threat-intel Claude Mythos AI Finds 10,000 High-Severity Flaws in Widely Used Software Anthropic’s Project Glasswing has identified over 10,000 high-severity vulnerabilities in widely used software, primarily through its Claude Mythos Preview AI model. This initiative focuses on proactively identifying and… The Hacker News · May 23, 2026 Critical CVE-2026-5194aivulnerabilitypatching
vulnerability ‘Underminr’ Vulnerability Lets Attackers Hide Malicious Connections Behind Trusted Domains The stealthy vulnerability impacts roughly 88 million domains and can be exploited to bypass DNS filtering and hide command-and-control traffic. The post ‘Underminr’ Vulnerability Lets Attackers Hide Malicious Connection… SecurityWeek · May 23, 2026 Medium
supply-chain Laravel-Lang PHP Packages Compromised to Deliver Cross-Platform Credential Stealer A sophisticated supply chain attack targeting Laravel-Lang PHP packages has been identified, involving the mass modification of Git tags to inject a cross-platform credential-stealing framework. The attacker leveraged co… The Hacker News · May 23, 2026 Critical USsupply-chaincredential-stealingphp
vulnerability LiteSpeed cPanel Plugin CVE-2026-48172 Exploited to Run Scripts as Root A maximum-severity security vulnerability impacting LiteSpeed User-End cPanel Plugin has come under active exploitation in the wild. The flaw, tracked as CVE-2026-48172 (CVSS score: 10.0), relates to an instance of incor… The Hacker News · May 23, 2026 Medium CVE-2026-48172CVE-2026-41940
vulnerability Drupal Core SQL Injection Bug Actively Exploited, Added to CISA KEV The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a recently patched critical security flaw impacting Drupal Core to its Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active… The Hacker News · May 23, 2026 Critical CVE-2026-9082
malware An Example of Stack String in High Level Language, (Sat, May 23rd) This article discusses a malware obfuscation technique called "stack strings," where strings are dynamically constructed on the stack at runtime rather than being stored as contiguous data in the binary. The example demo… SANS Internet Storm Center · May 23, 2026 Medium obfuscationstackassembly
threat-intel CISA to allow researchers to report vulnerabilities to exploited bugs catalog CISA has launched a new nomination form to allow external researchers, vendors, and industry partners to report exploited vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog. This initiative aims to enha… The Record · May 23, 2026 Medium USvulnerability disclosurethreat intelligencecybersecurity
Friday Squid Blogging: Regulating Squid Fishing in the South Pacific The South Pacific Regional Fisheries Management Organization (SPRFMO) needs to regulate squid fishing in the South Pacific. As usual, you can also use this squid post to talk about the security stories in the news that I… Schneier on Security · May 22, 2026
phishing FBI warns of Kali365 phishing-as-a-service after April Microsoft 365 attacks The FBI has issued a warning about Kali365, a Telegram-based phishing-as-a-service platform, following its use in April attacks targeting Microsoft 365 accounts. This service lowers the barrier to entry for cybercriminal… The Record · May 22, 2026 High USphishingoauthmfa
threat-intel Meta settles school district lawsuit claiming addictive design harmed students' mental health Meta has reached a settlement with the Breathitt County School District in Kentucky over claims that its platform designs were addictive and negatively impacted students’ mental health. This settlement marks the first of… The Record · May 22, 2026 Medium USsocial mediamental healthaddiction
threat-intel First VPN Dismantled in Global Takedown Over Use by 25 Ransomware Groups A global operation, dubbed Operation Saffron, led by France and the Netherlands, successfully dismantled the First VPN service, a virtual private network specifically designed for criminal use. The service was utilized b… The Hacker News · May 22, 2026 High USFRNLvpnransomwareanonymity
Netherlands seizes 800 servers of hosting firm enabling cyberattacks Financial crime investigators in the Netherlands (FIOD) arrested two men and seized 800 servers linked to a web hosting company that enabled cyberattacks, interference operations, and disinformation campaigns. BleepingComputer · May 22, 2026
vulnerability Drupal Vulnerability in Hacker Crosshairs Shortly After Disclosure Drupal is warning users that it has already seen attempts to exploit CVE-2026-9082 and security firms are seeing attacks against thousands of websites. The post Drupal Vulnerability in Hacker Crosshairs Shortly After Dis… SecurityWeek · May 22, 2026 Medium CVE-2026-9082
threat-intel Lawmakers Demand Answers as CISA Tries to Contain Data Leak A significant security breach occurred involving the intentional publication of sensitive CISA data, including AWS GovCloud keys and internal system credentials, by a CISA contractor. The exposed data, hosted on a public… Krebs on Security · May 22, 2026 High USgithubcredentialleak
phishing Ghostwriter Targets Ukraine Government Entities with Prometheus Phishing Malware The Ghostwriter threat actor, linked to Belarus, has been conducting a phishing campaign targeting Ukrainian government entities since the spring of 2026. This campaign utilizes lures related to the Prometheus online lea… The Hacker News · May 22, 2026 High UKBERUphishingmalwarecobalt strike
threat-intel Akamai Joins Growing Chorus of Vendors Betting Big on Secure Enterprise Browsers Akamai has acquired LayerX, a Tel Aviv-based startup, for $205 million to bolster its Zero Trust Network Access (ZTNA) portfolio. This move reflects a growing trend among cybersecurity vendors adding secure enterprise br… Dark Reading · May 22, 2026 Medium ILsecure browserztnasaas
threat-intel Former US execs plead guilty to aiding tech support scammers Two former executives of C.A. Cloud Attribution, Ltd. have pleaded guilty to aiding a years-long tech support fraud scheme that targeted individuals worldwide. The executives knowingly provided services to telemarketing… BleepingComputer · May 22, 2026 High USGBTNtech support fraudtelemarketingfraud
threat-intel Why the Supreme Court's Chatrie case could change the meaning of privacy in America The Supreme Court is considering a case, *Chatrie v. Google*, concerning the legality of geofence warrants, which allow law enforcement to obtain location history data from tech companies like Google. This case, the firs… The Record · May 22, 2026 Medium USgeofencingprivacyfourth amendment
ddos Canadian man arrested, charged for running KimWolf DDos botnet A Canadian man, Jacob Butler, has been arrested and charged with operating the KimWolf DDoS botnet, a significant online threat that disrupted numerous websites. Law enforcement agencies, in a coordinated international e… The Record · May 22, 2026 High CAUSGEddosbotnetcybercrime
threat-intel In Other News: Industrial Router Exploitation, CISA KEV Nomination Form, Gas Station Hacking This week’s cybersecurity news highlights several incidents, including Iranian hackers targeting US gas station tank monitor systems, a CISA contractor exposing sensitive credentials, a Huawei router vulnerability causin… SecurityWeek · May 22, 2026 High CVE-2024-9643CVE-2026-45401USLUiotcritical infrastructuresupply-chain