SecurityTicks

⚡ Weekly Recap: Linux Rootkit, macOS Crypto Stealer, WebSocket Skimmers and More

⚡ Weekly Recap: Linux Rootkit, macOS Crypto Stealer, WebSocket Skimmers and More 2026-05-11 at 16:48 By Rough Monday. Somebody poisoned a trusted download again, somebody else turned cloud servers into public housing, and a few crews are still getting into boxes with bugs that should’ve died years ago — the same old holes, same lazy […]

⚡ Weekly Recap: Linux Rootkit, macOS Crypto Stealer, WebSocket Skimmers and More Read More »

Cloudflare Lays Off 1,100 Employees in AI-Driven Restructuring

Cloudflare Lays Off 1,100 Employees in AI-Driven Restructuring 2026-05-11 at 15:09 By Eduard Kovacs The company topped revenue and earnings forecasts for the first quarter of 2026, but its shares plunged more than 20%. The post Cloudflare Lays Off 1,100 Employees in AI-Driven Restructuring appeared first on SecurityWeek. This article is an excerpt from SecurityWeek

Cloudflare Lays Off 1,100 Employees in AI-Driven Restructuring Read More »

Inside Meta’s threat to exit New Mexico over kids safety rules — and whether experts believe the ploy will work

Inside Meta’s threat to exit New Mexico over kids safety rules — and whether experts believe the ploy will work 2026-05-11 at 13:58 By Thomas Barrabi Meta claims the remedies sought by New Mexico Attorney General Raúl Torrez – including an effective age verification process and recommendation algorithms that prioritize user safety over engagement– are “so

Inside Meta’s threat to exit New Mexico over kids safety rules — and whether experts believe the ploy will work Read More »

Instagram messaging encryption removed, and privacy advocates are pushing back

Instagram messaging encryption removed, and privacy advocates are pushing back 2026-05-11 at 13:57 By Anamarija Pogorelec After introducing optional end-to-end encrypted messaging in 2023, Instagram announced in March 2026 that encryption for direct messages would be discontinued, and the feature was removed on May 8. The change allows Instagram to access direct message content, including

Instagram messaging encryption removed, and privacy advocates are pushing back Read More »

The questionnaire-based TPRM model is broken, and TrustCloud has a fix

The questionnaire-based TPRM model is broken, and TrustCloud has a fix 2026-05-11 at 13:57 By Industry News TrustCloud announced a new version of TrustLens, its third party risk management (TPRM) solution. The new TrustLens agentic AI capabilities focus on delivering four requirements every CISO wants in their TPRM program: speed, accuracy, coverage, and proactive risk

The questionnaire-based TPRM model is broken, and TrustCloud has a fix Read More »

SailPoint Discloses GitHub Repository Hack

SailPoint Discloses GitHub Repository Hack 2026-05-11 at 13:57 By Ionut Arghire The incident occurred on April 20 and did not affect customer data in the company’s production and staging environments. The post SailPoint Discloses GitHub Repository Hack appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

SailPoint Discloses GitHub Repository Hack Read More »

Checkmarx Jenkins AST Plugin Compromised in Supply Chain Attack

Checkmarx Jenkins AST Plugin Compromised in Supply Chain Attack 2026-05-11 at 13:57 By Ionut Arghire A malicious version of the plugin was published to the Jenkins Marketplace late last week. The post Checkmarx Jenkins AST Plugin Compromised in Supply Chain Attack appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Checkmarx Jenkins AST Plugin Compromised in Supply Chain Attack Read More »

The scam economy has found its AI upgrade

The scam economy has found its AI upgrade 2026-05-11 at 12:32 By Anamarija Pogorelec Scam attempts continue to reach consumers via email, text messages, social media, online advertising, and phone calls. The volume of exposure has remained stable over the past year, with more than half of consumers encountering scam attempts at least monthly, according

The scam economy has found its AI upgrade Read More »

Canvas System Is Online After a Cyberattack Disrupted Thousands of Schools

Canvas System Is Online After a Cyberattack Disrupted Thousands of Schools 2026-05-11 at 11:58 By Associated Press Tens of thousands of students studying for final exams around the world have regained access to a key online learning system after a cyberattack had earlier knocked it offline. The post Canvas System Is Online After a Cyberattack

