializes in non-human identity and credential security solutions, and it will enable SailPoint to enhance its products. The post SailPoint to Acquire Entro in Reported $200 Million Deal appeared first on SecurityWeek .SECURITYWEEK.COM
18 JunThe other half of the AI SOC: Intezer, now inside your AI workspaceYour team already lives in, Claude, Codex, Cursor, etc. Discover how to transform them into true security workspaces. The post The other half of the AI SOC: Intezer, now inside your AI workspace appeared first on Intezer .INTEZER.COM
18 JunF5 Patches Critical, High-Severity NGINX VulnerabilitiesCritical flaws in NGINX could allow remote, unauthenticated attackers to cause a restart and potentially execute arbitrary code. The post F5 Patches Critical, High-Severity NGINX Vulnerabilities appeared first on SecurityWeek .SECURITYWEEK.COM
18 JunAtlassian, Splunk Patch Critical VulnerabilitiesSplunk patched an OS command injection in AI Toolkit, while Atlassian fixed dozens of flaws in third-party dependencies. The post Atlassian, Splunk Patch Critical Vulnerabilities appeared first on SecurityWeek .SECURITYWEEK.COM
18 JunRokarolla Banking Trojan Targets 200 ApplicationsThe Android malware allows its operators to take control of infected devices and harvest sensitive information. The post Rokarolla Banking Trojan Targets 200 Applications appeared first on SecurityWeek .SECURITYWEEK.COM
18 JunEmbedding Forbidden Text in Spyware to Discourage AI AnalysisAt least one malware developer is adding text about nuclear and biological weapons to their spyware, in an effort to stop automatic AI analysis. Details : The _index.js payload begins with a large JavaScript block comment containing fake system instructions and policy-triggering …SCHNEIER.COM
18 JunDream Raises $260 Million at $3 Billion ValuationThe Israeli startup provides sovereign AI and cyber defenses for governments and critical infrastructure. The post Dream Raises $260 Million at $3 Billion Valuation appeared first on SecurityWeek .SECURITYWEEK.COM
18 JunMalware attacks strip Roblox developers of entire gamesHackers who once focused on stealing valuable Roblox items are now taking over entire games. Although Roblox operates the service, users can create and publish their own games on it. Successful games can generate substantial revenue through in-game purchases. Some developers have…HELPNETSECURITY.COM
18 Jun74,000 Fortinet firewall credentials exposed in FortiBleed data leakA Russian-speaking cybercriminal group has stolen credentials contained in the configuration files of nearly 74,000 Fortinet firewalls and VPN gateways around the world. The data was accidentally exposed by the group on a server, along with other artifacts and tools, and the expo…HELPNETSECURITY.COM
18 JunAccenture to Acquire Majority Stake in Dragos, All of runZero, NetRise in $4.1 Billion OT Cybersecurity PushThe deal values industrial cybersecurity giant Dragos at $3.25 billion, and runZero and NetRise will operate under Dragos. The post Accenture to Acquire Majority Stake in Dragos, All of runZero, NetRise in $4.1 Billion OT Cybersecurity Push appeared first on SecurityWeek .SECURITYWEEK.COM
18 JunNation-state rivals linked to majority of consequential attacks targeting critical UK sitesThe nation’s top cybersecurity official warned that business leaders, authorities need to rethink how they protect critical infrastructure from state-sponsored adversaries.CYBERSECURITYDIVE.COM
18 JunAccenture shells out $4.18B on three companies in big industrial cybersecurity pushThe consulting giant’s majority stake in Dragos, along with the purchase runZero and NetRise, marks its first major push into operational technology software as AI-driven threats to critical infrastructure intensify. The post Accenture shells out $4.18B on three companies in big …CYBERSCOOP.COM
18 JunUSB worm spreads crypto-stealing malware via Windows shortcut filesThreat actors targeting cryptocurrency wallets have been distributing clipboard-stealing malware with self-spreading capabilities and using the Tor network to conceal communication. [...]BLEEPINGCOMPUTER.COM
18 JunMajority of Internet-Accessible REDCap Servers OutdatedThese servers are regularly targeted by China-linked UNC6508 for initial access and backdoor deployment. The post Majority of Internet-Accessible REDCap Servers Outdated appeared first on SecurityWeek .SECURITYWEEK.COM
18 JunNew Forrester study shows customers who unified with Microsoft Security benefited from 124% ROINew Forrester Total Economic Impact™ study shows Microsoft Security consolidation delivers ROI, lowers risk, and prepares organizations to secure AI. The post New Forrester study shows customers who unified with Microsoft Security benefited from 124% ROI appeared first on Microso…MICROSOFT.COM
18 JunCongress tees up No FAKES Act, aiming at AI-generated deepfakesWhile preventing third parties from profiting off unauthorized deepfakes of artists and performers is a bipartisan concern, some business and digital rights groups are opposed. The post Congress tees up No FAKES Act, aiming at AI-generated deepfakes appeared first on CyberScoop .CYBERSCOOP.COM
18 JunGPS, PCI, ARCH, OH MY! - PSW #931In the security news this week: - GPS spoofing and satellite jamming are getting way too accessible - Rekeying satellites in orbit sounds terrifying - Cyber extortion and whether criminals still have ethics - AI helping cybersecurity research... and drug discovery - Data centers …YOUTUBE.COM
18 JunAuthorities disrupt Evil Corp’s SocGholish botnetCybersecurity firms, researchers and officials took down 106 servers and remediated nearly 15,000 sites that were infected with the malware. The post Authorities disrupt Evil Corp’s SocGholish botnet appeared first on CyberScoop .CYBERSCOOP.COM
17 JunISC Stormcast For Wednesday, June 17th, 2026 https://isc.sans.edu/podcastdetail/9976, (Wed, Jun 17th)(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.ISC.SANS.EDU
17 JunProduct showcase: From phishing texts to risky Wi-Fi, Norton 360 Deluxe watches the gapsNorton 360 Deluxe combines device security, scam detection, web protection, and VPN privacy in a single subscription that covers up to five devices. It is available for Windows, macOS, Android, and iOS. Setup and first impressions After downloading the app from the App Store, use…HELPNETSECURITY.COM
17 JunThe SOC’s visibility gap comes down to staffingAI has settled into security operations centers faster than any earlier wave of technology. Around four in five practitioners report reaching for AI or machine learning tools in their daily work. The catch shows up one layer down. Roughly a third of those same teams have built th…HELPNETSECURITY.COM
17 JunFortinet FortiSOC unifies SIEM, SOAR, threat intelligence, and AI in one platformFortinet has announced the availability of FortiSOC, a unified, cloud-delivered security operations center (SOC) platform. FortiSOC brings together six security operations functions into a single Software-as-a-Service (SaaS) experience and embeds agentic AI to autonomously invest…HELPNETSECURITY.COM
17 JunApple is bringing Hide My Email and Sign in with Apple under one domainApple will unify the email domains used by Sign in with Apple and iCloud+ Hide My Email under a shared domain, private.icloud.com, later this summer. Hide My Email is a service included with iCloud+, Apple’s subscription service. It allows users to generate one-time-use or …HELPNETSECURITY.COM
17 JunEnterprise Browers in the Age of AI as CISO Role Changes and Leaders Harness Stress - BSW #452The browser has become the primary gateway to work, data, and AI. In this episode, Arunesh Chandra, Head of Product, Microsoft Edge for Business at Microsoft Edges for Business, will discuss why security and IT teams are rethinking the role of the browser and what sets Edge for B…YOUTUBE.COM
17 JunWhat’s new in Android 17? Anti-theft tools, scam detection, and parental controlsThe Android 17 rollout has started for supported Pixel devices, delivering new security and privacy capabilities before expanding to other devices later this year. Security and privacy updates Google has improved location privacy features so users can choose to share their approx…HELPNETSECURITY.COM
17 JunRockwell Automation Patches Vulnerabilities in ICS Controllers and SoftwareThe industrial automation giant has fixed security holes in Logix, CompactLogix, Flex, RSLinx, and FactoryTalk products. The post Rockwell Automation Patches Vulnerabilities in ICS Controllers and Software appeared first on SecurityWeek .SECURITYWEEK.COM
17 Jun1Password Acquires Apono in Reported $250M-$300M DealApono specializes in just-in-time access governance technology for humans, machines, and AI agents. The post 1Password Acquires Apono in Reported $250M-$300M Deal appeared first on SecurityWeek .SECURITYWEEK.COM
17 JunTenet Security Emerges From Stealth With $6 Million Seed FundingTenet aims to detect and stop dangerous AI agentic behavior in real time. The post Tenet Security Emerges From Stealth With $6 Million Seed Funding appeared first on SecurityWeek .SECURITYWEEK.COM
17 JunFlip expands platform with digital identity, no-code apps, and AI automationFlip has announced Frontline Identity and Flip Fusion, two new offerings that help organizations securely connect frontline employees to enterprise systems, applications and AI-powered workflows. Flip’s new products expand the platform beyond employee communications, helpin…HELPNETSECURITY.COM
17 JunCorelight enhances Open NDR to detect AI-driven threats and unknown assetsCorelight has expanded its Open NDR platform to include native network performance monitoring and passive asset classification capabilities. The release adds asset visibility to its existing anomaly detection foundation, helping security teams defend against AI-powered threats th…HELPNETSECURITY.COM
17 JunFrom Stars to Upvotes: Fake Reputation Fueling a Crypto Clipboard HijackerKey Points Introduction In this research, we analyze a clipboard hijacker campaign that is hidden inside a collection of “solutions” and “tools” that claim to give users an unfair advantage. These offers include Solana and Pump.fun sniper bots (automated tools that try to buy new…RESEARCH.CHECKPOINT.COM
17 JunNorth Korean Hiring Fraud Runs on AI and US Laptop FarmsNisos infiltrated a North Korean IT-worker fraud cell running on AI interviews and a US laptop farmINFOSECURITY-MAGAZINE.COM
17 JunWitnessAI Agentic Control secures AI agents, tools, and MCP server accessWitnessAI has announced extended agentic security capabilities that govern how AI agents interact with enterprise systems, tools, and Model Context Protocol (MCP) servers. With the launch of Agentic Control, enterprises have greater visibility and control over their AI agents wit…HELPNETSECURITY.COM
17 JunMost Security Controls Just Slow AttackersAI agents can pursue goals, select tools, retain memory across sessions, communicate with other agents, and take actions inside systems without constant human oversight. Many existing security controls were designed around slowing down or interrupting human behavior. But autonomo…YOUTUBE.COM
17 JunForrester names Microsoft a Leader in the 2026 Extended Detection and Response Platforms Wave™ reportMicrosoft has been named a Leader in The Forrester Wave™: Extended Detection and Response Platforms, Q2 2026. The post Forrester names Microsoft a Leader in the 2026 Extended Detection and Response Platforms Wave™ report appeared first on Microsoft Security Blog .MICROSOFT.COM
17 JunTrain Your Team Or Fall BehindJason ABQ argues that organizations often prioritize nonstop productivity at the expense of professional development. His recommendation: teams should intentionally reserve time for training, certifications, leadership development, and learning new technologies. As AI tools and w…YOUTUBE.COM
17 JunCrypto Clipper uses Tor and worm-like propagation for persistence and controlMicrosoft Threat Intelligence analyzed a cryptocurrency clipper campaign that combines clipboard theft, wallet replacement, Tor-based communications, and worm-like propagation. Beyond stealing cryptocurrency transactions, the malware establishes persistent access and enables foll…MICROSOFT.COM
16 JunNorth Korean Hackers Are Turning Developer Tools Into Malware Delivery ChannelsCybersecurity researchers have flagged two malicious cyber campaigns that exhibit similarities with a persistent North Korean threat cluster known as Contagious Interview (aka Famous Chollima, HexagonalRodent, and Void Dokkaebi). According to a report published by Proofpoint, the…THEHACKERNEWS.COM
16 JunISC Stormcast For Tuesday, June 16th, 2026 https://isc.sans.edu/podcastdetail/9974, (Tue, Jun 16th)(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.ISC.SANS.EDU
16 JunA $2 trillion revenue shift hinges on AI data governanceAcross large enterprises, a single question keeps surfacing when teams want to put customer data to work. Can this record be used for a given purpose, and does the consent behind it still hold? The data sits in warehouses and customer databases, and the ability to answer that que…HELPNETSECURITY.COM
16 JunGitHub releases an open dataset for multilingual developer contentDevelopers coordinate code across README files, issue threads, and pull request discussions. Much of that exchange happens in English, and a large share happens in other languages. GitHub has released a dataset built to help researchers and developers locate public repositories t…HELPNETSECURITY.COM
16 JunFrom a VHDX File to a Remcos RAT, (Tue, Jun 16th)Yesterday, a reader reported to us a malicious ZIP archive (SHA256: a0104921a2d37ab87482ac9a9f5c3713479c118846c3e999178e75b81620c094[ 1 ]). Once unzipped, it contains a VHDX file that discloses a malicious JavaScript after being mounted (which is automatic on modern Win…ISC.SANS.EDU
16 JunFake Microsoft Alerts Used to Deploy North Korean NarwhalRAT MalwareThe North Korean state-sponsored hacking group known as ScarCruft (aka APT37) has been observed using spear-phishing messages impersonating Microsoft Account security notifications to deliver malware called NarwhalRAT. "The attack email contained a message impersonating an MS acc…THEHACKERNEWS.COM
16 JunESET discovers Windows SprySOCKS variant with rootkit capabilitiesESET researchers have uncovered two previously undocumented Windows variants of SprySOCKS, a backdoor previously known only as a Linux threat and linked to the China-aligned cyberespionage group FishMonger. The newly discovered malware variants significantly expand the group's ca…CYBERINSIDER.COM
16 JunWhy Does It Matter Who or What Created the Code? - Matias Madou - ASW #387Agents and LLMs are creating and reviewing code. They're a new tool to help developers write software and they're a new abstraction layer for expressing what code should do. But if we're focused on determining whether code is secure, where do we focus our attention on ensuring a …YOUTUBE.COM
16 JunTech Coalition ‘Athena’ Targets OSS Vulnerabilities Ahead of DisclosureOver two dozen organizations built a shared platform to triage vulnerabilities, fix them, and secure the software before patches arrive. The post Tech Coalition ‘Athena’ Targets OSS Vulnerabilities Ahead of Disclosure appeared first on SecurityWeek .SECURITYWEEK.COM
16 JunAtomic Arch Supply Chain Attack Hits 1,500 AUR PackagesArch Linux suspended account registrations in response to the wave of malicious packages being uploaded to AUR. The post Atomic Arch Supply Chain Attack Hits 1,500 AUR Packages appeared first on SecurityWeek .SECURITYWEEK.COM
16 JunCrypto scammers are sending couriers to victims’ homes to collect cashScammers behind cryptocurrency investment schemes are dispatching couriers to pick up cash from victims in person, the FBI warns. According to the agency, scammers usually approach victims through social media, text messages, or fake investment personas, luring them into cryptocu…HELPNETSECURITY.COM
16 JunFlock Cameras Are Being Used for StalkingThere are over a dozen cases around the country where police officers are using the Flock surveillance camera system to obsessively and illegally stalk people . Alternate link .SCHNEIER.COM
16 JunCal Water Investigating Iranian Hackers’ ClaimsCalifornia Water Service says there is no indication of operational disruptions to its water and wastewater systems. The post Cal Water Investigating Iranian Hackers’ Claims appeared first on SecurityWeek .SECURITYWEEK.COM
16 JunWhite House Issues Memo to Bolster NSS CybersecurityNSPM-12 establishes a clear structure for NSS cybersecurity governance and accountability and reestablishes CNSS. The post White House Issues Memo to Bolster NSS Cybersecurity appeared first on SecurityWeek .SECURITYWEEK.COM
16 JunSteam Workshop hosts wallpapers with account-stealing malwareResearchers at Kaspersky have uncovered dozens of malicious wallpapers distributed through Steam Workshop that were designed to steal Steam accounts and infect systems with malware. The campaign abuses Wallpaper Engine, a popular Steam application for animated desktop backgrounds…CYBERINSIDER.COM
16 JunEndpoint Security Startup Ent Emerges From Stealth With $100 Million Seed RoundEnt has developed an intent-aware platform designed to interpret user and agent behavior before risky actions are carried out. The post Endpoint Security Startup Ent Emerges From Stealth With $100 Million Seed Round appeared first on SecurityWeek .SECURITYWEEK.COM
16 JunCybercrime Group Claims Novo Nordisk HackThe hack-and-leak group FulcrumSec claims to have stolen 1.3TB of data from the pharmaceutical giant. The post Cybercrime Group Claims Novo Nordisk Hack appeared first on SecurityWeek .SECURITYWEEK.COM
16 JunCan CISOs Trust Their Applications? TrustCloud Wants to Replace the QuestionnaireBy continuously analyzing security, infrastructure, and governance data, TrustCloud aims to give CISOs a real-time view of application risk and board-ready assurance. The post Can CISOs Trust Their Applications? TrustCloud Wants to Replace the Questionnaire appeared first on Secu…SECURITYWEEK.COM
16 JunTeleport adds LLM Proxy and Delegated Identity to secure AI agent actions and accessTeleport has announced the debut of two foundational capabilities of its Agentic Identity Framework in the public beta of Beams: LLM Proxy and Delegated Identity. These capabilities address a critical gap in how organizations deploy AI agents: the lack of identity, access control…HELPNETSECURITY.COM
16 JunMagnitude Emerges From Stealth Mode With $10 Million in FundingThe company is enhancing third-party risk management (TPRM) through autonomous AI agents. The post Magnitude Emerges From Stealth Mode With $10 Million in Funding appeared first on SecurityWeek .SECURITYWEEK.COM
16 JunAI and Cybersecurity – Everything You Wanted to Know, But Were Afraid to AskFrom defending networks to enabling attacks, artificial intelligence is changing every aspect of cybersecurity. Here's what dozens of experts say security leaders need to understand now. The post AI and Cybersecurity – Everything You Wanted to Know, But Were Afraid to Ask appeare…SECURITYWEEK.COM
16 JunTekStream launches Proactive Cyber Defense to counter AI-driven threatsTekStream has announced the launch of TekStream Proactive Cyber Defense, a new expert-operated security service powered by Cosmos, the company’s cyber defense intelligence platform. The launch comes as organizations face a rapidly changing threat landscape shaped by AI-accelerate…HELPNETSECURITY.COM
16 JunAppViewX extends machine identity security to ai agents and post-quantum environmentsAppViewX has announced Agent Identity Security, a new product within the AppViewX platform that discovers, governs, secures, and monitors AI agents across the entire enterprise. Agent Identity Security extends AppViewX’s platform, built on a decade of machine identity and P…HELPNETSECURITY.COM
16 JunGovern AI Code Or ElseMatias Madou argues that software teams need to start governing AI-generated code, not just reviewing it. Traditional development workflows assume a human author creates code and another human reviews it. AI introduces additional contributors, making authorship, accountability, a…YOUTUBE.COM
16 JunHacker Conversations: Isira Adithya, the Evolution of an Ethical HackerFrom building LED bulbs to graduating college and buying a house with money earned from bug bounties. The post Hacker Conversations: Isira Adithya, the Evolution of an Ethical Hacker appeared first on SecurityWeek .SECURITYWEEK.COM
16 JunA case for how to shape ‘ingredient lists’ for AI modelsAI bills of materials (AIBOMs), modeled on standards that worked for software, could transform how policymakers understand and regulate AI. A new roadmap outlines what they need to include and how to get there. The post A case for how to shape ‘ingredient lists’ for AI models app…CYBERSCOOP.COM
16 JunSteam Workshop abused to spread malware via Wallpaper Engine appThreat actors are abusing Steam Workshop, Valve's community hub for downloading game-related content, to push various malware hidden in wallpaper packages. [...]BLEEPINGCOMPUTER.COM
16 JunThe Security Tool Nobody NoticesAn attacker attempted to submit backdoored code, but a linter repeatedly flagged issues during the development process. The common saying is that attackers only need to be right once. But in practice, many attacks require a sequence of successful actions that avoid detection. Eac…YOUTUBE.COM
16 JunTSME, ARCH, Maine, Fable, PANOS, Doug's Grandma, Vienna Sausages, Aaran Leyland - SWN #590TSME, ARCH, Maine, Fable, PANOS, Doug's Grandma, Vienna Sausages, Aaran Leyland, and More on the Security Weekly News. Visit https://www.securityweekly.com/swn for all the latest episodes! Show Notes: https://securityweekly.com/swn-590YOUTUBE.COM
16 JunAI’s constant patching treadmill can be a security problemThe breakneck speed of model releases may be creating short, silent security gaps as developers must choose between performance and security, according to a new report. The post AI’s constant patching treadmill can be a security problem appeared first on CyberScoop .CYBERSCOOP.COM
15 JunThe FCC Wants to Eliminate Burner PhonesA proposed FCC rule would kill burner phones: phones whose accounts are not attached to a particular person. The FCC plans to do this by legally forcing the country’s telecoms to store a wealth of personal information about essentially all phone customers, including a gover…SCHNEIER.COM
15 JunEvil MSI Background: BASE64 Statistical Analysis, (Mon, Jun 15th)I like it when a fellow handler posts a diary entry about images with malicious content. Last one is Xavier: " The Evil MSI Background is Back! ".
ISC.SANS.EDU
15 JunISC Stormcast For Monday, June 15th, 2026 https://isc.sans.edu/podcastdetail/9972, (Mon, Jun 15th)(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.ISC.SANS.EDU
15 JunPost Quantum Rollouts Break SystemsReadiness for post-quantum cryptography is uneven, with estimates suggesting a large portion of client software is prepared while only a small fraction of enterprise and server systems are ready. Concerns around deployment include system incompatibility, unreachable environments,…YOUTUBE.COM
15 JunCybersecurity experts don’t think Anthropic’s Fable 5 presents a unique threatDozens of practitioners said the decision to place export controls on the foreign use of Fable are misguided, and recent jailbreak reports don’t show the model providing unique hacking capabilities. The post Cybersecurity experts don’t think Anthropic’s Fable 5 presents a unique …CYBERSCOOP.COM
15 JunChina-nexus group linked to multiyear campaign targeting US, Canadian medical researchA report from Google links a sophisticated espionage effort targeting information about viruses, AI and military information.CYBERSECURITYDIVE.COM
15 JunCybersecurity experts blast US government for restricting Anthropic’s AI modelsChief information security officers and prominent researchers called a recent export-control ban “dangerous.”CYBERSECURITYDIVE.COM
15 JunChinese Hackers Target Medical, Military, and AI Research in North AmericaGoogle’s Threat Intelligence Group has been tracking the cyberespionage group as UNC6508 since early 2025. The post Chinese Hackers Target Medical, Military, and AI Research in North America appeared first on SecurityWeek .SECURITYWEEK.COM
15 JunNewCore Emerges From Stealth Mode With $66 Million in FundingThe startup has built a security-first identity platform to protect humans, machines, and AI agents. The post NewCore Emerges From Stealth Mode With $66 Million in Funding appeared first on SecurityWeek .SECURITYWEEK.COM
15 JunShinyHunters Claims Council of Europe HackThe extortion group threatens to leak 297 GB of data allegedly stolen from the Council of Europe, including employee personal information. The post ShinyHunters Claims Council of Europe Hack appeared first on SecurityWeek .SECURITYWEEK.COM
15 JunFBI, Google Dismantle ‘Outsider Enterprise’ Phishing ServiceThe platform used more than 9,000 phishing sites, stealing nearly 4 million credit cards and causing roughly $1.9 billion in losses. The post FBI, Google Dismantle ‘Outsider Enterprise’ Phishing Service appeared first on SecurityWeek .SECURITYWEEK.COM
15 JunChina-linked spies backdoored authentication stack to stay hidden for yearsA China-linked cyber espionage group known as Velvet Ant spent nearly a decade inside the internal network of an unnamed organization without being detected, according to the results of a forensic investigation published by cybersecurity firm Sygnia. The group’s defining ch…HELPNETSECURITY.COM
15 JunDelinea and Cyera integrate for data-aware identity securityDelinea and Cyera announced a product integration that connects privileged access to sensitive data exposure, automatically correlating identities with the data they can access. Together, Delinea and Cyera help security teams identify, prioritize, and remediate the highest-risk a…HELPNETSECURITY.COM
15 JunRed Sift, GMO GlobalSign partnership simplifies email authentication and BIMI adoptionRed Sift has announced a partnership with GMO GlobalSign to provide organizations with a direct path from email authentication to verified brand visibility in the inbox. Red Sift OnDMARC is now available through GMO GlobalSign, enabling secure outbound email protection and the ac…HELPNETSECURITY.COM
15 JunMicrosoft Defender email security benchmarking: Key insights from one year of dataSee how Microsoft Defender performed in one year of real-world email security benchmarking against SEG and ICES vendors. The post Microsoft Defender email security benchmarking: Key insights from one year of data appeared first on Microsoft Security Blog .MICROSOFT.COM
14 JunUpcoming Speaking EngagementsThis is a current list of where and when I am scheduled to speak: I’m giving a keynote at Cybernation 2026 in Berlin, Germany, on June 24, 2026. I’m speaking at the Potsdam Conference on National Cybersecurity at the Hasso Plattner Institut in Potsdam, Germany. The event runs Jun…SCHNEIER.COM
13 JunNPM 12 Will Change Script Execution Behavior to Prevent Supply Chain AttacksBy default, npm install will no longer execute scripts from dependencies, unless explicitly allowed. The post NPM 12 Will Change Script Execution Behavior to Prevent Supply Chain Attacks appeared first on SecurityWeek .SECURITYWEEK.COM
12 JunNew infosec products of the week: June 12, 2026Here’s a look at the most interesting products from the past week, featuring releases from AISLE, Drata, Elastic, Filigran, IDnow, and Ridge Security. RidgeBot 7.0 automates Active Directory attack simulations for security validation Ridge Security has announced the release of Ri…HELPNETSECURITY.COM
12 JunAI sovereignty makes data centers strategic targets for cyber operationsData centers built for frontier AI draw hundreds of megawatts of electricity and large volumes of cooling water from fixed locations with known addresses. Each one concentrates tens of thousands of graphics processors, liquid cooling systems, and high-density power equipment insi…HELPNETSECURITY.COM
12 JunProduct showcase: Avast One turns scam screenshots into actionable security adviceAvast One Free combines privacy, security, identity monitoring, and performance tools in a single platform. The app is available for Windows, macOS, Android, and iOS. Checking the device for security and privacy issues After installing it from the App Store, I ran Smart Scan, whi…HELPNETSECURITY.COM
12 JunEurope’s digital identity wallet gets its first set of standardsPeople across the European Union already use their phones for banking, travel, and government services. The European Digital Identity Wallet will bring those activities into one application, and the European Telecommunications Standards Institute (ETSI) has released the first sta…HELPNETSECURITY.COM
12 JunZeroFox releases AI Analytics to bring answers directly to security teamsZeroFox launched ZeroFox AI Analytics, a new platform capability that gives security teams real-time visibility into the signals, patterns, and trends shaping their external threat landscape. ZeroFox AI Analytics gives security teams the ability to move beyond static reports and …HELPNETSECURITY.COM
12 JunThe assembly line behind 1.5 million malicious domainsAttackers registered roughly 1.5 million malicious domains during the first five months of 2026. The registration patterns resemble industrial output. Most of the domains were created by attackers, put to use within weeks, and concentrated among a small set of registrars, top-lev…HELPNETSECURITY.COM
12 JunAnthropic Disputes Fable 5 AI JailbreakAn AI hacker claims to have achieved a prompt-based jailbreak shortly after Fable 5’s launch, but Anthropic says it’s not a real jailbreak. The post Anthropic Disputes Fable 5 AI Jailbreak appeared first on SecurityWeek .SECURITYWEEK.COM
12 JunCybercriminals are moving away from mass phishing campaignsPhishing activity declined by roughly 20% in both 2024 and 2025, according to research from Zscaler’s ThreatLabz team. The drop followed years of growth that pushed phishing activity above 2 billion hits in 2023. “Phishing volume measured by blocked emails is no longe…HELPNETSECURITY.COM
12 JunBernie Sanders’ AI Sovereign Wealth Fund PlanLet no one accuse Bernie Sanders of ducking the big questions. Writing in the New York Times last week, the senator asked : “Will the future of humanity be determined by a handful of billionaires who have promoted and developed AI, with virtually no democratic input, who st…SCHNEIER.COM
12 JunRethinking MDR as Attackers and Defenders Embrace AIFor most of the past decade, managed detection and response was the answer to a real problem. Security teams couldn't staff around the clock, couldn't hire enough analysts, and needed someone else to handle the alert queue. MDR stepped in. It worked well enough. Until now. The th…THEHACKERNEWS.COM
12 JunCyberCorps is adapting to AI. The budget isn’t keeping up.CyberCorps is evolving to tackle AI threats. But budget cuts could derail it before the work even starts. The post CyberCorps is adapting to AI. The budget isn’t keeping up. appeared first on CyberScoop .CYBERSCOOP.COM
12 JunIranian Cyber Group Handala Claims Cal Water HackThe hackers published 5GB of data, including customer personal information and credentials for the RTKBase platform. The post Iranian Cyber Group Handala Claims Cal Water Hack appeared first on SecurityWeek .SECURITYWEEK.COM
12 JunISC Stormcast For Friday, June 12th, 2026 https://isc.sans.edu/podcastdetail/9970, (Fri, Jun 12th)(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.ISC.SANS.EDU
12 JunIndustry Reactions to Claude Fable 5: Feedback FridayIndustry professionals comment on various aspects of Fable 5, including dual-use capabilities, safeguards, and tiered access. The post Industry Reactions to Claude Fable 5: Feedback Friday appeared first on SecurityWeek .SECURITYWEEK.COM
12 JunGoogle sues China-based scammers over Gemini AI abuseGoogle has filed a lawsuit against Outsider Enterprise, a China-based cybercrime network for using AI tools, including Gemini, to build phishing websites and scam infrastructure. The company said the operation has affected “hundreds of thousands of victims,” with loss…HELPNETSECURITY.COM
12 JunNavigating the New Federal Logging Mandate | OMB Memorandum M-26-14The White House Memorandum puts in place an “adaptive framework,” where agencies make risk-based, prioritized logging decisions.WIZ.IO
12 JunIt’s Mythos’ world now. How do we live in it?Anthropic's powerful model raises difficult questions about how government and industry should work together to safeguard systems in the AI era.CYBERSECURITYDIVE.COM
12 JunResearcher uses AI to hack Google and collect $500,000 in bountiesSecurity researcher Arvin Shivram has revealed how a custom AI-powered testing system uncovered dozens of vulnerabilities across Google's vast API ecosystem, earning more than $500,000 in bug bounty rewards. The findings included access control failures affecting Google Voice, Wi…CYBERINSIDER.COM
12 JunUS, France, and Italian authorities shut down massive deepfake porn siteThe website specialized in non-consensual sexual images of famous women, including politicians, first ladies, royalty, journalists, television presenters, athletes, and entertainers, and others. The post US, France, and Italian authorities shut down massive deepfake porn site app…CYBERSCOOP.COM
12 JunMisconfigured Tor hidden services leak IP addresses and server dataTor hidden services are designed to conceal a website's real location and IP address, allowing operators to remain anonymous while serving content through the Tor network. However, a new report from SOS Intelligence researcher Amir Hadzipasic shows that simple configuration mista…CYBERINSIDER.COM
12 JunChina-Linked Hackers Backdoored Linux Login Software to Hide for Nearly a DecadeInstead of hiding on the laptops and servers defenders watch most closely, a China-nexus group spent close to a decade hidden inside the Linux login system itself. Sygnia, which tracks the group as Velvet Ant, says it backdoored the PAM and OpenSSH components that decide who is a…THEHACKERNEWS.COM
12 JunFriday Squid Blogging: Squid-Inspired Fluid PumpThis fluid pump was inspired by the way squids propel themselves through the water. As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered. Blog moderation policy.SCHNEIER.COM
12 JunPhones, Sarlaccs, Maine, Chinese Sites, Ivanti, Bitlocker, Peoplesoft, and More - SWN #589Bad Phones, Sarlaccs, Maine, Chinese Sites, Ivanti, GreatXML, Bitlocker, Peoplesoft, Josh Marpet, and More on this episode of the Security Weekly News. Visit https://www.securityweekly.com/swn for all the latest episodes! Show Notes: https://securityweekly.com/swn-589YOUTUBE.COM
12 JunFBI takes down massive China-based cybercrime network that caused $1.9B in lossesOutsider provided phishing kits and infrastructure for cybercriminals to scam victims with lures claiming they missed packages, had unpaid tolls or parking violations. The post FBI takes down massive China-based cybercrime network that caused $1.9B in losses appeared first on Cyb…CYBERSCOOP.COM
12 JunTracing Digital Intent: New MacOS Tahoe 26 Artifact DiscoveredUnit 42 has discovered a new macOS Tahoe 26 forensic artifact that tracks user menu selections across the operating system. Learn more here. The post Tracing Digital Intent: New MacOS Tahoe 26 Artifact Discovered appeared first on Unit 42 .UNIT42.PALOALTONETWORKS.COM
11 JunChinese, N. Korean Threat Groups Build on Asia-Pacific SuccessNorth Korea's gross domestic product (GDP) has grown, in part because of the cybercrime gains of groups linked to the nation, which target business and financial firms.DARKREADING.COM
11 JunISC Stormcast For Thursday, June 11th, 2026 https://isc.sans.edu/podcastdetail/9968, (Thu, Jun 11th)(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.ISC.SANS.EDU
11 JunOrganizations can’t see much of their mobile AI activityOrganizations have limited visibility into AI activity on mobile devices despite security leaders expressing confidence in their AI governance, according to Lookout’s “Solving for the Mobile AI Blind Spot: Executive Confidence Meets Technical Reality” report. Mo…HELPNETSECURITY.COM
11 JunThreat actors are recruiting the people who hold cloud loginsCompanies keep most of their data and applications in cloud platforms that anyone can reach with the right login. That setup turns each employee holding those credentials into a security variable, and members of the cybercrime underground have built methods to reach those people.…HELPNETSECURITY.COM
11 JunMaking the cloud prove it followed your privacy wishesMaking companies that store personal data in cloud key-value databases handle deletion requests by running the operation and confirming the job is complete. The people making those requests and the regulators overseeing them have had limited means to confirm the data is gone or t…HELPNETSECURITY.COM
11 JunCheck Point expands MSP platform with with AI governance and unified security bundlesCheck Point has announced a major expansion of its Managed Service Provider (MSP) platform, designed to help MSPs secure AI adoption, streamline operations and simplify managed security delivery. The announcement brings together three strategic innovations under a single MSP visi…HELPNETSECURITY.COM
11 JunIDnow launches Trust Platform to help regulated firms move from KYC to continuous trustIDnow has announced the launch of the IDnow Trust Platform, designed to help regulated organisations orchestrate identity verification, fraud prevention, biometric authentication, and qualified digital trust services throughout the customer lifecycle. “The identity industry…HELPNETSECURITY.COM
11 Jun9 out of 10 people can no longer distinguish real from AI-generated contentOnline fraud is becoming harder to distinguish from legitimate activity as AI-generated messages, voices, photos, reviews, and identities become more convincing. Nearly nine in ten adults say they can no longer tell what is real from AI-generated content, according to the latest …HELPNETSECURITY.COM
11 JunOceanLotus Hits Vietnam Investors With SPECTRALVIPER in FireAnt AttackThe Vietnam-aligned threat actor known as OceanLotus has been attributed to two distinct campaigns that targeted domestic entities and stock investors with a backdoor known as SPECTRALVIPER. The campaigns involve a prolonged cyber espionage operation aimed at a Vietnamese infrast…THEHACKERNEWS.COM
11 JunTrust No Skill: Integrity Verification for AI Agent Supply ChainsProtect enterprise AI agents from supply chain risks by auditing third-party skills for hidden vulnerabilities and multi-stage attack chains. The post Trust No Skill: Integrity Verification for AI Agent Supply Chains appeared first on Unit 42 .UNIT42.PALOALTONETWORKS.COM
11 JunFBI seizes 13 websites linked to alleged Chinese intelligence-gathering effortFederal authorities have seized 13 internet domains allegedly used to target current and former U.S. government employees and military personnel with access to classified and sensitive information. The post FBI seizes 13 websites linked to alleged Chinese intelligence-gathering e…HELPNETSECURITY.COM
11 JunSiemens Says Desigo CC Files Flagged as Malware by Security EnginesA PowerShell script included in patch files appears to be triggering false positives by multiple security engines. The post Siemens Says Desigo CC Files Flagged as Malware by Security Engines appeared first on SecurityWeek .SECURITYWEEK.COM
11 JunFBI Seizes 13 Websites That Officials Say Were Used by China to Target and Recruit US WorkersThe 13 websites purported to be affiliated with consulting companies that advertised job openings for current and former holders of security clearances The post FBI Seizes 13 Websites That Officials Say Were Used by China to Target and Recruit US Workers appeared first on Securit…SECURITYWEEK.COM
11 JunOnyxC2 Stealer Offers Cybercriminals Enterprise-Grade Theft for $250 a MonthResearchers say the OnyxC2 malware targets more than 200 applications and extensions while evading detection through encrypted payloads, DLL sideloading, and in-memory execution techniques. The post OnyxC2 Stealer Offers Cybercriminals Enterprise-Grade Theft for $250 a Month appe…SECURITYWEEK.COM
11 JunAlert Fatigue Is Becoming a Security Threat of Its OwnAs alert volumes outpace human capacity, organizations are turning to AI, automation, and deeper context to separate real threats from the noise. The post Alert Fatigue Is Becoming a Security Threat of Its Own appeared first on SecurityWeek .SECURITYWEEK.COM
11 JunFake Spotify Premium tutorials on TikTok and Instagram Reels spread malwareCybercriminals are using TikTok and Instagram Reels videos to spread Vidar, an infostealer malware, through fake downloads for popular paid software, according to ReversingLabs. The researchers uncovered two campaigns behind the activity, each using a different approach to draw i…HELPNETSECURITY.COM
11 JunProxmox releases Mail Gateway 9.1 with quarantine and backup encryption changesProxmox Mail Gateway 9.1 adds updated system components, changes to the spam quarantine interface, and encryption for backups. It works as a mail proxy positioned between the firewall and internal mail servers, screening incoming and outgoing traffic for spam, viruses, Trojans, a…HELPNETSECURITY.COM
11 JunMaking secret scanning more trustworthy: Reducing false positives at scaleAlerts are more trustworthy and actionable when noise is reduced. See how we improved the verification step with context-aware LLM reasoning. The post Making secret scanning more trustworthy: Reducing false positives at scale appeared first on The GitHub Blog .GITHUB.BLOG
11 JunHacker linked to Void Blizzard faces charges over cyberespionage campaignDenis Obrezko, 36, made his initial appearance in federal court in Boston on Tuesday after being transferred to U.S. custody from Thailand, where he was arrested last November.THERECORD.MEDIA
11 JunEnterprises report increasing budgets for security training in AI and other critical topicsFinding the time to train employees remains the biggest impediment to programs’ success, according to a new report.CYBERSECURITYDIVE.COM
11 JunFIFA World Cup expected to face extensive criminal, hacktivist cyber threatsResearchers warn that thousands of malicious domains are already in place, as fans, tournament organizers face potential attacks.CYBERSECURITYDIVE.COM
11 JunHundreds of iPhone apps found leaking OpenAI, Gemini credentialsAn academic study has found that LLM-powered iOS applications routinely expose API credentials that can be abused to access AI services. Researchers discovered that nearly two-thirds of tested apps leaked credentials or exposed backend access mechanisms, with many vulnerabilities…CYBERINSIDER.COM
10 JunISC Stormcast For Wednesday, June 10th, 2026 https://isc.sans.edu/podcastdetail/9966, (Wed, Jun 10th)(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.ISC.SANS.EDU
10 JunCyber resilience metrics that drive actionIn this Help Net Security video, Pete Bowers, COO at NormCyber, explains how organizations can build a cyber resilience metrics program that supports better decisions. He questions common ways of measuring resilience, such as risk registers, tool scores, and annual tests, and poi…HELPNETSECURITY.COM
10 JunThe security in smartphones is helping send them to landfillsBillions of working smartphones reach the end of their service lives each year and move into drawers, recycling streams, and waste piles. The WEEE Forum estimated that 5.3 billion mobile phones became electronic waste in 2022. Many of these devices still function. The average sma…HELPNETSECURITY.COM
10 JunHow has use of framing protection security headers changed in the past 3 years?, (Wed, Jun 10th)Back in 2023, I wrote a diary[ 1 ] discussing how commonly X-Frame-Options and CSP headers containing the frame-ancestors directive were used on 1 million most popular domains on the internet (based on the Tranco list[ 2 ]), and how they were set. Given that t…ISC.SANS.EDU
10 JunEvery set of AI guardrails can be broken by the right promptCompanies that build AI systems wrap them in guardrails meant to block harmful output, including deepfakes, malware, and instructions for making biological weapons or illicit drugs. When a user prompts the system for such content, the guardrails are designed to flag the request a…HELPNETSECURITY.COM
10 JunApple extends Private Cloud Compute to third-party data centersApple is bringing its Private Cloud Compute (PCC) platform to Google Cloud, expanding the infrastructure behind Apple Intelligence to third-party data centers. Introduced in 2024, PCC provides cloud-based processing for AI workloads that exceed the capabilities of on-device model…HELPNETSECURITY.COM
10 JunAnthropic’s Claude Fable 5 is out for public use, with safeguards for high-risk requestsDays after publishing research on how advanced AI systems could amplify cyber operations in the wrong hands, Anthropic released Claude Fable 5, a Mythos-class model for general use. “Releasing a model this capable comes with risks. Without safeguards, Fable 5’s capabilities in ar…HELPNETSECURITY.COM
10 JunSignal and Mullvad warn about the UK’s plans to scan people’s phonesThe encrypted messaging platform Signal and privacy-focused VPN provider Mullvad have sharply criticized a new UK government proposal that would require technology companies to block children from taking, sharing, or viewing nude images on smartphones and tablets. Both companies …CYBERINSIDER.COM
10 JunNSO Group Hacking WhatsApp Despite Court OrderWhatsApp has caught the NSO Group phishing its users, in violation of a court order.SCHNEIER.COM
10 JunAfter AI Reaches Production: 12 Ways Security Teams Can Take ControlSecurity teams need more than visibility into AI applications, they need a repeatable framework for monitoring, investigating, and defending them in production. The post After AI Reaches Production: 12 Ways Security Teams Can Take Control appeared first on SecurityWeek .SECURITYWEEK.COM
10 JunBuilding reusable workflows with custom agents in Copilot CLIDevelopers spend much of their working time in the terminal, generating commands, debugging issues, and running scripts close to their systems. Repeated terminal work tends to pile up small steps such as re-running the same commands, re-explaining context, and translating logs in…HELPNETSECURITY.COM
10 JunCritical HVAC and UPS Vulnerabilities Could Let Hackers Disrupt Data CentersClaroty researchers have analyzed the security of Vertiv UPS network cards and the Trane Tracer SC+ HVAC controller. The post Critical HVAC and UPS Vulnerabilities Could Let Hackers Disrupt Data Centers appeared first on SecurityWeek .SECURITYWEEK.COM
10 JunCISO Forum Webinar Today: 2026 Mid-Year ReviewLearn more about protecting against unmonitored use of generative AI (Shadow AI) in business units and building and enforcing AI governance frameworks. The post CISO Forum Webinar Today: 2026 Mid-Year Review appeared first on SecurityWeek .SECURITYWEEK.COM
10 JunNew Browser-in-the-Browser phishing uses fake login popups to steal Microsoft 365 credentialsA new Browser-in-the-Browser (BitB) phishing campaign is targeting Microsoft 365 users with fake login popups designed to closely mimic legitimate browser authentication windows, according to Palo Alto Networks Unit 42. The attack relies on a fake browser window embedded within a…HELPNETSECURITY.COM
10 JunCyera Raises $600 Million at $12 Billion ValuationCyera is positioned as one of the most valuable privately held cybersecurity firms in the world with total funding topping $2 billion. The post Cyera Raises $600 Million at $12 Billion Valuation appeared first on SecurityWeek .SECURITYWEEK.COM
10 JunDrata brings visibility, control and auditability to enterprise AI agentsDrata has introduced AI Agent Governance, a new security category focused on managing the risks and oversight requirements of AI agents, while extending its trust platform to support enterprise adoption of autonomous AI systems. While McKinsey finds 57% of business leaders cite g…HELPNETSECURITY.COM
10 JunNew Intel 471 assessment helps organizations measure CTI program maturityIntel 471 has announced its new Cyber Threat Intelligence (CTI) Maturity Pulse Check, a free, lightweight self-assessment for practitioners based on the Cyber Threat Intelligence Capability Maturity Model (CTI-CMM v1.3). The CTI Maturity Pulse Check offers a quick, structured way…HELPNETSECURITY.COM
10 JunCompanies are failing to keep up with AI’s identity sprawl, creating entry points for hackersThree-quarters of organizations say they aren’t fully overseeing the activities of user accounts belonging to agents and other AI tools.CYBERSECURITYDIVE.COM
10 JunFake Software Tutorials on TikTok Spread Vidar StealerThreat actors push fake free-software tutorials on TikTok and Instagram to spread Vidar stealerINFOSECURITY-MAGAZINE.COM
10 JunChina-linked JDY botnet expands targeting of U.S. military networksThe JDY botnet, a malware network previously associated with Chinese threat actors like Volt Typhoon, has significantly expanded its targeting scope and reconnaissance efforts. [...]BLEEPINGCOMPUTER.COM
10 JunChina-Linked JDY Botnet Expands to 1,500+ Devices for Cyber ReconnaissanceCybersecurity researchers have warned of a "resurgence and expansion" of JDY, a covert network associated with China-nexus state-sponsored threat actors. "The JDY botnet comprises over 1,500 SOHO [small office and home office] and IoT devices and operates as a centrally controlle…THEHACKERNEWS.COM
10 JunNorth Koreans behind nearly half of US tech industry hacks, says CrowdStrikeNorth Koreans hackers posing as remote IT workers and recruiters remain a major threat to U.S., European, and Asian companies, accounting for about half of all attacks over the past 12 months.TECHCRUNCH.COM
10 JunOpenAI: ‘Likely’ Chinese influence operation tried to use ChatGPT to stir debate on data centersThe company says there’s little evidence it influenced any real policy discussion. The post OpenAI: ‘Likely’ Chinese influence operation tried to use ChatGPT to stir debate on data centers appeared first on CyberScoop .CYBERSCOOP.COM
10 JunMaking the Business Case for Your CTI BudgetThe 2026 SANS Cyber Threat Intelligence Survey confirms that CTI is considered essential at the executive level. Can your CISO see how the CTI program is shaping decisions and measurably reducing risk?INTEL471.COM
9 JunISC Stormcast For Tuesday, June 9th, 2026 https://isc.sans.edu/podcastdetail/9964, (Tue, Jun 9th)(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.ISC.SANS.EDU
9 JunThe security questions around Chinese AI coding models in U.S. softwareSoftware developers across the United States are using AI models built in China to write, debug, and review code, drawn by prices below those of American alternatives. These models carry risks for the security of American software, according to a report from Booz Allen Hamilton, …HELPNETSECURITY.COM
9 JunApple expands what parents can block, approve, and limitApple has previewed a set of new child safety features coming to iPhone, iPad, and the Mac later this year, expanding parental controls with tools that help families manage app access, web browsing, communication, and screen time. The features will arrive with updates to iOS 27, …HELPNETSECURITY.COM
9 JunApple Intelligence expands to Google infrastructure with privacy safeguardsApple has announced an expansion of its Private Cloud Compute (PCC) platform, extending the privacy-focused infrastructure behind Apple Intelligence beyond the company's own data centers for the first time. The move will allow certain AI workloads to run on Google Cloud systems p…CYBERINSIDER.COM
9 JunOver 100 NPM, PyPI Packages Hit in New Shai-Hulud Supply Chain AttacksThe most recent variants of the self-propagating attacks are named Miasma and Hades. The post Over 100 NPM, PyPI Packages Hit in New Shai-Hulud Supply Chain Attacks appeared first on SecurityWeek .SECURITYWEEK.COM
9 JunFiligran launches XTM One to automate CTEM with AI agentsFiligran has announced XTM One, an AI-native agentic layer that automates Continuous Threat Exposure Management (CTEM) workflows across the Filigran XTM Platform. XTM One introduces a dedicated AI orchestration layer that connects OpenCTI and OpenAEV into a single, continuous wor…HELPNETSECURITY.COM
9 JunRockwell Automation adds AI-powered security tools to SecureOT SuiteRockwell Automation has announced the launch of three enhanced offerings within the SecureOT solution suite: OT Cybersecurity Assessment Suite, SecureOT Platform Managed Services and Managed Secure Remote Access (MSRA). Facing an increasing volume of alerts and limited visibility…HELPNETSECURITY.COM
9 JunGPS As a Key Distribution PlatformThis is interesting: The U.S. military has likely been quietly broadcasting codes for its global encryption network using public GPS for nearly 20 years, turning each satellite into a hidden “numbers station,” according to Steven Murdoch… That means every device…SCHNEIER.COM
9 JunIT sector faces growing threats from IP-hungry China, AI-enabled cybercriminalsBusinesses also need to watch out for North Korean remote IT worker schemes, according to a new CrowdStrike report.CYBERSECURITYDIVE.COM
9 JunAnthropic’s new model is Mythos on a leashClaude Fable 5 offers Mythos-level performance for most tasks with safeguards on sensitive topics. Anthropic claims testing found no universal jailbreaks. Whether that actually holds up in practice is harder to predict. The post Anthropic’s new model is Mythos on a leash ap…CYBERSCOOP.COM
9 JunAnthropic Launches Claude Fable 5: Mythos-Class AI With Cybersecurity GuardrailsThe AI giant also announced that Project Glasswing partners are being given access to the upgraded Mythos 5. The post Anthropic Launches Claude Fable 5: Mythos-Class AI With Cybersecurity Guardrails appeared first on SecurityWeek .SECURITYWEEK.COM
9 JunAdobe Patches 123 VulnerabilitiesNearly half of the security holes, most allowing arbitrary code execution, have been fixed in Adobe’s Experience Manager product. The post Adobe Patches 123 Vulnerabilities appeared first on SecurityWeek .SECURITYWEEK.COM
9 JunWhy Teams Disable MFAHigh-profile social media accounts reportedly lacked MFA protection despite being obvious targets. The speakers argue that shared team access may be one reason why. Many authentication systems are designed around a single user, but modern organizations often have marketing teams,…YOUTUBE.COM
9 JunReconstructing AI activity in investigationsLearn how to investigate AI activity in Microsoft 365 Copilot and Azure AI services using a structured, telemetry-driven approach. This playbook helps security teams reconstruct events, assess data exposure, and detect potential threats faster. The post Reconstructing AI activity…MICROSOFT.COM
9 JunGeinbot, SolarWinds, Brave, UNK_Deaddrop, durabletask, Insta, Aaran Leyland - SWN #588Geinbot, SolarWinds, Brave, UNK_Deaddrop, durabletask, Insta, Aaran Leyland, and More on the Security Weekly News. Visit https://www.securityweekly.com/swn for all the latest episodes! Show Notes: https://securityweekly.com/swn-588YOUTUBE.COM
9 JunThe Free AI Era EndsMore than a billion people are using AI platforms, and most aren’t paying for them. The original business model assumed free users would eventually convert into paid subscribers, but adoption hasn’t fully translated into revenue. Large AI systems consume enormous amounts of compu…YOUTUBE.COM
9 JunBlinding the Watchmen: Abusing Cloud Logging Services for Defense Evasion and VisibilityUnit 42 research examines attack scenarios targeting cloud logging services. Learn how to defend against log manipulation and defense evasion. The post Blinding the Watchmen: Abusing Cloud Logging Services for Defense Evasion and Visibility appeared first on Unit 42 .UNIT42.PALOALTONETWORKS.COM
8 JunISC Stormcast For Monday, June 8th, 2026 https://isc.sans.edu/podcastdetail/9962, (Mon, Jun 8th)(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.ISC.SANS.EDU
8 JunGitHub Copilot app launches as desktop home for AI coding agentsGitHub introduced the Copilot app, a desktop application built for working with AI coding agents, at Microsoft Build 2026. The release expands GitHub’s Copilot product line beyond editor integrations and command-line tools into a dedicated workspace for directing several ag…HELPNETSECURITY.COM
8 Jun52% of direct-to-IP threats are missing from intelligence feedsSecurity tools are good at inspecting websites, domains, URLs, and files, so attackers are moving lower in the stack and communicating directly with IP addresses, where visibility is limited. According to Palo Alto Networks’ report, this creates a visibility gap that allows…HELPNETSECURITY.COM
8 JunOpenAI Rolling Out ChatGPT Account Security ControlsThe Active Sessions and Lockdown Mode features are being made more broadly available by the AI giant. The post OpenAI Rolling Out ChatGPT Account Security Controls appeared first on SecurityWeek .SECURITYWEEK.COM
8 JunSamsung just made Galaxy phones more secure in One UI 9 betaSamsung’s One UI 9 beta integrates Lockdown mode into the power menu. This is the screen that contains Power off, Restart, and emergency options. Opening it initiates Lockdown mode, disabling biometric authentication. “We tried it out on the Galaxy S26 Ultra running on One …HELPNETSECURITY.COM
8 JunVerdantBamboo Deploys BSD Variant of BRICKSTORM on Linux AppliancesA China-nexus cyber espionage group has been observed deploying a BSD variant of a known backdoor called BRICKSTORM, as well as two other malware families codenamed PLENET (aka GRIMBOLT) and AGENTPSD to target Linux systems. The activity has been attributed by Volexity to a threa…THEHACKERNEWS.COM
8 JunAnthropic’s Project Glasswing UpdateIn April, Anthropic initated Project Glasswing . The idea was to let companies use their new model to find and fix vulnerabilities in their own software. It was a fantastic PR move, and so many press outlets have uncritically parroted Anthropic’s claims that it’s now …SCHNEIER.COM
8 Jun1Password to add YubiKey PIN support to address reported security gap1Password has announced plans to add support for PIN-protected YubiKeys in its desktop applications after a customer identified a limitation that prevented certain hardware security key configurations from working. The company says the feature will arrive in an upcoming beta rele…CYBERINSIDER.COM
8 JunWhatsApp says it caught NSO attempting to spy on users againWhatsApp says it has disrupted new social engineering campaigns linked to Israeli spyware maker NSO Group and is now asking a US federal court to hold the company in contempt for violating a permanent injunction that barred it from targeting its users. The company also published …CYBERINSIDER.COM
8 JunCybersecurity M&A Roundup: 26 Deals Announced in May 2026Significant cybersecurity M&A deals announced by Akamai, Check Point, Cisco, Cyera, Dragos, WatchGuard and Zscaler. The post Cybersecurity M&A Roundup: 26 Deals Announced in May 2026 appeared first on SecurityWeek .SECURITYWEEK.COM
8 JunWhatsApp Catches Spyware Firm NSO Defying No-Hacking Court OrderThe Meta-owned communications app is filing a federal court contempt order against NSO. The post WhatsApp Catches Spyware Firm NSO Defying No-Hacking Court Order appeared first on SecurityWeek .SECURITYWEEK.COM
8 JunThe SIEM Problem Nobody SolvedSIEM correlation has been a core promise in cybersecurity for years, but building reliable correlations across multiple detections is still extremely difficult. Different organizations use different security stacks, which means correlation rules rarely translate cleanly between e…YOUTUBE.COM
8 JunNorth Korean Hackers Use Fake Coding Tasks to Steal CryptoNorth Korean actor UNK_DeadDrop targeted developers with fake coding tasks to steal cryptoINFOSECURITY-MAGAZINE.COM
8 JunCyber insurance policyholders facing heavier scrutiny in underwriting, claimsA multiyear lull in insurance rates and insurers’ over-dependence on large U.S. policyholders have led to more restrictions and exclusions in coverage.CYBERSECURITYDIVE.COM
8 JunCompanies aren’t prepared for how AI is accelerating impersonation attacksBusinesses generally aren’t taking a proactive enough approach to blocking schemes that spoof their leaders’ identities, according to a new report.CYBERSECURITYDIVE.COM
8 JunEverybody Is Vibe Coding But Nobody Told the Security TeamAI-driven development is not something organizations can or should block. But it must be governed. The post Everybody Is Vibe Coding But Nobody Told the Security Team appeared first on SecurityWeek .SECURITYWEEK.COM
8 JunCritical Infrastructure: The Risk Hiding in Plain Sight - Jason Manar - CSP #225In this episode, former FBI cyber leader Jason Manar joins us to unpack the state of critical infrastructure security and why small and medium-sized businesses are more connected to it than they realize. From power, telecom, healthcare, finance, and supply chains, Jason explains …YOUTUBE.COM
8 JunFake X-VPN installer deploys STX RAT malware on unsuspecting usersAn active malware distribution campaign employs a fake X-VPN installer to deploy the STX RAT in memory and steal credentials from victims. The campaign was documented by Cyderes threat researchers, who say the operation remained active after earlier disclosures, with the perpetra…CYBERINSIDER.COM
8 JunMeta accuses NSO Group of defying spyware injunction, files contempt of court complaintThe company said it spotted a spearphishing campaign linked to the Israeli spyware maker targeting WhatsApp users, despite a court order prohibiting it. The post Meta accuses NSO Group of defying spyware injunction, files contempt of court complaint appeared first on CyberScoop .CYBERSCOOP.COM
8 JunA Security Raises $37 Million for Autonomous Offensive Security PlatformThe company founded by Yossi Torati, Omer Gull, and Yuval Itzchakov has emerged from stealth mode. The post A Security Raises $37 Million for Autonomous Offensive Security Platform appeared first on SecurityWeek .SECURITYWEEK.COM
8 JunMeta claims NSO Group still targets WhatsApp users despite court orderMeta claims it disrupted spear-phishing attempts linked to NSO Group and is asking a US federal court to hold the spyware vendor in contempt for allegedly violating an injunction that bars it from targeting WhatsApp and its users. “We successfully disrupted NSO-linked social engi…HELPNETSECURITY.COM
8 JunAI brands as bait: How threat actors are using the AI hype in social engineeringAs threat actors operationalize AI to accelerate attacks, they are also leveraging the wider global interest around AI itself as a social engineering lure. The post AI brands as bait: How threat actors are using the AI hype in social engineering appeared first on Microsoft Securi…MICROSOFT.COM
8 JunWhen “Hi, This Is IT” Comes Through Microsoft TeamsAttackers are increasingly targeting collaboration platforms like Microsoft Teams. Learn the risks and key steps to strengthen your organization's security. The post When “Hi, This Is IT” Comes Through Microsoft Teams appeared first on Unit 42 .UNIT42.PALOALTONETWORKS.COM
7 JunSpoofing ships, jamming drones: how GPS manipulation confuses and compromises.GPS constellations have become foundational in modern society supporting everything from navigation to financial services, making the impacts of GPS disruptions all the more concerning. As reliance on these systems have grown, so too have efforts by threat actors to disrupt them …THECYBERWIRE.COM
6 JunYou've been muted...permanently.Ismael Valenzuela, Arctic Wolf’s VP of Labs, Threat Research and Intelligence, discusses their work on "BlueNoroff Uses ClickFix, Fileless PowerShell, and AI-Generated Fake Zoom Meetings to Target Web3 Sector." Arctic Wolf researchers uncovered a sophisticated campaign by Nor…THECYBERWIRE.COM
6 JunOpal Security Raises $23 Million for AI-Native Identity GovernanceRaising $59 million to date, Opal also announced five senior leadership appointments. The post Opal Security Raises $23 Million for AI-Native Identity Governance appeared first on SecurityWeek .SECURITYWEEK.COM
6 JunBanks Want Blockchain Without CryptoLarge banks are exploring “tokenized deposits” as a way to modernize banking infrastructure without converting customer funds into cryptocurrency. Instead of placing money directly on-chain, the blockchain can act as a record layer that references deposits still held inside the c…YOUTUBE.COM
5 JunThe Evil MSI Background is Back!, (Fri, Jun 5th)A few months ago, I wrote a diary about a payload that was embedded into a JPEG picture. It was a MSI-branded background[ 1 ]. Yesterday, I spotted another one! It seems that the technic is getting more and more popular. This time, it started with a mail containing…ISC.SANS.EDU
5 JunISC Stormcast For Friday, June 5th, 2026 https://isc.sans.edu/podcastdetail/9960, (Fri, Jun 5th)(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.ISC.SANS.EDU
5 JunFive Eyes: Chinese Spies Target Government, Military Staff With Fake Job OpportunitiesPosing as recruiters on online platforms, Chinese intelligence officers target personnel with access to classified or privileged information. The post Five Eyes: Chinese Spies Target Government, Military Staff With Fake Job Opportunities appeared first on SecurityWeek .SECURITYWEEK.COM
5 JunPhotos: Infosecurity Europe 2026Infosecurity Europe 2026 is a cybersecurity event that took place from June 2 to 4 in London. Help Net Security was on-site and here’s a closer look at the conference. The featured vendors are: Microsoft, JupiterOne, Menlo Security, Cato Networks, Falkin, Vivida, Pen Test P…HELPNETSECURITY.COM
5 JunAI agent governance gets harder when agents outnumber your peopleIn this Help Net Security video, Amit Gautam, CTO at Abluva, explains the security risks that autonomous AI agents bring into enterprise environments. He opens with a real case: a reconciliation agent at a financial services firm had legitimate access to a customer database. A po…HELPNETSECURITY.COM
5 JunMost pros have seen AI hallucinations in IT operationsAutonomous AI is taking action inside enterprise IT environments. Software is restarting services, isolating risky devices, and applying patches without waiting for a human to approve the step. The capability is spreading at the same time IT professionals are reporting frequent e…HELPNETSECURITY.COM
5 JunLet’s Encrypt works toward post-quantum certificates at web scaleLet’s Encrypt plans to pursue a post-quantum-safe Web PKI through Merkle Tree Certificates (MTCs), a new approach that adds post-quantum authentication to the web without sacrificing the speed and reliability that have made TLS universal. The project is targeting late 2026 for a …HELPNETSECURITY.COM
5 JunAI WormResearchers have prototyped an AI-powered internet worm . The coolest thing about the prototype is that it carries its own LLM with it, and runs it on computers that have been broken into. This is the closest to John Brunner’s original 1975 conception of a computer worm tha…SCHNEIER.COM
5 JunNew Threat Cluster OP-512 Targets Microsoft IIS Servers with Custom Web Shell FrameworkCybersecurity researchers have discovered a previously unreported threat cluster dubbed OP-512 that has been observed targeting Microsoft Internet Information Services (IIS) servers to deploy a bespoke web shell framework. ReliaQuest has assessed with moderate to high confidence …THEHACKERNEWS.COM
5 JunAdaptive, Agentic AI Worms Loom as Next Enterprise ThreatAI worms, or "viruses with wings and brains," adapt to new environments, seek out vulnerabilities, and will likely strike within a year, researchers say.DARKREADING.COM
5 JunSecuring CI/CD in an agentic world: Claude Code Github action caseMicrosoft Threat Intelligence identified a prompt injection pathway in Claude Code GitHub Action that allowed access to workflow secrets under specific conditions. This research examines the attack chain, responsible disclosure process, Anthropic's mitigation, and guidance for se…MICROSOFT.COM
5 JunIronWorm and New Miasma Worm Variant Hit npm in Supply Chain AttacksMultiple software supply chain attacks have hit the npm ecosystem, with threat actors using both malicious and poisoned versions of over 50 legitimate packages to distribute a Rust-based information stealer and a self-spreading worm, respectively. According to JFrog, the informat…THEHACKERNEWS.COM
4 JunISC Stormcast For Thursday, June 4th, 2026 https://isc.sans.edu/podcastdetail/9958, (Thu, Jun 4th)(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.ISC.SANS.EDU
4 JunThe modern-day business can learn a lot about risk from this year’s mega eventsEvery year brings its share of global events, but 2026 is proving to be a banner year for mega-scale entertainment. The year got off to a roaring start with the Winter Olympics, and now anticipation is building for the fast-approaching FIFA World Cup. But amid the buzz, have you …HELPNETSECURITY.COM
4 JunAttackers already know the secrets are on your developers’ machines. Do you?In a recent GitGuardian analysis, an average of 150 secrets were found on a sample of developer endpoints. Private keys accounted for 38% of unique secrets, while cloud, identity provider, and secret management credentials (AWS IAM, Hashicorp vault) added another 22%. Those figur…HELPNETSECURITY.COM
4 JunProduct showcase: Trend Micro Mobile Security detects scams in messages, QR codes, and websitesTrend Micro Mobile Security for iOS protects devices from potentially harmful websites while browsing, blocks ads and personal information trackers, helps users avoid unsafe Wi-Fi networks, and monitors data usage. The app is available for both iOS and Android devices. Getting St…HELPNETSECURITY.COM
4 JunETSI sets security requirements for AI data centers and cloud platformsETSI has published TS 104 033, a technical specification that defines security requirements for AI computing platforms. The specification establishes a security framework for platforms used to host AI applications in data center and edge computing environments, covering security …HELPNETSECURITY.COM
4 JunHackers Spied on a Stock Exchange Executive's Outlook Mailbox for Five MonthsUnknown attackers spent at least five months inside the Outlook mailbox of a senior executive at a major global stock exchange, copying the inbox out in small, repeated batches and routing it through Dropbox and OneDrive so the traffic blended into normal cloud activity. Symantec…THEHACKERNEWS.COM
4 JunHacking Meta’s AI ChatbotHackers are convincing Meta’s AI support chatbot to let them take over other peoples’ accounts: A video posted on X showed the step-by-step process to hack someone’s Instagram account. The hacker allegedly used a VPN to spoof the targets’ presumed location…SCHNEIER.COM
4 JunChinese Cybercrime Group in Spotlight for Record Campaign PaceRelying on social engineering, the hacking group engages in credential phishing, malware distribution, and fraud activities. The post Chinese Cybercrime Group in Spotlight for Record Campaign Pace appeared first on SecurityWeek .SECURITYWEEK.COM
4 JunOAuth marketplace apps keep access after publishers vanishInstalling an app from the Google Workspace Marketplace or GitHub Marketplace can grant a third party access to company email, files, calendars, code repositories, CI workflows, organization settings, and secrets. Marketplace presence gives these apps the appearance of approval. …HELPNETSECURITY.COM
4 JunGemini Voice Assistant Hijacked via Messaging NotificationsAttackers could have triggered dangerous actions, including controlling smart home devices via Google Home and starting Zoom video calls. The post Gemini Voice Assistant Hijacked via Messaging Notifications appeared first on SecurityWeek .SECURITYWEEK.COM
4 JunInside the race to adapt to an AI-powered security worldAI is breaking things faster than anyone can fix them. Security leaders across the industry are racing to figure out what comes next. The post Inside the race to adapt to an AI-powered security world appeared first on CyberScoop .CYBERSCOOP.COM
4 JunWebinar Today: Third-Party Risk in Practice – Where Programs Break Down and How to RespondJoin this live webinar as we examine the gap between how organizations think their third-party risk programs are performing and what’s actually happening in practice. The post Webinar Today: Third-Party Risk in Practice – Where Programs Break Down and How to Respond appeare…SECURITYWEEK.COM
4 JunWillow Raises $7 Million for Securing Autonomous AI AgentsWillow (formerly Webrix) emerged from stealth mode with an access platform designed to secure enterprise AI agents. The post Willow Raises $7 Million for Securing Autonomous AI Agents appeared first on SecurityWeek .SECURITYWEEK.COM
4 JunOffroad Emerges From Stealth With $7 Million to Tackle Enterprise Identity RiskAs AI agents, machine identities, and third-party applications multiply across enterprises, Offroad is betting autonomous security agents can restore control over an increasingly unmanageable identity landscape. The post Offroad Emerges From Stealth With $7 Million to Tackle Ente…SECURITYWEEK.COM
4 JunProton Drive adopts OpenPGP encryption, delivers 300% faster uploadsProton has announced a major cryptographic upgrade for Proton Drive that significantly improves the performance of its end-to-end encrypted cloud storage platform. The update makes encrypted file uploads up to 4x faster, while a broader overhaul of Drive's underlying architecture…CYBERINSIDER.COM
4 JunYour AI agent could become your biggest insider threatNew research details how the increasing integration of AI agents into businesses is making it easier than ever for insiders - malicious or otherwise - to put sensitive data at risk. The post Your AI agent could become your biggest insider threat appeared first on CyberScoop .CYBERSCOOP.COM
4 JunBrave launches minimalist Origin browser with only core privacy featuresBrave has officially launched Brave Origin, a new premium version of its browser designed for users who want Brave's privacy protections without the company's growing collection of integrated features. The release follows several months of testing in Nightly builds and arrives as…CYBERINSIDER.COM
4 JunUpdating the taxonomy of failure modes in agentic AI systems: What a year of red teaming taught usA surge in real-world attacks against agentic AI systems is reshaping how we think about risk. Based on 12 months of red teaming, this update introduces seven new failure modes, from supply chain compromise to goal hijacking, and the practical mitigations teams need now. The post…MICROSOFT.COM
4 JunChip Sanctions BackfireThe discussion centers on how semiconductor export restrictions may delay technological progress temporarily while simultaneously encouraging large-scale domestic investment in alternative chip ecosystems. Supply-chain restrictions can create second-order effects that extend beyo…YOUTUBE.COM
3 JunISC Stormcast For Wednesday, June 3rd, 2026 https://isc.sans.edu/podcastdetail/9956, (Wed, Jun 3rd)(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.ISC.SANS.EDU
3 JunAgent Threat Rules: Open detection rule format for AI agent security threatsAI agents run inside coding assistants, MCP servers, and multi-agent frameworks, and the access that makes them useful also opens paths to prompt injection, tool poisoning, and credential theft. Public CVE feeds carry agent-execution flaws that reach production faster than the to…HELPNETSECURITY.COM
3 JunWhat CISOs need to do about post-quantum migration in the next 24 monthsIn this Help Net Security video, Garfield Jones, SVP Global Strategy and Research, QuSecure, lays out what CISOs should do over the next 24 months. A recent Google paper moved the expected arrival of a cryptographically relevant quantum computer from 2035 to 2029, leaving organiz…HELPNETSECURITY.COM
3 JunNetskope adds AI asset discovery and AISecOps agent to AI security portfolioNetskope has announced Netskope One AI Command Center, bringing together AI discovery, risk intelligence, and autonomous response capabilities in a single platform. As the latest expansion of the Netskope One AI Security suite, it helps security teams understand what AI is runnin…HELPNETSECURITY.COM
3 JunCritical Start expands MDR capabilities with multi-agent AI systemCritical Start has released SOC AI, a production-proven multi-agent framework powering its AI-led Managed Detection and Response (MDR). SOC AI coordinates ten specialized agents across the full alert investigation and response lifecycle, covering detection, triage, response, thre…HELPNETSECURITY.COM
3 JunInfosecurity Europe: Execs Must Treat Cyber Threats as Statecraft, ISACA Expert SayPrivate firms are being targeted by nation-state groups for reasons beyond finance, argued ISACA’s Bharat ThakrarINFOSECURITY-MAGAZINE.COM
3 JunMicrosoft Scout agent opens a new category of always-on AutopilotsWorkplace AI assistants have mostly waited for a prompt before doing anything. A user asks, the tool answers, and the exchange ends there. Microsoft is putting a different kind of agent inside its Office applications, one designed to keep operating in the background once a person…HELPNETSECURITY.COM
3 JunGlobal Stock Exchange Hit by Monthslong Email CampaignA threat actor got a near-continuous view into an influential finance executive's email inbox, thanks to clever use of legitimate, native Windows tools.DARKREADING.COM
3 JunAI Used to Decrypt Medieval CiphersResearchers are using machine learning algorithms to decrypt historical pencil-and-paper ciphers.SCHNEIER.COM
3 JunOnly 11% of production agents pass the AI agent security barEnterprise teams are running AI agents that write code, drive browsers, answer customer calls, manage cloud infrastructure, and query data warehouses with standing credentials. A new independent assessment of 100 production agents finds that nearly all of them carry the condition…HELPNETSECURITY.COM
3 JunMalware campaign targeting Minecraft users infects over 116,000 systemsA Malware-as-a-Service (MaaS) operation named WeedHack is targeting Minecraft users and allows threat actors to gain remote access to victims’ screens, webcams, and files through a web-based dashboard, McAfee researchers found. Minecraft, developed by Mojang Studios and rel…HELPNETSECURITY.COM
3 JunImpersonation, Click Hijacking, and TDS: Inside a Malware Distribution EcosystemResearch by: Alexey Bukhteyev Key Takeaways Introduction When we search Google for a popular piece of software, we usually click the first result, sometimes without even looking at the rest, because official project sites tend to rank highest and appear near the top of the r…RESEARCH.CHECKPOINT.COM
3 JunThe $10M Exit DisappearedThis clip argues that the traditional founder exit may be changing. In the past, reaching a certain level of revenue could create a meaningful acquisition opportunity. For many entrepreneurs, selling the company was the expected next step. If valuations, ownership dilution, or ma…YOUTUBE.COM
3 Jun‘Don’t panic’: AI reality checks dominate major cybersecurity conferenceCISOs and their colleagues should focus on network security basics, not AI vendors’ overhyped promises, analysts said at an annual Gartner cybersecurity event.CYBERSECURITYDIVE.COM
3 JunHow attackers are gaining access to LLM inferenceThreat actors are wiring live LLM APIs into malware to generate malicious logic at runtime, and this research maps the five routes they use to access AI models for free. The post How attackers are gaining access to LLM inference appeared first on Intezer .INTEZER.COM
3 JunCoralogix Raises $200M at $1.6B Valuation to Scale AI Observability PlatformCoralogix offers a full-stack observability platform that unifies logs, metrics, traces, security, and AI observability. The post Coralogix Raises $200M at $1.6B Valuation to Scale AI Observability Platform appeared first on SecurityWeek .SECURITYWEEK.COM
3 JunThe Cybersecurity Stock SplitBoth the Security Weekly Index and the NASDAQ reached record highs. On the surface, the story looks simple: cybersecurity stocks are doing well. But a closer look at long-public companies reveals significant differences in performance. Market averages can hide large gaps between …YOUTUBE.COM
3 JunEuropean authorities crack down on illegal streaming networksOfficials said they dismantled nine organized crime groups and removed more than 27,000 URLs hosting live sports and other copyrighted media during a seven-month operation. The post European authorities crack down on illegal streaming networks appeared first on CyberScoop .CYBERSCOOP.COM
3 JunTropical Blend: Cyber & Politics Ramp Up Across Latin AmericaChina-linked espionage groups have attacked at least a dozen nations in the region, gathering information on maritime shipping, oil production, and other geopolitical interests.DARKREADING.COM
2 JunFrom API key to live threat detections in minutes: how Elastic Security ingests Google Threat IntelligenceFind out how Elastic Security ingests Google Threat Intelligence for continuous detection and uses AI-driven workflows to enrich alerts in real time, from API key to live detections in minutes.ELASTIC.CO
2 JunISC Stormcast For Tuesday, June 2nd, 2026 https://isc.sans.edu/podcastdetail/9954, (Tue, Jun 2nd)(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.ISC.SANS.EDU
2 JunThis AI model backdoor attack stays hidden until you customize the modelMost teams that deploy AI start with a backbone model. They download a large pre-trained system, adapt it to a specific task, and put it into production. The download step carries a security question: the origin of the model. A research team built an attack called BadBone. It pla…HELPNETSECURITY.COM
2 JunCybersecurity jobs available right now: June 2, 2026Agentic Safety and Ecosystem Architect, Trust and Safety Google | USA | On-site – View job details As an Agentic Safety and Ecosystem Architect, Trust and Safety, you will define safety controls and permission models for autonomous agents on Android, helping ensur…HELPNETSECURITY.COM
2 JunZero trust physical security needs trust decisions at the edgeIn this interview with Help Net Security, Chuck Davis, VP, Global Information Security at Hikvision, explains how zero trust applies to physical security systems like cameras and door controllers. He breaks down how to make trust decisions at the edge without recreating old perim…HELPNETSECURITY.COM
2 JunRSA extends passwordless authentication to Linux environmentsRSA has expanded its passwordless authentication capabilities to Linux environments, advancing its goal of delivering secure, password-free access for every user in every environment. Linux is ubiquitous in enterprise infrastructure, powering servers, developer workstations, and …HELPNETSECURITY.COM
2 JunNew Wave Of Phishing Emails with SVG Files, (Tue, Jun 2nd)For a few days, my SANS ISC mailbox is flooded with emails that delivers SVG files. An SVG ("Scalable Vector Graphic") is a web-friendly vector file format used for graphics and icons. No URL in the body, just “an imageâ€, that's the perf…ISC.SANS.EDU
2 JunOracle’s First Monthly Patches Resolve 77 VulnerabilitiesOracle’s monthly Critical Security Patch Update (CSPU) rollouts are meant to deliver critical fixes faster. The post Oracle’s First Monthly Patches Resolve 77 Vulnerabilities appeared first on SecurityWeek .SECURITYWEEK.COM
2 JunInfosecurity Europe: Business Leaders Lack Understanding of Threat Intelligence, Study WarnsA new Silobreaker and SANS Institute paper examines the ‘Intelligence-Stakeholder Gap’ and what organizations must do to achieve business buy-in on threat intelligenceINFOSECURITY-MAGAZINE.COM
2 JunKDE Linux security audit cuts kernel modules and unused packagesKDE Linux, the in-progress operating system from the KDE community, removed several kernel modules and software packages after a security audit of the components shipped with the system. The work followed the discovery of multiple security issues in the upstream Linux kernel duri…HELPNETSECURITY.COM
2 JunCybanetix unveils Managed AI Service to secure users, models, and agentsCybanetix has announced the launch of its Managed AI Service to address all three aspects of AI use within the enterprise. Covering employee AI usage, AI governance, and embedded AI, the Managed AI Service combines technology from NOMA, SentinelOne, Microsoft, and Exabeam with Cy…HELPNETSECURITY.COM
2 JunOpenAI brings frontier AI to existing AWS environmentsOpenAI frontier models and Codex are now available on AWS, giving customers access to OpenAI capabilities within AWS environments and the controls needed to move more quickly from evaluation to deployment. OpenAI capabilities on Amazon Bedrock These capabilities are available thr…HELPNETSECURITY.COM
2 JunBadHost, Dead CTFs, Exploding NPMs, and the Verizon DBIR - ASW #385We dedicate an episode to catching up on appsec news with Kalyani Pawar. We see parsing problems that led to the BadHost vuln, which exposed lots of LLMs, MCPs, and agents to potential compromise. We wonder where to look for security education and practice as the camaraderie of t…YOUTUBE.COM
2 JunSupply Chain Attack Hits 32 Red Hat NPM PackagesHackers published 96 malicious package versions, injected with a credential-stealing worm similar to Mini Shai-Hulud. The post Supply Chain Attack Hits 32 Red Hat NPM Packages appeared first on SecurityWeek .SECURITYWEEK.COM
2 JunThreat Actor Uses AI to Build EDR Evasion ToolsA threat actor used AI coding tools to build and test EDR evasion malware, Sophos findsINFOSECURITY-MAGAZINE.COM
2 JunOperation FlutterBridge: macOS Malvertising Campaign Spreads New FlutterShell BackdoorOperation FlutterBridge is a malvertising campaign targeting macOS users. It distributed the new backdoor FlutterShell, built using the Flutter framework. The post Operation FlutterBridge: macOS Malvertising Campaign Spreads New FlutterShell Backdoor appeared first on Unit 42 .UNIT42.PALOALTONETWORKS.COM
2 JunMicrosoft Entra pushes passkeys, tightens identity securityMicrosoft has released multiple identity and network access capabilities for Entra, its family of identity and network access products that help organizations implement a zero trust security strategy, over the last 30 days. Features reaching general availability Identity and auth…HELPNETSECURITY.COM
2 JunSophos uncovers AI-powered malware lab built for EDR evasionA threat actor used AI technologies to build a malware-testing framework for developing and refining endpoint detection and response (EDR) evasion techniques, according to Sophos. The investigation began after an anomalous endpoint in a customer environment triggered alerts tied …HELPNETSECURITY.COM
2 JunDiligent automates cyber risk assessments and reportingDiligent has announced Diligent Cyber Risk Management, an agentic solution designed to help organizations manage cybersecurity risk in a business context. Available in summer 2026, the platform reduces cyber risk assessment work from weeks to hours and links cyber threats to stra…HELPNETSECURITY.COM
2 JunLABScon25 Replay | Gamaredon x Turla: Unveiling a 2025 Espionage Alliance Targeting UkraineESET researchers show how Gamaredon facilitated Turla access to Ukrainian targets, revealing rare cooperation between FSB-linked espionage groups.SENTINELONE.COM
2 JunTurning tension into collaboration: How CIOs and CISOs can lead togetherIf properly managed and channeled, age-old friction between IT and cybersecurity can create a more resilient organization.CYBERSECURITYDIVE.COM
2 JunThe Zero-Knowledge Threat Actor and the End of Responsible DisclosureAI can help attackers generate malware, create malicious payloads, bypass simple security checks, and convert vague malicious intent into functional code. The post The Zero-Knowledge Threat Actor and the End of Responsible Disclosure appeared first on SecurityWeek .SECURITYWEEK.COM
2 JunAnthropic Expanding Mythos Access to 150 New OrganizationsOnly approximately 50 companies have had access to Mythos until now and they have found thousands of vulnerabilities in their products. The post Anthropic Expanding Mythos Access to 150 New Organizations appeared first on SecurityWeek .SECURITYWEEK.COM
2 JunAI's Real Security ProblemMany AI security conversations focus on prompt injection attacks. In this clip, Kalyani Pawar and Mike argue that AI may not be creating entirely new security threats. Instead, it often amplifies existing security problems that organizations already struggle with. The bigger conc…YOUTUBE.COM
2 JunAnthropic expanding access to Project GlasswingRoughly 150 new organizations across critical infrastructure sectors will gain access to Claude Mythos Preview, Anthropic's most capable — and most restricted — AI model. The post Anthropic expanding access to Project Glasswing appeared first on CyberScoop .CYBERSCOOP.COM
2 JunWeedHack Minecraft malware campaign infects over 116,000 PCsMcAfee researchers have uncovered a large Malware-as-a-Service (MaaS) operation targeting Minecraft players through trojanized mods, cheats, and game clients. The campaign, dubbed WeedHack, has infected more than 116,000 systems since January 2026 and offers aspiring cybercrimina…CYBERINSIDER.COM
2 JunExclusive: How One Line of Code Put Billions of Microsoft Android App Downloads at RiskA simple development setting bypassed protections designed to prevent unauthorized Android apps from accessing Microsoft account tokens, exposing billions of installations. The post Exclusive: How One Line of Code Put Billions of Microsoft Android App Downloads at Risk appeared f…SECURITYWEEK.COM
2 JunDozens of Red Hat npm packages targeted in supply- chain attackResearchers said a variant of the mini Shai-Hulud is involved in the compromise.CYBERSECURITYDIVE.COM
2 JunMicrosoft Build 2026: Securing code, agents, and models across the development lifecycleDiscover how Microsoft enables fast, secure AI development with MDASH and new security capabilities. The post Microsoft Build 2026: Securing code, agents, and models across the development lifecycle appeared first on Microsoft Security Blog .MICROSOFT.COM
2 JunHeraclitus, AI LLMs, SSO, TTP, NetLogon, PAN-OS, AI Cost, Aaran Leyland - SWN #586Heraclitus Unbound, AI LLMs, SSO, TTP, NetLogon, PAN-OS, AI Cost, Aaran Leyland, and More on the Security Weekly News. Visit https://www.securityweekly.com/swn for all the latest episodes! Show Notes: https://securityweekly.com/swn-586YOUTUBE.COM
1 JunISC Stormcast For Monday, June 1st, 2026 https://isc.sans.edu/podcastdetail/9952, (Mon, Jun 1st)(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.ISC.SANS.EDU
1 JunDNS-AID lets AI agents find and verify each other through DNSAI agents run across many platforms, and each one needs a way to locate and confirm the identity of the others it works with. The Linux Foundation’s DNS-AID project gives them that capability through the Domain Name System, the same address lookup system that has directed i…HELPNETSECURITY.COM
1 JunElection threats are focused on campaign systems, not voting machinesCheck Point said actors are shifting toward campaign systems and AI-generated content, outpacing the public's ability to understand and respond to the risks. The post Election threats are focused on campaign systems, not voting machines appeared first on CyberScoop .CYBERSCOOP.COM
1 JunAttackers Abuse Shared Content for ChatGPT Phishing CampaignPush Security says threat actors are delivering malware hosted on chatgpt.com/s/ domainINFOSECURITY-MAGAZINE.COM
1 JunDragos acquires Phosphorus to secure extended operational technologyDragos has acquired Phosphorus, extending the Dragos Platform to protect billions of connected devices embedded across critical infrastructure and other operational networks. Operational environments have outgrown traditional OT boundaries. Power grids, pipelines, manufacturing f…HELPNETSECURITY.COM
1 JunDragos Acquires xIoT Security Firm PhosphorusDragos said customers will soon gain expanded asset visibility and integrated device intelligence, with automated remediation workflows and a unified platform experience to follow. The post Dragos Acquires xIoT Security Firm Phosphorus appeared first on SecurityWeek .SECURITYWEEK.COM
1 JunSecure Code Warrior connects developer training to AI usage and code risksSecure Code Warrior has introduced Adaptive Learning, a capability designed to help organizations support AI software governance through targeted training based on identified risks. The feature delivers contextual microlearning and tracks outcomes at the code commit level. Softwa…HELPNETSECURITY.COM
1 JunPathSolutions brings on-premises AI troubleshooting to NetOps teamsPathSolutions has announced the launch of TotalView AI, a new capability within its TotalView platform that provides AI-driven troubleshooting for NetOps teams using network data analyzed on-premises. As enterprise networks become more distributed and complex, NetOps teams face i…HELPNETSECURITY.COM
1 JunHyland platform innovations focus on AI governance, context, and agent oversightHyland has unveiled platform innovations designed to move AI from experimentation to enterprise-wide adoption. Powered by the Content Innovation Cloud, these advancements transform governed enterprise content into trusted, actionable intelligence that accelerates business outcome…HELPNETSECURITY.COM
1 JunChina-Aligned Groups Ramp Up Attacks: Dragon Weave Hits Czech Republic & TaiwanA new cyber espionage campaign codenamed Operation Dragon Weave has been observed targeting officials and citizens in the Czech Republic and Taiwan to deliver an AdaptixC2 agent. According to Seqrite Labs, targets of the campaign include government, research, academic, technology…THEHACKERNEWS.COM
1 JunWithout strong governance, companies put credit ratings at risk in AI eraA new report from S&P Global provides a blueprint for how companies can adapt to the changing threat environment.CYBERSECURITYDIVE.COM
1 JunNetQuest expands NetworkLens to detect threats hidden in network management trafficNetQuest announced an expansion of its NetworkLens enriched dataset portfolio. The new network telemetry datasets deliver detailed traffic characteristics of network management transactions, giving security teams the granular, AI-ready intelligence needed to detect threats hidden…HELPNETSECURITY.COM
1 JunMeta tries to get ahead of scammers before the World Cup beginsFootball fans are counting down the days until the FIFA World Cup begins, and scammers are doing the same. Last week, the FBI warned that cybercriminals are spoofing FIFA websites to steal personal information, sell fake tickets, and promote fraudulent hospitality packages ahead …HELPNETSECURITY.COM
1 JunDutch Police Dismantle Massive 17-Million-Device BotnetDutch authorities seized command-and-control servers tied to a botnet of infected computers, smartphones, and tablets that was allegedly used to power a residential proxy network and facilitate cybercrime. The post Dutch Police Dismantle Massive 17-Million-Device Botnet appeared …SECURITYWEEK.COM
1 JunOpenAI requires stronger authentication for users of its most powerful AI modelsYubico announced its significant role in securing the AI frontier as OpenAI mandates the use of passkeys for individuals that are part of their Trusted Access for Cyber (TAC) program. As a leading global AI research and development company, OpenAI is setting a precedent for empow…HELPNETSECURITY.COM
1 JunHumans Could Become Cheaper Than AIAI infrastructure costs, including GPUs and token processing, continue to decrease as the technology matures. At the same time, organizations are dramatically increasing how much AI they consume, shifting many platforms toward usage-based pricing instead of flat monthly subscript…YOUTUBE.COM
31 MayYARA-X 1.17.0 Release, (Sun, May 31st)YARA-X&#;x26;#;39;s 1.17.0 release brings 5 improvements (several performance improvements) and 1 bugfix.
