Cybersecurity Social Media and Updates

Exploits Arrive Before Disclosure: Assume Exposure, Accelerate Detection
SocialMay 21, 2026

Exploits Arrive Before Disclosure: Assume Exposure, Accelerate Detection

“Mean time to exploit” is now effectively negative. Attackers are exploiting vulnerabilities before disclosure. Modern defense means assuming exposure, investing in detection and response, and using AI to reduce dwell time faster. https://t.co/3pHSy0XEWm https://t.co/Cma1mjX3V1

By Cristina Dolan
Europol and Eurojust Shut Down First VPN Network
SocialMay 21, 2026

Europol and Eurojust Shut Down First VPN Network

A joint operation led by Europol and Eurojust has dismantled 'First VPN,' taking 33 servers offline and seizing key domain names. https://t.co/K4asmKk77x

By TechRadar
Collaboration and AI Needed to Bridge Cyber Inequity
SocialMay 20, 2026

Collaboration and AI Needed to Bridge Cyber Inequity

Cyberattacks are increasingly targeting sectors with limited resources. Closing the growing cyber inequity gap will require collaboration, shared intelligence, and AI-enabled defense at scale. https://t.co/qcDAxmBp1E

By Cristina Dolan
Image Metadata Exploit Lets Attackers Hack Macs
SocialMay 20, 2026

Image Metadata Exploit Lets Attackers Hack Macs

We're covering CVE-2026-3102 in ExifTool, discovered by GReAT experts: how malicious... metadata (!) in image files can lead to Mac hacking. Learn more: https://t.co/2xP7Uzpwge https://t.co/btXdA79C49

By Eugene Kaspersky
Database Security Now the Foundation of AI
SocialMay 20, 2026

Database Security Now the Foundation of AI

PostgreSQL dropping MD5 auth. MongoBleed leaking server memory. SQL Server exposing vendor code on three clouds. Data governance broke out. Not because CDOs pushed. Because the attack surface got undeniable. The boring database work is now the load-bearing wall of your AI......

By Yves Mulkers
CIOs Must Act on Post‑quantum Cryptography Today.
SocialMay 19, 2026

CIOs Must Act on Post‑quantum Cryptography Today.

CIOs must take post quantum cryptography seriously today or risk future peril. #CIO #CISO #Quantum #Cybersecurity https://t.co/vZgTOh99DD

By Tim Crawford
AI Faces External and Internal Security Threats, Unprepared
SocialMay 19, 2026

AI Faces External and Internal Security Threats, Unprepared

AI Security Threats Coming From Outside And Inside, And Few Are Ready (My latest in @forbes) https://t.co/DzD1PKLGdd

By Joe McKendrick
Patch Fatigue Drives Surge in Vulnerability Exploitation
SocialMay 19, 2026

Patch Fatigue Drives Surge in Vulnerability Exploitation

Verizon DBIR 2026: Vulnerability Exploitation Takes the Lead, and Patch Fatigue Is the Reason https://t.co/VqEwEEH8Qb

By Shashi Bellamkonda
Secure Telegram: Update Weak Default Settings Now
SocialMay 18, 2026

Secure Telegram: Update Weak Default Settings Now

Whether you're an old hand or just jumping into Telegram, it's important to set up your privacy and security settings, because the defaults just ain't that good. Here's what to update: https://t.co/hFFAXUo8ox #telegram #privacy #security @telegram https://t.co/tduEu7WOa2

By Dave Taylor
Google Phone Adds Instant Hang‑up Button to Block Spoofed Calls
SocialMay 18, 2026

Google Phone Adds Instant Hang‑up Button to Block Spoofed Calls

Someone pretending to be your contact during calls? Google Phone could soon fight back. Users will be provided with a direct, prominent option to "Hang up" the call immediately from the alert screen ✅ Details - https://t.co/LXBGAuI68K https://t.co/Wv91QDRa87

By AssembleDebug (Shiv)
Federal Agencies Must Begin Post‑Quantum Crypto Transition Now
SocialMay 18, 2026

Federal Agencies Must Begin Post‑Quantum Crypto Transition Now

Transitioning to Post-Quantum Cryptography: What Federal Agencies Must Do Now - Intelligence Community News https://t.co/LAVSLjjCUB

By Chuck Brooks
Ransomware Attacks Dip, but Post‑quantum Threats Rise
SocialMay 18, 2026

Ransomware Attacks Dip, but Post‑quantum Threats Rise

Ransomware analytics and forecasts for 2026: the number of attacks is declining, but the risk remains high. We’re seeing new families based on post-quantum cryptography, a focus on RDWeb for initial access, and an increase in attacks involving data theft...

