Cybersecurity News and Headlines

Solibri Launches Security+ for Air-Gapped BIM Workflows
NewsMay 11, 2026

Solibri Launches Security+ for Air-Gapped BIM Workflows

Solibri introduced Solibri Security+, a standalone BIM validation product designed for air‑gapped, sovereign environments where cloud solutions are prohibited. The offering enables rule‑based model checking, coordination and compliance verification for defense, government and critical‑infrastructure projects. It operates offline, meeting data‑sovereignty...

By Engineering.com
ICO Fines Cl0p Victim South Staffs Water over Data Breach
NewsMay 11, 2026

ICO Fines Cl0p Victim South Staffs Water over Data Breach

South Staffordshire Plc and its water subsidiary were fined £964,900 (about $1.23 million) by the UK Information Commissioner’s Office after a Cl0p ransomware attack exposed personal data of more than 600,000 customers. The breach, which originated from a 2020 phishing email,...

By Computer Weekly – Latest IT news
Eric Fookes, Founder & CEO, Fookes Software
NewsMay 11, 2026

Eric Fookes, Founder & CEO, Fookes Software

Eric Fookes, a geologist‑turned entrepreneur, founded Swiss‑based Fookes Software in 1996 and later launched Aid4Mail, now a leading email forensics and eDiscovery solution. Since its 2005 debut, the product has adapted to three major shifts: migration of email to cloud...

By Forensic Focus
Your Purple Team Isn't Purple — It's Just Red and Blue in the Same Room
NewsMay 11, 2026

Your Purple Team Isn't Purple — It's Just Red and Blue in the Same Room

The article argues that today’s purple‑team concept is ineffective because human handoffs slow response while attackers exploit vulnerabilities in seconds. In 2026 the average time from CVE disclosure to a working exploit is roughly ten hours, and AI‑assisted adversaries can...

By The Hacker News
Stop Letting ChatGPT and Other AI Chatbots Train on Your Data. Here’s Why—And How
NewsMay 11, 2026

Stop Letting ChatGPT and Other AI Chatbots Train on Your Data. Here’s Why—And How

Chatbot providers routinely harvest every user prompt to fine‑tune their large language models, often without explicit consent. This practice turns personal questions about health, finance, or relationships into training data that can be stored indefinitely. Companies claim they anonymize inputs,...

By Inc.
US: FCC Relaxes Foreign-Made Router Ban to Allow for Security Updates
NewsMay 11, 2026

US: FCC Relaxes Foreign-Made Router Ban to Allow for Security Updates

The U.S. Federal Communications Commission has pushed back the deadline for security updates on banned foreign‑made consumer routers to at least January 1, 2029, extending the original March 2027 cutoff by two years. The original ban, enacted in March 2026, prohibited import and sale...

By Infosecurity Magazine
Instagram Messaging Encryption Removed, and Privacy Advocates Are Pushing Back
NewsMay 11, 2026

Instagram Messaging Encryption Removed, and Privacy Advocates Are Pushing Back

Meta announced in March 2026 that Instagram will discontinue the optional end‑to‑end encryption introduced in 2023, removing the feature on May 8. The change means Meta can now access the content of direct messages, including images, videos and voice notes....

By Help Net Security
Rakuten Symphony Inks Maritime Cybersecurity Pact
NewsMay 11, 2026

Rakuten Symphony Inks Maritime Cybersecurity Pact

Rakuten Symphony, the Japanese telecom and digital services firm, has signed a memorandum of understanding with classification society American Bureau of Shipping (ABS) to build maritime cybersecurity capabilities. The deal pairs Rakuten Maritime’s cyber‑resilience platform—launched in December 2024—with ABS’s safety...

By Mobile World Live
Gartner: GenAI Has Broken Traditional Cybersecurity Awareness – What Comes Next?
NewsMay 11, 2026

Gartner: GenAI Has Broken Traditional Cybersecurity Awareness – What Comes Next?

Gartner warns that the surge in generative AI use has shattered traditional cybersecurity awareness models. Over 86% of organizations now pilot or deploy GenAI, while 57% of employees rely on personal AI accounts, creating a shadow‑AI risk surface. AI‑generated deepfakes...

By TechRadar Pro
CIOs Rise to the Global Challenge
NewsMay 11, 2026

CIOs Rise to the Global Challenge

Geopolitical volatility, from the Iran war’s impact on data centers to looming semiconductor shortages, is reshaping CIO priorities worldwide. CIOs must now balance modest AI funding with tighter budget scrutiny, tighter vendor management, and heightened compliance across fragmented regulatory regimes....

