threat-intel Four Malicious npm Packages Deliver Infostealers and Phantom Bot DDoS Malware Four npm packages have been identified as containing malicious code, including a clone of the Shai-Hulud worm. One package delivers a DDoS botnet (Phantom Bot), while the others function as infostealers, stealing sensiti… The Hacker News · May 18, 2026 High NOsupply chainnpminfostealer
threat-intel Can Laws Stop Deepfakes? South Korea Aims to Find Out This article reports on South Korea's proactive approach to combating deepfakes ahead of upcoming local elections. The country is implementing new laws, including Article 82-8 of the Public Official Election Act and the… Dark Reading · May 18, 2026 Medium KRdeepfakeaielection
threat-intel Cyber Pioneers Ponder Past as Prologue This Dark Reading article reflects on the platform's 20-year history, featuring insights from prominent cybersecurity leaders who contributed to its content. Robert Hansen discusses his early work on robot scraping and A… Dark Reading · May 15, 2026 High aivulnerabilitybug bounties
threat-intel Bypassing On-Camera Age-Verification Checks This article discusses a research paper detailing a new approach to zero-knowledge proofs that achieves perfect soundness, no interaction, and no setup, effectively addressing key limitations of existing zero-knowledge p… Schneier on Security · May 15, 2026 Medium zero-knowledgefirmwarehardware
threat-intel Why geopolitical turmoil is a gift for scammers, and how to stay safe Geopolitical turmoil is being exploited by scammers to increase the success of their fraudulent schemes. The article details a range of scams – from fake charities and romance fraud to investment scams and sensational fa… WeLiveSecurity · May 15, 2026 Medium IRMIscamsfraudcybercrime
threat-intel [Guest Diary] New Malware Libraries means New Signatures, (Fri, May 15th) This SANS Internet Storm Center diary details a new observation of the long-running mdrfckr campaign, a Shellbot associated with the Outlaw/Dota group. The key finding is the identification of a previously undocumented v… SANS Internet Storm Center · May 15, 2026 Medium USCNshellbotlibsshmdrfckr
threat-intel ISC Stormcast For Friday, May 15th, 2026 https://isc.sans.edu/podcastdetail/9934, (Fri, May 15th) The SANS Internet Storm Center's Stormcast for May 15th, 2026 highlighted a concerning increase in several active threats across the internet landscape. The report detailed a rise in phishing campaigns, malicious email a… SANS Internet Storm Center · May 15, 2026 Medium phishingvulnerabilitythreat intelligence
threat-intel Taiwan Bullet Train Hack Highlights Cybersecurity Gaps in Rail Systems A Taiwanese student exploited vulnerabilities in the Taiwan High Speed Rail (THSR)'s TETRA radio system, causing a 48-minute delay in service by spoofing an emergency alarm. This incident highlights broader cybersecurity… Dark Reading · May 15, 2026 Medium TAPOISrailcyberattacktetra
threat-intel Suspected Dream Market kingpin arrested after gold bars sent to his home address Owe Martin Andresen, suspected to be the administrator of the notorious Dream Market dark web drug marketplace, has been arrested on money laundering charges in the US and Germany. Authorities allege he moved millions of… Graham Cluley · May 14, 2026 High USDEdark webdrug traffickingmoney laundering
threat-intel The time of much patching is coming This article from Cisco Talos anticipates a significant increase in software patching due to advancements in AI-powered vulnerability detection and the uncovering of long-standing technical debt. The surge in discovered… Cisco Talos · May 14, 2026 High USvulnerabilitypatchingai
threat-intel Siemens SIMATIC Siemens has released a security update for its SIMATIC CN 4100 system to address multiple vulnerabilities discovered within its Linux kernel components and libxml2. These vulnerabilities, including null pointer dereferen… CISA Advisories · May 14, 2026 High CVE-2024-47704CVE-2024-57924CVE-2024-58240DElinuxkernelvulnerability
threat-intel How Dangerous Is Anthropic’s Mythos AI? Anthropic’s Claude Mythos AI model demonstrates a significant capability in identifying software vulnerabilities, prompting concerns about its potential misuse by attackers. While the company initially restricted access… Schneier on Security · May 14, 2026 High UKaivulnerabilitycybersecurity
threat-intel Kimsuky targets organizations with PebbleDash-based tools This report details the ongoing activity of the Kimsuky threat actor group, also known as APT43, who have been utilizing a PebbleDash-based malware platform to conduct targeted attacks. The group has significantly evolve… Securelist · May 14, 2026 High KRBRDEspear phishingremote access trojansouth korea
threat-intel FrostyNeighbor: Fresh mischief and digital shenanigans FrostyNeighbor, a long-running cyberespionage group allegedly linked to Belarus, is continuing its operations targeting governmental organizations in Ukraine and other Eastern European countries. The latest activity invo… WeLiveSecurity · May 14, 2026 High BYPLLTcyberespionagecobalt strikepicassoloader
threat-intel ISC Stormcast For Thursday, May 14th, 2026 https://isc.sans.edu/podcastdetail/9932, (Thu, May 14th) The SANS Internet Storm Center's Stormcast for May 14th, 2026 highlighted a concerning increase in various online threats, including phishing campaigns and malicious activity targeting critical infrastructure. The report… SANS Internet Storm Center · May 14, 2026 Medium phishingddosiot
threat-intel Smashing Security podcast #467: How ShinyHunters hacked the world’s biggest universities This episode of Smashing Security discusses a recent incident where ShinyHunters, a known threat actor, compromised the networks of several major universities. The attackers leveraged a vulnerability to gain access, targ… Graham Cluley · May 13, 2026 High universityvulnerabilitythreat-actor
threat-intel A 0-click exploit chain for the Pixel 10: When a Door Closes, a Window Opens Google Project Zero researchers discovered a critical 0-click vulnerability in the Google Pixel 10's VPU driver, allowing for arbitrary kernel code execution. The vulnerability stems from a flaw in the `vpu_mmap` functio… Google Project Zero · May 13, 2026 Critical CVE-2025-54957zero-clickkernel-exploitationdriver-vulnerability
threat-intel [GUEST DIARY] Tearing apart website fraud to see how it works., (Wed, May 13th) This article, a guest diary by an ISC intern, details an investigation into a fraudulent marketplace operation. The author discovered a website using SEO poisoning to lure victims into purchasing goods from a fake market… SANS Internet Storm Center · May 13, 2026 High INseo poisoningfraudmarketplace
threat-intel ISC Stormcast For Wednesday, May 13th, 2026 https://isc.sans.edu/podcastdetail/9930, (Wed, May 13th) The SANS Internet Storm Center's Stormcast for May 13th, 2026 highlighted a concerning increase in several active threats across the internet landscape. The broadcast detailed ongoing campaigns involving phishing attacks… SANS Internet Storm Center · May 13, 2026 Medium phishingddosbotnet
threat-intel Patch Tuesday, May 2026 Edition This article reports on Patch Tuesday, May 2026, highlighting a significant increase in security vulnerabilities addressed by major software vendors like Microsoft, Apple, Google, Mozilla, and Oracle. The updates, spurre… Krebs on Security · May 12, 2026 Critical CVE-2026-41089CVE-2026-41096CVE-2026-41103USpatch tuesdayaivulnerability