Know What's Happening in Cybersecurity

Today's Cybersecurity Pulse

CISA adds critical Android and Linux flaws to KEV catalog

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) listed two high‑severity vulnerabilities in its Known Exploited Vulnerabilities catalog: Android CVE‑2025‑48595, an integer overflow that enables privilege escalation on Android 14‑16 without user interaction, and Linux CVE‑2022‑0492. Google released patches for the Android bug in June 2026.

Google Phone Adds Instant Hang‑up Button to Block Spoofed Calls
SocialMay 18, 2026

Google Phone Adds Instant Hang‑up Button to Block Spoofed Calls

Someone pretending to be your contact during calls? Google Phone could soon fight back. Users will be provided with a direct, prominent option to "Hang up" the call immediately from the alert screen ✅ Details - https://t.co/LXBGAuI68K https://t.co/Wv91QDRa87

By AssembleDebug (Shiv)
Bug Bounty Businesses Bombarded with AI Slop
NewsMay 18, 2026

Bug Bounty Businesses Bombarded with AI Slop

Bug bounty platforms are being flooded with low‑quality AI‑generated vulnerability reports, prompting some companies to pause or suspend their programs. Bugcrowd saw report volume quadruple in three weeks, while Curl and Nextcloud halted their bounties due to the “AI slop.”...

By Ars Technica – Security
Federal Agencies Must Begin Post‑Quantum Crypto Transition Now
SocialMay 18, 2026

Federal Agencies Must Begin Post‑Quantum Crypto Transition Now

Transitioning to Post-Quantum Cryptography: What Federal Agencies Must Do Now - Intelligence Community News https://t.co/LAVSLjjCUB

By Chuck Brooks
Coding Agent Horror Stories: The Security Crisis Threatening Developer Infrastructure
NewsMay 18, 2026

Coding Agent Horror Stories: The Security Crisis Threatening Developer Infrastructure

AI coding agents now power roughly 60% of developer tasks, accelerating feature delivery but also exposing critical security gaps. Documented incidents from late 2024 to early 2026 show agents unintentionally wiping files, deleting production environments, and leaking credentials. The root...

By Docker – Blog
How to Reduce Phishing Exposure Before It Turns Into Business Disruption
NewsMay 18, 2026

How to Reduce Phishing Exposure Before It Turns Into Business Disruption

Phishing attacks now bypass traditional filters, exposing credentials, SaaS apps, and cloud platforms before security teams can react. Early detection using interactive sandboxes uncovers the full attack chain in seconds, providing concrete evidence for rapid response. Enriching sandbox findings with...

By The Hacker News
Millions Impacted Across Several US Healthcare Data Breaches
NewsMay 18, 2026

Millions Impacted Across Several US Healthcare Data Breaches

Several U.S. healthcare providers disclosed massive data breaches that together affect millions of patients. The New York City Health and Hospitals Corporation reported a breach compromising 1.8 million records, while Erie Family Health Centers, Florida Physician Specialists, Coastal Carolina Health Care,...

By SecurityWeek
Continuous Detection, Continuous Response: Mate Security Redefines the Modern SOC
NewsMay 18, 2026

Continuous Detection, Continuous Response: Mate Security Redefines the Modern SOC

Mate Security unveiled its Continuous Detection, Continuous Response (CD/CR) model, which fuses detection and investigation into a single, self‑reinforcing loop. At the core is a Security Context Graph that aggregates real‑time organizational data from distributed sources, eliminating the need for...

By HackRead
Gamaredon Deploys GammaDrop, GammaLoad in Phishing Campaigns
NewsMay 18, 2026

Gamaredon Deploys GammaDrop, GammaLoad in Phishing Campaigns

Gamaredon, the Russian‑linked espionage group targeting Ukraine, has intensified its phishing campaign by leveraging the WinRAR directory‑traversal flaw CVE‑2025‑8088. The group distributes RAR (and now ARJ) archives that embed a VBScript downloader called GammaDrop, which drops a second‑stage HTA payload...

