no alarms and no surprises please..
-
Microsoft Warns HPE Operations Agent Abused in Malware-Free Attacks
Microsoft Warns HPE Operations Agent Abused in Malware-Free Attacks Microsoft has revealed a stealthy intrusion campaign where attackers bypassed traditional malware and exploits, instead abusing trusted enterprise tools to silently infiltrate networks. The… Delivered by PolitePaul service Go to gbhackers.com
-
Microsoft Edge, Windows 11, and LiteLLM Fall to Exploits at Pwn2Own Berlin 2026
Microsoft Edge, Windows 11, and LiteLLM Fall to Exploits at Pwn2Own Berlin 2026 The world’s top ethical hackers wasted no time breaking into modern software and AI systems on the opening day of Pwn2Own Berlin 2026, exposing… Delivered by PolitePaul service Go to gbhackers.com
-
Tycoon 2FA Operators Use OAuth Device Code Phishing to Bypass MFA
Tycoon 2FA Operators Use OAuth Device Code Phishing to Bypass MFA A new phishing campaign uncovered in late April 2026 shows how threat actors behind the Tycoon 2FA Phishing-as-a-Service (PhaaS) kit are evolving beyond traditional… Delivered by PolitePaul service Go to gbhackers.com
-
Amazon Redshift JDBC Driver Flaws Expose Systems to RCE Attacks
Amazon Redshift JDBC Driver Flaws Expose Systems to RCE Attacks Amazon Redshift users are facing a serious security risk after researchers uncovered a high-severity vulnerability that could allow attackers to execute arbitrary code on… Delivered by PolitePaul service Go to gbhackers.com
-
Microsoft warns of Exchange zero-day flaw exploited in attacks
Microsoft warns of Exchange zero-day flaw exploited in attacks On Thursday, Microsoft shared mitigations for a high-severity Exchange Server vulnerability exploited in attacks that allow threat actors to execute arbitrary code via cross-site scripting (XSS) while targeting Outlook on the web users. […] Sergiu Gatlan Go to bleepingcomputer
-
TeamPCP hackers advertise Mistral AI code repos for sale
TeamPCP hackers advertise Mistral AI code repos for sale The TeamPCP hacker group is threatening to leak source code from the Mistral AI project unless a buyer is found for the data. […] Ionut Ilascu Go to bleepingcomputer
-
Hackers exploit auth bypass flaw in Burst Statistics WordPress plugin
Hackers exploit auth bypass flaw in Burst Statistics WordPress plugin Hackers are leveraging a critical authentication bypass vulnerability in the WordPress plugin Burst Statistics to obtain admin-level access to websites. […] Bill Toulas Go to bleepingcomputer
-
Cisco warns of new critical SD-WAN flaw exploited in zero-day attacks
Cisco warns of new critical SD-WAN flaw exploited in zero-day attacks Cisco is warning that a critical Catalyst SD-WAN Controller authentication bypass flaw, tracked as CVE-2026-20182, was actively exploited in zero-day attacks that allowed attackers to gain administrative privileges on compromised devices. […] Lawrence Abrams Go to bleepingcomputer
-
OpenAI confirms security breach in TanStack supply chain attack
OpenAI confirms security breach in TanStack supply chain attack OpenAI says two employees’ devices were breached in the recent TanStack supply chain attack that impacted hundreds of npm and PyPI packages, causing the company to rotate code-signing certificates for its applications as a precaution. […] Lawrence Abrams Go to bleepingcomputer
-
Microsoft Details Kazuar Malware’s Modular Architecture and P2P Botnet Operations
Microsoft Details Kazuar Malware’s Modular Architecture and P2P Botnet Operations A nation-state malware known as Kazuar has resurfaced with a far more dangerous design than anyone expected. What once started as a relatively standard backdoor has now grown into a fully modular, peer-to-peer botnet specifically engineered for long-term, covert espionage against high-value government and diplomatic…
-
VMware Fusion Vulnerability Let Attackers Escalate Privilege to Root
VMware Fusion Vulnerability Let Attackers Escalate Privilege to Root A high-severity privilege escalation vulnerability has been discovered in VMware Fusion, Broadcom’s popular macOS virtualization software, allowing local attackers to gain root-level access on affected systems. Tracked as CVE-2026-41702, the flaw was privately reported to Broadcom and patched on May 14, 2026, under security advisory VMSA-2026-0003.…
-
Hackers Abuse Scheduled Tasks to Maintain Persistence in FrostyNeighbor Attacks
Hackers Abuse Scheduled Tasks to Maintain Persistence in FrostyNeighbor Attacks A state-aligned hacking group known as FrostyNeighbor has resurfaced with a fresh wave of cyberattacks targeting government organizations in Ukraine, using a carefully designed infection chain that is harder than ever to detect. The group, active since at least 2016, has a long history of…