ISC.SANS.EDU
30 MayMalicious npm packages abuse dependency confusion to profile developer environmentsA dependency confusion campaign leveraged 33 malicious npm packages to collect reconnaissance data from developer and build environments. This report details the attack chain, observed tradecraft, and detection opportunities to help organizations identify and disrupt related acti…MICROSOFT.COM
30 MayThe skills pay the bills.Today we are joined by Marco Giuliani, Vice President & Head of Research at ThreatDown, discussing their work on "GachiLoader adopts AI skill lure." Threat actors are now using fake AI agent “skills” as highly convincing social engineering lures, with a new campaign disguising th…THECYBERWIRE.COM
30 MayRussian Spies Are Aggressively Seeking Western Technology as Sanctions Bite, Officials SayMoscow’s agents are building fake companies, recruiting middlemen and deploying cyber spies and hackers who gather information that could be used to attack key infrastructure. The post Russian Spies Are Aggressively Seeking Western Technology as Sanctions Bite, Officials Say appe…SECURITYWEEK.COM
29 MayISC Stormcast For Friday, May 29th, 2026 https://isc.sans.edu/podcastdetail/9950, (Fri, May 29th)(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.ISC.SANS.EDU
29 MayNew infosec products of the month: May 2026Here’s a look at the most interesting products from the past month, featuring releases from Alation, AppOmni, Apricorn, ASAPP, Babel Street, Checksum, Cogent, CTERA, Forward, LastPass, Operant AI, Riverbed, Sysdig, Trust3 AI, TrustCloud, VIAVI, Versa Networks, and XM Cyber. Opera…HELPNETSECURITY.COM
29 MayTyposquatted npm packages used to steal cloud and CI/CD secretsThe Mini Shai-Hulud campaign used malicious npm packages to target cloud and CI/CD credentials across developer environments. This report details the attack chain, detection opportunities, and mitigation guidance to help organizations identify and disrupt related activity. The po…MICROSOFT.COM
29 MayThe behavioral signals that sharpen Trojan malware detectionMalware analysts spend a lot of time deciding which signals from a sandbox run are worth keeping. A sample executed in a controlled environment can generate hundreds of measurable attributes covering file structure, registry edits, process behavior, and network traffic. Most of t…HELPNETSECURITY.COM
29 MayClaroty targets cyber-physical system risks with AI-powered security agentClaroty has launched Claroty Claire, a CPS-native AI security agent designed to help organizations defend mission-critical infrastructure. Claire is powered by a CPS language model trained on more than a decade of industry expertise and CPS-related data. The launch expands organi…HELPNETSECURITY.COM
29 MayMicrosoft 365 Copilot redesign brings context and actions into one workspaceMicrosoft 365 Copilot, an AI assistant that helps people write, summarize, analyze information, and complete work tasks, has been redesigned. It now serves as a single, flexible entry point to Copilot across Microsoft 365 apps, suggesting relevant actions based on the user’…HELPNETSECURITY.COM
29 MayWebsites can spy on user activity by analyzing SSD behaviorWebsites have spent years collecting information about visitors through browser fingerprinting, tracking scripts, and other techniques designed to identify devices and monitor behavior. Researchers have demonstrated another method that relies on something most users would never e…HELPNETSECURITY.COM
29 MayNew FROST attack leverages SSD side-channel to reveal browsing activitySecurity researchers have demonstrated a new browser-based side-channel attack that can monitor user activity by measuring subtle timing variations in SSD access, allowing malicious websites to infer which sites users visit and which applications they launch. The attack, named FR…CYBERINSIDER.COM
29 MayThe Firmware Your PC TrustsMany hardware devices ship with small firmware components called option ROMs that help UEFI initialize hardware during the boot process. These aren’t traditional operating system drivers. They run earlier, inside firmware, and help systems communicate with components like network…YOUTUBE.COM
29 MayA Gartner take on the MDR market in 2026For CISOs navigating the AI era, the question is no longer whether AI will change the SOC. It is whether the current service model is the right vehicle for that change. The post A Gartner take on the MDR market in 2026 appeared first on Intezer .INTEZER.COM
29 MayCybersecurity & Arctic Sovereignty: Protecting Canada's Most Vulnerable Infrastructure Cheryl BiswasHost David Shipley speaks with cybersecurity professional Cheryl Biswas about her journey into the industry and why she believes Arctic sovereignty must be viewed as a cybersecurity challenge as much as a geopolitical one. Biswas traces her path from political science and a help …CYBERSECURITYTODAY.LIBSYN.COM
29 MayDNS-AID will make AI agents easier to discover, says Linux FoundationAs AI agents become more numerous and more communicative, keeping track of where to find them is becoming increasingly important. Numerous proprietary agent registries are on the market, but the Linux Foundation suggests we simply extend the distributed, open Domain Name System (…CSOONLINE.COM
29 MaySignal users targeted by attackers seeking backup recovery keysSignal users are being targeted in a new phishing campaign that attempts to steal recovery keys used to access the platform's encrypted cloud backups. Attackers who obtain these keys could gain access to entire message archives, including older conversations, photos, and document…CYBERINSIDER.COM
29 MayMicrosoft is named a Leader in the 2026 Gartner® Magic Quadrant™ for Endpoint ProtectionMicrosoft is named a Leader in the 2026 Gartner® Magic Quadrant™ for Endpoint Protection. The post Microsoft is named a Leader in the 2026 Gartner® Magic Quadrant™ for Endpoint Protection appeared first on Microsoft Security Blog .MICROSOFT.COM
29 MayChatGPT share links abused to host fake outage pages to deliver malwareThreat actors are abusing ChatGPT's content-sharing feature to display fake OpenAI outage pages that direct users to download malware disguised as the ChatGPT desktop application. [...]BLEEPINGCOMPUTER.COM
29 MayName That Toon: Mark of (Cybersecurity) ProgressAs part of Dark Reading's 20th anniversary package, we asked readers for a cybersecurity-related caption that captures their thoughts about the industry's last two decades.DARKREADING.COM
29 MayFriday Squid Blogging: Another SquidSomeone named “Squid” seems to be a “ West Country legend .” As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered. Blog moderation policy.SCHNEIER.COM
29 MaySidhe, GreyVibe, Claude, Lightwell, Eclipse, Kimsuky, Obscure Beliefs, Josh Marpet - SWN #585Sidhe, GreyVibe, Claude, Lightwell, Eclipse, Kimsuky, Obscure Belief Systems, Josh Marpet, and More on this episode of the Security Weekly News. Visit https://www.securityweekly.com/swn for all the latest episodes! Show Notes: https://securityweekly.com/swn-585YOUTUBE.COM
28 MayISC Stormcast For Thursday, May 28th, 2026 https://isc.sans.edu/podcastdetail/9948, (Thu, May 28th)(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.ISC.SANS.EDU
28 MayNudge Security adds browser-based discovery for shadow AI agentsNudge Security announced that its AI security platform offers discovery of shadow AI agents via the browser, extending its agent discovery capabilities to cover platforms that do not provide a public API for agent identity and inventory. The new browser-based agentic AI discovery…HELPNETSECURITY.COM
28 MayFrontier AI models collapse under multi-turn AI attacks, Cisco findsAttackers who probe large language models rarely give up after one refusal. They reframe, build context across turns, adopt personas, and escalate gradually. New research from Cisco’s AI threat intelligence team finds that the safety benchmarks used across the industry miss…HELPNETSECURITY.COM
28 MayChecksum introduces Continuous Quality Agent for automated test generation and healingChecksum has launched its Continuous Quality Agent, an autonomous system that runs nightly against deployed applications and automatically heals broken tests without waiting for an engineer to open a dashboard or write a prompt. AI coding has changed the constraint in software de…HELPNETSECURITY.COM
28 MayJINX-0164 Targets Cryptocurrency Firms with Fake Recruiter Lures and macOS MalwareA new campaign orchestrated by a previously undocumented threat actor has targeted cryptocurrency organizations with an aim to facilitate digital asset theft using recruitment-themed social engineering and bespoke macOS malware. "These campaigns leveraged sophisticated social eng…THEHACKERNEWS.COM
28 MayA single typo could derail your World Cup plansCybercriminals are spoofing Fédération Internationale de Football Association (FIFA) websites ahead of the 2026 FIFA World Cup, the FBI warns. The attackers are registering lookalike domains with small spelling changes or different domain endings to impersonate FIFA websites and …HELPNETSECURITY.COM
28 MayNew Threat Actor Jinx-0164 Targets Crypto Developers on macOSNew actor Jinx-0164 hit crypto developers with fake recruiter lures and macOS malwareINFOSECURITY-MAGAZINE.COM
28 MayNew Edamame Platform Aims to Catch AI Coding Agents Going Off the RailsFrance-based startup Edamame says its runtime verification platform uses host telemetry and AI analysis to detect coding-agent “intent drift,” secret theft and supply-chain attacks in real time. The post New Edamame Platform Aims to Catch AI Coding Agents Going Off the Rails appe…SECURITYWEEK.COM
28 MayRaising the Cybersecurity Stakes: Ante up for the Agentic EraCISOs are now facing machine-speed attacks and asking, “How do I agent?” The industry must provide remediation at scale. The post Raising the Cybersecurity Stakes: Ante up for the Agentic Era appeared first on SecurityWeek .SECURITYWEEK.COM
28 MayOpenAI prepares ChatGPT for the election misinformation waveAI-generated election misinformation could shape public opinion and influence the lives of millions of people. To address those risks, OpenAI outlined a series of safeguards ahead of the 2026 election cycle. The company said its efforts will focus on helping users access voting i…HELPNETSECURITY.COM
28 MayDigimarc adds provenance, audit, and verification controls for AI agent workflowsDigimarc has announced new provenance and verification infrastructure designed to secure autonomous and AI-enabled workflows. As enterprises increasingly adopt AI systems capable of generating content, orchestrating workflows, and taking action with minimal human intervention, es…HELPNETSECURITY.COM
28 MayZapier fixes bug chain that researchers say risked widespread account takeoverA five-step flaw chain in the popular automation service, now patched, could have let a single attacker act as any signed-in user across thousands of connected apps. The post Zapier fixes bug chain that researchers say risked widespread account takeover appeared first on CyberSco…CYBERSCOOP.COM
28 MayMicrosoft’s Copilot trust test: zero findings, more models, wider oversightMicrosoft 365 Copilot and Copilot Chat (Copilot) have been recertified under ISO/IEC 42001:2023 by an independent auditor for the second consecutive year. Copilot first received ISO 42001 certification in March 2025. This year’s recertification recorded zero non-conformities and …HELPNETSECURITY.COM
28 MayAWS Doesn’t Secure EverythingMany organizations move infrastructure into AWS or managed environments believing most security responsibilities transfer with it. In reality, customers still control major parts of configuration, identity management, permissions, and operational security. That misunderstanding c…YOUTUBE.COM
28 MayEnterprise data is creeping its way into shadow AI toolsExecutives and employees are clashing over usage policies as AI security concerns rise, an Okta report found.CYBERSECURITYDIVE.COM
28 MayHow CISOs can manage sovereign-cloud security risksSelecting and adopting cloud services from non-U.S. regional providers requires solid cyber risk and security assessment.CYBERSECURITYDIVE.COM
28 MayProton Mail adds support for Gmail account syncing and sendingProton has announced a new feature that allows users to connect their Gmail accounts directly to Proton Mail, enabling them to read and send Gmail messages from within Proton’s encrypted email platform. The feature is designed to simplify migration away from Google’s email ecosys…CYBERINSIDER.COM
28 MayQuantum breakthrough produces perfect randomness for secure communicationsETH Zurich researchers have demonstrated what they describe as the world’s first generation of certifiably perfect random numbers using a quantum experiment based on entangled superconducting qubits. The breakthrough could strengthen future encryption systems, digital identity pr…CYBERINSIDER.COM
28 MayGeordie Raises $30 Million for AI Security and Governance PlatformThe funding round was led by Balderton Capital, with additional support from Crosspoint Capital and previous investors General Catalyst and Ten Eleven Ventures. The post Geordie Raises $30 Million for AI Security and Governance Platform appeared first on SecurityWeek .SECURITYWEEK.COM
28 MayHouse panel poised to hold hearing centered on AI impact on cyberIt’s part of a series of examinations at the House Homeland Security Committee that now will include a public event. The post House panel poised to hold hearing centered on AI impact on cyber appeared first on CyberScoop .CYBERSCOOP.COM
28 MayGoogle security engineer accused of turning confidential search trends into $1.2M win on PolymarketMichele Spagnuolo allegedly placed multiple trades on the prediction marketplace, abusing internal access to Google’s nonpublic data on the most searched people in 2025. The post Google security engineer accused of turning confidential search trends into $1.2M win on Polymarket a…CYBERSCOOP.COM
27 MayISC Stormcast For Wednesday, May 27th, 2026 https://isc.sans.edu/podcastdetail/9946, (Wed, May 27th)(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.ISC.SANS.EDU
27 MayThe alert economy is driving security analyst burnoutIn this Help Net Security video, Ido Livneh, CEO of Jazz, explains why security analysts burn out and what leaders can do about it. The cause, he argues, is not long hours but meaningless work. Analysts spend their days closing repetitive tickets while the institutional knowledge…HELPNETSECURITY.COM
27 MayCoinflow CISO on crypto payments security under AI pressureCrypto payment firms sit near the top of the target list for advanced persistent threat groups, and the workload on their security leaders keeps growing. Malcolm Portelli, CISO at Coinflow, runs the company’s security program from Malta. Coinflow is headquartered in the Uni…HELPNETSECURITY.COM
27 MayAnthropic Releases New Claude Sandbox, Security Guidance PluginThe AI giant says the new plugin, which helps developers find vulnerabilities as they write code, has been used extensively internally. The post Anthropic Releases New Claude Sandbox, Security Guidance Plugin appeared first on SecurityWeek .SECURITYWEEK.COM
27 MayAppOmni’s Marlin AI automates SaaS threat analysis, triage, and remediation at scaleAppOmni has launched Marlin AI to transform how enterprise organizations defend complex SaaS applications. Marlin AI delivers autonomous AI-powered SaaS security that leverages AppOmni’s deep SaaS application observability. It actively correlates SaaS security indicators, perform…HELPNETSECURITY.COM
27 MayFBI: Hackers Sending Operatives in Person to Insert USB Drives and Steal DataThe FBI has issued an alert warning of Silent Ransom Group attacks targeting law firms. The post FBI: Hackers Sending Operatives in Person to Insert USB Drives and Steal Data appeared first on SecurityWeek .SECURITYWEEK.COM
27 MayFranklin Access adds three-layer security system to Wi-Fi routersFranklin Access has launched a three-layer security system integrated into its Wi-Fi routers, delivering enterprise-grade protection for consumers and small businesses. The system runs automatically in the background, blocking millions of malicious websites in real time to protec…HELPNETSECURITY.COM
27 MayWhat Security Leaders Should Expect from RSAC - Joseph Blankenship - BSW #449RSA Conference (RSAC) 2026, the 35th annual flagship event for cybersecurity, drew over 43,500 attendees, featuring more than 600 exhibitors, 570+ sessions, and 700+ speakers from 104 countries. It generated 370 million social media impressions. With this size and reach, what sho…YOUTUBE.COM
27 MayThe Credential Crisis: How Stolen Credentials Defeat Modern SecurityAs AI accelerates phishing, session hijacking, and credential abuse, security teams are racing to close the gap between attacker speed and defensive response. The post The Credential Crisis: How Stolen Credentials Defeat Modern Security appeared first on SecurityWeek .SECURITYWEEK.COM
27 May‘SymJack’ Attack Turns AI Coding Agents Into Supply Chain Attack Delivery SystemsMalicious repositories and disguised symlinks can trick AI coding agents into silently installing attacker-controlled MCP servers capable of stealing secrets, compromising CI pipelines, and deploying malicious code. The post ‘SymJack’ Attack Turns AI Coding Agents Into Supply Cha…SECURITYWEEK.COM
27 MayGlassWorm Botnet DisruptedSecurity firms took down all four command-and-control (C&C) channels used by the GlassWorm malware. The post GlassWorm Botnet Disrupted appeared first on SecurityWeek .SECURITYWEEK.COM
27 MayRevEng.AI Raises $15 Million to Hunt for Flaws and Backdoors in Software BinariesUsing an AI model called BinNet, RevEng hunts vulnerabilities and backdoors in released software binaries. The post RevEng.AI Raises $15 Million to Hunt for Flaws and Backdoors in Software Binaries appeared first on SecurityWeek .SECURITYWEEK.COM
27 MayRomanian Hacker Sentenced to Prison in US for Selling Access to State NetworkCatalin Dragomir previously pleaded guilty to selling access to an Oregon state government office’s network. The post Romanian Hacker Sentenced to Prison in US for Selling Access to State Network appeared first on SecurityWeek .SECURITYWEEK.COM
27 MayLastwall Raises $11.5 Million for Quantum-Resilient Identity PlatformThe new funding, led by BDC Capital’s StrongNorth Fund, will accelerate Lastwall’s North American expansion. The post Lastwall Raises $11.5 Million for Quantum-Resilient Identity Platform appeared first on SecurityWeek .SECURITYWEEK.COM
27 MaySecurityWeek to Host AI Risk Summit August 11-12 at the Ritz-Carlton, Half Moon BayNow in its third year, the AI Risk Summit is the leading conference that brings together CISOs, security leaders, AI researchers, developers, policymakers, and enterprise risk professionals. The post SecurityWeek to Host AI Risk Summit August 11-12 at the Ritz-Carlton, Half Moon …SECURITYWEEK.COM
27 MayeSentire launches new Atlas AI Operatives for autonomous threat detection and responseeSentire has unveiled new preempt, detect, and respond capabilities within the Atlas Platform, a unified agentic AI platform with purpose-built AI Operatives that work together in a continuous security lifecycle. Controlled autonomy SecOps The Atlas Platform delivers purpose-buil…HELPNETSECURITY.COM
27 MayFBI’s 2025 Internet Crime ReportThe 2025 Internet Crime Report was published a few weeks ago, but I only just saw it. Lots of interesting statistics. Press release . News articles .SCHNEIER.COM
27 MayDecrypting Customer Data On PurposeA telecom company asked how to “fix” an encryption problem. But according to the speaker, the real request was how to decrypt protected customer data so the company could build services and insights on top of it. The clip highlights a common security tension: businesses want more…YOUTUBE.COM
27 MayLeading AI models are more vulnerable to malicious prompts than vendors claimHackers could subvert frontier models with attacks that their developers overlook, Cisco said.CYBERSECURITYDIVE.COM
27 MayHackers are knocking on office doors pretending to be IT staffThe Silent Ransom Group (SRG) is targeting law firms using social engineering techniques and an unusual tactic for cybercriminals: showing up at victims’ offices in person while posing as IT staff, the FBI warns. The group, also known as Luna Moth, Chatty Spider, and UNC3753, has…HELPNETSECURITY.COM
27 MayCommit to Compromise: A New Threat Actor Targeting the Cryptocurrency Industry's Software Development InfrastructureWiz CIRT and Wiz Research detail JINX-0164, a threat actor using LinkedIn social engineering, custom macOS malware, and CI/CD hijacking to target cryptocurrency organizations.WIZ.IO
27 MayEvidence at the Moment of Attack. Answers at AI Speed.Wiz Sensor Forensics is now generally available - automatically capturing forensic artifacts at the moment of detection and using AI to accelerate investigation for SOC and IR teams.WIZ.IO
27 MayFBI warns US-based law firms to be on the lookout for cybercrime group that steals data in personSilent Ransom Group isn’t prolific, but it's demonstrated a knack for attacking the legal services sector with an extraordinary dual use of social engineering and in-person visits to victims’ workstations. The post FBI warns US-based law firms to be on the lookout for cybercrime …CYBERSCOOP.COM
27 MayAI’s Hype Cycle Is EndingResearchers analyzed decades of RSA Conference session titles and found that no major cybersecurity buzzword stayed dominant for more than about three years. The speaker argues AI may now be reaching that same turning point. After years of massive investment and nonstop attention…YOUTUBE.COM
27 MayOpenAI heralds cybersecurity, election interference safeguard plans for 2026 midtermsThe announcement builds on work from major tech firms in 2024 to combat AI-infused election chicanery. The post OpenAI heralds cybersecurity, election interference safeguard plans for 2026 midterms appeared first on CyberScoop .CYBERSCOOP.COM
27 MayGPU mining malware spreads via SEO poisoning, AI chatbotsThreat actors are targeting systems with high-performance computers in an ongoing cryptojacking campaign spread through a coordinated SEO poisoning operation that also manipulated AI chatbot recommendations. [...]BLEEPINGCOMPUTER.COM
27 MayOut of the Crypt: The Evolving Cyber Extortion EconomyUnit 42 explores trends in data theft and extortion, outlining key strategies for organizations as frontier AI models advance. The post Out of the Crypt: The Evolving Cyber Extortion Economy appeared first on Unit 42 .UNIT42.PALOALTONETWORKS.COM
26 MayISC Stormcast For Tuesday, May 26th, 2026 https://isc.sans.edu/podcastdetail/9944, (Tue, May 26th)(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.ISC.SANS.EDU
26 MayManage machine identities: The hidden privileged access layer you need to manageWhy are machine identities becoming the majority of “things with access”? Every automation, integration, and workload needs a way to authenticate and the right permissions to act. That quiet requirement has created a massive population of machine identities, also called non-human…HELPNETSECURITY.COM
26 MayRunning the Inverted Offensive Campaign with Adam KarcherHost Caleb Tolin sits down with Adam Karcher, FBI Supervisory Special Agent, Cyber Division, to discuss the urgent shift from reactive defense to a long-term operational campaign mindset. As threats evolve into a blended ecosystem of state and criminal actors, defenders must adap…THECYBERWIRE.COM
26 MayIranian Hackers Deploy MiniFast and MiniJunk V2 via Phishing and SEO PoisoningThe Iranian state-sponsored threat actor known as Nimbus Manticore (aka Screening Serpens and UNC1549) has been attributed to a fresh campaign using lures impersonating organizations in the aviation and software sectors across the U.S., Europe, and the Middle East following the j…THEHACKERNEWS.COM
26 MayAdmins of Bulletproof Hosting Service Used by Russian Hackers Arrested in NetherlandsThe two own Dutch companies that allegedly provided bulletproof hosting services to Russia-aligned threat actors. The post Admins of Bulletproof Hosting Service Used by Russian Hackers Arrested in Netherlands appeared first on SecurityWeek .SECURITYWEEK.COM
26 MayLithuania Suspects Foreign Involvement in Data Leak of Over 600,000 National Register EntriesLithuanian authorities are on high alert after a massive data leak involving more than 600,000 entries from national data registers. The post Lithuania Suspects Foreign Involvement in Data Leak of Over 600,000 National Register Entries appeared first on SecurityWeek .SECURITYWEEK.COM
26 MayAnthropic Expands Claude’s Enterprise Security Governance With 28 New IntegrationsNotable integrations include CrowdStrike, Palo Alto Networks, Microsoft, Okta, Zscaler, Netskope, Cloudflare, Fortinet, and Wiz. The post Anthropic Expands Claude’s Enterprise Security Governance With 28 New Integrations appeared first on SecurityWeek .SECURITYWEEK.COM
26 MayAppOmni’s Marlin AI Brings Autonomous Investigation to SaaS SecurityMarlin AI automatically analyzes SaaS misconfigurations, investigates related activity across enterprise environments, and recommends remediation steps — while stopping short of fully autonomous corrective action. The post AppOmni’s Marlin AI Brings Autonomous Investigation to Sa…SECURITYWEEK.COM
26 MayIranian APT Targets Aviation, Software Companies With Updated ToolsNimbus Manticore has continued its operations during and after the US military campaign against Iran. The post Iranian APT Targets Aviation, Software Companies With Updated Tools appeared first on SecurityWeek .SECURITYWEEK.COM
26 MayConifers rolls out AI-powered SOC for unified security operations and automated responseConifers has announced the launch of its agentic SOC, a unified AI platform designed to help security operations centers defend against cyber adversaries operating at machine speed. Built on the company’s CognitiveSOC platform, the new system connects threat intelligence, threat …HELPNETSECURITY.COM
26 MayAI Developers Never Go HomeAI coding agents are often compared to junior developers because of similar output quality, but their behavior is fundamentally different. They operate continuously, adapt dynamically, pursue assigned goals autonomously, and may hold system access that organizations do not fully …YOUTUBE.COM
26 MayIdentifying People Using Wi-Fi RoutersNot identifying people based on their use of Wi-Fi routers, but identifying people using Wi-Fi signals . This is accomplished through what is known as WiFi sensing , or the use of WiFi signals to infer information about a physical environment. When radio signals like WiFi travel …SCHNEIER.COM
26 MayAnthropic: Mythos finds more than 10,000 software flaws in first monthEarly results show a tenfold jump in bug discovery at some partners, and a widening gap between finding flaws and fixing them. The post Anthropic: Mythos finds more than 10,000 software flaws in first month appeared first on CyberScoop .CYBERSCOOP.COM
26 MayFBI warns about PhaaS platform used to access Microsoft 365 environmentsDevice code phishing enabled hackers to bypass multifactor authentication without credentials.CYBERSECURITYDIVE.COM
26 MayMuddyWater Uses DLL Side-Loading in Espionage Campaign Targeting 9 CountriesThe Iranian hacking group known as MuddyWater has been linked to a new campaign affecting at least nine organizations across nine countries on four continents in the first quarter of 2026. The activity targeted industrial and electronics manufacturing, education and public-sector…THEHACKERNEWS.COM
26 MayThe AI Accounts Nobody RemovesAI agents and non-human identities are increasingly being treated like employees because they also have operational lifecycles. Agents can be created quickly, assigned permissions, reorganized, and eventually become irrelevant to the business over time. The governance challenge i…YOUTUBE.COM
26 May KEVListening, Drupal, TTE, KEV, Mythos, Megalodon, Badanov, MFA, Pope Leo, Aaran Leyland - SWN #584They're Listening, Drupal, TTE, KEV, Mythos, Megalodon, Boris and Natasha, MFA, Pope Leo, Aaran Leyland, and More on the Security Weekly News. Visit https://www.securityweekly.com/swn for all the latest episodes! Show Notes: https://securityweekly.com/swn-584YOUTUBE.COM
26 MayFrom poisoned search results to GPU mining: A cryptojacking campaign abusing ScreenConnect and Microsoft .NET utilitiesMicrosoft exposes a cryptojacking campaign using SEO poisoning and ScreenConnect to target high-performance PCs, with malicious sites also surfaced through AI chatbots. The post From poisoned search results to GPU mining: A cryptojacking campaign abusing ScreenConnect and Microso…MICROSOFT.COM
25 MayBoards want cyber risk in dollars, not CVE countsIn this Help Net Security video, Ziv Levi, SVP of Technology at CYE, explains why translating cyber risk into dollars is one of the most pressing tasks for security leaders. Boards and executives want cyber exposure described in business terms, not technical jargon. Levi walks th…HELPNETSECURITY.COM
25 MayOver 5,500 GitHub Repositories Infected in ‘Megalodon’ Supply Chain AttackFake automated commits injected GitHub Actions workflows containing payloads to steal credentials, CI secrets, keys, and tokens. The post Over 5,500 GitHub Repositories Infected in ‘Megalodon’ Supply Chain Attack appeared first on SecurityWeek .SECURITYWEEK.COM
25 MayLazarus Deploys RemotePE Memory-Only RAT Against Financial and Crypto FirmsCybersecurity researchers have shed light on a cross-platform malware called RemotePE that has been put to use by the North Korea-linked Lazarus Group in attacks targeting financial and cryptocurrency organizations. RemotePE, per NCC Group subsidiary Fox-IT, is part of a multi-st…THEHACKERNEWS.COM
25 MayAnthropic: Mythos Detected 23,000 Potential Vulnerabilities Across 1,000 OSS ProjectsMany findings have been confirmed to be critical or high-severity vulnerabilities and the number will continue to increase. The post Anthropic: Mythos Detected 23,000 Potential Vulnerabilities Across 1,000 OSS Projects appeared first on SecurityWeek .SECURITYWEEK.COM
25 MayPrevention Alone Fails SecurityMost cybersecurity programs prioritize prevention first. Stop the attack before it happens. But this clip explains the weakness in relying on prevention alone. If attackers bypass defenses and nobody detects it, response becomes impossible. Detection and response are often treate…YOUTUBE.COM
25 MayMegalodon campaign compromises over 5,500 GitHub repositories with malicious commitsSecurity researchers have uncovered a large-scale supply chain attack dubbed “Megalodon” that injected malicious GitHub Actions workflows into more than 5,500 repositories. The campaign was discovered by researchers at SafeDep, who identified 5,718 malicious commits pushed across…CYBERINSIDER.COM
23 MayAn Example of Stack String in High Level Language, (Sat, May 23rd)This week, I'm attending the SEC670[ 1 ] training (“Red Teaming Tools - Developing Windows Implants, Shellcode, Command and Controlâ€). From my point of view, this training fits perfectly with FOR610 or FOR710 (malware analysis)…ISC.SANS.EDU
22 MayISC Stormcast For Friday, May 22nd, 2026 https://isc.sans.edu/podcastdetail/9942, (Fri, May 22nd)(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.ISC.SANS.EDU
22 MayFlipper Introduces Flipper One as a Modular Linux-Based CyberdeckFlipper Devices has officially unveiled Flipper One, a modular, Linux-based cyberdeck designed to push the boundaries of open hardware and portable network analysis platforms. Unlike the popular Flipper Zero, the new device targets high-performance networking, software-defin…GBHACKERS.COM
22 MayThe new economics of fraud: Cheaper, faster, more convincingScams have become one of the fastest-growing consumer risks, driven by AI-enabled impersonation, social engineering, and sophisticated attack methods, according to Visa’s Spring 2026 Biannual Threats Report. Criminals redirect efforts toward trust and third parties Fraud involves…HELPNETSECURITY.COM
22 MayNew infosec products of the week: May 22, 2026Here’s a look at the most interesting products from the past week, featuring releases from ASAPP, Babel Street, CTERA, Forward, Riverbed, and Trust3 AI. Babel Street targets AI-driven threats with new agentic investigation capabilities Babel Street has launched Insights Investiga…HELPNETSECURITY.COM
22 MayCross-Platform NPM Stealer, (Fri, May 22nd)I found a Node.js stealer that looked pretty well obfuscated. The file was not running out-of-the-box because it was uploaded on VT as “extracted-decoded.js†(and reformated). The SHA256 is 049300aa5dd774d6c984779a0570f59610399c71864b5d5c260…ISC.SANS.EDU
22 MayHackers Hide Malware in Nested macOS-Style Folders to Evade ScansHackers are increasingly adopting stealthy delivery techniques, and a newly uncovered spear-phishing campaign shows how nested macOS-like folder structures can be abused to evade detection while deploying advanced malware. The phishing email carries a ZIP attachment named “常州大学20…GBHACKERS.COM
22 MayOne Telecom Provider Hosted Most of the Middle East ’s Active C2 InfrastructureHunt.io mapped 1,350+ C2 servers across the Middle East, revealing how a small group of providers quietly supports major malware activity. For years, threat intelligence focused mostly on malware families, phishing domains, and individual indicators. But a new report from Hunt.io…SECURITYAFFAIRS.COM
22 MayHackers Weaponize NF-e Invoice Lures to Deploy Banana RATHackers are actively using Brazil’s electronic invoice system (NF-e) as a lure to distribute a sophisticated banking trojan known as Banana RAT. The campaign has been attributed to a financially motivated threat cluster tracked as SHADOW-WATER-063 and appears exclusively focused …GBHACKERS.COM
22 MayAndroid Malware Secretly Signs Users Up for Premium ServicesAndroid users are being targeted by a large-scale malware campaign that silently subscribes victims to premium mobile services without their knowledge. The malware campaign focuses on carrier billing fraud, abusing premium SMS services to generate revenue for attackers. What make…GBHACKERS.COM
22 MayMicrosoft 365 users targeted by new phishing threat that bypasses MFAMicrosoft 365 access tokens are being targeted by an emerging Phishing-as-a-Service (PhaaS) platform called Kali365, the FBI is warning. First observed in April 2026, Kali365 has been distributed through Telegram, allowing cybercriminals to obtain Microsoft 365 access tokens and …HELPNETSECURITY.COM
22 MayMeet Fractal, an OS made for microarchitecture reverse engineeringProbing how a CPU isolates user code from kernel code is messy work. Researchers patch kernels, write drivers, or boot stripped-down bare-metal programs, and any of those choices change variables they were trying to hold still. Fractal, a new operating system from MIT CSAIL, was …HELPNETSECURITY.COM
22 MayProton Pass adds monitored credential sharing for AI agentsProton Pass, a secure, end-to-end encrypted password manager, added credential sharing through AI access tokens, allowing users to give AI agents access to selected items and monitor activity. To gain access, an agent must provide a reason for the request so users can see what ac…HELPNETSECURITY.COM
22 MayWorld Cup Phishing Surge: 203 Malicious IPs DetectedThe scale of phishing activity targeting the 2026 FIFA World Cup has expanded dramatically, with new research revealing a far broader and more complex threat landscape than initially reported. What began as a cluster of 79 malicious domains has now evolved into a distributed phis…GBHACKERS.COM
22 MayDeleted Google API keys keep working for up to 23 minutes, researchers warnGoogle API keys are credentials that let applications access Google services, from Maps to the Gemini AI. If a key is leaked, an attacker can use it to make API calls, rack up charges, and, if Gemini is enabled, access uploaded files and cached conversations. The assumed fix is s…HELPNETSECURITY.COM
22 MayTracking Iranian APT Screening Serpens’ 2026 Espionage CampaignsUnit 42 details Screening Serpens' use of AppDomainManager hijacking and new RAT variants to target tech and defense sectors in recent campaigns. The post Tracking Iranian APT Screening Serpens’ 2026 Espionage Campaigns appeared first on Unit 42 .UNIT42.PALOALTONETWORKS.COM
22 MayShadow AI Is Old Security DebtThe discussion argues that “shadow AI” is really just the latest version of shadow IT — employees sending sensitive data to tools outside official security oversight. The same concerns once tied to Dropbox and cloud apps are now appearing with AI systems like ChatGPT. Unlike trad…YOUTUBE.COM
22 MayIran-linked hackers target key US, allied sectors with sophisticated spear-phishing messagesCompanies, particularly those in the affected industries, should harden their defenses against impersonation schemes, Palo Alto Networks said.CYBERSECURITYDIVE.COM
22 MayNew York regulator calls for additional cyber mitigation amid heightened threat environmentThe guidance from the state Department of Financial Services arises from concerns about frontier AI and threats linked to the Iran war and other geopolitical risks.CYBERSECURITYDIVE.COM
22 MayHow Agentic AI and Automation Are Changing CybersecurityThere is no question that AI is changing cybersecurity in a massive way. In many respects, its impact is comparable to the rise of the internet. AI tools are helping organizations improve efficiency, automate repetitive tasks, and process data at a speed humans simply cannot matc…KNOWBE4.COM
22 MayNordVPN wins early court victory against LaLiga’s VPN blocking campaignA Spanish court has rejected LaLiga’s request to fine NordVPN over alleged failures to comply with a controversial anti-piracy blocking order. The decision was issued on May 19, 2026, by the Commercial Court of Córdoba, which dismissed LaLiga’s petition seeking coercive penalties…CYBERINSIDER.COM
22 MayGhostwriter Targets Ukraine Government Entities with Prometheus Phishing MalwareThe Belarus-aligned threat actor known as Ghostwriter (aka UAC-0057 and UNC1151Ukraine's National Security and Defense Council) has been observed using lures related to Prometheus, a Ukrainian online learning platform, to target government organizations in the country. The activi…THEHACKERNEWS.COM
22 MayMicrosoft Security success stories: How St. Luke’s and ManpowerGroup are securing AI foundationsHow Frontier firms secure AI at scale: read how Microsoft customers embed governance, identity, and cloud security to make protection an enabler of AI growth. The post Microsoft Security success stories: How St. Luke’s and ManpowerGroup are securing AI foundations appeared …MICROSOFT.COM
22 MayTelegram’s MTProto protocol leaks persistent identifiers enabling user trackingA newly published technical review of Telegram’s MTProto protocol warns that the messaging platform exposes persistent device identifiers to passive network observers, potentially allowing users to be tracked across networks, locations, and sessions without breaking Telegram’s en…CYBERINSIDER.COM
22 MayFrom edge appliance to enterprise compromise: Multi-stage Linux intrusion via F5 and ConfluenceA multi-stage attack on Linux devices began with an exposed F5 BIG-IP edge appliance and pivoted to an internal Confluence server for credential theft and identity compromise. Learn how the threat actor attempted Kerberos relay and lateral movement, and how Microsoft Defender det…MICROSOFT.COM
22 MayFBI warns about fast-growing phishing kit targeting Microsoft 365 usersKali365, which was first observed in April, abuses legitimate Microsoft device authorization pages to grant persistent access to cybercriminal-controlled applications. The post FBI warns about fast-growing phishing kit targeting Microsoft 365 users appeared first on CyberScoop .CYBERSCOOP.COM
22 MayFriday Squid Blogging: Regulating Squid Fishing in the South PacificThe South Pacific Regional Fisheries Management Organization (SPRFMO) needs to regulate squid fishing in the South Pacific. As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered. Blog moderation policy.SCHNEIER.COM
22 MayTVs, Old York, Flipper One, Ubiquity, Underminr, CISOs, GitHub, Josh Marpet... - SWN #583TVs, Old York, Flipper One, Ubiquity, Underminr, CISOs, GitHub, Josh Marpet, and More on this episode of the Security Weekly News. Visit https://www.securityweekly.com/swn for all the latest episodes! Show Notes: https://securityweekly.com/swn-583YOUTUBE.COM
21 MayISC Stormcast For Thursday, May 21st, 2026 https://isc.sans.edu/podcastdetail/9940, (Thu, May 21st)(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.ISC.SANS.EDU
21 MayProduct showcase: Bitdefender Mobile Security for iOS protects privacy where scams beginBitdefender Mobile Security for iOS is a security and privacy application for iPhone and iPad that helps protect against phishing attempts, online scams, unsafe websites, and account exposure. I have used Bitdefender Mobile Security for iOS for the last two years. It was easy to …HELPNETSECURITY.COM
21 MayTwo U.S. Executives Plead Guilty in India-Based Tech Support Fraud SchemesTwo U.S.-based business executives have pleaded guilty to their roles in enabling large-scale tech-support fraud operations linked to call centers in India, according to the U.S. Department of Justice. Adam Young, 42, former CEO of a telecommunications services company based in M…GBHACKERS.COM
21 MayBadIIS Malware Hijacks IIS Servers to Redirect Users to Illicit SitesA new variant of the BadIIS malware that hijacks Microsoft IIS web servers to redirect users to illicit websites, highlighting an evolving malware-as-a-service (MaaS) ecosystem operated by Chinese-speaking cybercrime groups. The newly analyzed variant is marked by embedded “demo.…GBHACKERS.COM
21 MayMost dark web activity revolves around a handful of topicsDark web activity often becomes visible during marketplace seizures, major data leaks, or sudden spikes in criminal activity. Those events can create an impression of an ecosystem where attention shifts quickly and new trends regularly replace old ones. A six-year dataset coverin…HELPNETSECURITY.COM
21 MayP2PInfect Botnet Targets Kubernetes via Exposed RedisA persistent P2Pinfect botnet campaign targeting Google Kubernetes Engine (GKE) clusters through exposed Redis instances, highlighting how a single cloud misconfiguration can enable long-term compromise. In several investigated environments, attackers maintained access for up to …GBHACKERS.COM
21 MayRiverbed introduces new Aternity tools for autonomous IT operationsRiverbed has announced new capabilities for Aternity designed to support autonomous IT operations for digital experience management. The updates help digital workplace teams move toward prevention-focused operations through broader visibility, context-aware intelligence, and gove…HELPNETSECURITY.COM
21 MayForward launches Predict to test network changes before deploymentForward has unveiled Forward Predict, a new capability that allows organizations to evaluate the impact of network changes before deployment. By testing proposed changes against a digital twin of the production network, Forward Predict helps identify potential issues before they …HELPNETSECURITY.COM
21 MayCTERA brings AI insights and automation for unstructured dataCTERA has announced the launch of CTERA InsightAI, an agentic AI intelligence layer for the CTERA Intelligent Data Platform. The new capability is designed to help enterprises understand, manage, secure, and optimize unstructured data environments. CTERA InsightAI adds AI-driven …HELPNETSECURITY.COM
21 MayVirtru centers file collaboration around data-level protectionVirtru unveiled Virtru Collaborate, a new offering that eliminates that tradeoff, a FedRAMP authorized space where sensitive files are encrypted and protected by the Trusted Data Format (TDF), and where that protection travels seamlessly with the data as teams work together acros…HELPNETSECURITY.COM
21 MayTenable Hexa AI automates remediation across attack surfacesTenable has announced the general availability of Tenable Hexa AI, the agentic AI engine of the Tenable One Exposure Management Platform. Tenable Hexa AI is an advanced agentic AI for cybersecurity solution, equipped with advanced multi-step reasoning and Model Context Protocol (…HELPNETSECURITY.COM
21 MayTamperedChef Malware Hides in Signed Apps to Drop Stealers and RATsA large-scale malware campaign dubbed “TamperedChef” is leveraging trojanized productivity applications such as PDF editors, calendar tools, and file converters to silently deploy information stealers and remote access trojans (RATs), according to recent threat intelligence findi…GBHACKERS.COM
21 MayFake Microsoft Teams Downloads Spread ValleyRAT MalwareHackers are actively distributing a sophisticated ValleyRAT malware variant through fake Microsoft Teams download pages, leveraging social engineering and multi-stage execution techniques to evade detection. The campaign, first observed in mid-April on the X platform, uses fraudu…GBHACKERS.COM
21 MayThe readiness paradox: Why a false sense of cyber confidence is becoming a liabilityAs AI expands the attack surface and alert fatigue grows, cyber exposure management offers a clearer path to understanding where risk truly concentrates and how to reduce it before a crisis hits. The post The readiness paradox: Why a false sense of cyber confidence is becoming a …CYBERSCOOP.COM
21 MayDiscord Enables End-to-End Encryption by Default Across Voice and Video FeaturesDiscord has officially enabled end-to-end encryption (E2EE) by default for all voice and video communications across its platform, marking a significant shift in user privacy and secure communications. The announcement, made on May 18, 2026, confirms that every voice and video ca…GBHACKERS.COM
21 MayFitbit Air vs Pixel Watch 4: Which Should You Wear at Night?Fitbit Air offers $99 sleep-first tracking, Pixel Watch 4 pairing, and a cheaper Whoop alternative, but Google’s AI coaching remains unproven. The post Fitbit Air vs Pixel Watch 4: Which Should You Wear at Night? appeared first on TechRepublic .TECHREPUBLIC.COM
21 MayGoogle Health 5.0 Brings New Fitbit App Design, AI Coach, and Android WidgetGoogle Health 5.0 replaces the Fitbit app with a redesigned layout, Gemini-powered coaching, a new Android widget, and retired Fitbit features. The post Google Health 5.0 Brings New Fitbit App Design, AI Coach, and Android Widget appeared first on TechRepublic .TECHREPUBLIC.COM
21 MayGoogle Brings a Long-Missing Apple Feature to AndroidGoogle’s Continue On in Android 17 lets users move supported tasks from phone to tablet, bringing Apple-like Handoff to Android devices soon. The post Google Brings a Long-Missing Apple Feature to Android appeared first on TechRepublic .TECHREPUBLIC.COM
21 MayPermanent Jobs Fall in UK as Temporary Placements Rise: ReportUK permanent job placements fell in April while temporary hires rose due to economic uncertainty and global conflict, according to a new KPMG/REC report The post Permanent Jobs Fall in UK as Temporary Placements Rise: Report appeared first on TechRepublic .TECHREPUBLIC.COM
21 MayHistoric SpaceX IPO Filing Reveals Starlink, AI, and Mars AmbitionsSpaceX’s IPO filing reveals Starlink’s revenue role, major AI spending, Starship costs, Musk’s control, and legal risks facing investors. The post Historic SpaceX IPO Filing Reveals Starlink, AI, and Mars Ambitions appeared first on TechRepublic .TECHREPUBLIC.COM
21 MayGlucose Tracking Is Turning Into the Next Big Health Data PlatformGlucose tracking is moving beyond diabetes care as CGMs, AI platforms, and wearable sensors reshape personalized health data and wellness tools. The post Glucose Tracking Is Turning Into the Next Big Health Data Platform appeared first on TechRepublic .TECHREPUBLIC.COM
21 MayProton Pass adds new protections for AI agents with account accessA new Proton Pass feature allows users to securely share credentials with AI agents via “AI access tokens,” aiming to reduce the security risks posed by autonomous AI tools accessing private accounts. The feature lets users grant AI agents limited, read-only access to selected cr…CYBERINSIDER.COM
21 MayGoogle “Won’t Fix” API key staying active for 23 mins after deletionDeleted Google API keys remain valid for up to 23 minutes after revocation, potentially allowing attackers to continue accessing Google Cloud services and Gemini data long after the credentials have been disabled. Google acknowledged the behavior following a report by Aikido, but…CYBERINSIDER.COM
21 MayBuild Custom, High-Impact Training with KnowBe4’s Content Creation AgentIn the world of security awareness training, a comprehensive library of relevant and engaging content is a necessity. But even the best training can feel limited when you need to talk about your specific VPN rules, a policy that changed this morning, or a novel threat uniquely ta…KNOWBE4.COM
21 MayWhat’s new in Microsoft Security: May 2026Microsoft Security’s latest updates extend visibility, control, and protection across expanding ecosystems as organizations accelerate AI adoption. The post What’s new in Microsoft Security: May 2026 appeared first on Microsoft Security Blog .MICROSOFT.COM
20 MayISC Stormcast For Wednesday, May 20th, 2026 https://isc.sans.edu/podcastdetail/9938, (Wed, May 20th)(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.ISC.SANS.EDU
20 May7 hard truths security pros should know: 2026 DevOps Threats ReportIn 2025, trusted Git hosting platforms became a playground for cyber criminals. This is the main conclusion from the latest “DevOps Threat Unwrapped Report 2026” by GitProtect. If you want to effectively counter attacks targeted at your code (and business), you need security meas…HELPNETSECURITY.COM
20 MayWhen your AI assistant has the keys to productionLarge language models in operational roles query telemetry, propose configuration changes, and in some deployments execute those changes against live infrastructure. Ticket drafting and alert summarization were the starting point. Vendors describe this work as autonomous remediat…HELPNETSECURITY.COM
20 MayTrapdoor Android Ad Fraud Ring Abuses 455 Apps for Fake ClicksA large-scale Android ad fraud campaign named “Trapdoor,” exposing a sophisticated ecosystem built on 455 malicious apps and 183 command-and-control (C2) domains. The operation combines malvertising, automated click fraud, and advanced evasion techniques to create a self-sustaini…GBHACKERS.COM
20 MayDevilNFC Malware Traps Android Users in NFC Relay AttacksA newly identified Android malware family named DevilNFC is raising concern among cybersecurity researchers for its advanced use of kiosk mode to trap victims during NFC relay attacks. These malware families mark a significant evolution in NFC relay threats. Unlike earlier campai…GBHACKERS.COM
20 MayMini Shai-Hulud Attack Hits npm Ecosystem, Compromising Over 600 PackagesA large-scale supply chain attack targeting the npm ecosystem has resurfaced with a new variant of the Mini Shai-Hulud malware, compromising more than 600 packages and introducing advanced evasion techniques, including forged Sigstore provenance. The attack primarily targeted the…GBHACKERS.COM
20 MaySingle-Letter Go Module Typosquat Drops DNS-Based BackdoorA newly uncovered software supply chain attack targeting Go developers demonstrates how a single-character typo can silently introduce a persistent backdoor. A malicious Go module, github.com/shopsprint/decimal, designed to impersonate the widely trusted github.com/shopspring/dec…GBHACKERS.COM
20 MayCommunicating cyber risk in dollars boards understandIn this Help Net Security interview, Nick Nieuwenhuis, Cybersecurity Architect at Nedscaper, explains why cybersecurity has not delivered the resilience that decades of investment have promised. He argues that spending has leaned too heavily on technical controls while neglecting…HELPNETSECURITY.COM
20 MayVoid Botnet Leverages Ethereum for Resilient C2A newly identified botnet, named Void, is leveraging Ethereum smart contracts to build a resilient, hard-to-disrupt command-and-control (C2) infrastructure, marking a continued evolution in blockchain-enabled cybercrime. Discovered in March 2026 and advertised on a Russian-langua…GBHACKERS.COM
20 MayEviltokens: A Conversation with Huntress on an AI‑Enabled Device Code Phishing CampaignIn this episode of the Microsoft Threat Intelligence Podcast, host Sherrod DeGrippo joins researchers from Huntress to break down the rise of EvilTokens, an AI-powered phishing-as-a-service platform designed to bypass MFA and automate credential theft at scale. Together, t…THECYBERWIRE.COM
20 MayGUEST ESSAY: AI can speed up communication, but it can also weaken human connectionThe first warning sign came on stage. Related: Carol Sturka declares her agency I had turned to ChatGPT to help organize research notes for an upcoming keynote. I was pressed for time and wanted help spotting patterns I might have … (more…) The post GUEST ESSAY: AI can spee…LASTWATCHDOG.COM
20 MayDarwinium updates mobile SDKs to detect remote access scam activityDarwinium has announced updates to its Android and iOS mobile SDKs. It enables banks, payment providers, and digital businesses to tackle the proliferation of remote access scams, including those that manipulate live sessions and account farming operations that run mule networks.…HELPNETSECURITY.COM
20 MayFake Tax Assessment Pages Spread Windows MalwareHackers are actively targeting Windows users with fake Indian Income Tax assessment pages in a campaign tracked as TAX#TRIDENT. The campaign begins with fraudulent tax assessment or penalty pages designed to create urgency. Victims are prompted to download what appears to be an o…GBHACKERS.COM
20 MayTracking TamperedChef Clusters via Certificate and Code ReuseUnit 42 analyzes TamperedChef malware clusters that use trojanized productivity apps and malvertising to deliver stealthy payloads to targets. The post Tracking TamperedChef Clusters via Certificate and Code Reuse appeared first on Unit 42 .UNIT42.PALOALTONETWORKS.COM
20 MayTrust3 AI focuses on AI agent risks with MCP Security layerTrust3 AI has announced the launch of Model Context Protocol (MCP) Security, establishing a new standard for safeguarding enterprise agentic AI workloads. This solution forms a key capability within Trust3 AI’s enterprise agent control plane, empowering security and governa…HELPNETSECURITY.COM
20 MayGraphWorm Malware Abuses Microsoft OneDrive for Stealthy C2 OperationsA new activity from Webworm, a China-aligned advanced persistent threat (APT) group, revealing a significant evolution in its cyber espionage toolkit during 2025. The group, first publicly documented in 2022, has shifted its targeting from primarily Asian organizations to governm…GBHACKERS.COM
20 MayChina-Linked Webworm APT Evolves Tactics, Expands to European TargetsChina-linked Webworm APT expands beyond Asia, targeting European government organizations and refining its cyber espionage tactics, according to ESET researchINFOSECURITY-MAGAZINE.COM
20 MayFBI: $388 million lost in crypto ATM scams in 2026Americans lost more than $388 million to crypto kiosk scams in 2025, with the FBI warning that criminals are increasingly directing victims to transfer funds through these machines. Cryptocurrency kiosks, popularly known as Bitcoin ATMs, are physical automated teller machines tha…HELPNETSECURITY.COM
20 MayNovata uses AI to map risk across portfolios and supply chainsNovata has announced the launch of Risk Atlas, a new AI-powered risk monitoring tool designed to help organizations identify, compare, and prioritize risks across portfolios and supply chains. Framework for comparative risk visibility Risk Atlas provides a single, customizable fr…HELPNETSECURITY.COM
20 MayOn AI SecurityGood report : Executive Summary: Let’s say you wanted to make sure that your AI is secure. Can you just maximize the security and privacy benchmark and call it a day? Nope, because benchmarks don’t actually work for measuring AI capabilities (even when they are NOT em…SCHNEIER.COM
20 MayWebworm Deploys EchoCreep and GraphWorm Backdoors Using Discord and MS Graph APICybersecurity researchers have flagged fresh activity from a China-aligned threat actor known as Webworm in 2025, deploying custom backdoors that employ Discord and Microsoft Graph API for command-and-control (C2 or C&C) communications. Webworm, first publicly documented by B…THEHACKERNEWS.COM
20 MayReport: Romance Scams Cost UK Victims £102 Million Last YearUK residents lost £102 million ($138 million US) to romance scams in 2025, according to a new report from the City of London Police.KNOWBE4.COM
20 MayThey Put Industrial Systems On Wi-FiDoug White describes industrial control systems (ICS/OT) that were exposed online without password protection, including fuel tank gauge consoles such as the Veeder-Root TLS350 and TLS450 Plus. For years, many industrial environments relied on obscurity and isolation as informal …YOUTUBE.COM
20 MayBlock Everything By DefaultA Zero Trust Cloud Access model brokers connections to SaaS platforms through a controlled intermediary instead of exposing those services broadly to the internet. Instead of allowing access from anywhere, organizations can block all inbound access by default and permit only a ve…YOUTUBE.COM
20 MayHow Can MSSPs Scale Threat Detection Without Burning Out Their Analysts?Scaling threat detection as an MSSP doesn’t mean hiring more analysts — it means enabling the analysts you already have to handle more clients, more alerts, and more complex threats without burning out. The practical path forward combines three capabilities: continuous real…ANY.RUN
20 MaySame Problem, Different Angles: When Red Team and Blue Team Actually Talk to Each OtherThere is a certain kind of conversation that doesn’t get written up in a post-mortem, doesn’t generate a ticket, and never makes it into an end-of-quarter report. It happens on the margins—at a conference, in a hallway, or, in this case, at 30,000 feet above sea level. It’s the c…BLACKHILLSINFOSEC.COM
20 MayTor launches crowdfunding campaign to support internet freedom projectsThe Tor Project has launched a new cryptocurrency-based crowdfunding initiative aimed at supporting internet freedom and privacy tools amid growing financial pressure on nonprofit digital rights organizations. The campaign introduces a Web3-focused funding model that uses quadrat…CYBERINSIDER.COM
20 MayAI assistants can be hijacked and manipulated by inaudible soundsHidden audio commands can hijack AI voice assistants and transcription tools without users hearing anything unusual, according to new research set to be presented at the IEEE Symposium on Security and Privacy next week. The study shows that carefully crafted audio clips can elici…CYBERINSIDER.COM
20 MaySteam removes ‘Beyond The Dark’ horror game over malware reportsA malicious game distributed through Steam has been removed from Valve’s platform after users discovered it was secretly harvesting player data and communicating with remote command-and-control infrastructure. The game, titled Beyond The Dark, masqueraded as a free indie horror t…CYBERINSIDER.COM
20 MayWebworm APT targets European government organizations with new backdoorsESET has released an analysis of the 2025 activity of Webworm, a China-aligned APT group tracked as Space Pirates and UAT-8302. Active since at least 2022, the group initially focused on targets in Asia, but has recently expanded its operations into Europe. ESET observed Webworm …HELPNETSECURITY.COM
20 MaySecuring the gaming culture of culturesRead about the unique challenges and rewards of securing gaming platforms and how to better protect gaming communities. The post Securing the gaming culture of cultures appeared first on Microsoft Security Blog .MICROSOFT.COM
19 MayISC Stormcast For Tuesday, May 19th, 2026 https://isc.sans.edu/podcastdetail/9936, (Tue, May 19th)(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.ISC.SANS.EDU
19 MayMicrosoft to Retire Teams Together Mode to Improve PerformanceMicrosoft has announced it will retire the “Together mode” feature in Microsoft Teams, marking a shift toward simplified meeting layouts designed to improve performance, usability, and consistency across devices. The change, confirmed by Microsoft Product Manager Katarina Tranker…GBHACKERS.COM
19 MayJavaScript Malware Campaign Drops Crypto Clipper via PowerShellA large-scale CountLoader campaign that uses layered obfuscation, multi-stage payload delivery, and covert command-and-control (C2) communication to deploy cryptocurrency clipper malware. The campaign stands out for its complex infection chain, combining JavaScript, PowerShell, a…GBHACKERS.COM
19 MayBabel Street targets AI-driven threats with new agentic investigation capabilitiesBabel Street has launched Insights Investigator, a new agentic capability that puts tradecraft-trained AI agents at the front edge of investigative work while ensuring analysts remain in control of scope, logic, and outcomes of their missions. As part of the Babel Street Insights…HELPNETSECURITY.COM
19 MayEgnyte unveils Email Capture and AI features to unify fragmented dataEgnyte has announced a new set of capabilities designed to consolidate fragmented knowledge. Email Capture centralizes critical communications and attachments from siloed inboxes into the Egnyte folder structure, assisting users to make more informed data-driven decisions based o…HELPNETSECURITY.COM
19 MayThe State of AI & AppSec - Keith Hoodlet - ASW #383This year has been a dichotomy of established secure design fundamentals and burgeoning chaos of LLM-driven vuln discovery. Keith Hoodlet returns to share his latest observations on what the recent news about Mythos, models, and harnesses means for appsec. He walks through the pr…YOUTUBE.COM
19 MayDiscord enables E2EE by default for all voice and video communicationsDiscord announced that all voice and video calls on its platform are now protected with end-to-end encryption (E2EE) by default. The rollout applies to direct messages, group calls, voice channels, and Go Live streams, with Stage channels remaining the only exception. Discord fir…CYBERINSIDER.COM
19 MayLaurie Anderson Is Quoting MeNot by name, but Laurie Anderson quotes me in one of the tracks of her new album: My favorite quote is from a cryptologist who said “If you think technology will solve your problems, you don’t understand technology and you don’t understand your problems.” …SCHNEIER.COM
19 MayMicrosoft Edge Enhances Security by Preventing Password Loading at StartupMicrosoft is rolling out a key security change in its Edge browser to stop saved passwords from being loaded into memory as soon as the browser starts. The move comes after a security researcher showed that Edge was decrypting and keeping all stored passwords in cleartext in proc…GBHACKERS.COM
19 MayTop 5 Phishing-Driven Social Engineering Attacks on Companies in 2026Your employees are not falling for “bad grammar” phishing anymore. They are being pulled into fake Microsoft logins, banking pages, AI tool instructions, real OAuth flows, and event invitations that look close enough to daily work to pass without alarm. For CISOs, that is t…ANY.RUN
19 MayAnthropic Denies EU Access to Claude Mythos, ChatGPT 5.5 Comes to RescueAnthropic still hasn’t granted the EU access to Claude Mythos, but OpenAI’s ChatGPT 5.5-Cyber could help the bloc preempt vulnerabilities. The post Anthropic Denies EU Access to Claude Mythos, ChatGPT 5.5 Comes to Rescue appeared first on TechRepublic .TECHREPUBLIC.COM
19 MayVoidStealer Malware Targets Chrome Data Despite Built-In Browser ProtectionsA newly discovered infostealer called VoidStealer is raising concerns after researchers revealed it can bypass Google Chrome’s App-Bound Encryption (ABE), a security feature designed to protect sensitive browser data. The malware introduces a novel technique that allows attackers…GBHACKERS.COM
19 MayLaunchDarkly adds real-time controls for AI agents in productionLaunchDarkly has launched AgentControl, a new solution that gives software teams real-time control over AI agents in production. With AgentControl, teams can change how an agent behaves at runtime without redeploying the underlying application. As AI agents move into production, …HELPNETSECURITY.COM
19 MayCanonical ships Ubuntu Core 26 with 15 years of security maintenanceOperators of industrial sensors, edge AI controllers, and connected medical equipment now have a refreshed long-term Linux option for fleets that must stay patched for more than a decade. Canonical released Ubuntu Core 26, the latest long-term supported version of its minimal, im…HELPNETSECURITY.COM
19 MayNew macOS infostealer impersonates Apple, Microsoft, and Google in a single attack chainA SHub macOS infostealer variant called Reaper impersonates Apple, Microsoft, and Google to trick users into executing malicious code, then targets browser data, password managers, and cryptocurrency wallets while establishing persistence for continued access, SentinelOne found. …HELPNETSECURITY.COM
19 MayThe end of unencrypted Discord calls is hereDiscord has protected voice and video calls in DMs, group DMs, voice channels, and Go Live streams with end-to-end encryption (E2EE) by default. The company began experimenting with E2EE for voice and video in 2023, starting a long-term effort. End-to-end encryption allows only p…HELPNETSECURITY.COM
19 MayMicrosoft’s legacy MSHTA tool heavily abused in malware attacksMicrosoft’s legacy mshta.exe utility remains widely abused in malware campaigns despite the retirement of Internet Explorer and Microsoft’s ongoing deprecation of older scripting technologies. Bitdefender Labs reports a notable rise in detections involving mshta.exe over recent m…CYBERINSIDER.COM
19 MayTwo-Thirds of Nonhuman Accounts Are Unseen and Unmanaged, According to Orchid Security’s Identity Gap ReportNew York, United States, May 19th, 2026, CyberNewswire New research shows identity dark matter continues to expand and erode enterprise identity, resulting in a fragile foundation for agent AI readiness and adoption Orchid Security, the company solving identity at its core, today…GBHACKERS.COM
19 MayWarning: Phishing Attacks Are Abusing the Kuse AI AppAttackers are abusing the storage and sharing features of Kuse, a free AI app, to assist in phishing campaigns, according to researchers at Trend Micro. Kuse is a legitimate agentic AI platform used by employees to streamline workflows. Users can share files with coworkers, which…KNOWBE4.COM
19 MayMozilla hardens Firefox against fingerprinting, adds one-click session wipeMozilla has released Firefox 151, introducing new privacy-focused protections for Private Browsing Mode and stronger anti-fingerprinting defenses. A new “End Private Session” feature for Firefox’s Private Browsing Mode, accessible through a fire-shaped icon next to the address ba…CYBERINSIDER.COM
19 MayCriminal IP Returns to Infosecurity Europe 2026 with Advanced AI-Driven TI & ASMTorrance, United States / California, May 19th, 2026, CyberNewswire Criminal IP has announced its return to Infosecurity Europe 2026 with a focus on delivering more actionable, decision-ready intelligence through its continuously evolving platform. Taking place from June 2 to Jun…GBHACKERS.COM
19 MayAI Isn’t Finding Novel BugsThis discussion highlights a recurring pattern in AI-assisted security research: current systems are effective at identifying known classes of vulnerabilities and established error patterns, but evidence for discovering truly novel vulnerabilities remains limited. This may mean A…YOUTUBE.COM
19 MayMicrosoft Launches New Surface AI PCs for Business BuyersMicrosoft launched new Surface for Business PCs with Intel Core Ultra Series 3 chips, AI features, 5G options, and enterprise security tools. The post Microsoft Launches New Surface AI PCs for Business Buyers appeared first on TechRepublic .TECHREPUBLIC.COM
19 MayAnthropic Just Bought a Developer Tool Used by OpenAI, GoogleAnthropic acquired SDK startup Stainless, signaling a deeper push into developer tooling as AI labs compete beyond model performance. The post Anthropic Just Bought a Developer Tool Used by OpenAI, Google appeared first on TechRepublic .TECHREPUBLIC.COM
19 MayAgentic AI, Strong Racks, Weak Fabric: Inside Dell’s AI BetDell sharpens its AI vision with agentic endpoints, an AI-ready platform, and factory-built racks, but its muted networking story raises questions about how far its AI Factory can scale. The post Agentic AI, Strong Racks, Weak Fabric: Inside Dell’s AI Bet appeared first on TechRe…TECHREPUBLIC.COM
19 MayMac Users Face New Malware Threat Spoofing Apple, Google, and MicrosoftA new SHub Reaper macOS infostealer spoofs prompts from Apple, Google, and Microsoft to steal passwords, crypto data, and business files from Macs. The post Mac Users Face New Malware Threat Spoofing Apple, Google, and Microsoft appeared first on TechRepublic .TECHREPUBLIC.COM
19 MayApple’s Siri Could Get a Grammarly-Like AI Writing Tool at WWDCApple’s iOS 27 may add AI writing tools, prompt-built shortcuts, AI wallpapers, and a smarter Siri as WWDC 2026 approaches in June. The post Apple’s Siri Could Get a Grammarly-Like AI Writing Tool at WWDC appeared first on TechRepublic .TECHREPUBLIC.COM
19 MayApple Intelligence Powers New Accessibility Features for iPhone, MacApple Intelligence will upgrade VoiceOver, Voice Control, captions, and Vision Pro wheelchair controls in new accessibility features coming later this year. The post Apple Intelligence Powers New Accessibility Features for iPhone, Mac appeared first on TechRepublic .TECHREPUBLIC.COM
19 MayMicrosoft Confirms Windows Update Bug Blocking Security FixesMicrosoft confirmed that KB5089549 can fail with error 0x800f0922 on Windows 11 devices with low EFI partition space, and shared workarounds are available. The post Microsoft Confirms Windows Update Bug Blocking Security Fixes appeared first on TechRepublic .TECHREPUBLIC.COM
19 MayMy Mother the Car, AI Slop, Nginx, Polyscope, Drupal, , GitHub, Aaran Leyland - SWN #582My Mother the Car, AI Slop, Nginx, Polyscope, Drupal, GitHub, Aaran Leyland, and More on the Security Weekly News. Visit https://www.securityweekly.com/swn for all the latest episodes! Show Notes: https://securityweekly.com/swn-582YOUTUBE.COM
18 MayProduct showcase: McAfee + ChatGPT integration turns doubt into a scam checkMcAfee + ChatGPT integration brings real-time scam detection in conversations and gives users an easier way to verify suspicious content before clicking or responding. It is available to anyone, without requiring a McAfee or ChatGPT subscription. It combines conversational AI wit…HELPNETSECURITY.COM
18 MayLinux Torvalds Warns AI Bug Report Spam Is Disrupting Linux Security DiscussionsLinux kernel creator Linus Torvald has warned that a flood of low‑value, AI‑generated bug reports is overwhelming the private Linux security mailing list and actively disrupting real security work. The new kernel documentation for Linux 7.1 now explicitly tells AI users to treat …GBHACKERS.COM
18 May1 Million WordPress Websites Exposed by Avada Builder Security VulnerabilitiesA widely used WordPress plugin powering over one million websites has been found vulnerable to two serious security flaws that could expose sensitive data and server files. Security researchers warn that the issues in the Avada Builder plugin could allow both authenticated and un…GBHACKERS.COM
18 MayThe AI backdoor your security stack is not built to seeEnterprises deploying LLMs have spent the past two years building defenses around a reasonable assumption: malicious behavior leaves a trace in the input. Scan for suspicious tokens, filter unusual characters, watch for prompt injection patterns. New research from Microsoft and t…HELPNETSECURITY.COM
18 MayFast16 Malware Sabotages Nuclear Test Simulations by Altering DataA newly analyzed cyber-espionage framework called Fast16 has revealed one of the most precise and covert sabotage operations ever uncovered targeting nuclear weapons simulations by silently manipulating critical test data. Researchers confirm that the malware didn’t just infiltra…GBHACKERS.COM
18 MayHackers Hide PureLogs Infostealer in PawsRunner LoaderThreat actors are increasingly hiding malware inside seemingly harmless files, and a new campaign shows just how effective this tactic has become. The attack begins with a phishing email carrying a TXZ archive attachment. Disguised as an urgent invoice, the file pressures victims…GBHACKERS.COM
18 MayOtterCookie Malware Steals Dev Secrets, SSH Keys, Cloud Credentials, and TokensA newly analyzed malware strain, OtterCookie, is emerging as a serious threat to developers, quietly harvesting sensitive data from active workstations in real time. Unlike earlier assumptions, OtterCookie is not a variant of BeaverTail but a separate Node. js-based remote access…GBHACKERS.COM
18 MayANY.RUN Turns 10: Special Offers for Stronger Security OperationsTen years in cybersecurity is a long journey. Threats have changed, attacks have become harder to spot, and security teams now need answers faster than ever. ANY.RUN has grown with those teams. What started as an interactive sandbox is now a trusted company …ANY.RUN
18 MaySignal begins testing automatic key verification for encrypted chatsSignal has started public testing of a new security feature called “automatic key verification,” designed to simplify confirming end-to-end encrypted conversations without requiring users to manually compare safety numbers. The feature was announced by Signal staff member “jimio”…CYBERINSIDER.COM
18 MayHow a government contest launched a revolution in AI-based bug huntingSecurity researchers have spent months honing AI systems that can find and fix serious vulnerabilities. Critical infrastructure everywhere could benefit.CYBERSECURITYDIVE.COM
18 MaySmartBear expands ReadyAPI with AI-powered API testing capabilitiesSmartBear has announced ReadyAPI’s new AI test generation capability that accelerates API testing by up to 80% while giving teams control to enable or disable AI. While competitors focus on speed alone, ReadyAPI’s AI test generation capability is architected for quality at scale …HELPNETSECURITY.COM
18 MayWhat Is an Al Agent in Cybersecurity?At the Milken Conference in May 2026, Robert F. Smith, founder and CEO of Vista Equity Partners, described a shift that every security leader should hear. Software, he said, has moved through three states: product, then service and now worker. "That agent, that software, act…KNOWBE4.COM
18 MayGrafana Labs says hacker gained access to codebase through leaked tokenThe company, which operates a widely used observability platform, is refusing to pay an extortion demand.CYBERSECURITYDIVE.COM
18 May7 Hidden iPhone Features That Actually Make a DifferenceDiscover hidden iPhone features for messages, photos, accessibility, privacy, call screening, and battery life that make iOS easier to use. The post 7 Hidden iPhone Features That Actually Make a Difference appeared first on TechRepublic .TECHREPUBLIC.COM
18 MayFitbit Bug Leaves Pixel Watch Users Missing Sleep Data AgainPixel Watch users report a Fitbit bug that hides sleep stats on the watch while data still appears in the phone app. The post Fitbit Bug Leaves Pixel Watch Users Missing Sleep Data Again appeared first on TechRepublic .TECHREPUBLIC.COM
18 MayWindows 11 Start Menu, Taskbar Are Getting More CustomizationMicrosoft is testing Windows 11 taskbar and Start menu updates, including movable taskbar positions, cleaner Start controls, and compact layout options. The post Windows 11 Start Menu, Taskbar Are Getting More Customization appeared first on TechRepublic .TECHREPUBLIC.COM
18 MayMozilla calls on UK to exclude VPNs from age verification rulesMozilla urged UK regulators not to impose age restrictions on VPN services, warning that such measures would weaken privacy protections for all users while doing little to prevent minors from bypassing online age checks. In a submission to the UK Department for Science, Innovatio…CYBERINSIDER.COM
18 MayApple’s Siri Revamp May Add Auto-Deleting ChatsApple’s reported Siri revamp may add auto-deleting AI chats as the company prepares a privacy-focused software push at WWDC 2026. The post Apple’s Siri Revamp May Add Auto-Deleting Chats appeared first on TechRepublic .TECHREPUBLIC.COM
18 MayBanned Nvidia AI Chips Keep Reaching China Despite US CrackdownUS export-control cases show how Nvidia chips and other restricted tech are allegedly diverted to China and Russia through shell firms and intermediaries. The post Banned Nvidia AI Chips Keep Reaching China Despite US Crackdown appeared first on TechRepublic .TECHREPUBLIC.COM
18 MayApple’s Fall Lineup Could Include Foldable iPhone, New MacsApple is rumored to have more than 15 products planned for fall, including a foldable iPhone, new Macs, AirPods, Watches, and smart-home devices. The post Apple’s Fall Lineup Could Include Foldable iPhone, New Macs appeared first on TechRepublic .TECHREPUBLIC.COM
18 MayInterpol leads cybercrime crackdown across 13 countries in Middle East, North AfricaOperation Ramz resulted in 201 arrests and disrupted phishing services, malware and financial scams. The post Interpol leads cybercrime crackdown across 13 countries in Middle East, North Africa appeared first on CyberScoop .CYBERSCOOP.COM
18 MayPoland urges officials to ditch Signal for state-run messaging appsPoland’s government is urging public-sector organizations to reduce their reliance on Signal for official communications and instead adopt domestically controlled encrypted messaging systems following a surge in phishing attacks targeting politicians, government personnel, and mi…CYBERINSIDER.COM
18 MayTeamPCP Supply Chain Campaign: Activity Through 2026-05-17, (Mon, May 18th)Since the last update , the TeamPCP supply chain campaign produced its loudest stretch since the March Trivy disclosure: an officially confirmed Checkmarx Jenkins plugin compromise and a new self-spreading Mini Shai-Hulud worm across npm and PyPI.
