Cybersecurity 101
What Is SQL Injection (SQLi)?
A complete guide to SQL injection — how SQLi attacks work, the main types, what attackers can do with them, and the proven ways to prevent them.
Security Research
Apple published the post-quantum cryptography implementations in corecrypto — the library behind iOS, iPadOS, and macOS — alongside formal proofs and verification tools. It does not change today's encryption posture, but it lets outside experts audit the math that will protect tomorrow's.
Artificial Intelligence (AI)
Google Cloud launched AI Threat Defense on May 27, 2026 — an automated platform that pairs Gemini, the Wiz cloud-security stack, and the CodeMender AI code-fixing agent to find, prioritize, and patch software vulnerabilities at machine speed.
Data Breaches
A site branded as 'UK Visa Portal' exposed at least 100,000 applicants' passport scans and selfies, TechCrunch reported May 26. The site is not affiliated with the UK government, and the operator sent attorneys rather than fix the leak.
Supply Chain Attack
CrowdStrike's Counter Adversary Operations team, with Google and the Shadowserver Foundation, executed a simultaneous takedown of all four GlassWorm command-and-control channels — Solana, BitTorrent DHT, Google Calendar, and direct servers — on May 26-27, 2026.
Supply Chain Attack
Three independently disclosed campaigns in the May 26-27 cycle treat AI tools as a single trust surface — SymJack at the agent layer, fake installers impersonating Claude and ChatGPT at the brand layer, and AI chatbot recommendations at the discovery layer.
Vulnerabilities
Gitea disclosed CVE-2026-27771, a registry authorization flaw that lets unauthenticated attackers pull private container images from any self-hosted Gitea below 1.26.2. It collapses the security premise of self-hosting: keeping images off public registries.
Threat Actors
The FBI's May 26 FLASH alert warns that Silent Ransom Group — also tracked as Luna Moth, Chatty Spider, and UNC3753 — is now sending operatives in person to US law firms, posing as IT support and inserting USB drives to steal client data for extortion.
Nation-State Cyber Threats
Israeli firm Gambit Security says the 'Ababil of Minab' hacktivist persona that claimed the March 2026 LA Metro breach is, on its forensic evidence, a front for Iran's Ministry of Intelligence and Security. At least 700 GB was stolen, and attackers reached a rail-yard control display.
Cybersecurity 101
A complete guide to the Cyber Kill Chain — the seven stages of a cyberattack, how defenders use the model to break an attack, and how it compares to MITRE ATT&CK.
India's CERT-In issued guidelines on May 26, 2026 requiring organizations to patch critical internet-exposed vulnerabilities within 12 hours, "where feasible." The cited reason is explicit: AI-driven exploitation has compressed the patch window past what conventional SLAs can survive.
Google's Threat Intelligence Group caught attackers exploiting CVE-2026-5426, a hardcoded ASP.NET machineKey in Digital Knowledge's KnowledgeDeliver LMS, to forge ViewState payloads, drop the Godzilla web shell, and stage Cobalt Strike Beacon. The patch alone is not enough.
Nimbus Manticore — the Iran-nexus APT The CyberSignal covered as Screening Serpens — has returned with a new backdoor codenamed MiniFast that Check Point Research assesses was developed with AI assistance, and a target set that now spans aviation, aerospace, defense, software, and telecom.
Microsoft patched CVE-2026-45659, a CVSS 8.8 deserialization RCE in SharePoint Server. The 'authenticated' precondition is barely a precondition — any account with Site Member, the lowest SharePoint role, can trigger it. Patch this week.
Lithuania's Prosecutor General's Office says more than 600,000 records were pulled from the Centre of Registers using valid Migration Department login credentials issued queries from abroad. The registry itself was not breached — an authorized third party's login was.
A complete guide to DDoS attacks — how distributed denial-of-service attacks work, the main types, why attackers launch them, and how to defend against them.
Three breach disclosures landed in one cycle — Radiology Associates of Richmond (266,183 people), DocketWise (143,480), and a vendor breach at the Oncology Institute. None is a novel attack. Together they map 2026's two structural failures: repeat victimization and third-party risk.
Fox-IT disclosed RemotePE, a RAT the North Korea-linked Lazarus Group runs entirely in memory and never writes to disk. It is the final stage of a multi-stage chain, deployed only after the noisier RATs are deliberately cleaned up.
Socket disclosed TrapDoor, a coordinated attack that planted more than 34 malicious packages across npm, PyPI, and Crates.io at once. Its novel move: poisoned .cursorrules and CLAUDE.md files designed to trick a developer's AI coding assistant.
Attackers are exploiting CVE-2026-26980, a CVSS 9.4 SQL-injection flaw in Ghost CMS, to hijack more than 700 websites — Harvard, Oxford, and DuckDuckGo among them — and serve visitors a fake-CAPTCHA ClickFix lure. The flaw was patched three months ago.
A complete guide to malware — the major types, how it spreads and infects devices, the warning signs of an infection, and how to remove and prevent it.
Anthropic says Project Glasswing's Claude Mythos Preview has surfaced more than 10,000 high- or critical-severity vulnerabilities in roughly a month. The numbers move the defender bottleneck: finding flaws is no longer the hard part — verifying, disclosing, and patching them is.