Anthropic’s Claude Mythos Preview Uncovers 10,000+ 0-Days in Project Glasswing

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 23, 2026 Anthropic has revealed the staggering initial results of Project Glasswing, a collaborative cybersecurity initiative designed to secure critical infrastructure using advanced AI before malicious actors can exploit it. In its first month, the project leveraged the unreleased …

Hackers Abuse Middle East Telecom Networks for Large-Scale Command-and-Control Operations

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Hackers are using telecom networks and hosting providers across the Middle East as a foundation for massive command-and-control operations, turning trusted infrastructure into a launchpad for cyberattacks. A newly released threat intelligence report reveals that more than 1,350 active command-and-control …

World Cup Phishing Campaign Nearly Triples With 203 Unique IP Addresses

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 22, 2026 A large-scale phishing campaign targeting the 2026 FIFA World Cup has grown far beyond what security researchers originally thought. What began as a documented set of 79 fraudulent domains has ballooned into a network of at least …

Hackers Use Six-Layer Persistence to Maintain Access on Compromised FreePBX Systems

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 22, 2026 A hacker group known as INJ3CTOR3 has been running an active campaign against FreePBX systems, deploying a newly discovered PHP webshell called JOMANGY that uses six separate persistence layers to stay embedded on compromised servers. The campaign …

Ubiquiti Patches Critical UniFi OS Vulnerabilities Allowing Remote Privilege Escalation

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 22, 2026 Ubiquiti Networks has released urgent security updates to address a series of highly critical vulnerabilities affecting its UniFi OS platform. These severe flaws could allow unauthenticated, remote attackers to execute arbitrary code, escalate privileges, and severely compromise …

LiteSpeed cPanel Plugin 0-Day Exploited in the wild to Gain Server Root Access

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 22, 2026 LiteSpeed has disclosed and patched a critical 0‑day privilege escalation flaw in its user-end cPanel plugin that is already being actively exploited to gain root access on Linux hosting servers. The bug is tracked as CVE‑2026‑48172 and …

CISA adds Langflow Origin Validation Flaw to Known Exploited Vulnerabilities Catalog

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 22, 2026  The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical Langflow vulnerability, tracked as CVE-2025-34291, to its Known Exploited Vulnerabilities (KEV) Catalog, signaling active exploitation and urging organizations to remediate immediately. The flaw affects Langflow, …

Lawmakers Demand Answers as CISA Tries to Contain Data Leak

Blog WriterCybersecurity News - Original News Source is krebsonsecurity.com

Lawmakers in both houses of Congress are demanding answers from the U.S. Cybersecurity & Infrastructure Security Agency (CISA) after KrebsOnSecurity reported this week that a CISA contractor intentionally published AWS GovCloud keys and a vast trove of other agency secrets …

Android Malware Silently Subscribes Victims to Premium Services Without Consent

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 22, 2026 A newly uncovered Android malware campaign has been quietly draining money from mobile users across four countries by signing them up for paid services they never asked for. The operation ran for nearly ten months and carried …

Operation Dragon Whistle Uses Malicious LNK Files to Target Changzhou University

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 22, 2026 A newly uncovered cyber operation has raised concerns among security professionals after a coordinated wave of attacks targeted government institutions in Pakistan. The campaign, now tracked as Operation Dragon Whistle, used highly convincing phishing emails to trick …