Webinar: What are the riskiest SOC alerts that go unanswered?

hacker newsMay 12, 2026Threat detection/AI security Why are my highest-risk SOC alerts not being responded to? Security operations teams are overwhelmed with alerts. But the real issue isn’t necessarily the volume of alerts. That’s a blind spot. The most dangerous alerts are those that no one investigates. A recent report from The Hacker News investigated […]

Mini Shai-Hulud worm compromises packages including TanStack, Mistral AI, Guardrails AI

TeamPCP, the threat actor behind recent supply chain attacks, has been implicated in compromising npm and PyPI packages for TanStack, UiPath, Mistral AI, OpenSearch, and Guardrails AI as part of a new Mini Shai-Hulud campaign. The affected npm packages have been modified to include an obfuscated JavaScript file (‘router_init.js’) designed to profile the execution environment […]

Why Agentic AI is the next security blind spot

Agentic AI is already running in production environments in many organizations today. It performs tasks, consumes data, and takes actions, perhaps without any meaningful involvement from your security team. The industry debate has largely framed this as a policy issue: to allow, restrict, or monitor. But that framework misses the point. The more pressing question […]

Instructor enters ransom agreement with ShinyHunters to stop 3.65TB canvas leak

Ravi LakshmananMay 12, 2026Vulnerability/Network Security Canvas’ parent company, American education technology company Instructor, announced it had reached an “agreement” with a decentralized cybercrime extortion group after the group infiltrated its network and threatened to divulge information stolen from thousands of schools and universities. In an update shared on Monday, the Utah-based company said it had […]

OpenAI launches Daybreak, an AI-powered vulnerability detection and patch verification service

Ravi LakshmananMay 12, 2026Vulnerability/AI Security OpenAI has launched Daybreak, a new cybersecurity initiative that integrates frontier artificial intelligence (AI) modeling capabilities with Codex Security. This allows organizations to identify and patch vulnerabilities before attackers find a way to exploit the same issue. “Daybreak combines the intelligence of OpenAI models, the scalability of Codex as an […]

iOS 26.5 brings default end-to-end encrypted RCS messaging between iPhone and Android

Ravi LakshmananMay 12, 2026Encryption/Mobile Security Apple on Monday officially released iOS 26.5 in beta with support for end-to-end encryption (E2EE) for Rich Communications Services (RCS) as part of a “cross-industry effort” to replace traditional SMS with more secure alternatives. To that end, E2EE RCS Messaging is rolling out to iPhone users running iOS 26.5 on […]

Weeks after KICS supply chain attack, TeamPCP compromises Checkmarx Jenkins AST plugin

Ravi LakshmananMay 11, 2026Supply chain attack / DevSecOps Checkmarx has confirmed that a fixed version of the Jenkins AST plugin has been published on the Jenkins Marketplace. “If you are using the Checkmarx Jenkins AST plugin, you should ensure that you are using version 2.0.13-829.vc72453fa_1c16 published on or before December 17, 2025,” the cybersecurity firm […]

cPanel CVE-2026-41940 Active exploitation to deploy Filemanager backdoor

Ravi LakshmananMay 11, 2026Vulnerability/Ransomware A threat actor named Mr_Rot13 is believed to have exploited a recently revealed critical flaw in cPanel to deploy a backdoor codenamed Filemanager into compromised environments. This attack exploits vulnerability CVE-2026-41940, which affects cPanel and WebHost Manager (WHM), resulting in an authentication bypass that could allow a remote attacker to gain […]

Hackers use AI to develop first known zero-day 2FA bypass for large-scale exploitation

Google said on Monday that it had identified an unknown attacker using a zero-day exploit that was likely developed on an artificial intelligence (AI) system, marking the first time the technology has actually been used in a malicious context for vulnerability discovery and exploit generation. The activity is said to be the work of cybercriminal […]

Linux Rootkit, macOS Crypto Stealer, WebSocket Skimmers and More

Ravie LakshmananMay 11, 2026Cybersecurity / Hacking Rough Monday. Somebody poisoned a trusted download again, somebody else turned cloud servers into public housing, and a few crews are still getting into boxes with bugs that should’ve died years ago — the same old holes, same lazy access paths, same “how the hell is this still open” […]