threat-intel GitHub investigates internal repositories breach claimed by TeamPCP GitHub is investigating a breach of its internal repositories following a claim by the TeamPCP hacker group, who gained access to approximately 4,000 private code repositories. The incident highlights a vulnerability wit… BleepingComputer · May 20, 2026 High supply-chaingithubmalware
threat-intel Windows Zero-Day Barrage Continues After Patch Tuesday A security researcher known as "Nightmare Eclipse" has disclosed six Windows zero-day vulnerabilities over the past six weeks, some of which are actively being exploited. These vulnerabilities, including YellowKey, Green… Dark Reading · May 19, 2026 High CVE-2020-17103CVE-2026-33825USzero-daybitlockerprivilege escalation
threat-intel Huawei zero-day attack behind last year’s crash of Luxembourg's entire telecoms network A zero-day attack targeting a vulnerability in Huawei’s enterprise router software caused a three-hour nationwide telecoms outage in Luxembourg during July 2025. The attack, which exploited a previously undocumented beha… The Record · May 19, 2026 High CVE-2021-22359CVE-2022-29798LUzero-daydenied-servicenetwork
threat-intel ScadaBR CISA has issued an advisory regarding critical vulnerabilities in ScadaBR version 1.2.0, a SCADA system. The vulnerabilities include missing authentication, OS command injection, and CSRF, potentially allowing unauthenti… CISA Advisories · May 19, 2026 Critical CVE-2026-8602CVE-2026-8603CVE-2026-8604scadavulnerabilityremote code execution
vulnerability Kieback & Peter DDC Building Controllers This CISA advisory details a cross-site scripting (XSS) vulnerability affecting several versions of Kieback & Peter’s DDC Building Controllers. The vulnerability, CVE-2026-4293, allows an attacker to execute JavaScript c… CISA Advisories · May 19, 2026 Medium CVE-2026-4293AUATCNxssbuilding automationot
vulnerability ZKTeco CCTV Cameras A vulnerability has been identified in ZKTeco CCTV cameras, specifically models utilizing the SSC335-GC2063-Face-0b77 Solution firmware, allowing unauthorized access to camera credentials and configuration information. T… CISA Advisories · May 19, 2026 Medium CVE-2026-8598CHcctvcameraauthentication
threat-intel Drupal to Release Urgent Core Security Updates on May 20, Sites Told to Prepare Drupal has announced an upcoming core security release scheduled for May 20, 2026, urging users to prepare and update their systems proactively. The release addresses potential vulnerabilities that could be exploited qui… The Hacker News · May 19, 2026 High drupalsecurityupdate
vulnerability Multiples vulnérabilités dans les produits Mattermost (19 mai 2026) Multiple vulnerabilities have been discovered in Mattermost products, including desktop apps and server versions. These vulnerabilities could allow an attacker to elevate privileges, compromise data confidentiality, and… CERT-FR · May 19, 2026 Medium CVE-2026-3433CVE-2026-6046CVE-2026-6689vulnerabilitypatchsecurity
threat-intel 'Claw Chain' Vulnerabilities Threaten OpenClaw Deployments New vulnerabilities, dubbed 'Claw Chain,' have been discovered in the OpenClaw open-source AI agent framework, posing a significant risk to deployments. These four flaws – CVE-2026-44112, CVE-2026-44115, CVE-2026-44118,… Dark Reading · May 18, 2026 Critical CVE-2026-44112CVE-2026-44115CVE-2026-44118aiagentvulnerability
threat-intel ⚡ Weekly Recap: Exchange 0-Day, npm Worm, Fake AI Repo, Cisco Exploit and More This week’s security news highlights several active exploits and attacks, including a widespread vulnerability in on-prem Exchange Servers, a Cisco SD-WAN controller compromise attributed to UAT-8616, and a significant s… The Hacker News · May 18, 2026 High CVE-2026-42897CVE-2026-20182CVE-2026-20127USexchangesupply chainnpm
threat-intel The Boring Stuff Is Dangerous Now This article highlights a growing security challenge stemming from the widespread adoption of AI coding tools and the emergence of AI agents capable of exploiting obscure vulnerabilities. The combination creates a situat… Dark Reading · May 18, 2026 High aivulnerabilitycybersecurity
data-breach Boulevard of Broken Dreams: 2 Decades of Cyber Fails This Dark Reading article reflects on two decades of cybersecurity failures, highlighting recurring trends like data breaches, systemic vulnerabilities, and a growing sense of apathy among individuals regarding data secu… Dark Reading · May 18, 2026 High CVE-2023-34362USdata breachsql injectioncybersecurity
threat-intel Cyber Pioneers Ponder Past as Prologue This Dark Reading article reflects on the platform's 20-year history, featuring insights from prominent cybersecurity leaders who contributed to its content. Robert Hansen discusses his early work on robot scraping and A… Dark Reading · May 15, 2026 High aivulnerabilitybug bounties
threat-intel ISC Stormcast For Friday, May 15th, 2026 https://isc.sans.edu/podcastdetail/9934, (Fri, May 15th) The SANS Internet Storm Center's Stormcast for May 15th, 2026 highlighted a concerning increase in several active threats across the internet landscape. The report detailed a rise in phishing campaigns, malicious email a… SANS Internet Storm Center · May 15, 2026 Medium phishingvulnerabilitythreat intelligence
threat-intel Taiwan Bullet Train Hack Highlights Cybersecurity Gaps in Rail Systems A Taiwanese student exploited vulnerabilities in the Taiwan High Speed Rail (THSR)'s TETRA radio system, causing a 48-minute delay in service by spoofing an emergency alarm. This incident highlights broader cybersecurity… Dark Reading · May 15, 2026 Medium TAPOISrailcyberattacktetra
threat-intel The time of much patching is coming This article from Cisco Talos anticipates a significant increase in software patching due to advancements in AI-powered vulnerability detection and the uncovering of long-standing technical debt. The surge in discovered… Cisco Talos · May 14, 2026 High USvulnerabilitypatchingai
vulnerability Ongoing exploitation of Cisco Catalyst SD-WAN vulnerabilities Cisco Talos has identified ongoing exploitation of vulnerabilities within Cisco Catalyst SD-WAN Controller and Manager, specifically CVE-2026-20182 and a set of related vulnerabilities (CVE-2026-20133, CVE-2026-20128, an… Cisco Talos · May 14, 2026 High CVE-2026-20182CVE-2026-20133CVE-2026-20128sd-wanciscoauthentication
threat-intel Siemens SIMATIC Siemens has released a security update for its SIMATIC CN 4100 system to address multiple vulnerabilities discovered within its Linux kernel components and libxml2. These vulnerabilities, including null pointer dereferen… CISA Advisories · May 14, 2026 High CVE-2024-47704CVE-2024-57924CVE-2024-58240DElinuxkernelvulnerability
vulnerability Siemens Ruggedcom Rox This CISA advisory details a vulnerability affecting Siemens Ruggedcom Rox devices. The devices, specifically versions prior to 2.17.1, contain multiple third-party vulnerabilities, including those listed in CVEs from 20… CISA Advisories · May 14, 2026 Medium CVE-2019-13103CVE-2019-13104CVE-2019-13106vulnerabilitypatchingcve
vulnerability Siemens SIMATIC A vulnerability (CVE-2026-27662) has been identified in Siemens SIMATIC HMI Unified Comfort Panels. The flaw allows an unauthenticated attacker to gain access to the web browser through the help link, potentially enablin… CISA Advisories · May 14, 2026 High CVE-2026-27662hmiindustrial controlweb browser