<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[this week in security — may 17 2026 edition]]></title><description><![CDATA[

<div>~ ~</div>

<h3>
  THIS WEEK, TL;DR
</h3>

<p><a href="https://www.bbc.com/news/articles/cdepzg83x87o"><strong><u>Instructure paid and 'reached an agreement' with hackers who breached it twice; ShinyHunters says it won't extort victims</u></strong></a><br /><strong>BBC News ($): </strong>Canvas school system maker Instructure paid the hackers that breached the company (twice) and stole gobs of student data. Instructure CEO Steve Daly said the company "reached an agreement" with the hackers (heavy wink, of course) to not release the data, without saying how many millions it paid the hackers or estimating how many future hacks its ransom payment may have contributed to funding. The ShinyHunters gang told <a href="https://techcrunch.com/2026/05/12/instructure-strikes-deal-with-hackers-who-breached-it-twice/"><u>TechCrunch</u></a> and <a href="https://databreaches.net/2026/05/16/another-detail-emerges-about-instructures-agreement-with-shinyhunters-debate-continues-about-whether-to-pay/"><u>DataBreaches.net</u></a> that the data is "deleted, gone," and that victims will "not further be targeted or contacted for payment by us.” But that still leaves open the possibility — as has happened before — that another hacker group might extort them, à la the massive breach at ed-tech giant <a href="https://techcrunch.com/2025/05/08/powerschool-paid-a-hackers-ransom-but-now-schools-say-they-are-being-extorted/"><u>PowerSchool</u></a>; or that the hackers might not stick to their word. Lawmakers now <a href="https://techcrunch.com/2026/05/13/us-lawmakers-demand-answers-from-instructure-after-canvas-data-breaches/"><u>want answers</u></a> over Instructure's catastro<em>phish</em> (the hackers' main <em>modus operandi</em>). Instructure can't guarantee <em>jack</em> about any of the hackers' claims, so lawmakers should press them on it — and who, if anyone(!) — is ultimately responsible for cybersecurity at the company.<br /><strong>More: </strong><a href="https://techcrunch.com/2026/05/12/instructure-strikes-deal-with-hackers-who-breached-it-twice/"><u>TechCrunch ($)</u></a> | <a href="https://www.reuters.com/legal/litigation/canvas-parent-company-reaches-agreement-with-hacking-group-behind-recent-breach-2026-05-12/"><u>Reuters ($)</u></a> | <a href="https://apnews.com/article/canvas-outage-college-students-exams-grades-3d55b9399ae87d49276f354e1c34c180"><u>Associated Press</u></a> | <a href="https://www.insidehighered.com/news/tech-innovation/administrative-tech/2026/05/11/instructure-pays-ransom-canvas"><u>Inside Higher Ed</u></a> | <a href="https://www.harlemworldmagazine.com/nyc-public-schools-hit-by-separate-malware-attack-amid-canvas-hack-ongoing/"><u>Harlem World</u></a> | <a href="https://calmatters.org/economy/technology/2026/05/california-went-big-on-canvas-the-worst-happened/"><u>CalMatters</u></a> | <a href="https://bsky.app/profile/mzinshteyn.bsky.social/post/3mlmjanse2k2y"><u>@mzinshteyn</u></a> | <a href="https://infosec.exchange/@briankrebs/116558864224439236"><u>@briankrebs</u></a></p><p><a href="https://www.nytimes.com/2026/05/14/us/politics/china-us-sanctions-ai-cybersecurity.html"><strong><u>On state visit to Beijing, Trump discussed AI, cyberattacks, sanctions, and spying with China's Xi Jinping</u></strong></a><br /><strong>The New York Times ($): </strong>Trump and his entourage of senior staffers, <a href="https://apnews.com/article/trump-china-musk-apple-iran-boeing-fbc2bb27b6f77146dce1954502f9aeb8"><u>emotional support tech executives</u></a>, and family members (for some bizarre reason?), went to China and all they got <em><s>was this lousy T-shirt</s></em> were several gifts <a href="https://techcrunch.com/2026/05/15/us-orders-travelers-on-air-force-one-to-throw-away-gifts-pins-and-burner-phones-after-china-trip/"><u>probably laden with bugs</u></a> that they weren't even allowed to bring aboard Air Force One. As part of the state visit to Beijing, Trump and China's Xi Jinping talked <a href="https://www.nytimes.com/2026/05/14/us/politics/china-us-sanctions-ai-cybersecurity.html"><u>spies, sanctions, AI, and cyberattacks</u></a>, among other things, per <a href="https://bsky.app/profile/dustinvolz.bsky.social/post/3mltf4o52c22s"><u>@dustinvolz</u></a> (new byline!), who runs down the gist of the trip's aims as the long-running frenemies met over a largely conciliatory tone. China remains a <a href="https://this.weekinsecurity.com/the-most-dangerous-threats-to-the-internet-in-2026/"><u>major adversary ($)</u></a> in cyberspace as it continues to eye Taiwan for its own, and will keep hacking and spying its way around the world to meet its objectives. That also came up, with Trump <a href="https://x.com/atrupar/status/2055258495465759005"><u>telling reporters</u></a>: “They’re talking about the spying. Well, we do it too.” But whether or not anything actionable came of this visit remains to be seen. <em>Slightly </em>worried that Trump didn't seem to follow when a reporter asked about <a href="https://www.justice.gov/archives/opa/pr/us-government-disrupts-botnet-peoples-republic-china-used-conceal-hacking-critical"><u>Volt Typhoon</u></a>, the Chinese hacking group planting malware around the world so it can distract American forces during an invasion, responding: "You don’t know that," and that he would "like to see it."