vulnerability Verizon DBIR 2026: Vulnerability Exploitation Overtakes Credential Theft as Top Breach Vector Verizon’s 2026 Data Breach Investigations Report (DBIR) reveals that vulnerability exploitation has become the leading cause of data breaches, surpassing credential theft. The report highlights a concerning trend of slow… SecurityWeek · May 20, 2026 High USvulnerability managementpatchinggen-ai
threat-intel What Will Make AI BOMs Real? This article discusses the growing momentum behind the adoption of AI Bills of Materials (AIBOMs) within the cybersecurity industry. Driven by standards development, commercial tool releases, regulatory pressure, and evo… Dark Reading · May 19, 2026 Medium USEUaisbommodel-training
threat-intel Cybercrime service disrupted for abusing Microsoft platform to sign malware Microsoft disrupted a malware-as-a-service (MaaS) operation, dubbed Fox Tempest, that was abusing its Artifact Signing service to generate fraudulent code-signing certificates for ransomware gangs and other cybercriminal… BleepingComputer · May 19, 2026 High USCAmsaascode signingfraudulent certificates
threat-intel Windows Zero-Day Barrage Continues After Patch Tuesday A security researcher known as "Nightmare Eclipse" has disclosed six Windows zero-day vulnerabilities over the past six weeks, some of which are actively being exploited. These vulnerabilities, including YellowKey, Green… Dark Reading · May 19, 2026 High CVE-2020-17103CVE-2026-33825USzero-daybitlockerprivilege escalation
threat-intel CISA Exposes Secrets, Credentials in 'Private' Repo A public GitHub repository belonging to the Cybersecurity and Infrastructure Security Agency (CISA) was discovered containing 844MB of sensitive data, including plain-text passwords, authentication tokens, and cloud infr… Dark Reading · May 19, 2026 High USsecretsgithubcloud
malware Stealer Spoofs Google, Microsoft & Apple, Then Backdoors macOS A new macOS infostealer, dubbed SHub Reaper, is targeting users through fake WeChat and Miro installers, mimicking Google, Microsoft, and Apple to lure victims. This malware combines stealer and backdoor capabilities, ut… Dark Reading · May 19, 2026 High USmacosinfostealerbackdoor
malware Trapdoor Android Ad Fraud Scheme Hit 659 Million Daily Bid Requests Using 455 Apps A new Android ad fraud scheme, dubbed Trapdoor, has been identified by HUMAN Threat Intelligence, utilizing 455 malicious apps and 183 C2 domains to generate 659 million daily bid requests. The operation leverages malver… The Hacker News · May 19, 2026 High USandroidad fraudmalvertising
threat-intel The New Phishing Click: How OAuth Consent Bypasses MFA In February 2026, a phishing-as-a-service platform, EvilTokens, compromised over 340 Microsoft 365 organizations across five countries by exploiting OAuth consent screens. Attackers gained access to valid refresh tokens… The Hacker News · May 19, 2026 High USGBoauthconsentphishing
malware From PDB strings to MaaS: Tracking a commodity BadIIS ecosystem used by Chinese-speaking threat This report details the discovery of a commodity BadIIS malware variant, identified by its "demo.pdb" strings, being utilized by multiple Chinese-speaking cybercrime groups operating under a MaaS model. Developed by an a… Cisco Talos · May 19, 2026 Medium CNUSGBseomalware-as-a-serviceiis
threat-intel The quest for greater tech independence The article explores the growing trend of nations, particularly in Europe, seeking greater tech sovereignty – the ability to independently control their digital infrastructure and technology supply chains – driven by con… WeLiveSecurity · May 19, 2026 High EUCHUStech sovereigntydigital independencesupply chain
supply-chain Compromised Nx Console 18.95.0 Targeted VS Code Developers with Credential Stealer A compromised version of the Nx Console VS Code extension (version 18.95.0) was used to steal developer credentials through a supply chain attack. The extension, initially introduced by a developer whose machine was comp… The Hacker News · May 19, 2026 High RUUSsupply chaincredential theftvscode
supply-chain Popular GitHub Action Tags Redirected to Imposter Commit to Steal CI/CD Credentials A GitHub Actions workflow, actions-cool/issues-helper, was compromised through an imposter commit attack, allowing threat actors to steal CI/CD credentials from running workflows. The attack leveraged malicious code inje… The Hacker News · May 19, 2026 High USgithubci/cdsupply-chain
supply-chain Mini Shai-Hulud Pushes Malicious AntV npm Packages via Compromised Maintainer Account A sophisticated supply chain attack, dubbed Mini Shai-Hulud, is targeting npm packages within the @antv ecosystem. The attack leverages a compromised maintainer account to inject malicious code – specifically a credentia… The Hacker News · May 19, 2026 High USsupply chainnpmcredential theft
threat-intel CISA Admin Leaked AWS GovCloud Keys on Github A contractor for CISA inadvertently exposed highly privileged AWS GovCloud credentials and internal CISA system information via a public GitHub repository. The repository contained plaintext passwords, cloud keys, and lo… Krebs on Security · May 18, 2026 High USgithubawscredentials
threat-intel Fuel Tank Breaches Expand Scope of Iran's Cyber Offensive This article reports on a cyber offensive by Iran targeting fuel tank systems in the United States, exploiting insecure automatic tank gauge (ATG) systems exposed online. The attacks, which involved manipulating displaye… Dark Reading · May 18, 2026 High USIRcyberattackcritical infrastructuregeopolitics
threat-intel ⚡ Weekly Recap: Exchange 0-Day, npm Worm, Fake AI Repo, Cisco Exploit and More This week’s security news highlights several active exploits and attacks, including a widespread vulnerability in on-prem Exchange Servers, a Cisco SD-WAN controller compromise attributed to UAT-8616, and a significant s… The Hacker News · May 18, 2026 High CVE-2026-42897CVE-2026-20182CVE-2026-20127USexchangesupply chainnpm
phishing How to Reduce Phishing Exposure Before It Turns into Business Disruption This article discusses the increasing risk posed by phishing attacks, particularly due to their ability to quickly escalate into significant business disruptions. It highlights the challenges SOC teams face in identifyin… The Hacker News · May 18, 2026 High USphishingsandboxcredential theft
threat-intel IT threat evolution in Q1 2026. Mobile statistics This Securelist report analyzes mobile threat trends in Q1 2026, based on Kaspersky Security Network data. The report highlights a decrease in overall attack volume, primarily due to reduced adware and RiskTool detection… Securelist · May 18, 2026 Medium USmobile malwarebanking trojancrypto stealer
data-breach Boulevard of Broken Dreams: 2 Decades of Cyber Fails This Dark Reading article reflects on two decades of cybersecurity failures, highlighting recurring trends like data breaches, systemic vulnerabilities, and a growing sense of apathy among individuals regarding data secu… Dark Reading · May 18, 2026 High CVE-2023-34362USdata breachsql injectioncybersecurity
threat-intel Developer Workstations Are Now Part of the Software Supply Chain Recent attacks, including those mimicking the "mini Shai Hulud" and "Shai-Hulud 2.0" campaigns, have highlighted a growing threat: attackers targeting developer workstations to steal credentials and secrets from CI/CD pi… The Hacker News · May 18, 2026 High USdeveloper workstationssecretssupply chain