vulnerability Cisco Patches CVSS 10.0 Secure Workload REST API Flaw Enabling Data Access Cisco has rolled out updates for a maximum-severity security flaw impacting Secure Workload that could allow an unauthenticated, remote attacker to access sensitive data. Tracked as CVE-2026-20223 (CVSS score: 10.0), the… The Hacker News · May 22, 2026 Medium CVE-2026-20223CVE-2026-20182
threat-intel ISC Stormcast For Friday, May 22nd, 2026 https://isc.sans.edu/podcastdetail/9942, (Fri, May 22nd) The SANS Internet Storm Center's Stormcast for May 22nd, 2026 highlighted a concerning increase in several active threats across the internet landscape. The report detailed a rise in phishing campaigns, malicious email a… SANS Internet Storm Center · May 22, 2026 Medium phishingvulnerabilitythreat-intelligence
vulnerability Multiples vulnérabilités dans les produits Mattermost (22 mai 2026) Multiple vulnerabilities have been discovered in Mattermost products, allowing an attacker to bypass security policies and potentially lead to an unspecified security issue. These vulnerabilities affect various versions… CERT-FR · May 22, 2026 Medium CVE-2026-5139CVE-2026-6062CVE-2026-6517vulnerabilitysecuritypatch
supply-chain Hackers steal patient and billing data from German hospitals via third-party provider German hospitals are facing a significant patient data breach following an attack targeting Unimed, a third-party billing service provider. The attackers accessed sensitive patient information, including names, addresses… The Record · May 21, 2026 High DEdata-breachpatient-datathird-party
threat-intel Belarus-linked hackers use fake training certificates to target Ukrainian officials A Belarus-linked hacking group, GhostWriter (UNC1151/Storm-0257), is conducting a new espionage campaign targeting Ukrainian government officials. The operation utilizes sophisticated phishing emails disguised as trainin… The Record · May 21, 2026 High UABYphishingmalwareespionage
threat-intel Alleged Kimwolf Botmaster ‘Dort’ Arrested, Charged in U.S. and Canada A 23-year-old man, identified as Jacob Butler (a.k.a. ‘Dort’), has been arrested in Canada and faces criminal charges for operating the Kimwolf DDoS botnet. The botnet, responsible for massive DDoS attacks and targeting… Krebs on Security · May 21, 2026 High CAUSddosbotnetiot
threat-intel How CISOs Should Prep for Agentic-Ready AI BOMs This Dark Reading article discusses the evolving need for Artificial Intelligence Bills of Materials (AI BOMs) to address the unique security challenges posed by agentic AI systems. Traditional SBOMs focus on components… Dark Reading · May 21, 2026 Medium aibomagentic ai
threat-intel Google API Keys Remain Active After Deletion This article details a significant vulnerability in Google Cloud Platform (GCP) API key deletion processes. Researcher Joe Leon of Aikido Security discovered that API keys can remain active for up to 23 minutes after del… Dark Reading · May 21, 2026 High USSGapi keysgcpauthentication
threat-intel Tech giants promise British regulator they will tweak platforms to protect kids online Following pressure from the UK’s Ofcom regulator, several major tech companies – including Roblox, Snapchat, Instagram (Meta), and TikTok – have pledged to implement changes to their platforms to better protect children… The Record · May 21, 2026 High UKgroomingchild_safetyalgorithms
vulnerability Google accidentally exposed details of unfixed Chromium flaw Google inadvertently exposed details of a persistent vulnerability in Chromium, allowing for remote code execution on devices. The flaw, initially reported in December 2022, remained unfixed for over two years, leading t… BleepingComputer · May 21, 2026 High remote-code-executionbrowservulnerability
threat-intel Two Americans plead guilty to assisting India-based tech support scam centers Two American men, Adam Young and Harrison Gevirtz, have pleaded guilty to assisting India-based tech support scam centers. They operated a U.S.-based tech firm, C.A. Cloud Attribution, providing services like call routin… The Record · May 21, 2026 High USINTNscamfraudtelemarketing
malware The art of being ungovernable This analysis focuses on a Cisco Talos report detailing the emergence of a sophisticated, multi-year-old BadIIS malware variant being utilized by Chinese-speaking cybercrime groups as part of a malware-as-a-service (MaaS… Cisco Talos · May 21, 2026 High CHmalware-as-a-serviceseo fraudtraffic hijacking
data-breach Defenders fall behind, as AI rewrites the rules of a data breach For almost 20 years, stolen credentials have been the most common route for attackers into organizations, according to the Verizon Data Breach Investigations Report (DBIR). But that's no longer the case. Read more in my… Graham Cluley · May 21, 2026 High
vulnerability macOS Kernel Memory Corruption Exploit A group used Anthropic’s Mythos AI model to help find a kernel memory corruption vulnerability and exploit on Apple’s M5. News article . Schneier on Security · May 21, 2026 Medium
threat-intel AI Agents Are Shifting Identity Security Budget Dynamics This Dark Reading article reports on a new Omdia research study highlighting a shift in cybersecurity budget dynamics driven by the increasing adoption of AI agents within enterprises. Identity teams are establishing ded… Dark Reading · May 21, 2026 Medium aiidentitysecurity
Apple blocked over $11 billion in App Store fraud in 6 years Apple revealed that it blocked over $11 billion in fraudulent App Store transactions over the last six years, more than $2.2 billion in potentially fraudulent App Store transactions in 2025 alone. BleepingComputer · May 21, 2026
threat-intel UK plans for cybercrime law reform would protect almost no one, experts warn The UK government’s proposed reforms to the Computer Misuse Act 1990 are facing criticism from cybersecurity experts who believe they will offer minimal protection to researchers. The proposed changes would restrict the… The Record · May 21, 2026 Medium UKcybersecurityresearchlegal
malware Showboat Linux Malware Hits Middle East Telecom with SOCKS5 Proxy Backdoor A new Linux malware, dubbed Showboat, has been used in a campaign targeting a telecommunications provider in the Middle East since at least 2022. The malware, developed by a China-linked threat actor group known as Calyp… The Hacker News · May 21, 2026 High CVE-2021-26855AFAZCHlinuxsocks5c2
ransomware Inside a Crypto Drainer: How to Spot it Before it Empties Your Wallet This article details the evolving landscape of cryptocurrency drainer operations, specifically focusing on the rise of "Drainer-as-a-Service" (DaaS) platforms like "Lucifer." These operations, rather than relying on dire… BleepingComputer · May 21, 2026 High USdrainerdaascryptocurrency
threat-intel Chinese hackers target telcos with new Linux, Windows malware A Chinese cyber-espionage group, known as Calypso (Red Lamassu), has been targeting telecommunications providers globally since mid-2022 with a dual-pronged malware campaign utilizing Showboat (Linux) and JMFBackdoor (Wi… BleepingComputer · May 21, 2026 High CHMIASlinuxwindowsespionage