<br /><strong>More: </strong><a href="https://techcrunch.com/2026/05/15/us-orders-travelers-on-air-force-one-to-throw-away-gifts-pins-and-burner-phones-after-china-trip/"><u>TechCrunch ($)</u></a> | <a href="https://www.nextgov.com/cybersecurity/2026/05/trump-says-he-and-xi-discussed-cyberattacks-and-spying-between-us-china/413582/"><u>Nextgov</u></a> | <a href="https://apnews.com/article/trump-xi-china-trade-iran-taiwan-f6c59000412653e445acbf9672ac7f47"><u>Associated Press</u></a> | <a href="https://thehill.com/homenews/administration/5880675-china-taiwan-trump-policy/"><u>The Hill</u></a> | <a href="https://www.npr.org/2026/05/11/nx-s1-5812681/ai-on-the-agenda-as-trump-heads-to-china"><u>NPR</u></a> | <strong>For subscribers: </strong><a href="https://this.weekinsecurity.com/the-most-dangerous-threats-to-the-internet-in-2026/"><u>this week in security ($)</u></a></p><p><a href="https://www.securityweek.com/tanstack-mistral-ai-uipath-hit-in-fresh-supply-chain-attack/"><strong><u>Tanstack among many hacked in latest worm attack targeting developers; OpenAI says two staffers affected</u></strong></a><br /><strong>SecurityWeek: </strong>Another worm-like campaign mass-targeted developers this week by stealing their credentials and self-propagating, using stolen tokens to publish malicious versions of the packages that victims have access to. Hacking gang TeamPCP, which has been on a tear stealing developer tokens and backdooring <a href="https://www.bleepingcomputer.com/news/security/popular-litellm-pypi-package-compromised-in-teampcp-supply-chain-attack/"><u>popular open-source packages</u></a>, is behind this latest campaign, according to <a href="https://www.wiz.io/blog/mini-shai-hulud-strikes-again-tanstack-more-npm-packages-compromised"><u>Wiz</u></a>. Tanstack, an open-source tech stack for web developers, was one of the bigger projects hacked, allowing the hackers to pivot from there to gain access to two OpenAI staffers' devices. OpenAI <a href="https://openai.com/index/our-response-to-the-tanstack-npm-supply-chain-attack/"><u>said</u></a> the hackers accessed code repositories containing developer signing keys, so the ChatGPT maker had to <a href="https://techcrunch.com/2026/05/14/openai-says-hackers-stole-some-data-after-latest-code-security-issue/"><u>revoke those certificates</u></a> and ask Mac users to update their apps.<br /><strong>More: </strong><a href="https://openai.com/index/our-response-to-the-tanstack-npm-supply-chain-attack/"><u>OpenAI</u></a> | <a href="https://www.securityweek.com/tanstack-mistral-ai-uipath-hit-in-fresh-supply-chain-attack/"><u>SecurityWeek</u></a> | <a href="https://www.bleepingcomputer.com/news/security/shai-hulud-attack-ships-signed-malicious-tanstack-mistral-npm-packages/"><u>Bleeping Computer</u></a> | <a href="https://www.theregister.com/cyber-crime/2026/05/12/cache-poisoning-caper-turns-tanstack-npm-packages-toxic/5238650"><u>The Register</u></a> | <a href="https://www.wiz.io/blog/mini-shai-hulud-strikes-again-tanstack-more-npm-packages-compromised" rel="noreferrer">Wiz</a> | <a href="https://x.com/MsftSecIntel/status/2054041471280423424"><u>@MsftSecIntel</u></a> </p><p><a href="https://techcrunch.com/2026/05/15/a-hotel-check-in-system-left-a-million-passports-and-drivers-licenses-open-for-anyone-to-see/"><strong><u>A hotel check-in system exposed a million passports, driver's licenses, and selfies to the open web</u></strong></a><br /><strong>TechCrunch ($): </strong>Yes, it's the year 2026 and I'm still banging the "stop leaving your cloud storage buckets exposed to the web" drum. <a href="https://www.securetheleaks.com/" rel="noreferrer">Anurag Sen</a> found a publicly exposed AWS S3 bucket belonging to Japanese maker of hotel check-in tech Reqrea, storing a million identity documents and selfies that guests used to check in to their reservations. This is yet another <a href="https://this.weekinsecurity.com/it-is-far-too-easy-to-find-leaked-passports-and-drivers-licenses-online/"><u>major spill of identity documents</u></a> at a time when ID verification is on the rise around the world. I wrote this story <em>(disclosure alert!)</em> because it was a perfect example of how a dead-simple data exposure can result in major harm, even while there's a lot of buzz and hype about the threat from AI models finding and exploiting security flaws. AI <em>has</em> helped to find bugs, even though many of them <a href="https://cyberplace.social/@GossiTheDog/116572617454744876"><u>aren't much of a threat</u></a>. Daniel Stenberg who maintains the curl library (which is used in <em>everything</em>) has a <a href="https://daniel.haxx.se/blog/2026/05/11/mythos-finds-a-curl-vulnerability/"><u>great blog</u></a> on this worth a read, if not least to manage your general AI expectations. In reality, I'm more concerned about someone setting an AWS S3 bucket full of people's data to "public" than somehow using AI to take down the entire Social Security database, or <em>something</em> daft like that. <em>Also this week: </em>Best Western Hotels <a href="https://www.securityweek.com/bwh-hotels-says-hackers-had-access-to-reservation-data-for-6-months/"><u>emailed customers</u></a> to say hackers had access to their systems for <em>six months </em>before being evicted <em>(via </em><a href="https://old.reddit.com/r/bestwestern/comments/1t7dg8d/security_breach_of_bwh_booking_portal/"><em><u>Reddit</u></em></a><em>)</em>. It's not clear how many people's data is affected. <br /><strong>More: </strong><a href="https://www.securityweek.com/bwh-hotels-says-hackers-had-access-to-reservation-data-for-6-months/"><u>SecurityWeek</u></a> | <a href="https://www.theregister.com/security/2026/05/11/best-western-hotels-confirms-web-app-data-breach/5238020"><u>The Register</u></a> | <a href="https://bsky.app/profile/zackwhittaker.com/post/3mlw4jc3ac22x"><u>@zackwhittaker</u></a></p><figure><a href="https://bsky.app/profile/doublepulsar.com/post/3mlw66inmss25"><img src="https://storage.ghost.io/c/ed/a2/eda2c6f7-faef-48b4-9ed4-86a4fa4dca68/content/images/2026/05/gossi.jpeg" alt="Kevin Beaumont post on Bluesky: &quot;I’ve dealt with several thousand cyber incidents over the past 5 years, and currently lead a global emerging threat team.   Amount of those being GenAI incidents: zero. Amount being foundational causes: every single one.&quot;" width="1000" height="315" srcset="https://storage.ghost.io/c/ed/a2/eda2c6f7-faef-48b4-9ed4-86a4fa4dca68/content/images/size/w600/2026/05/gossi.jpeg 600w, https://storage.ghost.io/c/ed/a2/eda2c6f7-faef-48b4-9ed4-86a4fa4dca68/content/images/2026/05/gossi.jpeg 1000w" /></a></figure>
<div>
            
