π¨ One shared key. Every deployment at risk.
Attackers exploited CVE-2026-5426 in the KnowledgeDeliver LMS to gain unauthenticated RCE through hard-coded ASP-NET machineKeys, deploy the Godzilla (BLUEBEAM) web shell, and deliver Cobalt Strike Beacon on vulnerable internet-facing systems.
Read π https://thehackernews.com/2026/05/knowledgedeliver-lms-flaw-exploited-to.html
Attackers exploited CVE-2026-5426 in the KnowledgeDeliver LMS to gain unauthenticated RCE through hard-coded ASP-NET machineKeys, deploy the Godzilla (BLUEBEAM) web shell, and deliver Cobalt Strike Beacon on vulnerable internet-facing systems.
Read π https://thehackernews.com/2026/05/knowledgedeliver-lms-flaw-exploited-to.html
π₯8π€―4π2π1
β οΈ Cybercriminals are flooding the web with FIFA World Cup 2026 scams β before the tournament even starts.
https://thehackernews.com/expert-insights/2026/05/before-whistle-ctm360-reveals-how.html
Security firm CTM360 uncovered over 7,000 themed domains, with 4,500+ registered in just the last 5 months. Already 1,000+ malicious sites and 1,000+ fake social accounts are live.
Donβt get scammed before the first whistle.
https://thehackernews.com/expert-insights/2026/05/before-whistle-ctm360-reveals-how.html
Security firm CTM360 uncovered over 7,000 themed domains, with 4,500+ registered in just the last 5 months. Already 1,000+ malicious sites and 1,000+ fake social accounts are live.
Donβt get scammed before the first whistle.
π₯4π1
π¨ Iranian hackers deployed a new AI-assisted backdoor called MiniFast.
https://thehackernews.com/2026/05/iranian-hackers-deploy-minifast-and.html
IRGC-linked group Nimbus Manticore targeted aviation, software, telecom, and energy sectors across the U.S., Europe, and the Middle East.
The campaigns used:
β’ Phishing lures
β’ SEO poisoning
β’ Trojanized Zoom and SQL Developer installers
β’ Fake meeting invites
β’ AppDomain hijacking
Activity was tracked between February and April 2026.
https://thehackernews.com/2026/05/iranian-hackers-deploy-minifast-and.html
IRGC-linked group Nimbus Manticore targeted aviation, software, telecom, and energy sectors across the U.S., Europe, and the Middle East.
The campaigns used:
β’ Phishing lures
β’ SEO poisoning
β’ Trojanized Zoom and SQL Developer installers
β’ Fake meeting invites
β’ AppDomain hijacking
Activity was tracked between February and April 2026.
π€15β‘6π5π1
π¨ Indiaβs CERT-In has directed organizations to patch known exploited vulnerabilities in internet-facing systems within 12 hours where feasible as AI tools accelerate cyber attacks.
The guidance cites faster vulnerability discovery, phishing, malware generation, and exploitation workflows.
Read: https://thehackernews.com/2026/05/cert-in-mandates-12-hour-patching-for.html
The guidance cites faster vulnerability discovery, phishing, malware generation, and exploitation workflows.
Read: https://thehackernews.com/2026/05/cert-in-mandates-12-hour-patching-for.html
π9π€5π2π±2
Your "second factor" isn't as safe as you think.
Attackers donβt need to steal your MFA code anymore β they just exhaust you until you approve it.
MFA Prompt Bombing is quietly becoming one of the most effective attacks right now.
Read β https://thehackernews.com/2026/05/mfa-prompt-bombing-why-your-second.html
Attackers donβt need to steal your MFA code anymore β they just exhaust you until you approve it.
MFA Prompt Bombing is quietly becoming one of the most effective attacks right now.
Read β https://thehackernews.com/2026/05/mfa-prompt-bombing-why-your-second.html
π±6β‘2π1
β οΈ SharePoint RCE Vulnerability.
Details β https://thehackernews.com/2026/05/microsoft-patches-sharepoint-rce-flaw.html
CVE-2026-45659 allows authenticated attackers with only Site Member permissions to execute code remotely on SharePoint Server.
