no alarms and no surprises please..
-
Trend Micro warns of Apex One zero-day exploited in the wild
Trend Micro warns of Apex One zero-day exploited in the wild Japanese cybersecurity software company Trend Micro has addressed an Apex One zero-day vulnerability exploited in attacks targeting Windows systems. […] Sergiu Gatlan Go to bleepingcomputer
-
Drupal: Critical SQL injection flaw now targeted in attacks
Drupal: Critical SQL injection flaw now targeted in attacks Drupal is warning that hackers are attempting to exploit a “highly critical” SQL injection vulnerability announced earlier this week. […] Bill Toulas Go to bleepingcomputer
-
Why Chargebacks are Just One Piece of the Fraud Puzzle
Why Chargebacks are Just One Piece of the Fraud Puzzle Fraud losses don’t stop at chargebacks. False declines, account takeovers, and abuse also damage revenue and trust. IPQS breaks down why fraud teams need broader visibility into risk and customer impact. […] Sponsored by IPQS Go to bleepingcomputer
-
Hackers Compromised 233 Versions of Laravel-Lang Packages by Hacking 700 GitHub Repos
Hackers Compromised 233 Versions of Laravel-Lang Packages by Hacking 700 GitHub Repos A highly sophisticated supply chain attack has compromised the Laravel-Lang ecosystem, injecting credential-stealing remote code execution backdoors into 233 package versions across 700 GitHub repositories. Discovered in May 2026 by Socket and Aikido, threat actors manipulated GitHub tags to distribute malware through Composer’s…
-
Anthropic’s Claude Mythos Preview Uncovers 10,000+ 0-Days in Project Glasswing
Anthropic’s Claude Mythos Preview Uncovers 10,000+ 0-Days in Project Glasswing Anthropic has revealed the staggering initial results of Project Glasswing, a collaborative cybersecurity initiative designed to secure critical infrastructure using advanced AI before malicious actors can exploit it. In its first month, the project leveraged the unreleased Claude Mythos Preview model to autonomously discover over…
-
Hackers Abuse Middle East Telecom Networks for Large-Scale Command-and-Control Operations
Hackers Abuse Middle East Telecom Networks for Large-Scale Command-and-Control Operations Hackers are using telecom networks and hosting providers across the Middle East as a foundation for massive command-and-control operations, turning trusted infrastructure into a launchpad for cyberattacks. A newly released threat intelligence report reveals that more than 1,350 active command-and-control (C2) servers were identified across…
-
World Cup Phishing Campaign Nearly Triples With 203 Unique IP Addresses
World Cup Phishing Campaign Nearly Triples With 203 Unique IP Addresses A large-scale phishing campaign targeting the 2026 FIFA World Cup has grown far beyond what security researchers originally thought. What began as a documented set of 79 fraudulent domains has ballooned into a network of at least 222 domains spread across 203 unique IP…
-
Russian Threat Groups Use RDP, VPN, Supply Chain Attacks, and Social Engineering for Initial Access
Russian Threat Groups Use RDP, VPN, Supply Chain Attacks, and Social Engineering for Initial Access Russian state-sponsored threat groups significantly stepped up their cyber operations in 2025, using a range of methods to break into targeted systems. From exploiting remote desktop tools and virtual private networks to manipulating trusted supply chains and deceiving employees through…
-
Foul play: Fake FIFA websites target soccer fans looking for World Cup tickets, merchandise
Foul play: Fake FIFA websites target soccer fans looking for World Cup tickets, merchandise Watch out for bogus World Cup websites that mimic official ticket and merchandise flows to steal money and personal data Go to eset
-
First VPN Dismantled in Global Takedown Over Use by 25 Ransomware Groups
First VPN Dismantled in Global Takedown Over Use by 25 Ransomware Groups Authorities in Europe and North America have announced the dismantling of a criminal virtual private network (VPN) service used by criminal actors to obscure the origins of ransomware attacks, data theft, scanning, and denial-of-service attacks. Codenamed Operation Saffron, the disruption of First VPN…
-
Ghostwriter Targets Ukraine Government Entities with Prometheus Phishing Malware
Ghostwriter Targets Ukraine Government Entities with Prometheus Phishing Malware The Belarus-aligned threat actor known as Ghostwriter (aka UAC-0057 and UNC1151Ukraine’s National Security and Defense Council) has been observed using lures related to Prometheus, a Ukrainian online learning platform, to target government organizations in the country. The activity, per the Computer Emergency Response Team of Ukraine…
-
Megalodon GitHub Attack Targets 5,561 Repos with Malicious CI/CD Workflows