            <div>
                
                
                    <div>
                    
                        <div>
                            <p><span>~ ~</span></p>
                        </div>
                    
                    
                    </div>
                
            </div>
        </div>

<div>
            
                <div>
                    <div>
                        <span>PLEASE SUPPORT THIS NEWSLETTER!</span>
                    </div>
                </div>
            
            <div>
                
                
                    <div>
                    
                        <div>
                            <p><a href="/user/index%40this.weekinsecurity.com" rel="noreferrer"><b><strong>~this week in security~</strong></b></a><span> is my weekly cybersecurity newsletter supported by readers like you. Please consider signing up for a </span><a href="https://this.weekinsecurity.com/#/portal/signup" rel="noreferrer"><b><strong>paying subscription starting at $10/month</strong></b></a><span> for access to exclusive articles, analysis, and more.</span></p><p><span>Or, you can </span><a href="https://this.weekinsecurity.com/this-week-in-security-april-19-2026-edition/#/portal/support" rel="noreferrer"><b><strong>submit a one-time tip</strong></b></a><span> to show your support!</span></p>
                        </div>
                    
                    
                        <a href="https://this.weekinsecurity.com/#/portal/signup">
                            Subscribe to support this newsletter
                        </a>
                        
                    </div>
                
            </div>
        </div>
<div>
            
            <div>
                
                
                    <div>
                    
                        <div>
                            <p><span>~ ~</span></p>
                        </div>
                    