By GBHackers On Security
Ensure Code Integrity for AWS Lambda Functions with Automated Code Signing Using Terraform
NewsMay 18, 2026

Ensure Code Integrity for AWS Lambda Functions with Automated Code Signing Using Terraform

The article walks through building an automated AWS Lambda code‑signing pipeline using Terraform. It leverages AWS Signer with the SHA384‑ECDSA algorithm, stores source and signed packages in a versioned S3 bucket, and enforces signature validation at runtime. The solution also...

By AWS DevOps Blog
Ransomware Attacks Dip, but Post‑quantum Threats Rise
SocialMay 18, 2026

Ransomware Attacks Dip, but Post‑quantum Threats Rise

Ransomware analytics and forecasts for 2026: the number of attacks is declining, but the risk remains high. We’re seeing new families based on post-quantum cryptography, a focus on RDWeb for initial access, and an increase in attacks involving data theft...

By Eugene Kaspersky
Hospital Cyber Attacks Are Increasingly Hitting Patient Care
NewsMay 18, 2026

Hospital Cyber Attacks Are Increasingly Hitting Patient Care

European hospitals are facing a dramatic shift in cyber risk, with 82 % rating the threat as extreme and 74 % expecting a major incident this year. Attackers now target authentication, clinical workflows and digital patient‑care pathways, turning cybersecurity into a direct...

By ITPro
The Gentlemen Ransomware Gang Hit by Internal Breach, Operations Exposed
NewsMay 18, 2026

The Gentlemen Ransomware Gang Hit by Internal Breach, Operations Exposed

The Gentlemen ransomware gang suffered an internal breach in May 2026, exposing its backend infrastructure, affiliate communications, and victim‑management tools. Check Point Research uncovered leaked chats, databases, and evidence of over 1,570 probable victims, far exceeding the gang’s public leak counts....

By HackRead
Cyber Attacks Cost UK Businesses £3.7bn in Litigation in 2025
NewsMay 18, 2026

Cyber Attacks Cost UK Businesses £3.7bn in Litigation in 2025

Research by Gallagher and the Centre for Economics and Business Research shows UK large enterprises faced $14.6 billion in total cyber‑attack costs in 2025. Shareholder litigation alone accounted for $4.6 billion, making it the second‑largest expense after $6.8 billion in direct trading disruption....

By UKTN – People
Paper Werewolf APT Spreads EchoGather RAT via Fake Adobe Installer
NewsMay 18, 2026

Paper Werewolf APT Spreads EchoGather RAT via Fake Adobe Installer

The Russian‑language threat group Paper Werewolf (aka GOFFEE) launched a new wave of attacks against Russian industrial, financial and transport firms in March‑April 2026. The campaign begins with a phishing PDF that auto‑downloads a fake Adobe Reader installer, which silently...

By GBHackers On Security
Anthropic's Mythos and OpenAI's GPT‑5.5 Ignite a Cybersecurity Sprint for CIOs
NewsMay 18, 2026

Anthropic's Mythos and OpenAI's GPT‑5.5 Ignite a Cybersecurity Sprint for CIOs

Anthropic's Mythos model and OpenAI's upcoming GPT‑5.5 have revealed thousands of high‑severity software flaws, sparking a rapid‑fire response from regulators, security vendors and CIOs. The discovery has turned AI from a productivity boost into a top‑line cyber risk, forcing IT...

By Pulse
Impostor Takes $751,430 From Colgate‑Palmolive 401(k) via Social‑Engineering Scam
NewsMay 18, 2026

Impostor Takes $751,430 From Colgate‑Palmolive 401(k) via Social‑Engineering Scam

An impostor posing as a Colgate employee convinced Alight Solutions, the plan recordkeeper, to change contact details on a 401(k) account and redirected the full $751,430 balance to a Las Vegas address. The theft sparked a lawsuit against Alight, Colgate’s...

