ransomware State of ransomware in 2026 Kaspersky’s 2026 ransomware threat report highlights a shift in the landscape, with ransomware attacks declining overall but becoming more sophisticated. Key trends include the emergence of post-quantum cryptography rans… Securelist · May 12, 2026 High USransomwarequantum cryptographyedr
vulnerability Vulnérabilité dans LibreNMS (12 mai 2026) A vulnerability in LibreNMS allows for remote code injection via cross-site scripting (XSS). This affects versions prior to 26.3.0, potentially enabling attackers to execute malicious code on vulnerable systems. Users ar… CERT-FR · May 12, 2026 Medium CVE-2026-2728xssvulnerabilityremote
threat-intel Inside AD CS Escalation: Unpacking Advanced Misuse Techniques and Tools This report from Palo Alto Unit 42 details how Active Directory Certificate Services (AD CS) is frequently exploited by both financially motivated ransomware groups and state-sponsored actors due to misconfigured templat… Palo Alto Unit 42 · May 11, 2026 High CVE-2022-26923NOad cscertificate issuanceprivilege escalation
threat-intel LLMs and Text-in-Text Steganography This article discusses attempts to hide text within LLMs using techniques like phonological changes and unconventional formatting (e.g., white text on white backgrounds). The author explores the limitations of these meth… Schneier on Security · May 11, 2026 Low UKsteganographyllmstempeset
threat-intel Eyes wide open: How to mitigate the security and privacy risks of smart glasses This article discusses the growing security and privacy risks associated with smart glasses, particularly due to their advanced tracking and recording capabilities combined with AI integration. The proliferation of these… WeLiveSecurity · May 11, 2026 High GEUKsurveillanceprivacyai
phishing One in eight UK workers has sold their company passwords, and bosses think it’s fine A recent survey revealed that approximately one in eight UK workers has disclosed their company login credentials, either directly or through a connection. This practice is compounded by a concerning lack of concern from… Graham Cluley · May 8, 2026 High GBpasswordssecurityuk
threat-intel Inside Department 4: Russia’s secret school for hackers A new investigation has revealed a secret faculty within Bauman Moscow State Technical University, known as ‘Department 4,’ which has been training students to become hackers for Russian military intelligence, the GRU. T… Graham Cluley · May 8, 2026 High RUUSrussian hackingspywaregru
Sri Lanka makes 37 arrests as it raids another scam centre You don't need to live near a scam compound for it to wreck your life. Americans lost $5.8 billion to crypto investment scams last year alone - and a raid in Sri Lanka this month shows exactly how the operations behind t… Graham Cluley · May 8, 2026
vulnerability CVE-2025-68670: discovering an RCE vulnerability in xrdp This report details a remote code execution (RCE) vulnerability, CVE-2025-68670, discovered in the Kaspersky xrdp server. The vulnerability exists within the xrdp_wm_parse_domain_information function due to a buffer over… Securelist · May 8, 2026 Critical CVE-2025-68670buffer_overflowrcexrdp
threat-intel Canvas Breach Disrupts Schools & Colleges Nationwide A cybercrime group, ShinyHunters, disrupted the Canvas education technology platform, impacting schools and colleges nationwide. The group defaced the login page with a ransom demand, threatening to leak data from 275 mi… Krebs on Security · May 8, 2026 High USeducationdata breachransomware
threat-intel Unplug your way to better code This article from Cisco Talos discusses a shift in threat intelligence strategy, focusing on tracking phone numbers used in sophisticated scam campaigns. Attackers are increasingly utilizing API-driven VoIP numbers for T… Cisco Talos · May 7, 2026 Medium voipscamphone numbers
threat-intel Exploits and vulnerabilities in Q1 2026 This Securelist report analyzes vulnerability trends and exploitation activity during Q1 2026, focusing on the expansion of exploit kits targeting Microsoft Office, Windows, and Linux operating systems. The report highli… Securelist · May 7, 2026 High CVE-2018-0802CVE-2017-11882CVE-2017-0199USvulnerabilityexploitationrce
malware Fake call logs, real payments: How CallPhantom tricks Android users This report details a widespread Android scam, dubbed CallPhantom, where fraudulent apps masquerading as call log retrieval services tricked users into paying for randomly generated data. Twenty-eight apps, collectively… WeLiveSecurity · May 7, 2026 Medium INscamfraudandroid
threat-intel Fixing the password problem is as easy as 123456 This article highlights a persistent problem in cybersecurity: the widespread use of easily guessable passwords, particularly ‘123456’ and variations. Despite industry advice and password policies, numerous websites, inc… WeLiveSecurity · May 7, 2026 High password_securityweak_passwordsdata_breach
vulnerability Threat Brief: Exploitation of PAN-OS Captive Portal Zero-Day for Unauthenticated Remote Code Execution Unit 42 details CVE-2026-0300, a buffer overflow vulnerability in the PAN-OS User-ID Authentication Portal. Read now for details. The post Threat Brief: Exploitation of PAN-OS Captive Portal Zero-Day for Unauthenticated… Palo Alto Unit 42 · May 7, 2026 Critical CVE-2026-0300
threat-intel Smashing Security podcast #466: Meta sees everything, Copy Fail, and a deepfake gets hired This Smashing Security podcast episode discusses ongoing cybersecurity challenges, including the persistent issues of AI-related bugs, social engineering attacks, and the dangers of deepfakes. A key topic is Meta’s smart… Graham Cluley · May 6, 2026 Medium UKaiprivacydeepfake
supply-chain OceanLotus suspected of using PyPI to deliver ZiChatBot malware Securelist researchers identified a PyPI supply chain attack orchestrated by OceanLotus, utilizing seemingly legitimate Python packages (uuid32-utils, colorinal, and termncolor) to deliver the previously unknown malware… Securelist · May 6, 2026 High UKsupply-chainpythonpypi
threat-intel From Stuxnet to ChatGPT: 20 News Events That Shaped Cyber This Dark Reading article reflects on key cybersecurity events from the past two decades, highlighting the evolution of cyber threats and their impact on businesses and critical infrastructure. The piece emphasizes how a… Dark Reading · May 6, 2026 High CVE-2017-0144CVE-2021-44228IRUSISindustrial control systemsnation-state actorsair gap
threat-intel Insights into the clustering and reuse of phone numbers in scam emails This article details Cisco Talos’s intelligence gathering on the increasing use of phone numbers in scam email campaigns. Attackers are leveraging API-driven VoIP providers like Sinch and Twilio to operate high-volume, d… Cisco Talos · May 6, 2026 High USUKvoipscamphishing
threat-intel Websites with an undefined trust level: avoiding the trap This Securelist article discusses the growing threat of websites with an "undefined trust level," which are not traditional phishing sites but still pose significant risks to users. These sites, often mimicking legitimat… Securelist · May 6, 2026 Medium AFLARUscamfraudonline scams