threat-intel The Security Growth Platform: Why MSPs Are Moving Beyond vCISO Tools This article discusses the evolution of cybersecurity solutions for Managed Service Providers (MSPs), highlighting the shift from ‘vCISO’ platforms to ‘Security Growth Platforms’. The traditional vCISO tools were designe… The Hacker News · Jun 1, 2026 Medium mspcybersecuritysmb
vulnerability 19-Year-Old Linux Kernel Vulnerability Exposes Systems to Root Access proof-of-concept (PoC) exploit code has been released for the CIFSwitch flaw, which allows low-privileged users to escalate to root on vulnerable Linux systems. The post 19-Year-Old Linux Kernel Vulnerability Exposes Sys… SecurityWeek · Jun 1, 2026 Medium
vulnerability Recent Palo Alto Networks Vulnerability Exploited for Weeks Hackers began exploiting CVE-2026-0257, an authentication bypass in Palo Alto Networks PAN-OS, four days after public disclosure. The post Recent Palo Alto Networks Vulnerability Exploited for Weeks appeared first on Sec… SecurityWeek · Jun 1, 2026 Medium CVE-2026-0257
phishing ISC Stormcast For Monday, June 1st, 2026 https://isc.sans.edu/podcastdetail/9952, (Mon, Jun 1st) The SANS Internet Storm Center's June 1st, 2026 Stormcast reported a heightened level of online threats, primarily focused on phishing campaigns and malicious email activity. The report highlighted an increase in observe… SANS Internet Storm Center · Jun 1, 2026 Medium phishingemailthreat intelligence
malware Unidentified RAT pushes NetSupport RAT, (Mon, Jun 1st) Introduction SANS Internet Storm Center · Jun 1, 2026 Medium
vulnerability PAN-OS GlobalProtect Authentication Bypass (CVE-2026-0257) Under Active Exploitation Palo Alto Networks has warned that a recently disclosed medium-severity security flaw impacting PAN-OS and Prisma Access has come under active exploitation in the wild. The vulnerability, tracked as CVE-2026-0257 (CVSS s… The Hacker News · May 30, 2026 Medium CVE-2026-0257CVE-2026-35616
threat-intel Friday Squid Blogging: Another Squid This article, originating from Schneier on Security's 'Friday Squid Blogging' series, reports on ongoing activity attributed to a known threat actor nicknamed "Squid." The post serves as a platform for discussing recent… Schneier on Security · May 29, 2026 Medium threat actorcybersecurityintelligence
malware Dutch govt disrupts malware botnet with 17 million infected devices Dutch authorities have taken offline a massive botnet of 17 million devices and seized more than 200 servers at a local provider that supported the operation. BleepingComputer · May 29, 2026 Medium
threat-intel This month in security with Tony Anscombe – May 2026 edition In May 2026, Poland experienced cyberattacks targeting industrial control systems at water treatment facilities, mirroring attacks against the Polish energy sector. Simultaneously, a previously unknown group conducted a… WeLiveSecurity · May 29, 2026 Medium PLicscyberattacksai
threat-intel ISC Stormcast For Friday, May 29th, 2026 https://isc.sans.edu/podcastdetail/9950, (Fri, May 29th) The SANS Internet Storm Center's Stormcast for May 29th, 2026 highlighted several ongoing and emerging cyber threats. The report detailed a range of observed malicious activities, including increased phishing attempts an… SANS Internet Storm Center · May 29, 2026 Medium phishingvulnerabilitythreat intelligence
vulnerability Multiples vulnérabilités dans les produits Mattermost (29 mai 2026) Multiple vulnerabilities have been discovered in Mattermost Server, allowing attackers to compromise data confidentiality and bypass security policies. These vulnerabilities, detailed in Mattermost security bulletins, re… CERT-FR · May 29, 2026 Medium CVE-2026-3472CVE-2026-4339vulnerabilitymattermostsecurity
phishing BTMOB Android malware service generates custom phishing payloads An Android remote access trojan named BTMOB is offered to cybercriminals with a builder interface for generating malware payloads tailored to phishing lures. BleepingComputer · May 28, 2026 Medium
malware Analysis of a Year of Files Uploaded to DShield Sensors, (Wed, May 27th) Using the data collected over the past year and using Kibana these two ES|QL query to summarize the data, this shows the list of the most uploaded threat to two DShield sensors (local and cloud) over the past year. I hav… SANS Internet Storm Center · May 28, 2026 Medium
threat-intel Less panic patching, more precision This article from Cisco Talos discusses a shift in cybersecurity threat intelligence prioritization, moving away from solely relying on CVSS scores to incorporate exploit prediction and broader data enrichment. The core… Cisco Talos · May 28, 2026 Medium USDEvulnerability_managementepssgcve
vulnerability Hackers exploit FortiClient EMS flaw to push infostealer malware Hackers are exploiting an authentication bypass vulnerability (CVE-2026-35616) in FortiClient Enterprise Management Server (EMS) to deliver an undocumented credential stealer called EKZ. BleepingComputer · May 28, 2026 Medium CVE-2026-35616
vulnerability Threat Actors Exploit Critical FortiClient EMS Flaw to Deploy Credential Stealer Threat actors are continuing to exploit a critical, now-patched security flaw impacting FortiClient Endpoint Management Server (EMS) deployments to deliver credential-stealing malware. "The campaign abused trusted endpoi… The Hacker News · May 28, 2026 Medium CVE-2026-35616
data-breach New BTMOB Android Malware Enables Full Device Takeover Delivered via phishing lures, the malware combines financial theft with data exfiltration and remote access. The post New BTMOB Android Malware Enables Full Device Takeover appeared first on SecurityWeek . SecurityWeek · May 28, 2026 Medium
vulnerability ABB EIBPORT View CSAF Summary ABB is aware of vulnerabilities in the product versions listed as affected in the advisory. A firmware update is available that resolves these privately reported vulnerabilities in the product versions… CISA Advisories · May 28, 2026 Medium CVE-2021-22291
vulnerability DICOM, Pydicom, GDCM, and Orthanc: A technical tour of what really happens in the heap This white paper presents a concrete case study demonstrating the creation of a heap overflow vulnerability through the exploitation of the DICOM file format. Cisco Talos · May 28, 2026 Medium
threat-intel Nordic CISOs Handle Rising Cyber Threats Remarkably Well A recent report by Truesec found that CISOs in Nordic countries are not experiencing a rise in severe cybersecurity incidents, despite a global increase in cyber threats. This surprising trend is attributed to improved c… Dark Reading · May 28, 2026 Medium NOcybersecuritynordicthreat intelligence