Max-severity flaw in ChromaDB for AI apps allows server hijacking
!https://www.bleepstatic.com/content/hl-images/2026/05/19/Chroma.jpg A max‑severity vulnerability in the latest Python FastAPI version of the ChromaDB project a...
!https://www.bleepstatic.com/content/hl-images/2026/05/19/Chroma.jpg A max‑severity vulnerability in the latest Python FastAPI version of the ChromaDB project a...
End-to-End Encrypted Voice and Video Calls Messaging platform giant Discord has switched on end-to-end encrypted voice and video messaging for every user. The...
!https://www.bleepstatic.com/content/hl-images/2026/05/19/Discord.jpg Announcement Discord announced that all voice and video calls through the platform are now...
!https://www.bleepstatic.com/content/hl-images/2026/05/19/Microsoft365.jpg A threat actor targeting Microsoft 365 and Azure production environments is stealing...
May 12, 2026 Docker AI Governance: Unlock Agent Autonomy, Safely Introducing Docker AI Governance: centralized control over how agents execute, what they can re...
In February 2026, a phishing‑as‑a‑service PhaaS platform called EvilTokens went live. Within five weeks, it had compromised more than 340 Microsoft 365 organiza...
Origin of the Quote The original wording comes from computer scientist Roger Needham: > If you think cryptography can solve your problem, you don’t understand...
!StepSecurity analysis illustrationhttps://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgc7jpVO6HhBuEBTjkwmNjYhKlFmhhmytOqNZHYuGP-dNWrf3AoyE68yoKj77elddOX...
!GitHub Actions supply chain attack illustrationhttps://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgc7jpVO6HhBuEBTjkwmNjYhKlFmhhmytOqNZHYuGP-dNWrf3AoyE6...
PHP 7.4 reached end of life on November 28 2022. PHP 8.0 followed on November 26 2023. PHP 8.1 will reach EOL on December 31 2025. PHP powers roughly 77 % of al...
markdown !https://www.bleepstatic.com/content/hl-images/2026/05/18/Apple.jpg New “Reaper” Variant of the SHub macOS Infostealer A new variant of the SHub macOS...
Overview Ivanti, Fortinet, n8n, SAP, and VMware have released security fixes for a range of vulnerabilities that could be exploited by malicious actors to bypa...
!npm hackinghttps://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhbN7WbW1cUkMzMJl0HPvRrQQUc5MQEE3Pvrc735aG7RGwpguum4POxa4yeQjyIyiAYBDj_Zl6Ud8esex0AnQSG2J6...
!https://www.bleepstatic.com/content/hl-images/2024/05/31/Linux.jpg A recently patched local privilege‑escalation vulnerability in the Linux kernel's rxgk modul...
'Ravie Lakshmanan May 18, 2026 – Industrial Sabotage / Malware
The Pwn2Own Berlin 2026 hacking contest has concluded, with security researchers collecting $1,298,250 in rewards after exploiting 47 zero‑day flaws. The compet...
Summary Chaotic Eclipse, the security researcher behind the recently disclosed Windows flaws YellowKey and GreenPlasma, has released a proof‑of‑concept PoC for...
!https://www.bleepstatic.com/content/hl-images/2021/09/20/Windows.jpg A cybersecurity researcher has released a proof-of-concept exploit for a Windows privilege...
!https://www.bleepstatic.com/content/hl-images/2026/05/15/MS365.jpg The Tycoon2FA phishing kit now supports device-code phishing attacks and abuses Trustifi cli...
Ravie LakshmananMay 17, 2026Server Security / Vulnerability !https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgdFtAiSRukEdQXVvEzXdQKy0O9SY7RCuqFLuAE...
Ravie LakshmananMay 17, 2026Data Breach / Cybercrime !https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjNcCJY0s2GwOwFeSuqVz941pWrGK3theum-FBFyYO97Jn...
!https://www.bleepstatic.com/content/hl-images/2023/06/12/microsoft-azure.jpg A security researcher claims Microsoft quietly fixed an Azure Backup for AKS vulne...
Ravie LakshmananMay 16, 2026Vulnerability / Website Security !https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgYS8AhChFEeH6IwT4x1eB5VAeGfriF4VVcwIN...
!https://www.bleepstatic.com/content/hl-images/2026/05/15/Russia.jpg The Russian hacker group Secret Blizzard has developed its long-running Kazuar backdoor int...