-
79 Chrome Vulnerabilities Patched, Including 14 Critical One’s – Update Now!
79 Chrome Vulnerabilities Patched, Including 14 Critical One’s – Update Now! Google has rolled out a massive security update for its Chrome browser, sealing a staggering 79 vulnerabilities before threat actors can exploit them. With 14 of these flaws rated as critical, browsing the web on an outdated version leaves your entire system wide open…
-
Critical Microsoft Exchange Server Vulnerability Actively Exploited in Attacks
Critical Microsoft Exchange Server Vulnerability Actively Exploited in Attacks Microsoft issued an urgent security alert regarding a newly discovered vulnerability in Exchange Server that is currently being exploited in the wild. Tracked as CVE-2026-42897, this critical spoofing flaw carries a high CVSS 3.1 severity score of 8.1 and directly impacts on-premises email infrastructure. Threat actors…
-
FrostyNeighbor: Fresh mischief and digital shenanigans
FrostyNeighbor: Fresh mischief and digital shenanigans ESET researchers uncovered new activities attributed to FrostyNeighbor, updating its compromise chain to support the group’s continual cyberespionage operations Go to eset
-
TR-26-0257 (Lenovo Personal Cloud Storage Güvenlik Bildirimi)
TR-26-0257 (Lenovo Personal Cloud Storage Güvenlik Bildirimi) Go to usom.gov
-
TR-26-0256 (Grafana Güvenlik Bildirimi)
TR-26-0256 (Grafana Güvenlik Bildirimi) Go to usom.gov
-
TR-26-0255 (MISP Güvenlik Zafiyeti)
TR-26-0255 (MISP Güvenlik Zafiyeti) Go to usom.gov
-
TR-26-0254 (PostgreSQL Güvenlik Zafiyeti)
TR-26-0254 (PostgreSQL Güvenlik Zafiyeti) Go to usom.gov
-
TR-26-0253 (Elecom Access Point Güvenlik Bildirimi)
TR-26-0253 (Elecom Access Point Güvenlik Bildirimi) Go to usom.gov
-
On-Prem Microsoft Exchange Server CVE-2026-42897 Exploited via Crafted Email
On-Prem Microsoft Exchange Server CVE-2026-42897 Exploited via Crafted Email Microsoft has disclosed a new security vulnerability impacting on-premise versions of Exchange Server that it said has come under active exploitation in the wild. The vulnerability, tracked as CVE-2026-42897 (CVSS score: 8.1), has been described as a spoofing bug stemming from a cross-site scripting flaw. An…
-
CISA Adds Cisco SD-WAN CVE-2026-20182 to KEV After Admin Access Exploits
CISA Adds Cisco SD-WAN CVE-2026-20182 to KEV After Admin Access Exploits The U.S.Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a newly disclosed vulnerability impacting Cisco Catalyst SD-WAN Controller to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to remediate the issue by May 17, 2026. The vulnerability is…
-
Cisco Catalyst SD-WAN Controller Auth Bypass Actively Exploited to Gain Admin Access
Cisco Catalyst SD-WAN Controller Auth Bypass Actively Exploited to Gain Admin Access Cisco has released updates to address a maximum-severity authentication bypass flaw in Catalyst SD-WAN Controller that it said has been exploited in limited attacks. The vulnerability, tracked as CVE-2026-20182, carries a CVSS score of 10.0. “A vulnerability in the peering authentication in Cisco…
-
Stealer Backdoor Found in 3 Node-IPC Versions Targeting Developer Secrets
Stealer Backdoor Found in 3 Node-IPC Versions Targeting Developer Secrets Cybersecurity researchers are sounding the alarm about what has been described as “malicious activity” in newly published versions of node-ipc. According to Socket and StepSecurity, three different versions of the npm package have been confirmed as malicious – [email protected] [email protected] [email protected] “Early analysis indicates that…
-
ThreatsDay Bulletin: PAN-OS RCE, Mythos cURL Bug, AI Tokenizer Attacks, and 10+ Stories
ThreatsDay Bulletin: PAN-OS RCE, Mythos cURL Bug, AI Tokenizer Attacks, and 10+ Stories Everything is still on fire. This week feels dumb in the worst way — bad links, weak checks, fake help desks, shady forum posts, and people turning supply chain attacks into some cursed little game for clout and cash. Half of it…
-
Why AMOS matters: The macOS malware stealing data at scale
Why AMOS matters: The macOS malware stealing data at scale <p>Sophos X-Ops looks at the Atomic macOS Stealer and its capabilities</p> Categories: Threat Research Tags: MacOS, AMOS, infostealer Go to sophos
-
Upcoming Speaking Engagements
Upcoming Speaking Engagements This is a current list of where and when I am scheduled to speak: I’m giving a virtual talk on “The Security of Trust in the Age of AI,” hosted by the Financial Women’s Association of New York, at 6:00 PM ET on May 21, 2026. I’m speaking at the Potsdam Conference…
-
How Dangerous Is Anthropic’s Mythos AI?
