Previous Cyber Pulse

Previous weekly cybersecurity briefs from CyberMentor365, covering exploited vulnerabilities, breaches, OT/ICS risk, cyber governance, threat activity, and leadership takeaways. Each update is retained for reference, trend tracking, and ongoing cyber awareness.

Week of may 11–May 17, 2026

Cyber Pulse: Top 10 Cybersecurity Stories This Week

1. Microsoft May 2026 Patch Tuesday: 118–137 CVEs, No Zero-Days
Microsoft released its May 2026 Patch Tuesday fixes addressing between 118 and 137 vulnerabilities (counts vary slightly by vendor) across 20+ product families, including 16–31 marked Critical. Notably, this is the first Patch Tuesday since June 2024 with no zero-days actively exploited in the wild.
Source: BleepingComputer — https://www.bleepingcomputer.com/news/microsoft/microsoft-may-2026-patch-tuesday-fixes-120-flaws-no-zero-days/crowdstrike+2

2. Foxconn Ransomware Attack: Nitrogen Gang Claims 8TB of Data Stolen
Foxconn confirmed on May 12, 2026 that its North American manufacturing plants (primarily Mount Pleasant, Wisconsin) were hit by the Nitrogen ransomware group. The attackers claimed to have exfiltrated 8TB / 11+ million files including schematics tied to Apple, Google, Nvidia, Dell, and Intel. Production disruptions began as early as May 1 before public disclosure.
Source: TechCrunch / WIRED — https://techcrunch.com/2026/05/13/ransomware-hackers-claim-breach-at-foxconn/ | https://www.wired.com/story/foxconn-ransomware-attack-shows-nothing-is-safe-forever/ techcrunch+2

3. Instructure (Canvas LMS) Breach: ShinyHunters Claims 275 Million Records
Instructure, maker of the Canvas learning management system, confirmed a major data breach after ShinyHunters claimed to have stolen data from approximately 8,809 schools worldwide, affecting an estimated 275 million students, teachers, and staff. Exposed data includes names, email addresses, student IDs, and private messages. The attackers escalated by defacing hundreds of school login portals with ransom messages.
Source: LinkedIn / Check Point Research — https://www.linkedin.com/pulse/securefact-cyber-security-news-week-may-11-2026-magedatadotai-glfxc | https://research.checkpoint.com/2026/11th-may-threat-intelligence-report/ linkedin+1

4. Cisco Catalyst SD-WAN CVSS 10.0 Auth Bypass Actively Exploited
A maximum-severity authentication bypass vulnerability (CVE-2026-20182, CVSS 10.0) in Cisco Catalyst SD-WAN Controller and Manager was confirmed as actively exploited in May 2026. An unauthenticated remote attacker can abuse DTLS on UDP port 12346 to bypass authentication and gain full administrative privileges over the SD-WAN fabric. Cisco has released patches and urged immediate action.
Source: The Hacker News — https://thehackernews.com/2026/05/cisco-catalyst-sd-wan-controller-auth.htmlthehackernews+1

5. Verizon 2026 DBIR Published: Ransomware Now in 44% of Breaches
Verizon released its 2026 Data Breach Investigations Report, finding ransomware present in approximately 44% of all breaches (up from 32% the prior year), while third-party involvement in breaches doubled year-over-year. Credential abuse remains the top entry vector, and AI-generated phishing text in malicious emails doubled over the past two years.
Source: Verizon / DIESEC — https://www.verizon.com/business/resources/reports/dbir/ | https://diesec.com/2026/05/top-5-cybersecurity-news-stories-may-15-2026/ verizon+2

6. Palo Alto PAN-OS CVE-2026-0300: Critical RCE Being Actively Exploited
Palo Alto Networks disclosed and confirmed active exploitation of CVE-2026-0300, a critical buffer overflow in the PAN-OS User-ID Authentication Portal (Captive Portal). Unauthenticated attackers can achieve root-level remote code execution on PA-Series and VM-Series firewalls. No user interaction or credentials are required; CISA added it to the Known Exploited Vulnerabilities (KEV) catalog.
Source: Wiz / Help Net Security — https://www.wiz.io/blog/critical-vulnerability-in-pan-os-exploited-in-the-wild-cve-2026-0300 | https://www.helpnetsecurity.com/2026/05/06/palo-alto-firewalls-vulnerability-exploited-cve-2026-0300/ wiz+1

7. Best Western (BWH Hotels) Data Breach: Guest Data Exposed for 6 Months
BWH Hotels (parent of Best Western, WorldHotels, and SureStays) confirmed that hackers lurked inside its reservation web application from October 14, 2025 to April 22, 2026 — over six months — before detection. Stolen data includes guest names, emails, phone numbers, postal addresses, reservation numbers, dates of stay, and special requests. Payment data was not affected.
Source: Cybernews / TechRadar — https://cybernews.com/security/best-western-bwh-hotels-guest-data-breach/ | https://www.techradar.com/pro/security/best-western-hotels-warns-customers-reservation-data-may-have-been-spilled-in-breach cybernews+1

8. Exim Mail Server Critical RCE (CVE-2026-45185 “Dead.Letter”)
A critical use-after-free RCE vulnerability (CVE-2026-45185, CVSS 9.8) nicknamed “Dead.Letter” was disclosed in Exim mail transfer agent versions 4.97–4.99.2 on GnuTLS-compiled builds. An unauthenticated remote attacker can execute arbitrary code by sending a crafted TLS close_notify alert mid-BDAT transfer. Exim 4.99.3 patches the flaw; OpenSSL-based builds are not affected.
Source: BleepingComputer / runZero — https://www.bleepingcomputer.com/news/security/new-critical-exim-mailer-flaw-allows-remote-code-execution/ | https://www.runzero.com/blog/exim-mail-servers/ bleepingcomputer+1

9. NuGet Supply Chain Attack: 65,000 Downloads of Infostealer Packages
Five malicious NuGet packages (published by account “bmrxntfj”) impersonating popular Chinese .NET UI libraries accumulated nearly 65,000 downloads. The packages embed an infostealer that harvests browser credentials from 12 browsers, SSH keys, cryptocurrency wallet data, and local files — targeting both developer workstations and CI/CD pipelines. The campaign is ongoing.
Source: Cyberpress / SOC Prime — https://cyberpress.org/nuget-malware-steals-secrets/ | https://socprime.com/active-threats/malicious-nuget-packages-steal-wallets-and-credentials/ cyberpress+2

10. Zara (Inditex) Data Breach: 197,400 Customer Records Exposed
Spanish fashion giant Zara confirmed unauthorized access to a database hosted by a former third-party technology provider. Have I Been Pwned confirmed 197,400 unique email addresses were exposed, along with product SKUs, order IDs, and support ticket data. ShinyHunters claimed responsibility and leaked a 140GB archive, though names, phone numbers, payment card data, and credentials were not exposed.
Source: Check Point Research / LinkedIn — https://research.checkpoint.com/2026/11th-may-threat-intelligence-report/ | https://www.linkedin.com/pulse/securefact-cyber-security-news-week-may-11-2026-magedatadotai-glfxc

Threat Radar: Top 10 Active Threats, APTs & Dark Web Alerts

1. Nitrogen Ransomware — Active Double-Extortion Group Hits Foxconn
Nitrogen ransomware (active since 2023, linked to Conti 2 leaked code and ALPHV/BlackCat cartel) claimed its most high-profile attack yet against Foxconn’s North American operations, stealing 8TB of data and deploying double-extortion tactics. The group typically targets supply-chain entry points and uses Bring Your Own Vulnerable Driver (BYOVD) techniques to disable AV tools before deployment.
Source: Hoplon InfoSec / Cybersecurity Dive — https://hoploninfosec.com/foxconn-ransomware-attack-nitrogen-breach | https://www.cybersecuritydive.com/news/foxconn-confirms-cyberattack-affecting-some-north-american-facilities/820120/ hoploninfosec+1

