Skip to content
AttackFeed by Joe Wagner | Cybersecurity News from Across the Internet

AttackFeed by Joe Wagner

Cybersecurity News from Across the Internet

  • Attack/News Feeds
  • Gov Alerts/ISAC Feeds
  • Vulnerability Alerts
  • Privacy/Governance Feeds
  • Fraud Feeds
  • iOS App
  • Android App
AttackFeed by Joe Wagner | ZAST.AI Raises $6M Pre-A to Scale "Zero False Positive" AI-Powered Code Security  - The Hacker News
Attack Feeds
ZAST.AI Raises $6M Pre-A to Scale “Zero False Positive” AI-Powered Code Security  – The Hacker News
February 10, 2026
AttackFeed by Joe Wagner | CrowdStrike disrupts Glassworm botnet that preyed on open-source supply chain  - CyberScoop
Attack Feeds
CrowdStrike disrupts Glassworm botnet that preyed on open-source supply chain  – CyberScoop
May 27, 2026
AttackFeed by Joe Wagner | Hack-for-hire spyware campaign targets journalists in Middle East, North Africa  - CyberScoop
Attack Feeds
Hack-for-hire spyware campaign targets journalists in Middle East, North Africa  – CyberScoop
April 8, 2026
AttackFeed by Joe Wagner|Quish Splash QR Code Phishing Campaign Hits 1.6 Million Users  – Hackread – Cybersecurity News, Data Breaches, AI and More
Attack Feeds
Quish Splash QR Code Phishing Campaign Hits 1.6 Million Users  – Hackread – Cybersecurity News, Data Breaches, AI and More
March 26, 2026
AttackFeed by Joe Wagner | ⚡ Weekly Recap: Fast16 Malware, XChat Launch, Federal Backdoor, AI Employee Tracking & More  - The Hacker News
Attack Feeds
⚡ Weekly Recap: Fast16 Malware, XChat Launch, Federal Backdoor, AI Employee Tracking & More  – The Hacker News
April 27, 2026
AttackFeed by Joe Wagner | New PHP Composer Flaws Enable Arbitrary Command Execution — Patches Released  - The Hacker News
Attack Feeds
New PHP Composer Flaws Enable Arbitrary Command Execution — Patches Released  – The Hacker News
April 14, 2026

Attackers hit vulnerabilities hard last year, making exploits the top entry point for breaches  – CyberScoop

Posted on May 19, 2026 By Matt Kapko No Comments on Attackers hit vulnerabilities hard last year, making exploits the top entry point for breaches  – CyberScoop
Attackers hit vulnerabilities hard last year, making exploits the top entry point for breaches  – CyberScoop
Attack Feeds

Attackers couldn’t get enough of the vulnerabilities at their disposal last year, making exploits the top initial access vector across more than 22,000 breaches Verizon analyzed in its latest Data Breach Investigations Report released Tuesday. The massive annual study uncovered a surge of exploited vulnerabilities during a one-year period ending in October 2025. Exploited defects … Read More “Attackers hit vulnerabilities hard last year, making exploits the top entry point for breaches  – CyberScoop” »

Trapdoor Android Ad Fraud Scheme Hit 659 Million Daily Bid Requests Using 455 Apps  – The Hacker News

Posted on May 19, 2026 By [email protected] (The Hacker News) No Comments on Trapdoor Android Ad Fraud Scheme Hit 659 Million Daily Bid Requests Using 455 Apps  – The Hacker News
Trapdoor Android Ad Fraud Scheme Hit 659 Million Daily Bid Requests Using 455 Apps  – The Hacker News
Attack Feeds

Cybersecurity researchers have disclosed details of a new ad fraud and malvertising operation dubbed Trapdoor targeting Android device users. The activity, per HUMAN’s Satori Threat Intelligence and Research Team, encompassed 455 malicious Android apps and 183 threat actor-owned command-and-control (C2) domains, turning the infrastructure into a pipeline for multi-stage fraud. “Users  – Read More  – … Read More “Trapdoor Android Ad Fraud Scheme Hit 659 Million Daily Bid Requests Using 455 Apps  – The Hacker News” »

Pwn2Own Berlin 2026 Closes With $1.3 Million in Zero-Day Payouts  – Hackread – Cybersecurity News, Data Breaches, AI and More

Posted on May 19, 2026 By Deeba Ahmed No Comments on Pwn2Own Berlin 2026 Closes With $1.3 Million in Zero-Day Payouts  – Hackread – Cybersecurity News, Data Breaches, AI and More
Pwn2Own Berlin 2026 Closes With $1.3 Million in Zero-Day Payouts  – Hackread – Cybersecurity News, Data Breaches, AI and More
Attack Feeds

Cybersecurity researchers successfully demonstrated 47 unique zero-day exploits at Pwn2Own Berlin 2026, targeting major enterprise software and AI platforms.  – Read More  – Hackread – Cybersecurity News, Data Breaches, AI and More 

