1. Security News – 2026-05-16
Sat May 16 2026 00:00:00 GMT+0000 (Coordinated Universal Time)
SecurityWeek
Latest cybersecurity news
In Other News: Big Tech vs Canada Encryption Bill, Cisco’s Free AI Security Spec, Audi App Flaws - May 15, 2026
Other noteworthy stories that might have slipped under the radar: Nvidia cloud gaming data breach, Android 17 security upgrades, FBI warning after ShinyHunters hacks Canvas.
The post In Other News: Big Tech vs Canada Encryption Bill, Cisco’s Free AI Security Spec, Audi App Flaws appeared first on SecurityWeek.
The Hacker News
Cybersecurity news and insights
Four OpenClaw Flaws Enable Data Theft, Privilege Escalation, and Persistence - May 15, 2026
Cybersecurity researchers have disclosed a set of four security flaws in OpenClaw that could be chained to achieve data theft, privilege escalation, and persistence.
The vulnerabilities, collectively dubbed
Claw Chain
by Cyera, can permit an attacker to establish a foothold, expose sensitive data, and plant backdoors. A brief description of the flaws is below -
SecurityWeek
Latest cybersecurity news
Microsoft Warns of Exchange Server Zero-Day Exploited in the Wild - May 15, 2026
Microsoft has shared mitigations for CVE-2026-42897 until a permanent patch can be released for affected Exchange Server versions.
The post Microsoft Warns of Exchange Server Zero-Day Exploited in the Wild appeared first on SecurityWeek.
American Lending Center Data Breach Affects 123,000 Individuals - May 15, 2026
The non-bank lender discovered a ransomware attack nearly one year ago, but only recently completed its investigation.
The post American Lending Center Data Breach Affects 123,000 Individuals appeared first on SecurityWeek.
Schneier on Security
Security news and analysis by Bruce Schneier
Bypassing On-Camera Age-Verification Checks - May 15, 2026
Some AI-based video age-verification checks can be fooled with a fake mustache.
The Hacker News
Cybersecurity news and insights
What 45 Days of Watching Your Own Tools Will Tell You About Your Real Attack Surface - May 15, 2026
In Your Biggest Security Risk Isn’t Malware — It’s What You Already Trust, we made a simple argument: the most dangerous activity inside most organizations no longer looks like an attack. It looks like administration. PowerShell, WMIC, netsh, Certutil, MSBuild — the same trusted utilities your IT team uses every day are also the preferred toolkit of modern threat actors. Bitdefender’s analysis
TanStack Supply Chain Attack Hits Two OpenAI Employee Devices, Forces macOS Updates - May 15, 2026
OpenAI has disclosed that two of its employee devices in its corporate environment were impacted via the Mini Shai-Hulud supply chain attack on TanStack, but noted that no user data, production systems, or intellectual property were compromised or modified in an unauthorized manner. “Upon identification of the malicious activity, we worked quickly to investigate, contain, and take steps to
SecurityWeek
Latest cybersecurity news
OpenAI Hit by TanStack Supply Chain Attack - May 15, 2026
Two employee devices were compromised in the attack, and credential material was stolen from OpenAI code repositories.
The post OpenAI Hit by TanStack Supply Chain Attack appeared first on SecurityWeek.
TeamPCP Ups the Game, Releases Shai-Hulud Worm’s Source Code - May 15, 2026
The hacking group is encouraging miscreants to use the code in supply chain attacks, promising monetary rewards.
The post TeamPCP Ups the Game, Releases Shai-Hulud Worm’s Source Code appeared first on SecurityWeek.
Chrome 148 Update Patches Critical Vulnerabilities - May 15, 2026
The refresh resolves critical-severity use-after-free and other types of bugs in various browser components.
The post Chrome 148 Update Patches Critical Vulnerabilities appeared first on SecurityWeek.
Cisco Patches Another SD-WAN Zero-Day, the Sixth Exploited in 2026 - May 15, 2026
The zero-day, tracked as CVE-2026-20182, has been exploited in targeted attacks by a sophisticated threat actor identified as UAT-8616.
The post Cisco Patches Another SD-WAN Zero-Day, the Sixth Exploited in 2026 appeared first on SecurityWeek.