By Eugene Kaspersky
Hidden Audio Can Hijack AI Without User Awareness
SocialMay 17, 2026

Hidden Audio Can Hijack AI Without User Awareness

New research reveals how nearly imperceptible audio in videos, calls, or music can trigger unauthorized AI actions without users noticing. https://spectrum.ieee.org/voice-ai-audio-attacks?share_id=9501042

By IEEE Spectrum Threads
Diversify Custody: Combine Cold Wallets, Exchanges, Anchorage
SocialMay 15, 2026

Diversify Custody: Combine Cold Wallets, Exchanges, Anchorage

A hack at Anchorage cannot send your assets anywhere except your whitelisted cold wallet. Multi-sig process, 24 hour release SLA, and a verification call before anything moves. You are never a creditor of Anchorage. Assets sit in an FBO account...

By Jake Claver
Data Breaches Spawn Hidden Crimes, Even without Public Leaks
SocialMay 15, 2026

Data Breaches Spawn Hidden Crimes, Even without Public Leaks

Data breaches have a long tail of secondary crimes… even when no data is released publicly

By Troy Hunt
Five-Year Project Shattered in Five Days; Apple Scrambles
SocialMay 15, 2026

Five-Year Project Shattered in Five Days; Apple Scrambles

A product that took five years to build was broken into in five days, thanks to Mythos - and now Apple is working on a fix. https://t.co/ELqIjdHOVA

By TechRadar
Never Feed AI Your Financial Documents or Bank Links
SocialMay 15, 2026

Never Feed AI Your Financial Documents or Bank Links

Just worked w/ @CNN on a piece about why I wouldn't upload full financial docs (tax docs, statements, etc) to AI tools due to leakage & hacking risk. I don't recommend connecting bank accounts to AI tools. It becomes a 1...

By Rachel Tobac
AI-Driven SBOMs Enforce Data Protection Obligations Post‑GDPR
SocialMay 15, 2026

AI-Driven SBOMs Enforce Data Protection Obligations Post‑GDPR

'Where are companies' binding obligations to guard our data, our livelihoods, from misuse?' GDPR made that question expensive to ignore. AI is raising the stakes again. Cyber agencies already named it: AI-component SBOMs are the new supply-chain floor.

By Yves Mulkers
Incognito Doesn't Hide You From ISP Tracking
SocialMay 14, 2026

Incognito Doesn't Hide You From ISP Tracking

Going "Incognito" won't stop your internet provider from tracking, throttling, and selling your browsing history. Here is exactly how they see what you do online, and the best ways to shut them out. https://t.co/AoRYElRgkw

By TechRadar
Never Trust Nondeterministic AI Responses as Deterministic
SocialMay 14, 2026

Never Trust Nondeterministic AI Responses as Deterministic

LLMRisks Archive - OWASP Gen AI Security Project ~ just saw this. My number one would have been: Treating non-deterministic AI responses as deterministic and trusting them. https://t.co/psehlnxxXq

By Teri Radichel
Google Thwarts Massive Exploit by Securing Gemini APIs
SocialMay 13, 2026

Google Thwarts Massive Exploit by Securing Gemini APIs

On Google having disrupted a planned mass exploit: "In the last year, Google, Android, Chrome, etc., built Gemini in everywhere. "They found someone calling those APIs to say, 'Go find the attack surface and do exfiltration on the fly.'" 😱 --...

By Laura Shin
Chinese Laws Push BambuStudio to Breach Open‑Source License
SocialMay 13, 2026

Chinese Laws Push BambuStudio to Breach Open‑Source License

BambuStudio has been violating PrusaSlicer AGPL license since their fork, with the same networking binary black box in question today. Why are they willing to burn the goodwill over it? There's something most have sensed but never seen it all in...

By Josef Prusa
FBI Remotely Resets Compromised Routers, Evicts GRU
SocialMay 13, 2026

FBI Remotely Resets Compromised Routers, Evicts GRU

The FBI used court-authorization to remotely reset thousands of compromised home and small office routers, kicking the GRU out of sensitive networks. https://t.co/ap71RUhBGH

By TechRadar
Mini Shai-Hulud Threat Targets Emerging AI Coding Workflows
SocialMay 12, 2026

Mini Shai-Hulud Threat Targets Emerging AI Coding Workflows

the Mini Shai-Hulud attack is scary because it attacks new AI coding workflows like CI, editor hooks, agent configs, etc

By Yohei Nakajima
AI Accelerates Cyberattacks, Demands Stronger Defenses
SocialMay 12, 2026

AI Accelerates Cyberattacks, Demands Stronger Defenses

For our free newsletter this week, we discuss how AI-powered cyberattacks are a growing risk. And this morning a ton of hacks are being disclosed, as @emollick points out here. 
@IrenaCronin and I write this newsletter every week.   AI-powered cyberattacks are a...