Megalodon GitHub Attack Targets 5,561 Repos with Malicious CI/CD Workflows Cybersecurity researchers have disclosed details of a new automated campaign called Megalodon that has pushed 5,718 malicious commits to 5,561 GitHub repositories within a six-hour window. “Using throwaway accounts and forged author identities (build-bot, auto-ci, ci-bot, pipeline-bot), the attacker injected GitHub Actions workflows containing base64-encoded…
-
Making Vulnerable Drivers Exploitable Without Hardware – The BYOVD Perspective
Making Vulnerable Drivers Exploitable Without Hardware – The BYOVD Perspective 1 Introduction This article provides a technical analysis of how many Windows kernel mode drivers can be interacted with from user mode without the hardware they were developed for. This work was motivated by driver-oriented vulnerability research and the need to evaluate the exploitability of…
-
Kimwolf DDoS Botnet Operator Arrested in Canada Over DDoS-for-Hire Attacks
Kimwolf DDoS Botnet Operator Arrested in Canada Over DDoS-for-Hire Attacks The U.S. Department of Justice (DoJ) on Thursday announced the arrest of a Canadian man in connection with allegedly operating a distributed denial-of-service (DDoS) botnet known as Kimwolf. In tandem, Jacob Butler (aka Dort), 23, Ottawa, Canada, has been charged with offenses related to the…
-
Friday Squid Blogging: Regulating Squid Fishing in the South Pacific
Friday Squid Blogging: Regulating Squid Fishing in the South Pacific The South Pacific Regional Fisheries Management Organization (SPRFMO) needs to regulate squid fishing in the South Pacific. As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered. Blog moderation policy. Bruce Schneier Go…
-
CISA Security Leak
CISA Security Leak Crazy story: Until this past weekend, a contractor for the Cybersecurity & Infrastructure Security Agency (CISA) maintained a public GitHub repository that exposed credentials to several highly privileged AWS GovCloud accounts and a large number of internal CISA systems. Security experts said the public archive included files detailing how CISA builds, tests…
-
Cross-Platform NPM Stealer, (Fri, May 22nd)
Cross-Platform NPM Stealer, (Fri, May 22nd) I found a Node.js stealer that looked pretty well obfuscated. The file was not running out-of-the-box because it was uploaded on VT as “extracted-decoded.js” (and reformated). The SHA256 is 049300aa5dd774d6c984779a0570f59610399c71864b5d5c2605906db46ddeb9[1]. It did not run properly in a sandbox so only a static analysis was performed. The key point is…
-
Lawmakers Demand Answers as CISA Tries to Contain Data Leak
Lawmakers Demand Answers as CISA Tries to Contain Data Leak Lawmakers in both houses of Congress are demanding answers from the U.S. Cybersecurity & Infrastructure Security Agency (CISA) after KrebsOnSecurity reported this week that a CISA contractor intentionally published AWS GovCloud keys and a vast trove of other agency secrets on a public GitHub account.…
-
Akamai Joins Growing Chorus of Vendors Betting Big on Secure Enterprise Browsers
Akamai Joins Growing Chorus of Vendors Betting Big on Secure Enterprise Browsers When Akamai announced its LayerX acquisition, the company joined a growing list of vendors adding secure enterprise browsers to their product portfolios. Jeffrey Schwartz Go to gbhackers.com
-
Verizon DBIR: Healthcare Fends Off Increased Social Engineering Attacks
Verizon DBIR: Healthcare Fends Off Increased Social Engineering Attacks Ransomware and vendor breaches persist, but the 2026 Data Breach Investigations Report (DBIR) highlights how evolving social engineering tactics make the sector more vulnerable. Arielle Waldman Go to gbhackers.com
-
Popular npm Package “art-template” Backdoored in Watering-Hole Attack
Popular npm Package “art-template” Backdoored in Watering-Hole Attack Hackers compromised the popular art-template npm package to inject a stealthy backdoor that redirected users’ browsers to a malicious watering‑hole site delivering a Coruna‑class… Delivered by PolitePaul service Go to gbhackers.com
-
Hackers Use Six-Layer Persistence on FreePBX Systems
Hackers Use Six-Layer Persistence on FreePBX Systems Hackers are actively exploiting FreePBX systems using a highly resilient six-layer persistence mechanism. The campaign has been attributed with high confidence to the threat… Delivered by PolitePaul service Go to gbhackers.com
-
CISA Issues Alert on Exploited Microsoft Defender Zero-Day Vulnerabilities
CISA Issues Alert on Exploited Microsoft Defender Zero-Day Vulnerabilities CISA has issued an urgent alert warning organizations about two newly disclosed zero-day vulnerabilities affecting Microsoft Defender, both added to the Known Exploited Vulnerabilities… Delivered by PolitePaul service Go to gbhackers.com
-
Hackers Weaponize NF-e Invoice Lures to Deploy Banana RAT
Hackers Weaponize NF-e Invoice Lures to Deploy Banana RAT Hackers are actively using Brazil’s electronic invoice system (NF-e) as a lure to distribute a sophisticated banking trojan known as Banana RAT. The campaign has… Delivered by PolitePaul service Go to gbhackers.com
-
Android Malware Secretly Signs Users Up for Premium Services
