threat-intel Russia-Linked ‘GreyVibe’ Attackers Use AI to Supercharge Cyberattacks A newly identified Russia-linked threat actor, GreyVibe, is utilizing artificial intelligence to enhance the speed, scale, and sophistication of its cyberattacks, primarily targeting Ukrainian military, government, and b… SecurityWeek · May 28, 2026 High RUairussiamalware
vulnerability Microsoft Slams Public Zero-Day Disclosures Amid GitHub Researcher Account Removal Microsoft has strongly criticized the public disclosure of zero-day vulnerabilities affecting Windows components, particularly following a researcher's independent disclosures. The company asserts that uncoordinated disc… The Hacker News · May 28, 2026 High CVE-2026-33825CVE-2026-41091CVE-2026-45498zero-dayvulnerabilitydisclosure
ransomware Reconstructing an Akira Ransomware Kill Chain from Perimeter and Endpoint Logs, (Wed, May 27th) This report details the reconstruction of an Akira ransomware attack on a mid-sized organization, focusing on the critical early stages of the intrusion. The analysis, based solely on firewall and Windows event logs, rev… SANS Internet Storm Center · May 27, 2026 High USbrute-forcecredential-stuffinglateral-movement
threat-intel Introducing EvidenceForge: Synthetic security logs that don’t look (as) fake Cisco Talos has released EvidenceForge, an open-source synthetic security log generator designed to address the limitations of existing synthetic data solutions. The tool utilizes a canonical event model, causal ordering… Cisco Talos · May 27, 2026 Medium synthetic datalog generationthreat hunting
threat-intel Windows 11 KB5089573 update released with performance improvements This article reports on the release of Windows 11 KB5089573, a non-security preview update for Windows 11 versions 25H2 and 24H2. The update focuses on performance improvements and reliability enhancements, including sha… BleepingComputer · May 27, 2026 Low windows 11performancereliability
malware Possible ACR Stealer From Page Impersonating Claude, (Tue, May 26th) This report details the discovery of a fake Claude webpage distributing the ACR Stealer malware, targeting macOS and Windows users. The initial infection vector involves malicious ads leading to the deceptive site, which… SANS Internet Storm Center · May 26, 2026 High USstealermacoswindows
phishing Ghostwriter Targets Ukraine Government Entities with Prometheus Phishing Malware The Ghostwriter threat actor, linked to Belarus, has been conducting a phishing campaign targeting Ukrainian government entities since the spring of 2026. This campaign utilizes lures related to the Prometheus online lea… The Hacker News · May 22, 2026 High UKBERUphishingmalwarecobalt strike
threat-intel Making Vulnerable Drivers Exploitable Without Hardware - The BYOVD Perspective This article details a technique for evaluating the exploitability of Windows kernel mode drivers, focusing on the potential for BYOVD (Bring Your Own Vulnerability Driver) attacks. It highlights how vulnerabilities in d… The Hacker News · May 22, 2026 Medium USdriverbyovdkernel mode
malware Showboat Linux Malware Hits Middle East Telecom with SOCKS5 Proxy Backdoor A new Linux malware, dubbed Showboat, has been used in a campaign targeting a telecommunications provider in the Middle East since at least 2022. The malware, developed by a China-linked threat actor group known as Calyp… The Hacker News · May 21, 2026 High CVE-2021-26855AFAZCHlinuxsocks5c2
threat-intel ThreatsDay Bulletin: Linux Rootkits, Router 0-Day, AI Intrusions, Scam Kits and 25 New Stories This week's threat intelligence report highlights a diverse range of security incidents and vulnerabilities, including a significant Pwn2Own competition with substantial rewards, warnings about the risks of deploying age… The Hacker News · May 21, 2026 High CVE-2026-45793CVE-2026-8631UKUSCHzero-dayai securitysocial engineering
