Sandworm Hackers Pivot From Compromised IT Systems Toward Critical OT Assets

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 14, 2026 A Russian state-sponsored hacking group known as Sandworm has been caught making a calculated pivot from compromised IT networks into operational technology systems that control physical infrastructure. …

Chinese APT Hackers Exploit Microsoft Exchange to Breach Energy Sector Network

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 14, 2026 A Chinese state-linked hacking group known as FamousSparrow has quietly infiltrated an Azerbaijani oil and gas company, exploiting an unpatched Microsoft Exchange server to plant multiple backdoors …

New Malware Framework Enables Screen Control, Browser Artifact Access, and UAC Bypass

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 14, 2026 A newly uncovered malware framework is raising serious alarms across the cybersecurity community. Researchers have identified a previously unknown implant called TencShell, a sophisticated tool capable of …

Anthropic’s Mythos AI Reportedly Found macOS Vulnerabilities that Could Bypass Apple Security

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 14, 2026 Security researchers at Calif, a Palo Alto-based cybersecurity firm, have used techniques derived from an early version of Anthropic’s secretive Mythos AI model to uncover two previously …

Amazon Quick Bug Exposed AI Chat Agents to Users Blocked by Custom Permissions

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 14, 2026 Imagine locking your organization’s sensitive data behind a heavy vault door, only to realize the locking mechanism is entirely missing. Security researchers at Fog Security recently uncovered …

New Critical Exim Mailer Allows Remote Attacker to Execute Arbitrary Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 14, 2026 A critical vulnerability in the widely used Exim mail server allows unauthenticated attackers to execute arbitrary code and fully compromise exposed servers. Federico Kirschbaum, head of the …

Microsoft Research Shows AI Can Generate Realistic Command Lines and Process Telemetry

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 14, 2026 Artificial intelligence is now capable of generating attack telemetry that looks and behaves like the real thing, and that is changing how security teams think about testing …

Critical GitLab Vulnerabilities Enables XSS and Unauthenticated DoS Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 14, 2026 Threat actors are constantly hunting for infrastructure weaknesses, and a newly discovered batch of vulnerabilities in GitLab just handed them a dangerous roadmap. On May 13, 2026, …