ISC.SANS.EDU
18 MayFTC: Americans Lost $2.1 Billion to Social Media Scams Last YearA new report from the US Federal Trade Commission (FTC) has found that Americans lost $2.1 billion in 2025 to scams that began on social media. Nearly 30% of people who reported losing money to a scam said it started on social media, far outpacing other modes of contact.KNOWBE4.COM
18 MayHow to better protect your growing business in an AI-powered worldSee how built-in security helps keep your growing business running, protect customer trust, and support growth. The post How to better protect your growing business in an AI-powered world appeared first on Microsoft Security Blog .MICROSOFT.COM
16 MayFriday Squid Blogging: Bigfin SquidArticle about the bigfin squid. As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered. Blog moderation policy.SCHNEIER.COM
16 MayScam papers served.Thomas Elkins, SOC L3 Analyst from BlueVoyant, is discussing "Unpacking Augmented Marauder’s Multi-Pronged Casbaneiro Campaigns." BlueVoyant researchers uncovered a large-scale phishing campaign by the Brazil-linked threat group targeting Spanish-speaking users across Lat…THECYBERWIRE.COM
15 MayNew infosec products of the week: May 15, 2026Here’s a look at the most interesting products from the past week Alation, Apricorn, Versa Networks, and TrustCloud. The questionnaire-based TPRM model is broken, and TrustCloud has a fix TrustCloud announced a new version of TrustLens, its third party risk management (TPRM) solu…HELPNETSECURITY.COM
15 MayISC Stormcast For Friday, May 15th, 2026 https://isc.sans.edu/podcastdetail/9934, (Fri, May 15th)(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.ISC.SANS.EDU
15 MayPopular node-ipc npm Library Hit by Supply Chain Attack, Impacting 822K Weekly DownloadsA widely used npm package with more than 822,000 weekly downloads has once again become the center of a serious supply chain attack, raising fresh concerns across the JavaScript ecosystem. Security researchers at Socket have uncovered multiple malicious versions of the popular no…GBHACKERS.COM
15 MayDeepfake detection is losing ground to generative modelsDeepfake detection has been built around a single question for close to a decade. Given a video or audio clip, is it real or synthetic? Commercial detectors analyze pixels, frequencies, and biometric signals to answer that question, and the best of them post strong accuracy numbe…HELPNETSECURITY.COM
15 MayZombie linkages are keeping expired domains trusted for yearsDomains expire, get transferred, and return to the market every day. The systems connected to those domains can continue trusting the original owner long after control has changed. Researchers at USC and the University of Twente examined this problem in three widely used systems:…HELPNETSECURITY.COM
15 MayMicrosoft Exposes Kazuar Malware’s Modular P2P Botnet ArchitectureMicrosoft has revealed new technical insights into Kazuar, a long-running malware linked to the Russian state-backed group Secret Blizzard, highlighting its evolution into a stealthy, modular peer-to-peer (P2P) botnet designed for persistent cyber espionage. Originally identified…GBHACKERS.COM
15 MayKeycard helps developers secure autonomous AI agents with scoped accessKeycard has announced Keycard for Multi-Agent Apps, extending its platform to support delegated, session-based access across systems of autonomous agents. Keycard lets developers build apps where every agent has its own identity, access is scoped to each task and every action is …HELPNETSECURITY.COM
15 MayTycoon 2FA Operators Use OAuth Device Code Phishing to Bypass MFAA new phishing campaign uncovered in late April 2026 shows how threat actors behind the Tycoon 2FA Phishing-as-a-Service (PhaaS) kit are evolving beyond traditional credential theft. This development comes just weeks after a global takedown effort led by Microsoft and Europol dis…GBHACKERS.COM
15 MayOrBit Rootkit Targets Linux to Steal SSH and Sudo CredentialsHackers are continuing to abuse a stealthy Linux rootkit known as OrBit to harvest SSH and sudo credentials, with new research showing the threat has quietly evolved over four years while remaining active in the wild. First analyzed in 2022, OrBit was initially believed to be a c…GBHACKERS.COM
15 MayThieves unlock stolen iPhones using cheap tools sold on TelegramHelping a friend recover a stolen phone, Infoblox researchers uncovered a thriving Telegram-based underground marketplace selling unlocking tools and phishing infrastructure used to monetize stolen iPhones. Activation Lock can remotely disable a stolen iPhone and prevent normal r…HELPNETSECURITY.COM
15 MayBypassing On-Camera Age-Verification ChecksSome AI-based video age-verification checks can be fooled with a fake mustache .SCHNEIER.COM
15 MayGhostwriter group resumes attacks on Ukrainian Government targetsESET uncovered new Ghostwriter (aka FrostyNeighbor) activity targeting Ukrainian government organizations in a campaign active since March 2026. ESET researchers published a new report documenting fresh activity attributed to the APT group FrostyNeighbor, aka Ghostwriter, active …SECURITYAFFAIRS.COM
15 MayGoogle lets Workspace admins apply one policy across all SAML appsGoogle has updated Context-Aware Access (CAA) in Google Workspace to introduce a default policy assignment for SAML applications. SAML applications are third-party or internal applications that use the Security Assertion Markup Language (SAML) protocol to enable single sign-on (S…HELPNETSECURITY.COM
15 MayTraffic-Themed SMS Phishing Targets Users Around the WorldResearchers at Bitdefender are tracking 40 separate SMS phishing (smishing) campaigns impersonating transport authorities, toll operators, and parking services around the world. The researchers have observed more than 79,000 scam text messages with over 29,000 unique variant…KNOWBE4.COM
15 MayRaising the bar: Quality, shared responsibility, and the future of GitHub’s bug bounty programWe're updating our bug bounty program standards to prioritize quality submissions, clarify shared responsibility boundaries, and evolve how we reward low-risk findings. The post Raising the bar: Quality, shared responsibility, and the future of GitHub’s bug bounty program a…GITHUB.BLOG
15 MayFigure Humanoid Robots Sort Packages Non-Stop in 24/7 DemoFigure AI’s Helix 02 humanoid robots neared 40 hours of autonomous work and almost 50,000 packages in a livestreamed warehouse demo. The post Figure Humanoid Robots Sort Packages Non-Stop in 24/7 Demo appeared first on TechRepublic .TECHREPUBLIC.COM
15 MayGoogle’s Default 15GB Free Storage Is Ending for Some New AccountsGoogle is testing a change that gives some new accounts 5GB by default, with the full 15GB unlocked only after phone verification. The post Google’s Default 15GB Free Storage Is Ending for Some New Accounts appeared first on TechRepublic .TECHREPUBLIC.COM
15 MayMSPs need AI to fight AI-fueled cyberthreats: GuardzEntry points haven’t changed but the speed and scale of attacks have intensified, the security vendor found.CYBERSECURITYDIVE.COM
15 MayWhy Integrate Threat Intelligence Feeds into Email Security?It's getting harder to distinguish legitimate emails from malicious ones as phishing messages mimic real conversations, use trusted domains and increasingly leverage AI to scale and refine attacks.KNOWBE4.COM
15 MayUS Approves Nvidia H200 Sales to China, But Shipments Remain StalledUS approvals could let Nvidia sell H200 AI chips to China, but Beijing’s security concerns and export rules have stalled shipments. The post US Approves Nvidia H200 Sales to China, But Shipments Remain Stalled appeared first on TechRepublic .TECHREPUBLIC.COM
15 MayNew Windows Update May Undo Bad Driver Updates on Its OwnMicrosoft is testing Cloud-Initiated Driver Recovery, a Windows Update feature designed to roll back bad drivers with less manual IT work. The post New Windows Update May Undo Bad Driver Updates on Its Own appeared first on TechRepublic .TECHREPUBLIC.COM
15 MayApple and OpenAI’s ChatGPT Deal Reportedly Risks Legal ClashApple and OpenAI’s AI partnership is reportedly under strain as Siri plans, ChatGPT integration, and OpenAI hardware ambitions collide. The post Apple and OpenAI’s ChatGPT Deal Reportedly Risks Legal Clash appeared first on TechRepublic .TECHREPUBLIC.COM
15 MayOpenAI Warns Mac Users to Update Apps After Supply-Chain AttackOpenAI says Mac users must update ChatGPT, Codex, and Atlas apps by June 12 after an npm supply-chain attack exposed signing certificates. The post OpenAI Warns Mac Users to Update Apps After Supply-Chain Attack appeared first on TechRepublic .TECHREPUBLIC.COM
15 MayColorado governor commutes prison sentence for election denier Tina PetersPeters was sentenced to nine years for stealing voting data and has been publicly unrepentant. But Colorado Governor Jared Polis has been hinting at the decision for months. The post Colorado governor commutes prison sentence for election denier Tina Peters appeared first on Cybe…CYBERSCOOP.COM
14 MayISC Stormcast For Thursday, May 14th, 2026 https://isc.sans.edu/podcastdetail/9932, (Thu, May 14th)(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.ISC.SANS.EDU
14 MayLyrie.ai Unveils Open Standard for Agent Security and Joins Anthropic’s Cyber Verification ProgramDUBAI, UAE — May 14, 2026 — As autonomous AI agents begin to handle everything from corporate bank transfers to sensitive code deployments, the digital world is facing a new “Wild West” scenario: millions of autonomous entities operating without a badge or a passport.…GBHACKERS.COM
14 MayRussian official admits VPNs cannot be fully blocked without breaking the internetA senior Russian official has acknowledged that fully blocking or disabling VPN services in Russia is technically unfeasible, warning that such attempts could severely disrupt the country’s internet infrastructure. The remarks mark one of the clearest public admissions from a Kre…CYBERINSIDER.COM
14 MayTexas sues Netflix for profiling children and selling data to advertisersTexas Attorney General Ken Paxton has filed a sweeping lawsuit against Netflix, accusing the streaming giant of misleading consumers for years while secretly operating what the state describes as a massive behavioral surveillance and advertising system targeting both adults and c…CYBERINSIDER.COM
14 MayAI cyber capability is speeding past earlier projectionsAI cyber capability is improving faster than expected, with newer models surpassing earlier projections, according to the UK government’s AI Security Institute (AISI). AISI measures AI cyber capability using “time horizon benchmarks”, which estimate how long AI systems can comple…HELPNETSECURITY.COM
14 MayVector embedding security gap exposes enterprise AI pipelinesEnterprise adoption of retrieval-augmented generation has moved sensitive corporate content into a new storage format that existing security tools cannot inspect. Companies deploying internal AI assistants convert documents into high-dimensional numerical vectors and ship them to…HELPNETSECURITY.COM
14 MayClosing the AI governance gap in your enterpriseIn this Help Net Security video, Casey Bleeker, CEO at SurePath AI, talks about the AI governance gap that exists in almost every organization. Drawing from three years of conversations with IT, business, and security leaders, Casey explains why AI adoption is outpacing governanc…HELPNETSECURITY.COM
14 May170 npm Packages Hijacked to Steal GitHub, AWS & Kubernetes SecretsHackers have launched a large-scale supply chain attack by compromising more than 170 npm packages and two PyPI libraries, collectively downloaded over 200 million times weekly, to steal sensitive developer and cloud credentials. The malicious npm packages contain a hidden preins…GBHACKERS.COM
14 MayMicrosoft’s WinUI agent plugin trims token use by over 70% during developmentMicrosoft published a plugin on May 13 that lets GitHub Copilot CLI and Claude Code drive the full WinUI 3 development cycle, from project scaffolding through signed MSIX packaging. The WinUI agent plugin ships one agent, eight skills, and several supporting tools targeting the l…HELPNETSECURITY.COM
14 MayHow Dangerous Is Anthropic’s Mythos AI?Last month, Anthropic made a remarkable announcement about its new model, Claude Mythos Preview: it was so good at finding security vulnerabilities in software that the company would not release it to the general public. Instead, it would only be available to a select group of co…SCHNEIER.COM
14 MayKimsuky targets organizations with PebbleDash-based toolsKaspersky researchers analyze a range of new PebbleDash-based tools used in recent Kimsuky campaigns and reveal their connection to the AppleSeed malware cluster.SECURELIST.COM
14 MayCofense adds AI-powered campaign detection to stop phishing attacksCofense has announced new advancements to its Phishing Defense Platform aimed at improving detection and response to AI-powered phishing attacks. The updates include AI-driven phishing detection, enhanced triage automation, and AI-assisted training campaign creation designed to s…HELPNETSECURITY.COM
14 MayWarning: Netflix Phishing Scams Can Lead to Serious ConsequencesResearchers at Bitdefender warn that Netflix-themed phishing attacks can have far-reaching consequences if users follow poor security practices. While Netflix is generally associated with a user’s personal life, phishing attacks targeting personal accounts can put users’ employer…KNOWBE4.COM
14 MayGhostwriter Targets Ukrainian Government With Geofenced PDF Phishing, Cobalt StrikeThe Belarus-aligned threat group known as Ghostwriter has been attributed to a fresh set of attacks targeting governmental organizations in Ukraine. Active since at least 2016, Ghostwriter has been linked to both cyber espionage and influence operations targeting neighboring coun…THEHACKERNEWS.COM
14 MayA spyware investigator exposed Russian government hackers trying to hijack Signal accountsA group of likely Russian government hackers tried to hack a security researcher who investigates spyware attacks. He was then able to turn the tables on the hackers and reveal details of their espionage campaign.TECHCRUNCH.COM
14 MayMustang Panda Linked to Updated FDMTP Backdoor in Asia-Pacific Espionage CampaignMustang Panda campaign deploys updated FDMTP backdoor against Asia-Pacific and Japan networksINFOSECURITY-MAGAZINE.COM
14 MayApple’s iPhone Privacy Feature Expands to More Users WorldwideApple expanded Limit Precise Location in iOS 26.5, but the carrier privacy feature still requires select iPhones and iPads. The post Apple’s iPhone Privacy Feature Expands to More Users Worldwide appeared first on TechRepublic .TECHREPUBLIC.COM
14 MayJeff Bezos’ Blue Origin May Need Outside Cash to Catch SpaceXBlue Origin may seek outside funding for the first time as it looks to scale launches, compete with SpaceX, and expand its space business. The post Jeff Bezos’ Blue Origin May Need Outside Cash to Catch SpaceX appeared first on TechRepublic .TECHREPUBLIC.COM
14 MayLinkedIn Cuts Jobs Despite Revenue Growth as Tech Layoffs Keep SpreadingLinkedIn is cutting jobs and trimming spending across major teams despite revenue growth, as the Microsoft-owned company refocuses priorities. The post LinkedIn Cuts Jobs Despite Revenue Growth as Tech Layoffs Keep Spreading appeared first on TechRepublic .TECHREPUBLIC.COM
14 MayUpcoming Speaking EngagementsThis is a current list of where and when I am scheduled to speak: I’m giving a virtual talk on “The Security of Trust in the Age of AI,” hosted by the Financial Women’s Association of New York , at 6:00 PM ET on May 21, 2026. I’m speaking at the Potsdam Conference on National Cyb…SCHNEIER.COM
14 MayPhishing Attacks Begin Targeting the 2026 FIFA World CupA major phishing operation is targeting soccer/football fans ahead of the 2026 FIFA World Cup, which begins in June, according to researchers at Flare. The attackers have set up at least 79 phishing sites impersonating the official FIFA website.KNOWBE4.COM
14 MayMore money is going to physical security, but it’s often CISOs that oversee it: EYOrganizations should centralize physical security and cybersecurity so both are adequately prepared for, the consulting firm says in a survey report.CYBERSECURITYDIVE.COM
14 MayMicrosoft: Russian hackers evolved Kazuar malware into stealthy P2P botnet“Kazuar,” a long-running malware platform linked to the Russian state-sponsored threat group Secret Blizzard, has evolved into a stealthy peer-to-peer botnet designed for persistent intelligence collection. Microsoft Threat Intelligence reports that Kazuar has transformed from a …CYBERINSIDER.COM
14 May'FrostyNeighbor' APT Carefully Targets Govt Orgs in Poland, UkraineAttackers uniquely fingerprint victims before delivering spear-phishing payloads aimed at espionage, in the latest campaign from the Belarussian nation-state threat group.DARKREADING.COM
14 MayTrump’s China Summit Turns Into a Big Tech Power PlayTrump’s China summit brought Nvidia, Apple, and Tesla leaders into talks shaped by AI chips, trade pressure, and market-access demands. The post Trump’s China Summit Turns Into a Big Tech Power Play appeared first on TechRepublic .TECHREPUBLIC.COM
14 MayTop New Features in Android 17 You’ll Notice This YearGoogle previewed Android 17 with Gemini AI tools, AirDrop-style sharing, privacy upgrades, multitasking changes, and stronger security controls. The post Top New Features in Android 17 You’ll Notice This Year appeared first on TechRepublic .TECHREPUBLIC.COM
14 MayMicrosoft Retires ‘Copilot Mode’ as Edge Gets Built-In AI ToolsMicrosoft is retiring “Copilot Mode” in Edge as it builds AI browsing tools directly into Edge on desktop and mobile. The post Microsoft Retires ‘Copilot Mode’ as Edge Gets Built-In AI Tools appeared first on TechRepublic .TECHREPUBLIC.COM
14 May KEVKevin O’Leary’s ‘Wonder Valley’ Data Center Advances as Job Estimates ShiftKevin O’Leary’s Wonder Valley data center project faces scrutiny as job estimates shift and Utah residents raise environmental concerns. The post Kevin O’Leary’s ‘Wonder Valley’ Data Center Advances as Job Estimates Shift appeared first on TechRepublic .TECHREPUBLIC.COM
14 MayWhite House cyber official: identity security matters more than ever in the age of AIWhile AI tools present unique cybersecurity threats, they still rely on poor identity security by organizations to do the most damage, a White House official said Thursday. The post White House cyber official: identity security matters more than ever in the age of AI appeared fir…CYBERSCOOP.COM
14 MaySecurityScorecard Snags Driftnet to Level Up Threat IntelligenceThe new acquisition looks to boost visibility into third-party ecosystems that are becoming a bigger concern as vectors for supply-chain attacks.DARKREADING.COM
14 MayDefense in depth for autonomous AI agentsAs AI agents gain autonomy, defense in depth must evolve, with application-layer design, identity, and human oversight at the center. The post Defense in depth for autonomous AI agents appeared first on Microsoft Security Blog .MICROSOFT.COM
14 MayKazuar: Anatomy of a nation-state botnetKazuar, a sophisticated malware family attributed to the Russian state actor Secret Blizzard, has been under constant development for years and continues to evolve in support of espionage-focused operations. Over time, Kazuar has expanded from a relatively traditional backdoor in…MICROSOFT.COM
13 MayISC Stormcast For Wednesday, May 13th, 2026 https://isc.sans.edu/podcastdetail/9930, (Wed, May 13th)(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.ISC.SANS.EDU
13 MayAndroid pushes new scam, theft, and AI protections in 2026 update wavePhone scammers spoofing bank caller IDs have driven an estimated $980 million in annual losses worldwide, according to Europol. Android’s 2026 security roadmap takes direct aim at that pattern with a verified call system built in partnership with banks, alongside a wider se…HELPNETSECURITY.COM
13 MayThe hidden risk of non-human identities in AI adoptionAn employee with persistent, unsupervised admin access across critical systems, with no audit trail, no clear owner, and no regular access reviews, would raise immediate concern in most organizations. Yet non-human identities and AI agents are often granted that same kind of pers…HELPNETSECURITY.COM
13 MayFake FinalShell and Xshell Sites Push Kong RAT MalwareHackers are abusing fake download sites for popular tools like FinalShell and Xshell to deliver a new remote access trojan known as Kong RAT, in a highly staged and stealthy campaign that ran from at least May 2025 through March 2026. In this campaign, attackers poisoned search e…GBHACKERS.COM
13 MayProton Pass rated “well above par” in independent security auditProton Pass password manager has passed an independent security audit conducted by Recurity Labs, that described the product’s overall security posture as “well above par.” The audit, commissioned by Proton and carried out between January and April 2026, examined the Proton Pass …CYBERINSIDER.COM
13 MayOpenAI’s GPT-5.5 is as Good as Mythos at Finding Security VulnerabilitiesThe UK’s AI Security Institute evaluated GPT-5.5’s ability to find security vulnerabilities, and found that it is comparable to Claude Mythos. Note that the OpenAI model is generally available. Here is the Institute’s evaluation of Mythos. And here is an analysi…SCHNEIER.COM
13 MayLW ROUNDTABLE: Microsoft Edge normalizes credential exposure — security pros push backBy design. Two words that have done an awful lot of heavy lifting in the cybersecurity industry over the years. They tend to surface whenever a vendor wants to wave off a serious finding without fixing it. Related: The unending … (more…) The post LW ROUNDTABLE: Microsoft Ed…LASTWATCHDOG.COM
13 MayAndroid adds ‘Intrusion Logging’ system to detect spyware attacksGoogle has unveiled a new Android security feature called “Intrusion Logging,” a forensic logging system designed to help investigators detect spyware attacks and infections on mobile devices. The capability is rolling out as part of Android Advanced Protection Mode (AAPM) and wa…CYBERINSIDER.COM
13 MayAI Agents Generate Custom Hacking Tools on the FlyTwo threat campaigns heavily leveraged AI agents to support attacks against entities in Mexico and Brazil.DARKREADING.COM
13 MayChina's 'FamousSparrow' APT Nests in South Caucasus Energy FirmThe cyberthreat group targets an Azerbaijani oil and gas firm with repeated attacks, as the China-linked actors extend targeting beyond hospitality, telecom, and government sectors.DARKREADING.COM
13 MayThe Rise of Cyber Threats and AI in the Philippines: A New Era Beyond Legacy SecurityIntroduction The Philippines, like many other nations, is witnessing a dramatic increase in cyber threats, fueled by the rapid adoption of digital technologies and the proliferation of sophisticated cybercriminals. This article examines the evolution of cyber threats in the Phili…KNOWBE4.COM
13 MayDaybreak is OpenAI’s answer to the AI arms race in cybersecurityWith Daybreak, OpenAI is taking direct aim at Anthropic's tightly restricted Mythos model, offering a more open — but still carefully gated — path to AI-powered cyber defense. The post Daybreak is OpenAI’s answer to the AI arms race in cybersecurity appeared first on CyberS…CYBERSCOOP.COM
13 MayOpenAI launches Daybreak to combat cyber threatsThe cybersecurity initiative uses AI to detect software vulnerabilities, partnering with Cloudflare, Cisco and CrowdStrike to counter threats.CYBERSECURITYDIVE.COM
13 MayWhatsApp adds Incognito Chat for private Meta AI conversationsThe company launched Incognito Chat with Meta AI, a feature that lets users hold AI conversations the platform itself cannot read. The rollout will reach WhatsApp and the standalone Meta AI app over the coming months. How Incognito Chat works Incognito Chat runs on top of Meta…HELPNETSECURITY.COM
13 MayWeaponized AI: The new frontier of fraud and identity spoofingAs fake identity fraud is projected to cause $40 billion in losses next year, leaders must abandon static security in favor of rapid-iteration, AI-enabled defenses that adapt in days, not months. The post Weaponized AI: The new frontier of fraud and identity spoofing appeared fir…CYBERSCOOP.COM
13 MayGoogle Introduces Googlebook, a Gemini-First Laptop PlatformGooglebook brings Gemini Intelligence, Magic Pointer, Android app support, phone integration, and premium hardware to Google’s new laptop platform. The post Google Introduces Googlebook, a Gemini-First Laptop Platform appeared first on TechRepublic .TECHREPUBLIC.COM
13 MayTIOBE Index for May 2026: R Ascends as Statistical Tools ConsolidateMay 2026 TIOBE Index keeps Python #1 as Java edges past C++. R climbs to #8, and Paul Jansen says statistical tools are consolidating around Python and R. The post TIOBE Index for May 2026: R Ascends as Statistical Tools Consolidate appeared first on TechRepublic .TECHREPUBLIC.COM
13 MayDOJ releases legal rationale for nationwide voter data collectionThe memo claims a robust executive branch role vetting voter eligibility. One Secretary of State called it a “fantasy” that “isn’t worth the paper it’s printed on.” The post DOJ releases legal rationale for nationwide voter data collection appeared first on CyberScoop .CYBERSCOOP.COM
13 MayWhatsApp launches “Incognito Chat” for private AI conversationsMeta has announced “Incognito Chat with Meta AI,” a new private AI chat mode for WhatsApp and the Meta AI app. The feature is built on the firm’s existing “Private Processing” infrastructure and is designed for sensitive AI interactions involving personal, financial, health, or w…CYBERINSIDER.COM
13 MayAI Won’t Invent the FutureBen Carr argues that most AI systems — especially LLMs — are exceptional at processing and reusing existing information, but not necessarily creating fundamentally new approaches. They can optimize workflows, summarize knowledge, and accelerate execution. But true process inventi…YOUTUBE.COM
13 MayAttackers Weaponize RubyGems for Data Dead DropsThreat actors are publishing RubyGems packages that include scrapers targeting public-facing UK government servers, but with no clear objective.DARKREADING.COM
13 MayResearchers say AI just broke every benchmark for autonomous cyber capabilityTwo independent studies found that Anthropic's Claude Mythos Preview and OpenAI's GPT-5.5 have outpaced every trend line researchers were tracking. No one is sure if this is a one-time leap or the new normal. The post Researchers say AI just broke every benchmark for autonomous c…CYBERSCOOP.COM
13 MayClosed briefing sets stage for House hearing on Anthropic’s Mythos and cyber risksThe committee held a closed briefing Wednesday with company reps, and more oversight is in the works. The post Closed briefing sets stage for House hearing on Anthropic’s Mythos and cyber risks appeared first on CyberScoop .CYBERSCOOP.COM
12 MayISC Stormcast For Tuesday, May 12th, 2026 https://isc.sans.edu/podcastdetail/9928, (Tue, May 12th)(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.ISC.SANS.EDU
12 MayThe hidden smart fridge risks that emerge years after purchaseHousehold refrigerators are built to last more than a decade. The software, cloud services, and mobile apps that control them are not. A new analysis from Erik Buchmann at Leipzig University maps what happens when those two timelines collide, and the findings reach further than t…HELPNETSECURITY.COM
12 MayCybersecurity jobs available right now: May 12, 2026Application Security Engineer Total Quality Logistics | USA | On-site – View job details As an Application Security Engineer, you will design, implement, and maintain security controls across the software development lifecycle. You will work closely with engineeri…HELPNETSECURITY.COM
12 MayTrickMo Android Malware Targets Banking, Wallet, and Authenticator AppsTrickMo, the Android banking malware, has resurfaced with a significantly redesigned architecture, targeting banking, fintech, wallet, and authenticator applications while introducing advanced stealth and network capabilities. Rather than introducing entirely new user-facing func…GBHACKERS.COM
12 MayMini Shai-Hulud Worm Compromises TanStack, Mistral AI, Guardrails AI & More PackagesTeamPCP, the threat actor behind the recent supply chain attack spree, has been linked to the compromise of the npm and PyPI packages from TanStack, UiPath, Mistral AI, OpenSearch, and Guardrails AI as part of a fresh Mini Shai-Hulud campaign. The affected npm packages have …THEHACKERNEWS.COM
12 MayFake TronLink Chrome Extension Steals Crypto Wallet CredentialsA newly uncovered phishing campaign is targeting TRON wallet users through a deceptive Chrome extension that mimics the popular TronLink wallet. The campaign highlights how modern browser extension abuse is evolving beyond static code inspection, making detection significantly ha…GBHACKERS.COM
12 MayNorth Korea Hackers Abuse Git Hooks to Deploy Cross-Platform MalwareNorth Korean threat actors have introduced a stealthy new delivery mechanism in their ongoing “Contagious Interview” campaign, shifting tactics to abuse Git hooks for malware execution. The attack begins with a familiar social engineering lure. Victims, often developers targeted …GBHACKERS.COM
12 MayAI is separating the companies built to scale from the ones built to sellStartups are scaling faster, attackers are getting smarter, and investors are getting more selective. The cybersecurity industry is in the middle of a reset. The post AI is separating the companies built to scale from the ones built to sell appeared first on CyberScoop .CYBERSCOOP.COM
12 MayThe Civil War Spies and Saboteurs Across the Canadian BorderIt’s 1864, and against the backdrop of the US Civil War- a war the Confederacy is losing- a group of spies and saboteurs have set up a base in Montreal, Canada. Today we would call this a sanctuary or a safe haven. Canada would become home to several infamous Confederate missions…THECYBERWIRE.COM
12 MaySignal rolls out new protections against impersonation attacksSignal has announced a new set of in-app protections designed to help users identify phishing attempts and social engineering scams on the encrypted messaging platform. The changes introduce additional warning prompts, profile verification notices, and expanded safety guidance to…CYBERINSIDER.COM
12 MayVidar Stealer Campaign Evades EDR to Steal CredentialsA new Vidar Stealer campaign is abusing trusted tools, multi‑stage loaders, and heavy obfuscation to bypass EDR visibility and steal credentials from infected systems silently. This operation shows a clear shift toward “living‑off‑the‑land” techniques and stealthy backdoor archit…GBHACKERS.COM
12 MayAI and an absent government: Takeaways from RSAC 2026Cybersecurity professionals spent the recent conference discussing the balance between autonomy and oversight.CYBERSECURITYDIVE.COM
12 MayCyberheistNews Vol 16 #19 Crafty Criminals Continue to Pose as Help Desks in Social Engineering AttacksKNOWBE4.COM
12 MayGeneral Motors to pay $12.75 million over driver data salesGeneral Motors has agreed to a $12.75 million settlement with California over allegations that it unlawfully sold drivers’ location and behavioral data to brokers, marking the largest penalty in the history of the state’s Consumer Privacy Act. Prosecutors say GM made …HELPNETSECURITY.COM
12 MayDownload: The IT and security field guide to AI adoptionSecurity and IT teams are under pressure to adopt AI, but many are seeing the opposite of what was promised. Tools that demo well don’t hold up in real workflows. Complexity increases. Trust breaks down. And instead of reducing workload, AI can introduce new risks and oversight b…HELPNETSECURITY.COM
12 MayAI Can’t Detect Malicious IntentRob Allen describes a limitation in AI systems: they do not reliably understand user intent. A request may be rejected when framed explicitly as malicious, but accepted when reframed in a neutral or technical way that produces a similar outcome. This creates inconsistent behavior…YOUTUBE.COM
12 MayThis Samsung 4TB Portable SSD Moves Files at 2,000 MB/s For $1KThe Samsung T9 delivers read and write speeds of up to 2,000 MB/s, making large file transfers feel instant. The post This Samsung 4TB Portable SSD Moves Files at 2,000 MB/s For $1K appeared first on TechRepublic .TECHREPUBLIC.COM
12 MayVeeam Intelligent ResOps unifies data context and recoveryVeeam Software announced Veeam Intelligent ResOps, a new solution that unifies data context and recovery operations. As agentic AI accelerates change at machine speed, Intelligent ResOps gives teams the insight they need into their data to quickly understand impact and recover pr…HELPNETSECURITY.COM
12 MayFIRESIDE CHAT: Cyber insurers deepen SMB security role as supply chain attacks spreadThe cyber insurance industry set out to manage financial risk. Along the way, it has quietly became the security operations provider for a significant share of American small businesses. An $11 billion acquisition agreement announced earlier this year suggests it … (more…) …LASTWATCHDOG.COM
12 MayThreatDown ITDR prevents credential-based attacksThreatDown, the former corporate business unit of Malwarebytes, launched ThreatDown Identity Threat Detection and Response (ITDR). ITDR is a new product that helps security teams monitor identities to detect suspicious activity, misconfigurations, and active attacks targeting use…HELPNETSECURITY.COM
12 MaySAP unveils Autonomous Enterprise for AI-driven business operationsSAP introduced the Autonomous Enterprise to help enhance the world’s most critical business workflows, so that humans and AI work together to meet the accelerating demands of global business profitably, strategically and safely. “For the mission-critical processes of our customer…HELPNETSECURITY.COM
12 MayGoogle and Amnesty International teamed up to make it harder for spyware vendors to hideIntrusion Logging marks the first feature from a major device vendor to aid with forensic detection of sophisticated threats, Amnesty International said. The post Google and Amnesty International teamed up to make it harder for spyware vendors to hide appeared first on CyberScoop…CYBERSCOOP.COM
12 MayOver 1 Million Baby Monitors, Security Cameras Exposed Through Meari FlawsMeari IoT flaws reportedly exposed baby monitor images, camera activity, and device data across more than 1 million connected devices. The post Over 1 Million Baby Monitors, Security Cameras Exposed Through Meari Flaws appeared first on TechRepublic .TECHREPUBLIC.COM
12 MaySamsung Galaxy Watch Glucose Tracking: What Works Now and What Doesn’tSamsung Galaxy Watch can show compatible CGM glucose data today while Samsung works on future non-invasive blood sugar tracking features. The post Samsung Galaxy Watch Glucose Tracking: What Works Now and What Doesn’t appeared first on TechRepublic .TECHREPUBLIC.COM
12 May6 Best ChatGPT Photo Editing Trends in 2026 (With Prompts to Try)Explore the biggest ChatGPT photo editing trends of 2026, from caricatures and toy-style portraits to nostalgic film edits and AI collages. The post 6 Best ChatGPT Photo Editing Trends in 2026 (With Prompts to Try) appeared first on TechRepublic .TECHREPUBLIC.COM
12 MayTomato, JDownloader, TempPCP, Bad Vibes, Dirty Frag, Giedi Prime, Aaran Leyland - SWN #580Tomato, JDownloader, TempPCP, Bad Vibes, Dirty Frag, Marketing, Shai Haluds, Giedi Prime, Aaran Leyland, and More on the Security Weekly News. Visit https://www.securityweekly.com/swn for all the latest episodes! Show Notes: https://securityweekly.com/swn-580YOUTUBE.COM
12 MayFedora Hummingbird brings the container security model to a Linux host OSContainer image security pipelines have spent the past several years pushing toward minimal footprints, hermetic builds, and continuous CVE remediation. The Fedora Project is now applying that same approach to the host operating system. At Red Hat Summit 2026, Fedora announced Fe…HELPNETSECURITY.COM
11 MayISC Stormcast For Monday, May 11th, 2026 https://isc.sans.edu/podcastdetail/9926, (Mon, May 11th)(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.ISC.SANS.EDU
11 MayTop 10 Best Secure Code Review Services For Developers in 2026In the rapidly evolving landscape of software development, where speed and agility often take precedence, the imperative for robust security cannot be overstated. With cyber threats becoming increasingly sophisticated and the attack surface expanding due to complex architectures …GBHACKERS.COM
11 MayTop 10 Best DevSecOps Companies For Secure SDLC 2026In the fast-paced world of software development, where agility and speed are paramount, security often struggles to keep pace. The traditional “bolt-on” security approach, where security checks are performed at the end of the Software Development Life Cycle (SDLC), is…GBHACKERS.COM
11 MayCheckmarx Jenkins Plugin Backdoored in New TeamPCP Supply Chain AttackCheckmarx Jenkins Plugin Backdoored in New TeamPCP Supply Chain Attack It hasn’t been long since TeamPCP made headlines for compromising Checkmarx’s GitHub Actions and OpenVSX extensions as part of a sprawling supply chain campaign. Now the same threat actor is back; and this tim…SOCRADAR.IO
11 MayOpenClaw Malware Targets Crypto Wallets and Bitwarden CredentialsOpenClaw users are being targeted in a fresh malware campaign that abuses a fake installer to steal credentials from popular crypto wallets and password managers, including MetaMask, Phantom, and Bitwarden. The archive contains a 130MB Rust executable padded with fake documentati…GBHACKERS.COM
11 MayThe missing cybersecurity leader in small businessAs AI and quantum threats target the backbone of the American economy, Washington must provide the guidance and incentives necessary for SMBs to access executive-level cyber expertise. The post The missing cybersecurity leader in small business appeared first on CyberScoop .CYBERSCOOP.COM
11 MayFake Claude Campaign Uses PlugX-Style DLL Sideloading ChainHackers are abusing a fake Claude AI download site to deliver a PlugX‑style DLL sideloading chain that ultimately deploys a new Windows backdoor dubbed “Beagle.” The campaign blends malvertising, a trojanized installer, and signed security software components to achieve stealthy …GBHACKERS.COM
11 MayTrending Hugging Face Repo With 200K Downloads Spreads Windows MalwareA malicious Hugging Face repository, Open-OSS/privacy-filter, that abused the platform’s trust and trending algorithm to deliver a sophisticated Rust-based infostealer to Windows users. The project briefly reached the #1 trending position with roughly 244,000 downloads and hundre…GBHACKERS.COM
11 MaySandboxie Escape Flaw Could Let Attackers Gain SYSTEM-Level PrivilegesSecurity researchers have exposed critical sandbox escape vulnerabilities in Sandboxie and Sandboxie-Plus that allow attackers to gain full SYSTEM-level privileges. We strongly urge users to update to version 1.17.5, which was recently patched, to mitigate these severe execution …GBHACKERS.COM
11 MayInstagram messaging encryption removed, and privacy advocates are pushing backAfter introducing optional end-to-end encrypted messaging in 2023, Instagram announced in March 2026 that encryption for direct messages would be discontinued, and the feature was removed on May 8. The change allows Instagram to access direct message content, including images, vi…HELPNETSECURITY.COM
11 MayThe questionnaire-based TPRM model is broken, and TrustCloud has a fixTrustCloud announced a new version of TrustLens, its third party risk management (TPRM) solution. The new TrustLens agentic AI capabilities focus on delivering four requirements every CISO wants in their TPRM program: speed, accuracy, coverage, and proactive risk mitigation. In t…HELPNETSECURITY.COM
11 MayLLMs and Text-in-Text SteganographyTurns out that LLMs are really good at hiding text messages in other text messages.SCHNEIER.COM
11 MayNew cybersecurity industry alliance aims to lead US critical infrastructure protectionThe new Alliance for Critical Infrastructure’s biggest goal: changing how the U.S. plans for a major cybersecurity crisis.CYBERSECURITYDIVE.COM
11 MayPython Infostealer Hides in GitHub Releases to Bypass DetectionA stealthy Python-based infostealer campaign that abuses GitHub Releases to host payloads and maintain long-term, low‑visibility access to victim systems. The operation, dubbed “Operation HumanitarianBait” in some reporting, appears designed for cyberespionage against Russian‑spe…GBHACKERS.COM
11 MaySailPoint Agentic Fabric expands identity governance to autonomous AI agentsSailPoint has introduced SailPoint Agentic Fabric, a new platform designed to help enterprises secure AI agents and other non-human identities at scale. As organizations deploy autonomous AI agents across cloud environments, applications, and endpoints, they face a growing govern…HELPNETSECURITY.COM
11 MayGoogle’s new reCAPTCHA system restricts access to the open webGoogle’s latest reCAPTCHA changes are drawing backlash from privacy advocates and developers of alternative mobile operating systems, who argue the system effectively locks users out of websites unless they use Google-approved devices and software. The controversy centers on Goog…CYBERINSIDER.COM
11 MayLyrie.ai Joins First Batch of Anthropic’s Cyber Verification ProgramDubai, UAE, May 11th, 2026, CyberNewswire Dubai-founded OTT Cybersecurity LLC also unveils the Agent Trust Protocol (ATP), the first open cryptographic standard for AI agent identity, scope, and action verification — slated for IETF submission. OTT Cybersecurity LLC, the company …GBHACKERS.COM
11 MayApple, Intel Reportedly Near Chip Deal That Could Reduce TSMC RelianceApple and Intel reportedly reached an early chip manufacturing agreement that could reduce Apple’s TSMC reliance and boost Intel’s foundry ambitions. The post Apple, Intel Reportedly Near Chip Deal That Could Reduce TSMC Reliance appeared first on TechRepublic .TECHREPUBLIC.COM
11 MayMicrosoft’s Voluntary Retirement Offer: New Details Reveal Who QualifiesMicrosoft is offering longtime US employees severance, healthcare, and stock vesting through its first voluntary retirement program. The post Microsoft’s Voluntary Retirement Offer: New Details Reveal Who Qualifies appeared first on TechRepublic .TECHREPUBLIC.COM
11 MayYour Team of 10 Gets This AI Project Management Platform for Just $99Lyra combines issue tracking, sprints, Kanban, Gantt charts, and AI assistance for teams of up to 10 users. The post Your Team of 10 Gets This AI Project Management Platform for Just $99 appeared first on TechRepublic .TECHREPUBLIC.COM
11 MaySS&C Intralinks FundCentre AI vs. Juniper Square: Which platform better supports modern private markets fund managers?As private markets firms expand beyond single-asset strategies, platform limitations become more visible. FundCentre AI and Juniper Square take different approaches to scale, reporting, and operational efficiency. The post SS&C Intralinks FundCentre AI vs. Juniper Square: Wh…TECHREPUBLIC.COM
11 MaymacOS 27 May Get a New Look: Here’s What Apple Could ChangeApple’s reported macOS 27 redesign may reveal how far the company is willing to adjust Liquid Glass after Tahoe’s rocky debut. The post macOS 27 May Get a New Look: Here’s What Apple Could Change appeared first on TechRepublic .TECHREPUBLIC.COM
11 MayEntries now open for the 2026 CSO30 Australia AwardsNominations are now open for the 2026 CSO30 Australia Awards , celebrating the country’s most effective and influential cybersecurity leaders. The CSO30 Awards will once again be held alongside the CIO50 Award s, bringing together Australia’s leading technology and security execu…CSOONLINE.COM
11 MayNews Alert: Lyrie.ai joins Anthropic verification program, unveils protocol for securing AI agentsDUBAI, United Arab Emirates, May 11, 2026, CyberNewswire—Dubai-founded OTT Cybersecurity LLC today announced acceptance into Anthropic’s Cyber Verification Program and unveiled the Agent Trust Protocol (ATP), an open cryptographic standard for AI agent identity, scope and action …LASTWATCHDOG.COM
11 MayTikTok Launches £3.99 Ad-Free Plan for UK UsersTikTok is rolling out a £3.99 ad-free subscription in the UK, giving adults a paid option while keeping its free ad-supported feed in place. The post TikTok Launches £3.99 Ad-Free Plan for UK Users appeared first on TechRepublic .TECHREPUBLIC.COM
11 MayMac Users Warned Over Fake Claude Install InstructionsHackers are using Google Ads and Claude shared chats to target Mac users with fake setup instructions that can install malware. The post Mac Users Warned Over Fake Claude Install Instructions appeared first on TechRepublic .TECHREPUBLIC.COM
11 May1.8 Billion Gmail Users May Want to Check This AI Privacy SettingGoogle’s new Gmail AI personalization features are raising privacy concerns. Here’s what users should know and how to review smart settings. The post 1.8 Billion Gmail Users May Want to Check This AI Privacy Setting appeared first on TechRepublic .TECHREPUBLIC.COM
11 MayFCC moves to impose “Know Your Customer” rules for VoIP providersThe Federal Communications Commission (FCC) has proposed stricter “Know Your Customer” (KYC) requirements for voice service providers as part of a broader effort to stop illegal robocalls before they enter US telecommunications networks. The proposal would require providers to pe…CYBERINSIDER.COM
11 MayiOS 26.5 is out, bringing encrypted RCS messaging to iPhone and Android usersApple is bringing long-awaited end-to-end encryption to Rich Communication Services (RCS) messaging between iPhone and Android users in iOS 26.5. The feature is launching in beta for iPhone users running iOS 26.5 on supported carriers and Android users using the latest version of…HELPNETSECURITY.COM
11 MayPressure mounts on Canvas as data leak extortion deadline loomsAttackers affiliated with The Com are threatening to leak data from more than 8,800 school systems if Instructure doesn’t pay a ransom. The post Pressure mounts on Canvas as data leak extortion deadline looms appeared first on CyberScoop .CYBERSCOOP.COM
10 MayYARA-X 1.16.0 Release, (Sun, May 10th)YARA-X&#;x26;#;39;s 1.16.0 release brings 4 improvements and 4 bugfixes.
ISC.SANS.EDU
9 MayThe spy who logged me in.Mark Kelly, Staff Threat Researcher at Proofpoint, is discussing their work on "I’d come running back to EU again: TA416 resumes European government espionage campaigns." China-linked threat group TA416 has resumed large-scale phishing and malware campaigns targeting European…THECYBERWIRE.COM
9 MayTCLBANKER Malware Leverages WhatsApp and Outlook Worm Features in Active AttacksA sophisticated Brazilian banking trojan named TCLBANKER, deployed through a trojanized Logitech installer and capable of hijacking victims’ WhatsApp and Outlook accounts to spread itself to new targets. The campaign, tracked as REF3076, delivers TCLBANKER through a malicio…GBHACKERS.COM
9 MayAI Coding Agents Need SandboxesThe speaker argues that AI coding agents should be treated like privileged automation systems, not harmless autocomplete tools. Recommended controls include containerization, disposable workspaces, restricted network access, detailed process logging, and manual review of configur…YOUTUBE.COM
8 MayISC Stormcast For Friday, May 8th, 2026 https://isc.sans.edu/podcastdetail/9924, (Fri, May 8th)(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.ISC.SANS.EDU
8 MayNew infosec products of the week: May 8, 2026Here’s a look at the most interesting products from the past week LastPass, Operant AI, Sysdig, and VIAVI. Operant AI Endpoint Protector secures AI agents and MCP tools Operant AI has launched Operant Endpoint Protector, a new addition to its AI Defense Platform that enables ente…HELPNETSECURITY.COM
8 MayYour coworker might be selling company logins, and thinks it’s fineEmployee behavior once considered unacceptable is becoming tolerated across various industries, particularly in IT and telecommunications, and at all levels of seniority, including leadership. Cifas Workplace Fraud Trends research, based on a survey of 2,000 UK employees working …HELPNETSECURITY.COM
8 MayNew Infostealer Campaign Abuses GitHub Releases to Hide Malware PayloadsA new cyberespionage campaign that abuses GitHub Releases and a PE-less Python implant to steal data from targeted Windows systems quietly. The operation combines social engineering, trusted cloud infrastructure, and multi-stage obfuscation to maintain long-term, covert access to…GBHACKERS.COM
8 MayPCPJack Worm Targets Docker, Kubernetes, Redis, and MongoDB CredentialsA newly identified malware framework dubbed PCPJack is targeting exposed cloud and container infrastructure to steal credentials at scale while actively removing artifacts linked to the TeamPCP threat actor. Unlike typical cloud-focused campaigns, PCPJack skips cryptomining entir…GBHACKERS.COM
8 MayTransilience AI unveils Security Operating System for cloud remediationTransilience AI has announced the general availability of its Full Stack Security Operating System for the cloud, platform designed to solve one of enterprise security’s most persistent challenges: bridging the gap between detection and remediation. New platform replaces fragment…HELPNETSECURITY.COM
8 MayObject First Fleet Manager simplifies distributed backup storageObject First released Object First Fleet Manager, a cloud-based service that simplifies the management of distributed Ootbi backup storage deployments for Veeam Software environments. Built for enterprises and service providers with distributed backup storage infrastructures, Fle…HELPNETSECURITY.COM
8 MayRoblox chat moderation gets bypassed by leet speak and code wordsRoblox runs an automated chat filter at the scale of billions of messages per day. An independent audit of about two million chat messages from four of the platform’s most popular games shows that filter missing a wide range of harmful interactions, including grooming attem…HELPNETSECURITY.COM
8 MaySigned Logitech Installer Abused to Drop TCLBANKER Banking TrojanHackers are abusing a signed Logitech installer to stealthily deploy a new Brazilian banking trojan known as TCLBANKER, giving threat actors a powerful tool to steal financial data and self‑propagate through popular communication platforms. The malware specifically targets Brazil…GBHACKERS.COM
8 MaySecuronix launches AI threat research agent and ThreatWatch validation toolSecuronix announced the Securonix Threat Research Agent and ThreatWatch for ThreatQ, expanding how security teams research threats, validate exposure, and turn intelligence into documented action. Built on the ThreatQ platform and connected to Securonix security operations workfl…HELPNETSECURITY.COM
8 MayOpenAI tunes GPT-5.5-Cyber for more permissive security workflowsOpenAI is rolling out GPT-5.5-Cyber, a variant of its latest AI model, in limited preview for verified cybersecurity professionals and organizations through its Trusted Access for Cyber program. Trusted Access for Cyber is OpenAI’s identity and trust-based access framework for cy…HELPNETSECURITY.COM
8 MayZiChatBot Malware Abuses Zulip APIs for Stealthy C2 OperationsA new cross‑platform malware family, dubbed ZiChatBot, that abuses the trusted Python Package Index (PyPI) ecosystem and the Zulip team chat platform to run a stealthy command‑and‑control (C2) channel. During routine threat hunting, analysts observed a series of malicious wheel p…GBHACKERS.COM
8 MayGoogle is turning Android Studio into a policy watchdogGoogle has expanded Play Policy Insights in Android Studio to help developers catch policy issues while coding, including warnings for common problems such as missing login credentials. Later this year, developers who connect their Play developer account directly to Android Studi…HELPNETSECURITY.COM
8 MayModular RAT Campaign Steals Credentials and Captures ScreenshotsA sophisticated spear-phishing campaign, dubbed Operation GriefLure, targeting senior executives in Vietnam and the Philippines with a stealthy modular remote access trojan (RAT). The campaign focuses on high-value organizations, including Viettel Group Vietnam’s largest military…GBHACKERS.COM
8 MayFake OpenClaw Installer Targets Crypto Wallets and Password ManagersHackers are abusing a fake OpenClaw installer to deploy a modular Rust-based infostealer framework dubbed Hologram, aimed at harvesting credentials from more than 250 crypto wallet and password manager browser extensions while hiding behind trusted cloud and messaging services. T…GBHACKERS.COM
8 MayFlaw in Claude’s Chrome extension allowed ‘any’ other plugin to hijack victims’ AIAgentic AI is more popular than ever, but researchers keep finding trivial ways to hijack LLMs for nefarious purposes. The post Flaw in Claude’s Chrome extension allowed ‘any’ other plugin to hijack victims’ AI appeared first on CyberScoop .CYBERSCOOP.COM
8 MaySOCRadar Recognized in the 2026 Gartner® Magic Quadrant™ for Cyberthreat Intelligence TechnologiesSOCRadar Recognized in the 2026 Gartner® Magic Quadrant™ for Cyberthreat Intelligence Technologies SOCRadar is positioned as a Visionary in the inaugural Magic Quadrant report for Threat Intelligence, which helps leaders evaluate the right CTI technologies against the most impact…SOCRADAR.IO
8 MaySen. Schumer seeks DHS plan on AI cyber coordination with state, local governmentsThe Senate’s top Democrat is worried about smaller government entities being left behind as AI models advance hacking risks. The post Sen. Schumer seeks DHS plan on AI cyber coordination with state, local governments appeared first on CyberScoop .CYBERSCOOP.COM
8 MayFriday Squid Blogging: Giant Squid Live in the Waters of Western AustraliaEvidence of them has been found by analyzing DNA in the seawater. As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered. Blog moderation policy.SCHNEIER.COM
7 MayNorth Korean hackers targeted ethnic Koreans in China with Android ‘BirdCall’ malwareResearchers at cybersecurity firm ESET attributed the campaign to APT37 and said the hackers used a backdoor attached to a suite of card games from a company called Sqgame.THERECORD.MEDIA
7 MayISC Stormcast For Thursday, May 7th, 2026 https://isc.sans.edu/podcastdetail/9922, (Thu, May 7th)(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.ISC.SANS.EDU
7 MayAn Adaptive Cyber Analytics UI for Web Honeypot Logs [Guest Diary], (Wed, May 6th)[This is a Guest Diary by Eric Roldan, an ISC intern as part of the SANS.edu BACS program]
ISC.SANS.EDU
7 MayWatchGuard Agent Flaws Allow Attackers to Gain Full SYSTEM Privileges on WindowsMultiple high-severity vulnerabilities in the WatchGuard Agent for Windows could allow malicious actors to elevate their privileges to the highest system level or disrupt critical security services. With CVSS scores up to 8.5, these vulnerabilities pose a significant risk to orga…GBHACKERS.COM
7 MayFake Disk Cleanup Apps Fuel New macOS ClickFix AttackA wave of ClickFix-style social engineering attacks that specifically target macOS users, using fake disk cleanup and system utility tips hosted on popular content platforms. Instead of installing helpful tools, these Terminal commands silently fetch and execute infostealers such…GBHACKERS.COM
7 MayMulti-model AI is creating a routing headache for enterprisesApplication teams are moving AI inference into production systems that support business operations. Enterprises are expanding traffic management, identity controls, observability, and routing systems for multiple AI models and environments. F5’s 2026 State of Application Strategy…HELPNETSECURITY.COM
7 MayMalicious NuGet Packages Steal Browser Credentials, SSH Keys, and Crypto WalletsMalicious NuGet packages are quietly stealing browser credentials, SSH keys, and cryptocurrency wallet data from developer machines and CI/CD infrastructure, with a particular focus on Chinese .NET ecosystems. The campaign blends legitimate-looking UI and infrastructure libraries…GBHACKERS.COM
7 MayRed Hat Enterprise Linux adds post-quantum security and AI-driven automation in latest releasesRed Hat has announced the upcoming general availability of Red Hat Enterprise Linux 10.2 and 9.8. Building on the innovation of Red Hat Enterprise Linux 10, the latest versions help address security threats, speed AI innovation and minimize operational drift. What Red Hat announc…HELPNETSECURITY.COM
7 MayGoogle Chrome 148 Released With Fixes for 127 Security FlawsGoogle has officially rolled out Chrome version 148 to the stable channel, delivering a massive security overhaul that addresses 127 vulnerabilities across Windows, Mac, and Linux. The update, now available as version 148.0.7778.96 for Linux and 148.0.7778.96 or 148.0.7778.97 for…GBHACKERS.COM
7 MayWhy “Trusted Publishing” Can’t Save Us from Social Engineeringsubmitted by codeinabox to security 1 points | 0 comments https://adventures.nodeland.dev/archive/why-trusted-publishing-can-t-save-us/PROGRAMMING.DEV
7 MayDaemon Tools Developer Confirms Software Was TrojanizedA China-linked threat actor backdoored a version of Daemon Tools to infect thousandsINFOSECURITY-MAGAZINE.COM
7 MaySmart Glasses for the AuthoritiesICE is developing its own version of smart glasses, with facial recognition tied to various databases.SCHNEIER.COM
7 MayHackers Weaponize Claude AI in Attacks on Water and Drainage UtilitiesHackers have abused commercial Claude AI models to help compromise a Mexican water and drainage utility’s IT network and probe systems connected to critical infrastructure. The attackers used Claude as an operational “copilot” to discover industrial systems, build custom tools, a…GBHACKERS.COM
7 MayFake Claude AI Installers Used to Spread Malware in New Cyber ScamHackers are abusing fake Claude AI installer pages promoted through Google Ads to trick users into running malware in a campaign. The operation combines highly realistic install guides with a stealthy, multi‑stage infection chain that abuses trusted Windows components, fileless e…GBHACKERS.COM
7 MayFake Call History Apps on Google Play Steal Payments, Hit 7.3M+ Downloads28 fake “call history” utilities on Google Play, collectively installed more than 7.3 million times, have been exposed as subscription scams that generate fabricated logs instead of real phone records, with several also bypassing Google’s official billing system to make refunds h…GBHACKERS.COM
7 MayAmerican duo sentenced for hosting laptop farms for North Korean IT workersThe men’s separate schemes impacted almost 70 U.S. companies and generated a combined $1.2 million in revenue for the North Korean regime. The post American duo sentenced for hosting laptop farms for North Korean IT workers appeared first on CyberScoop .CYBERSCOOP.COM
7 MayManual Changes Break SecurityModern infrastructure practices define servers, databases, and networks entirely as code, eliminating manual changes after deployment. This approach reduces configuration drift and increases consistency, making systems easier to secure and audit. By enforcing policies during the …YOUTUBE.COM
7 MayGoogle Seeks EU Deal Over ‘Parasite SEO’ News RankingsGoogle reportedly proposed EU search changes to address concerns about news rankings, publisher revenue, and potential fines under the Digital Markets Act. The post Google Seeks EU Deal Over ‘Parasite SEO’ News Rankings appeared first on TechRepublic .TECHREPUBLIC.COM
7 MayAndroid 17: Everything We Know About Google’s Biggest Year YetAndroid 17 rumors point to Motion Assist, App Bubbles, native app locking, Gemini updates, and Android XR news ahead of Google I/O 2026. The post Android 17: Everything We Know About Google’s Biggest Year Yet appeared first on TechRepublic .TECHREPUBLIC.COM
7 MayApple’s $250M Siri Settlement Could Pay Eligible iPhone BuyersApple’s proposed $250M Siri settlement could pay eligible iPhone buyers. See who qualifies, how much they could receive, and what comes next. The post Apple’s $250M Siri Settlement Could Pay Eligible iPhone Buyers appeared first on TechRepublic .TECHREPUBLIC.COM
7 MayThis Dell 15 Laptop Offers a Sensible Daily Driver Setup for Just $307The Core 3 CPU, 8GB RAM, and 512GB SSD deliver smooth multitasking for office apps, browsing, and meetings. The post This Dell 15 Laptop Offers a Sensible Daily Driver Setup for Just $307 appeared first on TechRepublic .TECHREPUBLIC.COM
7 MayWorld Password Day 2026: Treat Identity as the Perimeter (and Act Like It)World Password Day is no longer just a nudge to pick stronger passwords, it’s a moment to rethink identity. Attackers rarely “hack” systems today; they log in as you. Combine expert guidance on phishing, MFA, password managers, behavioral defenses, and new threats from AI and qua…KNOWBE4.COM
7 MayNew TCLBANKER malware self-spreads through WhatsApp and OutlookA new banking trojan named TCLBANKER spreads through victims’ own WhatsApp and Microsoft Outlook accounts, allowing the malware to propagate autonomously. According to researchers at Elastic Security Labs, TCLBANKER appears to be a major evolution of the previously documented SOR…CYBERINSIDER.COM
7 MayMac Studio, Mac mini Buyers Are Losing Options Amid AI DemandApple reportedly removed several high-memory Mac Studio and Mac mini options as AI demand and memory shortages strain desktop Mac supply. The post Mac Studio, Mac mini Buyers Are Losing Options Amid AI Demand appeared first on TechRepublic .TECHREPUBLIC.COM
7 MayAlphabet Poised to Overtake Nvidia as the World’s Most Valuable Public CompanyAlphabet is closing in on Nvidia’s market value as Google Cloud growth, AI investments, and custom chips fuel Wall Street optimism. The post Alphabet Poised to Overtake Nvidia as the World’s Most Valuable Public Company appeared first on TechRepublic .TECHREPUBLIC.COM
7 MayElon Musk’s Texas Chip Plant Could Cost $119B, Filings ShowNew Texas filings suggest Elon Musk’s proposed Terafab chip plant could cost up to $119 billion, raising stakes for AI and semiconductor supply chains. The post Elon Musk’s Texas Chip Plant Could Cost $119B, Filings Show appeared first on TechRepublic .TECHREPUBLIC.COM
6 MayISC Stormcast For Wednesday, May 6th, 2026 https://isc.sans.edu/podcastdetail/9920, (Wed, May 6th)(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.ISC.SANS.EDU
6 MayRemus Infostealer Adopts Lumma-Style Browser Key Theft to Bypass App-Bound EncryptionRemus is a newly observed 64-bit infostealer that closely tracks the Lumma Stealer codebase while adding EtherHiding-based C2 resolution and a refined Application‑Bound Encryption (ABE) bypass for Chromium browsers. The first Remus activity dates back to early 2026, shortly after…GBHACKERS.COM
6 MayYour Container Is Not a Sandboxsubmitted by codeinabox to security 3 points | 0 comments https://emirb.github.io/blog/microvm-2026/PROGRAMMING.DEV
6 MayRowhammer Attack Against NVIDIA ChipsA new rowhammer attack gives complete control of NVIDIA CPUs. On Thursday, two research teams, working independently of each other, demonstrated attacks against two cards from Nvidia’s Ampere generation that take GPU rowhammering into new—and potentially much more conseque…SCHNEIER.COM
6 MayInsights into the clustering and reuse of phone numbers in scam emailsTalos has recently started to collect and gather intelligence around phone numbers within emails as an additional indicator of compromise (IOC). In this blog, we discuss new insights into in-the-wild phone number reuse in scam emails.TALOSINTELLIGENCE.COM
6 MayExtreme Networks introduces Agent ONE for autonomous enterprise networkingExtreme Networks has introduced Extreme Agent ONE, a new class of AI agents for enterprise networking. Moving beyond generic, prompt-based AI, Extreme Agent ONE runs on the Extreme AI stack purpose-built for enterprise environments, which combines advanced AI reasoning, live netw…HELPNETSECURITY.COM
6 May8×8 updates CX platform with AI, analytics, and frontline management capabilities8×8 has released a set of platform updates to the 8×8 Platform for CX that target the operational gaps most commonly stalling organizations, including AI deployments requiring months of integration, queues IT teams cannot monitor in real time, customers abandoning sessions a…HELPNETSECURITY.COM
6 MayProton Mail brings quantum-safe email encryption to all accountsPost-quantum protection is now available as an optional feature in Proton Mail across all plans, including the free tier. How post-quantum protection works Once enabled, Proton Mail generates new encryption keys designed to protect future encrypted emails against attacks from qua…HELPNETSECURITY.COM
6 Maygroundcover expands its observability platform with enhanced Synthetic Monitoring and RUMgroundcover has expanded its capabilities with new and enhanced offerings across Synthetic Monitoring and Real User Monitoring (RUM). These innovations give engineering teams greater visibility into the user experience, from proactive testing to real-world session insights, while…HELPNETSECURITY.COM
6 MayMegaport enhances network resilience with integrated DDoS protectionMegaport has announced the launch of Megaport DDoS Protection. This new built-in security capability for Megaport Internet allows customers to filter malicious traffic directly within the Megaport network, rather than routing it through a separate external service. This helps ens…HELPNETSECURITY.COM
6 MayDarkhub Hacking-for-Hire Portal Promotes Crypto Fraud and Spyware ServicesA newly identified dark web platform, Darkhub, is advertising a wide range of hacking-for-hire services, including account compromise, surveillance, and financial manipulation. The service, accessible via the Tor network, presents itself as a centralized hub for offensive cyber c…GBHACKERS.COM
6 MayMicrosoft Teams on Android Now Lets Users Join External Meetings Through SIPMicrosoft is set to bridge the gap in enterprise unified communications with a highly anticipated update to its conference room hardware. Starting in June 2026, Microsoft Teams Rooms on Android will officially support joining third-party external meetings through Session Initiati…GBHACKERS.COM
6 MayOceanLotus suspected of using PyPI to deliver ZiChatBot malwareKaspersky researchers uncovered malicious wheel packages in PyPI that targeted both Windows and Linux and contained a dropper delivering malware dubbed ZiChatBot. We attribute this activity to OceanLotus APT.SECURELIST.COM
6 MaySwapper – A Pure Regex Match/Replace Burp ExtensionTo get a valid session token to use with Burp Suite tools, I ended up writing a small Python extension (110 lines of code, but who’s counting?) that obtained a new session token for each request, allowing items like Intruder to work as intended. Cool, I was able to use it during …BLACKHILLSINFOSEC.COM
6 MayGoogle Chrome silently installs 4GB Gemini Nano AI model on user devicesGoogle Chrome has been quietly downloading and installing a 4GB Gemini Nano AI model on user devices without displaying a consent prompt or offering a clear opt-out mechanism. The findings were published by privacy researcher Alexander Hanff of That Privacy Guy, who documented th…CYBERINSIDER.COM
6 MaySalat Malware Abuses QUIC and WebSockets for Stealthy C2 ControlA powerful new Windows malware family dubbed Salat Stealer, a Go-based Remote Access Trojan (RAT) that blends classic infostealing with a stealthy QUIC/WebSocket command-and-control (C2) channel and resilient blockchain-backed infrastructure. Written in Go, it supports remote she…GBHACKERS.COM
6 MayBelief Comes Before GrowthThe framework is simple: belief comes first, then business generation, followed by infrastructure, and finally leadership. Each pillar builds on the one before it. If belief is weak, everything downstream—marketing, scaling, leadership—becomes unstable. You may still execute, but…YOUTUBE.COM
6 MayBusinesses eager but unprepared for AI to transform their security strategiesMeanwhile, a new report found, companies are neglecting other basic security tools.CYBERSECURITYDIVE.COM
6 MayMozilla, Mullvad, Proton, sign letter opposing UK age verificationPrivacy advocates, browser makers, VPN providers, and digital rights groups have signed a joint statement urging UK policymakers to abandon plans for broader online age verification requirements, warning that the measures could undermine privacy, weaken internet openness, and exp…CYBERINSIDER.COM
6 MayBuilding Trust in Low-Touch TeamsTrust inside teams doesn’t come from occasional alignment meetings. It comes from consistent interaction—balancing accountability with training and development across the week. If teams only meet monthly or quarterly, trust may remain shallow. That makes it harder to deliver hard…YOUTUBE.COM
6 MayA DOD contractor’s API flaw exposed military course data and service member recordsResearchers say Schemata’s platform exposed names, emails, base assignments, and course materials before the company patched the issue and contacted government authorities. The post A DOD contractor’s API flaw exposed military course data and service member records appeared first…CYBERSCOOP.COM
5 MayISC Stormcast For Tuesday, May 5th, 2026 https://isc.sans.edu/podcastdetail/9918, (Tue, May 5th)(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.ISC.SANS.EDU
5 MayMicrosoft Edge Found Storing Saved Passwords in Cleartext Memory at StartupA new security finding reveals that Microsoft Edge loads every saved password into its process memory as cleartext the moment the browser launches. Even more surprising to security professionals is Microsoft’s official response to the disclosure, which states that this inse…GBHACKERS.COM
5 Maypnpm 11 Enables Default Release-Age Guard to Curb npm Supply Chain Attackspnpm 11 has been released with a strong focus on reducing software supply chain risk, introducing security-first defaults that directly address modern package ecosystem threats. The most significant change in pnpm 11 is the introduction of a default Minimum Release Age of 24 hour…GBHACKERS.COM
5 MayFake “Notepad++ for Mac” Site May Pose Malware Risk for Mac UsersA deceptive website is circulating online that claims to offer an official “Notepad++ for Mac” download, and it has already misled some users and even tech media outlets into believing that Notepad++ has finally launched a native macOS version. The site operates under the domain …GBHACKERS.COM
5 MayNew Attribution Framework Links APT Campaigns Across Key LayersA new attribution framework is reshaping how cybersecurity analysts connect advanced persistent threat (APT) activity, moving beyond static group labels toward a dynamic, multi-layered model that reflects how modern adversaries actually operate. These profiles are built from obse…GBHACKERS.COM
5 MayNorth Korean hackers trojanize gaming platform to spy on ethnic Koreans in ChinaA gaming platform built for ethnic Koreans in China has been serving backdoored Windows and Android software to its users since late 2024. The platform, sqgame[.]net, hosts traditional card and board games for a community that sits along the North Korean border and includes many …HELPNETSECURITY.COM
5 MayMeta adds proof-based security to encrypted backupsMeta has updated its infrastructure for protecting password-based and end-to-end encrypted backups, introducing over-the-air fleet key distribution for Messenger and a commitment to publishing evidence of secure fleet deployments. How encrypted backups work These updates build on…HELPNETSECURITY.COM
5 MayCode of Conduct Phish Hits 35,000 Users in Multi-Stage AiTM AttackA highly sophisticated phishing campaign leveraging code-of-conduct-themed lures has targeted more than 35,000 users across 13,000 organizations. The multi-stage attack, observed between April 14 and April 16, 2026, highlights how threat actors are refining social engineering, de…GBHACKERS.COM
5 MayFTC orders Kochava to stop selling people’s location dataThe US Federal Trade Commission (FTC) has moved to permanently restrict data broker Kochava and its subsidiary from selling precise location data. This resolves allegations that the companies exposed the movements of millions of mobile users without their knowledge or consent. Th…CYBERINSIDER.COM
5 MayAnomali ThreatStream Next-Gen speeds threat response across workflowsAnomali has announced ThreatStream Next-Gen. Available standalone or within the Anomali Unified Security Data Lake, it turns threat intelligence into an active decisioning layer across security workflows, validated to drive investigations 300× faster than traditional methods acro…HELPNETSECURITY.COM
5 MayCerberus Stalkerware Hits Google Play, Abuses Accessibility and Firebase for Remote ControlCerberus Anti-theft, a long-running Android “security” app, is operating as full-featured stalkerware on Google Play, abusing accessibility services and Google Firebase to give abusers near-total remote control over victims’ phones. Once installed, Cerberus lets an abuser push a …GBHACKERS.COM
5 MayUAT-8302 and its box full of malwareCisco Talos is disclosing UAT-8302, a sophisticated, China-nexus advanced persistent threat (APT) group targeting government entities in South America since at least late 2024 and government agencies in southeastern Europe in 2025.TALOSINTELLIGENCE.COM
5 MayVIAVI CyberFlood CF1000 pushes 400G validation for multi-terabit AI data centersVIAVI Solutions has announced the launch of its next-generation CyberFlood CF1000 Appliance, a native 400G security and application performance test platform for the validation of multi-terabit security and AI data center infrastructures at scale. Developed for network equipment …HELPNETSECURITY.COM
5 MayOWASP AI Security Summit May 27Generative AI introduces risks like prompt injection, AI-generated code issues, and agentic workflows that traditional security tools weren’t designed to handle. This creates a growing gap between building software and securing it, especially as teams adopt AI faster than securit…YOUTUBE.COM
5 MayKaspersky suspects Chinese hackers planted a backdoor into Daemon Tools in ‘widespread’ attackThe cybersecurity company says it's seen thousands of infection attempts, and at least a dozen successful hacks after users installed malicious versions of the popular Windows software.TECHCRUNCH.COM
5 MaySamsung Display Reveals Screens That Measure Health, Stretch, and Fight GlareSamsung Display unveiled OLED, sensor, quantum dot, and stretchable screen prototypes that preview brighter phones, health tracking, and car displays. The post Samsung Display Reveals Screens That Measure Health, Stretch, and Fight Glare appeared first on TechRepublic .TECHREPUBLIC.COM
5 MayiOS 26.5 to Introduce Encrypted RCS, Maps Changes, and New EU FeaturesApple’s iOS 26.5 release candidate points to RCS encryption, Maps ad changes, EU device support, and App Store subscription updates. The post iOS 26.5 to Introduce Encrypted RCS, Maps Changes, and New EU Features appeared first on TechRepublic .TECHREPUBLIC.COM
5 MayEnhance Your Expertise Anytime with Unlimited Online Courses — Now $19.97Topics include growth hacking, game design, blockchain, AI, digital marketing, cybersecurity, copywriting, and big data. The post Enhance Your Expertise Anytime with Unlimited Online Courses — Now $19.97 appeared first on TechRepublic .TECHREPUBLIC.COM
5 MayWhat If Your Digital Footprint Could Shrink?Get Surfshark One+ with Incogni for $91.99 (reg. $500.40) and cover VPN, alerts, antivirus, and data removal. The post What If Your Digital Footprint Could Shrink? appeared first on TechRepublic .TECHREPUBLIC.COM
5 MayPower Through Projects with the Microsoft Office 2024 Home & BusinessThe newest Office version is here and includes a variety of updates to help you work more efficiently. The post Power Through Projects with the Microsoft Office 2024 Home & Business appeared first on TechRepublic .TECHREPUBLIC.COM
5 MayApple Wallet May Get ‘Create a Pass’ Tool for Event Tickets, Gift CardsApple’s reported iOS 27 Wallet update could let iPhone users turn QR codes, memberships, gift cards, event tickets, and more into custom passes. The post Apple Wallet May Get ‘Create a Pass’ Tool for Event Tickets, Gift Cards appeared first on TechRepublic .TECHREPUBLIC.COM
5 MayProton Mail rolls out quantum-resistant encryption for all usersProton Mail has introduced optional post-quantum cryptography (PQC) protection for all users, allowing them to secure their email communication against potential future attacks from quantum computers. The feature is available starting today across all plans, including free accoun…CYBERINSIDER.COM
5 MayBrave sees 100% Linux growth as browser reaches 115M monthly usersBrave has reported record growth across its browser and search products in April 2026, with Linux users emerging as the fastest-growing segment, more than doubling year-over-year. Brave co-founder and CEO Brendan Eich shared the company’s latest monthly metrics on X, highlighting…CYBERINSIDER.COM
5 MayLastPass Mobile Smart Scanner improves password securityLastPass has launched Mobile Smart Scanner, a solution that converts photographs of typed or handwritten credentials into structured, ready-to-use password entries that can be reviewed, saved, and autofilled directly from the vault. Available in early access for Free, Premium, an…HELPNETSECURITY.COM
5 MayNew WhatsApp Flaws Could Affect Billions of Users After Meta Security PatchMeta patched two WhatsApp flaws affecting iOS, Android, and Windows users, including bugs tied to risky files, links, and Reels previews. The post New WhatsApp Flaws Could Affect Billions of Users After Meta Security Patch appeared first on TechRepublic .TECHREPUBLIC.COM
5 MayNews alert: LuxSci launches HIPAA-compliant email platform for mid-size healthcare marketCAMBRIDGE, Mass., May 5, 2026, CyberNewswire — LuxSci , a leading provider of HIPAA compliant secure healthcare communications, today announced the launch of LuxSci Secure High Volume Email for mid-sized healthcare organizations , the industry’s trusted HIPPA-compliant email solu…LASTWATCHDOG.COM
5 MayTurn Intelligence into Action Instantly with Retroactive Threat Detection on Verity471Retroactive Threat Detection eliminates the manual work of extracting indicators of compromise (IOCs) and query writing, dynamically translating IOCs from reports on Verity471 into ready-to-run detection queries tailored for all major endpoint detection and response (EDR) and Sec…INTEL471.COM
5 MayGeneralist AI for your SOC: When and where to use itMany security leader are asking the same question right now. We already pay for Microsoft Copilot, ChatGPT Enterprise, or Claude. Why buy anything else? Here's what you need to know. The post Generalist AI for your SOC: When and where to use it appeared first on Intezer .INTEZER.COM
4 MayISC Stormcast For Monday, May 4th, 2026 https://isc.sans.edu/podcastdetail/9916, (Mon, May 4th)(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.ISC.SANS.EDU
4 MayYour work apps are quietly handing 19 data points to someoneOffice work in 2026 runs through a stack of mobile apps that sit on the same phones people use for banking, messaging family, and tracking their location. Ten of the most common workplace apps in use across U.S. companies, including Gmail, Microsoft Teams, Zoom Workplace, Slack, …HELPNETSECURITY.COM
4 MayBrush shell 0.4.0 tightens script safety, widens platform supportRust-based alternatives to traditional Unix shells continue to attract users who want bash compatibility alongside built-in features like syntax highlighting and history-based suggestions. Brush, a bash- and POSIX-compatible shell written in Rust, sits in that group, and version …HELPNETSECURITY.COM
4 MayEmail Bombing, Fake IT Support Calls Drive Microsoft Teams Phishing SurgeEmail bombing campaigns combined with fake IT support outreach are driving a surge in sophisticated Microsoft Teams phishing attacks. The attacks typically begin with email bombing, where victims are flooded with spam messages to create confusion and urgency. Shortly after, threa…GBHACKERS.COM
4 MayUK Government Announces Plans to Grow National AI InfrastructureThe UK Government is to support the development of Britain’s AI hardware infrastructure, while also committing to work in establishing international standards for the deployment of AI. The post UK Government Announces Plans to Grow National AI Infrastructure appeared first on Tec…TECHREPUBLIC.COM
4 MayAI Agent Reportedly Deletes Company’s Entire Database, Admits to Violating GuardrailsA Cursor AI agent deleted a company’s entire production database, ignoring instructions prohibiting it from running destructive commands. The post AI Agent Reportedly Deletes Company’s Entire Database, Admits to Violating Guardrails appeared first on TechRepublic .TECHREPUBLIC.COM
4 MayLens Agents brings policy control to AI across cloud and desktopLens by Mirantis has announced Lens Agents, a governed platform for running AI agents across enterprise systems, giving organizations a unified, policy-driven way to run, secure, and scale AI agents across desktop and cloud environments. Available in early access, Lens Agents ena…HELPNETSECURITY.COM
4 MayAttackers Hijack SAP npm Packages to Steal Dev SecretsA sophisticated supply chain attack hit the SAP developer ecosystem on April 29, 2026, compromising four widely-used npm packages with credential-stealing malware. The attackers modified package installation scripts to download the Bun JavaScript runtime a legitimate alternative …GBHACKERS.COM
4 MayHacking PolymarketPolymarket is a platform where people can bet on real-world events, political and otherwise. Leaving the ethical considerations of this aside (for one, it facilitates assassination ), one of the issues with making this work is the verification of these real-world events. Polymark…SCHNEIER.COM
4 MayWhy data centers now belong on the critical infrastructure listAs AI drives deeper dependence across business, supply chains, and national security, the buildings that run the cloud are becoming critical infrastructure — and increasingly attractive targets. The post Why data centers now belong on the critical infrastructure list appeared fir…CYBERSCOOP.COM
4 MayBotnet Hijacks ADB-Exposed Android Devices to Target Minecraft ServersNew research has uncovered a Mirai-derived botnet called xlabs_v1 that turns Android devices with exposed Android Debug Bridge (ADB) into a distributed attack platform for knocking Minecraft servers and other game hosts offline. By abusing TCP port 5555 on poorly secured Android-…GBHACKERS.COM
4 MayMeta enhances security of WhatsApp and Messenger encrypted backupsMeta has introduced new security and transparency enhancements to its end-to-end encrypted backup system for WhatsApp and Messenger, strengthening how encryption keys are distributed and verified while opening parts of its infrastructure to independent auditing. The updates build…CYBERINSIDER.COM
4 MayReport: Deepfake Fraud Causes Billions in LossesDeepfake-driven fraud has caused $2.19 billion in losses globally, with $1.65 billion reported in 2025 alone, according to an analysis by Surfshark. More than half of these losses were due to investment scams using deepfakes of high-profile figures.KNOWBE4.COM
4 MayNew MOVEit vulnerabilities prompt urgent vendor warningProgress Software warned customers to immediately upgrade to versions of the file-transfer tool that fix the serious flaws.CYBERSECURITYDIVE.COM
4 MaySilver Fox Springs Tax-Themed Attacks on Orgs in India, RussiaMore than 1,600 socially engineered messages from the China-backed advanced persistent threat (APT) group target various sectors to deliver the previously undocumented ABCDoor backdoor, ValleyRAT, and other malware.DARKREADING.COM
4 MayOperant AI Endpoint Protector secures AI agents and MCP toolsOperant AI has launched Operant Endpoint Protector, a new addition to its AI Defense Platform that enables enterprise IT and security teams to discover, detect, and defend against threats across every AI tool, coding agent, and Model Context Protocol (MCP)-connected workflow used…HELPNETSECURITY.COM
4 MayBlend Autopilot MCP brings AI agent orchestration to lending platformsBlend Labs has announced the launch of Autopilot MCP, a server built on the Model Context Protocol, an emerging open standard for AI agent connectivity, that gives authorized agents secure, programmatic access to the Blend platform. For lenders and partners, Autopilot MCP introdu…HELPNETSECURITY.COM
4 MayA college student is suing a dating app that allegedly used her TikTok videos to target men in her dormitoryThe woman’s lawyer told CyberScoop they believe the company edited her video to suggest she was a “friend with benefits” and intentionally geofenced it to men around her. The post A college student is suing a dating app that allegedly used her TikTok videos to target men in her d…CYBERSCOOP.COM
4 MayGen Z Is Bringing the iPod Back as a Distraction-Free Music EscapeGen Z is reviving the iPod as younger users seek distraction-free music, fewer algorithms, and more control over how they listen. The post Gen Z Is Bringing the iPod Back as a Distraction-Free Music Escape appeared first on TechRepublic .TECHREPUBLIC.COM
4 MayGoogle Workspace Adds 5 AI Upgrades That Could Change Daily WorkGoogle Workspace adds 5 AI upgrades at Cloud Next 2026, improving Sheets, Meet, automation, and Microsoft 365 migration tools. The post Google Workspace Adds 5 AI Upgrades That Could Change Daily Work appeared first on TechRepublic .TECHREPUBLIC.COM
4 MayThe $59 AI Tool Turning Forms Into Smart WorkflowsFormura Smart Form Builder uses AI to build forms, add logic, and track data, and it's $497 off (89%). The post The $59 AI Tool Turning Forms Into Smart Workflows appeared first on TechRepublic .TECHREPUBLIC.COM
4 MayApple Eyes ‘Aggressive Pricing’ for iPhone 18 Pro Amid Rising CostsApple may keep iPhone 18 Pro starting prices steady despite rising memory costs, but storage upgrades and a foldable model could cost more. The post Apple Eyes ‘Aggressive Pricing’ for iPhone 18 Pro Amid Rising Costs appeared first on TechRepublic .TECHREPUBLIC.COM
4 MayGameStop Launches $56 Billion Bid to Take Over eBayRyan Cohen’s $55.5 billion bid for eBay would pair GameStop stores with eBay’s marketplace, but financing questions loom over the deal. The post GameStop Launches $56 Billion Bid to Take Over eBay appeared first on TechRepublic .TECHREPUBLIC.COM
4 MayIndirect Prompt Injection Is Now a Real-World AI Security ThreatAI agents are now being weaponized through prompt injection, exposing why model guardrails are not enough to protect enterprise data. The post Indirect Prompt Injection Is Now a Real-World AI Security Threat appeared first on TechRepublic .TECHREPUBLIC.COM
4 MayMicrosoft Defender Bug Triggers False Malware Alerts for DigiCert CertificatesMicrosoft fixed a Defender false positive that flagged legitimate DigiCert certificates as malware, disrupting Windows trust stores for some IT teams. The post Microsoft Defender Bug Triggers False Malware Alerts for DigiCert Certificates appeared first on TechRepublic .TECHREPUBLIC.COM
4 May6 Best No-Log VPNs in 2026Looking for the best anonymous (no-log) VPN in 2026? Check out our comprehensive list to find the top VPN services that prioritize anonymity and security. The post 6 Best No-Log VPNs in 2026 appeared first on TechRepublic .TECHREPUBLIC.COM
4 May5 Best VPNs for Android in 2026Explore the best VPNs for Android devices in 2026. Find out which VPN offers the best security, speed and features for your Android device. The post 5 Best VPNs for Android in 2026 appeared first on TechRepublic .TECHREPUBLIC.COM
4 MayThe 7 Best iPhone VPNs in 2026Which VPN works best on iPhones? Use our guide to compare the pricing and features of the 7 best VPNs for iPhone in 2026. The post The 7 Best iPhone VPNs in 2026 appeared first on TechRepublic .TECHREPUBLIC.COM