How Dangerous Is Anthropic’s Mythos AI? Last month, Anthropic made a remarkable announcement about its new model, Claude Mythos Preview: it was so good at finding security vulnerabilities in software that the company would not release it to the general public. Instead, it would only be available to a select group of companies to scan…
-
Simple bypass of the link preview function in Outlook Junk folder, (Thu, May 14th)
Simple bypass of the link preview function in Outlook Junk folder, (Thu, May 14th) Besides serving as a place where Microsoft Outlook places suspected spam, the Outlook Junk folder has one additional function that can be quite helpful when it comes to identifying malicious messages. Any e-mail placed in this folder is stripped of all…
-
ISC Stormcast For Thursday, May 14th, 2026 https://isc.sans.edu/podcastdetail/9932, (Thu, May 14th)
ISC Stormcast For Thursday, May 14th, 2026 https://isc.sans.edu/podcastdetail/9932, (Thu, May 14th) (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License. Go to isc.sans.edu
-
[GUEST DIARY] Tearing apart website fraud to see how it works., (Wed, May 13th)
[GUEST DIARY] Tearing apart website fraud to see how it works., (Wed, May 13th) [This is a Guest Diary by Joshua Nikolson, an ISC Intern and part of the SANS.edu Bachelor’s degree in Applied Cybersecurity (BACS) program.] Introduction One day at work, a friend messaged me, “How do you check a website to see…
-
Suspected Dream Market kingpin arrested after gold bars sent to his home address
Suspected Dream Market kingpin arrested after gold bars sent to his home address Lesson one for aspiring dark web kingpins: don’t have your laundered gold bars shipped to your home address. Read more in my article on the Hot for Security blog. Graham Cluley Go to grahamcluley
-
When ransomware gets physical: cybercriminals turn to threats of violence
When ransomware gets physical: cybercriminals turn to threats of violence Pay up, or we’ll pay someone to pay you a visit. Cybercrime gangs are increasingly turning to real-world threats – and even hiring local muscle to deliver the message. Read more in my article on the Hot for Security blog. Graham Cluley Go to grahamcluley
-
Taiwan Incident Highlights Cybersecurity Gaps in Rail Systems
Taiwan Incident Highlights Cybersecurity Gaps in Rail Systems A Taiwanese student experimenting with software-defined radio technology shut down three bullet trains for nearly an hour, leading to an anti-terrorism response. Robert Lemos Go to gbhackers.com
-
Welcoming the Bahamian Government to Have I Been Pwned
Welcoming the Bahamian Government to Have I Been Pwned Today, we welcome the 44th government onboarded to Have I Been Pwned’s free gov service: The Bahamas. The National Computer Incident Response Team of The Bahamas, CIRT-BS, now has access to monitor government domains against the data in HIBP. As the national CIRT, CIRT-BS is responsible…
-
SecurityScorecard Snags Driftnet to Level Up Threat Intelligence
SecurityScorecard Snags Driftnet to Level Up Threat Intelligence The new acquisition looks to boost visibility into third-party ecosystems that are becoming a bigger concern as vectors for supply-chain attacks. Arielle Waldman Go to gbhackers.com
-
Maximum Severity Cisco SD-WAN Bug Exploited in the Wild
Maximum Severity Cisco SD-WAN Bug Exploited in the Wild This is the second time this year a threat actor has leveraged a CVSS 10.0 vulnerability in Cisco’s network control system. Nate Nelson Go to gbhackers.com
-
‘FrostyNeighbor’ APT Carefully Targets Govt Orgs in Poland, Ukraine
‘FrostyNeighbor’ APT Carefully Targets Govt Orgs in Poland, Ukraine Attackers uniquely fingerprint victims before delivering spear-phishing payloads aimed at espionage, in the latest campaign from the Belarussian nation-state threat group. Elizabeth Montalbano Go to gbhackers.com
-
AI Drives Cybersecurity Investments, Widening ‘Valley of Death’
AI Drives Cybersecurity Investments, Widening ‘Valley of Death’ In a role reversal, investment dollars in AI security startups exceeded the value of AI acquisitions in 1Q26 by more than $1 billion, a rare occurrence. Rob Wright Go to gbhackers.com
-
170 npm Packages Hijacked to Steal GitHub, AWS & Kubernetes Secrets
170 npm Packages Hijacked to Steal GitHub, AWS & Kubernetes Secrets Hackers have launched a large-scale supply chain attack by compromising more than 170 npm packages and two PyPI libraries, collectively downloaded over 200 million… Delivered by PolitePaul service Go to gbhackers.com
