<rss xmlns:source="http://source.scripting.com/" version="2.0">
  <channel>
    <title>Threat Intel</title>
    <link>https://threatintel.cc/</link>
    <description></description>
    
    <language>en</language>
    
    <lastBuildDate>Tue, 12 May 2026 16:54:03 -0400</lastBuildDate>
    <item>
      <title></title>
      <link>https://threatintel.cc/2026/05/12/apples-ios-update-patches-more.html</link>
      <pubDate>Tue, 12 May 2026 16:54:03 -0400</pubDate>
      
      <guid>http://threatintel.micro.blog/2026/05/12/apples-ios-update-patches-more.html</guid>
      <description>&lt;p&gt;&lt;a href=&#34;https://www.macrumors.com/2026/05/11/ios-26-5-security-fixes/&#34;&gt;Apple&amp;rsquo;s iOS 26.5 Update Patches More Than 50 Security Flaws - MacRumors&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Apple&amp;rsquo;s iOS 26.5 and iPadOS 26.5 updates resolve over 50 security vulnerabilities, including issues related to WebKit, kernel performance, and system applications. Users are encouraged to install these patches promptly to protect their devices from potential exploits.&lt;/p&gt;
</description>
      <source:markdown>[Apple&#39;s iOS 26.5 Update Patches More Than 50 Security Flaws - MacRumors](https://www.macrumors.com/2026/05/11/ios-26-5-security-fixes/)

Apple&#39;s iOS 26.5 and iPadOS 26.5 updates resolve over 50 security vulnerabilities, including issues related to WebKit, kernel performance, and system applications. Users are encouraged to install these patches promptly to protect their devices from potential exploits.
</source:markdown>
    </item>
    
    <item>
      <title></title>
      <link>https://threatintel.cc/2026/05/12/instructure-reaches-ransom-agreement-with.html</link>
      <pubDate>Tue, 12 May 2026 12:38:03 -0400</pubDate>
      
      <guid>http://threatintel.micro.blog/2026/05/12/instructure-reaches-ransom-agreement-with.html</guid>
      <description>&lt;p&gt;&lt;a href=&#34;https://thehackernews.com/2026/05/instructure-reaches-ransom-agreement.html&#34;&gt;Instructure Reaches Ransom Agreement with ShinyHunters to Stop 3.65TB Canvas Leak&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Instructure, the parent company of Canvas, has reached an agreement with the ShinyHunters extortion group to prevent the leak of 3.65TB of stolen data, which impacted nearly 9,000 organizations. The company paid a ransom, received the data back, and was assured that its customers would not be separately extorted.&lt;/p&gt;
</description>
      <source:markdown>[Instructure Reaches Ransom Agreement with ShinyHunters to Stop 3.65TB Canvas Leak](https://thehackernews.com/2026/05/instructure-reaches-ransom-agreement.html)

Instructure, the parent company of Canvas, has reached an agreement with the ShinyHunters extortion group to prevent the leak of 3.65TB of stolen data, which impacted nearly 9,000 organizations. The company paid a ransom, received the data back, and was assured that its customers would not be separately extorted.
</source:markdown>
    </item>
    
    <item>
      <title></title>
      <link>https://threatintel.cc/2026/05/11/deadline-set-by-cybercriminal-group.html</link>
      <pubDate>Mon, 11 May 2026 15:06:25 -0400</pubDate>
      
      <guid>http://threatintel.micro.blog/2026/05/11/deadline-set-by-cybercriminal-group.html</guid>
      <description>&lt;p&gt;&lt;a href=&#34;https://www.abc.net.au/news/2026-05-11/tas-universities-regain-access-to-canvas-hacker-deadline/106666744&#34;&gt;Deadline set by cybercriminal group looms as some institutions regain Canvas access - ABC News&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Some Australian universities and education departments are regaining access to the Canvas learning platform after a global outage caused by the ShinyHunters hacking group, who have set a deadline of Tuesday to negotiate a settlement before leaking compromised information. While some institutions like the University of Sydney have restored access, others, including Swinburne University and Queensland University of Technology, are still affected, impacting students&#39; ability to access materials and submit assignments.&lt;/p&gt;
</description>
      <source:markdown>[Deadline set by cybercriminal group looms as some institutions regain Canvas access - ABC News](https://www.abc.net.au/news/2026-05-11/tas-universities-regain-access-to-canvas-hacker-deadline/106666744)

Some Australian universities and education departments are regaining access to the Canvas learning platform after a global outage caused by the ShinyHunters hacking group, who have set a deadline of Tuesday to negotiate a settlement before leaking compromised information. While some institutions like the University of Sydney have restored access, others, including Swinburne University and Queensland University of Technology, are still affected, impacting students&#39; ability to access materials and submit assignments.
</source:markdown>
    </item>
    