3 MayWireshark 4.6.5 Released, (Sun, May 3rd)Wireshark release 4.6.5 fixes 43 vulnerabilities (38 CVEs) and 35 bugs.
ISC.SANS.EDU
3 MayChatGPT advanced account security adds passkeys and hardware keysJournalists, elected officials, researchers, and political dissidents have spent years adapting their accounts to phishing-resistant authentication on consumer platforms. ChatGPT now joins that list. OpenAI has introduced Advanced Account Security, an opt-in setting that strips p…HELPNETSECURITY.COM
2 MayThe Data That Actually MattersPost-quantum risk isn’t about breaking everything instantly. Attackers still need time, storage, and compute to decrypt data—even after Q-Day. That shifts the priority. Short-lived data like passwords may not matter much. But long-lived secrets—financial records, intellectual pro…YOUTUBE.COM
2 MayWhat Could Go Wrong With AI AuditAI in financial auditing introduces three primary risk categories: deficient outputs, misuse of outputs, and non-compliant methodology. Even when AI produces accurate results, downstream human interpretation or flawed underlying processes can lead to audit failure. In regulated f…YOUTUBE.COM
1 MayISC Stormcast For Friday, May 1st, 2026 https://isc.sans.edu/podcastdetail/9914, (Fri, May 1st)(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.ISC.SANS.EDU
1 MayIdentity is the control plane for distributed infrastructureTeleport CEO Ev Kontsevoy makes the case that distributed infrastructure, across cloud, Kubernetes, databases, and servers, can’t be secured by layering more tools on top of fragmented identity systems. He argues for fewer credentials, fewer entry points, and a single ident…HELPNETSECURITY.COM
1 MayRuby Gems and Go Modules Used in Campaign Targeting GitHub ActionsA sophisticated software supply chain attack originating from the GitHub account BufferZoneCorp has been uncovered, targeting developers and continuous integration environments through malicious Ruby gems and Go modules. The campaign deployed sleeper packages that impersonated le…GBHACKERS.COM
1 MayDeep#Door Stealer Targets Passwords, Tokens, SSH Keys, and Wi-Fi CredentialsDeep#Door is a stealthy Python-based Remote Access Trojan (RAT) that uses an obfuscated batch loader to deploy a persistent surveillance and credential-stealing implant on Windows systems. It aggressively turns off security controls, hides its traffic behind the bore.]pub tunneli…GBHACKERS.COM
1 MayFBI Warns Logistics Sector of Fake Business Identity Cargo ScamsThe FBI issued a public service announcement warning the transportation and logistics sectors about a massive increase in cyber-enabled strategic cargo theft. Threat actors are increasingly using sophisticated tactics to impersonate legitimate businesses, hijack freight, and stea…GBHACKERS.COM
1 MayCAPTCHA and ClickFix Abuse Fuels Credential Theft SurgeAttackers are increasingly combining QR codes, fake CAPTCHA gates, and ClickFix-style tricks to steal credentials at scale, even as major phishing-as-a-service (PhaaS) platforms face disruption. These tactics shift risk from traditional malware attachments to highly convincing, h…GBHACKERS.COM
1 MayNew Android Spyware Platform Enables Rebranding and ResaleA newly discovered Android spyware platform is raising concerns among cybersecurity researchers by introducing a business model that allows buyers to rebrand and resell surveillance malware as their own product. Buyers can subscribe to the service, customize branding, and launch …GBHACKERS.COM
1 MayName That Toon: Mark of (Security) ProgressFeeling creative? Have something to say about the last 20 years of cybersecurity? Our editors will award the best cybersecurity-related caption with a $20 gift card.DARKREADING.COM
1 MayDownload: Automating Pentest Delivery GuidePentesting remains one of the most effective ways to identify real-world weaknesses, but the method for delivering results hasn’t evolved. Manual workflows involving static documents and email threads introduce delays, create inefficiencies, and diminish the value of the work. Th…HELPNETSECURITY.COM
1 MayCyber spies target Russian aviation firms to steal satellite and GPS dataA cyber-espionage group has been targeting Russian government agencies and companies in the aviation industry to steal sensitive geospatial data.THERECORD.MEDIA
1 MaySamsung’s Next Galaxy Book Could Run Android Instead of WindowsSamsung is reportedly developing Android-powered Galaxy Book laptops with One UI 9 and Google’s upcoming Aluminium OS platform. The post Samsung’s Next Galaxy Book Could Run Android Instead of Windows appeared first on TechRepublic .TECHREPUBLIC.COM
1 MayUS and allies urge ‘careful adoption’ of AI agentsNew guidance from a coalition of Western governments underscores the difficult-to-predict risks of still-evolving agentic tools.CYBERSECURITYDIVE.COM
1 MayGerman MPs advised to drop Signal in favor of Wire over security concernsGermany’s Bundestag is moving to standardize on the Wire messaging platform following a wave of phishing attacks targeting politicians, with President Julia Klöckner urging lawmakers to abandon less controlled apps like Signal. In a letter dated April 24, 2026, Bundestag Presiden…CYBERINSIDER.COM
1 MayAs email phishing evolves, malicious attachments decline and QR codes surgeA new Microsoft report also describes the collapse of a once-dominant tool for generating phishing websites with fake CAPTCHAs.CYBERSECURITYDIVE.COM
1 MayOpenAI Introduces Password-Free Login for Millions of ChatGPT UsersOpenAI’s Advanced Account Security lets ChatGPT and Codex users replace passwords with passkeys or security keys, but recovery is limited. The post OpenAI Introduces Password-Free Login for Millions of ChatGPT Users appeared first on TechRepublic .TECHREPUBLIC.COM
1 MayMicrosoft Flagged 8.3B Phishing Emails in Q1 as QR Codes, CAPTCHAs RiseMicrosoft flagged 8.3 billion phishing emails as attackers turned to QR codes, fake CAPTCHAs, PhaaS kits, and file-based payloads. The post Microsoft Flagged 8.3B Phishing Emails in Q1 as QR Codes, CAPTCHAs Rise appeared first on TechRepublic .TECHREPUBLIC.COM
1 MayAlert: Payroll-Hijacking Attacks Are Targeting Canadian EmployeesMicrosoft warns that a new criminal threat actor dubbed “Storm-2755” is launching payroll-pirate attacks against Canadian users. These attacks use social engineering to compromise employee accounts and divert salary payments to attacker-controlled bank accounts.KNOWBE4.COM
1 MayCriminal IP and Securonix ThreatQ Collaborate to Enhance Threat Intelligence OperationsTorrance, United States / California, May 1st, 2026, CyberNewswire Criminal IP partners with Securonix to integrate Criminal IP’s Threat Intelligence into ThreatQ, allowing organizations to incorporate external IP intelligence into their existing workflows, helping security teams…GBHACKERS.COM
1 MayDOS, Seneca the Younger, Outlook, CopyFail, cPanel, QR, Ruby, Go, Talkie, Josh Marpet - SWN #577DOS, 0x1A4, Seneca the Younger, Outlook, Copy/Fail, cPanel, QR, Ruby, Go, Talkie, Josh Marpet, and More on this episode of the Security Weekly News. Visit https://www.securityweekly.com/swn for all the latest episodes! Show Notes: https://securityweekly.com/swn-577YOUTUBE.COM
1 MayWhite House questions tech industry on defensive AI use, cybersecurity resilienceCompanies may be reluctant to answer some of the government’s questions, given the sensitive topics they address.CYBERSECURITYDIVE.COM
1 MayApple Sales Jump as ‘Most Popular’ iPhone Fuels GrowthApple reported strong quarterly revenue as iPhone demand surged, but questions remain around AI strategy, rising costs, and leadership changes. The post Apple Sales Jump as ‘Most Popular’ iPhone Fuels Growth appeared first on TechRepublic .TECHREPUBLIC.COM
1 MayBreaking encryption with quantum computing — Interview with Chris PeikertThe idea that quantum computers could one day break today’s encryption has moved from theory into serious discussion. In practical terms, it means that the mathematical problems protecting everything from secure websites and messaging apps to cryptocurrencies could become solvabl…CYBERINSIDER.COM
1 May76% of All Crypto Stolen in 2026 Is Now in North KoreaNorth Korean threat actors are pulling off historic cryptocurrency heists on a yearly, sometimes weekly basis now. AI might be helping them.DARKREADING.COM
30 AprDanger of Libredtail [Guest Diary], (Wed, Apr 29th)[This is a Guest Diary by James Roberts, an ISC intern as part of the SANS.edu BACS program]
ISC.SANS.EDU
30 AprTesla Optimus Robot Launch Timeline Targets 2027 ScaleElon Musk says Tesla’s Optimus robot could launch next year, with production starting in 2026 and a major scale-up planned by 2027. The post Tesla Optimus Robot Launch Timeline Targets 2027 Scale appeared first on TechRepublic .TECHREPUBLIC.COM
30 AprISC Stormcast For Thursday, April 30th, 2026 https://isc.sans.edu/podcastdetail/9912, (Thu, Apr 30th)(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.ISC.SANS.EDU
30 AprLarge-scale Roblox hacking operation shut down by Ukrainian authoritiesUkrainian police arrested three hackers who hijacked 610,000 Roblox accounts and sold them for $225,000 in profit. Police in Ukraine arrested three suspects accused of hacking over 610,000 Roblox accounts and selling them for about $225,000. Officers carried out multiple searches…SECURITYAFFAIRS.COM
30 AprBackdoored WordPress Plugin Abuses Remote Update Checker for Silent Code DeliveryA long-dormant backdoor has been uncovered in the “Quick Page/Post Redirect Plugin,” a popular WordPress add-on with over 70,000 active installations. The tampered plugin, specifically version 5.2.3, contained two distinct malicious features. First, it featured a pass…GBHACKERS.COM
30 AprEveryone’s building AI agents. Almost nobody’s ready for what they do to identity.Anthropic recently announced that it would not release Mythos, its most powerful AI model, to the public. The model discovered thousands of previously unknown software vulnerabilities — flaws that had sat undetected in major operating systems and web browsers for as long as nearl…CYBERSCOOP.COM
30 AprFast16 MalwareResearchers have reverse-engineered a piece of malware named Fast16. It’s almost certainly state-sponsored, probably US in origin, and was deployed against Iran years before Stuxnet: “…the Fast16 malware was designed to carry out the most subtle form of sabotage…SCHNEIER.COM
30 AprOpenAI Unveils Cyber Defense Roadmap Focused on AI-Powered SecurityOpenAI has released a comprehensive cyber defense roadmap titled “Cybersecurity in the Intelligence Age” to responsibly equip defenders with AI-powered security tools faster than malicious actors can adapt. Spearheaded by Sasha Baker in April 2026, the action plan out…GBHACKERS.COM
30 AprMicrosoft PowerToys 0.99 Adds Multi-Monitor Tools for Windows UsersPowerToys 0.99 adds new monitor and window-management tools for Windows users, plus updates to Command Palette, Keyboard Manager, ZoomIt, and Image Resizer. The post Microsoft PowerToys 0.99 Adds Multi-Monitor Tools for Windows Users appeared first on TechRepublic .TECHREPUBLIC.COM
30 AprRelease Notes: Expanded Threat Intelligence Access, AI Assisted Search 1,770 New Detections and MoreApril brought several updates across ANY.RUN’s Threat Intelligence and detection coverage. The biggest change is expanded access to Threat Intelligence: Free plan users now get 20 premium requests in TI Lookup and YARA Search. This gives security teams a practical way …ANY.RUN
30 Apr5 Best Employer of Record Services in 2026There are no borders or boundaries when it comes to professional talent. With the right EOR, you can hire for quality, regardless of location. The post 5 Best Employer of Record Services in 2026 appeared first on TechRepublic .TECHREPUBLIC.COM
30 AprResearchers develop tool to expose GPS signal spoofing in transit networksThe Oak Ridge National Laboratory (ORNL) has developed a portable detector that identifies GPS spoofing in real time, including during motion, to help protect transportation systems. Spoofing involves transmitting counterfeit signals that imitate authentic GPS transmissions and p…HELPNETSECURITY.COM
30 AprProxmox Backup Server 4.2 arrives with S3 storage support and parallel sync jobsProxmox Backup Server 4.2 is a maintenance and feature update built on Debian 13.4 “Trixie” that adds S3-compatible object storage as a supported backend and introduces parallel processing for sync jobs. The server ships the new version with Linux kernel 7.0 as the st…HELPNETSECURITY.COM
30 AprTwo new extortion crews are speedrunning the Scattered Spider playbookCrowdStrike says The Com-affiliated threat groups are using voice phishing and fake SSO pages to break into SaaS environments and steal data fast for extortion. The post Two new extortion crews are speedrunning the Scattered Spider playbook appeared first on CyberScoop .CYBERSCOOP.COM
30 AprPwC partners with Google Cloud to take on the managed security marketThe professional services firm is stepping up its managed security ambitions with a Google Cloud-powered service that leans on agentic AI. The target market is companies that have outgrown DIY security.CYBERSECURITYDIVE.COM
30 AprSHARED INTEL Q&A: PKI’s unfinished business—’digital passports’ for content, models and agentsAs if keeping track of machine identities wasn’t hard enough. AI agents are now arriving by the thousands — and most enterprises are just handing them borrowed credentials and hoping for the best. Meanwhile, the cryptographic infrastructure asked to absorb … (more…) The pos…LASTWATCHDOG.COM
30 AprUS agencies promote zero-trust practices for operational technology networksMany zero-trust defenses work differently in industrial environments than in traditional business networks, five federal agencies said in newly published guidance.CYBERSECURITYDIVE.COM
30 AprAWS Expands Amazon Connect Into AI Tools for Hiring, Healthcare, and Supply ChainsAWS expanded Amazon Connect into four agentic AI tools for supply chain, hiring, customer service, and healthcare workflows, with humans still in control. The post AWS Expands Amazon Connect Into AI Tools for Hiring, Healthcare, and Supply Chains appeared first on TechRepublic .TECHREPUBLIC.COM
30 AprCongress kicks the can down the road on surveillance law (again)It’s the second extension of Section 702 of the Foreign Intelligence Surveillance Act in 10 days, and a regular ritual for the Hill. The post Congress kicks the can down the road on surveillance law (again) appeared first on CyberScoop .CYBERSCOOP.COM
30 AprFCC tightens KYC rules for telecoms, closes loophole for banned foreign servicesThe commission wants telecoms to do more to verify their callers and prevent illegal calls and scams from reaching Americans. The post FCC tightens KYC rules for telecoms, closes loophole for banned foreign services appeared first on CyberScoop .CYBERSCOOP.COM
29 AprISC Stormcast For Wednesday, April 29th, 2026 https://isc.sans.edu/podcastdetail/9910, (Wed, Apr 29th)(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.ISC.SANS.EDU
29 AprThe Exchange Online security controls organizations keep getting wrongIn this Help Net Security interview, Scott Schnoll, Microsoft MVP for Exchange, breaks down the Shared Responsibility Model, where Microsoft secures the cloud while organizations must protect their own data, identities, and configurations. The discussion covers default settings w…HELPNETSECURITY.COM
29 AprAI prompt confidentiality and false citations worry researchersAcademic researchers using commercial AI tools for literature review and idea generation are sending unpublished research questions, draft hypotheses, and proprietary domain knowledge into systems whose data handling they do not understand. A think-aloud study of 15 researchers d…HELPNETSECURITY.COM
29 AprIdentity discovery: The overlooked lever in strategic risk reductionIf you ask a CISO what keeps them up at night, the answer usually isn’t “lack of tools.” It’s uncertainty. Uncertainty about what they don’t see. Uncertainty about how far an attacker could move once inside. Uncertainty about whether identity programs are actually reducing risk, …HELPNETSECURITY.COM
29 AprFedora Linux 44 ships with GNOME 50 and KDE Plasma 6.6The Fedora Project released Fedora Linux 44, delivering updated desktop environments, revised installer behavior, and several lower-level system changes across its editions and spins. The release covers the project’s flagship editions, including Workstation, KDE Plasma Desk…HELPNETSECURITY.COM
29 AprMargin vs. Madness: Fixing MSSP Top 5 Operational NightmaresLeading a managed security services provider has never been a comfortable job. And it isn’t now, though the demand for MSSPs has never been higher. The global threat landscape is expanding faster than most enterprise security teams can keep pace with, and orga…ANY.RUN
29 AprEino’s agentic network observability platform enables real-time, AI-driven network insightsEino has introduced a new class of solution for enterprises known as agentic network observability. Designed for enterprises with multiple network technologies and mission-critical use cases, Eino’s agentic solution uses a 3D digital twin approach of the physical environment to d…HELPNETSECURITY.COM
29 AprMicrochip expands Trust Shield with PQC-ready root of trust and secure boot controllersMicrochip Technology is expanding its portfolio of Trust Shield, PQC‑ready devices with the TS1800 Platform Root of Trust controller and the TS50x secure boot controller. The devices are designed to help system architects address emerging cybersecurity mandates, including the Eur…HELPNETSECURITY.COM
29 AprKaseya agentic IT management unifies data and automates ticketing, security and backupsKaseya has introduced an agentic IT management platform powered by Kaseya Intelligence, combining unified data across IT operations, cybersecurity, and resilience with an execution layer that autonomously triages tickets, contains threats, verifies backups, and optimizes workflow…HELPNETSECURITY.COM
29 AprAt Machine Speedsubmitted by codeinabox to security 1 points | 0 comments https://matthiasott.com/notes/at-machine-speedPROGRAMMING.DEV
29 AprAI-powered honeypots: Turning the tables on malicious AI agentsJust as AI brings time-saving advantages to our lives, it brings similar advantages to threat actors. We can take the advantage back. This blog shows how generative AI can be used to rapidly deploy adaptive honeypot systems.TALOSINTELLIGENCE.COM
29 AprScam-checking just got a lot easier: Malwarebytes is now in ClaudeWe're in Claude! Now everyone can use our threat intel to check suspicious links, phone numbers, or email addresses. We're committed to helping you spot scams.MALWAREBYTES.COM
29 Apr9 Best Project Management Software in 2026We tested 10 leading project management tools and found monday.com best overall for its multiple views and extensive customization. ClickUp shines for affordability, while Confluence excels in project documentation. The post 9 Best Project Management Software in 2026 appeared fir…TECHREPUBLIC.COM
29 AprState CISOs losing confidence in ability to manage cyber risksDeloitte-NASCIO study shows AI, budget pressures are forcing states to make tough decisions.CYBERSECURITYDIVE.COM
29 AprApple removes AdGuard’s TrustTunnel iOS app from Russian App StoreApple has removed AdGuard’s TrustTunnel VPN client for iOS from Russia’s App Store following a request by the country’s internet regulator. Apple notified AdGuard via email of the app’s removal due to alleged violations of Russian law. According to the notice, the app “includes c…CYBERINSIDER.COM
29 AprWebinar: How to Automate Exposure Validation to Match the Speed of AI AttacksIn February 2026, researchers uncovered a shift that completely changed the game: threat actors are now using custom AI setups to automate attacks directly into the kill chain. We aren't just talking about AI writing better phishing emails anymore. We’re talking about autonomous …THEHACKERNEWS.COM
29 AprPhishing Attacks Target Executives via Microsoft TeamsA phishing campaign is targeting senior executives with social engineering attacks conducted over Microsoft Teams, according to researchers at ReliaQuest. The researchers believe former associates of the Black Basta criminal gang are running this operation.KNOWBE4.COM
29 AprLazarus Targets macOS Users With New “Mach-O Man” Malware KitLazarus Group is abusing “ClickFix” social engineering to push a new macOS malware kit dubbed “Mach-O Man,” giving attackers a direct path to credentials, Keychain secrets, and corporate access in fintech and crypto environments. This research is authored by Mauro Eldritch, an of…GBHACKERS.COM
29 AprA Practical Guide to BloodHound Data CollectionThis blog will not dive too deeply into BloodHound itself; instead, we will focus on various methods to collect AD data to provide BloodHound as input. The post A Practical Guide to BloodHound Data Collection appeared first on Black Hills Information Security, Inc. .BLACKHILLSINFOSEC.COM
29 AprSet AI Security Red Lines NowSecurity leaders are prioritizing speed and accuracy in AI adoption, while defining strict governance “red lines” around critical systems like identity and access. Without clear boundaries, AI deployments can introduce instability and risk into core enterprise functions. Governan…YOUTUBE.COM
29 AprThis $30 Subscription Will Bring AI Into Your BusinessTap into the power of OpenAI, Meta, Midjourney, and additional powerful AI models with 1min.AI. The post This $30 Subscription Will Bring AI Into Your Business appeared first on TechRepublic .TECHREPUBLIC.COM
29 AprCongress, industry ponder government posture for protecting data centersA hearing of the House Homeland Security panel’s cyber subcommittee weighed whether to designate data centers as a standalone critical infrastructure sector. The post Congress, industry ponder government posture for protecting data centers appeared first on CyberScoop .CYBERSCOOP.COM
29 AprSAS Launches AI Governance Tools to Tame Agentic AI in the EnterpriseSAS expands Viya with governed AI agents, copilots, and new governance tools aimed at helping enterprises manage shadow AI and build trust in automation. The post SAS Launches AI Governance Tools to Tame Agentic AI in the Enterprise appeared first on TechRepublic .TECHREPUBLIC.COM
29 AprAWS to Resell OpenAI Products After Microsoft Loses Exclusive LicenseAmazon is bringing OpenAI's models and Codex to AWS after Microsoft’s shift away from exclusivity, giving cloud customers more ways to use AI tools. The post AWS to Resell OpenAI Products After Microsoft Loses Exclusive License appeared first on TechRepublic .TECHREPUBLIC.COM
29 AprNew Apple Rumor: iOS 27 Could Add AI Editing Tools to PhotosApple reportedly plans new AI editing tools for Photos in iOS 27, including image expansion, spatial photo reframing, and smarter enhancements. The post New Apple Rumor: iOS 27 Could Add AI Editing Tools to Photos appeared first on TechRepublic .TECHREPUBLIC.COM
29 AprHackers Abuse Robinhood Signup Process to Deliver Phishing EmailsRobinhood fixed an account-creation flaw that hackers abused to send convincing phishing emails from its own system to some users over the weekend. The post Hackers Abuse Robinhood Signup Process to Deliver Phishing Emails appeared first on TechRepublic .TECHREPUBLIC.COM
29 AprCISOs Step Into the BoardroomCISOs are increasingly engaging in direct, strategic conversations at the board level, shifting beyond traditional reporting roles. As AI automates operational security tasks, leaders have more capacity—and expectation—to focus on governance, risk, and organizational direction. T…YOUTUBE.COM
28 AprChinese national extradited to US for pandemic-era Silk Typhoon attacksXu Zewei was allegedly directed by China’s intelligence services to conduct a sweeping espionage campaign to steal data on COVID-19 research and other U.S. policy interests. The post Chinese national extradited to US for pandemic-era Silk Typhoon attacks appeared first on CyberSc…CYBERSCOOP.COM
28 AprISC Stormcast For Tuesday, April 28th, 2026 https://isc.sans.edu/podcastdetail/9908, (Tue, Apr 28th)(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.ISC.SANS.EDU
28 AprMicrosoft Expands Copilot Agent Mode for Outlook Inbox and Calendar TasksMicrosoft announced a major evolution for Copilot in Outlook, shifting the tool from a passive assistant to an autonomous agent. Instead of simply drafting emails or summarizing threads on command, the AI now actively manages ongoing daily tasks. This agentic update enables the s…GBHACKERS.COM
28 AprChinese-Backed Smishing Rings Scale Credential Theft via SMS and OTT AppsChinese-language phishing-as-a-service (PhaaS) platforms are rapidly expanding their global reach by leveraging SMS and over-the-top (OTT) messaging channels such as iMessage and Rich Communication Services (RCS). Over the past several months, researchers have conducted large-sca…GBHACKERS.COM
28 AprSandworm Uses SSH-over-Tor Tunnel for Stealthy Long-Term PersistenceA significant evolution in Sandworm (APT-C-13) tradecraft, revealing the group’s use of SSH-over-Tor tunneling to achieve long-term, covert persistence inside targeted networks. Sandworm, also known as FROZENBARENTS, is a state-sponsored threat group active since 2014. It has con…GBHACKERS.COM
28 AprWhatsApp Tests Encrypted Cloud Backup Service for Safer Message StorageWhatsApp is actively developing an independent, first-party cloud backup service featuring mandatory end-to-end encryption. This upcoming feature aims to reduce users’ reliance on third-party storage providers such as Google Drive and Apple’s iCloud. By bringing backup stor…GBHACKERS.COM
28 AprOilRig Hides C2 Config in Google Drive Image via LSB SteganographyAPT-C-49 (OilRig), an Iranian state-sponsored advanced persistent threat group also known as APT34 and Helix Kitten, has deployed a sophisticated new attack campaign that conceals command-and-control configurations inside Google Drive images using LSB steganography. The group, wh…GBHACKERS.COM
28 AprFake KYC Android Malware Spreads via WhatsApp to Hijack Bank AccountsA new Android malware campaign is masquerading as a “Banking KYC” verification app and spreading via WhatsApp messages to target banking users in India. The malware is delivered as an APK shared over WhatsApp, posing as an urgent bank KYC or account verification update similar to…GBHACKERS.COM
28 AprGUEST ESSAY: How augmented reality (AR) can turn building images into ad space with no controlEvery major building in America has three things: a physical address, a legal owner, and an unmonitored attack surface. Related: Sam Altman’s quest to usurp the browswer That surface extends from the ground up through every floor, every facade, and … (more…) The post …LASTWATCHDOG.COM
28 AprU.S. companies hit with record fines for privacy in 2025The increase is being driven by powerful privacy laws in states like California, new interstate partnerships and a renewed focus on the privacy impacts of AI and automation. The post U.S. companies hit with record fines for privacy in 2025 appeared first on CyberScoop .CYBERSCOOP.COM
28 AprNorth Korean Hackers Target Crypto Firms with ClickFix and AI-Made Zoom LuresArctic Wolf attributed this large-scale spear-phishing campaign to BlueNoroff, a financially motivated subgroup of the Lazarus GroupINFOSECURITY-MAGAZINE.COM
28 AprGoogle Cloud Next AI Keynote: 5 Takeaways for IT LeadersThomas Kurian’s Google Cloud Next keynote framed Google’s agentic AI vision. Here are five key takeaways for IT leaders. The post Google Cloud Next AI Keynote: 5 Takeaways for IT Leaders appeared first on TechRepublic .TECHREPUBLIC.COM
28 AprBest Legal Project Management Software in 2026What is the best legal project management software? Use our guide to help you compare pricing and features of our top picks. The post Best Legal Project Management Software in 2026 appeared first on TechRepublic .TECHREPUBLIC.COM
28 AprFake CAPTCHA scam turns a quick click into a costly phone billScammers are using fake CAPTCHA pages to rack up international SMS charges on victims’ phone bills, and then take a cut.MALWAREBYTES.COM
28 AprSilk Typhoon Hacker Extradited to U.S. from ItalyChinese authorities-linked hacker Xu Zewei, accused of playing a central role in the notorious Silk Typhoon (HAFNIUM) cyber campaign, has been extradited from Italy to the United States, marking a significant development in ongoing efforts to combat state-sponsored cyber espionag…GBHACKERS.COM
28 AprPhishing-to-RMM Attacks: The Remote Access Blind Spot CISOs Can’t IgnoreCISOs are under pressure to prove that their security programs can detect threats early, reduce business risk, and support fast, confident response. But that becomes harder when attackers stop relying on obviously malicious tools. In recent phishing-to-RMM campaigns observed by A…ANY.RUN
28 AprChinese National Extradited Over Silk Typhoon Cyber CampaignExtradition links alleged MSS-directed hacker to Silk Typhoon and COVID-19 espionageINFOSECURITY-MAGAZINE.COM
28 Apr5 Stages of The Threat Intelligence Lifecycle5-stages-of-the-threat-intelligence-lifecycleSOCRADAR.IO
28 AprCyberheistNews Vol 16 #17 [Heads Up] This Sophisticated Scam Should Be a Warning to All CompaniesKNOWBE4.COM
28 AprAI’s False Novelty TrapAsking AI for “novel techniques” can produce a mix of non-working ideas and recycled methods that already exist. In some cases, researchers mistakenly publish these as new findings. This creates a hidden risk where AI accelerates output but degrades originality. Without proper ve…YOUTUBE.COM
28 AprRep. Delia Ramirez takes over as top House cybersecurity Demhe replaces Rep. Eric Swalwell following his resignation, giving her the position of ranking member of the Subcommittee on Cybersecurity and Infrastructure Protection. The post Rep. Delia Ramirez takes over as top House cybersecurity Dem appeared first on CyberScoop .CYBERSCOOP.COM
28 Apr‘Fundamental tension’ undermines manufacturers’ cybersecurityA simple security mistake caused roughly one-quarter of all financial losses in the sector in 2025, cybersecurity insurer Resilience said.CYBERSECURITYDIVE.COM
28 AprStop Juggling AI Tools — This Lifetime Deal Puts GPT‑4o and More in One PlaceHarness multiple top-tier models like GPT‑4o, Claude, Gemini, and more in one unified platform, now $75. The post Stop Juggling AI Tools — This Lifetime Deal Puts GPT‑4o and More in One Place appeared first on TechRepublic .TECHREPUBLIC.COM
28 AprVisual Studio 2026 Brings AI Deeper Into Development and It’s 90% Off Right NowMicrosoft's latest 64-bit IDE adds AI-assisted coding, faster performance, and advanced collaboration tools. The post Visual Studio 2026 Brings AI Deeper Into Development and It’s 90% Off Right Now appeared first on TechRepublic .TECHREPUBLIC.COM
28 Apr50k on YouTube!Built by this crew, powered by this community. 50,000 people decided cybersecurity content should be: real, unfiltered, occasionally chaotic, and always worth watching. We couldn’t agree more. Thank you for choosing Security Weekly. ❤️ Subscribe to our podcasts: https://securityw…YOUTUBE.COM
28 Apr50K Subscribers. This is Security Weekly.Built by this crew, powered by this community. 50,000 people decided cybersecurity content should be real, unfiltered, occasionally chaotic, and always worth watching. We couldn’t agree more. Thank you for choosing Security Weekly. ❤️ Subscribe to our podcasts: https://securitywe…YOUTUBE.COM
28 AprApple’s $599 Mac mini Sells Out, Resurfaces on eBay Above RetailApple’s sold-out $599 M4 Mac mini is getting marked up on eBay as buyers chase compact machines for local AI work while supplies stay tight. The post Apple’s $599 Mac mini Sells Out, Resurfaces on eBay Above Retail appeared first on TechRepublic .TECHREPUBLIC.COM
28 AprGoogle, Kaggle Relaunch Free AI Course Focused on ‘Vibe Coding’Google and Kaggle’s free AI agents course returns June 15-19, with vibe coding lessons, live sessions, and a hands-on capstone project. The post Google, Kaggle Relaunch Free AI Course Focused on ‘Vibe Coding’ appeared first on TechRepublic .TECHREPUBLIC.COM
28 AprSamsung Galaxy Glasses Leak: Pricing, Specs, and Launch Timeline RevealedSamsung’s rumored smart glasses may challenge Meta with AI features, display-free design, leaked pricing, and a possible 2027 AR roadmap. The post Samsung Galaxy Glasses Leak: Pricing, Specs, and Launch Timeline Revealed appeared first on TechRepublic .TECHREPUBLIC.COM
28 Apr‘Windows K2’ Could Be Microsoft’s Answer to Years of Windows 11 FrustrationMicrosoft’s Windows K2 effort aims to improve Windows 11 performance, reliability, updates, taskbar flexibility, and user feedback loops. The post ‘Windows K2’ Could Be Microsoft’s Answer to Years of Windows 11 Frustration appeared first on TechRepublic .TECHREPUBLIC.COM
28 AprXpeng Flying Car Deliveries Target 2027 as Certification Gaps RemainXpeng’s flying car factory is moving from prototype to production, but certification gaps still separate delivery plans from public passenger service. The post Xpeng Flying Car Deliveries Target 2027 as Certification Gaps Remain appeared first on TechRepublic .TECHREPUBLIC.COM
28 AprORMs Reopened Injection RisksSQL injection was largely mitigated by prepared statements. However, newer abstractions like ORMs reintroduce flexibility, allowing developers to construct queries in more dynamic ways. That added flexibility can recreate conditions similar to classic injection vulnerabilities. W…YOUTUBE.COM
28 AprPolice arrest 10 suspected members of Black Axe cybercrime gangA coordinated police operation in Switzerland has targeted suspected members of the Black Axe criminal network. On 28 April 2026, authorities carried out house searches across several Swiss cantons, leading to 10 arrests, including the Black Axe ‘Regional Head’ for Southern Europ…HELPNETSECURITY.COM
28 AprFederal CIO cautious on Anthropic’s Mythos despite planned rolloutGreg Barbaccia told CyberScoop that Anthropic's Mythos shows real promise for federal cyber defense, but warns that laboratory results and live network conditions are two very different things. The post Federal CIO cautious on Anthropic’s Mythos despite planned rollout appeared f…CYBERSCOOP.COM
28 AprElfsmasher, PYPI, Facebook, Glassworm, Medtronic, OpenSSH, Sararimen, Aaran Leyland - SWN #576Elfsmasher, PYPI, Facebook, Glassworm, Medtronic, OpenSSH, Entrepreneurs, Sararimen, Aaran Leyland, and More on the Security Weekly News. Visit https://www.securityweekly.com/swn for all the latest episodes! Show Notes: https://securityweekly.com/swn-576YOUTUBE.COM
28 AprClickUp Data Leak Exposes Enterprise Emails for Over a YearA hardcoded ClickUp API key exposed hundreds of corporate and government emails for over a year, raising new SaaS security concerns. The post ClickUp Data Leak Exposes Enterprise Emails for Over a Year appeared first on TechRepublic .TECHREPUBLIC.COM
28 AprBlueNoroff Uses Fake Zoom Calls to Turn Victims Into Attack LuresThe North Korean group is using stolen victim videos, AI-generated avatars, and fake Zoom calls to scale malware attacks against cryptocurrency executives.DARKREADING.COM
28 AprPlay-to-Earn Collapse RiskA play-to-earn game offered crypto rewards, NFT assets, and “founder nodes” that distributed tokens to early adopters. As prices rose, early buyers profited. But the structure resembles a pump-and-dump, where gains depend on later participants entering the system. That creates as…YOUTUBE.COM
28 AprFIDO Alliance wants to keep AI agents from going rogue on online paymentsAI agents are beginning to shop, log in, and complete tasks with little direct input. That shift is pushing the security industry to rethink how trust works when actions are carried out on a user’s behalf. The FIDO Alliance has announced a set of initiatives to build shared stand…HELPNETSECURITY.COM
28 AprSN 1076: FAST16.SYS - Unmasking the NSA's Most Diabolical Digital SabotageWhat if your engineering calculations secretly sabotaged your nation's best efforts? This week, we reveal how a newly uncovered 21-year-old NSA rootkit quietly corrupted scientific research in hostile states and why it changes everything you think you know about cyberwarfare. Bit…TWIT.TV
27 AprNPM Worm Hits Namastex Packages, Steals Secrets Across RegistriesA newly uncovered npm malware campaign is targeting packages linked to Namastex Labs, abusing developer trust to steal sensitive secrets and silently spread across both npm and PyPI ecosystems. The malicious activity centers on Namastex.ai, a company that promotes AI consulting s…GBHACKERS.COM
27 AprClickFix Attack Swaps PowerShell for Cmdkey, Remote Regsvr32 PayloadsA newly identified ClickFix attack variant is raising concerns among cybersecurity researchers after it was observed replacing traditional PowerShell-based delivery with a stealthier technique leveraging native Windows utilities. The infection begins with a familiar ClickFix tact…GBHACKERS.COM
27 AprVidar Malware Conceals Payloads in JPEG, TXT Files to Evade DetectionVidar has evolved from a basic Arkei-based credential stealer into a multi-stage, stealth-focused infostealer that now hides second‑stage payloads within JPEG and TXT files to evade modern defenses. First observed in 2018, Vidar now operates as a mature Malware‑as‑a‑Service (MaaS…GBHACKERS.COM
27 AprFast16 Malware Targets High-Value Systems With Sabotage CapabilitiesA previously unknown cyber sabotage framework called fast16, whose core components date back to 2005. This makes it the earliest known sabotage malware of its kind, predating the infamous Stuxnet worm by at least five years. The fast16 framework consists of two primary components…GBHACKERS.COM
27 AprSuspicious Microsoft Store App Vibing.exe Allegedly Harvests Screens and AudioA recently discovered application called Vibing.exe has raised major privacy and security alarms after researchers caught it stealthily recording user screens and audio. Originally available on the Microsoft Store as an AI productivity interface, the app was pulled in late April …GBHACKERS.COM
27 AprItaly moves to extradite Chinese national to the U.S. over hacking chargesItaly plans to extradite Xu Zewei to the U.S. over alleged hacks on COVID-19 research tied to state-backed operations. Italy is moving to extradite Xu Zewei, the Chinese national arrested in 2025 at the request of U.S. authorities on cyber-espionage charges, Bloomberg reported. T…SECURITYAFFAIRS.COM
27 AprAptori expands its platform with autonomous offensive testing to reduce security bottlenecksAptori has expanded its Runtime-Driven Validation Platform with autonomous offensive testing capabilities to address the growing gap between code output and security team capacity. By moving beyond passive scanning to active validation, the platform helps organizations identify, …HELPNETSECURITY.COM
27 AprYour IAM was built for humans, AI agents don’t careIdentity and access management was built for a simpler world. One where the hardest problem was a human logging in, and where “Who are you?” was sufficient to decide what someone could do. That model served enterprises well for decades. It was not built for a world wh…HELPNETSECURITY.COM
27 AprThe AI criminal mastermind is already hiring on gig platformsLabor-hire platforms let anyone with a credit card post a task and pay a stranger to complete it. The RentAHuman platform extends that model to AI agents through a Model Context Protocol server, allowing an agent to post gigs directly. Listed tasks include attending in-person mee…HELPNETSECURITY.COM
27 AprNorth Korean Hackers Target Pharma Firms with Malware-Laced Excel AttacksNorth Korean state-backed hackers are using weaponized Excel-themed files to infect pharmaceutical and life science companies with malware, abusing Windows shortcut files, PowerShell, and cloud storage for stealthy data theft. The campaign begins with highly tailored spear‑phishi…GBHACKERS.COM
27 AprWhy I Chose This $19.97 Lifetime Deal Over MasterClassCompared to MasterClass, this platform offers lifetime access to 1,000+ courses, and it’s worth $600 MSRP. The post Why I Chose This $19.97 Lifetime Deal Over MasterClass appeared first on TechRepublic .TECHREPUBLIC.COM
27 Apr7 Best Project Budgeting Software in 2026Looking for the best project budgeting software for your business? Discover the pros and cons of the top tools with our guide. The post 7 Best Project Budgeting Software in 2026 appeared first on TechRepublic .TECHREPUBLIC.COM
27 AprLinux ELF Malware Generator Evades ML Detection With Semantic-Preserving ChangesAs Linux continues to dominate high-performance computing, cloud services, and Internet of Things (IoT) devices, it has become a prime target for cybercriminals. However, while much research has focused on manipulating Windows executables to bypass security, the Linux Executable …GBHACKERS.COM
27 AprResearchers Warn macOS textutil, KeePassXC Can Fuel Automation AttacksResearchers are warning that widely trusted local tools such as macOS’s textutil and KeePassXC can pose unexpected security risks when used within automated workflows. The issue is not traditional vulnerabilities such as memory corruption or code execution, but how normal f…GBHACKERS.COM
27 AprMedieval Encrypted Letter DecodedSent by a Spanish diplomat. Apparently people have been working on it since it was rediscovered in 1860.SCHNEIER.COM
27 AprPrice Drop: Upgrade to Windows 11 Pro for Only $10Unlock the latest user interface, enhanced security features, and new tools for hybrid and remote workers. The post Price Drop: Upgrade to Windows 11 Pro for Only $10 appeared first on TechRepublic .TECHREPUBLIC.COM
27 AprNew Malware Hides Behind Obfuscation and Staged PayloadsA newly identified malware campaign is leveraging advanced obfuscation techniques and multi-stage payload delivery to bypass traditional security defenses, according to recent analysis from Joe Sandbox. The attack begins with a highly targeted spear-phishing email sent to employe…GBHACKERS.COM
27 AprFake YouTube Downloads Spread Vidar Malware to Steal Corporate LoginsA new Vidar infostealer campaign is abusing fake software download links on YouTube to compromise corporate employees and sell their stolen credentials on Russian cybercrime marketplaces. In the investigated case, the victim was searching for software on YouTube and likely follow…GBHACKERS.COM
27 AprAnthropic Draws Google’s $40B Bet in Latest AI MegadealGoogle is preparing an investment in Anthropic worth up to $40B, pairing cash with cloud capacity as demand for Claude fuels the latest major AI megadeal. The post Anthropic Draws Google’s $40B Bet in Latest AI Megadeal appeared first on TechRepublic .TECHREPUBLIC.COM
27 AprGet Lifetime Access to Microsoft Office 2021 for Just $30Whether you're starting a new business venture and need Microsoft Office's help or you just want to get better organized in your personal life, it's a good time to take advantage of this deal. The post Get Lifetime Access to Microsoft Office 2021 for Just $30 appeared first on Te…TECHREPUBLIC.COM
27 AprBlackFile actively extorting data-theft victims in retail and hospitality sectorSome attackers, which researchers link to The Com, have swatted company executives to increase leverage and pressure victims to pay their ransom demands. The post BlackFile actively extorting data-theft victims in retail and hospitality sector appeared first on CyberScoop .CYBERSCOOP.COM
27 AprNew Hack Lets 30-Year-Old Windows PCs Run Modern LinuxWSL9x lets Windows 9x systems run a modern Linux 6.19 kernel without virtualization, showing how vintage PCs can still stretch beyond old limits. The post New Hack Lets 30-Year-Old Windows PCs Run Modern Linux appeared first on TechRepublic .TECHREPUBLIC.COM
27 AprChina’s Honor Just Launched an iPhone Lookalike in EuropeHonor’s new 600 series arrives in Europe with iPhone-like styling, strong specs, and a 7,000mAh battery, but it is not really a budget phone. The post China’s Honor Just Launched an iPhone Lookalike in Europe appeared first on TechRepublic .TECHREPUBLIC.COM
27 AprApple Watch Blood Oxygen Monitoring Gets Major BreakthroughApple can keep selling Apple Watches with its redesigned blood oxygen feature in the US after the ITC declined to revive Masimo’s ban. The post Apple Watch Blood Oxygen Monitoring Gets Major Breakthrough appeared first on TechRepublic .TECHREPUBLIC.COM
27 AprEU’s proposed Google data access rule could enable large-scale surveillanceThe European Commission is facing criticism from security and privacy experts over a proposed Digital Markets Act (DMA) measure that would require Google to share vast amounts of search data with third parties via an automated API. Critics warn the plan could expose sensitive use…CYBERINSIDER.COM
27 AprEU Funds Sovereign Cloud Infrastructure with €180 Million ContractThe European Commission has awarded a €180 million contract to four providers—Post Telecom, STACKIT, Scaleway, and Proximus—to provide sovereign cloud services, ensuring EU data remains under European legal and strategic control. The post EU Funds Sovereign Cloud Infrastructure w…TECHREPUBLIC.COM
27 AprChina Startup Secures $8.4B in Credit Lines for Orbital Data Center PushChina’s Orbital Chenguang secured major credit lines for space-based data centers as AI demand strains power, land, and cooling capacity. The post China Startup Secures $8.4B in Credit Lines for Orbital Data Center Push appeared first on TechRepublic .TECHREPUBLIC.COM
27 AprThe Prompt Engineering Cheat Sheet: How to Write Better AI PromptsLearn prompt engineering with this practical cheat sheet that covers frameworks, techniques, and tips for producing more accurate and useful AI outputs. The post The Prompt Engineering Cheat Sheet: How to Write Better AI Prompts appeared first on TechRepublic .TECHREPUBLIC.COM
27 AprChina Shuts Down Meta’s $2.5B Bid for AI Startup ManusChina has blocked Meta’s $2.5 billion Manus AI acquisition, raising new questions about cross-border AI deals and who controls agent technology. The post China Shuts Down Meta’s $2.5B Bid for AI Startup Manus appeared first on TechRepublic .TECHREPUBLIC.COM
27 AprApple ‘Ultra’ 2026: A New iPhone, MacBook Tier May Be ComingApple may expand Ultra branding to a foldable iPhone and MacBook Ultra, creating a new premium tier above Pro devices. The post Apple ‘Ultra’ 2026: A New iPhone, MacBook Tier May Be Coming appeared first on TechRepublic .TECHREPUBLIC.COM
27 AprTruecaller Faces New Pressure in India as Growth MaturesTruecaller has hit 500 million monthly users, but slower growth in India, CNAP rollout, and ad pressure are testing whether its next phase can be as strong as its first. The post Truecaller Faces New Pressure in India as Growth Matures appeared first on TechRepublic .TECHREPUBLIC.COM
27 AprWhatsApp to End Support for Millions of Older Android Phones in 2026WhatsApp will stop supporting Android 5 devices in September 2026, requiring users to upgrade to Android 6 or newer. The post WhatsApp to End Support for Millions of Older Android Phones in 2026 appeared first on TechRepublic .TECHREPUBLIC.COM
27 AprUNC6692 Combines Social Engineering, Malware, Cloud AbuseA newly discovered threat actor is using Microsoft Teams, AWS S3 buckets, and custom "Snow" malware in a multipronged campaign.DARKREADING.COM
27 AprSupreme Court justices skeptically question both sides in geofence surveillance caseA ruling could come this summer in Chatrie v. United States, which could have bigger ramifications about the scope of government surveillance. The post Supreme Court justices skeptically question both sides in geofence surveillance case appeared first on CyberScoop .CYBERSCOOP.COM
26 AprXChat launches standalone iOS app as security concerns remainX has launched a standalone iOS app for its XChat messaging platform, promoting it as a private, end-to-end encrypted communication tool, but concerns about its security model continue to shadow the release. The announcement was made on X, marking the first time XChat has been of…CYBERINSIDER.COM
26 AprGopherWhisper: new China-linked APT targets Mongolia with Go-based malwareESET found a new China-linked APT, tracked as GopherWhisper, targeting Mongolia using Go-based malware, loaders, and backdoors. ESET researchers uncovered a new China-aligned APT group called GopherWhisper, targeting government institutions in Mongolia. The group’s arsenal …SECURITYAFFAIRS.COM
26 AprNpm Slop & Wonky Software Supply Chainssubmitted by codeinabox to security 1 points | 0 comments https://simonramstedt.com/blog/2026-04-09-npm-slop-and-wonky-software-supply-chains/ cross-posted from: lemmy.bestiver.se/post/1069240 CommentsPROGRAMMING.DEV
24 AprISC Stormcast For Friday, April 24th, 2026 https://isc.sans.edu/podcastdetail/9906, (Fri, Apr 24th)(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.ISC.SANS.EDU
24 AprPLC Cybersecurity — Securing Industrial Control Systemssubmitted by monica_b1998 to cybersecurity 2 points | 0 comments https://slicker.me/plc/cybersecurity.htmlINFOSEC.PUB
24 AprTurn Your iPad Into a Work Machine While This Keyboard Case Is $30 OffImprove multitasking on iPad with responsive keys, gesture controls, and flexible viewing angles built in. The post Turn Your iPad Into a Work Machine While This Keyboard Case Is $30 Off appeared first on TechRepublic .TECHREPUBLIC.COM
24 AprSign, Send, and Manage Documents Online for Just $79SignIt gives teams a complete eSignature platform with audit trails, bulk sending, and SSO for one low price. The post Sign, Send, and Manage Documents Online for Just $79 appeared first on TechRepublic .TECHREPUBLIC.COM
24 AprUbuntu 26.04 LTS delivers memory-safe system tools and live patching for Arm serversLinux distributions have spent the past few years absorbing GPU vendor toolchains, Rust-based system components, and more stringent encryption defaults. Ubuntu 26.04 LTS, codenamed Resolute Raccoon, pulls most of those threads together into a single release that will receive stan…HELPNETSECURITY.COM
24 AprOpenAI’s GPT-5.5 is out with expanded cybersecurity safeguardsCompetition to release stronger AI models is accelerating, and just weeks after the release of GPT-5.4, OpenAI has introduced GPT-5.5, pointing to expanded safeguards in the new model. GPT-5.5 is being rolled out to Plus, Pro, Business, and Enterprise users in ChatGPT and Codex, …HELPNETSECURITY.COM
24 AprVoid Dokkaebi Hackers Spread Malware Through Fake Job InterviewsVoid Dokkaebi, also known as Famous Chollima, is expanding its cyber operations by turning fake job interviews into a large-scale malware distribution campaign targeting developers. The campaign begins with attackers posing as recruiters from cryptocurrency or AI companies. Devel…GBHACKERS.COM
24 AprCovert telecom spying campaign “Ghost Operators” tracks users worldwideCitizen Lab has identified two advanced surveillance campaigns abusing weaknesses in global telecom networks to track mobile users and, in some cases, turn SIM cards into silent spying tools. The investigation began in late 2024 after anomalous activity was detected in signaling …CYBERINSIDER.COM
24 AprMeta is overhauling how you sign in, manage settings, and protect your accountsMeta Account gives users of Meta apps and devices a simpler way to access and manage their accounts. Accounts Center will automatically be updated to a Meta Account as part of a gradual rollout over the next year. Users will be notified when the change occurs. It supports Meta te…HELPNETSECURITY.COM
24 AprFake CAPTCHA Scam Triggers Costly SMS FraudHackers are abusing fake CAPTCHA pages to run a silent but lucrative international SMS fraud scheme, turning routine “prove you’re human” checks into a revenue engine built on international revenue share fraud (IRSF). Attackers set up lookalike and scam domains that eventually re…GBHACKERS.COM
24 AprHiding Bluetooth Trackers in MailIt was used to track a Dutch naval ship: Dutch journalist Just Vervaart, working for regional media network Omroep Gelderland, followed the directions posted on the Dutch government website and mailed a postcard with a hidden tracker inside. Because of this, they were able to tra…SCHNEIER.COM
24 AprGPT-5.5 Bio Bug Bounty Program Aims to Improve AI Safety and PerformanceOpenAI has officially launched the GPT-5.5 Bio Bug Bounty program to strengthen safeguards against emerging biological risks. As artificial intelligence models become more advanced, the potential for malicious actors to generate dangerous biological information increases. Advance…GBHACKERS.COM
24 AprClaude Desktop Reportedly Adds Browser Access Bridge for Chromium BrowsersA detailed cybersecurity report published by privacy expert Alexander Hanff on April 18, 2026, reveals that Anthropic’s Claude Desktop application for macOS silently installs a Native Messaging bridge across multiple Chromium-based browsers. This unprompted installation establish…GBHACKERS.COM
24 AprMythos Mystery in Mozilla Numbers: How 22 Vulns Became 271 or Maybe 3 in Aprilsubmitted by codeinabox to security 1 points | 0 comments https://www.flyingpenguin.com/mythos-mystery-in-mozilla-numbers-how-22-vulns-became-271-or-maybe-3-in-april/PROGRAMMING.DEV
24 AprInside agenteV2: How Brazilian Attackers Use Fake Court Summons to Steal Banking Credentials in Real TimeA new phishing campaign targeting Brazilian users demonstrates how modern financial malware has evolved from simple credential theft into full-scale, operator-driven fraud platforms. Disguised as a judicial summons, this campaign leverages social engineering, multi…ANY.RUN
24 AprOff-Topic Fridaysubmitted by shellsharks to cybersecurity 2 points | 0 comments Wanna chat about something non-infosec amongst those of us who frequent /c/cybersecurity? Here’s your chance! (Keep things civil & respectful please)INFOSEC.PUB
24 AprNorth Korea's Lazarus Targets macOS Users via ClickFixLazarus continues leveraging ClickFix for initial access and data theft, in this case, against Mac-centric organizations and their high-value leaders.DARKREADING.COM
24 AprWindows 10 Support Is Over. Here Are 6 Options for UsersWindows 10 support has ended, leaving millions exposed. Here are six options, from upgrading to Windows 11 to switching to Linux or ChromeOS Flex. The post Windows 10 Support Is Over. Here Are 6 Options for Users appeared first on TechRepublic .TECHREPUBLIC.COM
24 AprUS lawmakers introduce bill to require warrants for government data searchesUS lawmakers have introduced a new bill that would dramatically tighten government surveillance powers by requiring warrants for nearly all data searches involving Americans. The proposed “Surveillance Accountability Act” would also give individuals the right to sue federal offic…CYBERINSIDER.COM
24 AprHealth Records of 500,000 UK Biobank Volunteers Listed Online in ChinaHealth data from 500,000 UK Biobank participants was found listed for sale online in China, raising concerns over research access misuse and data security. The post Health Records of 500,000 UK Biobank Volunteers Listed Online in China appeared first on TechRepublic .TECHREPUBLIC.COM
24 AprTGR-STA-1030: New Activity in Central and South AmericaUnit 42 research reports that TGR-STA-1030 remains an active threat, particularly in Central and South America. The post TGR-STA-1030: New Activity in Central and South America appeared first on Unit 42 .UNIT42.PALOALTONETWORKS.COM
24 AprFriday Squid Blogging: How Squid Survived Extinction EventsScience news : Scientists have finally cracked a long-standing mystery about squid and cuttlefish evolution by analyzing newly sequenced genomes alongside global datasets. The research reveals that these bizarre, intelligent creatures likely originated deep in the ocean over 100 …SCHNEIER.COM
24 AprScylla &Charybdis, Kyber, Trigonia, Namastex, GitHub, Crypto, Cables, Aaran Leyland - SWN #575SScylla and Charybdis, Latin Phrasebook, Kyber, Trigonia, Namastex, GitHub, Crypto, Cables, Aaran Leyland, and More on this episode of the Security Weekly News. Visit https://www.securityweekly.com/swn for all the latest episodes! Show Notes: https://securityweekly.com/swn-575YOUTUBE.COM
24 AprThe npm Threat Landscape: Attack Surface and MitigationsUnit 42 analyzes npm supply chain evolution post-Shai Hulud. Discover wormable malware, CI/CD persistence, multi-stage attacks and more. The post The npm Threat Landscape: Attack Surface and Mitigations appeared first on Unit 42 .UNIT42.PALOALTONETWORKS.COM
24 AprDeepSeek Drops Cheaper V4 AI as Huawei Jumps InDeepSeek launches V4 AI model with Huawei chip support, offering lower costs and intensifying global AI competition. The post DeepSeek Drops Cheaper V4 AI as Huawei Jumps In appeared first on TechRepublic .TECHREPUBLIC.COM
🌐 CYBER THREAT LANDSCAPE 347[+]
23 JulBrazilian Banking Trojan Actively Spreading in PortugalPortuguese businesses operate in the same native language as Brazilian hackers, making those businesses easy targets.DARKREADING.COM
23 JulNew Dolphin X Stealer Employs AI Profiling to Prioritize TargetsDolphin X is a new infostealer that uses AI to sort and rank victims, giving cybercriminals a faster way to identify lucrative targetsINFOSECURITY-MAGAZINE.COM
23 JulThreatsDay: Android Spyware, PLC Attacks, AI Image Prompt Injection + 12 More StoriesMost of this week's trouble came dressed as something useful. A package stole data. A fake extension opened remote access. A safety app became spyware. An image gave hidden orders to an AI agent. Other threats hid in open systems, weak code, and normal network traffic. The threat…THEHACKERNEWS.COM
23 JulHackers abuse Notepad++ plugins to stealthily install malwareUkraine's CERT has uncovered attacks distributing an archive containing the legitimate Notepad++ application and a malicious utility called LunchPoke disguised as a plugin to establish persistence. [...]BLEEPINGCOMPUTER.COM
23 JulFake Claude app promoted by Bing ads pushes SectopRAT malwareA malvertising campaign on the Bing search service is pushing a fake Claude desktop app installer hosted on a legitimate Claude.ai domain to deliver the SectopRAT malware. [...]BLEEPINGCOMPUTER.COM
22 JulTrojanized Newtonsoft.Json Fork Hides Game-Rigging Code in a Working LibraryCybersecurity researchers have discovered a NuGet typosquat that's unlike the typical information-stealing malware distributed via package registries: usual info-stealers: it's designed to rig live game results on Digitain. The package, named "Newtonsoftt.Json.Net," masquerades a…THEHACKERNEWS.COM
22 JulSol Searching | Can Frontier Models Tackle Autonomous Long-Horizon Malware Analysis?A real-world benchmark tests whether powerful AI models can keep an investigation trustworthy when new evidence invalidates their conclusions.SENTINELONE.COM
21 Jul KEVSecuring Research Infrastructure and Managing Shadow AI with Kevin MortimerHost Caleb Tolin sits down with Kevin Mortimer to discuss securing higher education infrastructure and managing the shift toward autonomous AI deployment. Kevin details his experience supporting research environments, expanding multi factor authentication controls, and defending …THECYBERWIRE.COM
21 JulIran War Cyber Threat Landscape | A Midyear Assessment on What MattersIn April, SentinelLABS’ Tom Hegel published an initial assessment of the first five weeks of the conflict. Three months later, the evidence supports refinement.SENTINELONE.COM
21 JulNew ClickLock Stealer locks your Mac until you hand over your passwordA new macOS infostealer tricks victims into revealing their system password and installs a persistent backdoor for future access.MALWAREBYTES.COM
21 JulA Sneaky Hacking Tool Targeting AI Infrastructure Is Lurking in Victims’ Blind SpotsA new type of malware can worm deep into AI coding systems to steal data and logins—and can flip a “death switch” to destroy files and keep out real users.WIRED.COM
21 JulFakeGit campaign uses 7,600 GitHub repos to push SmartLoader malwareA large-scale operation dubbed 'FakeGit' is pushing SmartLoader and StealC malware through 7,600 malicious GitHub repositories that accumulated more than 14 million downloads. [...]BLEEPINGCOMPUTER.COM
20 JulSleeperGem Uses Three Malicious RubyGems Packages to Target Developer MachinesCybersecurity researchers have flagged a new software supply chain attack codenamed SleeperGem targeting the Ruby ecosystem after three malicious gems were published to RubyGems with the end goal of serving additional payloads. The rogue gems are listed below - git_credential_man…THEHACKERNEWS.COM
20 JulA week in security (July 13 – July 19)A list of topics we covered in the week of July 13 to July 19 of 2026MALWAREBYTES.COM
20 JulFake games spread stealers with RenPy Loader, MSBuild and EtherHidingWe look into how attackers are using the legitimate Ren'Py game engine to spread a malware loader that ultimately delivers Amatera Stealer.MALWAREBYTES.COM
20 JulNew HollowGraph Malware Hijacks Microsoft 365 Calendars for Covert C2 CommunicationsResearchers have linked HollowGraph malware to the Cavern framework after discovering its use of Microsoft 365 calendars and Microsoft Graph APIs as a stealthy C2 channelINFOSECURITY-MAGAZINE.COM
20 JulOdyssey piracy scams appear within hours of the movie’s releaseThe release of The Odyssey has already sparked a wave of piracy scams, from fake browser errors to malware masquerading as movie files.MALWAREBYTES.COM
20 JulExposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware CampaignA malware operator left its delivery server wide open, and Rapid7 pulled down the whole toolkit: 1,048 files spanning lure templates, filename-spoofing tests, execution experiments, droppers, builder notes, and two campaign chains. One was already live against Windows users in Me…THEHACKERNEWS.COM
20 JulAttackers Combo Up Evasion Tactics for BEC Phishing"The TFF Trap" uses fileless techniques and loaders with low detection rates to deploy various RATs and stealers, including Agent Tesla, Remcos, XWorm, and Best Private Logger.DARKREADING.COM
20 JulFakeGit Campaign Uses 7,600 GitHub Repositories to Spread SmartLoader MalwareCybersecurity researchers have discovered nearly 7,600 malicious GitHub repositories, out of which more than 800 pose as artificial intelligence (AI) skills or Model Context Protocol (MCP) servers to deliver a malware family known as SmartLoader as part of an ongoing campaign cod…THEHACKERNEWS.COM
19 JulSecurity Affairs newsletter Round 586 by Pierluigi Paganini – INTERNATIONAL EDITIONA new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including the international press. OpenSSL Fixes HollowByte Memo…SECURITYAFFAIRS.COM
18 JulSeven Malicious Vite npm Packages Use Blockchain C2 to Deliver a RATCybersecurity researchers have discovered a cluster of seven malicious npm packages targeting the Vite frontend tooling ecosystem as part of a software supply chain attack. The malicious package campaign, codenamed ViteVenom by Checkmarx, marks an expansion of ChainVeil, which wa…THEHACKERNEWS.COM
18 JulMicrosoft warns of surge in ACR Stealer attacks on customersMicrosoft has observed a surge in attacks using the ACR Stealer malware to steal browser-stored passwords, authentication tokens, and sensitive documents from its enterprise customers. [...]BLEEPINGCOMPUTER.COM
17 JulACR Stealer Uses ClickFix Lures to Steal Browser Tokens and Microsoft 365 FilesACR Stealer, an infostealer in circulation since 2024, is walking out of enterprise networks with saved browser passwords, live session tokens, PDFs, Microsoft 365 documents, and files from synced OneDrive and SharePoint folders. It gets in because someone pasted a command into a…THEHACKERNEWS.COM
17 JulHow to use GitHub safelyKnowing how to spot a malicious GitHub repository can help you avoid downloading malware disguised as legitimate software.MALWAREBYTES.COM
17 JulFBI arrests man accused of using Steam games to drain victims’ crypto walletsProsecutors accused 21-year-old student Zyaire Wilkins of publishing on Steam several fake video games that contained malware, infecting thousands of victims, and stealing crypto from some of them.TECHCRUNCH.COM
17 JulNew NadMesh Botnet Hunts Exposed AI Services for Cloud Keys and Kubernetes TokensA Go botnet called NadMesh turned up in early July hunting exposed AI services, and the operator's own dashboard claims 3,811 unique AWS keys. A Shodan harvester keeps the scan queue stocked with ComfyUI, Ollama, n8n, Open WebUI, Langflow, and Gradio: the image generators, local …THEHACKERNEWS.COM
16 JulTELEPUZ: a modular MaaS malware spreading via CLICKFIX-VIDAR chainsTELEPUZ is a modular malware that emerged through CLICKFIX-VIDAR attacks in April. We reverse-engineered it to show you the infrastructure and evasion techniques that matter.ELASTIC.CO
16 JulTuxBot v3: The IoT Botnet Built With AI – Bugs, Disclaimers and AllTuxBot v3, an AI-built IoT botnet for 17 architectures, shipped with LLM bugs and safety disclaimers the developer never removed. Palo Alto Networks’ Unit 42 identified a previously undocumented modular IoT botnet framework called TuxBot v3 Evolution, and it comes with an u…SECURITYAFFAIRS.COM
16 JulNew TELEPUZ Malware Spreads via ClickFix to Steal Data and Run CommandsCybersecurity researchers have called attention to a new modular malware called TELEPUZ that's been spreading via websites infected with ClickFix lures since late April 2026. "The malware is full-featured, lightweight, and modular," Elastic Security Labs researcher Cyril François…THEHACKERNEWS.COM
16 JulNew ClickLock macOS Stealer Kills Apps Every 210ms Until Victims Type Their PasswordClickLock Stealer, a new macOS infostealer, answers a victim's refusal by killing their apps on a loop until they hand over the login password. It arrives as a command pasted into Terminal, asks for the password behind a fake system dialog, and when the victim cancels, installs t…THEHACKERNEWS.COM
16 JulPhishing Campaign Hides Lua Loader as TrueType Font FileGlobal phishing campaign disguised a Lua loader as a font file to deploy RATs and infostealersINFOSECURITY-MAGAZINE.COM
16 JulPeriod tracker Stardust shares users’ health data with analytics firm, says Mozilla researchOne period tracker app tested by Mozilla was 'squeaky clean,' while another app was seen sharing users' health data with an analytics company, underscoring vast differences in user privacy among these apps.TECHCRUNCH.COM
15 Jul AsyncAPI npm packages infected with credential-stealing malwareFive malicious versions of AsyncAPI packages were published to the Node Package Manager (npm) in a supply-chain attack that delivered a remote access trojan with info-stealing capabilities. [...]BLEEPINGCOMPUTER.COM
15 JulOkoBot Malware Framework Injects Seed Phrase Phishing Into Ledger and Trezor AppsA malware framework called OkoBot has been running on Windows machines since April 2025, and one of its modules is built to con hardware wallet owners out of their recovery phrase. On an infected PC, the request comes from inside the wallet's own desktop software. Sometimes it wa…THEHACKERNEWS.COM
14 Jul148 npm Packages Disguised as Student Proxies Turned Browsers Into a DDoS BotnetA campaign of 148 npm packages disguised as student web proxies turned visitors' browsers into a distributed denial-of-service botnet for roughly two weeks in May, according to new research from JFrog. The packages did not go after the developers who might install them. The …THEHACKERNEWS.COM
14 JulM-Red-Team: AsyncAPI Supply Chain Compromise via GitHub ActionsDetect and mitigate malicious @asyncapi npm packages linked to the latest npm supply chain attack.WIZ.IO
14 JulClickFix's Mushrooming Ecosystem Demands New Defense TacticsThe attack vector is available for rent at scale, and evades AV and EDR, leaving YARA analysis as the best detection option.DARKREADING.COM
14 JulLabubaRAT Masquerades as NVIDIA Software to Control Windows HostsCybersecurity researchers have flagged a previously undocumented Rust-based remote access trojan (RAT) codenamed LabubaRAT that masquerades as NVIDIA software to blend into target environments. "LabubaRAT creates a reusable foothold for hands-on activity," Blackpoint Cyber resear…THEHACKERNEWS.COM
13 JulA week in security (July 6 – July 12)A list of topics we covered in the week of July 6 to July 12 of 2026MALWAREBYTES.COM
13 JulUS and allies warn of Russian critical infrastructure attacksCybersecurity agencies from the United States and eight other countries have issued a joint warning that Russian state hackers are targeting vulnerable and poorly configured routers to infiltrate critical infrastructure networks. [...]BLEEPINGCOMPUTER.COM
13 JulForg365 PhaaS Targets Microsoft 365 with Device Code and AitM Session TheftA new phishing-as-a-service (PhaaS) operation called Forg365 is using a combination of device code phishing, adversary-in-the-middle (AitM) tactics, antibot evasion, artificial intelligence (AI)-assisted lure creation, and post-compromise mailbox operations targeting Microsoft 36…THEHACKERNEWS.COM
13 JulNew CrashStealer malware poses as Apple crash reporting toolA new macOS information-stealing malware called CrashStealer pretends to be Apple's crash-reporting tool to steal credentials, keychain data, and crypto wallets. [...]BLEEPINGCOMPUTER.COM
12 JulRedHook Android malware now uses Wireless ADB for shell accessA new version of the RedHook Android malware abuses the Android Wireless Debugging (Wireless ADB) mechanism in a novel way to gain shell-level privileges without requiring a computer connection. [...]BLEEPINGCOMPUTER.COM
12 JulSECURITY AFFAIRS MALWARE NEWSLETTER ROUND 105Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter Novel Java-Based QuimaRAT Targets Windows, macOS, and Linux Vibe Coded Extortion: Avalon’s Path from Legal Lure to …SECURITYAFFAIRS.COM
11 JulAustralian telecom outage attributed to software bug.FBI disrupts residential proxy network used by botnet. Zimbra patches a critical flaw in its Classic Web Client.THECYBERWIRE.COM
10 JulFrom 17,000 to 1.1 Million Assets: How Lumen Technologies Rebuilt Exposure Management at ScaleMost enterprises assume their asset inventory is close enough to accurate. The evidence suggests otherwise. According to a survey of over 600 security leaders in the 2026 Axonius Actionability Report, only 45% of organizations consolidate their asset and exposure data into a sing…THEHACKERNEWS.COM
10 JulExposed Hacker Server Reveals WP-SHELLSTORM Backdooring Thousands of WordPress SitesA cybercrime crew left one of its own servers wide open on the internet for three weeks, and it exposed the operation's inner workings: the hacking tools, the activity logs, and target lists naming more than 1.4 million websites. Far fewer were actually broken into, but the expos…THEHACKERNEWS.COM
10 JulStudy of 281 Free Android VPN Apps Finds Traffic Leaks, Unencrypted Data, and TrackingResearchers ran 281 of the most popular free VPN apps on the Google Play Store through a new testing system and found that many fail at the basics people install a VPN for, i.e., keeping their traffic private and secure. The apps flagged with at least one problem have been instal…THEHACKERNEWS.COM
10 Jul222 GitHub Repositories Linked to Fake Go Package Malware OperationResearchers uncovered 222 GitHub repositories spreading malware through fake Go packages, delivering loaders, stealers, RATs, and cryptominers. Socket’s security research team started with the investigation of a single malicious Go module: github[.]com/kaleidora/dnsub-scann…SECURITYAFFAIRS.COM
10 JulNew MODBEACON RAT Uses gRPC Streaming for Encrypted C2 TrafficThe China-linked cybercrime group known as Silver Fox has been attributed to a new Rust-based remote access trojan (RAR) called MODBEACON. Chinese cybersecurity company QiAnXin said that while the threat cluster may appear like a low-sophistication, high-activity operation that p…THEHACKERNEWS.COM
10 JulThis new Windows malware can take over your PC and wipe it cleanGigaWiper is a remote access Trojan that can spy on victims and permanently wipe their systems in three different ways.MALWAREBYTES.COM
10 JulNew U-Boot flaws could enable stealthy firmware attacksSix vulnerabilities in the widely used U-Boot bootloader have been discovered that could allow attackers to execute malicious code during device boot, potentially enabling stealthy firmware attacks that compromise security protections and install persistent malware. [...]BLEEPINGCOMPUTER.COM
9 JulEuropean Organizations Have a Collaboration Security Confidence GapA new survey shows security leaders have an inflated sense of safety regarding their collaboration tools and platforms.DARKREADING.COM
9 JulFake VPN and 7-Zip Apps Turn Victims Into Residential Proxy NodesFake apps like WireVPN and a trojanized 7-Zip turn victims’ devices into residential proxies, letting criminals route traffic through their IPs. Infoblox’s threat research team started pulling on a single thread in early 2026: a fake version of the 7-Zip archive utili…SECURITYAFFAIRS.COM
9 JulEU takes member states to court over unimplemented cybersecurity lawIreland, Spain, France and the Netherlands are more than 20 months late in transposing the NIS2 Directive for the cybersecurity of critical infrastructure.THERECORD.MEDIA
9 Julnpm 12 Disables Install Scripts by Default to Reduce Supply Chain RiskGitHub has officially announced the release of npm version 12 with install scripts disabled by default, along with deprecating granular access tokens (GATs) designed to bypass two-factor authentication (2FA). The Microsoft-owned subsidiary noted that the following npm install beh…THEHACKERNEWS.COM
9 JulNew Helix vishing group emerges in SharePoint data theft attacksA new data-extortion group called Helix is using identity-focused tactics such as voice phishing (vishing), device code phishing, and multi-factor authentication (MFA) abuse to steal data from SharePoint environments. [...]BLEEPINGCOMPUTER.COM
8 JulRedWing Android Spyware Sold as a Service on TelegramZimperium found RedWing, an Android spyware sold as a service via Telegram to target banking appsINFOSECURITY-MAGAZINE.COM
8 JulNew HalluSquatting Attack Could Trick AI Coding Assistants Into Installing Botnet MalwareAI coding assistants have a habit of making things up. Ask one to fetch a popular tool, and it will sometimes hand back a real-sounding name for a project that does not exist. New research, which its authors call HalluSquatting, turns that habit into an attack: work out the …THEHACKERNEWS.COM
8 JulVidar Infostealer Hammers SMBs via Malvertising CampaignA financially motivated operation uses lures of cracked or pirated software to deliver a malware two-for-one combo for data theft and cryptomining.DARKREADING.COM
8 JulFake Paysafe, Skrill SDKs on NPM and PyPi steal credentialsMalicious packages on the Node Package Manager (npm) and the Python Package Index (PyPI) delivered stealer malware to developers and users of Paysafe, Skrill, and Neteller payment applications. [...]BLEEPINGCOMPUTER.COM
7 JulBig Brand Jobs Scam Targets Marketing Pros' Google AccountsThe phishing campaign uses several tactics, including nested redirects, to evade detection and steal credentials from unsuspecting targets.DARKREADING.COM
6 JulSkillCloak Lets Malicious AI Agent Skills Evade Static Scanners with Self-Extracting PackingScanners meant to catch malicious add-on "skills" for AI coding agents can be fooled by a few simple changes that leave the malware working, according to a new study from researchers at the Hong Kong University of Science and Technology. Their strongest trick slipped pa…THEHACKERNEWS.COM
6 JulA week in security (June 29 – July 5)A list of topics we covered in the week of June 29 to July 5 of 2026MALWAREBYTES.COM
6 JulNew TrojPix Attack Leaks Data From Air-Gapped Systems via Video Cable EmissionsResearchers at Shandong University have shown a fast new way to pull data off computers that are cut off from every network. The technique, called TrojPix, tweaks on-screen pixels in ways the eye cannot see, so that the video cable carrying them radiates a faint ra…THEHACKERNEWS.COM
6 JulNew Java-Based QuimaRAT MaaS Built to Run on Windows, Linux, and macOSCybersecurity researchers have flagged a novel Java-based remote access trojan (RAT) called QuimaRAT that's capable of targeting Windows, Linux, and macOS environments. According to LevelBlue, the cross-platform malware is advertised under a malware-as-a-service (MaaS) model, cos…THEHACKERNEWS.COM
6 JulNetNut botnet takes a hit. Don’t be part of the next one.Google, the FBI, and other partners have disrupted a residential proxy network built on millions of hijacked devices and used by criminals.MALWAREBYTES.COM
6 Jul'BusySnake' Infostealer Slithers into Critical Infrastructure NetworksA threat group researchers call "Armored Likho" has gained access to government agencies and electrical power entities in Russia, Brazil, and Kazakhstan.DARKREADING.COM
3 JulSpyware found on phone of European Parliament member probing itStelios Kouloglou, formerly a member of the European Parliament's committee investigation abuses of commercial spyware, was twice infected with Pegasus while serving, researchers said.THERECORD.MEDIA
3 JulEU Politicians Investigated Pegasus Spyware. Then It Ended Up on One of Their Phones“It is a direct attack on the rule of law,” says one European Parliament member of the new findings from Citizen Lab.WIRED.COM
2 JulContext Engineering | Compaction & Agent Memory for Automated Malware AnalysisCompaction cut input tokens 86% across long-running agent evals with no quality loss. Context discipline matters as much as model selection.SENTINELONE.COM
2 JulConsentFix and ClickFix: How Microsoft 365 Accounts are Hijacked in 3 SecondsConsentFix and ClickFix attacks steal Microsoft 365 tokens in seconds using fake prompts and OAuth flows. Learn how these MFA bypass tactics work and how to defend against them. [...]BLEEPINGCOMPUTER.COM
2 JulFake Google and Cloudflare verification pages spread multiple malware familiesWe uncovered ClickFix attacks using fake Google and Cloudflare pages to deliver everything from infostealers to a newly discovered malware loader.MALWAREBYTES.COM
1 JulResearcher Analyzes 3,000 Live ClickFix Payloads, Exposing API-Driven Malware DeliveryClickFix, the trick that fools people into running malware by hand, has quietly grown a back office. New research shows the malicious commands behind its fake "prove you're human" pages are now handed out by API-driven servers that give each visitor the same malware in a differen…THEHACKERNEWS.COM
1 JulPhantom Squatting Uses AI-Hallucinated Domains for Phishing and MalwareLarge language models keep inventing web addresses that do not exist. Attackers have started buying those made-up domains before anyone else can, then hosting phishing pages on them to catch traffic that AI tools point their way. Palo Alto Networks' Unit 42 calls the tr…THEHACKERNEWS.COM
1 JulMartin Lee: Running through the Arctic (and the threat landscape)Ever wonder how someone goes from studying human viruses to leading cybersecurity teams? In this Humans of Talos, we’re joined by Martin Lee, EMEA Lead, to talk about his journey into the industry.TALOSINTELLIGENCE.COM
1 Jul2026 Cybersecurity Assessment: The Gap Between Awareness and ResilienceOrganizations have never had greater awareness of cyber risk. Yet turning that awareness into operational resilience has never been more challenging. The 2026 Bitdefender Cybersecurity Assessment confirms this is the case, as this year's findings reveal a series of surprising con…THEHACKERNEWS.COM
1 JulBrazilian Banking Trojan Ousaban Targets Spain and PortugalFortiGuard says the Brazilian banking trojan Ousaban is targeting Spain and Portugal via phishingINFOSECURITY-MAGAZINE.COM
1 JulFileless Malware Abuses Google Blogspot to Deploy Infostealer in MemorySecuronix said the Veil#Drop campaign abuses Google Blogspot to deliver PureLog Stealer in memoryINFOSECURITY-MAGAZINE.COM
1 JulOusaban Banking Trojan Targets Iberian Bank Users with Fake PDF LuresA Brazilian banking trojan called Ousaban is going after Windows users who bank in Spain and Portugal. Fortinet's FortiGuard Labs identified the campaign in May 2026. It opens with a phishing PDF disguised as a corrupted file, checks that the visitor is really in Spain …THEHACKERNEWS.COM
1 Jul'Phantom Squatting': An Emerging AI-Driven Supply Chain ThreatLLMs consistently hallucinate Web domains for legitimate brands that attackers can register for malicious activity in a difficult-to-detect attack vector.DARKREADING.COM
1 JulVEIL#DROP Malware Chain Uses Blogger Platform to Deliver PureLogs StealerCybersecurity researchers have flagged a new multi-stage malware delivery attack chain that uses social engineering and Blogger pages to deliver an information stealer called PureLogs. The activity has been codenamed VEIL#DROP by Securonix. It's suspected that the initial payload…THEHACKERNEWS.COM
1 JulAnd the Winner in Dominant Malware Delivery? ClickFixResearchers say the highly effective social engineering technique is no longer the exception for malware attacks — it's now the rule.DARKREADING.COM
30 JunDefending the Authentication Flow: Device Code Phishing with Selena LarsonHost Caleb Tolin sits down with Selena Larson, Staff Threat Researcher and Lead, Intelligence Analysis and Strategy at Proofpoint and Host of the DISCARDED podcast, to discuss the mechanics of device code phishing and the widespread abuse of Microsoft OAuth authentication flows. …THECYBERWIRE.COM
30 JunUSB drives carrying China-linked malware infected Japanese military networks for nearly a yearRead more in my article on the Hot for Security blog.BITDEFENDER.COM
30 JunHackers Leverage Blockchain to Hit Japan's Hotels Through Booking.com PhishingA wave of phishing emails sent to Booking.com partner accommodations in Japan in May led to blockchain-hosted malwareINFOSECURITY-MAGAZINE.COM
30 JunClickFix Now Cybercriminals' Favorite Malware Delivery TechniqueReliaQuest report warns of a surge in ClickFix social engineering attacks against Windows and macOS usersINFOSECURITY-MAGAZINE.COM
30 JunRustDuck Botnet Rebuilds in Rust to Hijack Routers and Servers for DDoSA new two-stage malware family called RustDuck is hijacking home routers, IP cameras, Android boxes, and poorly secured servers, then stitching them into a network built to knock websites and online services offline. Researchers at QiAnXin's XLab have tracked it since F…THEHACKERNEWS.COM
30 JunPhishers Gain Persistence at EU, Asia Hospitality OrgsSeparate but similar campaigns described by Microsoft and Trend Micro use malicious zip files to spread malware via social engineering and obsfucation, including blockchain abuse.DARKREADING.COM
29 JunA week in security (June 22 – June 28)A list of topics we covered in the week of June 22 to June 28 of 2026MALWAREBYTES.COM
29 JunWebinar: Why business email compromise attacks keep succeedingBusiness email compromise attacks increasingly rely on convincing impersonation rather than malware, making them harder for employees and traditional email defenses to detect. This webinar explores how behavioral AI can help identify sophisticated email threats and automate respo…BLEEPINGCOMPUTER.COM
29 Jun⚡ Weekly Recap: Linux Kernel Flaws, AI Malware Tricks, Turla Backdoor, Infostealers and MoreThis week was a reminder that attackers do not always need big tricks. One small mistake, one old access path, one missed patch, and suddenly the door is open. The noise is not all noise, either. Forums are talking, researchers are finding easy cracks, and defenders have more cle…THEHACKERNEWS.COM
29 Jun119 Edge extensions promised useful tools, instead downloaded malwareMicrosoft has removed over 100 Edge extensions that were delivering malware hidden in images.MALWAREBYTES.COM
28 JunSpace supply chain pressures.Despite the space sector seeing greater investment and attention year-over-year, the sector still remains bound by an outdated and ineffective supply chain, especially in the United States. In this week’s episode, host Maria Varmazis sits down with Doug Anderson, Partner at Pw…THECYBERWIRE.COM
28 JunSpace’s fragile supply chain.This week on T-Minus: Space-Cyber Briefing: we look at recent research that examines the US’s current space supply chain. Despite increased investment and growing demand for space capabilities, the industry’s supply chain remains vulnerable to bottlenecks, shortages, and external…THECYBERWIRE.COM
27 JunMore bark than byte.This week we are joined by Daniel Schwalbe, Chief Information Security Officer & Head of Investigations at DomainTools, discussing their work on "ZionSiphon OT Malware First Attempts? Psyops? Both?" Researchers at DomainTools take a closer look at ZionSiphon, a purported oper…THECYBERWIRE.COM
27 JunSecurity News This Week: LastPass Users Had Their Data Stolen—AgainPlus: Former national security advisor John Bolton pleads guilty in classified-materials case, Microsoft helps take down major infostealer infrastructure, and more.WIRED.COM
27 JunSay hi to Pike!In this article we will introduce Pike, an experimental LLM agent that generates and analyzes Linux program execution traces. We will show that with its simple architecture paired with a good LLM, Pike can quickly help debug a crash, identify malware, or give valuable high level …SYNACKTIV.COM
27 JunCreating a "Two-Face" Rust binary on LinuxIn this article we will describe a technique to easily create a "Two-Face" Rust binary on Linux: an executable file that runs a harmless program most of the time, but will run a different, hidden code if deployed on a specific target host. This approach, which allows binding a bi…SYNACKTIV.COM
27 JunQuantum readiness: Hybridizing key exchangesFollowing our previous article on signatures hybridization, this article covers the basics of hybridizing your key exchanges to ensure maximal security of your data.SYNACKTIV.COM
27 JunLinkPro: eBPF rootkit analysisDuring a digital investigation related to the compromise of an AWS-hosted infrastructure, a stealthy backdoor targeting GNU/Linux systems was discovered. This backdoor features functionalities relying on the installation of two eBPF modules, on the one hand to conceal itself, and…SYNACKTIV.COM
