Known Exploited Vulnerabilities and counting....

A known exploited vulnerability (KEV) refers to a software vulnerability that is being actively exploited by cybercriminals or threat actors. When a vulnerability becomes known to be exploited in the wild, it signals that the vulnerability poses a significant and imminent risk to organizations.

Cybersecurity Brief – May 17, 2026

A prolific threat actor linked to the ShinyHunters, Scattered Spider, and LAPSUS$ ecosystems has struck multiple high-profile targets this week. Grafana Labs confirmed that stolen GitHub tokens allowed attackers to download portions of their codebase before launching an extortion attempt. Separately, ShinyHunters claimed responsibility for breaching Canvas, the widely-used learning management platform operated by Instructure, exposing personal data of approximately 306,000 University of Pennsylvania affiliates. The incidents underscore continued aggressive targeting of development infrastructure and SaaS platforms by groups known for data theft and extortion operations.

In the manufacturing sector, Foxconn confirmed cyberattacks on its North American factory operations, with the Nitrogen ransomware gang claiming theft of 8TB of data spanning 11 million files. The breach affects the world's largest electronics manufacturer, raising concerns about supply chain security and operational disruption. Meanwhile, European fitness chain Basic-Fit disclosed a breach exposing personal information of approximately one million customers. On the defensive front, Microsoft's May 2026 Patch Tuesday addressed over 120 vulnerabilities—including 17 rated critical—marking the first monthly update since June 2024 without any actively exploited zero-day flaws, a rare positive signal in an otherwise active threat landscape.

Sources: The Hacker News · Bleeping Computer · The Daily Pennsylvanian

Woman Looking at Computer Screen

CVEs form a database of known security vulnerabilities that are actively tracked and managed by a group of organizations, such as the U.S. National Cyber Security Alliance. CVEs are an important tool for network security management because they not only provide an inventory of existing vulnerabilities, but also provide information about how the vulnerability can be exploited and instructions on how to protect against it.

Search Known Exploits

Search for CVEs by vendor or product to identify known exploited vulnerabilities in your environment

Loading vendors and products...

Upcoming Patch Due Dates

via Binding Operational Directive 22-01

(BOD) 22-01 is a directive issued by the Cybersecurity and Infrastructure Security Agency (CISA) in the United States to federal agencies and federal contractors in order to improve their cybersecurity practices. It provides a set of guidelines and requirements that these agencies and contractors must follow to increase their defenses against cyber threats.

Loading...

News Logo

Cyber Security News

You may have missed...


📌 Pinned

*

https:betanews.comMar 5

Inside a cyberattack: How hackers steal data

The truth about cybersecurity is that it's almost impossible to keep hackers outside of an organization, particularly as the cybercrime industry ...

https://tech.yahoo.comMay 17

Internet connected Yarbo mowers turned into potential hacking weapon - Yahoo Tech

Hackers could theoretically activate blades remotely, scan nearby networks, or assemble the devices into a botnet for larger attacks. Makris noted ...

https://www.msn.comMay 17

Suspected Iranian hackers breach US gas station fuel monitors - MSN

What happened: Hackers accessed unprotected automatic tank gauge systems at U.S. gas stations, altering display readings but not fuel quantities.

https://www.thedp.comMay 17

University of Pennsylvania Canvas Data Breach Affects 306,000 Users After ShinyHunters Breaches Instructure

ShinyHunters claimed responsibility for breaching the Canvas learning management platform and leaking data affecting 306,000 University of Pennsylvani...

https://www.bleepingcomputer.comMay 17

Basic-Fit Dutch Fitness Giant Suffers Data Breach Exposing 1 Million Customer Records

Dutch fitness giant Basic-Fit announced that hackers breached its systems and gained access to personal information belonging to one million of its cu...

https://www.bleepingcomputer.comMay 17

Foxconn Confirms Cyberattack on North American Factories, Nitrogen Ransomware Claims 8TB Data Theft

The world's largest electronics manufacturer Foxconn confirmed a cyberattack affecting North American factories, with the Nitrogen ransomware gang cla...

https://www.msn.comMay 16

Canadian teen charged in US$13M cross-border crypto scam - MSN

New tech threats: AI tools like voice cloning are enabling more convincing scams that can bypass traditional security checks. Canadian teen indicted ....

https://www.commerce.senate.govDec 2

Experts Agree U.S. Communications Networks Remain Vulnerable Following Salt Typhoon Hack

U.S. Senator Maria Cantwell held a hearing with telecommunications and cybersecurity experts expressing concerns that telecom companies have failed to...

https://www.insidehighered.comMay 12

Instructure Pays Ransom to Canvas Hackers

Instructure paid a ransom to ShinyHunters that breached its Canvas learning management system twice over a week and a half, affecting 275 million user...


Updated daily