vulnerability Hitachi Energy GMS600 View CSAF Summary Hitachi Energy is aware of the vulnerability, CVE-2022-4304 in the OSS component OpenSSL, that affects the GMS600 versions that are listed below. An attacker successfully exploiting this vulnerability c… CISA Advisories · May 21, 2026 Medium CVE-2022-4304
vulnerability ABB Terra AC Wallbox ABB has identified and addressed vulnerabilities in its Terra AC Wallbox product versions (<=1.8.33). These vulnerabilities, specifically related to heap and stack memory pollution due to improper handling of communicati… CISA Advisories · May 21, 2026 Medium CVE-2025-10504CVE-2025-12142CVE-2025-12143GLbluetoothfirmwarebuffer overflow
vulnerability Google’s Surge in Chrome Vulnerability Discoveries Likely Driven by AI More than 200 vulnerabilities patched in recent Chrome releases are marked as ‘reported by Google’. The post Google’s Surge in Chrome Vulnerability Discoveries Likely Driven by AI appeared first on SecurityWeek . SecurityWeek · May 21, 2026 Medium
threat-intel ISC Stormcast For Thursday, May 21st, 2026 https://isc.sans.edu/podcastdetail/9940, (Thu, May 21st) The SANS Internet Storm Center's Stormcast for May 21st, 2026 highlighted a concerning increase in several active threats across the internet landscape. The report detailed a rise in phishing campaigns, malicious email a… SANS Internet Storm Center · May 21, 2026 Medium phishingvulnerabilitythreat intelligence
threat-intel Cyber Pros Can't Decide If AI Is a Good or a Bad Thing This article explores the complex and often contradictory opinions of cybersecurity professionals regarding the impact of artificial intelligence (AI) on the field. While many recognize AI's potential to improve security… Dark Reading · May 20, 2026 Medium aisocial engineeringdeepfakes
vulnerability CISA Adds Seven Known Exploited Vulnerabilities to Catalog CISA has added seven new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2008-4250 Microsoft Windows Buffer Overflow Vulnerability CVE-2009-1537 Micros… CISA Advisories · May 20, 2026 Medium CVE-2008-4250CVE-2009-1537CVE-2009-3459
threat-intel Agent AI is Coming. Are You Ready? Orchid Security’s 2026 Identity Gap Snapshot reveals a significant increase in ‘identity dark matter,’ primarily due to enterprises rapidly adopting Agent AI. This trend highlights vulnerabilities stemming from AI agents… The Hacker News · May 20, 2026 Medium USGBaiagent aiidentity management
threat-intel Caught Off Guard: Securing AI After It Hits Production This article highlights a critical security gap in the deployment of AI applications. It argues that security teams are often left out of the loop when AI use cases move to production, leading to reactive security measur… SecurityWeek · May 20, 2026 Medium aisecurityapplication security
threat-intel What It'll Take to Make AI BOMs Usable in a Modern Security Program This Dark Reading article discusses the nascent state of Artificial Intelligence Bills of Materials (AI BOMs) and the challenges security leaders face in utilizing them. While AI BOMs are emerging, most organizations lac… Dark Reading · May 20, 2026 Medium aibomsupply chain
threat-intel ISC Stormcast For Wednesday, May 20th, 2026 https://isc.sans.edu/podcastdetail/9938, (Wed, May 20th) The SANS Internet Storm Center's Stormcast for May 20th, 2026 highlighted several ongoing and emerging cyber threats. The broadcast detailed a concerning increase in phishing campaigns targeting financial institutions an… SANS Internet Storm Center · May 20, 2026 Medium phishingddosmalware
threat-intel What Will Make AI BOMs Real? This article discusses the growing momentum behind the adoption of AI Bills of Materials (AIBOMs) within the cybersecurity industry. Driven by standards development, commercial tool releases, regulatory pressure, and evo… Dark Reading · May 19, 2026 Medium USEUaisbommodel-training
vulnerability TP-Link, Photoshop, OpenVPN, Norton VPN vulnerabilities Cisco Talos has disclosed multiple vulnerabilities across several popular products, including TP-Link routers, Adobe Photoshop, OpenVPN, and Norton VPN. These vulnerabilities range from buffer overflows and OS command in… Cisco Talos · May 19, 2026 Medium CVE-2026-30814CVE-2026-30815CVE-2026-30816routerbuffer overflowos command injection
threat-intel Looking Back, Looking Forward: Digesting a Dynamic Bouillabaisse of Cyber Evolution This Dark Reading article reflects on the cybersecurity industry’s evolution over the past 20 years, highlighting key shifts like the move from perimeter defense to assume-breach strategies and the increasing complexity… Dark Reading · May 19, 2026 Medium cybersecuritycloud securityiot security
vulnerability Kieback & Peter DDC Building Controllers This CISA advisory details a cross-site scripting (XSS) vulnerability affecting several versions of Kieback & Peter’s DDC Building Controllers. The vulnerability, CVE-2026-4293, allows an attacker to execute JavaScript c… CISA Advisories · May 19, 2026 Medium CVE-2026-4293AUATCNxssbuilding automationot
vulnerability ZKTeco CCTV Cameras A vulnerability has been identified in ZKTeco CCTV cameras, specifically models utilizing the SSC335-GC2063-Face-0b77 Solution firmware, allowing unauthorized access to camera credentials and configuration information. T… CISA Advisories · May 19, 2026 Medium CVE-2026-8598CHcctvcameraauthentication
malware From PDB strings to MaaS: Tracking a commodity BadIIS ecosystem used by Chinese-speaking threat This report details the discovery of a commodity BadIIS malware variant, identified by its "demo.pdb" strings, being utilized by multiple Chinese-speaking cybercrime groups operating under a MaaS model. Developed by an a… Cisco Talos · May 19, 2026 Medium CNUSGBseomalware-as-a-serviceiis
threat-intel ISC Stormcast For Tuesday, May 19th, 2026 https://isc.sans.edu/podcastdetail/9936, (Tue, May 19th) The SANS Internet Storm Center's Stormcast for May 19th, 2026 highlighted a concerning increase in observed malicious activity across the internet. Specifically, the report detailed heightened phishing campaigns and a no… SANS Internet Storm Center · May 19, 2026 Medium phishingbotnetddos
vulnerability Multiples vulnérabilités dans les produits Mattermost (19 mai 2026) Multiple vulnerabilities have been discovered in Mattermost products, including desktop apps and server versions. These vulnerabilities could allow an attacker to elevate privileges, compromise data confidentiality, and… CERT-FR · May 19, 2026 Medium CVE-2026-3433CVE-2026-6046CVE-2026-6689vulnerabilitypatchsecurity
threat-intel Is 2026 the Year AI Bills of Materials Get Real? This Dark Reading article discusses the emerging importance of AI Bills of Materials (AI BOMs) as a critical component of managing risk associated with artificial intelligence systems. The article highlights the growing… Dark Reading · May 18, 2026 Medium aibomrisk management
threat-intel IT threat evolution in Q1 2026. Mobile statistics This Securelist report analyzes mobile threat trends in Q1 2026, based on Kaspersky Security Network data. The report highlights a decrease in overall attack volume, primarily due to reduced adware and RiskTool detection… Securelist · May 18, 2026 Medium USmobile malwarebanking trojancrypto stealer