27 JunLLM Poisoning [1/3] - Reading the Transformer's ThoughtsYour local LLM can hack you. This three-part series reveals how tiny weights edits can implant stealthy backdoors that stay dormant in everyday use, then fire on specific inputs, turning a "safe" offline model into an attacker. This article shows how transformers encode concepts …SYNACKTIV.COM
27 JunThe Mac Malware of 2019Our annual report on all the Mac malware of the year - including samples for download, infection vectors, persistence mechanisms, payloads and more!OBJECTIVE-SEE.ORG
27 JunThe Mac Malware of 2018Our annual report on all the Mac malware of the year - including samples for download, infection vectors, persistence mechanisms, payloads and more!OBJECTIVE-SEE.ORG
27 JunOSX.DummyA new Mac malware targets the cryptocurrency community. In this post, we dive into the malware and illustrate how Objective-See's tools can generically thwart this new threat at every step of the way.OBJECTIVE-SEE.ORG
27 JunTearing Apart the Undetected (OSX)Coldroot RATI uncovered a new cross-platform backdoor that provides remote attackers persistent access to infected systemsOBJECTIVE-SEE.ORG
27 JunAy MaMi - Analyzing a New macOS DNS HijackerOSX/MaMi (the first Mac malware of 2018) hijacks infected users' DNS settings and installs a malicious certificate into the System keychain, in order to give remote attackers 'access' to all network trafficOBJECTIVE-SEE.ORG
27 JunMac Malware of 2017Let's look at all the mac malware from 2017, for each - discussing their infection vector, persistence mechanism, features & goals.OBJECTIVE-SEE.ORG
27 JunOSX/Proton.B; a brief analysis, 6 miles upAnalysis of OSX/Proton.B reveals some interesting tricks plus a command file that can be decrypted to reveal the malware's capabilitiesOBJECTIVE-SEE.ORG
27 JunMac Malware of 2016Let's analyse the malware that appeared in 2016, discussing the infection vector, persistence mechanism, feature, and disinfection for each.OBJECTIVE-SEE.ORG
27 JunHackingTeam Reborn; A Brief Analyis of the RCS Implant InstallerHackingTeam using native OS X crypto to protect malware -neat! New blog w/ sample + decryptions/dumpings/detectionsOBJECTIVE-SEE.ORG
27 JunMore on, "Adware for OS X Distributes Trojans"A deeper dive into 'MacInstaller' and the adware it installsOBJECTIVE-SEE.ORG
27 JunClean GitHub repo tricks AI coding agents into running malwareAn agentic coding tool tasked with cloning and setting up a seemingly benign GitHub repository could execute a malicious payload that remains invisible to security scanners, AI agents, and human reviewers. [...]BLEEPINGCOMPUTER.COM
26 JunChina-Linked Hackers Strike Asian Critical Infrastructure with TinyRCT BackdoorA China-linked threat group has been targeting critical infrastructure in Southeast Asia with a new custom backdoor called TinyRCTINFOSECURITY-MAGAZINE.COM
26 JunMalware steals Chrome session cookies to take over your accountsA phishing campaign installs a malicious Chrome extension to hijack browser sessions and compromise Windows devices.MALWAREBYTES.COM
25 JunNew Gaslight macOS Malware Uses Prompt Injection to Disrupt AI-Assisted AnalysisA previously undocumented Rust-based macOS implant and information stealer has been found to embed a prompt injection payload designed to trick a malware analyst's artificial intelligence (AI) tools and trick it into aborting or refusing an analysis of the artifact. The malware h…THEHACKERNEWS.COM
25 JunNew Mistic Backdoor Linked to KongTuke in ClickFix and ModeloRAT CampaignsA new, stealthy backdoor named Mistic has been deployed as part of suspected financially motivated attacks aimed at multiple organizations spanning insurance, education, IT, and professional services sectors since April 2026. According to Symantec and Carbon Black's Threat Hunter…THEHACKERNEWS.COM
25 JunInside the 2026 SMB threat landscape: From phishing and scams to fake AI toolsKaspersky researchers analyze the threat landscape for SMBs in 2026: the rise of attacks involving fake AI tools, phishing schemes, and data sold on the dark web.SECURELIST.COM
25 JunInternational operation disrupts Amadey and StealC malware infrastructure.Cal Water says Handala's hacking claims were overstated. Stealthy new backdoor may be tied to initial access broker. DraftKings hacker is sentenced to eighteen months.THECYBERWIRE.COM
25 JunBritish Police Built a Sprawling Crime-Prediction Machine. Some Results Couldn’t Be TrustedAs UK police embrace the AI revolution, a WIRED investigation reveals the messy inside story of one region’s experiment with predictive analytics.WIRED.COM
25 JunNew macOS malware embeds fake errors to confuse AI analysis toolsA newly discovered macOS malware dubbed "Gaslight" is designed to confuse AI-assisted malware analysis tools by hiding prompt injection strings and fake debugging data within the executable. [...]BLEEPINGCOMPUTER.COM
24 JunStrikeShark: investigating a new campaign delivering Cobalt Strike through SharkLoaderKaspersky researchers analyze a new global campaign dubbed StrikeShark that delivers Cobalt Strike Beacon via custom SharkLoader malware.SECURELIST.COM
24 Jun“Total access to all your devices.” Sextortion scammers strike againThey say they have videos, malware, and total control of your devices. Here's how to read a sextortion email like a security researcher instead of a victim.MALWAREBYTES.COM
24 JunWatch out for renewal scams pretending to be MalwarebytesScammers are sending fake software renewal notices that claim you've been charged for a subscription. Some even impersonate Malwarebytes.MALWAREBYTES.COM
24 JunHow AI Is Rewriting the SecOps PlaybookThe threat landscape has changed. Adversaries operate at machine speed, shrinking attacks from days to minutes. Defenders can no longer investigate and respond before damage occurs. In this new era, Security Operations must prioritize speed, automation, and continuous decision-ma…WIZ.IO
24 JunEuropol-Led Operation Endgame Takes Down StealC and Amadey InfostealersOperation Endgame seized around 50 domains and nearly 200 active IP-based servers associated with the infostealersINFOSECURITY-MAGAZINE.COM
24 JunMore Malicious OpenClaw Skills Threaten AI Supply ChainOpenClaw removed five packages from ClawHub, its skills marketplace, that bypassed security checks even though they included infostealers and other threats.DARKREADING.COM
24 Jun2026 FIFA World Cup Faces Surge in Cyber ThreatsPersistent cybercrime, social engineering, and infrastructure threats continue to plague the FIFA 2026 World Cup across the US, Canada, and Mexico.DARKREADING.COM
24 JunDo CISOs Need a Code of Ethics?Dark Reading Confidential Episode 19: Kickbacks, no-show jobs, "dirty" VCs, and shelf ware — industry expert Robert "RSnake" Hansen explains why he thinks it's time for a CISO code of ethics. It could ensure cybersecurity bosses aren't engaged in self-dealing …DARKREADING.COM
23 JunBeyond the Doomsday: Operational Resilience, Identity Sprawl, and Back-to-Basics Cyber DefenseThis special episode brings together top industry experts to dissect the rapidly shifting landscape of modern cyber threats, cloud technologies, and artificial intelligence. The conversation moves past standard industry hype to deliver practical frameworks for building true opera…THECYBERWIRE.COM
23 JunMalicious npm Packages Pose as PostCSS Tools to Deliver Windows RATCybersecurity researchers have discovered a set of malicious npm packages that are designed to deliver a Windows-based remote access trojan (RAT). The list of identified packages, is below - aes-decode-runner-pro (145 downloads) postcss-minify-selector (256 downloads) postcss-min…THEHACKERNEWS.COM
23 JunInside the dark web: Stolen identities for 95¢, malware, and scams-for-hireWe spent 48 hours exploring the dark web and found stolen identities, malware, scams, and a thriving cybercrime economy.MALWAREBYTES.COM
23 JunNew macOS ClickFix attack silently mounts DMGs to push infostealerA new macOS ClickFix campaign is using Terminal commands to silently download, mount, and launch info-stealing malware from malicious disk image (DMG) files. [...]BLEEPINGCOMPUTER.COM
23 Jun'Cordyceps': Mushrooming Malicious Pull Requests Threaten Developer WorkflowsThe CI/CD workflow weakness affects Microsoft's Azure Sentinel, Google's AI Agent Development Kit, Apache's Doris analytics database, Cloudflare's Workers SDK, and Python Software Foundation's Black.DARKREADING.COM
23 JunmacOS.Gaslight | Rust Backdoor Turns Prompt Injection on the Analyst, Not the SandboxDPRK-linked implant embeds 38 fabricated system messages that spoof an LLM triage harness, hiding a credential stealer and Telegram C2 underneath.SENTINELONE.COM
22 JunAryStinger Malware Infects 4,300 Legacy Routers to Build Reconnaissance Proxy NetworkA new malware family is turning forgotten home routers into a distributed reconnaissance and proxy network, not the DDoS botnet these devices usually end up in. QiAnXin's XLab calls it AryStinger and counts at least 4,300 infected routers, a total it says is still risin…THEHACKERNEWS.COM
22 JunA week in security (June 15 – June 21)A list of topics we covered in the week of June 15 to June 21 of 2026MALWAREBYTES.COM
22 JunCanada’s Spy Agency Used First-of-Its-Kind Warrant to Clean Botnet-Infected DevicesCanada's spy service got a judge's permission to reach into infected servers, home routers, and IoT gear sitting on Canadian soil and neutralize two foreign-run botnets. The Federal Court released a public version of the ruling on June 15. It is the first time the Canadian S…THEHACKERNEWS.COM
22 JunWhatsApp phishing attack uses fake business docs to hack PCsAn ongoing malware campaign is targeting WhatsApp users in multiple countries with deceptive messages that push VBScript files, leading to remote system access. [...]BLEEPINGCOMPUTER.COM
21 JunNavigating the GPS threat landscape, with Brandon Karpf.Traditionally, GPS jamming attacks have been confined to the ground; however, new data shows that these attacks could be moving to target signals before they even reach the ground. In this week’s episode, host Maria Varmazis sits down with Dave Bittner and Brandon Karpf to discus…THECYBERWIRE.COM
19 JunLost in relocation: analysis of a new loader distributing CASTLESTEALERFind out how a new obfuscated loader evades static detection using .reloc section abuse, five anti-VM/language checks and MBA obfuscation to deliver infostealer malware via Google Ads.ELASTIC.CO
19 JunNearly 15,000 infected websites cleaned in SocGholish crackdownThousands of everyday websites were cleaned as part of a global operation targeting the malware network behind fake browser update scams.MALWAREBYTES.COM
19 JunPolice raid malware network tied to Russia's Evil Corp hacker groupAn international operation targeted the SocGholish botnet, which has been linked to the Russia-based cybercrime group Evil Corp.THERECORD.MEDIA
18 JunThe Scripts on Your Checkout Page Are Now a PCI DSS ProblemAn independent PCI assessor tested Reflectiz against the new PCI DSS rules. Here is the verdict: See the full QSA assessment here → When a customer types their card number into your checkout, their browser is running far more than your code. Analytics tags, a tag manager, a suppo…THEHACKERNEWS.COM
18 JunRetro gaming fans are the new target for fake GitHub malwareRetro gaming fans should be careful with GitHub projects that claim to be tools or plugins for their consoles. We looked at one example aimed at PlayStation Vita owners.MALWAREBYTES.COM
17 JunRisky Business #842 -- Anthropic needs an adult in the C suiteOn this week’s show Patrick Gray, Adam Boileau and James Wilson discuss the week’s cybersecurity news. They cover: Anthropic’s Fable 5 and Mythos 5 get nuked by the US government four days after launch “because security” Why “guardrails” won’t keep the world safe from your AI doo…RISKY.BIZ
17 JunMalwarebytes earns AV-TEST Top Product award, aces other third-party testsMalwarebytes got top marks in independent tests against malware, phishing, and other online threats.MALWAREBYTES.COM
17 JunAI Threats and Alert Fatigue Challenge Cybersecurity TeamsFiligran survey at Infosecurity Europe 2026 reveals AI-powered attacks as the top concern, with false positives, alert fatigue and manual processes draining security teamsINFOSECURITY-MAGAZINE.COM
17 JunRokarolla Android malware can take over your phone and steal banking loginsResearchers have uncovered an Android banking Trojan that targets more than 200 banking and cryptocurrency apps and can take over infected devices.MALWAREBYTES.COM
17 JunPresident Trump delays DNI confirmation hearings.ShinyHunters leaks data allegedly stolen from Madison Square Garden. New Android malware targets over 200 banking apps.THECYBERWIRE.COM
17 JunRoblox developers are losing entire games to malware attacksAttackers are using fake job offers and malware to steal accounts, Robux, and Roblox games from the developers who build them.MALWAREBYTES.COM
17 JunThe Economics of Downtime with Christy Wyatt, CEO from Absolute SecurityChristy Wyatt, CEO of Absolute Security, joins Dave Bittner on the CyberWire Daily podcast for a sponsored Industry Voices. Christy discusses why cybersecurity has evolved from a threat and prevention conversation into a business resilience discipline centered on downtime, contin…THECYBERWIRE.COMHTTPS:
16 JunDozens of malicious wallpapers found on Steam Workshop: gamers’ accounts at riskSince late 2025, malware has been spreading rapidly through the Steam Workshop, the gaming platform's built-in service for players to create and share custom content. The attackers are primarily targeting gamers in China and Russia.SECURELIST.COM
16 JunWindows version of SprySOCKS Linux malware used to attack govt orgsWindows variants for the SprySOCKS Linux malware have been used in attacks targeting government organizations in at least four countries. [...]BLEEPINGCOMPUTER.COM
16 JunChina-Linked SprySOCKS Backdoor Expands to Windows with Driver-Based StealthCybersecurity researchers have flagged two previously undocumented Windows variants of what was believed to be a Linux-only backdoor called SprySOCKS. "The Windows variants discovered are internally marked as WIN_DRV and WIN_PLUS," ESET said in a report shared with The Hacker New…THEHACKERNEWS.COM
16 JunNew Rokarolla Android Malware Steals PINs, SMS Codes, and Crypto Wallet FundsSecurity researchers at Zimperium's zLabs have documented a new Android banking trojan, Rokarolla, that targets 217 banking and cryptocurrency apps and packs 137 remote commands. Together, they give an operator near-total control of an infected phone: it lifts lock-scre…THEHACKERNEWS.COM
16 JunRokarolla Trojan Combines Banking Fraud With Device SurveillanceRokarolla Android trojan steals banking logins and spies on victims while blocking fraud alertsINFOSECURITY-MAGAZINE.COM
16 JunSprySOCKS Backdoor Expands From Linux to WindowsChina-linked SprySOCKS backdoor gains stealthy Windows variants and 30-plus C2 commandsINFOSECURITY-MAGAZINE.COM
16 JunGhostTree Attack Abused Recursive Windows Junctions to Hide MalwareGhostTree uses recursive NTFS junctions to generate vast numbers of valid Windows file paths. Varonis explains how the technique could cause Microsoft Defender folder scans to never complete, leaving malware undetected. [...]BLEEPINGCOMPUTER.COM
16 JunRokarolla Android Trojan Levels Up to Full Device Control, PersistenceThe emerging malware, spread via fake TikTok and Chrome downloads, demonstrates an evolution by combining banking fraud with extensive device surveillance and remote control.DARKREADING.COM
16 JunClickFix Campaigns Expand Malware Delivery With New Loaders and Fake Update LuresCybersecurity researchers have flagged multiple ClickFix campaigns that deliver three malware loaders called BabaDeda Loader, Lorem Ipsum Loader, and Potemkin, per independent reports from Morphisec, BlueVoyant, and Huntress, respectively. Attacks involving BabaDeda Loader, obser…THEHACKERNEWS.COM
16 JunSprySOCKS Windows Variant Abuses Kernel Drivers to Evade DetectionFishMonger, a China-nexus threat group, has deployed an undocumented version of the Linux backdoor against government targets in Honduras, Taiwan, Thailand, and Pakistan.DARKREADING.COM
16 JunNew Rokarolla Android malware targets 217 banking, crypto appsA new Android banking trojan named Rokarolla is targeting 217 banking and cryptocurrency applications using an extensive set of 137 commands. [...]BLEEPINGCOMPUTER.COM
16 JunFileless Phantom Stealer Targets Browser CredentialsIn addition to executing entirely in memory, the malware's infection chain incorporates other anti-analysis techniques designed to frustrate detection.DARKREADING.COM
15 JunInside a malicious infrastructure delivering EtherRAT, phishing pages, and malicious softwareWe found EtherRAT malware being distributed by a website with a strange homepage. Following the trail, we discovered a vast network of malicious infrastructures, distributing malware, malicious documents, remote desktop software, and phishing pages.MALWAREBYTES.COM
15 JunA week in security (June 8 – June 14)A list of topics we covered in the week of June 8 to June 14 of 2026MALWAREBYTES.COM
15 JunAttackers Hijack Popular WordPress Plugins to Deploy BackdoorsTampered OptinMonster and sister plugins plant hidden backdoors on 1.2 million WordPress sitesINFOSECURITY-MAGAZINE.COM
14 JunSecuring satellites already in space, with journalist Shaun Waterman.For years, space cybersecurity has been a long sought after goal, but due to operational constraints, it was largely unfeasible. In this week’s episode, host Maria Varmazis sits down with journalist Shaun Waterman to discuss his recent article “The Newest Space Race is Cyber.” As…THECYBERWIRE.COM
13 Jun400+ Arch Linux AUR Packages Hijacked to Install Rust Credential StealerAttackers took over more than 400 packages in the Arch User Repository (AUR) this week and rewrote their build scripts to install a credential stealer on any machine that built them. The malware is a Rust binary built to harvest developer secrets. When it lands with root, it can …THEHACKERNEWS.COM
13 JunOver 400 Arch Linux AUR Packages Hijacked to Deploy Infostealer and eBPF RootkitAttackers took over more than 400 packages in the Arch User Repository (AUR) this week and rewrote their build scripts to install a credential stealer on any machine that built them. The malware is a Rust binary built to harvest developer secrets. When it lands with root, it can …THEHACKERNEWS.COM
12 JunGitHub to Update npm to Thwart Software Supply Chain AttacksNPM, part of GitHub, announced a new version of the npm package manager with several security improvements, including disabling install scriptsINFOSECURITY-MAGAZINE.COM
11 JunGitHub to Disable npm Install Scripts by Default to Stop Supply Chain AttacksGitHub has announced what it said are "breaking changes" coming to npm version 12, one of which turns off install scripts by default to combat software supply chain threats. The changes aim to combat attack techniques that abuse the "npm install" command to trigger the execution …THEHACKERNEWS.COM
11 JunMost Cybersecurity Teams Struggle to Find Time for Training on New Cyber ThreatsOrganizations are aware of the challenges that new technologies like AI bring: but cybersecurity staff struggle to make time for the required training during working hoursINFOSECURITY-MAGAZINE.COM
11 JunThreatsDay Bulletin: Worm Code Leaked, AI Agent Phished, Claude Action Patch + 28 New StoriesIt's been one of those weeks. You expect the usual noise: recycled malware, sloppy attacks, another easy target getting hit. Instead, there's a supply chain attack kit in a public repo, a $5,000-a-month RAT that clones browsers, and research showing AI agents can be tricked into …THEHACKERNEWS.COM
11 JunCybercriminals Use Fake AI Guides and Dev Tools to Spread AsyncRAT MalwareFake AI guides hide a multi-stage chain that drops AsyncRAT, with signs of AI-assisted codingINFOSECURITY-MAGAZINE.COM
10 Jun88% of people struggle to tell what’s real onlineAs AI-generated scams, deepfakes, and impersonation spread, a new Malwarebytes report finds people increasingly unsure what to trust online.MALWAREBYTES.COM
10 JunNew SilabRAT Trojan Hijacks Sessions to Steal CryptoMaaS trojan SilabRAT uses HVNC and browser cloning to hijack sessions and steal cryptoINFOSECURITY-MAGAZINE.COM
10 JunCybersecurity Software Fails to Detect Fifth of Brower-Based Phishing AttacksMenlo Security research warns that as enterprise applications become increasingly browser based, traditional cybersecurity tools leave them vulnerable to cyber threatsINFOSECURITY-MAGAZINE.COM
10 JunFree Spotify Premium hacks on social media are spreading infostealersCybercriminals are turning TikTok and Instagram Reels into malware delivery platforms, using free software tutorials to spread infostealers.MALWAREBYTES.COM
10 JunDeceptive Installers: How Fake Apps Target macOSDeceptive installers disguised as legit macOS software deliver infostealers that grab passwords, cookies, and crypto wallets. Learn how to detect them.HUNTRESS.COM
9 JunGitHub disables Microsoft repos pushing password-stealing malwareMicrosoft removed 73 repositories across its Azure, microsoft, Azure-Samples, and MicrosoftDocs organizations on GitHub, disrupting continuous integration pipelines. [...]BLEEPINGCOMPUTER.COM
9 JunAI Threat Readiness Pillar 2: Accelerate Patching and ResponseYour guide to operationalizing ownership, remediation, and response with Wiz to keep pace with the AI threat landscape.WIZ.IO
9 JunOpenClaw AI agent found falling for phishing attacks, spills user dataPhishing simulation on an OpenClaw email agent with various configuration profiles showed that it was susceptible to tactics commonly used to compromise human users. [...]BLEEPINGCOMPUTER.COM
8 JunVS Code Adds 2-Hour Extension Auto-Update Delay to Limit Supply Chain AttacksMicrosoft has announced that Visual Studio Code (VS Code) will apply a two-hour delay before extensions for the integrated development environment (IDE) are updated automatically to a newer version in an attempt to tackle software supply chain threats. "When automatic updates are…THEHACKERNEWS.COM
8 JunA week in security (June 1 – June 7)A list of topics we covered in the week of June 1 to June 7 of 2026MALWAREBYTES.COM
8 JunPirated PC games are delivering password-stealing malwareCybercriminals are hiding malware in cracked and repacked games, infecting more than 400,000 devices worldwide.MALWAREBYTES.COM
8 JunAI Phishing Is Crushing SOCs with Alert Volume: How to Reduce Tier 1 OverloadPhishing has always been a numbers game. AI has turned it into a volume machine. Attackers can now create convincing emails, fake login pages, and tailored lures in minutes. Every polished message adds another case for Tier 1 to review, another link to inspect, and another alert …THEHACKERNEWS.COM
8 JunWhatsApp says it caught new spyware attacks linked to NSO Group in violation of court orderThe messaging giant announced that it disrupted a phishing campaign targeting its users with NSO’s spyware.TECHCRUNCH.COM
8 JunMeta Blocks NSO Group's New WhatsApp Phishing Attack, Files Contempt OrderMeta on Monday said it detected and blocked spear-phishing attempts linked to Israeli spyware vendor NSO Group. In addition, the tech giant said it's filing a federal court contempt order against the company for violating a permanent injunction that barred it from targeting Whats…THEHACKERNEWS.COM
8 Jun'Hades' Campaign Against PyPI Puts New Spin on Shai-HuludThe latest attacks, which hit 37 PyPI wheels and 19 code packages, show a continued evolution of the persistent software supply chain threat.DARKREADING.COM
8 JunWhatsApp says it disrupted new NSO spyware phishing attacksWhatsApp has detected and stopped spear-phishing campaigns allegedly conducted by the NSO Group after investigating user reports of social engineering attacks. [...]BLEEPINGCOMPUTER.COM
8 JunNFCShare Android malware spreads via fake banking app updates on GitHubNew variants of the NFCShare Android malware are being distributed as fake updates for legitimate banking apps hosted on GitHub. [...]BLEEPINGCOMPUTER.COM
7 JunC0XMO botnet spreads via DD-WRT router flaw, kills rival malwareA new variant of the Gafgyt botnet called C0XMO is targeting DD-WRT router firmware and can move to other device types with various CPU architectures. [...]BLEEPINGCOMPUTER.COM
5 JunFIFA World Cup 2026 Scams Are Already Live: Fake Sites, Banking Malware, and Stolen LoginsSecurity researchers and the FBI are warning that a wave of FIFA-themed fraud is already hitting World Cup 2026 fans, days before the June 11 kickoff. Recent reports describe thousands of lookalike FIFA domains, banking malware hidden inside pirate streaming apps, and at least on…THEHACKERNEWS.COM
5 JunOver 900 US gas station tank gauge systems exposed to attacksOver 900 automatic tank gauge (ATG) systems across the United States, used to monitor fuel and chemical storage tanks across various critical infrastructure sectors, have been found exposed online and are vulnerable to ongoing attacks. [...]BLEEPINGCOMPUTER.COM
5 JunThe Real Measure of SOC Maturity with Ashu Savani from TryHackMeAshu Savani, Co-Founder of TryHackMe, joins Dave Bittner on the CyberWire Daily podcast for a sponsored Industry Voices to discuss what separates high-performing security teams from the rest. Ashu explores why true SOC maturity is measured by performance under pressure rather tha…THECYBERWIRE.COMHTTPS:
4 JunChina-Linked TA4922 Expands Phishing Attacks to UK, Germany, Italy, and South AfricaA new China-linked cybercrime group known as TA4922 has expanded its targeting focus to target European organizations in the U.K., Germany, Italy, and South Africa. These efforts have been complemented by a "rapid operational tempo" and a continually evolving malware arsenal comp…THEHACKERNEWS.COM
4 JunFlutterShell Backdoor Spreads to macOS via Malicious Google and YouTube AdsCybersecurity researchers have shed light on a macOS malvertising campaign codenamed Operation FlutterBridge that spreads a new backdoor called FlutterShell. According to Palo Alto Networks Unit 42, the campaign is said to be the next stage of a previously reported activity clust…THEHACKERNEWS.COM
4 JunInfosecurity Europe: AI Adoption Creates New Opportunities for Attackers to Distribute Malware, Microsoft WarnsMicrosoft Detection and Response Team (DART) details how it has uncovered malicious AI applications as cyber criminals manipulate organizations adopting AI toolsINFOSECURITY-MAGAZINE.COM
4 JunThreatsDay Bulletin: AI Agents Gone Wrong, Sketchy C2 Tools, ClickFix Tricks, JS Backdoors & 20+ New StoriesIt got stupid again. The internet still feels held together with tape. Bad plugins, old bugs, fake tools, trusted apps doing shady things. Same mess, new wrapper. And now the weird stuff is normal. Forums go down and come back worse. Cheap hackers get better toys. AI starts break…THEHACKERNEWS.COM
4 JunNew IronWorm malware hits 36 packages in npm supply-chain attackA new supply-chain attack has infected 36 packages on the Node Package Manager (npm) index with infostealer malware called IronWorm. [...]BLEEPINGCOMPUTER.COM
4 JunRust-Written IronWorm Hits NPM Supply ChainLike Shai-Hulud, the campaign targets developers to steal credentials and reuses them to propagate across the software supply channel.DARKREADING.COM
3 JunWeedhack Attacks Minecraft Users, CountLoader Hits 86K, Miners Spread via Pirated ContentCybersecurity researchers have flagged a new campaign targeting Minecraft players via YouTube to spread malware capable of gaining control of victims' systems. The Minecraft-focused malware-as-a-service (MaaS) campaign has been codenamed Weedhack by McAfee Labs, stating the activ…THEHACKERNEWS.COM
3 JunArgamal: Malware hidden in hentai gamesKaspersky researchers analyze new Argamal RAT distributed via infected hentai games and allowing the attacker to control the target machine.SECURELIST.COM
3 JunInfostealers are becoming the go-to phishing payloadCybercriminals prefer infostealers to traditional phishing techniques because they reduce friction, scale well, and are widely available.MALWAREBYTES.COM
3 JunGoogle DoubleClick Abused in New Malspam Campaign to Deliver DesckVB RATCybersecurity researchers have flagged a new malspam campaign that makes use of Google's DoubleClick domain as a way to evade detection and ultimately deliver a remote access trojan (RAT) named DesckVB RAT. "Before the victim ever reaches attacker-controlled infrastructure, the l…THEHACKERNEWS.COM
3 JunAttackers Use AI to Automate EDR Evasion TestingPython scripts were used to test malware against endpoint detection and response agents from Sophos, CrowdStrike, and Windows Defender.DARKREADING.COM
2 JunFake virus alerts are invading mobile games"Your device is infected!" Fake account warnings and virus alerts are turning some in-game ads into malware traps.MALWAREBYTES.COM
2 JunAttackers Hijack Red Hat npm Scope to Steal Cloud SecretsAttackers backdoored 32 packages in Red Hat's official npm scope to steal cloud and CI secretsINFOSECURITY-MAGAZINE.COM
2 JunInfosecurity Europe: Cybersecurity Teams Which Don’t Leverage AI are "Doomed to Fail"Humans still need to be part of cyber defense, but refusing to deploy AI is no longer optional against AI-enhanced cyber threats, warns Dataminr’s Joe SlowikINFOSECURITY-MAGAZINE.COM
2 JunDriveSurge Hijacks Thousands of Sites for ClickFix, FakeUpdate AttacksA sneaky, wide-scale IAB operation uses a malicious traffic distribution system (TDS) to redirect visitors of trusted websites to ones that deliver malware.DARKREADING.COM
2 JunOver 116,000 Mincraft systems infected in WeedHack malware campaignA large-scale malware campaign dubbed WeedHack is targeting Minecraft players and has infected more than 116,000 systems since January. [...]BLEEPINGCOMPUTER.COM
1 JunA week in security (May 25 – May 31)A list of topics we covered in the week of May 25 to May 31 of 2026MALWAREBYTES.COM
1 JunRapid7 and Exclusive Networks Expand Partnership Across the NordicsBuilding stronger cybersecurity outcomes together The cybersecurity landscape across the Nordics is evolving rapidly. Organizations are facing increasing pressure to modernize security operations, reduce complexity, and respond faster to threats, all while navigating growing regu…RAPID7.COM
1 JunContainers on fire: from container escapes to supply chain attacksWe break down the primary attack vectors in containerized environments: exposed secrets, privilege misconfigurations, API compromise, and supply chain attacks.SECURELIST.COM
1 JunFake BlueWallet steals passwords, accounts, and crypto from MacsA fake BlueWallet download tricks Mac users into running malware that steals passwords, crypto wallets, and clipboard data.MALWAREBYTES.COM
1 JunWordPress malware campaign hides payloads in Steam profilesNearly 2,000 WordPress websites were infected with malware that relies on Steam Community profile comments to hide command-and-control (C2) data. [...]BLEEPINGCOMPUTER.COM
31 MayGPS: A backbone for critical infrastructure.Since its original creation in the 1970s, GPS has evolved from a technology primarily used by the military to a foundation for modern society. After the removal of selective availability for civilians in 2000, GPS’s value has significantly expanded. In the past two decades, nearl…THECYBERWIRE.COM
29 MayWhat’s in the container? Analyzing vulnerabilities, risks and protection with Kaspersky Container Security and the KIRA AI assistantWhat are the main risks for container environments: vulnerabilities, supply chain attacks, configuration errors; how to improve container security and how Kaspersky Container Security with the KIRA AI assistant can help.SECURELIST.COM
29 MayAI-Generated npm Malware Leaks Its Own GitHub TokenSloppy AI-generated npm infostealer leaked its own GitHub token, exposing the operatorINFOSECURITY-MAGAZINE.COM
29 MayFrom $5 Attacks to Botnet-Powered Platforms: Inside the DDoS-as-a- Service MarketDDoS attacks are increasingly being sold like subscription services, complete with pricing tiers, support, and reseller programs. Flare explores how the DDoS-as-a-Service market has evolved from scattered tools into polished attack platforms. [...]BLEEPINGCOMPUTER.COM
29 MayDutch govt disrupts malware botnet with 17 million infected devicesDutch authorities have taken offline a massive botnet of 17 million devices and seized more than 200 servers at a local provider that supported the operation. [...]BLEEPINGCOMPUTER.COM
29 MayResearchers blame Iranian government for LA transit authority hack.Thousands of domains are impersonating FIFA ahead of the World Cup. Dutch police dismantle a botnet.THECYBERWIRE.COM
28 MayFake ChatGPT download site infects Windows and Mac users with malwareSearching for ChatGPT? This fake download site serves malware to both Windows and Mac users, using separate payloads tailored to each platform.MALWAREBYTES.COM
28 MayGCHQ Chief Urges Action as AI Reshapes Cyber ThreatsGCHQ director urges urgent business cyber action as AI and quantum reshape the threatINFOSECURITY-MAGAZINE.COM
28 MayBTMOB Android malware service generates custom phishing payloadsAn Android remote access trojan named BTMOB is offered to cybercriminals with a builder interface for generating malware payloads tailored to phishing lures. [...]BLEEPINGCOMPUTER.COM
27 MayAI Chatbot Recommendations Redirect Users to Cryptojacking Malware SitesMicrosoft has warned of an active cryptojacking campaign that makes use of artificial intelligence (AI) chatbot interactions as a mechanism for surfacing malicious download sites. "This emerging delivery technique extends social engineering beyond conventional search results and …THEHACKERNEWS.COM
27 MayCompany bragged phone mics could listen to conversations. They couldn’t.Cox Media said it could spy on users through their devices and use the information for targeted advertising, except it wasn't true.MALWAREBYTES.COM
27 MayGlassWorm Malware Takedown Disrupts Developer Supply Chain Attack InfrastructureCrowdStrike, in partnership with Google and the Shadowserver Foundation, has announced the simultaneous disruption of all command-and-control (C2) channels associated with GlassWorm, a persistent software chain campaign targeting software developers through malicious packages and…THEHACKERNEWS.COM
27 MayCrowdStrike, Google Take Down Glassworm BotnetOperators of the malicious Glassworm botnet have been targeting software developers since at least early 2025INFOSECURITY-MAGAZINE.COM
27 MayGlassworm botnet disrupted after resilient C2 infrastructure takedownThe Glassworm botnet targeting developers in software supply-chain attacks has been disrupted after researchers took down its resilient command-and-control infrastructure relying on Solana blockchain transactions and the BitTorrent DHT network. [...]BLEEPINGCOMPUTER.COM
27 MayGrandoreiro Malware and BTMOB RAT Campaigns Target Windows and Android UsersLatin America and Europe become the target of two banking trojan campaigns that are designed to infect Windows and Android devices with Grandoreiro and BTMOB malware, respectively. That's according to new findings from WatchGuard and ESET, which have observed the two malware fami…THEHACKERNEWS.COM
26 MayIran-Linked Hackers Target US Aviation with Phishing and SEO Poisoning CampaignIran's Nimbus Manticore pushes AI-built MiniFast backdoor via phishing and SEO poisoningINFOSECURITY-MAGAZINE.COM
26 May700+ education and tech websites hijacked in huge ClickFix malware campaignHackers are abusing a Ghost CMS website flaw to serve fake Cloudflare verification pages that pressure users into infecting their own PCs.MALWAREBYTES.COM
26 MayFeeding Frenzy: 'Megalodon' Malware Infects Thousands of GitHub ReposIn just six hours, the campaign quietly pushed thousands of malicious commits to more than 5,500 GitHub repositories, stealing credentials, developer secrets, and more.DARKREADING.COM
25 MayThe Code of Honor: Paul J. Maurer and Ed Skoudis explore ethics in cybersecurity with Ben Yelin.Authors Paul J. Maurer and Ed Skoudis join Caveat podcast co host Ben Yelin to discuss their new book: "The Code of Honor: Embracing Ethics in Cybersecurity." The book is a comprehensive and practical framework for ethical practices in contemporary cybersecurity. Listen t…THECYBERWIRE.COM
25 MayTrapDoor Supply Chain Attack Spreads Credential-Stealing Malware via npm, PyPI, and CratesIOA new coordinated cross-ecosystem software supply chain attack campaign has targeted npm, PyPI, and Crates.io to distribute credential-stealing malware. The campaign, codenamed TrapDoor, spans more than 34 malicious packages across over 384 versions. The earliest activity was rec…THEHACKERNEWS.COM
25 MayA week in security (May 18 – May 24)A list of topics we covered in the week of May 18 to May 24 of 2026MALWAREBYTES.COM
23 Maynpm Adds 2FA-Gated Publishing and Package Install Controls Against Supply Chain AttacksGitHub has rolled out new controls for npm to improve the security of the software supply chain, giving maintainers the ability to explicitly approve a release prior to the packages becoming publicly available for installation. Called staged publishing, the feature is now general…THEHACKERNEWS.COM
23 MayPackagist Supply Chain Attack Infects 8 Packages Using GitHub-Hosted Linux MalwareA new "coordinated" supply chain attack campaign has impacted eight packages on Packagist including malicious code designed to run a Linux binary retrieved from a GitHub Releases URL. "Although the affected packages were all Composer packages, the malicious code was not added to …THEHACKERNEWS.COM
23 MayThese special phone and app features can help protect you from spywareApple, Meta, and Google offer special security modes that provide your devices more secure against targeted spyware attacks. Here are how those modes work, what they do, and how to switch them on.TECHCRUNCH.COM
23 MayLaravel Lang packages hijacked to deploy credential-stealing malwareA supply chain attack targeting the Laravel Lang localization packages has exposed developers to a sophisticated credential-stealing malware campaign after attackers abused GitHub version tags to distribute malicious code through Composer packages. [...]BLEEPINGCOMPUTER.COM
22 MayKimwolf DDoS Botnet Operator Arrested in Canada Over DDoS-for-Hire AttacksThe U.S. Department of Justice (DoJ) on Thursday announced the arrest of a Canadian man in connection with allegedly operating a distributed denial-of-service (DDoS) botnet known as Kimwolf. In tandem, Jacob Butler (aka Dort), 23, Ottawa, Canada, has been charged with offenses re…THEHACKERNEWS.COM
22 MayFake Gemini and Claude Code Sites Spread Infostealers Through SEO PoisoningThe infostealer payload in this campaign collect a vast amount of data, from collaboration authentication keys to cryptocurrency walletsINFOSECURITY-MAGAZINE.COM
22 MayAuthorities arrest 23-year-old accused of running the Kimwolf botnetCanadian authorities arrested a 23-year-old Ottawa man accused of running the Kimwolf DDoS botnet. The US is now seeking extradition. US authorities have charged 23-year-old Jacob Butler (aka “Dort”), an Ottawa resident, for allegedly operating the recently disrupted Kimwolf botn…SECURITYAFFAIRS.COM
22 MayCanadian man arrested, charged for running KimWolf DDos botnetIn court documents unsealed on Thursday, the Justice Department said Jacob Butler ran KimWolf as a DDoS-for-hire service that infected over a million devices worldwide.THERECORD.MEDIA
22 MayCyber Centre launches new initiative to help Canada’s critical infrastructure prepare for severe cyber threatsCANADA.CA
22 MayCritical infrastructure resilience and escalated threat navigation initiativeThe time to act is now: Strengthening critical infrastructure cyber readiness for a resilient Canada.CYBER.GC.CA
22 MayFormer US execs plead guilty to aiding tech support scammersTwo former executives of a call-tracking and analytics company pleaded guilty to concealing a years-long tech support fraud scheme that victimized individuals worldwide. [...]BLEEPINGCOMPUTER.COM
21 MayShifting Budget Dynamics for Identity Security and AI AgentsAI agent projects are proliferating throughout the enterprise, and those AI agent identities require management, security, and governance. New Omdia research shows the AI agent identity budget dynamics are very different than traditional IAM projects.DARKREADING.COM
21 MayASCII art in phishing emails | Kaspersky official blogCybercriminals using ASCII art to create pseudographics QR codes with embedded phishing links.KASPERSKY.COM
21 MayCatch spyware in the act with Windows Webcam MonitoringKnow when a program tries to access your webcam so you can allow or block, in real time.MALWAREBYTES.COM
21 MayThree-Quarters of Firms Knowingly Ship Vulnerable CodeAI risks threaten to permeate supply chains through unvetted code and unaudited suppliersINFOSECURITY-MAGAZINE.COM
21 MayAI Agents Are Shifting Identity Security Budget DynamicsAI agent projects are proliferating throughout the enterprise, and those AI agent identities require management, security, and governance. New Omdia research shows the AI agent identity budget dynamics are very different than traditional IAM projects.DARKREADING.COM
21 MayAlleged Kimwolf Botmaster ‘Dort’ Arrested, Charged in U.S. and CanadaCanadian authorities on Wednesday arrested a 23-year-old Ottawa man on suspicion of building and operating Kimwolf, a fast spreading Internet-of-Things botnet that enslaved millions of devices for use in a series of massive distributed denial-of-service (DDoS) attacks over the pa…KREBSONSECURITY.COM
20 MayTyposquatting Is No Longer a User Problem. It's a Supply Chain ProblemAI-generated lookalike domains are now embedded inside the third-party scripts running on your web properties. Here's why your current stack can't see them, and what detection actually requires. Download the CISO Expert Guide to Typosquatting in the AI Era → TL;DR Typosquat…THEHACKERNEWS.COM
20 MayMalicious TV boxes: how a cheap “SuperBox” turns your home into a proxy node for cybercriminals | Kaspersky official blogA cheap Android TV box promising free subscriptions can easily become the backbone for cybercriminal botnets and proxy servers. We break down how these streaming boxes lease out your IP address, and how to choose a device that’s secure.KASPERSKY.COM
20 MayFake malware-signing service Fox Tempest dismantled by MicrosoftThe service let malware authors sign malicious files with fraudulent Microsoft-issued certificates to bypass security checks.MALWAREBYTES.COM
20 MayAndroid Malware Campaign Used Hundreds of Fake Apps to Silently Charge UsersPremium Deception campaign uses 250 Android apps to silently sign victims up to paid servicesINFOSECURITY-MAGAZINE.COM
20 MayMini Shai-Hulud Hits Hundreds of npm Packages in AntV EcosystemMini Shai-Hulud worm hits Alibaba AntV ecosystem in largest npm supply chain wave to dateINFOSECURITY-MAGAZINE.COM
19 MayFrom PDB strings to MaaS: Tracking a commodity BadIIS ecosystem used by Chinese-speaking threatCisco Talos has uncovered a BadIIS variant — identifiable by its embedded "demo.pdb" strings — that functions as commodity malware, likely sold or shared among multiple Chinese-speaking cyber crime groups operating under a malware-as-a-service (MaaS) model for continuous monetiza…TALOSINTELLIGENCE.COM
19 MayFrom Ivory Tower to Iron Curtain: The Academics Who Reshaped the CIAIn 1947, a new civilian intelligence agency was established: the CIA. But a series of intelligence failures undermined its credibility. The White House and Congress were up in arms, and a new mission was formed- to recruit Ivy League professors with uncanny skills. Leaving their …THECYBERWIRE.COM
19 MayStealer Spoofs Google, Microsoft & Apple, Then Backdoors macOSThe SHub Reaper stealer, which hides behind fake WeChat and Miro installers, marks a shift from ClickFix social engineering to Apple script-based execution.DARKREADING.COM
19 Maydurabletask: TeamPCP's Latest PyPi CompromiseDiscover the latest on malicious versions of the pypi package durabletask, matching TeamPCP tactics.WIZ.IO
19 MayThe Worm That Keeps on Digging: TeamPCP Hits @antv in Latest WaveMulti-ecosystem supply chain compromise by TeamPCP targets GitHub, NPM, and VSCode to steal credentials and establish persistence.WIZ.IO
18 MayA week in security (May 11 – May 17)A list of topics we covered in the week of May 11 to May 17 of 2026MALWAREBYTES.COM
18 MayPre-Stuxnet Fast16 Malware Tampered with Nuclear Weapons SimulationsA new analysis of the Lua-based fast16 malware has confirmed that it was a cyber sabotage tool designed to tamper with nuclear weapons testing simulations. According to Broadcom-owned Symantec and Carbon Black teams, the pre-Stuxnet tool was engineered to corrupt uranium-compress…THEHACKERNEWS.COM
18 MayDeveloper Workstations Are Now Part of the Software Supply ChainSupply chain attackers are not only trying to slip malicious code into trusted software. They are trying to steal the access that makes trusted software possible. Recently, three separate campaigns hit npm, PyPI, and Docker Hub in a 48-hour window, and all three targeted secrets …THEHACKERNEWS.COM
18 MayIT threat evolution in Q1 2026. Mobile statisticsThis report contains mobile threat statistics for Q1 2026, along with noteworthy discoveries and quarterly trends: new versions of SparkCat and Triada.SECURELIST.COM
18 MayIT threat evolution in Q1 2026. Non-mobile statisticsThe report presents key trends and statistics on malware that targeted personal computers running Windows and macOS, as well as Internet of Things (IoT) devices, during Q1 2026.SECURELIST.COM
15 May[Guest Diary] New Malware Libraries means New Signatures, (Fri, May 15th)&#;xd; &#;xd; ;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;…ISC.SANS.EDU
14 MayWhy Malwarebytes blocks some Yahoo Mail redirectsSome Yahoo Mail users may see repeated Malwarebytes alerts caused by background connections to suspicious third-party domains. Here’s why.MALWAREBYTES.COM
14 MayGoogle Launches Android Spyware Forensics Tool for High-Risk UsersGoogle’s Android Advanced Protection Mode is getting a new feature allowing trusted security experts to investigate potential spyware infectionsINFOSECURITY-MAGAZINE.COM
14 MayStealer Backdoor Found in 3 Node-IPC Versions Targeting Developer SecretsCybersecurity researchers are sounding the alarm about what has been described as "malicious activity" in newly published versions of node-ipc. According to Socket and StepSecurity, three different versions of the npm package have been confirmed as malicious - node-ipc@9.1.6 node…THEHACKERNEWS.COM
13 MayAndroid Adds Intrusion Logging for Sophisticated Spyware ForensicsGoogle on Tuesday unveiled a new opt-in Android feature called Intrusion Logging for storing forensic logs to better analyze sophisticated spyware attacks. Intrusion Logging, available as part of Advanced Protection Mode, enables "persistent and privacy-preserving forensics loggi…THEHACKERNEWS.COM
13 MayGlobal Cyber Agencies Issue New SBOMs for AI Guidance to Tackle AI Supply Chain RisksThe G7 Cybersecurity Working Group releases new SBOM for AI guidance, outlining seven key data clusters to boost transparency and security across AI supply chainsINFOSECURITY-MAGAZINE.COM
13 MayThis is what some the world’s largest banks of malware look like stacked as hard drivesWhat would some of the world's largest repositories of malware look like if they were stacked as hard drives, one on top of the other?TECHCRUNCH.COM
12 MayTeamPCP Compromises Checkmarx Jenkins AST Plugin Weeks After KICS Supply Chain AttackCheckmarx has confirmed that a modified version of the Jenkins AST plugin was published to the Jenkins Marketplace. "If you are using Checkmarx Jenkins AST plugin, you need to ensure that you are using the version 2.0.13-829.vc72453fa_1c16 that was published on December 17, 2025 …THEHACKERNEWS.COM
12 MayAndroid banking Trojan TrickMo evolves using TON network for C2ThreatFabric found a new TrickMo Android trojan focused on stealth and persistence, moving its command-and-control traffic to the TON network. Security researchers at ThreatFabric have recently identified a new version of TrickMo, a dangerous Android banking trojan that shows how…SECURITYAFFAIRS.COM
12 MayMalicious Hugging Face Repository Typosquats OpenAIHiddenLayer reveals infostealer malware in a Hugging Face repositoryINFOSECURITY-MAGAZINE.COM
12 MayWebinar: What the Riskiest SOC Alerts Go Unanswered - and How Radiant Security Can HelpWhy do the Riskiest SOC Alerts Go Unanswered? Security operations teams are drowning in alerts. But the real problem isn't always alert volume; it's the blind spots. The most dangerous alerts are the ones no one is investigating. A recent report from The Hacker News examined why …THEHACKERNEWS.COM
12 MayNew TrickMo Variant Uses TON C2 and SOCKS5 to Create Android Network PivotsCybersecurity researchers have flagged a new version of the TrickMo Android banking trojan that uses The Open Network (TON) for command-and-control (C2). The new variant, observed by ThreatFabric between January and February 2026, has been observed actively targeting banking and …THEHACKERNEWS.COM
12 MayRubyGems Suspends New Signups After Hundreds of Malicious Packages Are UploadedRubyGems, the standard package manager for the Ruby programming language, has temporarily paused account sign ups following what has been described as a "major malicious attack." "We're dealing with a major malicious attack on Ruby Gems right now," Maciej Mensfeld, senior product…THEHACKERNEWS.COM
12 MayInstructure strikes a deal with ShinyHunters.Texas sues Netflix over alleged data sharing. Humanitarian-themed phishing lures deliver stealthy Python malware.THECYBERWIRE.COM
12 MayChina’s hackers aren’t invincible.Former NSA chief says the U.S. can beat China in cyberspace. Canvas cuts a deal with hackers. The FCC proposes KYC rules for phone users. SAP patches critical flaws. A poisoned TanStack npm supply chain attack spreads malware. Humanitarian aid lures deliver spyware. Japan launche…THECYBERWIRE.COM
11 MayA week in security (May 4 – May 10)A list of topics we covered in the week of May 4 to May 10 of 2026MALWAREBYTES.COM
11 May⚡ Weekly Recap: Linux Rootkit, macOS Crypto Stealer, WebSocket Skimmers and MoreRough Monday. Somebody poisoned a trusted download again, somebody else turned cloud servers into public housing, and a few crews are still getting into boxes with bugs that should’ve died years ago — the same old holes, same lazy access paths, same “how the hell is this still op…THEHACKERNEWS.COM
11 MayTrickMo Variant Routes Android Trojan Traffic Through TONThreatFabric finds new TrickMo Android banking trojan variant routing C2 through The Open NetworkINFOSECURITY-MAGAZINE.COM
11 MayFCC eases restrictions on foreign-made routers.Police shutter German-language criminal marketplace. TrickMo Android malware uses TON blockchain for stealthy communications.THECYBERWIRE.COM
10 MaySECURITY AFFAIRS MALWARE NEWSLETTER ROUND 96Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter CloudZ RAT potentially steals OTP messages using Pheno plugin Backdoored PyTorch Lightning package drops credential…SECURITYAFFAIRS.COM
9 MayQuasar Linux RAT (QLNX): A Fileless Linux Implant Built for Stealth and PersistenceResearchers uncovered QLNX, a Linux RAT targeting developers to steal credentials, log keystrokes, monitor systems, and enable remote access. Security researchers discovered a previously undocumented Linux malware called Quasar Linux RAT (QLNX) that targets developers and DevOps …SECURITYAFFAIRS.COM
8 MayAustralian Cyber Security Centre Issues Alert Over ClickFix AttacksACSC warns over a campaign targeting organizations which uses ClickFix to deliver Vidar infostealer malwareINFOSECURITY-MAGAZINE.COM
8 MayQuasar Linux RAT Steals Developer Credentials for Software Supply Chain CompromiseA previously undocumented Linux implant codenamed Quasar Linux RAT (QLNX) is targeting developers' systems to establish a silent foothold as well as facilitate a broad range of post-compromise functionality, such as credential harvesting, keylogging, file manipulation, clipboard …THEHACKERNEWS.COM
8 MayTCLBANKER Banking Trojan Targets Financial Platforms via WhatsApp and Outlook WormsThreat hunters have flagged a previously undocumented Brazilian banking trojan dubbed TCLBANKER that's capable of targeting 59 banking, fintech, and cryptocurrency platforms. The activity is being tracked by Elastic Security Labs under the moniker REF3076. The malware family is a…THEHACKERNEWS.COM
8 MaySpace, the internet's next frontier.For decades, the internet has depended on terrestrial infrastructure solutions like fiber optics, undersea cables, cell towers, and data centers. However, that infrastructure still has hard limits especially in rural areas, disaster zones, or contested environments where building…THECYBERWIRE.COM
7 MayTCLBANKER: Brazilian Banking Trojan Spreading via WhatsApp and OutlookREF3076 uses a trojanized Logitech installer to deploy TCLBANKER, a Brazilian banking trojan with environment-gated payloads, WPF fraud overlays, and self-propagating WhatsApp and Outlook worm modules.ELASTIC.CO
7 MayAI in the Wrong HandsAI is the most powerful tool defenders have ever had. It's also the most dangerous weapon attackers have ever had. Assaf Keren, CSO at Qualtrics and author of Lessons from the Frontlines, has seen AI reshape both sides of the threat equation. In this conversation, he gets speci…THECYBERWIRE.COM
7 MayPyPI Packages Deliver ZiChatBot Malware via Zulip APIs on Windows and LinuxCybersecurity researchers have discovered three packages on the Python Package Index (PyPI) repository that are designed to stealthily deliver a previously unknown malware family called ZiChatBot on Windows and Linux systems. "While these wheel packages do implement the feat…THEHACKERNEWS.COM
7 MayNearly half of the world’s passwords can be cracked in under a minute | Kaspersky official blogUsing just a powerful graphics card, hackers can crack 60% of real user passwords in less than an hour. Even more alarming, 48% of passwords take less than a minute to compromise! Read our report to learn about the methods attackers use, the common password patterns folks resort …KASPERSKY.COM
7 MayFrom Android TVs to routers: the xlabs_v1 Mirai-based botnet built for DDoS attacksA new Mirai‑based botnet, xlabs_v1, hijacks ADB‑exposed IoT devices for powerful DDoS attacks, with 21 flooding methods and DDoS‑for‑hire use. A new Mirai‑derived botnet called xlabs_v1 is hijacking internet‑exposed devices running Android Debug Bridge (ADB) and using them for la…SECURITYAFFAIRS.COM
7 MayOpenAI and Anthropic LLMs Used in Critical Infrastructure Cyber-Attack, Warns DragosCommercial AI models were used to help plan and conduct cyber-attack against operational technology of a water and drainage facility, say researchersINFOSECURITY-MAGAZINE.COM
7 MayFake Claude AI Site Drops Beagle Backdoor on Windows UsersSophos finds fake Claude site spreading DonutLoader and a new Beagle backdoor via DLL sideloadingINFOSECURITY-MAGAZINE.COM
7 MayAfter Replacing TeamPCP Malware, 'PCPJack' Steals Cloud SecretsPCPJack makes innovative use of parquet files for stealthy, pre-validated target discovery as it canvasses multiple cloud environments.DARKREADING.COM
6 MayMalicious PyTorch Lightning update hits AI supply chain securityA malicious PyTorch Lightning update (v2.6.3) on PyPI spread briefly, stealing credentials and raising major concerns about AI supply chain security. A malicious update of the PyTorch Lightning library exposed developers to credential theft and remote compromise. Attackers upload…SECURITYAFFAIRS.COM
6 MayGoogle's Android Apps Get Public Verification to Stop Supply Chain AttacksGoogle has announced expanded Binary Transparency for Android as a way to safeguard the ecosystem from supply chain attacks. "This new public ledger ensures the Google apps on your device are exactly what we intended to build and distribute," Google's product and security teams s…THEHACKERNEWS.COM
6 MayWebsites with an undefined trust level: avoiding the trapWe explain what suspicious websites are and how to distinguish a safe site from a fraudulent one. A new category in Kaspersky solutions: we're sharing global statistics on untrusted site detection.SECURELIST.COM
6 MayHow VoidStealer bypasses Chrome’s protections to hijack sessions and steal data | Kaspersky official blogThe VoidStealer malware employs a new technique to circumvent Chrome’s App-Bound Encryption mechanism, gaining access to session cookies and other sensitive user data.KASPERSKY.COM
6 MayLABScon25 Replay | Please Connect to the Foreign Entity to Enhance Your User ExperienceJoe FitzPatrick reveals how consumer imports of networked devices pose a real security risk to small businesses and critical infrastructure alike.SENTINELONE.COM
6 MayAttackers adopt JavaScript runtime Bun to spread NWHStealerA legitimate developer tool is being repurposed by attackers to package and spread this Windows infostealer in harder-to-detect ways.MALWAREBYTES.COM
6 MaySome kids are bypassing age verification checks with a fake mustacheA new survey found that kids find it easy to bypass age checks, despite a rise in age verification laws around the world.TECHCRUNCH.COM
6 MayYet Another Way to Bypass Google Chrome's Encryption ProtectionAuthors of the VoidStealer Trojan uncovered a way to get around Google's App-Bound Encryption (ABE), opening the door to infostealers.DARKREADING.COM
6 MayThe Jenkins Threat LandscapeWhat usage patterns, plugin adoption, and configuration choices reveal about the Jenkins attack surface.WIZ.IO
5 MaySupply chain attack via DAEMON Tools | Kaspersky official blogKaspersky experts have detected a supply chain attack using the popular DAEMON Tools software.KASPERSKY.COM
5 MayUpdate WhatsApp now: Two new flaws could expose you to malicious filesWhatsApp patches flaws that could expose users to malicious content and disguised malware.MALWAREBYTES.COM
5 MayFTC bans data broker Kochava from selling sensitive location infoThe FTC has said that Kochava sold precise geolocation data showing consumers visiting houses of worship and health care clinics without their consent or awareness, an alleged violation of a law barring companies from engaging in unfair and deceptive practices.THERECORD.MEDIA
4 MayA week in security (April 27 – May 3)A list of topics we covered in the week of April 27 to May 3 of 2026MALWAREBYTES.COM
4 MaySilver Fox Deploys ABCDoor Malware via Tax-Themed Phishing in India and RussiaThe China-based cybercrime group known as Silver Fox has been linked to a new campaign targeting organizations in Russia and India with a new malware called ABCDoor. The activity involved using phishing emails that mimic correspondence from the Income Tax Department of India in D…THEHACKERNEWS.COM
3 MaySECURITY AFFAIRS MALWARE NEWSLETTER ROUND 95Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter fast16 | Mystery ShadowBrokers Reference Reveals High-Precision Software Sabotage 5 Years Before Stuxnet 73 Open VSX Sleep…SECURITYAFFAIRS.COM
30 AprSilver Fox uses the new ABCDoor backdoor to target organizations in Russia and IndiaThe Silver Fox group is targeting companies in Russia and India by impersonating tax authorities to distribute ValleyRAT and the new ABCDoor backdoor.SECURELIST.COM
30 AprCyber is the Number One Global “People Risk,” Says MarshMarsh’s 2026 People Risks survey finds cyber‑related challenges dominate, as cyber‑threat literacy tops risks and cyber and AI skills shortages riseINFOSECURITY-MAGAZINE.COM
30 AprExposed Data Illustrates the Nightmare Scenario for a Stalkerware VictimExtremely sensitive personal data from a European celebrity that appears to have been compiled using spyware was publicly accessible until a researcher flagged the exposure.WIRED.COM
30 AprThreatsDay Bulletin: SMS Blaster Busts, OpenEMR Flaws, 600K Roblox Hacks and 25 More StoriesThe internet is noisy this week. We are seeing some wild new tactics, like people using fake cell towers to send scam texts, while some developers are accidentally downloading tools that peek into their private files during a simple install. It is definitely a busy time to be onl…THEHACKERNEWS.COM
30 AprDeep#Door Python Backdoor Evades Detection On WindowsDeep#Door Python RAT uses tunneling and obfuscation to evade detection and steal credentialsINFOSECURITY-MAGAZINE.COM
30 AprThree Arrested for Hacking Over 610,000 Roblox AccountsSuspects accused of distributing malware and selling access to stolen Roblox accounts on Russian marketplacesINFOSECURITY-MAGAZINE.COM
29 AprLotus Wiper Attack Targeted Venezuelan Energy Firms, UtilitiesAn analysis of the destructive malware reveals sophisticated living-off-the-land (LotL) techniques and detailed strategies for the widespread deletion of data.DARKREADING.COM
29 AprNew Wave of DPRK Attacks Uses AI-Inserted npm Malware, Fake Firms, and RATsCybersecurity researchers have discovered malicious code in an npm package after a malicious package as a dependency to the project by Anthropic's Claude Opus large language model (LLM). The package in question is "@validate-sdk/v2," which is listed on npm as a utility software d…THEHACKERNEWS.COM
29 AprSupply Chain Campaign Targets SAP npm Packages with Credential-Stealing MalwareDetect and mitigate malicious npm packages linked to the recent Shai-Hulud-style campaign - Mini Shai Hulud.WIZ.IO
29 AprWiz Code Week Recap: Securing AI Native DevelopmentProviding Application Security teams with visibility and guardrails to secure agentic software development and the modern software supply chainWIZ.IO
28 AprNew Android spyware Morpheus linked to Italian surveillance firmOsservatorio Nessuno uncovered Morpheus spyware spreading via fake Android apps to steal data, highlighting rising covert surveillance tools. The non-partisan, non-religious, nonprofit organization Osservatorio Nessuno exposed a new spyware called Morpheus, distributed through fa…SECURITYAFFAIRS.COM
28 AprWhy Secure Data Movement Is the Zero Trust Bottleneck Nobody Talks AboutEvery security program is betting on the same assumption: once a system is connected, the problem is solved. Open a ticket, stand up a gateway, push the data through. Done. That assumption is wrong. It is also a major reason Zero Trust programs stall. New research my team just pu…THEHACKERNEWS.COM
28 AprFresh Wave of GlassWorm VS Code Extensions Slices Through Supply ChainAttackers continue to scale a campaign to seed Open VSX with seemingly benign VS Code extensions that spread self-propagating malware.DARKREADING.COM
28 AprBrazilian LofyGang Resurfaces After Three Years With Minecraft LofyStealer CampaignA cybercrime group of Brazilian origin has resurfaced after more than three years to orchestrate a campaign that targets Minecraft players with a new stealer called LofyStealer (aka GrabBot). "The malware disguises itself as a Minecraft hack called 'Slinky,'" Brazil-based cyberse…THEHACKERNEWS.COM
28 AprParagon is not collaborating with Italian authorities probing spyware attacks, report saysDespite promising to help determine what happened with the hacks targeting journalists and activists in Italy, Israeli-American spyware maker Paragon has reportedly not responded to authorities’ requests for information.TECHCRUNCH.COM
27 AprA week in security (April 20 – April 26)A list of topics we covered in the week of April 20 to April 26 of 2026MALWAREBYTES.COM
27 AprFast16: Pre-Stuxnet malware that targeted precision engineering softwareFast16 is a pre-Stuxnet malware that tampered with precision software and spread itself. Evidence suggests links to U.S. operations during early cyber tensions. SentinelOne uncovered Fast16, a sabotage malware used in 2005, years before Stuxnet. The malicious code is written in L…SECURITYAFFAIRS.COM
27 AprResearchers Identify Fast16 Sabotage Malware That Pre-Dates StuxnetThe “fast16” malware may have been used to target Iran’s nuclear program prior to StuxnetINFOSECURITY-MAGAZINE.COM
27 AprResearchers Uncover 73 Fake VS Code Extensions Delivering GlassWorm v2 MalwareCybersecurity researchers have flagged dozens of Microsoft Visual Studio Code (VS Code) extensions on the Open VSX repository that are linked to a persistent information-stealing campaign dubbed GlassWorm. The cluster of 73 extensions has been identified as cloned versions of the…THEHACKERNEWS.COM
27 Apr20-Year-Old Malware Rewrites History of Cyber SabotageResearchers have uncovered a malware framework dubbed "fast16" that predates Stuxnet by 5 years.DARKREADING.COM
27 Apr⚡ Weekly Recap: Fast16 Malware, XChat Launch, Federal Backdoor, AI Employee Tracking & MoreEverything is dumb again. This week feels broken in a very familiar way. Old tricks are back. New tools are doing shady crap. Supply chains got hit. Fake help desks worked. Weird research showed how easy some attacks still are. Most of it feels like stuff we should have fixed yea…THEHACKERNEWS.COM
27 AprPhishing crypto-wallet clones in the App Store and other attacks on iOS and macOS crypto owners | Kaspersky official blogNew waves of attacks on Apple users are leading to stolen cryptocurrency: fake crypto wallets in the App Store, trojanized legitimate macOS crypto apps, and other threats. Here’s how to stay protected.KASPERSKY.COM
26 AprSECURITY AFFAIRS MALWARE NEWSLETTER ROUND 94Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Morpheus: A new Spyware linked to IPS Intelligence The iPhone — invincible no more: a look at DarkSword and Coruna Lotus Wiper: a new …SECURITYAFFAIRS.COM
25 AprResearchers Uncover Pre-Stuxnet ‘fast16’ Malware Targeting Engineering SoftwareCybersecurity researchers have discovered a new Lua-based malware created years before the notorious Stuxnet worm that aimed to sabotage Iran's nuclear program by destroying uranium enrichment centrifuges. According to a new report published by SentinelOne, the previously undocum…THEHACKERNEWS.COM
24 AprNpm Supply Chain Malware Attack Targets Developers With Worm-Like PropagationMalicious npm packages spread via worm-like propagation and steal developer credentialsINFOSECURITY-MAGAZINE.COM
24 Apr26 FakeWallet Apps Found on Apple App Store Targeting Crypto Seed PhrasesCybersecurity researchers have discovered a set of malicious apps on the Apple App Store that impersonate popular cryptocurrency wallets in an attempt to steal recovery phrases and private keys since at least fall 2025. "Once launched, these apps redirect users to browser pages d…THEHACKERNEWS.COM
24 AprAnother spyware maker caught distributing fake Android snooping appsResearchers have found a new case where government authorities used a fake Android app to plant spyware on a target’s phone. The company that allegedly developed the spyware was not previously known to sell this type of software.TECHCRUNCH.COM
📰 CYBERSECURITY BRIEFINGS 17[+]
19 JulReimagining European space sovereignty.This week on T-Minus: Space-Cyber Briefing: we look at the recent evolution of the European space program. Whereas the region had previously relied on the US to support its space goals, both the UK and the EU have begun to make significant changes to reduce this reliance.THECYBERWIRE.COM
12 JulSpace after quantum.This week on T-Minus: Space-Cyber Briefing: we look at how the space sector is preparing itself for quantum computing. While practical quantum computing has long seemed just over the horizon, governments and commercial space operators alike are now actively preparing for the day …THECYBERWIRE.COM
5 JulThe rise of the commercial space industry.This week on T-Minus: Space-Cyber Briefing: we look at how the space sector has continued to evolve in recent years as commercialization has continued to expand. As this market has changed, government agencies and companies have changed their approaches to innovation, interoperab…THECYBERWIRE.COM
4 JulSecurity Roundup: Apple’s Hide My Email Service Fails to Hide Your EmailPlus: Alleged Scattered Spider hacking member extradited, dozens of license plate reader errors, and Indian officials are concerned about WhatsApp’s username rollout.WIRED.COM
21 JunThe next era of GPS attacks.This week on T-Minus: Space-Cyber Briefing: we look at how GPS attacks are evolving. Whereas traditional GPS jamming and spoofing attacks have typically involved targeting weak signals as they reach the surface, new attacks are potentially targeting these signals in space.THECYBERWIRE.COM
14 JunThe space-cyber gap.This week on T-Minus: Space-Cyber Briefing: we dive deeper into Shaun Waterman’s recent article into recently launched initiatives that aim to bolster the US’s cyber-space capabilities, including the Department of Homeland Security’s research to better repel hostile cyber activit…THECYBERWIRE.COM
7 JunInside modern GPS attacks.This week on T-Minus: Space-Cyber Briefing: we dive into two of the most common ways actors target GPS signals. Whether it be through jamming or spoofing attacks, actors are increasingly utilizing these vectors to disrupt communications, sow confusion, and engage more effectively…THECYBERWIRE.COM
1 JunRed Canary CFP tracker: May 2026Red Canary's monthly roundup of upcoming security conferences and call for papers (CFP) submission deadlines May 2026REDCANARY.COM
31 MayThe evolution of GPS.This week on T-Minus: Space-Cyber Briefing: we look at GPS and how this technology has become instrumental to modern society. As governments have expanded the public’s use of this technology it has evolved from a fringe service to one that supports many of the modern day services…THECYBERWIRE.COM
18 MayN2K CyberWire's T-Minus returns with focus on the critical intersection of space and cybersecurityN2K Networks today announced the next evolution of its space-focused podcast as T-Minus: Space-Cyber Briefing, a new weekly program dedicated to the expanding intersection of space and cybersecurity, on the N2K CyberWire network.THECYBERWIRE.COM
13 May[Webinar] Why Your AppSec Tools Miss the "Lethal Path" (and How to Fix It)TL;DR: Stop chasing thousands of "toast" alerts. Join experts from Wiz and Okta/GitLab to learn how hackers connect tiny flaws to build a "Lethal Chain" to your data—and how to break it. Register for the Strategic Briefing Here. Most security tools work like a smoke alarm that go…THEHACKERNEWS.COM
13 MayUK moves to shield security researchers in cybercrime law overhaulThe proposed reforms, outlined in briefing documents published alongside the King’s Speech opening a new parliamentary session, would update the Computer Misuse Act 1990 as part of a broader national security package focused on cybercrime and digital threats.THERECORD.MEDIA
🎙️ PODCASTS 43[+]
23 JulSrsly Risky Biz: Knives are out for open-weight AI modelsTom Uren and James Wilson talk about the future of open-weight models. For different reasons, both the Chinese and American governments have reasons to crack down on them. They also talk about arrests of several members of the Scattered Spider juvenile cybercrime collective. This…RISKY.BIZ
21 JulBetween Two Nerds: What China gets wrong about Russia's cyber war in UkraineIn this edition of Between Two Nerds Tom Uren and The Grugq discuss what mainland Chinese analysts think about Russia’s use of cyber operations in the war in Ukraine. This episode is also available on YouTube.RISKY.BIZ
20 JulSponsored: Thinkst on building companies that don’t suckIn this Risky Business sponsor interview Casey Ellis chats with Haroon Meer from Thinkst about building companies customers don’t hate. Haroon explains why Thinkst still offers Canary tokens for free and why it has avoided annual price hikes on its paid products. They talk about …RISKY.BIZ
19 JulEurope's push for space sovereignty.As space becomes an increasingly critical part of modern infrastructure, governments are reevaluating decades of policy to ensure reliable, secure, and independent access to the systems they are increasingly relying on. In this week’s episode, host Maria Varmazis sits down with p…THECYBERWIRE.COM
16 JulSmashing Security podcast #476: Remote-control rickshaws and rogue book marketersAn app has appeared in India that lets anyone with a smartphone stop a passing e-rickshaw dead in its tracks - no login, no passwords, no permissions needed. Meanwhile, Geoff - swimming in money and Lamborghinis, as all published authors are - has been on the receiving end of a s…GRAHAMCLULEY.COM
13 JulTrusting your kids online isn’t enough (Lock and Code S07E14)This week on the Lock and Code podcast, we speak with Anna Brading about what actually works in keeping her kids safe online.MALWAREBYTES.COM
12 JulPreparing space for Q-day.As the world prepares itself for quantum computing, governments and private space enterprises alike are looking to get ahead of the technology and manage the rapidly-accelerating risks. In this week’s episode, host Maria Varmazis sits down with Eddy Zervigon, CEO of Quantum XC…THECYBERWIRE.COM
10 JulSponsored: Why Sublime doesn’t toss AI at every emailIn this Risky Business sponsored interview, Tom Uren chats with Sublime Security Product Manager AJ Williams about how the company targets its AI use. Rather than throwing its AI agents at everything, Sublime gives them the time-consuming email security tasks that humans don’t wa…RISKY.BIZ
9 JulSrsly Risky Biz: US Supreme Court undermines Section 702 intelTom Uren and James Wilson talk about a new US Supreme Court decision that puts the current EU-US data sharing agreement at risk. American intelligence collection efforts have been at the centre of legal challenges of these on-again off-again data transfer agreements, and if the c…RISKY.BIZ
8 JulSoap Box: Using threat hunting to drive detectionIn this wholly sponsored Soap Box edition of the podcast Patrick Gray chats with Damien Lewke, the CEO and founder of Nebulock, about the future of threat hunting and detection. Damien spent a decade in the EDR and MDR space before founding Nebulock in 2024. It started off as an …RISKY.BIZ
7 JulBetween Two Nerds: Why AI has not meant more hacks. Yet.In this edition of Between Two Nerds Tom Uren and The Grugq talk about why we haven’t seen an explosion of devastating hacks even though AI has been used to discover lots and lots of bugs. This episode is also available on YouTube.RISKY.BIZ
5 JulCommercializing space.Over the past two decades, the space industry has changed dramatically, evolving from a largely government led effort to one that is now rooted in private enterprises driving growth and innovation. In this week’s episode, host Maria Varmazis sits down with Damian DiPippa, CEO …THECYBERWIRE.COM
1 JulSmashing Security podcast #474: Polymarket can predict the future. So how did it miss this hack?Polymarket has built an entire business on predicting the future. So how did it manage to spectacularly fail to predict its own hack? Plus, the Google engineer with a million-dollar secret, and the curious case of the airport hairdryer. Meanwhile, "FortiBleed" sees 75,000 Fortine…GRAHAMCLULEY.COM
30 JunBetween Two Nerds: Set cyberspace ablazeIn this edition of Between Two Nerds, Tom Uren and The Grugq discuss whether cyber organisations should actually be separated from Signals Intelligence organisations. The Grugq argues that having cyber expertise subordinate to intelligence collection means that many opportunities…RISKY.BIZ
29 JunThis pay gap is programmed (Lock and Code S07E13)This week on the Lock and Code podcast, we speak with Veena Dubal about algorithmic wage discrimination and its appetite for all worker data.MALWAREBYTES.COM
28 JunUniting Women in Cyber Podcast: Breaking Barriers in Cybersecurity with Cybersecurity Girl.In this Special Edition episode, N2K CyberWire's Dave Bittner sits down with Caitlin Sarian, widely known as Cybersecurity Girl, to explore how storytelling, authenticity, and community are reshaping a more human-centered cybersecurity landscape.THECYBERWIRE.COM
24 JunHow to Run a Content Syndication Program That Works with Steve Piper of CyberEdge GroupContent syndication has earned a mixed reputation among cybersecurity marketers. Too often, programs generate large volumes of leads but little measurable pipeline. Sales teams question lead quality, marketing teams question whether the right buyers are being reached, and both si…THECYBERWIRE.COM
17 JunFrom First Talk to 89 Episodes a Year: The Cyber Creator Journey with Phillip WyliePhillip Wylie has been in cybersecurity for over 28 years and is now one of the most recognized names in offensive security as a speaker, podcaster, and evangelist. What most people don't know is that he started as a pro wrestler and powerlifter before finding his way into IT and…THECYBERWIRE.COM
15 JunDeepfake porn sites are going offline (re-air) (Lock and Code S07E12)This week on the Lock and Code podcast, we revisit an episode from 2024 with David Chiu that shows the progress made against deepfake porn.MALWAREBYTES.COM
11 JunDrug Sites Hijacked Spotify’s Search Ranking Through Fake PodcastsA joint congressional report describes a spam operation that turned tens of thousands of fake podcasts into search-engine bait for illegal pharmacy and scam sites.WIRED.COM
11 JunWhy Identity Must Evolve for AI-Driven Work with Peter Barker from Ping IdentityPeter Barker, Chief Product Officer at Ping Identity, joins Dave Bittner on the CyberWire Daily podcast for a sponsored Industry Voices. Peter discusses how AI agents, copilots, and automation are reshaping enterprise identity, creating demand for systems that can operate beyond …THECYBERWIRE.COMHTTPS:
10 JunSimplifying Security for SMBs with Joe Sykora, CEO from CoroJoe Sykora, CEO of Coro, joins Dave Bittner on the CyberWire Daily podcast for a sponsored Industry Voices to discuss the cybersecurity challenges facing SMBs and the MSPs that support them. Joe explains why fragmented security stacks create unnecessary complexity, how AI is help…THECYBERWIRE.COMHTTPS:
10 JunSmashing Security podcast #471: This AI worm just rewrote its own rulesResearchers at the University of Toronto have built a worm that thinks for itself. Using free off-the-shelf AI models it works out how to break into each new computer it encounters, and hijacks the powerful ones to host its own AI brain. And then the researchers discovered their …GRAHAMCLULEY.COM
9 JunInside the Media Mind of Joel Witts: Expert InsightsIn this episode of #IMM, Christine and Madison sit down with Joel Witts, Director of Content and Co-Founder at Expert Insights.THECYBERWIRE.COM
5 JunSoap Box: Detection and response in the AI ageIn this sponsored Soap Box edition of the Risky Business podcast Patrick Gray chats with Edward Wu, founder of Dropzone, about what AI is doing to detection, response and the SOC more generally. Dropzone makes AI agents that conduct alert investigations in your SOC, but will the …RISKY.BIZ
4 JunIs Your Enterprise AI Strategy Delivering ROI Yet?Your enterprise AI strategy isn’t as far along as you think. The reality for most organizations today is that AI is disrupting existing processes more than it’s delivering outcomes… so far. And according to Dr. Grace Trinidad, Research Director at IDC, that’s how it should be. In…THECYBERWIRE.COM
4 JunNavigating AI Vulnerabilities and Machine-Speed Threats with Jason Kikta from AutomoxJason Kikta, CTO at Automox, joins Dave Bittner on the CyberWire Daily podcast for a sponsored Industry Voices to discuss why speed has become the defining challenge in modern cybersecurity. Jason explores how organizations can balance AI-driven innovation with practical risk man…THECYBERWIRE.COMHTTPS:
3 JunSmashing Security podcast #470: This AI security flaw might be impossible to fixA website called "UK visa portal" has been quietly collecting passport scans, selfies, and personal data from thousands of travellers who thought they were applying through official channels. They weren't. And when a journalist tried to warn the company, it was lawyers who respon…GRAHAMCLULEY.COM
3 JunThe MSP's Expanding Security Mission with Benjamin Morrell from Coro CybersecurityBenjamin Morrell, Vice President of Security Strategy at Coro, joins Dave Bittner on the CyberWire Daily podcast for a sponsored Industry Voices to discuss the evolving cybersecurity challenges facing SMBs and the MSPs that support them. Ben explores the risks created by fragment…THECYBERWIRE.COMHTTPS:
1 JunPayment apps are watching what you say (Lock and Code S07E11)This week on the Lock and Code podcast, we speak with Rainey Reitman about financial censorship that boots customers off major payment apps.MALWAREBYTES.COM
1 JunThe Content Challenge Behind AI Adoption with Heather Ceylan from BoxHeather Ceylan, CISO at Box, joins Dave Bittner on the CyberWire Daily podcast for a sponsored Industry Voices to discuss why many organizations have a content problem, not just an AI problem. Heather explains how fragmented, unstructured, and poorly governed content undermines A…THECYBERWIRE.COMHTTPS:
28 MayBuilding Crisis Response Plans That Work Under Pressure with Courtney Guss of Semperis.Courtney Guss, Crisis Management Director at Semperis, joins Dave Bittner on the CyberWire Daily podcast for a sponsored Industry Voices to discuss why crisis planning must evolve beyond audit checklists and static documentation. She explains how organizations can build faster, m…THECYBERWIRE.COMHTTPS:
27 MayThe Case for Internal Comms with Thereasa RoyInternal comms is one of those marketing functions that doesn't always get its own seat at the table, but probably should. Thereasa Roy, formerly Director of Technical Solutions Marketing at Trail of Bits, now Director of Product Marketing at Oversight joins Gianna to talk throug…THECYBERWIRE.COM
21 MayWho’s responsible when AI starts making mistakes?With over two decades of experience spanning global CIO and CISO roles Sachin Jain has a perspective on accountability that goes well beyond the CISO's desk. In this episode, Sachin shares why AI governance is a shared responsibility across the organization, and offers practical …THECYBERWIRE.COM
20 MayBuilding AI Content Systems That Actually Work with David Ebner of Content WorkshopDavid Ebner has been building content for security and tech brands for 13 years, and the work has changed significantly with the dawn of the AI content era. He comes back on the show to talk about what AI systems look like inside a marketing team, how they get built, and what ste…THECYBERWIRE.COM
18 MayAI is distorting the Holocaust (Lock and Code S07E10)This week on the Lock and Code podcast, we speak with Clara Mansfeld about how AI-generated imagery is warping the history of the Holocaust.MALWAREBYTES.COM
17 MayFrom cyberspace to space-cyber.For years, in-space internet capabilities were rarely worth the hassle. Now, that’s changing. In today’s episode, Maria Varmazis and Ethan Cook sit down to discuss how internet data moves through space systems and its recent advancements. For decades, GEO satellites made up m…THECYBERWIRE.COM
13 MayCyber Creator Tyler Ramsbey Shares How to Grow an Audience & Community in CyberThis episode is a little different. We're sharing a session from Behind the Cyber Creator, a live AMA series we run at the Cybersecurity Marketing Society, and Tyler Ramsbey was our first guest. Tyler went from pastor to pentester, built a study group into a community of 15,000 p…THECYBERWIRE.COM
12 MayInside the Media Mind of Shaun Waterman: FreelancerIn this latest episode of #IMM, Christine and Madison welcome Shaun Waterman, freelance journalist specializing in cybersecurity, space and federal contracting.THECYBERWIRE.COM
7 MayHow do we secure applications when anyone can code?Ashish Rajan doesn’t sugarcoat what it means to be a security leader in the AI era. This is a moment where innovation is outpacing control. Where AI is being embedded into everything, often faster than organizations can understand, govern, or secure it. Ashish is a CISO, trusted …THECYBERWIRE.COM
6 MaySmashing Security podcast #466: Meta sees everything, Copy Fail, and a deepfake gets hiredMeta's smart glasses promise privacy "designed for you" - but everything they record was being beamed off to workers in Nairobi to label by hand. When those workers blew the whistle, Meta sacked all 1,108 of them. Meanwhile, the IT press is in a frenzy over a new Linux bug called…GRAHAMCLULEY.COM
5 MayHow the Story of a USB Penetration Test Went ViralTwo decades ago Dark Reading posted its first blockbuster — a column by a pen tester who sprinkled rigged thumb drives around a credit union parking lot and let curious employees do the rest. This episode looks back at the history-making piece with its author Steve Stasiukonis, D…DARKREADING.COM
25 AprCybersecurity Today Weekend: Deepfakes, the Death of Truth, and Verifying AI in the Enterprise📍 again, we'd like to thank Meter for their support in bringing you this podcast Meter delivers full stack networking infrastructure, wired, wireless, and cellular to leading enterprises. Working with their partners, meter designs, deploys and manages everything required to get p…CYBERSECURITYTODAY.LIBSYN.COM
📡 INFOSEC NEWS 1095[+]
23 JulGitHub Cuts Public Bug Bounty Payouts, Moves Top Rewards to VIP TierBeginning July 27, 2026, GitHub will cut public bug bounty payouts by at least half at every severity level. Critical findings will drop from $20,000-$30,000+ to a fixed $10,000, while its permanent invite-only VIP tier will pay $30,000 or more. Reports filed before that date, in…THEHACKERNEWS.COM
23 JulAI’s political and copyright reckoning.This week, Dave and Ben look at two stories centered around AI. The first involves how politicians are trying to combat how AI chatbots spread inaccurate or incomplete information on their campaigns to voters. The second story looks at how existing copyright laws are not robust e…THECYBERWIRE.COM
23 JulMicrosoft working to fix Exchange Online mailbox quarantine issueMicrosoft is working to resolve an ongoing Exchange Online issue that has been mistakenly quarantining customers' mailboxes since Sunday. [...]BLEEPINGCOMPUTER.COM
23 JulPreview: Cisco Talos at Black Hat USA 2026Here’s some of the ways Talos is showing up at Black Hat, alongside our friends at Cisco and Splunk.TALOSINTELLIGENCE.COM
23 JulHow Synthetic Identity Fraud is Coming for Machine IdentitiesMost people understand identity theft as an attacker stealing a real person's sensitive information and impersonating them. Synthetic identity fraud is much harder to catch. Instead of stealing a real identity, the attacker manufactures a new one, frankensteining together several…THEHACKERNEWS.COM