-
Microsoft Research: AI Can Generate Realistic Command-Line and Process Telemetry
Microsoft Research: AI Can Generate Realistic Command-Line and Process Telemetry A new approach showing how artificial intelligence can generate highly realistic command-line data and process telemetry potentially transforming how security teams build and test… Delivered by PolitePaul service Go to gbhackers.com
-
Amazon Quick Security Flaw Allowed Restricted Users to Access AI Chat Agents
Amazon Quick Security Flaw Allowed Restricted Users to Access AI Chat Agents A newly disclosed security flaw in Amazon’s AI-powered business intelligence platform has revealed how restricted users could quietly bypass controls and interact with AI… Delivered by PolitePaul service Go to gbhackers.com
-
GitLab Security Flaw Allows Cross-Site Scripting and Unauthenticated DoS
GitLab Security Flaw Allows Cross-Site Scripting and Unauthenticated DoS GitLab has issued an urgent security update to neutralise a massive wave of vulnerabilities. Threat actors could exploit these newly disclosed flaws to silently… Delivered by PolitePaul service Go to gbhackers.com
-
Hackers Hijack HWMonitor to Sideload Malicious DLL
Hackers Hijack HWMonitor to Sideload Malicious DLL Hackers are once again exploiting user trust in legitimate software, this time abusing the popular CPUID HWMonitor utility to deliver a stealthy remote access… Delivered by PolitePaul service Go to gbhackers.com
-
Dell confirms its SupportAssist software causes Windows BSOD crashes
Dell confirms its SupportAssist software causes Windows BSOD crashes Dell confirmed that its SupportAssist software is causing blue-screen crashes on some Windows systems following a wave of user reports about random reboots affecting Dell devices since Friday. […] Sergiu Gatlan Go to bleepingcomputer
-
US charges suspected Dream Market admin arrested in Germany
US charges suspected Dream Market admin arrested in Germany The alleged main administrator of Dream Market Incognito Market, one of the largest dark web marketplaces before its shutdown, has been indicted in the United States on money laundering charges. […] Sergiu Gatlan Go to bleepingcomputer
-
New Fragnesia Linux flaw lets attackers gain root privileges
New Fragnesia Linux flaw lets attackers gain root privileges Linux distros are rolling out patches for a new high-severity kernel privilege escalation vulnerability (known as Fragnasia and tracked as CVE-2026-46300) that allows attackers to run malicious code as root. […] Sergiu Gatlan Go to bleepingcomputer
-
West Pharmaceutical says hackers stole data, encrypted systems
West Pharmaceutical says hackers stole data, encrypted systems West Pharmaceutical Services disclosed that it was the target of a cyberattack that resulted in data exfiltration and system encryption. […] Bill Toulas Go to bleepingcomputer
-
Iranian hackers targeted major South Korean electronics maker
Iranian hackers targeted major South Korean electronics maker The Iran-linked hacking group MuddyWater (a.k.a. Seedworm, Static Kitten) launched a broad cyber-espionage campaign targeting at least nine high-profile organizations across multiple sectors and countries. […] Bill Toulas Go to bleepingcomputer
-
Langflow CVE-2026-33017 Exploited to Steal AWS Keys and Deploy NATS Worker
Langflow CVE-2026-33017 Exploited to Steal AWS Keys and Deploy NATS Worker Attackers are now abusing a fresh Langflow vulnerability to quietly steal cloud keys and turn victim systems into workers for a new NATS based botnet. This campaign shows how a single exposed AI workflow tool can become the start of large scale credential theft…
-
Packagist Urges Immediate Composer Update After GitHub Actions Token Leak
Packagist Urges Immediate Composer Update After GitHub Actions Token Leak Packagist is sounding the alarm for PHP developers everywhere. A flaw in Composer, the widely used PHP dependency manager, briefly caused GitHub authentication tokens to leak into publicly visible CI logs, raising urgent concerns about credential exposure across thousands of active software projects around the…
-
Seedworm APT Abuses Signed Fortemedia and SentinelOne Binaries for DLL Sideloading
Seedworm APT Abuses Signed Fortemedia and SentinelOne Binaries for DLL Sideloading Iran-linked hackers have been quietly breaking into networks around the world, and their latest campaign is more calculated than anything we have seen from them before. The group known as Seedworm, also tracked as MuddyWater, spent the first quarter of 2026 targeting at least…
