CyberNews 2026-05-23

Cybersecurity Headlines — May 23, 2026 Cyberattacks in supply chains: A multi-case study — Plos.org Trend Micro warns of Apex One zero-day exploited in the wild — BleepingComputer EU makes little progress in talks with Anthropic on Mythos testing — Crypto Briefing Cycurion Acquires Secuvant, Supercharging AI-Driven Cybersecurity with Automated, Scalable Threat Defense – Perfectly Complements HavenX Platform — Financial Post Cycurion Acquires Secuvant, Supercharging AI-Driven Cybersecurity with Automated, Scalable Threat Defense – Perfectly Complements HavenX Platform — GlobeNewswire How fast can AI-written code be exploited? #tech — Alltoc.com Ubiquiti patches three max severity UniFi OS vulnerabilities — BleepingComputer TechD Cybersecurity Launches TECHD ONE: AI-Native Unified Cybersecurity Platform — BusinessLine Why account recovery is now the weakest link in security — TechRadar CISA’s new KEV nomination form opens reporting to vendors and researchers — Help Net Security From the Trenches As a cybersecurity practitioner, I’m always on the lookout for stories that highlight the latest threats and vulnerabilities. Two recent headlines caught my attention - Ubiquiti patches three max severity UniFi OS vulnerabilities (BleepingComputer) and CISA’s new KEV nomination form opens reporting to vendors and researchers (Help Net Security). ...

May 23, 2026 · 2 min · Jason, Cyber Professional

CyberNews 2026-05-22

Cybersecurity Headlines — May 22, 2026 Darktrace Named a Leader in the 2026 Gartner® Magic Quadrant™ for Network Detection and Response for Second Consecutive Year — GlobeNewswire Vectra AI Named a Leader in the 2026 Gartner® Magic Quadrant™ for Network Detection and Response — PRNewswire OpenSSF Notes Quarter of Growth with New Members, Added AI Security Resources, and Growing Community — PRNewswire Defending Critical Infrastructure: Why OT Security Demands a Threat-Informed Approach — Fortinet.com AI impact makes vulnerability exploitation top cause of data breaches – Verizon — TelecomTV GreenboneOS: Attackers are increasingly shifting from stolen credentials to exploited vulnerabilities — Greenbone.net APT and financial attacks on industrial organizations in Q1 2026 — Kaspersky.com Microsoft Warns of Two Actively Exploited Defender Vulnerabilities — Internet AI-driven cyber discovery signals a new era of systemic risk for banks — TechRadar Microsoft warns of new Defender zero-days exploited in attacks — BleepingComputer From the Trenches As a cybersecurity practitioner, I’m seeing a clear trend emerging in the latest threat landscape. On one hand, we’ve got vendors like Darktrace and Vectra AI being named leaders in the 2026 Gartner Magic Quadrant for Network Detection and Response. This is a significant recognition of their capabilities in detecting and responding to network-based threats. ...

May 22, 2026 · 2 min · Jason, Cyber Professional

ShinyHunters' Salesforce Campaign: Three Rounds, 1.5 Billion Records

ShinyHunters didn’t hack Salesforce. That distinction matters. Across three separate campaigns spanning mid-2025 through early 2026, the group — tracked by security researchers as UNC6040 and UNC6395 — systematically exploited how organizations configure, connect, and authenticate into Salesforce. The platform’s infrastructure was never the vulnerability. The integrations, the OAuth flows, and the guest user permissions were. ...

May 22, 2026 · 7 min · Logan

CyberNews 2026-05-21

Cybersecurity Headlines — May 21, 2026 Securing the gaming culture of cultures — Microsoft.com What’s keeping IT leaders up at night in the AI era? — TechRadar Anticipated executive order could give NSA a role in voluntary AI model testing — Nextgov Verizon DBIR: Vulnerability exploitation is the dominant initial access vector — Help Net Security Cyber resilience defines SME competitiveness — TechRadar ‘There is no universe in which Proton VPN compromises its no-logs policy’ — Proton joins the backlash against Canada’s surveillance bill — TechRadar Exclusive—Sen. Rick Scott & Rep. Andy Ogles: America’s Cybersecurity Cannot Be an Easy Target for Communist China — Breitbart News Misconfigured, Enrolled and Dormant: Anatomy of a P2Pinfect Kubernetes Compromise — Fortinet.com Implement agentic AI in cybersecurity with Tenable Hexa AI: Reduce cyber risk at machine speed — Tenable.com Fears of Unfettered Hacking Spurred by Anthropic’s Mythos AI Model Overstated — Insurance Journal From the Trenches As a cybersecurity practitioner, I’ve been keeping an eye on the latest developments in our field, and there are two stories that caught my attention today. ...

