Cisco Patches CVSS 10.0 Secure Workload REST API Flaw Enabling Data Access | Cybersecurity
Ravie LakshmananMay 22, 2026Vulnerability / Network Security Cisco has rolled out updates for a maximum-severity security flaw impacting Secure Workload that could allow an unauthenticated, remote attacker to access sensitive…
Read moreMini Shai-Hulud worm injects disk wiper into Microsoft Azure PyPI package | News World
Supply chain attacks with a Dune sci-fi saga branding continue to spread across the open-source ecosystem, with a Microsoft package being among the latest target of worm-like malware that steals…
Read moreCatch spyware in the act with Windows Webcam Monitoring | Malware
You’re working hard late at night, replying to emails and planning the week ahead. Then suddenly, a PDF file requests access to your camera. Why would a PDF need camera access? Cybercriminals often disguise spyware…
Read moreMicrosoft Defender vulnerabilities are being exploited in the wild | Malware
Two Microsoft Defender vulnerabilities are being actively exploited in the wild. On May 20, 2026, the Cybersecurity and Infrastructure Security Agency (CISA) added a notable set of actively exploited vulnerabilities…
Read moreShowboat Linux Malware Hits Middle East Telecom with SOCKS5 Proxy Backdoor | Cybersecurity
Ravie LakshmananMay 21, 2026Cyber Espionage / Threat Intelligence Cybersecurity researchers have disclosed details of a new Linux malware dubbed Showboat that has been put to use in a campaign targeting…
Read moreTikTok, YouTube, and Roblox face scrutiny, but age gates won’t fix child safety | Malware
A damaging new report from Ofcom, the UK’s communications regulator, has delivered a stark verdict: TikTok and YouTube’s content feeds are “not safe enough” for children. This isn’t just another regulatory…
Read more9-Year-Old Linux Kernel Flaw Enables Root Command Execution on Major Distros | Cybersecurity
Ravie LakshmananMay 21, 2026Linux / Vulnerability Cybersecurity researchers have disclosed details of a vulnerability in the Linux kernel that remained undetected for nine years. The vulnerability, tracked as CVE-2026-46333 (CVSS…
Read moreGitHub Internal Repositories Breached via Malicious Nx Console VS Code Extension | Cybersecurity
Ravie LakshmananMay 21, 2026Supply Chain Attack / Developer Tools GitHub on Wednesday officially confirmed that the breach of its internal repositories was the result of a compromise of an employee…
Read moreFirefox 151 packs big privacy upgrades into a small update | Malware
Mozilla has published release notes for Firefox browser version 151.0, and this update includes several genuinely meaningful privacy and security improvements. Three changes stand out in particular: Stronger anti‑fingerprinting Broader…
Read moreMicrosoft Open-Sources RAMPART and Clarity to Secure AI Agents During Development | Cybersecurity
Ravie LakshmananMay 20, 2026Artificial Intelligence / Security Testing Microsoft has unveiled two new open-source tools called RAMPART and Clarity to assist developers in better testing the security of artificial intelligence…
Read moreFake malware-signing service Fox Tempest dismantled by Microsoft | Malware
Microsoft says it dismantled a malware-signing-as-a-service (MSaaS) called Fox Tempest, which helped cybercriminals make malware appear legitimate. The service let customers submit malicious files to be digitally signed with short-lived…
Read moreWebworm Deploys EchoCreep and GraphWorm Backdoors Using Discord and MS Graph API | Cybersecurity
Cybersecurity researchers have flagged fresh activity from a China-aligned threat actor known as Webworm in 2025, deploying custom backdoors that employ Discord and Microsoft Graph API for command-and-control (C2 or…
Read moreGrafana GitHub Breach Exposes Source Code via TanStack npm Attack | Cybersecurity
Ravie LakshmananMay 20, 2026Supply Chain Attack / Cloud Security Grafana Labs, on May 19, 2026, said an investigation into its recent breach found no evidence of customer production systems or…
Read moreFacebook scam promises cheap Aldi meat boxes, steals payment info instead | Malware
Sometimes you spot posts on social media that make you wonder if any moderation takes place at all. Which is concerning, because two–thirds of all online shopping scams now start…
Read moreBiometrics, diagnoses, and bank details exposed in major healthcare breach | Malware
NYC Health + Hospitals (NYC H+H) posted a data breach notice about a months‑long breach via a third‑party vendor that exposed highly sensitive patient and employee data for at least…
