vulnerability Trend Micro warns of Apex One zero-day exploited in the wild Japanese cybersecurity software company Trend Micro has addressed an Apex One zero-day vulnerability exploited in attacks targeting Windows systems. BleepingComputer · May 22, 2026 Critical CVE-2026-34926CVE-2025-54948CVE-2022-40139
threat-intel Verizon DBIR: Healthcare Fends Off Increased Social Engineering Attacks The Verizon 2026 Data Breach Investigations Report (DBIR) reveals a significant increase in social engineering attacks targeting the healthcare sector, driven by the adoption of generative AI. While ransomware and vendor… Dark Reading · May 22, 2026 High social engineeringaigenai
vulnerability Drupal: Critical SQL injection flaw now targeted in attacks Drupal is warning that hackers are attempting to exploit a "highly critical" SQL injection vulnerability announced earlier this week. BleepingComputer · May 22, 2026 Medium CVE-2026-9082
threat-intel Why Chargebacks are Just One Piece of the Fraud Puzzle This BleepingComputer article discusses the limitations of solely relying on chargeback rates to measure fraud performance. It highlights that focusing solely on chargebacks obscures a broader range of fraud impacts, inc… BleepingComputer · May 22, 2026 High account takeoverfraud detectionchargebacks
threat-intel Tracking Iranian APT Screening Serpens’ 2026 Espionage Campaigns This report from Palo Alto Unit 42 details ongoing espionage campaigns conducted by the Iran-nexus APT group Screening Serpens (UNC1549). The group, active since 2022, targeted entities in the U.S., Israel, the UAE, and… Palo Alto Unit 42 · May 22, 2026 High USIRILaptespionagesocial engineering
malware Canadian Man Arrested for Operating Kimwolf Botnet Jacob Butler, 23, has been arrested in Canada and US authorities are seeking his extradition on computer hacking charges. The post Canadian Man Arrested for Operating Kimwolf Botnet appeared first on SecurityWeek . SecurityWeek · May 22, 2026
vulnerability Ubiquiti patches three max severity UniFi OS vulnerabilities Ubiquiti Networks has released security patches for three critical vulnerabilities within its UniFi OS operating system, addressing potential remote exploitation risks. These flaws include improper access control, path t… BleepingComputer · May 22, 2026 Critical CVE-2026-34908CVE-2026-34909CVE-2026-34910UScommand injectionaccess controlpath traversal
supply-chain Megalodon GitHub Attack Targets 5,561 Repos with Malicious CI/CD Workflows A sophisticated cyberattack, dubbed Megalodon, has targeted over 5,500 GitHub repositories using malicious CI/CD workflows. The attacker leveraged throwaway accounts and forged author identities to exfiltrate sensitive d… The Hacker News · May 22, 2026 Critical IRILci/cdgithubsupply chain
threat-intel Making Vulnerable Drivers Exploitable Without Hardware - The BYOVD Perspective This article details a technique for evaluating the exploitability of Windows kernel mode drivers, focusing on the potential for BYOVD (Bring Your Own Vulnerability Driver) attacks. It highlights how vulnerabilities in d… The Hacker News · May 22, 2026 Medium USdriverbyovdkernel mode
threat-intel Paved With Intent: ROADtools and Nation-State Tactics in the Cloud This report details the use of ROADtools, an open-source toolkit primarily designed for red-teaming and research, by nation-state threat actors in cloud intrusions. The tool leverages legitimate Microsoft APIs to enumera… Palo Alto Unit 42 · May 22, 2026 High USentraidazureadtoken management
ransomware ‘First VPN’ Cybercrime Service Disrupted, Administrator Arrested The FBI says First VPN has been used by dozens of ransomware groups for network reconnaissance and intrusions. The post ‘First VPN’ Cybercrime Service Disrupted, Administrator Arrested appeared first on SecurityWeek . SecurityWeek · May 22, 2026 High
data-breach Cloud Atlas activity in the second half of 2025 and early 2026: new tools and a new payload The experienced Cloud Atlas group remains active, continuing to target government sectors and diplomatic entities in Russia and Belarus, employing both new and established techniques to maintain persistence in compromise… Securelist · May 22, 2026 High CVE-2018-0802
threat-intel US and Canada arrest and charge suspected Kimwolf botnet admin US and Canadian authorities have arrested Jacob Butler, an administrator of the KimWolf DDoS botnet, following a multi-national operation targeting several botnets. The botnet, which infected nearly two million devices g… BleepingComputer · May 22, 2026 High USCADEddosbotnetiot
malware Kimwolf DDoS Botnet Operator Arrested in Canada Over DDoS-for-Hire Attacks The U.S. Department of Justice (DoJ) on Thursday announced the arrest of a Canadian man in connection with allegedly operating a distributed denial-of-service (DDoS) botnet known as Kimwolf. In tandem, Jacob Butler (aka… The Hacker News · May 22, 2026
threat-intel Foul play: Fake FIFA websites target soccer fans looking for World Cup tickets, merchandise As the 2026 FIFA World Cup approaches, scammers are exploiting fans’ desire for tickets and merchandise by creating convincing fake websites mimicking FIFA’s official channels. These sites use tactics like typosquatting… WeLiveSecurity · May 22, 2026 High phishingsocial engineeringdomain spoofing
vulnerability TrendAI Patches Apex One Zero-Day Exploited in the Wild CVE-2026-34926 is a directory traversal flaw that can be exploited against the on-premise version of Apex One. The post TrendAI Patches Apex One Zero-Day Exploited in the Wild appeared first on SecurityWeek . SecurityWeek · May 22, 2026 Critical CVE-2026-34926
supply-chain Grafana Says Codebase and Other Data Stolen via TanStack Supply Chain Attack Hackers accessed Grafana’s GitHub repositories after a token compromised in the TanStack attack was not rotated. The post Grafana Says Codebase and Other Data Stolen via TanStack Supply Chain Attack appeared first on Sec… SecurityWeek · May 22, 2026
threat-intel China's Webworm Uses Discord, Microsoft Graphs to Hack EU Govts. A China-aligned Advanced Persistent Threat (APT) group known as Webworm has shifted its focus from Asia to targeting European governmental organizations, specifically in Belgium, Italy, Serbia, Spain, Poland, and South A… Dark Reading · May 22, 2026 High CHBEITaptdiscordmicrosoft graph
malware Cross-Platform NPM Stealer, (Fri, May 22nd) A cross-platform Node.js stealer has been discovered targeting Windows, macOS, and Linux systems. The malware, obfuscated to avoid detection, extracts sensitive data from various browsers and applications, including Chro… SANS Internet Storm Center · May 22, 2026 High USstealerobfuscatedbrowser
vulnerability CISA Adds Exploited Langflow and Trend Micro Apex One Vulnerabilities to KEV The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added two security flaws impacting Langflow and Trend Micro Apex One to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of a… The Hacker News · May 22, 2026 Medium CVE-2025-34291CVE-2026-34926