<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title>Zaufana Trzecia Strona</title><link>https://badcyber.com/</link><description>Recent content on Zaufana Trzecia Strona</description><generator>Hugo</generator><language>en-US</language><lastBuildDate>Fri, 12 Jun 2026 23:30:00 +0200</lastBuildDate><atom:link href="https://badcyber.com/feed.xml" rel="self" type="application/rss+xml"/><item><title>IT Security Weekend Catch Up – June 12, 2026</title><link>https://badcyber.com/it-security-weekend-catch-up-june-12-2026/</link><pubDate>Fri, 12 Jun 2026 23:30:00 +0200</pubDate><guid>https://badcyber.com/it-security-weekend-catch-up-june-12-2026/</guid><description><![CDATA[<div class="payload-richtext"><p>Afraid of missing important security news during the week? We&#39;re here to help! Every week we put together a curated list of all important security news in one place, for your reading pleasure. Enjoy!</p><h3>For the less technical</h3><ol class="list-number"><li
          class=""
          style="text-align: left;"
          value="1"
        >[PL] <a href="https://www.wnp.pl/tech/na-ten-cel-wydamy-nawet-100-mld-zl-rocznie-nowa-strategia-rzadu-w-cyfryzacji,1070455.html" rel="noopener noreferrer" target="_blank">Polish government approves National Digitalization Strategy</a></li><li
          class=""
          style="text-align: left;"
          value="2"
        >[PL] <a href="https://siecobywatelska.pl/czy-jawnosc-zagraza-bezpieczenstwu-panstwa/" rel="noopener noreferrer" target="_blank">Is transparency a threat to national security?</a></li><li
          class=""
          style="text-align: left;"
          value="3"
        >[PL][VIDEO] <a href="https://www.youtube.com/watch?v=61jjjKMZEqM" rel="noopener noreferrer" target="_blank">Secret Department No. 4: What Russian intelligence agents study?</a></li><li
          class=""
          style="text-align: left;"
          value="4"
        >[PL] <a href="https://www.pap.pl/aktualnosci/gosc-studia-pap-agata-slusarek-ekspertka-cyberbezpieczenstwa" rel="noopener noreferrer" target="_blank">Expert warns there’s no such thing as a risk-free investment. A “safe” profit offer online could be a scam</a></li><li
          class=""
          style="text-align: left;"
          value="5"
        >[PL] <a href="https://cert.orange.pl/ostrzezenia/deepfake-falszywa-platforma-bukmacherska/" rel="noopener noreferrer" target="_blank">The World Cup “guaranteed win” that drains your account: An analysis of a deepfake campaign ahead of the FIFA World Cup</a></li><li
          class=""
          style="text-align: left;"
          value="6"
        >[PL] <a href="https://czasopismo.legeartis.org/2026/06/weryfikacji-wieku-uzytkownikow-serwisow-pornograficznych-blokowanie-dostepu-maloletnim-internecie-projekt/" rel="noopener noreferrer" target="_blank">Mandatory age checks for porn sites</a></li><li
          class=""
          style="text-align: left;"
          value="7"
        >[PL][AUDIO] <a href="https://www.youtube.com/watch?v=HiL94WvjCww" rel="noopener noreferrer" target="_blank">Meta and Google in court. Will the verdicts change the internet?</a></li><li
          class=""
          style="text-align: left;"
          value="8"
        >[PL] <a href="https://krytykapolityczna.pl/swiat/usa-ai-sztuczna-inteligencja-centra-danych-szkodliwosc-protesty-mieszkancow/" rel="noopener noreferrer" target="_blank">Americans united in opposition to AI data centers</a></li><li
          class=""
          style="text-align: left;"
          value="9"
        >[PL] <a href="https://demagog.org.pl/analizy_i_raporty/ai-jako-narzedzie-skoordynowanej-dezinformacji-jak-odpowiedziec-na-ten-problem/" rel="noopener noreferrer" target="_blank">AI enables coordinated disinformation campaigns</a></li><li
          class=""
          style="text-align: left;"
          value="10"
        >[PL] <a href="https://uodo.gov.pl/pl/138/4423" rel="noopener noreferrer" target="_blank">Poland’s data protection chief appeals the closure of an investigation into AI-generated nude images of a student</a></li><li
          class=""
          style="text-align: left;"
          value="11"
        ><a href="https://www.theguardian.com/business/2026/jun/08/aviva-ai-bogus-insurance-claims-rocket" rel="noopener noreferrer" target="_blank">Aviva detects record £230m in bogus insurance claims as use of AI rises</a></li><li
          class=""
          style="text-align: left;"
          value="12"
        ><a href="https://www.theguardian.com/technology/2026/jun/12/pokemon-go-data-trained-ai-that-could-assist-military-drones-in-war-zones" rel="noopener noreferrer" target="_blank">Pokémon Go data trained AI that could assist military drones in war zones</a></li><li
          class=""
          style="text-align: left;"
          value="13"
        >[VIDEO] <a href="https://www.youtube.com/watch?v=tz23G_UXCGA" rel="noopener noreferrer" target="_blank">Something is jamming GPS over Europe. Here&#39;s what we found</a></li><li
          class=""
          style="text-align: left;"
          value="14"
        ><a href="https://www.bleepingcomputer.com/news/security/french-govt-messaging-service-breached-in-account-hijacking-attack/" rel="noopener noreferrer" target="_blank">French govt messaging service breached in account hijacking attack</a></li><li
          class=""
          style="text-align: left;"
          value="15"
        ><a href="https://www.theguardian.com/technology/2026/jun/09/spyware-firm-targeted-whatsapp-users-defiance-us-court-order-meta-says" rel="noopener noreferrer" target="_blank">Spyware firm targeted WhatsApp users in defiance of US court order, Meta says</a></li></ol><h3>For the more technical</h3><ol class="list-number"><li
          class=""
          style=""
          value="1"
        >[PL][VIDEO] <a href="https://www.youtube.com/watch?v=R5jTfcX6pf8" rel="noopener noreferrer" target="_blank">MCP – the hot topic in the world of app security</a></li><li
          class=""
          style=""
          value="2"
        >[PL] <a href="https://sekurak.pl/signal-wdraza-mechanizmy-chroniace-przed-phishingiem-czy-sa-wystarczajace-do-ochrony-uzytkownika/" rel="noopener noreferrer" target="_blank">Signal rolls out new anti-phishing features</a></li><li
          class=""
          style=""
          value="3"
        ><a href="https://cert.pl/en/posts/2026/06/UNC1151-gmail-campaign/" rel="noopener noreferrer" target="_blank">UNC1151/Ghostwriter phishing campaign targeting Gmail accounts</a></li><li
          class=""
          style=""
          value="4"
        ><a href="https://blog.checkpoint.com/security/check-point-releases-important-hotfix-for-vulnerabilities-in-deprecated-ikev1-vpn-protocol/" rel="noopener noreferrer" target="_blank">Active exploitation of Check Point VPN authentication bypass (CVE-2026-50751)</a></li><li
          class=""
          style=""
          value="5"
        ><a href="https://www.fortinet.com/blog/threat-research/inside-cross-platform-propagation-of-new-gafgyt-variant-c0xmo" rel="noopener noreferrer" target="_blank">Inside the cross-platform propagation of a new Gafgyt variant C0XMO</a></li><li
