Know What's Happening in Cybersecurity

Today's Cybersecurity Pulse

CISA adds critical Android and Linux flaws to KEV catalog

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) listed two high‑severity vulnerabilities in its Known Exploited Vulnerabilities catalog: Android CVE‑2025‑48595, an integer overflow that enables privilege escalation on Android 14‑16 without user interaction, patched in June 2026; and Linux CVE‑2022‑0492, a kernel flaw also deemed actively exploited.

Group-IB Named a Leader in the Inaugural Gartner® Magic Quadrant™ for Cyberthreat Intelligence Technologies
NewsMay 7, 2026

Group-IB Named a Leader in the Inaugural Gartner® Magic Quadrant™ for Cyberthreat Intelligence Technologies

Group‑IB has been named a Leader in Gartner’s inaugural 2026 Magic Quadrant for Cyberthreat Intelligence Technologies, joining only four other vendors. The accolade reflects the company’s two‑decade‑plus adversary‑centric research, its Unified Risk Platform, and unique telemetry from over 1,500 joint...

By ITWeb (South Africa) – Public Sector
Will This World Password Day Be the Last?
NewsMay 7, 2026

Will This World Password Day Be the Last?

World Password Day spotlights the growing weakness of password‑based security as attackers exploit reused credentials and AI‑enhanced phishing. Security leaders like Doug Kersten and Tim Chase argue that password risk stems from poor visibility and the outdated model of secret‑based login. They...

By Security Magazine (Cybersecurity)
Ivanti Warns of New EPMM Flaw Exploited in Zero-Day Attacks
NewsMay 7, 2026

Ivanti Warns of New EPMM Flaw Exploited in Zero-Day Attacks

Ivanti has issued an emergency advisory for a high‑severity remote code execution vulnerability (CVE‑2026‑6973) in its on‑prem Endpoint Manager Mobile (EPMM) product, which is being exploited in limited zero‑day attacks. The flaw affects EPMM versions up to 12.8.0.0 and can...

By BleepingComputer
Businesses Hide Vast Majority of Ransomware Attacks, Report Finds
NewsMay 7, 2026

Businesses Hide Vast Majority of Ransomware Attacks, Report Finds

BlackFog’s Q1 2026 report shows a massive disparity between disclosed and hidden ransomware attacks, with 2,160 incidents kept secret versus 264 publicly reported. The United States accounted for half of the undisclosed attacks and 61 % of disclosed ones, making it the...

By Cybersecurity Dive (Industry Dive)
ShinyHunters Publishes Potential Canvas Breach Victims List
SocialMay 7, 2026

ShinyHunters Publishes Potential Canvas Breach Victims List

ShinyHunters is increasing the heat on Instructure by listing all of the potential victims of the Canvas breach. https://t.co/gg7ZQdaDI3

By TechRadar
GitHub Builds an Immune System for AI Coding Agents Running on MCP
NewsMay 7, 2026

GitHub Builds an Immune System for AI Coding Agents Running on MCP

GitHub announced that its Model Context Protocol (MCP) server now supports dependency scanning in public preview and secret scanning as a generally available feature. The updates let AI‑driven coding agents query GitHub’s advisory database and secret‑detection tools while code is...

By The New Stack
AI Agent Erases Three Months of Data in Seconds
SocialMay 7, 2026

AI Agent Erases Three Months of Data in Seconds

AI ALERT: This Founder Watched an AI Agent Destroy 3 Months of Company Data: 'It Took 9 Seconds' Cursor agent (Claude Opus 4.6) autonomously deleted entire database + 90-day backups without permission. Agent's confession: "I violated every principle...guessed instead of...

By Efi Pylarinou
Legacy Security Tools Are Failing Data Protection, Capital One Software Report Finds
NewsMay 7, 2026

Legacy Security Tools Are Failing Data Protection, Capital One Software Report Finds

A Forrester study commissioned by Capital One Software finds that while 72% of security leaders consider data protection more critical than ever, legacy network and perimeter tools are hampering effective safeguards. Over half of respondents lack full visibility into vulnerabilities,...