    <item>
      <title></title>
      <link>https://threatintel.cc/2026/05/11/say-hello-to-the-internet.html</link>
      <pubDate>Mon, 11 May 2026 09:01:36 -0400</pubDate>
      
      <guid>http://threatintel.micro.blog/2026/05/11/say-hello-to-the-internet.html</guid>
      <description>&lt;p&gt;&lt;a href=&#34;https://om.co/2026/05/04/say-hello-to-the-internet-of-ai/&#34;&gt;Say Hello to the Internet of AI – On my Om&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;The &amp;ldquo;Internet of AI&amp;rdquo; is an emerging network architecture optimized for artificial intelligence, characterized by a shift in traffic patterns within data centers from north-south to east-west, and significant hyperscaler investment in private fiber networks and subsea cables. This new infrastructure prioritizes power and bandwidth for AI workloads, with hyperscalers increasingly controlling the physical network layers, akin to 19th-century railroad barons.&lt;/p&gt;
</description>
      <source:markdown>[Say Hello to the Internet of AI – On my Om](https://om.co/2026/05/04/say-hello-to-the-internet-of-ai/)

The &#34;Internet of AI&#34; is an emerging network architecture optimized for artificial intelligence, characterized by a shift in traffic patterns within data centers from north-south to east-west, and significant hyperscaler investment in private fiber networks and subsea cables. This new infrastructure prioritizes power and bandwidth for AI workloads, with hyperscalers increasingly controlling the physical network layers, akin to 19th-century railroad barons.
</source:markdown>
    </item>
    
    <item>
      <title></title>
      <link>https://threatintel.cc/2026/05/10/wwe-star-will-not-be.html</link>
      <pubDate>Sun, 10 May 2026 14:09:47 -0400</pubDate>
      
      <guid>http://threatintel.micro.blog/2026/05/10/wwe-star-will-not-be.html</guid>
      <description>&lt;p&gt;&lt;a href=&#34;https://heavy.com/sports/pro-wrestling/wwe-star-no-suspension-viral-leak/&#34;&gt;WWE Star Will Not be Suspended For Lewd Photo Leaks&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Despite a lewd photo leak of explicit images and videos shared online without her consent, WWE star Jordynne Grace will not be suspended. The private images were illegally leaked by hackers and were not from her OnlyFans account, leading WWE to not penalize her. Grace is not the only WWE star to fall victim to hacking, with Paige previously experiencing a similar incident.&lt;/p&gt;
</description>
      <source:markdown>[WWE Star Will Not be Suspended For Lewd Photo Leaks](https://heavy.com/sports/pro-wrestling/wwe-star-no-suspension-viral-leak/)

Despite a lewd photo leak of explicit images and videos shared online without her consent, WWE star Jordynne Grace will not be suspended. The private images were illegally leaked by hackers and were not from her OnlyFans account, leading WWE to not penalize her. Grace is not the only WWE star to fall victim to hacking, with Paige previously experiencing a similar incident.
</source:markdown>
    </item>
    
    <item>
      <title></title>
      <link>https://threatintel.cc/2026/05/08/hackers-leveraged-hugging-face-and.html</link>
      <pubDate>Fri, 08 May 2026 12:43:45 -0400</pubDate>
      
      <guid>http://threatintel.micro.blog/2026/05/08/hackers-leveraged-hugging-face-and.html</guid>
      <description>&lt;p&gt;&lt;a href=&#34;https://cybersecuritynews.com/hackers-leverage-hugging-face-and-clawhub/&#34;&gt;Hackers Leveraged Hugging Face and ClawHub With 575+ Malicious Skills to Deploy Malware&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Hackers are exploiting Hugging Face and ClawHub, popular AI platforms, to distribute malware like trojans, cryptominers, and infostealers by disguising them as legitimate AI tools and agent extensions. This campaign involves over 575 malicious skills published on ClawHub, with threat actors using techniques like indirect prompt injection to execute hidden malicious instructions within AI agents.&lt;/p&gt;
</description>
      <source:markdown>[Hackers Leveraged Hugging Face and ClawHub With 575+ Malicious Skills to Deploy Malware](https://cybersecuritynews.com/hackers-leverage-hugging-face-and-clawhub/)

Hackers are exploiting Hugging Face and ClawHub, popular AI platforms, to distribute malware like trojans, cryptominers, and infostealers by disguising them as legitimate AI tools and agent extensions. This campaign involves over 575 malicious skills published on ClawHub, with threat actors using techniques like indirect prompt injection to execute hidden malicious instructions within AI agents.
</source:markdown>
    </item>
    
    <item>
      <title></title>
      <link>https://threatintel.cc/2026/05/08/zara-data-breach-customers-exposed.html</link>
      <pubDate>Fri, 08 May 2026 12:41:36 -0400</pubDate>
      
