A new cyber espionage campaign codenamed Operation Dragon Weave has been observed targeting officials and citizens in the Czech Republic and Taiwan to deliver an AdaptixC2 agent. According to Seqrite Labs, targets of the campaign include government, research, academic, technology, and financial services sectors. The activity entails distributing spear-phishing emails containing ZIP attachments – Read … Read More “China-Aligned Groups Ramp Up Attacks: Dragon Weave Hits Czech Republic & Taiwan – The Hacker News” »
Zero-Click pretalx XSS Flaw Lets Hackers Hijack Conference Organizer Accounts – Hackread – Cybersecurity News, Data Breaches, AI and More
pretalx XSS flaw lets attackers hijack conference organizer accounts, steal sessions, auto-accept talks, and demote admins. Patched in v2026.1.0. – Read More – Hackread – Cybersecurity News, Data Breaches, AI and More
How to Get a Reddit API Key in 2026: Step-by-Step Guide – Hackread – Cybersecurity News, Data Breaches, AI and More
Getting a Reddit API key starts with creating an application through Reddit’s developer portal and understanding how its… – Read More – Hackread – Cybersecurity News, Data Breaches, AI and More
⚡ Weekly Recap: New Linux Flaw, PAN-OS Exploit, AI-Powered Attacks, OAuth Phishing and More – The Hacker News
Monday hit like a cron job with anger issues. A busted auth path here, a repo-side faceplant there, some “patched-ish” thing already getting chewed on in the wild, and then the usual bonus round: poisoned dev tools, sketchy forum chatter, phishing kits pretending to be productivity, and AI lowering the bar for people who already … Read More “⚡ Weekly Recap: New Linux Flaw, PAN-OS Exploit, AI-Powered Attacks, OAuth Phishing and More – The Hacker News” »
Obsidian publishes PoC for a 1-click Flowise RCE that can fully compromise self-hosted servers – Read More –
Infosecurity Europe: Tabletop Exercise to Test How CISOs Respond to Major Supermarket Cyber-Attack –
Semperis is set to bring ‘Enter the War Room: A Tabletop Experience’ to Infosecurity Europe to help cybersecurity leaders prepare to face real incidents – Read More –
Fake Purchase Order Emails Spread Fileless PureLogs Malware via RAR Archives – Hackread – Cybersecurity News, Data Breaches, AI and More
Hackers are using fake purchase order emails and process hollowing to deploy fileless PureLogs malware to steal Windows users’ browser, crypto, and Discord data. – Read More – Hackread – Cybersecurity News, Data Breaches, AI and More
Three years ago, the practical question for an MSP building a cybersecurity practice was which “vCISO platform” to buy. The term was good shorthand for the work at the time: assessments, advisory, reporting, maybe a compliance module bolted on the side. The work has since outgrown the descriptor. A Security Growth Platform is the more … Read More “The Security Growth Platform: Why MSPs Are Moving Beyond vCISO Tools – The Hacker News” »
How to Get the Most From Your Explainer Video Production Services – Hackread – Cybersecurity News, Data Breaches, AI and More
Video can simplify a hard offer, shorten sales conversations, and improve recall. Those gains depend on disciplined planning… – Read More – Hackread – Cybersecurity News, Data Breaches, AI and More
Top cybersecurity vendors said AI won’t replace entry-level – only routine ticket-taking and triage – Read More –
OpenAI Codex Authentication Tokens Stolen in codexui-android npm Supply Chain Attack – The Hacker News
Cybersecurity researchers have disclosed details of a new malicious supply chain campaign that’s targeting developers using OpenAI Codex through a legitimate-looking remote web UI. The tool, named codexui-android, is advertised on GitHub and npm as a remote web UI for OpenAI Codex, attracting over 29,000 weekly downloads. The package is still available for download from … Read More “OpenAI Codex Authentication Tokens Stolen in codexui-android npm Supply Chain Attack – The Hacker News” »
FSB-linked Gamaredon concealed a fileless worm in NTFS data streams to spy on Ukraine targets – Read More –
An unknown threat actor has been observed using a large language model (LLM) agent to conduct post-compromise actions after obtaining initial access following the exploitation of a publicly-accessible Marimo network using a recently disclosed vulnerability. “The attacker compromised an internet-reachable Marimo notebook via CVE-2026-39987, extracted two cloud credentials from the compromised – Read More – … Read More “Attackers Use LLM Agent for Post-Exploitation After Marimo CVE-2026-39987 Exploit – The Hacker News” »
Threat actors are attempting to actively exploit a critical security flaw impacting WP Maps Pro, a WordPress plugin that has had over 15,000 sales on the Envato Market, to create malicious administrator accounts on susceptible sites. WP Maps Pro allows site owners to embed customizable Google Maps and OpenStreetMap with markers, listings, and advanced location … Read More “Critical WP Maps Pro Flaw Actively Exploited to Create Admin Accounts – The Hacker News” »
