05/13

#BadWinmail Demo - YouTube

https://www.youtube.com/watch?v=ngWVbcLDPm8
#BadWinmail Demo - YouTube

Chaotic Eclipse: Two more public disclosures, it will never stop

https://deadeclipse666.blogspot.com/2026/05/two-more-public-disclosures-it-will.html
Chaotic Eclipse: Two more public disclosures, it will never stop

pocs/fragnesia at main · v12-security/pocs · GitHub

https://github.com/v12-security/pocs/tree/main/fragnesia
pocs/fragnesia at main · v12-security/pocs · GitHub

Thomas Dullien zu Anthropics Mythos: Software war nie auf perfekte Sicherheit ausgelegt - das rächt sich | FAZ

https://www.faz.net/premium/digitalwirtschaft/thomas-dullien-zu-anthropics-mythos-software-war-nie-auf-perfekte-sicherheit-ausgelegt-das-raecht-sich-accg-200822228.html
Thomas Dullien zu Anthropics Mythos: Software war nie auf perfekte Sicherheit ausgelegt - das rächt sich | FAZ

Sign in to your account

https://login.microsoftonline.com/
Sign in to your account

Fragnesia - New Linux Kernel Vulnerability Enables Root Access

https://cybersecuritynews.com/fragnesia-linux-vulnerability/
Fragnesia - New Linux Kernel Vulnerability Enables Root Access

Malware Analysis Space: Revisiting Stuxnet: Research Notes

https://malwareanalysisspace.blogspot.com/2026/05/revisiting-stuxnet-research-notes.html
Malware Analysis Space: Revisiting Stuxnet: Research Notes

Microsoft Teams Vulnerability Allows Hackers to Perform Spoofing Attacks

https://cybersecuritynews.com/microsoft-teams-vulnerability-spoofing/
Microsoft Teams Vulnerability Allows Hackers to Perform Spoofing Attacks

716,000 Impacted by OpenLoop Health Data Breach - SecurityWeek

https://www.securityweek.com/716000-impacted-by-openloop-health-data-breach/
716,000 Impacted by OpenLoop Health Data Breach - SecurityWeek

ICS Patch Tuesday: New Security Advisories From Siemens, Schneider, CISA - SecurityWeek

https://www.securityweek.com/ics-patch-tuesday-new-security-advisories-from-siemens-schneider-cisa/
ICS Patch Tuesday: New Security Advisories From Siemens, Schneider, CISA - SecurityWeek

Hundreds of Malicious Packages Force RubyGems to Suspend Registrations - SecurityWeek

https://www.securityweek.com/hundreds-of-malicious-packages-force-rubygems-to-suspend-registrations/
Hundreds of Malicious Packages Force RubyGems to Suspend Registrations - SecurityWeek

This guy crammed a laptop into an Altoids tin | Popular Science

https://www.popsci.com/technology/altoids-tin-computer/
This guy crammed a laptop into an Altoids tin | Popular Science

https://brutal-sam.github.io/uaf-maybe/

https://brutal-sam.github.io/uaf-maybe/

Windows BitLocker zero-day gives access to protected drives, PoC released

https://www.bleepingcomputer.com/news/security/windows-bitlocker-zero-day-gives-access-to-protected-drives-poc-released/
Windows BitLocker zero-day gives access to protected drives, PoC released

Gamaredon's infection chain: Spoofed emails, GammaDrop and GammaLoad - HarfangLab

https://harfanglab.io/insidethelab/gamaredon-gammadrop-gammaload/
Gamaredon's infection chain: Spoofed emails, GammaDrop and GammaLoad - HarfangLab

Foxconn confirms cyberattack claimed by Nitrogen ransomware gang

https://www.bleepingcomputer.com/news/security/electronics-giant-foxconn-confirms-cyberattack-on-north-american-factories/
Foxconn confirms cyberattack claimed by Nitrogen ransomware gang

UK fines water supplier $1.3M for exposing data of 664k customers

https://www.bleepingcomputer.com/news/security/uk-fines-water-supplier-13m-for-exposing-data-of-664k-customers/
UK fines water supplier $1.3M for exposing data of 664k customers

Critical Fortinet FortiSandbox Vulnerability Enables Code Execution Attacks

https://cybersecuritynews.com/fortinet-fortisandbox-vulnerability/
Critical Fortinet FortiSandbox Vulnerability Enables Code Execution Attacks

MalwareBazaar | SHA256 8aadebc4fb43fb6cf3d81d5aa35eb479b9f38087d7f5fcd8f5767535dc548859

https://bazaar.abuse.ch/sample/8aadebc4fb43fb6cf3d81d5aa35eb479b9f38087d7f5fcd8f5767535dc548859/
MalwareBazaar | SHA256 8aadebc4fb43fb6cf3d81d5aa35eb479b9f38087d7f5fcd8f5767535dc548859

Fortinet, Ivanti Patch Critical Vulnerabilities - SecurityWeek

https://www.securityweek.com/fortinet-ivanti-patch-critical-vulnerabilities/
Fortinet, Ivanti Patch Critical Vulnerabilities - SecurityWeek

Microsoft Patches Critical Zero-Click Outlook Vulnerability Threatening Enterprises - SecurityWeek

https://www.securityweek.com/microsoft-patches-critical-zero-click-outlook-vulnerability-threatening-enterprises/
Microsoft Patches Critical Zero-Click Outlook Vulnerability Threatening Enterprises - SecurityWeek

JS-Tap v3: JavaScript Post-Exploitation Moves to the Endpoint - Black Hat USA 2026 | Arsenal Schedule

https://blackhat.com/us-26/arsenal/schedule/index.html?track%5B%5D=exploitation-and-ethical-hacking#js-tap-v3-javascript-post-exploitation-moves-to-the-endpoint-52105
JS-Tap v3: JavaScript Post-Exploitation Moves to the Endpoint - Black Hat USA 2026 | Arsenal Schedule

Malware crew TeamPCP open-sources its Shai-Hulud worm on GitHub

https://www.theregister.com/security/2026/05/13/malware-crew-teampcp-open-sources-its-shai-hulud-worm-on-github/5239319
Malware crew TeamPCP open-sources its Shai-Hulud worm on GitHub

YARA-X just got faster

https://virustotal.github.io/yara-x/blog/yara-x-just-got-faster/
YARA-X just got faster

Microsoft fixes BitLocker recovery issue only for Windows 11 users

https://www.bleepingcomputer.com/news/microsoft/microsoft-fixes-bitlocker-recovery-issue-only-for-windows-11-users/
Microsoft fixes BitLocker recovery issue only for Windows 11 users