Afghan finance officials targeted by suspected Pakistani cyberespionage campaign A suspected Pakistan-linked hacking group has targeted Afghanistan's Ministry of Finance and provincial government officials in a new cyberespionage campaign, researchers have found. The Record · May 31, 2026
threat-intel YARA-X 1.17.0 Release, (Sun, May 31st) The SANS Internet Storm Center released version 1.17.0 of YARA-X, a tool used for identifying and analyzing malware. This update includes several performance enhancements and a single bug fix, indicating ongoing maintena… SANS Internet Storm Center · May 31, 2026 Info yaramalwarethreat-detection
vulnerability WP Maps Pro bug exploited to create admin accounts on WordPress sites A critical vulnerability (CVE-2026-8732) in the WP Maps Pro WordPress plugin has been exploited by threat actors to create administrator accounts on affected websites. The flaw stems from an insecure AJAX endpoint that a… BleepingComputer · May 31, 2026 Critical CVE-2026-8732wordpresswp maps provulnerability
malware Dutch Authorities Dismantle Botnet Linked to 17 Million Infected Devices Dutch authorities have announced the takedown of a botnet that enslaved millions of infected devices, including computers, tablets, smartphones, and IoT devices, to carry out malicious attacks. The bot network, per the D… The Hacker News · May 31, 2026
vulnerability Palo Alto GlobalProtect VPN auth bypass flaw now exploited in attacks Palo Alto Networks is warning of an actively exploited vulnerability (CVE-2026-0257) in its GlobalProtect VPN software, allowing attackers to bypass authentication and establish unauthorized VPN connections. The flaw, in… BleepingComputer · May 30, 2026 High CVE-2026-0257USvpnauthenticationcookie
threat-intel Russian Spies Are Aggressively Seeking Western Technology as Sanctions Bite, Officials Say As a result of sanctions and the ongoing war in Ukraine, Russian intelligence agencies are intensifying their efforts to steal Western technology and defense secrets. This includes targeting advanced machine tools, resea… SecurityWeek · May 30, 2026 High RUSEFIsanctionsespionagecyberattack
vulnerability Exploit Code Published for Critical Flowise RCE Vulnerability A critical remote code execution (RCE) vulnerability, CVE-2026-40933, has been discovered in Flowise, a popular open-source AI agent platform. The flaw, stemming from a command injection issue within the Anthropic MCP pr… SecurityWeek · May 30, 2026 Critical CVE-2026-40933rcecommand injectionai
vulnerability New CIFSwitch Linux flaw gives root on multiple distributions A newly discovered vulnerability, dubbed 'CIFSwitch,' in the Linux kernel allows attackers to escalate privileges to root by forging CIFS authentication key descriptions. The flaw, present since 2007, affects multiple Li… BleepingComputer · May 30, 2026 High CVE-2026-46243linuxkernelprivilege escalation
vulnerability PAN-OS GlobalProtect Authentication Bypass (CVE-2026-0257) Under Active Exploitation Palo Alto Networks has warned that a recently disclosed medium-severity security flaw impacting PAN-OS and Prisma Access has come under active exploitation in the wild. The vulnerability, tracked as CVE-2026-0257 (CVSS s… The Hacker News · May 30, 2026 Medium CVE-2026-0257CVE-2026-35616
threat-intel Friday Squid Blogging: Another Squid This article, originating from Schneier on Security's 'Friday Squid Blogging' series, reports on ongoing activity attributed to a known threat actor nicknamed "Squid." The post serves as a platform for discussing recent… Schneier on Security · May 29, 2026 Medium threat actorcybersecurityintelligence
malware ChatGPT share links abused to host fake outage pages to deliver malware Threat actors are exploiting ChatGPT's content-sharing feature to host convincing fake outage pages designed to trick users into downloading malware. This 'LLMShare' campaign leverages Google ads and a legitimate OpenAI… BleepingComputer · May 29, 2026 High aimalwarephishing
data-breach California AG sues 23andMe over 2023 breach exposing health data 23andMe faced a significant data breach in 2023, exposing the personal and genetic information of nearly 7 million customers, including a large number in California. The breach stemmed from a credential-stuffing attack a… BleepingComputer · May 29, 2026 High USdata breachgenetic datacredential stuffing
threat-intel ChatGPhish Vulnerability Turns ChatGPT Web Summaries Into a Phishing Surface A vulnerability, dubbed ChatGPhish, has been discovered in OpenAI’s ChatGPT that allows attackers to leverage the AI’s summarization feature to create phishing attacks. By appending malicious content to a webpage, attack… The Hacker News · May 29, 2026 High CVE-2026-25592CVE-2026-26030USprompt injectionphishingai
threat-intel In Other News: Trump Mobile Data Breach, FIFA World Cup Phishing, CISA Responds to Supply Chain Attacks This week’s cybersecurity news highlights a range of incidents, including a data breach affecting Trump Mobile customers, ongoing Russian government intrusion into US Treasury systems, and vulnerabilities in popular soft… SecurityWeek · May 29, 2026 High UNCHdata breachsupply chainphishing
data-breach Charter Communications Data Breach Could Impact Nearly 5 Million The notorious ShinyHunters extortion group leaked over 42 million records allegedly stolen from Charter in April. The post Charter Communications Data Breach Could Impact Nearly 5 Million appeared first on SecurityWeek . SecurityWeek · May 29, 2026 High
threat-intel Attackers Use LLM Agent for Post-Exploitation After Marimo CVE-2026-39987 Exploit An unknown threat actor exploited CVE-2026-39987 in Marimo to gain initial access, subsequently using a large language model (LLM) agent to conduct post-exploitation activities, including stealing credentials and exfiltr… The Hacker News · May 29, 2026 High CVE-2026-39987CNllmpost-exploitationcredential theft
threat-intel Asia's Cyber Insurance Market Shows Signs of Life The Asian cyber insurance market has historically lagged behind other regions due to low penetration rates, particularly among larger organizations and small businesses. However, a recent report indicates a potential shi… Dark Reading · May 29, 2026 High CHJASIcyberinsuranceransomwareapac
MokN Raises $15 Million for “Phish-Back” Platform MokN's platform deploys realistic decoy access points to lure attackers into revealing compromised credentials, enabling organizations to respond before abuse occurs. The post MokN Raises $15 Million for “Phish-Back” Pla… SecurityWeek · May 29, 2026
ddos From $5 Attacks to Botnet-Powered Platforms: Inside the DDoS-as-a- Service Market This article reports on the increasing commercialization of Distributed Denial-of-Service (DDoS) attacks, now offered as a ‘DDoS-as-a-Service’ (DDoSaaS) model. The trend shows a shift from fragmented, DIY attack methods… BleepingComputer · May 29, 2026 High USddosbotnetcloudflare
malware Dutch govt disrupts malware botnet with 17 million infected devices Dutch authorities have taken offline a massive botnet of 17 million devices and seized more than 200 servers at a local provider that supported the operation. BleepingComputer · May 29, 2026 Medium