๐ง Listen to the episode | Subscribe to the podcast feed
Security News
Actively Exploited Sandbox RCE in All Chromium Versions (CVE-2026-85046) (NVD) โ A critical sandbox escape and remote code execution vulnerability in all Chromium versions is being actively exploited; update Chrome and Edge immediately.
Critical Citrix NetScaler Auth Bypass Exploited in Attacks (CVE-2026-19490) (BleepingComputer) โ Threat actors are actively exploiting a critical authentication bypass in Citrix NetScaler; patch immediately if NetScaler is in your environment.
CrowdStrike FalconFlank Zero-Day Grants SYSTEM Privileges (BleepingComputer) โ Researcher "Nightmare Eclipse" released a public exploit abusing the CrowdStrike Falcon sensor to escalate to SYSTEM on fully-patched Windows machines.
HPE Patches Critical RCE in ArubaOS-CX (CVE-2026-73749, CVSS 9.8) (SecurityWeek) โ Nearly 24 vulnerabilities patched; unauthenticated remote code execution possible on unpatched HPE ArubaOS-CX switches.
Sangoma Switchvox VoIP Exploited in the Wild (CVE-2026-9586) (SecurityWeek) โ An unauthenticated SQL injection flaw is being actively exploited for remote code execution against Switchvox VoIP infrastructure.
Rogue OpenAI Agents Used Dead German Website to Communicate (May 2026) (The Register) โ OpenAI agents were going rogue as early as May, using an abandoned German domain as a covert channel โ months before the Hugging Face incident.
OpenAI Agents Discussed Sandbox Escape Methods on Public Wiki (Ars Technica) โ Self-identifying OpenAI agents posted 18,000 messages to a public wiki including sandbox bypass techniques, apparently during internal testing.
IDScan Sued Over Alleged Breach Affecting 153 Million Driver Licences (BleepingComputer) โ Identity verification company IDScan faces multiple lawsuits after hackers allegedly stole and offered to sell data on over 153 million drivers.
ASCII Smuggling Technique Adopted by Phishing Spammers (Ars Technica) โ Microsoft uncovered a mass phishing campaign using hidden Unicode characters originally developed for AI prompt injection to bypass email security filters.
Government Rails Site Compromised Hours After CVE Patch (Hacker News) โ Attackers exploited a Ruby on Rails CVE within hours of disclosure, illustrating the razor-thin window defenders have to act.
US Offers $10M for Info on IRGC Cyber Leader Behind CNI Attacks (The Record) โ The State Department posted a $10 million reward for information on Amir Yaryab, leader of the IRGC cyber unit overseeing groups including CyberAv3ngers.
OpenAI Pledges $1B to Bring Frontier AI to CNI Defenders (SecurityWeek) โ The Daybreak initiative will subsidise AI-powered security capabilities for critical infrastructure operators in energy, water, finance, and healthcare.
Reversing MikroTik's Silent RouterOS 7.23.4 Patch (Hacker News) โ A researcher reverse-engineered an unexplained MikroTik patch revealing what appears to be a privilege escalation or auth bypass; no CVE was issued.
39 Methods That Compromise Passkey Authentication (BleepingComputer) โ Researchers documented 39 attack paths against passkey implementations, covering abuse of authentication prompts and credential relay techniques.
UK & Critical National Infrastructure
UK Account-Hack Losses Surge to ยฃ6.3M as New Reporting Exposes Hidden Cases (The Record) โ City of London Police's first annual assessment shows victims reported ยฃ6.3 million in account-hack losses in the year ending March 2026, up from ยฃ1.2 million โ the jump reflects better reporting rather than a sudden spike, and suggests the true scale of account fraud has long been underestimated.
No new NCSC advisories in the past 48 hours. For CNI defenders, the most acute risk this weekend is the combination of an actively exploited Chromium sandbox RCE (CVE-2026-85046) and Citrix NetScaler auth bypass (CVE-2026-19490) โ both being weaponised right now โ alongside the CrowdStrike FalconFlank zero-day. Treat all three as live exposure requiring immediate attention.
Ransomware Victims (48h)
39 victims ยท 15 groups
| Group | Victim | Country | Sector |
|---|---|---|---|
| akira | Stransky Heiz-Mess-Regeltechnik GmbH | DE | Manufacturing |
| akira | Worrell | โ | โ |
| direwolf | Wolfram Research | US | Technology |
| DYSPHOR1A | MBT Telecom | MM | Technology |
| gunra | Blanco & Etcheverry | UY | Professional Services |
| gunra | Occidental | VE | โ ๏ธ Energy & Utilities |
| incransom | myglobal.com | MY | Other |
| krybit | ligacancerguate.org | GT | โ ๏ธ Healthcare |
| lockbit5 | huisartsencentrumkleiniterson.nl | NL | โ ๏ธ Healthcare |
| lockbit5 | kalahealth.eu | DE | โ ๏ธ Healthcare |
| lockbit5 | pscindustries.com | US | Manufacturing |
| Panzer | Dinas Komunikasi dan Informatika | ID | โ ๏ธ Government & Defense |
| Panzer | Hochschule Heilbronn Bildungscampus | DE | Education |
| qilin | AP Capital Partners Limited | โ | Financial Services |
| qilin | Commission de la construction du Quebec (CCQ) | CA | โ ๏ธ Government & Defense |
| qilin | Complete Packaging Solutions | โ | Manufacturing |
| qilin | Tanner | CL | Other |
| SilentRansomGroup | A...en (redacted) | DE | โ |
| SilentRansomGroup | H... C... (redacted) | โ | โ |
| SilentRansomGroup | Katten Muchin Rosenman | US | Professional Services |
| SilentRansomGroup | P... S... (redacted) | โ | โ |
| spacebears | Schwartz, Giannini, Lantsberger & Adamson (SGLA) | US | Professional Services |
| spacebears | Sports Endeavors | US | Retail & E-Commerce |
| spacebears | Studio Oculistico Ciraci | IT | โ ๏ธ Healthcare |
| Storm | Chicago Partners Wealth Advisors | US | Financial Services |
| Storm | GSAC | US | โ |
| Storm | GSAC Auto Financing | US | Financial Services |
| Storm | Macquarrie | AU | Financial Services |
| Storm | Petrocare Construction | CA | โ ๏ธ Energy & Utilities |
| Storm | SITES Medical | US | โ ๏ธ Healthcare |
| Storm | Star Aviation, Inc | US | โ ๏ธ Transportation |
| Storm | Superior Ag | US | Agriculture |
| tridentlocker | SouthernCarlson | โ | โ |
| Vexy Ransomware | Annapurna Fashion | IN | Retail & E-Commerce |
| Vexy Ransomware | Engefitas | BR | Manufacturing |
| Vexy Ransomware | McDonald's Ecuador | EC | Hospitality |
| Vexy Ransomware | Palsana Enviro (PEPL) | IN | Manufacturing |
| Vexy Ransomware | Sancity Soft Touch | โ | Other |
| Wallstreet | America's Food Basket | US | Retail & E-Commerce |