Canvas System Is Online After a Cyberattack Disrupted Thousands of Schools Read More »

New ‘Dirty Frag’ Linux Vulnerability Possibly Exploited in Attacks

New ‘Dirty Frag’ Linux Vulnerability Possibly Exploited in Attacks 2026-05-11 at 11:27 By Eduard Kovacs Also called Copy Fail 2 and tracked as CVE-2026-43284 and CVE-2026-43500, the exploit was disclosed before a patch was released. The post New ‘Dirty Frag’ Linux Vulnerability Possibly Exploited in Attacks appeared first on SecurityWeek. This article is an excerpt

New ‘Dirty Frag’ Linux Vulnerability Possibly Exploited in Attacks Read More »

Fake OpenAI Privacy Filter Repo Hits #1 on Hugging Face, Draws 244K Downloads

Fake OpenAI Privacy Filter Repo Hits #1 on Hugging Face, Draws 244K Downloads 2026-05-11 at 11:27 By A malicious Hugging Face repository managed to take a spot in the platform’s trending list by impersonating OpenAI’s Privacy Filter open-weight model to deliver a Rust-based information stealer to Windows users. The project, named Open-OSS/privacy-filter, masqueraded as its

Fake OpenAI Privacy Filter Repo Hits #1 on Hugging Face, Draws 244K Downloads Read More »

Resurrected ‘Crimenetwork’ Marketplace Taken Down, Administrator Arrested

Resurrected ‘Crimenetwork’ Marketplace Taken Down, Administrator Arrested 2026-05-11 at 10:38 By Ionut Arghire The second iteration of the German-speaking online crime marketplace had over 22,000 users and more than 100 sellers. The post Resurrected ‘Crimenetwork’ Marketplace Taken Down, Administrator Arrested appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Resurrected ‘Crimenetwork’ Marketplace Taken Down, Administrator Arrested Read More »

Rustinel: Open-source endpoint detection for Windows and Linux

Rustinel: Open-source endpoint detection for Windows and Linux 2026-05-11 at 08:51 By Mirko Zorz Open-source endpoint detection has long been split between Windows-focused tools built around Sysmon and Linux tools built around eBPF or auditd. Defenders running mixed environments have had to stitch together separate pipelines, separate rule sets, and separate maintenance burdens. Rustinel, a

Rustinel: Open-source endpoint detection for Windows and Linux Read More »

Security teams are turning to AI to survive alert overload

Security teams are turning to AI to survive alert overload 2026-05-11 at 08:18 By Anamarija Pogorelec The World Economic Forum white paper “Empowering Defenders: AI for Cybersecurity” identified AI as the biggest driver of change in cybersecurity for 94% of survey respondents. The paper found that 77% of organizations already use AI in cybersecurity, with

Security teams are turning to AI to survive alert overload Read More »

Review: Foundations of Cybersecurity, 2nd edition

Review: Foundations of Cybersecurity, 2nd edition 2026-05-11 at 08:18 By Mirko Zorz Jason Andress has refreshed his introductory security text for No Starch Press. He writes in the introduction that the term security now extends past data center servers to cloud resources, mobile devices, the Internet of Things, and AI. About the author Jason Andress

Review: Foundations of Cybersecurity, 2nd edition Read More »

Over 500 Organizations Hit in Years-Long Phishing Campaign

Over 500 Organizations Hit in Years-Long Phishing Campaign 2026-05-11 at 07:22 By Ionut Arghire Victims span across the aviation, critical infrastructure, energy, logistics, public administration, and technology sectors. The post Over 500 Organizations Hit in Years-Long Phishing Campaign appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Over 500 Organizations Hit in Years-Long Phishing Campaign Read More »

Ollama Out-of-Bounds Read Vulnerability Allows Remote Process Memory Leak

Ollama Out-of-Bounds Read Vulnerability Allows Remote Process Memory Leak 2026-05-10 at 16:03 By Cybersecurity researchers have disclosed a critical security vulnerability in Ollama that, if successfully exploited, could allow a remote, unauthenticated attacker to leak its entire process memory. The out-of-bounds read flaw, which likely impacts over 300,000 servers globally, is tracked as CVE-2026-7482 (CVSS

Ollama Out-of-Bounds Read Vulnerability Allows Remote Process Memory Leak Read More »

Scroll to Top