By Infosecurity Magazine
Police Arrest SMS Blaster Crew that Sent Malicious Messages to Thousands Across Toronto
NewsMay 7, 2026

Police Arrest SMS Blaster Crew that Sent Malicious Messages to Thousands Across Toronto

Toronto police arrested three men and filed 44 charges for operating the country’s first known SMS blaster. The device spoofed cellular towers, hijacking 2G connections to flood tens of thousands of phones with phishing‑laden texts. Authorities say the operation disrupted...

By TechCrunch (Main)
Info Session - Call for Proposals Digital Solutions for Regulatory Compliance Through Data
NewsMay 7, 2026

Info Session - Call for Proposals Digital Solutions for Regulatory Compliance Through Data

The European Commission’s DG CONNECT is hosting an online info session on June 8, 2026 to detail the DIGITAL‑2026‑AI‑DATA‑10‑COMPLIANCE call under the Digital Europe Programme. The call seeks consortia to develop AI‑driven digital tools that automate regulatory reporting and data management across...

By EU Digital Strategy – eIDAS tag
Claude Code OAuth Tokens Can Be Stolen Through Stealthy MCP Hijacking
NewsMay 7, 2026

Claude Code OAuth Tokens Can Be Stolen Through Stealthy MCP Hijacking

Security firm Mitiga Labs uncovered a stealthy man‑in‑the‑middle attack that lets threat actors steal OAuth tokens from Claude Code, Anthropic’s AI coding assistant. By publishing a malicious npm package that modifies the ~/.claude.json configuration, attackers can redirect MCP traffic through...

By SecurityWeek
Cline Kanban Flaw Lets Websites Hijack AI Coding Agents
NewsMay 7, 2026

Cline Kanban Flaw Lets Websites Hijack AI Coding Agents

A critical vulnerability in Cline’s Kanban module (CVSS 9.7) lets any website a developer visits connect to three unauthenticated WebSocket endpoints on the local server, harvest workspace data, and inject commands into the AI coding agent’s terminal. The flaw stems from...

By Infosecurity Magazine
WealthArc Gains ISO 27001:2022 Certification for AI Data Push
NewsMay 7, 2026

WealthArc Gains ISO 27001:2022 Certification for AI Data Push

Swiss‑born fintech WealthArc announced it has achieved ISO 27001:2022 certification from BSI, confirming its information security management system meets global standards. The certification follows a rigorous audit and underpins the company’s plan to scale to over 1,000 custodian data feeds...

By Fintech Global
Early‑Morning LockBit Siege Revealed by Zach Lewis
SocialMay 7, 2026

Early‑Morning LockBit Siege Revealed by Zach Lewis

#TimTalk - The 4:30 AM Wake-Up Call: Inside a Real-World LockBit Siege with Zach Lewis https://t.co/39y3CX0ybu

By Tim Hughes
The Browser Is Breaking Your DLP: How Data Slips Past Modern Controls
NewsMay 7, 2026

The Browser Is Breaking Your DLP: How Data Slips Past Modern Controls

A Keep Aware analysis reveals that 46% of sensitive file uploads to web applications are sent to unsanctioned accounts, exposing a blind spot in traditional data loss prevention (DLP). As enterprises migrate to browser‑based SaaS, AI tools, and collaborative platforms,...

By BleepingComputer
OpenAI and Anthropic LLMs Used in Critical Infrastructure Cyber-Attack, Warns Dragos
NewsMay 7, 2026

OpenAI and Anthropic LLMs Used in Critical Infrastructure Cyber-Attack, Warns Dragos

Cybersecurity firm Dragos reported that attackers leveraged Anthropic's Claude and OpenAI's GPT models to orchestrate a breach of a municipal water and drainage utility in Monterrey, Mexico. The AI tools generated malicious scripts, assisted in intrusion planning, and even produced...

