- New CIFSwitch Linux flaw gives root on multiple distributionsby Bill Toulas on May 30, 2026
A newly discovered local privilege escalation vulnerability dubbed 'CIFSwitch' in the Linux kernel could allow attackers to forge CIFS authentication key […]
- PAN-OS GlobalProtect Authentication Bypass (CVE-2026-0257) Under Active Exploitationby info@thehackernews.com (The Hacker News) on May 30, 2026
Palo Alto Networks has warned that a recently disclosed medium-severity security flaw impacting PAN-OS and Prisma Access has come under active exploitation in […]
- ChatGPT share links abused to host fake outage pages to deliver malwareby Lawrence Abrams on May 29, 2026
Threat actors are abusing ChatGPT's content-sharing feature to display fake OpenAI outage pages that direct users to download malware disguised as the ChatGPT […]
- California AG sues 23andMe over 2023 breach exposing health databy Bill Toulas on May 29, 2026
California Attorney General Rob Bonta filed a lawsuit against 23andMe, now Chrome Holding Co., over the company's failure to protect sensitive customer genetic […]
- ChatGPhish Vulnerability Turns ChatGPT Web Summaries Into a Phishing Surfaceby info@thehackernews.com (The Hacker News) on May 29, 2026
Cybersecurity researchers have disclosed details of a vulnerability in OpenAI ChatGPT that leverages the artificial intelligence (AI) assistant's implicit […]
- Attackers Use LLM Agent for Post-Exploitation After Marimo CVE-2026-39987 Exploitby info@thehackernews.com (The Hacker News) on May 29, 2026
An unknown threat actor has been observed using a large language model (LLM) agent to conduct post-compromise actions after obtaining initial access following […]
- From $5 Attacks to Botnet-Powered Platforms: Inside the DDoS-as-a- Service Marketby Sponsored by Flare on May 29, 2026
DDoS attacks are increasingly being sold like subscription services, complete with pricing tiers, support, and reseller programs. Flare explores how the […]
- Dutch govt disrupts malware botnet with 17 million infected devicesby Bill Toulas on May 29, 2026
Dutch authorities have taken offline a massive botnet of 17 million devices and seized more than 200 servers at a local provider that supported the operation. […]
- Google Chrome adds session cookie theft protection for all usersby Sergiu Gatlan on May 29, 2026
Google says the Chrome Device Bound Session Credentials (DBSC) security feature is now generally available and is rolling out to all users to prevent account […]
- New Russia-Linked GREYVIBE Targets Ukraine with AI-Powered Cyberattacksby info@thehackernews.com (The Hacker News) on May 29, 2026
A previously undocumented threat actor dubbed GREYVIBE has been attributed to ongoing and persistent attacks targeting Ukraine and Ukraine-related entities […]
- Man sent to prison for selling data of 7 millions elderly Americansby Sergiu Gatlan on May 29, 2026
A North Carolina man was sentenced to more than 10 years in prison for selling the personal information of over 7 million elderly Americans to Jamaican […]
- What 2,000 Exposed Vibe-Coded Apps Reveal About the Limits of Most Security Stacksby info@thehackernews.com (The Hacker News) on May 29, 2026
Shadow AI used to mean employees pasting things they shouldn't into ChatGPT. It now means something bigger: employees building full applications with AI, […]
- US charges Google security engineer with Polymarket insider tradingby Sergiu Gatlan on May 29, 2026
A Google security engineer was charged with insider trading after winning $1.2 million using confidential company data to place bets on the […]
- Malicious Sicoob NuGet Steals Banking Credentials as npm Packages Target Cloud Secretsby info@thehackernews.com (The Hacker News) on May 29, 2026
Cybersecurity researchers have discovered a malicious NuGet package that masquerades as a C# software development kit for Sicoob, one of Brazil's largest […]
- Charter Communications data breach affects 4.9 million accountsby Sergiu Gatlan on May 29, 2026
The ShinyHunters extortion gang stole personal information from 4.9 million accounts after hacking the U.S. telecom giant Charter Communications in early […]
- This month in security with Tony Anscombe – May 2026 editionon May 29, 2026
In this roundup, Tony looks at attacks against Polish water treatment facilities, how AI-directed attacks failed in Mexico, and what Google believes is the […]
- Kimsuky Deploys HTTPSpy, Expands Arsenal with HelloDoor and VS Code Tunnelsby info@thehackernews.com (The Hacker News) on May 29, 2026
The North Korean state-sponsored threat actor known as Kimsuky (aka Velvet Chollima) has been attributed to a fresh set of cyber attacks targeting South Korean […]
- Anthropic confirms Claude Mythos-class models will roll out to the publicby Mayank Parmar on May 29, 2026
Anthropic has confirmed that it plans to bring Mythos-class models to the general public after delaying the rollout due to security risks to public and private […]
- GreyVibe hackers use ChatGPT, Gemini to power cyberattacksby Bill Toulas on May 28, 2026
A likely Russian threat cluster tracked as GreyVibe has been targeting Ukrainian entities with AI-generated lures and a rich set of custom malware tools. [...]