-
Windows DNS Client Vulnerability Enables Remote Code Execution Attacks
Windows DNS Client Vulnerability Enables Remote Code Execution Attacks A newly disclosed vulnerability in the Microsoft Windows DNS Client could let attackers silently execute malicious code across enterprise networks, exposing a massive attack surface. Officially designated as CVE-2026-41096, this critical security flaw carries a severe CVSS score of 9.8 out of 10. By simply returning…
-
Critical 18-Year-Old NGINX Vulnerability Enables Remote Code Execution Attacks
Critical 18-Year-Old NGINX Vulnerability Enables Remote Code Execution Attacks A critical heap buffer overflow vulnerability has been discovered in the source code of NGINX, present since 2008. This vulnerability has been publicly disclosed, along with a working proof-of-concept exploit that can enable unauthenticated remote code execution (RCE) against one of the most widely used web…
-
TR-26-0237 (WordPress LiteSpeed Cache Güvenlik Zafiyeti)
TR-26-0237 (WordPress LiteSpeed Cache Güvenlik Zafiyeti) Go to usom.gov
-
TR-26-0236 (HashiCorp Nomad Güvenlik Bildirimi )
TR-26-0236 (HashiCorp Nomad Güvenlik Bildirimi ) Go to usom.gov
-
TR-26-0235 (Deskflow Güvenlik Zafiyeti)
TR-26-0235 (Deskflow Güvenlik Zafiyeti) Go to usom.gov
-
TR-26-0234 (Intel Çoklu Ürün Güvenlik Bildirimi)
TR-26-0234 (Intel Çoklu Ürün Güvenlik Bildirimi) Go to usom.gov
-
TR-26-0233 (Adobe After Effects Güvenlik Bildirimi )
TR-26-0233 (Adobe After Effects Güvenlik Bildirimi ) Go to usom.gov
-
18-Year-Old NGINX Rewrite Module Flaw Enables Unauthenticated RCE
18-Year-Old NGINX Rewrite Module Flaw Enables Unauthenticated RCE Cybersecurity researchers have disclosed multiple security vulnerabilities impacting NGINX Plus and NGINX Open, including a critical flaw that remained undetected for 18 years. The vulnerability, discovered by depthfirst, is a heap buffer overflow issue impacting ngx_http_rewrite_module (CVE-2026-42945, CVSS v4 score: 9.2) that could allow an attacker to…
-
Microsoft’s MDASH AI System Finds 16 Windows Flaws Fixed in Patch Tuesday
Microsoft’s MDASH AI System Finds 16 Windows Flaws Fixed in Patch Tuesday Microsoft has unveiled a new multi-model artificial intelligence (AI)-driven system called MDASH to facilitate vulnerability discovery and remediation at scale, adding that it’s being tested by some customers as part of a limited private preview. MDASH, short for multi-model agentic scanning harness, is…
-
Azerbaijani Energy Firm Hit by Repeated Microsoft Exchange Exploitation
Azerbaijani Energy Firm Hit by Repeated Microsoft Exchange Exploitation A threat actor with affiliations to China has been linked to a “multi-wave intrusion” targeting an unnamed Azerbaijani oil and gas company between late December 2025 and late February 2026, marking an expansion of its targeting. The activity has been attributed by Bitdefender with moderate-to-high confidence…
-
[Webinar] How Modern Attack Paths Cross Code, Pipelines, and Cloud
[Webinar] How Modern Attack Paths Cross Code, Pipelines, and Cloud TL;DR: Stop chasing thousands of “toast” alerts. Join experts from Wiz to learn how hackers connect tiny flaws to build a “Lethal Chain” to your data—and how to break it. Register for the Strategic Briefing Here. Most security tools work like a smoke alarm that…
-
Most Remediation Programs Never Confirm the Fix Actually Worked
Most Remediation Programs Never Confirm the Fix Actually Worked Security teams have never had better visibility into their environments and never been worse at confirming what they fix stays fixed. Mandiant’s M-Trends 2026 report puts the mean time to exploit at an estimated negative seven days. The Verizon 2025 DBIR puts median time to remediate…
-
May’s Patch Tuesday hauls out 132 CVEs
May’s Patch Tuesday hauls out 132 CVEs With advisories, this month’s count approaches 300 – though many are already in place Categories: Threat Research, X-ops Tags: Patch Tuesday, MICROSOFT PATCH TUESDAY Go to sophos
-
OpenAI’s GPT-5.5 is as Good as Mythos at Finding Security Vulnerabilities
OpenAI’s GPT-5.5 is as Good as Mythos at Finding Security Vulnerabilities The UK’s AI Security Institute evaluated GPT-5.5’s ability to find security vulnerabilities, and found that it is comparable to Claude Mythos. Note that the OpenAI model is generally available. Here is the Institute’s evaluation of Mythos. And here is an analysis of a smaller,…