By Infosecurity Magazine
Attackers Could Exploit AI Vision Models Using Imperceptible Image Changes
NewsMay 7, 2026

Attackers Could Exploit AI Vision Models Using Imperceptible Image Changes

Cisco’s AI Threat Intelligence team released a second study showing that vision‑language models can be tricked by imperceptibly altered images. By applying bounded pixel‑level perturbations, attackers can make blurred or filtered images readable to the model while remaining invisible to...

By SecurityWeek
Americans Sentenced for Running 'Laptop Farms' For North Korea
NewsMay 7, 2026

Americans Sentenced for Running 'Laptop Farms' For North Korea

Two U.S. nationals, Matthew Isaac Knoot and Erick Ntekereze Prince, were each sentenced to 18 months in federal prison for operating laptop farms that enabled North Korean IT workers to secure remote jobs at nearly 70 American companies. The schemes...

By BleepingComputer
SRCC Expert Warns of Emerging Threats to AI Assets and University Campuses
BlogMay 7, 2026

SRCC Expert Warns of Emerging Threats to AI Assets and University Campuses

A senior analyst at the SRCC warned that AI models and related data are becoming prime targets for cyber‑criminals, especially on university campuses where cutting‑edge research is housed. The expert highlighted a surge in model‑theft, data‑poisoning attacks, and physical breaches...

By InsuranceERM
Cyber Blind Spots: The Hidden Technology that Poses the Greatest Security Risk
BlogMay 7, 2026

Cyber Blind Spots: The Hidden Technology that Poses the Greatest Security Risk

Operational Technology (OT) that runs the UK’s critical national infrastructure is increasingly exposed as legacy systems become networked and integrated with IT environments. The lack of accurate asset inventories and outdated documentation creates blind spots that attackers can exploit. Geopolitical...

By IT Security Guru
Controllers Bring PQC to Boot and Root of Trust
NewsMay 7, 2026

Controllers Bring PQC to Boot and Root of Trust

Microchip introduced the TS1800 root‑of‑trust controller and the TS50x secure‑boot controller, expanding its TrustShield portfolio with hardware‑accelerated post‑quantum cryptography (PQC). The TS1800, built on a 192 MHz Cortex‑M4F, offers full platform root‑of‑trust features, OCP compliance, and up to double the processing...

By EDN
PAN-OS RCE Exploit Under Active Use Enabling Root Access and Espionage
NewsMay 7, 2026

PAN-OS RCE Exploit Under Active Use Enabling Root Access and Espionage

Palo Alto Networks disclosed a critical buffer‑overflow flaw (CVE‑2026‑0300) in the PAN‑OS User‑ID Authentication Portal that permits unauthenticated remote code execution with root privileges. Threat actors began probing the vulnerability on April 9, 2026 and achieved successful exploitation by mid‑April, injecting shellcode...

By The Hacker News
Guidance: Cyber Improvement Plan (CIP)
NewsMay 7, 2026

Guidance: Cyber Improvement Plan (CIP)

The UK Ministry of Defence has released a new Cyber Improvement Plan (CIP) template under Cyber Security Model (CSM) version 4, uploaded on 7 May 2026. Defence suppliers that fail to satisfy the Def Stan 05‑138 requirements via the Supplier Assurance Questionnaire must now...

By UK Ministry of Defence (GOV.UK)
Vendor Says Daemon Tools Supply Chain Attack Contained
NewsMay 7, 2026

Vendor Says Daemon Tools Supply Chain Attack Contained

Disc Soft, the developer of Daemon Tools, confirmed a supply‑chain intrusion that trojanized the free Daemon Tools Lite 12.5.1 installer between April 8 and May 5. Kaspersky warned that thousands of computers downloaded the malicious version, which installed an information‑stealing payload and...

By SecurityWeek
The Gaps in South Africa’s Digital ID Plan
NewsMay 7, 2026

The Gaps in South Africa’s Digital ID Plan

South Africa’s Department of Home Affairs released draft regulations to embed a digital identity layer alongside the traditional green ID book and smart ID card. The draft outlines cryptographic standards and envisions citizen‑controlled digital wallets, but industry experts flag critical...

