Cybersecurity News and Headlines

AI-Fueled Fraud Creates New Cybercrime Frontier for Risk Managers
NewsMay 4, 2026

AI-Fueled Fraud Creates New Cybercrime Frontier for Risk Managers

At the Riskworld conference, The Hartford’s cyber‑risk leader warned that AI is reshaping fraud, with deepfakes, business email compromise and payment‑transfer scams now eclipsing traditional ransomware. Threat actors use AI‑generated voices and videos to impersonate executives, while automated social‑engineering tools...

By Business Insurance
Weaver E-Cology Critical Bug Exploited in Attacks Since March
NewsMay 4, 2026

Weaver E-Cology Critical Bug Exploited in Attacks Since March

Researchers at Vega uncovered that a critical unauthenticated remote‑code‑execution flaw (CVE‑2026‑22679) in Weaver E‑cology 10.0 was actively exploited from mid‑March. The vulnerability stems from an exposed debug API that lets attackers execute system commands without authentication. Exploits began five days...

By BleepingComputer
Complaints Process Failing
NewsMay 4, 2026

Complaints Process Failing

The Office of the Australian Information Commissioner (OIAC) launched a privacy‑awareness campaign during Privacy Awareness Week to improve how agencies handle complaints. A new survey shows 93% of Australians consider data protection vital, yet 52% refrain from filing complaints because...

By Government News (Australia)
‘Copy Fail’ Is a Real Linux Security Crisis Wrapped in AI Slop
NewsMay 4, 2026

‘Copy Fail’ Is a Real Linux Security Crisis Wrapped in AI Slop

Researchers have identified a high‑severity Linux kernel flaw (CVE‑2026‑31431) that allows any authenticated local user to gain root privileges. The vulnerability, dubbed “Copy Fail,” affects mainstream kernels released since 2017 and was added to CISA’s exploited‑vulnerabilities catalog. Theori, the firm...

By CyberScoop
White House Officials Discuss Assessing AI Models That Pose Security Risks
NewsMay 4, 2026

White House Officials Discuss Assessing AI Models That Pose Security Risks

The White House is weighing a cybersecurity‑focused executive order that would create a formal review process for artificial‑intelligence tools deemed high‑risk. Officials plan to establish an oversight group to draft standards for powerful models such as Anthropic’s Mythos, which has...

By WSJ – Technology: What’s News
Kochava Won't Sell 'Sensitive' Location Data Without Consent
NewsMay 4, 2026

Kochava Won't Sell 'Sensitive' Location Data Without Consent

Data broker Kochava agreed to stop selling sensitive precise location data without explicit consumer consent, settling FTC privacy charges. The settlement defines sensitive data as GPS coordinates linked to medical, religious, educational, homeless, domestic‑violence, and law‑enforcement sites. Kochava does not...

By MediaPost
Webinar to Explore AI Use in Cybersecurity, Health Care Technology
NewsMay 4, 2026

Webinar to Explore AI Use in Cybersecurity, Health Care Technology

A joint webinar hosted by the American Hospital Association and the Joint Commission will explore how artificial intelligence can strengthen cybersecurity in health‑care settings. The event highlights the newly launched Cyber Resilience Readiness program, recent guidance from CISA and the...

By AHA News – American Hospital Association
AHA, Joint Commission Announce Cybersecurity Readiness Effort
NewsMay 4, 2026

AHA, Joint Commission Announce Cybersecurity Readiness Effort

The American Hospital Association and the Joint Commission unveiled the Cyber Resilience Readiness program, a voluntary initiative designed to help hospitals and health systems sustain safe, quality clinical operations during cyber‑related outages lasting 30 days or more. Unlike traditional IT‑focused...

By AHA News – American Hospital Association
RMM Tools Fuel Stealthy Phishing Campaign
NewsMay 4, 2026

RMM Tools Fuel Stealthy Phishing Campaign

Security firm Securonix has identified a stealthy phishing campaign, VENOMOUS#HELPER, that has compromised more than 80 organizations across the United States, Western Europe and Latin America since April 2025. The attackers bypass traditional malware by deploying two legitimate, signed remote...

