Know What's Happening in Cybersecurity

Today's Cybersecurity Pulse

CISA adds critical Android and Linux flaws to KEV catalog

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) listed two high‑severity vulnerabilities in its Known Exploited Vulnerabilities catalog: Android CVE‑2025‑48595, an integer overflow that enables privilege escalation on Android 14‑16 without user interaction, and Linux CVE‑2022‑0492. Google released patches for the Android bug in June 2026.

U.S. CISA Adds a Flaw in BerriAI LiteLLM to Its Known Exploited Vulnerabilities Catalog
BlogMay 11, 2026

U.S. CISA Adds a Flaw in BerriAI LiteLLM to Its Known Exploited Vulnerabilities Catalog

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the critical LiteLLM flaw (CVE‑2026‑42208, CVSS 9.3) to its Known Exploited Vulnerabilities catalog. Attackers began exploiting the SQL‑injection bug within 36 hours of disclosure, targeting the proxy’s database tables that store API...

By Security Affairs
TrickMo Android Banker Adopts TON Blockchain for Covert Comms
NewsMay 11, 2026

TrickMo Android Banker Adopts TON Blockchain for Covert Comms

A new TrickMo Android banking malware variant, dubbed TrickMo.C, uses The Open Network (TON) for its command‑and‑control traffic. The malware disguises itself as TikTok or streaming apps and targets banking and crypto wallets in France, Italy, and Austria. By routing...

By BleepingComputer
8 Guiding Principles for Reskilling the SOC for Agentic AI
NewsMay 11, 2026

8 Guiding Principles for Reskilling the SOC for Agentic AI

Top security leaders at DXC Technology, Accenture and former Virgin Atlantic CISO are pioneering the reskilling of SOC teams for agentic AI. They combine hands‑on sandbox environments, vendor‑led expertise and formal training tracks to embed AI agents into tier‑1 and...

By CSO Online
Identity Management Is More Important than Ever in an AI-Powered South Africa
NewsMay 11, 2026

Identity Management Is More Important than Ever in an AI-Powered South Africa

AI is lowering the barrier to cybercrime in South Africa, exposing businesses to automated attacks on bots, APIs and AI agents. At the same time, POPIA enforcement demands strict identity controls and accountability for personal data. Organizations must shift from...

By MyBroadband (South Africa)
Syndicate Impersonates Old Mutual Exec Online
NewsMay 11, 2026

Syndicate Impersonates Old Mutual Exec Online

Old Mutual warned that a coordinated cyber‑fraud syndicate is impersonating senior executives, including COO Zureida Ebrahim, to promote fake investment opportunities. The scammers distribute the scheme across social media, messaging apps, and email, using misspelled brand names and urgent language...

By ITWeb (South Africa) – Public Sector
National Technology Day 2026: India’s AI Growth Puts Security in Focus
NewsMay 11, 2026

National Technology Day 2026: India’s AI Growth Puts Security in Focus

India’s National Technology Day 2026 underscored a shift toward AI‑first enterprises, where intelligent systems are embedded in everyday workflows rather than treated as isolated tools. Executives highlighted that AI now analyses context, triggers actions, and supports decision‑making across sectors, propelled...

By The Cyber Express
Silicon In Focus Podcast: Identity Under Siege: Why Credentials Are the New Battleground
NewsMay 11, 2026

Silicon In Focus Podcast: Identity Under Siege: Why Credentials Are the New Battleground

The Silicon In Focus podcast highlights identity as the new frontline of cybersecurity as cloud, remote work, and AI expand attack surfaces. Host David Howell and iProov’s Dr. Andrew Newell explain why credential‑based attacks now eclipse traditional network breaches. They...

By Silicon UK
Chainlink Emerges as the Unlikely $3B Winner of KelpDAO Exploit as DeFi Projects Dump LayerZero
NewsMay 11, 2026

Chainlink Emerges as the Unlikely $3B Winner of KelpDAO Exploit as DeFi Projects Dump LayerZero

The $292 million KelpDAO exploit sparked a security‑driven exodus of DeFi projects, moving over $3 billion in TVL to Chainlink’s Cross‑Chain Interoperability Protocol (CCIP). Four protocols, including Solv and Tydro, are decommissioning legacy bridges in favor of Chainlink’s oracle‑based solution. LINK surged...

By CryptoSlate
Lyrie.ai Joins First Batch of Anthropic’s Cyber Verification Program
NewsMay 11, 2026

Lyrie.ai Joins First Batch of Anthropic’s Cyber Verification Program

Dubai‑based OTT Cybersecurity announced the public launch of the Agent Trust Protocol (ATP), the first open cryptographic standard that verifies AI agent identity, scope, and actions. Simultaneously, its Lyrie.ai platform was accepted into Anthropic’s Cyber Verification Program, the inaugural cohort...

