phishing BTMOB Android malware service generates custom phishing payloads An Android remote access trojan named BTMOB is offered to cybercriminals with a builder interface for generating malware payloads tailored to phishing lures. BleepingComputer · May 28, 2026 Medium
malware Analysis of a Year of Files Uploaded to DShield Sensors, (Wed, May 27th) Using the data collected over the past year and using Kibana these two ES|QL query to summarize the data, this shows the list of the most uploaded threat to two DShield sensors (local and cloud) over the past year. I hav… SANS Internet Storm Center · May 28, 2026 Medium
FBI warns of fake FIFA websites running World Cup fraud schemes The FBI is warning of fake websites impersonating FIFA ahead of the 2026 World Cup, to steal personal and financial information, sell fake tickets and hospitality packages, and push other fraud related to the event. BleepingComputer · May 28, 2026
threat-intel Dutch Raid Fails to Dent Russian Bulletproof Host A Dutch law enforcement operation targeting THE.Hosting, a bulletproof hosting network linked to Russian cybercrime, resulted in the seizure of 800 servers and arrests of two operators but failed to significantly disrupt… Dark Reading · May 28, 2026 High NLRUDKbulletproof hostingcybercrimesanctions evasion
threat-intel Russia-Linked ‘GreyVibe’ Attackers Use AI to Supercharge Cyberattacks A newly identified Russia-linked threat actor, GreyVibe, is utilizing artificial intelligence to enhance the speed, scale, and sophistication of its cyberattacks, primarily targeting Ukrainian military, government, and b… SecurityWeek · May 28, 2026 High RUairussiamalware
threat-intel Less panic patching, more precision This article from Cisco Talos discusses a shift in cybersecurity threat intelligence prioritization, moving away from solely relying on CVSS scores to incorporate exploit prediction and broader data enrichment. The core… Cisco Talos · May 28, 2026 Medium USDEvulnerability_managementepssgcve
vulnerability Hackers exploit FortiClient EMS flaw to push infostealer malware Hackers are exploiting an authentication bypass vulnerability (CVE-2026-35616) in FortiClient Enterprise Management Server (EMS) to deliver an undocumented credential stealer called EKZ. BleepingComputer · May 28, 2026 Medium CVE-2026-35616
vulnerability Critical Gogs RCE Vulnerability Lets Any Authenticated User Execute Arbitrary Code A critical remote code execution (RCE) vulnerability has been identified in Gogs, a popular self-hosted Git service, allowing authenticated users to execute arbitrary code. The flaw, detailed by Jonah Burgess, stems from… The Hacker News · May 28, 2026 Critical rcegitrebase
Geordie Raises $30 Million for AI Security and Governance Platform The funding round was led by Balderton Capital, with additional support from Crosspoint Capital and previous investors General Catalyst and Ten Eleven Ventures. The post Geordie Raises $30 Million for AI Security and Gov… SecurityWeek · May 28, 2026
threat-intel Agentic AI Isn't Risky; the Way Orgs Deploy It Is This article highlights a critical cybersecurity risk associated with the rapid deployment of agentic AI, focusing on vulnerabilities stemming from poor software development practices rather than inherent flaws in the AI… Dark Reading · May 28, 2026 High USaiagentic-aivulnerability
vulnerability Threat Actors Exploit Critical FortiClient EMS Flaw to Deploy Credential Stealer Threat actors are continuing to exploit a critical, now-patched security flaw impacting FortiClient Endpoint Management Server (EMS) deployments to deliver credential-stealing malware. "The campaign abused trusted endpoi… The Hacker News · May 28, 2026 Medium CVE-2026-35616
data-breach Carnival Data Breach Exposed 6 Million People Data breach leaves nearly 6 million Carnival customers navigating identity theft risks. The post Carnival Data Breach Exposed 6 Million People appeared first on SecurityWeek . SecurityWeek · May 28, 2026 High
vulnerability New Gogs zero-day flaw lets hackers get remote code execution A zero-day vulnerability (CVE-2024-39933) has been identified in Gogs, a self-hosted Git service, allowing authenticated attackers to execute remote code execution (RCE). The flaw, initially discovered by Jonah Burgess,… BleepingComputer · May 28, 2026 High CVE-2024-39933CVE-2024-39932CVE-2026-26194USCNJPzero-dayrcegit
threat-intel How SIEM helps MSPs reduce noise and stop threats faster This BleepingComputer article discusses the challenges MSPs face in managing security alerts due to fragmented security toolsets. The core issue is ‘alert fatigue’ and the inability to quickly identify and respond to act… BleepingComputer · May 28, 2026 High siemmspalert fatigue
data-breach Cruise giant Carnival confirms data breach affecting nearly 6 million people Carnival Corporation has confirmed a data breach impacting nearly 6 million individuals, stemming from a cyberattack attributed to the ShinyHunters hacking group. The attackers gained access through a compromised employe… The Record · May 28, 2026 High USdata-theftemployee-accountextortion
vulnerability Microsoft Slams Public Zero-Day Disclosures Amid GitHub Researcher Account Removal Microsoft has strongly criticized the public disclosure of zero-day vulnerabilities affecting Windows components, particularly following a researcher's independent disclosures. The company asserts that uncoordinated disc… The Hacker News · May 28, 2026 High CVE-2026-33825CVE-2026-41091CVE-2026-45498zero-dayvulnerabilitydisclosure
Canadian man gets 33 years for using social media to coerce US children into sending sexual content Prosecutors said the man spent years using fake online identities to contact children and manipulate them into sending sexually explicit images and videos. The Record · May 28, 2026 High
threat-intel MyPillow listed on ransomware gang’s leak site, but denies it has been breached The Play ransomware gang claims to have stolen data from MyPillow, a US pillow manufacturer, and threatens to release it publicly. MyPillow denies the breach and claims it doesn't hold sensitive data internally, relying… Graham Cluley · May 28, 2026 High USransomwaredata-breachthird-party
threat-intel ThreatsDay Bulletin: Claude Security Plugin, Azure Priv-Esc, Kali365 MFA Bypass, FIFA Scams +15 More This Hacker News bulletin details several recent cyber threats, including a massive C2 infrastructure footprint discovered in the Middle East dominated by IoT botnets, a privilege escalation vulnerability in Azure Backup… The Hacker News · May 28, 2026 High CVE-2026-8398SAROUSc2supply-chainprivilege-escalation
threat-intel Chinese-speaking fraud gang could be stealing millions from 2026 World Cup fans A Chinese-speaking fraud gang, dubbed GHOST STADIUM, is impersonating FIFA's official website to steal credentials and payment details from fans seeking tickets for the 2026 World Cup. The operation, involving over 300 f… The Record · May 28, 2026 High CNUSCAfraudphishingworld cup