threat-intel Shai-Hulud Worm Clones Spread After Code Release The release of Shai-Hulud source code by TeamPCP, a financially motivated threat actor, has triggered the spread of clones targeting software developers and the open-source ecosystem. This incident highlights a new attac… Dark Reading · May 18, 2026 High supply-chainopen-sourcedeveloper
threat-intel INTERPOL Operation Ramz Disrupts MENA Cybercrime Networks with 201 Arrests INTERPOL’s Operation Ramz was a coordinated international effort involving 13 MENA countries to combat cybercrime, resulting in 201 arrests and the disruption of phishing and malware operations. The operation targeted in… The Hacker News · May 18, 2026 High AEALBHcybercrimephishingmalware
threat-intel Fuel Tank Breaches Expand Scope of Iran's Cyber Offensive This article reports on a cyber offensive by Iran targeting fuel tank systems in the United States, exploiting insecure automatic tank gauge (ATG) systems exposed online. The attacks, which involved manipulating displaye… Dark Reading · May 18, 2026 High USIRcyberattackcritical infrastructuregeopolitics
threat-intel ⚡ Weekly Recap: Exchange 0-Day, npm Worm, Fake AI Repo, Cisco Exploit and More This week’s security news highlights several active exploits and attacks, including a widespread vulnerability in on-prem Exchange Servers, a Cisco SD-WAN controller compromise attributed to UAT-8616, and a significant s… The Hacker News · May 18, 2026 High CVE-2026-42897CVE-2026-20182CVE-2026-20127USexchangesupply chainnpm
phishing How to Reduce Phishing Exposure Before It Turns into Business Disruption This article discusses the increasing risk posed by phishing attacks, particularly due to their ability to quickly escalate into significant business disruptions. It highlights the challenges SOC teams face in identifyin… The Hacker News · May 18, 2026 High USphishingsandboxcredential theft
threat-intel The Boring Stuff Is Dangerous Now This article highlights a growing security challenge stemming from the widespread adoption of AI coding tools and the emergence of AI agents capable of exploiting obscure vulnerabilities. The combination creates a situat… Dark Reading · May 18, 2026 High aivulnerabilitycybersecurity
ransomware IT threat evolution in Q1 2026. Non-mobile statistics In Q1 2026, Kaspersky products blocked over 343 million attacks, with significant ransomware activity including 2938 new ransomware variants and 77,000 ransomware attacks. Law enforcement actions disrupted the RAMP cyber… Securelist · May 18, 2026 High CVE-2026-20131POUNransomwarezero-dayraas
data-breach Boulevard of Broken Dreams: 2 Decades of Cyber Fails This Dark Reading article reflects on two decades of cybersecurity failures, highlighting recurring trends like data breaches, systemic vulnerabilities, and a growing sense of apathy among individuals regarding data secu… Dark Reading · May 18, 2026 High CVE-2023-34362USdata breachsql injectioncybersecurity
threat-intel Developer Workstations Are Now Part of the Software Supply Chain Recent attacks, including those mimicking the "mini Shai Hulud" and "Shai-Hulud 2.0" campaigns, have highlighted a growing threat: attackers targeting developer workstations to steal credentials and secrets from CI/CD pi… The Hacker News · May 18, 2026 High USdeveloper workstationssecretssupply chain
vulnerability Zero-Day Exploit Against Windows BitLocker A new zero-day exploit, dubbed YellowKey, has been discovered targeting Windows BitLocker encryption. The vulnerability allows attackers to bypass BitLocker's security measures with physical access to the affected device… Schneier on Security · May 18, 2026 High zero-dayencryptionbitlocker
threat-intel Four Malicious npm Packages Deliver Infostealers and Phantom Bot DDoS Malware Four npm packages have been identified as containing malicious code, including a clone of the Shai-Hulud worm. One package delivers a DDoS botnet (Phantom Bot), while the others function as infostealers, stealing sensiti… The Hacker News · May 18, 2026 High NOsupply chainnpminfostealer
ransomware Congress Puts Heat on Instructure After Canvas Outage Following a high-profile cyberattack on its Canvas learning management system by the ShinyHunters group, Instructure is facing increased scrutiny from Congress. The House Committee on Homeland Security has requested a br… Dark Reading · May 15, 2026 High USedtechransomwaredata breach
threat-intel Cyber Pioneers Ponder Past as Prologue This Dark Reading article reflects on the platform's 20-year history, featuring insights from prominent cybersecurity leaders who contributed to its content. Robert Hansen discusses his early work on robot scraping and A… Dark Reading · May 15, 2026 High aivulnerabilitybug bounties
malware Gremlin Stealer's Evolved Tactics: Hiding in Plain Sight With Resource Files This report details the evolving tactics of the Gremlin stealer malware, specifically a recent variant employing sophisticated obfuscation techniques to evade detection. The malware, which targets sensitive data like pay… Palo Alto Unit 42 · May 15, 2026 High USobfuscationanti-analysisresource section
threat-intel Suspected Dream Market kingpin arrested after gold bars sent to his home address Owe Martin Andresen, suspected to be the administrator of the notorious Dream Market dark web drug marketplace, has been arrested on money laundering charges in the US and Germany. Authorities allege he moved millions of… Graham Cluley · May 14, 2026 High USDEdark webdrug traffickingmoney laundering
threat-intel The time of much patching is coming This article from Cisco Talos anticipates a significant increase in software patching due to advancements in AI-powered vulnerability detection and the uncovering of long-standing technical debt. The surge in discovered… Cisco Talos · May 14, 2026 High USvulnerabilitypatchingai
vulnerability Ongoing exploitation of Cisco Catalyst SD-WAN vulnerabilities Cisco Talos has identified ongoing exploitation of vulnerabilities within Cisco Catalyst SD-WAN Controller and Manager, specifically CVE-2026-20182 and a set of related vulnerabilities (CVE-2026-20133, CVE-2026-20128, an… Cisco Talos · May 14, 2026 High CVE-2026-20182CVE-2026-20133CVE-2026-20128sd-wanciscoauthentication
vulnerability Siemens Simcenter Femap A heap-based buffer overflow vulnerability has been identified in Siemens Simcenter Femap, specifically within the Datakit library. The vulnerability, reported by TrendAI Zero Day Initiative, allows for remote code execu… CISA Advisories · May 14, 2026 High CVE-2025-12659GEheap-overflowremote-code-executionipt
vulnerability Siemens gWAP A remote code execution vulnerability has been identified in Siemens gWAP, stemming from a prototype pollution issue within the Axios HTTP client library. This vulnerability, exploitable through a ‘Gadget’ attack chain,… CISA Advisories · May 14, 2026 High CVE-2026-40175DEremote code executionprototype pollutionaxios
vulnerability Siemens SENTRON 7KT PAC1261 Data Manager A vulnerability has been identified in the Siemens SENTRON 7KT PAC1261 Data Manager software, specifically within the Go Project’s net/http package. This allows an attacker to potentially gain administrative control over… CISA Advisories · May 14, 2026 High CVE-2025-22871DEhttprequest smugglingindustrial control systems