REPORTS
Fresh threat intelligence we ingest from public vendor and research feeds — each report linked to its original source. Search, filter by source, and open the reference.
Reports
Newest first. Search, filter by source, open the original.
2250 reports · page 41 of 57
huggingface_blog · tlp:amber · 5/27/2026, 12:00:00 AM
Shipping a Trillion Parameters With a Hub Bucket: Delta Weight Sync in TRL Shipping a Trillion Parameters With a Hub Bucket: Delta Weight Sync in TRL Hugging Face Models Datasets Spaces Buckets new Docs Enterprise Pricing Website Tasks HuggingChat Collections Languages Organizations Community Blog Posts Daily Papers Learn Discord Forum GitHub Solutions Team & Enterprise Hugging Face PRO Enterprise Support Inference Providers Inference Endpoints Storage Buckets Log In Sig…
Read original ↗https://huggingface.co/blog/delta-weight-syncmicrosoft_mstic · tlp:amber · 5/26/2026, 9:35:34 PM
From poisoned search results to GPU mining: A cryptojacking campaign abusing ScreenConnect and Microsoft .NET utilities Microsoft exposes a cryptojacking campaign using SEO poisoning and ScreenConnect to target high-performance PCs, with malicious sites also surfaced through AI chatbots. The post From poisoned search results to GPU mining: A cryptojacking campaign abusing ScreenConnect and Microsoft .NET utilities appeared first on Microsoft Security Blog . In this article …
ars_security · tlp:amber · 5/26/2026, 7:50:33 PM
Millions of AI agents imperiled by critical vulnerability in open source package "BadHost" was found in Starlette, a package with 325 million weekly downloads. Millions of AI agents and tools around the world have been imperiled by a critical vulnerability that can allow hackers to breach the servers running them and make off with sensitive data and credentials to third-party accounts, a security researcher is warning. The vulnerability is present in Starlette, an open sour…
Read original ↗https://arstechnica.com/information-technology/2026/05/millions-of-ai-agents-imperiled-by-critical-vulnerability-in-open-source-packagecisa_alerts · tlp:amber · 5/26/2026, 12:00:00 PM
ABB Ability Camera Connect View CSAF Summary ABB is aware of public reports of vulnerabilities in a 3rd party component VLC media player Version 2.2.4 which was delivered together with the installation package of Camera Connect Version 1.5.0.14 and below. An update is available that resolves a privately reported outdated 3rd party component with vulnerabilities in the product versions listed as affected in this advisory. An attacker who successfully exploited any of these vu…
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-146-05cisa_alerts · tlp:amber · 5/26/2026, 12:00:00 PM
ABB B&R Automation Runtime DoS Vulnerability in System Diagnostics Manager (SDM) View CSAF Summary An update is available that resolves a vulnerability identified by B&Rs internal security analysis in the product versions listed as affected in this advisory. An attacker who successfully exploited this vulnerability could cause the product to stop. The following versions of ABB B&R Automation Runtime DoS Vulnerability in System Diagnostics Manager (SDM) are affected: …
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-146-04cisa_alerts · tlp:amber · 5/26/2026, 12:00:00 PM
ABB LVS MConfig View CSAF Summary ABB became aware of an internally discovered vulnerability in the MConfig product versions listed as affected in the advisory. An attacker with access to local networks who successfully exploits vulnerability could have access to application’s sensitive information. ABB strongly advises customers to update MConfig with latest software version. The following versions of ABB LVS MConfig are affected: LVS <=1.4.9.21 CVSS Vendor Equipment Vul…
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-146-06cisa_alerts · tlp:amber · 5/26/2026, 12:00:00 PM
