• Multiple critical vulnerabilities in the SEPPmail Secure E-Mail Gateway are putting thousands of organizations at risk of remote code execution (RCE) and the interception of sensitive email. The flaws, tracked under several CVEs, impact widely deployed SEPPmail appliances used for encrypted email communication, particularly across the DACH region (Germany, Austria, Switzerland). Security researchers warn that […]

    The post SEPPmail Gateway Flaws Expose Organizations to RCE and Email Traffic Interception appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A new AI model from Anthropic is changing how security teams find and prove software vulnerabilities. It is raising hard questions about what happens when the same technology falls into the wrong hands. Cloudflare has published findings from its participation in Project Glasswing, Anthropic’s controlled research program, revealing that Mythos Preview, a security-focused large language model, can […]

    The post Mythos Preview Automates PoC Exploit Creation for Vulnerability Research appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Nx Console’s popular VS Code extension was briefly weaponized into a credential-stealing tool that can leak developer and cloud secrets and plant a persistent backdoor. Anyone who installed v18.95.0 should treat their environment as fully compromised. On May 18, 2026, a malicious build of the Nx Console VS Code extension, nrwl.angular-console v18.95.0 was published to the Visual […]

    The post Compromised Nx Console VS Code Extension Steals Developer and Cloud Secrets appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Cybersecurity researchers have discovered a fresh software supply chain attack campaign that has compromised various npm packages associated with the @antv ecosystem as part of the ongoing Mini Shai-Hulud attack wave. “The attack affects packages tied to the npm maintainer account atool, including echarts-for-react, a widely used React wrapper for Apache ECharts with roughly 1.1 million weekly

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • AI models with advanced hacking capabilities like Anthropic’s Mythos should concern federal agencies that handle sensitive information, a top CIA tech official said.

    “I think it is a reflection point and I think people need to view it in that fashion,” said Dan Richard, associate deputy director of the CIA’s Digital Innovation Directorate. Richard spoke on a panel Friday at the Qualys ROCon Public Sector 2026 conference in Tysons Corner, Virginia.

    An early version of the Mythos software was released to a limited group of tech companies in April with much fanfare, due to its ability to find long-hidden software bugs and defects. Security researchers and experts reacted with a mix of excitement and caution, with some warning the software could usher in a new era for hackers and lower the barrier to entry for attackers. Mythos and competing models like OpenAI’s GPT-5.5 have forced executive agencies to grapple with their capabilities and prompted emergency briefings for lawmakers.

    Richard said he feels “bullish in terms of the opportunities that are out there,” largely because these AI models can help agencies like the CIA deal with the deluge of data they generate and automate responses to potential threats. He likened the current Mythos-driven moment to Ukraine’s response to Russia’s invasion in 2022.

    Ukraine "had gone through a decade of the Russians infiltrating their networks and having to deal with that implication, but when the Russians attacked in 2022 the Ukrainians were prepared because they understood they couldn’t do it themselves,” he said. “Shoulder-to-shoulder with them were the private sector vendors to support what they were doing and to help what they’re doing.”

    Richard said the U.S. government is in the “same position” now, and public-private partnerships will be key to ensuring the nation gets it right.

    “80% of our nation’s critical infrastructure is in private sector hands, so there is no solution that does not include private sector partners,” Richard said. “We talk about partnership all the time, but this is really different. This isn’t transactional. This is us, as a country, figuring out with the academic community, with the private sector community and with our public-sector partners working together to be able to defeat and take advantage of what I see as an optimal opportunity for the agency, but for the country.”

    Joe Kelly, division director of the Applied Research Laboratory for Intelligence and Security at the University of Maryland, said advanced AI models are going to lower the barrier to entry for hackers.

    “The real danger when we look at something like Mythos — whether you believe the hype or not — is it certainly creates what we already see with Claude Code, the ability for script kiddies to cause real damage even without knowing what they’re doing,” Kelly said. “It’s going to lift all those. I do worry about the complexity that we’re entering in this era.”

    ‘It’s moving so fast, it’s scary’

    IonQ Chief Information Officer Katie Arrington, who served last year as the Pentagon’s chief information officer, said the influx of advanced AI tools — and the speed at which they’re emerging — will test government to the extreme. Existing governance requires IT security vulnerabilities be patched within 30 days, and 15 days for vulnerabilities designated “critical.”

    “You don’t have time like that anymore,” Arrington said during a panel at the Qualys event. “We’re talking about a tool that can find every vulnerability in seconds on a platform.”

    Arrington said these kinds of advanced AI models weren’t a discussion item even 12 months ago. At that time, the Pentagon was just trying to improve the speed that it could bring general AI tools into its networks.

    “It’s moving so fast, it’s scary,” Arrington said. “It scares me and it excites me how fast Mythos came alive.”