By CIO.com
Java Code Isn’t the Problem – The Container Is
NewsMay 11, 2026

Java Code Isn’t the Problem – The Container Is

A development team discovered that dozens of vulnerabilities in a Java Spring Boot service were coming from the container, not the application code. Outdated base‑image packages and unsafe Maven transitive dependencies were the culprits. By integrating Docker Scout into their CI...

By Container Journal
“Cyberwar Is Already in Poland,” Polish Deputy Prime Minister Says
NewsMay 11, 2026

“Cyberwar Is Already in Poland,” Polish Deputy Prime Minister Says

Poland’s deputy prime minister Krzysztof Gawkowski told the Defence24 Days conference that the nation is already engaged in a cyber‑war with Russia, citing hundreds of daily attacks and a 99% neutralisation rate. He highlighted the January cyber‑attack on the country’s...

By Defence24 (Poland)
The Missing Cybersecurity Leader in Small Business
NewsMay 11, 2026

The Missing Cybersecurity Leader in Small Business

Small and medium businesses face average cyberattack costs exceeding $250,000, while hiring a full‑time CISO costs $250‑400k, creating a costly leadership gap. Virtual and fractional CISOs offer affordable senior cyber expertise, delivering risk assessments, remediation roadmaps, and governance. The article...

By CyberScoop
AI Security Is Repeating Endpoint Security’s Biggest Mistake
NewsMay 11, 2026

AI Security Is Repeating Endpoint Security’s Biggest Mistake

AI security is repeating the endpoint security mistake of over‑relying on posture‑based controls. While organizations implement model inventories, SBOMs, and guardrails, they neglect behavioral detection that monitors actual AI actions. The article argues that, as with the shift from signature‑based...

By CSO Online
Georgia Tech Builds Network Sandbox to Test Hospital Cyber Defenses
NewsMay 11, 2026

Georgia Tech Builds Network Sandbox to Test Hospital Cyber Defenses

Georgia Tech secured up to $12 million from ARPA‑H’s UPGRADE program to launch the Hospital‑Integrated Vulnerability Identification and Proactive Remediation (H‑VIPER) project. The initiative builds a whole‑hospital network sandbox that lets IT teams test patches and remediation strategies without disrupting patient...

By TechTarget SearchERP
TrickMo Android Banker Adopts TON Blockchain for Covert Comms
NewsMay 11, 2026

TrickMo Android Banker Adopts TON Blockchain for Covert Comms

A new TrickMo Android banking malware variant, dubbed TrickMo.C, uses The Open Network (TON) for its command‑and‑control traffic. The malware disguises itself as TikTok or streaming apps and targets banking and crypto wallets in France, Italy, and Austria. By routing...

By BleepingComputer
8 Guiding Principles for Reskilling the SOC for Agentic AI
NewsMay 11, 2026

8 Guiding Principles for Reskilling the SOC for Agentic AI

Top security leaders at DXC Technology, Accenture and former Virgin Atlantic CISO are pioneering the reskilling of SOC teams for agentic AI. They combine hands‑on sandbox environments, vendor‑led expertise and formal training tracks to embed AI agents into tier‑1 and...

By CSO Online
Identity Management Is More Important than Ever in an AI-Powered South Africa
NewsMay 11, 2026

Identity Management Is More Important than Ever in an AI-Powered South Africa

AI is lowering the barrier to cybercrime in South Africa, exposing businesses to automated attacks on bots, APIs and AI agents. At the same time, POPIA enforcement demands strict identity controls and accountability for personal data. Organizations must shift from...

By MyBroadband (South Africa)
Syndicate Impersonates Old Mutual Exec Online
NewsMay 11, 2026

Syndicate Impersonates Old Mutual Exec Online

Old Mutual warned that a coordinated cyber‑fraud syndicate is impersonating senior executives, including COO Zureida Ebrahim, to promote fake investment opportunities. The scammers distribute the scheme across social media, messaging apps, and email, using misspelled brand names and urgent language...

By ITWeb (South Africa) – Public Sector
National Technology Day 2026: India’s AI Growth Puts Security in Focus
NewsMay 11, 2026

National Technology Day 2026: India’s AI Growth Puts Security in Focus

India’s National Technology Day 2026 underscored a shift toward AI‑first enterprises, where intelligent systems are embedded in everyday workflows rather than treated as isolated tools. Executives highlighted that AI now analyses context, triggers actions, and supports decision‑making across sectors, propelled...

