threat-intel Google API Keys Remain Active After Deletion This article details a significant vulnerability in Google Cloud Platform (GCP) API key deletion processes. Researcher Joe Leon of Aikido Security discovered that API keys can remain active for up to 23 minutes after del… Dark Reading · May 21, 2026 High USSGapi keysgcpauthentication
threat-intel Tech giants promise British regulator they will tweak platforms to protect kids online Following pressure from the UK’s Ofcom regulator, several major tech companies – including Roblox, Snapchat, Instagram (Meta), and TikTok – have pledged to implement changes to their platforms to better protect children… The Record · May 21, 2026 High UKgroomingchild_safetyalgorithms
threat-intel Two Americans plead guilty to assisting India-based tech support scam centers Two American men, Adam Young and Harrison Gevirtz, have pleaded guilty to assisting India-based tech support scam centers. They operated a U.S.-based tech firm, C.A. Cloud Attribution, providing services like call routin… The Record · May 21, 2026 High USINTNscamfraudtelemarketing
threat-intel AI Agents Are Shifting Identity Security Budget Dynamics This Dark Reading article reports on a new Omdia research study highlighting a shift in cybersecurity budget dynamics driven by the increasing adoption of AI agents within enterprises. Identity teams are establishing ded… Dark Reading · May 21, 2026 Medium aiidentitysecurity
threat-intel UK plans for cybercrime law reform would protect almost no one, experts warn The UK government’s proposed reforms to the Computer Misuse Act 1990 are facing criticism from cybersecurity experts who believe they will offer minimal protection to researchers. The proposed changes would restrict the… The Record · May 21, 2026 Medium UKcybersecurityresearchlegal
threat-intel Chinese APTs Share Linux Backdoor in Central Asia Telco Attacks This article details the discovery of "Showboat" (kworker), a Linux post-exploitation framework being shared among Chinese Advanced Persistent Threat (APT) groups, primarily Calypso and Red Lamassu. The malware has been… Dark Reading · May 21, 2026 Medium CHAFUKaptlinuxspyware
threat-intel Chinese hackers target telcos with new Linux, Windows malware A Chinese cyber-espionage group, known as Calypso (Red Lamassu), has been targeting telecommunications providers globally since mid-2022 with a dual-pronged malware campaign utilizing Showboat (Linux) and JMFBackdoor (Wi… BleepingComputer · May 21, 2026 High CHMIASlinuxwindowsespionage
threat-intel Police seize “First VPN” service used in ransomware, data theft attacks Law enforcement agencies, in a coordinated international effort led by France and the Netherlands, have taken down the ‘First VPN’ service, a virtual private network used extensively by ransomware and data theft groups.… BleepingComputer · May 21, 2026 High UKFRNEvpncybercrimeransomware
threat-intel Content Delivery Exploit Opens Websites to Brand Hijacking This article details a new exploit, dubbed "Underminr," that leverages vulnerabilities in Internet infrastructure to allow attackers to hijack websites and conceal malicious activity. The technique, a successor to domain… Dark Reading · May 21, 2026 High USEUCNcdndnsdomain fronting
threat-intel ThreatsDay Bulletin: Linux Rootkits, Router 0-Day, AI Intrusions, Scam Kits and 25 New Stories This week's threat intelligence report highlights a diverse range of security incidents and vulnerabilities, including a significant Pwn2Own competition with substantial rewards, warnings about the risks of deploying age… The Hacker News · May 21, 2026 High CVE-2026-45793CVE-2026-8631UKUSCHzero-dayai securitysocial engineering
threat-intel When Identity is the Attack Path This article highlights the increasing risk of attacks leveraging compromised identity credentials within complex IT environments. A single, exposed access key, often due to cached credentials or excessive permissions, c… The Hacker News · May 21, 2026 High USidentitycredentialspermissions
threat-intel GitHub Internal Repositories Breached via Malicious Nx Console VS Code Extension GitHub experienced a breach of its internal repositories due to a compromised employee device utilizing a malicious VS Code extension, the Nx Console. The attack, orchestrated by TeamPCP, leveraged a supply chain vulnera… The Hacker News · May 21, 2026 High CVE-2026-45321CVE-2026-48027supply chainvscodeopen source
threat-intel ISC Stormcast For Thursday, May 21st, 2026 https://isc.sans.edu/podcastdetail/9940, (Thu, May 21st) The SANS Internet Storm Center's Stormcast for May 21st, 2026 highlighted a concerning increase in several active threats across the internet landscape. The report detailed a rise in phishing campaigns, malicious email a… SANS Internet Storm Center · May 21, 2026 Medium phishingvulnerabilitythreat intelligence
threat-intel Smashing Security podcast #468: High-speed train hacks and homicidal lawnmowers This Smashing Security podcast episode discusses several ongoing cybersecurity incidents and investigations. The conversation touches on the ongoing Lazarus Group activities, including the upcoming ‘Cyberhack’ season, an… Graham Cluley · May 20, 2026 High NOTAnorth koreamalwarethreat intelligence
threat-intel Europe dismantles VPN service used by cybercriminals to hide ransomware attacks European law enforcement agencies successfully dismantled First VPN, a virtual private network (VPN) service heavily utilized by cybercriminals to mask their activities, including ransomware attacks and fraud schemes. Th… The Record · May 20, 2026 High FRNLUAvpncybercrimeransomware
threat-intel Hackers bypass SonicWall VPN MFA due to incomplete patching Hackers exploited a vulnerability (CVE-2024-12802) in SonicWall Gen6 SSL-VPN appliances to bypass multi-factor authentication and deploy ransomware tools. The attackers gained access to networks within 30-60 minutes, lev… BleepingComputer · May 20, 2026 High CVE-2024-12802USvpnmfacredential theft
threat-intel Cyber Pros Can't Decide If AI Is a Good or a Bad Thing This article explores the complex and often contradictory opinions of cybersecurity professionals regarding the impact of artificial intelligence (AI) on the field. While many recognize AI's potential to improve security… Dark Reading · May 20, 2026 Medium aisocial engineeringdeepfakes
threat-intel GitHub Confirms Breach, 4K Internal Repos Stolen GitHub experienced a data breach where approximately 4,000 internal code repositories were stolen by the threat actor TeamPCP. The breach originated from a poisoned VS Code extension compromising an employee's device, an… Dark Reading · May 20, 2026 High vscodeopen sourcedeveloper tooling
threat-intel FTC warns 12 major tech firms of violating Take It Down Act The Federal Trade Commission (FTC) has issued warnings to twelve major tech companies, alleging non-compliance with the newly enacted Take It Down Act (TIDA). This law mandates platforms swiftly remove non-consensual int… The Record · May 20, 2026 High image abuseonline safetyprivacy
threat-intel Patch Now: Critical Flaw in OT Robot OS Gives Attackers Control A critical command injection vulnerability (CVE-2026-8153) was discovered in the operating system of Universal Robots’ PolyScope 5 collaborative robots. This flaw allows unauthenticated attackers to gain remote access an… Dark Reading · May 20, 2026 Critical CVE-2026-8153DEcommand injectionotrobotics