Top Stories by Impact

🏢 Mandiant Threat Intel Critical

GTIG AI Threat Tracker: Adversaries Leverage AI for Vulnerability Exploitation, Augmented Operations, and Initial Access

Today · 14:00 UTC

Executive Summary Since our February 2026 report on AI-related threat activity, Google Threat Intelligence Group (GTIG) has continued to track a maturing transition from nascent AI…

Read full article →
🔐 The Hacker News Critical

cPanel CVE-2026-41940 Under Active Exploitation to Deploy Filemanager Backdoor

Today · 17:54 UTC

A threat actor named Mr_Rot13 has been attributed to the exploitation of a recently disclosed critical cPanel flaw to deploy a backdoor codenamed Filemanager on compromised environ…

Read full article →
🔐 The Hacker News Critical

Hackers Used AI to Develop First Known Zero-Day 2FA Bypass for Mass Exploitation

Today · 15:45 UTC

Google on Monday disclosed that it identified an unknown threat actor using a zero-day exploit that it said was likely developed with an artificial intelligence (AI) system, markin…

Read full article →
🔐 Dark Reading Critical

'Dirty Frag' Exploit Poised to Blow Up on Enterprise Linux Distros

Today · 15:05 UTC

The privilege escalation vulnerability, which is similar to other Linux flaws like Copy Fail and Dirty Pipe, may already be under limited exploitation.

Read full article →
🔐 CyberScoop Critical

Google spotted an AI-developed zero-day before attackers could use it

Today · 13:00 UTC

Researchers found artifacts in the code that proved AI was heavily involved. A prominent cybercrime group planned to exploit the zero-day en masse for financial gain. The post Goog…

Read full article →
🏢 Check Point Research Critical

11th May – Threat Intelligence Report

Today · 12:49 UTC

For the latest discoveries in cyber research for the week of 11th May, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Instructure, the US education tech…

Read full article →
🏢 Check Point Research High

The State of Ransomware – Q1 2026

Today · 09:58 UTC

Key Findings Ransomware in Q1 2026: Consolidation at Scale During the first quarter of 2026, we monitored more than 70 active data leak sites (DLS) that collectively listed 2,122 n…

Read full article →
🏢 Rapid7 Blog High

Final Countdown: Last Chance to Join the Rapid7 Global Cybersecurity Summit

Today · 12:54 UTC

The Rapid7 2026 Global Cybersecurity Summit is just around the corner, and with it, a final opportunity to join the conversations shaping how security teams are adapting to a rapid…

Read full article →
🔐

Cybersecurity

The Hacker News

1

cPanel CVE-2026-41940 Under Active Exploitation to Deploy Filemanager Backdoor

Critical

Today · 17:54 UTC

A threat actor named Mr_Rot13 has been attributed to the exploitation of a recently disclosed critical cPanel flaw to deploy a backdoor codenamed Filemanager on compromised environments. The attack exploits CVE-2026-4194…

Read full article →
2

Hackers Used AI to Develop First Known Zero-Day 2FA Bypass for Mass Exploitation

Critical

Today · 15:45 UTC

Google on Monday disclosed that it identified an unknown threat actor using a zero-day exploit that it said was likely developed with an artificial intelligence (AI) system, marking the first time the technology has been…

Read full article →
3

TeamPCP Compromises Checkmarx Jenkins AST Plugin Weeks After KICS Supply Chain Attack

High

Today · 18:30 UTC

Checkmarx has confirmed that a modified version of the Jenkins AST plugin was published to the Jenkins Marketplace. "If you are using Checkmarx Jenkins AST plugin, you need to ensure that you are using the version 2.0.13…

Read full article →

Dark Reading

1

'Dirty Frag' Exploit Poised to Blow Up on Enterprise Linux Distros

Critical

Today · 15:05 UTC

The privilege escalation vulnerability, which is similar to other Linux flaws like Copy Fail and Dirty Pipe, may already be under limited exploitation.

Read full article →
2

Tech Can't Stop These Threats — Your People Can

Medium

Today · 19:50 UTC

Security controls can do only so much. Here are four attacks where your employees are usually your first, and only, line of cyber defense.

Read full article →
3

FCC Softens Ban on Foreign-Made Routers

Today · 21:15 UTC

The Federal Communications Commission eased some restrictions and pushed back deadlines for foreign router manufacturers, but the ban is still in place.

