threat-intel 3 SOC Steps that Shut Down Incident Risks Early This article from The Hacker News discusses three key steps for modern Security Operations Centers (SOCs) to proactively reduce incident risks. It emphasizes the shift from perimeter defense to minimizing operational deb… The Hacker News · May 27, 2026 High threat intelligencesocincident response
supply-chain ‘SymJack’ Attack Turns AI Coding Agents Into Supply Chain Attack Delivery Systems The ‘SymJack’ attack leverages AI coding agents as a supply chain delivery mechanism, exploiting developer trust in automation to inject malicious code into CI pipelines. Attackers gain control by compromising coding age… SecurityWeek · May 27, 2026 High USaicoding agentssupply chain
threat-intel GlassWorm Botnet Disrupted The GlassWorm botnet, a persistent threat targeting open-source software developers, has been disrupted by a coordinated effort between CrowdStrike, Google, and the Shadowserver Foundation. The botnet utilized a multi-la… SecurityWeek · May 27, 2026 High RUbotnetopen sourcedeveloper
vulnerability Gitea Vulnerability Exposes Private Container Images without Authentication A significant vulnerability (CVE-2026-27771) has been identified in Gitea, a popular open-source Git repository hosting platform. The flaw allows unauthorized access to private container images, exposing sensitive data w… The Hacker News · May 27, 2026 High CVE-2026-27771CNUSDEcontainergitvulnerability
threat-intel FBI: Hackers Sending Operatives in Person to Insert USB Drives and Steal Data The FBI has issued an alert regarding a new tactic employed by the Silent Ransom Group (SRG) involving physical intrusion to steal data from law firms and other organizations. SRG is impersonating IT support personnel,… SecurityWeek · May 27, 2026 High social engineeringremote accessusb drive
malware AI Chatbot Recommendations Redirect Users to Cryptojacking Malware Sites Microsoft has identified a cryptojacking campaign utilizing AI chatbots to recommend malicious download sites, a novel approach to social engineering. The campaign impersonates legitimate system utilities like CrystalDis… The Hacker News · May 27, 2026 High CVE-2025-33073USaicryptojackingsocial engineering
supply-chain Feeding Frenzy: 'Megalodon' Malware Infects Thousands of GitHub Repos A six-hour malware campaign, dubbed 'Megalodon,' targeted over 5,500 GitHub repositories, injecting malicious commits containing credential-stealing payloads. The campaign, orchestrated by an unknown threat actor potenti… Dark Reading · May 26, 2026 High githubsupply-chainmalware
data-breach Charter confirms data breach after ShinyHunters extortion threat Charter Communications has confirmed a data breach following a threat from the ShinyHunters extortion group, resulting in the claimed theft of 40 million customer records. The breach originated from a voice phishing atta… BleepingComputer · May 26, 2026 High voice phishingdata breachsalesforce
threat-intel State Cyber Leaders Beg Congress for More Funding, Support This article reports on a congressional hearing where state cyber leaders urgently requested increased funding and support from the federal government, citing significant cuts to cybersecurity initiatives and a rise in s… Dark Reading · May 26, 2026 High UScybersecurityfundingthreat intelligence
threat-intel The Hackers Behind Shai-Hulud: Lucky or Skilled? The cybercrime group TeamPCP has been identified as a primary driver behind the Shai-Hulud worm, causing significant damage to the open-source ecosystem through exploiting vulnerabilities like React2Shell and misconfigur… Dark Reading · May 26, 2026 High USsupply-chainopen-sourcedeveloper-tooling
threat-intel For Enterprises, Security Remains Agentic AI's Biggest Challenge This article discusses the rapid adoption of OpenClaw, an agentic AI assistant, and the significant security challenges it presents to enterprises. Despite its popularity and endorsement from Nvidia, the software has bee… Dark Reading · May 26, 2026 High USagentic aiai securityopen source
phishing FBI warns of Kali365 phishing kit that breaks into Microsoft 365 accounts – no password required The FBI has issued a warning about Kali365, a phishing-as-a-service kit that allows attackers to compromise Microsoft 365 accounts without needing passwords, even when MFA is enabled. This kit leverages device code flow,… Graham Cluley · May 26, 2026 High USCAGBmfadevice-code-flowphishing
threat-intel MuddyWater Uses DLL Side-Loading in Espionage Campaign Targeting 9 Countries The MuddyWater hacking group, backed by Iran, has been conducting a sophisticated espionage campaign targeting organizations across nine countries on four continents during Q1 2026. The campaign utilizes DLL side-loading… The Hacker News · May 26, 2026 High KRSAAEdll-side-loadingcredential-stealingreconnaissance
data-breach Lithuania investigates theft of 600,000 state registry records by foreign actor Lithuania is investigating a significant data breach affecting its state registry systems, resulting in the theft of approximately 600,000 records containing personal and property information. The breach exploited compro… The Record · May 26, 2026 High LTRUBYdata breachregistrycyberattack
threat-intel Iranian APT Targets Aviation, Software Companies With Updated Tools The Iranian APT group, known as Nimbus Manticore, has been aggressively updating its tactics and tools to target aviation and software companies globally. The group, linked to Charming Kitten and the IRGC, is employing… SecurityWeek · May 26, 2026 High AEIRSAaptphishingappdomain
vulnerability ABB LVS MConfig ABB has identified and announced a vulnerability in its MConfig product versions (<=1.4.9.21) that allows attackers with local network access to potentially extract sensitive information, including passwords, from memory… CISA Advisories · May 26, 2026 High CVE-2025-9970WOmemory_dumppassword_leaklocal_access
vulnerability ABB B&R Automation Runtime DoS Vulnerability in System Diagnostics Manager (SDM) This advisory details a denial-of-service (DoS) vulnerability in ABB B&R Automation Runtime versions prior to 6.3 and Q4.93, specifically within the System Diagnostics Manager (SDM) component. An unauthenticated network… CISA Advisories · May 26, 2026 High CVE-2025-3450WOdosdenial of serviceresource locking
vulnerability ABB AbilityTM Zenon Remote Transport Vulnerability This advisory from CISA details a vulnerability in ABB AbilityTM Zenon Remote Transport, specifically versions 7.50 through 14. The flaw allows unauthorized access and remote system reboots without authentication, posing… CISA Advisories · May 26, 2026 High CVE-2025-8754WOauthenticationremote rebootcwe-306
data-breach 185,000 Likely Impacted by 7-Eleven Data Breach The allegedly stolen information leaked by ShinyHunters contains email addresses, names, addresses, and dates of birth. The post 185,000 Likely Impacted by 7-Eleven Data Breach appeared first on SecurityWeek . SecurityWeek · May 26, 2026 High
ddos New AI DDoS Attacks Are Smarter. Learn How to Fight Back in This Webinar This article reports a rise in sophisticated Distributed Denial of Service (DDoS) attacks leveraging Artificial Intelligence (AI) to enhance their speed and effectiveness. Hackers are utilizing AI to identify vulnerabili… The Hacker News · May 26, 2026 High ddosaicyberattack