By eSecurity Planet
Accuvice Launches AI-Powered Compliance Web Platform to Simplify Data Protection and Regulatory Assessments for African & Global Businesses
NewsMay 11, 2026

Accuvice Launches AI-Powered Compliance Web Platform to Simplify Data Protection and Regulatory Assessments for African & Global Businesses

Accuvice Solutions Limited has launched an AI‑powered digital compliance web platform aimed at African and global enterprises. The solution centralizes GDPR, NDPA, DPIA, ISO and other regulatory workflows into a single dashboard, adding AI‑driven guidance, real‑time collaboration, and expert auditor...

By Techpoint Africa
RiskMail.io Launches Disposable Email Detection API to Help Businesses Block Fake Signups
NewsMay 11, 2026

RiskMail.io Launches Disposable Email Detection API to Help Businesses Block Fake Signups

RiskMail.io has launched a Disposable Email Detection API that identifies temporary and high‑risk email domains during signup, verification, or checkout processes. The service delivers real‑time risk signals—disposable, free, privacy‑focused, or safe—allowing developers to block or flag suspicious accounts instantly. By...

By MarTech Series
Curl Audit Finds Single Low‑severity CVE, Others False Positives
SocialMay 11, 2026

Curl Audit Finds Single Low‑severity CVE, Others False Positives

Mythos on Curl: Once my curl security team fellows and I had poked on the this short list for a number of hours and dug into the details, we had trimmed the list down and were left with one confirmed...

By Teri Radichel
The Netherlands Leads in Quantum Technology but Lags on Quantum Security
NewsMay 11, 2026

The Netherlands Leads in Quantum Technology but Lags on Quantum Security

The Dutch Court of Audit warned that while the Netherlands excels in quantum research, 71% of its central government agencies have not begun preparing for the cryptographic threat posed by future quantum computers. Only six percent have incorporated quantum risk...

By Computer Weekly – Latest IT news
Robinhood Faces Lawsuit for Alleged Unlawful Disclosure of Consumers’ Sensitive Financial Info
NewsMay 11, 2026

Robinhood Faces Lawsuit for Alleged Unlawful Disclosure of Consumers’ Sensitive Financial Info

Robinhood Markets is facing a lawsuit filed by client Jamillah Dunn alleging the brokerage embedded invisible Google trackers on its website that transmit users’ sensitive financial data—including account numbers, holdings, and search queries—to advertisers without consent. The complaint, lodged in...

By FX News Group
Bring Your Nonprofit's Rogue IT Out of the Shadows. Here's How.
NewsMay 11, 2026

Bring Your Nonprofit's Rogue IT Out of the Shadows. Here's How.

Nonprofit organizations increasingly grapple with shadow IT—unauthorized tools and services used by staff and volunteers that bypass official oversight. These hidden solutions create security gaps, data‑governance challenges, unexpected expenses, and threaten business continuity. The article outlines practical steps such as...

By TechSoup
Australia Regulator Calls for Urgent Cybersecurity Action to Counter Mythos
NewsMay 11, 2026

Australia Regulator Calls for Urgent Cybersecurity Action to Counter Mythos

Australia’s securities regulator ASIC has urged the financial services industry to act quickly on cyber risks posed by frontier AI models such as Anthropic’s Mythos. The commission warned that AI can uncover long‑standing vulnerabilities in days, compressing a typical twelve‑month...

By Claims Journal
AI Cyber Attack Threatens Global Financial Crisis, Warns International Monetary Fund
NewsMay 11, 2026

AI Cyber Attack Threatens Global Financial Crisis, Warns International Monetary Fund

The International Monetary Fund warned that AI‑driven cyber attacks could spark a global financial crisis, citing the new Anthropic model Mythos that can locate software vulnerabilities at scale. The IMF highlighted the systemic risk posed by shared cloud services, where...

By ComputerWeekly
Cybersecurity: Briefing Your Board
BlogMay 11, 2026

Cybersecurity: Briefing Your Board

The BCLP blog outlines a structured agenda for cybersecurity briefings to corporate boards, emphasizing the threat landscape, risk profile, AI implications, regulatory updates, and program status. It recommends private sessions between the board and the CISO to foster trust and...

