threat-intel Microsoft says it will not pursue security researchers after zero-day backlash Microsoft retracted a controversial blog post condemning security researchers who disclose zero-day vulnerabilities, stating it has no intention to pursue legal action against them. The initial statement, perceived as a… The Record · Jun 1, 2026 Medium UKzero-dayvulnerabilityresponsible disclosure
vulnerability Critical WP Maps Pro Flaw Actively Exploited to Create Admin Accounts A critical security flaw (CVE-2026-8732) in the WP Maps Pro WordPress plugin has been actively exploited to create administrator accounts on vulnerable websites. The vulnerability stems from a flaw in the plugin's tempor… The Hacker News · Jun 1, 2026 Critical CVE-2026-8732wordpresspluginvulnerability
threat-intel OpenClaw: risks for agent users and how to mitigate them This Securelist article highlights the significant security risks associated with OpenClaw, a popular AI agent ecosystem used globally for automating tasks. The system’s widespread adoption, combined with a large marketp… Securelist · Jun 1, 2026 High USai agentsautomationsupply chain
vulnerability WP Maps Pro bug exploited to create admin accounts on WordPress sites A critical vulnerability (CVE-2026-8732) in the WP Maps Pro WordPress plugin has been exploited by threat actors to create administrator accounts on affected websites. The flaw stems from an insecure AJAX endpoint that a… BleepingComputer · May 31, 2026 Critical CVE-2026-8732wordpresswp maps provulnerability
threat-intel Microsoft calls zero-day releases ‘never justifiable’ as researcher threatens to drop more Microsoft is responding to a weeks-long campaign by a pseudonymous researcher, ‘Nightmare Eclipse,’ who released uncoordinated zero-day vulnerabilities in Windows. The researcher, motivated by grievances against Microsof… The Record · May 29, 2026 High zero-dayvulnerabilitydisclosure
threat-intel ISC Stormcast For Friday, May 29th, 2026 https://isc.sans.edu/podcastdetail/9950, (Fri, May 29th) The SANS Internet Storm Center's Stormcast for May 29th, 2026 highlighted several ongoing and emerging cyber threats. The report detailed a range of observed malicious activities, including increased phishing attempts an… SANS Internet Storm Center · May 29, 2026 Medium phishingvulnerabilitythreat intelligence
vulnerability Multiples vulnérabilités dans les produits Mattermost (29 mai 2026) Multiple vulnerabilities have been discovered in Mattermost Server, allowing attackers to compromise data confidentiality and bypass security policies. These vulnerabilities, detailed in Mattermost security bulletins, re… CERT-FR · May 29, 2026 Medium CVE-2026-3472CVE-2026-4339vulnerabilitymattermostsecurity
vulnerability Critical Gogs RCE Vulnerability Lets Any Authenticated User Execute Arbitrary Code A critical remote code execution (RCE) vulnerability has been identified in Gogs, a popular self-hosted Git service, allowing authenticated users to execute arbitrary code. The flaw, detailed by Jonah Burgess, stems from… The Hacker News · May 28, 2026 Critical rcegitrebase
threat-intel Agentic AI Isn't Risky; the Way Orgs Deploy It Is This article highlights a critical cybersecurity risk associated with the rapid deployment of agentic AI, focusing on vulnerabilities stemming from poor software development practices rather than inherent flaws in the AI… Dark Reading · May 28, 2026 High USaiagentic-aivulnerability
vulnerability Microsoft Slams Public Zero-Day Disclosures Amid GitHub Researcher Account Removal Microsoft has strongly criticized the public disclosure of zero-day vulnerabilities affecting Windows components, particularly following a researcher's independent disclosures. The company asserts that uncoordinated disc… The Hacker News · May 28, 2026 High CVE-2026-33825CVE-2026-41091CVE-2026-45498zero-dayvulnerabilitydisclosure
vulnerability KMW CCTV Security Cameras This advisory details a critical vulnerability in KMW CCTV Security Cameras, specifically versions KM-IP521 (V4.04.91.230307) and KM-IP421 (V4.04.53.210416), allowing unauthorized access to camera feeds and settings via… CISA Advisories · May 28, 2026 Critical CVE-2026-5386WOcctvpasswordunauthenticated
vulnerability CP Plus 8 Ch. Network Video Recorder A cross-site scripting (XSS) vulnerability has been identified in CP Plus 8 Ch. Network Video Recorder devices (CP-UNR-108F1 Hardware V1.0, CP-UNR-108F1 Web V3.2.7.128806, and CP-UNR-108F1 System V4.001.00AT009.0.R). Att… CISA Advisories · May 28, 2026 High CVE-2026-6824INNPAExsscwe-79firmware
vulnerability Fourth Frontier Frontier X Mobile Application, Frontier X2 A vulnerability has been identified in the Fourth Frontier Frontier X Mobile Application and Frontier X2 devices, allowing unauthorized access and control. Attackers could potentially read and modify patient data, trigge… CISA Advisories · May 28, 2026 High CVE-2026-5768USbleauthenticationdevice control
threat-intel MacGregor Voyage Data Recorder (VDR) G4e A vulnerability has been identified in MacGregor Voyage Data Recorder (VDR) G4e devices, specifically versions prior to V5.250, due to the use of default credentials, weak password hashing, and hard-coded credentials. Th… CISA Advisories · May 28, 2026 High CVE-2026-42941CVE-2026-42951CVE-2026-44611DKdefault credentialsvdrfirmware
threat-intel ISC Stormcast For Thursday, May 28th, 2026 https://isc.sans.edu/podcastdetail/9948, (Thu, May 28th) The SANS Internet Storm Center's Stormcast for May 28th, 2026 highlighted a concerning increase in observed malicious activity across the internet. The report detailed several ongoing threats, including observed phishing… SANS Internet Storm Center · May 28, 2026 Medium phishingvulnerabilitythreat intelligence
threat-intel AI-Assisted Exploit Development Outpaces Scanner Detection Research from Cogent indicates that AI-assisted exploit development is dramatically accelerating, reducing exploit creation time from 125 days to just 0.5 days using large language models. This creates significant ‘visib… Dark Reading · May 27, 2026 Critical USaiexploitvulnerability
vulnerability Gitea Vulnerability Exposes Private Container Images without Authentication A significant vulnerability (CVE-2026-27771) has been identified in Gitea, a popular open-source Git repository hosting platform. The flaw allows unauthorized access to private container images, exposing sensitive data w… The Hacker News · May 27, 2026 High CVE-2026-27771CNUSDEcontainergitvulnerability
vulnerability CISA Urges Immediate Patching of Exploited LiteSpeed cPanel Plugin Zero-Day The Cybersecurity and Infrastructure Security Agency (CISA) has issued a critical alert urging immediate patching of a zero-day vulnerability (CVE-2026-48172) in the LiteSpeed cPanel plugin. This flaw allows for privileg… SecurityWeek · May 27, 2026 Critical CVE-2026-48172UScpanelzero-dayprivilege escalation
threat-intel For Enterprises, Security Remains Agentic AI's Biggest Challenge This article discusses the rapid adoption of OpenClaw, an agentic AI assistant, and the significant security challenges it presents to enterprises. Despite its popularity and endorsement from Nvidia, the software has bee… Dark Reading · May 26, 2026 High USagentic aiai securityopen source
threat-intel AppOmni’s Marlin AI Brings Autonomous Investigation to SaaS Security This article discusses AppOmni’s new Marlin AI platform, designed to autonomously investigate security issues within Software-as-a-Service (SaaS) applications. The platform leverages AI to analyze configurations across n… SecurityWeek · May 26, 2026 Medium saasaiconfiguration