2. ShinyHunters — Prolific Extortion Group Targeting Education & Retail
ShinyHunters continued its rampage this week, claiming attacks against Instructure/Canvas (275M records), Zara (197K records), and NVIDIA GeForce NOW (Armenia region). The group leverages compromised authentication tokens (including Anodot tokens used in the Zara attack) and cloud infrastructure abuse to exfiltrate large-scale datasets from BigQuery and similar cloud databases.
Source: LinkedIn SecureFact / Check Point — https://www.linkedin.com/pulse/securefact-cyber-security-news-week-may-11-2026-magedatadotai-glfxcresearch.checkpoint+1

3. MuddyWater (Iran) — False Flag Ransomware Deployed as Espionage Cover
Iran-linked MuddyWater (Mango Sandstorm / Seedworm / Static Kitten), operating under Iran’s Ministry of Intelligence and Security (MOIS), ran a sophisticated false-flag operation using Microsoft Teams social engineering. Attackers impersonated IT support staff, convinced victims to grant remote access, deployed infostealers, altered MFA settings, and deployed Chaos ransomware as cover — while the real objective was credential theft and data exfiltration.
Source: The Hacker News / TechRadar — https://thehackernews.com/2026/05/muddywater-uses-microsoft-teams-to.html | https://www.techradar.com/pro/security/iranian-hackers-launch-ransomware-campaign-looking-to-steal-details-via-microsoft-teams thehackernews+1

4. Handala (Iran-Linked Hacktivists) — Targeting UAE & Gulf Critical Infrastructure
Handala, an Iran-aligned hacktivist group, escalated operations against UAE and Gulf targets. The group claimed to have breached the Port of Fujairah (releasing 430,000 classified documents including oil pipeline maps and ship movement data) and previously conducted cyberattacks on Gulf steel producers (Foulath Holding, Bahrain and SULB) targeting industrial SCADA systems.
Source: YouTube / Cyble — https://www.youtube.com/watch?v=SpGEkq7hS24 | https://cyble.com/blog/middle-east-cyber-warfare-2026-hybrid-conflict/ YouTube​cyble

5. BARADAI Ransomware — Newly Identified File-Encrypting Strain
CYFIRMA researchers identified BARADAI ransomware this week while monitoring underground forums. It is a file-encrypting malware strain that appends a distinct extension to compromised files, targets local systems and network resources, and supports a double-extortion model with a Tor-based leak site. Initial access vectors include phishing, social engineering, and vulnerability exploitation.
Source: CYFIRMA — https://www.cyfirma.com/news/weekly-intelligence-report-08-may-2026/cyfirma

6. Silver Fox APT — Tax-Themed Phishing Delivering ABCDoor Backdoor
Researchers detailed a Silver Fox campaign targeting organizations in India and Russia with tax-themed phishing emails delivering the previously undocumented ABCDoor backdoor, ValleyRAT, and related malware. The campaign affected industrial, consulting, retail, and transportation sectors through more than 1,600 socially engineered messages.
Source: Check Point Research — https://research.checkpoint.com/2026/11th-may-threat-intelligence-report/research.checkpoint

7. Sandworm (Russia GRU) — OT/ICS Lateral Movement Activity Detected
Russian state-linked Sandworm was reported moving from IT networks toward operational technology (OT) and industrial control system (ICS) environments, raising critical infrastructure alarms. The concern centers on leveraging existing footholds, unresolved vulnerabilities, and weak segmentation to approach energy, utilities, and manufacturing systems — where attacks can have physical-world consequences.
Source: LinkedIn Weekly Cyber Update — https://www.linkedin.com/pulse/weekly-update-cyber-news-week-ending-may-15th-2026-dr-jason-wrt6elinkedin

8. Qilin Ransomware (RaaS) — Ongoing Operations with In-House Legal Services
Qilin, operating a mature Ransomware-as-a-Service model, continued active operations against US, Canadian, French, UK, and Italian targets. Notably, the group has innovated with in-house legal services to increase pressure on victims, alongside AI chatbot integrations to streamline victim communications. Their RaaS infrastructure provides affiliates with full tooling and support ecosystems.
Source: CYFIRMA / ISACA — https://www.cyfirma.com/news/weekly-intelligence-report-08-may-2026/ | https://www.isaca.org/resources/news-and-trends/industry-news/2026/ai-driven-ransomware-fuels-rise-in-new-cyberthreat-groups cyfirma+1

9. BlueNoroff (DPRK) — Social Engineering Targeting Crypto Organizations
North Korea-linked BlueNoroff was reported conducting targeted intrusions against Web3 and cryptocurrency organizations using fake Zoom meeting invitations that redirect to malicious interfaces. Attacks enable webcam capture, credential theft from cryptocurrency wallets, Telegram session hijacking, and persistence. Stolen data is reused to build more convincing deepfake lures.
Source: Help AG — https://www.helpag.com/top-middle-east-cyber-threats-06-may-2026/helpag

10. RansomHouse — Claims Attack on Trellix Source Code Repository
The RansomHouse threat group claimed responsibility for attacking cybersecurity vendor Trellix’s source code repository, leaking a small set of images as proof of intrusion. The breach reportedly occurred on April 17, involving data encryption and exfiltration representing a double-extortion approach. The attack on a major security vendor’s code repository raises significant supply-chain concerns.
Source: LinkedIn SecureFact — https://www.linkedin.com/pulse/securefact-cyber-security-news-week-may-11-2026-magedatadotai-glfxc

Patch Priority: Top 10 Critical Vulnerabilities to Watch

  1. CVE-2026-20182 — Cisco Catalyst SD-WAN Authentication Bypass
  • CVSS Score: 10.0 (Critical)
  • Affected Products: Cisco Catalyst SD-WAN Controller, Cisco Catalyst SD-WAN Manager (On-Prem, Cloud-Pro, Cloud, FedRAMP)
  • Patch Status: Patches available — immediate patching required; active exploitation confirmed
  • Details: Unauthenticated remote attacker can bypass authentication via DTLS on UDP port 12346 to gain full administrative privileges over the SD-WAN fabric.
    Source: The Hacker News — https://thehackernews.com/2026/05/cisco-catalyst-sd-wan-controller-auth.htmlthehackernews

2. CVE-2026-42826 — Azure DevOps Information Disclosure

3. CVE-2026-0300 — Palo Alto PAN-OS Captive Portal RCE

4. CVE-2026-41089 — Windows Netlogon RCE (Wormable)

  • CVSS Score: 9.8 (Critical)
  • Affected Products: Windows Server (Domain Controllers)
  • Patch Status: Patched via May 2026 Patch Tuesday
  • Details: Stack-based buffer overflow allowing unauthenticated remote code execution on domain controllers. No credentials or user interaction required — classified as wormable. A compromised DC means a compromised domain.
    Source: Zero Day Initiative — https://www.thezdi.com/blog/2026/5/12/the-may-2026-security-update-reviewthezdi

5. CVE-2026-45185 — Exim Mail Server RCE (“Dead.Letter”)

6. CVE-2026-7482 — Ollama “Bleeding Llama” Memory Leak

7. CVE-2026-33109 — Azure Managed Instance for Apache Cassandra RCE

8. CVE-2026-31431 — Linux Kernel “Copy Fail” Local Privilege Escalation

  • CVSS Score: 8.8 (High)
  • Affected Products: Linux distributions using kernel versions released since 2017
  • Patch Status: Kernel patch required; PoC available
  • Details: Allows an unprivileged local user to gain full root access. Exploitation requires only a lightweight Python script with no race conditions or complex kernel offsets — significantly lower barrier than typical LPE flaws.
    Source: Integrity360 — https://www.integrity360.com/cyber-news-roundup-may-1st-2026integrity360

9. CVE-2026-42823 — Azure Logic Apps Elevation of Privilege

  • CVSS Score: 9.9 (Critical)
  • Affected Products: Azure Logic Apps
  • Patch Status: Patched by Microsoft via cloud infrastructure (no customer action needed)
  • Details: Allows privilege escalation within Azure Logic Apps workflows, potentially enabling an attacker to gain unauthorized access to connected services and data.
    Source: Sophos Patch Tuesday — https://www.sophos.com/en-us/blog/may-patch-tuesday-hauls-out-132-cvessophos