Eppendorf BioFlo 320 View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to gain full access to functionality and data with the bioreactor. The following versions of Eppendorf BioFlo 320 are affected: BioFlo 320 Bioreactor vers:all/* CVSS Vendor Equipment Vulnerabilities v3 9.8 Eppendorf Eppendorf BioFlo 320 Use of Hard-coded Password Background Critical Infrastructure Sectors: Healthcare and Public Health Countries/Areas Deployed: Worldwi…
Read original ↗https://www.cisa.gov/news-events/ics-medical-advisories/icsma-26-146-01cisa_alerts · tlp:amber · 5/26/2026, 12:00:00 PM
CISA Adds One Known Exploited Vulnerability to Catalog CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-48172 LiteSpeed cPanel Plugin Privilege Escalation Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Direct…
Read original ↗https://www.cisa.gov/news-events/alerts/2026/05/26/cisa-adds-one-known-exploited-vulnerability-catalogcisa_alerts · tlp:amber · 5/26/2026, 12:00:00 PM
ABB AC500 V2 View CSAF Summary ABB became aware of vulnerabilities in AC500 V2 listed as affected in the advisory. An attacker who successfully exploited this vulnerability could access fragments of Modbus telegrams that have been sent earlier by that PLC The following versions of ABB AC500 V2 are affected: AC500 V2 <=2.5.2, 2.5.3 CVSS Vendor Equipment Vulnerabilities v3 5.8 ABB ABB AC500 V2 Buffer Over-read Background Critical Infrastructure Sectors: Critical Manufacturi…
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-146-02cisa_alerts · tlp:amber · 5/26/2026, 12:00:00 PM
ABB Terra AC View CSAF Summary ABB is aware of vulnerabilities in the product versions listed as affected in the advisory. An attacker who successfully exploited this vulnerability could cause the pollution of heap memory which potentially takes remote control of the product and performs a write operation to the flash memory to alter the firmware behavior. The following versions of ABB Terra AC are affected: Terra AC wallbox (UL40/80A) <=1.8.32, 1.8.33 Terra AC wallbox (U…
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-146-01cisa_alerts · tlp:amber · 5/26/2026, 12:00:00 PM
ABB Ability Zenon Remote Transport Vulnerability (Update A) View CSAF Summary ABB is aware of vulnerabilities in the product versions listed as affected in the advisory. The vulnerability enables unauthorized access to the Reboot OS function within the Remote Transport Service, allowing an attacker to trigger a system reboot without the required authentication. This functionality initiates a system reboot on the target machine. However, remote exploitation of this vulnerabil…
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-146-03checkpoint_research · tlp:amber · 5/26/2026, 10:09:59 AM
AI Threat Landscape Digest March-April 2026 Executive Summary During the March–April 2026 reporting period, AI use in offensive operations advanced from development and planning to real-time operational deployment. Multiple independent cases, involving individual criminal actors, mass exploitation platforms, ransomware groups, and state-sponsored espionage, show evidence of commercial AI models executing autonomous attack workflows across extended campaigns. Key findings: AI…
Read original ↗https://research.checkpoint.com/2026/ai-threat-landscape-digest-march-april-2026eset · tlp:amber · 5/26/2026, 8:50:00 AM
BTMOB: A stealthy RAT burrowing deep into Android devices The malware pairs remote access capabilities with ready-made campaign tools, lowering the barrier for full device compromise BTMOB: A stealthy RAT burrowing deep into Android devices Award-winning news, views, and insight from the ESET security community English Español Deutsch Português Français TIPS & ADVICE BUSINESS SECURITY ESET RESEARCH About ESET Research Blogposts Podcasts White papers Threat reports WeLiv…
Read original ↗https://www.welivesecurity.com/en/malware/btmob-stealthy-rat-burrowing-deep-android-devicestrend_micro · tlp:amber · 5/26/2026, 12:00:00 AM
Smart Contracts for C&C: How ClearFake Hid in Plain Sight on BSC Testnet TrendAI™ Research analyzed an intrusion where threat actors used the EtherHiding technique to route ClearFake payload delivery through smart contracts on the BNB Smart Chain testnet. The attack chain ended with two simultaneously deployed stealers, SectopRAT and ACRStealer alongside an on-chain execution tracker that confirmed each victim compromise in real time. Smart Contracts for C&C: How ClearF…
