Known Exploited Vulnerabilities and counting....

A known exploited vulnerability (KEV) refers to a software vulnerability that is being actively exploited by cybercriminals or threat actors. When a vulnerability becomes known to be exploited in the wild, it signals that the vulnerability poses a significant and imminent risk to organizations.

Cybersecurity Brief – May 15, 2026

CISA added Cisco Catalyst SD-WAN vulnerability CVE-2026-20182 to its Known Exploited Vulnerabilities catalog Thursday following confirmed exploitation targeting administrative access. The agency's alert mandates federal agencies patch affected systems, reflecting active threat actor interest in the flaw. Separately, Microsoft's May Patch Tuesday addressed 120 vulnerabilities including 29 critical remote code execution flaws across Windows, Office, Azure, and Microsoft 365 platforms—notably without any zero-day exploits currently seen in the wild.

Foxconn confirmed a ransomware attack by the Nitrogen threat group impacting North American facilities, with attackers claiming exfiltration of over eight terabytes of data comprising 11 million files, including schematics from major technology clients. The breach underscores persistent targeting of manufacturing supply chains. Meanwhile, Comcast reached a $117.5 million settlement over its October 2023 Xfinity breach that exposed millions of customers' credentials and partial Social Security numbers, marking one of the larger data breach settlements in recent months.

A cybersecurity incident in Taiwan drew attention to operational technology vulnerabilities after a student using software-defined radio disrupted three high-speed trains for nearly an hour, exposing critical gaps in rail system security. On the policy front, NIST announced plans to release AI-specific cybersecurity guidelines this summer as two independent analyses from UK AISI and Palo Alto Networks indicate frontier AI systems have surpassed existing autonomous cybersecurity benchmarks, raising concerns about AI-enabled threat capabilities.

Sources: The Hacker News · CISA · Cybersecurity News · Cybersecurity Dive · Yahoo Finance · Dark Reading · Nextgov · National CIO Review

Woman Looking at Computer Screen

CVEs form a database of known security vulnerabilities that are actively tracked and managed by a group of organizations, such as the U.S. National Cyber Security Alliance. CVEs are an important tool for network security management because they not only provide an inventory of existing vulnerabilities, but also provide information about how the vulnerability can be exploited and instructions on how to protect against it.

Search Known Exploits

Search for CVEs by vendor or product to identify known exploited vulnerabilities in your environment

Loading vendors and products...

Upcoming Patch Due Dates

via Binding Operational Directive 22-01

(BOD) 22-01 is a directive issued by the Cybersecurity and Infrastructure Security Agency (CISA) in the United States to federal agencies and federal contractors in order to improve their cybersecurity practices. It provides a set of guidelines and requirements that these agencies and contractors must follow to increase their defenses against cyber threats.

Loading...

News Logo

Cyber Security News

You may have missed...


📌 Pinned

*

https:betanews.comMar 5

Inside a cyberattack: How hackers steal data

The truth about cybersecurity is that it's almost impossible to keep hackers outside of an organization, particularly as the cybercrime industry ...

https://www.yahoo.comMay 15

Pro-Iran Hackers Claim DDoS Attack on Spotify

The Islamic Cyber Resistance in Iraq – 313 Team claimed responsibility for a massive DDoS cyberattack against Spotify's servers, causing major disrupt...

https://www.siliconrepublic.comMay 15

Foxconn Confirms Cyberattack by Nitrogen Ransomware Group

Ransomware group Nitrogen claimed responsibility for breaching Foxconn's North American facilities and exfiltrating 8TB of data including sensitive fi...

https://decode39.comMay 15

Russian-linked hackers, hidden devices and Italian ferries. The Gnv case raises the specter ...

At the centre of the inquiry, according to reporting by Il Foglio, is a lead that points to servers used by a pro-Russian hacking group. That ...

https://www.cisa.govMay 15

CISA Adds One Known Exploited Vulnerability to Catalog | CISA

This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Note: Please ...

https://www.cnn.comMay 15

US fears cyber security breach in China | CNN

CNN's Kristen Holmes reports US officials traveling with President Donald Trump in China were warned of serious cybersecurity risks, ...

https://thehackernews.comMay 15

CISA Adds Cisco SD-WAN CVE-2026-20182 to KEV After Admin Access Exploits

The U.S.Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a newly disclosed vulnerability impacting Cisco Catalyst SD-WAN ...

https://thehackernews.comJun 15

Ripple's xrpl.js Library Compromised in Supply Chain Attack Targeting Cryptocurrency Private Keys

The Ripple cryptocurrency npm JavaScript library xrpl.js was compromised by unknown threat actors in a software supply chain attack designed to harves...

https://www.securityweek.comMay 14

Chinese APTs Expand Targets, Update Backdoors in Recent Campaigns

China-linked APT Twill Typhoon and Salt Typhoon expanded their target list and updated their arsenal in recent intrusions against entities in Asia-Pac...


Updated daily