23 JulGoogle Adds Selfie Video Recovery for Users Locked Out of Their AccountsGoogle on Thursday announced a new way for users to sign-in to their accounts by letting them take a selfie video. The selfie for sign-in, per the tech giant, is another option on top of existing recovery methods to log in to an account, including an email address or a phone numb…THEHACKERNEWS.COM
23 JulMillions of cars could be tracked and unlocked by a hidden security flawA hidden flaw in a dealer-installed car alarm could let attackers unlock vehicles and track their locations. Many owners don't know they have one.MALWAREBYTES.COM
23 JulAgentic AI Challenges Progress in Confidential ComputingCore issues that slowed down adoption of secure data vaults are being resolved by technology, but artificial intelligence poses new ones. Experts have some answers.DARKREADING.COM
23 JulEU fines Google $1 billion for search, app store antitrust violationsThe European Commission fined Google €890 million ($1 billion) on Thursday after finding the company had violated the European Union's Digital Markets Act (DMA), which ensures fair online competition. [...]BLEEPINGCOMPUTER.COM
23 JulMicrosoft Copilot Deployments Delayed Over Security ConcernsCoreView research finds that security leadership is concerned about AI Assistant exposing confidential dataINFOSECURITY-MAGAZINE.COM
23 JulFedRAMP Rev5 Is Ending: What the 20x Transition Really RequiresFedRAMP 20X replaces point-in-time assessments with continuous, machine-readable evidence that demonstrates security controls are working. Anecdotes explains what the transition from Rev5 to FedRAMP 20X means and how organizations can prepare for continuous, evidence-based assura…BLEEPINGCOMPUTER.COM
23 JulChina-Nexus JadeProx Uses New TriBack Loader in Government and Healthcare AttacksAn exposed Alibaba Cloud server has revealed a China-nexus operation that Group-IB tracks as JadeProx. The cluster has targeted government, healthcare, and education organizations across Asia and Latin America with a previously undocumented Windows loader called TriBack Loader. G…THEHACKERNEWS.COM
23 JulOpenAI’s AI “goes rogue” and hacks Hugging Face: what you need to knowYou can't have failed to hear the news headlines about "rogue" OpenAI models hacking into another AI organisation, Hugging Face. But what has actually happened, who is to blame, and is it as serious as some of the reports suggest? Find out in my article on the Hot for Security bl…BITDEFENDER.COM
23 JulMicrosoft 365 outage affects Teams, SharePoint and other servicesMicrosoft Teams and several Microsoft 365 services are experiencing an ongoing outage, with users reporting problems accessing Teams, SharePoint, Excel and the Microsoft 365 Admin Center. [...]BLEEPINGCOMPUTER.COM
23 JulEnterprise security at machine speed: AWS Black Hat 2026 previewBlack Hat 2026 (Aug 1-6, 2026) brings together over 22,000 security practitioners, researchers, and CISOs who build, break, and defend enterprise infrastructure. They’re security professionals who push the limits of offensive and defensive security and demand proof over promises.…AWS.AMAZON.COM
23 JulState Department imposes visa restrictions on foreign cyber scammersIndividuals connected to transnational cyber-scam operations face U.S. visa restrictions under a new policy announced by Secretary of State Marco Rubio.THERECORD.MEDIA
23 JulInternational alert spotlights Russia-linked attacks on Zimbra webmailA Kremlin-backed group known as Laundry Bear has been using a zero-click phishing technique to break into Zimbra webmail accounts worldwide, the U.S. and other nations said.THERECORD.MEDIA
23 JulIntelligence Insights: July 2026ClearFake claims the crown again and CastleLoader debuts in this month’s edition of Intelligence Insights.REDCANARY.COM
23 JulAegisAI, founded by former Google security execs, lands $36M to stop AI-driven spear phishingThe Series A was led by Battery Ventures, bringing AegisAI total funding to $49 million.TECHCRUNCH.COM
23 JulFor Taylor Swift, Madison Square Garden’s Controversial Cameras Briefly Went DarkMSG’s sprawling surveillance system can monitor guests down to the second. Its owners made an exception for the pop star’s rehearsal dinner.WIRED.COM
23 JulForgot your Google password? Now you can log in with a selfie.Google's selfie videos can be used for account access, AI Avatars, and age verification.ARSTECHNICA.COM
23 JulDon’t swing at everythingThorsten explores Q2 2026 stats, the artificial buffer zone of 2026, and why smart, prioritized patching is more critical than ever.TALOSINTELLIGENCE.COM
23 JulEU issues largest DSA fine against AliExpress.OpenAI backs Massachusetts AI safety efforts.THECYBERWIRE.COM
22 JulWeekly Threat Bulletin – July 22nd, 2026These are the top threats you should know about this week.F5.COM
22 JulBuilding a Security Company for a Market That Changes Every Four Months with Shahar Bahat of Pluto SecurityShahar Bahat is the CEO and co-founder of Pluto Security. With every employee now building things using tools like Cursor, Claude Code, Lovable, and n8n, security teams have no visibility into any of those layers. That is the problem Pluto is solving. She sat down with Gianna to …THECYBERWIRE.COM
22 JulMicrosoft Azure DevOps MCP Flaw Lets Hidden PR Comments Hijack AI Review AgentsA single invisible comment in an Azure DevOps pull request can turn a reviewer's own AI coding agent against them, driving it into projects the attacker has no rights to reach and quietly leaking what it finds. The flaw is in Microsoft's official Azure DevOps MCP server, and it w…THEHACKERNEWS.COM
22 JulGlow emerges from stealth at $1.2B valuation to challenge endpoint security in the AI eraGlow is targeting a new class of endpoint risks created by the rapid adoption of AI agents and developer tools inside enterprises.TECHCRUNCH.COM
22 JulStop renting storage space — this lifetime 2TB plan is yours for $59Cloud storage costs tend to creep up over time, since most services charge monthly or annually for as long as you use them. FileJump's Lifetime Plan skips that model entirely, offering 2TB of cloud storage for a single payment of $59 (MSRP $467). [...]BLEEPINGCOMPUTER.COM
22 JulChick-fil-A loyalty accounts hijacked using stolen passwordsIf you have a Chick-fil-A One account, now is a good time to change your password—and make sure it's one you don't use anywhere else.MALWAREBYTES.COM
22 JulAdobe Chrome extension flaw let sites access private WhatsApp chatsThe Adobe Acrobat extension for Chrome could be used to access conversations and data rendered in WhatsApp Web without any form of authentication. [...]BLEEPINGCOMPUTER.COM
22 JulTrickBot Ditches HTTP for DNS Tunneling in Latest VariantNew TrickBot variant hides C2 communication inside DNS queries, replacing decade-old HTTP patternINFOSECURITY-MAGAZINE.COM
22 JulNew InfraTrust report reveals infrastructure flaws admins should patch firstEclypsium has launched InfraTrust, a new infrastructure cybersecurity knowledge base and monthly InfraTrust Pulse report designed to help organizations prioritize vulnerabilities affecting infrastructure, firmware, networking, and edge devices. [...]BLEEPINGCOMPUTER.COM
22 JulOpening the Black Box: Agentless Threat Detection for Virtual AppliancesMapping FortiGate event logs to real-world campaigns: A step-by-step researcher’s guide to continuous agentless monitoring.WIZ.IO
22 JulIf you pay a hacker’s ransom, chances are that they’ll come back for moreThe long-held understanding among security researchers and network defenders is that it's impossible to negotiate in good faith with an extortion racket because there's no incentive for the other side to actually walk away.TECHCRUNCH.COM
22 JulOpenAI models escaped containment to hack Hugging Face.SolarWinds patches fifteen critical flaws. Business news: Neo emerges from stealth with $100 million.THECYBERWIRE.COM
22 JulWhen AI Attacks: OpenAI Models Autonomously Hack Hugging FaceAdvanced LLMs escaped their sandboxes while attempting to achieve a non-malicious benchmark test objective.DARKREADING.COM
22 JulRondo Meets Geoserver, (Wed, Jul 22nd)This isn&#;x26;#;39;t a new attack, but something I saw "pop-up" in our logs this week:
ISC.SANS.EDU
22 JulFrench Parliament greenlights social media ban for under-15sBoth houses of the French Parliament voted to block social media access for children under 15, making France the first European country to enact a ban amid a broadening global crackdown.THERECORD.MEDIA
22 JulHow OpenAI’s human mistake led to the AI-powered hack on Hugging FaceOpenAI made a mistake setting up what it called a “highly isolated” testing environment and sandbox. According to cybersecurity experts, that human mistake is what made the AI-powered attack on Hugging Face possible.TECHCRUNCH.COM
22 JulEndpoint security firm Glow emerges from stealth with $180 million.Neo has emerged from stealth with $100 million. Palo Alto Networks has agreed to acquire user-focused observability provider Embrace.THECYBERWIRE.COM
22 JulAI Threat Detection Is Not Enough Without Adversary IntelligenceThe 2026 emergence of Anthropic’s Claude Mythos Preview showed security leaders that AI can now find software vulnerabilities faster than the humans responsible for patching them.INTEL471.COM
21 JulNew Project CAV3RN module abuses Outlook calendar events for C2 and DNS AAAA records for configuration recoveryKaspersky GReAT experts describe a new Project CAV3RN C2 module. It uses Outlook calendar for communication via Microsoft Graph and has a backup connection via DNS AAAA responses.SECURELIST.COM
21 JulAI nudify apps spark legal scrutiny of Apple and Google’s profitsInstead of fighting over what app stores host, the San Francisco City Attorney is targeting how they make money from AI nudify apps.MALWAREBYTES.COM
21 JulDon’t trust that “FBI agent” in your DMsThe FBI is warning that fraudsters are using fake IC3 accounts and direct messages to target people who've already been scammed.MALWAREBYTES.COM
21 JulFBI Warns of Deepfake Videos Impersonating IC3 LeadershipFBI warned of deepfake videos of IC3 leadership directing users to spoofed complaint sitesINFOSECURITY-MAGAZINE.COM
21 JulUS seizes over 1,000 websites in FIFA World Cup piracy crackdownThe U.S. Justice Department has seized more than 1,000 websites and blocked 1,970 domains used to stream FIFA World Cup 2026 matches without authorization. [...]BLEEPINGCOMPUTER.COM
21 JulChoose Wisely: AI-Generated Coding Risk Varies, A LotAI-generated code introduces 15 vulnerabilities on average per codebase, but the actual risk depends on framework pairing more than the model used.DARKREADING.COM
21 Jul300 WINtegrations Strong: An Open Security Ecosystem Built for the Speed of AIAs AI accelerates how organizations build and how attackers operate, a deeply connected security ecosystem is how defenders keep up.WIZ.IO
21 JulAgentless Visibility: Uncovering Cloud Blind SpotsHow Agentless Workload Detection exposes hidden threats in virtual appliances and modern cloud networks.WIZ.IO
21 JulGoogle Launches Gemini 3.5 Flash Cyber AI to Find and Fix Software VulnerabilitiesGoogle's DeepMind on Tuesday announced the release of Gemini 3.5 Flash Cyber, a specialized artificial intelligence (AI) model built atop 3.5 Flash that's designed to discover, validate, and patch vulnerabilities quickly and efficiently. According to the tech giant, the model wil…THEHACKERNEWS.COM
21 JulDo more with AWS WAF labels using dynamic label interpolationAWS WAF classifies web traffic by attaching metadata to each request it evaluates. Managed rule groups such as AWS WAF Bot Control and AWS WAF Fraud Control account takeover prevention (ATP) attach labels that describe what they found. A label can record that a request came from …AWS.AMAZON.COM
21 JulHacker Turns AI Jailbreaks Into Offensive Attack PlatformA Russian-speaking actor, "Trim," dismantled publicly available frontier models and integrated them with offensive security tools.DARKREADING.COM
21 JulDNI nominee Clayton wins Senate panel’s approvalBy a party-line vote, the Senate Intelligence Committee sent the nomination of Jay Clayton to lead ODNI to the Senate floor.THERECORD.MEDIA
21 JulUsing LLMs to Find and Prioritize Vulnerabilities Is No Easy TaskThe latest large language models have high false-positive rates and fail to take into account the context of scans, leading to more work for AppSec professionals.DARKREADING.COM
21 JulPolice dismantle Kratos phishing platform, arrest developerAuthorities in Germany and the U.S. dismantled the central infrastructure of Kratos, a phishing-as-a-service (PhaaS) platform with global reach, and its developer was arrested in Indonesia. [...]BLEEPINGCOMPUTER.COM
20 JulYour attack surface is bigger than you thinkNew data reveals where attack surfaces are hiding the most risk.CYBERSECURITYDIVE.COM
20 JulThe secret problem in AI infrastructure: Why MCP security starts with secretsAI changes how infrastructure is accessed. Here's what to secure.CYBERSECURITYDIVE.COM
20 JulThe ACLU Is Arming Lawyers to Expose State Surveillance SecretsA new toolkit for attorneys in Massachusetts targets the technologies police use—and conceal—to build criminal cases, from facial recognition to AI-written police reports.WIRED.COM
20 JulApps Marketed to US Troops Are Shipping Chinese and Russian CodeA first-of-its-kind analysis found more than one in eight apps built for US service members carried foreign code—some from firms in nations the Pentagon designates as adversaries.WIRED.COM
20 JulPolice Chiefs Cite TfL Hack in Push for Cybercrime Risk OrdersTwo chiefs of UK policing agencies said the Transport for London prosecution demonstrates the need for Cybercrime Risk OrdersINFOSECURITY-MAGAZINE.COM
20 JulMicrosoft confirms Windows Server Update Services sync delaysMicrosoft is working to fix a known issue affecting Windows Server Update Services (WSUS) servers, which has caused synchronization problems for more than a week. [...]BLEEPINGCOMPUTER.COM
20 JulMythos Didn't Break Your Security Program. Your Exposure Window Could.The industry spent the initial months after Anthropic's April 7 Mythos reveal focused on volume. How many new CVEs would Mythos add to an already overloaded pipeline? How quickly would the flood of AI-driven discovery overwhelm triage capabilities? How long would it take adversar…THEHACKERNEWS.COM
20 JulCybersecurity Keeps Events 'Uneventful'From the World Cup to the United States' 250th celebration, this year's event calendar has been packed with high-profile gatherings that drew global audiences, intense scrutiny, and enormous security demands.DARKREADING.COM
20 JulWatch Flock Safety CEO Garrett Langley discuss the future of surveillance at TechCrunch Disrupt 2026Flock Safety sits right at the center of the debate over where the line should be drawn between privacy and public safety. That’s why we’re bringing Flock’s founder and CEO Garrett Langley to the stage to speak about those very issues.TECHCRUNCH.COM
20 JulCruciferra Crypter Uses Process Ghosting to Evade DetectionCruciferra crypter used process ghosting and 90 custom ciphers to hide payloads for multiple actorsINFOSECURITY-MAGAZINE.COM
20 JulAn AI SOC Evaluation Guide for Security LeadersChoosing an AI SOC platform requires understanding how it will perform in your own environment, not just during an evaluation. Prophet Security shares a practical framework for assessing AI SOC solutions, including how to validate accuracy, operating models, long-term reliability…BLEEPINGCOMPUTER.COM
20 Jul2026 ISO and CSA STAR certificates are now available with two additional servicesAmazon Web Services (AWS) successfully completed an onboarding audit with no findings for ISO 9001:2015, 27001:2022, 27017:2015, 27018:2019, 27701:2019, 20000-1:2018, and 22301:2019, and Cloud Security Alliance (CSA) STAR Cloud Controls Matrix (CCM) v4.0. EY Certify Point auditor…AWS.AMAZON.COM
20 JulMore than 1,000 domains illegally streaming World Cup games seized, DOJ saysOver the course of the World Cup tournament, the Department of Justice seized more than 1,000 domains for illegally streaming games.THERECORD.MEDIA
20 JulIndia says allegedly leaked nuclear plant files pose no safety riskDocuments that the World Leaks cybercrime group claimed to leak from the Kudankulam Nuclear Power Plant do not contain information pertaining to safety or security, Indian officials said.THERECORD.MEDIA
20 JulCISOs Feel the Heat Over AI RiskJob pressures have increased as companies run headlong into AI adoption, causing 26% of top security executives to consider leaving their position.DARKREADING.COM
20 JulFlock Safety kills acoustic system designed to detect 'human distress'"Community consultation" is one of the reasons automated license plate reader (ALPR) company Flock Safety cited in its decision to drop voice-oriented tech from a gunshot detection system.THERECORD.MEDIA
20 JulRemediating Vulnerabilities With LLMs: Inside Ivanti's Automation PushIvanti CSO Daniel Spicer says frontier models have shown surprising effectiveness in early stages; but cost and human-in-the-loop viability remain open questions.DARKREADING.COM
20 JulIntroducing the Amazon GuardDuty investigation agent: on-demand AI-powered threat assessmentThe new Amazon GuardDuty investigation agent (now in public preview) investigates security findings across your Amazon Web Services (AWS) environment, reducing investigation time from hours to minutes. GuardDuty is our managed threat detection service that continuously monitors y…AWS.AMAZON.COM
20 JulCursor, Codex, Gemini CLI, Antigravity hit by sandbox escapesResearchers escaped the sandboxes in Cursor, Codex, Gemini CLI and Antigravity by having the AI agent write files that trusted host tools later run. Multiple CVEs, patches, and Google downgrading two Antigravity findings. [...]BLEEPINGCOMPUTER.COM
20 JulHackers steal $23.7 million in crypto from Ostium in off-chain attackThe Ostium trading platform announced that an attacker stole $23.75 million from its liquidity provider vault last week, after compromising off-chain infrastructure used to feed prices into the protocol. [...]BLEEPINGCOMPUTER.COM
18 JulPrompt Injection Attacks Are Thwarting AI Hacking Agents“Context bombing” tricks malicious AI agents into shutting down before they can do harm.WIRED.COM
17 JulUS charges two over laundering $43 million from investment fraudU.S. prosecutors on Thursday charged a New York man and woman for their roles in a large-scale crime ring that laundered money stolen in cyber investment fraud scams. [...]BLEEPINGCOMPUTER.COM
17 JulSan Francisco Demands Apple and Google Delete AI ‘Nudify’ Apps From App StoresThe City Attorney’s Office sent the tech giants cease-and-desist letters this week telling them to stop profiting from 13 “face-swap” apps that are overwhelmingly used to target women and girls.WIRED.COM
17 JulE.U. Orders Google to Open Android Mic, Camera and Screen to Rival AI AssistantsThe European Commission on Thursday ordered Google to give rival AI assistants the same reach into Android that Gemini already has: the camera, the microphone, whatever is on screen, a wake word that fires with the display off, and the ability to drive other apps in the backgroun…THEHACKERNEWS.COM
17 JulGoogle Bets 'Agentic Defense' Strategy Can Outpace AttackersGoogle Cloud incorporates key Wiz capabilities into an agentic defense platform to automate threat detection and remediation against AI attacks.DARKREADING.COM
17 JulInside the Search for "Clean" Residential Proxies for CardingResidential proxies are no longer the silver bullet they once were for carding. Flare explains why cybercriminals increasingly seek "clean" residential proxies and combine them with browser fingerprints, device profiles, and other identity signals to evade modern fraud detection.…BLEEPINGCOMPUTER.COM
17 JulAmazon fixing bug that billed some AWS customers billions of dollarsSome Amazon customers logged on Friday to a surprise bill estimate claiming that they owed the tech and cloud giant billions in fees.TECHCRUNCH.COM
17 JulThe Real AI Threat Is Blind TrustAI models left to both interpret and execute commands eliminate critical cybersecurity oversight.DARKREADING.COM
17 JulThe Zoom hack that says, ‘Don’t record me’If every meeting, watercooler conversation, and date gets transcribed and summarized, who's actually reading any of it?TECHCRUNCH.COM
17 JulGoogle’s Gemini lets strangers send messages from your locked Android phoneGemini, Google's AI assistant, is supposed to make life easier for Android smartphone owners. But right now it may also be making life easier for anyone anyone who happens to pick up your phone. Read more in my article on the Hot for Security blog.BITDEFENDER.COM
16 JulThe future of transatlantic data sharing.This week, Dave and Ben look at how the Supreme Court's recent decision could impact data-sharing efforts with the European Union (EU). Additionally, they discuss how the LA Police Department has let its contract with Flock expire after reports emerged that the company was found …THECYBERWIRE.COM
16 JulSamsung backs down on threat to delete health dataSamsung threatened to delete users' health data if they refused AI training. After a backlash, it quickly backed down.MALWAREBYTES.COM
16 JulSANS Warns of AI Governance Gap as Use by Security Teams SurgesSANS Institute says governance programs are still nascent even as AI failures and threats growINFOSECURITY-MAGAZINE.COM
16 JulAI Can Find Bugs, But Human Knowledge Still Proves ThemArtificial intelligence (AI) is changing offensive security, but it has not changed the standard that matters most: a finding has to be proven before it becomes useful. AI-assisted tools can read code quickly, generate payloads, summarize attack surfaces, explain unfamiliar APIs,…THEHACKERNEWS.COM
16 JulThe Hunter's Paradox: Is it time to embrace automated threat hunting?Humans can no longer keep up with the volume and velocity of security data on their own, but AI can't be fully trusted. David discusses the merits of both and muses on what the future might look like.TALOSINTELLIGENCE.COM
16 JulUAT-11795 deploys novel Starland RAT and bespoke WLDR C2 implant in financially motivated campaignCisco Talos is disclosing UAT-11795, a sophisticated, Russian-speaking, financially motivated adversary that has been conducting a malicious campaign targeting users in the U.S. and Europe since at least June 2025.TALOSINTELLIGENCE.COM
16 Jul‘Selfish Bravado’ Behind TfL Cyber-Attack, Judge Says as Pair JailedThe perpetrators of the 2024 TfL cyber-attack have been jailed for five and a half years each after pleading guilty to Computer Misuse Act offencesINFOSECURITY-MAGAZINE.COM
16 JulWindows 11 24H2 Home and Pro reach end of support in 90 daysMicrosoft announced on Wednesday that systems running Windows 10 Enterprise LTSB 2016 and Home and Pro editions of Windows 11 24H2 will stop receiving updates in three months. [...]BLEEPINGCOMPUTER.COM
16 JulNew Agent Data Injection Attack Can Make AI Agents Misclick or Run Attacker CommandsAsk an AI agent to summarize the reviews on a product page, and a single planted review can make it click "Buy Now" instead. Ask a coding assistant to apply a maintainer's fix from a GitHub thread, and a fake comment can make it run a stranger's command on your computer. Neither …THEHACKERNEWS.COM
16 JulScattered Spider members behind TfL hack get five years in prisonTwo leading members of the Scattered Spider cybercrime collective were sentenced to five years and six months in prison each for hacking Transport for London (TfL) in 2024. [...]BLEEPINGCOMPUTER.COM
16 JulSingle Prompt Enables ChatGPT to Execute Full Cyber-Attack Chain, Researchers ClaimCybersecurity researchers tested Open AI GPT 5.5’s offensive cyber capabilities – and the results showed how effective a frontier LLM can be for hackersINFOSECURITY-MAGAZINE.COM
16 Juln8n Token Exchange Flaw Could Let Attackers Log In as Users From Another Issuern8n, the workflow automation platform, handed out the wrong accounts at login. On Enterprise instances configured to trust more than one external token issuer, it matched an incoming JWT to a local user on the sub claim alone and ignored iss. A valid token from iss…THEHACKERNEWS.COM
16 JulHow a former DeepMind researcher raised at a $300M pre-seed valuation before launching a productDrawing on more than a decade spent helping build some of the world's most influential AI systems, including research that later informed the development of ChatGPT, Andrew Dai explains why he believes visual AI is one of the next major frontiers in artificial intelligence.TECHCRUNCH.COM
16 JulThe backlash against Flock cameras is spreadingPrivacy concerns have dogged Flock's automated license plate recognition system for years. Now accuracy and reliability are coming under scrutiny too.MALWAREBYTES.COM
16 JulHelloNet campaign — new malicious modules launched through the ViPNet update systemWe identified targeted infection attempts against large Russian organizations using the ViPNet update system (a software suite for creating secure networks).SECURELIST.COM
16 JulAI Agents Broke the Security Playbook. Here's What Replaces It.Traditional security workflows were built for environments that changed at human speed. Token Security explains why AI agents require a new approach: building on a live identity foundation while giving security teams the flexibility to create workflows tailored to their own envir…BLEEPINGCOMPUTER.COM
16 JulUK cops say arrest of two young hackers disrupted the operations of an infamous hacking groupOwen Flowers and Thalha Jubair, two members of the prolific Scattered Spider hacking group, pleaded guilty and were sentenced to five years and six months in jail for hacking London’s metropolitan transit system.TECHCRUNCH.COM
16 JulUK investigates TikTok for alleged age-verification lapses, exposing kids to online harms“Age checks are a cornerstone of the UK’s online safety laws,” said Ofcom’s Chief Executive, Melanie Dawes. “Too many services have no or inadequate age checks in place, which is not good enough.”THERECORD.MEDIA
16 JulBegun, the Patch Wars haveLong foretold, the Great Patching has begun and it’s a doozy. Buckle in as Joe takes you through the story.TALOSINTELLIGENCE.COM
16 JulEU tells Meta to make major changes to its social media platforms.Pentagon suspends CMMC program.THECYBERWIRE.COM
16 JulNew OkoBot framework deploys 20 payloads to steal data, cryptoA new malicious framework called OkoBot is delivering more than 20 payloads in attacks focused on stealing cryptocurrency wallet seed phrases, credentials, and other sensitive data. [...]BLEEPINGCOMPUTER.COM
16 Jul1M+ Emails Use Hidden Text to Dupe AI Security FiltersArtificial intelligence and LLMs can be surprisingly ineffective against text salting, allowing phishing emails to slide right into your inbox.DARKREADING.COM
16 JulAgentic AI Is Untamable: Ask the Right Security QuestionsForget about attackers. Agentic artificial intelligence is creating enough risks for organizations and demands a security reframe.DARKREADING.COM
15 JulWeekly Threat Bulletin – July 15th, 2026These are the top threats you should know about this week.F5.COM
15 JulHow Absolute Security CMO Ash Parikh Thinks About Marketing, Pipeline, and Working with the BoardMost CMOs come up through marketing. Ash Parikh came up through engineering and sales, and he thinks that is exactly why he does the job differently. He joins Gianna and Charles on CyberCMO Confidential as the CMO of Absolute Security to talk about what 25 years of carrying a bag…THECYBERWIRE.COM
15 JulThis fake Apple app can unlock your Mac’s password vaultDisguised as Apple's CrashReporter, CrashStealer steals passwords, browser data, crypto wallets, and other sensitive information.MALWAREBYTES.COM
15 JulGovernment Updates UK’s National Risk Register with Cyber WarningsThe UK government is warning of the potential impact of catastrophic cyber-attacksINFOSECURITY-MAGAZINE.COM
15 JulSASE Has An AI Blind Spot. Inspecting Packets Is No Longer Enough.For years, routing traffic through cloud proxies was good enough. Then work moved to the browser, AI entered the workflow, and the inspection model stopped keeping up. Enterprise workflows now live across SaaS applications, browsers, and an expanding ecosystem of generative AI to…THEHACKERNEWS.COM
15 JulNew Webinar: Closing the Approval Gap in AI-Era Ad TechA single approved marketing tag can quietly load fourth-party code your security team has never seen, granting full access to your forms, customer data, and checkout pages. This on-demand webinar reveals how this Approval Gap forms, and gives your team the blueprint to close it b…THEHACKERNEWS.COM
15 JulLAPD sidelines relationship with license-plate reader company Flock SafetyThe Los Angeles Police Department is the latest U.S. municipal agency to rethink its relationship to ALPR company Flock Safety.THERECORD.MEDIA
15 JulEleven Vulnerable UEFI Shims Enable Secure Boot BypassEleven forgotten Microsoft-signed UEFI shims can bypass Secure Boot on almost any machineINFOSECURITY-MAGAZINE.COM
15 JulDutch police dismantle global crypto investment scam, arrest alleged mastermindAuthorities said Wednesday that the group operated like a legitimate international business since at least 2021, running about two dozen call centers across several countries and employing more than 700 people who posed as professional financial advisers.THERECORD.MEDIA
15 JulPhishing Campaign Abuses eCards to Deploy RMM ToolsSix-month phishing campaign used seasonal eCard lures to plant legitimate RMM tools on victimsINFOSECURITY-MAGAZINE.COM
15 JulThe Red Agent POV: The One Boolean That Broke a B2B Platform’s Credit SystemPart 3: How the Red Agent bypassed a credit and paywall system by changing a single client-side value from false to true.WIZ.IO
15 JulTrump’s DNI pick grilled about election security, voter fraudSenators pressed director of national intelligence nominee Jay Clayton about his stance on the 2020 election and previous statements about voter fraud. Other issues took a back seat.THERECORD.MEDIA
15 JulIs 'Tech-xit' Imminent? UK Steps Up Sovereignty Push Amid AI StrifeThe US government's restrictions on Anthropic and OpenAI frontier models have intensified calls in the UK and other countries to reduce their reliance on US tech companies, with significant cyber implications.DARKREADING.COM
15 JulIsraeli identity management startup Oak emerges from stealth with $60 million in seed funding.Barracuda Networks has acquired Austin, Texas-based identity and access management provider Evo Security.THECYBERWIRE.COM
15 JulHere’s the Truth About Whether Meta’s NameTag Face Recognition Tech ‘Exists’Since WIRED reported on Meta’s NameTag face recognition system, company executives have made confusing and conflicting remarks about its very existence.WIRED.COM
15 JulOperation Fake KickOff: Attackers Abuse Recruiters and SaaS to Harvest Work CredentialsIntel 471 investigated an ongoing, multi-stage phishing operation that systematically abuses legitimate software-as-a-service (SaaS) sales and marketing, and cloud platforms to orchestrate corporate credential theft.INTEL471.COM
15 JulCIS Benchmarks July 2026 UpdateThese CIS Benchmarks and CIS Build Kits have been updated or recently released and include a full changelog that references all changes.CISECURITY.ORG
15 JulDutch police bust investment fraud ring stealing over €100 millionThe Dutch Police announced the arrest of multiple individuals suspected of being part of an international investment fraud scheme estimated to have tens of thousands of victims. [...]BLEEPINGCOMPUTER.COM
15 JulForgotten Bootloaders Expose Secure Boot Blind SpotNearly a dozen vulnerable and now revoked UEFI shim bootloaders remained trusted for years, giving attackers a path to bypass Secure Boot.DARKREADING.COM
14 JulFive Charged in “Russian Coms” Fraud Platform CaseFive UK residents have been charged in relation to supplying Russian Coms fraud devices and appsINFOSECURITY-MAGAZINE.COM
14 JulMicrosoft starts testing cleaner Windows Search without adsMicrosoft is now testing a cleaner and faster version of Windows Search that should prioritize relevant results over ads and promotional content. [...]BLEEPINGCOMPUTER.COM
14 JulMicrosoft Entra ID gets passkeys default authentication starting SeptemberMicrosoft has announced that passkeys will become the default authentication method for the Entra ID enterprise identity service starting September 2026. [...]BLEEPINGCOMPUTER.COM
14 JulNew phishing kits target Microsoft 365 accounts, evade MFATwo new phishing kits, Jalisco and OmegaLord, have been discovered in attacks targeting Microsoft 365 accounts, using techniques that defeat multi-factor authentication (MFA). [...]BLEEPINGCOMPUTER.COM
14 JulStudy of 85 Crypto Wallet Extensions Finds Address Leaks and Cross-Site Tracking RisksResearchers at KU Leuven tested 85 of the most popular crypto wallets that run as browser extensions and found that the wallets themselves leak enough to link and track the people using them. The way these wallets talk to websites and blockchain servers can tie a person's separat…THEHACKERNEWS.COM
14 JulTelegram’s shortlink domain is back online after day-long suspensionTelegram CEO Pavel Durov confirmed an outage in a tweet, saying that shortlinks to the messaging app had "stopped working."TECHCRUNCH.COM
14 JulAuthenticate legitimate AI agent traffic with AWS WAF Bot ControlAs AI agents and automated tools increasingly access web applications, distinguishing legitimate bot traffic from malicious attempts has become a critical security challenge. Traditional approaches such as IP-based filtering and reverse DNS lookups fail in multi-tenant systems (s…AWS.AMAZON.COM
14 JulUS: Pentagon Suspends CMMC Phase II Requirements for Defense ContractorsThe US Department of Defense announced the immediate suspension of the CMMC Phase II requirements until further reviewINFOSECURITY-MAGAZINE.COM
14 JulLastPass, Bitwarden users targeted with fake security alertsLastPass is warning users about an ongoing phishing campaign that is using fake security notices to direct them to fraudulent websites. [...]BLEEPINGCOMPUTER.COM
14 JulFrontier AI: The Genie's Out of the Bottle, But Where's the Rulebook?Cutting-edge artificial intelligence models are deploying with more independence and less human oversight. Several state governments are trying to legislate transparency in their use.DARKREADING.COM
14 JulWindows 11 KB5101650 & KB5099414 cumulative updates releasedMicrosoft has released Windows 11 KB5101650 and KB5099414 cumulative updates for versions 25H2/24H2 and 23H2 to fix security vulnerabilities, bugs, and add new features. [...]BLEEPINGCOMPUTER.COM
14 JulManage Vendor Risk in a Few Practical StepsRisk tolerance, exposure visibility, board oversight — handling third-party risk is complicated but achievable with disciplined, precise governance.DARKREADING.COM
14 JulResearchers Say Claude for Chrome Flaw Lets Rogue Extensions Trigger Gmail ReadsAny other browser extension that can run a script on claude.ai can still trigger Claude for Chrome tasks aimed at your Gmail, your latest Google Doc and its comments, and your Calendar. Both this and ClaudeBleed need a rogue extension that can already run a script on claude.ai; t…THEHACKERNEWS.COM
14 JulSecurity Hub adds AI workload protection and multicloud support for Microsoft AzureSecurity Hub is our foundation for full-stack enterprise security across clouds. It centralizes your security operations and turns raw signals into prioritized insights, so your team spends its time managing real risk instead of stitching tools together. Today that foundation gro…AWS.AMAZON.COM
14 JulUS unseals indictment against alleged operators of Russian bulletproof hosting serviceThe Russians face multiple charges for allegedly providing cybercriminals with infrastructure and tech support through the St. Petersburg-based business Media Land and a sister company, ML Cloud.THERECORD.MEDIA
14 JulSpanish Police take down €140 million cyber fraud ring, arrest fourThe Spanish Police dismantled a cybercrime and money-laundering organization that made €140 million ($160 million) from investment fraud and business email compromise (BEC) attacks. [...]BLEEPINGCOMPUTER.COM
14 Jul6 GHz Wi-Fi Flaws Could Disrupt Critical SystemsAutomated Frequency Coordination systems by default trust client-side data, which could lead to location spoofing and other attacks that disrupt traffic.DARKREADING.COM
13 JulSomeone Is Scanning for Your MCP Servers and AI Assistant Credentials, (Mon, Jul 13th)The setup
ISC.SANS.EDU
13 JulMisconfigured Server Reveals Three Evilginx Phishing Operations Targeting Microsoft 365An attacker running a live Microsoft 365 phishing operation left a Python web server listening on a public port with directory listing switched on. The command that did it: python3 -m http.server 8080, was still sitting in the readable .bash_history. From that one lapse…THEHACKERNEWS.COM
13 JulA Leak of San Francisco Police Drone Footage Exposes the New Reality of Urban SurveillanceThe SFPD’s exposure of hours of videos from drone platform Skydio reveals how broadly it’s watching the city from above—and how the results can spill online.WIRED.COM
13 JulFake crypto gift card sites are getting harder to spotScam crypto gift card stores look almost identical to the real thing. One wrong click can leave you with no card and no way to get your money back.MALWAREBYTES.COM
13 JulProgress Software Warns of "External Security Threat" to ShareFileProgress Software, the provider of the popular file-sharing and data storage solutions, has urged customers to shut down the server hosting their Storage Zone ControllerINFOSECURITY-MAGAZINE.COM
13 JulMeta Files Patent for AI That Can Listen All Day and Track How You're FeelingMeta has filed a patent application for an AI that listens to your voice throughout the day, works out how it thinks you are feeling from the way you sound, and keeps a timestamped log of every read. Each read gets pinned to the moment it happened: the time, your location, what y…THEHACKERNEWS.COM
13 JulThinking Fast and Slow in the SOC: The Case for Combining Autonomous AI with Analyst CopilotsA few days ago, I was sitting with the CISO of a Fortune 50 company, walking through how his security team was thinking about AI agents in the SOC. Smart team. Serious program. They had already connected Claude to a few detection tools and were seeing real value in specific inves…THEHACKERNEWS.COM
13 JulNovel OAuth Client ID Spoofing Technique Targets Cloud EnvironmentsNew research reveals cyber-attackers can spoof OAuth Client IDs in Microsoft Entra ID, creating a stealthy path into cloud environmentsINFOSECURITY-MAGAZINE.COM
13 JulIntroducing Precursor: detecting agentic behavior with continuous client-side signalsPrecursor, our new continuous behavioral validation engine for bot management, offers visibility into how humans and bots actually interact across the full user journey. By turning session-level behavior into bot detection signals, it identifies advanced automation with higher pr…CLOUDFLARE.COM
13 JulUK charges suspects linked to Russian Coms call spoofing platformUK authorities charged five people following a National Crime Agency (NCA) investigation into Russian Coms, a major caller ID spoofing platform used by criminals to make over 1.8 million scam calls. [...]BLEEPINGCOMPUTER.COM
13 JulLAPD lets contract with surveillance giant Flock expire, citing ‘serious concerns’ over civil liberties and privacyThe LAPD, one of Flock's biggest government customers, is ending its contract with the company citing civil liberties concerns.TECHCRUNCH.COM
13 JulWhy IaC Coverage Belongs on Your Security DashboardRethinking IaC coverage as a funnel that shows how much of your infrastructure is governed, traceable, and ready for remediation at speedWIZ.IO
13 JulTurning Secure Software Development into a Measurable PracticeCIS and SAFECode have updated Secure by Design: A Developer’s Guide to Building Safer Software to address the role of AI on software security.CISECURITY.ORG
13 JulNew MemGhost Attack Plants Persistent False Memories in AI Agents Through One EmailGive an AI assistant a memory and access to your inbox, and you hand an attacker a way to rewrite what it thinks it knows about you. A single email can trick that agent into saving a false "fact" about the user, hide the change, and quietly steer its answers in later sessions. Wh…THEHACKERNEWS.COM
13 JulOpen Directory Exposes Three Evilginx Phishing OperatorsMisconfigured server exposed three phishing operators running Evilginx forks to bypass MFAINFOSECURITY-MAGAZINE.COM
13 JulJoint guidance on improving router hygiene to protect against Russian state-sponsored targetingCYBER.GC.CA
13 JulGoogle and Microsoft Pull ModHeader With 1.6 Million Installs After Dormant Collector FoundGoogle and Microsoft have pulled ModHeader, a popular header-editing extension with roughly 1.6 million installs across Chrome and Edge, after researchers found a hidden browsing-history collector built into its official store version. The collector was dormant. An empty allow-li…THEHACKERNEWS.COM
13 JulGuidance on securely configuring authorization and authentication frameworks - ITSP.40.063CYBER.GC.CA
13 Jul'Yellow Teams' Are Defining the Future of AI SecurityIn some companies, engineers are building defense and attack tools to test the potential of artificial intelligence for cybersecurity — and its threat.DARKREADING.COM
13 JulEU leaders eye social media ban for children under age 13“While ultimately it is up to parents to decide when children get their first smartphones, what we already have is a consensus that there needs to be a start date for the age children can join social media,” says European Commission President Ursula van der Leyen.THERECORD.MEDIA
12 JulProgress Told ShareFile Customers to Pull the Plug on Their Servers. Here’s What We Know.Progress urged ShareFile Storage Zone customers to shut down internet-facing servers immediately over a credible security threat under investigation. Progress Software sent an urgent email to ShareFile customers the evening of July 10 with a subject line that left no room for amb…SECURITYAFFAIRS.COM
12 JulClaude Fable 5 stays free for paid users until July 19 as Anthropic buys more timeAnthropic has just extended access to Claude Fable 5 for paid subscribers until July 19, giving you another week to keep using the most powerful model. [...]BLEEPINGCOMPUTER.COM
12 JulOpenAI temporarily relaxes GPT-5.6 Sol usage limitsOpenAI is temporarily relaxing GPT-5.6 Sol usage after demand for the company's most powerful model surged over the past 48 hours. [...]BLEEPINGCOMPUTER.COM
11 Jul'Ghostcommit' hides prompt injection in images to fool AI agents, steal secretsA PNG hiding a prompt injection could steal your repo's secrets, researchers demonstrate. The technique, dubbed 'Ghostcommit,' slipped past AI code reviewers CodeRabbit and Bugbot, which never open image files at all, then convinced a coding agent to read a repo's .env and write …BLEEPINGCOMPUTER.COM
11 JulAI Found a Root Bug in Linux That Everyone Missed for 15 YearsPlus: The Pentagon is training amateurs to become part of its hacker army, a Flock license plate reader error led to cops surrounding a car reviewer, and more.WIRED.COM
10 Jul"Comment stuffing" in an HTML phishing attachment as a mechanism for evading AI-based detection?, (Fri, Jul 10th)Anyone who deals with phishing messages caught by basic security filters knows that most phishing samples tend to blend into one another, since only a small set of techniques and approaches keeps reappearing in them. That is precisely why it is worth pausing on the occasional mes…ISC.SANS.EDU
10 JulTwo Chrome updates in two days fix critical vulnerabilitiesChrome updates are arriving within days of each other. Learn how to update Chrome and check if you're running the latest version.MALWAREBYTES.COM
10 JulHow mule betting scams recruit ordinary peopleEasy-money offers to open a gambling account could make you part of a money laundering operation. Here's how to spot a mule betting scam.MALWAREBYTES.COM
10 JulAI Coding: Do Security Risks Outweigh Productivity Gains?AI coding tools cost $19-$200/month/user, but security scanning, remediation, and false positives add hidden costs. Are the productivity gains worth it?DARKREADING.COM
10 JulThe Replicant in Your Directory: AI Agents and the Identity Security GapAI agents are accelerating the growth of non-human identities, making it harder for organizations to understand what exists, who owns it, and what it can access. Netwrix explains why stronger visibility and identity governance are essential as AI expands the enterprise attack sur…BLEEPINGCOMPUTER.COM
10 JulFresh ATM Crypto Software Bugs: Jackpot or Bust?Organizations, and possibly ATMs, are at risk of compromise, thanks to holes in a Microsoft BitLocker security wrapper.DARKREADING.COM
10 JulLaser Attack Resets Tangem Wallet Passwords on Cards That Can't Be PatchedResearchers at Ledger's Donjon security team have shown that a precisely timed laser pulse, aimed at the chip inside a Tangem crypto wallet card, can reset the card's password to anything the attacker picks. No old password. No backup card. Once it is reset, whoever did…THEHACKERNEWS.COM
10 JulMoney launderer accused of stealing seized crypto while in prisonA Bulgarian national has been charged with stealing $290,000 in government-seized cryptocurrency while serving 121 months in prison for helping launder millions stolen from American fraud victims. [...]BLEEPINGCOMPUTER.COM
10 JulLicense plate cameras may be next target after Supreme Court reins in location trackingIf a warrant is ultimately needed for ALPR searches, experts say, it would radically limit how the networks of cameras can be used and would change modern policing.THERECORD.MEDIA
10 JulProgress urges ShareFile admins to shut down servers over “credible” threatProgress Software is emailing ShareFile customers who use Storage Zone Controllers to immediately shut down their servers after identifying what it describes as a "credible external security threat" targeting the on-premises secure file-sharing software. [...]BLEEPINGCOMPUTER.COM
10 JulSix New U-Boot Flaws Could Let Malicious Images Crash Devices or Run Code at BootResearchers at firmware security firm Binarly have found six new flaws in U-Boot, the small program that starts up hardware as varied as home routers, smart cameras, and the management chips inside data-center servers. Four of the bugs can crash a device. The other two …THEHACKERNEWS.COM
10 JulURGENT - Progress Tells ShareFile Customers to Shut Down Storage Zone Controllers Over Security ThreatProgress Software has told ShareFile customers to shut down the Windows servers running their Storage Zone Controllers, confirming to The Hacker News that it is responding to a "credible external security threat." The company has temporarily disabled access to the affected accoun…THEHACKERNEWS.COM
10 JulEurope revives law allowing big tech to scan for CSAMThe law known as Chat Control 2.0 passed in the European Parliament, permitting companies like Google, Meta and Microsoft to scan users' messages to hunt for CSAM.THERECORD.MEDIA
10 JulJen Ellis: Connecting Cyber Community With Political MachineryOn the heels of her recent honors as a Member of the Order of the British Empire (MBE), we take a look back at the events that shaped Ellis' advocacy on behalf of security researchers.DARKREADING.COM
9 JulGhostApproval Symlink Flaws Could Let Malicious Repos Run Code in AI Coding AgentsResearchers at Wiz found that a flaw in six popular AI coding assistants lets a booby-trapped code project quietly take control of a developer's computer. The assistant asks permission to edit one harmless-looking file, but the write lands on a sensitive one instead. Th…THEHACKERNEWS.COM
9 JulMeta's New AI Image Tool Lets Others Use Your Public Instagram Photos in AI ImagesMeta has announced that its new artificial intelligence (AI) model Muse Image lets people use public Instagram posts and reels to generate AI content, and it's enabled by default. "You can also @-mention Instagram accounts in the Meta AI app to bring specific Instagram profiles r…THEHACKERNEWS.COM
9 JulTurn off this Meta setting before someone generates AI images of youMeta's new Muse Image tool lets anyone generate AI images of you from your public Insta profile. You won't be notified, and it's on by default.MALWAREBYTES.COM
9 JulMadison Square Garden Kept a List of Gay CelebritiesAn MSG database tracked and categorized hundreds of celebs, famous Knicks superfans, and even some of Taylor Swift’s wedding guests. Labels included “LGBTQIA,” “DO NOT HOST,” and low to high “risk.”WIRED.COM
9 JulNew AI Security Charter Backed by Over 70 Cyber FirmsOver 70 cybersecurity organizations have signed the CREST AI Charter detailing responsible use of AI for securityINFOSECURITY-MAGAZINE.COM
9 JulGhostApproval Flaw Hits Six Major AI Coding AssistantsWiz discovered GhostApproval, a symlink flaw in six major AI coding assistants that bypasses approvalINFOSECURITY-MAGAZINE.COM
9 JulMicrosoft to retire the OWA Light client in Exchange ServerMicrosoft has announced plans to disable Outlook Web Access (OWA) Light, the lightweight version of the Outlook Web App email client, in a future Exchange Server update. [...]BLEEPINGCOMPUTER.COM
9 JulSummer of ClearinghousesEveryone seems to have announced a clearinghouse over the past few weeks. We did too. Ours is called Athena, and the main thing that sets it apart is that it was already real and running when we announced it — built quietly months earlier, heads down, taking findings and shipping…THEHACKERNEWS.COM
9 JulChinese-Funded Interpol Cybercrime Crackdown Leads to 5,800 ArrestsOperation First Light 2026, coordinated by Interpol and funded by the Chinese government, has led to 5,811 arrestsINFOSECURITY-MAGAZINE.COM
9 JulAI Attacks Move in Minutes. Join This Webinar on Building a Defense That Keeps UpAI has changed how fast attacks move. Work that once took an attacker days now takes minutes. Using models like Mythos, attackers write tailored bait, pick targets, test what lands, and jump to the next host before your team clears the first alert. That is the gap, and it is not …THEHACKERNEWS.COM
9 JulInvited to a “job interview” with Netflix or OpenAI? Beware! Your Google password could be at riskHave you received an email from a recruiter at Adobe, Netflix, or OpenAI offering you an exciting new marketing role? Well, before you start brushing up your interview technique, take a closer look at who is really behind it. Read more in my article on the Hot for Security blog.BITDEFENDER.COM
9 JulNSA revives 'Tailored Access Operations' name for elite hacking unitNSA last week changed the moniker of its Office of Computer Network Operations (CNO) back to Tailored Access Operations (TAO), a name that is sure to elicit nostalgia among the broader digital community for a group with roots in the early 1990s.THERECORD.MEDIA
9 JulA Majority of European Lawmakers Voted Against Letting Big Tech Read Our Messages. They’re Going to Anyway.Companies will once again be allowed to scan citizens’ personal texts, emails, and social media messages via the “chat control” bill to find child abuse material online.WIRED.COM
9 JulNew Forg365 phishing platform uses AI to target Microsoft 365 accountsA new phishing-as-a-service (PhaaS) operation called Forg365 focuses on stealing Microsoft 365 accounts by combining adversary-in-the-middle (AiTM) and device code methods with AI-assisted lure generation. [...]BLEEPINGCOMPUTER.COM
9 JulThe Hidden Security Risks of Reduced Summer IT CoverageSecurity operations don't slow down when IT teams take vacation, but staffing levels often do. Kaseya explains how AI-driven automation can help organizations maintain consistent security operations and reduce reliance on manual processes year-round. [...]BLEEPINGCOMPUTER.COM
9 JulAs Global Conflicts Go Digital, Businesses Need Wartime GameplansThe fate of a Ukrainian tax software company shows how modern cyberwarfare can claim casualties far beyond the battlefield, and how businesses across the ocean still need to protect themselves.DARKREADING.COM
9 JulHow World Cup crypto prediction sites take your moneyCrypto prediction games promise easy wins, but some are little more than token sales or outright scams. Here's what to look for.MALWAREBYTES.COM
9 Jul6.9 million driver’s license numbers stolen from AssuranceAmericaMillions of AssuranceAmerica customers are being notified after attackers accessed driver's license numbers and other personal information.MALWAREBYTES.COM
9 JulThe SQL Server Unicode problem: why your data might not be what you think it is?Having examined Unicode handling in other databases, we will see that its implementation in SQL Server proves to be particularly complex. We will discover how the burden of backwards compatibility has given rise to new features which, in reality, have serious shortcomings.SYNACKTIV.COM
9 JulWhat About the Role of AI? Updated Guidance on Secure by DesignCIS and SAFECode have updated Secure by Design: A Developer’s Guide to Building Safer Software to address the role of AI on software security.CISECURITY.ORG
9 Jul5 Major Emerging Risks to Large-Scale EventsTo create safer, more secure large-scale events, read our recommendations for defending against five emerging risks to public gatherings.CISECURITY.ORG
9 JulWinning 54% of the timeWith Wimbledon's help, Hazel argues against the popular myth that "Attackers only need to be right once, but defenders need to be right 100% of the time."TALOSINTELLIGENCE.COM
9 JulThe Supreme Court allows Texas age-verification law.European Central Bank warns of AI risks.THECYBERWIRE.COM
9 JulReduce Human Risk | Build a Strong Security Awareness Training Program | HuntressBuild a security awareness training program that actually changes user behavior. Huntress Managed SAT delivers engaging content, phishing sims, and results.HUNTRESS.COM
9 JulAI Agents Are a New Kind of Identity & Most Organizations Aren't ReadyIf you're handling them like a service account or API token, consider yourself behind. AI agents need a fundamentally different approach.DARKREADING.COM
9 JulOpenMandriva Linux says contributor tried to sabotage the projectThe OpenMandriva Linux project announced that it was the target of an attempted act of internal sabotage after a dispute among contributors. [...]BLEEPINGCOMPUTER.COM
9 JulIntroducing OAuth Support for AWS MCP ServerAWS MCP Server using the same credentials and sign-in methods that you already use for connecting to the AWS Management Console or AWS Command Line Interface (AWS CLI) through a familiar browser-based experience powered by industry-standard OAuth. This new sign-in path supports A…AWS.AMAZON.COM
8 JulWeekly Threat Bulletin – July 8th, 2026These are the top threats you should know about this week.F5.COM
8 JulClickFix to Cash-Out: Anatomy of a Mexican Banking-Fraud ToolkitElastic Security Labs tracks REF6045, an active operator-assisted banking fraud operation targeting customers of Mexican banks, fintech, payment processors, and cryptocurrency exchanges.ELASTIC.CO
8 JulAI Readiness, Microsoft MISA, and the Punk Rock Museum with JP Bourget of Blue CycleJP Bourget sold a SOAR company, named his next one after cycling and blue teaming, got Fat Mike from NOFX to show up at his RSAC event, then took him to DEFCON, where he ended up in a DJ booth at Caesars Palace with Steve Aoki. Somewhere in between all of that, he built Blue Cycl…THECYBERWIRE.COM
8 JulMy Stack Simulator, (Wed, Jul 8th)The stack is a memory region where a program stores temporary data -&#;x26;#;xc2;&#;x26;#;xa0;like local variables and return addresses. Think of the stack as a pile of plates in your kitchen: you can only add a new plate to…ISC.SANS.EDU
8 JulState IDs for AI Agents: Will Estonia Set a Precedent?The world's digital testing ground plans to help people use AI agents for government purposes.DARKREADING.COM
8 JulDuckDuckGo browser now blocks YouTube video adsDuckDuckGo announced that its browser can now block most video ads on YouTube, including those shown before the video starts playing and during playback. [...]BLEEPINGCOMPUTER.COM
8 JulGitHub 'Verified' Commits Can Be Rewritten Into New Hashes Without Breaking SignaturesNew research shows that a signed Git commit's hash is not the one-of-a-kind name that much of the software world assumes it to be. Given any signed commit, someone without the signing key can mint a second commit with the same files, author, and date, and a valid signature, GitHu…THEHACKERNEWS.COM
8 JulThe Verification Step Is the New ATO Battleground in 2026For years, account takeover (ATO) followed a predictable script. Attackers bought stolen credentials in bulk, ran them through automated tools, and waited for matches. Credential stuffing was cheap, scalable, and for defenders, relatively well understood. That era is ending. Not …THEHACKERNEWS.COM
8 JulGitHub Copilot Refuses Harmful Requests in Chat, Then Writes Them in CodeAn AI coding assistant that refuses to answer a dangerous request in its chat box can answer it anyway if the same request is broken into small, ordinary-looking steps inside a code editor. That is the finding of a new study of GitHub Copilot by researchers Abhishek Kum…THEHACKERNEWS.COM
8 JulYour next car could be watching your faceDriver-monitoring technology is becoming mandatory in new cars, but privacy experts warn it could create new risks alongside the safety benefits.MALWAREBYTES.COM
8 JulSpain arrests alleged supporter of pro-Russian hacktivist groups after FBI tipAn FBI tip linked a man living in Spain to the hacking groups CyberArmy of Russia Reborn (CARR), Z-Pentest and NoName057(16).THERECORD.MEDIA
8 JulEU unveils cyber plan to reduce reliance on foreign AI systemsThe communication, adopted in Strasbourg on July 7, is built around three pillars: making frontier AI “safe, accessible and deployable” for European cybersecurity, preparing the EU’s cyber ecosystem and scaling European AI capabilities.THERECORD.MEDIA
8 Jul3 Ways AI Powers Service Desk Attacks and How to Prevent ThemSpecops Software explains how AI is making service desk impersonation attacks more convincing, personalized, and scalable, along with practical steps organizations can take to strengthen onboarding and identity verification. [...]BLEEPINGCOMPUTER.COM
8 JulWiz ASM for any environment, any risk, everywhereProtect the modern attack surface with new auto-reconnaissance capabilities, deep internal context, and the Red Agent to find any risk, anywhere.WIZ.IO
8 JulNew Ghost Phishing Wave Is Breaking Traditional Email SecurityA recent EvilTokens campaign targeting businesses across the US and Europe is exposing a new email security blind spot. This “ghost phishing” technique keeps the malicious page hidden until it decrypts and comes to life inside the victim’s browser. For security leaders, the risk …THEHACKERNEWS.COM
8 JulThe CISO’s guide to post-quantum mandates and migrationsOver a dozen major economies have now published post-quantum cryptography (PQC) adoption guidance. As a CISO, you’re probably well into your migration plan and know the most difficult part has little to do with changing algorithms. The real leadership challenge is driving coordin…AWS.AMAZON.COM
8 JulGhostApproval: A Trust Boundary Gap in AI Coding AssistantsUncovering a category-level blind spot in modern AI coding assistants, and why the Human-in-the-Loop safety model fails against this classic threatWIZ.IO
8 JulAI Coding Agents Found Triggering Endpoint Security Rules Built to Catch AttackersSophos looked at a week of its own endpoint data and found that AI coding agents such as Claude Code, Cursor, and OpenAI Codex are setting off detection rules written to catch human intruders. The agents are not malicious. They just do a lot of things that, to a behavioral engine…THEHACKERNEWS.COM
8 JulDesigning for the inevitable: System prompt leakage and mitigations in generative AI applicationsSystem prompts form the foundation of generative AI applications. A system prompt is a collection of instructions and operational context provided to a large language model (LLM) that shapes how the model behaves and interacts with users and tools. System prompts often contain pr…AWS.AMAZON.COM
8 JulCash App owner to pay $45 million to settle allegations of lax securityState attorneys general announced the bipartisan agreement with Block, Inc. on Wednesday, saying that the company incorrectly promised users that Cash App offered the same protections as a bank.THERECORD.MEDIA
8 JulMexico's New Cyber Plan Faces Its First Real TestThe Latin American nation's cybersecurity plan — still in the expansion phase — has to survive its own knockout round during the FIFA World Cup.DARKREADING.COM
7 JulMicrosoft testing new Cloud Rebuild Windows 11 recovery featureMicrosoft has begun testing the Cloud Rebuild recovery feature in the latest Windows 11 Insider Preview builds released for users in the Experimental channel. [...]BLEEPINGCOMPUTER.COM
7 JulBeyondTrust warns of critical flaws in remote access softwareBeyondTrust warned customers to patch two critical security flaws in its Remote Support (RS) and Privileged Remote Access (PRA) software that could allow attackers to bypass authentication. [...]BLEEPINGCOMPUTER.COM
7 JulScammers are using AI to sell impossible flowersAI-generated flower scams are blooming online, with scammers using fake images to sell seeds for plants that don't exist, like these "cat's face orchids."MALWAREBYTES.COM
7 JulUK Government Launches Cyber Resilience Pledge, Claiming 60+ SignatoriesMore than 60 organizations, including M&S, Microsoft UK and Vodafone, have signed the UK government's Cyber Resilience Pledge, a new initiative aimed at boosting cyber security and resilience across British businessesINFOSECURITY-MAGAZINE.COM
7 JulMicrosoft to enable Windows settings backup by default for orgsMicrosoft says the Windows settings backup and restore tool will be enabled by default on Microsoft Entra-joined or Microsoft Entra hybrid-joined enterprise systems after upgrading to Windows 11 26H2. [...]BLEEPINGCOMPUTER.COM
7 JulSavi’s app aims to protect consumers from realistic AI scams like kidnappers demanding ransomThe company just raised $7 million in seed funding, and is launching its app for iPhone and Android on Tuesday.TECHCRUNCH.COM
7 JulClaude Code’s hidden tracker was an “experiment,” says AnthropicAnthropic's hidden Claude Code tracker has raised new questions about prompt steganography and developer trust.MALWAREBYTES.COM
7 JulWebinar tomorrow: Why modern email attacks require a new approach to defenseTomorrow's webinar explores how behavioral AI can help organizations detect sophisticated phishing, business email compromise, and account takeover attacks while reducing alert fatigue through automated investigation and response workflows. [...]BLEEPINGCOMPUTER.COM
7 JulTwo arrested over credit card phishing – as the Netherlands is named Europe’s worst for payment fraudTwo young men have been arrested in the Netherlands on suspicion of running a phishing operation that harvested the credit card details of unsuspecting victims. Read more in my article on the Hot for Security blog.BITDEFENDER.COM
7 JulFake Netflix, Coca-Cola, and FIFA job scams target marketersA fake recruiter phishing campaign uses trusted brands, nested redirects, and fake Google prompts to steal accounts.MALWAREBYTES.COM
7 JulScattered Spider’s Structure More Like a Cybercrime Collective Than a Unified GangGroup-IB analysis argued Scattered Spider is a decentralized collective of independent clustersINFOSECURITY-MAGAZINE.COM
7 JulThe GitHub Actions Attack Pattern Your CI Security Scanners MissActiveState explains how GitHub Actions attack chains can evade traditional CI security scanners, why passing a scan doesn't guarantee a secure pipeline, and how organizations can better govern their CI/CD workflows. [...]BLEEPINGCOMPUTER.COM
7 JulPublic GitHub Issue Could Trick GitHub Agentic Workflows Into Leaking Private Repo DataA public issue can trick GitHub Agentic Workflows into leaking the contents of an organization's private repositories, researchers at Noma Security have shown. The attacker needs only to open a normal-looking issue on a public repository, with no stolen credentials and no access …THEHACKERNEWS.COM
7 JulSpain arrests suspected member of pro-Russian hacktivist groupsThe National Police in Spain have arrested a man who is suspected of being an active member of the CyberArmy of Russia Reborn (CARR) and Z-Pentest, both pro-Russian hacktivist groups. [...]BLEEPINGCOMPUTER.COM
7 Jul'GitLost' Flaw Leaks Private Data from GitHub's Agentic WorkflowsThe flaw allows an unauthenticated attacker to craft a GitHub Issue in an org's public repository and then silently pull data from its private repos, too.DARKREADING.COM
7 JulDEBULL Tooling Abuses Microsoft Device-Code Flow to Target M365 AccountsA Microsoft 365 device code phishing campaign has been observed leveraging collaboration-themed lures to take control of victim accounts between the last week of June 2026 and into early July, per findings from ZeroBEC. "The campaign did not depend on a fake Microsoft password pa…THEHACKERNEWS.COM
7 JulSupreme Court allows Texas app law requiring age verification to take effectA student advocacy organization and tech trade group had appealed to the high court to stay the Texas App Store Accountability Act on an emergency basis until the lower court rules.THERECORD.MEDIA
7 JulRogue Agent Flaw Could Have Let Attackers Hijack Google Dialogflow CX ChatbotsA critical flaw in Google's Dialogflow CX could have let an attacker with edit rights on one Code Block-enabled agent compromise other Code Block-enabled agents in the same Google Cloud project. From there, they could read live conversations, steal the data users shared, and make…THEHACKERNEWS.COM
7 JulHow the Reddit and Discord false report scam steals accountsScammers are tricking Reddit and Discord users into handing over login codes by claiming they were involved in a false report.MALWAREBYTES.COM
7 JulDialogflow CX 'Rogue Agent' Flaw Enabled AI Chatbot Data TheftVaronis reported the flaw to Google in late 2025 and it has been addressed, but it reminds defenders to take a fresh look at their AI Infrastructure security.DARKREADING.COM
6 JulOpera GX Flaw Let Malicious Sites Auto-Install Mods to Steal Data From Visited PagesResearchers found a flaw in Opera GX, the gaming-focused version of the Opera browser, that let a malicious website silently install a browser add-on and use it to lift specific data from the pages a victim visits. In a proof of concept, they reconstructed a signed-in user's…THEHACKERNEWS.COM
6 JulThe security leaders defining the next decade aren’t in CISO seats yetThe first recognition program for the security leaders who will define the future of cybersecurity.CYBERSECURITYDIVE.COM
6 JulWhy schools are easy prey for hackers — and why they struggle to fight backPower plants and gas pipelines might receive more attention, but schools are arguably more vulnerable.CYBERSECURITYDIVE.COM
6 JulHow to Evaluate an AI SOC Platform in 2026: 6 Capabilities That Separate Leaders from Bolt-On AI solutionsBuilding a shortlist for an AI SOC evaluation can be tough. SIEM, SOAR, and pureplay AI SOC vendors are all saying the same thing. But behind the identical label sit very different products, from chat assistants bolted onto a legacy SIEM to agent platforms that run detection, tri…THEHACKERNEWS.COM
6 JulChoose your WhatsApp username carefullyWhatsApp is introducing usernames to help protect your phone number. Just make sure you don't undermine that privacy by choosing the wrong one.MALWAREBYTES.COM
6 JulHidden Web Prompts Trick AI Agents Into Sending MoneyHidden prompts on malicious websites trick AI agents into making payments or trusting fake sites, exposing new risks for autonomous AI workflows. Zscaler ThreatLabz documented two active campaigns that embed hidden instructions in web pages to manipulate AI agents, not human user…SECURITYAFFAIRS.COM
6 JulIndirect Prompt Injection in Web Content Targets AI AgentsZscaler found sites hiding prompt-injection text to manipulate AI agents into crypto paymentsINFOSECURITY-MAGAZINE.COM
6 JulOpera GX Flaw Let Sites Auto-Install Mods to Steal DataOpera GX flaw let sites automatically install mods to steal data from other pages, now patchedINFOSECURITY-MAGAZINE.COM
6 JulSoftware Is Now Written at the Speed of Thought. Security Isn't.Every evolution in software development has reduced the friction between an idea and a deployable application. AI may remove the final barrier, but it also removes many of the moments where security decisions have traditionally taken place. [...]BLEEPINGCOMPUTER.COM
6 JulNew Iran-Nexus Hacking Group Targets Israel Government and IT SectorsCheck Point researchers have identified a new cyber adversary targeting Israeli government and IT businesses, tracked as ‘Cavern Manticore’INFOSECURITY-MAGAZINE.COM
6 JulHow to tell if an image is AI-generatedScammers are using AI-generated images to make fake stories more convincing. Here's how to separate real from fake.MALWAREBYTES.COM
6 JulVietnam arrests suspects behind HiAnime anime piracy serviceVietnamese authorities have arrested and are prosecuting seven suspects believed to have run HiAnime, the largest anime piracy streaming service before its shutdown in June. [...]BLEEPINGCOMPUTER.COM
6 JulAttackers vote themselves $20 million in BONK cryptocurrencyBonkDAO said in a social media post that it was the victim of a “malicious governance proposal,” or an attack in which holders of a large amount of BONK used that leverage to vote more coins into their wallets.THERECORD.MEDIA
6 JulPhishing poses as big-brand job interview to steal Google accountsA phishing campaign is impersonating more than 30 well-known brands, including Adobe, Netflix, Coca-Cola, and OpenAI, in fake job interviews to steal Google account credentials from marketing professionals. [...]BLEEPINGCOMPUTER.COM
5 JulFlipper Zero firmware development continues with community helpFlipper Devices says development of the Flipper Zero firmware will continue, albeit with a smaller internal team and greater reliance on community contributions. [...]BLEEPINGCOMPUTER.COM
4 JulAlibaba reportedly bans employees from using Claude CodeAlibaba has reportedly classified Claude Code as high-risk software.TECHCRUNCH.COM
3 JulGovernment and Healthcare Are the Weakest Links in Global Email SecurityGovernment and healthcare sectors have weak email security. Many domains lack SPF, DMARC, DKIM, and MTA-STS, leaving them open to phishing attacks. Comparitech analyzed live DNS records for 5,849 domains across 13 sectors and scored each one out of 8 points based on four standard…SECURITYAFFAIRS.COM
3 JulChinese LLMs Broaden the Gap Between Attackers & DefendersTwo new models from Chinese firms compete with top US mainstream and frontier models. Should cyber-defenders be worried?DARKREADING.COM
3 JulARToken PhaaS exposes EvilTokens' Microsoft 365 phishing toolkitA new phishing-as-a-service (PhaaS) platform dubbed "ARToken" appears to operate as an affiliate of the EvilTokens phishing platform, giving researchers a glimpse into an extensive toolkit designed to compromise Microsoft 365. [...]BLEEPINGCOMPUTER.COM
2 Jul19-Year-Old Scattered Spider Suspect Extradited to Face U.S. Hacking ChargesA teenager accused of belonging to the hacking group Scattered Spider has been extradited from Finland to face U.S. charges of conspiracy, computer intrusion, and fraud, the U.S. Department of Justice announced on July 1. Peter Stokes, 19, a dual U.S. and Estonian citiz…THEHACKERNEWS.COM
2 JulAlleged Scattered Spider Member Extradited to USA teenager accused of hacking as part of Scattered Spider has been arrestedINFOSECURITY-MAGAZINE.COM
2 JulAlleged Scattered Spider hacker extradited to the United StatesA dual United States and Estonian citizen has been extradited to the U.S. to face charges alleging he was a member of the Scattered Spider hacking collective. [...]BLEEPINGCOMPUTER.COM
2 JulOpera rolls out Paste Protect feature to fight ClickFix attacksOpera has introduced Paste Protect, a security feature designed to block ClickFix-style attacks that trick users into executing malicious commands through social engineering. [...]BLEEPINGCOMPUTER.COM
2 JulBuild AI Security Agents with Wiz MCPPower AI-driven security with trusted security context, Wiz AI Agents, and Wiz AI Skills.WIZ.IO
2 JulIdentity Lifecycle Management Wasn't Built for AI AgentsIdentity lifecycle management was architected around a person with an employment record, a manager, and a departure date. AI agents have none of those. As autonomous principals proliferate across enterprise environments, the governance model built for humans develops structural b…THEHACKERNEWS.COM
2 JulMicrosoft fixes bug that removed Copilot buttons in OutlookMicrosoft has fixed a known issue causing the Copilot Chat or Copilot buttons in Classic Outlook to disappear for Windows users with the Copilot Chat (Basic) license. [...]BLEEPINGCOMPUTER.COM
2 JulWinRAR flaw could allow attackers to take control of your computerA new WinRAR update fixes a serious security flaw, but without automatic updates many users could miss the patch.MALWAREBYTES.COM
2 JulGoogle loses final appeal to overturn €4.1 billion EU fineCourt of Justice of the European Union (CJEU) has dismissed Google's final appeal against a €4.1 billion ($4.7 billion) antitrust fine over the company's use of Android to promote its Chrome browser and search service. [...]BLEEPINGCOMPUTER.COM
2 JulSupreme Court decision threatens EU-US data transfer agreementIn a Tuesday letter, Max Schrems, the founder of the Vienna-based privacy advocacy organization noyb, told European officials he plans to sue to invalidate the EU-U.S. Data Privacy Framework (DPF) that allows for the transfer of personal data from the EU to U.S. companies.THERECORD.MEDIA
2 JulEurope Confirms Record €4.1B Penalty Against Google for Android PracticesEU’s top court upheld a €4.1B fine against Google, ruling it abused Android’s market dominance through restrictive licensing practices. The Court of Justice of the European Union issued its ruling on July 2, 2026, and Google lost. The court dismissed the appeal brough…SECURITYAFFAIRS.COM
2 JulThe Supreme Court rules that location history is protected by the Constitution.The KIDS Act clears the House of Representatives.THECYBERWIRE.COM
2 JulClaude Fable relaunch disappoints users with nerfed performanceClaude Fable, the company's most powerful model, is now available to all users, but early impressions are disappointing, as it appears to be nowhere near the original release. [...]BLEEPINGCOMPUTER.COM
2 JulClaude Fable 5 isn’t permanently leaving subscriptions, Anthropic saysAnthropic says Claude Fable 5 won't be accessible via Claude subscriptions after July 7, but it's not a permanent change, and the company expects the model to return outside the usage-based plan soon. [...]BLEEPINGCOMPUTER.COM
1 JulWeekly Threat Bulletin – July 1st, 2026These are the top threats you should know about this week.F5.COM
1 JulHow Madalina Petrea Runs Marketing for 27+ Cybersecurity Franchise Owners Across 4 ContinentsCyberGlobal is the world's first cybersecurity franchise, with Madalina Petrea heading up marketing there. What does it mean to run marketing at a cyber franchise? Supporting 27+ franchise owners across the US, Europe, Africa, and Asia who sell cybersecurity services to small bus…THECYBERWIRE.COM
1 JulAzure CLI Password Spray Hits at Least 78 Microsoft Accounts in 81M+ AttemptsCybersecurity researchers have warned of a "massive, ongoing, automated password spray attack" aimed at Microsoft's Azure command-line interface (CLI), compromising dozens of accounts in the process. The activity, per Huntress, originates from an IPv6 address range (2a0a:d683::/3…THEHACKERNEWS.COM
1 JulAdobe patches seven max severity ColdFusion, Campaign flawsAdobe has released security patches for seven maximum-severity vulnerabilities in the ColdFusion web app development platform and the Campaign Classic marketing automation platform. [...]BLEEPINGCOMPUTER.COM
1 JulChatGPT produced graphic violent images that shocked researchersAI assistants like ChatGPT are supposed to have appropriate guardrails to stop people creating harmful content. However, they don't always work.MALWAREBYTES.COM
1 JulMicrosoft Accelerates Quantum-Safe Push with New TimelineMicrosoft has brought forward its timelines for transitioning to post-quantum cryptography (PQC)INFOSECURITY-MAGAZINE.COM
1 JulAmazon fined $2.25M for withholding evidence from fraud victimsThe U.S. Federal Trade Commission (FTC) says Amazon will pay a $2.25 million civil penalty to settle charges that it blocked identity theft victims' access to transaction records. [...]BLEEPINGCOMPUTER.COM
1 JulAnthropic's Fable 5 and Mythos 5 Are Back with New Security GuardrailsThe new classifier in Fable 5 blocks the jailbreak technique that prompted the US export controls “in over 99% of cases”INFOSECURITY-MAGAZINE.COM
1 JulMicrosoft fixes GIF functionality in the Windows Emoji PanelMicrosoft has fixed the GIF functionality in the Emoji Panel for Windows 11 and Windows Server users after the provider shut down its service. [...]BLEEPINGCOMPUTER.COM
1 JulMicrosoft Accelerates Post-Quantum Cryptography Shift to 2029Microsoft on Tuesday said it's accelerating its quantum safe security roadmap, stating technology advances in quantum computing are making it essential to replace existing encryption standards sooner than previously expected. "Advances in quantum research and development have shi…THEHACKERNEWS.COM
1 JulChrome needs another whopper update to fix 382 security bugsGoogle released a huge update of 382 security fixes, 15 of which were rated as critical. So, it's time to update agaiMALWAREBYTES.COM
1 JulUS lifts export controls on Anthropic’s frontier cybersecurity AI modelsAnthropic said export controls on certain models had been lifted after the company came to a series of agreements with the government.THERECORD.MEDIA
1 JulHow to use the AWS Workload Credentials Provider for cross-account secret retrieval and prefetching secretsIf you manage secrets across multiple AWS accounts or need faster secret access for latency-sensitive applications, this post shows you how to meet those requirements using two new features of the AWS Workload Credentials Provider (provider). You will learn how to configure role …AWS.AMAZON.COM
1 JulUS lifts export restrictions on Anthropic’s most advanced AI models.Adobe patches seven maximum-severity flaws. Business news: Quantifind lands $200 million.THECYBERWIRE.COM
1 JulHackers target Microsoft 365 accounts with 81 million login attemptsAn aggressive password-spraying campaign targeting Microsoft 365 environments generated more than 81 million login attempts over a two-week period. [...]BLEEPINGCOMPUTER.COM
1 JulSecure Amazon container workloads using container attribute-based rules in AWS Network FirewallToday, you can use AWS Network Firewall to protect traffic flowing to and from containerized applications on Amazon Elastic Kubernetes Service (Amazon EKS) and Amazon Elastic Container Service (Amazon ECS) clusters. If you run AI and machine learning (ML) workloads on Amazon EKS—…AWS.AMAZON.COM
1 JulQuantifind has secured $200 million in a funding round led by Summit Partners.Straiker has raised $64 million in a Series A round. F5 has acquired Denver-based AI governance firm SurePath AI.THECYBERWIRE.COM
1 JulFake Perplexity Chrome extension spies on your searchesA fake Perplexity Chrome extension secretly monitored searches. If you installed "Search for perplexity ai," you need to remove it manually.MALWAREBYTES.COM
30 JunNew BioShocking Attack Tricks AI Browsers Into Leaking User CredentialsConvince an AI browser that it is playing a game, and it can hand over your login details. That is the finding behind BioShocking, a technique from security firm LayerX that tricked six AI browsers and assistants into copying a user's credentials and sending them to an attac…THEHACKERNEWS.COM
30 JunJune 2026 Apple Updates, (Tue, Jun 30th)Apple released updates for iOS/iPadOS, macOS, and Safari on Monday. There have been no updates for other Apple operating systems (visionOS, watchOS, tvOS). Usually, Apple updates all products at the same time.
ISC.SANS.EDU
30 JunUK Healthcare Sector Records Tenfold Increase in Cyber-AttacksSonicWall records 264,000 events in first five months of 2026 as UK hospitals come under siegeINFOSECURITY-MAGAZINE.COM
30 JunKali Linux 2026.2 released with 9 new tools, NetHunter updatesKali Linux 2026.2, the second release of the year, is now available for download, featuring 9 new tools and numerous Kali NetHunter improvements. [...]BLEEPINGCOMPUTER.COM
30 JunMircosoft adds smarter bot protection to Teams meetingsMicrosoft has introduced a new Teams admin policy that allows organizers to prevent third-party bots from joining meetings without approval. [...]BLEEPINGCOMPUTER.COM
30 JunVerifiable Digital Credential PresentmentThis blog post is #4 in our series on Verifiable Digital Credentials (VDCs). Our other posts can be found via Post #1, Post #2, and Post #3. In earlier posts, we discussed how verifiable digital credentials (VDCs) are issued and compared the underlying credential formats (ISO/IEC…NIST.GOV
30 JunAI-Generated Workflows Are a Silent Security DisasterTeams are dealing with a truly dangerous problem — automation that works, but that no one understands.DARKREADING.COM
30 JunTrain, triage, repeat: The AI agent changing how we fight phishingLearn how Red Canary engineered a super agent—blending ML, a rules engine, similarity, agentic AI, and LLMs—to classify phishing emails.REDCANARY.COM
30 JunAn intelligence budget 'super user' job is now in the hands of Russ VoughtRussell Vought, director of the White House Office of Management and Budget (OMB), assumed hands-on responsibility for overseeing the spending plans of intelligence agencies following the recent departure of Amaryllis Fox Kennedy, a senior intelligence official who simultaneously…THERECORD.MEDIA
30 JunMicrosoft 365 Hardening and Huntress Managed ISPMMost Microsoft 365 environments are missing more than half of the recommended security controls, even with tooling in place. Here's why that happens and what Huntress Managed ISPM does about it.HUNTRESS.COM
30 Jun282 iOS AI Apps Leak API Keys and Open AI Proxy Access in Network Traffic StudyResearchers tested 444 AI chatbot apps for iPhone and found that 282 of them, nearly two-thirds, exposed paid AI access through their network traffic. In many cases, the path in was visible just by watching what the app sent: a plaintext API key, a reusable token, or a backend se…THEHACKERNEWS.COM
30 JunUpdate time: Apple releases security patches for iOS, MacOS Tahoe, SafariA new Apple update fixes a multitude of browser and browser related vulnerabilities which have been public knowledge for a whileMALWAREBYTES.COM
30 Jun6 Key Takeaways: Strengthening Public Safety Through Collective DefenseHere are six key takeaways from a CIS webinar for how U.S. SLTT agencies can strengthen public safety through collective defense.CISECURITY.ORG
30 JunSilent Swap Crypto Clipper Uses Fake Google Notes Extension to Replace Wallet AddressesCybersecurity researchers have flagged an active browser extension campaign that is designed to steal cryptocurrency by stealthily replacing wallet addresses when unsuspecting users initiate a transaction. The cryptocurrency clipper activity has been codenamed Silent Swap by McAf…THEHACKERNEWS.COM
30 JunCIA chief highlights major shifts in agency’s tech approachCIA Director John Ratcliffe said artificial intelligence capabilities are "akin to digital nuclear weapons.”THERECORD.MEDIA
30 JunWhy Identity Security Is Your Cyber Career Entry PointAs AI reshapes cybersecurity workflows, John Paul Cunningham, CISO at SIlverfort, says the technology is creating opportunities rather than eliminating jobs — and there are more ways than ever to break into the essential field.DARKREADING.COM
30 JunWatch out for “high paying, low effort” Amazon job textsScammers are using Amazon and the promise of big money to lure people in to their trap.MALWAREBYTES.COM
30 JunNew BioShocking attack manipulates AI browser into data theftA new prompt injection attack dubbed "BioShocking" could trick AI-powered browsers into treating real-world risky actions as part of a fictional scenario, causing them to ignore any safety guardrails. [...]BLEEPINGCOMPUTER.COM
30 JunMicrosoft accelerates quantum-safe roadmap as risks growMicrosoft announced today that it is accelerating its quantum-safe security roadmap, saying advances in quantum computing are bringing the need to replace today's encryption standards sooner than previously expected. [...]BLEEPINGCOMPUTER.COM
30 JunAttackers Hijack Exposed AI Endpoints to Power Offensive OpsAttackers don't need any special authentication to reach a target endpoint — they just need to know where it is.DARKREADING.COM
30 JunAnthropic rolls out Sonnet 5 with near-Opus 4.8 performance at a lower priceAnthropic is now rolling out Sonnet 5, and it's almost as good as the Opus range, but it is designed to be cheaper than the company's flagship model. [...]BLEEPINGCOMPUTER.COM
29 JunFBI Sounds Alarm Over Russian Intelligence Signal PhishingThe FBI claims Russian spies are targeting Signal backup keysINFOSECURITY-MAGAZINE.COM
29 JunUS seizes hundreds of FIFA World Cup illegal streaming domainsThe U.S. Justice Department's Criminal Division has seized nearly 400 web domains used for illegally streaming matches at the FIFA World Cup. [...]BLEEPINGCOMPUTER.COM
29 JunThe Borderless Attack Surface: Securing Public Sector Hybrid EnvironmentsAligning Modern CNAPP Telemetry with realistic risk assessments to drive agency efficiency through cross-team collaborationWIZ.IO
29 JunAdding some Automation to the favicon.ico method of Host Recon, (Mon, Jun 29th)I&#;x26;#;39;m in the throes of target host recon for another pentest, and thought I&#;x26;#;39;d share some workflow / automation stuff.