Android Malware Secretly Signs Users Up for Premium Services Android users are being targeted by a large-scale malware campaign that silently subscribes victims to premium mobile services without their knowledge. The malware campaign focuses… Delivered by PolitePaul service Go to gbhackers.com
-
US and Canada arrest and charge suspected Kimwolf botnet admin
US and Canada arrest and charge suspected Kimwolf botnet admin U.S. and Canadian authorities arrested and charged a Canadian man with operating the KimWolf distributed denial-of-service (DDoS) botnet, which infected nearly two million devices worldwide. […] Sergiu Gatlan Go to bleepingcomputer
-
Google accidentally exposed details of unfixed Chromium flaw
Google accidentally exposed details of unfixed Chromium flaw Google has accidentally leaked details about an unfixed issue in Chromium that keeps JavaScript running in the background even when the browser is closed, allowing remote code execution on the device. […] Bill Toulas Go to bleepingcomputer
-
Apple blocked over $11 billion in App Store fraud in 6 years
Apple blocked over $11 billion in App Store fraud in 6 years Apple revealed that it blocked over $11 billion in fraudulent App Store transactions over the last six years, more than $2.2 billion in potentially fraudulent App Store transactions in 2025 alone. […] Sergiu Gatlan Go to bleepingcomputer
-
Inside a Crypto Drainer: How to Spot it Before it Empties Your Wallet
Inside a Crypto Drainer: How to Spot it Before it Empties Your Wallet Modern crypto drainers don’t hack wallets. They trick users into approving malicious transactions. Flare explores how the Lucifer DaaS platform scales wallet theft through phishing and automation. […] Sponsored by Flare Go to bleepingcomputer
-
Chinese hackers target telcos with new Linux, Windows malware
Chinese hackers target telcos with new Linux, Windows malware A Chinese cyber-espionage campaign has been targeting telecommunications providers with newly discovered Linux and Windows malware dubbed Showboat and JFMBackdoor, respectively. […] Bill Toulas Go to bleepingcomputer
-
Splunk Patches Multiple Vulnerabilities that Enable DOS Attack and Exposes Sensitive Data
Splunk Patches Multiple Vulnerabilities that Enable DOS Attack and Exposes Sensitive Data Splunk has released security updates addressing multiple vulnerabilities across Splunk Enterprise, Splunk Cloud Platform, and the Splunk AI Toolkit that could lead to denial-of-service (DoS) conditions and exposure of sensitive data. The issues, disclosed on May 20, 2026, include three tracked vulnerabilities: CVE-2026-20238,…
-
CISA Warns of Trend Micro Apex One Vulnerability Exploited in Attacks
CISA Warns of Trend Micro Apex One Vulnerability Exploited in Attacks The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability in Trend Micro Apex One to its Known Exploited Vulnerabilities (KEV) catalog, warning organizations of active exploitation risks. The flaw, tracked as CVE-2026-34926, affects on-premise deployments of Trend Micro Apex One…
-
FBI Warns of Kali365 Attacking Microsoft 365 Users to Steal Logins and Bypass MFA
FBI Warns of Kali365 Attacking Microsoft 365 Users to Steal Logins and Bypass MFA The FBI has issued a new cybersecurity warning about a rapidly emerging phishing-as-a-service (PhaaS) platform named Kali365, which is actively targeting Microsoft 365 users to steal access tokens and bypass multi-factor authentication (MFA). Kali365 is being distributed primarily through Telegram channels,…
-
Hackers Use Hugging Face to Host Second-Stage Malware for npm Supply Chain Attack
Hackers Use Hugging Face to Host Second-Stage Malware for npm Supply Chain Attack Hackers have found a new and alarming way to weaponize one of the most trusted platforms in the AI world. A threat actor linked to North Korea has embedded second-stage malware inside Hugging Face, the widely used AI and machine learning hub,…
-
Google Publishes Exploit Code for Unfixed Chromium Bug Exposing Millions of Users
Google Publishes Exploit Code for Unfixed Chromium Bug Exposing Millions of Users Google has publicly released proof-of-concept (PoC) exploit code for a critical, still-unpatched vulnerability in the Chromium codebase, potentially exposing millions of users across Chrome, Microsoft Edge, and other Chromium-based browsers to stealthy botnet-style abuse. The vulnerability, originally reported in late 2022 by independent…
-
TR-26-0286 (Türkiye Elektrik İletim A.Ş. – Mobil Uygulama Güvenlik Bildirimi)
TR-26-0286 (Türkiye Elektrik İletim A.Ş. – Mobil Uygulama Güvenlik Bildirimi) Go to usom.gov
-
TR-26-0285 (PosCube Donanım Yazılım – QR Menü Güvenlik Bildirimi)
TR-26-0285 (PosCube Donanım Yazılım – QR Menü Güvenlik Bildirimi) Go to usom.gov
-
TR-26-0284 (Digital Operasyon Hizmetleri – WifiBurada Güvenlik Bildirimi)
TR-26-0284 (Digital Operasyon Hizmetleri – WifiBurada Güvenlik Bildirimi) Go to usom.gov
-
China’s Webworm Uses Discord, Microsoft Graphs to Hack EU Govts.
