data-breach Ukraine probes teen suspect in cyber theft scheme targeting California online shoppers Ukrainian authorities are investigating an 18-year-old suspect linked to a cybercrime operation targeting California online shoppers. The scheme involved compromising nearly 30,000 customer accounts of a U.S.-based retai… The Record · May 20, 2026 High UKcybercrimedata-theftonline-shopping
Discord migrates all users to end-to-end encryption by default The move comes as other major social media platforms are killing end-to-end encryption for messaging. In recent months, Instagram and TikTok both announced they will no longer offer the feature. The Record · May 20, 2026
threat-intel Patch Now: Critical Flaw in OT Robot OS Gives Attackers Control A critical command injection vulnerability (CVE-2026-8153) was discovered in the operating system of Universal Robots’ PolyScope 5 collaborative robots. This flaw allows unauthenticated attackers to gain remote access an… Dark Reading · May 20, 2026 Critical CVE-2026-8153DEcommand injectionotrobotics
7-Eleven confirms breach after ShinyHunters claims The breach notification letters say 7-Eleven discovered the breach on April 8 and, after an investigation, determined that the cybercriminals gained access to “certain 7-Eleven systems used to store franchisee documents.… The Record · May 20, 2026
data-breach Grafana breach caused by missed token rotation after TanStack attack The Grafana data breach was caused by a single GitHub workflow token that slipped through the rotation process following the TanStack npm supply-chain attack last week. BleepingComputer · May 20, 2026 High
Quantum Bridge Raises $8 Million for Quantum-Safe Key Distribution Solution The new Series A funding round brings the total raised by Quantum Bridge to $16 million. The post Quantum Bridge Raises $8 Million for Quantum-Safe Key Distribution Solution appeared first on SecurityWeek . SecurityWeek · May 20, 2026
Microsoft Rolls Out Mitigations for ‘YellowKey’ BitLocker Bypass The exploitation is mitigated by preventing the FsTx Auto Recovery Utility from starting when the WinRE image launches. The post Microsoft Rolls Out Mitigations for ‘YellowKey’ BitLocker Bypass appeared first on Security… SecurityWeek · May 20, 2026 CVE-2026-45585
threat-intel AI-Powered App Attacks Are Faster, More Frequent and Harder to Stop This SecurityWeek article highlights a significant shift in app security driven by the rapid adoption of AI by cybercriminals. The report from Digital.ai indicates a dramatic increase in attacks against apps, moving from… SecurityWeek · May 20, 2026 High USGBaiagentic aiapp security
threat-intel Microsoft Takes Down Malware-Signing Service Behind Ransomware Attacks Microsoft disrupted a malware-signing-as-a-service (MSaaS) operation, dubbed OpFauxSign, led by the threat actor Fox Tempest, which was using its Artifact Signing system to distribute malware and ransomware. The operatio… The Hacker News · May 20, 2026 High USFRINmsaascode-signingmalware
On AI Security Good report : Executive Summary: Let’s say you wanted to make sure that your AI is secure. Can you just maximize the security and privacy benchmark and call it a day? Nope, because benchmarks don’t actually work for meas… Schneier on Security · May 20, 2026
threat-intel Identity Alone Isn't Enough: Why Device Security Has to Share the Load This article highlights the limitations of relying solely on identity verification in modern cybersecurity, arguing that it’s no longer sufficient against sophisticated attacks leveraging AI and phishing. The piece empha… BleepingComputer · May 20, 2026 High USzero trustmfadevice posture
threat-intel 1Password Teams With OpenAI to Stop AI Coding Agents From Leaking Credentials 1Password and OpenAI have partnered to create a new system, the Environments MCP Server, designed to protect sensitive credentials used by AI coding agents like OpenAI Codex. This integration addresses the growing risk o… SecurityWeek · May 20, 2026 High aicredentialssecrets
threat-intel Texas, Florida top list of states reporting millions of dollars lost through crypto ATMs A recent FBI report reveals a significant surge in financial losses linked to cryptocurrency ATMs across the United States, totaling $388 million in 2025. Texas and Florida topped the list of states experiencing these lo… The Record · May 20, 2026 High CHNEAUcryptocurrencyscamsfraud
vulnerability Anthropic Silently Patches Claude Code Sandbox Bypass Anthropic has addressed a vulnerability in its Claude Code network sandbox that could have allowed attackers to bypass security controls and potentially exfiltrate data. The vulnerability, discovered by researcher Aonan… SecurityWeek · May 20, 2026 High CVE-2025-66479sandboxprompt injectionsecurity
Drupal critical update to fix bug with high exploitation risk Drupal has announced a "core security release" scheduled for later today, warning that threat actors might develop exploits within hours of the update disclosure. BleepingComputer · May 20, 2026
threat-intel Webworm Deploys EchoCreep and GraphWorm Backdoors Using Discord and MS Graph API A China-aligned threat actor known as Webworm has expanded its arsenal with two new backdoors, EchoCreep and GraphWorm, utilizing Discord and the Microsoft Graph API for command-and-control communications. The group, act… The Hacker News · May 20, 2026 High CHRUGEdiscordmicrosoft graphrat
vulnerability CISA Adds Seven Known Exploited Vulnerabilities to Catalog CISA has added seven new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2008-4250 Microsoft Windows Buffer Overflow Vulnerability CVE-2009-1537 Micros… CISA Advisories · May 20, 2026 Medium CVE-2008-4250CVE-2009-1537CVE-2009-3459
vulnerability Schnieider Electric EcoStruxure Machine Expert HVAC (SEVD-2026-132-01) This CISA advisory details a vulnerability (SEVD-2026-132-01) in Schneider Electric’s Ecostruxure Machine Expert HVAC software, specifically versions prior to 1.10.0. The vulnerability, classified as CWE-312 (Cleartext S… CISA Advisories · May 20, 2026 High CVE-2026-6332WOcwe-312source codeconfidentiality
threat-intel Agent AI is Coming. Are You Ready? Orchid Security’s 2026 Identity Gap Snapshot reveals a significant increase in ‘identity dark matter,’ primarily due to enterprises rapidly adopting Agent AI. This trend highlights vulnerabilities stemming from AI agents… The Hacker News · May 20, 2026 Medium USGBaiagent aiidentity management
threat-intel GitHub Breached — Employee Device Hack Led to Exfiltration of 3,800+ Internal Repos GitHub experienced a breach originating from an employee device compromised by a poisoned Microsoft Visual Studio Code extension. The attacker exfiltrated over 3,800 internal repositories, facilitated by the threat actor… The Hacker News · May 20, 2026 High USILIRsupply chaincredential theftinfostealer