    Qualys CEO Sumedh Thakar said federal agencies may need to take a more proactive — rather than reactive — approach to risk management to deal with the growing range of threats from advanced AI tools. His company is using its AI-powered cybersecurity tools, including TotalCloud, which recently received authorization to operate in the government’s FedRAMP High environments, to allow customers to automate vulnerability patching, reducing some of the manual processes and “dashboard tourism” cyber professionals otherwise deal with.

    Thakar said autonomous remediation allows savvy customers to “battle AI with the speed of AI.”

    “Now with attackers leveraging AI, as soon as a patch comes out, they can reverse-engineer the patch and they can start to figure out the exploit. Your 30 days has become 30 hours, or three hours,” Thakar said. “What we really focus on is to get over the fear of autonomous remediation. It’s not an option.”

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Advanced AI models with unique hacking capabilities like Anthropic’s Mythos should bring federal agencies that handle some of the government’s most sensitive information to a “reflection point,” according to one of the CIA’s top tech officials.

    “I think it is a reflection point and I think people need to view it in that fashion,” said Dan Richard, Associate Deputy Director of the CIA’s Digital Innovation Directorate. Richard spoke on a panel Friday at the Qualys ROCon Public Sector 2026 conference in Tysons Corner, Virginia.

    A previous version of the Mythos software was released to a limited group of tech companies in April with much fanfare, due to its ability to detect countless software bugs and defects.

    Security researchers and experts reacted with a mix of excitement and caution, with some warning the software could usher in a new era for hackers and lower the barrier to entry for would-be attackers. Mythos and competing models like OpenAI’s GPT-5.5 have forced executive agencies to grapple with their capabilities and prompted emergency briefings for lawmakers.

    Richard said he feels “bullish in terms of the opportunities that are out there,” largely because these AI models can help agencies like the CIA deal with the deluge of data they generate and automate responses to potential threats. He likened the current Mythos-driven moment to Ukraine’s response to Russia’s invasion in 2022.

    “[Ukraine] had gone through a decade of the Russians infiltrating their networks and having to deal with that implication, but when the Russians attacked in 2022 the Ukrainians were prepared because they understood they couldn’t do it themselves,” he said. “Shoulder-to-shoulder with them were the private sector vendors to support what they were doing and to help what they’re doing.”

    Richard said the U.S. government is in the “same position” now, and public-private partnerships will be key to ensuring the nation gets it right.

    “80% of our nation’s critical infrastructure is in private sector hands, so there is no solution that does not include private sector partners,” Richard said. “We talk about partnership all the time, but this is really different. This isn’t transactional. This is us, as a country, figuring out with the academic community, with the private sector community and with our public sector partners working together to be able to defeat and take advantage of what I see as an optimal opportunity for the agency, but for the country.”

    Joe Kelly, division director of the Applied Research Laboratory for Intelligence and Security at the University of Maryland, said advanced AI models are going to lower the barrier to entry for would-be hackers.

    “The real danger when we look at something like Mythos — whether you believe the hype or not — is it certainly creates what we already see with Claude Code, the ability for script kiddies to cause real damage even without knowing what they’re doing,” Kelly said. “It’s going to lift all those. I do worry about the complexity that we’re entering in this era.”

    ‘It’s moving so fast, it’s scary’

    IonQ Chief Information Officer Katie Arrington, who spent most of 2025 serving as the Pentagon’s chief information officer, said the influx of advanced AI tools — and the speed at which they’re emerging — will test government to the extreme. Existing governance requires IT security vulnerabilities be patched within 30 days, and 15 days for vulnerabilities designated “critical.”

    “You don’t have time like that anymore,” Arrington said during a panel at the Qualys event. “We’re talking about a tool that can find every vulnerability in seconds on a platform.”

    Arrington said these kinds of advanced AI models weren’t a discussion item even 12 months ago. At that time, the Pentagon was just trying to improve the speed that it could bring general AI tools into its networks.

    “It’s moving so fast, it’s scary,” Arrington said. “It scares me and it excites me how fast Mythos came alive.”

    Qualys CEO Sumedh Thakar said federal agencies may need to take a more proactive — rather than reactive — approach to risk management to deal with the growing range of threats from advanced AI tools. His company is using its AI-powered cybersecurity tools, including TotalCloud, which recently received authorization to operate in the government’s FedRAMP High environments, to allow customers to automate vulnerability patching, reducing some of the manual processes and “dashboard tourism” cyber professionals otherwise deal with.

    Thakar said autonomous remediation allows savvy customers to “battle AI with the speed of AI.”

    “Now with attackers leveraging AI, as soon as a patch comes out, they can reverse engineer the patch and they can start to figure out the exploit. Your 30 days has become 30 hours, or three hours,” Thakar said. “What we really focus on is to get over the fear of autonomous remediation. It’s not an option.”

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Until this past weekend, a contractor for the Cybersecurity & Infrastructure Security Agency (CISA) maintained a public GitHub repository that exposed credentials to several highly privileged AWS GovCloud accounts and a large number of internal CISA systems. Security experts said the public archive included files detailing how CISA builds, tests and deploys software internally, and that it represents one of the most egregious government data leaks in recent history.

