May 26, 2026
- Sent
- May 26, 2026 at 18:03
- Articles
- 11
- Recipients
- 6
- Delivered
- 6
In this issue
China's Webworm hits EU govs via Discord and Microsoft Graph
Chinese APT Webworm targets EU governments using Discord and Microsoft Graph API as covert command-and-control channels.
CVE-2026-31635 DirtyDecrypt: public PoC for Linux kernel LPE
Public PoC released for CVE-2026-31635 (DirtyDecrypt), a Linux kernel local privilege escalation flaw discovered by Zellic and V12.
Linux rootkits, router 0-day, AI intrusions: 25 attacks
Attackers exploit trusted tokens, packages, and accounts across 25 incidents reported this week.
RAMPART & Clarity: security testing for AI agents
Microsoft open-sources RAMPART and Clarity, two frameworks for security-testing AI agents at development time.
Repo jacking on bundler.io: open supply chain attack
Repo jacking on bundler.io let an attacker claim Bundler's orphaned GitHub repo and inject malicious code into any Ruby project referencing it.
Megalodon: 5,561 GitHub repos hit with malicious CI/CD workflows
5,718 malicious commits pushed to 5,561 GitHub repos in six hours to steal CI/CD pipeline secrets.
FBI shuts down First VPN used by dozens of ransomware gangs
FBI shut down First VPN, a criminal VPN service used by dozens of ransomware groups for network reconnaissance and corporate intrusions.
Infosecurity Europe 2026: what to watch
Infosecurity Europe 2026 brings together ransomware, offensive AI, and critical infrastructure defense as the dominant themes in London.
Jacob Butler arrested for running Kimwolf botnet
Canadian Jacob Butler, 23, arrested for running the Kimwolf botnet; US seeks extradition on federal hacking charges.
Anthropic's restricted Mythos model may ship inside Claude Code
Anthropic is preparing to roll out Mythos to Claude Code, a restricted model flagged for major security risks to public and private software.
SharePoint RCE CVE-2026-45659 patched — CVSS 8.8
Microsoft patches CVE-2026-45659 in SharePoint Server — RCE via untrusted data deserialization, CVSS 8.8, no special attack conditions required.