Read full article →

CyberScoop

1

Google spotted an AI-developed zero-day before attackers could use it

Critical

Today · 13:00 UTC

Researchers found artifacts in the code that proved AI was heavily involved. A prominent cybercrime group planned to exploit the zero-day en masse for financial gain. The post Google spotted an AI-developed zero-day befo…

Read full article →
2

Pressure mounts on Canvas as data leak extortion deadline looms

High

Today · 23:31 UTC

Attackers affiliated with The Com are threatening to leak data from more than 8,800 school systems if Instructure doesn’t pay a ransom. The post Pressure mounts on Canvas as data leak extortion deadline looms appeared fi…

Read full article →
3

The missing cybersecurity leader in small business

Today · 10:00 UTC

As AI and quantum threats target the backbone of the American economy, Washington must provide the guidance and incentives necessary for SMBs to access executive-level cyber expertise. The post The missing cybersecurity…

Read full article →

SANS Internet Storm Center

1

Apple Patches Everything, (Mon, May 11th)

Medium

Today · 22:19 UTC

Apple today released its typical feature update across it&#;x26;#;39;s operating systems (iOS, iPadOS, macOS, tvOS, watchOS, vision OS). With this update, Apple patched 84 different vulnerabilities. Updates are available…

Read full article →
2

Why we use CAPTCHAs, (Mon, May 11th)

Today · 14:20 UTC

A few months ago, I implemented Cloudflare&#;x26;#;39;s Turnstile CAPTCHA on some pages. The reason for implementing these CAPTCHAs is obvious: Bots make up a large percentage of traffic and affect site performance.

Read full article →
3

ISC Stormcast For Monday, May 11th, 2026 https://isc.sans.edu/podcastdetail/9926, (Mon, May 11th)

Today · 02:15 UTC

(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.

Read full article →

Ars Technica

1

Linux bitten by second severe vulnerability in as many weeks

Medium

Today · 22:28 UTC

Production-version patches are coming online and should be installed pronto.

Read full article →
2

After banning foreign routers, FCC says existing ones can get updates until 2029

Medium

Today · 20:48 UTC

FCC extends waiver allowing routers and drones to get patches for two more years.

Read full article →
3

Audi has a new Q9 flagship coming soon: Here's its interior

Today · 22:01 UTC

Audi made sure to consult American tastes for its first full-size SUV.

Read full article →

BleepingComputer

1

New GhostLock tool abuses Windows API to block file access

Medium

Today · 22:02 UTC

A security researcher has released a proof-of-concept tool named GhostLock that demonstrates how a legitimate Windows file API can be abused in attacks to block access to files stored locally or on SMB network shares. [.…

Read full article →
2

Official CheckMarx Jenkins package compromised with infostealer

Today · 22:03 UTC

Checkmarx warned over the weekend that a rogue version of its Jenkins Application Security Testing (AST) plugin had been published on the Jenkins Marketplace. [...]

Read full article →
3

GM agrees to $12.75M California settlement over sale of drivers’ data

Today · 22:40 UTC

California Attorney General Rob Bonta announced a proposed $12.75 million settlement agreement with General Motors (GM) over allegations that the company violated the California Consumer Privacy Act (CCPA). [...]

Read full article →

Infosecurity Magazine

1

Rushed Patches Follow Broken Embargo on New Linux Kernel Vulnerabilities

Today · 14:30 UTC

Two new high-severity vulnerabilities, dubbed ’Dirty Frag’ when chained, have been found in the Linux kernel, affecting most Linux distributions

Read full article →
2

TrickMo Variant Routes Android Trojan Traffic Through TON

Today · 15:15 UTC

ThreatFabric finds new TrickMo Android banking trojan variant routing C2 through The Open Network

Read full article →
3

Fake Claude Code Page Pushes PowerShell Stealer at Devs

Today · 14:00 UTC

Ontinue uncovers fake Claude Code installer pushing PowerShell stealer abusing Chrome's IElevator2

Read full article →

Cybercrime Magazine

1

The Answer To India’s Cybersecurity Leadership Gap: AI And Managed Services

Today · 12:26 UTC

This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – May. 11, 2026 – Read the full story from Enterprise Times The 2026 CISO Report from Cybersecurity Ventures in partnership with Sophos…

Read full article →

Schneier on Security

1

LLMs and Text-in-Text Steganography

Today · 11:04 UTC

Turns out that LLMs are really good at hiding text messages in other text messages.