          class=""
          style=""
          value="6"
        ><a href="https://www.crowdstrike.com/en-us/blog/patch-tuesday-analysis-june-2026/" rel="noopener noreferrer" target="_blank">June 2026 Patch Tuesday: Microsoft patches 206 vulnerabilities including three publicly disclosed zero-days</a></li><li
          class=""
          style=""
          value="7"
        ><a href="https://www.huntress.com/blog/unpatched-ntlm-leak-windows-search-uri-handler" rel="noopener noreferrer" target="_blank">When &quot;moderate&quot; means &quot;sometimes&quot;</a></li><li
          class=""
          style=""
          value="8"
        ><a href="https://www.bleepingcomputer.com/news/security/google-patches-fifth-chrome-zero-day-bug-exploited-in-attacks-this-year/" rel="noopener noreferrer" target="_blank">Google patches new Chrome zero-day flaw exploited in the wild</a></li><li
          class=""
          style=""
          value="9"
        >[VIDEO] <a href="https://www.youtube.com/watch?v=eTdeFbWROeg" rel="noopener noreferrer" target="_blank">The only Open Redirect that scares me</a></li><li
          class=""
          style=""
          value="10"
        ><a href="https://www.bleepingcomputer.com/news/security/oracle-mitigates-peoplesoft-zero-day-exploited-in-data-theft-attacks/" rel="noopener noreferrer" target="_blank">Oracle mitigates PeopleSoft zero-day exploited in data theft attacks</a></li><li
          class=""
          style=""
          value="11"
        ><a href="https://blog.exodusintel.com/2026/06/08/off-by-exploiting-a-use-after-free-in-the-linux-kernel/" rel="noopener noreferrer" target="_blank">Off by !: Exploiting a use-after-free in the Linux kernel</a></li><li
          class=""
          style=""
          value="12"
        ><a href="https://blog.sekoia.io/fsbs-matryoshka-1-3-gamaredons-gifts-that-keeps-unpacking-gammaphish-and-gammaworm/" rel="noopener noreferrer" target="_blank">FSB’s matryoshka – Gamaredon’s gifts that keeps unpacking – GammaPhish and GammaWorm</a></li><li
          class=""
          style=""
          value="13"
        ><a href="https://blog.sekoia.io/fsbs-matryoshka-2-3-gamaredons-gifts-that-keeps-unpacking-gammaload/" rel="noopener noreferrer" target="_blank">FSB’s matryoshka #2/3 – Gamaredon’s gifts that keeps unpacking – GammaLoad</a></li><li
          class=""
          style=""
          value="14"
        ><a href="https://blog.sekoia.io/fsbs-matryoshka-3-3-gamaredons-gifts-that-keeps-unpacking-gammasteel/" rel="noopener noreferrer" target="_blank">FSB’s matryoshka #3/3 – Gamaredon’s gifts that keeps unpacking – GammaSteel</a></li><li
          class=""
          style=""
          value="15"
        ><a href="https://www.fortinet.com/blog/threat-research/threat-actors-weaponize-ai-hype-to-deliver-asyncrat" rel="noopener noreferrer" target="_blank">Threat actors weaponize AI hype to deliver AsyncRAT</a></li><li
          class=""
          style=""
          value="16"
        ><a href="https://research.jfrog.com/post/iron-worm-shai-hulud-rustier-cousin/" rel="noopener noreferrer" target="_blank">IronWorm: Shai-Hulud&#39;s rustier cousin</a></li><li
          class=""
          style=""
          value="17"
        ><a href="https://www.stepsecurity.io/blog/binding-gyp-npm-supply-chain-attack-spreads-like-worm" rel="noopener noreferrer" target="_blank">Miasma npm supply chain attack: Self-spreading worm via Phantom Gyp</a></li><li
          class=""
          style=""
          value="18"
        ><a href="https://safedep.io/inside-the-miasma-supply-chain-attack-toolkit/" rel="noopener noreferrer" target="_blank">Inside the Miasma software supply chain attack toolkit</a></li><li
          class=""
          style=""
          value="19"
        ><a href="https://opensourcemalware.com/blog/miasma-reaches-azure" rel="noopener noreferrer" target="_blank">The blight reaches Microsoft: 73 repos disabled in 105 seconds</a></li><li
          class=""
          style=""
          value="20"
        ><a href="https://www.sophos.com/en-us/blog/you-do-surprise-me-exe-an-unexpected-executable-in-hola-browser" rel="noopener noreferrer" target="_blank">You do surprise me.exe: An unexpected executable in Hola Browser</a></li><li
          class=""
          style=""
          value="21"
        ><a href="https://www.microsoft.com/en-us/security/blog/2026/06/08/ai-brands-as-bait-how-threat-actors-are-using-the-ai-hype-in-social-engineering/" rel="noopener noreferrer" target="_blank">AI brands as bait: How threat actors are using the AI hype in social engineering</a></li><li
          class=""
          style=""
          value="22"
        ><a href="https://www.proofpoint.com/us/blog/threat-insight/dont-fear-repo-unkdeaddrop-phishing-campaign-targets-developers-steal" rel="noopener noreferrer" target="_blank">Don&#39;t fear the repo: UNK_DeadDrop phishing campaign targets developers to steal cryptocurrency</a></li><li
          class=""
          style=""
          value="23"
        ><a href="https://www.gendigital.com/blog/insights/research/goflateloader-delivers-multiple-infostealers" rel="noopener noreferrer" target="_blank">GoFlateLoader: A widespread Golang loader delivering multiple infostealers</a></li><li
          class=""
          style=""
          value="24"
        ><a href="https://unit42.paloaltonetworks.com/cloud-logging-defense-evasion/" rel="noopener noreferrer" target="_blank">Blinding the watchmen: Abusing cloud logging services for defense evasion and visibility</a></li><li
          class=""
          style=""
          value="25"
        ><a href="https://www.zscaler.com/blogs/security-research/technical-analysis-mltbackdoor" rel="noopener noreferrer" target="_blank">Technical analysis of MLTBackdoor</a></li><li
          class=""
          style=""
          value="26"
        ><a href="https://www.catonetworks.com/blog/cato-ctrl-previously-undocumented-ninjaone-rmm-abuse-chain/" rel="noopener noreferrer" target="_blank">From fiscal lures to remote access, a previously undocumented NinjaOne RMM abuse chain</a></li><li
          class=""
          style=""
          value="27"
        ><a href="https://www.welivesecurity.com/en/eset-research/oceanlotus-external-espionage-domestic-targeting/" rel="noopener noreferrer" target="_blank">OceanLotus: From external espionage to domestic targeting</a></li><li
          class=""
          style=""
          value="28"
        ><a href="https://www.volexity.com/blog/2026/06/04/verdantbamboo-just-another-brickstorm-in-the-firewall/" rel="noopener noreferrer" target="_blank">VerdantBamboo: Just another BRICKSTORM in the firewall</a></li><li
          class=""
          style=""
          value="29"
        ><a href="https://blog.sekoia.io/apt28-an-evolution-of-tradecraft/" rel="noopener noreferrer" target="_blank">APT28, an evolution of tradecraft</a></li><li
          class=""
          style=""
          value="30"