Cybersecurity threats to the 2026 midterm elections are targeting the accounts and platforms that campaigns, donors and voters use to communicate, according to a security report released Monday by Check Point Software Technologies. So far in this election cycle, threats are not aimed at voting machines or ballot-counting systems. Instead, threat actors are going after … Read More “Election threats are focused on campaign systems, not voting machines – CyberScoop” »
Push Security says threat actors are delivering malware hosted on chatgpt.com/s/ domain – Read More –
A vulnerability in Palo Alto Networks’ PAN-OS software is being exploited in attacks – Read More –
OWASP’s new Agentic Research Council will aim to connect academic work to operational realities on agentic AI security – Read More –
bmcweb (OpenBMC web server): four vulnerabilities — two unfixed, GHSA without a CVE – Full Disclosure
Posted by binreaper via Fulldisclosure on May 31 Hi all, Posting a brief summary of a four-finding disclosure on bmcweb (the OpenBMC HTTP/Redfish web server), which ships in BMC firmware on most modern enterprise servers — Intel, IBM, HPE, NVIDIA, and various ODMs. Full timeline and analysis on the blog: https://binreaper.pages.dev/posts/2026-05-27-bmcweb-disclosure/ ## Why bmcweb … Read More “bmcweb (OpenBMC web server): four vulnerabilities — two unfixed, GHSA without a CVE – Full Disclosure” »
CyberDanube Security Research 20260528-0 | Multiple Vulnerabilities in Multiple Vulnerabilities in Mennekes Amtron Series – Full Disclosure
Posted by Thomas Weber | CyberDanube via Fulldisclosure on May 31 CyberDanube Security Research 20260528-0 ——————————————————————————- title| Multiple Vulnerabilities product| Mennekes Amtron Series and Smart-T PnC vulnerable version| 5.22.3 fixed version| 5.33.11-21500 CVE number| CVE-2026-8979, CVE-2026-8980 impact| High homepage| https://www.mennekes.at/ found|… – Read More – Full Disclosure
27,000-Download Codex UI Tool Secretly Stole OpenAI Refresh Tokens – Hackread – Cybersecurity News, Data Breaches, AI and More
A malicious Codex UI npm package with 27,000 weekly downloads was caught exfiltrating OpenAI refresh tokens, exposing developers to account takeover risks. – Read More – Hackread – Cybersecurity News, Data Breaches, AI and More
Dutch authorities have announced the takedown of a botnet that enslaved millions of infected devices, including computers, tablets, smartphones, and IoT devices, to carry out malicious attacks. The bot network, per the Dutch Politie and the National Cyber Security Center (NCSC), consisted of at least 17 million infected devices. More than 200 servers located in … Read More “Dutch Authorities Dismantle Botnet Linked to 17 Million Infected Devices – The Hacker News” »
Fake Anthropic Sites Deliver Fileless Infostealer to Claude Code Users – Hackread – Cybersecurity News, Data Breaches, AI and More
Fake Anthropic websites are being used to target Claude Code users with a fileless infostealer campaign that steals browser credentials and evades detection. – Read More – Hackread – Cybersecurity News, Data Breaches, AI and More
PAN-OS GlobalProtect Authentication Bypass (CVE-2026-0257) Under Active Exploitation – The Hacker News
Palo Alto Networks has warned that a recently disclosed medium-severity security flaw impacting PAN-OS and Prisma Access has come under active exploitation in the wild. The vulnerability, tracked as CVE-2026-0257 (CVSS score: 7.8), refers to a case of authentication bypass that could be exploited by bad actors to set up VPN connections. “Authentication bypass vulnerabilities … Read More “PAN-OS GlobalProtect Authentication Bypass (CVE-2026-0257) Under Active Exploitation – The Hacker News” »
Cybersecurity researchers have disclosed details of a vulnerability in OpenAI ChatGPT that leverages the artificial intelligence (AI) assistant’s implicit trust in Markdown links and images to trigger prompt injections and open the door to phishing attacks. The technique has been codenamed ChatGPhish by Permiso Security. “The chatgpt.com response renderer trusts Markdown links and Markdown – … Read More “ChatGPhish Vulnerability Turns ChatGPT Web Summaries Into a Phishing Surface – The Hacker News” »
Tennessee man linked to 764 accused of series of crimes against children dating back to 2022 – CyberScoop
A Tennessee man accused of abusing and sexually exploiting children while actively participating in 764, a sprawling online nihilistic violent extremist collective affiliated with The Com, pleaded not guilty Thursday to a series of charges that could keep him locked up for 50 years. Zachary Sweeney has allegedly victimized multiple children, on numerous occasions grooming … Read More “Tennessee man linked to 764 accused of series of crimes against children dating back to 2022 – CyberScoop” »