How Parts Inventory Management Software Fixes Inventory Challenges  – Hackread – Cybersecurity News, Data Breaches, AI and More

Posted on May 19, 2026 By Owais Sultan No Comments on How Parts Inventory Management Software Fixes Inventory Challenges  – Hackread – Cybersecurity News, Data Breaches, AI and More
How Parts Inventory Management Software Fixes Inventory Challenges  – Hackread – Cybersecurity News, Data Breaches, AI and More
Attack Feeds

Why do maintenance teams struggle? Is it because they lack skills? Or do they need more advanced resources?…  – Read More  – Hackread – Cybersecurity News, Data Breaches, AI and More 

Criminal IP Returns to Infosecurity Europe 2026 with Advanced AI-Driven TI & ASM  – Hackread – Cybersecurity News, Data Breaches, AI and More

Posted on May 19, 2026 By CyberNewswire No Comments on Criminal IP Returns to Infosecurity Europe 2026 with Advanced AI-Driven TI & ASM  – Hackread – Cybersecurity News, Data Breaches, AI and More
Criminal IP Returns to Infosecurity Europe 2026 with Advanced AI-Driven TI & ASM  – Hackread – Cybersecurity News, Data Breaches, AI and More
Attack Feeds

Torrance, United States / California, 19th May 2026, CyberNewswire  – Read More  – Hackread – Cybersecurity News, Data Breaches, AI and More 

Mini Shai-Hulud returns, compromising hundreds of npm packages  – CyberScoop

Posted on May 19, 2026 By Greg Otto No Comments on Mini Shai-Hulud returns, compromising hundreds of npm packages  – CyberScoop
Mini Shai-Hulud returns, compromising hundreds of npm packages  – CyberScoop
Attack Feeds

A self-replicating malware campaign known as Mini Shai-Hulud has resurfaced, this time embedding itself across hundreds of npm packages. The threat actor behind it, identified as TeamPCP, has been linked to earlier waves of the same campaign, with this latest variant more capable than previous waves. Researchers analyzing the payload found a worm that spreads … Read More “Mini Shai-Hulud returns, compromising hundreds of npm packages  – CyberScoop” »

DirtyDecrypt PoC Released for Linux Kernel CVE-2026-31635 LPE Vulnerability  – The Hacker News

Posted on May 19, 2026 By [email protected] (The Hacker News) No Comments on DirtyDecrypt PoC Released for Linux Kernel CVE-2026-31635 LPE Vulnerability  – The Hacker News
DirtyDecrypt PoC Released for Linux Kernel CVE-2026-31635 LPE Vulnerability  – The Hacker News
Attack Feeds

Proof-of-concept (PoC) exploit code has now been released for a recently patched security flaw in the Linux kernel that could allow for local privilege escalation (LPE). Dubbed DirtyDecrypt (aka DirtyCBC), the vulnerability was discovered and reported by the Zellic and V12 security team on May 9, 2026, only to be informed by the maintainers that … Read More “DirtyDecrypt PoC Released for Linux Kernel CVE-2026-31635 LPE Vulnerability  – The Hacker News” »

Microsoft disrupts cybercrime service that abused software verification systems en masse  – CyberScoop

Posted on May 19, 2026 By Matt Kapko No Comments on Microsoft disrupts cybercrime service that abused software verification systems en masse  – CyberScoop
Microsoft disrupts cybercrime service that abused software verification systems en masse  – CyberScoop
Attack Feeds

Microsoft seized infrastructure and disrupted a cybercrime service that created and sold more than 1,000 code-signing certificates that other cybercriminals used to make malware-riddled software appear trusted and legitimate for follow-on cyberattacks, including ransomware, the company said Tuesday. The financially-motivated threat group, which Microsoft tracks as Fox Tempest, provided the malware-signing-as-a-service to multiple ransomware groups, … Read More “Microsoft disrupts cybercrime service that abused software verification systems en masse  – CyberScoop” »

Microsoft Takes Down Fox Tempest for Providing Ransomware-Enabling Signing Tool –

Posted on May 19, 2026 By Joe-W No Comments on Microsoft Takes Down Fox Tempest for Providing Ransomware-Enabling Signing Tool –
Microsoft Takes Down Fox Tempest for Providing Ransomware-Enabling Signing Tool –
Privacy/Governance Feed

Microsoft’s Digital Crimes Unit has taken down the infrastructure of Fox Tempest, a prolific cybercrime-enabling threat group – Read More  –  

Security Researchers Find 47 Zero-Days at Pwn2Own Berlin –

Posted on May 19, 2026 By Joe-W No Comments on Security Researchers Find 47 Zero-Days at Pwn2Own Berlin –
Security Researchers Find 47 Zero-Days at Pwn2Own Berlin –
Privacy/Governance Feed

The research community was awarded $1.3m as it found dozens of novel vulnerabilities at Pwn2Own Berlin – Read More  –  

Two-Thirds of Nonhuman Accounts Are Unseen and Unmanaged, According to Orchid Security’s Identity Gap Report  – Hackread – Cybersecurity News, Data Breaches, AI and More

