Delivered via phishing lures, the malware combines financial theft with data exfiltration and remote access. The post New BTMOB Android Malware Enables Full Device Takeover appeared first on SecurityWeek. This article has been indexed from SecurityWeek Read the original article:…
Zapier exploit chain shows how known anti-patterns compose into critical risk
A five-stage exploit chain disclosed by Token Security researchers turned a free Zapier account into write access on Zapier’s public developer SDK packages and on internal packages that load in every authenticated zapier.com session. Each link in the chain was…
IT Security News Hourly Summary 2026-05-28 15h : 22 posts
22 posts were published in the last hour 13:2 : IBM and Red Hat Commit $5 Billion to Secure Open Source Supply Chains Under “Project Lightwell” 13:2 : Critical FortiClient EMS Vulnerability Exploited in Fresh Attacks 13:2 : CISOs Need…
IBM and Red Hat Commit $5 Billion to Secure Open Source Supply Chains Under “Project Lightwell”
Project Lightwell is designed to fix vulnerabilities without breaking what is already in production. The post IBM and Red Hat Commit $5 Billion to Secure Open Source Supply Chains Under “Project Lightwell” appeared first on SecurityWeek. This article has been…
Critical FortiClient EMS Vulnerability Exploited in Fresh Attacks
Fortinet rolled out hotfixes for the security defect in April, warning that it had been exploited in the wild as a zero-day and urging immediate patching. The post Critical FortiClient EMS Vulnerability Exploited in Fresh Attacks appeared first on SecurityWeek.…
CISOs Need Real Incident Experience, Survey Shows
Cybersecurity professionals place significant value on CISOs who have led organizations through major security incidents, according to new research from ISC2. This article has been indexed from CyberMaterial Read the original article: CISOs Need Real Incident Experience, Survey Shows
Malicious Websites Exploit SSD Timing Signals to Monitor Visitor Activity
Malicious websites can now exploit subtle SSD timing signals in modern browsers to quietly track what users are doing on their devices, including which sites and apps they open, using a new side‑channel technique called FROST. Security researchers Hannesweissteiner have…
Proton Mail Lets Users Send and Receive Gmail Directly Without Giving Google Access to Proton Inbox
Swiss privacy company Proton has rolled out a significant update to Proton Mail that allows users to connect their Gmail accounts directly to the platform. The feature, announced on 28 May 2026, enables Gmail messages to be imported into Proton…
Critical Roundcube Webmail Vulnerability Let Attackers Inject SQL Queries
Roundcube Webmail users are being urged to apply urgent updates after developers patched multiple security flaws. Including a critical pre-authentication SQL injection vulnerability that could allow attackers to manipulate backend databases without logging in. The issues affect Roundcube versions 1.6.…
New PureLogs Variant Uses MsBuild.exe Process Hollowing to Evade Detection
A new and dangerous version of the PureLogs information-stealing malware has emerged, raising serious concerns across the cybersecurity community. This variant takes a more evasive approach than its predecessors, using a carefully crafted chain of stages to reach victims without…
Gitea Container Vulnerability Exposes Private Container Images to Attackers
A critical security vulnerability in Gitea’s built-in container registry exposes private container images to unauthenticated attackers, raising significant concerns for organizations that rely on self-hosted Git and CI/CD environments. The flaw, tracked as CVE-2026-27771, allows remote attackers to access and…
Hackers Use GHOSTYNETWORKS and OMEGATECH to Host JS Malware Infrastructure
In March 2026, a wave of malicious spam emails began hitting inboxes across multiple countries and industries. Threat actors were quietly distributing a JavaScript-coded backdoor, targeting organizations in sectors as critical as energy, automotive, and government finance. The scale of…
Carnival Cruise Data Breach Exposes Millions of Customers’ Personal Information
Carnival Corporation, the world’s largest cruise company and parent of Carnival Cruise Line, has begun notifying customers of a significant cybersecurity breach that exposed sensitive personal data after a threat actor successfully used social engineering to compromise an employee account.…
Carnival confirms data breach impacting nearly 6 million
Cruise giant Carnival has suffered yet another data breach, with ShinyHunters claiming to have stolen personal data affecting nearly 6 million people. This article has been indexed from Malwarebytes Read the original article: Carnival confirms data breach impacting nearly 6…
Carnival confirms ShinyHunters cruised off with 6M customer records after April breach
Travel and leisure giant was just one of many victims of the cybercrooks’ crime spree this year This article has been indexed from www.theregister.com – Articles Read the original article: Carnival confirms ShinyHunters cruised off with 6M customer records after…
Qevlar’s new AI agents correlate CVEs, incident data, and active exploitation signals
Qevlar has announced a new set of AI agents designed to bridge the disconnect between Security Operations Centers (SOCs) and vulnerability management teams. The new capabilities help security teams correlate CVEs with live incident data for real-time risk prioritization, automatically…
Digimarc adds provenance, audit, and verification controls for AI agent workflows
Digimarc has announced new provenance and verification infrastructure designed to secure autonomous and AI-enabled workflows. As enterprises increasingly adopt AI systems capable of generating content, orchestrating workflows, and taking action with minimal human intervention, establishing trusted provenance and verifiable authenticity…
Qumulo NeuralProtect uses AI to detect and stop ransomware before encryption
Qumulo has unveiled Qumulo NeuralProtect, a ransomware resilience solution built to protect data at the storage layer by detecting and stopping threats before data is encrypted, corrupted, or lost. Integrated directly into the Qumulo Data Platform, NeuralProtect inspects every file…
OpenAI prepares ChatGPT for the election misinformation wave
AI-generated election misinformation could shape public opinion and influence the lives of millions of people. To address those risks, OpenAI outlined a series of safeguards ahead of the 2026 election cycle. The company said its efforts will focus on helping…
New AI Usage Report: Enterprise AI Risk Is Heavily Concentrated Among a Small Group of AI “Power users”
State of AI Usage Report 2026 (full report here) by LayerX Security reveals the extent of the enterprise AI visibility gap and why most organizations still don’t understand where their AI exposure is actually coming from. The research shows that…
VaultJacking: Google Password Manager PIN Compromise
A new phishing technique named VaultJacking has been disclosed by security researchers, demonstrating a critical vulnerability in how Google Password Manager protects stored credentials. This article has been indexed from CyberMaterial Read the original article: VaultJacking: Google Password Manager PIN…
Fake ChatGPT site delivers malware to Windows/Mac
A sophisticated phishing operation is targeting users searching for ChatGPT downloads, distributing platform-specific malware through a fake website that closely mimics OpenAI’s official download page. This article has been indexed from CyberMaterial Read the original article: Fake ChatGPT site delivers…
Motorola Smart Feed App Hijacks Amazon Shopping
Motorola has disabled functionality in its preinstalled Smart Feed app after security researchers and users discovered it was intercepting Amazon Shopping app launches to insert affiliate referral codes without user consent. This article has been indexed from CyberMaterial Read the…
Silent Ransom Group Targets Law Firms
A threat actor known as the Silent Ransom Group is conducting targeted attacks against US law firms using sophisticated social engineering techniques that bypass traditional ransomware detection methods. This article has been indexed from CyberMaterial Read the original article: Silent…