threat-intel ⚡ Weekly Recap: Exchange 0-Day, npm Worm, Fake AI Repo, Cisco Exploit and More This week’s security news highlights several active exploits and attacks, including a widespread vulnerability in on-prem Exchange Servers, a Cisco SD-WAN controller compromise attributed to UAT-8616, and a significant s… The Hacker News · May 18, 2026 High CVE-2026-42897CVE-2026-20182CVE-2026-20127USexchangesupply chainnpm
threat-intel The Boring Stuff Is Dangerous Now This article highlights a growing security challenge stemming from the widespread adoption of AI coding tools and the emergence of AI agents capable of exploiting obscure vulnerabilities. The combination creates a situat… Dark Reading · May 18, 2026 High aivulnerabilitycybersecurity
phishing How to Reduce Phishing Exposure Before It Turns into Business Disruption This article discusses the increasing risk posed by phishing attacks, particularly due to their ability to quickly escalate into significant business disruptions. It highlights the challenges SOC teams face in identifyin… The Hacker News · May 18, 2026 High USphishingsandboxcredential theft
threat-intel IT threat evolution in Q1 2026. Mobile statistics This Securelist report analyzes mobile threat trends in Q1 2026, based on Kaspersky Security Network data. The report highlights a decrease in overall attack volume, primarily due to reduced adware and RiskTool detection… Securelist · May 18, 2026 Medium USmobile malwarebanking trojancrypto stealer
ransomware IT threat evolution in Q1 2026. Non-mobile statistics In Q1 2026, Kaspersky products blocked over 343 million attacks, with significant ransomware activity including 2938 new ransomware variants and 77,000 ransomware attacks. Law enforcement actions disrupted the RAMP cyber… Securelist · May 18, 2026 High CVE-2026-20131POUNransomwarezero-dayraas
data-breach Boulevard of Broken Dreams: 2 Decades of Cyber Fails This Dark Reading article reflects on two decades of cybersecurity failures, highlighting recurring trends like data breaches, systemic vulnerabilities, and a growing sense of apathy among individuals regarding data secu… Dark Reading · May 18, 2026 High CVE-2023-34362USdata breachsql injectioncybersecurity
threat-intel Developer Workstations Are Now Part of the Software Supply Chain Recent attacks, including those mimicking the "mini Shai Hulud" and "Shai-Hulud 2.0" campaigns, have highlighted a growing threat: attackers targeting developer workstations to steal credentials and secrets from CI/CD pi… The Hacker News · May 18, 2026 High USdeveloper workstationssecretssupply chain
vulnerability Zero-Day Exploit Against Windows BitLocker A new zero-day exploit, dubbed YellowKey, has been discovered targeting Windows BitLocker encryption. The vulnerability allows attackers to bypass BitLocker's security measures with physical access to the affected device… Schneier on Security · May 18, 2026 High zero-dayencryptionbitlocker
threat-intel Ivanti, Fortinet, SAP, VMware, n8n Patch RCE, SQL Injection, Privilege Escalation Flaws Multiple vendors, including Ivanti, Fortinet, SAP, and VMware, have released security patches to address critical vulnerabilities across their products. These vulnerabilities include remote code execution, SQL injection,… The Hacker News · May 18, 2026 Critical CVE-2026-8043CVE-2026-44277CVE-2026-26083USUKremote code executionsql injectionprivilege escalation
vulnerability MiniPlasma Windows 0-Day Enables SYSTEM Privilege Escalation on Fully Patched Systems Chaotic Eclipse, the security researcher behind the recently disclosed Windows flaws, YellowKey and GreenPlasma, has released a proof-of-concept (PoC) for a Windows privilege escalation zero-day flaw that grants attacker… The Hacker News · May 18, 2026 Critical CVE-2020-17103CVE-2025-62221
threat-intel Four Malicious npm Packages Deliver Infostealers and Phantom Bot DDoS Malware Four npm packages have been identified as containing malicious code, including a clone of the Shai-Hulud worm. One package delivers a DDoS botnet (Phantom Bot), while the others function as infostealers, stealing sensiti… The Hacker News · May 18, 2026 High NOsupply chainnpminfostealer
threat-intel Can Laws Stop Deepfakes? South Korea Aims to Find Out This article reports on South Korea's proactive approach to combating deepfakes ahead of upcoming local elections. The country is implementing new laws, including Article 82-8 of the Public Official Election Act and the… Dark Reading · May 18, 2026 Medium KRdeepfakeaielection
other Friday Squid Blogging: Bigfin Squid This article is a blog post update from Schneier on Security, serving as a platform for discussing current security news. It directs readers to utilize the post to discuss relevant security stories and highlights the blo… Schneier on Security · May 16, 2026 Info blogsecuritynews
ransomware Congress Puts Heat on Instructure After Canvas Outage Following a high-profile cyberattack on its Canvas learning management system by the ShinyHunters group, Instructure is facing increased scrutiny from Congress. The House Committee on Homeland Security has requested a br… Dark Reading · May 15, 2026 High USedtechransomwaredata breach
threat-intel Cyber Pioneers Ponder Past as Prologue This Dark Reading article reflects on the platform's 20-year history, featuring insights from prominent cybersecurity leaders who contributed to its content. Robert Hansen discusses his early work on robot scraping and A… Dark Reading · May 15, 2026 High aivulnerabilitybug bounties
vulnerability CISA Adds One Known Exploited Vulnerability to Catalog CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-42897 Microsoft Exchange Server Cross-Site Scripting Vulnerability This type… CISA Advisories · May 15, 2026 Medium CVE-2026-42897
threat-intel Bypassing On-Camera Age-Verification Checks This article discusses a research paper detailing a new approach to zero-knowledge proofs that achieves perfect soundness, no interaction, and no setup, effectively addressing key limitations of existing zero-knowledge p… Schneier on Security · May 15, 2026 Medium zero-knowledgefirmwarehardware
malware Gremlin Stealer's Evolved Tactics: Hiding in Plain Sight With Resource Files This report details the evolving tactics of the Gremlin stealer malware, specifically a recent variant employing sophisticated obfuscation techniques to evade detection. The malware, which targets sensitive data like pay… Palo Alto Unit 42 · May 15, 2026 High USobfuscationanti-analysisresource section
threat-intel Why geopolitical turmoil is a gift for scammers, and how to stay safe Geopolitical turmoil is being exploited by scammers to increase the success of their fraudulent schemes. The article details a range of scams – from fake charities and romance fraud to investment scams and sensational fa… WeLiveSecurity · May 15, 2026 Medium IRMIscamsfraudcybercrime
threat-intel [Guest Diary] New Malware Libraries means New Signatures, (Fri, May 15th) This SANS Internet Storm Center diary details a new observation of the long-running mdrfckr campaign, a Shellbot associated with the Outlaw/Dota group. The key finding is the identification of a previously undocumented v… SANS Internet Storm Center · May 15, 2026 Medium USCNshellbotlibsshmdrfckr