By Robert Scoble
AI Supercharges Infrastructure Software and Cybersecurity Markets
SocialMay 12, 2026

AI Supercharges Infrastructure Software and Cybersecurity Markets

AI isn’t disrupting infrastructure software and cybersecurity - it’s supercharging them. Here’s why:• • Inference and agentic AI are exploding data volumes and complexity. That demands next-gen infrastructure software: smarter databases, orchestration, observability, IaC and data pipelines. Hyperscalers are dropping ~$700...

By Puru Saxena
Companies Face Lawsuits for Allegedly Addicting Users
SocialMay 12, 2026

Companies Face Lawsuits for Allegedly Addicting Users

Oh, FFS. These dolts will next sue Star Wars for addicting users. How about Dickens, folks? Not to mention Frito-Lay? Netflix sued by Texas for allegedly spying on children, addicting users https://t.co/qMiVieTu6o

By Jeff Jarvis
Free Open‑Source Browser Beats $500 Anti‑Detect Solutions
SocialMay 12, 2026

Free Open‑Source Browser Beats $500 Anti‑Detect Solutions

I'm done paying $500 a month for anti-detect browsers after finding this. It's called CloakBrowser. A stealth Chromium that scores 0.9 on reCAPTCHA v3 (same as a real human) and passes 14 out of 14 bot detection tests. - Auto-resolves Cloudflare Turnstile -...

By Hasan Toor
Binance AI Stops $10.5B Losses, Blocks 36K Threats
SocialMay 12, 2026

Binance AI Stops $10.5B Losses, Blocks 36K Threats

JUST IN: Binance's AI-powered security systems prevented $10.53B in user losses and blocked 36,000 malicious addresses since 2025.

By David Gokhshtein
Threats Hide in Plain Sight; Intelligence Beats Detection
SocialMay 12, 2026

Threats Hide in Plain Sight; Intelligence Beats Detection

As threats hide in plain sight, enterprises need intelligence and investigation, not just detection. https://t.co/KKOgpAAq5H

By TechRadar
Hyperscalers May Lose Public‑Sector Data Contracts
SocialMay 12, 2026

Hyperscalers May Lose Public‑Sector Data Contracts

US (and other global) hyperscalers could be pushed out of the running for contracts relating to sensitive public sector data. https://t.co/bzn1vgHBGg

By TechRadar
AI Powers Real‑World Zero‑Day Cyberattacks, Accelerating Threats
SocialMay 12, 2026

AI Powers Real‑World Zero‑Day Cyberattacks, Accelerating Threats

AI-assisted cyberattacks are no longer theoretical. Google says hackers used AI to discover an unknown software vulnerability, a glimpse of how offensive cyber capabilities may rapidly evolve. This is likely just the beginning. AI is accelerating not only innovation, but also the...

By Spiros Margaris
Critical Xrdp Buffer Overflow Fixed in Latest Release
SocialMay 12, 2026

Critical Xrdp Buffer Overflow Fixed in Latest Release

Our experts have discovered vulnerability CVE-2025-68670 in xrdp, a remote desktop server for Linux using the RDP protocol. A buffer overflow could lead to remote code execution without authentication. The issue has already been fixed in the latest versions. Details:...

By Eugene Kaspersky
Supply Chain Attacks Surge; Explore Mitigation Strategies and Vendors
SocialMay 12, 2026

Supply Chain Attacks Surge; Explore Mitigation Strategies and Vendors

Supply chain attacks are happening left and right with npm, PyPI and so many other places. It seems to be getting worse, everyone agrees. But what can you do about it? Some thoughts on possible approaches (all have tradeoffs). What did I...

By Gergely Orosz
Mythos Finds Just One Real Curl Vulnerability Amid False Positives
SocialMay 12, 2026

Mythos Finds Just One Real Curl Vulnerability Amid False Positives

The developer of curl tried using Anthropic’s Mythos to find security vulnerabilities. While it flagged 5 issues, 3 were false positives and 1 just a regular bug. So it only found 1 real security issue. That said curl already uses multiple...

By Dare Obasanjo
DWP Won’t DM You—Ignore Telegram/WhatsApp Scams
SocialMay 11, 2026

DWP Won’t DM You—Ignore Telegram/WhatsApp Scams

If someone messages you claiming to be from DWP on Telegram or WhatsApp, it is a scam. Direct outreach on social media does not happen. Team members respond to messages but there is no personal outreach. If you are unsure,...

