The “Disruption Week” operation began May 18, 2026, leading to the takedown of millions of social media, email, and internet access accounts used by transnational
Category Added in a WPeMatico Campaign
WhatsApp, Slack Notifications Could Hijack Google Gemini on Android
No malicious app on the phone is required. The assistant just had to treat a hostile
Google DoubleClick Abused in New Malspam Campaign to Deliver DesckVB RAT
“Before the victim ever reaches attacker-controlled infrastructure, the lure routes through DoubleClick, a legitimate Google-owned domain that many security tools are less likely to treat as
Beyond the Zero-Day: See Your Network Like an Attacker | Webinar with HD Moore
That is a question about the shape of your network, and most teams have the shape wrong. HD Moore, creator of Metasploit
Microsoft 365 Android Apps Let Any App Steal Account Tokens via Leftover Debug Flag
Any other app on the same phone could ask for the signed-in user’s token and get it, then read email, open files, browse the calendar, and send messages as that user. No password, no login screen, no permission prompt.
Autonomous AI Tool Finds 2-Year-Old RCE Flaw in Redis (CVE-2026-23479)
Tracked as CVE-2026-23479, the flaw was introduced in Redis 7.2.0 and remained in every stable branch until the May 5 fixes, unnoticed for over two years.
One-Click GitHub Dev Attack Lets Attackers Steal Full GitHub OAuth Tokens
“Just by clicking a link, it’s possible for an attacker to steal a GitHub token that can read and write to your repos, including private ones,” security researcher Ammar Askar said.
GitHub supports a feature called GitHub.dev that runs as
Unpatched Windows Search URI Vulnerability Lets Attackers Steal NTLMv2 Hashes
Like in the case of CVE-2026-33829, which impacted the Windows Snipping Tool’s ms-screensketch: URI handler, the newly flagged issue resides in the search: URI handler, per Huntress.
CVE-2026-33829 refers to a spoofing vulnerability that could expose
New HTTP/2 Bomb Vulnerability Allows Remote DoS on NGINX, Apache, IIS, Envoy & Cloudflare
The vulnerability has been codenamed HTTP/2 Bomb by Calif.
“The vulnerable behavior exists in each server’s default HTTP/2 configuration,” the company said, adding it was discovered by OpenAI Codex by chaining
Weedhack Attacks Minecraft Users, CountLoader Hits 86K, Miners Spread via Pirated Content
The Minecraft-focused malware-as-a-service (MaaS) campaign has been codenamed Weedhack by McAfee Labs, stating the activity has been active since January 2026 and impersonates Minecraft clients and mods to infect users. In all, 3820