By Dark Reading
NSW Downgrades Impact of Treasury Cyber Hit
NewsMay 4, 2026

NSW Downgrades Impact of Treasury Cyber Hit

New South Wales Treasury downgraded a previously labeled “significant cyber incident” after an alleged staff member attempted to exfiltrate over 5,600 sensitive documents. The downgrade was announced less than two weeks after the employee was formally charged. Treasury’s chief cyber...

By The Mandarin (Australia)
Amazon SES Increasingly Abused in Phishing to Evade Detection
NewsMay 4, 2026

Amazon SES Increasingly Abused in Phishing to Evade Detection

Security researchers at Kaspersky have observed a sharp increase in phishing campaigns that leverage Amazon’s Simple Email Service (SES). The surge is linked to large numbers of exposed AWS IAM access keys found in public code repositories, Docker images, and...

By BleepingComputer
5 Reasons You Should Ditch Cloudflare and Run Your Own DNS Server
NewsMay 4, 2026

5 Reasons You Should Ditch Cloudflare and Run Your Own DNS Server

The article argues that relying on Cloudflare’s 1.1.1.1 DNS exposes users to privacy risks and service outages, and recommends running a self‑hosted DNS resolver such as Pi‑hole or AdGuard Home. It cites a 2020 KPMG audit that found Cloudflare retained...

By MakeUseOf – Productivity
Operational Technology Providers Are Feeling ‘Annoyance’ at Exclusion From Anthropic’s Mythos Rollout, Sources Say
NewsMay 4, 2026

Operational Technology Providers Are Feeling ‘Annoyance’ at Exclusion From Anthropic’s Mythos Rollout, Sources Say

Anthropic's Mythos preview, part of the Project Glasswing initiative, was rolled out first to large tech and finance firms, leaving operational technology (OT) providers feeling excluded. OT industry groups and utilities such as American Water have voiced frustration and are...

By FCW (GovExec Technology)
Canadian Election Databases Use "Canary Traps"—And They Work
NewsMay 4, 2026

Canadian Election Databases Use "Canary Traps"—And They Work

Alberta’s elections authority used a classic canary trap to trace a leak of its voter list. The list, legally provided to the Republican Party of Alberta with injected bogus entries, appeared unchanged in a separatist group’s online database, confirming the...

By Ars Technica – Security
Agentic AI and the Evolution of Code Security in Modern Development
NewsMay 4, 2026

Agentic AI and the Evolution of Code Security in Modern Development

Agentic AI is transforming software development by letting autonomous agents write code, create tests, and iterate without direct human input. This acceleration shortens delivery cycles but also introduces hidden assumptions that can embed vulnerabilities early in the codebase. Traditional post‑CI...

By eSecurity Planet
Customers Sue Chime over Alleged Iran-Linked Hack
NewsMay 4, 2026

Customers Sue Chime over Alleged Iran-Linked Hack

Chime Financial’s mobile app outage on April 1 prompted the company to assure customers that their money and personal data remained secure. Within days, three class‑action lawsuits alleged that pro‑Iranian hacker group Team 313 breached Chime’s systems and stole Social Security numbers...

By American Banker
Exploit Cyber-Frenzy Threatens Millions via Critical cPanel Vulnerability
NewsMay 4, 2026

Exploit Cyber-Frenzy Threatens Millions via Critical cPanel Vulnerability

A critical authentication‑bypass flaw (CVE‑2026‑41940) in cPanel, WHM and WP Squared received a 9.8 CVSS rating and was patched on April 28, 2026. Within 24 hours of disclosure, researchers observed roughly 15,000 potentially compromised instances, with attackers deploying ransomware and Mirai‑derived botnets. The...