By TechCentral (South Africa)
SA Records Highest Global Cyberattack Rate & Identity Visibility Gap, Study Reveals
NewsMay 7, 2026

SA Records Highest Global Cyberattack Rate & Identity Visibility Gap, Study Reveals

Zoho’s State of Workforce Password Security 2026 report shows South Africa leading the world with 36% of organisations reporting cyber‑attacks, the highest global rate. A staggering 79% of firms lack complete visibility into user identities and access, while 71% have...

By IT News Africa
Cycurion (CYCU) Acquires Halo Privacy and HavenX to Build Comprehensive Secure Communications and Digital Defense Platform
NewsMay 7, 2026

Cycurion (CYCU) Acquires Halo Privacy and HavenX to Build Comprehensive Secure Communications and Digital Defense Platform

Cycurion (NASDAQ: CYCU) announced a binding agreement to acquire Halo Privacy and integrate its digital‑investigations unit, HavenX, within 45 days. Halo Privacy contributes roughly $7 million in revenue and $5.5 million in annual recurring revenue, with 80% of its sales recurring. The...

By Financial Post
Fake Claude AI Site Drops Beagle Backdoor on Windows Users
NewsMay 7, 2026

Fake Claude AI Site Drops Beagle Backdoor on Windows Users

A counterfeit Claude‑Pro website (claude‑pro.com) is serving a 505 MB ZIP that installs a malicious MSI. The MSI drops a signed G DATA antivirus updater renamed NOVupdate.exe, an encrypted data file, and a malicious avk.dll which is sideloaded by the updater. The...

By Infosecurity Magazine
Proofpoint Unveils Prism Investigator, Autonomous AI for Compliance Investigations
NewsMay 7, 2026

Proofpoint Unveils Prism Investigator, Autonomous AI for Compliance Investigations

Proofpoint has launched Prism Investigator, an autonomous AI platform that reconstructs events from scattered communications for compliance and legal teams. Available in mid‑June, the tool promises to replace manual keyword searches with explainable, source‑agnostic AI analysis, speeding up investigations in...

By Pulse
CrowdStrike Partners: AI Vulnerability Surge Means It’s Time To ‘Pick A Platform’ In Security
NewsMay 7, 2026

CrowdStrike Partners: AI Vulnerability Surge Means It’s Time To ‘Pick A Platform’ In Security

CrowdStrike is positioning its Falcon platform as the go‑to solution for AI‑accelerated vulnerability exploitation, urging customers to adopt a single, flexible security platform. At the Americas Partner Symposium, top partners such as Presidio, Optiv and GuidePoint highlighted the benefits of...

By CRN (US)
‘HELLO BOSS’: Inside the Chinese Realtime Deepfake Software Powering Scams Around the World
NewsMay 7, 2026

‘HELLO BOSS’: Inside the Chinese Realtime Deepfake Software Powering Scams Around the World

A Chinese startup has released a real‑time deepfake engine that can map a target’s face onto a live video feed within seconds, allowing scammers to impersonate victims on platforms like Microsoft Teams. The software runs on consumer‑grade gaming laptops and...

By 404 Media
Sumo Logic Hires Veteran CISO and SVP to Boost AI‑Ready Security Platform
NewsMay 7, 2026

Sumo Logic Hires Veteran CISO and SVP to Boost AI‑Ready Security Platform

Sumo Logic announced the appointment of Jeremy Powell as chief information security officer and Ben Cody as senior vice president of product management. The hires are aimed at hardening the company’s AI‑ready platform and accelerating product innovation as the market...

By Pulse
Corporate Cybersecurity Is the New Frontline of National Security
BlogMay 7, 2026

Corporate Cybersecurity Is the New Frontline of National Security

The article argues that corporate cybersecurity has become the new frontline of national security, as state actors increasingly target private digital infrastructure. It introduces the concept of "Synthetic Asymmetry," where low‑cost exploits can cripple multibillion‑dollar firms and, by extension, national...