A Department of Commerce inspector general report released Thursday found that the National Institute of Standards and Technology has mismanaged a critical cybersecurity vulnerability database through poor planning, inefficient operations, duplicate federal programs, and failure to communicate with users. The National Vulnerability Database, maintained by NIST since 2005, collects information about computer security flaws and … Read More “Federal audit reveals NIST’s NVD is plagued by poor planning and duplication – CyberScoop” »
Threat actors from the Silent Ransom Group, aka Luna Moth, are escalating attacks by impersonating IT staff in phone calls and even showing up in person to gain direct access to victim systems – Read More –
The Deliverability Problem: How New Platforms Are Solving Inbox Placement – Hackread – Cybersecurity News, Data Breaches, AI and More
Email still reaches more people than any other digital channel. Getting it to actually land in the inbox… – Read More – Hackread – Cybersecurity News, Data Breaches, AI and More
A previously undocumented threat actor dubbed GREYVIBE has been attributed to ongoing and persistent attacks targeting Ukraine and Ukraine-related entities since at least August 2025. GREYVIBE, per WithSecure, is assessed to be a Russian-speaking group operating broadly in the Russian time zone, with the activities aligning with Kremlin state interests, specifically when it comes to … Read More “New Russian-Linked GREYVIBE Targets Ukraine with AI-Powered Cyberattacks – The Hacker News” »
Microsoft Slams Public Zero-Day Disclosures Amid GitHub Researcher Account Removal – The Hacker News
Microsoft has come out strongly in favor of Coordinated Vulnerability Disclosure (CVD), urging the research community to share their findings and give affected vendors an opportunity to better understand the impact and address them before they are publicly disclosed. The development comes after a researcher named Chaotic Eclipse (aka Nightmare-Eclipse) disclosed details of multiple zero-day … Read More “Microsoft Slams Public Zero-Day Disclosures Amid GitHub Researcher Account Removal – The Hacker News” »
What 2,000 Exposed Vibe-Coded Apps Reveal About the Limits of Most Security Stacks – The Hacker News
Shadow AI used to mean employees pasting things they shouldn’t into ChatGPT. It now means something bigger: employees building full applications with AI, wiring them into production systems, and publishing them on the open internet. Without Security or IT in the loop. The artifact moved from a prompt to a product. The risk surface moved … Read More “What 2,000 Exposed Vibe-Coded Apps Reveal About the Limits of Most Security Stacks – The Hacker News” »
Malicious Sicoob NuGet Steals Banking Credentials as npm Packages Target Cloud Secrets – The Hacker News
Cybersecurity researchers have discovered a malicious NuGet package that masquerades as a C# software development kit for Sicoob, one of Brazil’s largest cooperative financial systems, to siphon client IDs and PFX certificates. According to Socket, versions 2.0.0 through 2.0.4 of “Sicoob.Sdk” contain functionality to exfiltrate sensitive information, including PFX certificates that are used to – … Read More “Malicious Sicoob NuGet Steals Banking Credentials as npm Packages Target Cloud Secrets – The Hacker News” »
From a research-driven pilot, the Cybersecurity Communities of Support (CyCOS) is about to be handed over to CIISec – Read More –
Cybermindz warns that cybersecurity burnout is a growing risk, urging organizations to move beyond wellness initiatives and adopt a measurable, risk-based approach to workforce stress – Read More –
Sloppy AI-generated npm infostealer leaked its own GitHub token, exposing the operator – Read More –
ESET’s 2026 APT Activity Report suggests China-backed APTs are using instability in the region to target victims, as well as continuing activity against organizations around the globe – Read More –
Dutch police have arrested a 35-year-old man suspected of hacking into the computer systems of Amsterdam football giant Ajax, after the personal data of hundreds of thousands of supporters was put at risk. Read more in my article on the Hot for Security blog. – Read More – GRAHAM CLULEY
The North Korean state-sponsored threat actor known as Kimsuky (aka Velvet Chollima) has been attributed to a fresh set of cyber attacks targeting South Korean military and corporate entities through March and April 2026. “Kimsuky employed a range of tailored social engineering tactics, such as spoofing security software installation pages and crafting a fake Webex … Read More “Kimsuky Deploys HTTPSpy, Expands Arsenal with HelloDoor and VS Code Tunnels – The Hacker News” »
The CISO Whisperer’s Watch List For The Gartner Security & Risk Management Summit 2026 – Hackread – Cybersecurity News, Data Breaches, AI and More
