Artificial Intelligence Microsoft, Palo Alto Networks Find Many Vulnerabilities by Using AI on Their Own Code Microsoft’s MDASH discovered 16 of the Patch Tuesday vulnerabilities, and Palo Alto used Mythos to find dozens of flaws. Eduard KovacsMay 13, 2026
Email Security Microsoft Patches Critical Zero-Click Outlook Vulnerability Threatening Enterprises CVE-2026-40361 is similar to a vulnerability found a decade ago, BadWinmail, which at the time was dubbed an “enterprise killer”. Eduard KovacsMay 13, 2026
Malware & Threats Hundreds of Malicious Packages Force RubyGems to Suspend Registrations More than 500 packages were pushed during the attack, but the target appears to have been RubyGems itself rather than users. Eduard KovacsMay 13, 2026
Vulnerabilities Microsoft Patches 137 Vulnerabilities Fresh security updates resolve critical flaws in Azure, Windows, Dynamics 365, and the SSO Plugin for Jira & Confluence. Ionut ArghireMay 12, 2026
Mobile & Wireless Apple Patches Dozens of Vulnerabilities in macOS, iOS The tech giant has also ported the patch for a recent deleted chats recovery issue to older versions of iOS. Eduard KovacsMay 12, 2026
Artificial Intelligence Claude Mythos Finds Only One Curl Vulnerability; Experts Divided on What It Really Means Curl’s lead developer says Mythos claims are marketing, but many in the industry believe the results stem from Curl’s robust security. Eduard KovacsMay 12, 2026
Malware & Threats TanStack, Mistral AI, UiPath Hit in Fresh Supply Chain Attack Over 400 malicious versions of 170 packages were published as part of the new Mini Shai-Hulud campaign. Ionut ArghireMay 12, 2026
Artificial Intelligence Google Detects First AI-Generated Zero-Day Exploit The zero-day was designed to bypass 2FA and it was developed by a prominent cybercrime group. Eduard KovacsMay 11, 2026
Artificial Intelligence Cloudflare Lays Off 1,100 Employees in AI-Driven Restructuring The company topped revenue and earnings forecasts for the first quarter of 2026, but its shares plunged more than 20%. Eduard KovacsMay 11, 2026
Data Breaches SailPoint Discloses GitHub Repository Hack The incident occurred on April 20 and did not affect customer data in the company’s production and staging environments. Ionut ArghireMay 11, 2026
Endpoint Security New ‘Dirty Frag’ Linux Vulnerability Possibly Exploited in Attacks Also called Copy Fail 2 and tracked as CVE-2026-43284 and CVE-2026-43500, the exploit was disclosed before a patch was released. Eduard KovacsMay 11, 2026
Artificial Intelligence Vulnerability in Claude Extension for Chrome Exposes AI Agent to Takeover Lax extension permissions and improper trust implementation allow attackers to inject prompts in the Claude Chrome extension. Ionut ArghireMay 8, 2026
Vulnerabilities Ivanti Patches EPMM Zero-Day Exploited in Targeted Attacks CVE-2026-6973 is a high-severity vulnerability that allows an attacker who has admin privileges to execute arbitrary code. Eduard KovacsMay 8, 2026
Nation-State Palo Alto Zero-Day Exploited in Campaign Bearing Hallmarks of Chinese State Hacking The cybersecurity firm has not explicitly accused China of being behind the attack, but the evidence suggests it was. Eduard KovacsMay 7, 2026
Artificial Intelligence AI Coding Agents Could Fuel Next Supply Chain Crisis “TrustFall” attack shows how AI coding agents can be manipulated into launching stealthy supply chain compromises. Kevin TownsendMay 7, 2026
Artificial Intelligence Claude AI Guided Hackers Toward OT Assets During Water Utility Intrusion Dragos has published a report describing how threat actors used Claude AI in an attack on a water and drainage utility in Mexico. Eduard KovacsMay 7, 2026
Government CISA Launches ‘CI Fortify’ to Prepare Critical Infrastructure for Geopolitical Cyber Conflict Agency issued guidance and calls on operators to build resilient OT environments capable of surviving extended isolation and cyber compromise. Eduard KovacsMay 6, 2026
Vulnerabilities Palo Alto Networks to Patch Zero-Day Exploited to Hack Firewalls CVE-2026-0300 affects the Captive Portal service of PAN-OS software on PA and VM series firewalls. Eduard KovacsMay 6, 2026
Artificial Intelligence Hacker Conversations: Joey Melo on Hacking AI AI red team specialist details his methods for manipulating AI guardrails through jailbreaking and data poisoning, helping developers harden machine learning models. Kevin TownsendMay 5, 2026
Artificial Intelligence Critical Bug Could Expose 300,000 Ollama Deployments to Information Theft Dubbed Bleeding Llama, the heap out-of-bounds read issue can be exploited remotely, without authentication. Ionut ArghireMay 5, 2026