Know What's Happening in Cybersecurity

Today's Cybersecurity Pulse

CISA adds critical Android and Linux flaws to KEV catalog

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) listed two high‑severity vulnerabilities in its Known Exploited Vulnerabilities catalog: Android CVE‑2025‑48595, an integer overflow that enables privilege escalation on Android 14‑16 without user interaction, and Linux CVE‑2022‑0492. Google released patches for the Android bug in June 2026.

Treasury Warns AI Model Could Hack Bank Accounts, Urges Immediate Action
NewsMay 5, 2026

Treasury Warns AI Model Could Hack Bank Accounts, Urges Immediate Action

Treasury Secretary Scott Bessent told Fox News that Americans should be worried about AI-driven hacks to their bank accounts, citing Anthropic’s Claude Mythos model that can locate thousands of software flaws. The warning follows an emergency April meeting with Federal Reserve...

By Pulse
Critical Apache HTTP/2 Flaw (CVE-2026-23918) Enables DoS and Potential RCE
NewsMay 5, 2026

Critical Apache HTTP/2 Flaw (CVE-2026-23918) Enables DoS and Potential RCE

The Apache Software Foundation disclosed a critical vulnerability, CVE‑2026‑23918, in the HTTP/2 module of Apache HTTP Server 2.4.66, earning an 8.8 CVSS rating. The flaw is a double‑free in `mod_http2` that can be triggered by sending a HEADERS frame followed by...

By The Hacker News
DAEMON Tools Supply Chain Attack Compromises Official Installers with Malware
NewsMay 5, 2026

DAEMON Tools Supply Chain Attack Compromises Official Installers with Malware

Kaspersky has uncovered a supply‑chain attack that trojanized DAEMON Tools Lite installers released between April 8 and early May 2026 (versions 12.5.0.2421‑12.5.0.2434). The compromised binaries launch a loader that contacts a command‑and‑control server, downloads a .NET info‑gatherer and a minimalist backdoor, and in...

By The Hacker News
The Convenience Trap and Why Retail Fraud Has Outgrown Checkout
NewsMay 5, 2026

The Convenience Trap and Why Retail Fraud Has Outgrown Checkout

Retailers' push for frictionless experiences has widened the fraud attack surface, with fraud now spanning account creation, login, loyalty and BNPL, not just checkout. A 2026 survey of over 1,000 fraud and AML leaders shows only 47% of retailers have...

By Total Retail
Please Report My Hacked X Account
BlogMay 5, 2026

Please Report My Hacked X Account

Dr. Joseph Sansone disclosed that his X (formerly Twitter) account was compromised on March 1, 2026 and is now being used to promote Bitcoin scams. He has repeatedly contacted X’s support team without success, filed a Better Business Bureau complaint, and reported...

By Mind Matters and Everything Else with Dr. Joseph Sansone
These 5 Critical Windows Defender Settings Are Off by Default - Turn Them on ASAP
NewsMay 5, 2026

These 5 Critical Windows Defender Settings Are Off by Default - Turn Them on ASAP

Microsoft’s built‑in Windows Defender protects most PCs, but five key defenses remain off by default. The article walks readers through enabling Controlled Folder Access, Memory Integrity, Reputation‑Based Protection, Smart App Control, and Tamper Protection, each found under the Windows Security...

By ZDNet – Enterprise IT
UAE Cyber Security Council, Cisco and Open Innovation AI Launch National AI Test and Validation Lab
NewsMay 5, 2026

UAE Cyber Security Council, Cisco and Open Innovation AI Launch National AI Test and Validation Lab

The UAE Cyber Security Council, Cisco and Open Innovation AI announced the creation of a National AI Test and Validation Lab in Abu Dhabi. The facility will certify AI models for security, safety and compliance, marking the first government‑backed AI...

