data-breach Cruise giant Carnival confirms data breach affecting nearly 6 million people Carnival Corporation has confirmed a data breach impacting nearly 6 million individuals, stemming from a cyberattack attributed to the ShinyHunters hacking group. The attackers gained access through a compromised employe… The Record · May 28, 2026 High USdata-theftemployee-accountextortion
vulnerability Microsoft Slams Public Zero-Day Disclosures Amid GitHub Researcher Account Removal Microsoft has strongly criticized the public disclosure of zero-day vulnerabilities affecting Windows components, particularly following a researcher's independent disclosures. The company asserts that uncoordinated disc… The Hacker News · May 28, 2026 High CVE-2026-33825CVE-2026-41091CVE-2026-45498zero-dayvulnerabilitydisclosure
Canadian man gets 33 years for using social media to coerce US children into sending sexual content Prosecutors said the man spent years using fake online identities to contact children and manipulate them into sending sexually explicit images and videos. The Record · May 28, 2026 High
threat-intel MyPillow listed on ransomware gang’s leak site, but denies it has been breached The Play ransomware gang claims to have stolen data from MyPillow, a US pillow manufacturer, and threatens to release it publicly. MyPillow denies the breach and claims it doesn't hold sensitive data internally, relying… Graham Cluley · May 28, 2026 High USransomwaredata-breachthird-party
threat-intel ThreatsDay Bulletin: Claude Security Plugin, Azure Priv-Esc, Kali365 MFA Bypass, FIFA Scams +15 More This Hacker News bulletin details several recent cyber threats, including a massive C2 infrastructure footprint discovered in the Middle East dominated by IoT botnets, a privilege escalation vulnerability in Azure Backup… The Hacker News · May 28, 2026 High CVE-2026-8398SAROUSc2supply-chainprivilege-escalation
threat-intel Chinese-speaking fraud gang could be stealing millions from 2026 World Cup fans A Chinese-speaking fraud gang, dubbed GHOST STADIUM, is impersonating FIFA's official website to steal credentials and payment details from fans seeking tickets for the 2026 World Cup. The operation, involving over 300 f… The Record · May 28, 2026 High CNUSCAfraudphishingworld cup
threat-intel Russia conducting daily attacks on UK 'from seabed to cyberspace,' spy chief warns GCHQ Director Anne Keast-Butler warned of daily, sophisticated cyberattacks originating from Russia targeting the UK and Europe, spanning undersea cables to cyberspace. These attacks are focused on critical infrastructur… The Record · May 28, 2026 High UKRUCHcyberattackhybrid warfareintelligence
vulnerability IBM and Red Hat Commit $5 Billion to Secure Open Source Supply Chains Under “Project Lightwell” Project Lightwell is designed to fix vulnerabilities without breaking what is already in production. The post IBM and Red Hat Commit $5 Billion to Secure Open Source Supply Chains Under “Project Lightwell” appeared first… SecurityWeek · May 28, 2026 High
threat-intel Focus on Cyber Insurance: How Quantifying Risk Is Reshaping Security This article discusses the evolving role of cyber insurance in reshaping cybersecurity strategy. The growth of cyber insurance is forcing organizations to quantify their risk exposure, moving beyond vague concerns about… Dark Reading · May 28, 2026 High cyber insuranceransomwarerisk quantification
threat-intel New Edamame Platform Aims to Catch AI Coding Agents Going Off the Rails Edamame Technologies has developed a new runtime security system designed to detect and mitigate ‘code drift’ in AI coding agents. This drift, caused by agents deviating from their intended purpose, can lead to security… SecurityWeek · May 28, 2026 High FRaicoding agentsruntime security
supply-chain Supply Chain Compromises Impact Nx Console and GitHub Repositories CISA is responding to multiple supply chain attacks targeting developer ecosystems, specifically CI/CD pipelines. A malicious Nx Console VS Code extension compromised a GitHub employee, leading to data exfiltration, and… CISA Advisories · May 28, 2026 High CVE-2026-48027supply chainci/cdgithub
vulnerability Fourth Frontier Frontier X Mobile Application, Frontier X2 A vulnerability has been identified in the Fourth Frontier Frontier X Mobile Application and Frontier X2 devices, allowing unauthorized access and control. Attackers could potentially read and modify patient data, trigge… CISA Advisories · May 28, 2026 High CVE-2026-5768USbleauthenticationdevice control
threat-intel MacGregor Voyage Data Recorder (VDR) G4e A vulnerability has been identified in MacGregor Voyage Data Recorder (VDR) G4e devices, specifically versions prior to V5.250, due to the use of default credentials, weak password hashing, and hard-coded credentials. Th… CISA Advisories · May 28, 2026 High CVE-2026-42941CVE-2026-42951CVE-2026-44611DKdefault credentialsvdrfirmware
vulnerability ABB Busch-Welcome 2 Wire Door Opener Actuator A vulnerability has been identified in ABB Busch-Welcome 2 Wire Door Opener Actuators, specifically due to a default compatibility mode that allows for authentication bypass. This could enable an attacker to gain unautho… CISA Advisories · May 28, 2026 High CVE-2025-7705WOdoor lockphysical accessauthentication
vulnerability CP Plus 8 Ch. Network Video Recorder A cross-site scripting (XSS) vulnerability has been identified in CP Plus 8 Ch. Network Video Recorder devices (CP-UNR-108F1 Hardware V1.0, CP-UNR-108F1 Web V3.2.7.128806, and CP-UNR-108F1 System V4.001.00AT009.0.R). Att… CISA Advisories · May 28, 2026 High CVE-2026-6824INNPAExsscwe-79firmware
threat-intel New AI Usage Report: Enterprise AI Risk Is Heavily Concentrated Among a Small Group of AI "Power users" A LayerX Security report reveals that enterprise AI risk is heavily concentrated among a small group of ‘AI power users’ rather than being evenly distributed across all employees. The report highlights the fragmented nat… The Hacker News · May 28, 2026 High aienterprisegovernance
vulnerability Gitea Vulnerability Exposed 30,000 Deployments to Attacks The security flaw allowed attackers to pull private container images, exposing source code, credentials, and infrastructure. The post Gitea Vulnerability Exposed 30,000 Deployments to Attacks appeared first on SecurityWe… SecurityWeek · May 28, 2026 High CVE-2026-27771
threat-intel Raising the Cybersecurity Stakes: Ante up for the Agentic Era This article discusses the emerging "agentic era" in cybersecurity, driven by the increasing use of AI-powered tools and agents by both attackers and defenders. The rapid evolution of AI is creating a significant securit… SecurityWeek · May 28, 2026 High USaiagenticautomation
data-breach Carnival Cruise confirms data breach affecting nearly 6 million people Carnival Corporation confirmed a data breach impacting nearly 6 million individuals, attributed to the ShinyHunters extortion gang. The breach occurred through a social engineering attack targeting an employee’s account,… BleepingComputer · May 28, 2026 High social engineeringloyalty programdata theft
threat-intel 2026 World Cup: Discussing The World’s Biggest Game’s Attack Surface This analysis from Palo Alto Unit 42 assesses the significant cyber threat landscape surrounding the 2026 FIFA World Cup, highlighting the expanded attack surface created by the event's scale and complexity. The report i… Palo Alto Unit 42 · May 28, 2026 High USIRRUmega-eventcybersecuritythreat intelligence