vulnerability ZKTeco CCTV Cameras A vulnerability has been identified in ZKTeco CCTV cameras, specifically models utilizing the SSC335-GC2063-Face-0b77 Solution firmware, allowing unauthorized access to camera credentials and configuration information. T… CISA Advisories · May 19, 2026 Medium CVE-2026-8598CHcctvcameraauthentication
threat-intel The New Phishing Click: How OAuth Consent Bypasses MFA In February 2026, a phishing-as-a-service platform, EvilTokens, compromised over 340 Microsoft 365 organizations across five countries by exploiting OAuth consent screens. Attackers gained access to valid refresh tokens… The Hacker News · May 19, 2026 High USGBoauthconsentphishing
Laurie Anderson Is Quoting Me Not by name, but Laurie Anderson quotes me in one of the tracks of her new album: My favorite quote is from a cryptologist who said “If you think technology will solve your problems, you don’t understand technology and y… Schneier on Security · May 19, 2026
threat-intel Drupal to Release Urgent Core Security Updates on May 20, Sites Told to Prepare Drupal has announced an upcoming core security release scheduled for May 20, 2026, urging users to prepare and update their systems proactively. The release addresses potential vulnerabilities that could be exploited qui… The Hacker News · May 19, 2026 High drupalsecurityupdate
malware From PDB strings to MaaS: Tracking a commodity BadIIS ecosystem used by Chinese-speaking threat This report details the discovery of a commodity BadIIS malware variant, identified by its "demo.pdb" strings, being utilized by multiple Chinese-speaking cybercrime groups operating under a MaaS model. Developed by an a… Cisco Talos · May 19, 2026 Medium CNUSGBseomalware-as-a-serviceiis
vulnerability SEPPMail Secure E-Mail Gateway Vulnerabilities Enable RCE and Mail Traffic Access SEPPMail Secure E-Mail Gateway has been found to contain multiple critical vulnerabilities, including remote code execution (RCE) and unauthorized access to mail traffic. These flaws, detailed in a report by InfoGuard La… The Hacker News · May 19, 2026 Critical CVE-2026-2743CVE-2026-7864CVE-2026-44125remote code executionemail securitylog rotation
threat-intel The quest for greater tech independence The article explores the growing trend of nations, particularly in Europe, seeking greater tech sovereignty – the ability to independently control their digital infrastructure and technology supply chains – driven by con… WeLiveSecurity · May 19, 2026 High EUCHUStech sovereigntydigital independencesupply chain
supply-chain Compromised Nx Console 18.95.0 Targeted VS Code Developers with Credential Stealer A compromised version of the Nx Console VS Code extension (version 18.95.0) was used to steal developer credentials through a supply chain attack. The extension, initially introduced by a developer whose machine was comp… The Hacker News · May 19, 2026 High RUUSsupply chaincredential theftvscode
supply-chain Popular GitHub Action Tags Redirected to Imposter Commit to Steal CI/CD Credentials A GitHub Actions workflow, actions-cool/issues-helper, was compromised through an imposter commit attack, allowing threat actors to steal CI/CD credentials from running workflows. The attack leveraged malicious code inje… The Hacker News · May 19, 2026 High USgithubci/cdsupply-chain
supply-chain Mini Shai-Hulud Pushes Malicious AntV npm Packages via Compromised Maintainer Account A sophisticated supply chain attack, dubbed Mini Shai-Hulud, is targeting npm packages within the @antv ecosystem. The attack leverages a compromised maintainer account to inject malicious code – specifically a credentia… The Hacker News · May 19, 2026 High USsupply chainnpmcredential theft
threat-intel ISC Stormcast For Tuesday, May 19th, 2026 https://isc.sans.edu/podcastdetail/9936, (Tue, May 19th) The SANS Internet Storm Center's Stormcast for May 19th, 2026 highlighted a concerning increase in observed malicious activity across the internet. Specifically, the report detailed heightened phishing campaigns and a no… SANS Internet Storm Center · May 19, 2026 Medium phishingbotnetddos
vulnerability Multiples vulnérabilités dans les produits Mattermost (19 mai 2026) Multiple vulnerabilities have been discovered in Mattermost products, including desktop apps and server versions. These vulnerabilities could allow an attacker to elevate privileges, compromise data confidentiality, and… CERT-FR · May 19, 2026 Medium CVE-2026-3433CVE-2026-6046CVE-2026-6689vulnerabilitypatchsecurity
threat-intel Is 2026 the Year AI Bills of Materials Get Real? This Dark Reading article discusses the emerging importance of AI Bills of Materials (AI BOMs) as a critical component of managing risk associated with artificial intelligence systems. The article highlights the growing… Dark Reading · May 18, 2026 Medium aibomrisk management
threat-intel Microsoft Exchange Zero-Day Under Attack, No Patch Available A zero-day vulnerability (CVE-2026-42897) affecting Microsoft Exchange Outlook Web Access (OWA) is under active exploitation, allowing attackers to compromise mailboxes through cross-site scripting (XSS). Despite Microso… Dark Reading · May 18, 2026 High CVE-2026-42897BEzero-dayxssexchange
threat-intel 'Claw Chain' Vulnerabilities Threaten OpenClaw Deployments New vulnerabilities, dubbed 'Claw Chain,' have been discovered in the OpenClaw open-source AI agent framework, posing a significant risk to deployments. These four flaws – CVE-2026-44112, CVE-2026-44115, CVE-2026-44118,… Dark Reading · May 18, 2026 Critical CVE-2026-44112CVE-2026-44115CVE-2026-44118aiagentvulnerability
threat-intel CISA Admin Leaked AWS GovCloud Keys on Github A contractor for CISA inadvertently exposed highly privileged AWS GovCloud credentials and internal CISA system information via a public GitHub repository. The repository contained plaintext passwords, cloud keys, and lo… Krebs on Security · May 18, 2026 High USgithubawscredentials
supply-chain TeamPCP Supply Chain Campaign: Activity Through 2026-05-17, (Mon, May 18th) The TeamPCP supply chain campaign intensified significantly on May 17th, 2026, marked by the confirmed compromise of a Checkmarx Jenkins plugin and the emergence of a new Mini Shai-Hulud worm. This campaign targeted npm… SANS Internet Storm Center · May 18, 2026 Critical CVE-2026-45321CVE-2025-29927CVE-2025-55182GBILIRsupply-chainnpmpypi
threat-intel Shai-Hulud Worm Clones Spread After Code Release The release of Shai-Hulud source code by TeamPCP, a financially motivated threat actor, has triggered the spread of clones targeting software developers and the open-source ecosystem. This incident highlights a new attac… Dark Reading · May 18, 2026 High supply-chainopen-sourcedeveloper
threat-intel INTERPOL Operation Ramz Disrupts MENA Cybercrime Networks with 201 Arrests INTERPOL’s Operation Ramz was a coordinated international effort involving 13 MENA countries to combat cybercrime, resulting in 201 arrests and the disruption of phishing and malware operations. The operation targeted in… The Hacker News · May 18, 2026 High AEALBHcybercrimephishingmalware
threat-intel Fuel Tank Breaches Expand Scope of Iran's Cyber Offensive This article reports on a cyber offensive by Iran targeting fuel tank systems in the United States, exploiting insecure automatic tank gauge (ATG) systems exposed online. The attacks, which involved manipulating displaye… Dark Reading · May 18, 2026 High USIRcyberattackcritical infrastructuregeopolitics