10. CVE-2026-41109 — GitHub Copilot & VS Code Security Feature Bypass

CVE Watch: Top 10 CVEs — Severity, Impact & Patch Status

CVE IDSeverity (CVSS)ProductImpactSource
CVE-2026-20182Critical (10.0)Cisco Catalyst SD-WAN Controller & ManagerAuth bypass → full admin control over SD-WAN fabric; actively exploitedThe Hacker Newsthehackernews
CVE-2026-42826Critical (10.0)Microsoft Azure DevOpsInformation disclosure of sensitive pipeline secrets and dataCrowdStrikecrowdstrike
CVE-2026-33109Critical (9.9)Azure Managed Instance for Apache CassandraUnauthenticated Remote Code Execution on Azure cloud serviceSophossophos
CVE-2026-42823Critical (9.9)Azure Logic AppsElevation of Privilege on cloud workflow automation serviceSophossophos
CVE-2026-41096Critical (9.8)Windows DNS ClientHeap buffer overflow → unauthenticated RCE via malicious DNS responseCrowdStrikecrowdstrike
CVE-2026-41089Critical (9.8)Windows Netlogon (Domain Controllers)Wormable RCE — stack-based buffer overflow; unauthenticated, no user interactionZero Day Initiativethezdi
CVE-2026-45185Critical (9.8)Exim Mail Server 4.97–4.99.2 (GnuTLS)UAF-based RCE via BDAT/TLS handling; unauthenticated; patched in 4.99.3BleepingComputerbleepingcomputer
CVE-2026-0300Critical (9.8)Palo Alto PAN-OS (PA-Series/VM-Series)RCE with root privileges via Captive Portal buffer overflow; KEV listed; actively exploitedNVD / Wiznvd.nist
CVE-2026-7482Critical (9.1)Ollama < 0.17.1 (GGUF model loader)Memory leak — API keys, system prompts, conversations exfiltrated; 300K servers at riskNVDnvd.nist
CVE-2026-35428Critical (9.6)Azure Cloud ShellCommand injection/spoofing; unauthenticated remote attacker; patched by Microsoft cloud updateCrowdStrikecrowdstrike

Attack Tracker: Top 10 Cyber Attacks (UAE, Gulf & Global)

1.  UAE — 600,000 Daily AI-Powered Cyberattacks as Regional Conflict Escalates
The UAE Cyber Security Council confirmed that daily cyberattack volumes have tripled to approximately 600,000 per day since the regional escalation in late February 2026. Authorities have identified 350 organized groups, 320 amateur hackers, and 120 malware-linked entities actively targeting UAE government systems, financial services, ports, and public utilities. Iranian actors using AI-powered deepfakes and wiper viruses pose the greatest risk.
Source: Analytics Insight UAE / Gulf News — https://www.analyticsinsight.ae/news/uae-cyberattacks-triple-to-600000-a-day-as-gulf-financial-hubs-become-conflict-target | https://gulfnews.com/uae/government/uae-issues-warning-as-iran-deploys-ai-for-cyber-attacks-1.500525604 analyticsinsight+1

2.  UAE — Handala Claims Breach of Port of Fujairah, 430K Documents Leaked
Iran-linked Handala hacker group claimed to have breached the Port of Fujairah ahead of missile and drone strikes on the strategic oil hub. The group alleged it exfiltrated over 430,000 classified documents including oil pipeline maps, ship movement data, and financial records, which it claimed were shared with IRGC-linked military units. The group warned Abu Dhabi to cease cooperation with the US and Israel.
Source: YouTube / Cyble — https://www.youtube.com/watch?v=SpGEkq7hS24 | https://cyble.com/blog/middle-east-cyber-warfare-2026-hybrid-conflict/ YouTube​cyble

3.  UAE /  Bahrain — DieNet Pro-Iran Group DDoS Attacks on Gulf Airports & Banks
Pro-Iran hacktivist group DieNet claimed responsibility for DDoS attacks targeting airports and financial institutions across the Gulf, including an airport in the UAE, Sharjah Airport in Saudi Arabia, Riyadh Bank, the Bank of Jordan, and a Bahrain airport. The group publicizes attacks via its Telegram board as part of a coordinated digital pressure campaign aligned with Iran’s regional posture.
Source: Palo Alto Unit 42 — https://unit42.paloaltonetworks.com/iranian-cyberattacks-2026/unit42.paloaltonetworks

4.  Bahrain /  Saudi Arabia — 800% Surge in Cyberattacks Post-Iran Conflict
Cyberattacks targeting Bahrain and Gulf neighbours surged 800% during March 2026 compared to February, with the trend continuing into May. Digital campaigns heavily targeted Israel (36% of strikes), UAE (21%), and Bahrain (14%), with the heaviest hits landing on public sector, banking, and telecommunications. Iranian-aligned hacktivists conducted DDoS campaigns against US-aligned Gulf states hosting American military installations.
Source: Gulf Daily News — https://www.gdnonline.com/Details/1380549gdnonline

 Global

5.  Foxconn — Nitrogen Ransomware Disrupts North American Manufacturing
The Nitrogen ransomware gang hit Foxconn’s North American operations (confirmed May 12), causing a two-week network collapse at the Mount Pleasant, Wisconsin plant. The attackers claimed to have stolen 8TB / 11 million files including confidential project data tied to Apple, Google, Nvidia, Dell, and Intel. The double-extortion attack underscores supply-chain vulnerability in global electronics manufacturing.
Source: TechCrunch / WIRED — https://techcrunch.com/2026/05/13/ransomware-hackers-claim-breach-at-foxconn/ | https://www.wired.com/story/foxconn-ransomware-attack-shows-nothing-is-safe-forever/ techcrunch+1

6.  Instructure / Canvas LMS — 275 Million Education Records Compromised
ShinyHunters breached Instructure’s cloud environment serving Canvas LMS, compromising data from 8,809 schools, colleges, and universities worldwide. Beyond data theft, attackers defaced hundreds of school login portals with ransom messages, escalating pressure on the educational technology company. The incident represents one of the largest education-sector breaches in history.
Source: LinkedIn SecureFact / Check Point — https://www.linkedin.com/pulse/securefact-cyber-security-news-week-may-11-2026-magedatadotai-glfxclinkedin+1

7.  Best Western (BWH Hotels) — 6-Month Undetected Intrusion into Reservation Systems
Hackers infiltrated BWH Hotels’ guest reservation system in October 2025 and remained undetected for over six months, exfiltrating reservation data for tens of thousands of guests. The breach exposed names, email addresses, phone numbers, postal addresses, and full reservation details. The long dwell time raises serious concerns about detection gaps in the hospitality sector.
Source: Cybernews — https://cybernews.com/security/best-western-bwh-hotels-guest-data-breach/cybernews

8.  Water Infrastructure — Hackers Access Industrial Controls at Public Water Plants
Researchers and responders reported active intrusions into water facility industrial control systems, with attackers testing access to programmable logic controllers and SCADA systems. The incidents coincide with Sandworm activity targeting OT environments, raising physical-world safety concerns as hackers probe the boundary between cyber and operational disruption in critical infrastructure.
Source: LinkedIn Daily Cyber News — https://www.linkedin.com/pulse/daily-cyber-news-may-11th-2026-dr-jason-edwards-dm-cissp-crisc-f0neelinkedin

9.  MuddyWater (Iran) — Microsoft Teams Social Engineering Espionage Campaign
Iran’s MuddyWater executed a false-flag ransomware campaign using Microsoft Teams, impersonating IT support staff via a deceptive Microsoft 365 tenant domain (e.g., “sarahwilson@seqhelpsitdevsupportops.onmicrosoft.com“). Victims were tricked into executing a malicious MSI installer (Dindoor backdoor), followed by credential theft, MFA modification, data exfiltration, and Chaos ransomware deployment as cover.
Source: The Hacker News / CyberProof — https://thehackernews.com/2026/05/muddywater-uses-microsoft-teams-to.html | https://www.cyberproof.com/blog/iranian-apt-seedworm-targets-global-organizations-via-microsoft-teams/ thehackernews+1