        ><a href="https://www.trendmicro.com/en_us/research/26/f/old-winrar-flaw-fuels-attacks-on-ukraine.html" rel="noopener noreferrer" target="_blank">Old WinRAR flaw fuels attacks on Ukraine: How unmanaged software keeps the door open</a></li><li
          class=""
          style=""
          value="31"
        ><a href="https://cloud.google.com/blog/topics/threat-intelligence/targeted-campaign-us-law-firms/" rel="noopener noreferrer" target="_blank">Seeking counsel: Ongoing targeted campaign against US law firms</a></li><li
          class=""
          style=""
          value="32"
        ><a href="https://www.acronis.com/en/tru/posts/behind-khmer-shadow-targeted-espionage-against-cambodian-government-entities/" rel="noopener noreferrer" target="_blank">Behind Khmer Shadow: Targeted espionage against Cambodian government entities</a></li></ol><p>Did you enjoy this list? You can subscribe to one of our feeds on <a href="https://twitter.com/badcybercom">Twitter</a>, <a href="https://www.facebook.com/badcyber/">Facebook</a> or <a href="/feed/">RSS</a>.</p></div>]]></description></item><item><title>IT Security Weekend Catch Up – June 7, 2026</title><link>https://badcyber.com/it-security-weekend-catch-up-june-7-2026/</link><pubDate>Sun, 07 Jun 2026 22:30:00 +0200</pubDate><guid>https://badcyber.com/it-security-weekend-catch-up-june-7-2026/</guid><description><![CDATA[<div class="payload-richtext"><p>Afraid of missing important security news during the week? We&#39;re here to help! Every week we put together a curated list of all important security news in one place, for your reading pleasure. Enjoy!</p><h3>For the less technical</h3><ol class="list-number"><li
          class=""
          style="text-align: left;"
          value="1"
        ><a href="https://krebsonsecurity.com/2026/06/hackers-used-metas-ai-support-bot-to-seize-instagram-accounts/" rel="noopener noreferrer" target="_blank">Hackers used Meta’s AI support bot to seize Instagram accounts</a></li><li
          class=""
          style="text-align: left;"
          value="2"
        ><a href="https://arstechnica.com/security/2026/05/fed-up-with-vibe-coders-dev-sneaks-data-nuking-prompt-injection-into-their-code/" rel="noopener noreferrer" target="_blank">Fed up with vibe coders, dev sneaks data-nuking prompt injection into their code</a></li><li
          class=""
          style="text-align: left;"
          value="3"
        ><a href="https://www.theregister.com/cyber-crime/2026/06/02/dumbass-criminal-breaks-the-first-rule-of-ransomware-club/5250380" rel="noopener noreferrer" target="_blank">&#39;Dumbass&#39; criminal breaks the &#39;first rule of ransomware club&#39;</a></li><li
          class=""
          style="text-align: left;"
          value="4"
        ><a href="https://arstechnica.com/security/2026/06/dashlane-issues-opaque-advisory-warning-20-encrypted-vaults-were-stolen/" rel="noopener noreferrer" target="_blank">Can’t make sense of Dashlane’s vault theft notification? You’re not alone</a></li><li
          class=""
          style="text-align: left;"
          value="5"
        ><a href="https://www.theregister.com/security/2026/06/01/gta-cheat-service-atlas-menu-hacked-as-attacker-alleges-screenshot-spying/5249192" rel="noopener noreferrer" target="_blank">GTA cheat service Atlas Menu hacked as attacker alleges screenshot spying</a></li></ol><h3>For the more technical</h3><ol class="list-number"><li
          class=""
          style=""
          value="1"
        ><a href="https://source.android.com/docs/security/bulletin/2026/2026-06-01" rel="noopener noreferrer" target="_blank">Android Security Bulletin—June 2026</a></li><li
          class=""
          style=""
          value="2"
        ><a href="https://mysk.blog/2026/05/19/cve-2026-28910/" rel="noopener noreferrer" target="_blank">CVE-2026-28910: Breaking macOS App Sandbox data containers, TCC, and hijacking apps using Archive Utility</a></li><li
          class=""
          style=""
          value="3"
        ><a href="https://heyitsas.im/posts/cifswitch/" rel="noopener noreferrer" target="_blank">CIFSwitch: a non-universal Linux local root vulnerability</a></li><li
          class=""
          style=""
          value="4"
        ><a href="https://www.bleepingcomputer.com/news/microsoft/critical-windows-netlogon-remote-code-execution-flaw-now-exploited-in-attacks/" rel="noopener noreferrer" target="_blank">Critical Windows Netlogon RCE flaw now exploited in attacks</a></li><li
          class=""
          style=""
          value="5"
        ><a href="https://blog.ammaraskar.com/github-token-stealing/" rel="noopener noreferrer" target="_blank">1-click GitHub token stealing via a VSCode bug</a></li><li
          class=""
          style=""
          value="6"
        ><a href="https://blog.calif.io/p/codex-discovered-a-hidden-http2-bomb" rel="noopener noreferrer" target="_blank">HTTP/2 Bomb: AI-discovered DoS hits every major web server</a></li><li
          class=""
          style=""
          value="7"
        ><a href="https://permiso.io/blog/chatgpt-markdown-rendering-vulnerability" rel="noopener noreferrer" target="_blank">ChatGPhish: The page is the payload</a></li><li
          class=""
          style=""
          value="8"
        ><a href="https://www.wordfence.com/blog/2026/05/15000-wordpress-sites-affected-by-administrator-account-creation-vulnerability-in-wp-maps-pro-wordpress-plugin/" rel="noopener noreferrer" target="_blank">15,000 WordPress sites affected by administrator account creation vulnerability in WP Maps Pro WordPress plugin</a></li><li
          class=""
          style=""
          value="9"
        ><a href="https://socket.dev/blog/malicious-nuget-package-impersonates-sicoob-sdk" rel="noopener noreferrer" target="_blank">Malicious NuGet package impersonates Sicoob SDK to exfiltrate banking certificates and passwords</a></li><li
          class=""
          style=""
          value="10"
        ><a href="https://www.microsoft.com/en-us/security/blog/2026/05/28/typosquatted-npm-packages-used-steal-cloud-ci-cd-secrets/" rel="noopener noreferrer" target="_blank">Typosquatted npm packages used to steal cloud and CI/CD secrets</a></li><li
          class=""
          style=""
          value="11"
        ><a href="https://www.aikido.dev/blog/red-hat-npm-packages-compromised-credential-stealing-worm" rel="noopener noreferrer" target="_blank">Red Hat npm packages compromised to spread a credential-stealing worm</a></li><li
          class=""
          style=""
          value="12"
        ><a href="https://socket.dev/blog/mini-shai-hulud-campaign-hits-red-hat-cloud-services-npm-packages" rel="noopener noreferrer" target="_blank">Mini Shai-Hulud campaign hits Red Hat Cloud Services npm packages</a></li><li
          class=""
          style=""
          value="13"
        ><a href="https://www.ox.security/blog/new-npm-supply-chain-attack-redhat-cloud-services-compromised/" rel="noopener noreferrer" target="_blank">New Shai-Hulud hits npm: @redhat-cloud-services compromised</a></li><li
          class=""
          style=""
          value="14"
