threat-intel Ivanti, Fortinet, SAP, VMware, n8n Patch RCE, SQL Injection, Privilege Escalation Flaws Multiple vendors, including Ivanti, Fortinet, SAP, and VMware, have released security patches to address critical vulnerabilities across their products. These vulnerabilities include remote code execution, SQL injection,… The Hacker News · May 18, 2026 Critical CVE-2026-8043CVE-2026-44277CVE-2026-26083USUKremote code executionsql injectionprivilege escalation
ransomware Congress Puts Heat on Instructure After Canvas Outage Following a high-profile cyberattack on its Canvas learning management system by the ShinyHunters group, Instructure is facing increased scrutiny from Congress. The House Committee on Homeland Security has requested a br… Dark Reading · May 15, 2026 High USedtechransomwaredata breach
malware Gremlin Stealer's Evolved Tactics: Hiding in Plain Sight With Resource Files This report details the evolving tactics of the Gremlin stealer malware, specifically a recent variant employing sophisticated obfuscation techniques to evade detection. The malware, which targets sensitive data like pay… Palo Alto Unit 42 · May 15, 2026 High USobfuscationanti-analysisresource section
threat-intel [Guest Diary] New Malware Libraries means New Signatures, (Fri, May 15th) This SANS Internet Storm Center diary details a new observation of the long-running mdrfckr campaign, a Shellbot associated with the Outlaw/Dota group. The key finding is the identification of a previously undocumented v… SANS Internet Storm Center · May 15, 2026 Medium USCNshellbotlibsshmdrfckr
threat-intel Suspected Dream Market kingpin arrested after gold bars sent to his home address Owe Martin Andresen, suspected to be the administrator of the notorious Dream Market dark web drug marketplace, has been arrested on money laundering charges in the US and Germany. Authorities allege he moved millions of… Graham Cluley · May 14, 2026 High USDEdark webdrug traffickingmoney laundering
threat-intel The time of much patching is coming This article from Cisco Talos anticipates a significant increase in software patching due to advancements in AI-powered vulnerability detection and the uncovering of long-standing technical debt. The surge in discovered… Cisco Talos · May 14, 2026 High USvulnerabilitypatchingai
threat-intel Patch Tuesday, May 2026 Edition This article reports on Patch Tuesday, May 2026, highlighting a significant increase in security vulnerabilities addressed by major software vendors like Microsoft, Apple, Google, Mozilla, and Oracle. The updates, spurre… Krebs on Security · May 12, 2026 Critical CVE-2026-41089CVE-2026-41096CVE-2026-41103USpatch tuesdayaivulnerability
threat-intel State-sponsored actors, better known as the friends you don’t want This Cisco Talos report highlights the significant differences in responding to state-sponsored cyber threats compared to conventional attacks like ransomware. It emphasizes that these actors operate within an organizati… Cisco Talos · May 12, 2026 High USUKstate-sponsoredzero trustosint
ransomware State of ransomware in 2026 Kaspersky’s 2026 ransomware threat report highlights a shift in the landscape, with ransomware attacks declining overall but becoming more sophisticated. Key trends include the emergence of post-quantum cryptography rans… Securelist · May 12, 2026 High USransomwarequantum cryptographyedr
threat-intel Inside Department 4: Russia’s secret school for hackers A new investigation has revealed a secret faculty within Bauman Moscow State Technical University, known as ‘Department 4,’ which has been training students to become hackers for Russian military intelligence, the GRU. T… Graham Cluley · May 8, 2026 High RUUSrussian hackingspywaregru
threat-intel Canvas Breach Disrupts Schools & Colleges Nationwide A cybercrime group, ShinyHunters, disrupted the Canvas education technology platform, impacting schools and colleges nationwide. The group defaced the login page with a ransom demand, threatening to leak data from 275 mi… Krebs on Security · May 8, 2026 High USeducationdata breachransomware
threat-intel Exploits and vulnerabilities in Q1 2026 This Securelist report analyzes vulnerability trends and exploitation activity during Q1 2026, focusing on the expansion of exploit kits targeting Microsoft Office, Windows, and Linux operating systems. The report highli… Securelist · May 7, 2026 High CVE-2018-0802CVE-2017-11882CVE-2017-0199USvulnerabilityexploitationrce
threat-intel From Stuxnet to ChatGPT: 20 News Events That Shaped Cyber This Dark Reading article reflects on key cybersecurity events from the past two decades, highlighting the evolution of cyber threats and their impact on businesses and critical infrastructure. The piece emphasizes how a… Dark Reading · May 6, 2026 High CVE-2017-0144CVE-2021-44228IRUSISindustrial control systemsnation-state actorsair gap
threat-intel Insights into the clustering and reuse of phone numbers in scam emails This article details Cisco Talos’s intelligence gathering on the increasing use of phone numbers in scam email campaigns. Attackers are leveraging API-driven VoIP providers like Sinch and Twilio to operate high-volume, d… Cisco Talos · May 6, 2026 High USUKvoipscamphishing
vulnerability Copy Fail: What You Need to Know About the Most Severe Linux Threat in Years A critical Linux kernel vulnerability, dubbed 'Copy Fail' (CVE-2026-31431), has been discovered allowing unprivileged local attackers to escalate their access to root across numerous Linux distributions since 2017. The f… Palo Alto Unit 42 · May 5, 2026 Critical CVE-2026-31431CVE-2026-314331USlinuxkernellpe
threat-intel CloudZ RAT potentially steals OTP messages using Pheno plugin Cisco Talos identified an intrusion campaign initiated in January 2026 involving the deployment of the CloudZ remote access tool (RAT) alongside a new plugin called ‘Pheno.’ This campaign leveraged the Microsoft Phone Li… Cisco Talos · May 5, 2026 High USotpphone linkcredential theft
threat-intel Teenager alleged to be Scattered Spider hacker arrested in Finland, faces US extradition A 19-year-old teenager, identified as "Bouquet," has been arrested in Finland and faces US extradition charges for allegedly being a member of the Scattered Spider cybercrime group. The investigation revealed the group’s… Graham Cluley · May 4, 2026 High USGBFIsocial engineeringphishingmfa
phishing “Legitimate” phishing: how attackers weaponize Amazon SES to bypass email security This Securelist article details a concerning trend of attackers leveraging Amazon Simple Email Service (Amazon SES) for phishing campaigns. Attackers exploit legitimate access keys to send convincing emails that bypass s… Securelist · May 4, 2026 High USphishingawsamazon ses
threat-intel 20 Years in Cyber: Dark Reading Marks Milestone With Month of Special Coverage This Dark Reading article celebrates the platform’s 20th anniversary, reflecting on its role in covering the evolution of cybersecurity over the past two decades. The piece highlights key moments and figures from the ind… Dark Reading · May 1, 2026 Medium UScybersecurityhistoryindustry
threat-intel That AI Extension Helping You Write Emails? It’s Reading Them First Palo Alto Unit 42 has identified 18 AI-powered browser extensions posing significant security risks. These extensions, masquerading as productivity tools, are actually delivering malicious payloads such as remote access… Palo Alto Unit 42 · Apr 30, 2026 High USaibrowser extensionsgenai