data-breach Grafana breach caused by missed token rotation after TanStack attack The Grafana data breach was caused by a single GitHub workflow token that slipped through the rotation process following the TanStack npm supply-chain attack last week. BleepingComputer · May 20, 2026 High
threat-intel AI-Powered App Attacks Are Faster, More Frequent and Harder to Stop This SecurityWeek article highlights a significant shift in app security driven by the rapid adoption of AI by cybercriminals. The report from Digital.ai indicates a dramatic increase in attacks against apps, moving from… SecurityWeek · May 20, 2026 High USGBaiagentic aiapp security
threat-intel Microsoft Takes Down Malware-Signing Service Behind Ransomware Attacks Microsoft disrupted a malware-signing-as-a-service (MSaaS) operation, dubbed OpFauxSign, led by the threat actor Fox Tempest, which was using its Artifact Signing system to distribute malware and ransomware. The operatio… The Hacker News · May 20, 2026 High USFRINmsaascode-signingmalware
threat-intel Identity Alone Isn't Enough: Why Device Security Has to Share the Load This article highlights the limitations of relying solely on identity verification in modern cybersecurity, arguing that it’s no longer sufficient against sophisticated attacks leveraging AI and phishing. The piece empha… BleepingComputer · May 20, 2026 High USzero trustmfadevice posture
threat-intel 1Password Teams With OpenAI to Stop AI Coding Agents From Leaking Credentials 1Password and OpenAI have partnered to create a new system, the Environments MCP Server, designed to protect sensitive credentials used by AI coding agents like OpenAI Codex. This integration addresses the growing risk o… SecurityWeek · May 20, 2026 High aicredentialssecrets
threat-intel Texas, Florida top list of states reporting millions of dollars lost through crypto ATMs A recent FBI report reveals a significant surge in financial losses linked to cryptocurrency ATMs across the United States, totaling $388 million in 2025. Texas and Florida topped the list of states experiencing these lo… The Record · May 20, 2026 High CHNEAUcryptocurrencyscamsfraud
vulnerability Anthropic Silently Patches Claude Code Sandbox Bypass Anthropic has addressed a vulnerability in its Claude Code network sandbox that could have allowed attackers to bypass security controls and potentially exfiltrate data. The vulnerability, discovered by researcher Aonan… SecurityWeek · May 20, 2026 High CVE-2025-66479sandboxprompt injectionsecurity
threat-intel Webworm Deploys EchoCreep and GraphWorm Backdoors Using Discord and MS Graph API A China-aligned threat actor known as Webworm has expanded its arsenal with two new backdoors, EchoCreep and GraphWorm, utilizing Discord and the Microsoft Graph API for command-and-control communications. The group, act… The Hacker News · May 20, 2026 High CHRUGEdiscordmicrosoft graphrat
vulnerability Schnieider Electric EcoStruxure Machine Expert HVAC (SEVD-2026-132-01) This CISA advisory details a vulnerability (SEVD-2026-132-01) in Schneider Electric’s Ecostruxure Machine Expert HVAC software, specifically versions prior to 1.10.0. The vulnerability, classified as CWE-312 (Cleartext S… CISA Advisories · May 20, 2026 High CVE-2026-6332WOcwe-312source codeconfidentiality
threat-intel GitHub Breached — Employee Device Hack Led to Exfiltration of 3,800+ Internal Repos GitHub experienced a breach originating from an employee device compromised by a poisoned Microsoft Visual Studio Code extension. The attacker exfiltrated over 3,800 internal repositories, facilitated by the threat actor… The Hacker News · May 20, 2026 High USILIRsupply chaincredential theftinfostealer
vulnerability Exploit released for new PinTheft Arch Linux root escalation flaw A publicly available exploit, dubbed ‘PinTheft’, has been released for a Linux kernel vulnerability allowing local attackers to gain root privileges on Arch Linux systems. The vulnerability, residing in the RDS module, w… BleepingComputer · May 20, 2026 High linuxprivilege escalationrds
threat-intel Real-World ICS Security Tales From the Trenches This article details real-world incidents involving industrial control systems (ICS) security vulnerabilities, highlighting the challenges of securing OT environments beyond traditional IT security practices. Two separat… SecurityWeek · May 20, 2026 High IRUSicsotlateral movement
malware Tracking TamperedChef Clusters via Certificate and Code Reuse This report details ongoing activity clusters closely resembling the TamperedChef (EvilAI) malware campaign, which involves trojanized productivity software like PDF editors and calendars. These campaigns utilize malicio… Palo Alto Unit 42 · May 20, 2026 High USpersistencecommand and controltrojan
threat-intel Webworm: New burrowing techniques This blog post details the evolving tactics of Webworm, a China-aligned APT group, particularly their activity in 2025. Webworm has shifted away from traditional backdoors in favor of more sophisticated techniques, inclu… WeLiveSecurity · May 20, 2026 High CVE-2017-7692BEITSEdiscordmicrosoft graph apic&c
ransomware FBI warns students and staff that ShinyHunters may come knocking after Canvas breach The FBI issued an advisory regarding the ShinyHunters extortion gang following a breach of an online Learning Management System used by educational institutions. Instructure, the provider of Canvas, quietly agreed to pay… Graham Cluley · May 20, 2026 High USransomwarelmseducation
vulnerability Microsoft Releases Mitigation for YellowKey BitLocker Bypass CVE-2026-45585 Exploit This report details a zero-day vulnerability, dubbed ‘YellowKey,’ affecting Windows 11 and Server 2025, allowing attackers to bypass BitLocker Device Encryption through a USB drive exploit. Microsoft has released a mitig… The Hacker News · May 20, 2026 High CVE-2026-45585USbitlockerwinrezero-day
supply-chain GitHub confirms breach of 3,800 repos via malicious VSCode extension GitHub experienced a breach affecting approximately 3,800 internal repositories after an employee installed a malicious VS Code extension. The incident is linked to a broader supply chain attack by TeamPCP, who are deman… BleepingComputer · May 20, 2026 High supply chainvscodeextension
vulnerability Microsoft shares mitigation for YellowKey Windows zero-day Microsoft has released mitigation steps for a newly disclosed Windows zero-day vulnerability, dubbed YellowKey, which allows unauthorized access to BitLocker-protected drives. The vulnerability was initially revealed by… BleepingComputer · May 20, 2026 High CVE-2026-33825CVE-2026-45585zero-daybitlockerwinre
threat-intel Interpol's 'Operation Ramz' Pioneers Cross-Region Collabs in Middle East Interpol’s ‘Operation Ramz’ was a five-month collaborative law enforcement effort involving 13 countries in the Middle East and North Africa (MENA) region to combat cybercrime. The operation resulted in the identificatio… Dark Reading · May 20, 2026 High AEEGIQcybercrimeregionalcollaboration
Grafana GitHub Breach Exposes Source Code via TanStack npm Attack Grafana Labs, on May 19, 2026, said an investigation into its recent breach found no evidence of customer production systems or operations being compromised. It said the scope of the incident is limited to the Grafana La… The Hacker News · May 20, 2026 High