FBI’s 2025 Internet Crime Report The 2025 Internet Crime Report was published a few weeks ago, but I only just saw it. Lots of interesting statistics. Press release . News articles . Schneier on Security · May 27, 2026
vulnerability MediaArea heap-based buffer overflow vulnerabilities Cisco Talos’ Vulnerability Discovery & Research team recently disclosed four vulnerabilities in MediaArea MediaInfoLib library. The vulnerabilities mentioned in this blog post have been patched by their respective vendor… Cisco Talos · May 27, 2026 High CVE-2026-25104CVE-2026-25713CVE-2026-28764
threat-intel Can you enforce strong Active Directory password rules without frustrating users? This article discusses the challenges of enforcing strong Active Directory (AD) password policies without frustrating users. It highlights the importance of using passphrases over complex passwords, blocking weak or comp… BleepingComputer · May 27, 2026 Medium active directorypassword policypassphrases
supply-chain Glassworm botnet disrupted after resilient C2 infrastructure takedown The Glassworm botnet, a supply-chain threat targeting developers, has been significantly disrupted following a coordinated takedown of its resilient command-and-control infrastructure. The botnet utilized a complex archi… BleepingComputer · May 27, 2026 High supply-chainbotnetc2
Dutch police arrest man over cyber breach at Ajax football club The suspect was detained in the central Dutch town of Buren, where law enforcement officers also searched his home and seized multiple digital storage devices, according to a statement released Tuesday by the Dutch Natio… The Record · May 27, 2026 High
apt Iranian intelligence service behind hack of LA transit system, researchers say Iranian intelligence service operatives, known as Ababil of Minab, were responsible for a significant cyberattack targeting the Los Angeles County Metropolitan Transportation Authority (LACMTA). The group, linked to the… The Record · May 27, 2026 High IRISTUirancyberattackcritical infrastructure
SecurityWeek to Host AI Risk Summit August 11-12 at the Ritz-Carlton, Half Moon Bay Now in its third year, the AI Risk Summit is the leading conference that brings together CISOs, security leaders, AI researchers, developers, policymakers, and enterprise risk professionals. The post SecurityWeek to Host… SecurityWeek · May 27, 2026
threat-intel Cybersecurity Evolution: How We Went From Perimeter Defense to AI-Native Security This Dark Reading article reflects on the evolution of the cybersecurity industry over the past 20 years, highlighting a shift from traditional perimeter defenses focused on antivirus and firewalls to a more complex land… Dark Reading · May 27, 2026 Medium cybersecuritycloud securityiot security
vulnerability CISA Adds Three Known Exploited Vulnerabilities to Catalog CISA has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-8398 Daemon Tools Lite Embedded Malicious Code Vulnerability CVE-2026-453… CISA Advisories · May 27, 2026 Medium CVE-2026-8398CVE-2026-45321CVE-2026-48027
vulnerability RevEng.AI Raises $15 Million to Hunt for Flaws and Backdoors in Software Binaries Using an AI model called BinNet, RevEng hunts vulnerabilities and backdoors in released software binaries. The post RevEng.AI Raises $15 Million to Hunt for Flaws and Backdoors in Software Binaries appeared first on Secu… SecurityWeek · May 27, 2026
threat-intel FBI warns of in-person data theft attacks from extortion gang The FBI has issued a warning about the Silent Ransom Group (SRG), an extortion gang now employing in-person data theft tactics targeting U.S. law firms. This shift involves social engineering, including phishing and impe… BleepingComputer · May 27, 2026 High USsocial engineeringphishingdata theft
threat-intel GlassWorm Malware Takedown Disrupts Developer Supply Chain Attack Infrastructure CrowdStrike, in collaboration with Google and Shadowserver Foundation, successfully disrupted the command-and-control infrastructure of the GlassWorm malware campaign, which targeted software developers through compromis… The Hacker News · May 27, 2026 High RUCIsupply chaindeveloperc2
threat-intel 3 SOC Steps that Shut Down Incident Risks Early This article from The Hacker News discusses three key steps for modern Security Operations Centers (SOCs) to proactively reduce incident risks. It emphasizes the shift from perimeter defense to minimizing operational deb… The Hacker News · May 27, 2026 High threat intelligencesocincident response
policy Romanian Hacker Sentenced to Prison in US for Selling Access to State Network Catalin Dragomir previously pleaded guilty to selling access to an Oregon state government office’s network. The post Romanian Hacker Sentenced to Prison in US for Selling Access to State Network appeared first on Securi… SecurityWeek · May 27, 2026
threat-intel 5 Steps to Managing Shadow AI Tools Without Slowing Down Employees This article discusses the growing ‘shadow AI’ gap – where employees use unapproved AI tools connected to corporate data without IT oversight. With 69% of organizations acknowledging this issue, it highlights the disconn… The Hacker News · May 27, 2026 Medium aishadow aioauth
Lastwall Raises $11.5 Million for Quantum-Resilient Identity Platform The new funding, led by BDC Capital’s StrongNorth Fund, will accelerate Lastwall’s North American expansion. The post Lastwall Raises $11.5 Million for Quantum-Resilient Identity Platform appeared first on SecurityWeek . SecurityWeek · May 27, 2026
phishing The Credential Crisis: How Stolen Credentials Defeat Modern Security As AI accelerates phishing, session hijacking, and credential abuse, security teams are racing to close the gap between attacker speed and defensive response. The post The Credential Crisis: How Stolen Credentials Defeat… SecurityWeek · May 27, 2026 Medium
supply-chain ‘SymJack’ Attack Turns AI Coding Agents Into Supply Chain Attack Delivery Systems The ‘SymJack’ attack leverages AI coding agents as a supply chain delivery mechanism, exploiting developer trust in automation to inject malicious code into CI pipelines. Attackers gain control by compromising coding age… SecurityWeek · May 27, 2026 High USaicoding agentssupply chain
threat-intel GlassWorm Botnet Disrupted The GlassWorm botnet, a persistent threat targeting open-source software developers, has been disrupted by a coordinated effort between CrowdStrike, Google, and the Shadowserver Foundation. The botnet utilized a multi-la… SecurityWeek · May 27, 2026 High RUbotnetopen sourcedeveloper
vulnerability Gitea Vulnerability Exposes Private Container Images without Authentication A significant vulnerability (CVE-2026-27771) has been identified in Gitea, a popular open-source Git repository hosting platform. The flaw allows unauthorized access to private container images, exposing sensitive data w… The Hacker News · May 27, 2026 High CVE-2026-27771CNUSDEcontainergitvulnerability