threat-intel Russia conducting daily attacks on UK 'from seabed to cyberspace,' spy chief warns GCHQ Director Anne Keast-Butler warned of daily, sophisticated cyberattacks originating from Russia targeting the UK and Europe, spanning undersea cables to cyberspace. These attacks are focused on critical infrastructur… The Record · May 28, 2026 High UKRUCHcyberattackhybrid warfareintelligence
threat-intel ESET APT Activity Report Q4 2025–Q1 2026 ESET’s Q4 2025 – Q1 2026 APT Activity Report highlights a period of intense geopolitical activity driving advanced cyber espionage. China-aligned actors were mobilized to monitor maritime and energy developments, while I… WeLiveSecurity · May 28, 2026 High CHIRPOaptcyber espionagegeopolitics
threat-intel UK Cyberspying Chief Calls AI ‘an Unstoppable Force’ and Warns About Russia British intelligence chief Anne Keast-Butler warned of the escalating threat posed by Russia’s cyber activities, particularly the weaponization of artificial intelligence, and emphasized the urgent need for increased cyb… SecurityWeek · May 27, 2026 High UKRUCHartificial intelligencecybersecurityrussia
threat-intel State Cyber Leaders Beg Congress for More Funding, Support This article reports on a congressional hearing where state cyber leaders urgently requested increased funding and support from the federal government, citing significant cuts to cybersecurity initiatives and a rise in s… Dark Reading · May 26, 2026 High UScybersecurityfundingthreat intelligence
vulnerability Microsoft Issues Out-of-Band SharePoint Patch Microsoft has released an out-of-band security patch to address a critical remote code execution vulnerability (CVE-2026-45659) in SharePoint Server. The flaw allows authenticated attackers to execute code without elevat… Dark Reading · May 26, 2026 Critical CVE-2026-45659CHremote code executionsharepointzero-day
data-breach Lithuania investigates theft of 600,000 state registry records by foreign actor Lithuania is investigating a significant data breach affecting its state registry systems, resulting in the theft of approximately 600,000 records containing personal and property information. The breach exploited compro… The Record · May 26, 2026 High LTRUBYdata breachregistrycyberattack
vulnerability CISA orders feds to patch actively exploited Drupal vulnerability The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a directive requiring federal agencies to patch a critical SQL injection vulnerability (CVE-2026-9082) in the Drupal content management system.… BleepingComputer · May 26, 2026 Critical CVE-2026-9082USGBDEsql injectiondrupalcisa
threat-intel Dutch authorities arrest men suspected of providing infrastructure for Russian cyber operations Dutch authorities have arrested two IT entrepreneurs suspected of providing hosting infrastructure used in pro-Russian cyberattacks and disinformation campaigns. The investigation, led by the FIOD, uncovered a network in… The Record · May 25, 2026 High NLMDRUcyberattackdisinformationsanctions
threat-intel Netherlands Seizes 800 Servers, Arrests 2 for Aiding Cyberattacks Dutch authorities have seized over 800 servers and arrested two individuals – Andrey Nesterenko and Youssef Zinad – operating MIRhosting and WorkTitans, respectively, for facilitating cyberattacks and disinformation camp… Krebs on Security · May 25, 2026 High NLDKRUcyberattackddossanctions
threat-intel Lawmakers Demand Answers as CISA Tries to Contain Data Leak A significant security breach occurred involving the intentional publication of sensitive CISA data, including AWS GovCloud keys and internal system credentials, by a CISA contractor. The exposed data, hosted on a public… Krebs on Security · May 22, 2026 High USgithubcredentialleak
phishing Ghostwriter Targets Ukraine Government Entities with Prometheus Phishing Malware The Ghostwriter threat actor, linked to Belarus, has been conducting a phishing campaign targeting Ukrainian government entities since the spring of 2026. This campaign utilizes lures related to the Prometheus online lea… The Hacker News · May 22, 2026 High UKBERUphishingmalwarecobalt strike
threat-intel In Other News: Industrial Router Exploitation, CISA KEV Nomination Form, Gas Station Hacking This week’s cybersecurity news highlights several incidents, including Iranian hackers targeting US gas station tank monitor systems, a CISA contractor exposing sensitive credentials, a Huawei router vulnerability causin… SecurityWeek · May 22, 2026 High CVE-2024-9643CVE-2026-45401USLUiotcritical infrastructuresupply-chain
data-breach CISA Security Leak A contractor for CISA inadvertently exposed sensitive credentials and internal system details through a public GitHub repository. This included access to highly privileged AWS GovCloud accounts and information about CISA… Schneier on Security · May 22, 2026 Critical USgithubawscredentials
threat-intel US and Canada arrest and charge suspected Kimwolf botnet admin US and Canadian authorities have arrested Jacob Butler, an administrator of the KimWolf DDoS botnet, following a multi-national operation targeting several botnets. The botnet, which infected nearly two million devices g… BleepingComputer · May 22, 2026 High USCADEddosbotnetiot
threat-intel China's Webworm Uses Discord, Microsoft Graphs to Hack EU Govts. A China-aligned Advanced Persistent Threat (APT) group known as Webworm has shifted its focus from Asia to targeting European governmental organizations, specifically in Belgium, Italy, Serbia, Spain, Poland, and South A… Dark Reading · May 22, 2026 High CHBEITaptdiscordmicrosoft graph
threat-intel Belarus-linked hackers use fake training certificates to target Ukrainian officials A Belarus-linked hacking group, GhostWriter (UNC1151/Storm-0257), is conducting a new espionage campaign targeting Ukrainian government officials. The operation utilizes sophisticated phishing emails disguised as trainin… The Record · May 21, 2026 High UABYphishingmalwareespionage
threat-intel ThreatsDay Bulletin: Linux Rootkits, Router 0-Day, AI Intrusions, Scam Kits and 25 New Stories This week's threat intelligence report highlights a diverse range of security incidents and vulnerabilities, including a significant Pwn2Own competition with substantial rewards, warnings about the risks of deploying age… The Hacker News · May 21, 2026 High CVE-2026-45793CVE-2026-8631UKUSCHzero-dayai securitysocial engineering
vulnerability Microsoft Warns of Two Actively Exploited Defender Vulnerabilities Microsoft has disclosed two actively exploited vulnerabilities within its Defender security platform, CVE-2026-41091 and CVE-2026-45498, both of which allow for privilege escalation and denial-of-service attacks. These v… The Hacker News · May 21, 2026 High CVE-2026-41091CVE-2026-45498CVE-2026-33825defendervulnerabilityprivilege escalation
vulnerability Microsoft Patches Exploited UnDefend and RedSun Defender Zero-Days Microsoft released patches for two previously exploited zero-day vulnerabilities within its Defender security software. These vulnerabilities, CVE-2026-41091 and CVE-2026-45498, allowed for privilege escalation and denia… SecurityWeek · May 21, 2026 High CVE-2026-41091CVE-2026-45498CVE-2008-4250zero-dayprivilege escalationdenial of service
vulnerability Microsoft warns of new Defender zero-days exploited in attacks Microsoft has released security patches for two zero-day vulnerabilities, CVE-2026-41091 (RedSun) and CVE-2026-45498 (UnDefend), that are being actively exploited in attacks. These flaws, affecting Microsoft Defender and… BleepingComputer · May 21, 2026 High CVE-2026-41091CVE-2026-45498USzero-dayprivilege escalationdefender