threat-intel MuddyWater Uses DLL Side-Loading in Espionage Campaign Targeting 9 Countries The MuddyWater hacking group, backed by Iran, has been conducting a sophisticated espionage campaign targeting organizations across nine countries on four continents during Q1 2026. The campaign utilizes DLL side-loading… The Hacker News · May 26, 2026 High KRSAAEdll-side-loadingcredential-stealingreconnaissance
threat-intel How Varonis Atlas integrates Claude Compliance API for AI governance Varonis has announced an integration between its Atlas AI Security Platform and the Claude Compliance API, allowing for enhanced monitoring and governance of activity within Claude Enterprise and Claude Platform. This in… BleepingComputer · May 26, 2026 Medium aillmcompliance
threat-intel AppOmni’s Marlin AI Brings Autonomous Investigation to SaaS Security This article discusses AppOmni’s new Marlin AI platform, designed to autonomously investigate security issues within Software-as-a-Service (SaaS) applications. The platform leverages AI to analyze configurations across n… SecurityWeek · May 26, 2026 Medium saasaiconfiguration
threat-intel Iranian APT Targets Aviation, Software Companies With Updated Tools The Iranian APT group, known as Nimbus Manticore, has been aggressively updating its tactics and tools to target aviation and software companies globally. The group, linked to Charming Kitten and the IRGC, is employing… SecurityWeek · May 26, 2026 High AEIRSAaptphishingappdomain
threat-intel Remembering Tim Wilson, Whose Legacy Lives on at Dark Reading This article celebrates the 20th anniversary of Dark Reading, highlighting the legacy of Tim Wilson, its co-founder and former editor-in-chief. Wilson’s focus on the human element of cybersecurity, combined with his inno… Dark Reading · May 26, 2026 Low anniversaryleadershipcybersecurity
threat-intel ABB AC500 V2 ABB has identified and addressed vulnerabilities in its AC500 V2 PLC firmware, specifically versions up to 2.5.3. An attacker could potentially access Modbus telegram fragments by sending unsupported function codes to th… CISA Advisories · May 26, 2026 Medium CVE-2025-7745WOmodbusplcfirmware
threat-intel Open Source DockSec Uses AI to Cut Through Vulnerability Noise in Docker Images This article reports on the development of DockSec, an open-source tool designed to address the challenge of vulnerability detection in Docker images. The tool utilizes an LLM to correlate findings from multiple vulnerab… SecurityWeek · May 26, 2026 Medium dockervulnerabilityai
threat-intel MFA Prompt Bombing: Why Your Second Factor Isn't Saving You This article details a new attack technique called ‘MFA prompt bombing,’ where attackers repeatedly trigger multi-factor authentication prompts to trick users into approving access. The attack leverages push-based MFA sy… The Hacker News · May 26, 2026 High USmfapush-mfaprompt bombing
threat-intel CERT-In Mandates 12-Hour Patching for Internet-Facing Flaws Amid AI-Assisted Attacks CERT-In has mandated a 12-hour patching window for critical internet-facing vulnerabilities, driven by the increasing use of AI by threat actors to automate attacks. This response is intended to address the accelerated a… The Hacker News · May 26, 2026 High INaicybersecurityvulnerability
threat-intel BTMOB: A stealthy RAT burrowing deep into Android devices BTMOB is a stealthy Android remote access trojan (RAT) that’s rapidly evolving and spreading through phishing campaigns and a ‘malware-as-a-service’ model. It allows attackers to steal data, take control of devices, and… WeLiveSecurity · May 26, 2026 High ARandroidmalwareremote access trojan
threat-intel KnowledgeDeliver LMS Flaw Exploited to Deploy Godzilla and Cobalt Strike A zero-day vulnerability in Digital Knowledge KnowledgeDeliver LMS was exploited to deploy the Godzilla web shell and establish Cobalt Strike Beacon access. The flaw, stemming from hard-coded ASP.NET machine keys, allowe… The Hacker News · May 26, 2026 Critical CVE-2026-5426JPzero-daydeserializationasp.net
threat-intel Dutch authorities arrest men suspected of providing infrastructure for Russian cyber operations Dutch authorities have arrested two IT entrepreneurs suspected of providing hosting infrastructure used in pro-Russian cyberattacks and disinformation campaigns. The investigation, led by the FIOD, uncovered a network in… The Record · May 25, 2026 High NLMDRUcyberattackdisinformationsanctions
threat-intel Anthropic’s restricted Claude Mythos model may be coming to Claude Code Anthropic is preparing to release a new AI model called Mythos, initially designed for advanced computer security tasks. The model demonstrates a concerning ability to autonomously develop cyberattacks, raising significa… BleepingComputer · May 25, 2026 High aicybersecurityvulnerability
threat-intel ⚡ Weekly Recap: Linux Flaws, Defender 0-Days, Router Botnets, and Supply Chain Chaos This week’s security news highlights a significant GitHub breach orchestrated by TeamPCP, stemming from a compromised developer’s device and leveraging vulnerabilities exposed by the TanStack supply chain attack. Simulta… The Hacker News · May 25, 2026 High CVE-2026-46333CVE-2026-41091CVE-2026-45498USGBsupply-chainlinuxgithub
threat-intel Netherlands Seizes 800 Servers, Arrests 2 for Aiding Cyberattacks Dutch authorities have seized over 800 servers and arrested two individuals – Andrey Nesterenko and Youssef Zinad – operating MIRhosting and WorkTitans, respectively, for facilitating cyberattacks and disinformation camp… Krebs on Security · May 25, 2026 High NLDKRUcyberattackddossanctions
threat-intel The Alert Firehose Finally Meets Its Match This article discusses the evolution of Network Detection and Response (NDR) systems, particularly with the integration of agentic AI. It highlights how early NDR deployments suffered from a "noisy" alert firehose due to… The Hacker News · May 25, 2026 Medium NOndraithreat intelligence
threat-intel Anthropic: Mythos Detected 23,000 Potential Vulnerabilities Across 1,000 OSS Projects Anthropic’s Claude Mythos AI model has identified a massive number of vulnerabilities – estimated between 6,200 and 23,000 – across over 1,000 open-source software projects. Many of these vulnerabilities, particularly t… SecurityWeek · May 25, 2026 Critical UKaivulnerabilityopen source
threat-intel Ghost CMS SQL injection flaw exploited in large-scale ClickFix campaign A large-scale campaign is exploiting a critical SQL injection vulnerability in Ghost CMS to deploy ClickFix attack flows, targeting over 700 websites across various sectors. The campaign leverages stolen admin API keys t… BleepingComputer · May 24, 2026 High CVE-2026-26980sql injectionclickfixghost cms
threat-intel Italy disrupts CINEMAGOAL piracy app that stole streaming auth codes Italian authorities disrupted a sophisticated piracy operation centered around the CINEMAGOAL app, which provided unauthorized access to streaming services like Netflix and Disney+. The operation, dubbed "Tutto Chiaro,"… BleepingComputer · May 23, 2026 Medium ITFRDEpiracystreamingauthentication
threat-intel Claude Mythos AI Finds 10,000 High-Severity Flaws in Widely Used Software Anthropic’s Project Glasswing has identified over 10,000 high-severity vulnerabilities in widely used software, primarily through its Claude Mythos Preview AI model. This initiative focuses on proactively identifying and… The Hacker News · May 23, 2026 Critical CVE-2026-5194aivulnerabilitypatching