supply-chain Typosquatting Is No Longer a User Problem. It's a Supply Chain Problem This article highlights a significant shift in cyberattack tactics, moving away from traditional phishing and towards a supply chain attack leveraging AI-generated lookalike domains and compromised third-party scripts. T… The Hacker News · May 20, 2026 Critical USsupply-chainbrowserai
malware Tracking TamperedChef Clusters via Certificate and Code Reuse This report details ongoing activity clusters closely resembling the TamperedChef (EvilAI) malware campaign, which involves trojanized productivity software like PDF editors and calendars. These campaigns utilize malicio… Palo Alto Unit 42 · May 20, 2026 High USpersistencecommand and controltrojan
vulnerability How an image could compromise your Mac: understanding an ExifTool vulnerability (CVE-2026-3102) This article details a vulnerability (CVE-2026-3102) in ExifTool for macOS, allowing an attacker to execute arbitrary commands by injecting malicious data into the FileCreateDate metadata field. The vulnerability stems f… Securelist · May 20, 2026 Critical CVE-2026-3102CVE-2021-22204exiftoolmacosmetadata
malware Trapdoor Android Ad Fraud Scheme Hit 659 Million Daily Bid Requests Using 455 Apps A new Android ad fraud scheme, dubbed Trapdoor, has been identified by HUMAN Threat Intelligence, utilizing 455 malicious apps and 183 C2 domains to generate 659 million daily bid requests. The operation leverages malver… The Hacker News · May 19, 2026 High USandroidad fraudmalvertising
threat-intel DirtyDecrypt PoC Released for Linux Kernel CVE-2026-31635 LPE Vulnerability A Proof-of-Concept (PoC) exploit, dubbed DirtyDecrypt, has been released for a Linux kernel vulnerability (CVE-2026-31635) allowing for local privilege escalation. The vulnerability, related to a missing copy-on-write (C… The Hacker News · May 19, 2026 High CVE-2026-31635CVE-2026-31431CVE-2026-43284linuxkernellpe
threat-intel The New Phishing Click: How OAuth Consent Bypasses MFA In February 2026, a phishing-as-a-service platform, EvilTokens, compromised over 340 Microsoft 365 organizations across five countries by exploiting OAuth consent screens. Attackers gained access to valid refresh tokens… The Hacker News · May 19, 2026 High USGBoauthconsentphishing
supply-chain Compromised Nx Console 18.95.0 Targeted VS Code Developers with Credential Stealer A compromised version of the Nx Console VS Code extension (version 18.95.0) was used to steal developer credentials through a supply chain attack. The extension, initially introduced by a developer whose machine was comp… The Hacker News · May 19, 2026 High RUUSsupply chaincredential theftvscode
threat-intel Microsoft Exchange Zero-Day Under Attack, No Patch Available A zero-day vulnerability (CVE-2026-42897) affecting Microsoft Exchange Outlook Web Access (OWA) is under active exploitation, allowing attackers to compromise mailboxes through cross-site scripting (XSS). Despite Microso… Dark Reading · May 18, 2026 High CVE-2026-42897BEzero-dayxssexchange
phishing How to Reduce Phishing Exposure Before It Turns into Business Disruption This article discusses the increasing risk posed by phishing attacks, particularly due to their ability to quickly escalate into significant business disruptions. It highlights the challenges SOC teams face in identifyin… The Hacker News · May 18, 2026 High USphishingsandboxcredential theft
threat-intel The Boring Stuff Is Dangerous Now This article highlights a growing security challenge stemming from the widespread adoption of AI coding tools and the emergence of AI agents capable of exploiting obscure vulnerabilities. The combination creates a situat… Dark Reading · May 18, 2026 High aivulnerabilitycybersecurity
data-breach Boulevard of Broken Dreams: 2 Decades of Cyber Fails This Dark Reading article reflects on two decades of cybersecurity failures, highlighting recurring trends like data breaches, systemic vulnerabilities, and a growing sense of apathy among individuals regarding data secu… Dark Reading · May 18, 2026 High CVE-2023-34362USdata breachsql injectioncybersecurity
threat-intel Developer Workstations Are Now Part of the Software Supply Chain Recent attacks, including those mimicking the "mini Shai Hulud" and "Shai-Hulud 2.0" campaigns, have highlighted a growing threat: attackers targeting developer workstations to steal credentials and secrets from CI/CD pi… The Hacker News · May 18, 2026 High USdeveloper workstationssecretssupply chain
threat-intel Ivanti, Fortinet, SAP, VMware, n8n Patch RCE, SQL Injection, Privilege Escalation Flaws Multiple vendors, including Ivanti, Fortinet, SAP, and VMware, have released security patches to address critical vulnerabilities across their products. These vulnerabilities include remote code execution, SQL injection,… The Hacker News · May 18, 2026 Critical CVE-2026-8043CVE-2026-44277CVE-2026-26083USUKremote code executionsql injectionprivilege escalation
threat-intel Four Malicious npm Packages Deliver Infostealers and Phantom Bot DDoS Malware Four npm packages have been identified as containing malicious code, including a clone of the Shai-Hulud worm. One package delivers a DDoS botnet (Phantom Bot), while the others function as infostealers, stealing sensiti… The Hacker News · May 18, 2026 High NOsupply chainnpminfostealer
threat-intel Taiwan Bullet Train Hack Highlights Cybersecurity Gaps in Rail Systems A Taiwanese student exploited vulnerabilities in the Taiwan High Speed Rail (THSR)'s TETRA radio system, causing a 48-minute delay in service by spoofing an emergency alarm. This incident highlights broader cybersecurity… Dark Reading · May 15, 2026 Medium TAPOISrailcyberattacktetra
vulnerability Siemens Ruggedcom Rox This CISA advisory details a vulnerability affecting Siemens Ruggedcom Rox devices. The devices, specifically versions prior to 2.17.1, contain multiple third-party vulnerabilities, including those listed in CVEs from 20… CISA Advisories · May 14, 2026 Medium CVE-2019-13103CVE-2019-13104CVE-2019-13106vulnerabilitypatchingcve
threat-intel A 0-click exploit chain for the Pixel 10: When a Door Closes, a Window Opens Google Project Zero researchers discovered a critical 0-click vulnerability in the Google Pixel 10's VPU driver, allowing for arbitrary kernel code execution. The vulnerability stems from a flaw in the `vpu_mmap` functio… Google Project Zero · May 13, 2026 Critical CVE-2025-54957zero-clickkernel-exploitationdriver-vulnerability
threat-intel [GUEST DIARY] Tearing apart website fraud to see how it works., (Wed, May 13th) This article, a guest diary by an ISC intern, details an investigation into a fraudulent marketplace operation. The author discovered a website using SEO poisoning to lure victims into purchasing goods from a fake market… SANS Internet Storm Center · May 13, 2026 High INseo poisoningfraudmarketplace
threat-intel Patch Tuesday, May 2026 Edition This article reports on Patch Tuesday, May 2026, highlighting a significant increase in security vulnerabilities addressed by major software vendors like Microsoft, Apple, Google, Mozilla, and Oracle. The updates, spurre… Krebs on Security · May 12, 2026 Critical CVE-2026-41089CVE-2026-41096CVE-2026-41103USpatch tuesdayaivulnerability
threat-intel Unplug your way to better code This article from Cisco Talos discusses a shift in threat intelligence strategy, focusing on tracking phone numbers used in sophisticated scam campaigns. Attackers are increasingly utilizing API-driven VoIP numbers for T… Cisco Talos · May 7, 2026 Medium voipscamphone numbers