VELVET CHOLLIMA Infostealer Campaign Using Trading App as Lure
PraisonAI CVE-2026-44338 Auth Bypass Targeted Within Hours of Disclosure

How AI Hallucinations Are Creating Real Security Risks

How Dangerous Is Anthropic’s Mythos AI?

What’s your daily workflow as an ethical hacker?

CVE-2026-42945 : NGINX Heap Buffer Overflow in rewrite module - Writeup and PoC
Q&A: Why Vulnerability Scans Are Giving Businesses a False Sense of Security

Phillip Wylie is an internationally recognised cybersecurity expert, ethical hacker and offensive security specialist with more than 28 years’ experience across IT, network security, application security, penetration testing, red teaming and social engineering. As co-author of The Pentester BluePrint, founder of The Pwn School Project and host of The Phillip Wylie Show, Phillip has built his career around […]
The post Q&A: Why Vulnerability Scans Are Giving Businesses a False Sense of Security appeared first on IT Security Guru.
When ransomware gets physical: cybercriminals turn to threats of violence

Windows Zero-Days Expose BitLocker Bypasses And CTFMON Privilege Escalation

New Fragnesia Linux Kernel LPE Grants Root Access via Page Cache Corruption

18-Year-Old NGINX Rewrite Module Flaw Enables Unauthenticated RCE
Welcoming the Bahamian Government to Have I Been Pwned
Today, we welcome the 44th government onboarded to Have I Been Pwned’s free gov service: The Bahamas. The National Computer Incident Response Team of The Bahamas, CIRT-BS, now has access to monitor government domains against the data in HIBP. As the national CIRT, CIRT-BS is responsible for coordinating
Smashing Security podcast #467: How ShinyHunters hacked the world’s biggest universities

WaSteal: 126 Chrome extensions, 148K installs, one Brazilian operator silently sending WhatsApp user data and ad cookies to its servers
Apple Maildrop lets you rewrite the filename, size, and icon on any icloud.com attachment link — no signature, no validation — reported July 2023, still live

/sbin/ping -G sweepmax has no bounds check on macOS: deterministic BSS out-of-bounds write, confirmed by Apple

Canvas developers could be added to 'sucker list' after deal with hackers

Our Path Forward
I made a game for Security and Risk Management
Over Half of MSPs Admit to Being Breached Multiple Times in Past Year
Economic pressures are pushing cybersecurity down the priority list for many SMBs according to The CyberSmart MSP Survey 2026. Notably, 46% of MSP customers are more concerned about operational challenges such as rising costs and inflation than cybersecurity risks, despite increasing threats. Meanwhile, MSPs themselves identified AI-driven threats as their top security concern for the […]
The post Over Half of MSPs Admit to Being Breached Multiple Times in Past Year appeared first on IT Security Guru.
a leak from "the gentleman" ransomware group confirms Infostealers were often used to establish initial access

A stealth approach to Process Injection - EntryPoint Hijacking
Microsoft's MDASH AI System Finds 16 Windows Flaws Fixed in Patch Tuesday

Azerbaijani Energy Firm Hit by Repeated Microsoft Exchange Exploitation

[Webinar] How Modern Attack Paths Cross Code, Pipelines, and Cloud

Most Remediation Programs Never Confirm the Fix Actually Worked

OpenAI’s GPT-5.5 is as Good as Mythos at Finding Security Vulnerabilities

Microsoft Patches 138 Vulnerabilities, Including DNS and Netlogon RCE Flaws

GemStuffer Abuses 150+ RubyGems to Exfiltrate Scraped U.K. Council Portal Data
Android Adds Intrusion Logging for Sophisticated Spyware Forensics

Accelerating detection engineering using AI-assisted synthetic attack logs generation

What if you could generate realistic attack telemetry on demand? Explore research methods that translate attacker behaviors (TTPs) into synthetic logs that can trigger detections at scale and without sensitive data.
The post Accelerating detection engineering using AI-assisted synthetic attack logs generation appeared first on Microsoft Security Blog.
Defense at AI speed: Microsoft’s new multi-model agentic security system tops leading industry benchmark

Today Microsoft is announcing a major step forward in AI-powered cyber defense: a new multi-model agentic scanning harness (codenamed MDASH).
The post Defense at AI speed: Microsoft’s new multi-model agentic security system tops leading industry benchmark appeared first on Microsoft Security Blog.
Foxconn Ransomware Attack Shows Nothing Is Safe Forever

Patch Tuesday, May 2026 Edition

Dead.Letter (CVE-2026-45185) How XBOW found an unauthenticated RCE on Exim
New Exim BDAT Vulnerability Exposes GnuTLS Builds to Potential Code Execution
Defending consumer web properties against modern DDoS attacks