Read moreTrapdoor Android Ad Fraud Scheme Hit 659 Million Daily Bid Requests Using 455 Apps | Cybersecurity
Ravie LakshmananMay 19, 2026Malvertising / Mobile Security Cybersecurity researchers have disclosed details of a new ad fraud and malvertising operation dubbed Trapdoor targeting Android device users. The activity, per HUMAN’s…
Read moreThe New Phishing Click: How OAuth Consent Bypasses MFA | Cybersecurity
In February 2026, a phishing-as-a-service (PhaaS) platform called EvilTokens went live. Within five weeks, it had compromised more than 340 Microsoft 365 organizations across five countries. The targets of the…
Read moreYouTube wants your face to fight deepfakes | Malware
If you’re worried about deepfake likenesses of yourself showing up online, you’re not alone; YouTube is worried for you. It wants to protect you by having you upload a selfie…
Read morePopular GitHub Action Tags Redirected to Imposter Commit to Steal CI/CD Credentials | Cybersecurity
Ravie LakshmananMay 19, 2026Software Security / Malware In yet another software supply chain attack, threat actors have compromised the popular GitHub Actions workflow, actions-cool/issues-helper, to run malicious code that harvests…
Read moreAI is distorting the Holocaust (Lock and Code S07E10) | Malware
This week on the Lock and Code podcast… In May of last year, a warning about AI came from somewhere unexpected: The Auschwitz-Birkenau State Museum. Posting publicly on social media,…
Read moreINTERPOL Operation Ramz Disrupts MENA Cybercrime Networks with 201 Arrests | Cybersecurity
INTERPOL has coordinated a first-of-its-kind cybercrime crackdown across the Middle East and North Africa (MENA) that led to 201 arrests and the identification of an additional 382 suspects. The initiative…
Read more⚡ Weekly Recap: Exchange 0-Day, npm Worm, Fake AI Repo, Cisco Exploit and More | Cybersecurity
Ravie LakshmananMay 18, 2026Cybersecurity / Hacking Monday opens with a trust problem. A mail server flaw is under active use. A network control system was targeted. Trusted packages were poisoned….
Read moreMicrosoft is changing Edge’s plaintext password behavior | Malware
Microsoft said it will change Edge’s password handling as a “defense‑in‑depth” measure. Originally, Edge decrypted the entire saved‑password store on startup and kept all credentials resident in process memory in…
Read moreDeveloper Workstations Are Now Part of the Software Supply Chain | Cybersecurity
Supply chain attackers are not only trying to slip malicious code into trusted software. They are trying to steal the access that makes trusted software possible. Recently, three separate campaigns…
Read moreA week in security (May 11 – May 17) | Malware
Last week on Malwarebytes Labs: Attackers replaced JDownloader installer downloads with malware Meta’s confusing new approach to chat privacy Why Malwarebytes blocks some Yahoo Mail redirects Fake Claude search results…
Read moreMiniPlasma Windows 0-Day Enables SYSTEM Privilege Escalation on Fully Patched Systems | Cybersecurity
Ravie LakshmananMay 18, 2026Zero Day / Vulnerability Chaotic Eclipse, the security researcher behind the recently disclosed Windows flaws, YellowKey and GreenPlasma, has released a proof-of-concept (PoC) for a Windows privilege…
Read moreGrafana GitHub Token Breach Led to Codebase Download and Extortion Attempt | Cybersecurity
Ravie LakshmananMay 17, 2026Data Breach / Cybercrime Grafana has disclosed that an “unauthorized party” obtained a token that granted them the ability to access the company’s GitHub environment and download…
Read moreFunnel Builder Flaw Under Active Exploitation Enables WooCommerce Checkout Skimming | Cybersecurity
Ravie LakshmananMay 16, 2026Vulnerability / Website Security A critical security vulnerability impacting the Funnel Builder plugin for WordPress has come under active exploitation in the wild to inject malicious JavaScript…
Read moreMeta’s confusing new approach to chat privacy | Malware
Recent news had us wondering whether Meta actually knows what it wants. On one platform, Meta is promoting AI chats that it says even it cannot read. On another, it…
Read moreAttackers replaced JDownloader installer downloads with malware | Malware
If you downloaded the JDownloader installer during the compromise window (May 6-7), you are advised to verify the file. JDownloader is a popular download management application, particularly favored for automated…
Read more