      <guid>http://threatintel.micro.blog/2026/05/08/zara-data-breach-customers-exposed.html</guid>
      <description>&lt;p&gt;&lt;a href=&#34;https://securityaffairs.com/191859/cyber-crime/zara-data-breach-197000-customers-exposed-in-third-party-security-incident.html&#34;&gt;Zara Data Breach: 197,000 Customers Exposed in Third-Party Security Incident&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;A third-party security incident involving a former technology provider exposed the data of nearly 197,000 Zara customers, including emails and purchase history. The ShinyHunters extortion group claimed responsibility for the breach, which exploited compromised Anodot analytics platform tokens.&lt;/p&gt;
</description>
      <source:markdown>[Zara Data Breach: 197,000 Customers Exposed in Third-Party Security Incident](https://securityaffairs.com/191859/cyber-crime/zara-data-breach-197000-customers-exposed-in-third-party-security-incident.html)

A third-party security incident involving a former technology provider exposed the data of nearly 197,000 Zara customers, including emails and purchase history. The ShinyHunters extortion group claimed responsibility for the breach, which exploited compromised Anodot analytics platform tokens.
</source:markdown>
    </item>
    
    <item>
      <title></title>
      <link>https://threatintel.cc/2026/05/08/new-zichatbot-malware-uses-zulip.html</link>
      <pubDate>Fri, 08 May 2026 12:40:33 -0400</pubDate>
      
      <guid>http://threatintel.micro.blog/2026/05/08/new-zichatbot-malware-uses-zulip.html</guid>
      <description>&lt;p&gt;&lt;a href=&#34;https://cybersecuritynews.com/new-zichatbot-malware-uses-zulip-rest-apis/&#34;&gt;New ZiChatBot Malware Uses Zulip REST APIs as Command and Control Server&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;A new malware named ZiChatBot is exploiting Zulip&amp;rsquo;s REST APIs for its command and control server, making it harder to detect. This malware was distributed through malicious Python packages on PyPI and targets both Windows and Linux systems.&lt;/p&gt;
</description>
      <source:markdown>[New ZiChatBot Malware Uses Zulip REST APIs as Command and Control Server](https://cybersecuritynews.com/new-zichatbot-malware-uses-zulip-rest-apis/)

A new malware named ZiChatBot is exploiting Zulip&#39;s REST APIs for its command and control server, making it harder to detect. This malware was distributed through malicious Python packages on PyPI and targets both Windows and Linux systems.
</source:markdown>
    </item>
    
    <item>
      <title></title>
      <link>https://threatintel.cc/2026/05/08/anthropics-claude-used-in-attempted.html</link>
      <pubDate>Fri, 08 May 2026 12:39:06 -0400</pubDate>
      
      <guid>http://threatintel.micro.blog/2026/05/08/anthropics-claude-used-in-attempted.html</guid>
      <description>&lt;p&gt;&lt;a href=&#34;https://www.cybersecuritydive.com/news/anthropics-claude-compromise-mexican-water-utility/819710/&#34;&gt;Anthropic’s Claude used in attempted compromise of Mexican water utility | Cybersecurity Dive&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;An unknown threat group abused Anthropic&amp;rsquo;s Claude AI to aid in a sophisticated takeover attempt against a Mexican water utility, highlighting how AI tools can empower untrained actors. The incident, part of a larger campaign targeting Mexican government agencies, saw attackers use Claude and OpenAI&amp;rsquo;s GPT-4.1 AP for reconnaissance, exploit customization, and privilege escalation, though the OT system breach ultimately failed.&lt;/p&gt;
</description>
      <source:markdown>[Anthropic’s Claude used in attempted compromise of Mexican water utility | Cybersecurity Dive](https://www.cybersecuritydive.com/news/anthropics-claude-compromise-mexican-water-utility/819710/)

An unknown threat group abused Anthropic&#39;s Claude AI to aid in a sophisticated takeover attempt against a Mexican water utility, highlighting how AI tools can empower untrained actors. The incident, part of a larger campaign targeting Mexican government agencies, saw attackers use Claude and OpenAI&#39;s GPT-4.1 AP for reconnaissance, exploit customization, and privilege escalation, though the OT system breach ultimately failed.
</source:markdown>
    </item>
    
    <item>
      <title></title>
      <link>https://threatintel.cc/2026/05/08/123800.html</link>
      <pubDate>Fri, 08 May 2026 12:38:00 -0400</pubDate>
      
