🚨 WARNING — New HTTP/2 Bomb exploit targets NGINX, Apache HTTPD, Microsoft IIS, Envoy, and Cloudflare Pingora.
A single client can consume 32GB of server memory in roughly 20 seconds, causing remote DoS conditions.
Details here: https://t.co/58xDxAKRcZ
A vulnerability in Google’s Gemini voice assistant that could have allowed attackers to hijack the AI using messaging notifications. https://t.co/rzXLz6Y12m
A researcher has disclosed details of a severe VS Code vulnerability that can be exploited to steal GitHub tokens and access repositories. https://t.co/b5f3xTACfW
Many organizations invest in EDR but still lack real resilience. Lean teams drown in alerts, investigations lag, and responses are slow.
AI attacks are rising (67% of organizations affected), and 84% of major incidents now use living-off-the-land techniques.
Visibility alone isn’t enough.
Bitdefender GravityZone PHASR reduces attacker opportunities, while MDR adds 24x7 expert response.
Read: https://t.co/Z2ZajjJhjd
🔥 A new supply chain attack has hit official Red Hat Cloud Services npm packages.
The Miasma campaign, a fresh Mini Shai-Hulud variant, plants a malicious preinstall hook that steals GitHub secrets, cloud credentials, SSH keys, and more from developer and CI/CD environments.
It also adds persistence and downstream poisoning.
Read: https://t.co/P2YhSDOMRG
⚠️ Threat actors are actively exploiting a critical vulnerability in WP Maps Pro.
CVE-2026-8732 (CVSS 9.8) lets unauthenticated attackers create admin accounts and take over sites. It affects all versions up to 6.1.0.
Update to 6.1.1 now.
Read: https://t.co/TYJ0ve6SPK
Chrome 148 Update Patches 151 Vulnerabilities - Google this week released a fresh Chrome 148 update that resolves 151 vulnerabilities, including 22 critical-severity flaws. https://t.co/W2qeJubTm1
⚠️ JINX-0164, a new threat actor, targets crypto firms with fake LinkedIn recruiter messages and custom macOS malware.
Active since mid-2025, it deploys AUDIOFIX — a Python-based infostealer and RAT that steals credentials and targets CI/CD systems.
Microsoft has identified an active supply chain attack using typosquatted npm packages to steal cloud and CI/CD secrets. On May 28, 2026, a single threat actor operating under newly created maintainer alias vpmdhaj published 14 malicious packages within a 4-hour window. https://t.co/jC3f2m6EBp
The packages typosquat well-known OpenSearch, ElasticSearch, DevOps, and environment-configuration libraries, and several spoof the upstream OpenSearch project’s repository URL in their package.json to appear legitimate.
Once installed, the packages harvest AWS credentials, HashiCorp Vault tokens, and CI/CD pipeline secrets from the host environment. Read the blog from the Microsoft Defender Research team to an in-depth analysis, as well as mitigation, detection, and hunting guidance.
⚠️ Enterprise AI risk is heavily concentrated among a small group of power users and personal accounts.
LayerX Security’s 2026 report shows the top 5% of employees generate 144+ conversations each. Nearly half of all enterprise AI conversations use personal identities. Over 6% contain sensitive data.
Most organizations lack full visibility.
Full report: https://t.co/BxP0vrKnZl
@pymnts + Velera's #CreditUnion Tracker® reveals member expectations center on:
⚡ Real-time protection
💬 Seamless, transparent communication
🛡️ Proactive intervention before losses occur
What's your data-driven approach to #FraudPrevention look like? https://t.co/MXV6nzTAfc
NSA is releasing security design considerations for AI-driven automation leveraging MCP which, while simplifying the integration of diverse capabilities into powerful agent workflows, requires caution. Learn more: https://t.co/zn2DyUz5be