threat-intel GitHub investigates internal repositories breach claimed by TeamPCP GitHub is investigating a breach of its internal repositories following a claim by the TeamPCP hacker group, who gained access to approximately 4,000 private code repositories. The incident highlights a vulnerability wit… BleepingComputer · May 20, 2026 High supply-chaingithubmalware
vulnerability Verizon DBIR 2026: Vulnerability Exploitation Overtakes Credential Theft as Top Breach Vector Verizon’s 2026 Data Breach Investigations Report (DBIR) reveals that vulnerability exploitation has become the leading cause of data breaches, surpassing credential theft. The report highlights a concerning trend of slow… SecurityWeek · May 20, 2026 High USvulnerability managementpatchinggen-ai
vulnerability Verizon DBIR: Enterprises Face a Dangerous Vulnerability Glut Verizon's 2026 Data Breach Investigations Report (DBIR) highlights a concerning trend: the increasing prevalence of exploits in initial breaches, rising to 31% in 2025. Organizations struggle to keep pace with the massiv… Dark Reading · May 19, 2026 High NOvulnerabilitiespatch managementai
threat-intel Cybercrime service disrupted for abusing Microsoft platform to sign malware Microsoft disrupted a malware-as-a-service (MaaS) operation, dubbed Fox Tempest, that was abusing its Artifact Signing service to generate fraudulent code-signing certificates for ransomware gangs and other cybercriminal… BleepingComputer · May 19, 2026 High USCAmsaascode signingfraudulent certificates
threat-intel Windows Zero-Day Barrage Continues After Patch Tuesday A security researcher known as "Nightmare Eclipse" has disclosed six Windows zero-day vulnerabilities over the past six weeks, some of which are actively being exploited. These vulnerabilities, including YellowKey, Green… Dark Reading · May 19, 2026 High CVE-2020-17103CVE-2026-33825USzero-daybitlockerprivilege escalation
threat-intel CISA Exposes Secrets, Credentials in 'Private' Repo A public GitHub repository belonging to the Cybersecurity and Infrastructure Security Agency (CISA) was discovered containing 844MB of sensitive data, including plain-text passwords, authentication tokens, and cloud infr… Dark Reading · May 19, 2026 High USsecretsgithubcloud
malware Stealer Spoofs Google, Microsoft & Apple, Then Backdoors macOS A new macOS infostealer, dubbed SHub Reaper, is targeting users through fake WeChat and Miro installers, mimicking Google, Microsoft, and Apple to lure victims. This malware combines stealer and backdoor capabilities, ut… Dark Reading · May 19, 2026 High USmacosinfostealerbackdoor
threat-intel Huawei zero-day attack behind last year’s crash of Luxembourg's entire telecoms network A zero-day attack targeting a vulnerability in Huawei’s enterprise router software caused a three-hour nationwide telecoms outage in Luxembourg during July 2025. The attack, which exploited a previously undocumented beha… The Record · May 19, 2026 High CVE-2021-22359CVE-2022-29798LUzero-daydenied-servicenetwork
threat-intel UK regulator to require tech firms to tackle deepfakes, non-consensual intimate images The UK’s communications regulator, Ofcom, is implementing new rules requiring tech companies to actively combat the spread of non-consensual intimate images and deepfakes. This initiative utilizes hash matching technolog… The Record · May 19, 2026 High GBdeepfakenon-consensualintimate images
malware Trapdoor Android Ad Fraud Scheme Hit 659 Million Daily Bid Requests Using 455 Apps A new Android ad fraud scheme, dubbed Trapdoor, has been identified by HUMAN Threat Intelligence, utilizing 455 malicious apps and 183 C2 domains to generate 659 million daily bid requests. The operation leverages malver… The Hacker News · May 19, 2026 High USandroidad fraudmalvertising
threat-intel DirtyDecrypt PoC Released for Linux Kernel CVE-2026-31635 LPE Vulnerability A Proof-of-Concept (PoC) exploit, dubbed DirtyDecrypt, has been released for a Linux kernel vulnerability (CVE-2026-31635) allowing for local privilege escalation. The vulnerability, related to a missing copy-on-write (C… The Hacker News · May 19, 2026 High CVE-2026-31635CVE-2026-31431CVE-2026-43284linuxkernellpe
vulnerability Siemens RUGGEDCOM APE1808 Devices A buffer overflow vulnerability (CVE-2026-0300) has been identified in Siemens RUGGEDCOM APE1808 devices, specifically the User-ID™ Authentication Portal service within Palo Alto Networks PAN-OS software. This vulnerabil… CISA Advisories · May 19, 2026 High CVE-2026-0300DEbuffer overflowcaptive portalroot privilege
vulnerability ABB CoreSense HM and CoreSense M10 This advisory from CISA details a path traversal vulnerability (CVE-2025-3465) affecting ABB CoreSense HM and CoreSense M10 devices. Unauthenticated users could potentially gain access to restricted directories, leading… CISA Advisories · May 19, 2026 High CVE-2025-3465WOpath traversalcve-2025-3465abb
threat-intel The New Phishing Click: How OAuth Consent Bypasses MFA In February 2026, a phishing-as-a-service platform, EvilTokens, compromised over 340 Microsoft 365 organizations across five countries by exploiting OAuth consent screens. Attackers gained access to valid refresh tokens… The Hacker News · May 19, 2026 High USGBoauthconsentphishing
threat-intel Drupal to Release Urgent Core Security Updates on May 20, Sites Told to Prepare Drupal has announced an upcoming core security release scheduled for May 20, 2026, urging users to prepare and update their systems proactively. The release addresses potential vulnerabilities that could be exploited qui… The Hacker News · May 19, 2026 High drupalsecurityupdate
threat-intel The quest for greater tech independence The article explores the growing trend of nations, particularly in Europe, seeking greater tech sovereignty – the ability to independently control their digital infrastructure and technology supply chains – driven by con… WeLiveSecurity · May 19, 2026 High EUCHUStech sovereigntydigital independencesupply chain
supply-chain Compromised Nx Console 18.95.0 Targeted VS Code Developers with Credential Stealer A compromised version of the Nx Console VS Code extension (version 18.95.0) was used to steal developer credentials through a supply chain attack. The extension, initially introduced by a developer whose machine was comp… The Hacker News · May 19, 2026 High RUUSsupply chaincredential theftvscode
supply-chain Popular GitHub Action Tags Redirected to Imposter Commit to Steal CI/CD Credentials A GitHub Actions workflow, actions-cool/issues-helper, was compromised through an imposter commit attack, allowing threat actors to steal CI/CD credentials from running workflows. The attack leveraged malicious code inje… The Hacker News · May 19, 2026 High USgithubci/cdsupply-chain
supply-chain Mini Shai-Hulud Pushes Malicious AntV npm Packages via Compromised Maintainer Account A sophisticated supply chain attack, dubbed Mini Shai-Hulud, is targeting npm packages within the @antv ecosystem. The attack leverages a compromised maintainer account to inject malicious code – specifically a credentia… The Hacker News · May 19, 2026 High USsupply chainnpmcredential theft
threat-intel Microsoft Exchange Zero-Day Under Attack, No Patch Available A zero-day vulnerability (CVE-2026-42897) affecting Microsoft Exchange Outlook Web Access (OWA) is under active exploitation, allowing attackers to compromise mailboxes through cross-site scripting (XSS). Despite Microso… Dark Reading · May 18, 2026 High CVE-2026-42897BEzero-dayxssexchange