Read original ↗https://www.trendmicro.com/en_us/research/26/e/smart-contracts-for-command-and-control.htmlcheckpoint_research · tlp:amber · 5/25/2026, 3:08:40 PM
25th May – Threat Intelligence Report For the latest discoveries in cyber research for the week of 25th May, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES 7-Eleven, the global convenience store chain, confirmed a breach after an unauthorized access to systems used for franchisee documents. ShinyHunters claimed responsibility and said it stole more than 600,000 Salesforce records containing personal […] The post 25th May – Threat Intelligenc…
Read original ↗https://research.checkpoint.com/2026/25th-may-threat-intelligence-reportmandiant · tlp:amber · 5/25/2026, 2:00:00 PM
2 PhaaS 2 Furious: The Evolution of Chinese-Language Phishing Services While Russian-speaking threat actors have historically dominated the phishing-as-a-service (PhaaS) landscape, a rival ecosystem is rapidly growing within the Chinese-language underground. Google Threat Intelligence Group (GTIG) analyzed a dozen current PhaaS offerings in the Chinese underground, all of them mature services and many likely tied intricately to the broader criminal ecosystem in that region. …
Read original ↗https://cloud.google.com/blog/topics/threat-intelligence/chinese-language-phishing-servicesmandiant · tlp:amber · 5/25/2026, 2:00:00 PM
Exploitation of KnowledgeDeliver via ViewState Deserialization Vulnerability Written by: Takahiro Sugiyama, Peter Revelant, Mathew Potaczek Introduction In late 2025, Mandiant responded to a security incident involving a compromised web server running KnowledgeDeliver . KnowledgeDeliver is a Learning Management System (LMS) developed by Digital Knowledge commonly used in Japan. Mandiant identified a critical vulnerability that allowed unauthenticated Remote Code Execution (R…
Read original ↗https://cloud.google.com/blog/topics/threat-intelligence/knowledgedeliver-viewstate-deserialization-vulnerabilitykrebs_on_security · tlp:amber · 5/25/2026, 1:21:49 PM
Netherlands Seizes 800 Servers, Arrests 2 for Aiding Cyberattacks Authorities in the Netherlands have arrested the co-owners of two related Internet hosting companies for operating IT infrastructure used by Russia to carry out cyberattacks, influence operations and disinformation campaigns inside the European Union. The two men were the focus of a 2025 KrebsOnSecurity story about how their hosting companies had assumed control over the technical infrastructure of Stark Indus…
Read original ↗https://krebsonsecurity.com/2026/05/netherlands-seizes-800-servers-arrests-2-for-aiding-cyberattackshuggingface_blog · tlp:amber · 5/25/2026, 12:00:00 AM
Harness, Scaffold, and the AI Agent Terms Worth Getting Right Harness, Scaffold, and the AI Agent Terms Worth Getting Right Hugging Face Models Datasets Spaces Buckets new Docs Enterprise Pricing Website Tasks HuggingChat Collections Languages Organizations Community Blog Posts Daily Papers Learn Discord Forum GitHub Solutions Team & Enterprise Hugging Face PRO Enterprise Support Inference Providers Inference Endpoints Storage Buckets Log In Sign Up Back to Articles Harn…
Read original ↗https://huggingface.co/blog/agent-glossarysnyk_blog · tlp:amber · 5/23/2026, 4:00:00 PM
Laravel Lang Supply Chain Advisory Hundreds of historical Laravel Lang Packagist releases were republished with malicious code, putting Composer installs at risk of credential theft and secret exfiltration. Laravel Lang Supply Chain Advisory | Snyk You need to enable JavaScript to run this app. Skip to main content Platform Platform Snyk AI Security Platform Modern security in a single platform Snyk AI Workflows AI-driven workflows to secure applications DeepCode AI Purpose…
Read original ↗https://snyk.io/blog/laravel-lang-supply-chain-advisoryars_security · tlp:amber · 5/22/2026, 6:43:54 PM