      <guid>http://threatintel.micro.blog/2026/05/08/123800.html</guid>
      <description>&lt;p&gt;&lt;a href=&#34;https://github.com/thechosenone-shall-prevail/cold-relay&#34;&gt;GitHub - thechosenone-shall-prevail/cold-relay: Cold Relay is a single-binary Active Directory security assessment tool that collects Windows authentication evidence across LDAP, Kerberos, SMB, DNS, GPO, delegation, certificate services, and more turning evidence into deterministic findings with an offline attack graph. · GitHub&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Cold Relay is a single-binary Active Directory security assessment tool that collects Windows authentication evidence across various protocols and services to build a deterministic attack graph. It provides findings with validation status, evidence, blockers, and next actions, differentiating between proven facts and theoretical possibilities.&lt;/p&gt;
</description>
      <source:markdown>[GitHub - thechosenone-shall-prevail/cold-relay: Cold Relay is a single-binary Active Directory security assessment tool that collects Windows authentication evidence across LDAP, Kerberos, SMB, DNS, GPO, delegation, certificate services, and more turning evidence into deterministic findings with an offline attack graph. · GitHub](https://github.com/thechosenone-shall-prevail/cold-relay)

Cold Relay is a single-binary Active Directory security assessment tool that collects Windows authentication evidence across various protocols and services to build a deterministic attack graph. It provides findings with validation status, evidence, blockers, and next actions, differentiating between proven facts and theoretical possibilities.
</source:markdown>
    </item>
    
    <item>
      <title></title>
      <link>https://threatintel.cc/2026/05/08/of-md-password-hashes-are.html</link>
      <pubDate>Fri, 08 May 2026 12:36:18 -0400</pubDate>
      
      <guid>http://threatintel.micro.blog/2026/05/08/of-md-password-hashes-are.html</guid>
      <description>&lt;p&gt;&lt;a href=&#34;https://www.theregister.com/security/2026/05/07/60-of-md5-password-hashes-are-crackable-in-under-an-hour/5234954&#34;&gt;60% of MD5 password hashes are crackable in under an hour&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;A recent study found that 60% of MD5 password hashes can be cracked in under an hour using a single GPU, with 48% cracked in under a minute, highlighting the vulnerability of passwords protected only by fast hashing algorithms. Experts emphasize that passwords should be part of a broader identity-based security strategy, including multi-factor authentication and zero trust models, rather than relied upon as the sole security measure.&lt;/p&gt;
</description>
      <source:markdown>[60% of MD5 password hashes are crackable in under an hour](https://www.theregister.com/security/2026/05/07/60-of-md5-password-hashes-are-crackable-in-under-an-hour/5234954)

A recent study found that 60% of MD5 password hashes can be cracked in under an hour using a single GPU, with 48% cracked in under a minute, highlighting the vulnerability of passwords protected only by fast hashing algorithms. Experts emphasize that passwords should be part of a broader identity-based security strategy, including multi-factor authentication and zero trust models, rather than relied upon as the sole security measure.
</source:markdown>
    </item>
    
    <item>
      <title></title>
      <link>https://threatintel.cc/2026/05/08/the-biggest-student-data-privacy.html</link>
      <pubDate>Fri, 08 May 2026 12:35:28 -0400</pubDate>
      
      <guid>http://threatintel.micro.blog/2026/05/08/the-biggest-student-data-privacy.html</guid>
      <description>&lt;p&gt;&lt;a href=&#34;https://www.404media.co/the-biggest-student-data-privacy-disaster-in-history-canvas-hack-shows-the-danger-of-centralized-edtech/&#34;&gt;&amp;lsquo;The Biggest Student Data Privacy Disaster in History&amp;rsquo;: Canvas Hack Shows the Danger of Centralized EdTech&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;A Canvas hack by ransomware group ShinyHunters has resulted in the theft of billions of messages and the data of over 275 million individuals, including student names, email addresses, and student ID numbers. This incident, described as the biggest student data privacy disaster in history, highlights the risks of centralizing sensitive educational data in a single platform, potentially enabling more targeted phishing attacks and exposing deeply personal student information.&lt;/p&gt;
</description>
      <source:markdown>[&#39;The Biggest Student Data Privacy Disaster in History&#39;: Canvas Hack Shows the Danger of Centralized EdTech](https://www.404media.co/the-biggest-student-data-privacy-disaster-in-history-canvas-hack-shows-the-danger-of-centralized-edtech/)

A Canvas hack by ransomware group ShinyHunters has resulted in the theft of billions of messages and the data of over 275 million individuals, including student names, email addresses, and student ID numbers. This incident, described as the biggest student data privacy disaster in history, highlights the risks of centralizing sensitive educational data in a single platform, potentially enabling more targeted phishing attacks and exposing deeply personal student information.
</source:markdown>
    </item>
    
    <item>
      <title></title>
      <link>https://threatintel.cc/2026/05/08/quacc-open-source-vulnerability-research.html</link>
      <pubDate>Fri, 08 May 2026 12:34:03 -0400</pubDate>
      
