Security · Top stories
F5 Releases Patches for Critical NGINX Vulnerability Allowing Remote Code Execution
F5 has released security patches for a critical vulnerability in NGINX (CVE-2026-42533) that allows remote attackers to trigger a heap buffer overflow, potentially leading to remote code execution and denial of service. This vulnerability affects numerous NGINX versions and some configurations, which could expose many installations unless updated.
Texas Police Acquire FalcoNet Surveillance System for $4.5 Million
Texas State Police purchased four FalcoNet-equipped Chevrolet Tahoes for $4.5 million to enhance surveillance capabilities. This technology, capable of intercepting mobile phone communications, raises significant concerns over privacy and data collection on civilians.
Hackers Target Russian Government Agencies via ViPNet Software Abuse
A threat actor is exploiting ViPNet's update mechanism to deploy malware against Russian organizations, including government agencies. The campaign, named HelloNet, impacts multiple sectors and reflects ongoing vulnerabilities in widely used security products.
Fraudsters Target X Accounts with Fake Login Alerts
Fraudulent emails impersonating X notify users of suspicious logins from unfamiliar devices. Clicking links in these emails can lead to credential theft, putting users' accounts at risk for scams.
Florida Man Arrested for Cryptocurrency Theft via Steam Game Malware
Zyaire Wilkins was arrested for allegedly using malware-laden games on Steam to steal $220,000 in cryptocurrency. The operation infected about 8,000 devices and targeted 80 crypto wallets from May 2024 to February 2026. This highlights security risks in digital distribution platforms like Steam.
OpenAI and Hugging Face Report Security Incident in Model Evaluation
OpenAI and Hugging Face confirmed a security incident during the evaluation of machine learning models. This incident emphasizes the need for robust security measures in AI development environments.
Claude for Chrome Vulnerability Exposes User Data to Rogue Extensions
A vulnerability in Claude for Chrome allows rogue extensions to trigger sensitive tasks without user consent. Discovered by Manifold Security, the flaw enables malicious extensions to access Gmail, Google Docs, Calendar, and Salesforce, posing a significant security risk. This issue persists in version 1.0.80, with no current patch.
Analysts Raise Concerns Over Cybersecurity Risks of Over-the-Air Tech in Automobiles
The growing use of over-the-air (OTA) technology in vehicles poses cybersecurity risks, with analysts urging intervention. This technology, while efficient for vehicle updates, may expose automotive systems to potential foreign cyber threats and national security issues.
Zoom Patches Critical Vulnerability Allowing Account Takeovers
Zoom has patched a critical vulnerability (CVE-2026-53412) in its Windows applications, rated 9.8 on the CVSS scale, which enabled potential account takeovers. The flaw affected Zoom Workplace, Zoom VDI Client, and Zoom Meeting SDK for Windows prior to version 7.0.0. This vulnerability impacts user security and necessitates immediate updates to prevent unauthorized account access.
Microsoft Revokes Vulnerable UEFI Shims Allowing Secure Boot Bypass
Microsoft has revoked the signatures of 11 old UEFI shims signed by them, which could bypass Secure Boot on Windows and Linux systems. This security flaw, discovered by ESET, existed due to old firmware remaining signed and trusted despite vulnerabilities. Addressing this issue is critical for preventing the unauthorized execution of code during the system boot process.
Craneware Reports Data Breach Affecting US Hospitals and Pharmacies
Craneware, a UK-based software provider for over 2,000 US hospitals, reported a data breach involving employee and customer information. The breach resulted in the theft of significant data, impacting hospitals' billing and patient management services. The incident has been contained, with investigations ongoing.
Hacker Attack Disrupts Romania's Land Registry Operations
Romania's land registry agency suffered a cyberattack, resulting in the wiping of its database and a halt in real estate transactions. The agency is migrating its systems to the government cloud to restore operations while ensuring data integrity.
Russian Hackers Use Security Cameras to Monitor NATO and Ukrainian Military Movements
Russian intelligence services are using internet-connected security cameras across Ukraine and NATO states to gather military intelligence. This operation involves exploiting cameras with default settings or security flaws, collecting data on military logistics and weapon shipments, and targeting Ukrainian troops. The breaches pose serious security risks across Europe and Ukraine.
Critical Vulnerability in Cursor IDE Allows Arbitrary Code Execution on Windows
A vulnerability in Cursor IDE enables arbitrary code execution by executing malicious git binaries in project roots. Reported by Mindgard in December 2025, the issue remains unpatched, affecting over 7 million users. The flaw involves Cursor executing 'git.exe' files in repository roots without user interaction, posing significant security risks.