By The Cipher Brief
Dimon Warns Cyber, Not Geopolitics, as Top Economic Threat
SocialMay 7, 2026

Dimon Warns Cyber, Not Geopolitics, as Top Economic Threat

Jamie Dimon's Greatest Economic Threat Shifts From Geopolitics to Cyber Years of "geopolitics" now replaced by "Cyber" as immediate answer. "Bad guys getting stronger at finding vulnerabilities." Context: Mythos risks, market rout. AI's potential = massive risk https://t.co/KfQmID9F51

By Efi Pylarinou
Spring Boot Interview Question — Your API Went Viral Overnight
BlogMay 7, 2026

Spring Boot Interview Question — Your API Went Viral Overnight

A merchant checkout API built with Spring Boot saw traffic surge from 2,000 to 250,000 requests per minute after a partner’s retry bug, overwhelming CPU, DB connections, Redis, and downstream gateways, dropping availability to 62%. Investigation revealed 80% of the...

By Engineering With Java
The $15 Raspberry Pi Upgrade Every Wi-Fi Router Needs
NewsMay 7, 2026

The $15 Raspberry Pi Upgrade Every Wi-Fi Router Needs

Consumer routers provide basic connectivity but lack granular control, and a $15 Raspberry Pi Zero 2W can upgrade any home network with Pi‑hole DNS filtering. Pi‑hole intercepts DNS queries, blocks domains on curated lists, and eliminates ads, malware, and phishing sites across...

By How-To Geek
Palo Alto Networks Confirms Active Exploitation of PAN‑OS Zero‑Day CVE‑2026‑0300
NewsMay 7, 2026

Palo Alto Networks Confirms Active Exploitation of PAN‑OS Zero‑Day CVE‑2026‑0300

Palo Alto Networks announced that the critical PAN‑OS zero‑day CVE‑2026‑0300 is being actively exploited in the wild, targeting PA‑Series and VM‑Series firewalls. The vulnerability, rated 9.3 on the CVSS scale, affects the User‑ID Authentication Portal and patches are expected on...

By Pulse
Portnox Launches PartnerEdge Reseller Program to Accelerate B2B Channel Sales
NewsMay 7, 2026

Portnox Launches PartnerEdge Reseller Program to Accelerate B2B Channel Sales

Portnox announced the launch of PartnerEdge, a structured reseller program aimed at boosting channel momentum for its cloud-native access control solution. The two‑tier model gives partners clear pathways to profitability as enterprises rush to replace legacy network access control with...

By Pulse
AWS Launches General Availability of MCP Server for Secure AI Agent Access
NewsMay 7, 2026

AWS Launches General Availability of MCP Server for Secure AI Agent Access

Amazon Web Services announced the general availability of its Managed Model Context Protocol (MCP) Server, a managed service that gives AI agents authenticated, fine‑grained access to over 15,000 AWS APIs. The rollout adds IAM context keys, a sandboxed run_script tool,...

By Pulse
'TrustFall' Convention Exposes Claude Code Execution Risk
NewsMay 7, 2026

'TrustFall' Convention Exposes Claude Code Execution Risk

Researchers at Adversa AI have uncovered a systemic risk in AI‑assisted coding tools such as Anthropic's Claude Code, Cursor CLI, Gemini CLI and GitHub Co‑Pilot CLI. A malicious repository can embed a Model Context Protocol (MCP) server that auto‑approves and launches...

By Dark Reading
AI Coding Agents Could Fuel Next Supply Chain Crisis
NewsMay 7, 2026

AI Coding Agents Could Fuel Next Supply Chain Crisis

Researchers at Adversa.AI uncovered that Claude Code and similar agentic AI coding tools can be duped into executing malicious code with a single trust‑dialog confirmation, granting attackers one‑click remote code execution and opening a supply‑chain vector, especially in CI/CD pipelines....