10.  Hungarian Mediaworks — World Leaks Posts 8.5TB of Internal Files
Hungarian media company Mediaworks, which operates dozens of newspapers and online outlets, was hit by a data-theft extortion attack. The World Leaks group posted 8.5TB of internal files online, reportedly including payroll records, contracts, financial documents, and internal communications. The attack demonstrates the continued targeting of media organizations in geopolitically sensitive regions.
Source: Check Point Research — https://research.checkpoint.com/2026/11th-may-threat-intelligence-report/

AI Watch: Top 10 AI Innovations Shaping Cyber & Tech

1. OpenAI Launches GPT-5.5 Instant as Default ChatGPT Model
OpenAI released GPT-5.5 Instant on May 5, 2026 as the new default model for all ChatGPT users, replacing GPT-5.3 Instant. The model reduces hallucinations in sensitive domains (law, medicine, finance), scores 81.2 on AIME 2025 (vs. 65.4 for predecessor), and achieves 76 on MMMU-Pro multimodal reasoning. It also introduces stronger personalization based on user conversation history.
Source: TechCrunch / OpenAI — https://techcrunch.com/2026/05/05/openai-releases-gpt-5-5-instant-a-new-default-model-for-chatgpt/ | https://openai.com/index/introducing-gpt-5-5/ techcrunch+1

2. OpenAI Launches GPT-5.5-Cyber: Security-Focused AI Model
On May 7, 2026, OpenAI announced GPT-5.5-Cyber, a limited-preview variant available to vetted cybersecurity teams under its “Trusted Access for Cyber” program. The model is purpose-built for vulnerability analysis, secure code review, and threat assessment workflows, becoming the first OpenAI model with a dedicated cybersecurity use case designation.
Source: Wikipedia / YouTube — https://en.wikipedia.org/wiki/GPT-5.5 | https://www.youtube.com/watch?v=8IzqzUQYqzE wikipedia​YouTube​

3. OpenAI Releases Three New Real-Time Voice Models
OpenAI launched three new real-time API voice models this week: GPT-Realtime-2 (GPT-5 class reasoning for real-time speech), GPT-Realtime-Translate (live speech-to-speech translation across 70+ languages), and GPT-Realtime-Whisper (live transcription). These models transition voice AI from “demo-ready” to production-grade, enabling complex multi-step voice agents.
Source: YouTube API Week Coverage — https://www.youtube.com/watch?v=8IzqzUQYqzEyoutube+1

4. Anthropic Releases Claude Opus 4.7 Fast Mode + Claude for Small Business & Legal
Anthropic released Fast mode for Claude Opus 4.7 in research preview, available through the API and top coding IDEs (Cursor, Windsurf, Warp). The company also launched Claude for Small Business (workflow automation across finance, ops, HR) and Claude for Legal (12 plugins + 20+ MCP connectors for legal practice areas), extending its enterprise footprint significantly.
Source: LinkedIn AI Daily Briefing — https://www.linkedin.com/pulse/ai-daily-briefing-thursday-14th-may-2026-david-wright-z3dlelinkedin

5. Anthropic Secures SpaceX Compute Partnership, Raises Usage Limits
Anthropic announced a partnership with SpaceX for substantially expanded compute capacity, allowing it to raise usage limits for Claude Code and the Claude API. Anthropic’s annualized revenue had crossed $24 billion by April 2026 (vs. OpenAI’s ~$19B), and the company has received investment offers valuing it above $710 billion.
Source: Anthropic — https://www.anthropic.com/news/higher-limits-spacexanthropic+1

6. Google Unveils “Gemini Intelligence” Platform at Android Show 2026
On May 12, 2026, Google unveiled a major paradigm shift at the Android Show 2026, moving away from traditional operating systems toward an “intelligence system” powered by Gemini. Android devices will feature agentic workflows that proactively execute multi-step tasks across apps (e.g., auto-converting a grocery list image to a delivery cart). Google also launched the Googlebook laptop running “Aluminium OS” with an AI-enhanced Magic Pointer cursor built with DeepMind.
Source: Champaign Magazine AI Weekly — https://champaignmagazine.com/2026/05/17/ai-by-ai-weekly-top-5-may-11-17-2026/champaignmagazine

7. xAI Grok 4.3: Multimodal AI with 2M Token Context Window
xAI’s Grok 4.3 reached broader API availability in early May 2026, featuring native video understanding, expanded context windows of up to 2 million tokens, improved multi-step reasoning and instruction following, voice generation and voice-cloning tools, and support for generating PDFs, spreadsheets, and presentations. It tops Artificial Analysis leaderboards in agentic tool calling and ranks #1 on enterprise domains (case law, corporate finance).
Source: Times of AI / Oracle OCI Blog — https://www.timesofai.com/news/grok-4-3-all-new-features-explained/ | https://blogs.oracle.com/ai-and-datascience/whats-new-in-ai-may-2026 timesofai+1

8. Stanford 2026 AI Index: Cybersecurity Agent Accuracy Reaches 93%
The Stanford HAI 2026 AI Index Report revealed that AI cybersecurity agent accuracy jumped from 15% to 93% in one year; SWE-bench performance (real GitHub bugs) rose from 60% to near 100%; global AI investment reached $581.7 billion (up 130%); and generative AI reached 53% population adoption — faster than the PC or the internet. The UAE achieved 54% genAI adoption, ranking above the US average.
Source: Stanford HAI / Reddit — https://hai.stanford.edu/ai-index/2026-ai-index-report | https://www.reddit.com/r/ArtificialInteligence/comments/1sncv1j/the_stanford_ai_index_report_of_2026_has_some/ hai.stanford+1

9. MIT Technology Review: Sovereign AI Delivers 5x ROI for Enterprises
A new MIT Technology Review Insights report (published May 14, 2026, in partnership with EnterpriseDB) found that enterprises “deeply committed” to AI and data sovereignty deliver 5x the ROI from generative and agentic AI initiatives, with a 0.93 correlation between sovereignty commitment and AI success. Over half of enterprises already have AI agents in production. Security and resilience (85%), data localization (74%), and ownership/control (72%) are the top sovereignty drivers.
Source: PR Newswire / MIT Tech Review — https://www.prnewswire.com/news-releases/sovereignty-is-the-new-operating-system-for-agentic-ai-new-mit-technology-review-insights-reportprnewswire

10. Sakana AI Unveils “RL Conductor”: Reinforcement Learning for Multi-Model Orchestration
Sakana AI introduced RL Conductor, a 7B parameter orchestration model trained through reinforcement learning to dynamically coordinate multiple frontier AI systems (GPT-5, Claude Sonnet 4, Gemini 2.5 Pro, and open-source models). Rather than rigid workflows, the model automatically routes tasks based on each model’s strength — representing a significant step toward autonomous multi-agent AI systems at production scale.
Source: MarketingProfs AI Update — https://www.marketingprofs.com/opinions/2026/54786/ai-update-may-15-2026-ai-news-and-views-from-the-past-weekmarketingprofs


