Latest Cybersecurity News and Articles


Grafana GitHub Token Breach Led to Codebase Download and Extortion Attempt

17 May 2026
Grafana has disclosed that an "unauthorized party" obtained a token that granted them the ability to access the company's GitHub environment and download its codebase. "Our investigation has determined that no customer data or personal information was accessed during this incident, and we have found no evidence of impact to customer systems or operations," Grafana said in a series of

Canvas hack: is it ever a good idea to pay a ransom, and what happens to the data?

16 May 2026
Canvas hack: is it ever a good idea to pay a ransom, and what happens to the data? Businesses are advised against paying – but many are prepared to deal to protect users’ privacyAfter a week of outages, hundreds of millions of students’ data stolen, delayed assignment due dates and school login pages being defaced by hackers, the US tech firm Instructure – which operates the education platform Canvas, used by education providers worldwide – announced it had “reached an agreement with the unauthorised actor” behind the ransomware attack.Experts read the careful language as a sign that a ransom has been paid. The company has not confirmed this. Continue reading...

Funnel Builder Flaw Under Active Exploitation Enables WooCommerce Checkout Skimming

16 May 2026
A critical security vulnerability impacting the Funnel Builder plugin for WordPress has come under active exploitation in the wild to inject malicious JavaScript code into WooCommerce checkout pages with the goal of stealing payment data. Details of the activity were published by Sansec this week. The vulnerability currently does not have an official CVE identifier. It

PoC Code Published for Critical NGINX Vulnerability

16 May 2026
Introduced in 2008, the critical-severity security defect was patched this week in NGINX Plus and NGINX open source. The post PoC Code Published for Critical NGINX Vulnerability appeared first on SecurityWeek.

Turla Turns Kazuar Backdoor Into Modular P2P Botnet for Persistent Access

15 May 2026
The Russian state-sponsored hacking group known as Turla has transformed its custom backdoor Kazuar into a modular peer-to-peer (P2P) botnet that's engineered for stealth and persistent access to compromised hosts. Turla, per the U.S. Cybersecurity and Infrastructure Security Agency (CISA), is assessed to be affiliated with Center 16 of Russia's Federal Security Service (FSB)

In Other News: Big Tech vs Canada Encryption Bill, Cisco’s Free AI Security Spec, Audi App Flaws

15 May 2026
Other noteworthy stories that might have slipped under the radar: Nvidia cloud gaming data breach, Android 17 security upgrades, FBI warning after ShinyHunters hacks Canvas. The post In Other News: Big Tech vs Canada Encryption Bill, Cisco’s Free AI Security Spec, Audi App Flaws appeared first on SecurityWeek.

Four OpenClaw Flaws Enable Data Theft, Privilege Escalation, and Persistence

15 May 2026
Cybersecurity researchers have disclosed a set of four security flaws in OpenClaw that could be chained to achieve data theft, privilege escalation, and persistence. The vulnerabilities, collectively dubbed Claw Chain by Cyera, can permit an attacker to establish a foothold, expose sensitive data, and plant backdoors. A brief description of the flaws is below -

AI-Assisted Cybersecurity Leadership Services For Small And Mid-Sized Businesses (SMBs)

15 May 2026
This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – May. 15, 2026 –Read the full story in SC Media According to the 2026 CISO Report from Cybersecurity Ventures, sponsored by Sophos, there are now about 35,000 full-time CISOs worldwide. Most of them are The post AI-Assisted Cybersecurity Leadership Services For Small And Mid-Sized Businesses (SMBs) appeared first on Cybercrime Magazine.

Microsoft Warns of Exchange Server Zero-Day Exploited in the Wild

15 May 2026
Microsoft has shared mitigations for CVE-2026-42897 until a permanent patch can be released for affected Exchange Server versions. The post Microsoft Warns of Exchange Server Zero-Day Exploited in the Wild appeared first on SecurityWeek.

American Lending Center Data Breach Affects 123,000 Individuals

15 May 2026
The non-bank lender discovered a ransomware attack nearly one year ago, but only recently completed its investigation. The post American Lending Center Data Breach Affects 123,000 Individuals appeared first on SecurityWeek.