                    
                    </div>
                
            </div>
        </div>





<h3>THE STUFF YOU MIGHT'VE MISSED
</h3>

<p><a href="https://www.hipaajournal.com/healthcare-organizations-exposing-patient-data-dicom-servers/"><strong><u>Medical imagery is still(!) spilling to the open web</u></strong></a><br /><strong>HIPAA Journal: </strong>PACS servers, which doctor's offices and hospitals use to store, share, and view patients' medical imagery, are often unsecured and, in some cases, accessible from the internet. This has been a chronic problem for years, and is happening again. (I wrote about <a href="https://techcrunch.com/2020/01/10/medical-images-exposed-pacs/"><u>this back in 2020</u></a>… 🫠) <a href="https://www.trendmicro.com/vinfo/us/security/news/cybercrime-and-digital-threats/a-hidden-vulnerability-in-healthcare-exposed-dicom-servers-and-the-risk-to-patient-data"><u>Trend Micro</u></a> has more on the technicals. If you work in healthcare, check your PACS servers for exposures before the <a href="https://www.hhs.gov/press-room/hhs-ocr-hipaa-settlement-nerad.html"><u>regulators find you</u></a>!</p><p><a href="https://www.theverge.com/tech/926487/meari-technology-hack-baby-monitor-security-camera"><strong><u>A million video baby monitors and security cameras were easily viewable by hackers</u></strong></a><br /><strong>The Verge ($): </strong>Hardcoded keys and public passwords found shipped in an Android app exposed over a million Meari internet-connected baby cameras to anyone who knew where to look. Thankfully a security researcher found the security lapse, as detailed by <a href="https://www.theverge.com/tech/926487/meari-technology-hack-baby-monitor-security-camera"><u>The Verge ($)</u></a>, which did a solid job on explaining the flaws.</p><figure><a href="http://theverge.com/tech/926487/meari-technology-hack-baby-monitor-security-camera"><img src="https://storage.ghost.io/c/ed/a2/eda2c6f7-faef-48b4-9ed4-86a4fa4dca68/content/images/2026/05/meari.jpeg" alt="a screenshot from The Verge's story, showing a dashboard created by the security researcher showing locations around the world where affected video cameras can be accessed." width="1000" height="508" srcset="https://storage.ghost.io/c/ed/a2/eda2c6f7-faef-48b4-9ed4-86a4fa4dca68/content/images/size/w600/2026/05/meari.jpeg 600w, https://storage.ghost.io/c/ed/a2/eda2c6f7-faef-48b4-9ed4-86a4fa4dca68/content/images/2026/05/meari.jpeg 1000w" /></a></figure><p><a href="https://arstechnica.com/security/2026/05/zero-day-exploit-completely-defeats-default-windows-11-bitlocker-protections/"><strong><u>Now-published zero-day can defeat default Windows 11 BitLocker protections</u></strong></a><br /><strong>Ars Technica: </strong>A zero-day dubbed <a href="https://github.com/Nightmare-Eclipse/YellowKey"><u>YellowKey</u></a>, released by disgruntled researcher Nightmare-Eclipse (who was behind the <a href="https://this.weekinsecurity.com/this-week-in-security-april-12-2026-edition/"><u>BlueHammer</u></a> exploit release), allows people with physical access to a Windows 11 system to bypass default BitLocker's encryption protections and gain complete access to an encrypted hard drive within seconds. <a href="https://cyberplace.social/@GossiTheDog/116565662607962457"><u>@GossiTheDog</u></a> called this "essentially… a backdoor." </p><p><a href="https://www.404media.co/mayo-clinic-is-using-ai-to-listen-to-emergency-room-visits/"><strong><u>Mayo Clinic is using AI to listen to emergency room visits</u></strong></a><br /><strong>404 Media ($): </strong>Hospital network giant Mayo Clinic has been collecting ambient audio from emergency rooms to record patient interactions, and feeding the data into AI. The audio collection is opt-out, and not opt-in. <em>Relatedly: </em>The Ontario government <a href="https://www.auditor.on.ca/en/content/specialreports/specialaudits/en2026/AR_2026_AI_EN.html"><u>recently found</u></a> in examining its use of AI transcription in healthcare that it was largely, well, <em>crap</em>, given that healthcare is too important for AI to get things wrong. "If the notes in the chart are wrong, the whole thing falls apart," per <a href="https://infosec.exchange/@mttaggart/116586007558212979"><u>@mttaggart</u></a>. Also, ICYMI: Professor extraordinaire <a href="https://dair-community.social/@emilymbender/116450850556202127"><u>@emilymbender</u></a> on <a href="https://buttondown.com/maiht3k/archive/why-you-should-refuse-to-let-your-doctor-record/"><u>why you should refuse</u></a> to let your doctor record you.