The CVSS 8.8 flaw affects SharePoint Server 2016, 2019, and Subscription Edition.
Details β https://thehackernews.com/2026/05/microsoft-patches-sharepoint-rce-flaw.html
CVE-2026-45659 allows authenticated attackers with only Site Member permissions to execute code remotely on SharePoint Server.
The CVSS 8.8 flaw affects SharePoint Server 2016, 2019, and Subscription Edition.
π3π2
The Zero Knowledge vault myth is over.
ETH Zurich (USENIX β26) identifies 27 attacks against cloud password managers. Storing secrets = a $150M+ systemic risk.
Unixi uSSO kills the vault via KDA:
πΉNo central DB
πΉNo phishing
πΉ100% enforcement
Details: https://thn.news/centralization-risk
ETH Zurich (USENIX β26) identifies 27 attacks against cloud password managers. Storing secrets = a $150M+ systemic risk.
Unixi uSSO kills the vault via KDA:
πΉNo central DB
πΉNo phishing
πΉ100% enforcement
Details: https://thn.news/centralization-risk
π₯5π€3π1
β‘AI is making DDoS attacks faster and smarter β helping attackers find weak spots, create new attack vectors, and scale attacks more efficiently.
Watch this WEBINAR to see how it works β https://thehackernews.com/2026/05/new-ai-ddos-attacks-are-smarter-learn.html
What youβll get:
β’ Real examples of todayβs AI-enhanced attacks
β’ How to find & fix hidden weaknesses fast
β’ Practical defenses you can apply immediately
Watch this WEBINAR to see how it works β https://thehackernews.com/2026/05/new-ai-ddos-attacks-are-smarter-learn.html
What youβll get:
β’ Real examples of todayβs AI-enhanced attacks
β’ How to find & fix hidden weaknesses fast
β’ Practical defenses you can apply immediately
π7π5β‘2π±2
π¨ MuddyWater hit 9 countries.
Read β https://thehackernews.com/2026/05/muddywater-uses-dll-side-loading-in.html
The Iranian hacking group targeted 9 organizations using signed Fortemedia and SentinelOne binaries to sideload malware, steal Chrome data, and quietly maintain access inside victim networks.
One intrusion lasted a full week inside a major South Korean electronics company.
Read β https://thehackernews.com/2026/05/muddywater-uses-dll-side-loading-in.html
The Iranian hacking group targeted 9 organizations using signed Fortemedia and SentinelOne binaries to sideload malware, steal Chrome data, and quietly maintain access inside victim networks.
One intrusion lasted a full week inside a major South Korean electronics company.
π₯10π±3π2β‘1
AI uncovered a 27-year-old bug in OpenBSD that survived decades of human audits.
RunSafe Securityβs CEO Joseph M. Saunders warns: you canβt patch your way out of this anymore.
With AI flooding teams with discoveries and EU CRA regulations incoming, remediation backlogs just became unmanageable.
Full insights here: https://thehackernews.com/expert-insights/2026/05/you-cant-patch-your-way-out-of-this-one.html
RunSafe Securityβs CEO Joseph M. Saunders warns: you canβt patch your way out of this anymore.
With AI flooding teams with discoveries and EU CRA regulations incoming, remediation backlogs just became unmanageable.
Full insights here: https://thehackernews.com/expert-insights/2026/05/you-cant-patch-your-way-out-of-this-one.html
π13π5π±4β‘1
π¨ AI chatbots are pushing cryptojacking malware.
Read β https://thehackernews.com/2026/05/ai-chatbot-recommendations-redirect.html
Attackers poisoned AI software recommendations to redirect users searching for tools like CrystalDiskInfo and HWMonitor to malicious download sites distributing ScreenConnect, rogue DLLs, and GPU mining malware.
More than 150 malicious domains were identified.
Read β https://thehackernews.com/2026/05/ai-chatbot-recommendations-redirect.html
Attackers poisoned AI software recommendations to redirect users searching for tools like CrystalDiskInfo and HWMonitor to malicious download sites distributing ScreenConnect, rogue DLLs, and GPU mining malware.
