vulnerability ABB Ability Camera Connect This CISA advisory details a vulnerability in ABB Ability Camera Connect, specifically related to the VLC media player component (version 2.2.4 and earlier). The vulnerability, a heap-based buffer overflow due to an inte… CISA Advisories · May 26, 2026 Medium CVE-2024-46461CVE-2023-47360CVE-2023-47359WOheap_overflowinteger_underflowvulnerability
threat-intel Open Source DockSec Uses AI to Cut Through Vulnerability Noise in Docker Images This article reports on the development of DockSec, an open-source tool designed to address the challenge of vulnerability detection in Docker images. The tool utilizes an LLM to correlate findings from multiple vulnerab… SecurityWeek · May 26, 2026 Medium dockervulnerabilityai
threat-intel CERT-In Mandates 12-Hour Patching for Internet-Facing Flaws Amid AI-Assisted Attacks CERT-In has mandated a 12-hour patching window for critical internet-facing vulnerabilities, driven by the increasing use of AI by threat actors to automate attacks. This response is intended to address the accelerated a… The Hacker News · May 26, 2026 High INaicybersecurityvulnerability
vulnerability CISA orders feds to patch actively exploited Drupal vulnerability The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a directive requiring federal agencies to patch a critical SQL injection vulnerability (CVE-2026-9082) in the Drupal content management system.… BleepingComputer · May 26, 2026 Critical CVE-2026-9082USGBDEsql injectiondrupalcisa
threat-intel Anthropic’s restricted Claude Mythos model may be coming to Claude Code Anthropic is preparing to release a new AI model called Mythos, initially designed for advanced computer security tasks. The model demonstrates a concerning ability to autonomously develop cyberattacks, raising significa… BleepingComputer · May 25, 2026 High aicybersecurityvulnerability
vulnerability Ghost CMS Vulnerability Exploited to Hack Over 700 Websites A previously disclosed SQL injection vulnerability (CVE-2026-26980) in the Ghost CMS has been actively exploited by multiple threat actors, leading to the compromise of over 700 websites. The attackers leveraged this vul… SecurityWeek · May 25, 2026 High CVE-2026-26980USGBsql injectionghost cmsvulnerability
threat-intel Anthropic: Mythos Detected 23,000 Potential Vulnerabilities Across 1,000 OSS Projects Anthropic’s Claude Mythos AI model has identified a massive number of vulnerabilities – estimated between 6,200 and 23,000 – across over 1,000 open-source software projects. Many of these vulnerabilities, particularly t… SecurityWeek · May 25, 2026 Critical UKaivulnerabilityopen source
vulnerability Wireshark 4.6.6 Released, (Sun, May 24th) Wireshark, a popular network protocol analyzer, released version 4.6.6, addressing several issues within the software. This update includes fixes for a single vulnerability and eleven bugs, alongside an update to the Npc… SANS Internet Storm Center · May 24, 2026 Medium wiresharknetwork analysissecurity update
threat-intel Claude Mythos AI Finds 10,000 High-Severity Flaws in Widely Used Software Anthropic’s Project Glasswing has identified over 10,000 high-severity vulnerabilities in widely used software, primarily through its Claude Mythos Preview AI model. This initiative focuses on proactively identifying and… The Hacker News · May 23, 2026 Critical CVE-2026-5194aivulnerabilitypatching
threat-intel ISC Stormcast For Friday, May 22nd, 2026 https://isc.sans.edu/podcastdetail/9942, (Fri, May 22nd) The SANS Internet Storm Center's Stormcast for May 22nd, 2026 highlighted a concerning increase in several active threats across the internet landscape. The report detailed a rise in phishing campaigns, malicious email a… SANS Internet Storm Center · May 22, 2026 Medium phishingvulnerabilitythreat-intelligence
vulnerability Multiples vulnérabilités dans les produits Mattermost (22 mai 2026) Multiple vulnerabilities have been discovered in Mattermost products, allowing an attacker to bypass security policies and potentially lead to an unspecified security issue. These vulnerabilities affect various versions… CERT-FR · May 22, 2026 Medium CVE-2026-5139CVE-2026-6062CVE-2026-6517vulnerabilitysecuritypatch
threat-intel Google API Keys Remain Active After Deletion This article details a significant vulnerability in Google Cloud Platform (GCP) API key deletion processes. Researcher Joe Leon of Aikido Security discovered that API keys can remain active for up to 23 minutes after del… Dark Reading · May 21, 2026 High USSGapi keysgcpauthentication
vulnerability Google accidentally exposed details of unfixed Chromium flaw Google inadvertently exposed details of a persistent vulnerability in Chromium, allowing for remote code execution on devices. The flaw, initially reported in December 2022, remained unfixed for over two years, leading t… BleepingComputer · May 21, 2026 High remote-code-executionbrowservulnerability
threat-intel UK plans for cybercrime law reform would protect almost no one, experts warn The UK government’s proposed reforms to the Computer Misuse Act 1990 are facing criticism from cybersecurity experts who believe they will offer minimal protection to researchers. The proposed changes would restrict the… The Record · May 21, 2026 Medium UKcybersecurityresearchlegal
vulnerability Microsoft Warns of Two Actively Exploited Defender Vulnerabilities Microsoft has disclosed two actively exploited vulnerabilities within its Defender security platform, CVE-2026-41091 and CVE-2026-45498, both of which allow for privilege escalation and denial-of-service attacks. These v… The Hacker News · May 21, 2026 High CVE-2026-41091CVE-2026-45498CVE-2026-33825defendervulnerabilityprivilege escalation
supply-chain Supply Chain Security Crisis: Too Many Vulnerabilities, Too Little Visibility This article highlights a growing cybersecurity crisis driven by the rapid proliferation of vulnerabilities and the decreasing time it takes for attackers to exploit them. The analysis, primarily based on a Black Kite re… SecurityWeek · May 21, 2026 High USsupply chainvulnerabilityai
vulnerability 9-Year-Old Linux Kernel Flaw Enables Root Command Execution on Major Distros A nine-year-old vulnerability in the Linux kernel, CVE-2026-46333, allows unprivileged users to execute commands as root, posing a significant risk to systems running affected distributions. The flaw stems from improper… The Hacker News · May 21, 2026 High CVE-2026-46333linuxkernelprivilege escalation
threat-intel ISC Stormcast For Thursday, May 21st, 2026 https://isc.sans.edu/podcastdetail/9940, (Thu, May 21st) The SANS Internet Storm Center's Stormcast for May 21st, 2026 highlighted a concerning increase in several active threats across the internet landscape. The report detailed a rise in phishing campaigns, malicious email a… SANS Internet Storm Center · May 21, 2026 Medium phishingvulnerabilitythreat intelligence
vulnerability Anthropic Silently Patches Claude Code Sandbox Bypass Anthropic has addressed a vulnerability in its Claude Code network sandbox that could have allowed attackers to bypass security controls and potentially exfiltrate data. The vulnerability, discovered by researcher Aonan… SecurityWeek · May 20, 2026 High CVE-2025-66479sandboxprompt injectionsecurity
vulnerability How an image could compromise your Mac: understanding an ExifTool vulnerability (CVE-2026-3102) This article details a vulnerability (CVE-2026-3102) in ExifTool for macOS, allowing an attacker to execute arbitrary commands by injecting malicious data into the FileCreateDate metadata field. The vulnerability stems f… Securelist · May 20, 2026 Critical CVE-2026-3102CVE-2021-22204exiftoolmacosmetadata