5/5/2026

China-Linked UAT-8302 Targets Governments Using Shared APT Malware Across Regions

North Korean APT ScarCruft Targets Yanbian Gamers via Trojanized Platform

Small Defense Firms Lack Network Data to Stop Nation-State Hackers, Analyst Says

States Concerned Over Access to Frontier AI Model Pilots

AI Adoption Outpaces Safety Policies, Leaving Organizations Exposed to Cyber Risk

Researchers Gaslit Claude Into Giving Instructions to Build Explosives

Student Hacked Taiwan High-Speed Rail to Trigger Emergency Brakes

Karakurt Extortion Gang ‘Cold Case’ Negotiator Gets 8.5 Years in Prison

Romance Scammers Turn Sweet Talk Into £102M Payday

FTC to Ban Data Broker Kochava From Selling Americans’ Location Data

Australia Launches Cyber Review Board Modeled on Version Disbanded in U.S.
Real Estate Giant Cushman & Wakefield Confirms Vishing Incident as ShinyHunters and Qilin Both Come Knocking

ShinyHunters Claims Dump Puts 119K Vimeo Emails in the Wild

Instructure Hacker Claims Data Theft From 8,800 Schools, Universities

Microsoft Flags Mass Phishing Campaign Using Fake Compliance Emails

CloudZ Malware Abuses Microsoft Phone Link to Steal SMS and OTPs

DAEMON Tools Supply Chain Attack Compromises Official Installers with Malware

MetInfo CMS CVE-2026-29014 Exploited for Remote Code Execution Attacks

Critical Apache HTTP/2 Flaw (CVE-2026-23918) Enables DoS and Potential RCE

Google Now Offers up to $1.5 Million for Some Android Exploits

German Officials Advance Legislation That Would Expand Law Enforcement Use of Surveillance Technology

5/4/2026

Itron Hackers Accessed Critical Infrastructure Operators

Silver Fox Deploys ABCDoor Malware via Tax-Themed Phishing in India and Russia

If the Vote You Rocked, Your Personal Info Can Be Grokked

EU Recommends Member States to Not Use Huwaei, ZTE in Connectivity Infrastructure

White House Considers Vetting AI Models Before They Are Released

ChatGPT Wrestles With Its Most Chilling Conversation: How Do I Plan an Attack?

You Have No Idea How Much You Still Use BlackBerry

DHS Demanded Google Surrender Data on Canadian’s Activity, Location Over Anti-ICE Posts

Forbes Preliminarily Agrees to Pay $10 Million to Settle California Wiretapping Lawsuit
Ransomware Group Claims Breach of Pro-Orbán Hungarian Media Firm

Instructure Confirms Data Breach, ShinyHunters Claims Attack

Hanover County Schools Confirms Data Breach Incident

Phishing Campaign Hits 80+ Orgs Using SimpleHelp and ScreenConnect RMM Tools

Amazon SES Increasingly Abused in Phishing to Evade Detection

Backdoored PyTorch Lightning Package Drops Credential Stealer

Weaver E-Cology Critical Bug Exploited in Attacks Since March

Progress Patches Critical MOVEit Automation Bug Enabling Authentication Bypass

CISA Says ‘Copy Fail’ Flaw Now Exploited to Root Linux Systems

Kids Say They Can Beat Age Checks by Drawing on a Fake Mustache

5/1-3/2026

Ubuntu Infrastructure Has Been Down for More Than a Day

Ubuntu Services Hit by Outages After DDoS Attack

Pro-Iran Crew turns DDoS into Shakedown as Ubuntu.com Stays Down

Cyber Spies Target Russian Aviation Firms to Steal Satellite and GPS Data

U.S. Officials Weigh Cutting Deadlines to Fix Digital Flaws Amid Worries Over AI-Powered Hacking, Sources Say

British Cyber Agency Warns of Looming ‘Patch Wave’ as AI Speeds Flaw Discovery

Brace for the Patch Tsunami: AI Is Unearthing Decades of Buried Code Debt

GPT-5.5 Matches Heavily Hyped Mythos Preview in New Cybersecurity Tests

Senate Judiciary Advances Bill That Would Bar Minors From Interacting With AI Companions

Security Strategies Shift Focus to Cyber Insurance

Two Cybersecurity Professionals Get 4-Year Sentences in BlackCat Ransomware Attacks

Disneyland Now Uses Face Recognition on Visitors
Edu Tech Firm Instructure Discloses Cyber Incident, Probes Impact

Trellix Confirms Source Code Breach With Unauthorized Repository Access

Critrical cPanel Flaw Mass-Exploited in “Sorry” Ransomware Attacks

City of Ardmore (OK) Issues Alert After Ransomware Attack

Ransomware Attack Cripples Adams County (MS) Systems, Officials Say

30,000 Facebook Accounts Hacked via Google AppSheet Phishing Campaign

Telegram Mini Apps Abused for Crypto Scams, Android Malware Delivery

ConsentFix v3 Attacks Target Azure with Automated OAuth Abuse

Cybercrime Groups Using Vishing and SSO Abuse in Rapid SaaS Extortion Attacks

CISA Adds Actively Exploited Linux Root Access Bug CVE-2026-31431 to KEV

Microsoft Fixes Remote Desktop Warnings Displaying Incorrectly

Microsoft Defender Wrongly Flags DigiCert Certs as Trojan:Win32/Cerdigent.A!dha