By Dark Reading
What to Expect at the DigiCert Trust Summit: Join theCUBE May 13
NewsMay 4, 2026

What to Expect at the DigiCert Trust Summit: Join theCUBE May 13

The DigiCert Trust Summit on May 13 will explore how enterprises can build an "intelligent trust" framework that unifies PKI, DNS, software integrity and device identity for AI‑driven environments. TheCUBE research shows 70% of firms have deployed AI security tools,...

By SiliconANGLE
How One Fake Google Ad Can Silently Steal Your Mac’s Passwords
NewsMay 4, 2026

How One Fake Google Ad Can Silently Steal Your Mac’s Passwords

A fake Google ad for Homebrew directs users to a cloned website that asks them to paste a Terminal command, which installs the MacSync infostealer. MacSync can bypass Apple’s built‑in defenses and exfiltrate Keychain passwords, session cookies, and crypto‑wallet data....

By MakeUseOf – Productivity
Encrypted RCS Between Android and iPhone Launching with iOS 26.5
NewsMay 4, 2026

Encrypted RCS Between Android and iPhone Launching with iOS 26.5

Apple announced that iOS 26.5 will support end‑to‑end encrypted RCS messaging with Android devices via Google Messages. The feature is available in the iOS 26.5 release candidate and will roll out to users once the final OS ships, displaying a lock icon...

By 9to5Google
Phishing Campaign Hits 80+ Orgs Using SimpleHelp and ScreenConnect RMM Tools
NewsMay 4, 2026

Phishing Campaign Hits 80+ Orgs Using SimpleHelp and ScreenConnect RMM Tools

A phishing campaign dubbed VENOMOUS#HELPER has compromised over 80 U.S. organizations by masquerading as the Social Security Administration and delivering malicious Remote Monitoring and Management (RMM) tools. The attackers use legitimate SimpleHelp and ConnectWise ScreenConnect binaries to create a redundant...

By The Hacker News
Cybersecurity Startup GRC Pro Lab© Launches AI-Powered SaaS Platform to Close the GRC Talent Experience Gap
NewsMay 4, 2026

Cybersecurity Startup GRC Pro Lab© Launches AI-Powered SaaS Platform to Close the GRC Talent Experience Gap

Irish‑based GRC Pro Lab has launched a SaaS platform that delivers scenario‑based, hands‑on training for governance, risk and compliance analysts, IT auditors and security professionals. The service replaces passive video courses with simulated engagements across six GRC domains, and includes...

By Techpoint Africa
Backdoored PyTorch Lightning Package Drops Credential Stealer
NewsMay 4, 2026

Backdoored PyTorch Lightning Package Drops Credential Stealer

A malicious version of the PyTorch Lightning package (v2.6.3) was published on PyPI, embedding a hidden execution chain that downloads the Bun JavaScript runtime and runs an obfuscated 11.4 MB payload. The payload, dubbed “ShaiWorm,” steals credentials from .env files, browsers...

By BleepingComputer
‘Patch Wave’ Warning: AI May Expose Decades of Hidden Software Bugs
NewsMay 4, 2026

‘Patch Wave’ Warning: AI May Expose Decades of Hidden Software Bugs

The UK National Cyber Security Centre warned that AI can now uncover decades‑old software flaws at a speed that will overwhelm existing patch‑management processes, creating a “patch wave” of critical updates. Anthropic’s Claude Mythos model identified over 2,000 hidden vulnerabilities,...

By eWeek
Syria Needs a Trustworthy Digital Ecosystem to Support Its Revival
NewsMay 4, 2026

Syria Needs a Trustworthy Digital Ecosystem to Support Its Revival

Syria’s median age of 23 contrasts with a 64% offline population, a barrier to post‑conflict growth. After sanctions lifted in 2025, the government partnered with Nokia for trial 5G, launched the $800 million SilkLink fiber‑optic project, and connected to the Medusa...