</p><figure><a href="https://infosec.exchange/@mttaggart/116586007558212979"><img src="https://storage.ghost.io/c/ed/a2/eda2c6f7-faef-48b4-9ed4-86a4fa4dca68/content/images/2026/05/taggart.jpeg" alt="Taggart post on Mastodon: &quot;This entire report from the Ontario government on genAI systems is worth a read, but the review of healthcare scribe accuracy is pretty devastating, imo. This has to work for the tech to be worth anything. If the notes in the chart are wrong, the whole thing falls apart,&quot; followed by a screenshot from the Ontario report, which reveals the Types of Inaccuracies Found in Notes Generated by AI Scribe for 20 Approved Vendors, including: Hallucinations, Incorrect Information, and Incomplete Information." width="1000" height="886" srcset="https://storage.ghost.io/c/ed/a2/eda2c6f7-faef-48b4-9ed4-86a4fa4dca68/content/images/size/w600/2026/05/taggart.jpeg 600w, https://storage.ghost.io/c/ed/a2/eda2c6f7-faef-48b4-9ed4-86a4fa4dca68/content/images/2026/05/taggart.jpeg 1000w" /></a></figure><p><a href="https://www.bankinfosecurity.com/tables-turned-gentlemen-ransomware-group-suffers-data-leak-a-31654"><strong><u>Ransomware gang The Gentleman hacked and dissected by researchers</u></strong></a><br /><strong>BankInfoSecurity:</strong> A prominent and <a href="https://www.darkreading.com/threat-intelligence/gentlemen-rapidly-rise-ransomware"><u>rising</u></a> ransomware gang called The Gentlemen was hacked earlier in May and its database leaked. Check-Point has <a href="https://blog.checkpoint.com/research/when-the-ransomware-gang-gets-hacked-what-the-gentlemen-leak-reveals-about-modern-ransomware-risk/"><u>a blog</u></a> with more details, including more about how the gang operates, how they hack, and what defenders can look out for. Ransom-ISAC also has a <a href="https://ransom-isac.org/blog/the-gentlemen-leak-analysis/"><u>solid blog</u></a>. <em>(via </em><a href="https://mastodon.social/@campuscodi/116586430158611976"><em><u>@campuscodi</u></em></a><em>)</em></p><p><a href="https://www.zetter-zeroday.com/experts-confirm-the-fast16-malware-was-sabotaging-nuclear-weapons-tests-likely-in-iran/"><strong><u>Fast16 malware from the mid-2000s likely sabotaged Iran's nuclear weapons tests</u></strong></a><br /><strong>Zero Day: </strong>Belter reporting by <a href="https://infosec.exchange/@kimzetter/116584486207385646"><u>@kimzetter</u></a> this weekend… A malware called Fast16, which was discovered years ago but recently analyzed, actually dates back to the mid-2000s when it was secretly fed to Iranian systems with the aim of altering nuclear weapons simulation data. The aim was to undermine those tests and slow the progress of a nuclear program. Amazing reporting here, and with many similarities to <a href="https://www.wired.com/2014/11/countdown-to-zero-day-stuxnet/"><u>Stuxnet</u></a>, the other famed malware that aimed to set back Iranian efforts to build a nuclear weapon. <a href="https://www.security.com/blog-post/fast16-nuclear-sabotage"><u>Symantec</u></a> has more in its blog, and Zetter's <a href="https://www.zetter-zeroday.com/timeline-of-irans-nuclear-program-and-the-stuxnet-and-fast16-attacks-2/"><u>sidebar timeline ($)</u></a> is a handy chronological guide.</p><div>
            
            <div>
                
                
                    <div>
                    
                        <div>
                            <p><span>~ ~</span></p>
                        </div>
                    
