threat-intel AppOmni’s Marlin AI Brings Autonomous Investigation to SaaS Security This article discusses AppOmni’s new Marlin AI platform, designed to autonomously investigate security issues within Software-as-a-Service (SaaS) applications. The platform leverages AI to analyze configurations across n… SecurityWeek · May 26, 2026 Medium saasaiconfiguration
vulnerability ABB B&R Automation Runtime DoS Vulnerability in System Diagnostics Manager (SDM) This advisory details a denial-of-service (DoS) vulnerability in ABB B&R Automation Runtime versions prior to 6.3 and Q4.93, specifically within the System Diagnostics Manager (SDM) component. An unauthenticated network… CISA Advisories · May 26, 2026 High CVE-2025-3450WOdosdenial of serviceresource locking
threat-intel ABB AC500 V2 ABB has identified and addressed vulnerabilities in its AC500 V2 PLC firmware, specifically versions up to 2.5.3. An attacker could potentially access Modbus telegram fragments by sending unsupported function codes to th… CISA Advisories · May 26, 2026 Medium CVE-2025-7745WOmodbusplcfirmware
vulnerability Eppendorf BioFlo 320 This CISA advisory details a critical vulnerability in Eppendorf BioFlo 320 bioreactors due to a hard-coded VNC password, allowing unauthorized remote access and control. The vulnerability affects all versions of the Bio… CISA Advisories · May 26, 2026 Critical CVE-2026-7251WOvncpasswordremote access
supply-chain npm Adds 2FA-Gated Publishing and Package Install Controls Against Supply Chain Attacks npm has implemented a new staged publishing feature to bolster the security of its software supply chain, addressing concerns about malicious package releases. This system requires maintainers to verify releases with a t… The Hacker News · May 23, 2026 High supply-chain2fasecurity
threat-intel Lawmakers Demand Answers as CISA Tries to Contain Data Leak A significant security breach occurred involving the intentional publication of sensitive CISA data, including AWS GovCloud keys and internal system credentials, by a CISA contractor. The exposed data, hosted on a public… Krebs on Security · May 22, 2026 High USgithubcredentialleak
ddos Canadian man arrested, charged for running KimWolf DDos botnet A Canadian man, Jacob Butler, has been arrested and charged with operating the KimWolf DDoS botnet, a significant online threat that disrupted numerous websites. Law enforcement agencies, in a coordinated international e… The Record · May 22, 2026 High CAUSGEddosbotnetcybercrime
data-breach CISA Security Leak A contractor for CISA inadvertently exposed sensitive credentials and internal system details through a public GitHub repository. This included access to highly privileged AWS GovCloud accounts and information about CISA… Schneier on Security · May 22, 2026 Critical USgithubawscredentials
threat-intel Making Vulnerable Drivers Exploitable Without Hardware - The BYOVD Perspective This article details a technique for evaluating the exploitability of Windows kernel mode drivers, focusing on the potential for BYOVD (Bring Your Own Vulnerability Driver) attacks. It highlights how vulnerabilities in d… The Hacker News · May 22, 2026 Medium USdriverbyovdkernel mode
vulnerability Multiples vulnérabilités dans les produits Mattermost (22 mai 2026) Multiple vulnerabilities have been discovered in Mattermost products, allowing an attacker to bypass security policies and potentially lead to an unspecified security issue. These vulnerabilities affect various versions… CERT-FR · May 22, 2026 Medium CVE-2026-5139CVE-2026-6062CVE-2026-6517vulnerabilitysecuritypatch
threat-intel How CISOs Should Prep for Agentic-Ready AI BOMs This Dark Reading article discusses the evolving need for Artificial Intelligence Bills of Materials (AI BOMs) to address the unique security challenges posed by agentic AI systems. Traditional SBOMs focus on components… Dark Reading · May 21, 2026 Medium aibomagentic ai
vulnerability Google accidentally exposed details of unfixed Chromium flaw Google inadvertently exposed details of a persistent vulnerability in Chromium, allowing for remote code execution on devices. The flaw, initially reported in December 2022, remained unfixed for over two years, leading t… BleepingComputer · May 21, 2026 High remote-code-executionbrowservulnerability
threat-intel AI Agents Are Shifting Identity Security Budget Dynamics This Dark Reading article reports on a new Omdia research study highlighting a shift in cybersecurity budget dynamics driven by the increasing adoption of AI agents within enterprises. Identity teams are establishing ded… Dark Reading · May 21, 2026 Medium aiidentitysecurity
vulnerability ABB B&R Automation Runtime This CISA advisory details vulnerabilities within ABB B&R Automation Runtime versions prior to 6.4. Specifically, the System Diagnostic Manager (SDM) component is susceptible to reflected cross-site scripting (XSS) and i… CISA Advisories · May 21, 2026 High CVE-2025-3449CVE-2025-3448CVE-2025-11498CHxsscsvsdm
vulnerability ABB B&R Automation Studio ABB has issued a security advisory regarding vulnerabilities in its B&R Automation Studio software. The issues, stemming from SQLite versions, could lead to memory corruption and heap buffer overflows, potentially allowi… CISA Advisories · May 21, 2026 High CVE-2025-6965CVE-2025-3277CVE-2023-7104CHsqliteheap-overflowmemory-corruption
threat-intel 1Password Teams With OpenAI to Stop AI Coding Agents From Leaking Credentials 1Password and OpenAI have partnered to create a new system, the Environments MCP Server, designed to protect sensitive credentials used by AI coding agents like OpenAI Codex. This integration addresses the growing risk o… SecurityWeek · May 20, 2026 High aicredentialssecrets
vulnerability Anthropic Silently Patches Claude Code Sandbox Bypass Anthropic has addressed a vulnerability in its Claude Code network sandbox that could have allowed attackers to bypass security controls and potentially exfiltrate data. The vulnerability, discovered by researcher Aonan… SecurityWeek · May 20, 2026 High CVE-2025-66479sandboxprompt injectionsecurity
vulnerability Schnieider Electric EcoStruxure Machine Expert HVAC (SEVD-2026-132-01) This CISA advisory details a vulnerability (SEVD-2026-132-01) in Schneider Electric’s Ecostruxure Machine Expert HVAC software, specifically versions prior to 1.10.0. The vulnerability, classified as CWE-312 (Cleartext S… CISA Advisories · May 20, 2026 High CVE-2026-6332WOcwe-312source codeconfidentiality
threat-intel Agent AI is Coming. Are You Ready? Orchid Security’s 2026 Identity Gap Snapshot reveals a significant increase in ‘identity dark matter,’ primarily due to enterprises rapidly adopting Agent AI. This trend highlights vulnerabilities stemming from AI agents… The Hacker News · May 20, 2026 Medium USGBaiagent aiidentity management
threat-intel Caught Off Guard: Securing AI After It Hits Production This article highlights a critical security gap in the deployment of AI applications. It argues that security teams are often left out of the loop when AI use cases move to production, leading to reactive security measur… SecurityWeek · May 20, 2026 Medium aisecurityapplication security