Posted on May 19, 2026 By CyberNewswire No Comments on Two-Thirds of Nonhuman Accounts Are Unseen and Unmanaged, According to Orchid Security’s Identity Gap Report  – Hackread – Cybersecurity News, Data Breaches, AI and More
Two-Thirds of Nonhuman Accounts Are Unseen and Unmanaged, According to Orchid Security’s Identity Gap Report  – Hackread – Cybersecurity News, Data Breaches, AI and More
Attack Feeds

New York, United States, 19th May 2026, CyberNewswire  – Read More  – Hackread – Cybersecurity News, Data Breaches, AI and More 

Drupal to Release Urgent Core Security Updates on May 20, Sites Told to Prepare  – The Hacker News

Posted on May 19, 2026 By [email protected] (The Hacker News) No Comments on Drupal to Release Urgent Core Security Updates on May 20, Sites Told to Prepare  – The Hacker News
Drupal to Release Urgent Core Security Updates on May 20, Sites Told to Prepare  – The Hacker News
Attack Feeds

Drupal has issued an alert stating that it intends to release a “core security release” for all supported branches on May 20, 2026, from 5-9 p.m. UTC. “The Drupal Security Team urges you to reserve time for core updates at that time because exploits might be developed within hours or days,” the maintainers of the … Read More “Drupal to Release Urgent Core Security Updates on May 20, Sites Told to Prepare  – The Hacker News” »

The New Phishing Click: How OAuth Consent Bypasses MFA  – The Hacker News

Posted on May 19, 2026 By [email protected] (The Hacker News) No Comments on The New Phishing Click: How OAuth Consent Bypasses MFA  – The Hacker News
The New Phishing Click: How OAuth Consent Bypasses MFA  – The Hacker News
Attack Feeds

In February 2026, a phishing-as-a-service (PhaaS) platform called EvilTokens went live. Within five weeks, it had compromised more than 340 Microsoft 365 organizations across five countries.  The targets of the platform received a message asking them to enter a short code at microsoft.com/devicelogin and complete their normal MFA challenge, then walked away believing they had … Read More “The New Phishing Click: How OAuth Consent Bypasses MFA  – The Hacker News” »

Agentic AI Accelerates Software Builds and Mobile App Attacks –

Posted on May 19, 2026 By Joe-W No Comments on Agentic AI Accelerates Software Builds and Mobile App Attacks –
Agentic AI Accelerates Software Builds and Mobile App Attacks –
Privacy/Governance Feed

Digital.ai data reveals 87% of apps were attacked over the past year – Read More  –  

AI Raises the Bar on Vulnerability Awareness and Secure-by-Design Software –

Posted on May 19, 2026 By Joe-W No Comments on AI Raises the Bar on Vulnerability Awareness and Secure-by-Design Software –
AI Raises the Bar on Vulnerability Awareness and Secure-by-Design Software –
Privacy/Governance Feed

AI-powered vulnerability scanning leaves no excuse for unpatched bugs as the EU Cyber Resilience Act pushes firms toward secure-by-design software – Read More  –  

Hackers Actively Exploit ‘Nginx Rift’ Vulnerability Affecting NGINX, F5 Products  – Hackread – Cybersecurity News, Data Breaches, AI and More

Posted on May 19, 2026 By Deeba Ahmed No Comments on Hackers Actively Exploit ‘Nginx Rift’ Vulnerability Affecting NGINX, F5 Products  – Hackread – Cybersecurity News, Data Breaches, AI and More
Hackers Actively Exploit ‘Nginx Rift’ Vulnerability Affecting NGINX, F5 Products  – Hackread – Cybersecurity News, Data Breaches, AI and More
Attack Feeds

Hackers are actively exploiting the Nginx Rift vulnerability affecting NGINX and F5 products, exposing servers to denial-of-service attacks.  – Read More  – Hackread – Cybersecurity News, Data Breaches, AI and More 

Hosting Service Standards That Define High-Performing Agencies  – Hackread – Cybersecurity News, Data Breaches, AI and More

Posted on May 19, 2026 By Owais Sultan No Comments on Hosting Service Standards That Define High-Performing Agencies  – Hackread – Cybersecurity News, Data Breaches, AI and More
Hosting Service Standards That Define High-Performing Agencies  – Hackread – Cybersecurity News, Data Breaches, AI and More
Attack Feeds

There’s a quiet pattern among the agencies that consistently outperform their competitors. Their client retention rates are higher.…  – Read More  – Hackread – Cybersecurity News, Data Breaches, AI and More 

Hackers Actively Exploit ‘Nginx Rift’ Vulnerability Affecting NGINX, F5 Products  – Hackread – Cybersecurity News, Data Breaches, AI and More

Posted on May 19, 2026 By Deeba Ahmed No Comments on Hackers Actively Exploit ‘Nginx Rift’ Vulnerability Affecting NGINX, F5 Products  – Hackread – Cybersecurity News, Data Breaches, AI and More
Hackers Actively Exploit ‘Nginx Rift’ Vulnerability Affecting NGINX, F5 Products  – Hackread – Cybersecurity News, Data Breaches, AI and More
Attack Feeds

