Cybersecurity
Cybersecurity collects analysis on vulnerabilities, exploits, patch management, ransomware, supply chain, AI security and threat intelligence. These articles help IT professionals, developers and security analysts follow operational threats, vendor updates and technical trends.

Microsoft Patch Tuesday: Legacy MSMQ Flaw Enables Local SYSTEM Escalation
The May 12, 2026, security update addresses CVE-2026-33838, an elevation-of-privilege vulnerability in Windows Message Queuing (MSMQ).…

Apple Patches Remote Code Execution Vulnerability in macOS USD Library
A newly disclosed out-of-bounds write flaw (ZDI-26-314) in the Universal Scene Description library could allow remote attackers to exe…

Microsoft Exchange Zero-Day Exploited: Permanent Patch Restricted to ESU Customers
Microsoft has confirmed active in-the-wild exploitation of CVE-2026-42897 affecting Exchange on-premise servers. CISA has issued a hig…

Burst Statistics Under Fire: Over 7,400 Attacks Blocked in 24 Hours
Threat actors are actively exploiting a critical authentication bypass (CVE-2026-8181) in the Burst Statistics WordPress plugin to hij…

Mistral AI Hit by Supply Chain Attack; 450 Repositories Put Up for Sale
Mistral AI has confirmed a supply chain compromise involving contaminated SDKs and abused SLSA provenance. The threat actor TeamPCP is…

OpenAI Confirms Corporate Devices Compromised in TanStack Supply Chain Attack
OpenAI has confirmed that two corporate devices were breached following the May 11 TanStack npm supply chain attack. While internal cr…

Yarix Y-Report 2026: Critical Security Events Surge 62% as Italy Falls to 6th in Global Ransomware Rankings
The Yarix Y-Report 2026 documents 522,486 security events and a 62% spike in critical threats, highlighting an increasingly aggressive…

May Patch Tuesday: AI-Driven Discovery Pushes 2026 Vulnerability Count Past 500
Microsoft's May 12, 2026, update addresses more than 130 vulnerabilities, revealing the impact of its internal MDASH AI system. The to…

ClawHavoc, Critical CVEs, and Agentic AI: Why Q1 2026 Shifted the Threat Model
The agentic AI ecosystem is under siege. From the coordinated ClawHavoc supply chain campaign to critical RCE vulnerabilities in Claud…

May 2026 Patch Tuesday: AI-Driven Discovery Marks a Turning Point in Vulnerability Management
Microsoft and industry partners address over 130 vulnerabilities as AI systems like MDASH and Project Glasswing accelerate the discove…

Microsoft MDASH Deployment Identifies 16 Windows Flaws via 100+ AI Agents
Microsoft’s MDASH, an agentic multi-model system, discovered 16 vulnerabilities—including four critical RCEs—patched in the May 2026 u…

Škoda Germany Data Breach: Online Store Offline After Password Hashes Exposed
Škoda has confirmed a cyberattack on its German online store. While customer data and password hashes were exposed, forensic investiga…