By Atlantic Council – All Content
Europe’s Laws ‘Ill-Equipped’ to Deal with Superhacking AI, Lawmakers Warn
NewsMay 4, 2026

Europe’s Laws ‘Ill-Equipped’ to Deal with Superhacking AI, Lawmakers Warn

European lawmakers warned that the EU’s current cybersecurity framework cannot cope with AI‑driven hacking tools such as Anthropic’s Mythos, which recently outperformed humans in finding vulnerabilities. In a letter signed by thirty MEPs, they called on Commission Vice‑President Henna Virkkunen...

By Politico Europe – Technology
Forbes Preliminarily Agrees to Pay $10 Million to Settle California Wiretapping Lawsuit
NewsMay 4, 2026

Forbes Preliminarily Agrees to Pay $10 Million to Settle California Wiretapping Lawsuit

Forbes Media has entered a preliminary settlement to pay $10 million and modify its data‑collection practices after a California class‑action lawsuit alleged illegal tracking of website visitors. The agreement mandates clearer notice and opt‑out mechanisms for California residents and acknowledges the...

By The Record by Recorded Future
Tracking Pixels, EU Regulators, and You: A Calm Person’s Guide to What Just Happened
NewsMay 4, 2026

Tracking Pixels, EU Regulators, and You: A Calm Person’s Guide to What Just Happened

In March and April 2026 France’s CNIL and Italy’s Garante issued guidance clarifying how the ePrivacy Directive and GDPR apply to email tracking pixels. Both regulators treat pixel data as ePrivacy‑subject, requiring consent unless a narrow exemption applies. France allows...

By Mailgun Blog
Trellix Discloses Data Breach After Source Code Repository Hack
NewsMay 4, 2026

Trellix Discloses Data Breach After Source Code Repository Hack

Trellix, the cybersecurity firm formed from the McAfee Enterprise‑FireEye merger, disclosed that attackers accessed a portion of its source‑code repository. The company says forensic experts are investigating and has found no evidence that the code was altered or exploited. Trellix...

By BleepingComputer
OpenAI Rolls Out Passkeys for ChatGPT, Partners with Yubico
NewsMay 4, 2026

OpenAI Rolls Out Passkeys for ChatGPT, Partners with Yubico

OpenAI unveiled Advanced Account Security, a password‑less sign‑in option for ChatGPT and Codex that supports any FIDO‑compliant passkey or hardware key. The company partnered with Yubico to sell a two‑pack bundle of the YubiKey C Nano and C NFC at a special...

By Biometric Update
The Coming Wave of Large-Scale Al-Enabled Cyberattacks
NewsMay 4, 2026

The Coming Wave of Large-Scale Al-Enabled Cyberattacks

Artificial intelligence is reshaping cyber offense as quickly as it empowers defenders, giving attackers tools to automate phishing, deep‑fakes, and large‑scale reconnaissance. Experts warn that the first truly massive AI‑enabled cyberattack will likely be a coordinated, machine‑speed campaign targeting multiple...

By Security Magazine (Cybersecurity)
Azure IaaS: Defense in Depth Built on Secure-by-Design Principles
NewsMay 4, 2026

Azure IaaS: Defense in Depth Built on Secure-by-Design Principles

Microsoft’s Azure IaaS blog outlines a defense‑in‑depth model built on three Secure Future Initiative principles—secure by design, secure by default, and secure in operation. It details how hardware roots of trust, measured boot, and Trusted Launch protect the host and...

By Azure Blog
Cisco To Acquire Astrix To Boost Identity Security For AI Agents
NewsMay 4, 2026

Cisco To Acquire Astrix To Boost Identity Security For AI Agents

Cisco Systems announced it will acquire identity‑protection startup Astrix Security, a move aimed at strengthening its portfolio for securing AI agents and non‑human identities. While the exact price was not disclosed, industry sources estimate the deal at roughly $400 million, higher...

