Security News
Latest Updates

Stay informed with the latest security trends and insights...

Latest Articles

Explore the most recent articles on security topics.

1. Security News – 2026-05-16

Sat May 16 2026 00:00:00 GMT+0000 (Coordinated Universal Time)

SecurityWeek

Latest cybersecurity news

In Other News: Big Tech vs Canada Encryption Bill, Cisco’s Free AI Security Spec, Audi App Flaws - May 15, 2026

Other noteworthy stories that might have slipped under the radar: Nvidia cloud gaming data breach, Android 17 security upgrades, FBI warning after ShinyHunters hacks Canvas.

The post In Other News: Big Tech vs Canada Encryption Bill, Cisco’s Free AI Security Spec, Audi App Flaws appeared first on SecurityWeek.

The Hacker News

Cybersecurity news and insights

Four OpenClaw Flaws Enable Data Theft, Privilege Escalation, and Persistence - May 15, 2026

Cybersecurity researchers have disclosed a set of four security flaws in OpenClaw that could be chained to achieve data theft, privilege escalation, and persistence.

The vulnerabilities, collectively dubbed

Claw Chain

by Cyera, can permit an attacker to establish a foothold, expose sensitive data, and plant backdoors. A brief description of the flaws is below -

SecurityWeek

Latest cybersecurity news

Microsoft Warns of Exchange Server Zero-Day Exploited in the Wild - May 15, 2026

Microsoft has shared mitigations for CVE-2026-42897 until a permanent patch can be released for affected Exchange Server versions.

The post Microsoft Warns of Exchange Server Zero-Day Exploited in the Wild appeared first on SecurityWeek.

American Lending Center Data Breach Affects 123,000 Individuals - May 15, 2026

The non-bank lender discovered a ransomware attack nearly one year ago, but only recently completed its investigation.

The post American Lending Center Data Breach Affects 123,000 Individuals appeared first on SecurityWeek.

Schneier on Security

Security news and analysis by Bruce Schneier

Bypassing On-Camera Age-Verification Checks - May 15, 2026

Some AI-based video age-verification checks can be fooled with a fake mustache.

The Hacker News

Cybersecurity news and insights

What 45 Days of Watching Your Own Tools Will Tell You About Your Real Attack Surface - May 15, 2026

In Your Biggest Security Risk Isn’t Malware — It’s What You Already Trust, we made a simple argument: the most dangerous activity inside most organizations no longer looks like an attack. It looks like administration. PowerShell, WMIC, netsh, Certutil, MSBuild — the same trusted utilities your IT team uses every day are also the preferred toolkit of modern threat actors. Bitdefender’s analysis

TanStack Supply Chain Attack Hits Two OpenAI Employee Devices, Forces macOS Updates - May 15, 2026

OpenAI has disclosed that two of its employee devices in its corporate environment were impacted via the Mini Shai-Hulud supply chain attack on TanStack, but noted that no user data, production systems, or intellectual property were compromised or modified in an unauthorized manner. “Upon identification of the malicious activity, we worked quickly to investigate, contain, and take steps to

SecurityWeek

Latest cybersecurity news

OpenAI Hit by TanStack Supply Chain Attack - May 15, 2026

Two employee devices were compromised in the attack, and credential material was stolen from OpenAI code repositories.

The post OpenAI Hit by TanStack Supply Chain Attack appeared first on SecurityWeek.

TeamPCP Ups the Game, Releases Shai-Hulud Worm’s Source Code - May 15, 2026

The hacking group is encouraging miscreants to use the code in supply chain attacks, promising monetary rewards.

The post TeamPCP Ups the Game, Releases Shai-Hulud Worm’s Source Code appeared first on SecurityWeek.

Chrome 148 Update Patches Critical Vulnerabilities - May 15, 2026

The refresh resolves critical-severity use-after-free and other types of bugs in various browser components.

The post Chrome 148 Update Patches Critical Vulnerabilities appeared first on SecurityWeek.

Cisco Patches Another SD-WAN Zero-Day, the Sixth Exploited in 2026 - May 15, 2026

The zero-day, tracked as CVE-2026-20182, has been exploited in targeted attacks by a sophisticated threat actor identified as UAT-8616.

The post Cisco Patches Another SD-WAN Zero-Day, the Sixth Exploited in 2026 appeared first on SecurityWeek.

