Vulnerabilities
24 storiesCisco Catalyst SD-WAN Controller Auth Bypass Actively Exploited to Gain Admin Access
Maximum-severity Cisco SD-WAN authentication bypass grants instant admin access in limited but active attacks, requiring immediate patching priority.
THN (Feedburner)CVE-2026-2018210.010/10Microsoft warns of Exchange zero-day flaw exploited in attacks
Active exploitation targeting European enterprises using Exchange creates immediate board-level risk requiring emergency patching cycles.
BleepingComputer9/10Security researcher says Microsoft built a Bitlocker backdoor, releases exploit
Hacker News (Security)9/10Microsoft BitLocker – YellowKey zero-day exploit
Hacker News (Security)9/10YellowKey Bitlocker Bypass Vulnerability
Hacker News (Security)9/10CERT is releasing six CVEs for serious security vulnerabilities in dnsmasq
Hacker News (Security)9/10Dead.Letter (CVE-2026-45185) – How XBOW found an unauthenticated RCE on Exim
Hacker News (Security)CVE-2026-451859.89/10Maximum Severity Cisco SD-WAN Bug Exploited in the Wild
Second CVSS 10.0 Cisco SD-WAN exploit this year demonstrates attackers systematically targeting network infrastructure with maximum-severity authentication bypasses.
Dark Reading9/10On-Prem Microsoft Exchange Server CVE-2026-42897 Exploited via Crafted Email
On-premise Exchange Server spoofing vulnerability enables attacks via crafted emails, adding to Microsoft's growing legacy infrastructure burden.
THN (Feedburner)CVE-2026-428978.19/10Windows Zero-Days Expose BitLocker Bypasses And CTFMON Privilege Escalation
Anonymous researcher's BitLocker bypass zero-days challenge European data protection assumptions for Windows-encrypted enterprise storage.
THN (Feedburner)9/1018-Year-Old NGINX Rewrite Module Flaw Enables Unauthenticated RCE
Eighteen-year latent NGINX vulnerability demonstrates technical debt risk in European web infrastructure requiring immediate reverse proxy security audits.
THN (Feedburner)9/10[UPDATE] [hoch] AMD Prozessor: Mehrere Schwachstellen
AMD processor vulnerabilities enable privilege escalation to administrator level, requiring urgent firmware updates across enterprise server fleets before attackers weaponize hardware-level access.
CERT-Bund (BSI)9/10[NEU] [kritisch] Cisco Catalyst SD-WAN Controller: Schwachstelle ermöglicht Erlangen von Administratorrechten
Critical Cisco SD-WAN Controller flaw grants anonymous attackers full network control, risking complete compromise of hybrid cloud connectivity.
CERT-Bund (BSI)9/10[NEU] [hoch] Palo Alto Networks PAN-OS: Mehrere Schwachstellen
Palo Alto PAN-OS critical flaws could enable firewall takeover and network segmentation bypass, threatening perimeter security architecture.
CERT-Bund (BSI)9/10[UPDATE] [hoch] Node.js: Mehrere Schwachstellen
JavaScript runtime environments require urgent updates as Node.js vulnerabilities compromise application security boundaries in microservices and serverless deployments.
CERT-Bund (BSI)9/10[UPDATE] [kritisch] Microsoft Windows Produkte: Mehrere Schwachstellen
Critical Windows vulnerabilities designated by BSI require emergency patching across European enterprise infrastructure before weekend exploitation attempts.
CERT-Bund (BSI)9/10[NEU] [hoch] Apache Tomcat: Mehrere Schwachstellen
Web application servers across European enterprises require immediate patching as foundational servlet container vulnerabilities enable widespread compromise.
CERT-Bund (BSI)9/10[NEU] [hoch] Microsoft Exchange Server: Schwachstelle ermöglicht Cross-Site-Scripting- und Spoofing-Angriffe
Microsoft Exchange Server XSS flaw enables email-based phishing attacks that bypass traditional security controls in corporate environments.
CERT-Bund (BSI)8/10Zero-Day Exploit Against Windows BitLocker
Physical access requirements limit YellowKey's enterprise risk, but the bypass undermines Windows 11's default encryption for mobile workforce scenarios.
Schneier on Security8/10Patch Tuesday, May 2026 Edition
AI-assisted vulnerability discovery is accelerating patch cycles for major software vendors, potentially straining enterprise change management processes.
Krebs on Security7/10[UPDATE] [hoch] strongSwan (NetworkManager-Plugin): Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen
VPN security frameworks compromised as strongSwan NetworkManager vulnerability enables local privilege escalation in remote access infrastructures.
CERT-Bund (BSI)7/10[NEU] [mittel] Aruba ArubaOS: Mehrere Schwachstellen
Enterprise wireless infrastructure faces elevated risk as network access points become vectors for SQL injection and remote code execution attacks.