By SecurityWeek
The Passkey You Can’t Steal: Why Hardware Beats Software for High-Stakes Authentication
PodcastMay 7, 202618 min

The Passkey You Can’t Steal: Why Hardware Beats Software for High-Stakes Authentication

In this episode of Payments Journal, host Rima Katz and guests Adam Lowe (Chief Product & Innovation Officer at Composecure/Arculus) and Tracy Goldberg (Director of Cybersecurity at Javelin) dissect the difference between software‑synced passkeys and hardware‑bound passkeys. They explain that...

By Payments Journal
How Cloudflare Responded to the “Copy Fail” Linux Vulnerability
NewsMay 7, 2026

How Cloudflare Responded to the “Copy Fail” Linux Vulnerability

On April 29, 2026, the Linux kernel “Copy Fail” (CVE‑2026‑31431) local‑privilege‑escalation bug was disclosed. Cloudflare’s security and engineering teams quickly mapped exposure, confirmed that existing behavioral detections caught the exploit pattern within minutes, and began a two‑track mitigation using a...

By Cloudflare Blog
World's First AI-Driven Cyberattack Couldn't Breach OT Systems
NewsMay 7, 2026

World's First AI-Driven Cyberattack Couldn't Breach OT Systems

In early 2026 a small hacker group leveraged the large‑language model Claude Code to launch the world’s first AI‑directed cyber campaign against Mexican government agencies, exfiltrating millions of tax and property records. The attackers successfully penetrated IT networks of nine entities...

By Dark Reading
Disappearing Data: Google Chrome Could Be Secretly Downloading a 4GB File
NewsMay 7, 2026

Disappearing Data: Google Chrome Could Be Secretly Downloading a 4GB File

Google Chrome is silently installing a 4 GB on‑device Gemini Nano AI model on users' machines without explicit consent. The download activates when Chrome’s AI features are enabled by default and re‑downloads automatically if the file is deleted. Users can only stop...

By MyBroadband (South Africa)
SGS Awards DOBOT Robotics ISO 10218 Cybersecurity Certification
NewsMay 7, 2026

SGS Awards DOBOT Robotics ISO 10218 Cybersecurity Certification

SGS partnered with collaborative‑robot maker DOBOT to certify its CR 30H Series against the cybersecurity provisions of ISO 10218‑1:2025. The verification, completed in February 2026 at SGS’s Guangzhou cyber lab, covered threat modeling, secure communications, access control and software‑update integrity. The certification...

By RoboticsTomorrow
Synack Announces General Availability of Sara AI Pentesting, Introducing a New Model for Continuous Security Validation
NewsMay 7, 2026

Synack Announces General Availability of Sara AI Pentesting, Introducing a New Model for Continuous Security Validation

Synack has launched the general availability of Sara AI Pentesting, an autonomous red‑agent that combines agentic AI with human validation to provide continuous security testing. Early deployments showed Sara matching senior researchers by autonomously exploiting a chain of critical vulnerabilities,...

By AiThority » Sales Enablement
Polish Intelligence Warns Hackers Attacked Water Treatment Control Systems
NewsMay 7, 2026

Polish Intelligence Warns Hackers Attacked Water Treatment Control Systems

Poland’s Internal Security Agency disclosed that hackers breached the control systems of water‑treatment facilities in five towns during 2025, gaining the ability to modify pump and alarm settings. The intrusions were linked to a broader surge in hostile cyber activity,...

By The Record by Recorded Future
1inch Resolver TrustedVolumes Drained for $6.7M on Ethereum
NewsMay 7, 2026

1inch Resolver TrustedVolumes Drained for $6.7M on Ethereum

Liquidity provider TrustedVolumes confirmed an Ethereum exploit that drained roughly $6.7 million, including about 1,300 wrapped Ether, 17 wrapped Bitcoin and over $1.5 million in stablecoins. Blockchain security firm Blockaid linked the attack to the same operator behind the March 2025 1inch Fusion...

By The Defiant