Progress Software Confirms Zero-Day Vulnerability in ShareFile Storage Zone Controllers
Progress Software advised ShareFile users to shut down Storage Zone Controllers due to a zero-day vulnerability. The high-severity path traversal flaw, affecting versions 5.x and 6.x, led to precautionary account access suspension and patches release. No customer data compromise has been reported.
xAI's Grok CLI Tool Exposed for Uploading Entire Repositories Without Consent
xAI's Grok Build CLI tool was found transmitting entire code repositories, including sensitive files, to its cloud storage, causing privacy concerns. After researcher cereblab's disclosure, xAI altered the tool silently. Elon Musk said all uploaded data would be deleted to maintain privacy standards.
Microsoft 365 Users Targeted in Voice Phishing Campaign for Fake Entra Passkey Enrollment
A voice phishing campaign is exploiting Microsoft 365 users to unwittingly enroll fake Entra passkeys, giving attackers unauthorized account access and facilitating potential data extortion. Initiated by the group O-UNC-066, the campaign began in April and spans multiple industries, highlighting vulnerabilities in the passkey adoption process Microsoft implemented. Okta reported the attacks, which utilize convincing phishing kits mimicking Microsoft's passkey enrollment portal.
US and Allied Nations Warn of Russian Router-Based Cyberattacks on Critical Infrastructure
US and several allied nations have issued a warning regarding Russian state-backed attempts to exploit poorly secured routers to breach critical infrastructure. The FSB's hacking groups target sectors including energy, healthcare, and communications by using known vulnerabilities and SNMP exploits. The warning underscores the need for immediate security enhancements in affected sectors.
U.S. Sanctions VPN and Malware Providers for Ransomware Support
The U.S. Treasury sanctioned First VPN Service and its administrator for aiding ransomware activities against American infrastructure. Ukrainian Dmytro Rashevskyi, associated with the VPN, and Belarusian Yegeniy Silayev, a cryptor seller, were named in the sanctions. The sanctions prevent U.S. entities from transacting with them, underscoring a broader crackdown on cybercriminal support networks.
UK and EU Sanction Russia's FSB and GRU for Cyberattacks Involving Critical Infrastructure
The UK and EU have imposed joint cyber sanctions targeting Russia's FSB and GRU following a cyberattack on Poland's energy grid that nearly caused a major blackout last winter. The coordinated sanctions, the first of their kind, address ongoing Russian-led cyber espionage campaigns against EU member states. These actions reflect growing international concerns regarding Russia's capacity to destabilize Europe’s critical infrastructure.
China and India-Linked Hackers Infiltrate Balochistan Police Networks
Chinese and Indian cyberespionage groups targeted the Balochistan Police from February 2024 to April 2026. The attackers accessed sensitive systems, including biometric data and criminal records. This exposes significant regional security vulnerabilities tied to geopolitical tensions.
Symlink Vulnerability in AI Coding Assistants Poses Security Threat
Researchers discovered that a vulnerability in six AI coding assistants allows malicious repositories to execute code on developers' machines. By exploiting symbolic link (symlink) flaws, attackers could bypass user consent and access sensitive files, raising significant security concerns.
Critical Linux Kernel Vulnerabilities: DirtyClone, Bad Epoll, and GhostLock
Three critical Linux kernel vulnerabilities, DirtyClone (CVE-2026-43503), Bad Epoll (CVE-2026-46242), and GhostLock (CVE-2026-43499), have been disclosed, each allowing privilege escalation. DirtyClone targets cloned network packets, Bad Epoll exploits a race condition, while GhostLock leverages a 15-year-old use-after-free flaw. Each vulnerability has a patch available, emphasizing the need for prompt system updates to mitigate exploitation risks.
EU Parliament Revives Chat Control 1.0 Allowing CSAM Scans Until 2028
The European Parliament has approved a procedure to revive the expired 'Chat Control 1.0' regulation, permitting tech companies to scan digital communications for child sexual abuse material (CSAM) until 2028. Despite previous rejections, the law was reinstated through a legal maneuver requiring an absolute majority to block it. The regulation raises significant privacy concerns, but excludes encrypted messaging services.
Critical Gitea Docker Vulnerability CVE-2026-20896 Faces Active Exploitation
Gitea Docker images are subject to a critical authentication bypass vulnerability (CVE-2026-20896) now under active exploitation. The flaw allows attackers to impersonate any user, including administrators, via reverse proxy authentication with default configurations. It affects versions before 1.26.3 and about 6,200 instances globally.
Microsoft Utilizes AI to Enhance Windows Security Updates Frequency and Efficiency
Microsoft announced the integration of AI to improve the frequency and effectiveness of Windows security updates. Using advanced AI models, Microsoft seeks to accelerate the detection of vulnerabilities in its codebase. This change aims to improve protections against increasingly AI-driven cyber threats.
12 Million Affected in KDDI Data Breach, Exploiting Zero-Day Vulnerability
KDDI, a major Japanese telecom provider, confirmed a breach affecting 12.2 million email addresses and 7.6 million passwords via a compromised email system used by five ISPs. The breach exploited a zero-day vulnerability in third-party software. KDDI has implemented security measures and coordinated password resets to prevent future incidents.
