vulnerability Microsoft Warns of Two Actively Exploited Defender Vulnerabilities Microsoft has disclosed two actively exploited vulnerabilities within its Defender security platform, CVE-2026-41091 and CVE-2026-45498, both of which allow for privilege escalation and denial-of-service attacks. These v… The Hacker News · May 21, 2026 High CVE-2026-41091CVE-2026-45498CVE-2026-33825defendervulnerabilityprivilege escalation
threat-intel When Identity is the Attack Path This article highlights the increasing risk of attacks leveraging compromised identity credentials within complex IT environments. A single, exposed access key, often due to cached credentials or excessive permissions, c… The Hacker News · May 21, 2026 High USidentitycredentialspermissions
vulnerability Microsoft Patches Exploited UnDefend and RedSun Defender Zero-Days Microsoft released patches for two previously exploited zero-day vulnerabilities within its Defender security software. These vulnerabilities, CVE-2026-41091 and CVE-2026-45498, allowed for privilege escalation and denia… SecurityWeek · May 21, 2026 High CVE-2026-41091CVE-2026-45498CVE-2008-4250zero-dayprivilege escalationdenial of service
supply-chain Supply Chain Security Crisis: Too Many Vulnerabilities, Too Little Visibility This article highlights a growing cybersecurity crisis driven by the rapid proliferation of vulnerabilities and the decreasing time it takes for attackers to exploit them. The analysis, primarily based on a Black Kite re… SecurityWeek · May 21, 2026 High USsupply chainvulnerabilityai
vulnerability Microsoft warns of new Defender zero-days exploited in attacks Microsoft has released security patches for two zero-day vulnerabilities, CVE-2026-41091 (RedSun) and CVE-2026-45498 (UnDefend), that are being actively exploited in attacks. These flaws, affecting Microsoft Defender and… BleepingComputer · May 21, 2026 High CVE-2026-41091CVE-2026-45498USzero-dayprivilege escalationdefender
vulnerability 9-Year-Old Linux Kernel Flaw Enables Root Command Execution on Major Distros A nine-year-old vulnerability in the Linux kernel, CVE-2026-46333, allows unprivileged users to execute commands as root, posing a significant risk to systems running affected distributions. The flaw stems from improper… The Hacker News · May 21, 2026 High CVE-2026-46333linuxkernelprivilege escalation
supply-chain GitHub links repo breach to TanStack npm supply-chain attack A supply-chain attack targeting GitHub originated with a malicious version of the Nx Console VS Code extension, facilitated by the TeamPCP threat group. The attack compromised over 3,800 internal repositories and extende… BleepingComputer · May 21, 2026 High USsupply-chainnpmvscode
threat-intel GitHub Internal Repositories Breached via Malicious Nx Console VS Code Extension GitHub experienced a breach of its internal repositories due to a compromised employee device utilizing a malicious VS Code extension, the Nx Console. The attack, orchestrated by TeamPCP, leveraged a supply chain vulnera… The Hacker News · May 21, 2026 High CVE-2026-45321CVE-2026-48027supply chainvscodeopen source
vulnerability Highly Critical Drupal Core Flaw Exposes PostgreSQL Sites to RCE Attacks Drupal has released security updates for a "highly critical" security vulnerability in Drupal Core that could be exploited by attackers to achieve remote code execution, privilege escalation, or information disclosure. T… The Hacker News · May 21, 2026 High CVE-2026-9082
threat-intel Smashing Security podcast #468: High-speed train hacks and homicidal lawnmowers This Smashing Security podcast episode discusses several ongoing cybersecurity incidents and investigations. The conversation touches on the ongoing Lazarus Group activities, including the upcoming ‘Cyberhack’ season, an… Graham Cluley · May 20, 2026 High NOTAnorth koreamalwarethreat intelligence
threat-intel Europe dismantles VPN service used by cybercriminals to hide ransomware attacks European law enforcement agencies successfully dismantled First VPN, a virtual private network (VPN) service heavily utilized by cybercriminals to mask their activities, including ransomware attacks and fraud schemes. Th… The Record · May 20, 2026 High FRNLUAvpncybercrimeransomware
Xi and Putin pledge closer cooperation on AI, cyberspace and satellite systems In a lengthy joint statement, Moscow and Beijing pledged closer cooperation on satellite internet technologies and joint work on software development and open-source initiatives — part of a broader effort to reduce relia… The Record · May 20, 2026 High
malware Ukraine identifies infostealer operator tied to 28,000 stolen accounts The Ukrainian cyberpolice, working in conjunction with U.S. law enforcement, has identified an 18-year-old man from Odesa suspected of running an infostealer malware operation targeting users of an online store in Califo… BleepingComputer · May 20, 2026 High
threat-intel Hackers bypass SonicWall VPN MFA due to incomplete patching Hackers exploited a vulnerability (CVE-2024-12802) in SonicWall Gen6 SSL-VPN appliances to bypass multi-factor authentication and deploy ransomware tools. The attackers gained access to networks within 30-60 minutes, lev… BleepingComputer · May 20, 2026 High CVE-2024-12802USvpnmfacredential theft
threat-intel GitHub Confirms Breach, 4K Internal Repos Stolen GitHub experienced a data breach where approximately 4,000 internal code repositories were stolen by the threat actor TeamPCP. The breach originated from a poisoned VS Code extension compromising an employee's device, an… Dark Reading · May 20, 2026 High vscodeopen sourcedeveloper tooling
malware Fake Android Apps Commit Carrier Billing Fraud for Premium Svcs. A coordinated campaign targeting Android users in Malaysia, Thailand, Romania, and Croatia has been identified, utilizing fake apps disguised as popular services to commit carrier billing fraud. The malware, employing te… Dark Reading · May 20, 2026 High MYTHROandroidcarrier billingfraud
data-breach Processes and Culture Top Reasons Behind Data Breaches This article examines the reasons behind persistent data breaches, particularly focusing on the issue of underreporting within organizations. The analysis, stemming from a Massachusetts state study, highlights weaknesses… Dark Reading · May 20, 2026 High USdata breachcyber hygienepassword security
threat-intel FTC warns 12 major tech firms of violating Take It Down Act The Federal Trade Commission (FTC) has issued warnings to twelve major tech companies, alleging non-compliance with the newly enacted Take It Down Act (TIDA). This law mandates platforms swiftly remove non-consensual int… The Record · May 20, 2026 High image abuseonline safetyprivacy
Microsoft Open-Sources RAMPART and Clarity to Secure AI Agents During Development Microsoft has unveiled two new open-source tools called RAMPART and Clarity to assist developers in better testing the security of artificial intelligence (AI) agents. RAMPART, short for Risk Assessment and Measurement P… The Hacker News · May 20, 2026 High
data-breach Ukraine probes teen suspect in cyber theft scheme targeting California online shoppers Ukrainian authorities are investigating an 18-year-old suspect linked to a cybercrime operation targeting California online shoppers. The scheme involved compromising nearly 30,000 customer accounts of a U.S.-based retai… The Record · May 20, 2026 High UKcybercrimedata-theftonline-shopping