-
Smashing Security podcast #467: How ShinyHunters hacked the world’s biggest universities
Smashing Security podcast #467: How ShinyHunters hacked the world’s biggest universities Welcome to the largest educational data breach in history – affecting nearly 9,000 institutions, every Ivy League university, and 30 million students mid-finals. When Canvas’s parent company refused to pay and announced they had deployed “security patches” instead, the hackers were less than impressed.…
-
Foxconn Attack Highlights Manufacturing’s Cyber Crisis
Foxconn Attack Highlights Manufacturing’s Cyber Crisis A Nitrogen ransomware attack on Foxconn’s North American facilities is one of 600 hits on manufacturers this year, as gangs increasingly target the sector for its low tolerance for downtime. Jai Vijayan Go to gbhackers.com
-
Checkbox Assessments Aren’t Fit to Measure to Risk
Checkbox Assessments Aren’t Fit to Measure to Risk Security governance needs to be more than an annual compliance exercise. New companies are emerging to address risk-management gaps in current audit tools. Arielle Waldman Go to gbhackers.com
-
Attackers Weaponize RubyGems for Data Dead Drops
Attackers Weaponize RubyGems for Data Dead Drops Threat actors are publishing RubyGems packages that include scrapers targeting public-facing UK government servers, but with no clear objective. Alexander Culafi Go to gbhackers.com
-
Tables Turn on ‘The Gentlemen’ RaaS Gang With Data Leak
Tables Turn on ‘The Gentlemen’ RaaS Gang With Data Leak An OPSEC failure provides a window into what helped the ransomware group rise: a generous affiliate model, opportunistic TTPs, and an effective organizational structure. Nate Nelson Go to gbhackers.com
-
Dark Reading Celebrates 20 Years as a Leading Authority on Cybersecurity, Highlighting the People, Events, Ideas, and Technologies Shaping the Modern Risk Landscape
Dark Reading Celebrates 20 Years as a Leading Authority on Cybersecurity, Highlighting the People, Events, Ideas, and Technologies Shaping the Modern Risk Landscape Informa TechTarget’s flagship cybersecurity media brand launches a special content series to mark two decades as a trusted source for cybersecurity professionals. Go to gbhackers.com
-
China’s ‘FamousSparrow’ APT Nests in South Caucasus Energy Firm
China’s ‘FamousSparrow’ APT Nests in South Caucasus Energy Firm The cyberthreat group targets an Azerbaijani oil and gas firm with repeated attacks, as the China-linked actors extend targeting beyond hospitality, telecom, and government sectors. Robert Lemos Go to gbhackers.com
-
LatAm Vibe Hackers Generate Custom Hacking Tools on the Fly
LatAm Vibe Hackers Generate Custom Hacking Tools on the Fly In the latest evolution of automated cyberattacks, two threat campaigns heavily leveraged AI agents to support attacks against entities in Mexico and Brazil. Alexander Culafi Go to gbhackers.com
-
ClickFix Evolves Using Decade-Old Open-Source Python SOCKS5 Proxy
ClickFix Evolves Using Decade-Old Open-Source Python SOCKS5 Proxy A newly observed ClickFix campaign is pushing beyond simple user-triggered infections, introducing a more persistent and stealthy intrusion chain using PySoxy, a 10-year-old open-source… Delivered by PolitePaul service Go to gbhackers.com
-
Ransomware Gangs Use BYOVD and EDR Killers to Disable Security Tools
Ransomware Gangs Use BYOVD and EDR Killers to Disable Security Tools Ransomware is evolving faster than many defenses can keep up. In 2026, attackers are no longer just encrypting files they are systematically dismantling security… Delivered by PolitePaul service Go to gbhackers.com
-
Infostealer Malware Fuels Corporate Breaches From Personal Devices
Infostealer Malware Fuels Corporate Breaches From Personal Devices Infostealer malware is no longer just a consumer nuisance it has become a direct bridge between personal device infections and full-scale enterprise breaches. Once… Delivered by PolitePaul service Go to gbhackers.com
-
Q1 2026 Ransomware Attacks Hits 2,122 Orgs Amid Fewer, More Impactful Groups
Q1 2026 Ransomware Attacks Hits 2,122 Orgs Amid Fewer, More Impactful Groups Ransomware activity remained elevated in Q1 2026, continuing the trend established over the past year. The latest State of Ransomware Q1 2026 report reveals that 2,122 organizations… Delivered by PolitePaul service Go to gbhackers.com
-
