May 15, 2026 A chain of four critical vulnerabilities discovered in OpenClaw, one of the fastest-growing open-source platforms for autonomous AI agents, has left an estimated 245,000 publicly accessible server …
Shai-Hulud Worm Steals npm, GitHub, AWS, and Kubernetes Secrets From Developers
May 15, 2026 A dangerous new piece of malware called Shai-Hulud has emerged as one of the most alarming supply chain threats of 2026. It is a self-propagating worm that …
Microsoft Edge, Windows 11 and LiteLLM Hacked in Pwn2Own Berlin 2026
May 15, 2026 Pwn2Own Berlin 2026 opened with a surge of zero-day exploits targeting modern browsers, operating systems, and emerging AI platforms. On Day One alone, security researchers successfully hacked …
Tycoon 2FA Operators Adopt OAuth Device Code Phishing to Bypass MFA
Cybercriminals behind the Tycoon 2FA phishing kit have added a powerful new weapon to their playbook. By combining their well-known phishing infrastructure with OAuth Device Code abuse, they can now …
PraisonAI Vulnerability Exploited Within Hours of Public Disclosure
May 15, 2026 As artificial intelligence frameworks become central to enterprise operations, a critical flaw in a popular AI platform has exposed organizations to serious security risks from threat actors. …
Amazon Redshift JDBC Driver Vulnerabilities Enables Remote Code Execution Attacks
May 15, 2026 A critical vulnerability in the Amazon Redshift JDBC driver has put enterprise applications at severe risk of Remote Code Execution (RCE). Threat actors can exploit this newly …
Microsoft Details Kazuar Malware’s Modular Architecture and P2P Botnet Operations
May 15, 2026 A nation-state malware known as Kazuar has resurfaced with a far more dangerous design than anyone expected. What once started as a relatively standard backdoor has now …
VMware Fusion Vulnerability Let Attackers Escalate Privilege to Root
May 15, 2026 A high-severity privilege escalation vulnerability has been discovered in VMware Fusion, Broadcom’s popular macOS virtualization software, allowing local attackers to gain root-level access on affected systems. Tracked …
Hackers Abuse Scheduled Tasks to Maintain Persistence in FrostyNeighbor Attacks
May 15, 2026 A state-aligned hacking group known as FrostyNeighbor has resurfaced with a fresh wave of cyberattacks targeting government organizations in Ukraine, using a carefully designed infection chain that …
OpenAI Confirms Security Breach Via TanStack npm Supply Chain Attack
May 15, 2026 Two employee devices at OpenAI were compromised in a sweeping software supply chain attack targeting TanStack npm, but the AI company confirmed no user data, production systems, …