- BTMOB Android malware service generates custom phishing payloadsby Bill Toulas on May 28, 2026
An Android remote access trojan named BTMOB is offered to cybercriminals with a builder interface for generating malware payloads tailored to phishing lures. […]
- FBI warns of fake FIFA websites running World Cup fraud schemesby Bill Toulas on May 28, 2026
The FBI is warning of fake websites impersonating FIFA ahead of the 2026 World Cup, to steal personal and financial information, sell fake tickets and […]
- Hackers exploit FortiClient EMS flaw to push infostealer malwareby Bill Toulas on May 28, 2026
Hackers are exploiting an authentication bypass vulnerability (CVE-2026-35616) in FortiClient Enterprise Management Server (EMS) to deliver an undocumented […]
- Critical Gogs RCE Vulnerability Lets Any Authenticated User Execute Arbitrary Codeby info@thehackernews.com (The Hacker News) on May 28, 2026
A critical security vulnerability has been disclosed in Gogs, a popular open-source self-hosted Git service, that allows an authenticated user to execute […]
- Threat Actors Exploit Critical FortiClient EMS Flaw to Deploy Credential Stealerby info@thehackernews.com (The Hacker News) on May 28, 2026
Threat actors are continuing to exploit a critical, now-patched security flaw impacting FortiClient Endpoint Management Server (EMS) deployments to deliver […]
- New Gogs zero-day flaw lets hackers get remote code executionby Sergiu Gatlan on May 28, 2026
An unpatched zero-day vulnerability in the Gogs self-hosted Git service can allow attackers to gain remote code execution (RCE) on Internet-facing instances. […]
- Healthcare Orgs Lack Confidence in Ability to Defend Against an AI-incited Identity Breachby Steve Alder on May 28, 2026
Healthcare organizations have embraced AI and are using AI agents to perform a range of functions, including handling IT support The post Healthcare Orgs Lack […]
- Microsoft Slams Public Zero-Day Disclosures Amid GitHub Researcher Account Removalby info@thehackernews.com (The Hacker News) on May 28, 2026
Microsoft has come out strongly in favor of Coordinated Vulnerability Disclosure (CVD), urging the research community to share their findings and give affected […]
- ThreatsDay Bulletin: Claude Security Plugin, Azure Priv-Esc, Kali365 MFA Bypass, FIFA Scams +15 Moreby info@thehackernews.com (The Hacker News) on May 28, 2026
Every time you think the industry has finally stopped doing some reckless, low-effort crap, somebody spins up a fresh box full of sketchy loaders, fake […]
- New AI Usage Report: Enterprise AI Risk Is Heavily Concentrated Among a Small Group of AI "Power users"by info@thehackernews.com (The Hacker News) on May 28, 2026
State of AI Usage Report 2026 (full report here) by LayerX Security reveals the extent of the enterprise AI visibility gap and why most organizations still […]
- ESET APT Activity Report Q4 2025–Q1 2026on May 28, 2026
An overview of the activities of selected APT groups investigated and analyzed by ESET Research in Q4 2025 and Q1 2026
- JINX-0164 Targets Cryptocurrency Firms with Fake Recruiter Lures and macOS Malwareby info@thehackernews.com (The Hacker News) on May 28, 2026
A new campaign orchestrated by a previously undocumented threat actor has targeted cryptocurrency organizations with an aim to facilitate digital asset theft […]
- Grandoreiro Malware and BTMOB RAT Campaigns Target Windows and Android Usersby info@thehackernews.com (The Hacker News) on May 27, 2026
Latin America and Europe become the target of two banking trojan campaigns that are designed to infect Windows and Android devices with Grandoreiro and BTMOB […]
- Malicious npm Package Stole Files From Claude AI User Directory via GitHubby info@thehackernews.com (The Hacker News) on May 27, 2026
Cybersecurity researchers have discovered a new malicious package on the npm registry that comes with information stealing capabilities. According to OX […]
- 5 Steps to Managing Shadow AI Tools Without Slowing Down Employeesby info@thehackernews.com (The Hacker News) on May 27, 2026
When an employee installs an AI writing assistant, connects a coding copilot to their IDE, or starts summarizing meetings with a new browser tool, they are […]
- Extortion Group Conducts Social Engineering Campaign Impersonating IT Support Staffby Steve Alder on May 27, 2026
Silent Ransom Group, a data theft and extortion group that targets law firms, healthcare organizations, and insurance and finance companies, The post […]
