// 1 CRITICAL · 11 ZERO-DAY · 9 CVE · 10 EXPLOIT IN THE LAST 24H
CYBERSEC

CISA Contractor Exposed AWS GovCloud Credentials and Plaintext Passwords on GitHub for Months

A federal contractor at Nightwing exposed administrative AWS GovCloud credentials and internal passwords in plaintext on GitHub for ov…

May 18, 2026views - 289

CYBERSEC

CERT-AGID: Italian Cyberattacks Surge 13% as PagoPA and INPS Face Targeted Campaigns

CERT-AGID identified 131 malicious campaigns in Italy between May 9 and 15, 2026. The activity involved 1,382 indicators of compromise…

May 18, 2026views - 160

CYBERSEC

ShinyHunters: A Serial Extortion Campaign Targets Enterprise SaaS (May 2026)

Between May 7 and May 18, 2026, ShinyHunters targeted Canvas, 7-Eleven, and Grafana in a high-profile data extortion spree. While Inst…

May 18, 2026views - 210

CYBERSEC

Grafana Refuses Ransom Following GitHub Token Theft and Codebase Breach

Grafana Labs has confirmed that a stolen GitHub access token allowed attackers to exfiltrate its source code. Despite extortion attemp…

May 18, 2026views - 210

CYBERSECCRITICAL

GitHub Enterprise RCE: Critical Vulnerability (CVE-2026-3854) Demands Immediate Updates

A flaw in GitHub’s push options handling allows for Remote Code Execution on Enterprise Server instances. With technical details now p…

May 17, 2026views - 235

CYBERSEC

Cisco Talos Unveils AI-Driven Honeypot PoC to Deceive Malicious Agents

Cisco Talos researchers have demonstrated a proof-of-concept for adaptive honeypots powered by generative LLMs, designed to exploit th…

May 17, 2026views - 251

CYBERSECZERO-DAY

PAN-OS Captive Portal Zero-Day: CVE-2026-0300 Exploited in Root-Level RCE Attacks

A deep dive into the critical CVE-2026-0300 vulnerability within Palo Alto Networks PAN-OS, detailing active in-the-wild exploitation…

May 17, 2026views - 185

CYBERSECEXPLOIT

Grafana Labs Hit by GitHub Breach: Source Code Stolen, Ransom Demands Rejected

Grafana Labs has confirmed a breach of its GitHub environment via a 'Pwn Request' vulnerability. While attackers exfiltrated proprieta…

May 17, 2026views - 739

CYBERSECZERO-DAY

Unpatched BlueHammer Zero-Day Enables Rapid Windows Privilege Escalation

A functional exploit dubbed 'BlueHammer' leverages logic flaws in Microsoft Defender and Volume Shadow Copy to grant SYSTEM privileges…

May 17, 2026views - 398

CYBERSECCVE

Ivanti Endpoint Manager Under Scrutiny Following CVE-2026-8109 Authentication Bypass Reports

An analysis of the CVE-2026-8109 vulnerability in Ivanti Endpoint Manager reveals a risk of authentication bypass within the RemoteCon…

May 17, 2026views - 189

CYBERSECCRITICAL

Ivanti Releases May 2026 Security Updates: Seven CVEs and a Critical SQLi-to-RCE Vulnerability

On May 13, 2026, Ivanti patched seven security flaws across four enterprise products, including a critical SQL injection-to-RCE in its…

May 17, 2026views - 263

CYBERSECCRITICAL

Ivanti Patches Critical RCE Flaws While Addressing Active EPMM Zero-Day

Ivanti has released its May security updates for EPM and confirmed an active zero-day in EPMM; with at least 22 vulnerabilities exploi…

May 16, 2026views - 176