These news items are automatically aggregated from industry sources and are not individually reviewed. Any inaccuracies are unintentional —
let us know and we'll correct or remove it.
iOS 26.5 and the latest Google Messages update are bringing end-to-end encrypted RCS messaging to cross-platform conversations between iPhone and Android users, ending years of reliance on unprotected SMS infrastructure for the most common mobile communication channel. Separately, Apple’s Siri deal with Google raises questions about where AI conversations are processed.
A highly critical SQL injection vulnerability in Drupal core, disclosed on May 20 and affecting PostgreSQL-backed sites from version 8.9.0 through 11.3.9, is under active exploitation with more than 15,000 attack attempts recorded against nearly 6,000 sites within the first 48 hours of disclosure.
A coordinated supply chain campaign called TrapDoor has deployed 34 malicious packages and more than 384 related versions across npm, PyPI, and Crates.io, targeting developers in crypto, AI, and security to steal AWS keys, GitHub tokens, SSH keys, and crypto wallets. The campaign also embeds hidden instructions in AI coding assistant configuration files to hijack Claude Code and Cursor sessions.
The FBI has issued a public service announcement about Kali365, a Phishing-as-a-Service platform first seen in April 2026 that captures Microsoft 365 OAuth tokens via the device code flow, rendering standard multi-factor authentication ineffective.
Attackers compromised four widely-used Laravel localisation packages on Packagist, rewriting Git tags across more than 700 versions to inject a 5,900-line PHP credential stealer that exfiltrates cloud keys, CI tokens, SSH material, and browser data on every request.
CVE-2026-42897 is an Outlook Web Access cross-site scripting vulnerability in on-premises Exchange Server that is being exploited in the wild via crafted emails. CISA added it to the Known Exploited Vulnerabilities catalog with a May 29 remediation deadline for federal agencies. No permanent patch exists yet.
A cooling system failure at an AWS Northern Virginia data centre caused a multi-hour outage in Availability Zone use1-az4 in early May 2026. Coinbase, FanDuel, and CME Group were among the platforms disrupted. Amazon later confirmed overheating as the root cause.
A compromised TanStack npm package gave attackers access to Grafana Labs’ GitHub environment, allowing them to download the company’s full codebase. Grafana received an extortion demand and refused to pay. The same supply chain attack also hit OpenAI and Mistral AI.
Ubiquiti has patched five vulnerabilities in UniFi OS, three of them rated maximum severity with CVSS scores of 10. All three allow unauthenticated remote attackers to take full control of affected devices. Censys tracks nearly 100,000 internet-exposed UniFi OS endpoints.
A CVSS 9.3 buffer overflow in Palo Alto Networks PAN-OS allows unauthenticated attackers to execute arbitrary code with root privileges on PA-Series and VM-Series firewalls. The vulnerability was added to CISA’s Known Exploited Vulnerabilities catalogue on May 6 following confirmed in-the-wild attacks.
This site uses cookies. By continuing to use this website, you agree to their use.
We’ll help you resolve your infrastructure challenges
Our team of experts is ready to help you with your infrastructure challenges. We’ll give you honest and personal treatment. Get in touch to learn more.