- GlassWorm Malware Takedown Disrupts Developer Supply Chain Attack Infrastructureby info@thehackernews.com (The Hacker News) on May 27, 2026
CrowdStrike, in partnership with Google and the Shadowserver Foundation, has announced the simultaneous disruption of all command-and-control (C2) channels […]
- 3 SOC Steps that Shut Down Incident Risks Earlyby info@thehackernews.com (The Hacker News) on May 27, 2026
Most organizations still picture cyber defense as a fortress problem: build stronger walls, add more guards, buy another detection engine. But modern incidents […]
- Gitea Vulnerability Exposes Private Container Images without Authenticationby info@thehackernews.com (The Hacker News) on May 27, 2026
Cybersecurity researchers have disclosed a security flaw in Gitea, an open-source, self-hosted platform for version control, that allows unauthenticated remote […]
- What to consider before asking an AI chatbot for health adviceon May 27, 2026
Using chatbots for medical advice could elicit hallucinations and even expose you to security and privacy risks. Here’s what’s at stake and how to stay […]
- AI Chatbot Recommendations Redirect Users to Cryptojacking Malware Sitesby info@thehackernews.com (The Hacker News) on May 27, 2026
Microsoft has warned of an active cryptojacking campaign that makes use of artificial intelligence (AI) chatbot interactions as a mechanism for surfacing […]
- MuddyWater Uses DLL Side-Loading in Espionage Campaign Targeting 9 Countriesby info@thehackernews.com (The Hacker News) on May 26, 2026
The Iranian hacking group known as MuddyWater has been linked to a new campaign affecting at least nine organizations across nine countries on four continents […]
- [THN Webinar] New AI DDoS Attacks Are Smarter. Learn How to Fight Backby info@thehackernews.com (The Hacker News) on May 26, 2026
Every single day, hackers are finding new ways to crash websites and steal data. But right now, something has changed. Hackers are no longer working alone. […]
- Microsoft Patches SharePoint RCE Flaw CVE-2026-45659 Across Server Versionsby info@thehackernews.com (The Hacker News) on May 26, 2026
Microsoft has rolled out updates to fix a remote code execution vulnerability impacting SharePoint that could be exploited by bad actors in attacks without […]
- MFA Prompt Bombing: Why Your Second Factor Isn't Saving Youby info@thehackernews.com (The Hacker News) on May 26, 2026
Multi-factor authentication (MFA) was supposed to close a critical gap in identity security. It meant that, even if an attacker possessed the account […]
- CERT-In Recommends 12-Hour Patching for Internet-Facing Flaws Amid AI-Assisted Attacksby info@thehackernews.com (The Hacker News) on May 26, 2026
The Indian Computer Emergency Response Team (CERT-In) has issued new guidelines requiring organizations to patch critical security vulnerabilities in […]
- BTMOB: A stealthy RAT burrowing deep into Android deviceson May 26, 2026
The malware pairs remote access capabilities with ready-made campaign tools, lowering the barrier for full device compromise
- Iranian Hackers Deploy MiniFast and MiniJunk V2 via Phishing and SEO Poisoningby info@thehackernews.com (The Hacker News) on May 26, 2026
The Iranian state-sponsored threat actor known as Nimbus Manticore (aka Screening Serpens and UNC1549) has been attributed to a fresh campaign using lures […]
- KnowledgeDeliver LMS Flaw Exploited to Deploy Godzilla and Cobalt Strikeby info@thehackernews.com (The Hacker News) on May 26, 2026
A now-patched high-severity security flaw affecting Digital Knowledge KnowledgeDeliver, a Learning Management System (LMS) popular in Japan, was exploited as a […]
- ⚡ Weekly Recap: Linux Flaws, Defender 0-Days, Router Botnets, and Supply Chain Chaosby info@thehackernews.com (The Hacker News) on May 25, 2026
Monday recap. Same mess, new week. A sketchy dev tool got people pwned, old bugs came back from the dead, and security products somehow needed protecting from […]
- Netherlands Seizes 800 Servers, Arrests 2 for Aiding Cyberattacksby BrianKrebs on May 25, 2026
Authorities in the Netherlands have arrested the co-owners of two related Internet hosting companies for operating IT infrastructure used by Russia to carry […]





















![[THN Webinar] New AI DDoS Attacks Are Smarter. Learn How to Fight Back](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiphaRoHMD4mkIzApkJZumEOEdIR0c_RxQrvmjv5qM6Kgo8MBnKrIAxicsojC-CdXhcOfRR9t0DxQeyEMXjXtER-bkSqe97zvFr7mfz3HjwA-79JjLWg0IwhZFTulr__kB02fXgX09tOpLWUjqy-fFmQbfvCZG-2uLLAhJpFAFrPo5d9H0PVZHEaSvmZKFE/s1600/ddossss.jpg)