      <guid>http://threatintel.micro.blog/2026/05/08/quacc-open-source-vulnerability-research.html</guid>
      <description>&lt;p&gt;&lt;a href=&#34;https://www.somersetrecon.com/blog/2026/4/27/quacc-automated-open-source-vulnerability-discovery&#34;&gt;Quacc++ | Open Source Vulnerability Research Tool Powered by Semgrep &amp;amp; Grep.app — Somerset Recon&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Quacc++ is an automated bug hunting tool that combines grep.app for searching public GitHub repositories with Semgrep for static code analysis to discover vulnerabilities. It scans repositories for specific patterns, downloads matching code, and uses Semgrep with custom rules to precisely identify security flaws.&lt;/p&gt;
</description>
      <source:markdown>[Quacc++ | Open Source Vulnerability Research Tool Powered by Semgrep &amp; Grep.app — Somerset Recon](https://www.somersetrecon.com/blog/2026/4/27/quacc-automated-open-source-vulnerability-discovery)

Quacc++ is an automated bug hunting tool that combines grep.app for searching public GitHub repositories with Semgrep for static code analysis to discover vulnerabilities. It scans repositories for specific patterns, downloads matching code, and uses Semgrep with custom rules to precisely identify security flaws.
</source:markdown>
    </item>
    
    <item>
      <title></title>
      <link>https://threatintel.cc/2026/05/08/nvidia-confirms-geforce-now-data.html</link>
      <pubDate>Fri, 08 May 2026 12:31:34 -0400</pubDate>
      
      <guid>http://threatintel.micro.blog/2026/05/08/nvidia-confirms-geforce-now-data.html</guid>
      <description>&lt;p&gt;&lt;a href=&#34;https://www.bleepingcomputer.com/news/security/nvidia-confirms-geforce-now-data-breach-affecting-armenian-users/&#34;&gt;NVIDIA confirms GeForce NOW data breach affecting Armenian users&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;NVIDIA has confirmed a data breach affecting GeForce NOW users, specifically impacting those in Armenia. The breach was caused by a compromise of infrastructure operated by a regional partner, GFN.am, and did not affect NVIDIA&amp;rsquo;s own networks. Exposed information includes names, email addresses, usernames, and dates of birth, though no account passwords were compromised.&lt;/p&gt;
</description>
      <source:markdown>[NVIDIA confirms GeForce NOW data breach affecting Armenian users](https://www.bleepingcomputer.com/news/security/nvidia-confirms-geforce-now-data-breach-affecting-armenian-users/)

NVIDIA has confirmed a data breach affecting GeForce NOW users, specifically impacting those in Armenia. The breach was caused by a compromise of infrastructure operated by a regional partner, GFN.am, and did not affect NVIDIA&#39;s own networks. Exposed information includes names, email addresses, usernames, and dates of birth, though no account passwords were compromised.
</source:markdown>
    </item>
    
    <item>
      <title></title>
      <link>https://threatintel.cc/2026/05/08/u-of-t-ocad-among.html</link>
      <pubDate>Fri, 08 May 2026 12:29:21 -0400</pubDate>
      
      <guid>http://threatintel.micro.blog/2026/05/08/u-of-t-ocad-among.html</guid>
      <description>&lt;p&gt;&lt;a href=&#34;https://www.cbc.ca/news/canada/toronto/ontario-universities-canvas-breach-9.7192287&#34;&gt;U of T, OCAD among Ontario universities impacted by Canvas cyber breach | CBC News&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Thousands of schools, including University of Toronto and OCAD University, were impacted by a cybersecurity incident involving the Canvas learning software. While names, emails, and student numbers may have been affected, Instructure, Canvas&amp;rsquo;s parent company, stated there was no evidence of passwords or financial information being compromised.&lt;/p&gt;
</description>
      <source:markdown>[U of T, OCAD among Ontario universities impacted by Canvas cyber breach | CBC News](https://www.cbc.ca/news/canada/toronto/ontario-universities-canvas-breach-9.7192287)

Thousands of schools, including University of Toronto and OCAD University, were impacted by a cybersecurity incident involving the Canvas learning software. While names, emails, and student numbers may have been affected, Instructure, Canvas&#39;s parent company, stated there was no evidence of passwords or financial information being compromised.
</source:markdown>
    </item>
    
    <item>
      <title></title>
      <link>https://threatintel.cc/2026/05/07/hackers-hack-victims-hacked-by.html</link>
      <pubDate>Thu, 07 May 2026 19:00:55 -0400</pubDate>
      
      <guid>http://threatintel.micro.blog/2026/05/07/hackers-hack-victims-hacked-by.html</guid>
      <description>&lt;p&gt;[Hackers hack victims hacked by other hackers&lt;/p&gt;
&lt;p&gt;| TechCrunch](&lt;a href=&#34;https://techcrunch.com/2026/05/07/hackers-hack-victims-hacked-by-other-hackers/&#34;&gt;https://techcrunch.com/2026/05/07/hackers-hack-victims-hacked-by-other-hackers/&lt;/a&gt;)&lt;/p&gt;
</description>
      <source:markdown>[Hackers hack victims hacked by other hackers 

| TechCrunch](https://techcrunch.com/2026/05/07/hackers-hack-victims-hacked-by-other-hackers/)



