Aggregator
Official CheckMarx Jenkins package compromised with infostealer
New GhostLock tool abuses Windows API to block file access
Qilin
You must login to view this content
Google Says Hackers Used AI to Develop a Zero-Day Exploit
VMware at Pwn2Own Berlin 2026
Update, May 16, 2026 Pwn2Own 2026 has finished and we have witnessed one successful attempt on our products. On May 16, 2026, Nguyen Hoang Thach of STARLabs SG successfully demonstrated an exploit targeting VMware ESX. We are actively working on the remediation and we plan to publish a VMware Security Advisory to provide information on … Continued
The post VMware at Pwn2Own Berlin 2026 appeared first on VMware Security Blog.
KAMS PARIS Allegedly Breached Exposing 187,927 Customer Records From the French Niche Perfumery
FCC Softens Ban on Foreign-Made Routers
The Threat Window Is Shrinking. The Response Gap Isn't
AI is shrinking the window between vulnerability disclosure and active exploitation from weeks to hours. But remediation workflows haven't kept pace. Security teams need real-time intelligence, unified IT and security operations, and automated remediation to close the gap before attackers do.
AI Researchers Target SIEM Migration Bottleneck
Researchers developed an AI framework that converts threat detection rules between major SIEM platforms including Splunk, Microsoft Sentinel and QRadar. The system uses LLMs and automated validation steps to preserve detection logic during migrations that often require months of manual work.
Cops Shutter Rebooted German Language Cybercrime Market
Spanish police have arrested a German national suspected of a string of cybercrime offenses, including remotely administering from the sunny island of Mallorca a relaunched version of "Crimenetwork," a German-language cybercrime market for stolen data, forged documents and drugs.
Tables Turned: Gentlemen Ransomware Group Suffers Data Leak
Ransomware group The Gentlemen, a relative newcomer to the cybercrime scene, suffered a leak of its internal communications, revealing previously non-public victims, a variety of tactics, techniques and tools, and a relentless focus on popping backup and storage infrastructure.
INC
You must login to view this content
Apple security advisory (AV26-446)
Qilin
You must login to view this content
Texas sues Netflix over alleged data practices that create ‘surveillance machinery’ without user consent
Tech Can't Stop These Threats — Your People Can
JetBrains security advisory (AV26-445)
CMD
You must login to view this content
iOS 26.5 is out, bringing encrypted RCS messaging to iPhone and Android users
Apple is bringing long-awaited end-to-end encryption to Rich Communication Services (RCS) messaging between iPhone and Android users in iOS 26.5. The feature is launching in beta for iPhone users running iOS 26.5 on supported carriers and Android users using the latest version of Google Messages. “When RCS messages are end-to-end encrypted, they can’t be read while they’re sent between devices,” Apple said. “Users will know that a conversation is end-to-end encrypted when they see a … More →
The post iOS 26.5 is out, bringing encrypted RCS messaging to iPhone and Android users appeared first on Help Net Security.