vulnerability Max-severity flaw in ChromaDB for AI apps allows server hijacking A critical vulnerability (CVE-2026-45829) has been identified in the ChromaDB project, allowing unauthenticated attackers to execute arbitrary code on exposed servers. This flaw stems from a misplacement of authenticatio… BleepingComputer · May 19, 2026 Critical CVE-2026-45829apipythonfastapi
threat-intel What Will Make AI BOMs Real? This article discusses the growing momentum behind the adoption of AI Bills of Materials (AIBOMs) within the cybersecurity industry. Driven by standards development, commercial tool releases, regulatory pressure, and evo… Dark Reading · May 19, 2026 Medium USEUaisbommodel-training
vulnerability Verizon DBIR: Enterprises Face a Dangerous Vulnerability Glut Verizon's 2026 Data Breach Investigations Report (DBIR) highlights a concerning trend: the increasing prevalence of exploits in initial breaches, rising to 31% in 2025. Organizations struggle to keep pace with the massiv… Dark Reading · May 19, 2026 High NOvulnerabilitiespatch managementai
threat-intel Cybercrime service disrupted for abusing Microsoft platform to sign malware Microsoft disrupted a malware-as-a-service (MaaS) operation, dubbed Fox Tempest, that was abusing its Artifact Signing service to generate fraudulent code-signing certificates for ransomware gangs and other cybercriminal… BleepingComputer · May 19, 2026 High USCAmsaascode signingfraudulent certificates
threat-intel Windows Zero-Day Barrage Continues After Patch Tuesday A security researcher known as "Nightmare Eclipse" has disclosed six Windows zero-day vulnerabilities over the past six weeks, some of which are actively being exploited. These vulnerabilities, including YellowKey, Green… Dark Reading · May 19, 2026 High CVE-2020-17103CVE-2026-33825USzero-daybitlockerprivilege escalation
Discord rolls out end-to-end encryption on voice, video calls Discord announced that all voice and video calls through the communication platform are now protected by default with end-to-end encryption (E2EE). BleepingComputer · May 19, 2026
threat-intel CISA Exposes Secrets, Credentials in 'Private' Repo A public GitHub repository belonging to the Cybersecurity and Infrastructure Security Agency (CISA) was discovered containing 844MB of sensitive data, including plain-text passwords, authentication tokens, and cloud infr… Dark Reading · May 19, 2026 High USsecretsgithubcloud
malware Stealer Spoofs Google, Microsoft & Apple, Then Backdoors macOS A new macOS infostealer, dubbed SHub Reaper, is targeting users through fake WeChat and Miro installers, mimicking Google, Microsoft, and Apple to lure victims. This malware combines stealer and backdoor capabilities, ut… Dark Reading · May 19, 2026 High USmacosinfostealerbackdoor
FBI: Americans lost over $388 million to scams using crypto ATMs in 2025 The FBI says Americans have lost over $388 million last year to scams using cryptocurrency kiosks, also known as crypto ATMs or Bitcoin ATMs. BleepingComputer · May 19, 2026
threat-intel Huawei zero-day attack behind last year’s crash of Luxembourg's entire telecoms network A zero-day attack targeting a vulnerability in Huawei’s enterprise router software caused a three-hour nationwide telecoms outage in Luxembourg during July 2025. The attack, which exploited a previously undocumented beha… The Record · May 19, 2026 High CVE-2021-22359CVE-2022-29798LUzero-daydenied-servicenetwork
threat-intel UK regulator to require tech firms to tackle deepfakes, non-consensual intimate images The UK’s communications regulator, Ofcom, is implementing new rules requiring tech companies to actively combat the spread of non-consensual intimate images and deepfakes. This initiative utilizes hash matching technolog… The Record · May 19, 2026 High GBdeepfakenon-consensualintimate images
malware Trapdoor Android Ad Fraud Scheme Hit 659 Million Daily Bid Requests Using 455 Apps A new Android ad fraud scheme, dubbed Trapdoor, has been identified by HUMAN Threat Intelligence, utilizing 455 malicious apps and 183 C2 domains to generate 659 million daily bid requests. The operation leverages malver… The Hacker News · May 19, 2026 High USandroidad fraudmalvertising
Drupal to Patch Highly Critical Vulnerability at Risk of Quick Exploitation Drupal says attackers may develop an exploit for the vulnerability within hours or days. The post Drupal to Patch Highly Critical Vulnerability at Risk of Quick Exploitation appeared first on SecurityWeek . SecurityWeek · May 19, 2026
vulnerability TP-Link, Photoshop, OpenVPN, Norton VPN vulnerabilities Cisco Talos has disclosed multiple vulnerabilities across several popular products, including TP-Link routers, Adobe Photoshop, OpenVPN, and Norton VPN. These vulnerabilities range from buffer overflows and OS command in… Cisco Talos · May 19, 2026 Medium CVE-2026-30814CVE-2026-30815CVE-2026-30816routerbuffer overflowos command injection
threat-intel DirtyDecrypt PoC Released for Linux Kernel CVE-2026-31635 LPE Vulnerability A Proof-of-Concept (PoC) exploit, dubbed DirtyDecrypt, has been released for a Linux kernel vulnerability (CVE-2026-31635) allowing for local privilege escalation. The vulnerability, related to a missing copy-on-write (C… The Hacker News · May 19, 2026 High CVE-2026-31635CVE-2026-31431CVE-2026-43284linuxkernellpe
threat-intel Looking Back, Looking Forward: Digesting a Dynamic Bouillabaisse of Cyber Evolution This Dark Reading article reflects on the cybersecurity industry’s evolution over the past 20 years, highlighting key shifts like the move from perimeter defense to assume-breach strategies and the increasing complexity… Dark Reading · May 19, 2026 Medium cybersecuritycloud securityiot security
threat-intel ScadaBR CISA has issued an advisory regarding critical vulnerabilities in ScadaBR version 1.2.0, a SCADA system. The vulnerabilities include missing authentication, OS command injection, and CSRF, potentially allowing unauthenti… CISA Advisories · May 19, 2026 Critical CVE-2026-8602CVE-2026-8603CVE-2026-8604scadavulnerabilityremote code execution
vulnerability Kieback & Peter DDC Building Controllers This CISA advisory details a cross-site scripting (XSS) vulnerability affecting several versions of Kieback & Peter’s DDC Building Controllers. The vulnerability, CVE-2026-4293, allows an attacker to execute JavaScript c… CISA Advisories · May 19, 2026 Medium CVE-2026-4293AUATCNxssbuilding automationot
vulnerability ABB CoreSense HM and CoreSense M10 This advisory from CISA details a path traversal vulnerability (CVE-2025-3465) affecting ABB CoreSense HM and CoreSense M10 devices. Unauthenticated users could potentially gain access to restricted directories, leading… CISA Advisories · May 19, 2026 High CVE-2025-3465WOpath traversalcve-2025-3465abb
vulnerability Siemens RUGGEDCOM APE1808 Devices A buffer overflow vulnerability (CVE-2026-0300) has been identified in Siemens RUGGEDCOM APE1808 devices, specifically the User-ID™ Authentication Portal service within Palo Alto Networks PAN-OS software. This vulnerabil… CISA Advisories · May 19, 2026 High CVE-2026-0300DEbuffer overflowcaptive portalroot privilege