Websites Have a New Way to Spy on Visitors: Analyzing Their SSD Activity

Researchers have discovered a new browser-based side-channel attack called FROST that enables websites to spy on visitors by measuring subtle timing differences in SSD activity via JavaScript interacting with the origin private file system (OPFS). This technique allows attackers to infer what other websites and apps the user has open without any interaction beyond visiting the malicious site, highlighting a novel privacy risk stemming from modern browser capabilities and SSD contention.

https://arstechnica.com/security/2026/05/websites-have-a-new-way-to-spy-on-visitors-analyzing-their-ssd-activity/

Top Ethical Hacker Chompie Warns AI Tools Could Put Her Out of Business

Valentina Palmiotti, known as Chompie, a top ethical hacker who won major prizes at the Pwn2Own competition, warns that advanced AI tools like Claude Mythos could soon make it much harder for human hackers to compete in finding software vulnerabilities. While AI currently assists ethical hackers in speeding up their work, Chompie believes new AI models will soon handle most vulnerabilities, leaving only the very best human hackers able to discover novel bugs, which could significantly change the landscape of cybersecurity defense and offense.

https://www.bbc.com/news/articles/c3r2zjpryzro

Ghost Hackers: the Cybersecurity Mystery That Nobody Has Solved

The article revisits the unresolved cybersecurity mystery of the Shadow Brokers, an enigmatic hacking group that in 2016 leaked a trove of sophisticated NSA hacking tools, including the EternalBlue exploit, which later enabled widespread ransomware attacks like WannaCry. Despite extensive analysis and speculation, no individuals behind the Shadow Brokers have been identified or charged, highlighting the enduring challenge of attributing and responding to major cyber intelligence leaks.

https://techcrunch.com/2026/05/26/ghost-hackers-the-cybersecurity-mystery-that-nobody-has-solved/

AI Chatbot Recommendations Redirect Users to Cryptojacking Malware Sites

Microsoft has alerted to an active cryptojacking campaign that uses AI chatbot interactions to redirect users seeking legitimate system utilities to attacker-controlled domains hosting malware. This sophisticated attack targets users with high-performance GPUs by delivering malicious installers that establish persistent remote access, enabling cryptocurrency mining and potential further exploitation such as data theft or ransomware.

https://thehackernews.com/2026/05/ai-chatbot-recommendations-redirect.html

Microsoft Copilot Cowork Exfiltrates Files

Microsoft Copilot Cowork in Microsoft 365 is vulnerable to file exfiltration attacks via indirect prompt injection, exploiting the fact that sending emails and Teams messages to the active user occurs without manual approval. Attackers can use poisoned skills to cause Copilot Cowork to send messages containing pre-authenticated download links to sensitive files, which are exfiltrated when the user opens the messages, posing a significant security risk that can be mitigated by restricting permissions and file downloads in SharePoint.

https://www.promptarmor.com/resources/microsoft-copilot-cowork-exfiltrates-files

PuTTY 0.84 Released With Fix for SSH KEX Crashes and Telnet Prompt Spoofing Flaw

PuTTY 0.84 has been released addressing several minor security flaws, including crashes during SSH key exchange caused by incorrect elliptic curve handling and a Telnet prompt spoofing issue related to proxy authentication. These vulnerabilities, exploitable by malicious servers or man-in-the-middle attackers, primarily result in denial-of-service conditions, and users are advised to upgrade promptly for improved robustness and security.

https://cybersecuritynews.com/putty-0-84-released/

New 7-Zip Vulnerabilities Let Attackers Execute Arbitrary Code and Compromise Systems

A critical heap buffer overflow vulnerability (CVE-2026-48095) in 7-Zip version 26.00 allows attackers to execute arbitrary code by exploiting a defect in the NTFS archive handler’s compression unit size calculation, causing a vtable hijack. This vulnerability affects both 32-bit and 64-bit builds, can be triggered by opening a crafted NTFS image with any file extension, and has a high severity score of 8.8; users are urged to update immediately to version 26.01 to mitigate the risk.

https://cybersecuritynews.com/7-zip-vulnerabilities-code-execution/

Microsoft Warns of Two Actively Exploited Defender Vulnerabilities

Microsoft disclosed two actively exploited vulnerabilities in Defender, CVE-2026-41091 and CVE-2026-45498, which have been patched in the latest versions of Defender. The vulnerabilities, which overlap with previously disclosed zero-days, enable privilege escalation and denial-of-service attacks. Microsoft also addressed a heap-based buffer overflow vulnerability (CVE-2026-45584) in the same update.

