Recent Advisories

Severity ID Title Vendor Product Date Type
NONE SCHNEIER:0106E1...

Friday Squid Blogging: Bigfin Squid_SCHNEIER:0106E1E046AEAF90A02057F602F0B689

Article about the bigfin squid. As usual, you can also use this squid post to talk about the security stories in the news that I haven't covered. ...

N/A N/A SCHNEIER
NONE HACKREAD:2BAEC4...

The Next Cybersecurity Challenge May Be Verifying AI Agents_HACKREAD:2BAEC4D0EC8AEE5AA53F0B31B512F92A

AI agents are reshaping cybersecurity. Learn why verification, trusted identity standards, and runtime controls are now essential.

N/A N/A HACKREAD
NONE MSSECURE:EFB879...

Kazuar: Anatomy of a nation-state botnet_MSSECURE:EFB8794560583CDED3097080E38D8DB2

In this article 1. Delivery 2. Module types 3. Botnet operations 4. Who is Secret Blizzard? 5. Mitigation and protection guidance 6. M...

N/A N/A MSSECURE
NONE AKAMAIBLOG:F4D2...

Mini Shai-Hulud: The Worm Returns and Goes Public_AKAMAIBLOG:F4D25B1D0D97F1FD5B5A9DFB2A4FA4C5

{“lastseen”:”2026-05-15T18:05:07″,”description”:””,”published”:”2026-05-15T14:00:...

N/A N/A AKAMAIBLOG
NONE HACKREAD:C2038D...

Hackers Use PyInstaller and AMSI Patching to Deliver XWorm RAT v7.4_HACKREAD:C2038D5E91B5BF75E99339EAFC00B266

Hackers are hiding XWorm malware in PyInstaller files to bypass Windows security, steal data and remotely control devices through ads.

N/A N/A HACKREAD
NONE THN:ABF8D55EC17...

Turla Turns Kazuar Backdoor Into Modular P2P Botnet for Persistent Access_THN:ABF8D55EC17616A17F41AE04CCAFCABE

![](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg8BT1AOScncZQM_A-0WBdCzTDAHGHSey48_Mywhij-TJupCdzP3s3o-MIImRtMZcoV2OqX3RjRV4COpVqkB1...

N/A N/A THN
CRITICAL 9.6 THN:7B70F7FA3D1...

Four OpenClaw Flaws Enable Data Theft, Privilege Escalation, and Persistence_THN:7B70F7FA3D169B0C37FE8A4B304EDDC9

![OpenClaw Flaws](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgz_tK9S8jS_n5CK694-FLGjQP5_Mmpg7z9ZRiBayWsJLsuFRIm-8j1hTlhH90779Fvnvhp...

N/A N/A THN
NONE MALWAREBYTES:AD...

Attackers replaced JDownloader installer downloads with malware_MALWAREBYTES:ADBA5FBB43CDF0C2A7E760B56A5EB285

If you downloaded the JDownloader installer during the compromise window (May 6-7), you are advised to verify the file. JDownloader is a popular d...

N/A N/A MALWAREBYTES
NONE MALWAREBYTES:0E...

Meta’s confusing new approach to chat privacy_MALWAREBYTES:0EBFBEBA3FE059126E8DB76BB934D2F6

Recent news had us wondering whether Meta actually knows what it wants. On one platform, Meta is promoting AI chats that it says even it cannot re...

N/A N/A MALWAREBYTES
NONE HACKREAD:6A519A...

CalPhishing Scam Uses EvilTokens Kit, Outlook Invites to Steal M365 Sessions_HACKREAD:6A519A75E1CC5FFA979C45A02F000751

Hackers are exploiting Outlook calendar invites and device code phishing to steal M365 session tokens, bypass MFA and breach enterprise accounts.

N/A N/A HACKREAD