What's happening in security
Breaches, credential dumps, actively exploited bugs and AI incidents — pulled from 3,043 items across public feeds, Have I Been Pwned and CISA KEV.
Biggest this week
- Cisco alerts customers to second actively exploited zero-day in as many days — CyberScoop, 2d ago
- Unauthenticated attackers are bypassing Cisco ISE’s management interface (CVE-2026-76460) — Help Net Security, 3d ago
- Google fixes actively exploited Android zero-day on Pixel devices — BleepingComputer, 4d ago
- Cisco warns customers of actively exploited zero-day in email gateways — CyberScoop, 5d ago
- Cisco patches actively exploited email gateway zero-day (CVE-2026-76461) — Help Net Security, 5d ago
-
CVE-2026-45247: Mirasvit Mirasvit Full Page Cache Warmer — Mirasvit Full Page Cache Warmer Deserialization of Untrusted Data Vulnerability
Mirasvit Full Page Cache Warmer contains a deserialization of untrusted data vulnerability that could allow unauthenticated attackers to achieve remote code execution by supplying a crafted serialized PHP object in the CacheWarmer…
-
Basecamp Briefing: June 2, 2026
InfoSec + Data Privacy news with a side order of tools, resources, as well as community and vendor happenings. InfoSecSherpa Sherpa Intelligence : Your Guides Up a Mountain of Information! InfoSec Data Privacy Industry News 🔒📰 Dat…
-
Unpatched NTLM Leakage in Windows search: URI Handler, Same Bug, No CVE, No Fix
The same NTLM leakage primitive that got patched in the Snipping Tool exists in Windows Explorer's search: handler. No CVE. No fix. If your patching relies on CVE coverage, you have a blind spot.
-
CVE-2022-0492: Linux Kernel — Linux Kernel Improper Authentication Vulnerability
Linux Kernel contains an improper authentication vulnerability which could allow for privilege escalation via the cgroups v1 release_agent feature.
-
CVE-2025-48595: Android Framework — Android Framework Integer Overflow Vulnerability
Android Framework contains an integer overflow vulnerability that allows for code execution that could allow for local privilege escalation.
-
How I'm Thinking About the Anthropic and OpenAI IPOs
A charcoal architectural sketch: a lone figure steps out of a broken, tangled sienna structure on the left—current state—into a clean purple architectural corridor that races toward bright open light on the right—ideal state/image…
-
Red Canary CFP tracker: June 2026
Red Canary's monthly roundup of upcoming security conferences and call for papers (CFP) submission deadlines June 2026
-
Paid, Hidden, and Legal: Covert Political Sponsorship Between FARA and the FEC
U.S. election law catches covert paid influence only when a foreign principal is involved. A narrow federal statute can close the gap without becoming a censorship regime.
-
Investigating suspicious AI workflows in Microsoft Entra Agent ID: Agent’s user account
Entra ID agent users can send malicious content to human users via Microsoft Teams. Here’s what to look out for.