By Pulse
Hackers Abuse Cloudflare Storage to Exfiltrate Network Files
NewsMay 18, 2026

Hackers Abuse Cloudflare Storage to Exfiltrate Network Files

Researchers at Oasis Security uncovered a sophisticated cyber‑espionage campaign targeting multiple Malaysian organizations. The attackers leveraged an Azure virtual machine to run custom Python, Laravel, and C# tools that enumerated networks, accessed internal databases, and harvested Active Directory credentials. Data...

By GBHackers On Security
AI Coding Is Fueling a Secrets-Sprawl Crisis Few CISOs Are Containing
NewsMay 18, 2026

AI Coding Is Fueling a Secrets-Sprawl Crisis Few CISOs Are Containing

AI‑assisted "vibe coding" is accelerating secret sprawl, as illustrated by Moltbook’s launch on Jan. 28, 2026, which exposed 1.5 million API tokens, 35,000 email addresses and private agent messages due to a misconfigured Supabase database. Researchers at Wiz and independent analyst...

By CSO Online
Why the Best Security Investment a Board Can Make in 2026 Isn’t Another Tool
NewsMay 18, 2026

Why the Best Security Investment a Board Can Make in 2026 Isn’t Another Tool

Boardrooms repeatedly approve new security tools, yet gaps persist because organizations lack true visibility into their environments. The article argues that the most valuable security capability in 2026 is a unified view of assets, access rights, and activity, not another...

By CSO Online
Four Malicious Npm Packages Deliver Infostealers and Phantom Bot DDoS Malware
NewsMay 18, 2026

Four Malicious Npm Packages Deliver Infostealers and Phantom Bot DDoS Malware

Researchers identified four npm packages—chalk‑tempalte, @deadcode09284814/axios‑util, axois‑utils, and color‑style‑utils—containing malicious code that either steals credentials or deploys a Golang‑based Phantom Bot DDoS malware. One package clones the open‑source Shai‑Hulud worm, while another delivers a distributed denial‑of‑service bot capable of HTTP,...

By The Hacker News
Critical Marimo RCE Flaw Could Let Attackers Execute Malicious Code Remotely
NewsMay 18, 2026

Critical Marimo RCE Flaw Could Let Attackers Execute Malicious Code Remotely

A critical remote code execution flaw (CVE‑2026‑39987) has been discovered in the Marimo Python notebook framework. The vulnerability resides in the /terminal/ws WebSocket endpoint, which fails to enforce authentication and spawns a system‑level shell for any requester. All Marimo versions...

By GBHackers On Security
Microsoft Confirms Windows 11 Security Update Install Issues
NewsMay 18, 2026

Microsoft Confirms Windows 11 Security Update Install Issues

Microsoft confirmed that the May 2026 Windows 11 cumulative update (KB5089549) fails to install on devices with limited free space on the EFI System Partition, triggering 0x800f0922 errors and automatic rollback. The issue surfaces when the ESP has 10 MB or less, causing...

By BleepingComputer
OtterCookie Malware Steals Dev Secrets, SSH Keys, Cloud Credentials, and Tokens
NewsMay 18, 2026

OtterCookie Malware Steals Dev Secrets, SSH Keys, Cloud Credentials, and Tokens

OtterCookie is a newly identified Node.js‑based remote‑access trojan that leverages persistent Socket.IO connections to monitor infected workstations in real time. Unlike earlier malware such as BeaverTail, it captures live developer activity—including clipboard data, keystrokes, screenshots, SSH keys, cloud credentials, and...

By GBHackers On Security
Exploit Available for New DirtyDecrypt Linux Root Escalation Flaw
NewsMay 18, 2026

Exploit Available for New DirtyDecrypt Linux Root Escalation Flaw

A new Linux kernel local‑privilege‑escalation flaw dubbed DirtyDecrypt (also known as DirtyCBC) has a publicly released proof‑of‑concept exploit. The bug stems from a missing copy‑on‑write guard in the rxgk_decrypt_skb function of the rxgk module and was patched in the mainline...