By Pulse
State Audit Slams NYC Schools for Lack of Student Data Privacy Oversight
NewsMay 5, 2026

State Audit Slams NYC Schools for Lack of Student Data Privacy Oversight

The New York City Department of Education failed a state audit that revealed extensive gaps in student data privacy oversight. Auditors found the district lacks a comprehensive inventory of third‑party software, has experienced 141 security incidents—including breaches affecting 820,000 students—and...

By Route Fifty — Finance
Exclusive: What the Celebrity Stalkerware Breach Means for Executive Protection
NewsMay 5, 2026

Exclusive: What the Celebrity Stalkerware Breach Means for Executive Protection

Cybersecurity researcher Jeremiah Fowler uncovered a publicly accessible database containing 86,859 screenshots taken from a celebrity’s device, exposing personal communications, invoices, and identification data. The leak appears tied to stalkerware used by an individual targeting a European entrepreneur‑media figure, and...

By Security Magazine (Cybersecurity)
AI Agents Expose a Costly Blind Spot in Fraud Prevention
BlogMay 5, 2026

AI Agents Expose a Costly Blind Spot in Fraud Prevention

Merchants are now seeing legitimate AI‑driven purchases flagged as fraud as AI shopping agents mimic bot behavior. Traditional fraud models, which rely on human‑centric signals, struggle to distinguish authorized agents from malicious bots. The resulting false declines generate lost revenue...

By Payments Cards & Mobile (Payments Industry Intelligence)
The Coming Hackastrophe
BlogMay 5, 2026

The Coming Hackastrophe

The Atlantic and NYT highlight a looming shift as AI models such as Claude Mythos enable bots to discover and exploit software flaws at scale. Experts warn that within a year or two these tools could make most existing applications...

By Overcoming Bias
SSE Vs. SASE: Federal Agencies’ Guide to Cloud Security Architecture
NewsMay 5, 2026

SSE Vs. SASE: Federal Agencies’ Guide to Cloud Security Architecture

Federal agencies advancing zero‑trust and hybrid work are shifting from perimeter security to cloud‑delivered models. Two frameworks—Security Service Edge (SSE) and Secure Access Service Edge (SASE)—offer distinct paths: SSE provides security‑only services such as SWG, CASB and ZTNA, while SASE...

By FedTech Magazine
Bipartisan Senate Bill Takes Aim at AI Voice Cloning and Deepfake Fraud Targeting Mobile Users
NewsMay 5, 2026

Bipartisan Senate Bill Takes Aim at AI Voice Cloning and Deepfake Fraud Targeting Mobile Users

The bipartisan AI Fraud Accountability Act (S.3982), introduced by Senators Lisa Blunt Rochester and Tim Sheehy, would make it a federal crime to use AI‑generated voice clones, synthetic video, or other deepfakes for financial fraud and identity theft on mobile...

By Mobile ID World
Synthetic Identity Fraud Now 11 Percent of All Global Fraud, Posing Escalating Threat to Mobile Banking
NewsMay 5, 2026

Synthetic Identity Fraud Now 11 Percent of All Global Fraud, Posing Escalating Threat to Mobile Banking

LexisNexis Risk Solutions’ 2025 cybercrime report finds synthetic identity fraud now represents 11% of all global fraud, an eightfold rise since 2024. The study also documents a 450% surge in agentic bot traffic and a 59% year‑over‑year increase in malicious...

By Mobile ID World
Oracle Will Patch More Often to Counter AI Cybersecurity Threat
NewsMay 5, 2026

Oracle Will Patch More Often to Counter AI Cybersecurity Threat

Oracle announced it will move from quarterly to monthly security patch cycles for its ERP, database and other software, beginning May 28, 2026. The first Critical Security Patch Update (CSPU) will be released on the fourth Thursday of May, with subsequent patches...