Police boast of hacking VPN where criminals "believed themselves to be safe" Law enforcement intercepted VPN traffic, seized domains, and arrested its operator. European law enforcement say they hacked into a VPN (virtual private network) service used for ransomware attacks and other crimes, and identified thousands of users before shutting the VPN down and arresting its administrator. Europol announced yesterday the results of the operation against the service, First VPN. …
Read original ↗https://arstechnica.com/tech-policy/2026/05/police-boast-of-hacking-vpn-where-criminals-believed-themselves-to-be-safears_security · tlp:amber · 5/22/2026, 6:13:05 PM
Texas AG sues Meta over claims that WhatsApp doesn't provide end-to-end encryption Critics note a lack of factual support in lawsuit filed by US Senate candidate. The Texas Attorney General has sued Meta over allegations that the company’s WhatsApp messenger, used by more than 3 billion people, doesn’t provide the end-to-end encryption (E2EE) it has long claimed. Since at least 2016, Meta (then named Facebook) has said WhatsApp provides robust end-to-end encryption, meaning…
Read original ↗https://arstechnica.com/security/2026/05/texas-ag-sues-meta-over-claims-that-whatsapp-doesnt-provide-end-to-end-encryptionchainalysis · tlp:amber · 5/22/2026, 6:08:12 PM
OFAC and Crypto Crime: Every OFAC Specially Designated National with Identified Cryptocurrency Addresses As far back as the early 1800s, the U.S. Department of the Treasury has issued economic sanctions to achieve foreign… The post OFAC and Crypto Crime: Every OFAC Specially Designated National with Identified Cryptocurrency Addresses appeared first on Chainalysis . OFAC Sanctions Tracker: How Sanctions Impact Crypto Crime - Chainalysis Chainalysis Products Crypto Inv…
Read original ↗https://www.chainalysis.com/blog/ofac-sanctionsmicrosoft_mstic · tlp:amber · 5/22/2026, 5:00:00 PM
Microsoft recognized as a Leader in The Forrester Wave™ for Workforce Identity Security Platforms Microsoft has been recognized as a Leader in The Forrester Wave™: Workforce Identity Security Platforms, Q2 2026, receiving the highest scores in both the current offering and strategy categories. The post Microsoft recognized as a Leader in The Forrester Wave™ for Workforce Identity Security Platforms appeared first on Microsoft Security Blog . Identity is the backbone of mode…
Read original ↗https://www.microsoft.com/en-us/security/blog/2026/05/22/microsoft-recognized-as-a-leader-in-the-forrester-wave-for-workforce-identity-security-platformsmicrosoft_mstic · tlp:amber · 5/22/2026, 4:53:39 PM
From edge appliance to enterprise compromise: Multi-stage Linux intrusion via F5 and Confluence A multi-stage attack on Linux devices began with an exposed F5 BIG-IP edge appliance and pivoted to an internal Confluence server for credential theft and identity compromise. Learn how the threat actor attempted Kerberos relay and lateral movement, and how Microsoft Defender detected, blocked, and unraveled the attack. The post From edge appliance to enterprise compromise: Multi-…
Read original ↗https://www.microsoft.com/en-us/security/blog/2026/05/22/from-edge-appliance-to-enterprise-compromise-multi-stage-linux-intrusion-via-f5-and-confluencekrebs_on_security · tlp:amber · 5/22/2026, 4:34:24 PM
Lawmakers Demand Answers as CISA Tries to Contain Data Leak Lawmakers in both houses of Congress are demanding answers from the U.S. Cybersecurity & Infrastructure Security Agency (CISA) after KrebsOnSecurity reported this week that a CISA contractor intentionally published AWS GovCloud keys and a vast trove of other agency secrets on a public GitHub account. The inquiry comes as CISA is still struggling to contain the breach and invalidate the leaked credentials. Lawm…
Read original ↗https://krebsonsecurity.com/2026/05/lawmakers-demand-answers-as-cisa-tries-to-contain-data-leakmicrosoft_mstic · tlp:amber · 5/22/2026, 4:00:00 PM
Microsoft Security success stories: How St. Luke’s and ManpowerGroup are securing AI foundations How Frontier firms secure AI at scale: read how Microsoft customers embed governance, identity, and cloud security to make protection an enabler of AI growth. The post Microsoft Security success stories: How St. Luke’s and ManpowerGroup are securing AI foundations appeared first on Microsoft Security Blog . AI is reshaping how work gets done—and how risks emerge …