Week of may 04–May 10, 2026

Cyber Pulse: Top 10 Cybersecurity Stories This Week

  1. Palo Alto PAN-OS Zero-Day (CVE-2026-0300) Actively Exploited — Internet-exposed Palo Alto firewalls face root-level takeover risk after state-linked actors began exploiting the User-ID/Captive Portal authentication flaw. CISA added it to the KEV catalog this week. Source: Dr. Jason Edwards Weekly – May 8linkedin
  2. MuddyWater Uses Microsoft Teams for Espionage Masquerading as Chaos Ransomware — Iranian state-linked MuddyWater operators used Microsoft Teams to socially engineer credential theft, MFA manipulation, and data exfiltration — disguising espionage as a ransomware campaign. Source: Dr. Jason Edwards Weekly – May 8linkedin
  3. DAEMON Tools Supply Chain Attack Hits 100+ Countries — Attackers poisoned official DAEMON Tools installers with a backdoor starting April 8, reaching thousands of systems worldwide. Second-stage payloads were selectively deployed to high-value targets. Source: Cybersecurity Help – May 8cybersecurity-help
  4. 35,000 Users Hit in 48-Hour Global Phishing Blitz — A rapid token-theft phishing campaign targeted 35,000 users across 26 countries in just two days, hitting 13,000+ organisations including healthcare, finance, and tech sectors. Source: Dr. Jason Edwards Weekly – May 8linkedin
  5. Microsoft Edge Dumps Passwords in Cleartext Memory — A serious flaw in Edge’s password manager exposes Azure logins and site credentials in cleartext memory on shared desktops or compromised sessions. No CVE assigned and no patch planned yet. Source: Cyber Recaps – May 5cyberrecaps
  6. Ollama “Bleeding Llama” Bug Exposes AI Server Memory (CVE-2026-7482, CVSS 9.3) — An unauthenticated heap out-of-bounds read in Ollama’s GGUF model loader allows attackers to dump process memory from exposed AI servers. Public PoC available. Source: Cyber Recaps – May 5cyberrecaps
  7. Ivanti EPMM Zero-Day Abused in Limited Attacks — Ivanti Endpoint Manager Mobile contained a flaw being actively exploited in limited real-world attacks, placing enterprise mobile fleets, policies, and certificates at risk. Source: Dr. Jason Edwards Weekly – May 8linkedin
  8. Progress Software MOVEit Automation Auth Bypass Fixed — Progress issued urgent patches for MOVEit Automation addressing a high-severity authentication bypass. MOVEit remains a top target following its 2025 mass-exploitation campaign. Source: Cybersecurity Help – May 8cybersecurity-help
  9. BARADAI Ransomware Discovered on Underground Forums — CYFIRMA researchers identified a new double-extortion ransomware called BARADAI, using AES-256+RSA-2048 encryption, Tor-based infrastructure, and targeting IT, government, and finance sectors. Source: CYFIRMA Weekly Intel – May 8cyfirma
  10. UAE Cautions Against “Rushed Digital Decision-Making” Amid AI Attack Surge — Abu Dhabi’s cybersecurity guidelines urge citizens and businesses not to act hastily on AI-powered phishing and deepfake attacks, as Microsoft Threat Intelligence confirmed phishing remains the leading attack vector. Source: The National Newsthenationalnews

Threat Radar: Top 10 Active Threats, APTs & Dark Web Alerts

  1. Handala Wiper Group Claims 200,000 Systems Wiped Across 79 Countries — Handala used compromised Microsoft Intune Global Admin accounts to deploy BiBi Wiper, Hamsa (Linux), CoolWipe, and ChillWipe variants. C2 infrastructure runs via Telegram Bot API. Source: Help AG – May 5helpag
  2. Brain Cipher Ransomware Targeting UAE, Finance & Government — CYFIRMA’s May 8 report confirms Brain Cipher uses double-extortion with AES-256/RSA-2048 encryption. UAE is a primary target, alongside Canada, US, Spain, and France. Source: CYFIRMA Weekly Intel – May 8cyfirma
  3. Qilin RaaS Continues Dominant Activity — Qilin ransomware, operating a cross-platform RaaS model (Windows, Linux, VMware ESXi), remains among the most active threat actors with double-extortion campaigns across US, Canada, France, UK, and Italy. Source: CYFIRMA Weekly Intel – May 8cyfirma
  4. PCPJack Cloud Credential Stealer Targets Exposed Infrastructure — A newly tracked tool “PCPJack” is actively scanning for exposed cloud infrastructure services to harvest access keys — potentially opening lateral movement pathways across enterprise environments. Source: Dr. Jason Edwards Weekly – May 8linkedin
  5. Firestarter Backdoor Persists After Cisco Patches — US/UK Joint Advisory — A joint US/UK advisory warns that the Firestarter backdoor maintains persistence even after patching affected Cisco devices, attributed to a sophisticated state-linked actor that targeted a federal agency. Source: Senthorus Weekly Reviewsenthorus
  6. MuddyWater (Iran) Pivots to Teams-Based Hybrid Espionage-Ransomware TTPs — MuddyWater is evolving its playbook, using Microsoft Teams as a social engineering vector to steal credentials and mimic Chaos ransomware behavior, making attribution and incident classification significantly harder. Source: Dr. Jason Edwards Weekly – May 8linkedin
  7. North Korea (Lazarus) Continues Targeting Web3 Executives — North Korean actors are conducting tailored spear-phishing and social engineering campaigns against crypto wallet holders and Web3 company founders, consistent with Lazarus Group’s ~$2B in 2025 crypto theft. Source: Senthorus Weekly Reviewsenthorus
  8. RMM Tool Abuse Campaign Hits 80+ Organisations Globally — A sophisticated phishing campaign is abusing legitimate Remote Monitoring & Management (RMM) tools to blend with normal IT activity, establishing persistence across 80+ organisations while bypassing traditional security controls. Source: Senthorus Weekly Reviewsenthorus
  9. ShinyHunters Widens Salesforce-Linked Data Extortion Spree — ShinyHunters continued targeting organisations via compromised Salesforce integrations, adding Udemy (1.4M records), Canada Life (70,000 individuals), Vimeo, and Zara to its dark web leak site this week. Source: LinkedIn Cybersecurity Daily Digestlinkedin
  10. Red Piranha 2026 TI Report: Cyber Espionage Replaces Disruption as Primary Goal — Analysis of 80M+ security events and 110 APT campaigns reveals attackers now prioritise long-term stealth and intelligence gathering over immediate disruption, using identity-based attacks and living-off-the-land techniques. Source: Red Piranha 2026 TI Reportredpiranha

Patch Priority: Top 10 Critical Vulnerabilities to Watch

  1. Palo Alto PAN-OS — CVE-2026-0300 (Critical) — Unauthenticated RCE at root level via the Captive Portal/User-ID service on PA-Series and VM-Series firewalls. State-linked actors actively exploiting exposed management portals. Patch immediately. Source: Dr. Jason Edwards Weekly – May 8linkedin
  2. Ollama “Bleeding Llama” — CVE-2026-7482 (CVSS 9.3) — Heap out-of-bounds read in GGUF model loader allowing unauthenticated memory dump and data exfiltration from exposed Ollama AI servers. Public PoC available. No auth required. Source: Cyber Recaps – May 5cyberrecaps
  3. Ivanti EPMM — Zero-Day (Active Exploitation) — Flaw in Ivanti Endpoint Manager Mobile exploited in limited attacks, enabling attackers to compromise enterprise mobile management platforms, certificates, and user policies. Source: Dr. Jason Edwards Weekly – May 8linkedin
  4. Weaver E-cology CMS — CVE-2026-22679 (High) — Critical RCE vulnerability in the Weaver E-cology office automation platform actively exploited since mid-March for post-compromise reconnaissance across enterprise networks. Source: Cyber Recaps – May 5cyberrecaps
  5. MOVEit Automation — Authentication Bypass (High) — Progress Software patched a high-severity auth bypass in MOVEit Automation this week. MOVEit remains an active target following the mass-exploitation incidents of 2025. Source: Cybersecurity Help – May 8cybersecurity-help
  6. MetInfo CMS — CVE-2026-29014 (RCE, Active Exploitation) — Exploitation of this RCE in the MetInfo enterprise CMS spiked on May 1, with attack traffic originating from IPs in China and Hong Kong. Source: Cybersecurity Help – May 8cybersecurity-help
  7. SimpleHelp — CVE-2024-57726 (CVSS 9.9) — Missing authorization vulnerability allowing full service takeover. CISA federal deadline was May 8, 2026. Linked to ransomware delivery campaigns. Source: The Hacker News / CISA KEVthehackernews
  8. WordPress MStore API — CVE-2021-47933 (CVSS 9.8) — Critical unauthenticated arbitrary file upload vulnerability in MStore API 2.0.6 allowing PHP file uploads and remote code execution via REST API. Source: Red Hot Cyberredhotcyber
  9. Samsung MagicINFO 9 — CVE-2024-7399 (CVSS 8.8) — Path traversal flaw allowing attackers to write arbitrary files as SYSTEM on MagicINFO digital signage servers. CISA federal deadline passed May 8. Source: The Hacker News / CISA KEVthehackernews
  10. Microsoft Edge — Cleartext Password Memory Exposure — Edge’s password manager leaks credentials in cleartext process memory on shared desktops. No CVE assigned, no patch scheduled — a significant risk for shared/enterprise workstations. Source: Cyber Recaps – May 5cyberrecaps