By CRN (US)
FIDO Alliance Announces Agenda for Authenticate APAC 2026
NewsMay 4, 2026

FIDO Alliance Announces Agenda for Authenticate APAC 2026

The FIDO Alliance unveiled the agenda for Authenticate APAC 2026, its first Asia‑Pacific conference on digital identity and authentication, scheduled for June 2‑3 in Singapore. The two‑day event, backed by signature sponsors Google, Visa and Yubico, will feature leaders from...

By FIDO Alliance – News/Blog
Ransomware Group Claims Breach of Pro-Orbán Hungarian Media Firm
NewsMay 4, 2026

Ransomware Group Claims Breach of Pro-Orbán Hungarian Media Firm

A ransomware group called World Leaks claimed responsibility for a breach of Hungarian media conglomerate Mediaworks, releasing about 8.5 terabytes of data that includes payroll records, contracts, financial statements, and internal communications. Mediaworks confirmed the incident, warned that the data...

By The Record by Recorded Future
CTSI-Global Names Kevin Beall as Chief Information Security Officer
NewsMay 4, 2026

CTSI-Global Names Kevin Beall as Chief Information Security Officer

CTSI-Global, a long‑standing supply‑chain technology provider, has appointed former CTO Kevin Beall as its Chief Information Security Officer. Beall, who spent 16 years at the firm in roles ranging from CTO to VP of Business Insight, will oversee the company’s...

By SalesTech Star
Cyphercor Wins OCI Grant to Boost Critical Infrastructure MFA
NewsMay 4, 2026

Cyphercor Wins OCI Grant to Boost Critical Infrastructure MFA

Ontario‑based Cyphercor secured an Ontario Centre for Innovation grant to enhance its LoginTC multi‑factor authentication platform for operational technology and manufacturing settings. The funding will add contextual push alerts, biometric checks, and FIDO2‑compatible smart‑card access that work both online and...

By Fintech Global
Anthropic’s Claude Rolls Out End-User Identity Verification
NewsMay 4, 2026

Anthropic’s Claude Rolls Out End-User Identity Verification

Anthropic announced that select Claude users must complete a physical government‑issued ID verification (PIDV) using Persona Identities before accessing certain capabilities. The move is framed as part of Anthropic’s AI safety commitments and a response to rising regulatory and abuse...

By Forrester Blogs
Wiz ZeroDay.Cloud Event Reveals 20-Year-Old PostgreSQL Vulnerabilities
NewsMay 4, 2026

Wiz ZeroDay.Cloud Event Reveals 20-Year-Old PostgreSQL Vulnerabilities

Cybersecurity researchers at Wiz’s ZeroDay.Cloud event uncovered two critical, decade‑old vulnerabilities in PostgreSQL’s pgcrypto extension, CVE‑2026‑2005 and CVE‑2026‑2006. The flaws, dating back to 2005, enable buffer overflows and out‑of‑bounds memory writes that can lead to full database compromise. Wiz’s scans...

By HackRead
Palo Alto Networks Makes a $700M-Class AI Bet on Portkey Gateway
NewsMay 4, 2026

Palo Alto Networks Makes a $700M-Class AI Bet on Portkey Gateway

Palo Alto Networks announced its intent to acquire AI‑gateway startup Portkey, a deal valued in the $700 million range. Portkey already routes trillions of tokens each month for Fortune 500 firms and supports 3,000 LLMs, MCP servers, and agents via a single...

By The New Stack
Silver Fox Springs Tax-Themed Attacks on Orgs in India, Russia
NewsMay 4, 2026

Silver Fox Springs Tax-Themed Attacks on Orgs in India, Russia

Silver Fox, a China‑backed threat group, launched a tax‑themed phishing campaign targeting organizations in India and, for the first time, Russia. The emails impersonated tax authorities and delivered a Rust‑based loader that installed the known ValleyRAT RAT and a previously...