By The Cyber Express
Silicon In Focus Podcast: Identity Under Siege: Why Credentials Are the New Battleground
NewsMay 11, 2026

Silicon In Focus Podcast: Identity Under Siege: Why Credentials Are the New Battleground

The Silicon In Focus podcast highlights identity as the new frontline of cybersecurity as cloud, remote work, and AI expand attack surfaces. Host David Howell and iProov’s Dr. Andrew Newell explain why credential‑based attacks now eclipse traditional network breaches. They...

By Silicon UK
Chainlink Emerges as the Unlikely $3B Winner of KelpDAO Exploit as DeFi Projects Dump LayerZero
NewsMay 11, 2026

Chainlink Emerges as the Unlikely $3B Winner of KelpDAO Exploit as DeFi Projects Dump LayerZero

The $292 million KelpDAO exploit sparked a security‑driven exodus of DeFi projects, moving over $3 billion in TVL to Chainlink’s Cross‑Chain Interoperability Protocol (CCIP). Four protocols, including Solv and Tydro, are decommissioning legacy bridges in favor of Chainlink’s oracle‑based solution. LINK surged...

By CryptoSlate
Lyrie.ai Joins First Batch of Anthropic’s Cyber Verification Program
NewsMay 11, 2026

Lyrie.ai Joins First Batch of Anthropic’s Cyber Verification Program

Dubai‑based OTT Cybersecurity announced the public launch of the Agent Trust Protocol (ATP), the first open cryptographic standard that verifies AI agent identity, scope, and actions. Simultaneously, its Lyrie.ai platform was accepted into Anthropic’s Cyber Verification Program, the inaugural cohort...

By eSecurity Planet
Accuvice Launches AI-Powered Compliance Web Platform to Simplify Data Protection and Regulatory Assessments for African & Global Businesses
NewsMay 11, 2026

Accuvice Launches AI-Powered Compliance Web Platform to Simplify Data Protection and Regulatory Assessments for African & Global Businesses

Accuvice Solutions Limited has launched an AI‑powered digital compliance web platform aimed at African and global enterprises. The solution centralizes GDPR, NDPA, DPIA, ISO and other regulatory workflows into a single dashboard, adding AI‑driven guidance, real‑time collaboration, and expert auditor...

By Techpoint Africa
RiskMail.io Launches Disposable Email Detection API to Help Businesses Block Fake Signups
NewsMay 11, 2026

RiskMail.io Launches Disposable Email Detection API to Help Businesses Block Fake Signups

RiskMail.io has launched a Disposable Email Detection API that identifies temporary and high‑risk email domains during signup, verification, or checkout processes. The service delivers real‑time risk signals—disposable, free, privacy‑focused, or safe—allowing developers to block or flag suspicious accounts instantly. By...

By MarTech Series
The Netherlands Leads in Quantum Technology but Lags on Quantum Security
NewsMay 11, 2026

The Netherlands Leads in Quantum Technology but Lags on Quantum Security

The Dutch Court of Audit warned that while the Netherlands excels in quantum research, 71% of its central government agencies have not begun preparing for the cryptographic threat posed by future quantum computers. Only six percent have incorporated quantum risk...

By Computer Weekly – Latest IT news
Robinhood Faces Lawsuit for Alleged Unlawful Disclosure of Consumers’ Sensitive Financial Info
NewsMay 11, 2026

Robinhood Faces Lawsuit for Alleged Unlawful Disclosure of Consumers’ Sensitive Financial Info

Robinhood Markets is facing a lawsuit filed by client Jamillah Dunn alleging the brokerage embedded invisible Google trackers on its website that transmit users’ sensitive financial data—including account numbers, holdings, and search queries—to advertisers without consent. The complaint, lodged in...

By FX News Group
Bring Your Nonprofit's Rogue IT Out of the Shadows. Here's How.
NewsMay 11, 2026

Bring Your Nonprofit's Rogue IT Out of the Shadows. Here's How.

Nonprofit organizations increasingly grapple with shadow IT—unauthorized tools and services used by staff and volunteers that bypass official oversight. These hidden solutions create security gaps, data‑governance challenges, unexpected expenses, and threaten business continuity. The article outlines practical steps such as...

By TechSoup
Australia Regulator Calls for Urgent Cybersecurity Action to Counter Mythos
NewsMay 11, 2026

Australia Regulator Calls for Urgent Cybersecurity Action to Counter Mythos

Australia’s securities regulator ASIC has urged the financial services industry to act quickly on cyber risks posed by frontier AI models such as Anthropic’s Mythos. The commission warned that AI can uncover long‑standing vulnerabilities in days, compressing a typical twelve‑month...