Hackers are actively exploiting the Nginx Rift vulnerability affecting NGINX and F5 products, exposing servers to denial-of-service attacks.  – Read More  – Hackread – Cybersecurity News, Data Breaches, AI and More 

SEPPMail Secure E-Mail Gateway Vulnerabilities Enable RCE and Mail Traffic Access  – The Hacker News

Posted on May 19, 2026 By [email protected] (The Hacker News) No Comments on SEPPMail Secure E-Mail Gateway Vulnerabilities Enable RCE and Mail Traffic Access  – The Hacker News
SEPPMail Secure E-Mail Gateway Vulnerabilities Enable RCE and Mail Traffic Access  – The Hacker News
Attack Feeds

Critical security vulnerabilities have been disclosed in SEPPMail Secure E-Mail Gateway, an enterprise-grade email security solution, that could be exploited to achieve remote code execution and enable an attacker to read arbitrary mails from the virtual appliance. “These vulnerabilities could have been exploited to read all mail traffic or as an entry vector into the … Read More “SEPPMail Secure E-Mail Gateway Vulnerabilities Enable RCE and Mail Traffic Access  – The Hacker News” »

SEPPMail Secure E-Mail Gateway Vulnerabilities Enable RCE and Mail Traffic Access  – The Hacker News

Posted on May 19, 2026 By [email protected] (The Hacker News) No Comments on SEPPMail Secure E-Mail Gateway Vulnerabilities Enable RCE and Mail Traffic Access  – The Hacker News
SEPPMail Secure E-Mail Gateway Vulnerabilities Enable RCE and Mail Traffic Access  – The Hacker News
Attack Feeds

Critical security vulnerabilities have been disclosed in SEPPMail Secure E-Mail Gateway, an enterprise-grade email security solution, that could be exploited to achieve remote code execution and enable an attacker to read arbitrary mails from the virtual appliance. “These vulnerabilities could have been exploited to read all mail traffic or as an entry vector into the … Read More “SEPPMail Secure E-Mail Gateway Vulnerabilities Enable RCE and Mail Traffic Access  – The Hacker News” »

Why HSMs Are Central to Any Quantum-Safe Migration Strategy – JISA Softech Pvt Ltd

Posted on May 19, 2026 By Aakash Chaudhary No Comments on Why HSMs Are Central to Any Quantum-Safe Migration Strategy – JISA Softech Pvt Ltd
Why HSMs Are Central to Any Quantum-Safe Migration Strategy – JISA Softech Pvt Ltd
Privacy/Governance Feed

In August 2024, NIST finalised its first set of post-quantum cryptographic standards, ML-KEM, ML-DSA, and SLH-DSA, marking a watershed… The post Why HSMs Are Central to Any Quantum-Safe Migration Strategy appeared first on JISA Softech Pvt Ltd.  – Read More  – JISA Softech Pvt Ltd 

Grafana Labs Confirms Hackers Stole Source Code –

Posted on May 19, 2026 By Joe-W No Comments on Grafana Labs Confirms Hackers Stole Source Code –
Grafana Labs Confirms Hackers Stole Source Code –
Privacy/Governance Feed

Open source tool maker Grafana says hackers stole codebase via GitHub breach – Read More  –  

Compromised Nx Console 18.95.0 Targeted VS Code Developers with Credential Stealer  – The Hacker News

Posted on May 19, 2026 By [email protected] (The Hacker News) No Comments on Compromised Nx Console 18.95.0 Targeted VS Code Developers with Credential Stealer  – The Hacker News
Compromised Nx Console 18.95.0 Targeted VS Code Developers with Credential Stealer  – The Hacker News
Attack Feeds

Cybersecurity researchers have flagged a compromised version of the Nx Console extension that was published to the Microsoft Visual Studio Code (VS Code) Marketplace. The extension in question is rwl.angular-console (version 18.95.0), a popular user interface and plugin for code editors like VS Code, Cursor, and JetBrains. The VS Code extension has more than 2.2 … Read More “Compromised Nx Console 18.95.0 Targeted VS Code Developers with Credential Stealer  – The Hacker News” »

Hackers Bypass Security Tools to Target Users Directly –

Posted on May 19, 2026 By Joe-W No Comments on Hackers Bypass Security Tools to Target Users Directly –
Hackers Bypass Security Tools to Target Users Directly –
Privacy/Governance Feed

Bridewell report calls out emergence of “fix-style” attacks – Read More  –  

Mini Shai-Hulud Pushes Malicious AntV npm Packages via Compromised Maintainer Account  – The Hacker News

Posted on May 19, 2026 By [email protected] (The Hacker News) No Comments on Mini Shai-Hulud Pushes Malicious AntV npm Packages via Compromised Maintainer Account  – The Hacker News
Mini Shai-Hulud Pushes Malicious AntV npm Packages via Compromised Maintainer Account  – The Hacker News
Attack Feeds

