05/04

2033170 - DigiCert: Misissued code signing certificates

https://bugzilla.mozilla.org/show_bug.cgi?id=2033170
2033170 - DigiCert: Misissued code signing certificates

CISA says ‘Copy Fail’ flaw now exploited to root Linux systems

https://www.bleepingcomputer.com/news/security/cisa-says-copy-fail-flaw-now-exploited-to-root-linux-systems/
CISA says ‘Copy Fail’ flaw now exploited to root Linux systems

Global Crackdown Arrests 276, Shuts 9 Crypto Scam Centers, Seizes $701M

https://thehackernews.com/2026/05/global-crackdown-arrests-276-shuts-9.html
Global Crackdown Arrests 276, Shuts 9 Crypto Scam Centers, Seizes $701M

FreeBSD DHCP Client Vulnerability Enables Remote Code Execution as Root

https://cybersecuritynews.com/freebsd-dhcp-client-vulnerability/
FreeBSD DHCP Client Vulnerability Enables Remote Code Execution as Root

Microsoft confirms April Windows updates cause backup failures

https://www.bleepingcomputer.com/news/microsoft/microsoft-confirms-backup-failures-caused-by-vulnerable-driver-block/
Microsoft confirms April Windows updates cause backup failures

Bluekit phishing kit enables automated phishing with 40+ templates and AI tools - Security Affairs

https://securityaffairs.com/191646/cyber-crime/bluekit-phishing-kit-enables-automated-phishing-with-40-templates-and-ai-tools.html
Bluekit phishing kit enables automated phishing with 40+ templates and AI tools - Security Affairs

"AccountDumpling" – The Google-Sent Phishing Wave Hijacking 30k Facebook Accounts

https://guard.io/labs/accountdumpling---hunting-down-the-google-sent-phishing-wave-compromising-30-000-facebook-accounts
"AccountDumpling" – The Google-Sent Phishing Wave Hijacking 30k Facebook Accounts

Over 40,000 Servers Compromised in Ongoing cPanel Exploitation - SecurityWeek

https://www.securityweek.com/over-40000-servers-compromised-in-ongoing-cpanel-exploitation/
Over 40,000 Servers Compromised in Ongoing cPanel Exploitation - SecurityWeek

Instructure confirms data breach, ShinyHunters claims attack

https://www.bleepingcomputer.com/news/security/instructure-confirms-data-breach-shinyhunters-claims-attack/
Instructure confirms data breach, ShinyHunters claims attack

Experience Report: AI-Assisted BOF Development in Red Teaming

https://avantguard.io/en/blog/erfahrungsbericht-ki-gest%C3%BCtzte-bof-entwicklung-im-red-team
Experience Report: AI-Assisted BOF Development in Red Teaming

Salt Typhoon breach IBM subsidiary in Italy: a warning for Europe’s digital defenses

https://securityaffairs.com/191638/apt/salt-typhoon-breach-ibm-subsidiary-in-italy-a-warning-for-europes-digital-defenses.html
Salt Typhoon breach IBM subsidiary in Italy: a warning for Europe’s digital defenses

Flashback

http://hzed.flashback.sh
Flashback

Exploitation of 'Copy Fail' Linux Vulnerability Begins - SecurityWeek

https://www.securityweek.com/exploitation-of-copy-fail-linux-vulnerability-begins/
Exploitation of 'Copy Fail' Linux Vulnerability Begins - SecurityWeek

Edtech Firm Instructure Discloses Data Breach Amid Hacker Leak Threats - SecurityWeek

https://www.securityweek.com/edtech-firm-instructure-discloses-data-breach/
Edtech Firm Instructure Discloses Data Breach Amid Hacker Leak Threats - SecurityWeek

Progress warns of critical MOVEit Automation auth bypass flaw

https://www.bleepingcomputer.com/news/security/moveit-automation-customers-warned-to-patch-critical-auth-bypass-flaw/
Progress warns of critical MOVEit Automation auth bypass flaw