Microsoft Patch Tuesday May 2026 – 120 Vulnerabilities Fixed, Including 29 Critical RCE Flaws

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 12, 2026 Microsoft’s May 2026 Patch Tuesday lands with a heavy enterprise focus, fixing 120 vulnerabilities across Windows, Office, Azure, developer tools, and Microsoft 365 apps, including 29 remote code execution (RCE) flaws rated Critical. Unlike several recent cycles, …

Fortinet Patches Five Vulnerabilities Across FortiAP, FortiOS, and Enterprise Products

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 12, 2026 Fortinet released security advisories on May 12, 2026, addressing five vulnerabilities spanning its wireless access point controllers, network operating system, and enterprise management platforms, including a critical unauthenticated authorization bypass in FortiSandbox. Critical Flaw in FortiSandbox The …

Critical Fortinet FortiSandbox Vulnerability Enables Code Execution Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 12, 2026 A critical security flaw in Fortinet’s FortiSandbox platform is putting enterprise networks at serious risk, allowing unauthenticated attackers to execute arbitrary code or commands remotely, with no credentials required. Fortinet disclosed the vulnerability on May 12, 2026, …

Threat Actors Leverage Vercel’s AI Tools to Mass‑Produce Realistic Phishing Sites

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 12, 2026 A new and growing wave of phishing attacks is making credential theft easier than ever before. Threat actors are now using Vercel, a legitimate AI-powered web development platform, to build convincing fake login pages that closely mirror …

Zoom Rooms and Workplace Vulnerabilities Allow Attackers to Escalate Privileges

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 12, 2026 A series of newly discovered vulnerabilities in Zoom’s software ecosystem could hand local attackers the keys to your system. As organizations continue to rely heavily on virtual meetings, threat actors are constantly hunting for ways to exploit …

North Korean Hackers Weaponize Git Hooks to Deploy Cross-Platform Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 12, 2026 North Korean hackers have found a new way to hide malware inside the tools that software developers rely on every single day. Instead of sending phishing emails or planting fake links, they are now burying malicious code …

Malicious Chrome MV3 Extension Impersonates TronLink to Steal Crypto Wallet Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 12, 2026 A fake Chrome browser extension pretending to be the popular TronLink crypto wallet has been caught stealing sensitive wallet credentials from unsuspecting users. The malicious extension operates silently in the background, harvesting mnemonic phrases, private keys, and …

MistralAI PyPI Package Compromised to Inject Malicious Code – Microsoft Warns

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 12, 2026 A popular AI development library has been turned into a weapon. The mistralai PyPI package, version 2.4.6, was found to contain malicious code secretly injected by attackers, putting developers and organizations worldwide at serious risk. The compromise …

Claude’s Chrome Extension Vulnerability Allows Malicious Extensions to Steal Gmail and Drive Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 12, 2026 Researchers have exposed a catastrophic vulnerability hiding inside the “Claude in Chrome” extension. By weaponizing an otherwise harmless, zero-permission extension, invisible attackers can completely hijack the trusted AI assistant. Transform it into a malicious puppet that silently …

Critical PHP SOAP Extension Vulnerabilities Enables Remote Code Execution Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 12, 2026 A serious cluster of vulnerabilities has been uncovered in PHP’s core string processing and ext-soap components, putting numerous web servers at immediate risk of total takeover. While the SOAP extension has a notorious history of memory corruption …