                    
                    </div>
                
            </div>
        </div>

<h3>OTHER NEWSY NUGGETS</h3>

<p><strong>Europe exporting electronic exfiltrators: </strong>Six EU member states, including Denmark, have sold surveillance tech to dozens of countries known for human rights violations. The EU's top body keeps complaining about spyware abuses across Europe but does nothing about spyware makers selling to abusive governments from its own turf. <em>(via </em><a href="https://www.bloomberg.com/news/articles/2026-05-12/europe-exports-spyware-to-human-rights-abusers-watchdog-says"><em><u>Bloomberg ($)</u></em></a><em>, </em><a href="https://www.hrw.org/report/2026/05/12/looking-the-other-way/eu-failure-to-prevent-surveillance-exports-to-rights"><em><u>Human Rights Watch</u></em></a><em>)</em></p><figure><a href="https://tenor.com/view/simpsons-weve-tried-nothing-tried-nothing-nothing-were-all-out-of-ideas-gif-22788553"><img src="https://storage.ghost.io/c/ed/a2/eda2c6f7-faef-48b4-9ed4-86a4fa4dca68/content/images/2026/05/eu-flag-simpsons-gif.gif" alt="an animated GIF of a Simpsons clip, of alternate-reality Ned &amp; Maude Flanders in this scene, saying, &quot;We've tried nothing and we're all out of ideas,&quot; with the EU flag overlayed Maude's head." width="640" height="480" srcset="https://storage.ghost.io/c/ed/a2/eda2c6f7-faef-48b4-9ed4-86a4fa4dca68/content/images/size/w600/2026/05/eu-flag-simpsons-gif.gif 600w, https://storage.ghost.io/c/ed/a2/eda2c6f7-faef-48b4-9ed4-86a4fa4dca68/content/images/2026/05/eu-flag-simpsons-gif.gif 640w" /></a></figure><p><strong>Cisco layoffs amid 'record revenue': </strong>In the <em>same</em> blog post, Cisco CEO Chuck Robbins <a href="https://blogs.cisco.com/news/our-path-forward"><u>announced</u></a> record revenue and double-digit growth while also laying off 4,000 people, or 5% of the company, to spend more on AI. Robbins, meanwhile, had a total compensation package of ~$53 million last year. When I asked if Robbins planned on taking a pay cut, a spokesperson wouldn't comment. <em>(via </em><a href="https://techcrunch.com/2026/05/14/cisco-cuts-nearly-4000-jobs-to-spend-more-on-ai-reports-record-quarterly-revenue/"><em><u>TechCrunch ($)</u></em></a><em>; I wrote this story!)</em></p><p><strong>Cisco's security woes hit again: </strong>Oh look, <em>another </em>top-severity Cisco zero-day exploited in the wild; what a surprise, it's a day ending in "y." The bug was found in Cisco's SD-WAN products, aka <a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-rpa-EHchtZk"><u>CVE-2026-20127</u></a>. Cisco's research arm Talos — still doing good work — <a href="https://blog.talosintelligence.com/uat-8616-sd-wan/"><u>found exploitation</u></a> dating back to <em>at least</em> 2023 (woooof). Per Talos, the hackers sought to "establish persistent footholds into high value organizations including critical infrastructure sectors," which… sounds a lot like Volt Typhoon again, no? <em>(via </em><a href="https://blogs.cisco.com/news/our-path-forward"><em><u>Cisco</u></em></a><em>, </em><a href="https://techcrunch.com/2026/05/14/cisco-cuts-nearly-4000-jobs-to-spend-more-on-ai-reports-record-quarterly-revenue/"><em><u>TechCrunch ($)</u></em></a><em>, </em><a href="https://x.com/stephenfewer/status/2054959580333965761"><em><u>@stephenfewer</u></em></a><em>)</em></p><p><strong>Iranian hackers targeting gas stations: </strong>U.S. officials suspect Iranian hackers are accessing unprotected automatic tank gauge systems, used by gas and petrol stations to monitor the amounts of fuel in storage tanks. (Experts say this could allow gas leaks to go undetected, for example.) This was much to the chagrin of security researchers, who've been warning about this for <a href="https://masto.deoan.org/@neurovagrant/116580939631170699"><u>literally years</u></a>. <em>(via </em><a href="https://edition.cnn.com/2026/05/15/politics/iran-hackers-tank-readers-gas-stations"><em><u>CNN ($)</u></em></a><em>, </em><a href="https://discourse.ifin.network/t/iran-conflict-cyber-threat-activity/145/31"><em><u>IFIN</u></em></a><em>, </em><a