</source:markdown>
    </item>
    
    <item>
      <title></title>
      <link>https://threatintel.cc/2026/05/07/coinbase-cuts-jobs-before-q.html</link>
      <pubDate>Thu, 07 May 2026 15:22:00 -0400</pubDate>
      
      <guid>http://threatintel.micro.blog/2026/05/07/coinbase-cuts-jobs-before-q.html</guid>
      <description>&lt;p&gt;&lt;a href=&#34;https://blocknow.com/coinbase-stock-layoffs-700-jobs-ai-restructuring-2026/&#34;&gt;Coinbase Cuts 700 Jobs Before Q1 Earnings in AI Pivot&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Coinbase is cutting 700 employees, or 14% of its workforce, as CEO Brian Armstrong pivots the company towards AI and leaner management structures, citing cost reductions and weak market conditions. This move occurs just before the company&amp;rsquo;s Q1 earnings report, following a significant net loss in Q4 2025.&lt;/p&gt;
</description>
      <source:markdown>[Coinbase Cuts 700 Jobs Before Q1 Earnings in AI Pivot](https://blocknow.com/coinbase-stock-layoffs-700-jobs-ai-restructuring-2026/)

Coinbase is cutting 700 employees, or 14% of its workforce, as CEO Brian Armstrong pivots the company towards AI and leaner management structures, citing cost reductions and weak market conditions. This move occurs just before the company&#39;s Q1 earnings report, following a significant net loss in Q4 2025.
</source:markdown>
    </item>
    
    <item>
      <title></title>
      <link>https://threatintel.cc/2026/05/07/enterprise-ai-deployment-is-rewriting.html</link>
      <pubDate>Thu, 07 May 2026 15:19:49 -0400</pubDate>
      
      <guid>http://threatintel.micro.blog/2026/05/07/enterprise-ai-deployment-is-rewriting.html</guid>
      <description>&lt;p&gt;&lt;a href=&#34;https://siliconangle.com/2026/05/07/enterprise-ai-deployment-rewriting-security-rulebook-securingtheaifactory/&#34;&gt;Enterprise AI deployment is rewriting the security rulebook - SiliconANGLE&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Enterprise AI deployment significantly expands the cybersecurity attack surface, making traditional defenses inadequate for new targets like data pipelines and model training environments. Security must be integrated from the outset of AI projects to avoid costly halts, with approaches like Dell&amp;rsquo;s treating the AI factory as a single, integrated security surface.&lt;/p&gt;
</description>
      <source:markdown>[Enterprise AI deployment is rewriting the security rulebook - SiliconANGLE](https://siliconangle.com/2026/05/07/enterprise-ai-deployment-rewriting-security-rulebook-securingtheaifactory/)

Enterprise AI deployment significantly expands the cybersecurity attack surface, making traditional defenses inadequate for new targets like data pipelines and model training environments. Security must be integrated from the outset of AI projects to avoid costly halts, with approaches like Dell&#39;s treating the AI factory as a single, integrated security surface.
</source:markdown>
    </item>
    
    <item>
      <title></title>
      <link>https://threatintel.cc/2026/05/07/australia-warns-of-clickfix-attacks.html</link>
      <pubDate>Thu, 07 May 2026 15:18:08 -0400</pubDate>
      
      <guid>http://threatintel.micro.blog/2026/05/07/australia-warns-of-clickfix-attacks.html</guid>
      <description>&lt;p&gt;&lt;a href=&#34;https://www.bleepingcomputer.com/news/security/australia-warns-of-clickfix-attacks-pushing-vidar-stealer-malware/&#34;&gt;Australia warns of ClickFix attacks pushing Vidar Stealer malware&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;The Australian Cyber Security Center (ACSC) has issued a warning about ClickFix attacks that are distributing the Vidar Stealer malware. These attacks trick users into executing malicious PowerShell commands through fake verification prompts, leading to the theft of sensitive information like passwords and cryptocurrency. ACSC recommends restricting PowerShell execution, implementing application allow-listing, and keeping WordPress sites updated to mitigate these threats.&lt;/p&gt;
</description>
      <source:markdown>[Australia warns of ClickFix attacks pushing Vidar Stealer malware](https://www.bleepingcomputer.com/news/security/australia-warns-of-clickfix-attacks-pushing-vidar-stealer-malware/)

The Australian Cyber Security Center (ACSC) has issued a warning about ClickFix attacks that are distributing the Vidar Stealer malware. These attacks trick users into executing malicious PowerShell commands through fake verification prompts, leading to the theft of sensitive information like passwords and cryptocurrency. ACSC recommends restricting PowerShell execution, implementing application allow-listing, and keeping WordPress sites updated to mitigate these threats.
</source:markdown>
    </item>
    