Fake FinalShell and Xshell Sites Push Kong RAT Malware
Fake FinalShell and Xshell Sites Push Kong RAT Malware Hackers are abusing fake download sites for popular tools like FinalShell and Xshell to deliver a new remote access trojan known as Kong RAT,… Delivered by PolitePaul service Go to gbhackers.com
-
US govt seeks Instructure testimony on massive Canvas cyberattack
US govt seeks Instructure testimony on massive Canvas cyberattack The U.S. House Committee on Homeland Security is calling on Instructure executives to testify about two cyberattacks by the ShinyHunters extortion group that targeted the company’s Canvas platform, allowing threat actors to steal student data and disrupt schools during final exams. […] Lawrence Abrams Go to…
-
UK fines water supplier $1.3M for exposing data of 664k customers
UK fines water supplier $1.3M for exposing data of 664k customers The Information Commissioner’s Office has fined South Staffordshire Water Plc and parent company South Staffordshire Plc £963,900 ($1.3 million) over a cyberattack that exposed the personal data of 663,887 customers and employees. […] Bill Toulas Go to bleepingcomputer
-
Webinar: Fixing the gaps in network incident response
Webinar: Fixing the gaps in network incident response IT teams often struggle to quickly coordinate responses across disparate systems during network incidents. This upcoming webinar explores how automation and AI-assisted workflows can reduce response times and help prevent outages. […] BleepingComputer Go to bleepingcomputer
-
Signal adds security warnings for social engineering, phishing attacks
Signal adds security warnings for social engineering, phishing attacks Signal has introduced new in-app confirmations and warning messages as additional safeguards against phishing and social engineering attempts that could lead to various forms of fraud. […] Bill Toulas Go to bleepingcomputer
-
Microsoft releases Windows 10 KB5087544 extended security update
Microsoft releases Windows 10 KB5087544 extended security update Microsoft has released the Windows 10 KB5087544 extended security update to fix the May 2026 Patch Tuesday vulnerabilities and resolve an issue with the new Remote Desktop warnings. […] Lawrence Abrams Go to bleepingcomputer
-
New Exim BDAT GnuTLS Vulnerability Enables Code Execution Attacks
New Exim BDAT GnuTLS Vulnerability Enables Code Execution Attacks A serious security flaw has been found in Exim, one of the most widely deployed mail transfer agents on the internet today. The vulnerability, tracked as EXIM-Security-2026-05-01.1, allows a remote attacker to corrupt server memory and potentially execute malicious code without needing any special privileges or…
-
Google Enhances Android Mobile Security with New AI-Powered Protections
Google Enhances Android Mobile Security with New AI-Powered Protections Android smartphones have become the go-to device for billions of people around the world. From banking and messaging to storing personal photos and sensitive documents, people rely on them for almost everything. That reliance has made mobile devices a prime target for scammers, cybercriminals, and threat…
-
Microsoft Releases Cumulative Update for Windows 11, Version 25H2 and 24H2
Microsoft Releases Cumulative Update for Windows 11, Version 25H2 and 24H2 Microsoft pushed out a significant cumulative update for Windows 11 on May 12, 2026, covering both version 25H2 and version 24H2. The update, identified as KB5089549, brings OS Builds 26200.8457 and 26100.8457 to users running these versions. It bundles the latest security fixes alongside…
-
Top 10 Best Data Loss Prevention Software in 2026
Top 10 Best Data Loss Prevention Software in 2026 In 2026, data is the undisputed lifeblood of the modern enterprise. As organizations shift completely to decentralized, multi-cloud architectures, the challenge of securing sensitive information—such as Intellectual Property (IP), Personally Identifiable Information (PII), and Protected Health Information (PHI)—has grown exponentially. It is no longer enough to…
-
Microsoft Teams Vulnerability Allows Hackers to Perform Spoofing Attacks
Microsoft Teams Vulnerability Allows Hackers to Perform Spoofing Attacks A newly disclosed security vulnerability in Microsoft Teams could allow attackers to spoof local devices, raising concerns for enterprises and individual users who rely on the platform for daily communications. Microsoft disclosed CVE-2026-32185 on May 12, 2026, as part of its coordinated May 2026 Patch Tuesday…
