vulnerability Microsoft Patches SharePoint RCE Flaw CVE-2026-45659 Across Server Versions Microsoft has rolled out updates to fix a remote code execution vulnerability impacting SharePoint that could be exploited by bad actors in attacks without requiring any specialized conditions to be met. The vulnerabilit… The Hacker News · May 26, 2026 High CVE-2026-45659CVE-2026-32201
threat-intel MFA Prompt Bombing: Why Your Second Factor Isn't Saving You This article details a new attack technique called ‘MFA prompt bombing,’ where attackers repeatedly trigger multi-factor authentication prompts to trick users into approving access. The attack leverages push-based MFA sy… The Hacker News · May 26, 2026 High USmfapush-mfaprompt bombing
threat-intel CERT-In Mandates 12-Hour Patching for Internet-Facing Flaws Amid AI-Assisted Attacks CERT-In has mandated a 12-hour patching window for critical internet-facing vulnerabilities, driven by the increasing use of AI by threat actors to automate attacks. This response is intended to address the accelerated a… The Hacker News · May 26, 2026 High INaicybersecurityvulnerability
threat-intel BTMOB: A stealthy RAT burrowing deep into Android devices BTMOB is a stealthy Android remote access trojan (RAT) that’s rapidly evolving and spreading through phishing campaigns and a ‘malware-as-a-service’ model. It allows attackers to steal data, take control of devices, and… WeLiveSecurity · May 26, 2026 High ARandroidmalwareremote access trojan
malware Iranian Hackers Deploy MiniFast and MiniJunk V2 via Phishing and SEO Poisoning Iranian state-sponsored threat actor Nimbus Manticore (UNC1549) has launched a new campaign utilizing the MiniFast backdoor, developed with potential AI assistance, to target organizations in the aviation and software se… The Hacker News · May 26, 2026 High SAAUIRphishingbackdoorappdomain hijacking
data-breach 7-Eleven data breach exposes personal information of 185,000 people 7-Eleven experienced a data breach following a cyberattack by the ShinyHunters extortion gang, exposing the personal information of over 185,000 individuals. The attackers gained access to 7-Eleven’s systems, primarily a… BleepingComputer · May 26, 2026 High DEdata breachsalesforceextortion
malware Possible ACR Stealer From Page Impersonating Claude, (Tue, May 26th) This report details the discovery of a fake Claude webpage distributing the ACR Stealer malware, targeting macOS and Windows users. The initial infection vector involves malicious ads leading to the deceptive site, which… SANS Internet Storm Center · May 26, 2026 High USstealermacoswindows
threat-intel Dutch authorities arrest men suspected of providing infrastructure for Russian cyber operations Dutch authorities have arrested two IT entrepreneurs suspected of providing hosting infrastructure used in pro-Russian cyberattacks and disinformation campaigns. The investigation, led by the FIOD, uncovered a network in… The Record · May 25, 2026 High NLMDRUcyberattackdisinformationsanctions
threat-intel Anthropic’s restricted Claude Mythos model may be coming to Claude Code Anthropic is preparing to release a new AI model called Mythos, initially designed for advanced computer security tasks. The model demonstrates a concerning ability to autonomously develop cyberattacks, raising significa… BleepingComputer · May 25, 2026 High aicybersecurityvulnerability
threat-intel ⚡ Weekly Recap: Linux Flaws, Defender 0-Days, Router Botnets, and Supply Chain Chaos This week’s security news highlights a significant GitHub breach orchestrated by TeamPCP, stemming from a compromised developer’s device and leveraging vulnerabilities exposed by the TanStack supply chain attack. Simulta… The Hacker News · May 25, 2026 High CVE-2026-46333CVE-2026-41091CVE-2026-45498USGBsupply-chainlinuxgithub
vulnerability Ghost CMS Vulnerability Exploited to Hack Over 700 Websites A previously disclosed SQL injection vulnerability (CVE-2026-26980) in the Ghost CMS has been actively exploited by multiple threat actors, leading to the compromise of over 700 websites. The attackers leveraged this vul… SecurityWeek · May 25, 2026 High CVE-2026-26980USGBsql injectionghost cmsvulnerability
supply-chain TeamPCP Supply Chain Campaign: Activity Through 2026-05-24, (Mon, May 25th) TeamPCP, a threat actor, launched a sophisticated supply chain campaign involving the malicious publication of compromised code extensions and SDKs across multiple platforms, including GitHub, npm, and PyPI. This campaig… SANS Internet Storm Center · May 25, 2026 High CVE-2026-45321supply chaincredential theftdeveloper tools
supply-chain TeamPCP Supply Chain Campaign: Activity Through 2026-05-24, (Mon, May 25th) TeamPCP, a threat actor, launched a sophisticated supply chain campaign involving the trojanization of multiple software packages, impacting GitHub, Microsoft, OpenAI, Grafana Labs, and Mistral AI. The campaign utilized… SANS Internet Storm Center · May 25, 2026 High CVE-2026-45321supply chain attackcredential theftpublisher badge
threat-intel Netherlands Seizes 800 Servers, Arrests 2 for Aiding Cyberattacks Dutch authorities have seized over 800 servers and arrested two individuals – Andrey Nesterenko and Youssef Zinad – operating MIRhosting and WorkTitans, respectively, for facilitating cyberattacks and disinformation camp… Krebs on Security · May 25, 2026 High NLDKRUcyberattackddossanctions
phishing FBI warns of Kali365 phishing service targeting Microsoft 365 accounts The FBI has issued a warning about Kali365, a phishing-as-a-service (PhaaS) platform, being used to target Microsoft 365 accounts. This platform leverages device code authentication to bypass multi-factor authentication… BleepingComputer · May 25, 2026 High USphishingoauthmfa
data-breach Oncology Institute Discloses Data Breach The affected third-party vendor has not been named, but one possible candidate is TriZetto. The post Oncology Institute Discloses Data Breach appeared first on SecurityWeek . SecurityWeek · May 25, 2026 High
data-breach 266,000 Affected by Data Breach at Radiology Associates of Richmond Threat actors stole files containing names and protected health information from the healthcare organization’s systems. The post 266,000 Affected by Data Breach at Radiology Associates of Richmond appeared first on Secur… SecurityWeek · May 25, 2026 High
data-breach DocketWise Data Breach Impacts 143,000 Hackers accessed names, addresses, Social Security numbers, financial information, and medical data from third-party partner repositories. The post DocketWise Data Breach Impacts 143,000 appeared first on SecurityWeek . SecurityWeek · May 25, 2026 High
malware Lazarus Deploys RemotePE Memory-Only RAT Against Financial and Crypto Firms The Lazarus Group, a North Korean threat actor, has deployed a new memory-only remote access trojan (RAT) called RemotePE to target financial and cryptocurrency firms. This multi-stage attack chain utilizes several loade… The Hacker News · May 25, 2026 High KPremote access trojannorth koreasocial engineering
supply-chain Over 5,500 GitHub Repositories Infected in ‘Megalodon’ Supply Chain Attack A sophisticated supply chain attack, dubbed Megalodon, has infected over 5,500 GitHub repositories by injecting malicious code into automated workflows. The attack leverages compromised versions of the Tiledesk package t… SecurityWeek · May 25, 2026 High supply chaingithubmalware