CVE Watch: Top 10 CVEs — Severity, Impact & Patch Status

#CVE IDCVSSProductImpactSource
1CVE-2026-0300CriticalPalo Alto PAN-OSUnauth RCE at root via Captive PortalLinkedIn linkedin
2CVE-2026-74829.3Ollama AI ServerHeap OOB read — memory dump & data exfiltrationCyber Recaps cyberrecaps
3CVE-2024-577269.9SimpleHelp RMMMissing auth — full impersonation takeoverThe Hacker News thehackernews
4CVE-2026-22679HighWeaver E-cologyRCE via office automation exploitCyber Recaps cyberrecaps
5CVE-2026-29014HighMetInfo CMSRCE — active exploitation spike from China/HK IPsCybersecurity Help cybersecurity-help
6CVE-2021-479339.8WordPress MStore APIUnauth arbitrary file upload → RCERed Hot Cyber redhotcyber
7CVE-2024-73998.8Samsung MagicINFO 9Path traversal → SYSTEM-level file writeThe Hacker News thehackernews
8CVE-2025-32975CriticalQuest KACE SMAImproper auth — impersonate any userCISA KEV / CVEFeed cvefeed
9CVE-2026-20131CriticalCisco FMC / SCCJava deserialization → arbitrary code as rootRecorded Future recordedfuture
10CVE-2025-296357.5D-Link DIR-823XCommand injection on EOL routers — botnet recruitmentThe Hacker News thehackernews

Attack Tracker: Top 10 Cyber Attacks (UAE, Gulf & Global)

  1.  UAE — Handala Wiper Hits Local Organisation, 200K Systems Wiped Globally — Iran-linked Handala group targeted a UAE-connected organisation as part of its ongoing wiper campaign that disrupted over 200,000 systems in 79 countries using compromised Microsoft Intune admin accounts. Source: Help AG – May 5helpag
  2.  UAE — 600,000–700,000 Daily Attacks Continue Amid Iran Conflict — UAE remains under sustained assault with cyberattack attempts holding at triple pre-conflict levels. Banks, financial services, e-commerce, oil & gas, and government platforms remain top targets. Source: Economic Timeseconomictimes
  3.  DAEMON Tools Supply Chain Attack — 100+ Countries — Attackers compromised the official DAEMON Tools website to distribute backdoor-laced installers, silently infecting thousands of systems globally since April 8, with targeted second-stage payloads on high-value victims. Source: Cybersecurity Help – May 8cybersecurity-help
  4.  35,000-User Phishing Campaign — 26 Countries in 48 Hours — A Microsoft-tracked credential-theft blitz impersonating compliance/regulatory alerts stole authentication tokens across 13,000+ organisations in healthcare, finance, and tech sectors. Source: Dr. Jason Edwards Weekly – May 8linkedin
  5.  Canada Life Breach — 70,000 Individuals Exposed (ShinyHunters) — ShinyHunters gained access via a compromised employee account at Canada Life, exposing names, DOBs, addresses, and income-related data of up to 70,000 individuals. Source: LinkedIn Cybersecurity Daily Digestlinkedin
  6.  Udemy Breach — 1.4 Million Records Leaked (ShinyHunters) — ShinyHunters listed Udemy on its dark web leak site claiming 1.4 million records stolen. The deadline for negotiations passed April 27, raising likelihood of full data release. Source: LinkedIn Cybersecurity Daily Digestlinkedin
  7.  eBay DDoS Attack — $200M/Day in Estimated Lost Transactions — The 313 Team pro-activist group claimed a large-scale DDoS attack that disrupted eBay’s marketplace for 42–48 hours, causing estimated losses of $200M per day in transactions. Source: LinkedIn Cybersecurity Daily Digestlinkedin
  8.  Venezuelan Energy Sector — Lotus Wiper Destroys Critical Systems — The Lotus Wiper malware destroyed critical operational data across Venezuelan utility firms on April 29, reflecting a growing trend of sabotage-focused attacks on energy infrastructure in geopolitically sensitive regions. Source: Senthorus Weekly Reviewsenthorus
  9.  Vimeo Breach via Third-Party Vendor Anodot (ShinyHunters) — ShinyHunters exploited Vimeo’s analytics vendor Anodot to steal technical data, video metadata, and customer email addresses, threatening to release stolen data unless a ransom is paid. Source: LinkedIn Cybersecurity Daily Digestlinkedin
  10.  Sandhills Medical — Ransomware Breach Affecting 170,000 Patients Disclosed — The Inc Ransom group breached Sandhills Medical Foundation in May 2025 but the healthcare provider only publicly disclosed the incident a full year later in April 2026, exposing SSNs, health records, and financial data. Source: LinkedIn Cybersecurity Daily Digestlinkedin

AI Watch: Top 10 AI Innovations Shaping Cyber & Tech

  1. GPT-5.5 Rolls Out to Enterprise & API — OpenAI’s Smartest Model Yet — OpenAI’s GPT-5.5, released April 23, is now broadly available via API and to Plus/Pro/Enterprise users. It leads in agentic coding, computer use, parallel reasoning, and scientific research tasks. Source: AI Tools Recap – May 2026aitoolsrecap
  2. Anthropic Claude Opus 4.7 Generally Available — Anthropic’s Claude Opus 4.7 launched with notable improvements in advanced software engineering and safety. Claude Mythos — designed to autonomously find software flaws — remains in limited internal testing. Source: Anthropicanthropic
  3. Anthropic NLA: AI “Thoughts” Now Translatable to Human Text — Anthropic’s Natural Language Autoencoders (NLAs) can now translate internal model activations into readable human text, allowing auditors to detect hidden AI motivations — a breakthrough for AI interpretability. Source: LinkedIn AI Highlights – May 9linkedin
  4. AlphaEvolve (Gemini-Powered) Solving Open Problems in Maths & Physics — Google DeepMind’s AlphaEvolve is now designing advanced algorithms to solve previously unsolved mathematical and physics problems autonomously — moving well beyond code generation into original scientific discovery. Source: LinkedIn AI Highlights – May 9linkedin
  5. OpenAI Realtime Suite Goes Live — GPT-Realtime-2, Translate & Whisper — OpenAI launched three new real-time audio models for conversational AI agents, enabling live voice reasoning, real-time translation, and enterprise-grade conversational AI at scale. Source: MarketingProfs AI Update – May 8marketingprofs
  6. Mistral 128B Flagship + Agentic Work Mode in Le Chat — Mistral launched its 128B model with async cloud coding sessions and a new “Work” agentic mode in Le Chat, targeting HR, finance, and customer support automation at enterprise scale. Source: AI Tools Recap – May 2026aitoolsrecap
  7. AWS Bedrock High-Speed — Sub-100ms Inference for Claude & Llama — Amazon Web Services launched Bedrock High Speed using specialised hardware clusters to drive inference latency below 100 milliseconds for massive models like Claude 3.5 and Llama 3. Source: YouTube – May 6 AI Daily Newsyoutube
  8. Zhipu AI GLM-4.7 — Frontier AI Without NVIDIA, 1.2% Hallucination Rate — China’s Zhipu AI released GLM-4.7 trained entirely on Huawei Ascend chips, achieving a 1.2% hallucination rate — the lowest reported by any frontier lab — at just $0.11/M tokens vs Claude Opus at $15/M. Source: AI Model Releases – May 2026mean
  9. IBM Predicts Quantum Outperforms Classical Computers in 2026 — IBM stated that 2026 will mark the first time a quantum computer solves problems better than all classical methods, unlocking breakthroughs in drug development, materials science, and financial optimization. Source: IBM Thinkibm
  10. Ambient AI Emerges as the Architecture Winner of 2026 — AI industry observers are converging on “Ambient AI” — always-on, context-aware AI embedded invisibly into workflows — as the dominant paradigm replacing traditional chatbot interfaces, with Grok Voice Mode and Claude Code leading adoption. Source: LinkedIn AI Highlights – May 9linkedin