New York, USA, 28th May 2026, CyberNewswire – Read More – Hackread – Cybersecurity News, Data Breaches, AI and More
Google security engineer accused of turning confidential search trends into $1.2M win on Polymarket – CyberScoop
A Google security engineer was arrested in New York and charged with crimes related to bets he allegedly placed on Polymarket using confidential information he pulled from Google systems, the Justice Department said Wednesday. Michele Spagnuolo, a 36-year-old Italian citizen who lives in Switzerland, is accused of placing multiple trades on the prediction marketplace last … Read More “Google security engineer accused of turning confidential search trends into $1.2M win on Polymarket – CyberScoop” »
A House subcommittee will hold an open hearing next week on how frontier artificial intelligence models are shaping the cybersecurity landscape, for good and for ill. The June 4 hearing will be the second the Homeland Security Subcommittee on Cybersecurity and Infrastructure Protection has held that was focused at least in part on the subject, … Read More “House panel poised to hold hearing centered on AI impact on cyber – CyberScoop” »
Critical Gogs RCE Vulnerability Lets Any Authenticated User Execute Arbitrary Code – The Hacker News
A critical security vulnerability has been disclosed in Gogs, a popular open-source self-hosted Git service, that allows an authenticated user to execute arbitrary code under certain conditions. The security flaw, per Rapid7, is rated 9.4 on the CVSS scoring system. It does not have a CVE identifier. “The vulnerability allows any authenticated user to achieve … Read More “Critical Gogs RCE Vulnerability Lets Any Authenticated User Execute Arbitrary Code – The Hacker News” »
Threat actors are continuing to exploit a critical, now-patched security flaw impacting FortiClient Endpoint Management Server (EMS) deployments to deliver credential-stealing malware. “The campaign abused trusted endpoint management infrastructure to deliver malware across managed endpoints,” Arctic Wolf said. “Threat actors disguised the credential stealer payload as a Fortinet endpoint – Read More – The Hacker … Read More “Threat Actors Exploit Critical FortiClient EMS Flaw to Deploy Credential Stealer – The Hacker News” »
Most malicious open source packages now mimic real code rather than rely on typosquatting – Read More –
ThreatsDay Bulletin: Claude Security Plugin, Azure Priv-Esc, Kali365 MFA Bypass, FIFA Scams +15 More – The Hacker News
Every time you think the industry has finally stopped doing some reckless, low-effort crap, somebody spins up a fresh box full of sketchy loaders, fake installers, recycled social-engineering bait, and enough exposed infrastructure to make you wonder if prod is just a public beta now – meanwhile some researcher casually drops a technique that turns … Read More “ThreatsDay Bulletin: Claude Security Plugin, Azure Priv-Esc, Kali365 MFA Bypass, FIFA Scams +15 More – The Hacker News” »
Every time you think the industry has finally stopped doing some reckless, low-effort crap, somebody spins up a fresh box full of sketchy loaders, fake installers, recycled social-engineering bait, and enough exposed infrastructure to make you wonder if prod is just a public beta now – meanwhile some researcher casually drops a technique that turns … Read More “ThreatsDay Bulletin: Claude Security Plugin, Azure Priv-Esc, Kali365 MFA Bypass, FIFA Scams +15 More – The Hacker News” »
Security researchers chained together five separate weaknesses in the popular workflow automation service Zapier that, if first discovered by a malicious actor, could have granted access to millions of user accounts and the systems those accounts connect to. The flaws, disclosed by security firm Token Security, did not require malware or insider access. The only … Read More “Zapier fixes bug chain that researchers say risked widespread account takeover – CyberScoop” »
A notorious ransomware gang claims to have stolen MyPillow’s private data, but CEO Mike Lindell calls it a politically motivated “hit job.” With the countdown ticking toward a massive dark web leak, who is telling the truth? Read more in my article on the Hot for Security blog. – Read More – GRAHAM CLULEY
New AI Usage Report: Enterprise AI Risk Is Heavily Concentrated Among a Small Group of AI “Power users” – The Hacker News
State of AI Usage Report 2026 (full report here) by LayerX Security reveals the extent of the enterprise AI visibility gap and why most organizations still don’t understand where their AI exposure is actually coming from. The research shows that enterprise AI risk is not distributed evenly across users or platforms. Instead, it is heavily … Read More “New AI Usage Report: Enterprise AI Risk Is Heavily Concentrated Among a Small Group of AI “Power users” – The Hacker News” »