        ><a href="https://www.godaddy.com/resources/news/malware-targeting-wordpress-abuses-steam-community-profiles" rel="noopener noreferrer" target="_blank">Malware targeting WordPress abuses Steam community profiles for command &amp; control operations</a></li><li
          class=""
          style=""
          value="15"
        ><a href="https://www.mcafee.com/blogs/other-blogs/mcafee-labs/weedhack-minecraft-malware-as-a-service-campaign-research/" rel="noopener noreferrer" target="_blank">Game Over: WeedHack – The rise of Minecraft malware-as-a-service campaign</a></li><li
          class=""
          style=""
          value="16"
        ><a href="https://www.picussecurity.com/resource/blog/nightspire-ransomware-attack-chain-tools-and-tactics" rel="noopener noreferrer" target="_blank">NightSpire ransomware attack chain, tools and tactics</a></li><li
          class=""
          style=""
          value="17"
        ><a href="https://www.withsecure.com/en/resources-hub/w-labs/greyvibe/" rel="noopener noreferrer" target="_blank">GREYVIBE: A Russia-nexus group leveraging AI across state-aligned operations</a></li><li
          class=""
          style=""
          value="18"
        ><a href="https://ellio.tech/en/blog/sanctioned-seized-still-scanning-inside-a-russian-bulletproof-hosting-network-targeting-the-eu/" rel="noopener noreferrer" target="_blank">Sanctioned, seized, still scanning: Inside a Russian bulletproof hosting network targeting the EU</a></li></ol><p>Did you enjoy this list? You can subscribe to one of our feeds on <a href="https://twitter.com/badcybercom">Twitter</a>, <a href="https://www.facebook.com/badcyber/">Facebook</a> or <a href="/feed/">RSS</a>.</p></div>]]></description></item><item><title>IT Security Weekend Catch Up – May 30, 2026</title><link>https://badcyber.com/it-security-weekend-catch-up-may-30-2026/</link><pubDate>Sat, 30 May 2026 22:00:00 +0200</pubDate><guid>https://badcyber.com/it-security-weekend-catch-up-may-30-2026/</guid><description><![CDATA[<div class="payload-richtext"><p>Afraid of missing important security news during the week? We&#39;re here to help! Every week we put together a curated list of all important security news in one place, for your reading pleasure. Enjoy!</p><h3>For the less technical</h3><ol class="list-number"><li
          class=""
          style="text-align: left;"
          value="1"
        >[PL] <a href="https://rys.io/pl/183.html" rel="noopener noreferrer" target="_blank">Age verification means internet filtering</a></li><li
          class=""
          style="text-align: left;"
          value="2"
        >[PL][VIDEO] <a href="https://www.youtube.com/watch?v=ablcBPMxSn8" rel="noopener noreferrer" target="_blank">Another VPN mishap? Not quite</a></li><li
          class=""
          style="text-align: left;"
          value="3"
        >[PL] <a href="https://demagog.org.pl/analizy_i_raporty/nowe-oblicze-platnej-dezinformacji-ai-wkracza-do-gry/" rel="noopener noreferrer" target="_blank">Paid disinformation takes a new turn as AI enters the game</a></li><li
          class=""
          style="text-align: left;"
          value="4"
        >[PL] <a href="https://siecobywatelska.pl/jawnosc-ai-w-administracji-publicznej-musi-byc-standardem/" rel="noopener noreferrer" target="_blank">AI transparency in public administration must be the standard</a></li><li
          class=""
          style="text-align: left;"
          value="5"
        >[PL] <a href="https://cert.pl/posts/2026/05/cra-dobre-praktyki/" rel="noopener noreferrer" target="_blank">CRA: good practices for managing software security</a></li><li
          class=""
          style="text-align: left;"
          value="6"
        >[PL] <a href="https://czasopismo.legeartis.org/2026/05/identyfikacja-osoby-numeru-telefonu-ustalenie-tozsamosci-dane-osobowe-wyrok-nsa/" rel="noopener noreferrer" target="_blank">Identifying someone by their phone number under GDPR</a></li><li
          class=""
          style="text-align: left;"
          value="7"
        >[PL] <a href="https://policja.pl/pol/aktualnosci/277555,Zatrzymania-w-sprawie-falszywych-alarmow-dotyczacych-zagrozenia-zdrowia-i-zycia.html" rel="noopener noreferrer" target="_blank">Arrests over false alerts about threats to life and health</a></li><li
          class=""
          style="text-align: left;"
          value="8"
        >[PL] <a href="https://polskieradio24.pl/artykul/3691584,alarm-u-rodziny-prezydenta-i-slady-w-sieci-ekspert-wyjasnia-mity-o-metodach-oszustow" rel="noopener noreferrer" target="_blank">Alarm at the president’s family home. An expert debunks myths about scam tactics</a></li><li
          class=""
          style="text-align: left;"
          value="9"
        >[PL] <a href="https://opensecurity.pl/otomoto-jak-wystawiajac-ogloszenie-wystawiamy-swoje-dane-na-tacy-oszustom/" rel="noopener noreferrer" target="_blank">Otomoto: posting a listing can expose your data to scammers</a></li><li
          class=""
          style="text-align: left;"
          value="10"
        >[PL] <a href="https://opensecurity.pl/oszustwo-na-pracownika-banku-zapis-i-analiza-rozmowy-ze-zlodziejami/" rel="noopener noreferrer" target="_blank">The bank employee scam: a call transcript and analysis</a></li><li
          class=""
          style="text-align: left;"
          value="11"
        >[PL] <a href="https://www.wnp.pl/tech/korporacje-oszustow-tak-wyglada-cyberprzestepczy-rynek-od-kulis,1065626.html" rel="noopener noreferrer" target="_blank">Scammers’ “corporations”: inside the cybercrime market</a></li><li
          class=""
          style="text-align: left;"
          value="12"
        >[PL] <a href="https://www.sirt.pl/pulapka-na-wlascicieli-domen-jak-dziala-phishing-na-home-pl/" rel="noopener noreferrer" target="_blank">A trap for domain owners: how phishing targeting home.pl works</a></li><li
          class=""
          style="text-align: left;"
          value="13"
        >[PL] <a href="https://demagog.org.pl/analizy_i_raporty/oszusci-w-sluzbie-rosji-jak-wyglada-podszywanie-sie-pod-znane-organizacje/" rel="noopener noreferrer" target="_blank">Scammers working for Russia: how they impersonate well-known organizations</a></li><li
          class=""
          style="text-align: left;"
          value="14"
        ><a href="https://www.ic3.gov/CSA/2026/260526.pdf" rel="noopener noreferrer" target="_blank">Silent Ransom Group impersonating IT personnel through social engineering</a></li><li
          class=""
          style="text-align: left;"
          value="15"
        ><a href="https://www.europol.europa.eu/media-press/newsroom/news/cybercriminal-vpn-used-ransomware-actors-dismantled-in-global-crackdown" rel="noopener noreferrer" target="_blank">Cybercriminal VPN used by ransomware actors dismantled in global crackdown</a></li><li
          class=""
          style="text-align: left;"
          value="16"
        ><a href="https://blog.gitguardian.com/how-we-got-a-cisa-github-leak-taken-down-in-26-hours/" rel="noopener noreferrer" target="_blank">How we got a CISA GitHub leak taken down in under a day</a></li><li