CERT-Bund (BSI)7/10[NEU] [hoch] BigBlueButton: Schwachstelle ermöglicht Cross-Site Scripting
Authenticated XSS vulnerability in video conferencing platform affects European organizations relying on remote collaboration infrastructure for business continuity.
CERT-Bund (BSI)6/10[NEU] [UNGEPATCHT] [mittel] aria2: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen
Unpatched aria2 download manager vulnerability remains exploitable with no fix timeline, creating persistent risk for automated download systems.
CERT-Bund (BSI)6/10
AI Security
12 storiesCompositional Jailbreaking: An Empirical Analysis of Mutator Chain Interactions in Aligned LLMs
Research demonstrates how combining multiple jailbreak techniques creates exponentially more effective attacks against LLM safety guardrails than isolated methods.
arXiv Crypto & Security9/10Who Owns This Agent? Tracing AI Agents Back to Their Owners
Autonomous AI agents lack traceability mechanisms to identify deploying accounts, creating accountability gaps for both malicious use and legitimate harm under EU AI Act liability frameworks.
arXiv Crypto & Security9/10A Cross-Modal Prompt Injection Attack against Large Vision-Language Models with Image-Only Perturbation
Image-only perturbations enable cross-modal prompt injection attacks against vision-language models without text manipulation, expanding attack vectors for multimodal AI systems.
arXiv Crypto & Security9/10How Dangerous Is Anthropic’s Mythos AI?
Anthropic's restricted release suggests AI vulnerability scanners may soon outperform human security teams, forcing enterprises to reconsider threat modeling assumptions.
Schneier on Security9/10FlipAttack: Jailbreak LLMs via Flipping
Text-flipping technique bypasses LLM safety guardrails by exploiting models' left-to-right processing bias, potentially enabling harmful output generation in enterprise AI deployments.
arXiv Crypto & Security9/10Probing Privacy Leaks in LLM-based Code Generation via Test Generation
Code-generating LLMs leak personally identifiable information from training data through generated test cases, posing GDPR compliance risks for European enterprises using AI coding assistants.
arXiv Crypto & Security8/10Do Coding Agents Understand Least-Privilege Authorization?
Enterprise AI coding assistants may lack understanding of authorization boundaries, creating privilege escalation risks in production environments.
arXiv Crypto & Security8/10The Adversarial Discount -- AI, Signal Correlation, and the Cybersecurity Arms Race
Contest-theoretic modeling reveals how AI amplification creates asymmetric advantages favoring attackers in multi-surface enterprise environments.
arXiv Crypto & Security8/10Breaking the Black Box: A Case Study in Red-Teaming a Government Education AI
Government AI chatbot compromise through social engineering to advanced tunneling reveals regulatory gaps in public sector AI deployment security standards.
SentinelOne Blog8/10[NEU] [mittel] Microsoft Word für Android und 365 Copilot: Mehrere Schwachstellen ermöglichen Darstellen falscher Informationen
AI-assisted productivity tools in European offices create new attack surface for misinformation campaigns targeting business decision-making.
CERT-Bund (BSI)8/10Experts warn of privacy risks as AI firms looks to connect to financial accounts
Financial account integration with LLMs creates new GDPR compliance surface for European enterprises considering AI-driven finance automation.
The Record8/10Introducing the updated AWS User Guide to Governance, Risk, and Compliance for Responsible AI Adoption
European FSI adopting AI for portfolio management and customer services faces heightened regulatory scrutiny under emerging EU AI Act compliance frameworks.
AWS Security Blog7/10
Threat Intel
9 storiesShai-Hulud Worm Clones Spread After Code Release
Public release of self-replicating worm source code creates immediate supply chain risk for European software development, potentially automating large-scale repository infections similar to SolarWinds impact.
Dark Reading9/10'FrostyNeighbor' APT Carefully Targets Govt Orgs in Poland, Ukraine
Belarussian state actors deploy sophisticated victim fingerprinting before launching espionage campaigns against Polish and Ukrainian government infrastructure.
Dark Reading9/10Turla Turns Kazuar Backdoor Into Modular P2P Botnet for Persistent Access
Russian Turla group evolves Kazuar backdoor into peer-to-peer botnet architecture, demonstrating advanced persistent threat modernization tactics.
THN (Feedburner)9/10Ghostwriter Targets Ukrainian Government With Geofenced PDF Phishing, Cobalt Strike
Belarus-linked Ghostwriter deploys geofenced PDF phishing against Ukrainian government, reflecting sophisticated targeting techniques in ongoing regional cyber warfare.
THN (Feedburner)9/10Kimsuky targets organizations with PebbleDash-based tools
North Korean Kimsuky group's tool evolution shows APT adaptation patterns that European organizations should integrate into threat modeling frameworks.