About Bruce Schneier !https://www.schneier.com/wp-content/uploads/2019/10/Bruce-Schneier.jpg I am a public-interest technologisthttps://public-interest-tech.co...
!https://www.bleepstatic.com/content/hl-images/2026/05/15/Woo.jpg A critical vulnerability in the Funnel Builder plugin for WordPress is being actively exploite...
!https://www.bleepstatic.com/content/hl-images/2025/05/19/Pwn2Own_Berlin.jpg During the second day of Pwn2Own Berlin 2026, competitors collected $385,750 in ca...
!https://www.bleepstatic.com/content/hl-images/2026/05/15/npm.jpg Hackers have injected credential-stealing malware into newly published versions of node-ipc, a...
Ravie LakshmananMay 15, 2026Botnet / Threat Intelligence !https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg8BT1AOScncZQM_A-0WBdCzTDAHGHSey48_Mywhij...
!https://www.bleepstatic.com/content/hl-images/2026/05/14/wordpress.jpg Two vulnerabilities in the Avada Builder plugin for WordPress, with an estimated one mil...
!https://www.bleepstatic.com/content/hl-images/2026/05/15/Microsoft-Edge.jpg Microsoft is updating the Edge web browser to ensure it no longer loads saved passw...
!https://www.bleepstatic.com/content/posts/2026/05/infostealer-header.jpg In recent months, a new infostealer malwarehttps://flare.io/learn/resources/blog/infos...
Ravie LakshmananMay 15, 2026Vulnerability / AI Security !OpenClaw Flawshttps://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgz_tK9S8jS_n5CK694-FLGjQP5_M...
!https://www.bleepstatic.com/content/hl-images/2026/03/10/Windows.jpg Microsoft is introducing a new capability that will allow it to remotely roll back problem...
About Bruce Schneier !https://www.schneier.com/wp-content/uploads/2019/10/Bruce-Schneier.jpg I am a public-interest technologisthttps://public-interest-tech.co...
The Hacker NewsMay 15, 2026Endpoint Security / Threat Detection !https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhVcSUDrpIZyFrHqIlIGnXfIShsEamRNvia...
!https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj1l4Vq20M4553fkDfGbO9VqLV9Au-6EefivLp8HT2W5QxJvgWf1mr6pg5xsbC5j3FCJzOOCJv_CImY1LjjFYIN_25ajki1iS_EVP...
!https://www.bleepstatic.com/content/hl-images/2026/05/15/Microsoft-Exchange.jpg On Thursday, Microsoft shared mitigations for a high-severity Exchange Server v...
Ravie LakshmananMay 15, 2026Microsoft / Vulnerability !https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEirN79ZRjEd5wnVbOTlJJsWjQ54cwSj2bM5NDzBSgAFO8...
Ravie LakshmananMay 15, 2026Vulnerability / Credential Theft !https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg4XG5z00sF3uL0ZbhtZNiergQ9QVaZJydwP1p...
!https://www.bleepstatic.com/content/hl-images/2026/05/14/Mistral_AI.jpg The TeamPCP hacker group is threatening to leak source code from the Mistral AI project...
!https://www.bleepstatic.com/content/hl-images/2026/04/15/WordPress.jpg Hackers are leveraging a critical authentication bypass vulnerability in the WordPress p...
!https://www.bleepstatic.com/content/hl-images/2024/07/18/Cisco.jpg Cisco is warning that a critical Catalyst SD-WAN Controller authentication bypass flaw, trac...
!https://www.bleepstatic.com/content/hl-images/2023/04/11/OpenAI_headpic.jpeg OpenAI says two employees' devices were breached in the recent TanStack supply cha...
!https://www.bleepstatic.com/content/hl-images/2025/05/15/Pwn2Own_Berin.jpg On the first day of Pwn2Own Berlin 2026, security researchers collected $523,000 in...
Ravie LakshmananMay 14, 2026Vulnerability / Network Security !https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh9rok1ToP_K0gWug0GnICltZkvx6bMRyhHfTJ...
!https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhTj2m9-HHmDEDzKIsalsJ_HJcwcUsIFajvcpTLP9QMyqS9F_JroTH7lXeOGZFuO6j6F-RzbIo1kBIQ0udSFQGzjN2hxO8ZfyFeHM...
Ravie LakshmananMay 14, 2026Hacking News / Cybersecurity News !https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjImYNT-qC7frGzEXeok3KDX_JNMKote6V1FV...