May 21, 2026 · 2 min · Jason, Cyber Professional

CyberNews 2026-05-20

Cybersecurity Headlines — May 20, 2026 Critical Microsoft Vulnerabilities Doubled: From Exposure to Escalation — BleepingComputer Purple Announces Urgent Cybersecurity Webinar: Why AI-Driven Attacks Make Traditional Staff Wi-Fi Indefensible — GlobeNewswire Zscaler Partners with Global System Integrators to Launch Project AI-Guardian to Help Accelerate Enterprise AI Adoption — GlobeNewswire Key findings from the Verizon DBIR 2026: Slower vulnerability remediation meets faster exploitation — Tenable.com Vulnerability Exploitation Top Breach Entry Point, 2026 Industry-Wide DBIR Finds — GlobeNewswire Hackers Actively Exploit ‘Nginx Rift’ Vulnerability Affecting NGINX, F5 Products — HackRead HDFC AMC notifies cybersecurity incident on IT infrastructure, says unlikely to affect business — MediaNama.com Cybersecurity jobs available right now: May 19, 2026 — Help Net Security South Korean Startup Captures Workers Movement To Train AI — Ponoko.com Mexican government breached by solo user with Claude, 150 GB exfiltrated — Konstantintkachuk.com From the Trenches As a cybersecurity practitioner, I’m seeing a disturbing trend emerging from recent vulnerability reports. The most notable is that critical Microsoft vulnerabilities have doubled in exposure to escalation, according to BleepingComputer. This means that attackers are not only exploiting existing vulnerabilities but also actively working to escalate their impact. It’s a stark reminder of the importance of patch management and the need for organizations to prioritize timely updates. ...

May 20, 2026 · 2 min · Jason, Cyber Professional

CyberNews 2026-05-19

Cybersecurity Headlines — May 19, 2026 Windows Netlogon RCE exploited, domain controllers at risk (CVE-2026-41089) — Help Net Security Taiwan and Poland on the Frontline of Hybrid Conflict — The Diplomat Synergy Quantum Launches SynQ MythGuard, an AI-Powered MythosBreaker Tool for Complete Discovery and Protection Against Mythos Attacks — BusinessLine WP Maps Pro plugin flaw to create admin accounts on WordPress sites saw 3,600 attempts in a single day — TechRadar Residual-guided hybrid framework for adversarially robust deep learning-based network intrusion detection — Plos.org ⚡ Weekly Recap: New Linux Flaw, PAN-OS Exploit, AI-Powered Attacks, OAuth Phishing and More — Internet The Green Grid’s Hidden Backdoor: Who Controls Europe’s Clean Energy? — Forbes AI agents help Cato slash ‘time-to-protect’ from new CVEs — ComputerWeekly.com Zero-Click pretalx XSS Flaw Lets Hackers Hijack Conference Organizer Accounts — HackRead Critical Windows Netlogon RCE flaw now exploited in attacks — BleepingComputer From the Trenches The past week has been a wild ride for cybersecurity practitioners like myself. I’ve seen two stories that really caught my attention and warrant immediate action from organizations across the board. ...

May 19, 2026 · 2 min · Jason, Cyber Professional

CyberNews 2026-05-18

Cybersecurity Headlines — May 18, 2026 Security Affairs newsletter Round 577 by Pierluigi Paganini – INTERNATIONAL EDITION — Securityaffairs.com U.S. CISA adds a flaw in Microsoft Exchange Server to its Known Exploited Vulnerabilities catalog — Securityaffairs.com Europe built sovereign clouds to escape US control. Then forgot about the processors — Theregister.com The Next Cybersecurity Challenge May Be Verifying AI Agents — HackRead AI gave North Korean hackers a $600 million month. DeFi is still working out how to respond. — The Next Web CVE-2026-42897: Microsoft confirms active exploitation of Exchange Server zero-day — Securityaffairs.com Was Your Data Exposed in the Massive New Cyberattack? — Geeky Gadgets TanStack Supply Chain Attack Hits Two OpenAI Employee Devices, Forces macOS Updates — Internet AI is having its “Ford T” moment as Zero Day assembly lines appear — TechRadar Microsoft warns of Exchange zero-day flaw exploited in attacks — BleepingComputer From the Trenches As I dive into today’s cybersecurity landscape, two stories stand out to me as particularly noteworthy. First, the U.S. CISA has added a flaw in Microsoft Exchange Server to its Known Exploited Vulnerabilities catalog, which is a stark reminder of the ongoing threat landscape. This zero-day vulnerability has already seen active exploitation, and it’s essential for organizations that use Microsoft Exchange Server to take immediate action and patch their systems. ...