More than 150 malicious domains were identified.
β‘5π1
π¨ Gitea flaw exposes private container images without authentication.
https://thehackernews.com/2026/05/gitea-vulnerability-exposes-private.html
CVE-2026-27771 affects all Gitea versions before 1.26.2 and likely impacts 30,000+ deployments worldwide. Attackers can pull private images without an account or password.
Update now or enable REQUIRE_SIGNIN_VIEW as a temporary workaround.
https://thehackernews.com/2026/05/gitea-vulnerability-exposes-private.html
CVE-2026-27771 affects all Gitea versions before 1.26.2 and likely impacts 30,000+ deployments worldwide. Attackers can pull private images without an account or password.
Update now or enable REQUIRE_SIGNIN_VIEW as a temporary workaround.
π8π₯1
π§ βMicrosoft Teamsβ download from X? Itβs likely malware.
Read: https://thehackernews.com/2026/05/weekly-recap-linux-flaws-defender-0.html#:~:text=Fake%20Microsoft%20Teams%20Sites%20Deliver%20ValleyRAT
Fake sites push trojanized ZIPs. NSIS installer drops real Teams (looks clean) + uses legit Tencent GameBox.exe to sideload Utility.dll β deploys ValleyRAT (SilverFox group).
Adds Defender exclusions, in-memory decryption, hidden files, and _CCGDAT service for persistence.
Read: https://thehackernews.com/2026/05/weekly-recap-linux-flaws-defender-0.html#:~:text=Fake%20Microsoft%20Teams%20Sites%20Deliver%20ValleyRAT
Fake sites push trojanized ZIPs. NSIS installer drops real Teams (looks clean) + uses legit Tencent GameBox.exe to sideload Utility.dll β deploys ValleyRAT (SilverFox group).
Adds Defender exclusions, in-memory decryption, hidden files, and _CCGDAT service for persistence.
π8β‘4π2π₯1
π₯ GlassWorm disrupted.
Read - https://thehackernews.com/2026/05/glassworm-malware-takedown-disrupts.html
The malware poisoned 300+ GitHub repositories through:
β’ Malicious VS Code extensions
β’ Compromised npm packages
β’ Trojanized Python packages
Its infrastructure used Solana, BitTorrent DHT, Google Calendar, and VPS servers as resilient C2 layers β all now neutralized.
Read - https://thehackernews.com/2026/05/glassworm-malware-takedown-disrupts.html
The malware poisoned 300+ GitHub repositories through:
β’ Malicious VS Code extensions
β’ Compromised npm packages
β’ Trojanized Python packages
Its infrastructure used Solana, BitTorrent DHT, Google Calendar, and VPS servers as resilient C2 layers β all now neutralized.
π₯7π1
Media is too big
VIEW IN TELEGRAM
AI agents aren't taking over humanityβ¦ yet. But they are multiplying in places you probably can't see, especially if youβre relying only on API-based agent discovery.
That limitation stops today. Nudge Security is the first solution provider to offer browser-based agentic AI discovery, extending agent visibility to more of the platforms where your teams are building agents.
With Nudge Security you can:
β Discover agents across 20+ platforms
β Inventory agent permissions, resources, and capabilities
β Surface risky integrations, publicly accessible agents, hardcoded credentials, and other risks
β Nudge agent creators to confirm purpose, justify use, and remediate risks
Take control of agentic AI risks with a free trial of Nudge Security. Get started here: https://thn.news/ai-agent-discovery
That limitation stops today. Nudge Security is the first solution provider to offer browser-based agentic AI discovery, extending agent visibility to more of the platforms where your teams are building agents.
With Nudge Security you can:
β Discover agents across 20+ platforms
β Inventory agent permissions, resources, and capabilities
β Surface risky integrations, publicly accessible agents, hardcoded credentials, and other risks
β Nudge agent creators to confirm purpose, justify use, and remediate risks
Take control of agentic AI risks with a free trial of Nudge Security. Get started here: https://thn.news/ai-agent-discovery
π₯5π1
Employees are secretly using 3β5 AI tools every day β most unapproved by IT.