By BleepingComputer
The AI Backdoor Your Security Stack Is Not Built to See
NewsMay 18, 2026

The AI Backdoor Your Security Stack Is Not Built to See

Enterprises have built LLM defenses around detecting malicious tokens, but new research from Microsoft and the Institute of Science Tokyo uncovers MetaBackdoor—a length‑based trigger that evades content filters. By poisoning a model with as few as 90 examples, attackers can...

By Help Net Security
Shadow AI Is Growing in Silence While Enterprise Security Falls Behind
NewsMay 18, 2026

Shadow AI Is Growing in Silence While Enterprise Security Falls Behind

Shadow AI is proliferating as enterprises rush to adopt generative AI, outpacing existing governance frameworks. A World Economic Forum survey shows 87% of organizations view AI‑related vulnerabilities as the fastest‑growing cyber risk, and 75% of CISOs have discovered unsanctioned GenAI...

By The Cyber Express
AI Shrinks Vulnerability Exploitation Window to Hours
NewsMay 18, 2026

AI Shrinks Vulnerability Exploitation Window to Hours

Synack’s 2026 State of Vulnerabilities Report finds AI is compressing the gap between vulnerability disclosure and exploitation to a matter of hours. Mean time to remediation fell 47% in 2025, dropping from 63 to 38 days, while high‑severity findings rose...

By Help Net Security
How Criminals Are Using AI to Target Social Media Users and Steal Their Money and Confidential Data
BlogMay 18, 2026

How Criminals Are Using AI to Target Social Media Users and Steal Their Money and Confidential Data

Since ChatGPT’s public launch in late 2022, cybercriminals have weaponized large language models to automate and amplify phishing, deepfake creation, malware obfuscation, and vulnerability scanning. AI‑generated content makes scams appear more authentic, while AI‑tuned malware slips past traditional signatures. Researchers note...

By Genetic Literacy Project
AI Security Risks: 7 Threats and How to Manage Them
NewsMay 18, 2026

AI Security Risks: 7 Threats and How to Manage Them

Enterprise AI adoption is outpacing security controls, exposing organizations to seven major risks. Shadow AI, data leaks, credential theft, insecure code, prompt injection, unvetted AI apps, and deepfake fraud each create new attack vectors. The article outlines practical mitigations, emphasizing...

By Zapier – Blog
Linus Torvalds: AI-Detected Bug Reports Make Kernel Security List 'Almost Entirely Unmanageable'
NewsMay 18, 2026

Linus Torvalds: AI-Detected Bug Reports Make Kernel Security List 'Almost Entirely Unmanageable'

Linus Torvalds announced a new Linux release candidate and warned that AI‑generated bug reports are overwhelming the kernel security mailing list. He said the flood creates massive duplication because many researchers submit the same findings on the same day. New...

By Slashdot
Baidam Partners with AUSCERT for Cyber Security Collab
NewsMay 18, 2026

Baidam Partners with AUSCERT for Cyber Security Collab

Baidam has signed a 12‑month memorandum of understanding with the University of Queensland’s not‑for‑profit AUSCERT to strengthen Australia’s cyber security ecosystem. The partnership will focus on five pillars: cyber threat intelligence, incident response, phishing takedowns, security capability training for technical,...

By ARN (Australia)
Microsoft's May Patch Tuesday Fixes 137 Flaws Using AI System MDASH
NewsMay 18, 2026

Microsoft's May Patch Tuesday Fixes 137 Flaws Using AI System MDASH

Microsoft’s May 2026 Patch Tuesday addressed more than 137 security vulnerabilities, the largest monthly count this year, thanks to an internal AI system called MDASH that discovered 16 of the flaws. The surge puts Microsoft on pace to exceed 500...

By Pulse
Fragnesia Vulnerability Gives Linux Attackers Root Access, Threatening Cloud Servers
NewsMay 18, 2026

Fragnesia Vulnerability Gives Linux Attackers Root Access, Threatening Cloud Servers

Security researcher William Bowling and the V12 team disclosed Fragnesia, a logic‑flaw privilege‑escalation bug in the Linux XFRM ESP‑in‑TCP subsystem. The exploit can corrupt in‑memory page cache of any readable file, including /usr/bin/su, granting root shells without needing host‑level privileges,...

