Cyber Alert Security News Daily · 2026-05-27 Daily Digest
No significant updates today.

Created by CuratorMaster
Data breaches, hacks, and digital security
Explore the latest content tracked by Cyber Alert Security News Daily
No significant updates today.
A high-severity RCE flaw (CVE-2026-9089, CVSS 8.8) in ConnectWise Automate lets attackers bypass integrity checks via plugin and self-update features...
Ivanti released a security update for Ivanti Xtraction addressing CVE-2026-8043.
Attackers are refining multi-stage obfuscation across both niche and broad phishing campaigns.
Attackers hid Megalodon malware in commit messages using encoded, self-assembling base64 payloads that only triggered when repositories were fully...
A five-year study reveals exposed databases are almost always compromised, powering a low-yield but massive ransomware operation.
Attackers are shifting from stealing passwords to hijacking OAuth tokens via legitimate flows, rendering traditional MFA ineffective.
May campaigns turned everyday tools into access risks, from fake invites to fileless delivery.
AI infrastructure faces escalating risks from targeted supply chain attacks and critical open-source flaws.
Hackers claim to sell 340 million stolen OnlyFans records, yet experts are already skeptical about the hack's seriousness and scale. Verifying such massive leaks remains a core challenge.
Critical integer overflow in llama.cpp's GGUF parser enables arbitrary file seeks and out-of-bounds reads on 32-bit systems, hitting every Ollama and...
Two recent breaches by the same group highlight shared risks across sectors.
Microsoft has released patches addressing the critical remote code execution vulnerability CVE-2026-45659 in SharePoint across multiple server...
Attackers are exploiting AI coding tools through poisoned configs and symlink tricks, amplifying risks in the TrapDoor campaign.
Critical SQL injection in Ghost CMS (CVE-2026-26980) let attackers steal Admin API keys without authentication and inject ClickFix malware.
This week's incidents reveal ongoing PII exposure risks across sectors.
Two infrastructure-level flaws underscore the urgency of rapid updates across core systems.
Exploits drove 31% of initial breach access amid a massive surge in vulnerabilities.
Iran-linked Screening Serpens has intensified spear-phishing with tailored lures and six new RATs targeting aerospace, defense, and telecom in the US, Israel, and UAE. Companies in these sectors should harden defenses against impersonation attacks.