By The CorporateCounsel.net Blog
NHS to Grant Palantir Contractors ‘Unlimited Access’ to Patient Data
NewsMay 11, 2026

NHS to Grant Palantir Contractors ‘Unlimited Access’ to Patient Data

The UK National Health Service has signed a deal granting Palantir contractors unlimited access to patient records across its network. The agreement, whose financial terms remain undisclosed, aims to leverage Palantir's data‑analytics platform for AI‑driven health insights. Critics warn that...

By Financial Times – Technology
SANS Stormcast Monday, May 11th, 2026: New Linux Priv Escalation; PAM Backdoors; CPanel Updates; Let’s Encrypt
PodcastMay 11, 20266 min

SANS Stormcast Monday, May 11th, 2026: New Linux Priv Escalation; PAM Backdoors; CPanel Updates; Let’s Encrypt

In this 7‑minute StormCast, Johannes Ulrich warns of a new Linux privilege‑escalation flaw called DirtyFrag, which requires both the RPCRX kernel module and an ESP (IPSec) module to be loaded. He also highlights recent research showing how compromised PAM modules...

By SANS Internet StormCast
AWS Launches Rex, New Runtime Guardrails for Agentic AI Data‑Layer Security
NewsMay 11, 2026

AWS Launches Rex, New Runtime Guardrails for Agentic AI Data‑Layer Security

Amazon Web Services rolled out Rex, a runtime guardrail system built into its Bedrock AI service that checks agentic AI actions against data‑layer policies before execution. The move targets the growing threat of prompt‑injection attacks that could let AI agents...

By Pulse
HIBP Adds Costa Rica as 42nd Government Partner
SocialMay 11, 2026

HIBP Adds Costa Rica as 42nd Government Partner

HIBP’s free gov program keeps growing, helping governments get ahead of data breaches before attackers do. Today, we welcome our 42nd government: Costa Rica, protecting departments, public resources and the people behind them. https://t.co/GD14TAF6sU

By Troy Hunt
Microsoft Adds AI Prompt Risk Monitoring to Purview, Preview Starts This Month
NewsMay 11, 2026

Microsoft Adds AI Prompt Risk Monitoring to Purview, Preview Starts This Month

Microsoft announced a preview of AI prompt risk monitoring inside its Purview Insider Risk Management platform, slated for later this month with general availability next month. The feature lets authorized security and IT staff review employee prompts and AI responses...

By Pulse
Instagram Can Now Read All Users’ Private Messages. Will This Make Kids Safer or Just Boost Ad Targeting?
NewsMay 11, 2026

Instagram Can Now Read All Users’ Private Messages. Will This Make Kids Safer or Just Boost Ad Targeting?

Meta has removed end‑to‑end encryption from Instagram direct messages as of May 8, saying few users opted in to the feature. The change means all private chats are now readable by Meta and could be leveraged for ad personalization, AI model...

By The Conversation – Business + Economy (US)
Nigeria Faces 24.1 Million Compromised Accounts Since 2004, Q1 2026 Adds 281,500 Leaks
NewsMay 11, 2026

Nigeria Faces 24.1 Million Compromised Accounts Since 2004, Q1 2026 Adds 281,500 Leaks

Nigeria’s National Information Technology Development Agency (NITDA) highlighted a Surfshark study that tallied 24.1 million compromised user accounts since 2004, making the country the third‑most affected in Sub‑Saharan Africa. The same report recorded 281,500 leaked accounts in the first quarter of...

By Pulse
Singapore Minister Flags Telcos as High‑Value AI Cyber Threat Target
NewsMay 11, 2026

Singapore Minister Flags Telcos as High‑Value AI Cyber Threat Target

Coordinating Minister for National Security K Shanmugam warned that Singapore’s telecommunications sector is a high‑value target for AI‑enhanced cyber attacks, citing recent activity by APT group UNC3886. He called for board‑level responsibility and highlighted a fresh advisory from the Infocomm Media...

By Pulse
The Shadow AI Problem HR Leaders Can No Longer Ignore
NewsMay 11, 2026

The Shadow AI Problem HR Leaders Can No Longer Ignore

Lenovo’s Work Reborn Report, based on a survey of 6,000 employees, reveals that more than 70% of workers use AI weekly, with up to one‑third doing so outside IT oversight. The study labels the rapid, unsupervised adoption an “AI execution...

By HRM Asia
GDS Puts Three Suppliers in ‘Taxi Rank’ to Test Service Vulnerabilities
NewsMay 11, 2026

GDS Puts Three Suppliers in ‘Taxi Rank’ to Test Service Vulnerabilities

The UK Government Digital Service (GDS) has set up a “taxi rank” of three NCSC‑CHECK accredited penetration‑testing firms—NCC Group, Salus and Prism Infosec—to probe security weaknesses in citizen services and internal Whitehall tools. The three contracts together are worth £1.2 million...