China’s Webworm Uses Discord, Microsoft Graphs to Hack EU Govts. The advanced persistent threat group also relied on SOCKS proxies like SoftEther VPN, tunneling tools that act as a middleman between victim and attacker. Alexander Culafi Go to gbhackers.com
-
CISA Adds Exploited Langflow and Trend Micro Apex One Vulnerabilities to KEV
CISA Adds Exploited Langflow and Trend Micro Apex One Vulnerabilities to KEV The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added two security flaws impacting Langflow and Trend Micro Apex One to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerabilities in question are listed below – CVE-2025-34291 (CVSS…
-
Cisco Patches CVSS 10.0 Secure Workload REST API Flaw Enabling Data Access
Cisco Patches CVSS 10.0 Secure Workload REST API Flaw Enabling Data Access Cisco has rolled out updates for a maximum-severity security flaw impacting Secure Workload that could allow an unauthenticated, remote attacker to access sensitive data. Tracked as CVE-2026-20223 (CVSS score: 10.0), the vulnerability arises from insufficient validation and authentication when accessing REST API endpoints.…
-
Showboat Linux Malware Hits Middle East Telecom with SOCKS5 Proxy Backdoor
Showboat Linux Malware Hits Middle East Telecom with SOCKS5 Proxy Backdoor Cybersecurity researchers have disclosed details of a new Linux malware dubbed Showboat that has been put to use in a campaign targeting a telecommunications provider in the Middle East since at least mid-2022. “Showboat is a modular post-exploitation framework designed for Linux systems, capable…
-
ThreatsDay Bulletin: Linux Rootkits, Router 0-Day, AI Intrusions, Scam Kits and 25 New Stories
ThreatsDay Bulletin: Linux Rootkits, Router 0-Day, AI Intrusions, Scam Kits and 25 New Stories This week starts small. A token leaks. A bad package slips in. A login trick works. An old tool shows up again. At first, it feels like the usual mess. Then you see the pattern: attackers are not always breaking in.…
-
Microsoft Warns of Two Actively Exploited Defender Vulnerabilities
Microsoft Warns of Two Actively Exploited Defender Vulnerabilities Microsoft has disclosed that a privilege escalation and a denial-of-service flaw in Defender has come under active exploitation in the wild. The former, tracked as CVE-2026-41091, is rated 7.8 on the CVSS scoring system. Successful exploitation of the flaw could allow an attacker to gain SYSTEM privileges.…
-
GitHub internal repositories breached
GitHub internal repositories breached <p>A malicious VS Code extension led to cloned private repositories, reportedly offered for sale on a criminal forum</p> Categories: Threat Research Tags: GitHub, Supply chain Go to sophos
-
macOS Kernel Memory Corruption Exploit
macOS Kernel Memory Corruption Exploit A group used Anthropic’s Mythos AI model to help find a kernel memory corruption vulnerability and exploit on Apple’s M5. News article. Bruce Schneier Go to bruce schneier
-
ISC Stormcast For Friday, May 22nd, 2026 https://isc.sans.edu/podcastdetail/9942, (Fri, May 22nd)
ISC Stormcast For Friday, May 22nd, 2026 https://isc.sans.edu/podcastdetail/9942, (Fri, May 22nd) (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License. Go to isc.sans.edu
-
Selective HTTP Proxying in Linux, (Thu, May 21st)
Selective HTTP Proxying in Linux, (Thu, May 21st) Recently, Rob wrote about a tool, Proxifier, that can intercept requests from specific processes. Proxifier is available for Windows, macOS, and Android. But I have not seen a generic Linux option yet. The advantage of a tool like Proxifier is the ability to target specific software. For…
-
Alleged Kimwolf Botmaster ‘Dort’ Arrested, Charged in U.S. and Canada
Alleged Kimwolf Botmaster ‘Dort’ Arrested, Charged in U.S. and Canada Canadian authorities on Wednesday arrested a 23-year-old Ottawa man on suspicion of building and operating Kimwolf, a fast spreading Internet-of-Things botnet that enslaved millions of devices for use in a series of massive distributed denial-of-service (DDoS) attacks over the past six months. KrebsOnSecurity publicly named…
-
Defenders fall behind, as AI rewrites the rules of a data breach
Defenders fall behind, as AI rewrites the rules of a data breach For almost 20 years, stolen credentials have been the most common route for attackers into organizations, according to the Verizon Data Breach Investigations Report (DBIR). But that’s no longer the case. Read more in my article on the Fortra blog. Graham Cluley Go…