Read original ↗https://www.microsoft.com/en-us/security/blog/2026/05/22/microsoft-security-success-stories-how-st-lukes-and-manpowergroup-are-securing-ai-foundationshuggingface_blog · tlp:amber · 5/22/2026, 3:25:59 PM
Specialization Beats Scale: A Strategic Variable Most AI Procurement Decisions Overlook Specialization Beats Scale: A Strategic Variable Most AI Procurement Decisions Overlook Hugging Face Models Datasets Spaces Buckets new Docs Enterprise Pricing Website Tasks HuggingChat Collections Languages Organizations Community Blog Posts Daily Papers Learn Discord Forum GitHub Solutions Team & Enterprise Hugging Face PRO Enterprise Support Inference Providers Inference Endpoints …
Read original ↗https://huggingface.co/blog/Dharma-AI/specialization-beats-scalecheckpoint_research · tlp:amber · 5/22/2026, 3:09:29 PM
Fast and Furious – Nimbus Manticore Operations During the Iranian Conflict Key Findings Introduction During the recent geopolitical tensions in the Middle East, we reported on multiple Iran-nexus threat actors advancing Iran’s strategic objectives through cyber operations. These activities included targeting internet-connected cameras, conducting destructive attacks against US and Israeli entities, and exfiltrating data from cloud environme…
Read original ↗https://research.checkpoint.com/2026/fast-and-furious-nimbus-manticore-operations-during-the-iranian-conflictunit42 · tlp:amber · 5/22/2026, 1:00:42 PM
Tracking Iranian APT Screening Serpens’ 2026 Espionage Campaigns Unit 42 details Screening Serpens' use of AppDomainManager hijacking and new RAT variants to target tech and defense sectors in recent campaigns. The post Tracking Iranian APT Screening Serpens’ 2026 Espionage Campaigns appeared first on Unit 42 . Tracking Iranian APT Screening Serpens’ 2026 Espionage Campaigns Menu Tools ATOMs Security Consulting About Us Under Attack? Threat Research Center Threat Actor Grou…
Read original ↗https://unit42.paloaltonetworks.com/tracking-iran-apt-screening-serpenscisa_alerts · tlp:amber · 5/22/2026, 12:00:00 PM
CISA Adds One Known Exploited Vulnerability to Catalog CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-9082 Drupal Core SQL Injection Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnera…
Read original ↗https://www.cisa.gov/news-events/alerts/2026/05/22/cisa-adds-one-known-exploited-vulnerability-catalogtrail_of_bits · tlp:amber · 5/22/2026, 11:00:00 AM
We hardened zizmor's GitHub Actions static analyzer In March 2026, attackers exploited a pull_request_target misconfiguration in the aquasecurity/trivy-action GitHub Action to exfiltrate organization and repository secrets, then used those credentials to backdoor LiteLLM on PyPI (see Trivy’s post-mortem for the full timeline). zizmor is a static analyzer that GitHub Actions users run to catch exactly these misconfigurations before they ship. When GitHub Actions added s…
Read original ↗https://blog.trailofbits.com/2026/05/22/we-hardened-zizmors-github-actions-static-analyzerars_security · tlp:amber · 5/22/2026, 10:30:14 AM
A hacker group is poisoning open source code at an unprecedented scale GitHub is just the latest victim of TeamPCP, a gang that has carried out a spree of software supply chain attacks. A so-called software supply chain attack , in which hackers corrupt a legitimate piece of software to hide their own malicious code, was once a relatively rare event but one that haunted the cybersecurity world with its insidious threat of turning any innocent application into a dangerous fo…
Read original ↗https://arstechnica.com/information-technology/2026/05/a-hacker-group-is-poisoning-open-source-code-at-an-unprecedented-scaleunit42 · tlp:amber · 5/22/2026, 10:00:24 AM
