// 1 CRITICAL · 6 ZERO-DAY · 10 CVE · 11 EXPLOIT · 1 ADVISORY IN THE LAST 24H
CYBERSEC

CISA Faces Congressional Scrutiny After Months-Long AWS GovCloud Credential Leak on GitHub

Senator Maggie Hassan has demanded a classified briefing from CISA following the discovery of a public GitHub repository that exposed…

May 20, 2026views - 214

phishing

Italian Revenue Agency Phishing: Cloned SPID Portal Uses Pre-filled Emails to Target Public Sector

CERT-AGID has identified a targeted phishing campaign against the Italian Revenue Agency (Agenzia delle Entrate) featuring cloned SPID…

May 20, 2026views - 164

VULNCRITICAL

ExifTool RCE: Kaspersky GReAT Uncovers macOS Command Injection via Metadata

CVE-2026-3102 impacts ExifTool versions 13.49 and earlier on macOS. The vulnerability allows for command injection within the SetMacOS…

May 20, 2026views - 156

CYBERSEC

GitHub Breach: 3,800 Internal Repositories Stolen via Malicious VS Code Extension

GitHub has confirmed a security breach affecting approximately 3,800 internal repositories after an employee device was compromised by…

May 20, 2026views - 560

CYBERSEC

AI-Powered Honeypots: Cisco Talos Flips the Script on Automated Threats

On April 29, Cisco Talos Intelligence researchers released a proof-of-concept aimed at neutralizing offensive asymmetry in cyberspace.…

May 20, 2026views - 164

agentic

AI Agents in Production: Addressing the Confused-Deputy Threat in Operational Automation

New research identifies a critical architectural gap in operational AI agents where a lack of separation between reasoning and executi…

May 20, 2026views - 141

CYBERSEC

Grafana Labs Breach: Forgotten Workflow Token Exposes Internal Repositories

Grafana Labs has disclosed a security breach involving its GitHub repositories after an overlooked CI/CD token—missed during an emerge…

May 20, 2026views - 160

CYBERSEC

GitHub Investigates Alleged Exfiltration of 4,000 Internal Repositories by TeamPCP

GitHub is investigating claims from the threat group TeamPCP, which alleges to have exfiltrated nearly 4,000 internal repositories and…

May 20, 2026views - 174

CYBERSEC

AI Productivity Facade: 18 Malicious Extensions Discovered with RAT and MitM Capabilities

Palo Alto Networks’ Unit 42 has identified 18 high-risk AI browser extensions that surveil emails, steal prompts, and compromise user…

May 20, 2026views - 120

agentic

Zealot: How Autonomous AI Orchestrates Multi-Stage Cloud Compromise

Palo Alto Networks’ Unit 42 has demonstrated Zealot, a multi-agent PoC capable of executing end-to-end cloud attack chains without hum…

May 20, 2026views - 158

CYBERSECZERO-DAY

BitLocker Bypassed: New Zero-Day Trio Targets Windows Following Patch Tuesday

An analysis of the YellowKey, GreenPlasma, and MiniPlasma vulnerabilities disclosed shortly after the May 2026 Patch Tuesday, impactin…

May 20, 2026views - 254

CYBERSEC

Microsoft Neutralizes Fox Tempest: Malware-Signing-as-a-Service Operation Dismantled

Microsoft has disrupted Fox Tempest, a sophisticated 'Malware-Signing-as-a-Service' operation that leveraged stolen identities to expl…

May 20, 2026views - 141

CYBERSECEXPLOIT

Verizon DBIR 2026: Vulnerability Exploitation Overtakes Credentials as Patching Cycles Falter

The 2026 Verizon DBIR marks a structural shift in the threat landscape: vulnerability exploitation (31%) has surpassed credential abus…

May 20, 2026views - 162

CYBERSECCVE

Critical RCE in ChromaDB: 73% of Exposed Servers Vulnerable to CVE-2026-45829

A maximum-severity vulnerability in ChromaDB’s Python FastAPI server allows unauthenticated remote code execution. The flaw, which ste…

May 19, 2026views - 209

CYBERSEC

7-Eleven Confirms Data Breach After ShinyHunters Leaks 9.4GB of Files

7-Eleven has officially confirmed a cyberattack originating in April 2026. Following a failed ransom negotiation with the ShinyHunters…

May 19, 2026views - 473

VULNCRITICAL

Drupal to Release ‘Highly Critical’ Core Patch on May 20; Exploit Expected Within Hours

Drupal administrators are on high alert as the Security Team prepares a coordinated release for a major core vulnerability, warning th…

May 19, 2026views - 234

cybersec

Microsoft Dismantles Fox Tempest: The Takedown of a Global Malware-Signing Syndicate

Microsoft’s Digital Crimes Unit has seized the infrastructure of Fox Tempest, a major 'malware-signing-as-a-service' provider that ena…

May 19, 2026views - 156

CYBERSECCRITICAL

SEPPMail Security Crisis: Seven Critical Flaws Grant Full Access to Corporate Email

A cluster of seven vulnerabilities in the SEPPMail Secure E-Mail Gateway, including flaws with CVSS scores up to 10.0, enables unauthe…

May 19, 2026views - 325

roboticsCVE

CVE-2026-8153: Universal Robots Cobots Vulnerable to Unauthenticated RCE

An OS command injection vulnerability in the PolyScope 5 Dashboard Server enables unauthenticated remote code execution on Universal R…

May 19, 2026views - 181

CYBERSECCVE

NGINX Rift Under Active Exploitation: A Technical Analysis of CVE-2026-42945

A 16-year-old vulnerability in the NGINX rewrite module, dubbed NGINX Rift (CVE-2026-42945), is currently being exploited in the wild.…

May 19, 2026views - 198

phishing

15 Instagram Posts and One Cent: The New Price of Convincing Spear-Phishing

Research from UT Arlington and LSU demonstrates how 10-15 public Instagram posts and less than a penny can generate personalized phish…

May 19, 2026views - 157

CYBERSEC

Linux Kernel Page Cache Vulnerabilities: CopyFail, Fragnesia, and DirtyDecrypt LPE Risks

An analysis of the CopyFail (CVE-2026-31431), Fragnesia, and DirtyDecrypt vulnerabilities within the Linux kernel, including exploitat…

May 19, 2026views - 192

VULNCVE

18-Year-Old NGINX Bug CVE-2026-42945 Under Active Attack

Exploitation attempts are underway for CVE-2026-42945, an 18-year-old heap buffer overflow in the NGINX rewrite module. The flaw enabl…

May 19, 2026views - 167

cveCVE

NGINX Rift: Active Exploitation of CVE-2026-42945 Detected In the Wild

In-the-wild attacks targeting CVE-2026-42945 (NGINX Rift) began on May 16, 2026. Security researchers analyze the critical heap buffer…

May 19, 2026views - 182