By Jake Claver
GeForce NOW Breach Affects Single Country, No Passwords Taken
SocialMay 11, 2026

GeForce NOW Breach Affects Single Country, No Passwords Taken

The breach is limited to GeForce NOW users in just one country, and no passwords were stolen. https://t.co/6CZUppgiu8

By TechRadar
OpenAI Launches Daybreak to Accelerate Continuous Cyber Defense
SocialMay 11, 2026

OpenAI Launches Daybreak to Accelerate Continuous Cyber Defense

OpenAI is launching Daybreak, our effort to accelerate cyber defense and continuously secure software. AI is already good and about to get super good at cybersecurity; we'd like to start working with as many companies as possible now to help them...

By Sam Altman
NightBeacon Slashes Detection to Seconds, Cuts False Positives 87%
SocialMay 11, 2026

NightBeacon Slashes Detection to Seconds, Cuts False Positives 87%

NightBeacon is changing the game for us @Binary_Defense - we have this technology so dialed into every aspect of what we do. Our MTTD and MTTR has drastically been reduces to seconds and minutes, not multiple minutes or hours....

By Dave Kennedy
AI-Generated Scam Calls Now Mimic Real Voices
SocialMay 11, 2026

AI-Generated Scam Calls Now Mimic Real Voices

Scary indeed. AI-powered scam calls are getting more convincing—and more common: 'It was her voice, I know her scared cry' https://t.co/lV7jJx5BFm #CIO #AI

By Tim Crawford
Unified Tech, Law, and Innovation Needed to Stop Live Piracy
SocialMay 11, 2026

Unified Tech, Law, and Innovation Needed to Stop Live Piracy

Looking for an informed discussion navigating the intersection of 🔒 security technology stack, 🧑‍⚖️ legal frameworks and enforcement, as well as 📲 product innovation, here we go: In „Streaming Security at Scale: Protecting Live Sports Broadcasts,“ we are covering why an...

By Yannick Ramcke
AI Could Expose Every Open‑source Vulnerability, Ending Its Safety
SocialMay 11, 2026

AI Could Expose Every Open‑source Vulnerability, Ending Its Safety

We've had Linus's Law for decades: "Given enough eyeballs, all bugs are shallow." #catb After last week's Canvas breach, perhaps we need Linus's Corollary: Given powerful enough AI, all bugs will be found and exploited. Will AI's superhuman ability to find...

By David Wiley
Beware Spam: Don't Click Fake Alert Links
SocialMay 11, 2026

Beware Spam: Don't Click Fake Alert Links

FOLLOWERS.......I have some spam dirt bags out there trying to trick you. Do NOT click on any links that say I am sending out alerts or a strategy.

By Sunrise Trader
LLM Agents Link Anonymized Data to Individuals at Scale
SocialMay 11, 2026

LLM Agents Link Anonymized Data to Individuals at Scale

While gathering that data has become easier in the smartphone era, making use of it at scale has remained difficult. But researchers are beginning to show that LLM agents can connect anonymized data to real people quickly, cheaply, and at...

By MIT Technology Review Threads
1 Billion IDs Exposed: America’s Data Security Crisis
SocialMay 11, 2026

1 Billion IDs Exposed: America’s Data Security Crisis

Every day, in every way, it gets worse. Surely there’s no one left in America whose personal information isn’t already in the hands of crooks.. IDMerit exposes 1 billion identity records in unprotected database | Fox News

By Dave Birch
Canvas Hack Exposes Risks of Centralized EdTech Data
SocialMay 11, 2026

Canvas Hack Exposes Risks of Centralized EdTech Data

'The Biggest Student Data Privacy Disaster in History': Canvas Hack Shows the Danger of Centralized EdTech https://t.co/uYhtnaIe2g

By Chuck Brooks
Purple Teams Are Just Red and Blue Co‑Located
SocialMay 11, 2026

Purple Teams Are Just Red and Blue Co‑Located

Your Purple Team Isn't Purple — It's Just Red and Blue in the Same Room https://t.co/SgiQ1iLO6J https://t.co/n2GviJHqgA

By Eric Vanderburg
Curl Audit Finds Single Low‑severity CVE, Others False Positives
SocialMay 11, 2026

Curl Audit Finds Single Low‑severity CVE, Others False Positives

Mythos on Curl: Once my curl security team fellows and I had poked on the this short list for a number of hours and dug into the details, we had trimmed the list down and were left with one confirmed...

By Teri Radichel
HIBP Adds Costa Rica as 42nd Government Partner
SocialMay 11, 2026

HIBP Adds Costa Rica as 42nd Government Partner

HIBP’s free gov program keeps growing, helping governments get ahead of data breaches before attackers do. Today, we welcome our 42nd government: Costa Rica, protecting departments, public resources and the people behind them. https://t.co/GD14TAF6sU

By Troy Hunt