    On May 15, KrebsOnSecurity heard from Guillaume Valadon, a researcher with the security firm GitGuardian. Valadon’s company constantly scans public code repositories at GitHub and elsewhere for exposed secrets, automatically alerting the offending accounts of any apparent sensitive data exposures. Valadon said he reached out because the owner in this case wasn’t responding and the information exposed was highly sensitive.

    A redacted screenshot of the now-defunct “Private CISA” repository maintained by a CISA contractor.

    The GitHub repository that Valadon flagged was named “Private-CISA,” and it harbored a vast number of internal CISA/DHS credentials and files, including cloud keys, tokens, plaintext passwords, logs and other sensitive CISA assets.

    Valadon said the exposed CISA credentials represent a textbook example of poor security hygiene, noting that the commit logs in the offending GitHub account show that the CISA administrator disabled the default setting in GitHub that blocks users from publishing SSH keys or other secrets in public code repositories.

    “Passwords stored in plain text in a csv, backups in git, explicit commands to disable GitHub secrets detection feature,” Valadon wrote in an email. “I honestly believed that it was all fake before analyzing the content deeper. This is indeed the worst leak that I’ve witnessed in my career. It is obviously an individual’s mistake, but I believe that it might reveal internal practices.”

    One of the exposed files, titled “importantAWStokens,” included the administrative credentials to three Amazon AWS GovCloud servers. Another file exposed in their public GitHub repository — “AWS-Workspace-Firefox-Passwords.csv” — listed plaintext usernames and passwords for dozens of internal CISA systems. According to Caturegli, those system included one called “LZ-DSO,” which appears short for “Landing Zone DevSecOps,” the agency’s secure code development environment.

    Philippe Caturegli, founder of the security consultancy Seralys, said he tested the AWS keys only to see whether they were still valid and to determine which internal systems the exposed accounts could access. Caturegli said the GitHub account that exposed the CISA secrets exhibits a pattern consistent with an individual operator using the repository as a working scratchpad or synchronization mechanism rather than a curated project repository.

    “The use of both a CISA-associated email address and a personal email address suggests the repository may have been used across differently configured environments,” Caturegli observed. “The available Git metadata alone does not prove which endpoint or device was used.”

    The Private CISA GitHub repo exposed dozens of plaintext credentials for important CISA GovCloud resources.

    Caturegli said he validated that the exposed credentials could authenticate to three AWS GovCloud accounts at a high privilege level. He said the archive also includes plain text credentials to CISA’s internal “artifactory” — essentially a repository of all the code packages they are using to build software — and that this would represent a juicy target for malicious attackers looking for ways to maintain a persistent foothold in CISA systems.

    “That would be a prime place to move laterally,” he said. “Backdoor in some software packages, and every time they build something new they deploy your backdoor left and right.”

    In response to questions, a spokesperson for CISA said the agency is aware of the reported exposure and is continuing to investigate the situation.

    “Currently, there is no indication that any sensitive data was compromised as a result of this incident,” the CISA spokesperson wrote. “While we hold our team members to the highest standards of integrity and operational awareness, we are working to ensure additional safeguards are implemented to prevent future occurrences.”

    A review of the GitHub account and its exposed passwords show the “Private CISA” repository was maintained by a contractor employed by Nightwing, a government contractor based in Dulles, Va. Nightwing declined to comment, directing inquiries to CISA.

    CISA has not responded to questions about the potential duration of the data exposure, but Caturegli said the Private CISA repository was created on November 13, 2025. The contractor’s GitHub account was created back in September 2018.

    The GitHub account that included the Private CISA repo was taken offline shortly after both KrebsOnSecurity and Seralys notified CISA about the exposure. But Caturegli said the exposed AWS keys inexplicably continued to remain valid for another 48 hours.

    The now-defunct Private CISA repo showed the contractor also used easily-guessed passwords for a number of internal resources; for example, many of the credentials used a password consisting of each platform’s name followed by the current year. Caturegli said such practices would constitute a serious security threat for any organization even if those credentials were never exposed externally, noting that threat actors often use key credentials exposed on the internal network to expand their access after establishing initial access to a targeted system.

    “What I suspect happened is [the CISA contractor] was using this GitHub to synchronize files between a work laptop and a home computer, because he has regularly committed to this repo since November 2025,” Caturegli said. “This would be an embarrassing leak for any company, but it’s even more so in this case because it’s CISA.”

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Modern OSINT platforms rely more on AI and automation, while older social tracking methods keep losing access due to privacy and API restrictions.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • The newly discovered Reaper malware bypasses Apple’s macOS Tahoe 26.4 security updates to steal passwords, crypto assets, and install a permanent backdoor.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • INTERPOL has coordinated a first-of-its-kind cybercrime crackdown across the Middle East and North Africa (MENA) that led to 201 arrests and the identification of an additional 382 suspects. The initiative involved the efforts of 13 countries from the region between October 2025 and February 2026, aiming to investigate and neutralize malicious infrastructure, arrest perpetrators behind these

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