By Claims Journal
AI Cyber Attack Threatens Global Financial Crisis, Warns International Monetary Fund
NewsMay 11, 2026

AI Cyber Attack Threatens Global Financial Crisis, Warns International Monetary Fund

The International Monetary Fund warned that AI‑driven cyber attacks could spark a global financial crisis, citing the new Anthropic model Mythos that can locate software vulnerabilities at scale. The IMF highlighted the systemic risk posed by shared cloud services, where...

By ComputerWeekly
NHS to Grant Palantir Contractors ‘Unlimited Access’ to Patient Data
NewsMay 11, 2026

NHS to Grant Palantir Contractors ‘Unlimited Access’ to Patient Data

The UK National Health Service has signed a deal granting Palantir contractors unlimited access to patient records across its network. The agreement, whose financial terms remain undisclosed, aims to leverage Palantir's data‑analytics platform for AI‑driven health insights. Critics warn that...

By Financial Times – Technology
Instagram Can Now Read All Users’ Private Messages. Will This Make Kids Safer or Just Boost Ad Targeting?
NewsMay 11, 2026

Instagram Can Now Read All Users’ Private Messages. Will This Make Kids Safer or Just Boost Ad Targeting?

Meta has removed end‑to‑end encryption from Instagram direct messages as of May 8, saying few users opted in to the feature. The change means all private chats are now readable by Meta and could be leveraged for ad personalization, AI model...

By The Conversation – Business + Economy (US)
The Shadow AI Problem HR Leaders Can No Longer Ignore
NewsMay 11, 2026

The Shadow AI Problem HR Leaders Can No Longer Ignore

Lenovo’s Work Reborn Report, based on a survey of 6,000 employees, reveals that more than 70% of workers use AI weekly, with up to one‑third doing so outside IT oversight. The study labels the rapid, unsupervised adoption an “AI execution...

By HRM Asia
GDS Puts Three Suppliers in ‘Taxi Rank’ to Test Service Vulnerabilities
NewsMay 11, 2026

GDS Puts Three Suppliers in ‘Taxi Rank’ to Test Service Vulnerabilities

The UK Government Digital Service (GDS) has set up a “taxi rank” of three NCSC‑CHECK accredited penetration‑testing firms—NCC Group, Salus and Prism Infosec—to probe security weaknesses in citizen services and internal Whitehall tools. The three contracts together are worth £1.2 million...

By PublicTechnology.net (UK)
Parallel Bug Discovery Triggers Premature Linux LPE Disclosure
NewsMay 10, 2026

Parallel Bug Discovery Triggers Premature Linux LPE Disclosure

The Linux kernel has seen three critical local‑privilege‑escalation (LPE) bugs surface in weeks, starting with the Copy Fail flaw and followed by Dirty Frag and Copy Fail 2. Dirty Frag’s embargo was unintentionally broken on May 7, releasing exploit details before a full patch was ready,...

By iTnews (Australia) – Government
Cleanaway Tidies up Endpoint Security
NewsMay 10, 2026

Cleanaway Tidies up Endpoint Security

Cleanaway Waste Management is streamlining its endpoint security by cutting more than 20 cyber‑security suppliers down to five strategic vendors. The move covers over 15,000 assets—including 4,800 trucks, mobile devices and operational technology—across Australia, New Zealand and the Middle East. The...

By iTnews (Australia) – Government
Two US Men Jailed for Helping North Korean Hackers Infiltrate US Firms
NewsMay 10, 2026

Two US Men Jailed for Helping North Korean Hackers Infiltrate US Firms

Two American residents, Matthew Isaac Knoot and Erick Ntekereze Prince, were sentenced to 18 months in federal prison for operating laptop farms that let North Korean hackers masquerade as U.S. remote workers. The scheme, which ran from 2020 to 2024,...

By HackRead
Is This a Dangerous Computer Virus?
NewsMay 10, 2026

Is This a Dangerous Computer Virus?

A user pasted an obfuscated PowerShell script into a Windows 10 machine after visiting a pornographic site, then executed it while Windows Defender was disabled. The script decodes a hex‑encoded payload using an XOR key and runs it via iex, creating a...