By InfoWorld
The Former President of NABIP Was Minutes Away From Losing $25,000
BlogMay 5, 2026

The Former President of NABIP Was Minutes Away From Losing $25,000

Former NABIP president David Saltzman narrowly avoided a $25,000 loss after a sophisticated vishing scam. A fake Apple pop‑up prompted him to call an 800 number where a calm voice, posing as an FTC agent, instructed him to create a...

By The CyberFin Substack
Microsoft Edge Stores Passwords in Process Memory, Posing Enterprise Risk
NewsMay 5, 2026

Microsoft Edge Stores Passwords in Process Memory, Posing Enterprise Risk

Microsoft Edge decrypts and retains all saved passwords in cleartext within its process memory, even when the browser isn’t actively used. Security researcher Tom Rønning demonstrated a proof‑of‑concept that lets an attacker with administrative rights dump these credentials via memory...

By Dark Reading
FTC to Ban Data Broker Kochava From Selling Americans’ Location Data
NewsMay 5, 2026

FTC to Ban Data Broker Kochava From Selling Americans’ Location Data

The Federal Trade Commission has moved to ban data‑broker Kochava and its subsidiary Collective Data Solutions from selling precise location data without explicit consumer consent. The order stems from a 2022 FTC lawsuit alleging that Kochava harvested and sold geolocation...

By BleepingComputer
Cyborg Partners with Austin Artificial Intelligence to Deliver End-to-End Secure AI in Production
NewsMay 5, 2026

Cyborg Partners with Austin Artificial Intelligence to Deliver End-to-End Secure AI in Production

Cyborg announced a partnership with Austin Artificial Intelligence to deliver end‑to‑end encrypted AI infrastructure using its CyborgDB vector database. CyborgDB offers sub‑millisecond latency for searching hundreds of millions of vectors while keeping all data encrypted, targeting regulated industries. The collaboration...

By AiThority » Sales Enablement
CISA Urges Critical Infrastructure Firms to ‘Fortify’ Before It’s Too Late
NewsMay 5, 2026

CISA Urges Critical Infrastructure Firms to ‘Fortify’ Before It’s Too Late

The Cybersecurity and Infrastructure Security Agency (CISA) released new guidance under its international “CI Fortify” initiative to help critical infrastructure operators isolate and recover from cyber intrusions. The advice, modeled on Australian 2025 guidance, stresses preparing for unreliable third‑party connections...

By Cybersecurity Dive (Industry Dive)
The EOL Blind Spot in Your CVE Feed: What SCA Tools Miss
NewsMay 5, 2026

The EOL Blind Spot in Your CVE Feed: What SCA Tools Miss

HeroDevs warns that most vulnerability scanners miss end‑of‑life (EOL) open‑source packages because CVE advisories rarely list those versions. Their analysis shows roughly 80 % of new CVEs affect EOL releases that are not flagged, and only about 7,000 of the 5.4 million...

By BleepingComputer
Emphasis on Cybersecurity in Medical Practices Could Protect Both Patients and Health Care
NewsMay 5, 2026

Emphasis on Cybersecurity in Medical Practices Could Protect Both Patients and Health Care

Healthcare providers are increasingly targeted by cyberattacks as digital workflows expand, raising the risk of data leaks and service disruptions. The February 2024 Change Healthcare ransomware incident exposed the records of roughly 192.7 million Americans and highlighted the vulnerability of even large...

By AJMC (The American Journal of Managed Care)
What If Your Digital Footprint Could Shrink?
NewsMay 5, 2026

What If Your Digital Footprint Could Shrink?

TechRepublic Academy highlights two steeply discounted offers aimed at bolstering digital security and career growth. The Surfshark One+ with Incogni bundle, now $91.99 for two years (down from $500.40), combines VPN, antivirus, breach alerts, and automated data‑broker removal. Meanwhile, ExpertEase...

