Kimwolf DDoS botnet operator arrested in Canada for DDoS-for-Hire attack

Rabi LakshmananMay 22, 2026Cybercrime/Law Enforcement The U.S. Department of Justice (DoJ) announced Thursday that it has arrested a Canadian man suspected of operating a distributed denial of service (DDoS) botnet known as Kimwolf. At the same time, Jacob Butler (also known as Dort), 23, of Ottawa, Canada, was also charged with crimes related to the […]
CISA adds exploited Langflow and Trend Micro Apex One vulnerabilities to KEV

Rabi LakshmananMay 22, 2026Vulnerability/Cyber attack The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added two security flaws affecting Langflow and Trend Micro Apex One to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerabilities in question are as follows. CVE-2025-34291 (CVSS Score: 9.4) – An origin validation error vulnerability […]
Cisco patches CVSS 10.0 secure workload REST API to enable data access flaw

Rabi LakshmananMay 22, 2026Vulnerability/Network Security Cisco has issued an update for a maximum severity security flaw impacting secure workloads that could allow an unauthenticated, remote attacker to access sensitive data. The vulnerability, tracked as CVE-2026-20223 (CVSS score: 10.0), is due to insufficient validation and authentication when accessing REST API endpoints. “An attacker could exploit this […]
Showboat Linux malware uses SOCKS5 proxy backdoor to attack telecom companies in the Middle East

Rabi LakshmananMay 21, 2026Cyber espionage/threat intelligence Cybersecurity researchers have revealed details of a new Linux malware called Showboat that has been used in campaigns targeting telecommunications providers in the Middle East since at least mid-2022. “Showboat is a modular post-exploitation framework designed for Linux systems that can spawn remote shells, transfer files, and act as […]
Linux Rootkits, Router 0-Day, AI Intrusions, Scam Kits and 25 New Stories

Ravie LakshmananMay 21, 2026Hacking News / Cybersecurity News This week starts small. A token leaks. A bad package slips in. A login trick works. An old tool shows up again. At first, it feels like the usual mess. Then you see the pattern: attackers are not always breaking in. They are using the parts we […]
Microsoft warns of two actively exploited Defender vulnerabilities

Rabi LakshmananMay 21, 2026Endpoint security/vulnerabilities Microsoft has revealed that a privilege escalation and denial of service flaw in Defender is being exploited in the wild. The former is tracked as CVE-2026-41091 and is rated 7.8 on the CVSS scoring system. Successful exploitation of this flaw could allow an attacker to gain SYSTEM privileges. “Microsoft Defender’s […]
When identity becomes an attack vector

Consider access keys cached on a single Windows machine. Like most cached credentials, the key itself is automatically saved when the user logs in. Standard AWS behavior. No one misconfigured or violated any policies. But that one key, easily accessible to a minor league attacker, could have paved the way to approximately 98% of the […]
Nine-year-old Linux kernel flaw allows major distributions to run root commands

Rabi LakshmananMay 21, 2026Linux / Vulnerabilities Cybersecurity researchers have revealed details of a vulnerability in the Linux kernel that went undetected for nine years. This vulnerability, tracked as CVE-2026-46333 (CVSS score: 5.5), is a case of improper privilege management that could allow unprivileged local users to disclose sensitive files or execute arbitrary commands as root […]
GitHub internal repository compromised via malicious Nx console VS Code extension

Rabi LakshmananMay 21, 2026Supply chain attacks/developer tools GitHub formally acknowledged on Wednesday that the compromise of its internal repositories was the result of a compromise of an employee’s device involving a poisoned version of the Microsoft Visual Studio Code (VS Code) extension for the Nx Console. This development comes after the Nx team revealed that […]
Highly critical Drupal core flaw exposes PostgreSQL sites to RCE attacks

Rabi LakshmananMay 21, 2026Web security/vulnerabilities Drupal has released a security update for a “very critical” security vulnerability in Drupal Core. This vulnerability could be exploited by an attacker to accomplish remote code execution, privilege escalation, or information disclosure. This vulnerability is currently tracked as CVE-2026-9082 and has a CVSS score of 6.5 out of 10.0, […]