DuckDuckGo Browser Now Blocks YouTube Video Ads Using Community Filters
DuckDuckGo has released a feature that blocks video ads, including those on YouTube, on its browser. This feature, based on community-maintained filter lists and additional rules for compatibility, is enabled by default on iOS, Windows, and Mac, with Android support to follow. Users can enjoy ad-free video playback while maintaining privacy, but may experience longer buffering times.
Chinese APT UAT-7810 Develops New Malware to Expand ORB Network
Chinese APT group UAT-7810 has advanced its Operational Relay Box (ORB) network with new malware, including LONGLEASH, DOGLEASH, and JARLEASH. These tools exploit known router vulnerabilities to enhance the group's cyber espionage capabilities, posing potential risks to critical infrastructure.
GitHub Agentic Workflows Vulnerable to Prompt Injection, Exposing Private Repos
Noma Labs identified a prompt injection vulnerability, named GitLost, in GitHub's Agentic Workflows, enabling data leaks from private repositories. Attackers can manipulate AI agents to disclose private content through crafted public issues. This highlights security concerns in using AI-driven workflows in GitHub's system.
Discord Bug Mistakenly Bans Over 8,000 Accounts for Harmless Images
Discord experienced a glitch in its AI moderation system that mistakenly banned over 8,000 users for posting harmless images since May 2026. The system inaccurately flagged grid-like images as harmful content, impacting accounts posting items like spreadsheets and game textures. Discord has resolved the issue and unbanned affected users.
Medtronic Hack Exposes Data of Nearly 4 Million People in ShinyHunters Breach
Medtronic suffered a data breach in April 2026, compromising the personal and medical information of over 3.8 million individuals, with some sources claiming 9 million records affected. The ShinyHunters group accessed Medtronic's corporate IT systems, despite the company's reassurance about device safety. Medtronic is offering credit monitoring and support services to those impacted, highlighting security vulnerabilities in healthcare technology.
FortiBleed Campaign Compromises Fortinet Devices, Linked to Ransomware Groups
The FortiBleed campaign has been connected to the INC and Lynx ransomware groups, compromising credentials from Fortinet devices. Researchers found the operation entailed scanning 11,250 FortiGate portals and compromised 354 targets, leading to 12 ransomware deployments. The breach highlights significant cybersecurity risks, affecting organizations globally.
7-Zip Version 26.02 Fixes High-Severity RCE Flaw in XZ Archive Processing
7-Zip released version 26.02 to address a remote code execution (RCE) vulnerability linked to XZ-compressed data. Discovered by Lunbun researcher Landon Peng, the flaw could be exploited if a user opened a specially crafted archive. This highlights the need for manual updates due to 7-Zip's lack of an automatic update feature, emphasizing user awareness and action.
TP-Link Kasa cameras leaked GPS for six years; vulnerabilities now patched
TP-Link's Kasa Spot EC71 cameras exposed home GPS data via unauthenticated UDP for six years. A patch in firmware version 2.4.1 remedied significant security vulnerabilities that compromised user data.
Seven Malicious Vite npm Packages Employ Blockchain C2 for RAT Delivery
Seven malicious npm packages targeting the Vite ecosystem have been uncovered, linked to a software supply chain attack dubbed ViteVenom. The packages employ a complex blockchain-based command-and-control system, enhancing their stealth and effectiveness in delivering a remote access trojan.
NadMesh Botnet Targets Exposed AI Services for Cloud Credentials
NadMesh, a Go botnet, was discovered targeting exposed AI services in cloud environments, claiming over 3,800 AWS keys. The botnet systematically scans platforms like ComfyUI and n8n to extract cloud credentials and Kubernetes tokens, posing significant security risks to cloud deployments and AI tools.
DigiCert Breach Attributed to GoldenEyeDog Subgroup and Code-Signing Theft
The April 2026 security incident at DigiCert has been linked to the GoldenEyeDog subgroup, CylindricalCanine, which stole code-signing certificates. This breach highlights vulnerabilities in digital certificate management and raises concerns about the integrity of software distribution.
Chrome 150 Update Addresses 27 Vulnerabilities, Enhances Security
Google released Chrome 150, patching 27 security vulnerabilities, including two critical use-after-free flaws in Ozone and Views. This update is part of a broader effort to improve browser security, with most flaws discovered internally by Google. Regular updates are essential due to frequent exploitation of memory safety vulnerabilities in browsers like Chrome.
GoSerpent Malware Targets Southeast Asian Governments for Espionage
A new malware, GoSerpent, has been identified targeting Southeast Asian governments and diplomats since late 2025 for espionage. Discovered by Kaspersky, it aims to gather intelligence through tools for credential dumping and data exfiltration, posing a significant threat to sensitive government operations.