          class=""
          style="text-align: left;"
          value="17"
        ><a href="https://therecord.media/lithuania-investigates-theft-of-state-records" rel="noopener noreferrer" target="_blank">Lithuania investigates theft of 600,000 state registry records by foreign actor</a></li><li
          class=""
          style="text-align: left;"
          value="18"
        ><a href="https://www.justice.gov/usao-ak/pr/canadian-man-arrested-international-authorities-charged-administrating-kimwolf-ddos" rel="noopener noreferrer" target="_blank">Canadian man arrested by international authorities, charged with administrating KimWolf DDoS botnet</a></li><li
          class=""
          style="text-align: left;"
          value="19"
        ><a href="https://unit42.paloaltonetworks.com/fifa-world-cup-attack-surface/" rel="noopener noreferrer" target="_blank">2026 World Cup: Discussing the world’s biggest game’s attack surface</a></li><li
          class=""
          style="text-align: left;"
          value="20"
        ><a href="https://arstechnica.com/ai/2026/05/us-law-enforcement-warns-of-anti-tech-extremism-as-ai-hatred-grows/" rel="noopener noreferrer" target="_blank">US law enforcement warns of “anti-tech extremism” as AI hatred grows</a></li></ol><h3>For the more technical</h3><ol class="list-number"><li
          class=""
          style=""
          value="1"
        >[PL] <a href="https://adwersarz.pl/jak-stworzyc-domowy-radar-lotniczy/" rel="noopener noreferrer" target="_blank">How to set up a home flight tracking radar</a></li><li
          class=""
          style=""
          value="2"
        ><a href="https://www.bleepingcomputer.com/news/microsoft/microsoft-defender-can-now-automatically-isolate-hacked-endpoints/" rel="noopener noreferrer" target="_blank">Microsoft Defender can now automatically isolate hacked endpoints</a></li><li
          class=""
          style=""
          value="3"
        ><a href="https://www.rapid7.com/blog/post/ve-authenticated-rce-via-argument-injection-gogs-unfixed/" rel="noopener noreferrer" target="_blank">Authenticated RCE via argument injection in Gogs</a></li><li
          class=""
          style=""
          value="4"
        ><a href="https://hannesweissteiner.com/pdfs/frost.pdf" rel="noopener noreferrer" target="_blank">FROST: Fingerprinting Remotely using OPFS-based SSD Timing</a></li><li
          class=""
          style=""
          value="5"
        ><a href="https://arcticwolf.com/resources/blog/forticlient-ems-exploited-via-cve-2026-35616-to-deliver-ekz-infostealer-disguised-as-a-fortinet-patch/" rel="noopener noreferrer" target="_blank">FortiClient EMS exploited via CVE-2026-35616 to deliver EKZ infostealer disguised as a Fortinet patch</a></li><li
          class=""
          style=""
          value="6"
        ><a href="https://www.microsoft.com/en-us/security/blog/2026/05/22/from-edge-appliance-to-enterprise-compromise-multi-stage-linux-intrusion-via-f5-and-confluence/" rel="noopener noreferrer" target="_blank">From edge appliance to enterprise compromise: Multi-stage Linux intrusion via F5 and Confluence</a></li><li
          class=""
          style=""
          value="7"
        ><a href="https://securitylab.github.com/advisories/GHSL-2026-140_7-Zip/" rel="noopener noreferrer" target="_blank">Heap buffer write overflow in 7-Zip</a></li><li
          class=""
          style=""
          value="8"
        ><a href="https://www.microsoft.com/en-us/security/blog/2026/05/20/mini-shai-hulud-compromised-antv-npm-packages-enable-ci-cd-credential-theft/" rel="noopener noreferrer" target="_blank">Mini Shai-Hulud: Compromised @antv npm packages enable CI/CD credential theft</a></li><li
          class=""
          style=""
          value="9"
        ><a href="https://www.wiz.io/blog/mini-shai-hulud-strikes-again-tanstack-more-npm-packages-compromised" rel="noopener noreferrer" target="_blank">Mini Shai-Hulud strikes again: TanStack + more npm packages compromised</a></li><li
          class=""
          style=""
          value="10"
        ><a href="https://www.ox.security/blog/megalodon-cicd-malware-github/" rel="noopener noreferrer" target="_blank">Megalodon: New CI/CD malware spreads across GitHub, infecting ~5,000+ repositories</a></li><li
          class=""
          style=""
          value="11"
        ><a href="https://github.blog/changelog/2026-05-22-staged-publishing-and-new-install-time-controls-for-npm/" rel="noopener noreferrer" target="_blank">Staged publishing and new install-time controls for npm</a></li><li
          class=""
          style=""
          value="12"
        ><a href="https://www.ox.security/blog/malware-slop-new-malicious-npm-package-leaks-its-own-github-private-token/" rel="noopener noreferrer" target="_blank">Malware-slop: New malicious npm package leaks its own GitHub private token</a></li><li
          class=""
          style=""
          value="13"
        ><a href="https://www.stepsecurity.io/blog/laravel-lang-supply-chain-attack" rel="noopener noreferrer" target="_blank">Laravel-Lang supply chain attack: Every tag across multiple composer packages rewritten to steal CI secrets</a></li><li
          class=""
          style=""
          value="14"
        ><a href="https://blog.xlab.qianxin.com/ghost-cms-mass-compromised-via-cve-2026-26980-now-fueling-clickfix-attacks/" rel="noopener noreferrer" target="_blank">Ghost CMS mass compromised via CVE-2026-26980, now fueling ClickFix attacks</a></li><li
          class=""
          style=""
          value="15"
        ><a href="https://www.elastic.co/security-labs/tycoon-2fa-aitm-detection-engineering" rel="noopener noreferrer" target="_blank">Detecting Tycoon 2FA AiTM attacks across Entra ID and Google Workspace</a></li><li
          class=""
          style=""
          value="16"
        ><a href="https://www.fortra.com/blog/ratpressto-phishing-kit" rel="noopener noreferrer" target="_blank">RatPressto phish kit</a></li><li
          class=""
          style=""
          value="17"
        ><a href="https://www.sentinelone.com/blog/shub-reaper-macos-stealer-spoofs-apple-google-and-microsoft-in-a-single-attack-chain/" rel="noopener noreferrer" target="_blank">SHub Reaper: macOS stealer spoofs Apple, Google, and Microsoft in a single attack chain</a></li><li
          class=""
          style=""
          value="18"
        ><a href="https://www.microsoft.com/en-us/security/blog/2026/05/26/poisoned-search-results-gpu-mining-cryptojacking-campaign-abusing-screenconnect-microsoft-net-utilities/" rel="noopener noreferrer" target="_blank">From poisoned search results to GPU mining: A cryptojacking campaign abusing ScreenConnect and Microsoft .NET utilities</a></li><li
          class=""
          style=""
          value="19"
        ><a href="https://www.crowdstrike.com/en-us/blog/inside-crowdstrike-takedown-of-a-developer-targeting-botnet/" rel="noopener noreferrer" target="_blank">Disrupting Glassworm: Inside CrowdStrike’s takedown of a developer-targeting botnet</a></li><li