Cybersecurity researchers have discovered a fresh software supply chain attack campaign that has compromised various npm packages associated with the @antv ecosystem as part of the ongoing Mini Shai-Hulud attack wave. “The attack affects packages tied to the npm maintainer account atool, including echarts-for-react, a widely used React wrapper for Apache ECharts with roughly 1.1 … Read More “Mini Shai-Hulud Pushes Malicious AntV npm Packages via Compromised Maintainer Account  – The Hacker News” »

GitHub Actions Supply Chain Attack Redirects Tags to Steal CI/CD Credentials  – The Hacker News

Posted on May 19, 2026 By [email protected] (The Hacker News) No Comments on GitHub Actions Supply Chain Attack Redirects Tags to Steal CI/CD Credentials  – The Hacker News
GitHub Actions Supply Chain Attack Redirects Tags to Steal CI/CD Credentials  – The Hacker News
Attack Feeds

In yet another software supply chain attack, threat actors have compromised the popular GitHub Actions workflow, actions-cool/issues-helper, to run malicious code that harvests sensitive credentials and exfiltrates them to an attacker-controlled server. “Every existing tag in the repository has been moved to point to an imposter commit that does not appear in the action’s normal … Read More “GitHub Actions Supply Chain Attack Redirects Tags to Steal CI/CD Credentials  – The Hacker News” »

CISA Admin Leaked AWS GovCloud Keys on Github  – Krebs on Security

Posted on May 18, 2026 By BrianKrebs No Comments on CISA Admin Leaked AWS GovCloud Keys on Github  – Krebs on Security
CISA Admin Leaked AWS GovCloud Keys on Github  – Krebs on Security
Attack Feeds

Until this past weekend, a contractor for the Cybersecurity & Infrastructure Security Agency (CISA) maintained a public GitHub repository that exposed credentials to several highly privileged AWS GovCloud accounts and a large number of internal CISA systems. Security experts said the public archive included files detailing how CISA builds, tests and deploys software internally, and … Read More “CISA Admin Leaked AWS GovCloud Keys on Github  – Krebs on Security” »

Multiple Vulnerabilities in NGINX Could Allow for Remote Code Execution  – Cyber Security Advisories – MS-ISAC

Posted on May 18, 2026 By Joe-W No Comments on Multiple Vulnerabilities in NGINX Could Allow for Remote Code Execution  – Cyber Security Advisories – MS-ISAC
Gov/ISAC Feeds

Multiple vulnerabilities have been discovered in NGINX, the most severe of which could allow for remote code execution. NGINX is a software used for web serving, reverse proxying, caching, and load balancing. Successful exploitation of the most severe of these vulnerabilities may allow an unauthenticated threat actor to crash vulnerable NGINX worker processes by sending … Read More “Multiple Vulnerabilities in NGINX Could Allow for Remote Code Execution  – Cyber Security Advisories – MS-ISAC” »

10 Top OSINT Tools Every Investigator Should Know in 2026  – Hackread – Cybersecurity News, Data Breaches, AI and More

Posted on May 18, 2026 By Owais Sultan No Comments on 10 Top OSINT Tools Every Investigator Should Know in 2026  – Hackread – Cybersecurity News, Data Breaches, AI and More
10 Top OSINT Tools Every Investigator Should Know in 2026  – Hackread – Cybersecurity News, Data Breaches, AI and More
Attack Feeds

Modern OSINT platforms rely more on AI and automation, while older social tracking methods keep losing access due to privacy and API restrictions.  – Read More  – Hackread – Cybersecurity News, Data Breaches, AI and More 

AI might cut false positives, but it won’t stop the slop   – CyberScoop

Posted on May 18, 2026 By djohnson No Comments on AI might cut false positives, but it won’t stop the slop   – CyberScoop
AI might cut false positives, but it won’t stop the slop   – CyberScoop
Attack Feeds

As defenders get their hands on newer AI models with more powerful cybersecurity capabilities like Anthropic’s Mythos and OpenAI’s Daybreak, organizations are being told to prepare for a flood of new vulnerability reports. But for bug bounty programs across the nation, that day may already be here, as yesterday’s frontier models and today’s open-source AI … Read More “AI might cut false positives, but it won’t stop the slop   – CyberScoop” »

Interpol leads cybercrime crackdown across 13 countries in Middle East, North Africa  – CyberScoop

Posted on May 18, 2026 By Matt Kapko No Comments on Interpol leads cybercrime crackdown across 13 countries in Middle East, North Africa  – CyberScoop
Interpol leads cybercrime crackdown across 13 countries in Middle East, North Africa  – CyberScoop
Attack Feeds

Interpol coordinated an expansive investigation with 13 countries in the Middle East and North Africa to disrupt and take down cybercrime operations, including phishing services and tools, malware and scams. The law enforcement effort netted 201 arrests, led to the seizure of 53 servers and disrupted multiple cybercrime services, Interpol said Monday. Operation Ramz, which … Read More “Interpol leads cybercrime crackdown across 13 countries in Middle East, North Africa  – CyberScoop” »

