NGINX CVE-2026-42945 Actively Exploited — Heap Buffer Overflow Enables Worker Crashes and Possible RCE
A critical heap buffer overflow vulnerability in NGINX, tracked as CVE-2026-42945 (CVSS 9.2), is now being actively exploited in the wild just days after public disclosure. The flaw affects NGINX…
New “Sorry” Ransomware Gang Weaponizes cPanel Authentication Bypass Within 48 Hours of Disclosure
An emerging ransomware group calling itself “Sorry” has surfaced with an aggressive opportunistic strategy: exploiting the cPanel authentication bypass vulnerability (CVE-2026-41940) within just 48 hours of its public disclosure. The…
Researchers Use Anthropic’s Claude Mythos to Crack Apple M5 Memory Security — Root Access Achieved in 5 Days
Summary A security research team called Calif has achieved the first public privilege escalation exploit on Apple’s M5 silicon, bypassing the chip’s Memory Integrity Enforcement (MIE) — a hardware-assisted memory…
Microsoft Exchange Server Zero-Day (CVE-2026-42897) Actively Exploited — CISA Orders Emergency Mitigation
Summary Microsoft has confirmed that a high-severity zero-day vulnerability in Exchange Server, tracked as CVE-2026-42897, is being actively exploited in the wild. The flaw is a cross-site scripting (XSS) vulnerability…
UK Regulators Sound the Alarm: Frontier AI Models Now Outpace Human Hackers and Threaten Financial Stability
Summary The UK’s most powerful financial authorities — the Bank of England, HM Treasury, and the Financial Conduct Authority — issued a joint warning on May 15, 2026, declaring that…
Anthropic Introduces Agentic Credit System as AI Agents Outgrow Standard Chat Subscriptions
Summary Anthropic announced on May 14, 2026, a new “programmatic credit pool” system designed to separate agentic AI usage from standard chat subscriptions. Taking effect June 15, the change acknowledges…
Google Patches 79 Chrome Vulnerabilities — 14 Rated Critical in Massive Security Update
Summary Google has released Chrome version 148.0.7778.167/168 across Windows, macOS, and Linux, addressing a staggering 79 security vulnerabilities — 14 of which are classified as critical. This is one of…
Apple Patches Critical Kernel Wi-Fi RCE (CVE-2026-28819) in Massive iOS 26.5 Security Update
What Happened Apple has released iOS 26.5, iPadOS 26.5, and updates across its entire OS lineup patching over 60 security vulnerabilities. The most severe is CVE-2026-28819, a kernel-level Wi-Fi remote…
NASA Tests AI Space Chip 500x Faster Than Current Spaceflight Computers
What Happened NASA announced today that its High Performance Spaceflight Computing project has begun testing a new radiation-hardened AI processor that delivers roughly 500 times the computing power of chips…
Anthropic’s Mythos Model Forces U.S. and China Into Emergency AI Talks Ahead of Trump State Visit
What Happened In a dramatic reversal, the Trump administration — previously “laissez-faire” on AI governance — is now quietly negotiating with China to establish an emergency communication channel for AI,…