    <item>
      <title></title>
      <link>https://threatintel.cc/2026/05/07/us-cisa-adds-a-flaw.html</link>
      <pubDate>Thu, 07 May 2026 15:17:27 -0400</pubDate>
      
      <guid>http://threatintel.micro.blog/2026/05/07/us-cisa-adds-a-flaw.html</guid>
      <description>&lt;p&gt;&lt;a href=&#34;https://securityaffairs.com/191822/security/u-s-cisa-adds-a-flaw-in-ivanti-endpoint-manager-mobile-epmm-to-its-known-exploited-vulnerabilities-catalog.html&#34;&gt;U.S. CISA adds a flaw in Ivanti Endpoint Manager Mobile (EPMM) to its Known Exploited Vulnerabilities catalog&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;The U.S. CISA has added a zero-day vulnerability (CVE-2026-6973) in Ivanti Endpoint Manager Mobile (EPMM) to its Known Exploited Vulnerabilities catalog, urging federal agencies to patch by May 10, 2026. This flaw, requiring admin privileges, allows for arbitrary code execution and is already being exploited.&lt;/p&gt;
</description>
      <source:markdown>[U.S. CISA adds a flaw in Ivanti Endpoint Manager Mobile (EPMM) to its Known Exploited Vulnerabilities catalog](https://securityaffairs.com/191822/security/u-s-cisa-adds-a-flaw-in-ivanti-endpoint-manager-mobile-epmm-to-its-known-exploited-vulnerabilities-catalog.html)

The U.S. CISA has added a zero-day vulnerability (CVE-2026-6973) in Ivanti Endpoint Manager Mobile (EPMM) to its Known Exploited Vulnerabilities catalog, urging federal agencies to patch by May 10, 2026. This flaw, requiring admin privileges, allows for arbitrary code execution and is already being exploited.
</source:markdown>
    </item>
    
    <item>
      <title></title>
      <link>https://threatintel.cc/2026/05/07/new-pcpjack-worm-steals-credentials.html</link>
      <pubDate>Thu, 07 May 2026 15:16:14 -0400</pubDate>
      
      <guid>http://threatintel.micro.blog/2026/05/07/new-pcpjack-worm-steals-credentials.html</guid>
      <description>&lt;p&gt;&lt;a href=&#34;https://www.bleepingcomputer.com/news/security/new-pcpjack-worm-steals-credentials-cleans-teampcp-infections/&#34;&gt;New PCPJack worm steals credentials, cleans TeamPCP infections&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;A new malware framework named PCPJack is actively stealing credentials from exposed cloud infrastructure and is designed to remove TeamPCP infections. It targets services like Docker, Kubernetes, and MongoDB, and researchers believe it may be operated by a former TeamPCP affiliate.&lt;/p&gt;
</description>
      <source:markdown>[New PCPJack worm steals credentials, cleans TeamPCP infections](https://www.bleepingcomputer.com/news/security/new-pcpjack-worm-steals-credentials-cleans-teampcp-infections/)

A new malware framework named PCPJack is actively stealing credentials from exposed cloud infrastructure and is designed to remove TeamPCP infections. It targets services like Docker, Kubernetes, and MongoDB, and researchers believe it may be operated by a former TeamPCP affiliate.
</source:markdown>
    </item>
    
    <item>
      <title></title>
      <link>https://threatintel.cc/2026/05/07/of-ceos-worry-their-job.html</link>
      <pubDate>Thu, 07 May 2026 15:14:13 -0400</pubDate>
      
      <guid>http://threatintel.micro.blog/2026/05/07/of-ceos-worry-their-job.html</guid>
      <description>&lt;p&gt;&lt;a href=&#34;https://www.fastcompany.com/91537318/80-of-ceos-worry-their-job-is-at-risk-if-ai-fails-this-year-survey-shows&#34;&gt;80% of CEOs worry their job is at risk if AI fails this year - Fast Company&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;A new survey reveals that 80% of CEOs believe their job is at risk if AI initiatives fail this year, with 72% of U.S. CEOs feeling pressure from their boards to demonstrate AI-driven ROI. Despite concerns about over-investment, 87% of global CEOs acknowledge their roles are dependent on the success of AI.&lt;/p&gt;
</description>
      <source:markdown>[80% of CEOs worry their job is at risk if AI fails this year - Fast Company](https://www.fastcompany.com/91537318/80-of-ceos-worry-their-job-is-at-risk-if-ai-fails-this-year-survey-shows)

A new survey reveals that 80% of CEOs believe their job is at risk if AI initiatives fail this year, with 72% of U.S. CEOs feeling pressure from their boards to demonstrate AI-driven ROI. Despite concerns about over-investment, 87% of global CEOs acknowledge their roles are dependent on the success of AI.
</source:markdown>
    </item>
    
