supply-chain Over 320 NPM Packages Hit by Fresh Mini Shai-Hulud Supply Chain Attack A compromised maintainer account was used to publish malicious package versions across the @antv namespace. The post Over 320 NPM Packages Hit by Fresh Mini Shai-Hulud Supply Chain Attack appeared first on SecurityWeek . SecurityWeek · May 20, 2026
threat-intel Caught Off Guard: Securing AI After It Hits Production This article highlights a critical security gap in the deployment of AI applications. It argues that security teams are often left out of the loop when AI use cases move to production, leading to reactive security measur… SecurityWeek · May 20, 2026 Medium aisecurityapplication security
vulnerability Exploit released for new PinTheft Arch Linux root escalation flaw A publicly available exploit, dubbed ‘PinTheft’, has been released for a Linux kernel vulnerability allowing local attackers to gain root privileges on Arch Linux systems. The vulnerability, residing in the RDS module, w… BleepingComputer · May 20, 2026 High linuxprivilege escalationrds
supply-chain Typosquatting Is No Longer a User Problem. It's a Supply Chain Problem This article highlights a significant shift in cyberattack tactics, moving away from traditional phishing and towards a supply chain attack leveraging AI-generated lookalike domains and compromised third-party scripts. T… The Hacker News · May 20, 2026 Critical USsupply-chainbrowserai
threat-intel Real-World ICS Security Tales From the Trenches This article details real-world incidents involving industrial control systems (ICS) security vulnerabilities, highlighting the challenges of securing OT environments beyond traditional IT security practices. Two separat… SecurityWeek · May 20, 2026 High IRUSicsotlateral movement
malware Tracking TamperedChef Clusters via Certificate and Code Reuse This report details ongoing activity clusters closely resembling the TamperedChef (EvilAI) malware campaign, which involves trojanized productivity software like PDF editors and calendars. These campaigns utilize malicio… Palo Alto Unit 42 · May 20, 2026 High USpersistencecommand and controltrojan
Virtual Event Today: Threat Detection & Incident Response Summit Don't miss this virtual event as we explore how to cut through alert fatigue, leverage AI and unified platforms to accelerate investigations, and apply actionable threat intelligence. The post Virtual Event Today: Threat… SecurityWeek · May 20, 2026
GitHub Confirms Hack Impacting 3,800 Internal Repositories The TeamPCP hacking group accessed the repositories after a GitHub employee installed a poisoned VS Code extension. The post GitHub Confirms Hack Impacting 3,800 Internal Repositories appeared first on SecurityWeek . SecurityWeek · May 20, 2026
vulnerability How an image could compromise your Mac: understanding an ExifTool vulnerability (CVE-2026-3102) This article details a vulnerability (CVE-2026-3102) in ExifTool for macOS, allowing an attacker to execute arbitrary commands by injecting malicious data into the FileCreateDate metadata field. The vulnerability stems f… Securelist · May 20, 2026 Critical CVE-2026-3102CVE-2021-22204exiftoolmacosmetadata
threat-intel Webworm: New burrowing techniques This blog post details the evolving tactics of Webworm, a China-aligned APT group, particularly their activity in 2025. Webworm has shifted away from traditional backdoors in favor of more sophisticated techniques, inclu… WeLiveSecurity · May 20, 2026 High CVE-2017-7692BEITSEdiscordmicrosoft graph apic&c
ransomware FBI warns students and staff that ShinyHunters may come knocking after Canvas breach The FBI issued an advisory regarding the ShinyHunters extortion gang following a breach of an online Learning Management System used by educational institutions. Instructure, the provider of Canvas, quietly agreed to pay… Graham Cluley · May 20, 2026 High USransomwarelmseducation
vulnerability Microsoft Releases Mitigation for YellowKey BitLocker Bypass CVE-2026-45585 Exploit This report details a zero-day vulnerability, dubbed ‘YellowKey,’ affecting Windows 11 and Server 2025, allowing attackers to bypass BitLocker Device Encryption through a USB drive exploit. Microsoft has released a mitig… The Hacker News · May 20, 2026 High CVE-2026-45585USbitlockerwinrezero-day
supply-chain GitHub confirms breach of 3,800 repos via malicious VSCode extension GitHub experienced a breach affecting approximately 3,800 internal repositories after an employee installed a malicious VS Code extension. The incident is linked to a broader supply chain attack by TeamPCP, who are deman… BleepingComputer · May 20, 2026 High supply chainvscodeextension
vulnerability Microsoft shares mitigation for YellowKey Windows zero-day Microsoft has released mitigation steps for a newly disclosed Windows zero-day vulnerability, dubbed YellowKey, which allows unauthorized access to BitLocker-protected drives. The vulnerability was initially revealed by… BleepingComputer · May 20, 2026 High CVE-2026-33825CVE-2026-45585zero-daybitlockerwinre
threat-intel Interpol's 'Operation Ramz' Pioneers Cross-Region Collabs in Middle East Interpol’s ‘Operation Ramz’ was a five-month collaborative law enforcement effort involving 13 countries in the Middle East and North Africa (MENA) region to combat cybercrime. The operation resulted in the identificatio… Dark Reading · May 20, 2026 High AEEGIQcybercrimeregionalcollaboration
Grafana GitHub Breach Exposes Source Code via TanStack npm Attack Grafana Labs, on May 19, 2026, said an investigation into its recent breach found no evidence of customer production systems or operations being compromised. It said the scope of the incident is limited to the Grafana La… The Hacker News · May 20, 2026 High
threat-intel GitHub investigates internal repositories breach claimed by TeamPCP GitHub is investigating a breach of its internal repositories following a claim by the TeamPCP hacker group, who gained access to approximately 4,000 private code repositories. The incident highlights a vulnerability wit… BleepingComputer · May 20, 2026 High supply-chaingithubmalware
threat-intel What It'll Take to Make AI BOMs Usable in a Modern Security Program This Dark Reading article discusses the nascent state of Artificial Intelligence Bills of Materials (AI BOMs) and the challenges security leaders face in utilizing them. While AI BOMs are emerging, most organizations lac… Dark Reading · May 20, 2026 Medium aibomsupply chain
threat-intel ISC Stormcast For Wednesday, May 20th, 2026 https://isc.sans.edu/podcastdetail/9938, (Wed, May 20th) The SANS Internet Storm Center's Stormcast for May 20th, 2026 highlighted several ongoing and emerging cyber threats. The broadcast detailed a concerning increase in phishing campaigns targeting financial institutions an… SANS Internet Storm Center · May 20, 2026 Medium phishingddosmalware
vulnerability Verizon DBIR 2026: Vulnerability Exploitation Overtakes Credential Theft as Top Breach Vector Verizon’s 2026 Data Breach Investigations Report (DBIR) reveals that vulnerability exploitation has become the leading cause of data breaches, surpassing credential theft. The report highlights a concerning trend of slow… SecurityWeek · May 20, 2026 High USvulnerability managementpatchinggen-ai