vulnerability Microsoft Warns of Two Actively Exploited Defender Vulnerabilities Microsoft has disclosed two actively exploited vulnerabilities within its Defender security platform, CVE-2026-41091 and CVE-2026-45498, both of which allow for privilege escalation and denial-of-service attacks. These v… The Hacker News · May 21, 2026 High CVE-2026-41091CVE-2026-45498CVE-2026-33825defendervulnerabilityprivilege escalation
vulnerability Microsoft Patches Exploited UnDefend and RedSun Defender Zero-Days Microsoft released patches for two previously exploited zero-day vulnerabilities within its Defender security software. These vulnerabilities, CVE-2026-41091 and CVE-2026-45498, allowed for privilege escalation and denia… SecurityWeek · May 21, 2026 High CVE-2026-41091CVE-2026-45498CVE-2008-4250zero-dayprivilege escalationdenial of service
vulnerability Microsoft warns of new Defender zero-days exploited in attacks Microsoft has released security patches for two zero-day vulnerabilities, CVE-2026-41091 (RedSun) and CVE-2026-45498 (UnDefend), that are being actively exploited in attacks. These flaws, affecting Microsoft Defender and… BleepingComputer · May 21, 2026 High CVE-2026-41091CVE-2026-45498USzero-dayprivilege escalationdefender
vulnerability Microsoft Releases Mitigation for YellowKey BitLocker Bypass CVE-2026-45585 Exploit This report details a zero-day vulnerability, dubbed ‘YellowKey,’ affecting Windows 11 and Server 2025, allowing attackers to bypass BitLocker Device Encryption through a USB drive exploit. Microsoft has released a mitig… The Hacker News · May 20, 2026 High CVE-2026-45585USbitlockerwinrezero-day
vulnerability Microsoft shares mitigation for YellowKey Windows zero-day Microsoft has released mitigation steps for a newly disclosed Windows zero-day vulnerability, dubbed YellowKey, which allows unauthorized access to BitLocker-protected drives. The vulnerability was initially revealed by… BleepingComputer · May 20, 2026 High CVE-2026-33825CVE-2026-45585zero-daybitlockerwinre
vulnerability Verizon DBIR 2026: Vulnerability Exploitation Overtakes Credential Theft as Top Breach Vector Verizon’s 2026 Data Breach Investigations Report (DBIR) reveals that vulnerability exploitation has become the leading cause of data breaches, surpassing credential theft. The report highlights a concerning trend of slow… SecurityWeek · May 20, 2026 High USvulnerability managementpatchinggen-ai
threat-intel Windows Zero-Day Barrage Continues After Patch Tuesday A security researcher known as "Nightmare Eclipse" has disclosed six Windows zero-day vulnerabilities over the past six weeks, some of which are actively being exploited. These vulnerabilities, including YellowKey, Green… Dark Reading · May 19, 2026 High CVE-2020-17103CVE-2026-33825USzero-daybitlockerprivilege escalation
vulnerability Zero-Day Exploit Against Windows BitLocker A new zero-day exploit, dubbed YellowKey, has been discovered targeting Windows BitLocker encryption. The vulnerability allows attackers to bypass BitLocker's security measures with physical access to the affected device… Schneier on Security · May 18, 2026 High zero-dayencryptionbitlocker
threat-intel The time of much patching is coming This article from Cisco Talos anticipates a significant increase in software patching due to advancements in AI-powered vulnerability detection and the uncovering of long-standing technical debt. The surge in discovered… Cisco Talos · May 14, 2026 High USvulnerabilitypatchingai
threat-intel Patch Tuesday, May 2026 Edition This article reports on Patch Tuesday, May 2026, highlighting a significant increase in security vulnerabilities addressed by major software vendors like Microsoft, Apple, Google, Mozilla, and Oracle. The updates, spurre… Krebs on Security · May 12, 2026 Critical CVE-2026-41089CVE-2026-41096CVE-2026-41103USpatch tuesdayaivulnerability