By TechRepublic – Articles
Android Zero-Click RCE Vulnerability Enables Remote Shell Access
NewsMay 5, 2026

Android Zero-Click RCE Vulnerability Enables Remote Shell Access

Google has issued a patch for a critical Android zero‑click vulnerability (CVE‑2026‑0073) that grants remote shell access via the adbd daemon. The flaw spans Android 14 through 16‑QPR2, allowing attackers on the same network or within physical proximity to execute...

By eSecurity Planet
Surfshark Launches Native VPN App for Amazon Fire TV’s Vega OS, Restoring Streaming Privacy
NewsMay 5, 2026

Surfshark Launches Native VPN App for Amazon Fire TV’s Vega OS, Restoring Streaming Privacy

Surfshark has released a native application for Amazon’s Vega OS, the Linux‑based platform that powers the newest Fire TV devices. The move restores VPN functionality that vanished when Amazon shifted away from Android‑based Fire OS in late 2025, giving users...

By Pulse
Instructure Breach Exposes Data of 275 Million Users, Raises DevSecOps Alarm
NewsMay 5, 2026

Instructure Breach Exposes Data of 275 Million Users, Raises DevSecOps Alarm

Instructure confirmed a cyberattack that exposed personal data of roughly 275 million teachers, students and staff across 9,000 schools. The breach, claimed by the ShinyHunters group, highlighted gaps in the ed‑tech platform’s DevSecOps processes and sparked industry‑wide calls for stronger security...

By Pulse
Broadcom Bets Big on VMware Cloud Foundation 9.1
NewsMay 5, 2026

Broadcom Bets Big on VMware Cloud Foundation 9.1

Broadcom unveiled VMware Cloud Foundation 9.1, branding it as an AI‑ and Kubernetes‑native private cloud that supports AMD, Intel and Nvidia hardware. The release targets three pillars: mitigating hardware supply constraints, accelerating AI‑enabled application delivery, and enforcing zero‑trust security. New...

By Network World
From Diagnosis to Deterrence: The Emerging U.S. Response to Adversarial Distillation
BlogMay 5, 2026

From Diagnosis to Deterrence: The Emerging U.S. Response to Adversarial Distillation

In April the White House and the House Foreign Affairs Committee moved to counter Chinese adversarial distillation of U.S. frontier AI models. The Deterring American AI Model Theft Act of 2026 (DAAMTA) would require a 180‑day assessment, publish an attackers...

By Just Security
Orange Cyberdefense Report Shows Insider Threats Now Top Enterprise Risk at 57%
NewsMay 5, 2026

Orange Cyberdefense Report Shows Insider Threats Now Top Enterprise Risk at 57%

Orange Cyberdefense’s latest threat‑landscape report reveals internal threats now account for 57% of cyber incidents, surpassing external hacking for the first time. The shift, driven by employee misuse and shadow‑IT, forces firms to double down on zero‑trust, credential hygiene and...

By Pulse
Berkshire Hathaway Flags Cyber Uncertainty and Holds Back on Data Centre Cover
BlogMay 5, 2026

Berkshire Hathaway Flags Cyber Uncertainty and Holds Back on Data Centre Cover

Berkshire Hathaway’s insurance arm is deliberately holding back on two fast‑growing lines – cyber and data‑centre coverage. Vice Chairman Ajit Jain said the firm sees strong global demand for cyber policies but cannot reliably model aggregate exposure, and recent low...

By Reinsurance News
EU Reaches Out to Anthropic Over Mythos AI Threat
NewsMay 5, 2026

EU Reaches Out to Anthropic Over Mythos AI Threat

EU Economy Commissioner Valdis Dombrovskis announced talks with Anthropic to test European firms and banks for vulnerabilities from the unreleased Mythos AI model. Finance ministers are pushing for access amid fears the model could expose systemic cyber risks to the...

By Bloomberg — Business
SentinelOne (S) Partners with Silverfort on AI and Identity Security
NewsMay 5, 2026

SentinelOne (S) Partners with Silverfort on AI and Identity Security

On April 21, 2026 SentinelOne announced a strategic partnership with Silverfort to secure human, AI‑agent and other non‑human identities. The joint solution blends SentinelOne’s AI‑driven detection platform with Silverfort’s runtime identity protection across endpoints, cloud workloads and AI applications. By...

