US National Guard Deployed to Combat Ransomware Attacks in Minnesota and Texas
Summary The United States National Guard has been activated in multiple states to respond to ransomware attacks that overwhelmed local government cybersecurity capabilities. In Minnesota, Governor Tim Walz authorized the…
A Dozen Critical vm2 Node.js Sandbox Escape Flaws Disclosed — Update to 3.11.2 Immediately
Summary Twelve critical security vulnerabilities have been disclosed in vm2, the widely-used Node.js library for running untrusted JavaScript inside sandboxed environments. The flaws — including CVE-2026-24118, CVE-2026-24120, CVE-2026-24781, and CVE-2026-26332,…
EU Strikes Deal to Ban AI-Generated Sexualized Deepfakes — Delays High-Risk AI Rules to 2027
Summary The European Union has reached a landmark agreement to explicitly ban AI systems that generate sexualized deepfakes, marking the first time EU legislation directly targets so-called “nudifier” applications. The…
Microsoft, Google, and xAI Agree to Give US Government Early Access to AI Models for National Security Testing
What Happened Microsoft, Google, and Elon Musk’s xAI have agreed to provide the U.S. government with early access to new AI models for national security testing. The agreements, announced by…
OpenAI Rolls Out GPT-5.5 Instant as Default ChatGPT Model — Faster, More Accurate Responses for All Users
What Happened OpenAI has made GPT-5.5 Instant the default model powering ChatGPT as of May 5, 2026. The new model replaces the previous default and promises more accurate and responsive…
MuddyWater Uses Microsoft Teams for False Flag Ransomware Attack — Iranian State Hackers Disguise Espionage as Cybercrime
What Happened Security firm Rapid7 has attributed a sophisticated ransomware attack to MuddyWater (aka Mango Sandstorm, Seedworm, Static Kitten), an Iranian state-sponsored hacking group, in what researchers describe as a…
Linux “Copy Fail” Vulnerability (CVE-2026-31431) Enables Root Privilege Escalation Across Cloud Environments
What Happened Microsoft Defender researchers have published a detailed analysis of CVE-2026-31431, a high-severity local privilege escalation vulnerability in the Linux kernel’s cryptographic subsystem. Dubbed “Copy Fail,” the flaw affects…
Palo Alto Networks PAN-OS Zero-Day (CVE-2026-0300) Actively Exploited — Root-Level RCE with No Patch Available
What Happened Palo Alto Networks has confirmed that a critical zero-day vulnerability in its PAN-OS software is being actively exploited in the wild. Tracked as CVE-2026-0300, the flaw is a…
Critical Apache HTTP/2 Double-Free Flaw (CVE-2026-23918) Enables DoS and Remote Code Execution
What Happened The Apache Software Foundation has released version 2.4.67 of the Apache HTTP Server to address CVE-2026-23918 (CVSS 8.8), a critical double-free vulnerability in the HTTP/2 protocol handler (mod_http2).…
Critical MetInfo CMS Flaw (CVE-2026-29014) Under Active Exploitation — CVSS 9.8 Code Injection Hits Thousands of Sites
Summary A critical unauthenticated PHP code injection vulnerability in MetInfo CMS (CVE-2026-29014, CVSS 9.8) is being actively exploited in the wild. The flaw affects MetInfo versions 7.9, 8.0, and 8.1,…