By PublicTechnology.net (UK)
Welcoming the Costa Rican Government to Have I Been Pwned
BlogMay 11, 2026

Welcoming the Costa Rican Government to Have I Been Pwned

Have I Been Pwned (HIBP) has added Costa Rica as its 42nd government client for the free government‑focused breach‑monitoring service. The Costa Rican CSIRT now gains continuous visibility into compromised government email addresses, enabling faster identification of exposure and more...

By Troy Hunt’s Blog
GitLab Makes Anthropic’s Claude Default Engine in Duo Agent Platform
NewsMay 11, 2026

GitLab Makes Anthropic’s Claude Default Engine in Duo Agent Platform

GitLab has expanded its partnership with Anthropic, positioning Claude as the default model across its Duo Agent Platform. The move embeds AI code generation, review and vulnerability remediation within GitLab’s existing governance framework, while leveraging Google Cloud Vertex AI and...

By Pulse
CISA Launches “CI Fortify” Roadmap to Harden State and Local Cyber Resilience
NewsMay 11, 2026

CISA Launches “CI Fortify” Roadmap to Harden State and Local Cyber Resilience

The Cybersecurity and Infrastructure Security Agency (CISA) released its CI Fortify roadmap this week, outlining isolation and recovery steps for critical infrastructure operators. The guidance targets state and local governments facing unreliable third‑party connections and hostile nation‑state actors, aiming to keep...

By Pulse
Braintrust AI Platform Breach Exposes AWS API Keys, Raising Supply‑Chain Alarm
NewsMay 11, 2026

Braintrust AI Platform Breach Exposes AWS API Keys, Raising Supply‑Chain Alarm

AI observability startup Braintrust disclosed that attackers breached an AWS account on May 4, exposing API keys used for cloud‑based AI models. The company locked the account, rotated credentials and urged all customers to rotate org‑level AI provider keys, underscoring...

By Pulse
AI Could Multiply Software Vulnerabilities Twentyfold, Globally
SocialMay 10, 2026

AI Could Multiply Software Vulnerabilities Twentyfold, Globally

What we can see is only a fraction of what exists. Jay Chaudhry has been in cybersecurity for over 30 years. In a recent CRN interview, the @zscaler CEO said he's never seen anxiety in the field like this. He's staring...

By Shashi Bellamkonda
Parallel Bug Discovery Triggers Premature Linux LPE Disclosure
NewsMay 10, 2026

Parallel Bug Discovery Triggers Premature Linux LPE Disclosure

The Linux kernel has seen three critical local‑privilege‑escalation (LPE) bugs surface in weeks, starting with the Copy Fail flaw and followed by Dirty Frag and Copy Fail 2. Dirty Frag’s embargo was unintentionally broken on May 7, releasing exploit details before a full patch was ready,...

By iTnews (Australia) – Government
FCC Extends Software Update Waivers for Foreign Drones and Routers to 2029
NewsMay 10, 2026

FCC Extends Software Update Waivers for Foreign Drones and Routers to 2029

The U.S. Federal Communications Commission announced on May 8 that it will allow software and firmware updates for foreign‑made drones and consumer routers through Jan. 1, 2029, reversing earlier restrictions. The move, issued by the FCC’s Office of Engineering and Technology,...

By Pulse
Vercel Open‑Sources DeepSec, AI‑Driven Scanner to Shift Security Left in CI/CD
NewsMay 10, 2026

Vercel Open‑Sources DeepSec, AI‑Driven Scanner to Shift Security Left in CI/CD

Vercel has open‑sourced DeepSec, an AI‑powered security scanner that integrates directly into development workflows. The tool can cost thousands of dollars per scan for large repositories, yet promises a false‑positive rate of only 10‑20 percent, aiming to move vulnerability detection...

By Pulse
Sandhills Medical Names Sena Ocloo as CIO to Accelerate Tech and Security Overhaul
NewsMay 10, 2026

Sandhills Medical Names Sena Ocloo as CIO to Accelerate Tech and Security Overhaul

Sandhills Medical announced the appointment of Sena Ocloo as chief information officer. Ocloo, who brings 13 years of IT leadership at Kintegra Health, will steer a multi‑year technology refresh that includes automation, next‑gen wireless and stronger system redundancy, positioning the...