INTERPOL Operation Ramz Disrupts MENA Cybercrime Networks with 201 Arrests  – The Hacker News

Posted on May 18, 2026 By [email protected] (The Hacker News) No Comments on INTERPOL Operation Ramz Disrupts MENA Cybercrime Networks with 201 Arrests  – The Hacker News
INTERPOL Operation Ramz Disrupts MENA Cybercrime Networks with 201 Arrests  – The Hacker News
Attack Feeds

INTERPOL has coordinated a first-of-its-kind cybercrime crackdown across the Middle East and North Africa (MENA) that led to 201 arrests and the identification of an additional 382 suspects. The initiative involved the efforts of 13 countries from the region between October 2025 and February 2026, aiming to investigate and neutralize malicious infrastructure, arrest perpetrators behind … Read More “INTERPOL Operation Ramz Disrupts MENA Cybercrime Networks with 201 Arrests  – The Hacker News” »

New Reaper Malware Uses Fake Microsoft Domain to Steal macOS Passwords  – Hackread – Cybersecurity News, Data Breaches, AI and More

Posted on May 18, 2026 By Deeba Ahmed No Comments on New Reaper Malware Uses Fake Microsoft Domain to Steal macOS Passwords  – Hackread – Cybersecurity News, Data Breaches, AI and More
New Reaper Malware Uses Fake Microsoft Domain to Steal macOS Passwords  – Hackread – Cybersecurity News, Data Breaches, AI and More
Attack Feeds

The newly discovered Reaper malware bypasses Apple’s macOS Tahoe 26.4 security updates to steal passwords, crypto assets, and install a permanent backdoor.  – Read More  – Hackread – Cybersecurity News, Data Breaches, AI and More 

Government Backed Hackers Abuse Cloudflare in Malaysian Espionage Campaign  – Hackread – Cybersecurity News, Data Breaches, AI and More

Posted on May 18, 2026 By Waqas No Comments on Government Backed Hackers Abuse Cloudflare in Malaysian Espionage Campaign  – Hackread – Cybersecurity News, Data Breaches, AI and More
Government Backed Hackers Abuse Cloudflare in Malaysian Espionage Campaign  – Hackread – Cybersecurity News, Data Breaches, AI and More
Attack Feeds

Government Backed Hackers abused Cloudflare storage services in a Malaysian espionage campaign involving hidden C2 systems and data exfiltration.  – Read More  – Hackread – Cybersecurity News, Data Breaches, AI and More 

⚡ Weekly Recap: Exchange 0-Day, npm Worm, Fake AI Repo, Cisco Exploit and More  – The Hacker News

Posted on May 18, 2026 By [email protected] (The Hacker News) No Comments on ⚡ Weekly Recap: Exchange 0-Day, npm Worm, Fake AI Repo, Cisco Exploit and More  – The Hacker News
⚡ Weekly Recap: Exchange 0-Day, npm Worm, Fake AI Repo, Cisco Exploit and More  – The Hacker News
Attack Feeds

Monday opens with a trust problem. A mail server flaw is under active use. A network control system was targeted. Trusted packages were poisoned. A fake model page pushed a stealer. Then came the familiar ransom claim: the data was returned and deleted. The pattern is clear. One weak dependency can leak keys. One leaked … Read More “⚡ Weekly Recap: Exchange 0-Day, npm Worm, Fake AI Repo, Cisco Exploit and More  – The Hacker News” »

10 Tips for Phrasing Employee Feedback in Reviews  – Hackread – Cybersecurity News, Data Breaches, AI and More

Posted on May 18, 2026 By Owais Sultan No Comments on 10 Tips for Phrasing Employee Feedback in Reviews  – Hackread – Cybersecurity News, Data Breaches, AI and More
10 Tips for Phrasing Employee Feedback in Reviews  – Hackread – Cybersecurity News, Data Breaches, AI and More
Attack Feeds

Performance reviews inside cybersecurity teams carry unusually high stakes. Security analysts, incident responders, IT administrators, and compliance staff…  – Read More  – Hackread – Cybersecurity News, Data Breaches, AI and More 

How to Reduce Phishing Exposure Before It Turns into Business Disruption  – The Hacker News

Posted on May 18, 2026 By [email protected] (The Hacker News) No Comments on How to Reduce Phishing Exposure Before It Turns into Business Disruption  – The Hacker News
How to Reduce Phishing Exposure Before It Turns into Business Disruption  – The Hacker News
Attack Feeds

What happens when a phishing email looks clean enough to pass through security, but dangerous enough to expose the business after one click? That is the gap many SOCs still struggle with: the attacks that leave teams unsure what was exposed, who else was targeted, and how far the risk has spread. Early phishing detection … Read More “How to Reduce Phishing Exposure Before It Turns into Business Disruption  – The Hacker News” »