The Hacker News

Cybersecurity news and insights

On-Prem Microsoft Exchange Server CVE-2026-42897 Exploited via Crafted Email - May 15, 2026

Microsoft has disclosed a new security vulnerability impacting on-premise versions of Exchange Server that it said has come under active exploitation in the wild. The vulnerability, tracked as CVE-2026-42897 (CVSS score: 8.1), has been described as a spoofing bug stemming from a cross-site scripting flaw. An anonymous researcher has been credited with discovering and reporting the issue. “

CISA Adds Cisco SD-WAN CVE-2026-20182 to KEV After Admin Access Exploits - May 15, 2026

The U.S.Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a newly disclosed vulnerability impacting Cisco Catalyst SD-WAN Controller to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to remediate the issue by May 17, 2026. The vulnerability is a critical authentication bypass tracked as CVE-2026-20182. It’s

Cisco Catalyst SD-WAN Controller Auth Bypass Actively Exploited to Gain Admin Access - May 14, 2026

Cisco has released updates to address a maximum-severity authentication bypass flaw in Catalyst SD-WAN Controller that it said has been exploited in limited attacks. The vulnerability, tracked as CVE-2026-20182, carries a CVSS score of 10.0. “A vulnerability in the peering authentication in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, and Cisco Catalyst SD-WAN Manager, formerly

Stealer Backdoor Found in 3 Node-IPC Versions Targeting Developer Secrets - May 14, 2026

Cybersecurity researchers are sounding the alarm about what has been described as “malicious activity” in newly published versions of node-ipc. According to Socket and StepSecurity, three different versions of the npm package have been confirmed as malicious -

node-ipc@9.1.6 node-ipc@9.2.3 node-ipc@12.0.1

“Early analysis indicates that node-ipc@9.1.6, node-ipc@9.2.3, and node-ipc@12.0.1

ThreatsDay Bulletin: PAN-OS RCE, Mythos cURL Bug, AI Tokenizer Attacks, and 10+ Stories - May 14, 2026

Everything is still on fire. This week feels dumb in the worst way — bad links, weak checks, fake help desks, shady forum posts, and people turning supply chain attacks into some cursed little game for clout and cash. Half of it feels new. Half of it feels like crap we should have fixed years ago. The mess keeps getting louder: users get tricked, boxes get popped, tools meant for normal work

Schneier on Security

Security news and analysis by Bruce Schneier

Upcoming Speaking Engagements - May 14, 2026

This is a current list of where and when I am scheduled to speak:

The Hacker News

Cybersecurity news and insights

Ghostwriter Targets Ukrainian Government With Geofenced PDF Phishing, Cobalt Strike - May 14, 2026

The Belarus-aligned threat group known as Ghostwriter has been attributed to a fresh set of attacks targeting governmental organizations in Ukraine. Active since at least 2016, Ghostwriter has been linked to both cyber espionage and influence operations targeting neighboring countries, particularly Ukraine. It’s also tracked under the monikers FrostyNeighbor, PUSHCHA, Storm-0257, TA445, UAC‑0057

SecurityWeek

Latest cybersecurity news

Enhancing Data Center Security Without Sacrificing Performance - May 14, 2026

For AI data centers, where the stakes are the highest and performance constraints are the tightest, security and performance are no longer a zero-sum game.

The post Enhancing Data Center Security Without Sacrificing Performance appeared first on SecurityWeek.

New Linux Kernel Vulnerability Fragnesia Allows Root Privilege Escalation - May 14, 2026

The vulnerability, tracked as CVE-2026-46300, is similar to the recently disclosed exploits named Dirty Frag and Copy Fail.

The post New Linux Kernel Vulnerability Fragnesia Allows Root Privilege Escalation appeared first on SecurityWeek.

Mythos Proves Potent in Vulnerability Discovery, Less Convincing Elsewhere - May 14, 2026

Independent benchmarking finds Mythos highly effective for source code audits, reverse engineering, and native-code analysis, though its exploit validation and reasoning capabilities remain inconsistent.

The post Mythos Proves Potent in Vulnerability Discovery, Less Convincing Elsewhere appeared first on SecurityWeek.

Schneier on Security

Security news and analysis by Bruce Schneier

How Dangerous Is Anthropic’s Mythos AI? - May 14, 2026

Last month, Anthropic made a remarkable announcement about its new model, Claude Mythos Preview: it was so good at finding security vulnerabilities in software that the company would not release it to the general public. Instead, it would only be available to a select group of companies to scan and fix their own software.

The announcement requires context—but it contained an essential truth.

While Anthropic’s model is really good at finding software vulnerabilities, so are other models. The UK’s AI Security Institute found that OpenAI’s GPT-5.5, already generally available, is comparable in capability. The company Aisle ...

OpenAI’s GPT-5.5 is as Good as Mythos at Finding Security Vulnerabilities - May 13, 2026

The UK’s AI Security Institute evaluated GPT-5.5’s ability to find security vulnerabilities, and found that it is comparable to Claude Mythos. Note that the OpenAI model is generally available.

Here is the Institute’s evaluation of Mythos.

And here is an analysis of a smaller, cheaper model. It requires more scaffolding from the prompter, but it is also just as good.

View All Security News

Upcoming Events

Check out the upcoming security conferences and webinars.

Security Tools

Discover the latest tools and resources for enhancing security.