Latest NEWS
Security Advisory

Cyber Pioneers Ponder Past as Prologue
Robert "RSnake" Hansen, Katie Moussouris, Rich Mogull, Richard Stiennon, and Bruce Schneier reflect on how their favorite columns penned for Dark Reading over the past 20 years have stood the test of time.
Sun May 17 2026 13:35:09 GMT+0000 (Coordinated Universal Time)
From:
Kelly Jackson Higgins, Becky Bracken [darkreading]

Avada Builder WordPress plugin flaws allow site credential theft
Two vulnerabilities in the Avada Builder plugin for WordPress, with an estimated one million active installations, allow hackers to read arbitrary files and extract sensitive information from the database. [...]
Sun May 17 2026 13:35:09 GMT+0000 (Coordinated Universal Time)
From:
Bill Toulas [BleepingComputer]

PhantomRPC: A new privilege escalation technique in Windows RPC
Kaspersky researcher discovered a vulnerability in RPC architecture that enables an attacker to create a fake RPC server and escalate their privileges.
Sun May 17 2026 13:35:09 GMT+0000 (Coordinated Universal Time)
From:
Haidar Kabibo [Securelist]

Inside the REMUS Infostealer: Session Theft, MaaS, and Rapid Evolution
Stolen browser sessions and authentication tokens are becoming more valuable than stolen passwords. Flare explains how the REMUS infostealer evolved around session theft and operational scalability. [...]
Sun May 17 2026 13:35:09 GMT+0000 (Coordinated Universal Time)
From:
Sponsored by Flare [BleepingComputer]

Grafana GitHub Token Breach Led to Codebase Download and Extortion Attempt
Grafana has disclosed that an "unauthorized party" obtained a token that granted them the ability to access the company's GitHub environment and download its codebase.
"Our investigation has determined that no customer data or personal information was accessed during this incident, and we have found no evidence of impact to customer systems or operations," Grafana
said
in a series of
Sun May 17 2026 13:35:09 GMT+0000 (Coordinated Universal Time)
From:
info@thehackernews.com (The Hacker News) [The Hacker News]

Microsoft backpedals: Edge to stop loading passwords into memory
Microsoft is updating the Edge web browser to ensure it no longer loads saved passwords into process memory in clear text at startup after previously stating it was "by design." [...]
Sun May 17 2026 13:35:09 GMT+0000 (Coordinated Universal Time)
From:
Sergiu Gatlan [BleepingComputer]

The Boring Stuff is Dangerous Now
AI agents capable of discovering and exploiting obscure vulnerabilities are emerging alongside developers producing vast amounts of potentially flawed AI-generated code, forcing defenders to adapt accordingly.
Sun May 17 2026 13:35:09 GMT+0000 (Coordinated Universal Time)
From:
Shlomie Liberow [darkreading]

Taiwan Bullet Train Hack Highlights Cybersecurity Gaps in Rail Systems
A Taiwanese student experimenting with software-defined radio technology shut down three bullet trains for nearly an hour, leading to an anti-terrorism response.
Sun May 17 2026 13:35:09 GMT+0000 (Coordinated Universal Time)
From:
Robert Lemos [darkreading]


.jpg)