In the past, I&#;x26;#;39;ve discussed using histori…ISC.SANS.EDU
29 JunStegoAd: How 119 Fake Browser Extensions Stole Credentials and Ran Ad Fraud for Two YearsMicrosoft shut down the StegoAd campaign, which used 119 malicious Edge extensions, hit 2.6M installs, and ran undetected for two years. Microsoft just shut down one of the more technically clever malicious extension campaigns it’s ever documented. The operation, named Steg…SECURITYAFFAIRS.COM
29 JunUkraine to use seized crypto from cybercrime group to buy war bondsUkraine's Asset Recovery and Management Agency (ARMA), which manages property seized in criminal proceedings, said more than $8.3 million in cryptocurrency had been transferred to its official digital wallet following a court order.THERECORD.MEDIA
29 JunOpenAI Reveals GPT-5.6 Sol Cybersecurity Model, Restricts Early AccessOpenAI is previewing its GPT-5.6 Sol model to a vetted few at the US government's requestINFOSECURITY-MAGAZINE.COM
29 JunTelegram-Based Millenium RAT Campaign Infects 60,000 DevicesGroup-IB says Millenium RAT, now rewritten in C++, has hit 62,289 devices in 160+ countriesINFOSECURITY-MAGAZINE.COM
29 JunAgentic AI Has an Identity Problem and Attackers Know ItAI agents can access data, trigger workflows, and take action across enterprise systems. Token Security explains why governing these privileged identities is becoming essential for enterprise security. [...]BLEEPINGCOMPUTER.COM
29 JunWhatsApp is Finally Getting Usernames to Help Keep Phone Numbers PrivateWhatsApp on Monday officially announced the start of global reservations of usernames with an aim to protect the privacy of more than three billion users on the messaging platform. The optional feature is designed to help users connect with someone on the service through username…THEHACKERNEWS.COM
29 JunIn major privacy win, Supreme Court rules geofence warrants are protected by privacy rightsThe Supreme Court's decision to limit geofence warrants is a win for privacy advocates, who called their use unconstitutional but sought an outright ban.TECHCRUNCH.COM
29 JunUS posts $10 million reward over Russian cyber campaign targeting Signal, WhatsAppRussia-linked hacking groups tracked as UNC5792 and UNC4221 have socially engineered their way into the messaging accounts of government officials.THERECORD.MEDIA
29 JunU.S. offers $10 million for hackers targeting WhatsApp, Signal usersThe U.S. Department of State is offering up to $10 million for information that helps identify or locate members of the UNC5792 and UNC4221 hacker groups, which are linked to Russia's intelligence and military services. [...]BLEEPINGCOMPUTER.COM
29 JunBridging the Visibility Gap: A Unified Security Operating Model for Hybrid Cloud TeamsMove beyond chasing vulnerabilities to a unified hybrid risk strategy. The Sensor Workload Scanner is now GA and extends our risk prioritization engine to on-premise environments to identify the critical attack paths across your hybrid cloud.WIZ.IO
29 JunWhatsApp rolls out usernames to help users hide their phone numberWhatsApp is finally allowing users to reserve usernames, a privacy feature that lets them hide their phone numbers from people not in their contact list. [...]BLEEPINGCOMPUTER.COM
29 JunMicrosoft extends Windows Server 2022 hotpatching until October 2027Microsoft has extended Windows Server 2022 hotpatching until October 2027, one year after the mainstream end date of October 2026. [...]BLEEPINGCOMPUTER.COM
29 JunJustices rule that cellphone location histories are protected by the Fourth AmendmentPolice must get a warrant to request geofence data involving individual cellphones, the U.S. Supreme Court ruled in what represents a victory for privacy advocates.THERECORD.MEDIA
29 JunCan Clothes Make You Invisible to Facial Recognition?Does life feel Orwellian sometimes? One researcher has a solution for you: graphic tees that confuse the neural networks in surveillance cameras.DARKREADING.COM
29 JunMeta Contractors Posed as Teens to Prompt Rival Chatbots About Suicide, Sex, and DrugsHundreds of contractors working on a project for Meta pretended to be kids—and then prompted rival chatbots like Gemini and ChatGPT to discuss high-risk subjects.WIRED.COM
29 JunWhatsApp Usernames Are Coming. You Can Reserve Yours Right NowWhatsApp will introduce usernames later this year, letting its 3 billion users connect without sharing phone numbers. WhatsApp has over three billion users, and it’s finally letting them talk to each other without exchanging phone numbers. The company announced this week th…SECURITYAFFAIRS.COM
28 JunSecurity Affairs newsletter Round 583 by Pierluigi Paganini – INTERNATIONAL EDITIONA new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including the international press. New FBI Alert: Russian Intell…SECURITYAFFAIRS.COM
27 JunHooking Windows Named PipesDuring security assessments, we often see desktop applications composed of several processes. Some of them run as SYSTEM, and others run in the user session context, meaning they are unprivileged. These processes need to communicate in some way, and often use Windows Named Pipes …SYNACKTIV.COM
27 JunDeep-dive into the deployment of an on-premise low-privileged LLM serverIn 1826, children fantasized riding horses in the Wild West. In 1926, it was outrunning the law as a moonshiner. In 2026, managing distributed inference servers without leaking all the company data is surely a universal dream among the new generation. This article rewinds our jou…SYNACKTIV.COM
27 Jun2025 winter challenge writeupCreating quines is a game that has always fascinated computer scientists. The journal Software: Practice and Experience dedicated an article to the subject in 1972—well before Intel released its first 32-bit x86 processor (1985). Even today, many enthusiasts continue to explore t…SYNACKTIV.COM
27 JunWireless-(in)Fidelity: Pentesting Wi-Fi in 2025Despite the advancements that have been made in Wi-Fi security with the arrival of WPA3, some misconfigurations and legacy protocols still remain. In this blogpost, we share insights into Wi-Fi related findings encountered during penetration testing engagements. We will present c…SYNACKTIV.COM
27 JunWhat could go wrong when MySQL strict SQL mode is off?This article shows some examples of attacks that can abuse MySQL behavior when the strict SQL mode is disabled, especially when string characters are invalid in the current encoding. This happens when the encoding of the application (e.g. UTF-8) is wider than that of the database…SYNACKTIV.COM
27 JunQuantum readiness: Hybridizing signaturesIn light of new legal requirements being enacted in many countries for software providers to adopt hybrid post-quantum cryptography, Synacktiv has initiated research into these novel cryptographic algorithms. After having studied what makes post-quantum cryptography “post-quantum…SYNACKTIV.COM
27 JunMass Surveillance, is an (un)Complicated BusinessA massively popular iOS application turns out to be a government spy tool! Here, we analyze the app; decrypting its binary and studying its network traffic.OBJECTIVE-SEE.ORG
27 JunWriting a File Monitor with Apple's Endpoint Security FrameworkLearn how to leverage Apple's new Endpoint Security Framework to create a comprehensive (user-mode) File Monitor for macOS 10.15!OBJECTIVE-SEE.ORG
27 JunWriting a Process Monitor with Apple's Endpoint Security FrameworkLearn how to leverage Apple's new Endpoint Security Framework to create a comprehensive (user-mode) Process Monitor for macOS 10.15!OBJECTIVE-SEE.ORG
27 JunGetting Root with Benign AppStore AppsIn this guest blog post, "Objective by the Sea" speaker, Csaba Fitzl writes about an interesting way to get root via Apps from the official Mac App Store!OBJECTIVE-SEE.ORG
27 Jun"Objective by the Sea" v2.0After the success of #OBTS v1.0, we decided to go international and plan #OBTS v2.0 in Europe! In this blog post, we re-live the highlights (from Monaco!) of "Objective by the Sea" v2.0.OBJECTIVE-SEE.ORG
27 JunRootpipe Reborn (Part I)In part one of a guest blog post, @CodeColorist writes about several neat macOS vulnerabilities.OBJECTIVE-SEE.ORG
27 JunMac Adware, à la PythonLet's tear apart a persistent piece of adware, decompiling, decoding, and decompressing it's code to uncover its methods and capabilities.OBJECTIVE-SEE.ORG
27 JunDeath by vmmapA core Mojave utility is rather disastrously broken - causing a full-system lockup. Let's find out why!OBJECTIVE-SEE.ORG
27 JunWord to Your MacA malicious Word document targeting macOS users, was recently uncovered. Let's extract the embedded macros, decode an embedded downloader, and retrieve the 2nd-stage payload!OBJECTIVE-SEE.ORG
27 JunA Deceitful 'Doctor' in the Mac App StoreA massively popular app from the official Mac App Store, surreptitiously steals your browsing history! By fully reversing the application, we can fully expose its functionality and rather shady capabilities.OBJECTIVE-SEE.ORG
27 JunA Remote iOS BugApple wrote code to appease the Chinese government ...it was buggy. In certain configurations, iOS devices were vulnerable a "emoji-related" flaw that could be triggered remotely!OBJECTIVE-SEE.ORG
27 JunBlock Blocking Login ItemsApple recently updated the way login items are stored by the OS. In this post, we'll illustrate how to parse the (new) login item files to detect persistenceOBJECTIVE-SEE.ORG
27 JunCache Me OutsideAre full paths and preview thumbnails for files even on encrypted containers and removable usb devices really persistently stored? ...yes :( Apple's 'QuickLook' cache is to blame.OBJECTIVE-SEE.ORG
27 JunBreaking macOS Mojave (Beta)In macOS Mojave apps, to have to obtain user permission before using the Mac camera & microphone. We'll illustrate how this is trivial to bypass (at least in the current beta).OBJECTIVE-SEE.ORG
27 JunWhen Disappearing Messages Don't DisappearDid you know on macOS, notifications are stored in a unencrypted database? Which means that even 'disappearing' messages from apps such as Signal - may not really disappear. Yikes!OBJECTIVE-SEE.ORG
27 JunAn Insecurity in Apple's Security Framework?Turns out that writing security tools is a great way to inadvertently uncover bugs in macOS. How about a crash in Apple's 'Security' framework ... that can't be good!?OBJECTIVE-SEE.ORG
27 JunA Surreptitious Cryptocurrency Miner in the Mac App Store?Turns out the innocuously named "Calendar 2" app, found on the official Mac App Store, was surreptitiously turning Mac into cryptocurrency miners!OBJECTIVE-SEE.ORG
27 JunAnalyzing OSX/CreativeUpdaterRecently, the popular MacUpdate website was subverted to distribute a new macOS cryptominer; OSX/CreativeUpdater.OBJECTIVE-SEE.ORG
27 JunAnalyzing CrossRATThe EFF/Lookout discovered a cross-platform implant, named CrossRat with ties to nationstate operators. Here, we tear it apart; analyzing its persistence mechanisms, features, and network communications.OBJECTIVE-SEE.ORG
27 JunAll Your Docs Are Belong To UsHere, we reverse, then 'extend' a popular macOS anti-virus engine. With the creation of a new anti-virus signature, classified documents will be automatically detected!OBJECTIVE-SEE.ORG
27 JunWhy _blank_ Gets You RootYet another a massive security flaw affects the latest version of macOS (High Sierra), allowing anybody to log into the root account with a blank, or password, of their choosing!OBJECTIVE-SEE.ORG
27 JunHigh Sierra's 'Secure Kernel Extension Loading' is BrokenA new 'security' feature in macOS 10.13, is trivial to bypass.OBJECTIVE-SEE.ORG
27 JunWTF is Mughthesec!? poking on a piece of undetected adwareSome undetected adware named "Mughthesec" is infecting Macs...let's check it out!OBJECTIVE-SEE.ORG
27 JunTwo Bugs, One Func(), part twoApple's 'fix' for a macOS kernel panic, fixes nothing and worse, introduces a new bug.OBJECTIVE-SEE.ORG
27 JunTwo Bugs, One Func(), part oneThe macOS kernel had an (intentional?) off-by-one bug that could trigger a kernel panic.OBJECTIVE-SEE.ORG
27 JunHappy Birthday to Objective-SeeToday is our 2nd birthday! Let's look at our past, present, and future.OBJECTIVE-SEE.ORG
27 JunFrom Italy With Love?Reverse-engineering a 'Russian' implant reveals HackingTeam's code!?OBJECTIVE-SEE.ORG
27 Jun'Untranslocating' an AppApple's App Translocation broke several of my tools, but we can locally undo it to restore broken functionality!OBJECTIVE-SEE.ORG
27 JunForget the NSA, it's Shazam that's always listening!Does Shazam's Mac App keep recording even when you turn the app off? ...yes :/OBJECTIVE-SEE.ORG
27 JunClick File, App OpensThe 'Mac File Opener' adware is fairly normal, except for it how it persists via registered document handlersOBJECTIVE-SEE.ORG
27 JunPersisting via a Finder SyncLearn how a Finder Sync can 'extend' Finder.app and how this could be abused for persistenceOBJECTIVE-SEE.ORG
27 JunAre you from the Mac App Store?How to verify that an application came from the official Mac App Store, via receipt validationOBJECTIVE-SEE.ORG
27 JunAnalysis of an Intrusive Cross-Platform Adware; OSX/PirritIn Objective-See's first guest blog post, Amit Serper presents his detailed analysis of OSX/PirritOBJECTIVE-SEE.ORG
27 JunAnalyzing the Anti-Analysis Logic of an Adware InstallerDissecting string obfuscations, junk code insertions, and anti-debugging logic of InstallCoreOBJECTIVE-SEE.ORG
27 Jun KEVMonitoring Process Creation via the Kernel (Part III)Getting process creation notifcations from kernel-mode to user-mode, via the undocumented kev_msg_post functionOBJECTIVE-SEE.ORG
27 JunMonitoring Process Creation via the Kernel (Part II)Process monitoring via the KAuth Subsystem (and some limitations)OBJECTIVE-SEE.ORG
27 JunMonitoring Process Creation via the Kernel (Part I)Why BlockBlock needs a kext (hint: process monitoring), and how the kext was createdOBJECTIVE-SEE.ORG
27 JunKernel Debugging a Virtualized OS X El Capitan ImageHow to remotely kernel-debug a OS X 10.11 VMOBJECTIVE-SEE.ORG
27 JunReversing to Engineer: Learning to 'Secure' XPC from a PatchHow reversing Apple's 'RootPipe' patch provided the means to secure TaskExplorer's XPC serviceOBJECTIVE-SEE.ORG
27 JunBuilding HackingTeam's OS X Implant For Fun & ProfitHow to build HackingTeam's OS X implant in XcodeOBJECTIVE-SEE.ORG
27 JunDylib Hijack Scanner ReleasedAnnouncing the release of DHS; a tool to help detect (dylib) hijackersOBJECTIVE-SEE.ORG
27 JunOpenAI Previews GPT-5.6 Sol With Restricted Access and Stronger Cyber SafeguardsOpenAI on Friday released three versions of GPT-5.6, called Sol, Terra, and Luna, as a limited preview to a small number of companies as part of an ongoing engagement with the U.S. government. While Sol is the latest flagship model and the most powerful, Terra strikes a balance b…THEHACKERNEWS.COM
26 JunStatement from the Canadian Centre for Cyber Security on frontier artificial intelligence models and their impact on cyber securityCANADA.CA
26 JunRussia Used Cellebrite on Jailed Activist's iPhone Months After Sales CutoffRussian authorities used Cellebrite's UFED forensic tools to break into the iPhone of detained opposition activist Andrey Pivovarov in June 2021, three months after Cellebrite said it would stop selling its tools and services to Russia and Belarus. The finding, published Jun…THEHACKERNEWS.COM
26 JunGuardian Agents: The Next Layer of Identity GovernanceAI agents are moving through enterprise environments, inheriting permissions, traversing systems, and executing decisions at machine speed with minimal oversight. The identity infrastructure built to govern human access wasn't designed for autonomous actors, and the gap between w…THEHACKERNEWS.COM
26 JunFCC votes to toughen rules in bid to better protect undersea cablesIn an unprecedented move, the FCC also said it plans to mandate that owners and operators of submarine line terminal equipment (SLTE) be licensed.THERECORD.MEDIA
26 JunThanks for Crushing the Submissions Inbox. We're Trying to Keep UpIt might be taking a bit longer than usual to respond to your submissions — here's why.DARKREADING.COM
26 JunMCP Auto-Execution: From Git Clone to Cloud Compromise in Amazon Q VS Code ExtensionBy automatically loading MCP servers from workspace files, Amazon Q enabled attackers to execute code and access sensitive cloud environments.WIZ.IO
26 JunRussia accuses Apple of ‘political censorship’ after VK apps removed from App StoreApple removed VK's flagship social network VKontakte, often described as Russia's equivalent of Facebook, along with VK Music, VK Messenger, VK Video, Odnoklassniki and Mail.ru services, including its email application.THERECORD.MEDIA
26 JunMeeting Trump's 2030 Quantum Deadline Will be Expensive, ComplexGetting accurate visibility into IT and OT systems will be compounded by multivendor environments, misaligned update life cycles, and interoperability gaps.DARKREADING.COM
26 JunYour First GRC Agent: A Red Teamer's WalkthroughAI won't replace GRC analysts, but it can eliminate much of the repetitive work they do. Anecdotes walks through building an agent that continuously monitors controls, identifies evidence gaps, and opens remediation tasks. [...]BLEEPINGCOMPUTER.COM
26 JunThe Pentagon Is Looking Into the Dialog Data Exposure for Unmasking National Security OfficialsExposed records from the private group included the personal information of a senior White House intelligence official and an active-duty special operations officer.WIRED.COM
26 JunAI Won't Wipe-Out Entry-Level Cybersecurity JobsInstead of eliminating jobs for early-career cyber pros, AI is creating new opportunities for candidates with strong human decision-making skills.DARKREADING.COM
26 JunAI Decline? Confidence in Autonomous Penetration Testing FallsCompanies are still experimenting with automated AI systems to find security weaknesses, but fewer are relying on the technology.DARKREADING.COM
25 JunChrome Ad Blocker with 10M+ Installs Found with Dormant Script Injection CapabilityAn analysis of a popular Google Chrome ad block extension for YouTube has uncovered the ability to execute arbitrary JavaScript code. According to Island, the extension, named Adblock for YouTube (ID: cmedhionkhpnakcndndgjdbohmhepckk), has more than 10 million installs and carrie…THEHACKERNEWS.COM
25 JunThreatsDay Bulletin: Smart TV Proxyware, 24-Year curl Bug, AI Crime Forums + 13 More StoriesIt’s dumb out there again. This week has the usual smell of prod on fire and nobody wanting to admit who left the door open — old creds still working, trusted apps doing sketchy crap, browser tricks jumping the fence, and “normal” workflows turning into phishing pipes because app…THEHACKERNEWS.COM
25 JunUpdate Chrome to patch critical browser security flawsChrome has patched 18 vulnerabilities, including four critical flaws. Two WebGL bugs could allow attackers to escape the browser's security sandbox.MALWAREBYTES.COM
25 JunFake domain renewal emails trick website owners into paying scammersWe uncovered fake domain renewal notices and convincing websites to pressure website owners into paying scammers.MALWAREBYTES.COM
25 JunCourt allows for Ohio to implement restrictions on social media use.Five Eyes warns about the frontier AI model.THECYBERWIRE.COM
25 JunHR1 and the future of U.S. tech securityWe hope you enjoy this encore of Caveat. This week on Caveat, Dave and Ben welcome back N2K’s own Ethan Cook for our latest policy deep dive segment. As our lead analyst, Ethan shares his knowledge of law, privacy, and surveillance on the latest policy developments sh…THECYBERWIRE.COM
25 JunRussia used Cellebrite phone-hacking tool to crack down on dissident after firm cut off countryThe continued use of the powerful data extraction product soon after the company in March 2021 said it would stop working with Russia suggests the firm has been unable to pull back its technology from authoritarian government customers, researchers say.THERECORD.MEDIA
25 JunTwenty Million US IP Connections Used by Proxy ServicesDigital Citizens Alliance report claims that millions of Americans may have unwittingly had IP connections used by cybercriminalsINFOSECURITY-MAGAZINE.COM
25 JunmacOS Flaw Lets Standard Users Disable EDR and MDMmacos-xpc-flaw-disable-edr-mdm-standard-user-xm-cyberINFOSECURITY-MAGAZINE.COM
25 JunHow to Spot a Client in the DoD Industrial Base That Handles CUILearn how MSPs/MSSPs can identify if a client is a DoD contractor handling CUI.HUNTRESS.COM
25 JunAnthropic is testing desktop-like Claude Cowork for mobileAnthropic appears to be testing Claude Cowork support on mobile, allowing you to manage long-running Claude tasks from your phone. [...]BLEEPINGCOMPUTER.COM
25 JunPirloTV sports piracy network disrupted as 44 domains seizedA major sports piracy ring linked to the illegal PirloTV streaming platform has been disrupted in an action that targeted 44 domains. [...]BLEEPINGCOMPUTER.COM
25 JunBluekit phishing kit adopts browser-in-the-middle for login theftThe Bluekit phishing-as-a-service platform continues to evolve with nearly 70 new hostnames identified over the past week and by adding browser-in-the-middle capabilities for improved data theft. [...]BLEEPINGCOMPUTER.COM
25 JunThe Four Elevations of Effective Fraud PreventionFraudsters don't attack just one transaction. They target accounts, platforms, and entire ecosystems. IPQS explains the four elevations of fraud prevention and why broader visibility improves fraud detection. [...]BLEEPINGCOMPUTER.COM
25 JunIn Less Than 24 Hours, Attackers Weaponize Cisco CUCM FlawThe flaw enables server-side request forgery (SSRF) and escalates privileges to root, impacting Cisco Unified CM and Unified CM SME deployments.DARKREADING.COM
25 JunEdTech Attackers Shift From Schools to Their Software SuppliersEducational institutions, the edtech companies they rely on, and, more concerningly, the challenges they pose for schools are the focus of the latest Reporters' Notebook video series.DARKREADING.COM
25 JunUncovering Hidden Attack Paths in Cloud Environments Using Runtime SignalsWiz now layers runtime signals into the Security Graph, exposing hidden attack paths to give security teams a complete picture of risk.WIZ.IO
24 JunWeekly Threat Bulletin – June 24th, 2026These are the top threats you should know about this week.F5.COM
24 JunUK Museums Face Cybersecurity Risks, MPs WarnPublic Accounts Committee (PAC) warns that museums and galleries aren’t getting enough government support on cyberINFOSECURITY-MAGAZINE.COM
24 JunDoJ Seizes Huione Cloud Account Tied to Cyber Scam Money LaunderingThe U.S. Department of Justice (DoJ) on Tuesday announced the seizure of a cloud computing account put to use by subsidiaries of Cambodia-based corporate conglomerate HuiOne Group, as the Treasury unveiled fresh sanctions against nine individuals and 26 entities linked to Prince …THEHACKERNEWS.COM
24 JunAI Is Making Attacks Cheaper, Faster and More Covert, Says ReliaQuestNew ReliaQuest study reveals the six ways AI is practically being used in attacks todayINFOSECURITY-MAGAZINE.COM
24 JunDawn of the Apex Agentic AdversaryWe are standing at the end of an era we never thought to mourn: the era of human-speed threats. For years, cybersecurity moved to a rhythm organizations could follow. A researcher found a bug, a CVE was cataloged, a vendor navigated a patch cycle, and weeks or even months later, …THEHACKERNEWS.COM
24 JunGerman rail services resume after wireless communications outageDeutsche Bahn said a nationwide disruption of railway services was tied to a malfunction in its 2G-based GSM-R communications system.THERECORD.MEDIA
24 JunSecuring the service desk: Why social engineering attacks keep succeedingService desks have become a favored target for attackers seeking password resets, MFA changes, and access to corporate accounts. Specops Software breaks down how service desk social engineering attacks work and how organizations can defend against them. [...]BLEEPINGCOMPUTER.COM
24 JunResearchers Trick AI Browsers Into Leaking CredentialsLayerX tricked AI browsers including ChatGPT Atlas and Comet into bypassing their guardrailsINFOSECURITY-MAGAZINE.COM
24 JunPixelSmash flaw turns video files into attack toolsResearchers have found a critical FFmpeg flaw that could let attackers use a malicious video file to compromise vulnerable systems.MALWAREBYTES.COM
24 JunAccenture acquires Dragos, runZero, and NetRise for more than $4 billion.Dream has raised $260 million in funding led by Bicycle Capital and Group 11.THECYBERWIRE.COM
24 JunNew website names and shames companies that still don’t offer passkeys to usersAccording to a new site, 24% of the most popular websites in the world don't offer support for passkeys, which are considered the most secure way to log in to apps and services.TECHCRUNCH.COM
24 JunGoogle releases new privacy controls for activity history, personalizationGoogle is rolling out new privacy controls for Search services and Google Play, giving you more control over saved history and personalized recommendations. [...]BLEEPINGCOMPUTER.COM
24 JunAttackers Hit Cisco SD-WAN Flaw 2 Months Before DisclosureResearchers believe rogue peering was used to connect to the victim's SD-WAN devices to gain admin privileges and root-level access.DARKREADING.COM
23 JunOpenAI Expands Daybreak With GPT-5.5-Cyber to Help Defenders Patch Security FlawsOpenAI on Monday said it's releasing an improved version of its GPT‑5.5‑Cyber model to trusted defenders as part of the Daybreak initiative, the artificial intelligence (AI) company announced last month. Calling GPT‑5.5‑Cyber its "strongest model yet for finding and helping patch…THEHACKERNEWS.COM
23 JunWhatsApp VBScript Campaign Uses Fake Documents to Install ManageEngine RMM ToolDirect messages sent via WhatsApp are being used to distribute malicious Visual Basic Script (VBScript) files that lead to the installation of legitimate Remote Monitoring and Management (RMM) software. Per findings from Kaspersky, the active campaign is targeting users of WhatsA…THEHACKERNEWS.COM
23 JunFive Eyes Group Issues Urgent Call to Tackle Frontier AI ThreatsThe Five Eyes Alliance has published a rare call to action for organizations facing AI threatsINFOSECURITY-MAGAZINE.COM
23 JunGTA 6 early access is nothing but a scamNo matter what a website claims, nobody is selling legitimate GTA 6 early access. And scammers are counting on fans believing otherwise.MALWAREBYTES.COM
23 JunScattered Spider Teens Convicted of TfL Cyber-AttackTwo young British men have pleaded guilty to hacking Transport for London as part of a Scattered Spider plotINFOSECURITY-MAGAZINE.COM
23 JunAgentic AI: The Weapon That No Longer Needs a WarriorEvery weapon begins as an extension of the hand that holds it. The spear lengthened the reach of the arm. The bow sent the point flying without the throw. The rifle placed a man's death a quarter mile beyond his sight, and the aircraft carried that death across oceans. At each tu…THEHACKERNEWS.COM
23 JunHacker hijacks Brazil’s national alert system, sending “misanthropy” to millions of phonesEmergency alert systems work because people believe them. Every time one of these systems issues a false alert - whether through negligence or a deliberate attack - trust erodes. Read more in my article on the Hot for Security blog.BITDEFENDER.COM
23 JunGTA 6 Scams Emerge as Pre-Orders OpenCybercriminals launch fake GTA 6 pre-order sites offering early access for crypto paymentsINFOSECURITY-MAGAZINE.COM
23 JunWebinar: Why email security teams are drowning in alertsPhishing, BEC, and account takeover attacks continue to overwhelm security teams with alerts and investigations. This webinar explores how behavioral AI can help automate detection and response workflows, reducing alert fatigue and improving operational efficiency. [...]BLEEPINGCOMPUTER.COM
23 JunMeta pauses controversial employee-tracking program after security reviewMeta has paused its controversial employee-tracking program. Unfortunately, employee privacy wasn't what stopped it.MALWAREBYTES.COM
23 JunSocGholish Takedown Highlights Malicious TDS ThreatsSocGholish uses traffic distribution systems (TDSs) to provide initial access into victims' networks for cybercrime groups such as the notorious Evil Corp.DARKREADING.COM
23 JunAI Threat Readiness Pillar 4: Detect and contain threats in real-timeYour guide to operationalizing AI-powered threat detection and response with Wiz to stay ahead of AI-driven attackers.WIZ.IO
23 JunLookalike npm Package Hides a Multi-Stage Windows RATJFrog found an npm package impersonating postcss-selector-parser to drop a multi-stage Windows RATINFOSECURITY-MAGAZINE.COM
23 JunOpenAI Expands Daybreak to Help Defenders Patch FlawsOpenAI expanded Daybreak with a full GPT-5.5-Cyber release to help defenders patch software flawsINFOSECURITY-MAGAZINE.COM
23 JunCompromise kids online safety bill unveiled by House leaders, with key omissionThe so-called duty of care provision that was excluded would have mandated that online platforms take reasonable measures to prevent specific harms such as suicidal ideation, eating disorders and cyberbullying by changing algorithm and design features.THERECORD.MEDIA
23 JunScattered Spider members plead guilty to hacking Transport for LondonTwo members of the 'Scattered Spider' cybercrime group pleaded guilty to hacking the Transport for London (TfL) systems in 2024. [...]BLEEPINGCOMPUTER.COM
23 JunFake AI Agent Skill Passed Security Scans and Reportedly Reached 26,000 AgentsSecurity firm AIR built a fake AI agent skill, pushed it through a popular skill marketplace and an Instagram ad, and says it reached roughly 26,000 agents, including some on corporate accounts. Every skill security scanner the firm tested it against marked it safe. The…THEHACKERNEWS.COM
23 JunFive Eyes agencies sound alarm about AI’s threat to cybersecurity"The timeline is not years, it is months,” the nations of the Five Eyes intelligence alliance said in a joint alert about the cybersecurity concerns of artificial intelligence.THERECORD.MEDIA
23 JunFeds seize alleged cyber-scam infrastructure connected to Southeast Asian companyThe Department of Justice announced the “seizure of a cloud computing account” used by subsidiaries of the Huione Group, a conglomerate severed from the U.S. financial system last year.THERECORD.MEDIA
23 JunFortiBleed Targeted FortiGate Firewalls in 110 Million-Credential Harvesting OperationA Russian-speaking initial access broker (IAB) driven by financial gain is assessed to be behind a large-scale credential-harvesting operation known as FortiBleed that has targeted over 430,000 FortiGate firewalls globally. The campaign, active since February 2026, involves colle…THEHACKERNEWS.COM
23 JunWindows 11 KB5095093 update rolls out new Point-in-Time restore featureMicrosoft has released the KB5095093 preview cumulative update for Windows 11 24H2 and 25H2, which fixes numerous bugs and begins rolling out new features, including the new Point-in-Time restore feature. [...]BLEEPINGCOMPUTER.COM
22 JunA VBScript campaign distributed through WhatsApp deploying RMM softwareA Kaspersky researcher analyzes a global malicious campaign that distributes VBS scripts via WhatsApp delivering a UEMS RMM agent through a multi-stage infection chain.SECURELIST.COM
22 JunAI is transforming enterprise data risk. Here’s how security leaders are responding.New research from 1,700 security leaders reveals 3 imperatives for securing AI adoption.CYBERSECURITYDIVE.COM
22 Jun3 ways AI is transforming security operations - and where it delivers real impactSecurity operations (SecOps) teams have long been exhorted to “work smarter, not harder,” but they need the right tools and processes to actually achieve that aim.CYBERSECURITYDIVE.COM
22 JunWorld Cup Scams Are Getting Harder to SpotFrom fake tickets to cloned websites, AI is magnifying World Cup scams. Can fans distinguish between what’s real and what’s not?WIRED.COM
22 JunUK Information Commissioner Resigns After Workplace InvestigationThe UK’s data protection regulator the information commissioner has resigned after his position became “untenable”INFOSECURITY-MAGAZINE.COM
22 JunFive Eyes cyber security agencies statement on the AI shift in cyber risk: why leaders must act nowCYBER.GC.CA
22 JunStop Your Legacy Infrastructure from Hijacking Your AI AgentsEarlier this month, I spoke at the Gartner Security & Risk Management Summit about a blind spot most security programs are still not accounting for - how attackers are circumventing AI security programs by using legacy infrastructure to hijack AI agents. AI adoption is moving…THEHACKERNEWS.COM
22 JunGoogle Sets Sept. 30 Deadline for Android Developer Verification in Four CountriesGoogle has set September 30, 2026, as the day it begins enforcing Android developer verification in the first four countries, and the major device-maker app stores are in from the start. On that date, certified Android phones in Brazil, Indonesia, Singapore, and Thailan…THEHACKERNEWS.COM
22 JunDocument delivery scams: What are they and what’s their goal?A seemingly official voicemail turned out to be a scam. Learn how document delivery scams work and what to do if you receive one.MALWAREBYTES.COM
22 JunA Glimpse into the “Search Your Target” Market for Stolen CredentialsAttackers no longer need to sift through massive credential dumps. They can pay others to do it for them. Flare explores how an emerging underground market searches stolen credential databases for specific companies, domains, and accounts. [...]BLEEPINGCOMPUTER.COM
22 JunCloud-native Security for your Windows environment: Announcing the Wiz Runtime Sensor for WindowsSecure your Windows fleet without sacrificing performance. Wiz pairs real-time threat detection with a memory-safe architecture that scales efficiently to protect your essential cloud infrastructure.WIZ.IO
22 JunCrypto Heist Fueled by Elaborate Fake Reputation-Boosting CampaignAttackers are using multiple online channels — including GitHub, YouTube, and VirusTotal — to build an illusion of trust to spread a cross-platform clipboard hijacker.DARKREADING.COM
22 JunMicrosoft says Windows 11 26H2 is coming soon, details upgrade processMicrosoft has confirmed that Windows 11 version 26H2 will be the next feature update and that devices running Windows 11 24H2 and 25H2 will be able to upgrade using a small enablement package. [...]BLEEPINGCOMPUTER.COM
22 JunAnthropic says Claude may want to see your IDClaude's chatbot may ask to verify your age and identity "in certain circumstances," such as with a passport or driver's license, according to a privacy policy change.TECHCRUNCH.COM
21 JunA Critical Deadline Is Approaching for Windows and Linux SecurityThe cryptographic keys that secure your computer's boot sequence will start to expire on June 24. Here's what that means for you.WIRED.COM
20 JunHackers Claim to Leak Stolen Madison Square Garden DataPlus: Gay bars in San Francisco using face scanners, France quits Palantir, Apple plans to change its private email and more.WIRED.COM
20 JunSignal’s Meredith Whittaker wants you to remember that AI chatbots ‘are not your friends’"These are not your friends. These are not conscious beings. These are not sentient interlocutors.”TECHCRUNCH.COM
19 JunForget Data Leakage: Shadow AI's Real Threat Is Access ControlThe first wave of enterprise AI concern was straightforward. It was simply employees pasting sensitive data into public AI tools. Security teams responded with usage policies, domain blocks, and data loss prevention rules. That response made sense at the time. It doesn't fit the …THEHACKERNEWS.COM
19 JunFrom PGP to Mythos: a brief history of export controls that didn’t stop anyoneFor the last 30 years, stopping the flow of cybersecurity-related software has proven to be ineffective. It's unclear why it would work now with Anthropic’s cybersecurity model Mythos.TECHCRUNCH.COM
19 JunApple’s Hide My Email tweak leaves privacy fans fumingApple has long marketed itself as the privacy-first tech giant. So why is it making a change to Hide My Email that will make it easier for websites to block anonymous sign-ups - and harder for you to stay private online? Read more in my article on the Hot for Security blog.BITDEFENDER.COM
19 JunImposter scams cost Americans $3.5 billion in 2025 – and it’s getting worseSomeone is pretending to be your bank, your government, or your local planning office. And according to the FTC, they're making billions doing it. Read more in my article on the Fortra blog.FORTRA.COM
19 JunAzure AD Graph Activity Logs: Ingestion and threat detection to close the visibility gapAzure AD Graph Activity Logs land in Elastic with full ECS parsing. Detect ROADrecon and AADInternals enumeration with ready-to-use detection rules.ELASTIC.CO
19 JunUK's information commissioner resigns over ‘inappropriate humour’Writing on LinkedIn, Edwards said that while he has not agreed with how the investigation into him has been conducted, he has come to accept that his position “has become untenable.”THERECORD.MEDIA
19 JunConfidence Lacks in Threat Detection Across Non-Email Channels like Slack and TeamsHalf of cybersecurity leaders lack confidence in detecting threats on Slack, Teams and other non-email platforms, despite growing attacker focusINFOSECURITY-MAGAZINE.COM
19 JunEvery AI Agent Is an Identity. Most Organizations Don't Treat Them That WayAI agents can access data, trigger workflows, deploy code, and interact with critical business systems, often with little oversight. Token Security breaks down why AI agents are becoming a new identity and governance challenge. [...]BLEEPINGCOMPUTER.COM
19 JunMicrosoft: June 2026 Windows updates break Recycle Bin promptsMicrosoft has confirmed a confusing Windows bug that causes different filenames to appear in the confirmation dialog when deleting a file from the Recycle Bin. [...]BLEEPINGCOMPUTER.COM
19 JunNY man charged after harassing college student with AI-generated nudesA New York man faces cyberstalking charges after allegedly sharing AI-generated nude images and fabricated racist messages using fake social media profiles to harass a Georgia college student. [...]BLEEPINGCOMPUTER.COM
19 JunStressors, AI Forcing Changes to Cybersecurity TeamsAs threats proliferate and AI complicates cybersecurity, CISOs say the job is getting harder, but more companies still want cybersecurity expertise, if even on a part-time basis.DARKREADING.COM
18 JunA world without Section 702.This week, Dave and Ben take a look at a recent ruling against Google by a German court holding them liable for any false statements generated by its AI Overviews. Additionally, the two examine how Congress failed to extend Section 702.THECYBERWIRE.COM
18 JunThe UK Will Scan Asylum-Seekers’ Faces for Age Checks—Despite Knowing the Tech Is FlawedInternal Home Office tests of age-verification technology show the risks of life-altering errors. It’s moving forward anyway.WIRED.COM
18 JunEU Gets a Head Start in Developing 6G Network Security"Shield-6G" will combine AI threat detection, digital twins, honeypots, and more, to help carriers protect 6G networks against the threats of tomorrow.DARKREADING.COM
18 JunCybercrime Surges in APAC as Digitalization Takes HoldInterpol claims cybercrime accounts for third of crime in over half of Asia and South Pacific countriesINFOSECURITY-MAGAZINE.COM
18 JunHow to Watch the Knicks Parade on NYC Traffic Surveillance CamerasArtist Morry Kolman will be livestreaming feeds of the NBA champions’ ticker-tape parade from NYC’s traffic cameras—and this time, the city’s Department of Transportation isn’t demanding he stop.WIRED.COM
18 JunScripting the disassembler: Local agentic reverse engineering through vbdec’s live COM object modelCisco Talos detailed a new approach to reverse engineering that pairs local AI agents with traditional analysis tools like the VB6 disassembler vbdec. Instead of awkwardly bolting AI onto the software, vbdec exposes its parsed data through a live COM interface.TALOSINTELLIGENCE.COM
18 JunCybercriminals Are Worried About AI Taking Their Jobs TooAnalysis of chatter on underground forums by Sophos finds that hackers fear AI could take work away from themINFOSECURITY-MAGAZINE.COM
18 JunTelegram admits it couldn't police exam-leak channels, India tells courtIndia's government has told the Delhi High Court that Telegram was warned about two weeks before it was blocked, and that the platform admitted it could not proactively detect the channels selling leaked exam papers. Telegram says it cooperated and the ban is unlawful. [...]BLEEPINGCOMPUTER.COM
18 JunGet Out of Security Debt by Tackling the Exposure ProblemTeams digging out of security debt need to answer only two simple questions: Which vulnerabilities in our systems are exposed, and how long should they stay that way?DARKREADING.COM
18 JunThe President’s Executive Actions on AI Have a Lot to Say on CybersecurityThe spotlight has been on frontier models, but the goals are more far reaching -- including supercharging cyber defense and remediating risk at machine speedWIZ.IO
18 Jun5 reasons Microsoft 365 backup isn’t enough for business data protectionMicrosoft 365 helps keep services running, but protecting and recovering business data remains your responsibility. Acronis breaks down five gaps organizations should consider when evaluating Microsoft 365 data protection. [...]BLEEPINGCOMPUTER.COM
18 JunFake GitHub Stars and AI Videos Mask a Crypto ClipperA Rust crypto clipper hides behind fake GitHub stars and AI-narrated YouTube videosINFOSECURITY-MAGAZINE.COM
18 JunSpring 2026 SOC 1 and 2 reports are now available in OSCAL formatAmazon Web Services (AWS) is excited to release the Spring 2026 System and Organization Controls (SOC) 1 and 2 reports in machine-readable OSCAL format alongside the PDF version of the reports. The reports cover 188 services over the 12-month period from April 1, 2025 to March 31…AWS.AMAZON.COM
18 JunCIS Benchmarks June 2026 UpdateThe following CIS Benchmarks and CIS Build Kits have been updated or recently released. We've highlighted the major updates below.CISECURITY.ORG
18 JunIntelligence Insights: June 2026ClearFake is the clear-cut number one again and Kali365 debuts in this month’s edition of Intelligence InsightsREDCANARY.COM
18 JunAccelerate security investigations with Kiro CLIWhen a security event occurs in your Amazon Web Services (AWS) environment, rapid response is critical. However security teams often struggle with time-consuming, manual processes that slow down investigations. Analysts must recall complex AWS Command Line Interface (AWS CLI) syn…AWS.AMAZON.COM
18 JunUS regulators are increasing scrutiny over financial AI use.Britain bans social media for kids.THECYBERWIRE.COM
18 JunHow the Peter Thiel-Linked Dialog Club Secretly Ranks Its MembersLeaked files show the invite-only network grades members by their money and fame, shaping who’s in, who’s out, and who pays.WIRED.COM
17 JunWeekly Threat Bulletin – June 17th, 2026These are the top threats you should know about this week.F5.COM
17 JunUK Social Media Ban for Minors Has Privacy Experts WorriedThe UK will ban adolescents under 16 years old from user-to-user social-media platforms, despite age-verification issues and privacy concerns.DARKREADING.COM
17 JunStaffing Is Top SOC Challenge Even as AI Proliferates, Says SANSSANS Institute study finds few SOCs have built AI into defined workflows, despite widespread adoptionINFOSECURITY-MAGAZINE.COM
17 JunFifteen JetBrains Marketplace Plugins Found Stealing API KeysAikido Security has discovered at least 15 IDE plugins on the JetBrains MarketplaceINFOSECURITY-MAGAZINE.COM
17 Jun24 billion stolen records found in giant data dump. Check if you’re affectedResearchers found an exposed collection of 24 billion stolen records, including usernames, passwords, and other sensitive account data.MALWAREBYTES.COM
17 JunMicrosoft confirms Office apps launch issues after June updatesMicrosoft is investigating a new issue preventing third-party applications from launching Microsoft Office applications or opening documents on up-to-date Windows systems. [...]BLEEPINGCOMPUTER.COM
17 JunAdversarial Exposure Validation Turns Security Visibility into Confident PrioritizationFor security teams, the findings never stop, but confidence in knowing which ones matter is becoming harder to maintain. The problem is no longer visibility. It's validation. Security teams must decide which findings warrant action while operating under constant pressure and inco…THEHACKERNEWS.COM
17 JunServerless Phishing Kit on GitHub Targets Mexican BanksGitBait phishing kit abuses GitHub Pages and the SheetBest API to steal Mexican banking credentialsINFOSECURITY-MAGAZINE.COM
17 JunSensitive Enterprise Data Uploads to AI Models Double in a YearThe rise of AI-assistants and applications in the enterprise has seen a 93% increase in employees attempting to upload sensitive data, bringing security challengesINFOSECURITY-MAGAZINE.COM
17 JunIndia's Telegram ban hit the UAE too. Here's how to get around itIndia has banned Telegram until June 22 after the app was used to circulate leaked exam papers. CEO Pavel Durov accuses telecom Reliance of BGP hijacking that disrupted the app as far away as the UAE. Here's what happened, and how to get around the block with an MTProto proxy. [.…BLEEPINGCOMPUTER.COM
17 JunWhy Account Takeovers Are Rising and How to Stop ThemAccount takeovers are rising as attackers bypass traditional defenses through phishing, session hijacking, and MFA fatigue. Specops Software explores how device trust and continuous verification help reduce account takeover risk. [...]BLEEPINGCOMPUTER.COM
17 JunThe browser blind spot: Why your security tool may not be blocking what you think it is, (Wed, Jun 17th)[This is a guest diary submitted by Varun Murdula]
ISC.SANS.EDU
17 JunIntroducing AWS Continuum: Security at machine speedWhat we believe We’ve been thinking deeply about enterprise security. The operating model that served us for the past decade (collect telemetry, store it, query it, build dashboards to watch it) is no longer keeping pace. We need to shift to the new world: telemetry, context, rea…AWS.AMAZON.COM
17 JunFortiBleed leak exposes Fortinet VPN credentials for 73,000 devices.A newly discovered data leak dubbed "FortiBleed" has exposed what appears to be a collection of Fortinet and FortiGate VPN credentials for 73,932 firewall URLs at organizations worldwide. [...]BLEEPINGCOMPUTER.COM
17 JunThe Red Agent POV: How it Reasoned its Way to SSRFPart 1: How the Red Agent uncovered a multi-step attack chain allowing SSRF-to-Local-File-Read on GCP Cloud RunWIZ.IO
17 JunJunior Hacker Used Tailscale and OpenSSH to Keep Access After His C2 Went OfflineA French-speaking attacker broke into a small French automotive business, planted a keylogger, and stole banking and email credentials. Ordinary stuff, until one move near the end. Before his command-and-control server went dark, he installed OpenSSH and Tailscale on a victim's m…THEHACKERNEWS.COM
17 JunThe dual-use dilemma: Rethinking detection for remote access tool abuseA comprehensive guide to the most commonly abused RMM tools, including technical guidance for detection and preventionREDCANARY.COM
17 JunGoogle to use UK and EU user IP addresses for ad personalizationFrom August 3, 2026, Google will use IP addresses from UK, EEA and Switzerland users for ad measurement and personalization. It lands as the ICO weighs new consent rules, and years after Google itself called using such signals to identify devices "wrong." [...]BLEEPINGCOMPUTER.COM
17 JunLeak confirms OpenAI is testing a ChatGPT for Science subscriptionOpenAI appears to be testing a new subscription and experience for science use cases, but it's unclear if it'll be available to everyone regardless of their background. [...]BLEEPINGCOMPUTER.COM
16 JunUK to ban social media access for children under 16The ban will apply to all “user-to-user platforms, whose purpose is to enable social interaction and which allow users to post material, alongside algorithms,” according to a press release from the government’s Department for Science, Innovation and Technology.THERECORD.MEDIA
16 JunFBI Warns Courier Cash Pickups Are Driving Crypto ScamsThe FBI claims couriers are being used to circumvent bank transfers in crypto investment schemesINFOSECURITY-MAGAZINE.COM
16 JunDeepfake posting sites depicting famous women taken down by fedsThanks to Uncle Sam, anyone trying to find nonconsensual intimate deepfakes on CFake.com and SOCFake.com will be disappointed.MALWAREBYTES.COM
16 JunIndia orders temporary ban on Telegram over exam fraud concernsThe restrictions include a nationwide ban on Telegram until June 22 and a requirement to disable the app's message editing feature.TECHCRUNCH.COM
16 JunOver Two-Thirds of Security Pros Say Cyber Is Getting HarderISSA study finds most security professionals feel challenged by colleagues’ involvement in cyberINFOSECURITY-MAGAZINE.COM
16 Jun“Free World Cup stream” sites are serving scams, not footballWe found dozens of fake World Cup streaming sites using football as bait to funnel visitors through a malicious advertising network.MALWAREBYTES.COM
16 JunCardiac patients’ medical data stolen and held to ransomCardiac monitoring provider iRhythm has been hit by a data theft followed by an extortion attempt.MALWAREBYTES.COM
16 JunFTC warns of record $3.5 billion losses to imposter scams in 2025The U.S. Federal Trade Commission (FTC) warned that Americans lost $3.5 billion to imposter scams in 2025, with reported losses nearly tripling since 2020. [...]BLEEPINGCOMPUTER.COM
16 Jun‘Dangerous’ AI Models Are Coming No Matter WhatThe US government crackdown on Anthropic’s Claude Fable 5 and Mythos 5 hides a glaring truth: AI models with advanced hacking capabilities will soon be the norm.WIRED.COM
16 JunBug in FIFA World Cup internal system gave anyone ability to modify TV streamA security researcher said a flaw in FIFA’s online platforms allowed her to access several internal systems, including one that could have allowed her to take control of the TV stream of every World Cup match.TECHCRUNCH.COM
16 JunLeak Exposes Members of Peter Thiel’s Secretive ‘Dialog’ SocietyMore than 200 of the world's elites registered for a retreat whose agenda runs from panels on cult-building and sex to prepping for World War III. An associated app offers matchmaking.WIRED.COM
16 JunMalicious JetBrains Marketplace plugins steal AI API keys from developersAt least 15 malicious plugins found on the JetBrains Marketplace were designed to steal AI API keys from developers. [...]BLEEPINGCOMPUTER.COM
16 JunSecurity Community Slams US Ban on Exporting Mythos, FableAn open letter signed by dozens of security experts asked the government to reverse export restrictions on Anthropic's Claude Fable 5 and Mythos 5 models.DARKREADING.COM
16 JunApple plans to change its Hide My Email privacy feature that could make it less effectiveIn the coming weeks, Apple will move anonymously generated emails addresses to a different domain.TECHCRUNCH.COM
15 JunThe Onboarding Password Mistake That Creates Unnecessary RiskEmployee onboarding is a busy time for IT teams. New starters need devices, accounts, access permissions, and passwords, all delivered within a tight timeframe. That usually means sharing a temporary "first-day" password so employees can access systems for the first time. The iss…THEHACKERNEWS.COM
15 Jun152 Chrome Wallpaper Extensions with 105K Installs Linked to Adware and Fake TrafficCybersecurity researchers have discovered a network of 152 Google Chrome extensions that act as new tab live wallpaper add-ons to distribute a potentially unwanted program (PUP) family. The cluster spans 38 separate Chrome Web Store publisher accounts and three brand backends: ta…THEHACKERNEWS.COM
15 JunCybersecurity vets protest ‘dangerous’ US government ban on Anthropic’s most powerful modelsA group made up of dozens of cybersecurity experts urged the White House to remove export-control restrictions on Anthropic’s Fable and Mythos models, arguing that the order is going to limit the ability of cybersecurity defenders to secure their software and products.TECHCRUNCH.COM
15 JunAs AI agents become employees, NewCore emerges with $66M to give them identitiesNewCore argues the next challenge in enterprise security will be managing AI agents, not people.TECHCRUNCH.COM
15 JunClaude Fable 5 and Mythos 5 “abruptly disabled” after US gov. banAnthropic has been ordered by the US government to cut off its newest Claude Fable 5 and Mythos 5 models for fear of abuse.MALWAREBYTES.COM
15 JunThe fable ends before it begins.Anthropic pulls Fable 5. OpenAI faces a multistate probe. Handala targets a California water utility. ShinyHunters claims another victim. The FBI and Google take down a major phishing platform. The latest cybersecurity business news. Our guest is Bogdan Botezatu, Senior Director,…THECYBERWIRE.COM
15 JunFinland brings charges against cargo ship officers for cutting submarine cablesAccording to the deputy prosecutor general, the ship’s officers have now been charged with “having damaged two subsea telecommunications cables and of having attempted to damage a total of eight other subsea connections.”THERECORD.MEDIA
15 JunMeta Tapped a Pentagon Supplier to Prototype Face Recognition for Its GlassesRank One, whose board includes a former CIA deputy director and a former FBI science chief, supplied face recognition to Meta for internal development of its smart glasses app.WIRED.COM
15 JunUK Government Finds 400+ Vulnerabilities in AI HackathonsGovernment departments find hundreds of vulnerabilities after testing frontier modelsINFOSECURITY-MAGAZINE.COM
15 JunDOJ seizes CFAKE, SOCFAKE deepfake nude sites under TAKE IT DOWN ActThe U.S. Department of Justice announced Friday that it has seized the CFAKE.com and SOCFAKE.com websites, which allegedly hosted nonconsensual AI-generated nude images and videos of women, in what appears to be the first publicly announced domain seizure under the TAKE IT DOWN A…BLEEPINGCOMPUTER.COM
15 JunFBI: Fraudsters use couriers to steal money in crypto scamsThe U.S. Federal Bureau of Investigation (FBI) warned that criminals are using couriers to collect money from victims of cryptocurrency investment scams, also known as pig butchering or romance baiting. [...]BLEEPINGCOMPUTER.COM
15 JunVibe coders are gonna vibe code: How CISOs are tackling code sprawlEmployees are increasingly building automations, agents, and apps with AI tools outside traditional security oversight. Tines explores how CISOs are handling AI-driven code sprawl, shadow tooling, and governance challenges. [...]BLEEPINGCOMPUTER.COM
15 JunWebinar: How behavioral AI stops phishing and account takeoversModern phishing, BEC, and account takeover attacks increasingly bypass traditional email defenses and create operational strain for security teams. This webinar explores how behavioral AI can help automate detection, investigation, and remediation to reduce alert fatigue and acce…BLEEPINGCOMPUTER.COM
15 JunCopilot 'SearchLeak' Attack Allows 1-Click Data TheftThe critical, three-stage attack is now patched, but it's part of a new group of AI prompt-injection issues that use hidden URLs and other variables.DARKREADING.COM
15 JunMost CISOs Report Pressure to Bury Bad Security NewsExecutive leaders may not be saying it aloud, but business objectives and priorities don't always promote timely disclosures.DARKREADING.COM
15 JunUS Cracks Down on Anthropic AI Models Amid Abuse ConcernsAnthropic abruptly suspended all access to Fable 5 and Mythos 5 after receiving an export control directive that banned foreign nationals from using the technology.DARKREADING.COM
14 JunFBI disrupts massive AI-powered phishing service using a million URLsIn a coordinated effort, the FBI, working with Google and Black Lotus Labs, has dismantled a massive Chinese phishing-as-a-service operation called Outsider Enterprise with thousands of phishing websites used to steal credit card data and passwords. [...]BLEEPINGCOMPUTER.COM
14 JunBelarus-linked hackers target Gmail accounts of Polish public figures and their familiesPoland has warned that Ghostwriter, the Belarus-linked hacker group, has expanded its phishing operations to target personal Gmail accounts belonging to senior public figures and their relatives.THERECORD.MEDIA
13 JunGoogle Sues Chinese Smishing Network Accused of Using Gemini AI in PhishingGoogle on Friday said it's pursuing legal action against a Chinese cybercrime network, accusing it of using its Gemini artificial intelligence (AI) agent to send phishing text messages targeting Americans. The network is said to be behind the development and management of a phish…THEHACKERNEWS.COM
13 JunU.S. Orders Anthropic to Suspend Fable 5 and Mythos 5 Access for Foreign NationalsAnthropic said on Friday it will "abruptly disable" its most advanced artificial intelligence (AI) models, Claude Fable 5 and Mythos 5, for all users after the U.S. government ordered it to suspend access to the models for foreign nationals, whether inside or outside the U.S., ci…THEHACKERNEWS.COM
13 JunUS Gov asks Anthropic to ban 'foreign national' access to Fable, MythosThe US government has ordered Anthropic to block all foreign nationals from accessing Fable 5 and Mythos 5, forcing the company to suspend both models worldwide. Anthropic is complying but disputes the basis, calling the cited jailbreak narrow and the capability widely available …BLEEPINGCOMPUTER.COM
12 JunPhishing Attack Volume Down 20%, but Risk Still RisingHackers are valuing quality over quantity, using AI to upgrade their phishing attacks rather than multiplying them.DARKREADING.COM
12 JunFake verification pages are stealing Steam accounts from playersA convincing fake FACEIT verification page is stealing Steam accounts by using a fake login window that looks completely legitimate.MALWAREBYTES.COM
12 JunOver 80% of Sports Organizations Targeted by Hackers in the Last YearAs the FIFA World Cup 2026 kicks off, a new Darktrace report warns that sports teams and bodies are a major target for cyber criminalsINFOSECURITY-MAGAZINE.COM
12 JunUS surveillance law to expire for first time after lawmakers reject Trump’s controversial pick to lead spy agenciesThe spy law known as Section 702, which authorizes the NSA and FBI's warrantless surveillance, will all but certainly expire on Friday for the first time.TECHCRUNCH.COM
12 JunMicrosoft fixes Windows update failures linked to WUSA installerMicrosoft has fixed a known issue that caused Windows updates released since May 2025 to fail when installed via the Windows Update Standalone Installer (WUSA) from a network share. [...]BLEEPINGCOMPUTER.COM
12 JunStolen iPhones could soon be worth a lot less to thievesApple and the Met Police are working together to make stolen iPhones harder to reset, resell, and profit from.MALWAREBYTES.COM
12 JunEarly Warning Signs of Supply-Chain Attacks Live in the Dark WebGitHub access sales, leaked repositories, and stolen API keys can all become supply-chain attack footholds. Flare explores how underground forums expose early signals tied to software supply-chain risk. [...]BLEEPINGCOMPUTER.COM
12 JunClaude Fable 5 Doesn't Change the Mythos Security StoryStay cool: Mythos 5 is an upgrade over Mythos Preview while Fable 5 is Mythos "made safe for general use," Anthropic explained.DARKREADING.COM
12 JunGoogle sues alleged Chinese cybercrime operation that used AI to send scam textsThe tech giant said a group called "Outsider Enterprise" used AI to scam hundreds of thousands of victims, sending 2.5 million text messages over a span of two weeks.TECHCRUNCH.COM
12 JunMajor US surveillance program poised to lapse after legislative deadlockIt is the first lapse of the spy program, known as Section 702 of the Foreign Intelligence Surveillance Act (FISA), since it was passed into law in 2008.THERECORD.MEDIA
12 JunPrivacy own-goal: World Cup blunder leaks Lionel Messi’s passport detailsArgentina's World Cup squad had their passport numbers leaked before a ball was kicked - not by hackers, but by someone who failed to redact a document properly. document. It's a mistake that has been made many times in the past... Read more in my article on the Hot for Security …BITDEFENDER.COM
11 JunNew “Agentjacking” Attacks Could Hijack AI Coding AgentsTenet Security researchers reveal how new “agentjacking” attacks could trick coding agents into executing arbitrary codeINFOSECURITY-MAGAZINE.COM
11 JunChildren’s phones must block nude images by September, UK saysApple and Google have three months to block nude images on children's phones. They're not allowed to collect any data while they do it.MALWAREBYTES.COM
11 JunData of 2.4 million VRChat users stolenWe explain what data was exposed, the potential risks, and the steps you should take now.MALWAREBYTES.COM
11 JunInterpol Dismantles SniperDz Phishing-as-a-Service PlatformNew revelations by Group-IB expose the full scale of the decade-old SniperDz phishing operationINFOSECURITY-MAGAZINE.COM
11 JunLABScon25 Replay | Keynote: Steps to an Ecology of CyberDecades of piling complexity onto non-standardized stacks have left security unsteerable. Juan Andrés Guerrero-Saade makes the case for a new approach.SENTINELONE.COM
11 JunWhy AI-driven threats are exposing the limits of MSP security stacksAI-driven attacks are exposing the limits of fragmented MSP security stacks and slow response workflows. Kaseya breaks down why integrated security, automation, and recovery are becoming essential. [...]BLEEPINGCOMPUTER.COM
11 JunHow threat hunting evolves at scaleWe offer a practical roadmap for evolving informal, ad hoc threat hunting practices into a mature, scalable programREDCANARY.COM
11 JunGoogle can be liable for false AI Overviews, court rules"AI can make mistakes" isn't a good enough legal defense for defamatory or incorrect AI Overviews, a German court has ruled.MALWAREBYTES.COM
11 JunSegmentation Works for OT If Operators Are Paying AttentionOperational technology security remains as difficult as ever, with even the best practice recommendation falling short.DARKREADING.COM
11 JunNew Attacks Trick OpenClaw AI Agent Into Running Code and Leaking SecretsTwo security teams have shown, in separate research published this week, that OpenClaw, the popular self-hosted AI agent, can be driven to run attacker-controlled code or hand over sensitive data through ordinary-looking inputs. Imperva buried instructions inside shared contacts,…THEHACKERNEWS.COM
11 JunA tale of two erasIn this week’s newsletter, Amy reminisces on the tech toys of their childhood, inspired by a hilarious lesson about why your digital privacy shouldn't be left on an open channel.TALOSINTELLIGENCE.COM
11 JunGrok Is Still Hosting Sexualized Deepfakes of Famous WomenA WIRED investigation found dozens of “nudified” deepfake images and videos on Grok's website, including nonconsensual depictions of celebrities and at least one prominent US politician.WIRED.COM
11 JunNY State Congress passes new bills focused on AI and consumer protections.Meta files a complaint against NSO Group.THECYBERWIRE.COM
10 JunWeekly Threat Bulletin – June 10th, 2026These are the top threats you should know about this week.F5.COM
10 JunIvanti: Max severity Sentry flaw allows code execution as rootIvanti has patched two critical vulnerabilities in its Sentry secure mobile gateway solution, including a maximum-severity flaw that enables remote attackers to execute code with root privileges. [...]BLEEPINGCOMPUTER.COM
10 JunAnthropic Releases Claude Fable 5, Its Most Powerful AI Yet, With Cyber SafeguardsOn June 9, Anthropic released Claude Fable 5, the most capable model it has ever made, generally available. It also did something unusual: it shipped one model as two products, split not by capability but by a layer of safety classifiers. Fable 5 goes to the public. Its twin, Cla…THEHACKERNEWS.COM
10 JunSoccer Fans, You’re Being WatchedFrom anti-drone tech to face recognition, 2026 World Cup stadiums in the US, Canada, and Mexico are subjecting fans to an array of surveillance tech. Here’s what you need to know.WIRED.COM
10 JunMapping Every Flock License Plate Reader Near US World Cup StadiumsMost US World Cup stadiums are surrounded by surveillance cameras. Want to know if you’re being watched on your way to a match? These maps will help you.WIRED.COM
10 JunAmnesty International Warns That World Cup Fans Face Potential Human Rights ViolationsThe organization claims that the FIFA tournament could have impacts on the rights of local people and visiting soccer fans in all three host countries.WIRED.COM
10 JunYour Automated Pentest Looks Clean. See What It Missed in This Expert WebinarYour pentest report looks clean. That might be the problem. Run automated pentesting long enough, and the new findings start to dry up. By the third or fourth run, fewer issues appear. The report looks stable. Leadership reads "stable" as "secure." It usually isn't. The work slow…THEHACKERNEWS.COM
10 JunNew Fable 5 Is a "Mythos-Class" LLM Available to All, Anthropic AnnouncesAnthropic unveils Claude Mythos 5 and Fable 5, a restricted-access frontier AI model and guardrailed version for everyone to useINFOSECURITY-MAGAZINE.COM
10 JunMicrosoft: Some Windows PCs fail to install latest monthly updatesMicrosoft warned customers on Tuesday that they may have issues installing the latest monthly updates on some Windows devices that were upgraded to Windows 11 24H2 or 25H2. [...]BLEEPINGCOMPUTER.COM
10 JunServiceNow tells customers a bug left some of their data exposed to the internetServiceNow is used by thousands of enterprises to automate their internal processes, but says several customers had data accessed because of a security bug.TECHCRUNCH.COM
10 JunWrongful Arrest Exposes Failures in One of the Oldest Police Face-Recognition Tools in the USThe ACLU is suing two Florida police departments over the arrest of a Fort Myers man in a child-abduction case, saying officers treated a flawed face-recognition match as a near-certain ID.WIRED.COM
10 JunThe 5 Best Practices for Secure Identity VerificationAttackers are increasingly bypassing weak authentication through phishing, MFA fatigue, and service desk social engineering. Specops Software breaks down five best practices for stronger identity verification and access security. [...]BLEEPINGCOMPUTER.COM
10 JunCybersecurity researchers aren’t happy about the guardrails on Anthropic’s FableCybersecurity researchers are complaining that Anthropic's new model Fable has guardrails that are too strict for any cybersecurity work.TECHCRUNCH.COM
10 JunGitHub announces npm security changes to tackle supply-chain attacksGitHub has announced that npm v12, expected next month, will introduce several security-focused changes aimed at blocking supply-chain attacks abusing behaviors triggered by the 'npm install' command. [...]BLEEPINGCOMPUTER.COM
10 JunCyera raises $600 million in a Series G round led by Evolution Equity Partners.A Security has emerged from stealth with $37 million in funding.THECYBERWIRE.COM
10 JunTrump Risks Key Surveillance Authority Over ‘Unqualified’ Spy-Chief PickUS lawmakers are alarmed that Bill Pulte, a housing official with no intelligence experience, is poised to take charge of one of the government's most powerful surveillance tools.WIRED.COM
10 JunAI Risk Worries Insurers and Businesses AlikeAs companies adopt AI, many insurance firms are explicitly excluding AI risks, while others are forging ahead to create the right framework. What risks can firms reasonably manage?DARKREADING.COM
9 JunWhatsApp Discovers NSO Group-Linked Spearphishing AttemptsMeta’s WhatsApp demands contempt ruling after users report NSO Group-linked phishingINFOSECURITY-MAGAZINE.COM
9 JunNew FROST Attack Lets Websites Track What Sites and Apps You Open via SSD TimingA malicious website can work out which sites you visit and which apps you open, using nothing but JavaScript and the timing of your SSD. The attack, called FROST, needs no native code, no extension, and no permission prompt. You open the page, leave the tab sitting there, and it …THEHACKERNEWS.COM
9 JunThe Hidden Security Risk in Modern Networks: The Work Between ToolsOrganizations have more visibility than ever. Growing tech stacks provide greater coverage, and network security teams are increasingly adopting AI and automation to help with routine tasks and reduce manual effort. But the same challenges persist. Outages still last hours, causi…THEHACKERNEWS.COM
9 JunScammers love Meta, according to Lloyds BankFacebook, Instagram, and WhatsApp account for more than two thirds of fraud reports made by Lloyds customers.MALWAREBYTES.COM
9 JunCritical phpBB Flaw Lets Attackers Hijack Any Account with One RequestCritical phpBB authentication bypass lets attackers hijack any account with one requestINFOSECURITY-MAGAZINE.COM
9 JunMeta’s face-recognition code raises new concerns about smart glassesAs smart glasses become more capable, concerns about face recognition, covert recording, and biometric surveillance are growing.MALWAREBYTES.COM
9 JunAI Coding Adoption Hits 97% but Governance Lags BehindMost dev teams use AI coding assistants but only 30% have full governance in placeINFOSECURITY-MAGAZINE.COM
9 JunWindows 11 KB5094126 & KB5093998 cumulative updates releasedMicrosoft has released Windows 11 KB5094126 and KB5093998 cumulative updates for versions 25H2/24H2 and 23H2 to fix security vulnerabilities, bugs, and add new features. [...]BLEEPINGCOMPUTER.COM
9 JunMeta to Use Off-Site Business Data for Feed and AI PersonalizationMeta on Tuesday announced that it will use information shared by other businesses to personalize users' feed and responses from its artificial intelligence (AI) chatbot, expanding its scope beyond targeted ads. "Businesses often share information about people's activity on their …THEHACKERNEWS.COM
9 JunMicrosoft Exchange Flaw Lets Attackers Spoof Any Email Address"Ghost-Sender" uses Exchange Online or on-premises in hybrid mode with a third-party mail server or spam filter to achieve this level of spoofing.DARKREADING.COM
9 JunAnthropic rolls out Claude Fable 5, but it's available for a limited timeAnthropic has begun rolling out a new model called "Fable," which is based on the same underlying model as Mythos, its most powerful AI model class. [...]BLEEPINGCOMPUTER.COM
8 JunAll the Ways Europe Is Ditching American TechnologyA WIRED timeline shows how dozens of governments, companies, and other organizations across Europe are moving, or planning to shift, away from US Big Tech.WIRED.COM
8 JunThe new risk equation: Why endpoint security is a financial imperativeCyber risk is financial risk; endpoint security in financial services is a business imperative.CYBERSECURITYDIVE.COM
8 JunInfosecurity Europe: How DSIT Protects Thousands of UK Orgs from Cyber VulnerabilitiesThe Department of Science, Innovation and Technology details how a combination of hands-on human advice and technology systems keeps government agencies safeINFOSECURITY-MAGAZINE.COM
8 JunInfosecurity Europe: Prompt Injection Remains Unsolved, OWASP Researcher WarnsAt Infosecurity Europe 2026, OWASP’s Ariel Fogel warned that prompt injection remains an “unresolved problem” within generative AI architectureINFOSECURITY-MAGAZINE.COM
8 JunIntroducing Wiz Cloud Cost: Powering Cost Management and Optimization with ContextWiz unifies cloud and AI cost visibility to help teams eliminate waste and improve spend efficiency across their AWS, Azure, and GCP environments.WIZ.IO
8 JunMassachusetts votes to pass new privacy rights bill that bans sale of precise location dataThe bill is expected to blanket ban companies and startups from selling people's precise location data across the state.TECHCRUNCH.COM
8 JunOpenAI Unveils ChatGPT Account Security ControlsOpenAI brings Lockdown Mode and Active Sessions to ChatGPT to curb prompt injection data theftINFOSECURITY-MAGAZINE.COM
8 JunReducing security operations complexity with Wazuh CloudSecurity teams are increasingly overwhelmed by alert fatigue, infrastructure maintenance, and complex hybrid environments. This article explores how Wazuh Cloud helps simplify SIEM/XDR operations through managed infrastructure, automated scaling, and AI-driven security analysis. …BLEEPINGCOMPUTER.COM
8 JunAmericans lost nearly $900 million to AI-powered scams, FBI saysDeepfakes, voice cloning, and other AI-powered scams cost Americans nearly $900 million in 2025, says the 2025 FBI Internet Crime Report.MALWAREBYTES.COM
8 JunCritical UniFi OS bug lets hackers gain root without authenticationAttackers can chain three already fixed vulnerabilities in the Ubiquiti UniFi OS server to execute remote code with root privileges and without authentication. [...]BLEEPINGCOMPUTER.COM
8 JunInvestigating suspicious AI workflows in Microsoft Entra Agent ID: Assistive agentsEntra ID agent users can send malicious content to human users via Microsoft Teams. Here’s what to look out for.REDCANARY.COM
8 JunOperationalizing AWS security: A maturity roadmapEnabling security tooling is the starting point. Making it operational—where findings drive decisions, response times are measurable, and your security posture improves week over week—is where most organizations struggle. This blog post provides a phased maturity roadmap for orga…AWS.AMAZON.COM
8 JunWhatsApp says NSO targeted users with spearfishing attacks in violation of court orderWhatsApp said it is filing a federal court contempt order against NSO for violating a permanent injunction that bars it from mounting attacks against its users.THERECORD.MEDIA
8 JunArmenia’s pro-Europe party wins election despite Russia-linked disinformationPashinyan's Civil Contract party won nearly 50% of Sunday's vote, defeating the pro-Russian Strong Armenia party led by Russian-Armenian billionaire Samvel Karapetyan, which received around 23% of the vote.THERECORD.MEDIA
8 JunMeta Deletes Face-Recognition System From Its Smart Glasses App After WIRED ReportThe code WIRED identified is gone from the latest version of Meta AI, the companion app for the company’s smart glasses. Meta won’t say why or whether it’s coming back.WIRED.COM
8 JunIran Signed a Ceasefire — Its Hackers Didn'tAn extension of the Geneva Conventions could impose restrictions on cyberwarfare under ceasefire conditions and close a major loophole in international conflict.DARKREADING.COM
8 JunSilent Ransom Group Hits US Law Firms in Escalating Extortion AttacksThe financially motivated group is combining vishing, IT impersonation, and in-person office intrusions to steal data and extort victims.DARKREADING.COM
7 JunSilent Ransom Group targets law firms with fake IT support callsThe Silent Ransom Group extortion gang is actively targeting U.S. law firms and professional services organizations in social engineering attacks that often lead to data theft within hours of initial contact, according to a new report by cybersecurity firm Mandiant. [...]BLEEPINGCOMPUTER.COM
6 JunFree Apps Are Quietly Turning Smart TVs Into Web-Scraping Proxies for AIA researcher has reverse-engineered the iOS SDK that Bright Data embeds in consumer apps and documented how it turns devices, including always-on smart TVs, into exit nodes that relay web-scraping traffic for a data business Bright Data markets heavily to the AI industry. The com…THEHACKERNEWS.COM
6 JunCrypto-Funded Chinese Peptide Labs Are BoomingPlus: Hackers use Meta’s AI bots to hack Instagram accounts, Anthropic helps NSA hackers, a decades-long GPS satellite mystery may have been solved, and more.WIRED.COM
6 JunOpenAI unveils Lockdown Mode to protect sensitive data from prompt injection attacksEven with Lockdown Mode, ChatGPT could be still vulnerable to prompt injections, but the goal is to reduce the likelihood that sensitive data gets shared in the process.TECHCRUNCH.COM
5 JunInfosecurity Europe: AI Coding Tools Need Built-In Security for Agentic Development EraOx Security field CTO, Boaz Barzel, makes the case for vibe security to tackle AI agent coding risksINFOSECURITY-MAGAZINE.COM
5 JunInfosecurity Europe: Reactive Security Is Failing Healthcare Organizations, Experts WarnA perfect storm of legacy devices, hyper connectivity and human fatigue is bad news for the healthcare sector, warns Cyber SalusINFOSECURITY-MAGAZINE.COM
5 JunAI: Threat, tool, or both?Public concern about AI is rising. We look at what's driving it, and why cybersecurity occupies a unique place in this debate.MALWAREBYTES.COM
5 JunInfosecurity Europe: OWASP Introduces Agentic AI Security Maturity FrameworkThe OWASP agentic AI security framework helps organizations assess governance maturity vs adoption and adjust governance as neededINFOSECURITY-MAGAZINE.COM
5 JunInfosecurity Europe: Practical Lessons From Lloyds' Agentic AI Security PlaybookLloyds Banking Group shared its approach for securing agentic AI workflows, with a mix of hands on experimentation and cross functional governanceINFOSECURITY-MAGAZINE.COM
5 JunOnly 10% of SOCs Say They’re Getting Excellent Value From AI. Here’s What the Second Wave Has to DeliverEighteen months ago, the AI SOC was a marketing line. Today it's a budget item. The category has crossed over from interesting to inevitable, with billions of dollars now flowing into AI-powered security operations platforms, agentic SOC tools, and AI co-pilots built into every l…THEHACKERNEWS.COM
5 JunWhat 2026 DBIR Confirms: Attacks Are Living in the BrowserPhishing, shadow AI, malicious extensions, and credential theft increasingly happen inside the browser. Keep Aware explains what the 2026 Verizon DBIR reveals about browser-layer security gaps and modern attacks. [...]BLEEPINGCOMPUTER.COM
5 JunGot a LinkedIn message from a recruiter? It might be Chinese intelligence, warn FBI and MI5If you've ever received an out-of-the-blue message via LinkedIn from a recruiter offering some well-paid consultancy work, intelligence agencies have a message for you: be very careful. Read more in my article on the Hot for Security blog.BITDEFENDER.COM
5 JunDark web Nemesis Market vendor gets 26 years for selling drugsA California man was sentenced to more than 26 years in federal prison for trafficking fentanyl and methamphetamine through Nemesis Market, one of the world's largest dark web marketplaces. [...]BLEEPINGCOMPUTER.COM
5 JunSuspicious Polyfill login prompts pop up on Toshiba, Muji websitesTech giant Toshiba and mega-retailer Muji warned visitors that suspicious sign-in screens popping up on their websites could collect credentials. [...]BLEEPINGCOMPUTER.COM
4 JunDoJ Disrupts Southeast Asia Crypto Fraud Networks, Freezes $3.8 Million in AssetsThe U.S. Department of Justice (DoJ) on Wednesday announced the results of a sweeping action undertaken by government authorities and private sector companies to combat cyber-enabled and cryptocurrency fraud targeting Americans. The "Disruption Week" operation began May 18, 2026,…THEHACKERNEWS.COM
4 JunWhatsApp, Slack Notifications Could Hijack Google Gemini on AndroidA single poisoned notification from WhatsApp, Slack, SMS, Signal, Instagram, or Messenger could have hijacked Google Gemini's voice assistant on Android and made it open a victim's connected windows, fake a message from their boss, push the phone into a Zoom call, or quietly pois…THEHACKERNEWS.COM
4 JunMicrosoft's Coreutils for Windows, (Thu, Jun 4th)I&#;x26;#;39;ve been using the GnuWin32 CoreUtils for Windows for many years now (it gives you many *nix core commands on Windows).
ISC.SANS.EDU
4 JunEnterprise Spotlight: Rethinking cloud strategy in the age of AICloud computing has reached a crossroads. The high cost and data sensitivity of AI workloads are raising the appeal of private clouds, even as neoclouds and sovereign clouds shake up the cloud provider landscape. New cyberthreats, shifting compute requirements, and management com…US.RESOURCES.CSOONLINE.COM
4 JunFlorida vs OpenAI.This week, Dave and Ben sit down to Florida's recent lawsuit against OpenAI and Sam Altman. In the suit, Florida alleges that the company placed profits over safety needs. Additionally, the two cover a story on an ad-based surveillance network.THECYBERWIRE.COM
4 JunInfosecurity Europe: Raise Security Concerns with Procurement Now, Because Quantum Can’t WaitForescout VP of security intelligence, Rik Ferguson, warns that Q-day is fast approachingINFOSECURITY-MAGAZINE.COM
4 JunMeta’s AI support bot happily handed Instagram accounts to hackersHackers convinced an AI support bot to hand over Instagram accounts by changing recovery email addresses.MALWAREBYTES.COM
4 JunTravel scams are everywhere. Here’s how to avoid themLearn how to spot travel scams, avoid risky bookings, and keep your personal information out of the wrong hands.MALWAREBYTES.COM
4 JunWinning the cyber marathon with Tony GiandomenicoTony Giandomenico, Senior Director of Product Management, joins Amy to discuss the Talos Threat Hunting launch what he's excited about for the future of cybersecurity, and, of course, his Ironman triathlons.TALOSINTELLIGENCE.COM
4 JunHypotheses, telemetry, and human judgment: Inside Cisco Talos Threat HuntingLearn how Cisco Talos Threat Hunting uses hypothesis-driven methods and multi-domain telemetry correlation to find stealthy threats operating below automated detection thresholds.TALOSINTELLIGENCE.COM
4 JunInfosecurity Europe: How Proton Fights Against Cybercriminals Using Its ServicesProton uses machine learning models to detect abuse of its services – especially email addresses used by cybercriminalsINFOSECURITY-MAGAZINE.COM
4 JunPolice dismantles fake ID marketplace used by migrant smugglersFrench and Spanish authorities took down an online marketplace selling fake identity documents to migrant smuggling rings operating within the European Union. [...]BLEEPINGCOMPUTER.COM
4 JunFive Eyes warn Chinese spies are using job sites to recruit insidersThe alert warned that Chinese intelligence officers are posing as recruiters and consultants for front companies based outside China in order to target Five Eyes government and military personnel “and anyone with access to classified or privileged information.”THERECORD.MEDIA
4 JunChinese-Speaking Actor TA4922 Widens Its Global ReachNewly named Chinese-speaking actor TA4922 expands from East Asia into Europe and AfricaINFOSECURITY-MAGAZINE.COM
4 JunMicrosoft blames unexpected Windows driver updates on caching issueOn Wednesday, Microsoft fixed an issue that caused some Windows devices to install driver updates without notice despite policies configured to prevent auto-updates. [...]BLEEPINGCOMPUTER.COM
4 JunAI Threat Readiness Pillar 1: Reduce Critical Exposures & Scan with AIDiving into the first pillar of the AI Threat Readiness Framework and how Wiz helpsWIZ.IO
4 JunClaude Code GitHub Action Flaw Let One Malicious Issue Hijack RepositoriesA security researcher found a flaw in Anthropic's Claude Code GitHub Action that let an attacker take over vulnerable public repositories running it, with nothing more than a single opened GitHub issue. Because Anthropic's own action repo used the same workflow, a working attack …THEHACKERNEWS.COM
4 JunCustomize federated sign-in with new Amazon Cognito Lambda triggerYou can use Amazon Cognito user pools to add sign-up and sign-in functionality to your web and mobile applications. You can authenticate users directly with Amazon Cognito managed accounts using passwords, passwordless flows, or custom authentication flows, or let users federate …AWS.AMAZON.COM
4 JunMeta Silently Added Face-Recognition Code for Its Smart Glasses to Millions of PhonesCode reviewed by WIRED uncovered an unreleased face-recognition system embedded in Meta’s smart glasses platform. It’s designed to identify people via biometric data stored on users’ phones.WIRED.COM
4 JunReporting from Vegas: Networking, AI, and good boysJoe’s on-the-ground report from Cisco Live U.S. is here, complete with therapy dog pictures and tips on handling conference overstimulation.TALOSINTELLIGENCE.COM
4 JunFTC considers setting aside or modifying $150 million privacy penalty against XTwitter, renamed X in 2023, filed a petition saying that the settlement terms are unfair because the order was issued against a company that “no longer exists,” the workers responsible for the scheme no longer work for X and the firm has since established a “world class” privacy …THERECORD.MEDIA
4 JunFiltr is a new privacy tool that blocks ads in almost every iPhone and Mac appThis popular ad blocker app for iPhones, iPads, and Macs can now block ads from loading inside apps, including web browsers, thanks to a new feature in the latest Apple software.TECHCRUNCH.COM
4 JunDefense tech, AI, and fundraising take center stage at StrictlyVC Los Angeles on June 18With just two weeks to go, StrictlyVC Los Angeles is quickly approaching. On Thursday, June 18, at The Aerospace Corporation Campus in El Segundo, investors, founders, and tech leaders will gather for an evening of conversation exploring some of the most consequential shifts taki…TECHCRUNCH.COM
4 JunAmazon Cognito unlocks advanced capabilities with next-generation infrastructureAmazon Cognito recently introduced high-throughput performance for demanding workloads, customer-managed keys for full control over data encryption at rest, and multi- Region replication for business continuity improvement. These capabilities were made possible through a next-gen…AWS.AMAZON.COM
4 JunBrave Software releases Origin for a paid, bloat-free browsing experienceBrave has announced the public release of Brave Origin, a paid minimalist version of its browser that strips out cryptocurrency, AI, rewards, and other monetization-focused features. [...]BLEEPINGCOMPUTER.COM
4 JunChina's TA4922 Expands Cybercrime Attacks GloballyOne of the world's most diverse, least-focused cybercrime groups is enlarging its footprint beyond East Asia.DARKREADING.COM
4 Jun4 Critical Threats Where Attackers Have the AdvantageGartner analysts issued a call to action to bolster defenses against several emerging critical threats, such as deepfakes and prompt injections.DARKREADING.COM
3 JunWeekly Threat Bulletin – June 3rd, 2026These are the top threats you should know about this week.F5.COM
3 JunInfosecurity Europe: AI-Powered Cybercrime Tools Surge on Dark WebHalcyon’s Cynthia Kaiser lifts the lid on the dark web market for AI cybercrime toolsINFOSECURITY-MAGAZINE.COM
3 JunInfosecurity Europe: Patch Responsibility Remains Up for Grabs as AI Unearths Decades of FlawsThe emergence of AI models capable to autonomously find and fix vulnerabilities at scale is having a significant impact on patching management, experts sayINFOSECURITY-MAGAZINE.COM
3 JunGoogle adds Android protection against AI deepfake scam callsGoogle is introducing a new Android security feature that will detect and flag phone calls in which scammers use artificial intelligence to impersonate a user's personal contacts. [...]BLEEPINGCOMPUTER.COM
3 JunAnthropic Expands Mythos Access to 150 More OrganizationsAnthropic widens Project Glasswing access to 150 more firms as patching becomes the bottleneckINFOSECURITY-MAGAZINE.COM
3 JunInfosecurity Europe: How to Get Boards to Prioritize Cyber Risk QuantificationCybersecurity leaders major companies discuss how they got support from the board on cyber riskINFOSECURITY-MAGAZINE.COM
3 JunMalicious Notifications Could Trick Google Gemini UsersA prompt injection flaw in Google Gemini's voice assistant let attackers hide malicious commands in notifications, enabling social engineering and more.DARKREADING.COM
3 JunShrinking the IAM Attack Surface through Identity Visibility and Intelligence Platforms (IVIP)The Fragmented State of Modern Enterprise Identity Enterprise IAM is approaching a breaking point. As organizations scale, identity becomes increasingly fragmented across thousands of applications, decentralized teams, machine identities, and autonomous systems. The result is Ide…THEHACKERNEWS.COM
3 JunKeep getting calls from questionable numbers? Meet Scam Number CheckScam Number Check lets you quickly check whether a number has been linked to scams before you call back, share information, or send money.MALWAREBYTES.COM
3 JunContinuing Scans for swagger.json, (Wed, Jun 3rd)Enterprise applications often still use complex standards like SOAP for web services. The big advantage of SOAP is its tight and extensive standards, which enable interoperability across an enterprise governed by web services. The disadvantage of SOAP: First, while it is de facto…ISC.SANS.EDU
3 JunWhat 345 Days of Untested Exposure Looks Like at a BankA two-week penetration test can leave roughly 345 days of real-world exposure unvalidated. Sprocket Security explores why continuous testing is becoming critical as attack surfaces constantly change. [...]BLEEPINGCOMPUTER.COM
3 JunInstagram is alerting users who were targeted by hackers during AI chatbot attacksHackers appeared to take over victims’ accounts even after Meta said it fixed its AI-powered support chatbot, which granted hackers access to victims’ accounts.TECHCRUNCH.COM
3 JunWe found this fake-invoice campaign while scammers were still building itInvoices pretending to be from Amazon, PayPal, and others reveal how criminals use fear and phone calls to steal money and devices.MALWAREBYTES.COM
3 JunxAI Asks Court to Strip Alleged Grok Deepfake Nudes Victims of AnonymityFour people suing Elon Musk's AI firm under pseudonyms due to the risks of being identified may face a difficult choice: Reveal your real names, or drop the lawsuit.WIRED.COM
3 JunThreat Hunting Case Study: FileFixFileFix bypasses Mark of the Web (MotW) protections by hijacking the Windows File Explorer address bar. Here is how to hunt for it.INTEL471.COM
3 JunAI observability platform Coralogix raises $200 million in a Series F round.Dragos has acquired Nashville-based embedded device security company Phosphorus.THECYBERWIRE.COM
3 JunNew 'HTTP/2 Bomb' DoS attack crashes web servers in under a minuteA new denial-of-service (DoS) attack dubbed HTTP/2 Bomb can be launched from a single machine to take down web servers within seconds. [...]BLEEPINGCOMPUTER.COM
3 JunCyber Insurance Rates Are Dropping, but Exclusions WidenCyber insurance coverage is slowly changing, and some policies may not provide coverage for social engineering attacks like ClickFix.DARKREADING.COM
3 JunCoding Gaffe Exposes Microsoft 365 Accounts to Widespread TakeoverA disabled security setting meant to protect authentication across Android versions of key apps like Word, PowerPoint, and Excel paved the way for attackers to steal logins and data.DARKREADING.COM
2 Jun23andMe exposed genetic information of millions, lawsuit saysWhat began with stolen passwords ended with the exposure of nearly seven million users' DNA-related data, according to California's lawsuit.MALWAREBYTES.COM
2 JunInfosecurity Europe: UK Firms Prioritize AI Threat Preparedness as Cyber Risks EvolveUK organizations are prioritizing AI-driven cybersecurity as 43% cite AI-powered attacks as their top risk, prompting significant investment in advanced threat defenseINFOSECURITY-MAGAZINE.COM
2 JunThe Weather Report that Changed History"If any blame or fault attaches to the attempt, it is mine alone." This is the end of the announcement Supreme Allied Commander General Dwight David Eisenhower had prepared in June 1944 in case the D-Day landings failed. He never had to deliver it, but the fact that he wrote it t…THECYBERWIRE.COM
2 JunHow Leading Organizations Are Turning EDR Into Operational ResilienceMost organizations now recognize that endpoint protection alone is no longer sufficient. That's why adoption of endpoint detection and response (EDR) has accelerated rapidly in recent years. Organizations understand that modern attacks move faster, evade traditional prevention co…THEHACKERNEWS.COM
2 JunWardriving assessment across Mexico: Preparing for the 2026 World CupIn the lead-up to the 2026 FIFA World Cup, Kaspersky GReAT experts conducted a wardriving assessment in Mexico City, Monterrey, and Guadalajara to evaluate Wi-Fi hotspot security configurations and potential exposure risks.SECURELIST.COM
2 JunInfosecurity Europe: Bayer Reinvents Security Awareness Training to Counter AI ThreatsBayer’s security awareness training now focuses on psychological approaches rather than technical methods for detecting social engineeringINFOSECURITY-MAGAZINE.COM
2 JunInstagram users locked out after Meta AI abused to steal accountsMultiple Instagram users had their accounts hijacked after attackers convinced Meta's AI-powered support tools that they were the legitimate owners. [...]BLEEPINGCOMPUTER.COM
2 JunWhy the browser is now the front line for AI securityAI-powered attacks and shadow AI adoption are creating new security risks inside the browser. Push Security explains why browser visibility is becoming critical for both threat detection and AI governance. [...]BLEEPINGCOMPUTER.COM
2 JunMicrosoft Exchange Online outage causes email delays, failuresMicrosoft is working to address a widespread service issue affecting the mail flow pipeline for Exchange Online customers across North America and Germany. [...]BLEEPINGCOMPUTER.COM
2 JunAndroid Is Fighting Phone Scams With a New Feature to Prove Who's CallingAvailable for Android 12 and later, the anti-scam feature is baked into Google Dialer, which sends a silent “confirmation signal” to ensure whoever's calling you is who they appear to be.WIRED.COM
2 JunThese convincing copyright notices are designed to steal Google loginsScammers use fake takedown requests, countdown timers, and spoofed sign-in screens to steal Google logins from Chrome developers.MALWAREBYTES.COM
2 JunSecuring AI Agents Before They Go Rogue Is Next to ImpossibleHigh-autonomy agents with broad permissions and unfettered access are a recipe for disaster, and enterprises need to act now before they become the next horror story.DARKREADING.COM
2 JunFBI-Flagged Phishing Kit Kali365 Expands Its ReachOnce targeting just Microsoft 365, the phishing-as-a-service platform now aims at AWS, Okta, and Russian platforms, while relying on device code phishing.DARKREADING.COM
2 JunCyera eyes $12B valuation at 80x ARR multiple despite operating lossesThe cybersecurity company is nearing a $300 million round led by Evolution Equity Partners.TECHCRUNCH.COM
2 JunMicrosoft's Coreutils project brings Linux commands to WindowsMicrosoft announced today at its Build 2026 developer conference the release of Coreutils for Windows, bringing many commonly used Linux command-line utilities to Windows as native applications. [...]BLEEPINGCOMPUTER.COM
2 JunOpenAI upgrades GPT-5.5, as it plans to retire legacy ChatGPT modelsOpenAI says it's rolling out a new update that improves the existing GPT-5.5 Instant model, and this move comes ahead of the scheduled retirement of multiple legacy models, including o3. [...]BLEEPINGCOMPUTER.COM
2 JunZoom CISO: AI as Security Enabler, Not Role-ReplacerAs Zoom's CISO, Sandra McLeod, discusses the challenges of securing a global communication platform, the promise of AI-driven security workflows, and advice for aspiring cybersecurity leaders.DARKREADING.COM
1 JunCrowdStrike Scales AI-Native Agents Across Falcon Exposure Management with NVIDIACROWDSTRIKE.COM
1 JunCrowdStrike Brings Enterprise-Grade Security to the AI Factory with NVIDIA Vera BlueField-4 STXCROWDSTRIKE.COM
1 JunInfosecurity Europe: OWASP Forms New Agentic Research CouncilOWASP’s new Agentic Research Council will aim to connect academic work to operational realities on agentic AI securityINFOSECURITY-MAGAZINE.COM
1 JunYour phone called. It needs a cleanup.Introducing Android Junk Cleaner. It scans your phone for leftover files, temporary data, and outdated caches that build up and slow down your device.MALWAREBYTES.COM
1 JunHow Canva scaled to 260+M users while elevating security and productivitySee how Canva uses 1Password to integrate new teams fast, empower developers and maintain high standards for customers.CYBERSECURITYDIVE.COM
1 JunWebsites Can Now Spy on You Through Your Hard DriveThanks to the newly detailed FROST technique, telltale SSD activity can be measured in the browser using simple JavaScript.WIRED.COM
1 JunThe Romance Scammer Who Made a Small Fortune Posing as a WWE SuperstarIn this excerpt from WIRED Book Club pick The Yahoo Boys, journalist Carlos Barragán traces one scammer’s journey from flop to fortune.WIRED.COM
1 JunFSB Group Gamaredon Hides Worm in Windows Data StreamsFSB-linked Gamaredon concealed a fileless worm in NTFS data streams to spy on Ukraine targetsINFOSECURITY-MAGAZINE.COM
1 JunInfosecurity Europe: AI SOCs Will Still Need SOC Analysts, Security Vendors SayTop cybersecurity vendors said AI won't replace entry-level – only routine ticket-taking and triageINFOSECURITY-MAGAZINE.COM
1 JunInvestigating suspicious AI workflows in Microsoft Entra Agent ID: Agent’s user accountEntra ID agent users can send malicious content to human users via Microsoft Teams. Here’s what to look out for.REDCANARY.COM
1 JunSpring 2026 SOC 1, 2, and 3 reports are now available with 188 services in scopeAmazon Web Services (AWS) is pleased to announce that the Spring 2026 System and Organization Controls (SOC) 1, 2, and 3 reports are now available. The reports cover 188 services over the 12-month period from April 1, 2025–March 31, 2026, giving customers a full year of assurance…AWS.AMAZON.COM
1 JunNSA selects new leads for key cybersecurity postsDavid Imbordino, an NSA senior executive who most recently led its cybersecurity directorate in an acting capacity, has been named as its new chief. Bruce Jones, a career NSA technical and operational leader, as the new head of its Cybersecurity Collaboration Center.THERECORD.MEDIA
1 JunSpain arrests doxer leaking sensitive data of govt employeesThe Spanish National Police has arrested an individual for leaking sensitive information related to members of various key state organizations, including the National Cybersecurity Institute (INCIBE). [...]BLEEPINGCOMPUTER.COM
30 MayG7 Cybersecurity Working Group Statement on preparing for a post-quantum cryptography migrationCYBER.GC.CA
29 MayPolice arrest man following hack of Ajax football clubDutch police have arrested a 35-year-old man suspected of hacking into the computer systems of Amsterdam football giant Ajax, after the personal data of hundreds of thousands of supporters was put at risk. Read more in my article on the Hot for Security blog.BITDEFENDER.COM
29 MayInfosecurity Europe: CyCOS Project Expands to Support UK SMEs as CIISec Takes OverFrom a research-driven pilot, the Cybersecurity Communities of Support (CyCOS) is about to be handed over to CIISecINFOSECURITY-MAGAZINE.COM
29 MayUS charges Google security engineer with Polymarket insider tradingA Google security engineer was charged with insider trading after winning $1.2 million using confidential company data to place bets on the cryptocurrency-based Polymarket decentralized prediction market. [...]BLEEPINGCOMPUTER.COM
29 MayWhat 2,000 Exposed Vibe-Coded Apps Reveal About the Limits of Most Security StacksShadow AI used to mean employees pasting things they shouldn't into ChatGPT. It now means something bigger: employees building full applications with AI, wiring them into production systems, and publishing them on the open internet. Without Security or IT in the loop. The artifac…THEHACKERNEWS.COM
29 MayMan sent to prison for selling data of 7 millions elderly AmericansA North Carolina man was sentenced to more than 10 years in prison for selling the personal information of over 7 million elderly Americans to Jamaican scammers. [...]BLEEPINGCOMPUTER.COM
29 MaySignal users targeted in backup-stealing phishing attacksCybercriminals are impersonating Signal Support to steal backup recovery keys, giving them access to victims' entire message archives.MALWAREBYTES.COM
29 MayGoogle Chrome adds session cookie theft protection for all usersGoogle says the Chrome Device Bound Session Credentials (DBSC) security feature is now generally available and is rolling out to all users to prevent account takeovers. [...]BLEEPINGCOMPUTER.COM
29 MayFinal 24 hours to save up to $410 on your TechCrunch Disrupt 2026 ticketYou now have until tonight at 11:59 p.m. PT to lock in Early Bird savings of up to $410 for TechCrunch Disrupt 2026 before prices increase. Join 10,000+ tech leaders in October for one of the most anticipated tech events of the year. Register now.TECHCRUNCH.COM
29 MayAsia's Cyber Insurance Market Shows Signs of LifeThe cyber insurance industry has made relatively weak inroads into Asia due to a a variety of factors, but that could be changing.DARKREADING.COM
29 MayFrontier artificial intelligence (ITSAP.10.050)This publication provides your organization with additional details on frontier AI, the associated risks and suggested mitigation measures to enhance your cyber security posture.CYBER.GC.CA
29 MayMicrosoft under fire for threatening security researcher with criminal investigationA public spat between Microsoft and an independent security researcher reopens a long-running debate over who is responsible for securing software.TECHCRUNCH.COM
28 MayPirates in the crosshairs: how one cybercrime gang has been infecting book, movie, and TV show fans for yearsOur experts continue to track attacks targeting consumers of pirated content, both books and movies. 2026 saw the discovery of new target sites with tens of millions of visitors, while the miner gained a RAT module.SECURELIST.COM
28 MayScammers Are Using Your Real Hotel Reservations to Trick You With Spear-Phishing AttacksCustomer data from more than 350 hotels around the world may have been accessed as part of realistic reservation-hijacking scams.WIRED.COM
28 MayYour Windows PC has a security deadline in June 2026Windows is replacing old Secure Boot certificates, and some older PCs could miss future security protections if the update fails.MALWAREBYTES.COM
28 MayNew AI Usage Report: Enterprise AI Risk Is Heavily Concentrated Among a Small Group of AI "Power users"State of AI Usage Report 2026 (full report here) by LayerX Security reveals the extent of the enterprise AI visibility gap and why most organizations still don't understand where their AI exposure is actually coming from. The research shows that enterprise AI risk is not distribu…THEHACKERNEWS.COM
28 MayThreatsDay Bulletin: Claude Security Plugin, Azure Priv-Esc, Kali365 MFA Bypass, FIFA Scams +15 MoreEvery time you think the industry has finally stopped doing some reckless, low-effort crap, somebody spins up a fresh box full of sketchy loaders, fake installers, recycled social-engineering bait, and enough exposed infrastructure to make you wonder if prod is just a public beta…THEHACKERNEWS.COM
28 MayChinese-speaking fraud gang could be stealing millions from 2026 World Cup fansCybercriminals have registered more than 4,300 fraudulent domains impersonating FIFA's official web presence since August 2025.THERECORD.MEDIA
28 MayRussia conducting daily attacks on UK 'from seabed to cyberspace,' spy chief warnsAnne Keast-Butler, director of GCHQ, said Russia's actions have prompted the agency to defend subsea cables and energy pipelines in British waters, disrupt Russian networks smuggling sanctioned technology and countering “reckless sabotage and assassination attempts.”THERECORD.MEDIA
28 MayGrading on a curve: How to assess a pentestDefenders don’t need to detect every adversary action to prevent a threat. Here’s a more realistic, optimized approach to testing.REDCANARY.COM
28 MayHow SIEM helps MSPs reduce noise and stop threats fasterMSPs don't lack security data. They struggle to separate real threats from alert noise. Kaseya explains how SIEM helps MSPs improve visibility, reduce fatigue, and respond faster. [...]BLEEPINGCOMPUTER.COM
28 MayFocus on Cyber Insurance: How Quantifying Risk Is Reshaping SecurityIn this latest installment of the Reporters' Notebook video series, we discuss how cyber insurance is forcing organizations to quantify risk, what's covered (and what's not), and why this could be the best thing to happen to cybersecurity.DARKREADING.COM
28 MayU.S. says troops were targeted with location data, as senator warns ad industry is a ‘national security threat’One leading privacy lawmaker said it was time to "start treating the adtech industry as a national security threat."TECHCRUNCH.COM
28 MayAgentic AI Isn't Risky; the Way Orgs Deploy It IsAI agents aren't black boxes — they're models interacting with software tools. The risk lies in their overlap.DARKREADING.COM
28 MayThe Pentagon Knew Enemies Could Track Troops’ Phones for Years. Now They AreThe US military has long known that cheap fixes could stop location data from exposing its troops. It adopted almost none—and now says adversaries are using the data to target soldiers during a war.WIRED.COM
28 MayA security lapse at prison pay phone service Pay Tel publicly exposed over 300K callers’ driver’s licensesPay Tel secured the publicly exposed data after security researchers discovered the leak containing callers' sensitive ID documents and inmate communications.TECHCRUNCH.COM
28 MayAnalysis of a Year of Files Uploaded to DShield Sensors, (Wed, May 27th)Using the data collected over the past year and using Kibana these two ES|QL query to summarize the data, this shows the list of the most uploaded threat to two DShield sensors (local and cloud) over the past year. I have sorted the activity by months that shows the evolutio…ISC.SANS.EDU
28 MayHackers are trying to steal Signal users’ backups in new wave of phishing attacksA new hacking campaign is trying to trick Signal users to give up their secret recovery key, which can be used to access online backups containing past messages.TECHCRUNCH.COM
28 MayNewsom signs new AI-related EO.Supreme Court declines to hear Meta's challenge to social media addiction lawsuit.THECYBERWIRE.COM
28 MayFBI warns of fake FIFA websites running World Cup fraud schemesThe FBI is warning of fake websites impersonating FIFA ahead of the 2026 World Cup, to steal personal and financial information, sell fake tickets and hospitality packages, and push other fraud related to the event. [...]BLEEPINGCOMPUTER.COM
28 MayLess panic patching, more precisionIn this newsletter, Thor breaks down why you should stop relying solely on CVSS and start using EPSS and GCVE to focus your patching efforts on the threats that actually matter.TALOSINTELLIGENCE.COM
28 MayWhy and how to migrate to a Transit Gateway-attached AWS Network FirewallAWS Network Firewall now supports native attachment to AWS Transit Gateway. Customers commonly use Transit Gateway to route traffic from Amazon Virtual Private Cloud (Amazon VPC) networks to a centralized inspection VPC (a VPC dedicated to hosting firewall endpoints for traffic i…AWS.AMAZON.COM
28 MayAnthropic confirms Claude Mythos-class models will roll out to the publicAnthropic has confirmed that it plans to bring Mythos-class models to the general public after delaying the rollout due to security risks to public and private software. [...]BLEEPINGCOMPUTER.COM
27 MayWeekly Threat Bulletin – May 27th, 2026These are the top threats you should know about this week.F5.COM
27 MayPureLogs Variant Steals Data via Purchase Order LuresFortiGuard Labs detailed a PureLogs campaign using JavaScript, PowerShell and process hollowingINFOSECURITY-MAGAZINE.COM
27 MayWindows 11 KB5089573 update released with performance improvementsMicrosoft has released the KB5089573 preview cumulative update for Windows 11 versions 25H2 and 24H2, which comes with 30 changes, including performance and reliability improvements. [...]BLEEPINGCOMPUTER.COM
27 MayFake LinkedIn emails abuse Adobe to track victimsPhishers are stealing LinkedIn credentials while abusing Adobe Target to track victims and redirect them to real LinkedIn pages.MALWAREBYTES.COM
27 May68% of UK Firms Plan to Increase Cyber Spending as AI Risks RiseUK firms plan higher cyber spending as AI adoption raises security concernsINFOSECURITY-MAGAZINE.COM
27 MayDutch police arrests suspect linked to Ajax football club hackThe Dutch National Police arrested a 35-year-old man suspected of hacking the professional football club Ajax Amsterdam (AFC Ajax) earlier this year. [...]BLEEPINGCOMPUTER.COM
27 MayIntroducing EvidenceForge: Synthetic security logs that don’t look (as) fakeEvidenceForge generates high-quality, realistic, and consistent datasets across multiple log formats, enabling teams to effectively train personnel and validate detection models without the need for complex manual simulations.TALOSINTELLIGENCE.COM
27 May5 Steps to Managing Shadow AI Tools Without Slowing Down EmployeesWhen an employee installs an AI writing assistant, connects a coding copilot to their IDE, or starts summarizing meetings with a new browser tool, they are doing exactly what a productive employee should do: finding faster ways to work. Across most organizations today, employees …THEHACKERNEWS.COM
27 MayKali365 phishing kit bypasses MFA and steals Microsoft loginsThe FBI has warned that attackers are using a new phishing kit to gain long-term access to Microsoft Outlook, Teams, and OneDrive accounts.MALWAREBYTES.COM
27 MayThousands of Fake FIFA Domains Target World Cup FansGroup-IB uncovered Ghost Stadium phishing and 4300 fake FIFA World Cup domains targeting fansINFOSECURITY-MAGAZINE.COM
27 MayFBI warns of in-person data theft attacks from extortion gangThe FBI warned on Tuesday that the Silent Ransom Group (SRG) extortion gang is now targeting U.S.-based law firms in in-person data theft attacks. [...]BLEEPINGCOMPUTER.COM
27 MayCybersecurity Evolution: How We Went From Perimeter Defense to AI-Native SecurityThe cybersecurity industry of 2006 barely resembled today's billion-dollar behemoth. As part of Dark Reading's 20th anniversary celebration, we trace the industry's evolution through a technology lens.DARKREADING.COM
27 MayInvestigating suspicious AI workflows in Microsoft Entra Agent ID: Autonomous agentsRead our primer on how to detect and respond to an autonomous agent escalating privileges and persisting in your Entra ID tenantREDCANARY.COM
27 MayDefending at Machine-Speed: Building AI Threat Readiness with WizHow Wiz helps organizations adopt an AI Operating Model for AI Threat ReadinessWIZ.IO
27 MayTechCrunch Disrupt 2026 Early Bird ticket savings end in 3 daysThere are only 3 days left to save up to $410 on your ticket to TechCrunch Disrupt 2026. Early Bird pricing ends May 29 at 11:59 p.m. PT, and once the deadline passes, ticket prices increase. If you plan to attend one of the most influential gatherings in tech this year, now is t…TECHCRUNCH.COM
27 MayRudd orders Cyber Command reviews as Pentagon presses reform agendaArmy Gen. Joshua Rudd, who took the twin-leadership reins of Cyber Command and the NSA in March, recently tapped MITRE to conduct a potentially wide-ranging review into the organization, according to three people familiar with the matter.THERECORD.MEDIA
27 MayMalicious npm Package Stole Files From Claude AI User Directory via GitHubCybersecurity researchers have discovered a new malicious package on the npm registry that comes with information stealing capabilities. According to OX Security, the package, named "mouse5212-super-formatter," is designed to upload files from "/mnt/user-data," a dedicated direct…THEHACKERNEWS.COM
27 MayRomanian national sentenced to more than 4 years for hacking Oregon government systemsDragomir was arrested in Romania in November 2024 and brought to the U.S. last year to face charges for hacking into the network belonging to Oregon’s Office of Emergency Management.THERECORD.MEDIA
27 MayZscaler intends to acquire identity mapping company Symmetry Systems.Check Point has agreed to acquire AI evaluation platform Deepchecks.THECYBERWIRE.COM
26 MayScammers pretending to be Microsoft had help from US executivesCourt documents reveal how tech support scammers relied on infrastructure supplied by a US business.MALWAREBYTES.COM
26 MayFrom Cartels to Terrorists, the CIA, FBI, and White House: The Vast Career of Karen SchaeferKaren Schaefer retired from the CIA in 2019, after 26 years of service. She started out in Latin America and ended with a stint at the FBI. In between, she earned numerous intelligence awards and held key positions that spanned operational, supervisory, and policy roles. Her many…THECYBERWIRE.COM
26 MayRemembering Tim Wilson, Whose Legacy Lives on at Dark ReadingThe co-founder and former editor-in-chief passed away five years ago in November. As Dark Reading enters is third decade, we pause to celebrate and honor Wilson's instrumental role in building and elevating the media site.DARKREADING.COM
26 MayNew AI DDoS Attacks Are Smarter. Learn How to Fight Back in This WebinarEvery single day, hackers are finding new ways to crash websites and steal data. But right now, something has changed. Hackers are no longer working alone. They are now using powerful Artificial Intelligence (AI) tools to make their attacks faster, stronger, and much harder to st…THEHACKERNEWS.COM
26 MayBTMOB Android RAT Spreads Through No-Code Builder ToolingBTMOB Android RAT sold as a service with a no-code builder for fast, regional phishing luresINFOSECURITY-MAGAZINE.COM
26 MayIntelligence Insights: May 2026ClearFake is in command and ACR Stealer and GraphRunner debut in this month’s edition of Intelligence InsightsREDCANARY.COM
26 MayState of SDLC Security 2026: How Risk Scales in Modern DevelopmentInsights from real-world environments into how code, developer tooling, automation, and AI are reshaping application security.WIZ.IO
26 MayDutch government blocks US company from acquisition, citing ‘risk to public interest’The move to block the acquisition of the cloud company that hosts the Dutch digital ID service comes as Europe continues to reduce its reliance on U.S. technology.TECHCRUNCH.COM
26 MayGhost hackers: the cybersecurity mystery that nobody has solvedA shadowy group that stole and dumped the NSA’s most powerful hacking tools still has implications for how companies think about digital risk today.TECHCRUNCH.COM
26 MayFBI warns of Kali365 phishing kit that breaks into Microsoft 365 accounts – no password requiredSo, you've enabled multi-factor authentication. You've taught your staff never to type their passwords into dodgy-looking login pages. Surely your Microsoft 365 accounts are safe now? Well, think again. Read more in my article on the Hot for Security blog.BITDEFENDER.COM
26 MayInternet Starts to Return in Iran After 3-Month BlackoutSome internet connectivity is returning in Iran after nearly 90 days offline, web monitoring groups say. But it isn’t clear if the reconnection is permanent.WIRED.COM
26 MayMicrosoft Issues Out-of-Band SharePoint PatchSharePoint access often means access to the keys of the kingdom, something attackers and defenders understand all too well.DARKREADING.COM
26 MayUK Visa Portal spilled thousands of applicants’ passports and selfies online — and hasn’t fixed the leakThe third-party website exposed applicants' sensitive documents as part of the U.K. visa application process. Instead of fixing the issue, the company sent attorneys.TECHCRUNCH.COM
25 MayFBI Warns 'Kali365' Phishing Kit Hijacks Microsoft 365 OAuth TokensThe Kali365 phishing-as-a-service platform lowers the barrier of entry for cybercriminals, said the FBIINFOSECURITY-MAGAZINE.COM
25 MayThe Alert Firehose Finally Meets Its MatchAsk a cybersecurity pro about Network Detection and Response (NDR) and you might still hear "Noisy," "Too much data." But ask the teams running NDR that includes agentic AI capabilities and you'll hear they're actually using it to catch threats earlier, triage faster, and chase f…THEHACKERNEWS.COM
25 MayFBI warns of Kali365 phishing service targeting Microsoft 365 accountsThe FBI is warning about the Kali365 phishing-as-a-service platform (PhaaS) that is used to hijack Microsoft 365 accounts by abusing OAuth device code authentication to steal session tokens and bypass multi-factor authentication (MFA). [...]BLEEPINGCOMPUTER.COM
25 MayMicrosoft Access VBA, (Mon, May 25th)Microsoft Access files (Microsoft Office&#;x26;#;39;s Database) can contain VBA code.