By Pulse
Cleanaway Tidies up Endpoint Security
NewsMay 10, 2026

Cleanaway Tidies up Endpoint Security

Cleanaway Waste Management is streamlining its endpoint security by cutting more than 20 cyber‑security suppliers down to five strategic vendors. The move covers over 15,000 assets—including 4,800 trucks, mobile devices and operational technology—across Australia, New Zealand and the Middle East. The...

By iTnews (Australia) – Government
Two US Men Jailed for Helping North Korean Hackers Infiltrate US Firms
NewsMay 10, 2026

Two US Men Jailed for Helping North Korean Hackers Infiltrate US Firms

Two American residents, Matthew Isaac Knoot and Erick Ntekereze Prince, were sentenced to 18 months in federal prison for operating laptop farms that let North Korean hackers masquerade as U.S. remote workers. The scheme, which ran from 2020 to 2024,...

By HackRead
Is This a Dangerous Computer Virus?
NewsMay 10, 2026

Is This a Dangerous Computer Virus?

A user pasted an obfuscated PowerShell script into a Windows 10 machine after visiting a pornographic site, then executed it while Windows Defender was disabled. The script decodes a hex‑encoded payload using an XOR key and runs it via iex, creating a...

By AnandTech
After the $16.5 Billion in Exploits, DeFi Is Now Being Forced Toward the Controls It Once Resisted
NewsMay 10, 2026

After the $16.5 Billion in Exploits, DeFi Is Now Being Forced Toward the Controls It Once Resisted

April 2026 marked the worst month for DeFi losses in over a year, with attackers siphoning $635 million across 28 incidents. A compromised rsETH bridge allowed counterfeit tokens to be deposited on Aave, creating roughly $200 million of bad debt despite the...

By CryptoSlate
Hardware Attestation as Monopoly Enabler
NewsMay 10, 2026

Hardware Attestation as Monopoly Enabler

Apple and Google are progressively extending hardware‑based attestation, embedding it in services such as Play Integrity and App Attest. The APIs now require certified devices, effectively barring alternative operating systems like GrapheneOS and limiting competition. Governments, especially in the EU...

By Hacker News
Never Trust Unknown Calls: My Hubris Cost Everything
SocialMay 10, 2026

Never Trust Unknown Calls: My Hubris Cost Everything

“I still love you even though you are a dummy,” Maryam told me as she gave me a needed hug this morning after I wished her happy Mother’s Day. Yesterday’s social hack wherei basically gave a caller access to everything...

By Robert Scoble
Shared Observability Unites SOCs and DevOps
SocialMay 10, 2026

Shared Observability Unites SOCs and DevOps

RT SOCs and DevOps will need shared observability for agents: data access, tool calls, MCP interactions, and risk levels in one view. #Security #DevOps @Star_CIO https://t.co/tRGwCPc4Mb

By Isaac Sacolick
Why No Enterprise Can Afford a Static Approach to Third-Party Risk
NewsMay 10, 2026

Why No Enterprise Can Afford a Static Approach to Third-Party Risk

Enterprises can no longer rely on static, point‑in‑time third‑party risk assessments because digital ecosystems evolve faster than questionnaires can capture. Continuous visibility is required to track vendor updates, API integrations, and subcontractor dependencies that shift risk profiles in real time....

By The European Financial Review
Beware: Impersonator Sending Scam Emails, Not on Instagram
SocialMay 10, 2026

Beware: Impersonator Sending Scam Emails, Not on Instagram

PSA: There’s an impersonator pretending to be me sending out scam emails about some trading system. Please disregard emails like that. Same for scams on Instagram and such. I’m not on Instagram. (sigh)

By Lynn Alden
SAP Teams with S3NS to Launch Trusted Cloud for Thales in France by H2 2026
NewsMay 10, 2026

SAP Teams with S3NS to Launch Trusted Cloud for Thales in France by H2 2026

SAP and S3NS have sealed a partnership to run SAP RISE private‑cloud edition on the PREMI3NS SecNumCloud‑qualified platform, with French defence giant Thales as the first strategic customer. The joint offering will be commercially available by the second half of...

By Pulse
Riskified Launches AI‑Powered Fraud Suite at Ascend 2026, Boosting Merchant Visibility
NewsMay 10, 2026

Riskified Launches AI‑Powered Fraud Suite at Ascend 2026, Boosting Merchant Visibility

Riskified announced a next‑generation AI risk‑management suite at its Ascend 2026 summit in New York, adding conversational analytics, network‑wide identity mapping and real‑time control tools for merchants. The launch targets rising AI‑driven fraud and aims to give fraud teams deeper...

By Pulse