href="https://masto.deoan.org/@neurovagrant/116580907211504633"><em><u>@neurovagrant</u></em></a><em>)</em></p><p><strong>Signal, Windscribe plans to bounce from Canada: </strong>Canada is preparing to vote on Bill C-22, a new surveillance bill that would require tech companies to collect customer metadata and store it for up to a year. E2EE messaging app <a href="https://www.theglobeandmail.com/politics/article-signal-warns-it-would-pull-out-of-canada-if-made-to-comply-with-lawful/"><u>Signal</u></a> and VPN provider <a href="https://www.theglobeandmail.com/politics/article-online-privacy-windscribe-lawful-access-bill/"><u>Windscribe</u></a> said they'd leave Canada if the bill passes rather than give up data about their customers. <em>(via </em><a href="https://www.theglobeandmail.com/politics/article-online-privacy-windscribe-lawful-access-bill/"><em><u>Globe and Mail ($)</u></em></a><em>, </em><a href="https://www.junonews.com/p/constitutional-lawyer-warns-of-bill"><em><u>Juno News</u></em></a><em>, </em><a href="https://bsky.app/profile/privacylawyer.ca/post/3mlyv3ukxkk2x"><em><u>@privacylawyer</u></em></a>)</p><p><strong>DOJ seeks to unmask app users: </strong>According to <a href="https://www.forbes.com/sites/thomasbrewster/2026/05/14/government-demands-apple-and-google-identify-over-100000-users-of-car-app/"><u>Forbes ($)</u></a>, the Justice Department wants Amazon, Apple, and Google to turn over the identities, addresses, and purchase histories of at least 100,000 users who downloaded the EZ Lynk app, which prosecutors accused of breaking federal emissions laws. It's a rare case of authorities trying to app users, but looks like a major overreach. </p><p><strong>Grand jury subpoena demands<em> healthcare</em> data: </strong>This is really f-ed up: The DOJ <a href="https://apnews.com/article/transgender-children-nyu-langone-hospital-subpoena-4b3e9eb234d2795d0893f57f9fa1cfdf"><u>secured</u></a> grand jury subpoenas for several U.S. hospitals, such as <a href="https://nyulangone.org/public-notices/TYHPsubpoena"><u>NYU Langone</u></a> in New York, demanding a ton of medical records of <em>children</em> who received gender affirming care since 2020. This is a <em>huge</em> privacy risk for potentially anyone who seeks healthcare of <em>any</em> kind. This may start by targeting trans people, but it will not stop there. <a href="https://www.thehandbasket.co/p/subpoena-texas-nyu-langone-trans-youth-health-records"><u>The Handbasket</u></a> reports on some of those affected. More from <a href="https://www.erininthemorning.com/p/nyu-langone-releases-grand-jury-subpoena" rel="noreferrer">Erin Reed</a>.</p><p><strong>Grafana extorted over stolen source code: </strong>Observability software Grafana says hackers (known for <a href="https://www.halcyon.ai/jp/threat-group/coinbasecartel"><u>using credentials</u></a> stolen from infostealers) broke in, stole its source code, and tried to extort the company into paying. Grafana said no, and went public instead, and blamed the breach on hackers stealing an authentication token. <em>(via </em><a href="https://bsky.app/profile/grafana.bsky.social/post/3mlzaritvzk2y"><em><u>@grafana</u></em></a><em>)</em></p><figure><a href="https://bsky.app/profile/grafana.bsky.social/post/3mlzariuilc2y"><img src="https://storage.ghost.io/c/ed/a2/eda2c6f7-faef-48b4-9ed4-86a4fa4dca68/content/images/2026/05/grafana.jpeg" alt="Two posts by Grafana on Bluesky, which reads: &quot;The attacker attempted to blackmail us, demanding payment to prevent the release of our codebase. Based on our operational experience and the published stance of the FBI, which notes that &quot;paying a ransom doesn't guarantee you or your organization will get any data back&quot; and only &quot;offers an incentive for others to get involved in this type of illegal activity&quot;.&quot;" width="1000" height="416" srcset="https://storage.ghost.io/c/ed/a2/eda2c6f7-faef-48b4-9ed4-86a4fa4dca68/content/images/size/w600/2026/05/grafana.jpeg 600w, https://storage.ghost.io/c/ed/a2/eda2c6f7-faef-48b4-9ed4-86a4fa4dca68/content/images/2026/05/grafana.jpeg 1000w" /></a></figure><div>
            
