threat-intel AI-Powered App Attacks Are Faster, More Frequent and Harder to Stop This SecurityWeek article highlights a significant shift in app security driven by the rapid adoption of AI by cybercriminals. The report from Digital.ai indicates a dramatic increase in attacks against apps, moving from… SecurityWeek · May 20, 2026 High USGBaiagentic aiapp security
threat-intel Microsoft Takes Down Malware-Signing Service Behind Ransomware Attacks Microsoft disrupted a malware-signing-as-a-service (MSaaS) operation, dubbed OpFauxSign, led by the threat actor Fox Tempest, which was using its Artifact Signing system to distribute malware and ransomware. The operatio… The Hacker News · May 20, 2026 High USFRINmsaascode-signingmalware
threat-intel Identity Alone Isn't Enough: Why Device Security Has to Share the Load This article highlights the limitations of relying solely on identity verification in modern cybersecurity, arguing that it’s no longer sufficient against sophisticated attacks leveraging AI and phishing. The piece empha… BleepingComputer · May 20, 2026 High USzero trustmfadevice posture
threat-intel 1Password Teams With OpenAI to Stop AI Coding Agents From Leaking Credentials 1Password and OpenAI have partnered to create a new system, the Environments MCP Server, designed to protect sensitive credentials used by AI coding agents like OpenAI Codex. This integration addresses the growing risk o… SecurityWeek · May 20, 2026 High aicredentialssecrets
threat-intel Texas, Florida top list of states reporting millions of dollars lost through crypto ATMs A recent FBI report reveals a significant surge in financial losses linked to cryptocurrency ATMs across the United States, totaling $388 million in 2025. Texas and Florida topped the list of states experiencing these lo… The Record · May 20, 2026 High CHNEAUcryptocurrencyscamsfraud
threat-intel Webworm Deploys EchoCreep and GraphWorm Backdoors Using Discord and MS Graph API A China-aligned threat actor known as Webworm has expanded its arsenal with two new backdoors, EchoCreep and GraphWorm, utilizing Discord and the Microsoft Graph API for command-and-control communications. The group, act… The Hacker News · May 20, 2026 High CHRUGEdiscordmicrosoft graphrat
threat-intel Agent AI is Coming. Are You Ready? Orchid Security’s 2026 Identity Gap Snapshot reveals a significant increase in ‘identity dark matter,’ primarily due to enterprises rapidly adopting Agent AI. This trend highlights vulnerabilities stemming from AI agents… The Hacker News · May 20, 2026 Medium USGBaiagent aiidentity management
threat-intel GitHub Breached — Employee Device Hack Led to Exfiltration of 3,800+ Internal Repos GitHub experienced a breach originating from an employee device compromised by a poisoned Microsoft Visual Studio Code extension. The attacker exfiltrated over 3,800 internal repositories, facilitated by the threat actor… The Hacker News · May 20, 2026 High USILIRsupply chaincredential theftinfostealer
threat-intel Caught Off Guard: Securing AI After It Hits Production This article highlights a critical security gap in the deployment of AI applications. It argues that security teams are often left out of the loop when AI use cases move to production, leading to reactive security measur… SecurityWeek · May 20, 2026 Medium aisecurityapplication security
threat-intel Real-World ICS Security Tales From the Trenches This article details real-world incidents involving industrial control systems (ICS) security vulnerabilities, highlighting the challenges of securing OT environments beyond traditional IT security practices. Two separat… SecurityWeek · May 20, 2026 High IRUSicsotlateral movement
threat-intel Webworm: New burrowing techniques This blog post details the evolving tactics of Webworm, a China-aligned APT group, particularly their activity in 2025. Webworm has shifted away from traditional backdoors in favor of more sophisticated techniques, inclu… WeLiveSecurity · May 20, 2026 High CVE-2017-7692BEITSEdiscordmicrosoft graph apic&c
threat-intel Interpol's 'Operation Ramz' Pioneers Cross-Region Collabs in Middle East Interpol’s ‘Operation Ramz’ was a five-month collaborative law enforcement effort involving 13 countries in the Middle East and North Africa (MENA) region to combat cybercrime. The operation resulted in the identificatio… Dark Reading · May 20, 2026 High AEEGIQcybercrimeregionalcollaboration
threat-intel GitHub investigates internal repositories breach claimed by TeamPCP GitHub is investigating a breach of its internal repositories following a claim by the TeamPCP hacker group, who gained access to approximately 4,000 private code repositories. The incident highlights a vulnerability wit… BleepingComputer · May 20, 2026 High supply-chaingithubmalware
threat-intel What It'll Take to Make AI BOMs Usable in a Modern Security Program This Dark Reading article discusses the nascent state of Artificial Intelligence Bills of Materials (AI BOMs) and the challenges security leaders face in utilizing them. While AI BOMs are emerging, most organizations lac… Dark Reading · May 20, 2026 Medium aibomsupply chain
threat-intel ISC Stormcast For Wednesday, May 20th, 2026 https://isc.sans.edu/podcastdetail/9938, (Wed, May 20th) The SANS Internet Storm Center's Stormcast for May 20th, 2026 highlighted several ongoing and emerging cyber threats. The broadcast detailed a concerning increase in phishing campaigns targeting financial institutions an… SANS Internet Storm Center · May 20, 2026 Medium phishingddosmalware
threat-intel What Will Make AI BOMs Real? This article discusses the growing momentum behind the adoption of AI Bills of Materials (AIBOMs) within the cybersecurity industry. Driven by standards development, commercial tool releases, regulatory pressure, and evo… Dark Reading · May 19, 2026 Medium USEUaisbommodel-training
threat-intel Cybercrime service disrupted for abusing Microsoft platform to sign malware Microsoft disrupted a malware-as-a-service (MaaS) operation, dubbed Fox Tempest, that was abusing its Artifact Signing service to generate fraudulent code-signing certificates for ransomware gangs and other cybercriminal… BleepingComputer · May 19, 2026 High USCAmsaascode signingfraudulent certificates
threat-intel Windows Zero-Day Barrage Continues After Patch Tuesday A security researcher known as "Nightmare Eclipse" has disclosed six Windows zero-day vulnerabilities over the past six weeks, some of which are actively being exploited. These vulnerabilities, including YellowKey, Green… Dark Reading · May 19, 2026 High CVE-2020-17103CVE-2026-33825USzero-daybitlockerprivilege escalation
threat-intel CISA Exposes Secrets, Credentials in 'Private' Repo A public GitHub repository belonging to the Cybersecurity and Infrastructure Security Agency (CISA) was discovered containing 844MB of sensitive data, including plain-text passwords, authentication tokens, and cloud infr… Dark Reading · May 19, 2026 High USsecretsgithubcloud
threat-intel Huawei zero-day attack behind last year’s crash of Luxembourg's entire telecoms network A zero-day attack targeting a vulnerability in Huawei’s enterprise router software caused a three-hour nationwide telecoms outage in Luxembourg during July 2025. The attack, which exploited a previously undocumented beha… The Record · May 19, 2026 High CVE-2021-22359CVE-2022-29798LUzero-daydenied-servicenetwork