What 45 Days of Watching Your Own Tools Will Tell You About Your Real Attack Surface

15 May 2026
In Your Biggest Security Risk Isn't Malware — It's What You Already Trust, we made a simple argument: the most dangerous activity inside most organizations no longer looks like an attack. It looks like administration. PowerShell, WMIC, netsh, Certutil, MSBuild — the same trusted utilities your IT team uses every day are also the preferred toolkit of modern threat actors. Bitdefender's analysis

TanStack Supply Chain Attack Hits Two OpenAI Employee Devices, Forces macOS Updates

15 May 2026
OpenAI has disclosed that two of its employee devices in its corporate environment were impacted via the Mini Shai-Hulud supply chain attack on TanStack, but noted that no user data, production systems, or intellectual property were compromised or modified in an unauthorized manner. "Upon identification of the malicious activity, we worked quickly to investigate, contain, and take steps to

OpenAI Hit by TanStack Supply Chain Attack

15 May 2026
Two employee devices were compromised in the attack, and credential material was stolen from OpenAI code repositories. The post OpenAI Hit by TanStack Supply Chain Attack appeared first on SecurityWeek.

TeamPCP Ups the Game, Releases Shai-Hulud Worm’s Source Code

15 May 2026
The hacking group is encouraging miscreants to use the code in supply chain attacks, promising monetary rewards. The post TeamPCP Ups the Game, Releases Shai-Hulud Worm’s Source Code appeared first on SecurityWeek.

Developer withdraws plans for Perth datacentre after fierce community opposition

15 May 2026
Developer withdraws plans for Perth datacentre after fierce community opposition Three-storey GreenSquare datacentre in Hazelmere was to power cloud computing and the acceleration of AIGet our breaking news email, free app or daily news podcastA 15,000 sq metre datacentre near Perth will no longer go ahead after the developer withdrew plans amid community opposition over its impact on culturally significant sites.The three-storey, 120-megawatt GreenSquare datacentre in the town of Hazelmere had been intended to power cloud computing and the acceleration of artificial intelligence, but faced fierce community backlash. Continue reading...

Chrome 148 Update Patches Critical Vulnerabilities

15 May 2026
The refresh resolves critical-severity use-after-free and other types of bugs in various browser components. The post Chrome 148 Update Patches Critical Vulnerabilities appeared first on SecurityWeek.

Cisco Patches Another SD-WAN Zero-Day, the Sixth Exploited in 2026

15 May 2026
The zero-day, tracked as CVE-2026-20182, has been exploited in targeted attacks by a sophisticated threat actor identified as UAT-8616. The post Cisco Patches Another SD-WAN Zero-Day, the Sixth Exploited in 2026 appeared first on SecurityWeek.

On-Prem Microsoft Exchange Server CVE-2026-42897 Exploited via Crafted Email

15 May 2026
Microsoft has disclosed a new security vulnerability impacting on-premise versions of Exchange Server that it said has come under active exploitation in the wild. The vulnerability, tracked as CVE-2026-42897 (CVSS score: 8.1), has been described as a spoofing bug stemming from a cross-site scripting flaw. An anonymous researcher has been credited with discovering and reporting the issue. "

CISA Adds Cisco SD-WAN CVE-2026-20182 to KEV After Admin Access Exploits

15 May 2026
The U.S.Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a newly disclosed vulnerability impacting Cisco Catalyst SD-WAN Controller to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to remediate the issue by May 17, 2026. The vulnerability is a critical authentication bypass tracked as CVE-2026-20182. It's

Cisco Catalyst SD-WAN Controller Auth Bypass Actively Exploited to Gain Admin Access

14 May 2026
Cisco has released updates to address a maximum-severity authentication bypass flaw in Catalyst SD-WAN Controller that it said has been exploited in limited attacks. The vulnerability, tracked as CVE-2026-20182, carries a CVSS score of 10.0. "A vulnerability in the peering authentication in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, and Cisco Catalyst SD-WAN Manager, formerly