Cybersecurity 101
What Is a Vulnerability in Cybersecurity?
A clear guide to security vulnerabilities — what they are, the common types, how they are discovered and tracked with CVE and CVSS, and how they are managed.
Vulnerabilities
Arctic Wolf says threat actors are exploiting the patched FortiClient EMS flaw CVE-2026-35616 to deploy EKZ, a previously unreported credential stealer disguised as a Fortinet endpoint update and pushed across managed endpoints through the EMS management pathway itself.
Nation-State Cyber Threats
ENKI says Kimsuky ran a March-April 2026 wave against South Korean military and corporate targets, delivering an HTTPSpy variant through a fake Webex meeting page wired to a real scheduled event and a new infection-verification technique it calls JSONPing.
Vulnerabilities
The researcher behind a six-week run of uncoordinated Microsoft zero-day disclosures pledged a July 14, 2026 'bone-shattering' Windows exploit drop. Microsoft signaled law-enforcement action and pulled the researcher's GitHub account. Both sides have hardened.
Ransomware
Microsoft Threat Intelligence has named the operators of The Gentlemen ransomware Storm-2697, and its new deep technical analysis dissects a Go encryptor that uses per-file ephemeral keys and an aggressive self-propagation module.
Social Engineering
A phishing wave is impersonating Signal Support to ask users for their secret recovery key — the key that decrypts online backups containing past messages. The defender utility is simple: Signal will never ask for it, ever.
Policy & Government
US Central Command confirmed foreign adversaries are using commercial location data to track and surveil US troops in theater. Sen. Ron Wyden said it is time to treat the adtech industry as a national security threat. Adversaries were not named.
Data Breaches
Pay Tel, a US prison calling vendor, left a Microsoft Azure storage server holding 300,000-plus driver's license scans and inmate communications open to the web without a password, UpGuard told TechCrunch on May 28. It is Pay Tel's second known security failure in a year.
Nation-State Cyber Threats
WithSecure has tied a likely-Russian threat cluster named GreyVibe to a Ukraine-focused campaign that uses ChatGPT, Gemini and Ideogram AI as productivity tooling across lures, malware and post-compromise operations.
Cybersecurity 101
A clear guide to how attackers use artificial intelligence — for phishing, malware, deepfakes, and attacks on AI systems — and how organizations can defend.
A threat actor advertised a 340 million-record OnlyFans dataset for 0.313 BTC on May 25, then privately admitted they did not breach the platform. The compilation stitches old breach data to public profiles, and the framing failure is itself the editorial story.
Carnival Corporation began notifying 5,995,277 people on May 27, 2026 that their personal data was stolen in an April vishing breach — the corporate confirmation of an extortion claim ShinyHunters posted to its leak site 38 days earlier.
Wiz disclosed JINX-0164, a previously unreported actor running LinkedIn recruiter lures, custom macOS malware, and CI/CD hijacking against cryptocurrency developers. The playbook mirrors documented North Korean tradecraft, but Wiz preserves the attribution hedge.
Charter Communications, the parent of Spectrum, confirmed a cybersecurity incident on May 26-27, 2026 after ShinyHunters claimed 42 million customer records via the same vishing-to-Microsoft-Entra-to-Salesforce playbook documented across the 2026 cluster at ADT, Amtrak, Odido, and Vimeo.
Rapid7 Labs disclosed an unpatched CVSSv4 9.4 argument-injection (CWE-88) flaw in Gogs that lets any authenticated user achieve remote code execution by injecting --exec into git rebase via a malicious branch name. The second critical self-hosted-Git flaw in one week.
Microsoft's MSRC publicly condemned a six-flaw run of uncoordinated zero-day disclosures, saying the leaks put customers at 'unnecessary risk.' It's a position shift after six weeks of researcher disclosures that forced emergency response. The story is the tension itself.
ESET's October 2025 - March 2026 APT report names two findings defenders cannot ignore: a Polish energy company hit in December 2025 by a new wiper, DynoWiper, attributed to Sandworm with medium confidence, and the npm package axios compromised by attackers ESET ties to Lazarus.
A City Hall clerk in Alexandria, Tennessee caught a hacker using the town's Amazon account to order three cameras and an iPad. The detection was a person noticing — no security control fired. Thousands of US municipalities are in the same posture.
A complete guide to SQL injection — how SQLi attacks work, the main types, what attackers can do with them, and the proven ways to prevent them.
Apple published the post-quantum cryptography implementations in corecrypto — the library behind iOS, iPadOS, and macOS — alongside formal proofs and verification tools. It does not change today's encryption posture, but it lets outside experts audit the math that will protect tomorrow's.
Google Cloud launched AI Threat Defense on May 27, 2026 — an automated platform that pairs Gemini, the Wiz cloud-security stack, and the CodeMender AI code-fixing agent to find, prioritize, and patch software vulnerabilities at machine speed.
A site branded as 'UK Visa Portal' exposed at least 100,000 applicants' passport scans and selfies, TechCrunch reported May 26. The site is not affiliated with the UK government, and the operator sent attorneys rather than fix the leak.