-
New Exim BDAT Vulnerability Exposes GnuTLS Builds to Potential Code Execution
New Exim BDAT Vulnerability Exposes GnuTLS Builds to Potential Code Execution Exim has released security updates to address a severe security issue affecting certain configurations that could enable memory corruption and potential code execution. Exim is an open-source Mail Transfer Agent (MTA) designed for Unix-like systems to receive, route, and deliver email. The vulnerability, tracked…
-
RubyGems Suspends New Signups After Hundreds of Malicious Packages Are Uploaded
RubyGems Suspends New Signups After Hundreds of Malicious Packages Are Uploaded RubyGems, the standard package manager for the Ruby programming language, has temporarily paused account sign ups following what has been described as a “major malicious attack.” “We’re dealing with a major malicious attack on Ruby Gems right now,” Maciej Mensfeld, senior product manager for…
-
New TrickMo Variant Uses TON C2 and SOCKS5 to Create Android Network Pivots
New TrickMo Variant Uses TON C2 and SOCKS5 to Create Android Network Pivots Cybersecurity researchers have flagged a new version of the TrickMo Android banking trojan that uses The Open Network (TON) for command-and-control (C2). The new variant, observed by ThreatFabric between January and February 2026, has been observed actively targeting banking and cryptocurrency wallet…
-
Webinar: What the Riskiest SOC Alerts Go Unanswered – and How Radiant Security Can Help
Webinar: What the Riskiest SOC Alerts Go Unanswered – and How Radiant Security Can Help Why do the Riskiest SOC Alerts Go Unanswered? Security operations teams are drowning in alerts. But the real problem isn’t always alert volume; it’s the blind spots. The most dangerous alerts are the ones no one is investigating. A recent…
-
Mini Shai-Hulud Worm Compromises TanStack, Mistral AI, Guardrails AI & More Packages
Mini Shai-Hulud Worm Compromises TanStack, Mistral AI, Guardrails AI & More Packages TeamPCP, the threat actor behind the recentsupply chain attack spree, has been linked to the compromise of the npm and PyPI packages from TanStack, UiPath, Mistral AI, OpenSearch, and Guardrails AI as part of a fresh Mini Shai-Hulud campaign. The affected npm packages…
-
Inside the lethal trifecta: Blast radius reduction in AI agent deployments
Inside the lethal trifecta: Blast radius reduction in AI agent deployments <p>Seven things security teams can start doing today to reduce risk</p> Categories: Threat Research Tags: AI, CISO, risk Go to sophos
-
Copy.Fail Linux Vulnerability
Copy.Fail Linux Vulnerability This is the worst Linux vulnerability in years. TL;DR copy.fail is a Linux kernel local privilege escalation, not a browser or clipboard attack. Disclosed by Theori on 29 April 2026 with a working PoC. It abuses the kernel crypto API (AF_ALG sockets) plus splice() to write four bytes at a time straight…
-
ISC Stormcast For Wednesday, May 13th, 2026 https://isc.sans.edu/podcastdetail/9930, (Wed, May 13th)
ISC Stormcast For Wednesday, May 13th, 2026 https://isc.sans.edu/podcastdetail/9930, (Wed, May 13th) (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License. Go to isc.sans.edu
-
Proxying the Unproxyable? Sending EXE traffic to a Proxy, (Wed, May 13th)
Proxying the Unproxyable? Sending EXE traffic to a Proxy, (Wed, May 13th) .. if “unproxyable” is a word that is .. I had a recent engagement where I had to look at the network traffic generated by a Windows executable. Unfortunately, it was all TLS, and all TLS1.3 to boot. So from a PCAP all…
-
Microsoft May 2026 Patch Tuesday, (Tue, May 12th)
Microsoft May 2026 Patch Tuesday, (Tue, May 12th) Today’s Microsoft patch Tuesday fixes 137 different vulnerabilities. In addition, the update addresses 137 Chromium-related issues affecting Microsoft Edge. There are no already disclosed or already exploited vulnerabilities included in today’s patches. I removed the Chromium issues from the table below and included only the 137 Microsoft issues…
-
Patch Tuesday, May 2026 Edition
Patch Tuesday, May 2026 Edition Artificial intelligence platforms may be just as susceptible to social engineering as human beings, but they are proving remarkably good at finding security vulnerabilities in human-made computer code. That reality is on full display this month with some of the more widely-used software makers — including Apple, Google, Microsoft, Mozilla…