Week of April 28–May 4, 2026

Cyber Pulse: Top 10 Cybersecurity Stories This Week

  1. UAE Issues Critical AI-Driven Cyberattack Warning — Dr. Mohammed Al Kuwaiti confirmed Iranian hackers are using ChatGPT to craft phishing emails, build malware, and deploy deepfakes, with up to 700,000 daily attack attempts on the UAE. Source: CXO Insight MEcxoinsightme
  2. ADT Breach Exposes 5.5 Million Records — The ShinyHunters extortion group stole names, phone numbers, addresses, SSN fragments, and dates of birth from home security giant ADT. Notified via Have I Been Pwned. Source: Integrity360integrity360
  3. Windows Shortcut Zero-Day (CVE-2026-32202) Exploited by Russian APT — Microsoft confirmed active exploitation of this LNK file bypass vulnerability by a Russian-linked campaign targeting Ukraine and European entities. Source: LinkedIn / Dr. Jason Edwards Weekly Updatelinkedin
  4. Salesforce-Linked ShinyHunters Breaches Widen — Udemy, Zara, and 7-Eleven were named in dark web leak claims tied to Salesforce integrations, highlighting third-party cloud data exposure risks. Source: LinkedIn Cyber Weeklylinkedin
  5. Social Media Scam Losses Hit $2.1 Billion in US — Fake investment and CAPTCHA SMS fraud schemes are draining bank accounts at scale across the US, per the FTC’s latest data. Source: Integrity360integrity360
  6. Cloudflare 2026 Threat Report: AI Automating Attacks — Cloudflare’s annual report highlights AI being used for real-time network mapping, exploit development, and deepfakes — enabling low-skill actors to run high-impact campaigns. Source: Cloudflare Blogcloudflare
  7. LiteLLM SQL Injection (CVE-2026-42208) Actively Abused — Attackers are exploiting a pre-login SQL injection flaw in the LiteLLM AI gateway to steal cloud credentials and master API keys from OpenAI, Anthropic, and AWS Bedrock integrations. Source: LinkedIn Cyber Weeklylinkedin
  8. UK 2025/26 Cyber Breaches Survey: 43% of Businesses Hit — The UK Government’s annual survey shows phishing remains the #1 attack vector, with nearly half of businesses experiencing incidents. Source: Cyber News Centrecybernewscentre
  9. Venezuelan Energy Firms Hit by Data-Wiping Malware — Critical utility operators in Venezuela were targeted with wiper malware designed to destroy data and impair recovery, elevating OT/ICS threat levels globally. Source: Dr. Jason Edwards Weeklylinkedin
  10. North Korea Controls 76% of All Crypto Stolen in 2026 — Dark Reading reports that DPRK-linked actors have stolen the vast majority of global crypto assets this year via sophisticated exchange and DeFi attacks. Source: Dark Reading

Threat Radar: Top 10 Active Threats, APTs & Dark Web Alerts

  1. KRYBIT Ransomware Identified on Underground Forums — CYFIRMA’s research team discovered a new structured double-extortion ransomware using Tor-based infrastructure, shadow copy deletion, and credential harvesting. Active since April 3, 2026. Source: CYFIRMA Weekly Intel Reportcyfirma
  2. DragonForce Leads Ransomware Activity at 12.3% — Red Piranha’s weekly report shows DragonForce is the most active ransomware operator, followed by Coinbase Cartel (11.23%), ShinyHunters (8.56%), and Qilin (5.88%). Source: Red Piranharedpiranha
  3. APT28 (Fancy Bear) Exploiting Windows Shortcut Files — Recorded Future’s Insikt Group tracked APT28 using CVE-2026-21513 malicious LNK files for multi-stage payload delivery. Source: Recorded Futurerecordedfuture
  4. Iran-Aligned Groups Targeting UAE Infrastructure — Groups including 313 Team, DieNet, Fatimion Cyber Team, and ALTOUFAN TEAM are conducting campaigns against UAE/GCC airports, telecoms, government portals, and media. Source: Economic Timeseconomictimes
  5. UNC6201 (China-Nexus) Deploying BRICKSTORM Backdoor — Suspected Chinese threat actor exploited CVE-2026-22769 in Dell RecoverPoint, deploying the SLAYSTYLE web shell and BRICKSTORM C# backdoor. Source: Recorded Futurerecordedfuture
  6. Qilin Ransomware Joins DragonForce Cartel — Qilin, now part of DragonForce’s RaaS cartel alongside LockBit, targets healthcare, manufacturing, and real estate with double-extortion tactics. Source: FortiGuard Labsfortiguard
  7. Supply Chain Extortion Up 63% in 2025–2026 — Intel 471’s 2026 Cyber Threat Outlook reports supply chain-driven extortion surged 63%, with Qilin as the dominant RaaS force. Top stealers: Lumma, Stealc, Vidar. Source: Intel 471intel471
  8. WallStealer & ShadowLink: Two New Threats Identified — Red Piranha’s April 14–20 report flagged two new tools — WallStealer (credential theft) and ShadowLink (C2 tunneling) — circulating on cybercrime forums. Source: Red Piranharedpiranha
  9. Lotus Blossom APT Exploiting Notepad++ Updater — CVE-2025-15556 (Risk Score: 99) was used over 6 months to replace Notepad++ update packages with Cobalt Strike + Chrysalis backdoor installers. Added to CISA KEV February 12, 2026. Source: Recorded Futurerecordedfuture
  10. Medusa Ransomware Affiliate Using Zero-Days (Storm-1175) — Microsoft linked Storm-1175 to zero-day exploitation enabling rapid network infiltration, data theft, and Medusa ransomware deployment across healthcare, education, and finance. Source: CM Alliancecm-alliance.

Patch Priority: Top 10 Critical Vulnerabilities to Watch

  1. Microsoft Office Remote Code Execution (CVSS 8.4) — CVEs 2026-32190, 2026-33114, 2026-33115: Unauthenticated RCE via use-after-free and untrusted pointer dereference in Office/Word. Patched in April 2026. Source: CrowdStrikecrowdstrike
  2. Windows Shell Zero-Day — LNK File Bypass (CVE-2026-32202) — Attackers use malicious shortcut files to bypass Windows protection checks. Actively exploited by Russian-linked APT, patched in April 2026 Patch Tuesday. Source: LinkedIn Cyber Weeklylinkedin
  3. SimpleHelp CVSS 9.9 Flaw — Remote Code Execution — A critical flaw in SimpleHelp remote support software added to CISA KEV with a May 8, 2026 federal deadline. Actively linked to ransomware delivery. Source: The Hacker Newsthehackernews
  4. Samsung MagicINFO 9 Path Traversal (CVE-2024-7399, CVSS 8.8) — Allows attackers to write arbitrary files as SYSTEM, enabling full server takeover. Added to CISA KEV. Source: The Hacker Newsthehackernews
  5. Microsoft SharePoint Zero-Day Spoofing (CVE-2026-32201) — Actively exploited improper input validation vulnerability used in spoofing attacks. Included in April’s CISA KEV alerts. Source: LinkedIn KEV Reportlinkedin
  6. Fortinet FortiClient EMS SQL Injection (CVE-2026-21643) — Unauthenticated remote code execution via crafted HTTP requests in FortiClient EMS. Added to CISA KEV. Source: LinkedIn KEV Reportlinkedin
  7. ConnectWise ScreenConnect Auth Bypass — Exploited zero-click flaw allowing credential theft and remote access abuse. Federal patching deadline issued by CISA. Source: Dr. Jason Edwards Weeklylinkedin
  8. Linux Zero-Day “Copy Fail” — Root Access — Critical Linux kernel vulnerability enabling local privilege escalation to root. Confirmed exploitation in the wild as of May 1, 2026. Source: Integrity360integrity360
  9. nginx-ui Authentication Bypass (CVE-2026-33032) — Full service takeover via authentication bypass in the popular nginx management UI. Actively exploited. Source: LinkedIn KEVlinkedin
  10. .NET Framework DoS — CVE-2026-23666 (CVSS 7.5) — Critical denial-of-service in .NET Framework allowing unauthenticated remote DoS, no user interaction required. Patched April 2026. Source: CrowdStrike Patch Tuesdaycrowdstrike