The Infosecurity Europe Cyber Startup Competition: Meet the Finalists –

Posted on May 18, 2026 By Joe-W No Comments on The Infosecurity Europe Cyber Startup Competition: Meet the Finalists –
The Infosecurity Europe Cyber Startup Competition: Meet the Finalists –
Privacy/Governance Feed

New for 2026, the Infosecurity Europe Startup competition will see five finalists pitch their ideas in front of a live audience, including senior industry leaders, investors and buyers – Read More  –  

Interpol Launches Sweeping Cybercrime Crackdown in MENA Region –

Posted on May 18, 2026 By Joe-W No Comments on Interpol Launches Sweeping Cybercrime Crackdown in MENA Region –
Interpol Launches Sweeping Cybercrime Crackdown in MENA Region –
Privacy/Governance Feed

Over 200 people were arrested in an anti-cybercrime operation that spanned 13 countries across the Middle East and North Africa – Read More  –  

The Gentlemen Ransomware Gang Hit by Internal Breach, Operations Exposed  – Hackread – Cybersecurity News, Data Breaches, AI and More

Posted on May 18, 2026 By Waqas No Comments on The Gentlemen Ransomware Gang Hit by Internal Breach, Operations Exposed  – Hackread – Cybersecurity News, Data Breaches, AI and More
The Gentlemen Ransomware Gang Hit by Internal Breach, Operations Exposed  – Hackread – Cybersecurity News, Data Breaches, AI and More
Attack Feeds

The Gentlemen ransomware gang suffered an internal breach in May 2026, exposing victim data, affiliate activity, and backend operations.  – Read More  – Hackread – Cybersecurity News, Data Breaches, AI and More 

Continuous Detection, Continuous Response: Mate Security Redefines the Modern SOC  – Hackread – Cybersecurity News, Data Breaches, AI and More

Posted on May 18, 2026 By CyberNewswire No Comments on Continuous Detection, Continuous Response: Mate Security Redefines the Modern SOC  – Hackread – Cybersecurity News, Data Breaches, AI and More
Continuous Detection, Continuous Response: Mate Security Redefines the Modern SOC  – Hackread – Cybersecurity News, Data Breaches, AI and More
Attack Feeds

New York, USA, 18th May 2026, CyberNewswire  – Read More  – Hackread – Cybersecurity News, Data Breaches, AI and More 

Ivanti, Fortinet, SAP, VMware, n8n Patch RCE, SQL Injection, Privilege Escalation Flaws  – The Hacker News

Posted on May 18, 2026 By [email protected] (The Hacker News) No Comments on Ivanti, Fortinet, SAP, VMware, n8n Patch RCE, SQL Injection, Privilege Escalation Flaws  – The Hacker News
Ivanti, Fortinet, SAP, VMware, n8n Patch RCE, SQL Injection, Privilege Escalation Flaws  – The Hacker News
Attack Feeds

Ivanti, Fortinet, n8n, SAP, and VMware have released security fixes for various vulnerabilities that could be exploited by bad actors to bypass authentication and execute arbitrary code. Topping the list is a critical flaw impacting Ivanti Xtraction (CVE-2026-8043, CVSS score: 9.6) that could be exploited to achieve information disclosure or client-side attacks. “External control of … Read More “Ivanti, Fortinet, SAP, VMware, n8n Patch RCE, SQL Injection, Privilege Escalation Flaws  – The Hacker News” »

Developer Workstations Are Now Part of the Software Supply Chain  – The Hacker News

Posted on May 18, 2026 By [email protected] (The Hacker News) No Comments on Developer Workstations Are Now Part of the Software Supply Chain  – The Hacker News
Developer Workstations Are Now Part of the Software Supply Chain  – The Hacker News
Attack Feeds

Supply chain attackers are not only trying to slip malicious code into trusted software. They are trying to steal the access that makes trusted software possible. Recently, three separate campaigns hit npm, PyPI, and Docker Hub in a 48-hour window, and all three targeted secrets from developer environments and CI/CD pipelines, including API keys, cloud … Read More “Developer Workstations Are Now Part of the Software Supply Chain  – The Hacker News” »

Four Malicious npm Packages Deliver Infostealers and Phantom Bot DDoS Malware  – The Hacker News

Posted on May 18, 2026 By [email protected] (The Hacker News) No Comments on Four Malicious npm Packages Deliver Infostealers and Phantom Bot DDoS Malware  – The Hacker News
Four Malicious npm Packages Deliver Infostealers and Phantom Bot DDoS Malware  – The Hacker News
Attack Feeds

Cybersecurity researchers have discovered four new npm packages containing information-stealing malware, one of which is a clone of the Shai-Hulud worm open-sourced by TeamPCP. The list of identified packages is below – chalk-tempalte (825 Downloads) @deadcode09284814/axios-util (284 Downloads) axois-utils (963 Downloads) color-style-utils (934 Downloads) “One of the packages (chalk-tempalte)  – Read More  – The Hacker … Read More “Four Malicious npm Packages Deliver Infostealers and Phantom Bot DDoS Malware  – The Hacker News” »