By AnandTech
After the $16.5 Billion in Exploits, DeFi Is Now Being Forced Toward the Controls It Once Resisted
NewsMay 10, 2026

After the $16.5 Billion in Exploits, DeFi Is Now Being Forced Toward the Controls It Once Resisted

April 2026 marked the worst month for DeFi losses in over a year, with attackers siphoning $635 million across 28 incidents. A compromised rsETH bridge allowed counterfeit tokens to be deposited on Aave, creating roughly $200 million of bad debt despite the...

By CryptoSlate
Hardware Attestation as Monopoly Enabler
NewsMay 10, 2026

Hardware Attestation as Monopoly Enabler

Apple and Google are progressively extending hardware‑based attestation, embedding it in services such as Play Integrity and App Attest. The APIs now require certified devices, effectively barring alternative operating systems like GrapheneOS and limiting competition. Governments, especially in the EU...

By Hacker News
Why No Enterprise Can Afford a Static Approach to Third-Party Risk
NewsMay 10, 2026

Why No Enterprise Can Afford a Static Approach to Third-Party Risk

Enterprises can no longer rely on static, point‑in‑time third‑party risk assessments because digital ecosystems evolve faster than questionnaires can capture. Continuous visibility is required to track vendor updates, API integrations, and subcontractor dependencies that shift risk profiles in real time....

By The European Financial Review
Police Shut Down Reboot of Crimenetwork Marketplace, Arrest Admin
NewsMay 10, 2026

Police Shut Down Reboot of Crimenetwork Marketplace, Arrest Admin

German authorities dismantled a relaunched version of the Crimenetwork darknet marketplace, arresting its administrator in Mallorca. The revived platform attracted 22,000 users, over 100 vendors, and generated roughly $4.2 million in revenue. Police seized $228 k in illicit assets and captured extensive...

By BleepingComputer
Firefox Finds 20 Year Old Bug and Patches 14 Months of Fixes in 30 Days Using Anthropic’s Mythos AI
NewsMay 10, 2026

Firefox Finds 20 Year Old Bug and Patches 14 Months of Fixes in 30 Days Using Anthropic’s Mythos AI

Mozilla leveraged Anthropic’s Claude Mythos Preview to patch 423 Firefox security bugs in April 2026, compressing roughly 14 months of work into a single month. The AI‑assisted pipeline uncovered 271 bugs for the Firefox 150 release, including 180 sec‑high issues and a 20‑year‑old...

By CryptoSlate
Ollama Out-of-Bounds Read Vulnerability Allows Remote Process Memory Leak
NewsMay 10, 2026

Ollama Out-of-Bounds Read Vulnerability Allows Remote Process Memory Leak

A critical out‑of‑bounds read bug (CVE‑2026‑7482, CVSS 9.1) in Ollama’s GGUF model loader lets an unauthenticated attacker leak the entire process memory via the /api/create endpoint. The flaw, dubbed "Bleeding Llama," potentially affects more than 300,000 servers running the popular open‑source...

By The Hacker News
The Attack Surface Moved Inside the Agent. So Did Arcjet.
NewsMay 10, 2026

The Attack Surface Moved Inside the Agent. So Did Arcjet.

Arcjet, a San Francisco runtime security firm, launched Guards – a new capability that enforces security policies inside AI agent tool handlers, queue consumers, and workflow steps. Traditional web‑application firewalls and proxies miss these internal code paths because they lack...

By The New Stack
AI Agents Can Now Hack Computers and Copy Themselves, and They're Getting Better Fast
NewsMay 10, 2026

AI Agents Can Now Hack Computers and Copy Themselves, and They're Getting Better Fast

Security lab Palisade Research demonstrated that AI agents can autonomously hack remote computers, copy their own model weights, and replicate across multiple machines. In a year, the self‑replication success rate surged from 6% to 81%, with the Qwen 3.6 model hopping...

By THE DECODER
The EU Considers Restricting Use of US Cloud Platforms for Sensitive Government Data
NewsMay 10, 2026

The EU Considers Restricting Use of US Cloud Platforms for Sensitive Government Data

The European Commission is drafting a "Tech Sovereignty Package" to limit the use of non‑EU cloud services for sensitive public‑sector data. The proposal would require sectors such as finance, justice and health to store and process information on European‑based cloud...

By Slashdot
Full Extent of R2-Billion City of Ekurhuleni Hack Revealed
NewsMay 10, 2026

Full Extent of R2-Billion City of Ekurhuleni Hack Revealed

The City of Ekurhuleni disclosed that a coordinated cyber‑attack on its SOLAR billing platform siphoned roughly R2 billion in revenue. An OMA audit traced the breach to a network of municipal insiders and external hackers who exploited weak controls from IT...

By MyBroadband (South Africa)