May 18, 2026 · 2 min · Jason, Cyber Professional

CyberNews 2026-05-17

Cybersecurity Headlines — May 17, 2026 Europe built sovereign clouds to escape US control. Then forgot about the processors — Theregister.com The Next Cybersecurity Challenge May Be Verifying AI Agents — HackRead AI gave North Korean hackers a $600 million month. DeFi is still working out how to respond. — The Next Web CVE-2026-42897: Microsoft confirms active exploitation of Exchange Server zero-day — Securityaffairs.com Was Your Data Exposed in the Massive New Cyberattack? — Geeky Gadgets TanStack Supply Chain Attack Hits Two OpenAI Employee Devices, Forces macOS Updates — Internet AI is having its “Ford T” moment as Zero Day assembly lines appear — TechRadar Microsoft warns of Exchange zero-day flaw exploited in attacks — BleepingComputer Finding the blind spot: How Canonical hunts logic flaws with AI — Ubuntu.com 15 maja 2026 — Mrugalski.pl From the Trenches As a cybersecurity practitioner, I’m seeing two trends that are making me sit up and take notice. First, it’s the fact that Europe has built its own sovereign clouds to escape US control, only to forget about the processors behind them. This is a classic case of “out of sight, out of mind” when it comes to cybersecurity. Cloud providers need to ensure that their infrastructure is secure, not just the data stored on it. It’s a sobering reminder that security isn’t just about compliance, but also about the underlying technology. ...

May 17, 2026 · 2 min · Jason, Cyber Professional

CyberNews 2026-05-16

Cybersecurity Headlines — May 16, 2026 CVE-2026-42897: Microsoft confirms active exploitation of Exchange Server zero-day — Securityaffairs.com Was Your Data Exposed in the Massive New Cyberattack? — Geeky Gadgets TanStack Supply Chain Attack Hits Two OpenAI Employee Devices, Forces macOS Updates — Internet AI is having its “Ford T” moment as Zero Day assembly lines appear — TechRadar Microsoft warns of Exchange zero-day flaw exploited in attacks — BleepingComputer Finding the blind spot: How Canonical hunts logic flaws with AI — Ubuntu.com 15 maja 2026 — Mrugalski.pl CISA Adds Cisco SD-WAN CVE-2026-20182 to KEV After Admin Access Exploits — Internet Providence’s Ratliff Says Merging Cybersecurity and Emergency Management Builds Stronger Cyber Resiliency — Healthsystemcio.com Untrained AI agents are easy security targets — they don’t know bad people exist, says KnowBe4 CEO — SiliconANGLE News From the Trenches As a cybersecurity practitioner, I’m seeing two major red flags that require immediate attention from organizations across various industries. The first is the confirmed active exploitation of a zero-day flaw in Microsoft’s Exchange Server (CVE-2026-42897). This means attackers have already found and are exploiting a previously unknown vulnerability in the server software, making it a prime target for malware and lateral movement. ...

May 16, 2026 · 2 min · Jason, Cyber Professional

CyberNews 2026-05-15

Cybersecurity Headlines — May 15, 2026 Kazuar: Anatomy of a nation-state botnet — Microsoft.com Combating the new wave of AI crimes and threats — Techtarget.com Siemens Ruggedcom Rox — Cisa.gov Siemens Ruggedcom Rox — Cisa.gov Siemens Ruggedcom Rox — Cisa.gov How AI Hallucinations Are Creating Real Security Risks — Internet Microsoft unveils MDASH, its AI agent-driven security platform — and it’s already spotted a host of new Windows flaws — TechRadar Trend Micro Reports Earnings Results for Q1 2026 — PRNewswire ICO Publishes Five-Step Plan to Counter Emerging AI-Powered Attacks — Infosecurity Magazine Caveat Canvas: ShinyHunters Hacks the Education Sector — CounterPunch From the Trenches As a cybersecurity practitioner, I’m always on the lookout for threats that can compromise our systems and data. Two stories caught my attention recently - Kazuar: Anatomy of a nation-state botnet and Microsoft unveils MDASH, its AI agent-driven security platform. ...

May 15, 2026 · 2 min · Jason, Cyber Professional