CVE Watch: Top 10 CVEs — Severity, Impact & Patch Status

#CVE IDSeverityProductImpact
1CVE-2026-32202CriticalWindows ShellLNK bypass, actively exploited by APT28 linkedin
2CVE-2026-32190Critical (CVSS 8.4)Microsoft OfficeUnauthenticated RCE via use-after-free crowdstrike
3CVE-2025-32975Critical (CVSS 10.0)Quest KACE SMAAuth bypass — impersonate any user, no credentials needed thehackernews
4CVE-2026-42208HighLiteLLMPre-auth SQL injection — AI gateway credential theft linkedin
5CVE-2024-7399High (CVSS 8.8)Samsung MagicINFOPath traversal — write arbitrary files as SYSTEM thehackernews
6CVE-2026-21643HighFortinet FortiClient EMSSQL injection, unauthenticated RCE linkedin
7CVE-2026-32201HighMicrosoft SharePointZero-day spoofing via improper input validation linkedin
8CVE-2026-33032Highnginx-uiAuthentication bypass → full service takeover linkedin
9CVE-2025-29635High (CVSS 7.5)D-Link DIR-823XCommand injection in EOL routers — botnet recruitment thehackernews
10CVE-2026-23666High (CVSS 7.5).NET FrameworkUnauthenticated remote DoS, no interaction required crowdstrike

Attack Tracker: Top 10 Cyber Attacks (UAE, Gulf & Global)

  1.  UAE — 700,000 Daily AI-Powered Attacks from Iran-Linked Actors — Iranian hackers using ChatGPT for deepfakes, phishing, and malware. Targets include hospitals, government databases, and critical infrastructure. Source: The Media Linethemedialine
  2.  UAE — Dubai Land Department, Courts & RTA Hit — DLD, Dubai Courts, and the Road & Transport Authority (RTA) faced cyber incidents in April 2026, along with Sharjah Electricity, Water and Gas Authority. Source: Economic Timeseconomictimes
  3.  ADT — 5.5 Million Customer Records Stolen (ShinyHunters) — US home security giant ADT breached on April 20, 2026, with data including names, addresses, and partial SSNs exfiltrated. Source: Integrity360integrity360
  4.  April 2026 Patch Tuesday Zero-Day Exploited — APT28 (Fancy Bear) conducted DNS hijacking across 120+ countries to intercept Microsoft 365 authentication traffic and steal credentials/tokens. Source: CM Alliancecm-alliance
  5.  EU Commission & Booking.com Among April Breach Victims — A wave of attacks in April 2026 hit the EU Commission, Booking.com, McGrawHill, and Medtronic, across government, healthcare, and travel sectors. Source: CM Alliancecm-alliance
  6.  Venezuelan Utility Operators Hit by Wiper Malware — Energy and utility firms across Venezuela were targeted with data-erasing malware, raising fears of OT infrastructure destruction during geopolitical conflicts. Source: Dr. Jason Edwards Weeklylinkedin
  7.  €50 Million Crypto Fraud Ring Disrupted — European law enforcement broke up a major crypto investment fraud operation that victimized hundreds across the EU using social engineering and pressure tactics. Source: Dr. Jason Edwards Weeklylinkedin
  8.  GitHub Push Bug Exposed Private Enterprise Code — A bug in GitHub’s push mechanism inadvertently leaked private repository code in enterprise systems, putting intellectual property and credentials at risk. Source: Dr. Jason Edwards Weeklylinkedin
  9.  Itron (Utility Systems Supplier) Reports Cyber Intrusion — A confirmed breach at critical infrastructure technology supplier Itron raised concerns across the global utility and smart grid sector. Source: Dr. Jason Edwards Weeklylinkedin
  10.  Medusa Ransomware Zero-Day Campaign — 120+ Countries — Storm-1175 launched zero-day attacks enabling Medusa ransomware deployment across healthcare, education, and finance in 120+ countries within hours. Source: CM Alliancecm-alliance

AI Watch: Top 10 AI Innovations Shaping Cyber & Tech

  1. GPT-5.4 Pro & Gemini 3.1 Pro — Real-Time Multimodal Reasoning — Both models now process text, images, and video simultaneously in real-time, enabling autonomous video analysis and cross-modal task execution without human prompting. Source: LinkedIn / Decoding Data Sciencelinkedin
  2. Google TurboQuant: 80% GPU Cost Reduction for LLMs — Google Research’s TurboQuant compresses LLM key-value cache from 16-bit to 3-bit, enabling massive context processing without hardware upgrades — slashing GPU costs by up to 80%. Source: LinkedIn / Decoding Data Sciencelinkedin
  3. Zhipu AI GLM-5.1: Sovereign AI Reaches Frontier Level — China’s 744-billion-parameter MoE model, trained entirely on Huawei Ascend chips, achieves 94% of Claude’s coding performance — proving sovereign AI stacks are now competitive without NVIDIA. Source: LinkedIn / Decoding Data Sciencelinkedin
  4. Agentic AI Goes Mainstream — 40% of Enterprise Apps by End of 2026 — Gartner predicts 40% of enterprise applications will embed task-specific AI agents by late 2026, up from under 5% in 2025. Orchestration platforms like CrewAI and LangGraph are leading adoption. Source: BuildMVPFastbuildmvpfast
  5. MIT Technology Review: 10 AI Things That Matter in 2026 — MIT’s authoritative annual AI overview identifies the biggest trends shaping AI this year, from memory compression to sovereign infrastructure and autonomous execution layers. Source: MIT Technology Reviewtechnologyreview
  6. Meta Acquires Robotics Startup to Advance Humanoid AI — Meta’s acquisition aims to integrate humanoid robotics capabilities into its AI models, accelerating physical-world AI automation and data collection for self-driving systems. Source: COAIO.comcoaio
  7. RunPod Launches Flash — Open-Source AI Inference SDK — Flash allows developers to go from a local Python function to a live, auto-scaling AI endpoint in minutes, removing container complexity and cutting startup infrastructure costs. Source: COAIO.comcoaio
  8. AI Models Now Match Humans in 83% of Knowledge Work — ARC-AGI-2 and GDPval benchmarks show current frontier models matching professional-level human performance across 83% of knowledge work categories, with hallucination rates dropping sharply. Source: LinkedIn / Decoding Data Sciencelinkedin
  9. UAE, India & Saudi Arabia Building Sovereign AI Infrastructure — The Gulf region is shifting toward nationally controlled AI compute stacks, with UAE emerging as a key global node for sovereign AI development independent of US/Chinese platforms. Source: LinkedIn / Decoding Data Sciencelinkedin
  10. Claude Code Can Now Autonomously Test & Fix Apps — Anthropic’s Claude Code update enables it to independently test software, identify bugs, and apply fixes in multi-step dev workflows — a major leap for autonomous software development agents. Source: Instagram / AI Weeklyinstagram