-
1,000 Data Breaches Later, the Disclosure Lag is Worse Than Ever
Today, I loaded the 1,000th data breach into Have I Been Pwned . Reflecting on that milestone number, I pondered how to mark the occasion in writing, and what immediately came to mind was a very simple question: why is it still ne…
-
Edmunds: 177,860 accounts breached
Data exposed: Device information, Email addresses, IP addresses, Passwords, Phone numbers, Usernames. In January 2026, the automotive research and car-shopping platform Edmunds was listed by the ShinyHunters hacking group as havin…
-
Weekly Update 506
I m finding it quite fascinating to watch the current spate of ShinyHunters breaches and dumps. There s the obvious criminality of it all, but then there s also the response from organisations (or lack thereof, as it relates to di…
-
CVE-2024-21182: Oracle WebLogic Server — Oracle WebLogic Server Unspecified Vulnerability
Oracle WebLogic contains an unspecified vulnerability that could allow an unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unaut…
-
The Top 11 Cybersecurity Risks to Small Businesses
I frequently am asked what the biggest cybersecurity risks are for small businesses. While every business is unique, and, as a result, is vulnerable to somewhat different dangers than every other business, there are certain common…
-
Après-climb: the Security + Privacy Weekend Magazine for May 30–31, 2026
Your weekend magazine for Information Security Data Privacy! InfoSecSherpa Sherpa Intelligence : Your Guides Up a Mountain of Information! Tools Resources ⚙️ 200+ Review Questions for Getting Started in Industrial (ICS/OT) Cyber S…
-
Atlas Menu: 63,926 accounts breached
Data exposed: Email addresses, IP addresses, Passwords, Support tickets, Usernames. In May 2026, the GTA V and CS2 cheat service Atlas Menu suffered a data breach. An attacker claimed to have gained access to all Atlas systems and…
-
Weekly Cyber Update: 29 May 2026
Drupal and TrendAI vulnerabilities are exploited in the wild; fake AI web pages install infostealers; Kali365 PhaaS platform steals credentials; and GCHQ sounds the alarm over AI The Cyber Threat Intelligence Briefing is a weekly …
-
CVE-2026-0257: Palo Alto Networks PAN-OS — Palo Alto Networks PAN-OS Authentication Bypass Vulnerability
Palo Alto Networks PAN-OS contains an authentication bypass vulnerability that allows attackers to bypass security restrictions and establish an unauthorized VPN connection.
-
Breaking the Patch Sound Barrier Part 2: So Is The Apocalypse Coming and What Is It?
So, you read my previous blog post about breaking the patch sound barrier , but it left you wanting more? Well, this is that “more.” Gemini blog illustration / steampunk vuln apoc Here are three useful ideas to advance the convers…
-
Charter: 4,851,517 accounts breached
Data exposed: Email addresses, Job titles, Names, Phone numbers, Physical addresses. In May 2026, the telecommunications company Charter Communications (the parent company behind the consumer broadband and cable brand Spectrum) wa…
-
Microsoft’s stance on zero day exploits is a dumpster fire of their own making
Recently, somebody going by the name of Nightmare Eclipse has been having an online beef with Microsoft around security vulnerabilities they claim they had been trying to report. Their posts read like those of a former Microsoft e…
-
Grading on a curve: How to assess a pentest
Defenders don’t need to detect every adversary action to prevent a threat. Here’s a more realistic, optimized approach to testing.
-
Kemper: 269,299 accounts breached
Data exposed: Email addresses, Names, Partial credit card data, Phone numbers, Physical addresses, Purchases. In April 2026, the American insurance holding company Kemper Corporation was named by the ShinyHunters ransomware group …
-
Your Profile Is a Dossier. Here's Who's Reading It.
Your social media profiles are an attacker's dossier. Learn how attackers use public data to build attack playbooks and what you can do to give them less to work with.
-
The Top CISO Stories from Around the Web: May 2026
From the Pentagon overhauling its paper-heavy compliance process to hackers poisoning AI coding assistants with the new "TrapDoor" malware, CISOs are fighting on entirely new battlegrounds. Let’s dive into the major shifts, high-s…
-
My local grocer recently upgraded their self-checkout lanes with some kind of AI loss prevention system, using…
My local grocer recently upgraded their self-checkout lanes with some kind of AI loss prevention system, using overhead cameras to track purchases. So far it's 0-2 for me. The last two times I've gone through the checkout it's err…
-
Before Your MSP Chases CMMC, Take an Honest Look at Your Operations
CMMC is an operating model, not a checklist. Before chasing defense work, audit your MSP's internal operations, including access controls and data handling, to ensure you’re ready for the scrutiny.