By Insider Monkey
AWS Nitro Isolates Resources, Blocking Copy‑Fail Exploit
SocialMay 5, 2026

AWS Nitro Isolates Resources, Blocking Copy‑Fail Exploit

If you were wondering if this affects AWS VMs ~ per Google aimode and AWS documentation: The AWS Nitro System mitigates the Copy Fail vulnerability through architectural isolation, specifically by pinning dedicated physical resources and eliminating shared Dom0 kernel components. AWS...

By Teri Radichel
Anti-ICE Site GTFO ICE Accused of Exposing Data of 17,000+ Activists
NewsMay 5, 2026

Anti-ICE Site GTFO ICE Accused of Exposing Data of 17,000+ Activists

Former DHS chief Miles Taylor launched GTFO ICE, an anti‑ICE advocacy platform, in April 2026. Researchers discovered the site’s public REST API was unprotected and lacked rate‑limiting, allowing anyone to download the personal data of 17,662 users in seconds. The breach...

By HackRead
Foreign-Invested Apps and Taiwan’s Cybersecurity Blind Spot
NewsMay 5, 2026

Foreign-Invested Apps and Taiwan’s Cybersecurity Blind Spot

Taiwan’s food‑delivery market is on the cusp of a major shift as Grab moves to acquire foodpanda for roughly $600 million, potentially securing over half of the sector’s share. The deal would transfer vast troves of location, consumption, and labor data...

By The Diplomat – Asia-Pacific
LinkedIn Faces GDPR Scrutiny Over Paid Profile View Data and Access Rights Dispute
NewsMay 5, 2026

LinkedIn Faces GDPR Scrutiny Over Paid Profile View Data and Access Rights Dispute

LinkedIn is under renewed GDPR scrutiny after privacy group noyb filed a complaint in Germany, alleging the platform violates Article 15 by restricting profile‑visitor data to Premium subscribers. The social network’s practice of refusing a standard data‑access request while selling the...

By TelecomLead
Proton Mail Rolls Out Post-Quantum Encryption for All Users as Industry Braces for ‘Harvest Now, Decrypt Later’ Threat
BlogMay 5, 2026

Proton Mail Rolls Out Post-Quantum Encryption for All Users as Industry Braces for ‘Harvest Now, Decrypt Later’ Threat

Proton Mail announced that its email service now offers post‑quantum encryption (PQC) to all users, including those on free plans, adding a quantum‑resistant layer to newly sent messages. The PQC keys are generated alongside existing RSA and ECC algorithms rather...

By IT Security Guru
Google Cloud Next ’26: Rubrik Announces Cyber Resilience for Google Cloud SQL
BlogMay 5, 2026

Google Cloud Next ’26: Rubrik Announces Cyber Resilience for Google Cloud SQL

Rubrik announced a new cyber‑resilience add‑on for Google Cloud SQL, extending its Security Cloud platform to protect managed PostgreSQL databases. The integration delivers immutable, automated backups that operate alongside existing disaster‑recovery workflows without architectural changes. Customers can apply global policies,...

By StorageNewsletter
Opswat and Emerson to Strengthen Cybersecurity for Critical Infrastructure Operators with Global Reseller Agreement
BlogMay 5, 2026

Opswat and Emerson to Strengthen Cybersecurity for Critical Infrastructure Operators with Global Reseller Agreement

Opswat and Emerson have signed a global reseller agreement to embed Opswat’s operational‑technology (OT) patch‑management suite into Emerson’s Ovation Automation Platform. The deal targets power generation and water‑utility operators, extending the existing DeltaV Alliance to a broader set of critical‑infrastructure...