Read full article →
🤖

AI & Technology

The Verge

1

OpenAI just released its answer to Claude Mythos

High

Today · 23:05 UTC

OpenAI is launching Daybreak, an AI initiative focused on detecting and patching vulnerabilities before attackers find them. Daybreak uses the Codex Security AI agent that launched in March to create a threat model based…

Read full article →
2

Yarbo says it will remove the intentional backdoor from its robot lawn mower

Medium

Today · 22:40 UTC

The company behind the robot lawn mower that ran me over has changed its tune. Yarbo now plans to completely remove the remote backdoor access that could have let bad actors reprogram the robot over the internet. Yarbo c…

Read full article →
3

Here’s what Mira Murati’s AI company is up to

Today · 22:19 UTC

Thinking Machines, the AI company founded by former OpenAI CTO Mira Murati, announced Monday that it's working on something called "interaction models." The idea behind interaction models, according to Thinking Machines,…

Read full article →

AI News

1

Bain sees US$100 billion SaaS market in agentic AI automation

Medium

Today · 10:00 UTC

Bain & Company has estimated a US$100 billion market in the US for SaaS companies using agentic AI. The firm said the market is tied to automating coordination work in enterprise systems. The estimate comes from the seco…

Read full article →
2

AI automates HR compliance, except for the area tech companies need

Today · 14:34 UTC

Artificial intelligence is transforming how companies handle compliance. Background checks run in real-time. Payroll monitoring flags discrepancies automatically. Predictive analytics anticipate employee churn before it…

Read full article →

The Guardian Technology

1

Palantir’s access to identifiable NHS England patient data is ‘dangerous’, MPs say

Medium

Today · 12:01 UTC

Health service has given US tech firm ‘unlimited access’ to certain data to build integrated platform, according to reportsUK politics live – latest updatesMPs have warned that an NHS decision to grant Palantir access to…

Read full article →
2

Molière Ex Machina: AI used to create ‘new work’ by beloved French playwright

Today · 12:29 UTC

Comedy debuts at Versailles featuring dialogue, music, costumes and scenery created with help of AI tool Le ChatEurope live – latest updatesMolière is to the French what Shakespeare is to the English: the last word in hi…

Read full article →
3

Forget the AI job apocalypse. AI’s real threat is worker control and surveillance

Today · 11:00 UTC

A new divide is emerging: between workers who use AI at work and those who are managed by itThe real danger that artificial intelligence poses to work is not just job loss – it is the growing divide between people who us…

Read full article →

MIT Technology Review AI

1

Fostering breakthrough AI innovation through customer-back engineering

Today · 13:33 UTC

Despite years of digitization, organizations capture less than one-third of the value expected from digital investments, according to McKinsey research. That’s because most big companies begin with technological capabili…

Read full article →
2

Three things in AI to watch, according to a Nobel-winning economist

Today · 17:35 UTC

This story originally appeared in The Algorithm, our weekly newsletter on AI. To get stories like this in your inbox first, sign up here. A few months before he was awarded the Nobel Prize in economics in 2024, Daron Ace…

Read full article →
3

Implementing advanced AI technologies in finance

Today · 13:00 UTC

In finance departments that have long been defined by precision and control, AI has arrived less as a neatly managed upgrade than as a quiet insurgency. Employees are already using it while leadership races to impose str…

Read full article →

ITNews Australia

1

EU says OpenAI offers to open access to cyber security model

Today · 20:44 UTC

Anthropic not there yet.

Read full article →
2

Lendi Group runs first project through "agentic SDLC"

Today · 20:47 UTC

Software delivery gets an AI makeover.

Read full article →
3

CBA opens a second US 'tech hub'

Today · 20:35 UTC

Aims to get even closer to AI firms and development ecosystems.

Read full article →

Wired AI

1

Ilya Sutskever Stands by His Role in Sam Altman’s OpenAI Ouster: ‘I Didn’t Want It to Be Destroyed’

Today · 23:51 UTC

The former OpenAI chief scientist may be estranged from the company, but he still came to its defense as he testified on Monday.

Read full article →
2

CUDA Proves Nvidia Is a Software Company

Today · 10:00 UTC

There’s a deep, forbidding moat that surrounds Nvidia—and it has nothing to do with hardware.

Read full article →
3

I Work in Hollywood. Everyone Who Used to Make TV Is Now Secretly Training AI

Today · 10:00 UTC

For screenwriters like me—and job seekers all over—AI gig work is the new waiting tables. In eight months, I’ve done 20 of these soul-crushing contracts for five different platforms. It’s bad.

Read full article →

TechCrunch AI

1

Digg tries again, this time as an AI news aggregator

Today · 17:02 UTC

In an email to beta testers, the company said the site's goal is to "track the most influential voices in a space" and to surface the news that's actually worth "paying attention to."

Read full article →
2

There aren’t enough rockets for space data centers — Cowboy Space raised $275M to build them

Today · 13:00 UTC

The apparently insatiable demand for AI compute has data center entrepreneurs looking to the stars. There's a key problem: There aren't enough rockets to put data centers in orbit around Earth, and they're too expensive.

Read full article →
3

Get ready for the whisper-filled office of the future

Yesterday · 21:15 UTC

How will work setups change if we spend more and more time talking to our computers?