NCSC Publishes Guidance on Securing Agentic AI Use –

Posted on May 18, 2026 By Joe-W No Comments on NCSC Publishes Guidance on Securing Agentic AI Use –
NCSC Publishes Guidance on Securing Agentic AI Use –
Privacy/Governance Feed

The UK’s National Cyber Security Centre is helping organizations to understand agentic AI security risks – Read More  –  

The Canvas breach proved that prevention is no longer enough  – CyberScoop

Posted on May 18, 2026 By Greg Otto No Comments on The Canvas breach proved that prevention is no longer enough  – CyberScoop
The Canvas breach proved that prevention is no longer enough  – CyberScoop
Attack Feeds

Earlier this month, ShinyHunters breached Instructure’s Canvas platform twice within a single week — stealing 3.65 terabytes of data from approximately 275 million users across more than 8,000 institutions. The group defaced login pages at hundreds of schools during final exam periods, forced Canvas offline, and extracted a ransom payment before Congress opened a formal … Read More “The Canvas breach proved that prevention is no longer enough  – CyberScoop” »

Post-Quantum Cryptography: A Practical Roadmap for Indian Enterprises – JISA Softech Pvt Ltd

Posted on May 18, 2026 By Aakash Chaudhary No Comments on Post-Quantum Cryptography: A Practical Roadmap for Indian Enterprises – JISA Softech Pvt Ltd
Post-Quantum Cryptography: A Practical Roadmap for Indian Enterprises – JISA Softech Pvt Ltd
Privacy/Governance Feed

Quantum computing is no longer a theoretical field of research or the domain of research labs and academia, but… The post Post-Quantum Cryptography: A Practical Roadmap for Indian Enterprises appeared first on JISA Softech Pvt Ltd.  – Read More  – JISA Softech Pvt Ltd 

MiniPlasma Windows 0-Day Enables SYSTEM Privilege Escalation on Fully Patched Systems  – The Hacker News

Posted on May 18, 2026 By [email protected] (The Hacker News) No Comments on MiniPlasma Windows 0-Day Enables SYSTEM Privilege Escalation on Fully Patched Systems  – The Hacker News
MiniPlasma Windows 0-Day Enables SYSTEM Privilege Escalation on Fully Patched Systems  – The Hacker News
Attack Feeds

Chaotic Eclipse, the security researcher behind the recently disclosed Windows flaws, YellowKey and GreenPlasma, has released a proof-of-concept (PoC) for a Windows privilege escalation zero-day flaw that grants attackers SYSTEM privileges on fully patched Windows systems. Codenamed MiniPlasma, the vulnerability impacts “cldflt.sys,” which refers to the Windows Cloud Files Mini Filter Driver,  – Read More  … Read More “MiniPlasma Windows 0-Day Enables SYSTEM Privilege Escalation on Fully Patched Systems  – The Hacker News” »

Pre-Stuxnet Fast16 Malware Tampered with Nuclear Weapons Simulations  – The Hacker News

Posted on May 18, 2026 By [email protected] (The Hacker News) No Comments on Pre-Stuxnet Fast16 Malware Tampered with Nuclear Weapons Simulations  – The Hacker News
Pre-Stuxnet Fast16 Malware Tampered with Nuclear Weapons Simulations  – The Hacker News
Attack Feeds

A new analysis of the Lua-based fast16 malware has confirmed that it was a cyber sabotage tool designed to tamper with nuclear weapons testing simulations. According to Broadcom-owned Symantec and Carbon Black teams, the pre-Stuxnet tool was engineered to corrupt uranium-compression simulations that are central to nuclear weapon design. “Fast16’s hook engine is selectively interested … Read More “Pre-Stuxnet Fast16 Malware Tampered with Nuclear Weapons Simulations  – The Hacker News” »

Bank of England, FCA and Treasury Raise Alarm Over Frontier AI –

Posted on May 18, 2026 By Joe-W No Comments on Bank of England, FCA and Treasury Raise Alarm Over Frontier AI –
Bank of England, FCA and Treasury Raise Alarm Over Frontier AI –
Privacy/Governance Feed

The UK’s financial authorities have set expectations for the sector on cybersecurity and operational resilience – Read More  –  

Posts pagination

Previous 1 … 4 5 6 … 41 Next
  • Attack Feeds
  • Privacy/Governance Feed
  • Gov/ISAC Feeds
  • Alert Feeds
  • Privacy Policy
  • Wagner Cybersecurity

Copyright © 2026 AttackFeed by Joe Wagner.

Theme: Oceanly News Dark by ScriptsTown

We are using cookies for analytics purposes only.  We do not store, track or sell user information.

You can find out more about which cookies we are using or switch them off in .

AttackFeed by Joe Wagner
Powered by  GDPR Cookie Compliance
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.

Strictly Necessary Cookies

Strictly Necessary Cookie should be enabled at all times so that we can save your preferences for cookie settings.