vulnerability CISA gives feds 4 days to patch actively exploited cPanel plugin flaw The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has given U.S. federal agencies four days to secure their servers against a critical vulnerability in the LiteSpeed cPanel user-end plugin, which is active… BleepingComputer · May 27, 2026 Critical CVE-2026-48172
threat-intel Introducing EvidenceForge: Synthetic security logs that don’t look (as) fake Cisco Talos has released EvidenceForge, an open-source synthetic security log generator designed to address the limitations of existing synthetic data solutions. The tool utilizes a canonical event model, causal ordering… Cisco Talos · May 27, 2026 Medium synthetic datalog generationthreat hunting
apt LA Metro Cyberattack Linked to Iranian State-Sponsored Hackers The attack was claimed by a hacktivist group, but evidence showed it used infrastructure linked to Iranian government threat actors. The post LA Metro Cyberattack Linked to Iranian State-Sponsored Hackers appeared first… SecurityWeek · May 27, 2026
Dutch police arrests suspect linked to Ajax football club hack The Dutch National Police arrested a 35-year-old man suspected of hacking the professional football club Ajax Amsterdam (AFC Ajax) earlier this year. BleepingComputer · May 27, 2026
threat-intel What to consider before asking an AI chatbot for health advice This article warns against relying on AI chatbots for health advice, highlighting significant risks related to inaccurate information, data privacy, and potential misuse of sensitive medical data. The piece emphasizes th… WeLiveSecurity · May 27, 2026 Medium aihealthcareprivacy
threat-intel Windows 11 KB5089573 update released with performance improvements This article reports on the release of Windows 11 KB5089573, a non-security preview update for Windows 11 versions 25H2 and 24H2. The update focuses on performance improvements and reliability enhancements, including sha… BleepingComputer · May 27, 2026 Low windows 11performancereliability
threat-intel FBI: Hackers Sending Operatives in Person to Insert USB Drives and Steal Data The FBI has issued an alert regarding a new tactic employed by the Silent Ransom Group (SRG) involving physical intrusion to steal data from law firms and other organizations. SRG is impersonating IT support personnel,… SecurityWeek · May 27, 2026 High social engineeringremote accessusb drive
malware AI Chatbot Recommendations Redirect Users to Cryptojacking Malware Sites Microsoft has identified a cryptojacking campaign utilizing AI chatbots to recommend malicious download sites, a novel approach to social engineering. The campaign impersonates legitimate system utilities like CrystalDis… The Hacker News · May 27, 2026 High CVE-2025-33073USaicryptojackingsocial engineering
vulnerability CISA Urges Immediate Patching of Exploited LiteSpeed cPanel Plugin Zero-Day The Cybersecurity and Infrastructure Security Agency (CISA) has issued a critical alert urging immediate patching of a zero-day vulnerability (CVE-2026-48172) in the LiteSpeed cPanel plugin. This flaw allows for privileg… SecurityWeek · May 27, 2026 Critical CVE-2026-48172UScpanelzero-dayprivilege escalation
vulnerability Anthropic Releases New Claude Sandbox, Security Guidance Plugin The AI giant says the new plugin, which helps developers find vulnerabilities as they write code, has been used extensively internally. The post Anthropic Releases New Claude Sandbox, Security Guidance Plugin appeared fi… SecurityWeek · May 27, 2026
threat-intel ISC Stormcast For Wednesday, May 27th, 2026 https://isc.sans.edu/podcastdetail/9946, (Wed, May 27th) The SANS Internet Storm Center's Stormcast for May 27th, 2026 highlighted a concerning increase in several active threats across the internet landscape. The broadcast detailed ongoing campaigns involving phishing attacks… SANS Internet Storm Center · May 27, 2026 Medium phishingmalwareemail
vulnerability KnowledgeDeliver flaw exploited as a zero-day to install web shells Hackers exploited a critical zero-day vulnerability in a server running the KnowledgeDeliver learning management system (LMS) to deploy the Godzilla web shell. BleepingComputer · May 26, 2026 Critical CVE-2026-5426
supply-chain Feeding Frenzy: 'Megalodon' Malware Infects Thousands of GitHub Repos A six-hour malware campaign, dubbed 'Megalodon,' targeted over 5,500 GitHub repositories, injecting malicious commits containing credential-stealing payloads. The campaign, orchestrated by an unknown threat actor potenti… Dark Reading · May 26, 2026 High githubsupply-chainmalware
data-breach Charter confirms data breach after ShinyHunters extortion threat Charter Communications has confirmed a data breach following a threat from the ShinyHunters extortion group, resulting in the claimed theft of 40 million customer records. The breach originated from a voice phishing atta… BleepingComputer · May 26, 2026 High voice phishingdata breachsalesforce
threat-intel State Cyber Leaders Beg Congress for More Funding, Support This article reports on a congressional hearing where state cyber leaders urgently requested increased funding and support from the federal government, citing significant cuts to cybersecurity initiatives and a rise in s… Dark Reading · May 26, 2026 High UScybersecurityfundingthreat intelligence
threat-intel The Hackers Behind Shai-Hulud: Lucky or Skilled? The cybercrime group TeamPCP has been identified as a primary driver behind the Shai-Hulud worm, causing significant damage to the open-source ecosystem through exploiting vulnerabilities like React2Shell and misconfigur… Dark Reading · May 26, 2026 High USsupply-chainopen-sourcedeveloper-tooling
threat-intel For Enterprises, Security Remains Agentic AI's Biggest Challenge This article discusses the rapid adoption of OpenClaw, an agentic AI assistant, and the significant security challenges it presents to enterprises. Despite its popularity and endorsement from Nvidia, the software has bee… Dark Reading · May 26, 2026 High USagentic aiai securityopen source
vulnerability Microsoft Issues Out-of-Band SharePoint Patch Microsoft has released an out-of-band security patch to address a critical remote code execution vulnerability (CVE-2026-45659) in SharePoint Server. The flaw allows authenticated attackers to execute code without elevat… Dark Reading · May 26, 2026 Critical CVE-2026-45659CHremote code executionsharepointzero-day
phishing FBI warns of Kali365 phishing kit that breaks into Microsoft 365 accounts – no password required The FBI has issued a warning about Kali365, a phishing-as-a-service kit that allows attackers to compromise Microsoft 365 accounts without needing passwords, even when MFA is enabled. This kit leverages device code flow,… Graham Cluley · May 26, 2026 High USCAGBmfadevice-code-flowphishing
threat-intel MuddyWater Uses DLL Side-Loading in Espionage Campaign Targeting 9 Countries The MuddyWater hacking group, backed by Iran, has been conducting a sophisticated espionage campaign targeting organizations across nine countries on four continents during Q1 2026. The campaign utilizes DLL side-loading… The Hacker News · May 26, 2026 High KRSAAEdll-side-loadingcredential-stealingreconnaissance