Theyβre connecting straight to company emails, docs & drives via OAuth, bypassing security entirely.
Smart fix: Donβt ban it. Build a fast, safe approval path instead.
Get new 5-step playbook to manage Shadow AI without slowing teams down β https://thehackernews.com/2026/05/5-steps-to-managing-shadow-ai-tools.html
Theyβre connecting straight to company emails, docs & drives via OAuth, bypassing security entirely.
Smart fix: Donβt ban it. Build a fast, safe approval path instead.
Get new 5-step playbook to manage Shadow AI without slowing teams down β https://thehackernews.com/2026/05/5-steps-to-managing-shadow-ai-tools.html
π1
Malware that canβt be taken down?
Void Botnet β Rust loader using Ethereum smart contracts for seizure-resistant C2.
https://thehackernews.com/2026/05/weekly-recap-linux-flaws-defender-0.html#:~:text=Void%20Botnet%20Uses%20Ethereum%20Smart%20Contracts%20for%20C2
Built by TheVoidStl, sold on crime forums. ~1.5MB Windows binary with dual modes:
πΈ Blockchain: Commands via smart contract, bots poll RPCs (3-5 min)
πΈ Direct: Web panel (<30s)
Void Botnet β Rust loader using Ethereum smart contracts for seizure-resistant C2.
https://thehackernews.com/2026/05/weekly-recap-linux-flaws-defender-0.html#:~:text=Void%20Botnet%20Uses%20Ethereum%20Smart%20Contracts%20for%20C2
Built by TheVoidStl, sold on crime forums. ~1.5MB Windows binary with dual modes:
πΈ Blockchain: Commands via smart contract, bots poll RPCs (3-5 min)
πΈ Direct: Web panel (<30s)
π₯3π1
β οΈ WARNING - A malicious npm package was caught stealing files from Claude AI usersβ /mnt/user-data directories and uploading them to attacker-controlled GitHub repositories.
Check your installed packages: https://thehackernews.com/2026/05/malicious-npm-package-stole-files-from.html
The package, βmouse5212-super-formatter,β used npm postinstall scripts, hard-coded GitHub tokens, and fake network logs to hide the theft.
Downloaded 676 times so far.
Check your installed packages: https://thehackernews.com/2026/05/malicious-npm-package-stole-files-from.html
The package, βmouse5212-super-formatter,β used npm postinstall scripts, hard-coded GitHub tokens, and fake network logs to hide the theft.
Downloaded 676 times so far.
π1
Most breaches slip in as βnormalβ activity.
Top SOCs shrink uncertainty before it becomes an incident using 3 steps:
βΎοΈ Fresh sandbox IOCs (domains, C2s) auto-updating SIEM/EDR
βΎοΈ One-click alert context: malware family, behavior & execution chain
βΎοΈ Automated sandbox reports with AI summaries & visual chains
Prevention happens before the incident gets a name.
Read the full 3 steps β https://thehackernews.com/2026/05/3-soc-steps-that-shut-down-incident.html
Top SOCs shrink uncertainty before it becomes an incident using 3 steps:
βΎοΈ Fresh sandbox IOCs (domains, C2s) auto-updating SIEM/EDR
βΎοΈ One-click alert context: malware family, behavior & execution chain
βΎοΈ Automated sandbox reports with AI summaries & visual chains
Prevention happens before the incident gets a name.
Read the full 3 steps β https://thehackernews.com/2026/05/3-soc-steps-that-shut-down-incident.html
π2
π Banking malware is hiding in WebRTC traffic on Windows while Android RATs spread via fake Google Play pages.
Read - https://thehackernews.com/2026/05/grandoreiro-malware-and-btmob-rat.html
β’ Grandoreiro targets Portugal, Spain, and Mexico using DLL side-loading.
β’ BTMOB targets Brazil with phishing, remote control, and banking theft features.
Read - https://thehackernews.com/2026/05/grandoreiro-malware-and-btmob-rat.html
β’ Grandoreiro targets Portugal, Spain, and Mexico using DLL side-loading.
β’ BTMOB targets Brazil with phishing, remote control, and banking theft features.
π€5β‘2