supply-chain ‘SymJack’ Attack Turns AI Coding Agents Into Supply Chain Attack Delivery Systems The ‘SymJack’ attack leverages AI coding agents as a supply chain delivery mechanism, exploiting developer trust in automation to inject malicious code into CI pipelines. Attackers gain control by compromising coding age… SecurityWeek · May 27, 2026 High USaicoding agentssupply chain
vulnerability Gitea Vulnerability Exposes Private Container Images without Authentication A significant vulnerability (CVE-2026-27771) has been identified in Gitea, a popular open-source Git repository hosting platform. The flaw allows unauthorized access to private container images, exposing sensitive data w… The Hacker News · May 27, 2026 High CVE-2026-27771CNUSDEcontainergitvulnerability
malware AI Chatbot Recommendations Redirect Users to Cryptojacking Malware Sites Microsoft has identified a cryptojacking campaign utilizing AI chatbots to recommend malicious download sites, a novel approach to social engineering. The campaign impersonates legitimate system utilities like CrystalDis… The Hacker News · May 27, 2026 High CVE-2025-33073USaicryptojackingsocial engineering
vulnerability CISA Urges Immediate Patching of Exploited LiteSpeed cPanel Plugin Zero-Day The Cybersecurity and Infrastructure Security Agency (CISA) has issued a critical alert urging immediate patching of a zero-day vulnerability (CVE-2026-48172) in the LiteSpeed cPanel plugin. This flaw allows for privileg… SecurityWeek · May 27, 2026 Critical CVE-2026-48172UScpanelzero-dayprivilege escalation
threat-intel State Cyber Leaders Beg Congress for More Funding, Support This article reports on a congressional hearing where state cyber leaders urgently requested increased funding and support from the federal government, citing significant cuts to cybersecurity initiatives and a rise in s… Dark Reading · May 26, 2026 High UScybersecurityfundingthreat intelligence
threat-intel The Hackers Behind Shai-Hulud: Lucky or Skilled? The cybercrime group TeamPCP has been identified as a primary driver behind the Shai-Hulud worm, causing significant damage to the open-source ecosystem through exploiting vulnerabilities like React2Shell and misconfigur… Dark Reading · May 26, 2026 High USsupply-chainopen-sourcedeveloper-tooling
threat-intel For Enterprises, Security Remains Agentic AI's Biggest Challenge This article discusses the rapid adoption of OpenClaw, an agentic AI assistant, and the significant security challenges it presents to enterprises. Despite its popularity and endorsement from Nvidia, the software has bee… Dark Reading · May 26, 2026 High USagentic aiai securityopen source
phishing FBI warns of Kali365 phishing kit that breaks into Microsoft 365 accounts – no password required The FBI has issued a warning about Kali365, a phishing-as-a-service kit that allows attackers to compromise Microsoft 365 accounts without needing passwords, even when MFA is enabled. This kit leverages device code flow,… Graham Cluley · May 26, 2026 High USCAGBmfadevice-code-flowphishing
threat-intel MuddyWater Uses DLL Side-Loading in Espionage Campaign Targeting 9 Countries The MuddyWater hacking group, backed by Iran, has been conducting a sophisticated espionage campaign targeting organizations across nine countries on four continents during Q1 2026. The campaign utilizes DLL side-loading… The Hacker News · May 26, 2026 High KRSAAEdll-side-loadingcredential-stealingreconnaissance
threat-intel Iranian APT Targets Aviation, Software Companies With Updated Tools The Iranian APT group, known as Nimbus Manticore, has been aggressively updating its tactics and tools to target aviation and software companies globally. The group, linked to Charming Kitten and the IRGC, is employing… SecurityWeek · May 26, 2026 High AEIRSAaptphishingappdomain
threat-intel MFA Prompt Bombing: Why Your Second Factor Isn't Saving You This article details a new attack technique called ‘MFA prompt bombing,’ where attackers repeatedly trigger multi-factor authentication prompts to trick users into approving access. The attack leverages push-based MFA sy… The Hacker News · May 26, 2026 High USmfapush-mfaprompt bombing
vulnerability CISA orders feds to patch actively exploited Drupal vulnerability The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a directive requiring federal agencies to patch a critical SQL injection vulnerability (CVE-2026-9082) in the Drupal content management system.… BleepingComputer · May 26, 2026 Critical CVE-2026-9082USGBDEsql injectiondrupalcisa
malware Possible ACR Stealer From Page Impersonating Claude, (Tue, May 26th) This report details the discovery of a fake Claude webpage distributing the ACR Stealer malware, targeting macOS and Windows users. The initial infection vector involves malicious ads leading to the deceptive site, which… SANS Internet Storm Center · May 26, 2026 High USstealermacoswindows
threat-intel ⚡ Weekly Recap: Linux Flaws, Defender 0-Days, Router Botnets, and Supply Chain Chaos This week’s security news highlights a significant GitHub breach orchestrated by TeamPCP, stemming from a compromised developer’s device and leveraging vulnerabilities exposed by the TanStack supply chain attack. Simulta… The Hacker News · May 25, 2026 High CVE-2026-46333CVE-2026-41091CVE-2026-45498USGBsupply-chainlinuxgithub
vulnerability Ghost CMS Vulnerability Exploited to Hack Over 700 Websites A previously disclosed SQL injection vulnerability (CVE-2026-26980) in the Ghost CMS has been actively exploited by multiple threat actors, leading to the compromise of over 700 websites. The attackers leveraged this vul… SecurityWeek · May 25, 2026 High CVE-2026-26980USGBsql injectionghost cmsvulnerability
phishing FBI warns of Kali365 phishing service targeting Microsoft 365 accounts The FBI has issued a warning about Kali365, a phishing-as-a-service (PhaaS) platform, being used to target Microsoft 365 accounts. This platform leverages device code authentication to bypass multi-factor authentication… BleepingComputer · May 25, 2026 High USphishingoauthmfa
supply-chain TrapDoor Supply Chain Attack Spreads Credential-Stealing Malware via npm, PyPI, and CratesIO A sophisticated supply chain attack, dubbed TrapDoor, is spreading credential-stealing malware across npm, PyPI, and Crates.io, targeting developers in the crypto, DeFi, Solana, and AI communities. The attack utilizes a… The Hacker News · May 25, 2026 High USsupply-chaincredential-stealingdeveloper-workflow
malware Laravel Lang packages hijacked to deploy credential-stealing malware A supply chain attack targeting Laravel Lang localization packages has resulted in attackers injecting credential-stealing malware through manipulated GitHub tags. The malicious code, disguised as legitimate releases, do… BleepingComputer · May 23, 2026 High USsupply chaincredential theftgithub
supply-chain Laravel-Lang PHP Packages Compromised to Deliver Cross-Platform Credential Stealer A sophisticated supply chain attack targeting Laravel-Lang PHP packages has been identified, involving the mass modification of Git tags to inject a cross-platform credential-stealing framework. The attacker leveraged co… The Hacker News · May 23, 2026 Critical USsupply-chaincredential-stealingphp
threat-intel CISA to allow researchers to report vulnerabilities to exploited bugs catalog CISA has launched a new nomination form to allow external researchers, vendors, and industry partners to report exploited vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog. This initiative aims to enha… The Record · May 23, 2026 Medium USvulnerability disclosurethreat intelligencecybersecurity