vulnerability New Gogs zero-day flaw lets hackers get remote code execution A zero-day vulnerability (CVE-2024-39933) has been identified in Gogs, a self-hosted Git service, allowing authenticated attackers to execute remote code execution (RCE). The flaw, initially discovered by Jonah Burgess,… BleepingComputer · May 28, 2026 High CVE-2024-39933CVE-2024-39932CVE-2026-26194USCNJPzero-dayrcegit
threat-intel Russia conducting daily attacks on UK 'from seabed to cyberspace,' spy chief warns GCHQ Director Anne Keast-Butler warned of daily, sophisticated cyberattacks originating from Russia targeting the UK and Europe, spanning undersea cables to cyberspace. These attacks are focused on critical infrastructur… The Record · May 28, 2026 High UKRUCHcyberattackhybrid warfareintelligence
threat-intel 2026 World Cup: Discussing The World’s Biggest Game’s Attack Surface This analysis from Palo Alto Unit 42 assesses the significant cyber threat landscape surrounding the 2026 FIFA World Cup, highlighting the expanded attack surface created by the event's scale and complexity. The report i… Palo Alto Unit 42 · May 28, 2026 High USIRRUmega-eventcybersecuritythreat intelligence
threat-intel UK Cyberspying Chief Calls AI ‘an Unstoppable Force’ and Warns About Russia British intelligence chief Anne Keast-Butler warned of the escalating threat posed by Russia’s cyber activities, particularly the weaponization of artificial intelligence, and emphasized the urgent need for increased cyb… SecurityWeek · May 27, 2026 High UKRUCHartificial intelligencecybersecurityrussia
vulnerability CISA orders feds to patch actively exploited Drupal vulnerability The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a directive requiring federal agencies to patch a critical SQL injection vulnerability (CVE-2026-9082) in the Drupal content management system.… BleepingComputer · May 26, 2026 Critical CVE-2026-9082USGBDEsql injectiondrupalcisa
threat-intel Anthropic: Mythos Detected 23,000 Potential Vulnerabilities Across 1,000 OSS Projects Anthropic’s Claude Mythos AI model has identified a massive number of vulnerabilities – estimated between 6,200 and 23,000 – across over 1,000 open-source software projects. Many of these vulnerabilities, particularly t… SecurityWeek · May 25, 2026 Critical UKaivulnerabilityopen source
threat-intel First VPN Dismantled in Global Takedown Over Use by 25 Ransomware Groups A global operation, dubbed Operation Saffron, led by France and the Netherlands, successfully dismantled the First VPN service, a virtual private network specifically designed for criminal use. The service was utilized b… The Hacker News · May 22, 2026 High USFRNLvpnransomwareanonymity
phishing Ghostwriter Targets Ukraine Government Entities with Prometheus Phishing Malware The Ghostwriter threat actor, linked to Belarus, has been conducting a phishing campaign targeting Ukrainian government entities since the spring of 2026. This campaign utilizes lures related to the Prometheus online lea… The Hacker News · May 22, 2026 High UKBERUphishingmalwarecobalt strike
threat-intel Tech giants promise British regulator they will tweak platforms to protect kids online Following pressure from the UK’s Ofcom regulator, several major tech companies – including Roblox, Snapchat, Instagram (Meta), and TikTok – have pledged to implement changes to their platforms to better protect children… The Record · May 21, 2026 High UKgroomingchild_safetyalgorithms
threat-intel UK plans for cybercrime law reform would protect almost no one, experts warn The UK government’s proposed reforms to the Computer Misuse Act 1990 are facing criticism from cybersecurity experts who believe they will offer minimal protection to researchers. The proposed changes would restrict the… The Record · May 21, 2026 Medium UKcybersecurityresearchlegal
malware Showboat Linux Malware Hits Middle East Telecom with SOCKS5 Proxy Backdoor A new Linux malware, dubbed Showboat, has been used in a campaign targeting a telecommunications provider in the Middle East since at least 2022. The malware, developed by a China-linked threat actor group known as Calyp… The Hacker News · May 21, 2026 High CVE-2021-26855AFAZCHlinuxsocks5c2
threat-intel Chinese APTs Share Linux Backdoor in Central Asia Telco Attacks This article details the discovery of "Showboat" (kworker), a Linux post-exploitation framework being shared among Chinese Advanced Persistent Threat (APT) groups, primarily Calypso and Red Lamassu. The malware has been… Dark Reading · May 21, 2026 Medium CHAFUKaptlinuxspyware
threat-intel Police seize “First VPN” service used in ransomware, data theft attacks Law enforcement agencies, in a coordinated international effort led by France and the Netherlands, have taken down the ‘First VPN’ service, a virtual private network used extensively by ransomware and data theft groups.… BleepingComputer · May 21, 2026 High UKFRNEvpncybercrimeransomware
threat-intel ThreatsDay Bulletin: Linux Rootkits, Router 0-Day, AI Intrusions, Scam Kits and 25 New Stories This week's threat intelligence report highlights a diverse range of security incidents and vulnerabilities, including a significant Pwn2Own competition with substantial rewards, warnings about the risks of deploying age… The Hacker News · May 21, 2026 High CVE-2026-45793CVE-2026-8631UKUSCHzero-dayai securitysocial engineering
data-breach Ukraine probes teen suspect in cyber theft scheme targeting California online shoppers Ukrainian authorities are investigating an 18-year-old suspect linked to a cybercrime operation targeting California online shoppers. The scheme involved compromising nearly 30,000 customer accounts of a U.S.-based retai… The Record · May 20, 2026 High UKcybercrimedata-theftonline-shopping
threat-intel Ivanti, Fortinet, SAP, VMware, n8n Patch RCE, SQL Injection, Privilege Escalation Flaws Multiple vendors, including Ivanti, Fortinet, SAP, and VMware, have released security patches to address critical vulnerabilities across their products. These vulnerabilities include remote code execution, SQL injection,… The Hacker News · May 18, 2026 Critical CVE-2026-8043CVE-2026-44277CVE-2026-26083USUKremote code executionsql injectionprivilege escalation
threat-intel How Dangerous Is Anthropic’s Mythos AI? Anthropic’s Claude Mythos AI model demonstrates a significant capability in identifying software vulnerabilities, prompting concerns about its potential misuse by attackers. While the company initially restricted access… Schneier on Security · May 14, 2026 High UKaivulnerabilitycybersecurity
threat-intel State-sponsored actors, better known as the friends you don’t want This Cisco Talos report highlights the significant differences in responding to state-sponsored cyber threats compared to conventional attacks like ransomware. It emphasizes that these actors operate within an organizati… Cisco Talos · May 12, 2026 High USUKstate-sponsoredzero trustosint
threat-intel LLMs and Text-in-Text Steganography This article discusses attempts to hide text within LLMs using techniques like phonological changes and unconventional formatting (e.g., white text on white backgrounds). The author explores the limitations of these meth… Schneier on Security · May 11, 2026 Low UKsteganographyllmstempeset
threat-intel Eyes wide open: How to mitigate the security and privacy risks of smart glasses This article discusses the growing security and privacy risks associated with smart glasses, particularly due to their advanced tracking and recording capabilities combined with AI integration. The proliferation of these… WeLiveSecurity · May 11, 2026 High GEUKsurveillanceprivacyai