Securelist (Kaspersky)8/10SHub Reaper | macOS Stealer Spoofs Apple, Google, and Microsoft in a Single Attack Chain
macOS stealer bypassing Apple's Terminal protections demonstrates platform security controls failing against sophisticated credential harvesting campaigns targeting enterprise users.
SentinelOne Blog8/10Topical Shifts in the Dark Web: A Longitudinal Analysis of Content from the Cybercrime Ecosystem
Longitudinal analysis reveals how cybercrime forums pivot topic focus following law enforcement takedowns, providing predictive intelligence for threat actors' next moves.
arXiv Crypto & Security8/10Welcome to BlackFile: Inside a Vishing Extortion Operation
BlackFile's sophisticated voice phishing campaigns target organizational decision-makers directly, bypassing traditional email security controls favored by European enterprises.
Google Threat Intel8/10Gremlin Stealer's Evolved Tactics: Hiding in Plain Sight With Resource Files
Crypto-clipper functionality added to credential stealer targeting European financial transactions through session hijacking represents escalation in Mittelstand banking threats.
Unit 42 (Palo Alto)7/10
DevSecOps
7 storiesRisky Business #837 -- GitHub Actions footgun claims TanStack
TanStack compromise demonstrates how GitHub Actions misconfigurations create supply chain vulnerabilities affecting popular JavaScript frameworks used across European enterprises.
Risky Business9/10OpenAI asks macOS users to update after TanStack npm supply chain attack
OpenAI-prompted emergency patching reveals AI supply chain as high-value target, with implications for European enterprises deploying AI development frameworks.
The Record9/10[UPDATE] [hoch] Microsoft Developer Tools: Mehrere Schwachstellen
Software development environments across European enterprises face supply chain compromise through malicious code injection in trusted toolchains.
CERT-Bund (BSI)9/10Leaked Shai-Hulud malware fuels new npm infostealer campaign
Weekend npm package poisoning campaign leveraging leaked malware demonstrates how quickly public exploits translate into active supply chain attacks affecting European development pipelines.
BleepingComputer9/10Popular node-ipc npm package compromised to steal credentials
Supply chain compromise of widely-used IPC library demonstrates dependency risk management gaps in European software development pipelines.
BleepingComputer9/10Automating post-quantum cryptography readiness using AWS Config
Quantum threat timelines compress as NIST finalizes standards, making cryptographic inventory automation critical before mass Y2K-style migrations begin.
AWS Security Blog8/10Attackers Weaponize RubyGems for Data Dead Drops
RubyGems weaponization targeting UK government demonstrates how package repositories become covert communication channels for threat actor reconnaissance.
Dark Reading8/10
Research
3 storiesOpenAI’s GPT-5.5 is as Good as Mythos at Finding Security Vulnerabilities
UK evaluation confirms commercially available AI models now match specialized vulnerability discovery tools, democratizing code audit capabilities for both defenders and attackers.
Schneier on Security9/10A 0-click exploit chain for the Pixel 10: When a Door Closes, a Window Opens
Mobile device attack surface evolution demonstrates zero-interaction compromise paths despite security model hardening in latest generation hardware.
Project ZeroCVE-2025-549579.89/10Microsoft Exchange, Windows 11 hacked on second day of Pwn2Own
Multiple zero-days in enterprise-critical platforms signal coordinated vulnerability research targeting European business infrastructure.
BleepingComputer9/10
Cloud
3 stories[UPDATE] [hoch] Kiali für Red Hat OpenShift Service Mesh (Axios, Go, Follow-redirects): Mehrere Schwachstellen
Service mesh deployments require immediate patching as Kiali vulnerabilities enable container breakouts and privilege escalation in OpenShift environments.
CERT-Bund (BSI)9/10Microsoft rejects critical Azure vulnerability report, no CVE issued
Vendor resistance to vulnerability disclosure creates compliance gaps for European organizations relying on Azure backup services.
BleepingComputer8/10A Multi-Layer Cloud-IDS Pipeline with LLM and Adaptive Q-Learning Calibration
Multi-layer cloud intrusion detection system combines LLM analysis with adaptive Q-learning to address zero-day attacks across dynamic cloud architectures, enhancing SOC detection capabilities.
arXiv Crypto & Security8/10
OT/IoT Security
2 storiesFrom Backup Restoration to Minimum Viable Factory Recovery: A Systematization of Ransomware Recovery in Manufacturing Systems
Manufacturing ransomware recovery extends far beyond backup restoration to encompass coupled IT-OT systems, supply chains, and production capability restoration under NIS2 critical infrastructure requirements.
arXiv Crypto & Security9/10Taiwan Bullet Train Hack Highlights Cybersecurity Gaps in Rail Systems
Student's accidental radio interference disruption of Taiwan's high-speed rail exposes critical infrastructure vulnerability to simple RF attacks requiring minimal technical skill.
Dark Reading8/10