threat-intel Anthropic: Mythos Detected 23,000 Potential Vulnerabilities Across 1,000 OSS Projects Anthropic’s Claude Mythos AI model has identified a massive number of vulnerabilities – estimated between 6,200 and 23,000 – across over 1,000 open-source software projects. Many of these vulnerabilities, particularly t… SecurityWeek · May 25, 2026 Critical UKaivulnerabilityopen source
data-breach Laravel-Lang Packages Poisoned for Malware Delivery Published within a 15-minute window, the malicious tags introduced backdoors to exfiltrate CI secrets. The post Laravel-Lang Packages Poisoned for Malware Delivery appeared first on SecurityWeek . SecurityWeek · May 25, 2026 Medium
data-breach DocketWise Data Breach Impacts 143,000 Hackers accessed names, addresses, Social Security numbers, financial information, and medical data from third-party partner repositories. The post DocketWise Data Breach Impacts 143,000 appeared first on SecurityWeek . SecurityWeek · May 25, 2026 High
supply-chain Over 5,500 GitHub Repositories Infected in ‘Megalodon’ Supply Chain Attack A sophisticated supply chain attack, dubbed Megalodon, has infected over 5,500 GitHub repositories by injecting malicious code into automated workflows. The attack leverages compromised versions of the Tiledesk package t… SecurityWeek · May 25, 2026 High supply chaingithubmalware
vulnerability ‘Underminr’ Vulnerability Lets Attackers Hide Malicious Connections Behind Trusted Domains The stealthy vulnerability impacts roughly 88 million domains and can be exploited to bypass DNS filtering and hide command-and-control traffic. The post ‘Underminr’ Vulnerability Lets Attackers Hide Malicious Connection… SecurityWeek · May 23, 2026 Medium
vulnerability Drupal Vulnerability in Hacker Crosshairs Shortly After Disclosure Drupal is warning users that it has already seen attempts to exploit CVE-2026-9082 and security firms are seeing attacks against thousands of websites. The post Drupal Vulnerability in Hacker Crosshairs Shortly After Dis… SecurityWeek · May 22, 2026 Medium CVE-2026-9082
threat-intel In Other News: Industrial Router Exploitation, CISA KEV Nomination Form, Gas Station Hacking This week’s cybersecurity news highlights several incidents, including Iranian hackers targeting US gas station tank monitor systems, a CISA contractor exposing sensitive credentials, a Huawei router vulnerability causin… SecurityWeek · May 22, 2026 High CVE-2024-9643CVE-2026-45401USLUiotcritical infrastructuresupply-chain
malware Canadian Man Arrested for Operating Kimwolf Botnet Jacob Butler, 23, has been arrested in Canada and US authorities are seeking his extradition on computer hacking charges. The post Canadian Man Arrested for Operating Kimwolf Botnet appeared first on SecurityWeek . SecurityWeek · May 22, 2026
ransomware ‘First VPN’ Cybercrime Service Disrupted, Administrator Arrested The FBI says First VPN has been used by dozens of ransomware groups for network reconnaissance and intrusions. The post ‘First VPN’ Cybercrime Service Disrupted, Administrator Arrested appeared first on SecurityWeek . SecurityWeek · May 22, 2026 High
vulnerability TrendAI Patches Apex One Zero-Day Exploited in the Wild CVE-2026-34926 is a directory traversal flaw that can be exploited against the on-premise version of Apex One. The post TrendAI Patches Apex One Zero-Day Exploited in the Wild appeared first on SecurityWeek . SecurityWeek · May 22, 2026 Critical CVE-2026-34926
supply-chain Grafana Says Codebase and Other Data Stolen via TanStack Supply Chain Attack Hackers accessed Grafana’s GitHub repositories after a token compromised in the TanStack attack was not rotated. The post Grafana Says Codebase and Other Data Stolen via TanStack Supply Chain Attack appeared first on Sec… SecurityWeek · May 22, 2026
vulnerability Cisco Patches Critical Vulnerability in Secure Workload Insufficient validation and authentication in the Secure Workload’s REST APIs provide remote attackers with Site Admin privileges. The post Cisco Patches Critical Vulnerability in Secure Workload appeared first on Securi… SecurityWeek · May 21, 2026 Critical CVE-2026-20223
Ocean Emerges From Stealth With $28M for Agentic Email Security Platform The company has developed a platform that uses specialized AI agents to inspect every incoming message. The post Ocean Emerges From Stealth With $28M for Agentic Email Security Platform appeared first on SecurityWeek . SecurityWeek · May 21, 2026
Apple Rejected 2 Million App Store Submissions in 2025 for Security and Fraud Prevention The company blocked over 1.1 billion accounts and $2.2 billion in potentially fraudulent transactions. The post Apple Rejected 2 Million App Store Submissions in 2025 for Security and Fraud Prevention appeared first on S… SecurityWeek · May 21, 2026
vulnerability Drupal Patches Highly Critical Vulnerability Exposing Websites to Hacking CVE-2026-9082 can be exploited without authentication for information disclosure, privilege escalation, and remote code execution. The post Drupal Patches Highly Critical Vulnerability Exposing Websites to Hacking appear… SecurityWeek · May 21, 2026 Critical CVE-2026-9082
Socket Raises $60 Million at $1 Billion Valuation The company will invest in its firewall, certified patches, protection extensions, new products, and team expansion. The post Socket Raises $60 Million at $1 Billion Valuation appeared first on SecurityWeek . SecurityWeek · May 21, 2026
vulnerability Microsoft Patches Exploited UnDefend and RedSun Defender Zero-Days Microsoft released patches for two previously exploited zero-day vulnerabilities within its Defender security software. These vulnerabilities, CVE-2026-41091 and CVE-2026-45498, allowed for privilege escalation and denia… SecurityWeek · May 21, 2026 High CVE-2026-41091CVE-2026-45498CVE-2008-4250zero-dayprivilege escalationdenial of service
vulnerability Google’s Surge in Chrome Vulnerability Discoveries Likely Driven by AI More than 200 vulnerabilities patched in recent Chrome releases are marked as ‘reported by Google’. The post Google’s Surge in Chrome Vulnerability Discoveries Likely Driven by AI appeared first on SecurityWeek . SecurityWeek · May 21, 2026 Medium
supply-chain Supply Chain Security Crisis: Too Many Vulnerabilities, Too Little Visibility This article highlights a growing cybersecurity crisis driven by the rapid proliferation of vulnerabilities and the decreasing time it takes for attackers to exploit them. The analysis, primarily based on a Black Kite re… SecurityWeek · May 21, 2026 High USsupply chainvulnerabilityai
Quantum Bridge Raises $8 Million for Quantum-Safe Key Distribution Solution The new Series A funding round brings the total raised by Quantum Bridge to $16 million. The post Quantum Bridge Raises $8 Million for Quantum-Safe Key Distribution Solution appeared first on SecurityWeek . SecurityWeek · May 20, 2026