Paved With Intent: ROADtools and Nation-State Tactics in the Cloud Open-source framework ROADtools is being misused by threat actors for cloud intrusions. Learn how to identify its malicious use. The post Paved With Intent: ROADtools and Nation-State Tactics in the Cloud appeared first on Unit 42 . Paved With Intent: ROADtools and Nation-State Tactics in the Cloud Menu Tools ATOMs Security Consulting About Us Under Attack? Threat Research Center Threat Research Cloud Cybers…
Read original ↗https://unit42.paloaltonetworks.com/roadtools-cloud-attackseset · tlp:amber · 5/22/2026, 8:50:00 AM
Foul play: Fake FIFA websites target soccer fans looking for World Cup tickets, merchandise Watch out for bogus World Cup websites that mimic official ticket and merchandise flows to steal money and personal data Foul play: Scams target soccer fans with fake World Cup tickets, merchandise Award-winning news, views, and insight from the ESET security community English Español Deutsch Português Français TIPS & ADVICE BUSINESS SECURITY ESET RESEARCH About ESET Research Blo…
Read original ↗https://www.welivesecurity.com/en/cybersecurity/foul-play-fake-fifa-world-cup-websites-ticketstrend_micro · tlp:amber · 5/22/2026, 12:00:00 AM
Analyzing Void Dokkaebi’s Cython-Compiled InvisibleFerret Malware Void Dokkaebi, a North Korea-aligned intrusion set, has updated its information-stealing malware, InvisibleFerret, shifting its delivery format to evade script-based detections. Analyzing Void Dokkaebi’s Cython-Compiled InvisibleFerret Malware | Trend Micro (US) search close About Mission and Culture Mission and Culture As a leader in the AI-driven shift, we are committed to helping organizations navigate and…
Read original ↗https://www.trendmicro.com/en_us/research/26/e/analyzing-void-dokkaebi-invisibleferret-malware.htmlkrebs_on_security · tlp:amber · 5/21/2026, 9:50:25 PM
Alleged Kimwolf Botmaster ‘Dort’ Arrested, Charged in U.S. and Canada Canadian authorities on Wednesday arrested a 23-year-old Ottawa man on suspicion of building and operating Kimwolf, a fast spreading Internet-of-Things botnet that enslaved millions of devices for use in a series of massive distributed denial-of-service (DDoS) attacks over the past six months. KrebsOnSecurity publicly named the suspect in February 2026 after the accused launched a volley of DDoS, doxing an…
Read original ↗https://krebsonsecurity.com/2026/05/alleged-kimwolf-botmaster-dort-arrested-charged-in-u-s-and-canadatalos · tlp:amber · 5/21/2026, 6:00:14 PM
The art of being ungovernable In this edition of the Threat Source newsletter, William explores the value of being "ungovernable" in a professional setting, sharing how challenging the status quo and seeking out the smartest people in the room can lead to a more fulfilling and successful career. Welcome to this week’s edition of the Threat Source newsletter.   “It takes very little to govern good people. Very little. And bad people
…
Read original ↗https://blog.talosintelligence.com/the-art-of-being-ungovernablesnyk_blog · tlp:amber · 5/21/2026, 5:00:00 PM
Snyk announces Anthropic updates: Evo integrates with Claude Enterprise, and Snyk Desk comes to Claude Desktop Snyk announces two new integrations with Anthropic that cover both sides of AI-assisted development. Evo by Snyk now integrates with Anthropic's Claude Enterprise, and the Snyk Security Desktop Extension is now available in Claude for macOS and Windows. Snyk announces Evo Integration with Claude Enterprise and Snyk Desk comes to Claude Desktop | Snyk You need to en…
Read original ↗https://snyk.io/blog/claude-enterprise-integration-desktop-expansionmicrosoft_mstic · tlp:amber · 5/21/2026, 4:00:00 PM
What’s new in Microsoft Security: May 2026 Microsoft Security’s latest updates extend visibility, control, and protection across expanding ecosystems as organizations accelerate AI adoption. The post What’s new in Microsoft Security: May 2026 appeared first on Microsoft Security Blog . At Microsoft, security innovations are purpose-built to help every organization protect end-to-end with the speed and scale of AI. Our vision is simple: security should be ambient and autonom…
Read original ↗https://www.microsoft.com/en-us/security/blog/2026/05/21/whats-new-in-microsoft-security-may-2026