Microsoft open sources RAMPART and Clarity to protect AI agents during development

Rabi LakshmananMay 20, 2026Artificial intelligence/security testing Microsoft announced two new open source tools, RAMPART and Clarity, to help developers better test the security of their artificial intelligence (AI) agents. RAMPART, which stands for Risk Assessment and Measurement Platform for Agentic Red Teaming, serves as a Pytest-native safety and security testing framework for creating and running […]
Microsoft suspends malware signing service behind ransomware attack

Microsoft announced on Tuesday that it had disrupted a Malware Signing-as-a-Service (MSaaS) operation that used its Artifact Signing system as a weapon to distribute malicious code, carry out ransomware and other attacks, and compromise thousands of machines and networks around the world. The tech giant attributed the activity to a threat actor called Fox Tempest, […]
Webworm uses Discord and MS Graph API to deploy EchoCreep and GraphWorm backdoors

Cybersecurity researchers have alerted to new activity by a Chinese-aligned threat actor known as the Webworm in 2025, deploying a custom backdoor that uses Discord and Microsoft Graph API for command and control (C2 or C&C) communications. The webworm was first publicly documented by Broadcom-owned Symantec in September 2022 and is assessed to have been […]
Agent AI is here. are you ready?

hacker newsMay 20, 2026Identity Security/Enterprise Security New industry data just released suggests otherwise. On May 19, 2026, Orchid Security announced the results of the Identity Gap: Snapshot 2026. Among the findings, “identity dark matter” (invisible and unmanaged elements of identity) overshadows visible elements by 57% vs. 43%. And it couldn’t have come at a worse […]
Typosquatting is no longer a user problem. it’s a supply chain issue

AI-generated lookalike domains are now embedded within third-party scripts that run on your web properties. Here’s why the current stack can’t recognize them, and what detection actually requires: Download the CISO expert guide to typosquatting in the age of AI → TL;DR Typosquatting is no longer a user problem. Attackers are currently embedding lookalike domains […]
Microsoft releases mitigation for YellowKey BitLocker bypass CVE-2026-45585 exploit

Rabi LakshmananMay 20, 2026Vulnerabilities/Encryption Microsoft on Tuesday released a mitigation for a BitLocker bypass vulnerability called YellowKey, following a public release last week. This zero-day flaw is currently tracked as CVE-2026-45585 and has a CVSS score of 6.8. This is described as bypassing the BitLocker security feature. “Microsoft is publicly aware of a Windows security […]
Grafana GitHub breach exposes source code via TanStack npm attack

Rabi LakshmananMay 20, 2026Supply chain attack/cloud security Grafana Labs announced on May 19, 2026 that an investigation into a recent breach found no evidence that any of its customers’ production systems or operations were compromised. The scope of the incident is limited to Grafana Labs’ GitHub environment, which includes public and private source code and […]
TeamPCP claims nearly 4,000 internal repositories have been compromised, GitHub is investigating

Ravi LakshmananMay 20, 2026Malware/Cloud Security GitHub announced Tuesday that it is investigating unauthorized access to its internal repositories after a notorious threat actor known as TeamPCP listed the platform’s source code and internal organization for sale on a cybercrime forum. “At this time, there is no evidence of any impact to customer information stored outside […]
Trapdoor Android ad fraud scheme reaches 659 million bid requests per day using 455 apps

Ravi LakshmananMay 19, 2026Malvertising/Mobile Security Cybersecurity researchers have revealed details of a new ad fraud and malvertising operation called “Trapdoor” targeting Android device users. According to HUMAN’s Satori Threat Intelligence and Research Team, this activity involved 455 malicious Android apps and 183 threat actor-owned command and control (C2) domains, turning the infrastructure into a multi-stage […]
DirtyDecrypt PoC released for Linux kernel CVE-2026-31635 LPE vulnerability

Proof-of-concept (PoC) exploit code has been published that could allow local privilege escalation (LPE) for a security flaw in the recently patched Linux kernel. The vulnerability, known as DirtyDecrypt (also known as DirtyCBC), was discovered and reported by Zellic and the V12 security team on May 9, 2026, but was informed by the maintainer that […]