vulnerability Critical FortiClient EMS Vulnerability Exploited in Fresh Attacks Fortinet rolled out hotfixes for the security defect in April, warning that it had been exploited in the wild as a zero-day and urging immediate patching. The post Critical FortiClient EMS Vulnerability Exploited in Fres… SecurityWeek · May 28, 2026 Critical CVE-2026-35616
policy Romanian gets 5 years in prison for hacking Oregon govt network A Romanian national was sentenced this week to 56 months in federal prison for breaking into an Oregon state government computer network and fr cyberattacks targeting dozens of other U.S. victims. BleepingComputer · May 28, 2026
vulnerability IBM and Red Hat Commit $5 Billion to Secure Open Source Supply Chains Under “Project Lightwell” Project Lightwell is designed to fix vulnerabilities without breaking what is already in production. The post IBM and Red Hat Commit $5 Billion to Secure Open Source Supply Chains Under “Project Lightwell” appeared first… SecurityWeek · May 28, 2026 High
threat-intel Focus on Cyber Insurance: How Quantifying Risk Is Reshaping Security This article discusses the evolving role of cyber insurance in reshaping cybersecurity strategy. The growth of cyber insurance is forcing organizations to quantify their risk exposure, moving beyond vague concerns about… Dark Reading · May 28, 2026 High cyber insuranceransomwarerisk quantification
Webinar: Why network incidents take too long to resolve Many organizations can detect network issues quickly, but investigations and coordination often slow incident resolution. This webinar explores how automation and AI-assisted workflows can help IT teams reduce delays and… BleepingComputer · May 28, 2026
vulnerability ABB EIBPORT View CSAF Summary ABB is aware of vulnerabilities in the product versions listed as affected in the advisory. A firmware update is available that resolves these privately reported vulnerabilities in the product versions… CISA Advisories · May 28, 2026 Medium CVE-2021-22291
supply-chain Supply Chain Compromises Impact Nx Console and GitHub Repositories CISA is responding to multiple supply chain attacks targeting developer ecosystems, specifically CI/CD pipelines. A malicious Nx Console VS Code extension compromised a GitHub employee, leading to data exfiltration, and… CISA Advisories · May 28, 2026 High CVE-2026-48027supply chainci/cdgithub
threat-intel New Edamame Platform Aims to Catch AI Coding Agents Going Off the Rails Edamame Technologies has developed a new runtime security system designed to detect and mitigate ‘code drift’ in AI coding agents. This drift, caused by agents deviating from their intended purpose, can lead to security… SecurityWeek · May 28, 2026 High FRaicoding agentsruntime security
vulnerability KMW CCTV Security Cameras This advisory details a critical vulnerability in KMW CCTV Security Cameras, specifically versions KM-IP521 (V4.04.91.230307) and KM-IP421 (V4.04.53.210416), allowing unauthorized access to camera feeds and settings via… CISA Advisories · May 28, 2026 Critical CVE-2026-5386WOcctvpasswordunauthenticated
threat-intel XCharge C6 This CISA advisory details a critical vulnerability series affecting XCharge C6 charging controllers worldwide. The vulnerabilities include a firmware validation flaw, a stack-based buffer overflow, and a misconfigured r… CISA Advisories · May 28, 2026 Critical CVE-2026-9037CVE-2026-9038CVE-2026-9039USfirmwarebuffer overflowremote management
vulnerability Fourth Frontier Frontier X Mobile Application, Frontier X2 A vulnerability has been identified in the Fourth Frontier Frontier X Mobile Application and Frontier X2 devices, allowing unauthorized access and control. Attackers could potentially read and modify patient data, trigge… CISA Advisories · May 28, 2026 High CVE-2026-5768USbleauthenticationdevice control
vulnerability CP Plus 8 Ch. Network Video Recorder A cross-site scripting (XSS) vulnerability has been identified in CP Plus 8 Ch. Network Video Recorder devices (CP-UNR-108F1 Hardware V1.0, CP-UNR-108F1 Web V3.2.7.128806, and CP-UNR-108F1 System V4.001.00AT009.0.R). Att… CISA Advisories · May 28, 2026 High CVE-2026-6824INNPAExsscwe-79firmware
vulnerability Jinan USR IOT Technology Limited (PUSR) USR-W610 RS232/485 to Wi-Fi/Ethernet Converter This advisory details a critical vulnerability in the Jinan USR IOT Technology Limited (PUSR) USR-W610 RS232/485 to Wi-Fi/Ethernet Converter, specifically version 7.03T.07. The device contains hardcoded administrative cr… CISA Advisories · May 28, 2026 Critical CVE-2026-7786CNfirmwarecredentialsiot
vulnerability ABB Busch-Welcome 2 Wire Door Opener Actuator A vulnerability has been identified in ABB Busch-Welcome 2 Wire Door Opener Actuators, specifically due to a default compatibility mode that allows for authentication bypass. This could enable an attacker to gain unautho… CISA Advisories · May 28, 2026 High CVE-2025-7705WOdoor lockphysical accessauthentication
threat-intel MacGregor Voyage Data Recorder (VDR) G4e A vulnerability has been identified in MacGregor Voyage Data Recorder (VDR) G4e devices, specifically versions prior to V5.250, due to the use of default credentials, weak password hashing, and hard-coded credentials. Th… CISA Advisories · May 28, 2026 High CVE-2026-42941CVE-2026-42951CVE-2026-44611DKdefault credentialsvdrfirmware
threat-intel New AI Usage Report: Enterprise AI Risk Is Heavily Concentrated Among a Small Group of AI "Power users" A LayerX Security report reveals that enterprise AI risk is heavily concentrated among a small group of ‘AI power users’ rather than being evenly distributed across all employees. The report highlights the fragmented nat… The Hacker News · May 28, 2026 High aienterprisegovernance
vulnerability Gitea Vulnerability Exposed 30,000 Deployments to Attacks The security flaw allowed attackers to pull private container images, exposing source code, credentials, and infrastructure. The post Gitea Vulnerability Exposed 30,000 Deployments to Attacks appeared first on SecurityWe… SecurityWeek · May 28, 2026 High CVE-2026-27771
threat-intel Raising the Cybersecurity Stakes: Ante up for the Agentic Era This article discusses the emerging "agentic era" in cybersecurity, driven by the increasing use of AI-powered tools and agents by both attackers and defenders. The rapid evolution of AI is creating a significant securit… SecurityWeek · May 28, 2026 High USaiagenticautomation
data-breach Carnival Cruise confirms data breach affecting nearly 6 million people Carnival Corporation confirmed a data breach impacting nearly 6 million individuals, attributed to the ShinyHunters extortion gang. The breach occurred through a social engineering attack targeting an employee’s account,… BleepingComputer · May 28, 2026 High social engineeringloyalty programdata theft
threat-intel 2026 World Cup: Discussing The World’s Biggest Game’s Attack Surface This analysis from Palo Alto Unit 42 assesses the significant cyber threat landscape surrounding the 2026 FIFA World Cup, highlighting the expanded attack surface created by the event's scale and complexity. The report i… Palo Alto Unit 42 · May 28, 2026 High USIRRUmega-eventcybersecuritythreat intelligence