By Pulse
GitLab Dedicated for Government Now GovRAMP-Authorized
NewsMay 18, 2026

GitLab Dedicated for Government Now GovRAMP-Authorized

GitLab announced that its Dedicated for Government offering has earned GovRAMP authorization, clearing a major procurement hurdle for state and local agencies. The single‑tenant SaaS solution provides U.S.‑only data residency, isolated infrastructure, and private networking to satisfy stringent compliance rules....

By GitLab Blog
New Windows 'MiniPlasma' Zero-Day Exploit Gives SYSTEM Access, PoC Released
NewsMay 17, 2026

New Windows 'MiniPlasma' Zero-Day Exploit Gives SYSTEM Access, PoC Released

Researcher Chaotic Eclipse released a proof‑of‑concept for the MiniPlasma zero‑day, which escalates privileges to SYSTEM on fully patched Windows 11 systems. The exploit targets the cldflt.sys Cloud Filter driver and its HsmOsBlockPlaceholderAccess routine, a flaw originally reported as CVE‑2020‑17103 and supposedly...

By BleepingComputer
Student Hacks Taiwan High‑Speed Rail, Halting Four Trains for Nearly an Hour
NewsMay 17, 2026

Student Hacks Taiwan High‑Speed Rail, Halting Four Trains for Nearly an Hour

A 23‑year‑old Taiwanese college student hacked the Taiwan High‑Speed Rail (THSRC) system with a laptop and radios, forcing a travel‑stop that delayed four trains for almost an hour. The breach exposed 19‑year‑old cryptographic keys and ignited political calls for urgent...

By Pulse
Npm Registry Attack Exposes Millions of Apps, Highlights Software Supply‑Chain Risks
NewsMay 17, 2026

Npm Registry Attack Exposes Millions of Apps, Highlights Software Supply‑Chain Risks

A recent report details a supply‑chain attack on the npm registry that compromised millions of enterprise applications and exposed billions of user records. The breach, driven by a hijacked utility package, spotlights the fragility of JavaScript's deep dependency trees and...

By Pulse
AI Framework CONSET Finds 7 Critical 5G Flaws in 542 Smartphone Models
NewsMay 17, 2026

AI Framework CONSET Finds 7 Critical 5G Flaws in 542 Smartphone Models

University researchers deployed an AI‑driven testing system called CONSET to uncover seven new 5G vulnerabilities—three high‑severity—in 542 smartphone models. The findings, affecting 64 modem chipsets, triggered patches from MediaTek and a review by Qualcomm, highlighting a new AI‑enabled attack surface...

By Pulse
Estia Health Drives Zero Trust Security Overhaul
NewsMay 17, 2026

Estia Health Drives Zero Trust Security Overhaul

Estia Health, Australia’s second‑largest aged‑care provider, is overhauling its security with a Zero Trust model to protect sensitive resident data. The initiative centers on three pillars—identity, data, and endpoints—leveraging Okta single sign‑on, AI‑driven data classification, and strict device controls. With...

By iTnews (Australia) – Government
Foxconn Confirms Cyberattack, Ransomware Group Claims 8 TB Data Theft
NewsMay 17, 2026

Foxconn Confirms Cyberattack, Ransomware Group Claims 8 TB Data Theft

Foxconn disclosed a cyberattack this week, with the Nitrogen ransomware gang asserting it exfiltrated 8 TB of data. The breach underscores the vulnerability of the world’s largest electronics assembler and its downstream supply‑chain partners.