By Dark Reading
Quantum eMotion Launches eShield-Q for Runtime Cryptographic Protection
NewsMay 4, 2026

Quantum eMotion Launches eShield-Q for Runtime Cryptographic Protection

Quantum eMotion Corp. unveiled eShield‑Q on May 4, 2026, a runtime cryptographic protection platform that secures encryption keys while they are in use. The solution combines quantum‑generated entropy, register‑based key storage, just‑in‑time decryption, and continuous integrity checks to guard against memory‑scraping and...

By Quantum Computing Report
US Healthcare Marketplaces Shared Citizenship and Race Data with Ad Tech Giants
NewsMay 4, 2026

US Healthcare Marketplaces Shared Citizenship and Race Data with Ad Tech Giants

An investigation by Bloomberg found that most of the 20 state‑run health insurance exchanges in the U.S. transmitted applicants' personal data—including citizenship, race, sex, and even information about incarcerated family members—to advertising platforms such as Google, Meta, LinkedIn, Snap, and...

By TechCrunch (Main)
Kaspersky Spots Rising Scam Activity Around the 2026 World Cup
NewsMay 4, 2026

Kaspersky Spots Rising Scam Activity Around the 2026 World Cup

Kaspersky has detected a sharp rise in World Cup‑related scams as the 2026 tournament approaches, including fake $500,000 grant emails and counterfeit merchandise ads. The malicious messages mimic official tournament resources, aiming to steal personal data and financial assets. Kaspersky’s...

By IT News Africa
EasyDMARC and KnowBe4 Partner to Advance Proactive Email Security as Phishing Fuels More Than One-Third of Cyberattacks
NewsMay 4, 2026

EasyDMARC and KnowBe4 Partner to Advance Proactive Email Security as Phishing Fuels More Than One-Third of Cyberattacks

EasyDMARC and KnowBe4 announced a strategic partnership that blends domain protection with digital workforce security to curb phishing, spoofing and domain‑impersonation attacks. The deal makes EasyDMARC the exclusive DMARC service provider for KnowBe4’s customer base, embedding DMARC reporting, authentication gap...

By SalesTech Star
Opaque Buys Post-Quantum Cryptographic AI Tech From Abu Dhabi’s TII
NewsMay 4, 2026

Opaque Buys Post-Quantum Cryptographic AI Tech From Abu Dhabi’s TII

Opaque Systems Inc. announced the acquisition of advanced cryptographic AI technologies from Abu Dhabi’s Technology Innovation Institute. The deal adds multiparty computation, fully homomorphic encryption, and post‑quantum cryptographic safeguards to Opaque’s confidential AI platform, covering training, fine‑tuning, inference and agent...

By SiliconANGLE
They Don’t Hack, They Borrow: How Fraudsters Target Credit Unions
NewsMay 4, 2026

They Don’t Hack, They Borrow: How Fraudsters Target Credit Unions

Researchers at Flare uncovered a structured loan‑fraud playbook circulating on underground forums that targets small‑ to mid‑size credit unions. The method bypasses traditional security by using stolen personal data to pass knowledge‑based authentication and complete a full loan application, culminating...

By BleepingComputer
AI Deepfakes Are Moving Into Commercial Real Estate Operations
NewsMay 4, 2026

AI Deepfakes Are Moving Into Commercial Real Estate Operations

Artificial intelligence‑generated deepfakes are amplifying business email compromise schemes, now targeting commercial real‑estate operations. The FBI attributes over $2.9 billion in losses to BEC, and AI voice cloning is making vendor invoices, escrow wires and vacancy transitions vulnerable. Fraudsters start with...

By Buildings.com
Cisco Nerds Out: May the Fourth Be with Your AI Assistant
NewsMay 4, 2026

Cisco Nerds Out: May the Fourth Be with Your AI Assistant

Cisco unveiled "Galaxy Mode" for its AI Assistant, a limited‑time Star Wars‑themed interface for Meraki and Thousand Eyes customers that runs through June 4. The release introduces Deep Reasoning, an AI‑driven analysis engine that interprets network events and offers security compliance...

By Network World