threat-intel Chinese APTs Share Linux Backdoor in Central Asia Telco Attacks This article details the discovery of "Showboat" (kworker), a Linux post-exploitation framework being shared among Chinese Advanced Persistent Threat (APT) groups, primarily Calypso and Red Lamassu. The malware has been… Dark Reading · May 21, 2026 Medium CHAFUKaptlinuxspyware
vulnerability Max severity Cisco Secure Workload flaw gives Site Admin privileges Cisco has released security updates to address a maximum-severity vulnerability in Secure Workload that allows attackers to gain Site Admin privileges. BleepingComputer · May 21, 2026 Medium CVE-2026-20223CVE-2026-20182
Selective HTTP Proxying in Linux, (Thu, May 21st) Recently, Rob wrote about a tool, Proxifier , that can intercept requests from specific processes. Proxifier is available for Windows, macOS, and Android. But I have not seen a generic Linux option yet. The advantage of… SANS Internet Storm Center · May 21, 2026 High
threat-intel Police seize “First VPN” service used in ransomware, data theft attacks Law enforcement agencies, in a coordinated international effort led by France and the Netherlands, have taken down the ‘First VPN’ service, a virtual private network used extensively by ransomware and data theft groups.… BleepingComputer · May 21, 2026 High UKFRNEvpncybercrimeransomware
threat-intel Content Delivery Exploit Opens Websites to Brand Hijacking This article details a new exploit, dubbed "Underminr," that leverages vulnerabilities in Internet infrastructure to allow attackers to hijack websites and conceal malicious activity. The technique, a successor to domain… Dark Reading · May 21, 2026 High USEUCNcdndnsdomain fronting
vulnerability Cisco Patches Critical Vulnerability in Secure Workload Insufficient validation and authentication in the Secure Workload’s REST APIs provide remote attackers with Site Admin privileges. The post Cisco Patches Critical Vulnerability in Secure Workload appeared first on Securi… SecurityWeek · May 21, 2026 Critical CVE-2026-20223
vulnerability ABB B&R Automation Studio ABB has issued a security advisory regarding vulnerabilities in its B&R Automation Studio software. The issues, stemming from SQLite versions, could lead to memory corruption and heap buffer overflows, potentially allowi… CISA Advisories · May 21, 2026 High CVE-2025-6965CVE-2025-3277CVE-2023-7104CHsqliteheap-overflowmemory-corruption
vulnerability ABB B&R Automation Runtime This CISA advisory details vulnerabilities within ABB B&R Automation Runtime versions prior to 6.4. Specifically, the System Diagnostic Manager (SDM) component is susceptible to reflected cross-site scripting (XSS) and i… CISA Advisories · May 21, 2026 High CVE-2025-3449CVE-2025-3448CVE-2025-11498CHxsscsvsdm
vulnerability Hitachi Energy GMS600 View CSAF Summary Hitachi Energy is aware of the vulnerability, CVE-2022-4304 in the OSS component OpenSSL, that affects the GMS600 versions that are listed below. An attacker successfully exploiting this vulnerability c… CISA Advisories · May 21, 2026 Medium CVE-2022-4304
vulnerability ABB B&R PCs This CISA advisory details a vulnerability (CVE-2023-45229 through CVE-2023-45237) affecting ABB B&R PCs, specifically versions of the EDK2 Network Package. The vulnerability, a critical out-of-bounds read, allows for re… CISA Advisories · May 21, 2026 Critical CVE-2023-45229CVE-2023-45230CVE-2023-45231uefidhcpv6remote code execution
vulnerability CISA Adds Two Known Exploited Vulnerabilities to Catalog CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2025-34291 Langflow Origin Validation Error Vulnerability CVE-2026-34926 Trend M… CISA Advisories · May 21, 2026 Medium CVE-2025-34291CVE-2026-34926
vulnerability ABB Terra AC Wallbox ABB has identified and addressed vulnerabilities in its Terra AC Wallbox product versions (<=1.8.33). These vulnerabilities, specifically related to heap and stack memory pollution due to improper handling of communicati… CISA Advisories · May 21, 2026 Medium CVE-2025-10504CVE-2025-12142CVE-2025-12143GLbluetoothfirmwarebuffer overflow
threat-intel ThreatsDay Bulletin: Linux Rootkits, Router 0-Day, AI Intrusions, Scam Kits and 25 New Stories This week's threat intelligence report highlights a diverse range of security incidents and vulnerabilities, including a significant Pwn2Own competition with substantial rewards, warnings about the risks of deploying age… The Hacker News · May 21, 2026 High CVE-2026-45793CVE-2026-8631UKUSCHzero-dayai securitysocial engineering
Ocean Emerges From Stealth With $28M for Agentic Email Security Platform The company has developed a platform that uses specialized AI agents to inspect every incoming message. The post Ocean Emerges From Stealth With $28M for Agentic Email Security Platform appeared first on SecurityWeek . SecurityWeek · May 21, 2026
Apple Rejected 2 Million App Store Submissions in 2025 for Security and Fraud Prevention The company blocked over 1.1 billion accounts and $2.2 billion in potentially fraudulent transactions. The post Apple Rejected 2 Million App Store Submissions in 2025 for Security and Fraud Prevention appeared first on S… SecurityWeek · May 21, 2026
other Flipper One project needs community help to build open Linux platform This article reports on Flipper Devices’ ambitious project, Flipper One, an open Linux platform designed for networking and hardware experimentation, utilizing an ARM-based Rockchip RK3576 SoC. The project aims to provid… BleepingComputer · May 21, 2026 Low linuxarmopen source
vulnerability Drupal Patches Highly Critical Vulnerability Exposing Websites to Hacking CVE-2026-9082 can be exploited without authentication for information disclosure, privilege escalation, and remote code execution. The post Drupal Patches Highly Critical Vulnerability Exposing Websites to Hacking appear… SecurityWeek · May 21, 2026 Critical CVE-2026-9082
vulnerability Microsoft Warns of Two Actively Exploited Defender Vulnerabilities Microsoft has disclosed two actively exploited vulnerabilities within its Defender security platform, CVE-2026-41091 and CVE-2026-45498, both of which allow for privilege escalation and denial-of-service attacks. These v… The Hacker News · May 21, 2026 High CVE-2026-41091CVE-2026-45498CVE-2026-33825defendervulnerabilityprivilege escalation
Socket Raises $60 Million at $1 Billion Valuation The company will invest in its firewall, certified patches, protection extensions, new products, and team expansion. The post Socket Raises $60 Million at $1 Billion Valuation appeared first on SecurityWeek . SecurityWeek · May 21, 2026
threat-intel When Identity is the Attack Path This article highlights the increasing risk of attacks leveraging compromised identity credentials within complex IT environments. A single, exposed access key, often due to cached credentials or excessive permissions, c… The Hacker News · May 21, 2026 High USidentitycredentialspermissions