    <item>
      <title></title>
      <link>https://threatintel.cc/2026/05/04/backdoored-pytorch-lightning-package-drops.html</link>
      <pubDate>Mon, 04 May 2026 15:24:15 -0400</pubDate>
      
      <guid>http://threatintel.micro.blog/2026/05/04/backdoored-pytorch-lightning-package-drops.html</guid>
      <description>&lt;p&gt;&lt;a href=&#34;https://www.bleepingcomputer.com/news/security/backdoored-pytorch-lightning-package-drops-credential-stealer/&#34;&gt;Backdoored PyTorch Lightning package drops credential stealer&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;A malicious version of the PyTorch Lightning package, version 2.6.3, was found to contain a credential stealer that targets browsers, environment files, and cloud services. The package, which has over 11 million downloads, automatically downloads and executes a JavaScript payload upon import, potentially compromising secrets, keys, and tokens.&lt;/p&gt;
</description>
      <source:markdown>[Backdoored PyTorch Lightning package drops credential stealer](https://www.bleepingcomputer.com/news/security/backdoored-pytorch-lightning-package-drops-credential-stealer/)

A malicious version of the PyTorch Lightning package, version 2.6.3, was found to contain a credential stealer that targets browsers, environment files, and cloud services. The package, which has over 11 million downloads, automatically downloads and executes a JavaScript payload upon import, potentially compromising secrets, keys, and tokens.
</source:markdown>
    </item>
    
    <item>
      <title></title>
      <link>https://threatintel.cc/2026/05/04/phishing-campaign-hits-orgs-using.html</link>
      <pubDate>Mon, 04 May 2026 15:22:36 -0400</pubDate>
      
      <guid>http://threatintel.micro.blog/2026/05/04/phishing-campaign-hits-orgs-using.html</guid>
      <description>&lt;p&gt;&lt;a href=&#34;https://thehackernews.com/2026/05/phishing-campaign-hits-80-orgs-using.html?m=1&#34;&gt;Phishing Campaign Hits 80+ Orgs Using SimpleHelp and ScreenConnect RMM Tools&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;A phishing campaign named VENOMOUS#HELPER has impacted over 80 organizations by using legitimate Remote Monitoring and Management (RMM) tools like SimpleHelp and ScreenConnect to gain persistent remote access. The campaign begins with a phishing email impersonating the U.S. Social Security Administration, leading victims to download an executable that installs the RMM software, enabling attackers to control compromised hosts.&lt;/p&gt;
</description>
      <source:markdown>[Phishing Campaign Hits 80+ Orgs Using SimpleHelp and ScreenConnect RMM Tools](https://thehackernews.com/2026/05/phishing-campaign-hits-80-orgs-using.html?m=1)

A phishing campaign named VENOMOUS#HELPER has impacted over 80 organizations by using legitimate Remote Monitoring and Management (RMM) tools like SimpleHelp and ScreenConnect to gain persistent remote access. The campaign begins with a phishing email impersonating the U.S. Social Security Administration, leading victims to download an executable that installs the RMM software, enabling attackers to control compromised hosts.
</source:markdown>
    </item>
    
    <item>
      <title></title>
      <link>https://threatintel.cc/2026/05/04/cisco-moves-to-acquire-astrix.html</link>
      <pubDate>Mon, 04 May 2026 15:21:26 -0400</pubDate>
      
      <guid>http://threatintel.micro.blog/2026/05/04/cisco-moves-to-acquire-astrix.html</guid>
      <description>&lt;p&gt;&lt;a href=&#34;https://www.securityweek.com/cisco-moves-to-acquire-astrix-security-to-tackle-non-human-identity-risks/&#34;&gt;Cisco Moves to Acquire Astrix Security to Tackle Non-Human Identity Risks - SecurityWeek&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Cisco is acquiring Astrix Security to address the growing risks associated with non-human identities (NHIs) like API keys and service accounts, which are increasingly used by AI agents. This acquisition aims to extend zero trust principles to the expanding agentic workforce and integrate Astrix&amp;rsquo;s technology for discovering, governing, and securing these identities into Cisco&amp;rsquo;s security platform.&lt;/p&gt;
</description>
      <source:markdown>[Cisco Moves to Acquire Astrix Security to Tackle Non-Human Identity Risks - SecurityWeek](https://www.securityweek.com/cisco-moves-to-acquire-astrix-security-to-tackle-non-human-identity-risks/)

Cisco is acquiring Astrix Security to address the growing risks associated with non-human identities (NHIs) like API keys and service accounts, which are increasingly used by AI agents. This acquisition aims to extend zero trust principles to the expanding agentic workforce and integrate Astrix&#39;s technology for discovering, governing, and securing these identities into Cisco&#39;s security platform.
</source:markdown>
    </item>
    
  </channel>
</rss>
