Ghostwriter, geofenced PDF phishing, and Cobalt Strike target Ukrainian government

A Belarusian threat group known as Ghostwriter is believed to be behind new attacks targeting government agencies in Ukraine. Ghostwriter has been active since at least 2016 and is said to be involved in both cyber espionage and influence operations targeting neighboring countries, particularly Ukraine. It has also been tracked under the names FrostyNeighbor, PUSHCHA, […]

PraisonAI CVE-2026-44338 Authentication bypass targeted within hours of release

Rabi LakshmananMay 14, 2026Vulnerabilities/API Security Threat actors have been observed attempting to exploit recently disclosed security vulnerabilities in PraisonAI, an open source multi-agent orchestration framework, within four hours of publication. The vulnerability in question is CVE-2026-44338 (CVSS score: 7.3), which exposes sensitive endpoints when authentication is missing, allowing an attacker to call protected functions of […]

How AI illusions are creating real security risks

AI illusions are abusing human trust through reliable but inaccurate outputs, posing serious security risks to critical infrastructure decision-making. If an AI model lacks certainty, there is no mechanism to recognize it. Instead, it generates the most likely response based on patterns in the training data, even if that response is inaccurate. These outputs can […]

Windows zero-day exposes BitLocker bypass and CTFMON privilege escalation

The anonymous cybersecurity researcher who disclosed three vulnerabilities in Microsoft Defender is back with two more zero-days involving BitLocker bypass and privilege escalation affecting Windows Collaborative Translation Framework (CTFMON). The security flaws have been codenamed YellowKey and GreenPlasma by researchers operating under the online aliases Chaotic Eclipse and Nightmare-Eclipse, respectively. The researcher described YellowKey as […]

New Fragnesia Linux kernel LPE allows root access due to page cache corruption

Ravi LakshmananMay 14, 2026Vulnerabilities / Linux Details have emerged about a new variant of the recent Dirty Frag Linux Local Privilege Escalation (LPE) vulnerability that allows local attackers to gain root access, making it the third such bug in the kernel within two weeks. The security vulnerability codenamed ‘Fragnesia’ is tracked as CVE-2026-46300 (CVSS score: […]

Who decides what AI communicates? Campbell Brown, former head of news at Meta, thinks:

Campbell Brown has spent his career pursuing accurate information, first as a renowned television journalist and then as Facebook’s first and only full-time news chief. Today, we see the threat of history repeating itself as we watch AI change the way people consume information. This time, she’s not waiting for someone else to fix it. […]

Flaw in 18-year-old NGINX rewrite module allows unauthenticated RCE

Rabi LakshmananMay 14, 2026Vulnerabilities / Web Server Cybersecurity researchers have uncovered multiple security vulnerabilities affecting NGINX Plus and NGINX Open, including a critical flaw that went undetected for 18 years. This vulnerability, discovered by DepthFirst, is a heap buffer overflow issue affecting ngx_http_rewrite_module (CVE-2026-42945, CVSS v4 score: 9.2) that could allow an attacker to execute […]

Anthropic raises funding while Clio hits $500 million milestone

AI is now being applied to everything from healthcare to customer support, but no use case is yet as popular or profitable as writing code. Jack Newton, co-founder and CEO of Clio, a Canadian law firm management software company, believes legal tech is poised to be the next big winner of the LLM era. It’s […]

YouTube Wants to Be a Home, Not a Launchpad

This story was originally published in On Background with Mark Stenberg, a free, weekly newsletter that explores the key themes shaping the media industry. You can sign up for it here. Late last year, Netflix signed a deal to bring more than a dozen popular podcasts to its platform on one condition: They had to stop […]

Notion turns your workspace into a hub for AI agents

Productivity software maker Notion is stepping into the agent era. In a livestreamed product announcement Wednesday, the company best known for its collaborative note-taking app expanded the capabilities of its custom AI agents, connected them with external agents, and introduced a new developer platform that lets teams build automated, multi-step workflows that can ingest data […]