The Hacker News
Cybersecurity news and insights
On-Prem Microsoft Exchange Server CVE-2026-42897 Exploited via Crafted Email - May 15, 2026
Microsoft has disclosed a new security vulnerability impacting on-premise versions of Exchange Server that it said has come under active exploitation in the wild. The vulnerability, tracked as CVE-2026-42897 (CVSS score: 8.1), has been described as a spoofing bug stemming from a cross-site scripting flaw. An anonymous researcher has been credited with discovering and reporting the issue. “
CISA Adds Cisco SD-WAN CVE-2026-20182 to KEV After Admin Access Exploits - May 15, 2026
The U.S.Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a newly disclosed vulnerability impacting Cisco Catalyst SD-WAN Controller to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to remediate the issue by May 17, 2026. The vulnerability is a critical authentication bypass tracked as CVE-2026-20182. It’s
Cisco Catalyst SD-WAN Controller Auth Bypass Actively Exploited to Gain Admin Access - May 14, 2026
Cisco has released updates to address a maximum-severity authentication bypass flaw in Catalyst SD-WAN Controller that it said has been exploited in limited attacks. The vulnerability, tracked as CVE-2026-20182, carries a CVSS score of 10.0. “A vulnerability in the peering authentication in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, and Cisco Catalyst SD-WAN Manager, formerly
Stealer Backdoor Found in 3 Node-IPC Versions Targeting Developer Secrets - May 14, 2026
Cybersecurity researchers are sounding the alarm about what has been described as “malicious activity” in newly published versions of node-ipc. According to Socket and StepSecurity, three different versions of the npm package have been confirmed as malicious -
node-ipc@9.1.6 node-ipc@9.2.3 node-ipc@12.0.1
“Early analysis indicates that node-ipc@9.1.6, node-ipc@9.2.3, and node-ipc@12.0.1
ThreatsDay Bulletin: PAN-OS RCE, Mythos cURL Bug, AI Tokenizer Attacks, and 10+ Stories - May 14, 2026
Everything is still on fire. This week feels dumb in the worst way — bad links, weak checks, fake help desks, shady forum posts, and people turning supply chain attacks into some cursed little game for clout and cash. Half of it feels new. Half of it feels like crap we should have fixed years ago. The mess keeps getting louder: users get tricked, boxes get popped, tools meant for normal work
Schneier on Security
Security news and analysis by Bruce Schneier
Upcoming Speaking Engagements - May 14, 2026
This is a current list of where and when I am scheduled to speak:
- I’m giving a virtual talk on “The Security of Trust in the Age of AI,” hosted by the Financial Women’s Association of New York, at 6:00 PM ET on May 21, 2026.
- I’m speaking at the Potsdam Conference on National Cybersecurity at the Hasso Plattner Institut in Potsdam, Germany. The event runs June 24–25, 2026, and my talk will be the evening of June 24.
- I’m speaking at the Digital Humanism Conference in Vienna, Austria, on Tuesday, June 26, 2026.
- I’m speaking at the ...
The Hacker News
Cybersecurity news and insights
Ghostwriter Targets Ukrainian Government With Geofenced PDF Phishing, Cobalt Strike - May 14, 2026
The Belarus-aligned threat group known as Ghostwriter has been attributed to a fresh set of attacks targeting governmental organizations in Ukraine. Active since at least 2016, Ghostwriter has been linked to both cyber espionage and influence operations targeting neighboring countries, particularly Ukraine. It’s also tracked under the monikers FrostyNeighbor, PUSHCHA, Storm-0257, TA445, UAC‑0057
SecurityWeek
Latest cybersecurity news
Enhancing Data Center Security Without Sacrificing Performance - May 14, 2026
For AI data centers, where the stakes are the highest and performance constraints are the tightest, security and performance are no longer a zero-sum game.
The post Enhancing Data Center Security Without Sacrificing Performance appeared first on SecurityWeek.
New Linux Kernel Vulnerability Fragnesia Allows Root Privilege Escalation - May 14, 2026
The vulnerability, tracked as CVE-2026-46300, is similar to the recently disclosed exploits named Dirty Frag and Copy Fail.
The post New Linux Kernel Vulnerability Fragnesia Allows Root Privilege Escalation appeared first on SecurityWeek.
Mythos Proves Potent in Vulnerability Discovery, Less Convincing Elsewhere - May 14, 2026
Independent benchmarking finds Mythos highly effective for source code audits, reverse engineering, and native-code analysis, though its exploit validation and reasoning capabilities remain inconsistent.
The post Mythos Proves Potent in Vulnerability Discovery, Less Convincing Elsewhere appeared first on SecurityWeek.
Schneier on Security
Security news and analysis by Bruce Schneier
How Dangerous Is Anthropic’s Mythos AI? - May 14, 2026
Last month, Anthropic made a remarkable announcement about its new model, Claude Mythos Preview: it was so good at finding security vulnerabilities in software that the company would not release it to the general public. Instead, it would only be available to a select group of companies to scan and fix their own software.
The announcement requires context—but it contained an essential truth.
While Anthropic’s model is really good at finding software vulnerabilities, so are other models. The UK’s AI Security Institute found that OpenAI’s GPT-5.5, already generally available, is comparable in capability. The company Aisle ...
OpenAI’s GPT-5.5 is as Good as Mythos at Finding Security Vulnerabilities - May 13, 2026
The UK’s AI Security Institute evaluated GPT-5.5’s ability to find security vulnerabilities, and found that it is comparable to Claude Mythos. Note that the OpenAI model is generally available.
Here is the Institute’s evaluation of Mythos.
And here is an analysis of a smaller, cheaper model. It requires more scaffolding from the prompter, but it is also just as good.