-
How CISOs Should Prep for Agentic-Ready AI BOMs
How CISOs Should Prep for Agentic-Ready AI BOMs Finding ways to document both component and execution attributes for AI bill of materials (AI BOM). Ericka Chickowski, Contributing Writer Go to gbhackers.com
-
Google API Keys Remain Active After Deletion
Google API Keys Remain Active After Deletion A security researcher discovered the API keys can still be used for 23 minutes after deletion, even though the cloud provider claims deletion is immediate. Rob Wright Go to gbhackers.com
-
AI Agents Are Shifting Identity Security Budget Dynamics
AI Agents Are Shifting Identity Security Budget Dynamics AI agent projects are proliferating throughout the enterprise, and those AI agent identities require management, security, and governance. New Omdia research shows the AI agent identity budget dynamics are very different than traditional IAM projects. Todd Thiemann Go to gbhackers.com
-
Chinese APTs Share Linux Backdoor in Central Asia Telco Attacks
Chinese APTs Share Linux Backdoor in Central Asia Telco Attacks “Showboat” doesn’t show off, but clearly it doesn’t need to, as it’s long helped China spy on small market communications providers. Nate Nelson Go to gbhackers.com
-
Content Delivery Exploit Opens Websites to Brand Hijacking
Content Delivery Exploit Opens Websites to Brand Hijacking The Underminr domain-fronting attack allows threat actors to modify Web requests and leverage trusted websites to cloak malicious activity. Nate Nelson Go to gbhackers.com
-
Google Chrome Security Flaws Could Let Attackers Execute Code Remotely
Google Chrome Security Flaws Could Let Attackers Execute Code Remotely Google has released a critical security update for its Chrome browser, addressing multiple vulnerabilities that could allow attackers to execute arbitrary code on affected… Delivered by PolitePaul service Go to gbhackers.com
-
Fake Microsoft Teams Downloads Spread ValleyRAT Malware
Fake Microsoft Teams Downloads Spread ValleyRAT Malware Hackers are actively distributing a sophisticated ValleyRAT malware variant through fake Microsoft Teams download pages, leveraging social engineering and multi-stage execution techniques to evade… Delivered by PolitePaul service Go to gbhackers.com
-
TamperedChef Malware Hides in Signed Apps to Drop Stealers and RATs
TamperedChef Malware Hides in Signed Apps to Drop Stealers and RATs A large-scale malware campaign dubbed “TamperedChef” is leveraging trojanized productivity applications such as PDF editors, calendar tools, and file converters to silently deploy information… Delivered by PolitePaul service Go to gbhackers.com
-
New NGINX 0-Day RCE “nginx-poolslip” Threatens Millions of Servers
New NGINX 0-Day RCE “nginx-poolslip” Threatens Millions of Servers A newly discovered zero-day vulnerability in NGINX, dubbed “nginx-poolslip,” is raising serious concerns across the global cybersecurity community, as it exposes millions of servers… Delivered by PolitePaul service Go to gbhackers.com
-
Critical Vulnerability in Cisco Secure Workload Threatens Enterprise API Security
Critical Vulnerability in Cisco Secure Workload Threatens Enterprise API Security Cisco has disclosed a critical security vulnerability in its Secure Workload platform that could allow unauthenticated attackers to gain high-level administrative access to sensitive… Delivered by PolitePaul service Go to gbhackers.com
-
Microsoft warns of new Defender zero-days exploited in attacks
Microsoft warns of new Defender zero-days exploited in attacks On Wednesday, Microsoft started rolling out security patches for two Defender vulnerabilities that have been exploited in zero-day attacks. […] Sergiu Gatlan Go to bleepingcomputer
-
GitHub links repo breach to TanStack npm supply-chain attack
GitHub links repo breach to TanStack npm supply-chain attack GitHub says the hackers who breached 3,800 internal repositories gained access via a malicious version of the Nx Console VS Code extension, compromised in last week’s TanStack npm supply-chain attack. […] Sergiu Gatlan Go to bleepingcomputer
-
Ukraine identifies infostealer operator tied to 28,000 stolen accounts
Ukraine identifies infostealer operator tied to 28,000 stolen accounts The Ukrainian cyberpolice, working in conjunction with U.S. law enforcement, has identified an 18-year-old man from Odesa suspected of running an infostealer malware operation targeting users of an online store in California. […] Bill Toulas Go to bleepingcomputer
