Known Exploited Vulnerabilities and counting....

A known exploited vulnerability (KEV) refers to a software vulnerability that is being actively exploited by cybercriminals or threat actors. When a vulnerability becomes known to be exploited in the wild, it signals that the vulnerability poses a significant and imminent risk to organizations.

Cybersecurity Brief — May 20, 2026

GitHub is investigating a claimed breach by the group TeamPCP, who allege they've accessed approximately 4,000 internal repositories. The group has reportedly dumped data publicly and stated this is "not a ransom," suggesting the breach was conducted for exposure rather than financial gain. GitHub has not yet confirmed the scope or validity of the claims, but the incident raises questions about code repository security at a platform that hosts critical infrastructure for millions of development projects worldwide.

On the mobile threat front, researchers have uncovered "Trapdoor," a sophisticated ad fraud operation targeting Android users through 455 malicious apps. The scheme generated 659 million fraudulent ad bid requests daily, representing a significant monetization of compromised devices. Meanwhile, CISA faces scrutiny after reports emerged that the agency maintained lists of government accounts and passwords on a publicly accessible database—a fundamental security lapse at an organization tasked with protecting federal infrastructure. Senator Hassan is now demanding answers about the exposure and its potential impact on agency security postures.

Small and medium businesses report reaching a breaking point as 91% express fear about AI-driven attacks, according to new research. The concern reflects a broader pattern: threat complexity and velocity are outpacing defensive capabilities, even as most organizations believe they maintain adequate staffing levels. The gap between perceived and actual security readiness continues to widen as adversaries increasingly leverage automation and AI to scale attacks.

Sources: The Hacker News · The Hacker News · Senator Hassan · Yahoo Finance

Woman Looking at Computer Screen

CVEs form a database of known security vulnerabilities that are actively tracked and managed by a group of organizations, such as the U.S. National Cyber Security Alliance. CVEs are an important tool for network security management because they not only provide an inventory of existing vulnerabilities, but also provide information about how the vulnerability can be exploited and instructions on how to protect against it.

Search Known Exploits

Search for CVEs by vendor or product to identify known exploited vulnerabilities in your environment

Loading vendors and products...

Upcoming Patch Due Dates

via Binding Operational Directive 22-01

(BOD) 22-01 is a directive issued by the Cybersecurity and Infrastructure Security Agency (CISA) in the United States to federal agencies and federal contractors in order to improve their cybersecurity practices. It provides a set of guidelines and requirements that these agencies and contractors must follow to increase their defenses against cyber threats.

Loading...

News Logo

Cyber Security News

You may have missed...


📌 Pinned

*

https:betanews.comMar 5

Inside a cyberattack: How hackers steal data

The truth about cybersecurity is that it's almost impossible to keep hackers outside of an organization, particularly as the cybercrime industry ...

https://thehackernews.comMay 20

NGINX Vulnerability CVE-2026-42945 Under Active Exploitation

A newly disclosed security flaw impacting NGINX Plus and NGINX Open is under active exploitation, tracked as CVE-2026-42945, a heap buffer overflow af...

https://www.binance.comMay 20

Hackers Claim Access to 4,000 GitHub Repositories, Demand $50,000 | Binance News on ...

Hackers from TeamPCP have reportedly accessed source code from approximately 4000 private repositories on GitHub, according to Foresight News.

https://www.pcmag.comMay 20

ShinyHunters Goes After Cybersecurity Firm Warning Victims Not to Pay Ransoms | PCMag

... hacking Canvas, an online educational system used by thousands of universities and schools in the US. The hackers posted an extortion note on ...

https://www.yahoo.comMay 20

Analysis-Fears of unfettered hacking spurred by Anthropic's Mythos AI model overstated

By AJ Vicens May 20 (Reuters) - Early fears that Anthropic's new AI model, Mythos, could dramatically turbocharge hacking are looking overstated a ...

https://www.hassan.senate.govMay 20

Senator Hassan Presses for Answers on Major Reported Data Leak at Leading ...

... Cybersecurity and Infrastructure Security Agency (CISA) maintained lists of agency accounts and passwords on a public database. Senator Hassan ...

https://www.rickscott.senate.govMay 20

Sen. Rick Scott Introduces Bill to Strengthen American Cybersecurity Infrastructure

This legislation would create a joint interagency task force led by the Cybersecurity and Infrastructure Security Agency (CISA) with the goal of ...

https://thehackernews.comMay 20

Trapdoor Android Ad Fraud Scheme Hit 659 Million Daily Bid Requests Using 455 Apps

Cybersecurity researchers have disclosed details of a new ad fraud and malvertising operation dubbed Trapdoor targeting Android device users.

https://www.axios.comMay 20

Scoop: Trump AI executive order seeks early government access to advanced models

The White House plans to release its much-discussed executive order on cybersecurity and AI safety as soon as this week, sources familiar with the ...


Updated daily