ISC.SANS.EDU
25 MayAnthropic’s restricted Claude Mythos model may be coming to Claude CodeAnthropic appears to be preparing for the public rollout of the Mythos model, which was announced in April as a restricted model that poses major security risks to private and public software. [...]BLEEPINGCOMPUTER.COM
24 MayGPS, an outdated, but indispensable technology.GPS systems are the backbone of many core technologies found across commercial, military, and governmental organizations. Positioning, navigation, and timing (PNT) systems underpin everything from aviation and shipping to emergency response, energy grids, and financial services. …THECYBERWIRE.COM
23 MayItaly disrupts CINEMAGOAL piracy app that stole streaming auth codesItalian authorities have dismantled a piracy ecosystem centered around the CINEMAGOAL app that provided access to various streaming platforms, including Netflix, Disney+, and Spotify. [...]BLEEPINGCOMPUTER.COM
22 MayChina's Webworm Uses Discord, Microsoft Graphs to Hack EU Govts.The advanced persistent threat group also relied on SOCKS proxies like SoftEther VPN, tunneling tools that act as a middleman between victim and attacker.DARKREADING.COM
22 MayApple Blocked $2.2bn in App Store Fraud in the Last YearTotal figure for fraudulent transactions Apple has blocked since 2020 now stands at over $11bnINFOSECURITY-MAGAZINE.COM
22 MayTrump Mobile confirms it exposed customers’ personal data, including phone numbers and home addressesPresident Trump’s branded cell phone maker and cell provider said the exposure was linked to a third-party platform, and was evaluating whether it needs to notify customers.TECHCRUNCH.COM
22 MayWhy the Supreme Court's Chatrie case could change the meaning of privacy in AmericaLawyer Adam Unikowsky spoke with Recorded Future News about why he believes geofence searches are problematic and why the way the court rules could have a dramatic impact on Americans’ right to privacy.THERECORD.MEDIA
22 MayAkamai Joins Growing Chorus of Vendors Betting Big on Secure Enterprise BrowsersWhen Akamai announced its LayerX acquisition, the company joined a growing list of vendors adding secure enterprise browsers to their product portfolios.DARKREADING.COM
22 MayThe Coverage Gap: Why Your Blocklist Is Missing 119,000 Malicious IPs TodayGreyNoise compared 119,842 malicious IPs against 11 major threat feeds. The average coverage: just 2%, exposing the limits of static blocklists.GREYNOISE.IO
22 MaySecurity configurations and best practices to protect your mobile device (ITSM.80.002)CYBER.GC.CA
22 MayJoint guidance on the careful adoption of agentic artificial intelligence servicesThis joint guidance is intended for organizations that are considering developing or deploying agentic AI systems. It outlines security considerations related to LLMs and AI and describes the key risks associated with agentic AI.CYBER.GC.CA
22 MayJoint guidance on defending against the People’s Republic of China -linked covert networksCYBER.GC.CA
22 MayCyber security considerations for passkeys (ITSAP.30.033)While passkeys provide a strong and phishing-resistant authentication mechanism, there are several security considerations that your organization should be aware of.CYBER.GC.CA
22 MayMeta settles school district lawsuit claiming addictive design harmed students' mental healthThe bellwether lawsuit was the first of at least 1,200 to be brought by a school district against Meta, Snap, YouTube and TikTok for similar alleged harms. The other cases have not yet been tried.THERECORD.MEDIA
21 MayScam ads, AI hallucinations, and legal implications.This week, Dave and Ben sit down to discuss two legal cases. The first case involves Santa Clara suing Meta over alleged scam ads. The second story looks at a now dismissed case where the lawyers could potentially face consequences for allegedly using fake AI citations in their f…THECYBERWIRE.COM
21 MayThe EU Is Going Through a Trump-Fueled Breakup With Big TechFrance is already moving on from Zoom and Microsoft Teams in favor of homegrown alternatives. Other countries are quickly following suit.WIRED.COM
21 MayDiscord adds end-to-end encryption to voice and video calls by defaultDiscord now enables end-to-end encryption by default for all voice and video calls, making conversations inaccessible even to the platform itself. No announcement fanfare, no opt-in required, no settings to dig through. Discord flipped a switch on Monday and end-to-end encryption…SECURITYAFFAIRS.COM
21 MayWhen Identity is the Attack PathConsider a cached access key on a single Windows machine. It got there the way most cached credentials do - a user logged in, and the key stored itself automatically. Standard AWS behavior. No one misconfigured anything or violated a policy. Yet that single key, which was easily …THEHACKERNEWS.COM
21 MayResearchers left AI agents alone in a virtual town and watched it all unravelTold not to commit crimes, the AI agents mostly did anyway. Arson, violence, romance, self-deletion, and general chaos quickly ensued.MALWAREBYTES.COM
21 MayScammers are abusing an internal Microsoft account to send spam linksThe loophole allows spammers and scammers to send emails from a legitimate Microsoft email address typically used for sending genuine account alerts.TECHCRUNCH.COM
21 MayTikTok, YouTube, and Roblox face scrutiny, but age gates won’t fix child safetyOfcom says TikTok and YouTube are "not safe enough" for children, but simply adding stricter age checks is not the answer.MALWAREBYTES.COM
21 MayNine-Year-Old Linux Kernel Flaw Leaks SSH Keys and Password HashesQualys finds nine-year-old Linux ptrace flaw exposing SSH keys and password hashes locallyINFOSECURITY-MAGAZINE.COM
21 MayAutomating identity lifecycle and security with AWS Directory Service APIsManaging identities and access across complex environments has become more critical than ever. AWS Directory Service for Managed Microsoft Active Directory, also known as AWS Managed Microsoft AD, has added new capabilities to manage users and groups. Now, you can perform create,…AWS.AMAZON.COM
21 MayTwo Americans plead guilty to assisting India-based tech support scam centersAdam Young, 42, and Harrison Gevirtz, 33, pleaded guilty to misprision of a felony after they were accused of offering phone numbers, call routing services, call tracking tools and call forwarding services to India-based telemarketing fraudsters.THERECORD.MEDIA
21 MayApple Blocks Over 2 Million Apps in 2025 Fraud CrackdownApple 2025 fraud report shows major App Store protections: over 2M apps rejected, 1B fake accounts blocked, and billions in fraud prevented. Apple ‘s annual fraud prevention report for 2025 paints a striking picture of just how much effort goes into keeping the App Store cl…SECURITYAFFAIRS.COM
21 MayAWS KY3P report now available for third-party supplier due diligenceWe’re excited to announce that Amazon Web Services (AWS) has completed the S&P Global Know Your Third Party (KY3P) assessment of its security posture. This assessment demonstrates our continued commitment to meet the heightened expectations of cloud service providers. Custome…AWS.AMAZON.COM
21 MayTech giants promise British regulator they will tweak platforms to protect kids onlineThe regulator, Ofcom, had required Roblox, Snapchat, Instagram, Facebook, YouTube and TikTok to answer questions about their efforts to remove harmful algorithms, check kids’ ages and protect them from sexual predators by the end of April.THERECORD.MEDIA
21 MayGoogle API Keys Remain Active After DeletionA security researcher discovered the API keys can still be used for 23 minutes after deletion, even though the cloud provider claims deletion is immediate.DARKREADING.COM
21 May‘Creepy’ Listening Tool for Targeted Ads Didn’t Actually Work, FTC SaysThree firms will pay nearly $1 million for selling “Active Listening” technology that they claimed tapped people’s phones for advertising. The FTC alleges the “tech” was just pricey email lists.WIRED.COM
21 MayHow CISOs Should Prep for Agentic-Ready AI BOMsFinding ways to document both component and execution attributes for AI bill of materials (AI BOM).DARKREADING.COM
20 MayWeekly Threat Bulletin – May 20th, 2026These are the top threats you should know about this week.F5.COM
20 MayData Brokers’ and AI Firms’ Opt-Out Forms Are Built to Fail, Report FindsA new study finds AI companies, defense firms, and dating apps are among 38 data collectors allegedly using manipulative design to confuse users while collecting their data.WIRED.COM
20 MayResearchers Warn CypherLoc Scareware Has Targeted Millions of UsersBarracuda reveals new CypherLoc scareware has featured in nearly three million attacksINFOSECURITY-MAGAZINE.COM
20 MayFirefox 151 packs big privacy upgrades into a small updateFirefox 151 adds major privacy improvements and fixes high-priority security vulnerabilities, making this an update you shouldn’t ignore.MALWAREBYTES.COM
20 MayAgent AI is Coming. Are You Ready?New Industry Data Just Released Suggests Not. On May 19th, 2026, Orchid Security released the results of our Identity Gap: Snapshot 2026. Among the findings, "identity dark matter" (the unseen, unmanaged elements of identity) now overshadows the visible elements 57% vs. 43%. And …THEHACKERNEWS.COM
20 MayAWS Security Hub Extended: Why enterprise security products should sell themselvesOur largest security services customers started the same way every customer does – with a click. They enabled Amazon GuardDuty, Amazon Inspector, AWS WAF, and AWS Security Hub, experienced the benefits in real time, and evaluated with transparent pay-as-you-go pricing. No RFP. No…AWS.AMAZON.COM
20 MayFTC warns 12 major tech firms of violating Take It Down ActThe law mandates that platforms make it easy for people to ask that nonconsensual intimate images be removed and to delete them within 48 hours of a request.THERECORD.MEDIA
20 MayDiscord migrates all users to end-to-end encryption by defaultThe move comes as other major social media platforms are killing end-to-end encryption for messaging. In recent months, Instagram and TikTok both announced they will no longer offer the feature.THERECORD.MEDIA
20 MayTexas, Florida top list of states reporting millions of dollars lost through crypto ATMsIn most complaints, victims said they were given detailed information by fraudsters on how to take money from their bank account, where to find a cryptocurrency kiosk and how to send the funds.THERECORD.MEDIA
20 MayA New York Cop Got Injured at a Boxing Match. Now Madison Square Garden Is Banning His LawyerAttorney John Scola is representing a police officer who is suing over injuries allegedly sustained while working security at an MSG property in 2025.WIRED.COM
20 MayA Bipartisan Amendment Would End Police License Plate Tracking NationwideOne line tucked into a federal highway bill would strip funds from cities and states unless they kill their automated plate tracking programs—effectively banning the tech for all but toll collection.WIRED.COM
20 MayCyber Pros Can't Decide If AI Is a Good or a Bad ThingThere is nothing cybersecurity professionals are more excited about, and nothing they fear more, than AI.DARKREADING.COM
19 MayHackers Bypass Security Tools to Target Users DirectlyBridewell report calls out emergence of “fix-style” attacksINFOSECURITY-MAGAZINE.COM
19 MayHow to Make Apps and Websites Remove Your Nonconsensual NudesStarting May 19, tech platforms in the US will have to start complying with the Take It Down Act. Here's how more than a dozen of the largest platforms are handling takedown demands for your nudes.WIRED.COM
19 MayMassive MENA cybercrime Operation Ramz disrupts infrastructure and arrests 201 suspectsINTERPOL led Operation Ramz in MENA, resulting in 201 arrests and 382 suspects tied to cybercrime networks. INTERPOL coordinated Operation Ramz across the Middle East and North Africa, leading to 201 arrests and identifying 382 additional suspects. ” A first-of-its-kind cyb…SECURITYAFFAIRS.COM
19 MayYouTube wants your face to fight deepfakes"Likeness detection" promises protection from AI deepfakes, but some creators are uneasy about handing over biometric data in return.MALWAREBYTES.COM
19 MayAgentic AI Accelerates Software Builds and Mobile App AttacksDigital.ai data reveals 87% of apps were attacked over the past yearINFOSECURITY-MAGAZINE.COM
19 MayFacebook scam promises cheap Aldi meat boxes, steals payment info insteadA fake Aldi “meat box” offer spreading on Facebook tricks victims into handing over personal and payment info.MALWAREBYTES.COM
19 MayTools for spotting and disabling AI systems in an enterpriseKey methods for cutting off AI access to an organization’s core IT assets.KASPERSKY.COM
19 MayTelecom sector launches its own private ISACFederal government involvement in an existing group chilled some cybersecurity discussions among major telecom providers. The new group is intended to alleviate those anxieties.CYBERSECURITYDIVE.COM
19 MayUK regulator to require tech firms to tackle deepfakes, non-consensual intimate imagesThe regulator’s announcement said the change is being made due to the “urgent need to better protect women and girls online.”THERECORD.MEDIA
19 MayDiscord enables end-to-end encrypted voice and video calling for every userGood news! Discord's hundreds of millions of users now have their communications scrambled, so not even Discord can see them.TECHCRUNCH.COM
19 MayFrom teen hacker to Iron Dome researcher, this founder raised $28M to fight AI phishingOcean, an agentic email security platform, raised funding from Lightspeed Venture Partners.TECHCRUNCH.COM
19 MayMicrosoft Exchange ProxyShell Scanning Doubles in April 2026 as Two Distinct Campaign Clusters EmergeSensor Intel Series: April 2026 CVE TrendsF5.COM
19 MayIntroducing Runtime Threat Detection for Google Cloud RunWiz Runtime Sensor support for Google Cloud Run Containers is now generally available, giving teams real-time threat detection and response for their serverless container workloads.WIZ.IO
18 MayBank of England, FCA and Treasury Raise Alarm Over Frontier AIThe UK’s financial authorities have set expectations for the sector on cybersecurity and operational resilienceINFOSECURITY-MAGAZINE.COM
18 MayAn ICE Firearms Trainer Was Involved in At Least 4 Deadly ShootingsDavid Norman, a former Phoenix police officer who’s described himself as “a fucking savage,” now runs a company that provided training to Homeland Security’s Special Response Teams.WIRED.COM
18 MayMicrosoft is changing Edge’s plaintext password behaviorSaved passwords in Microsoft Edge will no longer sit in plaintext memory for the entire browser session after a researcher raised concerns.MALWAREBYTES.COM
18 MayHow to Reduce Phishing Exposure Before It Turns into Business DisruptionWhat happens when a phishing email looks clean enough to pass through security, but dangerous enough to expose the business after one click? That is the gap many SOCs still struggle with: the attacks that leave teams unsure what was exposed, who else was targeted, and how far the…THEHACKERNEWS.COM
18 MayInterpol Launches Sweeping Cybercrime Crackdown in MENA RegionOver 200 people were arrested in an anti-cybercrime operation that spanned 13 countries across the Middle East and North AfricaINFOSECURITY-MAGAZINE.COM
18 MayThe Infosecurity Europe Cyber Startup Competition: Meet the FinalistsNew for 2026, the Infosecurity Europe Startup competition will see five finalists pitch their ideas in front of a live audience, including senior industry leaders, investors and buyersINFOSECURITY-MAGAZINE.COM
18 MayPublic Amazon bucket leaks sensitive guest data from Japanese hotel platform TabiqA hotel check-in system exposed over 1 million passports, IDs, and selfies online due to a misconfigured cloud storage bucket. A security lapse in the Reqrea’s Tabiq hotel check-in system exposed over 1 million passports, driver’s licenses, and selfie verification photos on…SECURITYAFFAIRS.COM
18 MayB1ack’s Stash Releases 4.6 Million Stolen Credit Cards for FreeB1ack’s Stash Releases 4.6 Million Stolen Credit Cards for Free A notorious Dark Web carding marketplace is making headlines again. B1ack’s Stash, one of the most active illicit card shops on the Dark Web, has announced the free release of approximately 4.6 million stolen credit …SOCRADAR.IO
18 MayExperts warn of privacy risks as AI firms looks to connect to financial accountsOpenAI announced Friday that it is rolling out a new ChatGPT feature allowing users to connect all of their financial accounts to the chatbot for personal finance advice.THERECORD.MEDIA
18 MayINTERPOL Operation Ramz Disrupts MENA Cybercrime Networks with 201 ArrestsINTERPOL has coordinated a first-of-its-kind cybercrime crackdown across the Middle East and North Africa (MENA) that led to 201 arrests and the identification of an additional 382 suspects. The initiative involved the efforts of 13 countries from the region between October 2025 …THEHACKERNEWS.COM
18 May'Claw Chain' Vulnerabilities Threaten OpenClaw DeploymentsThe now patched vulnerabilities in the rapidly growing AI agent framework allow attackers to steal credentials, escalate privileges, and maintain persistence.DARKREADING.COM
18 MayFrom Cryptographic Blind Spots to Post-Quantum Agility: Introducing Wiz for PQC ReadinessEliminate cryptographic blind spots and neutralize legacy debt with an integrated cryptographic asset inventory. Identify risks across code, cloud, and runtime, using the Wiz Security Graph to prioritize migration and protect against "Harvest Now, Decrypt Later" attacks.WIZ.IO
15 MayStrong Stack. Strong Team. Real Security Resilience.Learn how to build a resilient security stack and program that cuts alert noise, strengthens identity defense, and helps teams respond faster.HUNTRESS.COM
15 MayCyber Pioneers Ponder Past as PrologueRobert "RSnake" Hansen, Katie Moussouris, Rich Mogull, Richard Stiennon, and Bruce Schneier reflect on how their favorite columns penned for Dark Reading over the past 20 years have stood the test of time.DARKREADING.COM
15 MayMeta’s confusing new approach to chat privacyWhatsApp now offers disappearing AI chats Meta says it cannot read. While Instagram just removed the feature that stopped Meta reading your messages.MALWAREBYTES.COM
15 MayGremlin Stealer Evolves into Modular Threat with Advanced Evasion CapabilitiesA new Gremlin stealer variant has evolved into a modular toolkit with advanced evasion and data theft capabilities, according to new Unit 42 researchINFOSECURITY-MAGAZINE.COM
15 MayThe AWS AI Security Framework: Securing AI with the right controls, at the right layers, at the right phasesTL;DR for busy executives The AWS AI Security Framework helps security leaders move fast and stay secure with AI. Security compounds from day 1 as workloads evolve from prototype to production to scale. Assess first. Request a no-cost SHIP engagement to baseline your posture and …AWS.AMAZON.COM
15 MayA hotel check-in system left a million passports and driver’s licenses open for anyone to seeThe tech company that maintains the hotel check-in system set its cloud storage to public, allowing anyone to access customers' data without a password.TECHCRUNCH.COM
14 MaySimple bypass of the link preview function in Outlook Junk folder, (Thu, May 14th)Besides serving as a place where Microsoft Outlook places suspected spam, the Outlook Junk folder has one additional function that can be quite helpful when it comes to identifying malicious messages. Any e-mail placed in this folder is stripped of all formatting, and destination…ISC.SANS.EDU
14 MayMost Organizations Now Use AI Agents for Sensitive Security TasksSemperis study finds 74% of organizations believe AI will increase attacks on identity infrastructureINFOSECURITY-MAGAZINE.COM
14 MayICO Publishes Five-Step Plan to Counter Emerging AI-Powered AttacksThe Information Commissioner’s Office has released new guidance on how to mitigate the risk of AI-powered attacksINFOSECURITY-MAGAZINE.COM
14 MayYour iPhone Gets Stolen. Then the Hacking BeginsA bustling underground ecosystem is providing criminals with the tools to unlock iPhones—and wage phishing attacks against their contacts to access bank accounts and more.WIRED.COM
14 MayNew Fragnesia Flaw Hands Linux Local Users Root AccessNew Fragnesia kernel flaw lets unprivileged local users escalate to root on Linux systemsINFOSECURITY-MAGAZINE.COM
14 MayAI Drives Cybersecurity Investments, Widening 'Valley of Death'In a role reversal, investment dollars in AI security startups exceeded the value of AI acquisitions in 1Q26 by more than $1 billion, a rare occurrence.DARKREADING.COM
14 MayCisco cuts nearly 4,000 jobs to spend more on AI, reports ‘record quarterly revenue’This is Cisco's latest layoff in recent years, while the company's chief executive touts record revenue and growth.TECHCRUNCH.COM
14 MayOpenAI says hackers stole some data after latest code security issueOpenAI said the damage was limited to the employees’ devices, and did not affect user data nor its production systems, and none of its intellectual property was stolen.TECHCRUNCH.COM
14 MayAutomating post-quantum cryptography readiness using AWS ConfigMigrating your TLS endpoints to Post-quantum cryptography (PQC) starts with understanding your current TLS endpoint inventory and posture. This post introduces the PQC Readiness Scanner — an automated tool that inventories your Application Load Balancer (ALB), Network Load Balanc…AWS.AMAZON.COM
14 MaySuspected Dream Market kingpin arrested after gold bars sent to his home addressLesson one for aspiring dark web kingpins: don't have your laundered gold bars shipped to your home address. Read more in my article on the Hot for Security blog.BITDEFENDER.COM
14 May13 Cybersecurity Frameworks for 2026 and How to Choose | HuntressDiscover some of the most common cybersecurity frameworks by what they’re best for, plus tips for choosing the right one for your organization.HUNTRESS.COM
13 MayWeekly Threat Bulletin – May 13th, 2026These are the top threats you should know about this week.F5.COM
13 MayProxying the Unproxyable? Sending EXE traffic to a Proxy, (Wed, May 13th).. if “unproxyable†is a word that is ..
ISC.SANS.EDU
13 May[GUEST DIARY] Tearing apart website fraud to see how it works., (Wed, May 13th)&#;x26;#;x5b;This is a Guest Diary by Joshua Nikolson, an ISC Intern and part of the SANS.edu Bachelor&#;x26;#;39;s degree in Applied Cybersecurity (BACS) program.]
ISC.SANS.EDU
13 MayUK Cybersecurity Market Expands to £14.7bn with Strong Growth in AI Security FirmsUK cybersecurity sector reaches £14.7bn in revenue, driven by rapid growth in AI security firms, increased investment and rising employment across the industryINFOSECURITY-MAGAZINE.COM
13 MayDark Web Profile: Keymous+Dark Web Profile: Keymous+ Keymous Plus, also known as Keymous+ threat group, markets itself as a hacktivist collective fighting for humanity. What intelligence investigations have documented is structurally different: a North African hybrid actor blending political performance w…SOCRADAR.IO
13 MayTexas sued Netflix over claims it secretly collected and sold users’ dataThe Texas AG sued Netflix, accusing the company of secretly tracking viewers, selling user data, and using addictive features targeted at minors.MALWAREBYTES.COM
13 MayAvada Builder Flaws Expose One Million WordPress SitesAvada Builder flaws allowed file read and SQL injection on one million WordPress sitesINFOSECURITY-MAGAZINE.COM
13 MayWhatsApp Adds Meta AI Chats That Are Built to Be Fully PrivateThe company says its new Incognito Chat allows you to use its AI chatbot without anyone else—including Meta—being able to access your conversations.WIRED.COM
13 MayEuropean Commission head pushes creation of new law delaying teens’ social media accessThe comments come as several European countries, including Spain, Greece, Norway, France, Denmark, Turkey and the Netherlands have said they are considering or are implementing age verification protocols to restrict young teens from accessing social media platforms.THERECORD.MEDIA
13 MayAlleged Dream Market admin arrested in Germany after US indictmentCourt documents said Dream Market was launched in 2013 by Owe Martin Andresen and others before becoming one of the biggest criminal marketplaces online.THERECORD.MEDIA
13 MayDHS Plans Experiment Running ‘Reconnaissance’ Drones Along the US-Canada BorderAutonomous drones and ground vehicles will stream “battlefield intelligence” over 5G along the US-Canada border in a bilateral DHS experiment this fall.WIRED.COM
13 MayDetecting and preventing crypto mining in your AWS environmentThis article guides you on how to use Amazon GuardDuty to identify and mitigate cryptocurrency mining threats in your Amazon Web Services (AWS) environment. You’ll learn about the specialized detection capabilities of GuardDuty and best practices to build a multi-layered defense …AWS.AMAZON.COM
12 MayElastic Security MCP App: Interactive security operations inside your AI ToolsElastic Security is the first security vendor to ship an interactive UI in AI tools. Triage alerts, hunt threats, correlate attack chains, and open cases, all from inside your AI conversation.ELASTIC.CO
12 MayiOS 26.5 Brings Default End-to-End Encrypted RCS Messaging Between iPhone and AndroidApple on Monday officially released iOS 26.5 with support for end-to-end encryption (E2EE) to Rich Communication Services (RCS) in beta as part of a "cross-industry effort" to replace traditional SMS with a more secure alternative. To that end, E2EE RCS messaging is rolling out t…THEHACKERNEWS.COM
12 May1 in 8 employees have sold company logins or know someone who hasCifas just published research that should bother anyone who runs a business, or buys from one.MALWAREBYTES.COM
12 MayWhy Agentic AI Is Security's Next Blind SpotAgentic AI is already running in production environments across many organizations today. It is executing tasks, consuming data, and taking actions — most likely without meaningful involvement from the security team. The industry conversation has largely framed this as a question…THEHACKERNEWS.COM
12 May10 Best Dark / Deep Web Browsers for Anonymity10 Best Dark / Deep Web Browsers for AnonymitySOCRADAR.IO
12 MayEnd‑to‑End Encrypted RCS Messaging Arrives Across iPhone and AndroidApple begins rolling out end-to-end encrypted RCS messaging between iPhone and Android in iOS 26.5INFOSECURITY-MAGAZINE.COM
12 May20 Leaders Who Built the CISO Era: 2 Decades of ChangeAs part of Dark Reading's 20th anniversary special coverage, we profile the CISOs, founders, researchers, criminals, and policymakers who rewrote the enterprise risk playbook.DARKREADING.COM
12 MayMini Shai-Hulud Hits TanStack npm PackagesMini Shai-Hulud compromises TanStack npm packages and spreads across PyPIINFOSECURITY-MAGAZINE.COM
12 MayEnabling AI sovereignty on AWSCloud and AI are transforming industries and societies at unprecedented speed, from accelerating research and enhancing customer experiences to optimizing business processes and enriching public services. At Amazon Web Services (AWS), we believe that for the cloud and AI to reach…AWS.AMAZON.COM
12 MayOpenAI Launches 'Daybreak' to Help Build Secure By Design SoftwareWith Daybreak, OpenAI wants its frontier AI models to be used to deploy secure by design software from the ground upINFOSECURITY-MAGAZINE.COM
12 MayU.S. bank disclose security lapse after sharing customer data with AI appThe bank said the security lapse was due to the use of an “unauthorized” AI software app.TECHCRUNCH.COM
12 MayFake Claude search results lure Mac users into ClickFix attackResearchers found a ClickFix campaign that uses fake Claude setup guides to trick Mac users into infecting themselves.MALWAREBYTES.COM
12 MayEuropean countries are exporting surveillance tech to countries with poor human rights records, report saysThe report, released by the advocacy group Human Rights Watch on Tuesday, alleges that the European Commission has failed to effectively police member states' surveillance tech sales despite the 2021 implementation of updated bloc-wide export rules designed to rein in the practic…THERECORD.MEDIA
12 MayGuardrail Technologies launches Traffic Light for Code & AI™; first security technology to verify & secure AI code and the people creating itPARK CITY, Utah (May 5, 2026) — Guardrail Technologies, the leading provider of AI security and governance software for enterprises building with AI, today announced the launch of Traffic Light for Code & AI™, which verifies both the code AI generat…CYBERSECURITYDIVE.COM
12 MayTwin brothers wipe 96 gov't databases minutes after being firedA case study in why credentials are revoked before firings.ARSTECHNICA.COM
12 MayCongressman launches inquiry into how food retailers use surveillance pricingThe letter noted that many Americans are unaware that their data is being used to set variable prices, a trend that is particularly pervasive for online shoppers.THERECORD.MEDIA
12 MayIran Is Using Tiny ‘Mosquito’ Boats to Shut Down the Strait of HormuzIran’s traditional naval fleet has been almost completely destroyed by US-Israeli raids. But Iran’s military has put a fleet of small vessels on the water that is crippling every passageway.WIRED.COM
12 MayLLMjacking: what these attacks are, and how to protect AI serversAn analysis of attacks on Ollama, LM Studio, AutoGPT, and LangServe servers, and recommendations on protecting your organization from the LLMjacking threat.KASPERSKY.COM
11 MayInstagram removed end-to-end encryption for DMs. What should users do?Instagram removes direct messages (DM) end-to-end encryption May 8, 2026, letting Meta access chats. Users should download backups amid privacy concerns and U.S. law pressure. Starting May 8, 2026, Instagram users who previously enabled end-to-end encryption in direct messages wi…SECURITYAFFAIRS.COM
11 MayFake OpenAI Privacy Filter Repo Hits #1 on Hugging Face, Draws 244K DownloadsA malicious Hugging Face repository managed to take a spot in the platform's trending list by impersonating OpenAI's Privacy Filter open-weight model to deliver a Rust-based information stealer to Windows users. The project, named Open-OSS/privacy-filter, masqueraded as its legit…THEHACKERNEWS.COM
11 MayIdentity is the new perimeter as rapid NHI proliferation threatens visibility and controlNHIs are linked to diverse assets across the enterprise technology ecosystem, creating a highly fragmented architecture and making it challenging for security teams to maintain visibility and control.CYBERSECURITYDIVE.COM
11 MayCrimenetwork returns after takedown, dismantled again by German authoritiesGerman police shut down a revived Crimenetwork marketplace with 22,000 users and 100+ sellers months after the original takedown. German police dismantled a resurrected version of the German-language cybercrime marketplace Crimenetwork, just months after the original platform was…SECURITYAFFAIRS.COM
11 MayYarbo responds to robot flaws that could mow down their ownersA researcher found a host of vulnerabilities in Yarbo garden robots that could expose Wi-Fi passwords, hijack cameras, and run over their owners on command.MALWAREBYTES.COM
11 MayFake Claude Code Page Pushes PowerShell Stealer at DevsOntinue uncovers fake Claude Code installer pushing PowerShell stealer abusing Chrome's IElevator2INFOSECURITY-MAGAZINE.COM
11 MayRushed Patches Follow Broken Embargo on New Linux Kernel VulnerabilitiesTwo new high-severity vulnerabilities, dubbed ’Dirty Frag’ when chained, have been found in the Linux kernel, affecting most Linux distributionsINFOSECURITY-MAGAZINE.COM
11 MayComplimentary virtual training: Get hands-on with AWS Security ServicesIf you’re looking to strengthen your organization’s security posture on Amazon Web Services (AWS) but aren’t sure where to start, then we’re here to help. Security Activation Days are complimentary, virtual, hands-on workshops designed to help you get practical experience with AW…AWS.AMAZON.COM
11 MayTexas sues Netflix over alleged data practices that create ‘surveillance machinery’ without user consentIn addition to fines, Texas is asking a judge to prevent Netflix from illegally collecting and sharing user data and to mandate that the company no longer use autoplay by default on kids’ profiles.THERECORD.MEDIA
11 MayApple Patches Everything, (Mon, May 11th)Apple today released its typical feature update across it&#;x26;#;39;s operating systems (iOS, iPadOS, macOS, tvOS, watchOS, vision OS). With this update, Apple patched 84 different vulnerabilities. Updates are available for the "26" series of operatin…ISC.SANS.EDU
11 MayFCC Softens Ban on Foreign-Made RoutersThe Federal Communications Commission eased some restrictions and pushed back deadlines for foreign router manufacturers, but the ban is still in place.DARKREADING.COM
11 MayTech Can't Stop These Threats — Your People CanSecurity controls can do only so much. Here are four attacks where your employees are usually your first, and only, line of cyber defense.DARKREADING.COM
11 MayWiz at Wiz: Reducing Risk through Service OwnershipHow Wiz security uses Service Catalog to turn cloud risk into service ownershipWIZ.IO
8 MayDetecting Web Server Probing & Fuzzing in Traefik with Automated Cloudflare ResponseThis article shows how a customized Elastic Security ES|QL detection rule can identify web server probing and fuzzing activity in Traefik logs and automatically block the attacking IP via Cloudflare.ELASTIC.CO
8 MayMeet Rassvet, Russia’s Answer to StarlinkWith the launch of the first 16 satellites, Russia begins construction of a network for satellite internet that aims to cover the entire country by 2030. But getting there won’t be easy.WIRED.COM
8 MayAI, Cyberwarfare, and Autonomous Weapons: Inside America’s New Military StrategyThe Pentagon is integrating AI into military operations, transforming cybersecurity, targeting, and command systems into a unified warfare architecture. May 2026 marks a turning point in the evolution of modern warfare: the convergence of artificial intelligence, cybersecurity, a…SECURITYAFFAIRS.COM
8 MaySri Lanka makes 37 arrests as it raids another scam centreYou don't need to live near a scam compound for it to wreck your life. Americans lost $5.8 billion to crypto investment scams last year alone - and a raid in Sri Lanka this month shows exactly how the operations behind them keep finding new places to hide. Read more in my article…BITDEFENDER.COM
8 MayOne Missed Threat Per Week: What 25M Alerts Reveal About Low-Severity RiskThe dark secret of enterprise security operations is that defenders have quietly institutionalized the practice of not looking. This is not just anecdotal, but rather backed by a recent report investigating more than 25 million security alerts, including informational and low-sev…THEHACKERNEWS.COM
8 MayShinyHunters escalates Canvas attacks with school login defacementsDays after the first attack, ShinyHunters is applying pressure with ransom messages on school login portals.MALWAREBYTES.COM
8 MayInside Department 4: Russia’s secret school for hackersMost universities have a careers fair. At Bauman Moscow State Technical University, however, an elite group of students appear to have something rather more unusual: a direct pipeline into some of the world's most notorious state-sponsored hacking groups. Read more in my article …BITDEFENDER.COM
8 MayOne in eight UK workers has sold their company passwords, and bosses think it’s fineOne in eight UK workers admits to selling their company login credentials - or knowing someone who has - in the past 12 months. The really alarming bit? Their bosses are even more relaxed about it. Read more in my article on the Fortra blog.FORTRA.COM
8 MayThe Evolution of Kaspersky SIEM | Kaspersky official blogThe evolution of correlation rules in the Kaspersky Unified Monitoring and analysis SIEM system.KASPERSKY.COM
8 MayFake Call History Apps Stole Payments From Users After 7.3 Million Play Store DownloadsCybersecurity researchers have discovered fraudulent apps on the official Google Play Store for Android that falsely claimed to offer access to call histories for any phone number, only to trick users into joining a subscription that provided fake data and incurred financial loss…THEHACKERNEWS.COM
8 MayUS defense contractor who sold hacking tools to Russian broker ordered to pay $10M to former employersFormer cybersecurity executive Peter Williams stole several surveillance and hacking tools and sold them for $1.3 million to a Russian broker that works with Putin’s government.TECHCRUNCH.COM
8 MayVirginia man found guilty of deleting 96 government databasesA Virginia man was convicted on federal charges Thursday after a jury found him guilty of deleting 96 government databases and stealing an individual’s password, leading their email account to be accessed without permission.THERECORD.MEDIA
8 MayGM to pay over $12 million in California privacy settlement involving driver dataThe settlement, announced by California officials Friday, is the largest fine issued under the California Consumer Privacy Act (CCPA) in its more than five-year history.THERECORD.MEDIA
8 MayShinyHunters Claims Second Attack Against InstructureThe edtech company is struggling to wrest control from its hackers. PII belonging to hundreds of millions of people is on the line.DARKREADING.COM
8 MaySee and Secure Everything at the Edge with Wiz and AkamaiAkamai edge configurations are now visible on the Wiz Security Graph, giving teams a single understanding of risk from edge to runtimeWIZ.IO
7 MayPCPJack | Cloud Worm Evicts TeamPCP and Steals Credentials at ScaleCloud attack framework skips cryptomining, harvests financial, messaging, and enterprise credentials for fraud, spam, and potential extortion.SENTINELONE.COM
7 MayThousands of Vibe-Coded Apps Expose Corporate and Personal Data on the Open WebCompanies like Lovable, Base44, Replit, and Netlify use AI to let anyone build a web app in seconds—and in thousands of cases, spill highly sensitive data onto the public internet.WIRED.COM
7 May'TrustFall' Exposes Claude Code Execution RiskResearchers find malicious repositories can trigger code execution in Claude Code with minimal or no user interaction.DARKREADING.COM
7 MayOperation HookedWing: 4-Year Multi-Sector Attack AnalysisOperation HookedWing: 4-Year Multi-Sector Phishing Campaign From 2022 to the present, a persistent phishing campaign that has not been publicly documented until now, referred to in this report as Operation HookedWing, has been compromising organizations across multiple sectors an…SOCRADAR.IO
7 MayPolice arrest SMS blaster crew that sent malicious messages to thousands across TorontoToronto police said this is the "first known instance" of an SMS blaster being used in Canada.TECHCRUNCH.COM
7 May2 days left: Get 50% off a second pass to TechCrunch Disrupt 2026Two days left to save up to $410 on your pass, and get a second one at 50% off to TechCrunch Disrupt 2026. Offer ends May 8, 11:59 p.m. PT. Register now.TECHCRUNCH.COM
7 MayMassive AI investment scam network spans 15,500 domainsAI investment scammers abused the Keitaro ad-tracking platform to cloak their campaign, exposing it only to likely targets.MALWAREBYTES.COM
7 MayLegacy Security Tools Are Failing Data Protection, Capital One Software Report FindsTraditional network security tools are undermining data protection, with Forrester and Capital One Software research warning AI adoption is impossible without rethinking data securityINFOSECURITY-MAGAZINE.COM
7 MayCline Kanban Flaw Lets Websites Hijack AI Coding AgentsOasis Security finds critical Cline kanban WebSocket flaw exposing AI coding agents to hijackINFOSECURITY-MAGAZINE.COM
7 MayHow Anthropic’s Mythos has rewritten Firefox’s approach to cybersecuritySecurity researchers at Mozilla say Anthropic's Mythos has unearthed a wealth of high-severity bugs in Firefox.TECHCRUNCH.COM
7 MayAWS achieves SNI 27017, SNI 27018, and SNI 9001 certifications for the AWS Asia Pacific (Jakarta) RegionAmazon Web Services (AWS) achieved three Standar Nasional Indonesia (SNI) certifications for the AWS Asia Pacific (Jakarta) Region: SNI ISO/IEC 27017:2015, SNI ISO/IEC 27018:2019, and SNI ISO 9001:2015. SNI represents Indonesia’s national standards framework, comprising standards…AWS.AMAZON.COM
7 MayHow to Disable Google's Gemini in ChromeChrome users were caught off guard by a 4-GB Google AI model baked into Chrome, sparking privacy concerns. The good news: You can easily uninstall it. The bad? You might not want to.WIRED.COM
7 MayBuild Fast, Build Secure: Wiz findings are now in LovableWith Wiz in Lovable, every builder can catch and fix risks in real time, keeping apps secure as they’re createdWIZ.IO
7 MayIt's Time to Go After Achieving Zero Code CriticalsReady to hit Zero Code Criticals? Here's how Wiz helps you get there and stay there, with the badge to prove you did.WIZ.IO
6 MayWeekly Threat Bulletin – May 6th, 2026These are the top threats you should know about this week.F5.COM
6 MayOne in Eight Workers Has Sold Their Corporate LoginsCifas says that 13% of employees admit selling company credentials to a former colleagueINFOSECURITY-MAGAZINE.COM
6 MayFrom Stuxnet to ChatGPT: 20 News Events That Shaped CyberAs part of Dark Reading's 20th anniversary celebration, its staff looks back on 20 of the biggest newmaking events from the past two decades that shaped our industry and the risk landscape for today's security teams.DARKREADING.COM
6 MayThe Hacker News Launches 'Cybersecurity Stars Awards 2026' — Submissions Now OpenFor nearly 20 years, we at The Hacker News have mostly told scary stories about cyberspace — big hacks, broken systems, and new threats. But behind every headline, there’s a quieter, better story. It’s the story of leaders making tough calls under pressure, teams building smarter…THEHACKERNEWS.COM
6 MayYour AI Agents Are Already Inside the Perimeter. Do You Know What They're Doing?Analysts recently confirmed what identity security teams have quietly feared: AI agents are being deployed faster than enterprises can govern them. In their inaugural Market Guide for Guardian Agents, Gartner states that “enterprise adoption of AI agents is accelerating, outpacin…THEHACKERNEWS.COM
6 MayHackers compromise Daemon Tools in global supply-chain attack, researchers sayResearchers at Kaspersky said attackers tampered with installers for Daemon Tools — a popular program used to mount disk images as virtual drives — and distributed them through the software’s official website.THERECORD.MEDIA
6 MayGoogle Chrome’s silent 4GB AI download problemGoogle Chrome writes a 4GB AI model to users’ devices without asking, and reinstalls it if you delete it.MALWAREBYTES.COM
6 MayXBOW secures an additional $35 million in Series C funding.Palo Alto Networks will acquire AI security gateway company Portkey.THECYBERWIRE.COM
6 MayA Kid With a Fake Mustache Tricked an Online Age-Verification ToolTo stop children from bypassing its age checks, Meta is revamping its age-verification tools with an AI system that analyzes images and videos for “visual cues,” such as height and bone structure.WIRED.COM
6 MayAfter 17 years, Gavril Sandu extradited to U.S. for hacking schemeRomanian citizen Gavril Sandu was extradited to the U.S. nearly 17 years after a hacking scheme. He was indicted in 2017 and arrested in 2026. Romanian national Gavril Sandu, 53, has been extradited to the United States for his role in a hacking scheme that took place 17 years ag…SECURITYAFFAIRS.COM
6 MayTaiwan High-Speed Rail Emergency Braking Hack: How a Student Stopped the Trains and Exposed a Major Security GapTaiwan high‑speed rail was disrupted after a 23‑year‑old student spoofed signals and triggered an emergency alarm, stopping four trains for nearly an hour. Taiwan high‑speed rail system, one of the most important pieces of national infrastructure, was thrown into chaos during the…SECURITYAFFAIRS.COM
5 MayElastic Workflows GA: automation where your security data already livesElastic Workflows is generally available in 9.4, bringing production-ready security automation with deeper case management integration, human-in-the-loop support, natural language authoring, and more.ELASTIC.CO
5 MayThe Back Door Attackers Know About — and Most Security Teams Still Haven’t ClosedEvery AI tool, workflow automation, and productivity app your employees connected to Google or Microsoft this year left something behind: a persistent OAuth token with no expiration date, no automatic cleanup, and in most organizations, no one watching it. Your perimeter controls…THEHACKERNEWS.COM
5 MayCleartext Passwords in MS Edge? In 2026?, (Mon, May 4th)Yup, that is for real.
ISC.SANS.EDU
5 MaySSL.com rotates their root certificate today, (Tue, May 5th)I just got an email from SSL.com last night, they are rotating &#;x26;#;xc2;&#;x26;#;xa0;out their root certificate today (May 5,2026). &#;x26;#;xc2;&#;x26;#;xa0;This i…ISC.SANS.EDU
5 MayCloudZ RAT potentially steals OTP messages using Pheno pluginCisco Talos discovered an intrusion, active since at least January 2026, where an unknown attacker implanted a CloudZ remote access tool (RAT) and a previously undocumented plugin called “Pheno.”TALOSINTELLIGENCE.COM
5 MayAI Adoption Outpaces Safety Policies, Leaving Organizations Exposed to Cyber RiskISACA report warns that while AI has become the norm, many organizations are yet to formally apply safety or security policies around its useINFOSECURITY-MAGAZINE.COM
5 May4 days left: Get 50% off a second TechCrunch Disrupt 2026 pass to make more deals fasterFor the next four days only, you can buy one pass to TechCrunch Disrupt 2026 and get 50% off a second of the same ticket type. That window closes May 8 at 11:59 p.m. PT. After that, prices go up, and you’ll pay more to bring a partner or colleague. Register today to get your plus…TECHCRUNCH.COM
5 MayIntroducing AI traffic analysis dashboards for AWS WAFAs AI agents, bots, and programmatic access become an increasingly significant portion of web traffic, organizations need better tools to understand, analyze, and manage this activity. Today, we’re excited to announce AI Traffic Analysis dashboards for AWS WAF protection packs—al…AWS.AMAZON.COM
5 MayIntroducing Penetration Test Findings: Unified Offensive Security in WizStreamline pen-testing by unifying findings from bug bounties, manual audits, and Wiz Red Agent into a single, context-rich view.WIZ.IO
4 MayBluekit phishing kit enables automated phishing with 40+ templates and AI toolsBluekit is a new phishing kit with AI features, automated domain setup, and tools like spoofing, voice cloning, and 40+ attack templates. Bluekit is a newly discovered phishing kit still in development that includes advanced features such as an AI assistant and automated domain r…SECURITYAFFAIRS.COM
4 MayHow OpenClaw’s agent skills become an attack surfaceOpenClaw and similar AI agent ecosystems, present pressing security risks.CYBERSECURITYDIVE.COM
4 May“Legitimate” phishing: how attackers weaponize Amazon SES to bypass email securityKaspersky expert breaks down a new phishing scheme that uses the Amazon SES cloud email service. Let's look at some examples to see how you can tell a phishing email from a real one.SECURELIST.COM
4 MayTeenager alleged to be Scattered Spider hacker arrested in Finland, faces US extraditionHere's a tip for you all. Unless you want to draw attention to yourself as a cybercriminal, don't flaunt your diamond-encrusted "HACK THE PLANET" necklace on Snapchat, or pose as a Sopranos crime boss while the FBI is reportedly closing in. Read more in my article on the Hot for …BITDEFENDER.COM
4 MayThe motivation of droids from the “Star Wars” universe | Kaspersky official blogHow and why droids from “Star Wars: Skeleton Crew” and “Andor” switch their allegiances.KASPERSKY.COM
4 MayThousands of Facebook accounts stolen by phishing emails sent through GoogleIn an ongoing operation, hackers are hijacking Facebook accounts using Google AppSheet to send phishing emails that pass security checks.MALWAREBYTES.COM
4 MayThe 2026 World Cup scam economy is already running before the first whistleA four-part scam economy is already forming around the 2026 World Cup, using the tournament’s brand to sell everything from fake visas to worthless tokens.MALWAREBYTES.COM
4 MayHow Dark Reading Lifted Off the Launchpad in 2006Twenty years ago, this media brand didn't have a print edition to attract eyeballs and sponsors. Top-notch content and editorial talent did the heavy lifting.DARKREADING.COM
4 MayDShield Honeypot Update, (Mon, May 4th)This week, I will release a few updates to our DShield honeypot. The update should happen automatically if you have "automatic updates" enabled on your system. There will be two major changes:
ISC.SANS.EDU
4 MayUS healthcare marketplaces shared citizenship and race data with ad tech giantsVirginia and Washington D.C. paused the data collection and sharing, after Bloomberg's investigation found their health insurance marketplaces were sharing users' information with advertisers.TECHCRUNCH.COM
4 May5 days only: Bring a partner or colleague and get 50% off a second TechCrunch Disrupt 2026 passThe BOGO offer is live. For a limited time, buy one pass to TechCrunch Disrupt 2026 and get 50% off a second of the same ticket type. Offer ends this Friday, May 8. Save here.TECHCRUNCH.COM
4 MayDHS Demanded Google Surrender Data on Canadian's Activity, Location Over Anti-ICE PostsUsing a 1930s trade law, Homeland Security targeted the man—who hasn't entered the US in more than a decade—following posts on X condemning the killings of Renee Good and Alex Pretti.WIRED.COM
4 MayForbes preliminarily agrees to pay $10 million to settle California wiretapping lawsuitThe preliminary settlement agreement, released on Thursday, said that Forbes has agreed to give users “greater notice” of its use of trackers and will add language to its website providing California residents with more control over how their data is collected and shared with thi…THERECORD.MEDIA
4 MayProgress Patches Critical MOVEit Automation Bug Enabling Authentication BypassProgress Software has released updates to address two security flaws in MOVEit Automation, including a critical bug that could result in an authentication bypass. MOVEit Automation (formerly Central) is a secure, server-based managed file transfer (MFT) solution used to schedule …THEHACKERNEWS.COM
4 MayTeamPCP Weekly Analysis: 2026-W18 (2026-04-27 through 2026-05-03), (Mon, May 4th)Summary
ISC.SANS.EDU
4 MaySecuring open proxies in your AWS environmentThis article shows you how to identify and secure open proxies in your AWS environment to prevent abuse, protect your IP address reputation, and control costs. An open proxy is a server that forwards traffic on behalf of internet users without requiring authentication. While prox…AWS.AMAZON.COM
4 MayRMM Tools Fuel Stealthy Phishing CampaignAttackers are abusing two remote monitoring and management (RMM) tools to evade detection in a campaign that has impacted over 80 organizations so far.DARKREADING.COM
4 MayPractical Package Security: The Unofficial GuideGet actionable best practices to shrink your attack surface, protect execution environments, control package ingestion, and catch compromises early.WIZ.IO
4 MayMeet Wiz for M365: Bringing SaaS into the Security GraphSecure Microsoft 365 and the cloud it powers — one platform, one graph, complete context.WIZ.IO
3 May3 easy-to-miss cybersecurity risks for small businessesSmall business owners should be sure to fix these three non-technical risks that require little cybersecurity expertise.MALWAREBYTES.COM
2 MayDisneyland Now Uses Face Recognition on VisitorsPlus: The NSA tests Anthropic’s Mythos Preview to find vulnerabilities, a Finnish teen is charged over the Scattered Spider hacking spree, and more.WIRED.COM
1 MayEnterprise Spotlight: Transforming software development with AIArtificial intelligence has had an immediate and profound impact on software development. Coding practices, coding tools, developer roles, and the software development process itself are all being reimagined as AI agents advance on every stage of the software development life cyc…US.RESOURCES.CSOONLINE.COM
1 MayTop Five Sales Challenges Costing MSPs Cybersecurity RevenueThe managed security services market is projected to grow from $38.31 billion in 2025 to $69.16 billion by 2030[1], with cybersecurity being the fastest-growing sector[2]. Despite this opportunity, many MSPs leave revenue on the table because their go-to-market strategy fails to …THEHACKERNEWS.COM
1 May20 Years in Cyber: Dark Reading Marks Milestone With Month of Special CoverageOn this day in 2006, Dark Reading went live. We have a celebration planned that spans our two decades of covering the industry, and you, dear readers, are invited.DARKREADING.COM
1 MayCybercrime Groups Using Vishing and SSO Abuse in Rapid SaaS Extortion AttacksCybersecurity researchers are warning of two cybercrime groups that are carrying out "rapid, high-impact attacks" operating almost within the confines of SaaS environments, while leaving minimal traces of their actions. The clusters, Cordial Spider (aka BlackFile, CL-CRI-1116, O-…THEHACKERNEWS.COM
1 MayCarding service Jerry’s Store leak exposes 345,000 stolen payment cardsJerry’s Store, a card-checking service used by cybercriminals, exposed 345,000 stolen payment cards after leaving its server open, revealing sensitive data. A cybercriminal operation known as Jerry’s Store has reportedly exposed a large cache of stolen payment card data after lea…SECURITYAFFAIRS.COM
1 MayUbuntu services hit by outages after DDoS attackA group of hacktivists have claimed responsibility for a distributed denial-of-service attack, which has affected several Ubuntu and Canonical websites, and prevented users from updating the Linux-based operating system.TECHCRUNCH.COM
1 MayIf AI's So Smart, Why Does It Keep Deleting Production Databases?The issue isn't artificial intelligence, but rather an industry adding AI agent integrations into production environments before proper security testing.DARKREADING.COM
1 MaySenate Judiciary advances bill that would bar minors from interacting with AI companionsThe bill, known as the GUARD Act, also requires that AI companions advise users of all ages that they are not human and lack professional credentials. It also makes it a crime for AI companions to knowingly ask kids for sexual content or to produce it.THERECORD.MEDIA
1 MayDigital attacks drive a new wave of cargo theft, FBI saysThe FBI warns of rising cyber cargo theft, with hackers targeting brokers and carriers. Experts say digital attacks are replacing traditional cargo theft. The FBI has issued a Public Service Announcement (PSA) about a surge in cyber-enabled cargo theft, with hackers increasingly …SECURITYAFFAIRS.COM
1 MaySecurity posture improvement in the AI eraIt’s only been a few weeks since Anthropic announced the Claude Mythos Preview model and launched Project Glasswing with AWS and other leading organizations. This has generated a lot of discussion about the future of cybersecurity and what the ever-increasing capabilities of foun…AWS.AMAZON.COM
1 MaySocial Engineering Leveled Up. Has Your Security Program?Social engineering has evolved. Device code phishing and AI lures bypass MFA and blend in. Build a cyber resilience strategy before the next attack lands.HUNTRESS.COM
1 MayHow Much Does Anthropic’s Mythos Change Enterprise Security?There has been a significant amount of interest by CISOs in the impact of frontier artificial intelligence (AI) models for offensive and defensive purposes following Anthropic’s Claude Mythos Preview release April 7, 2026.INTEL471.COM
30 AprClaude Mythos Fears Startle Japan's Financial Services SectorGlobal financial institutions are panicked over Anthropic's new superhacker AI model. Cyber experts aren't quite as worried.DARKREADING.COM
30 AprAll rise for the Chatrie.This week, Dave and Ben sit down with N2K's Lead Analyst Ethan Cook to look at the Supreme Court's new case examining geofencing. In the conversation, the three break down the various stances the justice's have already begun to take up and what the potential fallouts of this case…THECYBERWIRE.COM
30 AprIran-linked Handala hackers leak US Marines data, send chilling WhatsApp threatsUS Marines stationed around the Persian Gulf have been receiving WhatsApp messages from strangers suggesting they call home and make their final goodbyes. Read more in my article on the Hot for Security blog.BITDEFENDER.COM
30 AprEuropol Busts Albanian Scam Call Centers in Major Online Fraud CaseEuropean police arrested 10 suspects after dismantling Albanian scam call centers linked to a €50m ($58m) online investment fraud operationINFOSECURITY-MAGAZINE.COM
30 AprPost-quantum encryption for Cloudflare IPsec is generally availableCloudflare IPsec now has generally available support for post-quantum encryption via hybrid ML-KEM. We’ve confirmed interoperability with Cisco and Fortinet.CLOUDFLARE.COM
30 AprOracle Red Bull Racing Team Revs Up Automation to Boost SecurityWhile drivers race to shave off seconds on the track, the team's IT and engineering staff are speeding up how they deliver security.DARKREADING.COM
30 AprDental practice software maker fixes bug that exposed patients’ medical recordsThe security bug is now fixed, but the patient who found it said it was challenging to alert the software company about the issue.TECHCRUNCH.COM
30 AprHackers stole hundreds of thousands of Roblox accounts: Here’s what to doHackers used fake Roblox “game enhancements” to steal login details from hundreds of thousands of players, then sold the accounts for profit.MALWAREBYTES.COM
30 AprTrump’s cyber ambassador nominee advances to full Senate voteAdam Cassady, who was nominated last month to helm the State Department’s Bureau of Cyberspace and Digital Policy, was approved by a vote of 17-5.THERECORD.MEDIA
30 AprOpenAI Rolls Out ‘Advanced’ Security Mode for At-Risk AccountsOpenAI is rolling out Advanced Account Security for people concerned that their ChatGPT or Codex accounts could be potential targets of phishing attacks.WIRED.COM
30 AprAfter dissing Anthropic for limiting Mythos, OpenAI restricts access to Cyber, tooOpenAI will begin rolling out it cybersecurity testing tool, GPT-5.5 Cyber only "to critical cyber defenders" at first.TECHCRUNCH.COM
30 AprGreat responsibility, without great powerIn this week’s newsletter, Hazel uses International Superhero Day as a springboard to explore why empathy — rather than just technical prowess — is the most essential, underrated superpower for navigating the human side of cybersecurity.TALOSINTELLIGENCE.COM
30 AprMore PayPal emails hijacked to deliver tech support scamsWe investigate how scammers are abusing PayPal’s systems to push victims into calling fake support numbers.MALWAREBYTES.COM
30 AprOne copy too many.A critical Linux flaw dubbed “Copy Fail” raises alarm. The House moves to extend Section 702. The White House pushes back on expanded Mythos access. cPanel and SonicWall rush out security patches. Researchers warn AI agents may leak credentials. Smishing targets key industries. U…THECYBERWIRE.COM
30 AprAnthropic's Mythos Has Landed: Here's What Comes Next for CyberIn this latest installment of the Reporters' Notebook video series, we discuss how the new AI model threatens to completely upend cybersecurity, and what industry leaders are telling the press.DARKREADING.COM
30 AprCongress punts FISA renewal to JuneThe latest House action came after the Senate declared the previous bill dead on arrival because it included a ban on the Federal Reserve’s ability to issue a digital currency. Instead, the upper chamber approved a 45-day extension by unanimous consent.THERECORD.MEDIA
30 AprRed Agent and Claude Opus: Securing Production Targets at ScaleDelivering enterprise-grade continuous AI-powered risk assessment to hundreds of customers through the combined power of Wiz and AnthropicWIZ.IO
30 AprThe (In)security Landscape of AI-Powered GitHub Actions (Part 2/2)When AI meets CI/CD: permission bypasses, prompt injection, and what to do about it.WIZ.IO
29 AprWeekly Threat Bulletin – April 29th, 2026These are the top threats you should know about this week.F5.COM
29 AprA Quarter of Healthcare Organizations Report Medical Device Cyber-AttacksRunSafe report reveals most attacks on medical devices disrupt patient careINFOSECURITY-MAGAZINE.COM
29 AprWhat to Look for in an Exposure Management Platform (And What Most of Them Get Wrong)Every security team has a version of the same story. The quarter ends with hundreds of vulnerabilities closed. The dashboards are bursting with green. Then someone in a leadership meeting asks: "So, are we actually safer now?" Crickets. The room goes quiet because an honest answe…THEHACKERNEWS.COM
29 AprToday's Odd Web Requests, (Wed, Apr 29th)Today, two different "new" requests hit our honeypots. Both appear to be recon requests and not associated with specific vulnerabilities. But as always, please let me know if you have additional information
ISC.SANS.EDU
29 AprMalicious npm Dependency Linked to AI Assisted Commit Targets Crypto WalletsResearchers uncover a malicious npm dependency linked to an AI‑assisted code commit that steals sensitive data and exposes crypto walletsINFOSECURITY-MAGAZINE.COM
29 AprWhat Is Dark Web Monitoring?What Is Dark Web Monitoring? Every day, stolen credentials, leaked records, and sensitive data show up in hidden corners of the internet. Most security tools never reach those places. Dark Web Monitoring does. In this guide, you will learn the Dark Web Monitoring meaning, how it …SOCRADAR.IO
29 AprCursor Extension Flaw Exposes Developer API KeysCursor flaw lets extensions steal API keys and session tokens without user interaction, according to researchers at LayerXINFOSECURITY-MAGAZINE.COM
29 AprInternet censorship index reveals Russia’s lead and widespread content blockingGlobal study shows targeted internet censorship worldwide, with Russia leading; VPNs, news, and adult content are most frequently blocked categories. The Global Internet Censorship Index 2026 offers a clear view of how governments around the world control online access. Researche…SECURITYAFFAIRS.COM
29 AprVehicle-based surveillance tools | Kaspersky official blogAn inside look at who uses built-in automotive tracking and how you can avoid being monitoredKASPERSKY.COM
29 AprDesigning trust and safety into Amazon Bedrock powered applicationsGenerative AI brings promising innovation, transforming how individuals and organizations approach everything from customer service to content creation and more. As AI continues to expand its capabilities, organizations are increasingly focused on how they can integrate the respo…AWS.AMAZON.COM
29 AprCloudsmith raises $72 million in Series C funding.Spectrum Security emerges from stealth with $19 million. Israeli data security company Cyera acquires Ryft.THECYBERWIRE.COM
29 AprUS, China partner on scam center takedown in DubaiThe Justice Department said the operation began last year following “numerous” victim complaints to the FBI by U.S. victims who lost millions through cryptocurrency investment fraud schemes.THERECORD.MEDIA
29 AprResearchers built a chatbot that only knows the world before 1931What happens when you strip the internet out of AI? Researchers built a chatbot that only knows the world before 1931.MALWAREBYTES.COM
29 AprHouse approves spy program on second attempt, Senate fate murkyThe bill, which passed 235-191, would renew Section 702 of the Foreign Intelligence Surveillance Act for three years.THERECORD.MEDIA
29 AprProject Swarm: Join the Collective. Defend the EdgeToday, we're launching Project Swarm — a research initiative that opens the GreyNoise deception platform to the global security community. Project Swarm transforms GreyNoise from a proprietary sensor network into a collective intelligence platform.GREYNOISE.IO
29 AprKey Takeaways from the 2026 State of AI in the Cloud ReportHow AI Adoption, Autonomy, and Attacker Innovation Are Reshaping Cloud SecurityWIZ.IO
28 AprChinese engineer stole US military and NASA software for yearsHe created Gmail accounts, impersonated real US researchers, and convinced NASA, the military, and universities to hand over sensitive code.MALWAREBYTES.COM
28 AprFrom DMV to Wallet: Understanding Verifiable Digital Credential IssuanceIn our last post in this series, we compared two credential formats that shape the digital identity ecosystem: ISO/IEC 18013-5 and -7 mobile documents (mdocs) and W3C Verifiable Credentials (VCs). Both formats define how a credential is structured and shared, but neither can func…NIST.GOV
28 AprThe Hunt for American Turncoats in World War II EuropeIt’s a story that journalist and veteran Stephen Harding uncovered: a secret component of the FBI’s “European Operation,” whereby agents traveled abroad working undercover to track down American citizens who had betrayed their country during World War II. These traitors ran the g…THECYBERWIRE.COM
28 AprFrom the Kaiser to the Führer: Inside the World of Lothar WitzkeOne of the more notorious German spies of the 20th century, Lothar Witzke lived a life of intrigue: from escaping the death penalty in the First World War to joining the Nazi party in the Second. It's a story that Robert Hornick and Paul Friedland stumbled on by chance. With help…THECYBERWIRE.COM
28 AprA practical guide to secure vibe-coding for small businesses | Kaspersky official blogConfiguration and prompting tips to get an AI assistant to write more secure code.KASPERSKY.COM
28 AprFive defender priorities from the Talos Year in ReviewWith attackers moving faster than ever, it’s easy to feel overwhelmed. This blog breaks down five practical priorities from the Cisco Talos 2025 Year in Review to help defenders focus and prioritize, amidst all the noise.TALOSINTELLIGENCE.COM
28 AprUkrainian police detain hackers suspected of stealing thousands of Roblox accounts for resalePolice said on Monday the victims included both Ukrainian and foreign players whose accounts contained valuable digital items, rare equipment and in-game currency purchased with real money.THERECORD.MEDIA
28 AprThe Race Is on to Keep AI Agents From Running Wild With Your Credit CardsAI agents may soon be buying your stuff for you. The FIDO Alliance has teamed up with Google and Mastercard to try to ensure that shopping in the near future isn't a complete disaster.WIRED.COM
28 AprUS Supreme Court appears split over controversial use of ‘geofence’ search warrantsThe U.S. top court is expected to rule on whether to allow police to identify criminal suspects by dragnet searching the databases of tech giants.TECHCRUNCH.COM
28 AprCyber Command, NSA chief warns foreign adversaries likely to target midtermsArmy Gen. Joshua Rudd told lawmakers “we are postured and ready to support as required or tasked, making sure that we safeguard our elections.”THERECORD.MEDIA
28 AprNSA Chief During Snowden Affair Shares Regrets, Reflections 13 Years LaterChris Inglis was the head civilian in charge at the NSA when the Snowden leak exploded. He gets candid about mistakes the organization made, and what CISOs need to know about spotting potential threats, media disclosures, and "enculturation."DARKREADING.COM
27 AprWhen security becomes the attack surface: Why endpoint protection must evolveWhen attackers target security tools, protection must be resilient, self-healing and always on.CYBERSECURITYDIVE.COM
27 AprBlackFile Group Targets Retail and Hospitality with Vishing AttacksResearchers uncover a new data theft and extortion group dubbed “BlackFile”INFOSECURITY-MAGAZINE.COM
27 AprMost Cybersecurity Professionals Feel Undervalued and UnderpaidA new report by global technology recruitment firm, Harvey Nash, found that three quarters of cybersecurity staff are pessimistic on pay and half are looking for a new jobINFOSECURITY-MAGAZINE.COM
27 AprParsing Agentic Offensive Security's Existential ThreatSome fear frontier LLMs like Claude Mythos and Anthropic's GPT-5.5 will lead to cybersecurity annihilation. Ari Herbert-Voss notes this could be an opportunity.DARKREADING.COM
27 AprWidely Used Browser Extensions Selling User DataDozens of browser extensions openly sell user data via privacy policy disclosuresINFOSECURITY-MAGAZINE.COM
27 AprChinese spy posed as researcher in spear-phishing campaign targeting NASA to steal defense softwareA Chinese national posed as a U.S. researcher, tricking NASA staff in a phishing campaign to steal sensitive data tied to defense software and exports. A Chinese national ran a spear-phishing campaign by posing as a U.S. researcher and tricked NASA employees into sharing sensitiv…SECURITYAFFAIRS.COM
27 AprUS Sanctions Target Cambodian Scam Network LeadersUS sanctions target Cambodian scam networks tied to crypto fraud and traffickingINFOSECURITY-MAGAZINE.COM
27 AprDisinformation campaign targeted Tibetan parliament-in-exile electionsThe operation, identified by the Digital Forensic Research Lab (DFRLab), was part of Spamouflage, a long-running influence network linked to Beijing.THERECORD.MEDIA
27 AprItaly extradites alleged Chinese state hacker to USA Chinese national accused of being a member of a state-backed hacking group that allegedly broke into systems to steal COVID-19 vaccine information has been extradited to the U.S. from Milan.THERECORD.MEDIA
27 AprCan I do that with policy? Understanding the AWS Service Authorization ReferenceUnderstanding what AWS Identity and Access Management (IAM) policies can control helps you build better security controls and avoid spending time on approaches that won’t work. You’ve likely encountered questions like: Can I use AWS Organizations service control policies (SCPs) t…AWS.AMAZON.COM
27 AprUS Supreme Court weighs legality of geofence warrants.Researchers analyze a cyber sabotage framework that predates Stuxnet. Toronto police arrest three men accused of operating an SMS blaster.THECYBERWIRE.COM
27 AprMoney launderer for crypto thieves given 5-year sentenceA California man was sentenced to more than five years in prison for his role in supporting a cybercriminal organization that stole about $260 million worth of cryptocurrency from victims.THERECORD.MEDIA
27 AprCole Allen Charged With Attempting to Assassinate TrumpThe suspected shooter at Saturday night’s White House Correspondents’ Dinner faces three felony charges. He remains in custody following Monday’s hearing.WIRED.COM
27 AprSupreme Court signals location data searches should require a warrantPrivacy advocates had worried that the high court would rule that geofencing does not qualify as a constitutionally protected search, opening the door to much broader use of warrantless reverse searches of all types.THERECORD.MEDIA
27 AprTennessee becomes second state to ban cryptocurrency ATMs over scam concernsState officials said they observed overseas criminals carrying out government impersonation or tech support cons, as well as romance and pig butchering scams using cryptocurrency ATMs.THERECORD.MEDIA
26 AprCalifornia Engineer Identified in Suspected Shooting at White House Correspondents' DinnerThe 31-year-old engineer and self-described indie game developer is suspected of firing shots at the annual event attended by President Donald Trump, high-profile media figures, and US government officials.WIRED.COM
25 AprMonitoring Claude Code/Cowork at scale with OTel in ElasticHow Elastic's InfoSec team built a monitoring pipeline for Claude Code and Claude Cowork using their native OTel export capabilities and Elastic's OTel ingestion infrastructure.ELASTIC.CO
25 AprA QRazy clever scam.This week, we are joined by Juliana Testa, Senior Security Engineer from 7AI, sharing their work on "Quish Splash - When the QR Code Is the Weapon: A Multi-Wave Phishing Campaign That Slipped Past Every Filter." A large-scale “quishing” campaign used QR codes embedded in imag…THECYBERWIRE.COM
24 AprBridging the AI Agent Authority Gap: Continuous Observability as the Decision EngineThe AI Agent Authority Gap - From Ungoverned to Delegation As discussed in our previous article, AI agents are exposing a structural gap in enterprise security, but the problem is often framed too narrowly. The issue is not simply that agents are new actors. It is that agents are…THEHACKERNEWS.COM
24 AprMedical data of 500,000 UK volunteers listed for sale on AlibabaDespite strict access controls, medical data from half a million UK Biobank volunteers ended up listed for sale on Alibaba.MALWAREBYTES.COM
24 AprAI Rush is Reviving Old Cybersecurity Mistakes, Mandiant VP WarnsAI tools are not just creating new vulnerabilities, they are reviving old security failures, warned Jurgen Kutscher, VP of Mandiant ConsultingINFOSECURITY-MAGAZINE.COM
24 AprToronto police arrest three in Canada’s first mobile SMS blaster caseCanadian police arrested three men over the use of a mobile “SMS blaster,” a device capable of impersonating a cellular tower to send mass phishing messages and disrupt mobile networks.THERECORD.MEDIA
24 AprThe Latest Push to Extend Key US Spy Powers Is Still a MessA US surveillance program that lets the FBI view Americans’ communications without a warrant is up for renewal. A new bill aims to address mounting lawmaker concerns—with smoke and mirrors.WIRED.COM
24 AprGlasswing Secured the Code. The Rest of Your Stack Is Still on YouForgotten integrations, shadow IT, SaaS, and now shadow AI and agents are everywhere, and attackers don't need sophisticated AI models to take advantage.DARKREADING.COM
24 AprPentagon grapples with securing AI as it moves toward autonomous warfareAutonomous weapons are becoming an "essential" part of modern war, Chairman of the Joint Chiefs of Staff Gen. Dan Caine told an audience at Vanderbilt University’s Asness Summit on Modern Conflict and Emerging Threats.THERECORD.MEDIA
24 AprProtecting your secrets from tomorrow’s quantum risksAs outlined in the AWS post-quantum cryptography (PQC) migration plan, addressing the risk of harvest now, decrypt later (HNDL) attack is an important part of your post-quantum plan. Upgrading the client-side of your workloads to support quantum-resistant confidentiality is an im…AWS.AMAZON.COM
24 AprUS Busts Myanmar Ring Targeting US Citizens in Financial FraudSome 29 people were charged, including a Cambodian senator, and authorities seized more than 500 Web domains tied to fake investment sites.DARKREADING.COM
24 AprEavesdropping via fiber-optic cables | Kaspersky official blogA side-channel attack that allows a fiber-optic cable to be used as a microphone.KASPERSKY.COM