-
Investigating suspicious AI workflows in Microsoft Entra Agent ID: Autonomous agents
Read our primer on how to detect and respond to an autonomous agent escalating privileges and persisting in your Entra ID tenant
-
Mytheresa: 84,108 accounts breached
Data exposed: Email addresses, Names, Partial credit card data, Phone numbers, Physical addresses, Purchases, Salutations. In April 2026, the luxury fashion e-commerce platform Mytheresa was listed as a victim of the ShinyHunters …
-
CVE-2026-48027: Nx Nx Console — Nx Console Embedded Malicious Code Vulnerability
Nx Console contains an embedded malicious code vulnerability that allowed a malicious version of Nx Console to be published. The compromised extension fetched an obfuscated payload that could harvested credentials from multiple so…
-
CVE-2026-45321: TanStack TanStack — TanStack Unspecified Vulnerability
TanStack contains an unspecified vulnerability that allowed malicious versions of the product to be published to the npm registry to publish credential-stealing malware under a trusted identity.
-
CVE-2026-8398: Daemon Daemon Tools Lite — Daemon Tools Lite Embedded Malicious Code Vulnerability
Daemon Tools contains an unspecified vulnerability that has a high impact on confidentiality, integrity, and availability.
-
Ameriprise: 502,597 accounts breached
Data exposed: Email addresses, Employers, Financial transactions, Job titles, Names, Phone numbers, Physical addresses. In March 2026, the financial services firm Ameriprise Financial was named by the ShinyHunters group in a "pay …
-
Post-AI Jobs Will Go to a Tiny Sliver
A small elite stands on an elevated platform under cold purple light while a vast crowd in warm sienna looks up from below/images/ai-jobs-tiny-sliver.webp/images/ai-jobs-tiny-sliver.webp I think people are missing the point on the…
-
Calling in to my doctor’s office to schedule my annual physical, and noticed the AI assistant has fake keyboar…
Calling in to my doctor’s office to schedule my annual physical, and noticed the AI assistant has fake keyboard clicking sounds to support the illusion.
-
Security Roundup May 2026
Curated advice, guidance, learning and trends in cybersecurity and privacy, as chosen by our consultants. Verizon DBIR spotlights software vulnerabilities For the first time in the history of Verizon’s Data Breach Investigations R…
-
From Cookies to Keys: The Threat of Session Hijacking
See how session hijacking reshaped cyber threats. Learn how stolen tokens enable rapid breaches, bypass security, and impact enterprise protection.
-
CVE-2026-48172: LiteSpeed cPanel Plugin — LiteSpeed cPanel Plugin Privilege Escalation Vulnerability
LiteSpeed cPanel Plugin contains privilege escalation vulnerability that is exposed via the user-end cPanel plugin, which can be abused by any cPanel user account to execute arbitrary scripts with root privileges.
-
Welcoming the Bhutanese Government to Have I Been Pwned
Today, we welcome the 45th government onboarded to Have I Been Pwned s free gov service: Bhutan. The Bhutan Computer Incident Response Team, BtCIRT, now has access to monitor Bhutanese government domains against the data in HIBP. …
-
Tom Kean Jr.'s X account is still posting. He hasn't been seen since March.
He last cast a vote on March 5. He has missed nearly a hundred since. His party says he sounds fine on the phone. Neighbors haven't seen him in months. Neither has any reporter.
-
What Fostering A Difficult Rescue Dog Taught Me About Cybersecurity Awareness
I didn t expect to learn anything about cybersecurity last week from a dog. I was fostering a rescue Podenco called Robbie. He’d arrived from Spain via a circuitous route — starvation as a hunting dog, abandoned and left as a stra…
-
7-Eleven: 185,256 accounts breached
Data exposed: Dates of birth, Email addresses, Names, Phone numbers, Physical addresses. In April 2026, 7-Eleven was the victim of a "pay or leak" extortion campaign by ShinyHunters , with the data later published that month. The …
-
Could Suddenly-Great Open Source AI Crash the US Economy?
A charcoal architectural sketch: a colossal monolithic tower cracked at the base, washed in deep purple, while a horizontal current of small distributed structures in burnt sienna flows beneath the fracture/images/could-open-sourc…
Last fetch 12m ago · 0 new · 2 source error(s)