Cybersecurity May 2026

Global headlines curated by our intelligent agents.

Latest News

Security Bite Q1 Review: May 2026
9 to 5 Mac
31 May 2026, 23:22
11

Security Bite Q1 Review: May 2026

9to5Mac Security Bite is exclusively brought to you by Mosyle, the only Apple Unified Platform. Making Apple devices work-ready and enterprise-safe...

Microsoft is threatening legal action for disclosing exploits
The Verge
30 May 2026, 15:19
8

Microsoft is threatening legal action for disclosing exploits

What qualifies as “responsible disclosure” though?

PAN-OS GlobalProtect Authentication Bypass (CVE-2026-0257) Under Active Exploitation
The Hacker News
30 May 2026, 06:41
5

PAN-OS GlobalProtect Authentication Bypass (CVE-2026-0257) Under Active Exploitation

CVE-2026-0257 is being actively exploited on PAN-OS devices since May 17, 2026, enabling unauthorized VPN access and network exposure.

ChatGPhish Vulnerability Turns ChatGPT Web Summaries Into a Phishing Surface
The Hacker News
29 May 2026, 18:07
6

ChatGPhish Vulnerability Turns ChatGPT Web Summaries Into a Phishing Surface

ChatGPhish exploits ChatGPT Markdown rendering to deliver phishing content from summarized web pages, increasing AI attack surfaces.

Attackers Use LLM Agent for Post-Exploitation After Marimo CVE-2026-39987 Exploit
The Hacker News
29 May 2026, 14:39
6

Attackers Use LLM Agent for Post-Exploitation After Marimo CVE-2026-39987 Exploit

LLM-driven attackers exploited CVE-2026-39987 on May 10, 2026, to steal credentials and exfiltrate a PostgreSQL database.

Malicious Sicoob NuGet Steals Banking Credentials as npm Packages Target Cloud Secrets
The Hacker News
29 May 2026, 09:11
5

Malicious Sicoob NuGet Steals Banking Credentials as npm Packages Target Cloud Secrets

Malicious Sicoob.Sdk stole PFX certificates and client IDs via NuGet downloads, enabling API impersonation and payment abuse risks.

California Attorney General sues 23andMe successor for 2023 data breach
BBC News Technology
28 May 2026, 18:28
6

California Attorney General sues 23andMe successor for 2023 data breach

Attorney General Rob Bonta alleges the company lied about the breach's severity.

Advertisement
Critical Gogs RCE Vulnerability Lets Any Authenticated User Execute Arbitrary Code
The Hacker News
28 May 2026, 17:24
6

Critical Gogs RCE Vulnerability Lets Any Authenticated User Execute Arbitrary Code

Gogs 9.4 CVSS flaw exploits git rebase injection on 1,141 exposed instances, enabling remote code execution.

Threat Actors Exploit Critical FortiClient EMS Flaw to Deploy Credential Stealer
The Hacker News
28 May 2026, 15:26
5

Threat Actors Exploit Critical FortiClient EMS Flaw to Deploy Credential Stealer

FortiClient EMS flaw CVE-2026-35616 enabled malware delivery via fake updates, risking credential theft across endpoints.

Microsoft Slams Public Zero-Day Disclosures Amid GitHub Researcher Account Removal
The Hacker News
28 May 2026, 13:53
5

Microsoft Slams Public Zero-Day Disclosures Amid GitHub Researcher Account Removal

Microsoft urged coordinated disclosure after three Windows zero-days were actively exploited, increasing customer security risks.

JINX-0164 Targets Cryptocurrency Firms with Fake Recruiter Lures and macOS Malware
The Hacker News
28 May 2026, 07:54
6

JINX-0164 Targets Cryptocurrency Firms with Fake Recruiter Lures and macOS Malware

JINX-0164 targeted cryptocurrency organizations using recruitment-themed social engineering and custom macOS malware to steal digital assets.

Grandoreiro Malware and BTMOB RAT Campaigns Target Windows and Android Users
The Hacker News
27 May 2026, 16:10
6

Grandoreiro Malware and BTMOB RAT Campaigns Target Windows and Android Users

Grandoreiro and BTMOB campaigns targeted Europe and Latin America in 2026, increasing banking malware risks.