-
Hackers bypass SonicWall VPN MFA due to incomplete patching
Hackers bypass SonicWall VPN MFA due to incomplete patching Threat actors brute-forced VPN credentials and bypassed multi-factor authentication (MFA) on SonicWall Gen6 SSL-VPN appliances to deploy tools used in ransomware attacks. […] Bill Toulas Go to bleepingcomputer
-
Grafana breach caused by missed token rotation after TanStack attack
Grafana breach caused by missed token rotation after TanStack attack The Grafana data breach was caused by a single GitHub workflow token that slipped through the rotation process following the TanStack npm supply-chain attack last week. […] Bill Toulas Go to bleepingcomputer
-
Nine-year-old Linux Kernel Vulnerability Let Attackers Exfiltrate SSH Private Keys
Nine-year-old Linux Kernel Vulnerability Let Attackers Exfiltrate SSH Private Keys A newly disclosed Linux kernel vulnerability, tracked as CVE-2026-46333, exposes a serious local privilege escalation flaw that has remained undetected for nearly nine years. Security researchers at the Qualys Threat Research Unit (TRU) revealed that the issue allows attackers to exfiltrate sensitive data, including SSH…
-
New Microsoft Defender 0‑Days Actively Exploited in the Wild
New Microsoft Defender 0‑Days Actively Exploited in the Wild Two newly disclosed Microsoft Defender vulnerabilities are being actively exploited in the wild, enabling local attackers to elevate privileges to SYSTEM and potentially disrupt endpoint protection across Windows environments. The bugs, tracked as CVE‑2026‑41091 (Elevation of Privilege) and CVE‑2026‑45498 (Denial of Service), were published on May…
-
BadIIS Malware Turns Hijacks IIS Servers and Redirect Users to Illicit Sites
BadIIS Malware Turns Hijacks IIS Servers and Redirect Users to Illicit Sites A dangerous piece of malware known as BadIIS has been actively targeting Internet Information Services (IIS) web servers, quietly hijacking them and redirecting unsuspecting visitors to illegal gambling sites, adult content platforms, and other illicit destinations. The attacks have been going on for…
-
Critical Cisco Secure Workload Vulnerability Enables Unauthorized API Access
Critical Cisco Secure Workload Vulnerability Enables Unauthorized API Access Cisco has disclosed a critical security vulnerability in its Secure Workload platform that could allow unauthenticated attackers to gain unauthorized access to sensitive resources via internal APIs. The flaw, tracked as CVE-2026-20223, carries a maximum CVSS score of 10.0 and is categorized under CWE-306 (Missing Authentication…
-
Critical Drupal Core Security Vulnerability Exposes Websites to Cyberattack
Critical Drupal Core Security Vulnerability Exposes Websites to Cyberattack A highly critical security vulnerability in Drupal core is set to impact websites worldwide, with the official security release scheduled for May 20, 2026. The vulnerability has been assigned a “Highly Critical” severity rating (20/25), indicating potential risks to confidentiality and integrity across affected systems. While…
-
Webworm: New burrowing techniques
Webworm: New burrowing techniques ESET researchers describe new tools and techniques that the Webworm APT group recently added to its arsenal Go to eset
-
TR-26-0283 (Esri ArcGIS Güvenlik Bildirimi)
TR-26-0283 (Esri ArcGIS Güvenlik Bildirimi) Go to usom.gov
-
TR-26-0282 (Open5GS Güvenlik Zafiyeti)
TR-26-0282 (Open5GS Güvenlik Zafiyeti) Go to usom.gov
-
TR-26-0281 (Traefik Proxy Güvenlik Zafiyeti)
TR-26-0281 (Traefik Proxy Güvenlik Zafiyeti) Go to usom.gov
-
TR-26-0280 (NVIDIA Çoklu Ürün Güvenlik Bildirimi)
TR-26-0280 (NVIDIA Çoklu Ürün Güvenlik Bildirimi) Go to usom.gov
-
TR-26-0279 (Google Chrome Güvenlik Bildirimi)
TR-26-0279 (Google Chrome Güvenlik Bildirimi) Go to usom.gov
-
GitHub Internal Repositories Breached via Malicious Nx Console VS Code Extension
GitHub Internal Repositories Breached via Malicious Nx Console VS Code Extension GitHub on Wednesday officially confirmed that the breach of its internal repositories was the result of a compromise of an employee device involving a poisoned version of the Nx Console Microsoft Visual Studio Code (VS Code) extension. The development comes as the Nx team…
-