Read full article →

Ars Technica AI

1

Data center guzzled 30 million gallons of water and nobody noticed for months

Today · 20:37 UTC

Can AI save us from the AI industry’s endless thirst for water? Outlook not so good.

Read full article →

Import AI

1

Import AI 456: RSI and economic growth; radical optionality for AI regulation; and a neural computer

Today · 12:46 UTC

What laws does superintelligence demand?

Read full article →

NVIDIA AI Blog

1

‘Your Career Starts at the Beginning of the AI Revolution,’ NVIDIA CEO Tells Graduates

Yesterday · 22:00 UTC

“You are entering the world at an extraordinary moment,” NVIDIA founder and CEO Jensen Huang told graduates as he delivered the keynote address at Carnegie Mellon University’s 128th commencement ceremony on Sunday. “A ne…

Read full article →

ABC Technology (AU)

1

Darwin company's $50 million plan to make diesel from gas condensate

Today · 23:35 UTC

Global Resource Recovery NT says production of the first diesel made from Central Australian gas condensate will leave Darwin in July.

Read full article →
2

Apple's Tim Cook and Tesla's Elon Musk among top US CEOs to accompany Trump to China

Today · 21:08 UTC

According to a list shared by a White House official, speaking on condition of anonymity, Elon Musk and Tim Cook will be accompanied by 15 other chief executive officers when Donald Trump visits China.

Read full article →
3

Small robots drafted to help tackle looming renewable skills shortage

Today · 21:00 UTC

Students are using tiny, programmable robots to code in a bid to encourage them to consider careers in renewable energy due to predicted skill shortages.

Read full article →
🏢

Vendor Security

Mandiant Threat Intel

1

GTIG AI Threat Tracker: Adversaries Leverage AI for Vulnerability Exploitation, Augmented Operations, and Initial Access

Critical

Today · 14:00 UTC

Executive Summary Since our February 2026 report on AI-related threat activity, Google Threat Intelligence Group (GTIG) has continued to track a maturing transition from nascent AI-enabled operations to the industrial-sc…

Read full article →

Check Point Research

1

11th May – Threat Intelligence Report

Critical

Today · 12:49 UTC

For the latest discoveries in cyber research for the week of 11th May, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Instructure, the US education technology company behind the Canvas learnin…

Read full article →
2

The State of Ransomware – Q1 2026

High

Today · 09:58 UTC

Key Findings Ransomware in Q1 2026: Consolidation at Scale During the first quarter of 2026, we monitored more than 70 active data leak sites (DLS) that collectively listed 2,122 new victims. This figure represents a 12.…

Read full article →

Rapid7 Blog

1

Final Countdown: Last Chance to Join the Rapid7 Global Cybersecurity Summit

High

Today · 12:54 UTC

The Rapid7 2026 Global Cybersecurity Summit is just around the corner, and with it, a final opportunity to join the conversations shaping how security teams are adapting to a rapidly changing landscape.Over the past few…

Read full article →

StepSecurity

1

Mini Shai-Hulud Is Back: A Self-Spreading Supply Chain Attack Compromises TanStack npm Packages

High

Today · 23:57 UTC

The Mini Shai-Hulud worm is actively compromising legitimate npm packages by hijacking CI/CD pipelines and stealing developer secrets. StepSecurity's OSS Package Security Feed first detected the attack in official @tanst…

Read full article →

Palo Alto Unit 42

1

Inside AD CS Escalation: Unpacking Advanced Misuse Techniques and Tools

High

Today · 22:00 UTC

Unit 42 analyzes AD CS exploitation through template misconfigurations and shadow credential misuse while offering behavioral detection for defenders. The post Inside AD CS Escalation: Unpacking Advanced Misuse Technique…

Read full article →

AWS Security

1

Complimentary virtual training: Get hands-on with AWS Security Services

Today · 17:58 UTC

If you’re looking to strengthen your organization’s security posture on Amazon Web Services (AWS) but aren’t sure where to start, then we’re here to help. Security Activation Days are complimentary, virtual, hands-on wor…

Read full article →

OpenAI News

1

How ChatGPT adoption broadened in early 2026

Today · 15:00 UTC

ChatGPT adoption surged in Q1 2026, with fastest growth among users over 35 and more balanced gender usage, signaling broader mainstream AI adoption.

Read full article →
2

How enterprises are scaling AI

Today · 10:00 UTC

How enterprises scale AI: from early experiments to compounding impact through trust, governance, workflow design, and quality at scale.

Read full article →
3

OpenAI Campus Network: Student club interest form

Today · 10:00 UTC

Join the OpenAI Campus Network—connect student clubs worldwide, access AI tools, host events, and build an AI-powered campus community.

Read full article →