By Pulse
Palo Alto Networks Flags Month‑long Exploitation of PAN‑OS Zero‑day CVE‑2026‑0300
NewsMay 17, 2026

Palo Alto Networks Flags Month‑long Exploitation of PAN‑OS Zero‑day CVE‑2026‑0300

Palo Alto Networks announced that a remote‑code‑execution vulnerability (CVE‑2026‑0300) in its PAN‑OS firewalls has been actively exploited for roughly a month by a suspected nation‑state group. The company is preparing a patch for release on May 13, while the U.S. CISA...

By Pulse
Sysadmin Creates 'ModuleJail' To Automatically Blacklist Unused Kernel Modules
NewsMay 17, 2026

Sysadmin Creates 'ModuleJail' To Automatically Blacklist Unused Kernel Modules

Belgian sysadmin Jasper Nuyens released ModuleJail, a GPL‑v3 shell script that scans Linux hosts and automatically blacklists kernel modules that are not in use. The tool creates a single modprobe blacklist file, preserving essential modules while disabling obscure ones that...

By Slashdot
"Private DNS" Isn't as Private as You Think
NewsMay 17, 2026

"Private DNS" Isn't as Private as You Think

Private DNS, typically implemented via DNS‑over‑TLS or DNS‑over‑HTTPS, encrypts only the DNS query itself. While it prevents ISPs and local Wi‑Fi from reading those lookups, the ISP still sees the destination IP and the hostname in the TLS SNI field,...

By How-To Geek
The Hidden Cost of Slow Cyber Remediation in Healthcare
NewsMay 17, 2026

The Hidden Cost of Slow Cyber Remediation in Healthcare

Healthcare ransomware incidents are rising as hospitals struggle with slow vulnerability remediation. Nearly 90% of organizations run exploitable systems, and compliance timelines lag behind attacker speed. Governance layers, manual approvals, and siloed ownership extend exposure windows, prompting insurers and regulators...

By MedCity News
Hidden Audio Can Hijack AI Without User Awareness
SocialMay 17, 2026

Hidden Audio Can Hijack AI Without User Awareness

New research reveals how nearly imperceptible audio in videos, calls, or music can trigger unauthorized AI actions without users noticing. https://spectrum.ieee.org/voice-ai-audio-attacks?share_id=9501042

By IEEE Spectrum Threads
Voice AI Systems Are Vulnerable to Hidden Audio Attacks
NewsMay 17, 2026

Voice AI Systems Are Vulnerable to Hidden Audio Attacks

Researchers unveiled AudioHijack, an adversarial technique that embeds inaudible commands in audio clips to hijack large audio‑language models (LALMs). Tested on 13 open and commercial models—including Microsoft’s service—the method achieved 79‑96% success, forcing models to conduct web searches, download files,...

By IEEE Spectrum AI
The Role of Zero-Knowledge Technology in Web2 Security
NewsMay 17, 2026

The Role of Zero-Knowledge Technology in Web2 Security

The article highlights how traditional Web2 security models, exemplified by the 2025 Salesforce OAuth token breach, expose massive data stores to attackers. It proposes zero‑knowledge (ZK) cryptography as a structural remedy, allowing verification without revealing raw data. Two ZK approaches...

By The European Financial Review
Anonymous Nigeria Attacks South Africa
NewsMay 17, 2026

Anonymous Nigeria Attacks South Africa

Nullsec Nigeria, also known as Anonymous Nigeria, announced it breached the South African Department of Correctional Services and threatened to leak roughly 11 GB of sensitive data unless xenophobic attacks on Nigerians cease. The group also claimed responsibility for hacking the...

By MyBroadband (South Africa)
NGINX CVE-2026-42945 Exploited in the Wild, Causing Worker Crashes and Possible RCE
NewsMay 17, 2026

NGINX CVE-2026-42945 Exploited in the Wild, Causing Worker Crashes and Possible RCE

A heap‑buffer overflow in NGINX’s rewrite module (CVE‑2026‑42945) has been actively exploited just days after disclosure, allowing unauthenticated attackers to crash worker processes and, on systems with ASLR disabled, execute remote code. The flaw spans NGINX versions 0.6.27 through 1.30.0...

By The Hacker News