Highly Critical Drupal Core Flaw Exposes PostgreSQL Sites to RCE Attacks
Highly Critical Drupal Core Flaw Exposes PostgreSQL Sites to RCE Attacks Drupal has released security updates for a “highly critical” security vulnerability in Drupal Core that could be exploited by attackers to achieve remote code execution, privilege escalation, or information disclosure. The vulnerability, now tracked as CVE-2026-9082, carries a CVSS score of 6.5 out of…
-
Microsoft Open-Sources RAMPART and Clarity to Secure AI Agents During Development
Microsoft Open-Sources RAMPART and Clarity to Secure AI Agents During Development Microsoft has unveiled two new open-source tools called RAMPART and Clarity to assist developers in better testing the security of artificial intelligence (AI) agents. RAMPART, short for Risk Assessment and Measurement Platform for Agentic Red Teaming, functions as a Pytest-native safety and security testing…
-
Microsoft Takes Down Malware-Signing Service Behind Ransomware Attacks
Microsoft Takes Down Malware-Signing Service Behind Ransomware Attacks Microsoft on Tuesday said it disrupted a malware-signing-as-a-service (MSaaS) operation that weaponized the company’s Artifact Signing system to deliver malicious code and conduct ransomware and other attacks, compromising thousands of machines and networks across the world. The tech giant attributed the activity to a threat actor it…
-
Webworm Deploys EchoCreep and GraphWorm Backdoors Using Discord and MS Graph API
Webworm Deploys EchoCreep and GraphWorm Backdoors Using Discord and MS Graph API Cybersecurity researchers have flagged fresh activity from a China-aligned threat actor known as Webworm in 2025, deploying custom backdoors that employ Discord and Microsoft Graph API for command-and-control (C2 or C&C) communications. Webworm, first publicly documented by Broadcom-owned Symantec in September 2022, is…
-
On AI Security
On AI Security Good report: Executive Summary: Let’s say you wanted to make sure that your AI is secure. Can you just maximize the security and privacy benchmark and call it a day? Nope, because benchmarks don’t actually work for measuring AI capabilities (even when they are NOT emergent systemic properties like security). So let’s…
-
ISC Stormcast For Thursday, May 21st, 2026 https://isc.sans.edu/podcastdetail/9940, (Thu, May 21st)
ISC Stormcast For Thursday, May 21st, 2026 https://isc.sans.edu/podcastdetail/9940, (Thu, May 21st) (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License. Go to isc.sans.edu
-
Smashing Security podcast #468: High-speed train hacks and homicidal lawnmowers
Smashing Security podcast #468: High-speed train hacks and homicidal lawnmowers A 23-year-old radio enthusiast spent £300 on a piece of kit from the internet, and used it to bring four packed high-speed trains to a screeching halt. His defence in court? Possibly the most creative excuse we’ve heard all year. Meanwhile, owners of $4,000 robot…
-
FBI warns students and staff that ShinyHunters may come knocking after Canvas breach
FBI warns students and staff that ShinyHunters may come knocking after Canvas breach Having receive a ransom payment for its attack on Canvas, ShinyHunters and other extortion gangs are only likely to be further incentivised to launch similar attacks in future. Read more in my article on the Hot for Security blog. Graham Cluley Go…
-
Cyber Pros Can’t Decide If AI Is a Good or a Bad Thing
Cyber Pros Can’t Decide If AI Is a Good or a Bad Thing There is nothing cybersecurity professionals are more excited about, and nothing they fear more, than AI. Nate Nelson Go to gbhackers.com
-
GitHub Confirms Breach, 4K Internal Repos Stolen
GitHub Confirms Breach, 4K Internal Repos Stolen Open source software giant GitHub confirmed a data breach this week involving the theft of thousands of repos. One threat actor — TeamPCP — took credit. Alexander Culafi Go to gbhackers.com
-
Processes and Culture Top Reasons Behind Data Breaches
Processes and Culture Top Reasons Behind Data Breaches Government leaders revealed that, in spite of state laws meant to improve cyber hygiene, an analysis of incidents showed issues persist and visibility falls short. Arielle Waldman Go to gbhackers.com
-
Patch Now: Critical Flaw in OT Robot OS Gives Attackers Control
Patch Now: Critical Flaw in OT Robot OS Gives Attackers Control An unauthenticated attacker can exploit the command injection vulnerability to gain remote access to robotic systems, causing significant disruption to the environment. Elizabeth Montalbano Go to gbhackers.com