Read how to protect consumer websites and defend against modern DDoS attacks with layered security, resilient architecture, and graceful service degradation.
The post Defending consumer web properties against modern DDoS attacks appeared first on Microsoft Security Blog.
Undermining the trust boundary: Investigating a stealthy intrusion through third-party compromise

Microsoft Incident Response investigated an attack operated through legitimate and trusted administrative mechanisms to blend seamlessly into routine operations and remain undetected demonstrating that intrusions have increasingly avoided using noisy exploits, obvious malware, or custom tooling, instead leveraging systems that organizations already trust within their environments.
The post Undermining the trust boundary: Investigating a stealthy intrusion through third-party compromise appeared first on Microsoft Security Blog.
RubyGems Suspends New Signups After Hundreds of Malicious Packages Are Uploaded
Huntress and Acrisure Team Up to Offer Zero-Deductible Cyber Insurance for SMBs
Cybersecurity firm Huntress has joined forces with global fintech and insurance giant Acrisure to launch a new cyber insurance programme targeting small and mid-sized businesses, with no deductible for eligible applicants. The programme, announced today, gives qualifying Huntress customers and partners access to either Cyber or Tech Errors and Omissions (Tech E&O) insurance policies placed […]
The post Huntress and Acrisure Team Up to Offer Zero-Deductible Cyber Insurance for SMBs appeared first on IT Security Guru.
New TrickMo Variant Uses TON C2 and SOCKS5 to Create Android Network Pivots

Webinar: What the Riskiest SOC Alerts Go Unanswered - and How Radiant Security Can Help

Mini Shai-Hulud Worm Compromises TanStack, Mistral AI, Guardrails AI & More Packages

WorkNest Launches WorkNest Secure to Expand Cybersecurity and Compliance Services
WorkNest Secure has launched a new cybersecurity and compliance division aimed at helping organizations strengthen security, manage risk, and meet growing regulatory demands. The new division, called WorkNest Secure, brings together the cyber, information security, and data protection capabilities of Pentest People and Bulletproof under one brand. Both companies became part of WorkNestGroup following a […]
The post WorkNest Launches WorkNest Secure to Expand Cybersecurity and Compliance Services appeared first on IT Security Guru.
Copy.Fail Linux Vulnerability

Why Agentic AI Is Security's Next Blind Spot

Curl lead developer Daniel Stenberg provides insightful feedbacks from Mythos analysis results
New ipTIME Pre-Auth RCE in CWMP
Postmortem: TanStack npm supply-chain compromise
Instructure Reaches Ransom Agreement with ShinyHunters to Stop 3.65TB Canvas Leak

OpenAI Launches Daybreak for AI-Powered Vulnerability Detection and Patch Validation
iOS 26.5 Brings Default End-to-End Encrypted RCS Messaging Between iPhone and Android

Canvas developer Instructure says 'agreement' reached with hackers

Mini Shai-Hulud worm hits npm supply chain, compromising 160+ packages via GitHub Actions cache poisoning
Welcoming the Bangladesh Government to Have I Been Pwned

Today, we welcome the 43rd government onboarded to Have I Been Pwned's free gov service, Bangladesh. The BGD e-GOV CIRT department now has full access to query all their government domains via API, and monitor them against future breaches.

Bangladesh joins a growing list of national governments using
GhostLock: SMB Deny-Share Handles as a Zero-Privilege Availability Weapon
Adelaide University students critical after global data breach

TeamPCP Compromises Checkmarx Jenkins AST Plugin Weeks After KICS Supply Chain Attack
cPanel CVE-2026-41940 Under Active Exploitation to Deploy Filemanager Backdoor

simple PE packer/crypter for Windows. compresses and encrypts executables with a custom vm

Foxconn Wisconsin breach reportedly linked to Nitrogen ransomware, 8TB data theft claim

Hackers Used AI to Develop First Known Zero-Day 2FA Bypass for Mass Exploitation

⚡ Weekly Recap: Linux Rootkit, macOS Crypto Stealer, WebSocket Skimmers and More

Your Purple Team Isn't Purple — It's Just Red and Blue in the Same Room

LLMs and Text-in-Text Steganography
Fake OpenAI Privacy Filter on Hugging Face Dropped a Rust Infostealer
MyAudi app:Security issues in Audi Connected Vehicle experience
Giving Claude Code Full Control of a Hardware Fault Injection Setup to Bypass Secure Boot
Fake OpenAI Privacy Filter Repo Hits #1 on Hugging Face, Draws 244K Downloads

Some universities regain access to Canvas as hacker's deadline looms

cPanel & WHM Patches CVSS 9.8 Account Takeover Flaw, DoS Bugs & Multiple Security Issues