By StorageNewsletter
What Are Managed Identities in SQL Server 2025? A Complete Guide
NewsMay 5, 2026

What Are Managed Identities in SQL Server 2025? A Complete Guide

Managed identities—Microsoft Entra‑backed, password‑less identities—are now supported in SQL Server 2025 when the instance is Azure Arc‑enabled. The feature allows a system‑assigned managed identity to obtain tokens for Azure services, eliminating stored secrets and reducing credential‑rotation overhead. Configuration requires Windows Server,...

By Redgate Simple Talk
AI Finds 20-Year-Old Bugs in PostgreSQL and MariaDB
NewsMay 5, 2026

AI Finds 20-Year-Old Bugs in PostgreSQL and MariaDB

AI‑driven security tool Xint Code uncovered a high‑severity heap overflow in PostgreSQL’s pgcrypto extension and a buffer‑overflow in MariaDB’s JSON schema validation, both tracing back to code written over two decades ago. The PostgreSQL flaws (CVE‑2026‑2005 and CVE‑2026‑2006) received CVSS...

By CSO Online
Security Vendors Must Own AI, Not Serve It
SocialMay 5, 2026

Security Vendors Must Own AI, Not Serve It

GenAI is going to augment nearly every layer of the security stack. The interesting question for vendors is not whether the stack disappears. It is whether you become a feature of someone else's AI, or whether AI becomes a feature of...

By Sean D. Mack
Hackers Hijack AWS Tools to Power Phishing Attacks
SocialMay 5, 2026

Hackers Hijack AWS Tools to Power Phishing Attacks

Hackers are stealing access to legitimate AWS tools and using them to launch phishing campaigns. https://t.co/qLfuOeGReN

By TechRadar
Flip the Ratio: Cheap Assessment, Board‑
SocialMay 5, 2026

Flip the Ratio: Cheap Assessment, Board‑

"The answer probably starts with flipping the ratio: making assessment as cheap as generation, paying for fixes instead of just finds, and treating supply chain security as the board-level priority it has been pretending to be."

By Richard Seroter
AI and Quantum Threats Demand New Cybersecurity Frameworks
SocialMay 5, 2026

AI and Quantum Threats Demand New Cybersecurity Frameworks

Why Cybersecurity Strategies and Frameworks Must Be Recalibrated in the Age of AI and Quantum Threats

By Chuck Brooks
Assess if Cloud Credentials Exposed Beyond Authentication
SocialMay 5, 2026

Assess if Cloud Credentials Exposed Beyond Authentication

I need to take a look at this and see if you can essentially expose cloud platform credentials and permissions or it is purely auth with no additional attack surface.

By Teri Radichel
Governance Gaps Amplify Risk; Enforce Ownership, Access, Monitoring
SocialMay 5, 2026

Governance Gaps Amplify Risk; Enforce Ownership, Access, Monitoring

Digital infrastructure operates as a single layer across operations, where gaps in governance accumulate risk. Clear ownership, controlled access and real-time monitoring must become daily disciplines, since failures propagate across providers and teams. Microblog @antgrasso https://t.co/hplDKIGUOd

By Antonio Grasso
Tax‑authority Phishing Spreads ValleyRAT and New ABCDoor Backdoor
SocialMay 5, 2026

Tax‑authority Phishing Spreads ValleyRAT and New ABCDoor Backdoor

Phishing "from the tax authorities" → a modified downloader → the well-known ValleyRAT backdoor + the previously undocumented Python backdoor, ABCDoor. Learn more: https://t.co/8mFxmep5xC https://t.co/9yUZwdH8mO

By Eugene Kaspersky
World Rushes to Enforce ID, Threatening VPN Anonymity
SocialMay 5, 2026

World Rushes to Enforce ID, Threatening VPN Anonymity

There’s something ominous about the speed with which the entire world has marched to require identification on platforms and, as I expected, begin the process of banning anonymous VPNs.

By Matthew Green