-
Infosecurity Europe
Infosecurity Europe Go to gbhackers.com
-
GitHub confirms breach of 3,800 repos via malicious VSCode extension
GitHub confirms breach of 3,800 repos via malicious VSCode extension GitHub has confirmed that roughly 3,800 internal repositories were breached after one of its employees installed a malicious VS Code extension. […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft shares mitigation for YellowKey Windows zero-day
Microsoft shares mitigation for YellowKey Windows zero-day Microsoft has shared mitigations for YellowKey, a recently disclosed Windows BitLocker zero-day vulnerability that grants access to protected drives. […] Sergiu Gatlan Go to bleepingcomputer
-
GitHub investigates internal repositories breach claimed by TeamPCP
GitHub investigates internal repositories breach claimed by TeamPCP GitHub is investigating a breach of its internal repositories after the TeamPCP hacker group claimed to have accessed approximately 4,000 repositories containing private code. […] Sergiu Gatlan Go to bleepingcomputer
-
Max-severity flaw in ChromaDB for AI apps allows server hijacking
Max-severity flaw in ChromaDB for AI apps allows server hijacking A max-severity vulnerability in the latest Python FastAPI version of the ChromaDB project allows unauthenticated attackers to run arbitrary code on exposed servers. […] Bill Toulas Go to bleepingcomputer
-
Cybercrime service disrupted for abusing Microsoft platform to sign malware
Cybercrime service disrupted for abusing Microsoft platform to sign malware Microsoft says it has disrupted a malware-signing-as-a-service (MSaaS) operation that abused the company’s Artifact Signing service to generate fraudulent code-signing certificates used by ransomware gangs and other cybercriminals. […] Lawrence Abrams Go to bleepingcomputer
-
Microsoft Releases Mitigation for Windows BitLocker Security Bypass 0-Day Vulnerability
Microsoft Releases Mitigation for Windows BitLocker Security Bypass 0-Day Vulnerability Microsoft has disclosed a critical zero-day vulnerability in Windows BitLocker, tracked as CVE-2026-45585, that allows threat actors with physical access to bypass full-disk encryption entirely, potentially exposing sensitive data within minutes. The flaw was publicly disclosed on May 19, 2026, and while no active exploitation…
-
New NGINX Vulnerability Allow Remote Attackers to Trigger Malicious Code
New NGINX Vulnerability Allow Remote Attackers to Trigger Malicious Code A new vulnerability in NGINX JavaScript (njs), tracked as CVE‑2026‑8711, allows unauthenticated remote attackers to trigger a heap‑based buffer overflow that can lead to denial‑of‑service and, in some conditions, remote code execution in the NGINX worker process. The flaw is tied to how the js_fetch_proxy…
-
Fox Tempest Malware-Signing Service Abused Microsoft Artifact Signing to Certify Malware
Fox Tempest Malware-Signing Service Abused Microsoft Artifact Signing to Certify Malware A financially motivated threat actor known as Fox Tempest has been operating a sophisticated malware-signing-as-a-service (MSaaS) platform that abused Microsoft’s Artifact Signing infrastructure to generate trusted digital signatures for malicious code. This activity enabled cybercriminals to bypass security controls and distribute malware that appeared…
-
GitHub Hacked – Internal Source Code Repositories Compromised via Employee Device
GitHub Hacked – Internal Source Code Repositories Compromised via Employee Device GitHub has confirmed unauthorized access to its internal repositories after detecting a compromised employee device infected through a malicious Visual Studio Code extension, the company disclosed in a series of official statements on May 20, 2026. The Microsoft-owned code hosting platform said it identified…
-
PoC Exploit Released for 20-Year Old PostgreSQL RCE Vulnerability
PoC Exploit Released for 20-Year Old PostgreSQL RCE Vulnerability A proof-of-concept (PoC) exploit has been publicly released for CVE-2026-2005, a critical remote code execution (RCE) vulnerability affecting PostgreSQL’s pgcrypto extension. The flaw, rooted in legacy code dating back nearly two decades, highlights the long-standing risks associated with memory handling issues in widely deployed database systems.…