Cybersecurity 101
How AI Is Used in Cyberattacks
A clear guide to how attackers use artificial intelligence — for phishing, malware, deepfakes, and attacks on AI systems — and how organizations can defend.
Data Breaches
A threat actor advertised a 340 million-record OnlyFans dataset for 0.313 BTC on May 25, then privately admitted they did not breach the platform. The compilation stitches old breach data to public profiles, and the framing failure is itself the editorial story.
Data Breaches
Carnival Corporation began notifying 5,995,277 people on May 27, 2026 that their personal data was stolen in an April vishing breach — the corporate confirmation of an extortion claim ShinyHunters posted to its leak site 38 days earlier.
Threat Actors
Wiz disclosed JINX-0164, a previously unreported actor running LinkedIn recruiter lures, custom macOS malware, and CI/CD hijacking against cryptocurrency developers. The playbook mirrors documented North Korean tradecraft, but Wiz preserves the attribution hedge.
Data Breaches
Charter Communications, the parent of Spectrum, confirmed a cybersecurity incident on May 26-27, 2026 after ShinyHunters claimed 42 million customer records via the same vishing-to-Microsoft-Entra-to-Salesforce playbook documented across the 2026 cluster at ADT, Amtrak, Odido, and Vimeo.
Vulnerabilities
Rapid7 Labs disclosed an unpatched CVSSv4 9.4 argument-injection (CWE-88) flaw in Gogs that lets any authenticated user achieve remote code execution by injecting --exec into git rebase via a malicious branch name. The second critical self-hosted-Git flaw in one week.
Vulnerabilities
Microsoft's MSRC publicly condemned a six-flaw run of uncoordinated zero-day disclosures, saying the leaks put customers at 'unnecessary risk.' It's a position shift after six weeks of researcher disclosures that forced emergency response. The story is the tension itself.
Nation-State Cyber Threats
ESET's October 2025 - March 2026 APT report names two findings defenders cannot ignore: a Polish energy company hit in December 2025 by a new wiper, DynoWiper, attributed to Sandworm with medium confidence, and the npm package axios compromised by attackers ESET ties to Lazarus.
Public Sector Security
A City Hall clerk in Alexandria, Tennessee caught a hacker using the town's Amazon account to order three cameras and an iPad. The detection was a person noticing — no security control fired. Thousands of US municipalities are in the same posture.
Cybersecurity 101
A complete guide to SQL injection — how SQLi attacks work, the main types, what attackers can do with them, and the proven ways to prevent them.
Apple published the post-quantum cryptography implementations in corecrypto — the library behind iOS, iPadOS, and macOS — alongside formal proofs and verification tools. It does not change today's encryption posture, but it lets outside experts audit the math that will protect tomorrow's.
Google Cloud launched AI Threat Defense on May 27, 2026 — an automated platform that pairs Gemini, the Wiz cloud-security stack, and the CodeMender AI code-fixing agent to find, prioritize, and patch software vulnerabilities at machine speed.
A site branded as 'UK Visa Portal' exposed at least 100,000 applicants' passport scans and selfies, TechCrunch reported May 26. The site is not affiliated with the UK government, and the operator sent attorneys rather than fix the leak.
CrowdStrike's Counter Adversary Operations team, with Google and the Shadowserver Foundation, executed a simultaneous takedown of all four GlassWorm command-and-control channels — Solana, BitTorrent DHT, Google Calendar, and direct servers — on May 26-27, 2026.
Three independently disclosed campaigns in the May 26-27 cycle treat AI tools as a single trust surface — SymJack at the agent layer, fake installers impersonating Claude and ChatGPT at the brand layer, and AI chatbot recommendations at the discovery layer.
Gitea disclosed CVE-2026-27771, a registry authorization flaw that lets unauthenticated attackers pull private container images from any self-hosted Gitea below 1.26.2. It collapses the security premise of self-hosting: keeping images off public registries.
The FBI's May 26 FLASH alert warns that Silent Ransom Group — also tracked as Luna Moth, Chatty Spider, and UNC3753 — is now sending operatives in person to US law firms, posing as IT support and inserting USB drives to steal client data for extortion.
Israeli firm Gambit Security says the 'Ababil of Minab' hacktivist persona that claimed the March 2026 LA Metro breach is, on its forensic evidence, a front for Iran's Ministry of Intelligence and Security. At least 700 GB was stolen, and attackers reached a rail-yard control display.
A complete guide to the Cyber Kill Chain — the seven stages of a cyberattack, how defenders use the model to break an attack, and how it compares to MITRE ATT&CK.
India's CERT-In issued guidelines on May 26, 2026 requiring organizations to patch critical internet-exposed vulnerabilities within 12 hours, "where feasible." The cited reason is explicit: AI-driven exploitation has compressed the patch window past what conventional SLAs can survive.
Google's Threat Intelligence Group caught attackers exploiting CVE-2026-5426, a hardcoded ASP.NET machineKey in Digital Knowledge's KnowledgeDeliver LMS, to forge ViewState payloads, drop the Godzilla web shell, and stage Cobalt Strike Beacon. The patch alone is not enough.
Nimbus Manticore — the Iran-nexus APT The CyberSignal covered as Screening Serpens — has returned with a new backdoor codenamed MiniFast that Check Point Research assesses was developed with AI assistance, and a target set that now spans aviation, aerospace, defense, software, and telecom.