(Adobe Stock) Critical bug in F5 NGINX actively exploitedSteve ZurierMay 18, 2026Experts raise concerns because NGINX runs in front of one-third of al website worldwide.
Windows 11 update KB5089549 causes installation errors due to low EFI partition spaceSC StaffMay 18, 2026
Interpol operation leads to 201 arrests in Middle East and North Africa cybercrime crackdownSC StaffMay 18, 2026
Handling shadow AI at the source: Why the browser is the new control layerPaul WagenseilApril 29, 2026
Trust or fail: AI unlocks the value of unstructured data but raises new challenges for AI successPaul WagenseilApril 28, 2026
Controlling AI at machine speed: Detecting risk, protecting systems, and reversing mistakesPaul WagenseilApril 24, 2026
Critical Infrastructure SecurityIBM executive floated for CISA director as concerns persist for agencySteve ZurierMay 18, 2026Cybersecurity leaders warn weakened CISA could hurt AI-era defense and threat response.
Critical Infrastructure SecurityTeamPCP releases ‘vibe coded’ Shai-Hulud source code, issues challengeLaura FrenchMay 15, 2026The variant was used in recent attacks against TanStack and others – but it’s not the original, researchers say.
Vulnerability Management10.0 Cisco Catalyst SD-WAN Controller bug added to CISA’s KEV listSteve ZurierMay 15, 2026Maximum-severity bug an authentication bypass flaw that’s considered the highest value target in an attacker’s playbook.
Vulnerability ManagementNew Linux privilege escalation flaw ‘Fragnesia’ disclosed; PoC availableLaura FrenchMay 15, 2026Fragnesia is at least the fourth privilege escalation flaw affecting Linux systems disclosed in the last three weeks.
AI/MLOpenAI Daybreak joins growing movement of AI-driven vulnerability discoveryLaura FrenchMay 14, 2026The program aims to leverage GPT models and Codex Security to improve software resilience.
IdentityHouse calls on Instructure to brief Congress on Canvas hackSteve ZurierMay 13, 2026ShinyHunters hit Canvas twice, exposing student data via XSS and identity compromise.
Vulnerability ManagementPatch Tuesday: No zero days among 137 Microsoft CVEs, 4 Word RCEsLaura FrenchMay 12, 2026The May 2026 Microsoft security update included no zero days for the first time since June 2024.
Identity‘Mini’ Shai-Hulud attack compromises hundreds of npm, PyPI packagesSteve ZurierMay 12, 2026Teams warn the latest Shai-Hulud wave weaponizes trusted OIDC tokens to bypass package integrity checks.