threat-intel Inspector general finds NIST mistakes have made vulnerability database ineffective A recent inspector general report has identified significant mismanagement and strategic failures within the National Institute of Standards and Technology (NIST)’s National Vulnerability Database (NVD), resulting in a m… The Record · Jun 1, 2026 High UNvulnerabilitybacklogmanagement
threat-intel In Other News: Trump Mobile Data Breach, FIFA World Cup Phishing, CISA Responds to Supply Chain Attacks This week’s cybersecurity news highlights a range of incidents, including a data breach affecting Trump Mobile customers, ongoing Russian government intrusion into US Treasury systems, and vulnerabilities in popular soft… SecurityWeek · May 29, 2026 High UNCHdata breachsupply chainphishing
threat-intel Microsoft calls zero-day releases ‘never justifiable’ as researcher threatens to drop more Microsoft is responding to a weeks-long campaign by a pseudonymous researcher, ‘Nightmare Eclipse,’ who released uncoordinated zero-day vulnerabilities in Windows. The researcher, motivated by grievances against Microsof… The Record · May 29, 2026 High zero-dayvulnerabilitydisclosure
threat-intel Less panic patching, more precision This article from Cisco Talos discusses a shift in cybersecurity threat intelligence prioritization, moving away from solely relying on CVSS scores to incorporate exploit prediction and broader data enrichment. The core… Cisco Talos · May 28, 2026 Medium USDEvulnerability_managementepssgcve
vulnerability New Gogs zero-day flaw lets hackers get remote code execution A zero-day vulnerability (CVE-2024-39933) has been identified in Gogs, a self-hosted Git service, allowing authenticated attackers to execute remote code execution (RCE). The flaw, initially discovered by Jonah Burgess,… BleepingComputer · May 28, 2026 High CVE-2024-39933CVE-2024-39932CVE-2026-26194USCNJPzero-dayrcegit
threat-intel ThreatsDay Bulletin: Claude Security Plugin, Azure Priv-Esc, Kali365 MFA Bypass, FIFA Scams +15 More This Hacker News bulletin details several recent cyber threats, including a massive C2 infrastructure footprint discovered in the Middle East dominated by IoT botnets, a privilege escalation vulnerability in Azure Backup… The Hacker News · May 28, 2026 High CVE-2026-8398SAROUSc2supply-chainprivilege-escalation
vulnerability ABB Busch-Welcome 2 Wire Door Opener Actuator A vulnerability has been identified in ABB Busch-Welcome 2 Wire Door Opener Actuators, specifically due to a default compatibility mode that allows for authentication bypass. This could enable an attacker to gain unautho… CISA Advisories · May 28, 2026 High CVE-2025-7705WOdoor lockphysical accessauthentication
threat-intel State Cyber Leaders Beg Congress for More Funding, Support This article reports on a congressional hearing where state cyber leaders urgently requested increased funding and support from the federal government, citing significant cuts to cybersecurity initiatives and a rise in s… Dark Reading · May 26, 2026 High UScybersecurityfundingthreat intelligence
vulnerability CISA orders feds to patch actively exploited Drupal vulnerability The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a directive requiring federal agencies to patch a critical SQL injection vulnerability (CVE-2026-9082) in the Drupal content management system.… BleepingComputer · May 26, 2026 Critical CVE-2026-9082USGBDEsql injectiondrupalcisa
threat-intel CISA to allow researchers to report vulnerabilities to exploited bugs catalog CISA has launched a new nomination form to allow external researchers, vendors, and industry partners to report exploited vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog. This initiative aims to enha… The Record · May 23, 2026 Medium USvulnerability disclosurethreat intelligencecybersecurity
threat-intel Lawmakers Demand Answers as CISA Tries to Contain Data Leak A significant security breach occurred involving the intentional publication of sensitive CISA data, including AWS GovCloud keys and internal system credentials, by a CISA contractor. The exposed data, hosted on a public… Krebs on Security · May 22, 2026 High USgithubcredentialleak
threat-intel In Other News: Industrial Router Exploitation, CISA KEV Nomination Form, Gas Station Hacking This week’s cybersecurity news highlights several incidents, including Iranian hackers targeting US gas station tank monitor systems, a CISA contractor exposing sensitive credentials, a Huawei router vulnerability causin… SecurityWeek · May 22, 2026 High CVE-2024-9643CVE-2026-45401USLUiotcritical infrastructuresupply-chain
data-breach CISA Security Leak A contractor for CISA inadvertently exposed sensitive credentials and internal system details through a public GitHub repository. This included access to highly privileged AWS GovCloud accounts and information about CISA… Schneier on Security · May 22, 2026 Critical USgithubawscredentials
malware The art of being ungovernable This analysis focuses on a Cisco Talos report detailing the emergence of a sophisticated, multi-year-old BadIIS malware variant being utilized by Chinese-speaking cybercrime groups as part of a malware-as-a-service (MaaS… Cisco Talos · May 21, 2026 High CHmalware-as-a-serviceseo fraudtraffic hijacking
vulnerability Microsoft Patches Exploited UnDefend and RedSun Defender Zero-Days Microsoft released patches for two previously exploited zero-day vulnerabilities within its Defender security software. These vulnerabilities, CVE-2026-41091 and CVE-2026-45498, allowed for privilege escalation and denia… SecurityWeek · May 21, 2026 High CVE-2026-41091CVE-2026-45498CVE-2008-4250zero-dayprivilege escalationdenial of service
threat-intel What Will Make AI BOMs Real? This article discusses the growing momentum behind the adoption of AI Bills of Materials (AIBOMs) within the cybersecurity industry. Driven by standards development, commercial tool releases, regulatory pressure, and evo… Dark Reading · May 19, 2026 Medium USEUaisbommodel-training
threat-intel CISA Exposes Secrets, Credentials in 'Private' Repo A public GitHub repository belonging to the Cybersecurity and Infrastructure Security Agency (CISA) was discovered containing 844MB of sensitive data, including plain-text passwords, authentication tokens, and cloud infr… Dark Reading · May 19, 2026 High USsecretsgithubcloud
threat-intel Is 2026 the Year AI Bills of Materials Get Real? This Dark Reading article discusses the emerging importance of AI Bills of Materials (AI BOMs) as a critical component of managing risk associated with artificial intelligence systems. The article highlights the growing… Dark Reading · May 18, 2026 Medium aibomrisk management
threat-intel CISA Admin Leaked AWS GovCloud Keys on Github A contractor for CISA inadvertently exposed highly privileged AWS GovCloud credentials and internal CISA system information via a public GitHub repository. The repository contained plaintext passwords, cloud keys, and lo… Krebs on Security · May 18, 2026 High USgithubawscredentials
threat-intel Fuel Tank Breaches Expand Scope of Iran's Cyber Offensive This article reports on a cyber offensive by Iran targeting fuel tank systems in the United States, exploiting insecure automatic tank gauge (ATG) systems exposed online. The attacks, which involved manipulating displaye… Dark Reading · May 18, 2026 High USIRcyberattackcritical infrastructuregeopolitics