          class=""
          style=""
          value="20"
        ><a href="https://www.halcyon.ai/ransomware-research-reports/threat-assessment-the-gentlemen-ransomware-group" rel="noopener noreferrer" target="_blank">The Gentlemen ransomware group is scaling faster than any other group on record</a></li></ol><p>Did you enjoy this list? You can subscribe to one of our feeds on <a href="https://twitter.com/badcybercom">Twitter</a>, <a href="https://www.facebook.com/badcyber/">Facebook</a> or <a href="/feed/">RSS</a>.</p></div>]]></description></item><item><title>IT Security Weekend Catch Up – May 23, 2026</title><link>https://badcyber.com/it-security-weekend-catch-up-may-23-2026/</link><pubDate>Sat, 23 May 2026 23:30:00 +0200</pubDate><guid>https://badcyber.com/it-security-weekend-catch-up-may-23-2026/</guid><description><![CDATA[<div class="payload-richtext"><p>Afraid of missing important security news during the week? We&#39;re here to help! Every week we put together a curated list of all important security news in one place, for your reading pleasure. Enjoy!</p><h3>For the less technical</h3><ol class="list-number"><li
          class=""
          style="text-align: left;"
          value="1"
        >[PL] <a href="https://demagog.org.pl/analizy_i_raporty/e-karta-szczepien-wzbudza-kontrowersje-czy-to-infrastruktura-przymusu/" rel="noopener noreferrer" target="_blank">E-vaccination card sparks controversy. Is it &quot;coercion infrastructure&quot;?</a></li><li
          class=""
          style="text-align: left;"
          value="2"
        >[PL] <a href="https://www.rp.pl/sluzby/art44414001-raport-ws-pegasusa-przed-wakacjami-sluzby-zablokowaly-odtajnienie-danych" rel="noopener noreferrer" target="_blank">Pegasus report before summer break. Services block declassification of data</a></li><li
          class=""
          style="text-align: left;"
          value="3"
        >[PL] [VIDEO] <a href="https://www.youtube.com/watch?v=3Cp_ozOyj90" rel="noopener noreferrer" target="_blank">ABW report: Are we safe?</a></li><li
          class=""
          style="text-align: left;"
          value="4"
        >[PL] <a href="https://siecobywatelska.pl/ai-w-administracji/" rel="noopener noreferrer" target="_blank">Who uses AI, for what, and how in public institutions?</a></li><li
          class=""
          style="text-align: left;"
          value="5"
        >[PL] <a href="https://www.rp.pl/sluzby/art44424621-wojsko-stawia-na-sztuczna-inteligencje-tworza-wlasny-model-jezykowy" rel="noopener noreferrer" target="_blank">Military bets on artificial intelligence. Creates its own language model</a></li><li
          class=""
          style="text-align: left;"
          value="6"
        >[PL] <a href="https://www.wnp.pl/tech/za-kilkaset-milionow-zlotych-obroncy-polskiej-cyberprzestrzeni-zyskaja-nowa-siedzibe-dolozy-sie-ue,1064517.html" rel="noopener noreferrer" target="_blank">Warsaw will host NASK cybersecurity center</a></li><li
          class=""
          style="text-align: left;"
          value="7"
        >[PL] <a href="https://www.wnp.pl/tech/to-juz-nie-samotny-wilk-za-oszustwami-stoja-najczesciej-cyberprzestepcze-korporacje,1062161.html" rel="noopener noreferrer" target="_blank">Scams are most often run by cybercriminal corporations</a></li><li
          class=""
          style="text-align: left;"
          value="8"
        >[PL] <a href="https://oko.press/na-zywo/na-zywo-relacja/estonski-inspektorat-finansowy-zawiesza-licencje-zondacrypto" rel="noopener noreferrer" target="_blank">Estonian financial inspectorate suspends Zondacrypto license</a></li><li
          class=""
          style="text-align: left;"
          value="9"
        >[PL] <a href="https://oko.press/prezes-cinkciarz-pl-zatrzymany-w-usa" rel="noopener noreferrer" target="_blank">Cinkciarz.pl site CEO arrested. Lived a comfortable life in the USA</a></li><li
          class=""
          style=""
          value="10"
        ><a href="https://www.bleepingcomputer.com/news/security/grafana-says-stolen-github-token-let-hackers-steal-codebase/" rel="noopener noreferrer" target="_blank">Grafana says stolen GitHub token let hackers steal codebase</a></li><li
          class=""
          style=""
          value="11"
        ><a href="https://www.bleepingcomputer.com/news/security/github-confirms-breach-of-3-800-repos-via-malicious-vscode-extension/" rel="noopener noreferrer" target="_blank">GitHub confirms breach of 3,800 repos via malicious VSCode extension</a></li><li
          class=""
          style=""
          value="12"
        ><a href="https://arstechnica.com/security/2026/05/google-publishes-exploit-code-threatening-millions-of-chromium-users/" rel="noopener noreferrer" target="_blank">Google publishes exploit code threatening millions of Chromium users</a></li><li
          class=""
          style=""
          value="13"
        ><a href="https://blog.mozilla.org/netpolicy/files/2026/05/Mozilla-submission_-Growing-up-in-the-digital-world-consultation.pdf" rel="noopener noreferrer" target="_blank">Mozilla ’ s response to the UK Department of Science, Innovation and Technology’s consultation “Growing up in the online world”</a></li><li
          class=""
          style=""
          value="14"
        ><a href="https://istories.media/en/stories/2026/05/18/independent-review-confirms-critical-telegram-vulnerability/" rel="noopener noreferrer" target="_blank">Independent review confirms critical Telegram vulnerability</a></li><li
          class=""
          style=""
          value="15"
        ><a href="https://discord.com/blog/every-voice-and-video-call-on-discord-is-now-end-to-end-encrypted" rel="noopener noreferrer" target="_blank">Every voice and video call on Discord is now end-to-end encrypted</a></li></ol><h3>For the more technical</h3><ol class="list-number"><li
          class=""
          style=""
          value="1"
        >[PL] <a href="https://cert.pl/uploads/docs/Podsumowanie_CERT_Polska_2026_04.pdf" rel="noopener noreferrer" target="_blank">CERT Poland releases April 2026 monthly threat report</a></li><li
          class=""
          style=""
          value="2"
        >[PL] <a href="https://www.sirt.pl/flyhack-obiecuje-tanie-loty-dostarcza-malware-na-androida/" rel="noopener noreferrer" target="_blank">FlyHack ad offers cheap flights but delivers malicious Android app</a></li><li
          class=""
          style=""
          value="3"
        >[PL] <a href="https://nfsec.pl/security/6722" rel="noopener noreferrer" target="_blank">New vulnerabilities Fragnesia (CVE-2026-46300) and DirtyDecrypt (CVE-2026-31635) disclosed</a></li><li
          class=""
          style=""
          value="4"
        ><a href="https://www.usehacker.com/blog/open-webui-one-click-rce" rel="noopener noreferrer" target="_blank">Open WebUI - stored XSS via file upload that leads to RCE with 1-click</a></li><li
          class=""
          style=""
          value="5"
