vulnerability ‘Underminr’ Vulnerability Lets Attackers Hide Malicious Connections Behind Trusted Domains The stealthy vulnerability impacts roughly 88 million domains and can be exploited to bypass DNS filtering and hide command-and-control traffic. The post ‘Underminr’ Vulnerability Lets Attackers Hide Malicious Connection… SecurityWeek · May 23, 2026 Medium
vulnerability LiteSpeed cPanel Plugin CVE-2026-48172 Exploited to Run Scripts as Root A maximum-severity security vulnerability impacting LiteSpeed User-End cPanel Plugin has come under active exploitation in the wild. The flaw, tracked as CVE-2026-48172 (CVSS score: 10.0), relates to an instance of incor… The Hacker News · May 23, 2026 Medium CVE-2026-48172CVE-2026-41940
malware An Example of Stack String in High Level Language, (Sat, May 23rd) This article discusses a malware obfuscation technique called "stack strings," where strings are dynamically constructed on the stack at runtime rather than being stored as contiguous data in the binary. The example demo… SANS Internet Storm Center · May 23, 2026 Medium obfuscationstackassembly
threat-intel CISA to allow researchers to report vulnerabilities to exploited bugs catalog CISA has launched a new nomination form to allow external researchers, vendors, and industry partners to report exploited vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog. This initiative aims to enha… The Record · May 23, 2026 Medium USvulnerability disclosurethreat intelligencecybersecurity
threat-intel Meta settles school district lawsuit claiming addictive design harmed students' mental health Meta has reached a settlement with the Breathitt County School District in Kentucky over claims that its platform designs were addictive and negatively impacted students’ mental health. This settlement marks the first of… The Record · May 22, 2026 Medium USsocial mediamental healthaddiction
vulnerability Drupal Vulnerability in Hacker Crosshairs Shortly After Disclosure Drupal is warning users that it has already seen attempts to exploit CVE-2026-9082 and security firms are seeing attacks against thousands of websites. The post Drupal Vulnerability in Hacker Crosshairs Shortly After Dis… SecurityWeek · May 22, 2026 Medium CVE-2026-9082
threat-intel Akamai Joins Growing Chorus of Vendors Betting Big on Secure Enterprise Browsers Akamai has acquired LayerX, a Tel Aviv-based startup, for $205 million to bolster its Zero Trust Network Access (ZTNA) portfolio. This move reflects a growing trend among cybersecurity vendors adding secure enterprise br… Dark Reading · May 22, 2026 Medium ILsecure browserztnasaas
threat-intel Why the Supreme Court's Chatrie case could change the meaning of privacy in America The Supreme Court is considering a case, *Chatrie v. Google*, concerning the legality of geofence warrants, which allow law enforcement to obtain location history data from tech companies like Google. This case, the firs… The Record · May 22, 2026 Medium USgeofencingprivacyfourth amendment
vulnerability Drupal: Critical SQL injection flaw now targeted in attacks Drupal is warning that hackers are attempting to exploit a "highly critical" SQL injection vulnerability announced earlier this week. BleepingComputer · May 22, 2026 Medium CVE-2026-9082
threat-intel Making Vulnerable Drivers Exploitable Without Hardware - The BYOVD Perspective This article details a technique for evaluating the exploitability of Windows kernel mode drivers, focusing on the potential for BYOVD (Bring Your Own Vulnerability Driver) attacks. It highlights how vulnerabilities in d… The Hacker News · May 22, 2026 Medium USdriverbyovdkernel mode
vulnerability CISA Adds Exploited Langflow and Trend Micro Apex One Vulnerabilities to KEV The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added two security flaws impacting Langflow and Trend Micro Apex One to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of a… The Hacker News · May 22, 2026 Medium CVE-2025-34291CVE-2026-34926
vulnerability Cisco Patches CVSS 10.0 Secure Workload REST API Flaw Enabling Data Access Cisco has rolled out updates for a maximum-severity security flaw impacting Secure Workload that could allow an unauthenticated, remote attacker to access sensitive data. Tracked as CVE-2026-20223 (CVSS score: 10.0), the… The Hacker News · May 22, 2026 Medium CVE-2026-20223CVE-2026-20182
threat-intel ISC Stormcast For Friday, May 22nd, 2026 https://isc.sans.edu/podcastdetail/9942, (Fri, May 22nd) The SANS Internet Storm Center's Stormcast for May 22nd, 2026 highlighted a concerning increase in several active threats across the internet landscape. The report detailed a rise in phishing campaigns, malicious email a… SANS Internet Storm Center · May 22, 2026 Medium phishingvulnerabilitythreat-intelligence
vulnerability Multiples vulnérabilités dans les produits Mattermost (22 mai 2026) Multiple vulnerabilities have been discovered in Mattermost products, allowing an attacker to bypass security policies and potentially lead to an unspecified security issue. These vulnerabilities affect various versions… CERT-FR · May 22, 2026 Medium CVE-2026-5139CVE-2026-6062CVE-2026-6517vulnerabilitysecuritypatch
threat-intel How CISOs Should Prep for Agentic-Ready AI BOMs This Dark Reading article discusses the evolving need for Artificial Intelligence Bills of Materials (AI BOMs) to address the unique security challenges posed by agentic AI systems. Traditional SBOMs focus on components… Dark Reading · May 21, 2026 Medium aibomagentic ai
vulnerability macOS Kernel Memory Corruption Exploit A group used Anthropic’s Mythos AI model to help find a kernel memory corruption vulnerability and exploit on Apple’s M5. News article . Schneier on Security · May 21, 2026 Medium
threat-intel AI Agents Are Shifting Identity Security Budget Dynamics This Dark Reading article reports on a new Omdia research study highlighting a shift in cybersecurity budget dynamics driven by the increasing adoption of AI agents within enterprises. Identity teams are establishing ded… Dark Reading · May 21, 2026 Medium aiidentitysecurity
threat-intel UK plans for cybercrime law reform would protect almost no one, experts warn The UK government’s proposed reforms to the Computer Misuse Act 1990 are facing criticism from cybersecurity experts who believe they will offer minimal protection to researchers. The proposed changes would restrict the… The Record · May 21, 2026 Medium UKcybersecurityresearchlegal
threat-intel Chinese APTs Share Linux Backdoor in Central Asia Telco Attacks This article details the discovery of "Showboat" (kworker), a Linux post-exploitation framework being shared among Chinese Advanced Persistent Threat (APT) groups, primarily Calypso and Red Lamassu. The malware has been… Dark Reading · May 21, 2026 Medium CHAFUKaptlinuxspyware
vulnerability Max severity Cisco Secure Workload flaw gives Site Admin privileges Cisco has released security updates to address a maximum-severity vulnerability in Secure Workload that allows attackers to gain Site Admin privileges. BleepingComputer · May 21, 2026 Medium CVE-2026-20223CVE-2026-20182