Welcoming the Costa Rican Government to Have I Been Pwned
Today, we welcome the 42nd government onboarded to Have I Been Pwned’s free gov service: Costa Rica.
The CSIRT of the Government of Costa Rica now has access to monitor government domains against the data in HIBP. This enables their national cybersecurity incident response team to identify exposure
Weekly Update 503
Well, it's the day before the Instructure "pay or leak" deadline (at least by my Aussie watch), and the company remains removed from the ShinyHunters website. In its place sits a press statement that amounts to "we're not making any statements". So
Autonomous Vulnerability Hunting with MCP
ShinyHunters / AT&T ransom payment traced on-chain — paper draft, seeking arXiv cs.CR endorsement

Ollama Out-of-Bounds Read Vulnerability Allows Remote Process Memory Leak

Data in Use Protection: How MPC Keeps Inputs Hidden from the Cloud - Stoffel - MPC Made Simple

Why AI Agents Make API Security a CISO Priority

AI agents are not a future concern. They are already changing how enterprise systems are accessed, automated, and abused. And the security implication is clear: the more autonomous systems rely on APIs, the more important it becomes to know exactly which APIs exist, how they are being used, and whether they are being misused. If […]
The post Why AI Agents Make API Security a CISO Priority appeared first on Blog.
The compression of the exploit timeline: Why n-day gaps and 90-day embargoes are failing in practice.

Are days really over?
Outrunning SHA256 with Physics
Defence in Depth: A Practical Secure Corporate Network Topology
CVE-2026-23870: Imperva Customers Protected Against Critical React Server Components DoS Vulnerability
TL;DR: A newly disclosed denial-of-service vulnerability, CVE-2026-23870, impacts React Server Components and dependent frameworks, including Next.js App Router deployments. The flaw enables unauthenticated attackers to send specially crafted HTTP requests that trigger excessive CPU consumption during request deserialization, leading to potential service degradation or total unavailability. Imperva Threat Research Group has analyzed the vulnerability and associated […]
The post CVE-2026-23870: Imperva Customers Protected Against Critical React Server Components DoS Vulnerability appeared first on Blog.
Technical Analysis of EagleSpy V6.0 (CraxsRAT Rebrand) Distributed Through Odysee and Telegram
Getting LLMs Drunk to Find Remote Linux Kernel OOB Writes (and More)

cPanel, WHM Release Fixes for Three New Vulnerabilities — Patch Now

Friday Squid Blogging: Giant Squid Live in the Waters of Western Australia
Securing CI/CD for an open source project: lessons from Cilium
TCLBANKER Banking Trojan Targets Financial Platforms via WhatsApp and Outlook Worms

Insider Betting on Polymarket
Active attack: Dirty Frag Linux vulnerability expands post-compromise risk

Dirty Frag is a newly disclosed Linux local privilege escalation vulnerability affecting kernel networking and memory-fragment handling components including esp4, esp6, and rxrpc. The vulnerability enables reliable escalation from an unprivileged user to root and may be leveraged after initial compromise through SSH access, web shells, containers, or low-privileged accounts. Microsoft Defender is actively monitoring limited in-the-wild activity and provides detection coverage for exploitation attempts.
The post Active attack: Dirty Frag Linux vulnerability expands post-compromise risk appeared first on Microsoft Security Blog.
One in eight UK workers has sold their company passwords, and bosses think it’s fine

Fake Call History Apps Stole Payments From Users After 7.3 Million Play Store Downloads

Inside Department 4: Russia’s secret school for hackers

One Click, Total Shutdown: The "Patient Zero" Webinar on Killing Stealth Breaches

Quasar Linux RAT Steals Developer Credentials for Software Supply Chain Compromise

The Canvas Hack Is a New Kind of Ransomware Debacle

Needle crypto-stealer C2 analysis: API key embedded in plain text inside the Rust malware unlocked 1,932 victims and the operator's withdrawal config
One Missed Threat Per Week: What 25M Alerts Reveal About Low-Severity Risk
Pentest-Tools.com Releases Free Scanner for CVE-2026-41940 as cPanel Authentication Bypass Enters Its Third Week of Active Exploitation

Pentest-Tools.com has released a free, no-login scanner for CVE-2026-41940, the critical authentication bypass affecting cPanel & WHM and WP Squared that has been actively exploited in the wild since at least February 2026. The vulnerability, rated CVSS 9.8 Critical and added to CISA’s Known Exploited Vulnerabilities catalog, allows an unauthenticated attacker to bypass cPanel’s login […]
The post Pentest-Tools.com Releases Free Scanner for CVE-2026-41940 as cPanel Authentication Bypass Enters Its Third Week of Active Exploitation appeared first on IT Security Guru.