        ><a href="https://www.bleepingcomputer.com/news/microsoft/new-windows-miniplasma-zero-day-exploit-gives-system-access-poc-released/" rel="noopener noreferrer" target="_blank">New Windows &#39;MiniPlasma&#39; zero-day exploit gives SYSTEM access, PoC released</a></li><li
          class=""
          style=""
          value="6"
        ><a href="https://github.com/Delphos-Labs/disclosures/tree/main/DirtyCBC" rel="noopener noreferrer" target="_blank">DirtyCBC — Linux RxGK chosen-plaintext page-cache poisoning to root shell</a></li><li
          class=""
          style=""
          value="7"
        ><a href="https://www.cyera.com/blog/claw-chain-cyera-research-unveil-four-chainable-vulnerabilities-in-openclaw" rel="noopener noreferrer" target="_blank">Claw Chain: Cyera research unveil four chainable vulnerabilities in OpenClaw</a></li><li
          class=""
          style=""
          value="8"
        ><a href="https://oddguan.com/blog/second-time-same-sandbox-anthropic-claude-code-network-allowlist-bypass-data-exfiltration/" rel="noopener noreferrer" target="_blank">Second time, same sandbox: Another Anthropic Claude Code network sandbox bypass enables data exfiltration</a></li><li
          class=""
          style=""
          value="9"
        ><a href="https://www.microsoft.com/en-us/security/blog/2026/05/19/exposing-fox-tempest-a-malware-signing-service-operation/" rel="noopener noreferrer" target="_blank">Exposing Fox Tempest: A malware-signing service operation</a></li><li
          class=""
          style=""
          value="10"
        ><a href="https://guard.io/labs/accountdumpling---hunting-down-the-google-sent-phishing-wave-compromising-30-000-facebook-accounts" rel="noopener noreferrer" target="_blank">Hunting down the Google-sent phishing wave compromising 30,000+ Facebook accounts</a></li><li
          class=""
          style=""
          value="11"
        ><a href="https://unit42.paloaltonetworks.com/tracking-tampered-chef-clusters/" rel="noopener noreferrer" target="_blank">Tracking TamperedChef clusters via certificate and code reuse</a></li><li
          class=""
          style=""
          value="12"
        ><a href="https://blog.eclecticiq.com/seo-poisoning-campaign-leverages-gemini-and-claude-code-impersonation-to-deliver-infostealer" rel="noopener noreferrer" target="_blank">SEO poisoning campaign leverages Gemini and Claude Code impersonation to deliver infostealer</a></li><li
          class=""
          style=""
          value="13"
        ><a href="https://zimperium.com/blog/premium-deception-uncovering-a-global-android-carrier-billing-fraud-campaign" rel="noopener noreferrer" target="_blank">Premium Deception: Uncovering a global Android carrier billing fraud campaign</a></li><li
          class=""
          style=""
          value="14"
        ><a href="https://socket.dev/blog/antv-packages-compromised" rel="noopener noreferrer" target="_blank">Mini Shai-Hulud hits @antv ecosystem, 639 compromised npm package versions</a></li><li
          class=""
          style=""
          value="15"
        ><a href="https://unit42.paloaltonetworks.com/gremlin-stealer-evolution/" rel="noopener noreferrer" target="_blank">Gremlin Stealer&#39;s evolved tactics: Hiding in plain sight with resource files</a></li><li
          class=""
          style=""
          value="16"
        ><a href="https://labs.k7computing.com/index.php/fake-microsoft-teams-campaign-delivers-valleyrat-via-nsis-installer-and-dll-sideloading/" rel="noopener noreferrer" target="_blank">Fake Microsoft Teams campaign delivers ValleyRAT via NSIS installer and DLL sideloading</a></li><li
          class=""
          style=""
          value="17"
        ><a href="https://www.trendmicro.com/en_us/research/26/e/banana-rat.html" rel="noopener noreferrer" target="_blank">Inside SHADOW-WATER-063’s Banana RAT: From build server to banking fraud</a></li><li
          class=""
          style=""
          value="18"
        ><a href="https://www.sophos.com/en-us/blog/wanttocry-ransomware-remotely-encrypts-files" rel="noopener noreferrer" target="_blank">WantToCry ransomware remotely encrypts files</a></li><li
          class=""
          style=""
          value="19"
        ><a href="https://blog.barracuda.com/2026/05/20/threat-spotlight-cypherloc-scareware" rel="noopener noreferrer" target="_blank">CypherLoc, an advanced browser-locking scareware targeting millions</a></li><li
          class=""
          style=""
          value="20"
        ><a href="https://www.welivesecurity.com/en/eset-research/webworm-new-burrowing-techniques/" rel="noopener noreferrer" target="_blank">Webworm: New burrowing techniques</a></li><li
          class=""
          style=""
          value="21"
        ><a href="https://blog.talosintelligence.com/from-pdb-strings-to-maas-tracking-a-commodity-badiis-ecosystem/" rel="noopener noreferrer" target="_blank">From PDB strings to MaaS: Tracking a commodity BadIIS ecosystem used by Chinese-speaking threat</a></li><li
          class=""
          style=""
          value="22"
        ><a href="https://www.seqrite.com/blog/operation-dragon-whistle-ung002-targets-chinese-academia-via-weaponized-institutional-lure/" rel="noopener noreferrer" target="_blank">Operation Dragon Whistle: UNG0002 targets Chinese academia via weaponized institutional lure</a></li><li
          class=""
          style=""
          value="23"
        ><a href="https://www.securonix.com/blog/taxtrident-indian-fax-lures/" rel="noopener noreferrer" target="_blank">Analyzing TAX#TRIDENT: Fake Indian tax lures pivot across ZIP, VBS, stego and PHP-wrapped VBS delivery</a></li><li
          class=""
          style=""
          value="24"
        ><a href="https://www.microsoft.com/en-us/security/blog/2026/05/18/storm-2949-turned-compromised-identity-into-cloud-wide-breach/" rel="noopener noreferrer" target="_blank">How Storm-2949 turned a compromised identity into a cloud-wide breach</a></li><li
          class=""
          style=""
          value="25"
        ><a href="https://blog.synapticsystems.de/uac-0184-from-hta-to-a-signed-network-stack/" rel="noopener noreferrer" target="_blank">UAC-0184: From HTA to a signed network stack</a></li></ol><p>Did you enjoy this list? You can subscribe to one of our feeds on <a href="https://twitter.com/badcybercom">Twitter</a>, <a href="https://www.facebook.com/badcyber/">Facebook</a> or <a href="/feed/">RSS</a>.</p></div>]]></description></item><item><title>IT Security Weekend Catch Up – May 16, 2026</title><link>https://badcyber.com/it-security-weekend-catch-up-may-15-2026/</link><pubDate>Sat, 16 May 2026 23:30:00 +0200</pubDate><guid>https://badcyber.com/it-security-weekend-catch-up-may-15-2026/</guid><description><![CDATA[<div class="payload-richtext"><p>Afraid of missing important security news during the week? We&#39;re here to help! Every week we put together a curated list of all important security news in one place, for your reading pleasure. Enjoy!</p><h3>For the less technical</h3><ol class="list-number"><li
          class=""
          style=""
          value="1"