Malicious npm Package Stole Files From Claude AI User Directory via GitHub
The Hacker News
27 May 2026, 15:44
4

Malicious npm Package Stole Files From Claude AI User Directory via GitHub

Malicious npm package downloaded 676 times stole Claude AI files via GitHub uploads, increasing AI-driven malware risks.

GlassWorm Malware Takedown Disrupts Developer Supply Chain Attack Infrastructure
The Hacker News
27 May 2026, 11:48
6

GlassWorm Malware Takedown Disrupts Developer Supply Chain Attack Infrastructure

GlassWorm poisoned 300 GitHub repositories since 2025, enabling supply chain attacks against developers and organizations.

Gitea Vulnerability Exposes Private Container Images without Authentication
The Hacker News
27 May 2026, 10:06
5

Gitea Vulnerability Exposes Private Container Images without Authentication

Gitea flaw CVE-2026-27771 exposed private container images across 30,000 deployments, risking unauthorized access worldwide.

AI Chatbot Recommendations Redirect Users to Cryptojacking Malware Sites
The Hacker News
27 May 2026, 07:45
5

AI Chatbot Recommendations Redirect Users to Cryptojacking Malware Sites

Microsoft uncovered 150+ AI-assisted cryptojacking domains using fake software downloads to deploy persistent malware.

Champion ethical hacker warns AI tools like Mythos could put her out of business
BBC News Technology
27 May 2026, 00:43
8

Champion ethical hacker warns AI tools like Mythos could put her out of business

Chompie, one of the world's tops ethical hackers, says AI like Claude Mythos will make it harder for people like her to compete.

Previous OS updates contained security patches which have now been detailed by Apple
Apple Insider
26 May 2026, 23:15
9

Previous OS updates contained security patches which have now been detailed by Apple

Apple's security releases page has been updated with additional information regarding the security issues resolved in iOS 18, iOS 26, and other OS versions.

Apple adds new CVE details to several macOS, iOS, iPadOS, visionOS, and watchOS updates
9 to 5 Mac
26 May 2026, 22:14
8

Apple adds new CVE details to several macOS, iOS, iPadOS, visionOS, and watchOS updates

Apple today updated the security content pages for several macOS, iOS, iPadOS, visionOS, and watchOS releases. Here are the details.

MuddyWater Uses DLL Side-Loading in Espionage Campaign Targeting 9 Countries
The Hacker News
26 May 2026, 15:48
5

MuddyWater Uses DLL Side-Loading in Espionage Campaign Targeting 9 Countries

MuddyWater targeted 9 organizations in 9 countries during Q1 2026, using DLL side-loading to steal data and evade detection.

New AI DDoS Attacks Are Smarter. Learn How to Fight Back in This Webinar
The Hacker News
26 May 2026, 11:58
6

New AI DDoS Attacks Are Smarter. Learn How to Fight Back in This Webinar

Learn how to fight back against AI-powered cyber attacks. Register for our free 45-minute live webinar and protect your business today.

Microsoft Patches SharePoint RCE Flaw CVE-2026-45659 Across Server Versions
The Hacker News
26 May 2026, 11:49
7

Microsoft Patches SharePoint RCE Flaw CVE-2026-45659 Across Server Versions

Microsoft released fixes for SharePoint remote code execution vulnerability CVE-2026-45659 with a CVSS score of 8.8.

CERT-In Mandates 12-Hour Patching for Internet-Facing Flaws Amid AI-Assisted Attacks
The Hacker News
26 May 2026, 09:13
5

CERT-In Mandates 12-Hour Patching for Internet-Facing Flaws Amid AI-Assisted Attacks

CERT-In ordered 12-hour patching for critical internet-facing flaws as AI-driven attacks accelerate cyber exploitation.

Iranian Hackers Deploy MiniFast and MiniJunk V2 via Phishing and SEO Poisoning
The Hacker News
26 May 2026, 07:13
8

Iranian Hackers Deploy MiniFast and MiniJunk V2 via Phishing and SEO Poisoning

Nimbus Manticore used AI-assisted MiniFast malware in 2026 campaigns, expanding espionage through SEO poisoning and phishing.