Backdoor attackers know, but most security teams haven’t shut them down yet

All the AI ​​tools, workflow automation, and productivity apps that employees have connected to Google and Microsoft this year have left something behind. It’s a persistent OAuth token with no expiration date, no automatic cleanup, and, in most organizations, no one to monitor it. Boundary controls don’t know about it. MFA doesn’t stop that. And […]

MetInfo CMS CVE-2026-29014 can be exploited for remote code execution attacks

Ravi LakshmananMay 5, 2026Vulnerability/Network Security Threat actors are actively exploiting a critical security flaw affecting the open-source content management system (CMS) known as MetInfo, according to new findings from VulnCheck. The vulnerability in question is CVE-2026-29014 (CVSS score: 9.8), which is a code injection flaw that could lead to arbitrary code execution. The NIST National […]

We scanned 1 million publicly available AI services. How Bad Is Security Really?

The software industry has made real strides in delivering products securely over the past few decades, but the breakneck pace of AI adoption is putting that progress at risk. The promise of AI as a power multiplier and the pressure to deliver more value, faster, are driving companies to rapidly migrate to self-hosted LLM infrastructure. […]

Celebrities and creators who are leading culture in new directions

Atsuko Okatsukacomedian Drop It Like It’s Hot: What started as a quirky comedian trying to make his grandmother laugh turned into Atsuko Okatsuka’s viral drop challenge. When the beat drops on Beyoncé’s “Partition,” participants who are just going about their daily routines suddenly feel depressed. Shortly thereafter, HBO came calling to air a stand-up special […]

Genre-defining artists and makers

Anna Fleischlproduction designer Bring receipts: During Lily Allen’s “West End Girl” tour, production designer Fleischl had the singer wrap up sheets with printed receipts for items her ex-husband had allegedly gifted to other women. It was one of the concert’s many powerful moments, and its lauded visual and production values ​​were shaped by Fleischl’s long […]

Media, TV and streaming innovators know how to win

Ali BrownPresident and Partner of Pretty BirdVentureland co-founder and president COMMERCIAL SUCCESS: From Super Bowl domination to Sundance buzz, production lead Ali Brown has racked up wins on every screen. In 2025 alone, her team created campaigns for Nike, Elf, Levi’s, Verizon, Netflix, and Mazda and earned four Super Bowl berths, three of which Brown […]

Social Natives With Bold Ideas

Charlotte Frank & Elizabeth SwartzACDs, nice&frank Welcome to New York: If you’ve been clocking the down home marketing around Nathan’s Famous, it’s the work of Charlotte Frank and Elizabeth Swartz. They penned the tagline “100% Beef. 100% New York,” and continue to make Nathan’s synonymous with the city. Most recently, they linked up with the […]

2026 Creative 100 games that will change culture

Now in its 12th year, ADWEEK’s Creative 100 recognizes the artists and agency talent whose original ideas, keen observations of the world, and hard work have created the most impactful work in advertising, marketing, entertainment, social media, filmmaking, and visual arts. Despite having more entertainment options than ever before, the 2026 winners made a breakthrough […]

ScarCruft hacks gaming platforms and deploys BirdCall malware on Android and Windows

Ravi LakshmananMay 5, 2026Cyber ​​espionage/surveillance A North Korean-aligned state-sponsored hacker group known as ScarCruft compromised video gaming platforms with supply chain espionage attacks and trojanized their components with a backdoor called BirdCallto, likely targeting ethnic Koreans living in China. While previous versions of the backdoor primarily targeted only Windows users, the supply chain attack is […]

Weaver E-cology RCE flaw CVE-2026-22679 can be actively exploited via the debug API

Ravi LakshmananMay 5, 2026Vulnerability/Network Security A critical security vulnerability in Weaver (Fanwei) E-cology, an enterprise office automation (OA) and collaboration platform, has been exploited in the wild. This vulnerability (CVE-2026-22679, CVSS score: 9.8) is related to an unauthenticated remote code execution case that affects Weaver E-cology 10.0 versions prior to 20260312. The issue exists in […]