Known Exploited Vulnerabilities and counting....
A known exploited vulnerability (KEV) refers to a software vulnerability that is being actively exploited by cybercriminals or threat actors. When a vulnerability becomes known to be exploited in the wild, it signals that the vulnerability poses a significant and imminent risk to organizations.
Cybersecurity Brief — May 20, 2026
GitHub is investigating a claimed breach by the group TeamPCP, who allege they've accessed approximately 4,000 internal repositories. The group has reportedly dumped data publicly and stated this is "not a ransom," suggesting the breach was conducted for exposure rather than financial gain. GitHub has not yet confirmed the scope or validity of the claims, but the incident raises questions about code repository security at a platform that hosts critical infrastructure for millions of development projects worldwide.
On the mobile threat front, researchers have uncovered "Trapdoor," a sophisticated ad fraud operation targeting Android users through 455 malicious apps. The scheme generated 659 million fraudulent ad bid requests daily, representing a significant monetization of compromised devices. Meanwhile, CISA faces scrutiny after reports emerged that the agency maintained lists of government accounts and passwords on a publicly accessible database—a fundamental security lapse at an organization tasked with protecting federal infrastructure. Senator Hassan is now demanding answers about the exposure and its potential impact on agency security postures.
Small and medium businesses report reaching a breaking point as 91% express fear about AI-driven attacks, according to new research. The concern reflects a broader pattern: threat complexity and velocity are outpacing defensive capabilities, even as most organizations believe they maintain adequate staffing levels. The gap between perceived and actual security readiness continues to widen as adversaries increasingly leverage automation and AI to scale attacks.
Sources: The Hacker News · The Hacker News · Senator Hassan · Yahoo Finance
Common Vulnerability and Exposure
CVEs form a database of known security vulnerabilities that are actively tracked and managed by a group of organizations, such as the U.S. National Cyber Security Alliance. CVEs are an important tool for network security management because they not only provide an inventory of existing vulnerabilities, but also provide information about how the vulnerability can be exploited and instructions on how to protect against it.
Search Known Exploits
Search for CVEs by vendor or product to identify known exploited vulnerabilities in your environment
Upcoming Patch Due Dates
via Binding Operational Directive 22-01
(BOD) 22-01 is a directive issued by the Cybersecurity and Infrastructure Security Agency (CISA) in the United States to federal agencies and federal contractors in order to improve their cybersecurity practices. It provides a set of guidelines and requirements that these agencies and contractors must follow to increase their defenses against cyber threats.
Loading...
Cyber Security News
You may have missed...
*
Inside a cyberattack: How hackers steal data
The truth about cybersecurity is that it's almost impossible to keep hackers outside of an organization, particularly as the cybercrime industry ...
NGINX Vulnerability CVE-2026-42945 Under Active Exploitation
A newly disclosed security flaw impacting NGINX Plus and NGINX Open is under active exploitation, tracked as CVE-2026-42945, a heap buffer overflow af...
Hackers Claim Access to 4,000 GitHub Repositories, Demand $50,000 | Binance News on ...
Hackers from TeamPCP have reportedly accessed source code from approximately 4000 private repositories on GitHub, according to Foresight News.
ShinyHunters Goes After Cybersecurity Firm Warning Victims Not to Pay Ransoms | PCMag
... hacking Canvas, an online educational system used by thousands of universities and schools in the US. The hackers posted an extortion note on ...
Analysis-Fears of unfettered hacking spurred by Anthropic's Mythos AI model overstated
By AJ Vicens May 20 (Reuters) - Early fears that Anthropic's new AI model, Mythos, could dramatically turbocharge hacking are looking overstated a ...
Senator Hassan Presses for Answers on Major Reported Data Leak at Leading ...
... Cybersecurity and Infrastructure Security Agency (CISA) maintained lists of agency accounts and passwords on a public database. Senator Hassan ...
Sen. Rick Scott Introduces Bill to Strengthen American Cybersecurity Infrastructure
This legislation would create a joint interagency task force led by the Cybersecurity and Infrastructure Security Agency (CISA) with the goal of ...
Trapdoor Android Ad Fraud Scheme Hit 659 Million Daily Bid Requests Using 455 Apps
Cybersecurity researchers have disclosed details of a new ad fraud and malvertising operation dubbed Trapdoor targeting Android device users.
Scoop: Trump AI executive order seeks early government access to advanced models
The White House plans to release its much-discussed executive order on cybersecurity and AI safety as soon as this week, sources familiar with the ...
Updated daily
