vulnerability Fourth Frontier Frontier X Mobile Application, Frontier X2 A vulnerability has been identified in the Fourth Frontier Frontier X Mobile Application and Frontier X2 devices, allowing unauthorized access and control. Attackers could potentially read and modify patient data, trigge… CISA Advisories · May 28, 2026 High CVE-2026-5768USbleauthenticationdevice control
threat-intel Out of the Crypt: The Evolving Cyber Extortion Economy This report from Palo Alto Unit 42 highlights a significant shift in the cyber extortion landscape, moving away from ransomware-based pressure towards pure data theft and extortion. The trend is driven by factors like ad… Palo Alto Unit 42 · May 27, 2026 High USdata theftextortionsupply chain
threat-intel Ransomware Actors Show Up In Person to Steal Law Firm Data The Silent Ransom Group (SRG), also known as Luna Moth and UNC3753, is targeting law firms through sophisticated social engineering tactics, including impersonating IT personnel and conducting in-person visits to gain ac… Dark Reading · May 27, 2026 High RUsocial engineeringdata theftlaw firms
vulnerability Gitea Vulnerability Exposes Private Container Images without Authentication A significant vulnerability (CVE-2026-27771) has been identified in Gitea, a popular open-source Git repository hosting platform. The flaw allows unauthorized access to private container images, exposing sensitive data w… The Hacker News · May 27, 2026 High CVE-2026-27771CNUSDEcontainergitvulnerability
threat-intel What to consider before asking an AI chatbot for health advice This article warns against relying on AI chatbots for health advice, highlighting significant risks related to inaccurate information, data privacy, and potential misuse of sensitive medical data. The piece emphasizes th… WeLiveSecurity · May 27, 2026 Medium aihealthcareprivacy
vulnerability Eppendorf BioFlo 320 This CISA advisory details a critical vulnerability in Eppendorf BioFlo 320 bioreactors due to a hard-coded VNC password, allowing unauthorized remote access and control. The vulnerability affects all versions of the Bio… CISA Advisories · May 26, 2026 Critical CVE-2026-7251WOvncpasswordremote access
threat-intel Verizon DBIR: Healthcare Fends Off Increased Social Engineering Attacks The Verizon 2026 Data Breach Investigations Report (DBIR) reveals a significant increase in social engineering attacks targeting the healthcare sector, driven by the adoption of generative AI. While ransomware and vendor… Dark Reading · May 22, 2026 High social engineeringaigenai
supply-chain Hackers steal patient and billing data from German hospitals via third-party provider German hospitals are facing a significant patient data breach following an attack targeting Unimed, a third-party billing service provider. The attackers accessed sensitive patient information, including names, addresses… The Record · May 21, 2026 High DEdata-breachpatient-datathird-party
malware The art of being ungovernable This analysis focuses on a Cisco Talos report detailing the emergence of a sophisticated, multi-year-old BadIIS malware variant being utilized by Chinese-speaking cybercrime groups as part of a malware-as-a-service (MaaS… Cisco Talos · May 21, 2026 High CHmalware-as-a-serviceseo fraudtraffic hijacking
data-breach Processes and Culture Top Reasons Behind Data Breaches This article examines the reasons behind persistent data breaches, particularly focusing on the issue of underreporting within organizations. The analysis, stemming from a Massachusetts state study, highlights weaknesses… Dark Reading · May 20, 2026 High USdata breachcyber hygienepassword security
threat-intel Patch Now: Critical Flaw in OT Robot OS Gives Attackers Control A critical command injection vulnerability (CVE-2026-8153) was discovered in the operating system of Universal Robots’ PolyScope 5 collaborative robots. This flaw allows unauthenticated attackers to gain remote access an… Dark Reading · May 20, 2026 Critical CVE-2026-8153DEcommand injectionotrobotics
threat-intel Microsoft Takes Down Malware-Signing Service Behind Ransomware Attacks Microsoft disrupted a malware-signing-as-a-service (MSaaS) operation, dubbed OpFauxSign, led by the threat actor Fox Tempest, which was using its Artifact Signing system to distribute malware and ransomware. The operatio… The Hacker News · May 20, 2026 High USFRINmsaascode-signingmalware
phishing How to Reduce Phishing Exposure Before It Turns into Business Disruption This article discusses the increasing risk posed by phishing attacks, particularly due to their ability to quickly escalate into significant business disruptions. It highlights the challenges SOC teams face in identifyin… The Hacker News · May 18, 2026 High USphishingsandboxcredential theft
data-breach Boulevard of Broken Dreams: 2 Decades of Cyber Fails This Dark Reading article reflects on two decades of cybersecurity failures, highlighting recurring trends like data breaches, systemic vulnerabilities, and a growing sense of apathy among individuals regarding data secu… Dark Reading · May 18, 2026 High CVE-2023-34362USdata breachsql injectioncybersecurity
threat-intel FrostyNeighbor: Fresh mischief and digital shenanigans FrostyNeighbor, a long-running cyberespionage group allegedly linked to Belarus, is continuing its operations targeting governmental organizations in Ukraine and other Eastern European countries. The latest activity invo… WeLiveSecurity · May 14, 2026 High BYPLLTcyberespionagecobalt strikepicassoloader
apt Alleged Silk Typhoon hacker extradited to the United States to face charges A Chinese national, Xu Zewei, has been extradited to the United States to face charges related to his alleged involvement with the Hafnium hacking group, also known as Silk Typhoon. He is accused of attempting to steal c… Graham Cluley · Apr 29, 2026 Critical CHUSstate-sponsoredcyber espionageexchange server
threat-intel The calm before the ransom: What you see is not all there is This article highlights a common cybersecurity pitfall: organizations can become overly confident in their security posture due to a period of stability, leading to complacency and a failure to adequately assess current… WeLiveSecurity · Apr 24, 2026 High UScomplacencyrisk assessmentcybersecurity
ransomware What the ransom note won’t say This article details the ongoing issues surrounding the BlackCat ransomware gang’s affiliate, who attempted to defraud the group after carrying out a significant attack on Change Healthcare. The incident highlights the i… WeLiveSecurity · Apr 20, 2026 High USransomwarefranchisesupply chain
supply-chain Supply chain dependencies: Have you checked your blind spot? This article highlights the growing risk of cyberattacks originating through supply chain vulnerabilities, particularly among small and medium-sized businesses (SMBs). It emphasizes that complex, digitized supply chains… WeLiveSecurity · Apr 16, 2026 High CVE-2019-15126CAUNsupply chaincybersecurityrisk management
threat-intel A cunning predator: How Silver Fox preys on Japanese firms this tax season A targeted spearphishing campaign, dubbed ‘Silver Fox’, is actively exploiting the Japanese tax filing season to compromise businesses. The campaign utilizes convincing lures related to tax compliance, salary adjustments… WeLiveSecurity · Mar 27, 2026 High JPspearphishingjapantax season