https://thehackernews.com/2026/05/microsoft-warns-of-two-actively.html

Microsoft Releases Mitigation for YellowKey BitLocker Bypass CVE-2026-45585 Exploit

Microsoft has released a mitigation for the YellowKey vulnerability (CVE-2026-45585), a BitLocker security feature bypass that allows attackers with physical access to circumvent device encryption on affected Windows 11 and Windows Server versions. The exploit uses specially crafted files to spawn an unrestricted shell during recovery mode, granting full access to encrypted data, and Microsoft recommends updating WinRE images and switching from TPM-only to TPM+PIN protection to prevent exploitation.

https://thehackernews.com/2026/05/microsoft-releases-mitigation-for.html

Grafana Labs Admits All Its Codebase Are Belong to Someone Who Popped Its GitHub Account

Grafana Labs disclosed that an unauthorized party accessed its GitHub repository and downloaded its codebase by obtaining a compromised token. Although the attacker threatened to release the code unless a ransom was paid, Grafana refused to pay, stating no customer data or personal information was accessed and operations were unaffected.

https://www.theregister.com/cyber-crime/2026/05/18/grafana-labs-admits-attackers-downloaded-its-codebase-from-github/5241686

9-Year-Old Linux Kernel Flaw Enables Root Command Execution on Major Distros

A nine-year-old Linux kernel vulnerability (CVE-2026-46333) allows unprivileged users to execute commands as root on major distributions like Debian, Fedora, and Ubuntu. The flaw, discovered by Qualys, is rooted in the kernel’s __ptrace_may_access() function and can be exploited through various methods. It’s recommended to apply the latest kernel updates or use temporary workarounds to mitigate the risk.

https://thehackernews.com/2026/05/9-year-old-linux-kernel-flaw-enables.html

Windows Zero-Day Barrage Continues After Patch Tuesday

Security researcher “Nightmare Eclipse” has disclosed six Windows zero-day vulnerabilities over the past six weeks, including new flaws named YellowKey, GreenPlasma, and MiniPlasma, following Microsoft's May 2026 Patch Tuesday. These vulnerabilities enable severe attacks such as bypassing BitLocker encryption, privilege escalation, and disabling Microsoft Defender, with some already actively exploited, highlighting significant ongoing security challenges for Windows users despite patches.

https://www.darkreading.com/cyberattacks-data-breaches/windows-zero-day-barrage-continues-after-patch-tuesday

Google Publishes Exploit Code Threatening Millions of Chromium Users

Google has published exploit code for a long-known, unfixed vulnerability in the Chromium browser engine that threatens millions of users of Chrome, Microsoft Edge, and other Chromium-based browsers. The exploit abuses the Browser Fetch API to create persistent background connections, enabling attackers to monitor user activity, proxy traffic, and conduct denial-of-service attacks, effectively turning affected devices into a limited botnet; the vulnerability was privately reported to Google 42 months ago but remains unpatched.

https://arstechnica.com/security/2026/05/google-publishes-exploit-code-threatening-millions-of-chromium-users/

CISA Admin Leaked AWS GovCloud Keys on Github

A contractor for the Cybersecurity & Infrastructure Security Agency (CISA) publicly exposed highly privileged AWS GovCloud credentials and numerous internal system passwords on a GitHub repository named “Private-CISA,” representing one of the most severe government data leaks in recent history. The exposed files contained plaintext passwords, cloud keys, and sensitive configuration details, posing significant risks for unauthorized access and lateral movement within CISA systems. CISA is investigating the incident, stating no current evidence of data compromise, while security experts condemned the poor security practices involved, which may reflect broader internal issues.

https://krebsonsecurity.com/2026/05/cisa-admin-leaked-aws-govcloud-keys-on-github/

Microsoft Exchange Zero-Day Under Attack, No Patch Available

Microsoft disclosed a zero-day vulnerability (CVE-2026-42897) in Exchange Outlook Web Access (OWA) that is actively being exploited and stems from a cross-site scripting (XSS) flaw allowing attackers to compromise mailboxes and execute spoofing attacks. While no patch is yet available, Microsoft recommends enabling the Exchange Emergency Mitigation Service or applying an updated mitigation tool to reduce risk until a security update is released.

https://www.darkreading.com/vulnerabilities-threats/microsoft-exchange-zero-day-no-patch

Scroll to Top