threat-intel CISA to allow researchers to report vulnerabilities to exploited bugs catalog CISA has launched a new nomination form to allow external researchers, vendors, and industry partners to report exploited vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog. This initiative aims to enha… The Record · May 23, 2026 Medium USvulnerability disclosurethreat intelligencecybersecurity
threat-intel Meta settles school district lawsuit claiming addictive design harmed students' mental health Meta has reached a settlement with the Breathitt County School District in Kentucky over claims that its platform designs were addictive and negatively impacted students’ mental health. This settlement marks the first of… The Record · May 22, 2026 Medium USsocial mediamental healthaddiction
threat-intel First VPN Dismantled in Global Takedown Over Use by 25 Ransomware Groups A global operation, dubbed Operation Saffron, led by France and the Netherlands, successfully dismantled the First VPN service, a virtual private network specifically designed for criminal use. The service was utilized b… The Hacker News · May 22, 2026 High USFRNLvpnransomwareanonymity
threat-intel Lawmakers Demand Answers as CISA Tries to Contain Data Leak A significant security breach occurred involving the intentional publication of sensitive CISA data, including AWS GovCloud keys and internal system credentials, by a CISA contractor. The exposed data, hosted on a public… Krebs on Security · May 22, 2026 High USgithubcredentialleak
threat-intel Akamai Joins Growing Chorus of Vendors Betting Big on Secure Enterprise Browsers Akamai has acquired LayerX, a Tel Aviv-based startup, for $205 million to bolster its Zero Trust Network Access (ZTNA) portfolio. This move reflects a growing trend among cybersecurity vendors adding secure enterprise br… Dark Reading · May 22, 2026 Medium ILsecure browserztnasaas
threat-intel Former US execs plead guilty to aiding tech support scammers Two former executives of C.A. Cloud Attribution, Ltd. have pleaded guilty to aiding a years-long tech support fraud scheme that targeted individuals worldwide. The executives knowingly provided services to telemarketing… BleepingComputer · May 22, 2026 High USGBTNtech support fraudtelemarketingfraud
threat-intel Why the Supreme Court's Chatrie case could change the meaning of privacy in America The Supreme Court is considering a case, *Chatrie v. Google*, concerning the legality of geofence warrants, which allow law enforcement to obtain location history data from tech companies like Google. This case, the firs… The Record · May 22, 2026 Medium USgeofencingprivacyfourth amendment
threat-intel In Other News: Industrial Router Exploitation, CISA KEV Nomination Form, Gas Station Hacking This week’s cybersecurity news highlights several incidents, including Iranian hackers targeting US gas station tank monitor systems, a CISA contractor exposing sensitive credentials, a Huawei router vulnerability causin… SecurityWeek · May 22, 2026 High CVE-2024-9643CVE-2026-45401USLUiotcritical infrastructuresupply-chain
threat-intel Verizon DBIR: Healthcare Fends Off Increased Social Engineering Attacks The Verizon 2026 Data Breach Investigations Report (DBIR) reveals a significant increase in social engineering attacks targeting the healthcare sector, driven by the adoption of generative AI. While ransomware and vendor… Dark Reading · May 22, 2026 High social engineeringaigenai
threat-intel Why Chargebacks are Just One Piece of the Fraud Puzzle This BleepingComputer article discusses the limitations of solely relying on chargeback rates to measure fraud performance. It highlights that focusing solely on chargebacks obscures a broader range of fraud impacts, inc… BleepingComputer · May 22, 2026 High account takeoverfraud detectionchargebacks
threat-intel Tracking Iranian APT Screening Serpens’ 2026 Espionage Campaigns This report from Palo Alto Unit 42 details ongoing espionage campaigns conducted by the Iran-nexus APT group Screening Serpens (UNC1549). The group, active since 2022, targeted entities in the U.S., Israel, the UAE, and… Palo Alto Unit 42 · May 22, 2026 High USIRILaptespionagesocial engineering
threat-intel Making Vulnerable Drivers Exploitable Without Hardware - The BYOVD Perspective This article details a technique for evaluating the exploitability of Windows kernel mode drivers, focusing on the potential for BYOVD (Bring Your Own Vulnerability Driver) attacks. It highlights how vulnerabilities in d… The Hacker News · May 22, 2026 Medium USdriverbyovdkernel mode
threat-intel Paved With Intent: ROADtools and Nation-State Tactics in the Cloud This report details the use of ROADtools, an open-source toolkit primarily designed for red-teaming and research, by nation-state threat actors in cloud intrusions. The tool leverages legitimate Microsoft APIs to enumera… Palo Alto Unit 42 · May 22, 2026 High USentraidazureadtoken management
threat-intel US and Canada arrest and charge suspected Kimwolf botnet admin US and Canadian authorities have arrested Jacob Butler, an administrator of the KimWolf DDoS botnet, following a multi-national operation targeting several botnets. The botnet, which infected nearly two million devices g… BleepingComputer · May 22, 2026 High USCADEddosbotnetiot
threat-intel Foul play: Fake FIFA websites target soccer fans looking for World Cup tickets, merchandise As the 2026 FIFA World Cup approaches, scammers are exploiting fans’ desire for tickets and merchandise by creating convincing fake websites mimicking FIFA’s official channels. These sites use tactics like typosquatting… WeLiveSecurity · May 22, 2026 High phishingsocial engineeringdomain spoofing
threat-intel China's Webworm Uses Discord, Microsoft Graphs to Hack EU Govts. A China-aligned Advanced Persistent Threat (APT) group known as Webworm has shifted its focus from Asia to targeting European governmental organizations, specifically in Belgium, Italy, Serbia, Spain, Poland, and South A… Dark Reading · May 22, 2026 High CHBEITaptdiscordmicrosoft graph
threat-intel ISC Stormcast For Friday, May 22nd, 2026 https://isc.sans.edu/podcastdetail/9942, (Fri, May 22nd) The SANS Internet Storm Center's Stormcast for May 22nd, 2026 highlighted a concerning increase in several active threats across the internet landscape. The report detailed a rise in phishing campaigns, malicious email a… SANS Internet Storm Center · May 22, 2026 Medium phishingvulnerabilitythreat-intelligence
threat-intel Belarus-linked hackers use fake training certificates to target Ukrainian officials A Belarus-linked hacking group, GhostWriter (UNC1151/Storm-0257), is conducting a new espionage campaign targeting Ukrainian government officials. The operation utilizes sophisticated phishing emails disguised as trainin… The Record · May 21, 2026 High UABYphishingmalwareespionage
threat-intel Alleged Kimwolf Botmaster ‘Dort’ Arrested, Charged in U.S. and Canada A 23-year-old man, identified as Jacob Butler (a.k.a. ‘Dort’), has been arrested in Canada and faces criminal charges for operating the Kimwolf DDoS botnet. The botnet, responsible for massive DDoS attacks and targeting… Krebs on Security · May 21, 2026 High CAUSddosbotnetiot
threat-intel How CISOs Should Prep for Agentic-Ready AI BOMs This Dark Reading article discusses the evolving need for Artificial Intelligence Bills of Materials (AI BOMs) to address the unique security challenges posed by agentic AI systems. Traditional SBOMs focus on components… Dark Reading · May 21, 2026 Medium aibomagentic ai