vulnerability Microsoft Patches Exploited UnDefend and RedSun Defender Zero-Days Microsoft released patches for two previously exploited zero-day vulnerabilities within its Defender security software. These vulnerabilities, CVE-2026-41091 and CVE-2026-45498, allowed for privilege escalation and denia… SecurityWeek · May 21, 2026 High CVE-2026-41091CVE-2026-45498CVE-2008-4250zero-dayprivilege escalationdenial of service
vulnerability Google’s Surge in Chrome Vulnerability Discoveries Likely Driven by AI More than 200 vulnerabilities patched in recent Chrome releases are marked as ‘reported by Google’. The post Google’s Surge in Chrome Vulnerability Discoveries Likely Driven by AI appeared first on SecurityWeek . SecurityWeek · May 21, 2026 Medium
supply-chain Supply Chain Security Crisis: Too Many Vulnerabilities, Too Little Visibility This article highlights a growing cybersecurity crisis driven by the rapid proliferation of vulnerabilities and the decreasing time it takes for attackers to exploit them. The analysis, primarily based on a Black Kite re… SecurityWeek · May 21, 2026 High USsupply chainvulnerabilityai
vulnerability Microsoft warns of new Defender zero-days exploited in attacks Microsoft has released security patches for two zero-day vulnerabilities, CVE-2026-41091 (RedSun) and CVE-2026-45498 (UnDefend), that are being actively exploited in attacks. These flaws, affecting Microsoft Defender and… BleepingComputer · May 21, 2026 High CVE-2026-41091CVE-2026-45498USzero-dayprivilege escalationdefender
vulnerability 9-Year-Old Linux Kernel Flaw Enables Root Command Execution on Major Distros A nine-year-old vulnerability in the Linux kernel, CVE-2026-46333, allows unprivileged users to execute commands as root, posing a significant risk to systems running affected distributions. The flaw stems from improper… The Hacker News · May 21, 2026 High CVE-2026-46333linuxkernelprivilege escalation
supply-chain GitHub links repo breach to TanStack npm supply-chain attack A supply-chain attack targeting GitHub originated with a malicious version of the Nx Console VS Code extension, facilitated by the TeamPCP threat group. The attack compromised over 3,800 internal repositories and extende… BleepingComputer · May 21, 2026 High USsupply-chainnpmvscode
threat-intel GitHub Internal Repositories Breached via Malicious Nx Console VS Code Extension GitHub experienced a breach of its internal repositories due to a compromised employee device utilizing a malicious VS Code extension, the Nx Console. The attack, orchestrated by TeamPCP, leveraged a supply chain vulnera… The Hacker News · May 21, 2026 High CVE-2026-45321CVE-2026-48027supply chainvscodeopen source
vulnerability Highly Critical Drupal Core Flaw Exposes PostgreSQL Sites to RCE Attacks Drupal has released security updates for a "highly critical" security vulnerability in Drupal Core that could be exploited by attackers to achieve remote code execution, privilege escalation, or information disclosure. T… The Hacker News · May 21, 2026 High CVE-2026-9082
threat-intel ISC Stormcast For Thursday, May 21st, 2026 https://isc.sans.edu/podcastdetail/9940, (Thu, May 21st) The SANS Internet Storm Center's Stormcast for May 21st, 2026 highlighted a concerning increase in several active threats across the internet landscape. The report detailed a rise in phishing campaigns, malicious email a… SANS Internet Storm Center · May 21, 2026 Medium phishingvulnerabilitythreat intelligence
threat-intel Smashing Security podcast #468: High-speed train hacks and homicidal lawnmowers This Smashing Security podcast episode discusses several ongoing cybersecurity incidents and investigations. The conversation touches on the ongoing Lazarus Group activities, including the upcoming ‘Cyberhack’ season, an… Graham Cluley · May 20, 2026 High NOTAnorth koreamalwarethreat intelligence
threat-intel Europe dismantles VPN service used by cybercriminals to hide ransomware attacks European law enforcement agencies successfully dismantled First VPN, a virtual private network (VPN) service heavily utilized by cybercriminals to mask their activities, including ransomware attacks and fraud schemes. Th… The Record · May 20, 2026 High FRNLUAvpncybercrimeransomware
Xi and Putin pledge closer cooperation on AI, cyberspace and satellite systems In a lengthy joint statement, Moscow and Beijing pledged closer cooperation on satellite internet technologies and joint work on software development and open-source initiatives — part of a broader effort to reduce relia… The Record · May 20, 2026 High
malware Ukraine identifies infostealer operator tied to 28,000 stolen accounts The Ukrainian cyberpolice, working in conjunction with U.S. law enforcement, has identified an 18-year-old man from Odesa suspected of running an infostealer malware operation targeting users of an online store in Califo… BleepingComputer · May 20, 2026 High
threat-intel Hackers bypass SonicWall VPN MFA due to incomplete patching Hackers exploited a vulnerability (CVE-2024-12802) in SonicWall Gen6 SSL-VPN appliances to bypass multi-factor authentication and deploy ransomware tools. The attackers gained access to networks within 30-60 minutes, lev… BleepingComputer · May 20, 2026 High CVE-2024-12802USvpnmfacredential theft
threat-intel Cyber Pros Can't Decide If AI Is a Good or a Bad Thing This article explores the complex and often contradictory opinions of cybersecurity professionals regarding the impact of artificial intelligence (AI) on the field. While many recognize AI's potential to improve security… Dark Reading · May 20, 2026 Medium aisocial engineeringdeepfakes
threat-intel GitHub Confirms Breach, 4K Internal Repos Stolen GitHub experienced a data breach where approximately 4,000 internal code repositories were stolen by the threat actor TeamPCP. The breach originated from a poisoned VS Code extension compromising an employee's device, an… Dark Reading · May 20, 2026 High vscodeopen sourcedeveloper tooling
malware Fake Android Apps Commit Carrier Billing Fraud for Premium Svcs. A coordinated campaign targeting Android users in Malaysia, Thailand, Romania, and Croatia has been identified, utilizing fake apps disguised as popular services to commit carrier billing fraud. The malware, employing te… Dark Reading · May 20, 2026 High MYTHROandroidcarrier billingfraud
data-breach Processes and Culture Top Reasons Behind Data Breaches This article examines the reasons behind persistent data breaches, particularly focusing on the issue of underreporting within organizations. The analysis, stemming from a Massachusetts state study, highlights weaknesses… Dark Reading · May 20, 2026 High USdata breachcyber hygienepassword security
threat-intel FTC warns 12 major tech firms of violating Take It Down Act The Federal Trade Commission (FTC) has issued warnings to twelve major tech companies, alleging non-compliance with the newly enacted Take It Down Act (TIDA). This law mandates platforms swiftly remove non-consensual int… The Record · May 20, 2026 High image abuseonline safetyprivacy
Microsoft Open-Sources RAMPART and Clarity to Secure AI Agents During Development Microsoft has unveiled two new open-source tools called RAMPART and Clarity to assist developers in better testing the security of artificial intelligence (AI) agents. RAMPART, short for Risk Assessment and Measurement P… The Hacker News · May 20, 2026 High