threat-intel Google Chrome adds session cookie theft protection for all users Google has launched a new security feature, Device Bound Session Credentials (DBSC), for Chrome to protect users from session cookie theft and subsequent account takeovers. This feature cryptographically links session co… BleepingComputer · May 29, 2026 High session cookiesaccount takeovercryptography
threat-intel New Russian-Linked GREYVIBE Targets Ukraine with AI-Powered Cyberattacks A new, Russian-linked cyber threat group, dubbed GREYVIBE, has been targeting Ukraine and related entities since August 2025 with a range of sophisticated attacks. The group utilizes multiple attack vectors, including ph… The Hacker News · May 29, 2026 High RUrussianaigenai
data-breach California Sues 23andMe, Alleging It Failed to Protect User Data in 2023 Breach California’s Attorney General has filed a lawsuit against 23andMe, alleging a significant data breach in 2023 that exposed the personal information of nearly 7 million users. The lawsuit highlights 23andMe’s lax security… SecurityWeek · May 29, 2026 High USdata breachgenetic datapassword security
threat-intel Chilling Effects This article details a concerning trend of self-censorship and disengagement among students and professionals in the United States, driven by the perceived threat of punitive measures from the Trump administration. The p… Schneier on Security · May 29, 2026 High UScensorshipfearconformity
threat-intel What 2,000 Exposed Vibe-Coded Apps Reveal About the Limits of Most Security Stacks This article highlights a growing security risk stemming from the rise of ‘vibe coding’ – AI-driven application development platforms that allow employees to rapidly build and deploy applications. Over 2,000 of these pub… The Hacker News · May 29, 2026 High aishadow-itvibe-coding
vulnerability Chrome 148 Update Patches 151 Vulnerabilities The browser update resolves critical-severity security defects that could potentially lead to remote code execution. The post Chrome 148 Update Patches 151 Vulnerabilities appeared first on SecurityWeek . SecurityWeek · May 29, 2026 High CVE-2026-9872CVE-2026-9873CVE-2026-9874
threat-intel US charges Google security engineer with Polymarket insider trading A Google security engineer, Michele Spagnuolo, has been charged with insider trading after exploiting confidential ‘Year in Search’ data to profit from bets on the Polymarket prediction market. He used his access to Goog… BleepingComputer · May 29, 2026 High USITSWinsider-tradingconfidential-datacryptocurrency
supply-chain Malicious Sicoob NuGet Steals Banking Credentials as npm Packages Target Cloud Secrets A malicious NuGet package, 'Sicoob.Sdk,' disguised as a C# SDK for Sicoob, Brazil's largest cooperative financial system, was discovered to be stealing client IDs and PFX certificates. This allowed unauthorized access to… The Hacker News · May 29, 2026 High BRsupply-chaincredentialsbanking
data-breach Charter Communications data breach affects 4.9 million accounts Charter Communications experienced a data breach impacting approximately 4.9 million accounts following a sophisticated attack by the ShinyHunters extortion gang. The attackers gained access through a voice phishing (vis… BleepingComputer · May 29, 2026 High USCHdata breachvishingsalesforce
data-breach Police arrest man following hack of Ajax football club A 35-year-old man has been arrested in the Netherlands following a significant security breach at Ajax football club. The incident exposed the personal data of approximately 300,000 supporters due to a vulnerability in t… Graham Cluley · May 29, 2026 High NLdata-leakmobile-appfan-data
threat-intel What’s in the container? Analyzing vulnerabilities, risks and protection with Kaspersky Container Security and the KIRA AI assistant This Securelist article discusses the security risks associated with containerization using Docker, particularly the prevalence of outdated and vulnerable software within pre-built images. The article highlights how atta… Securelist · May 29, 2026 High CVE-2025-55182CVE-2023-4911CVE-2021-4034UScontainersdockervulnerabilities
threat-intel Kimsuky Deploys HTTPSpy, Expands Arsenal with HelloDoor and VS Code Tunnels North Korean state-sponsored threat actor Kimsuky has expanded its arsenal and tactics, utilizing HTTPSpy, HelloDoor, and VS Code tunnels to target South Korean military and corporate entities between March and April 202… The Hacker News · May 29, 2026 High KRnorth koreanremote access trojansocial engineering
threat-intel As Global Powers Explore Humanoid Robots, Cyber-Risk Looms This article discusses the emerging cybersecurity risks associated with the rapid development and deployment of embodied AI, particularly humanoid robots. The core concern is that these systems, currently being developed… Dark Reading · May 28, 2026 High CHRUCAembodied aicyberespionagerobotics
threat-intel GreyVibe hackers use ChatGPT, Gemini to power cyberattacks GreyVibe, a threat actor likely linked to Russia, has been conducting cyber espionage campaigns targeting Ukrainian organizations since August 2025, utilizing a diverse range of custom malware and AI-generated lures. The… BleepingComputer · May 28, 2026 High RUUKaiphishingmalware
threat-intel Dutch Raid Fails to Dent Russian Bulletproof Host A Dutch law enforcement operation targeting THE.Hosting, a bulletproof hosting network linked to Russian cybercrime, resulted in the seizure of 800 servers and arrests of two operators but failed to significantly disrupt… Dark Reading · May 28, 2026 High NLRUDKbulletproof hostingcybercrimesanctions evasion
threat-intel Russia-Linked ‘GreyVibe’ Attackers Use AI to Supercharge Cyberattacks A newly identified Russia-linked threat actor, GreyVibe, is utilizing artificial intelligence to enhance the speed, scale, and sophistication of its cyberattacks, primarily targeting Ukrainian military, government, and b… SecurityWeek · May 28, 2026 High RUairussiamalware
threat-intel Agentic AI Isn't Risky; the Way Orgs Deploy It Is This article highlights a critical cybersecurity risk associated with the rapid deployment of agentic AI, focusing on vulnerabilities stemming from poor software development practices rather than inherent flaws in the AI… Dark Reading · May 28, 2026 High USaiagentic-aivulnerability
data-breach Carnival Data Breach Exposed 6 Million People Data breach leaves nearly 6 million Carnival customers navigating identity theft risks. The post Carnival Data Breach Exposed 6 Million People appeared first on SecurityWeek . SecurityWeek · May 28, 2026 High
vulnerability New Gogs zero-day flaw lets hackers get remote code execution A zero-day vulnerability (CVE-2024-39933) has been identified in Gogs, a self-hosted Git service, allowing authenticated attackers to execute remote code execution (RCE). The flaw, initially discovered by Jonah Burgess,… BleepingComputer · May 28, 2026 High CVE-2024-39933CVE-2024-39932CVE-2026-26194USCNJPzero-dayrcegit
threat-intel How SIEM helps MSPs reduce noise and stop threats faster This BleepingComputer article discusses the challenges MSPs face in managing security alerts due to fragmented security toolsets. The core issue is ‘alert fatigue’ and the inability to quickly identify and respond to act… BleepingComputer · May 28, 2026 High siemmspalert fatigue