        ><a href="https://www.bleepingcomputer.com/news/security/electronics-giant-foxconn-confirms-cyberattack-on-north-american-factories/" rel="noopener noreferrer" target="_blank">Foxconn confirms cyberattack claimed by Nitrogen ransomware gang</a></li><li
          class=""
          style=""
          value="2"
        ><a href="https://www.zetter-zeroday.com/experts-confirm-the-fast16-malware-was-sabotaging-nuclear-weapons-tests-likely-in-iran/" rel="noopener noreferrer" target="_blank">Experts confirm the Fast16 malware was sabotaging nuclear weapons tests, likely in Iran</a></li><li
          class=""
          style=""
          value="3"
        ><a href="https://english.elpais.com/international/2026-05-07/hondurasgate-the-alleged-us-and-israeli-interference-plot-to-destabilize-mexico-and-other-progressive-governments.html" rel="noopener noreferrer" target="_blank">‘Hondurasgate,’ the alleged US and Israeli interference plot to destabilize Mexico and other progressive governments</a></li><li
          class=""
          style=""
          value="4"
        ><a href="https://www.bleepingcomputer.com/news/security/instructure-confirms-data-breach-shinyhunters-claims-attack/" rel="noopener noreferrer" target="_blank">Instructure confirms data breach, ShinyHunters claims attack</a></li></ol><h3>For the more technical</h3><ol class="list-number"><li
          class=""
          style=""
          value="1"
        ><a href="https://www.crowdstrike.com/en-us/blog/patch-tuesday-analysis-may-2026/" rel="noopener noreferrer" target="_blank">May 2026 Patch Tuesday: 30 critical vulnerabilities among 130 CVEs</a></li><li
          class=""
          style=""
          value="2"
        ><a href="https://github.com/Nightmare-Eclipse/YellowKey" rel="noopener noreferrer" target="_blank">YellowKey Bitlocker bypass vulnerability</a></li><li
          class=""
          style=""
          value="3"
        ><a href="https://github.com/Nightmare-Eclipse/GreenPlasma" rel="noopener noreferrer" target="_blank">GreenPlasma Windows CTFMON arbitrary section creation elevation of privileges vulnerability</a></li><li
          class=""
          style=""
          value="4"
        ><a href="https://github.com/v12-security/pocs/tree/main/fragnesia" rel="noopener noreferrer" target="_blank">Fragnesia (CVE-2026-46300), a universal Linux local privilege escalation exploit</a></li><li
          class=""
          style=""
          value="5"
        ><a href="https://depthfirst.com/research/nginx-rift-achieving-nginx-rce-via-an-18-year-old-vulnerability" rel="noopener noreferrer" target="_blank">NGINX Rift: Achieving NGINX remote code execution via an 18-year-old vulnerability</a></li><li
          class=""
          style=""
          value="6"
        ><a href="https://xbow.com/blog/dead-letter-cve-2026-45185-xbow-found-rce-exim" rel="noopener noreferrer" target="_blank">Dead.Letter (CVE-2026-45185) How XBOW found an unauthenticated RCE on Exim</a></li><li
          class=""
          style=""
          value="7"
        ><a href="https://layerxsecurity.com/blog/cursorjacking-every-cursor-user-is-vulnerable-to-api-key-theft-by-rogue-extensions/" rel="noopener noreferrer" target="_blank">CursorJacking: Every Cursor user is vulnerable to API key theft by rogue extensions</a></li><li
          class=""
          style=""
          value="8"
        ><a href="https://hackarcana.com/article/floating-friday-0.1-plus-0.2-is-not-0.3" rel="noopener noreferrer" target="_blank">Why 0.1 + 0.2 is not 0.3, or about floating-point numbers</a></li><li
          class=""
          style=""
          value="9"
        ><a href="https://www.zerodayinitiative.com/blog/2026/5/13/pwn2own-berlin-2026-day-one-results">Pwn2Own Berlin 2026 - Day One Results</a></li><li
          class=""
          style=""
          value="10"
        ><a href="https://www.zerodayinitiative.com/blog/2026/5/15/pwn2own-berlin-2026-day-two-results">Pwn2Own Berlin 2026 - Day Two Results</a></li><li
          class=""
          style=""
          value="11"
        ><a href="https://www.zerodayinitiative.com/blog/2026/5/16/pwn2own-berlin-2026-day-three-results-and-master-of-pwn">Pwn2Own Berlin 2026: Day Three Results and Master of Pwn</a></li><li
          class=""
          style=""
          value="12"
        ><a href="https://github.com/Bin4ry/yarbo-nat-in-my-back-yard" rel="noopener noreferrer" target="_blank">Yarbo - NAT in my back yard</a></li><li
          class=""
          style=""
          value="13"
        ><a href="https://layerxsecurity.com/blog/stealtok-130k-users-compromised-by-data-stealing-tiktok-video-downloaders/" rel="noopener noreferrer" target="_blank">StealTok: 130k users compromised by data stealing TikTok video “downloaders”</a></li><li
          class=""
          style=""
          value="14"
        ><a href="https://www.hiddenlayer.com/research/malware-found-in-trending-hugging-face-repository-open-oss-privacy-filter" rel="noopener noreferrer" target="_blank">Malware found in trending Hugging Face repository &quot;Open-OSS/privacy-filter&quot;</a></li><li
          class=""
          style=""
          value="15"
        ><a href="https://securelist.com/tr/daemon-tools-backdoor/119654/" rel="noopener noreferrer" target="_blank">DAEMON Tools software infected – supply chain attack ongoing since April 8, 2026</a></li><li
          class=""
          style=""
          value="16"
        ><a href="https://www.ox.security/blog/shai-hulud-open-source-malware-github/" rel="noopener noreferrer" target="_blank">Shai-Hulud goes open source: Malware creators leak their own code to GitHub</a></li><li
          class=""
          style=""
          value="17"
        ><a href="https://www.sentinelone.com/labs/cloud-worm-evicts-teampcp-and-steals-credentials-at-scale/" rel="noopener noreferrer" target="_blank">PCPJack: Cloud worm evicts TeamPCP and steals credentials at scale</a></li><li
          class=""
          style=""
          value="18"
        ><a href="https://cloud.google.com/blog/topics/threat-intelligence/ai-vulnerability-exploitation-initial-access" rel="noopener noreferrer" target="_blank">Adversaries leverage AI for vulnerability exploitation, augmented operations, and initial access</a></li><li
          class=""
          style=""
          value="19"
        ><a href="https://www.rapid7.com/blog/post/tr-it-support-dissecting-modelorat-campaign-microsoft-teams-compromise/" rel="noopener noreferrer" target="_blank">When IT support calls: Dissecting a ModeloRAT campaign from Teams to domain compromise</a></li><li
          class=""
          style=""
          value="20"
        ><a href="https://www.welivesecurity.com/en/eset-research/frostyneighbor-fresh-mischief-digital-shenanigans/" rel="noopener noreferrer" target="_blank">FrostyNeighbor: Fresh mischief and digital shenanigans</a></li></ol><p>Did you enjoy this list? You can subscribe to one of our feeds on <a href="https://twitter.com/badcybercom">Twitter</a>, <a href="https://www.facebook.com/badcyber/">Facebook</a> or <a href="/feed/">RSS</a>.</p></div>]]></description></item></channel></rss>