Critical Fortinet Vulnerabilities in FortiSandbox and FortiAuthenticator — Unauthenticated RCE Possible
Summary Fortinet has issued urgent patches for critical vulnerabilities in two of its security products: FortiSandbox and FortiAuthenticator. Both flaws allow unauthenticated attackers to execute unauthorized code or commands remotely,…
Nature Study Reveals Governments Can Shape AI Chatbot Responses by Controlling Training Data
Summary A new study published in Nature on May 13, 2026, reveals that governments can indirectly influence what large language models say by shaping the online media environment from which…
OpenAI Rolls Out GPT-5.5 Instant as Default ChatGPT Model — 50% Fewer Hallucinations Claimed
Summary OpenAI has rolled out GPT-5.5 Instant as the new default model powering ChatGPT, replacing the previous default for all users. The update focuses on delivering more accurate, personalized, and…
Microsoft Patch Tuesday Fixes 138 Vulnerabilities Including 30 Critical — AI System MDASH Discovers 16 Flaws
Summary Microsoft’s May 2026 Patch Tuesday addresses a massive 138 security vulnerabilities across its product portfolio, with 30 rated Critical. While none were publicly known or under active exploitation at…
Ransomware Gangs Escalate to Physical Threats — Attackers Now Visiting Homes and Threatening Employees’ Families
Summary A disturbing escalation in ransomware tactics has been documented: cybercriminal groups are now resorting to threats of physical violence against employees and their families when organizations refuse to pay…
Critical WebSocket Hijacking Flaw (CVSS 9.7) in Cline AI Coding Agent — Workspace Data Exfiltration via Any Website
Summary A critical WebSocket hijacking vulnerability with a CVSS score of 9.7 has been discovered in Cline’s local Kanban server, the widely-used open-source AI coding agent. The flaw allowed any…
Škoda Data Breach Exposes Online Shop Customers — Names, Addresses, and Password Hashes Accessed
Summary Czech automaker Å koda, a wholly-owned subsidiary of Volkswagen Group, has disclosed a data breach affecting users of its online shop. The incident was discovered through the company’s technical security…
PAN-OS Authentication Portal Zero-Day (CVE-2026-0300) Under Active State-Sponsored Exploitation — No Patch Available
Summary A critical buffer overflow vulnerability in Palo Alto Networks PAN-OS, tracked as CVE-2026-0300 (CVSSv4 9.3), is being actively exploited by a suspected state-sponsored threat cluster designated CL-STA-1132. The flaw…
“ClaudeBleed” — Critical Flaw in Anthropic’s Claude Chrome Extension Lets Any Extension Hijack the AI Agent
Summary Security researchers at LayerX have disclosed “ClaudeBleed,” a critical vulnerability in Anthropic’s Claude Chrome extension that allows any other browser extension — even those with zero special permissions —…
Google Disrupts First Known AI-Generated Zero-Day Exploit — Criminals Used LLM to Bypass 2FA at Scale
Summary Google disclosed on Monday that its Threat Intelligence Group (GTIG) identified and disrupted a criminal operation that used an AI model to develop a working zero-day exploit — marking…