            <div>
                
                
                    <div>
                    
                        <div>
                            <p><span>~ ~</span></p>
                        </div>
                    
                    
                    </div>
                
            </div>
        </div>

<h3>THE HAPPY CORNER</h3>

<p><em>Ding dong!</em> What's that sound…? Hell yeah, it's the happy corner gong!</p><figure><a href="https://giphy.com/gifs/HallmarkChannel-meet-the-peetes-peeties-hallmarkies-5Yum3956ZBLSVb3WC6"><img src="https://storage.ghost.io/c/ed/a2/eda2c6f7-faef-48b4-9ed4-86a4fa4dca68/content/images/2026/05/giphy.gif" alt="an animated GIF of a radio show presenter in front of a microphone, hitting a gong with a mallet." width="480" height="270" /></a></figure><p>Trust me, you'll want to read this fictional but brilliantly <a href="https://nesbitt.io/2026/02/03/incident-report-cve-2024-yikes.html"><u>written "incident" report</u></a>. The only remediation you need is to laugh and enjoy — and maybe hide your Yubikeys from the office dog. CVE-2024-<em>YIKES,</em> indeed!</p><p>A smidge of good news for Android users (running the latest Pixel phones) who will get a new Intrusion Logging feature aimed at helping to <a href="https://cyberscoop.com/google-android-intrusion-logging-amnesty-spyware-detection/"><u>identify spyware and surveillance attacks</u></a>. More words from <a href="https://securitylab.amnesty.org/latest/2026/05/android-intrusion-logging-as-a-new-source-of-data-for-consensual-forensic-analysis/"><u>Amnesty</u></a>, which helped Google develop the feature. <em>Plus: </em>iOS and Android devices <a href="https://9to5google.com/2026/05/11/iphone-android-encrypted-rcs-ios-26-5/"><u>can now</u></a> send and receive end-to-end encrypted RCS messages!</p><p>Meanwhile: It looks like the U.K. is <a href="https://therecord.media/uk-moves-to-shield-security-researchers-cybercrime"><u>making good</u></a> on its earlier promise to shield security researchers from its decades-old hacking laws. It's a great step in the right direction (finally). </p><p>A fab offer here from threat analysis <em>sensei</em> <a href="https://x.com/JohnHultquist/status/2054629618892566647"><u>@JohnHultquist</u></a>: CYBERWARCON is an absolute hoot, and I've heard <a href="https://x.com/SLEUTHCON"><u>SLEUTHCON</u></a> is also a must-go event. </p><figure><a href="https://x.com/JohnHultquist/status/2054629618892566647"><img src="https://storage.ghost.io/c/ed/a2/eda2c6f7-faef-48b4-9ed4-86a4fa4dca68/content/images/2026/05/john.jpeg" alt="John Hultquist tweet: &quot;If you've been laid off from a cyber threat intel position and would like to come to @SLEUTHCON  this year, please reach out.&quot;" width="1000" height="203" srcset="https://storage.ghost.io/c/ed/a2/eda2c6f7-faef-48b4-9ed4-86a4fa4dca68/content/images/size/w600/2026/05/john.jpeg 600w, https://storage.ghost.io/c/ed/a2/eda2c6f7-faef-48b4-9ed4-86a4fa4dca68/content/images/2026/05/john.jpeg 1000w" /></a></figure><p>And lastly, this week. Since <a href="https://x.com/vxunderground/status/2051305793614385552"><u>vx-underground</u></a> and <a href="https://x.com/bquintero/status/2051675228678365614"><u>VirusTotal</u></a> have some of the world's largest repositories of malware, I wondered (<em>disclosure alert!</em><img src="https://board.circlewithadot.net/assets/plugins/nodebb-plugin-emoji/emoji/android/1f61e.png?v=28325c671da" class="not-responsive emoji emoji-android emoji--disappointed" style="height:23px;width:auto;vertical-align:middle" title="):" alt="😞" /> What would this look like, visualized stacked as hard drives, one on top of another? <a href="https://techcrunch.com/2026/05/13/this-is-what-some-the-worlds-largest-banks-of-malware-look-like-stacked-as-hard-drives/"><u>Guess no more…</u></a></p><figure><a href="https://techcrunch.com/2026/05/13/this-is-what-some-of-the-worlds-largest-banks-of-malware-look-like-stacked-as-hard-drives/"><img src="https://storage.ghost.io/c/ed/a2/eda2c6f7-faef-48b4-9ed4-86a4fa4dca68/content/images/2026/05/hard-drives.jpg" alt="a partial screenshot featuring a stack of hard drives from left-to-right in descending order, starting with: Burj Khalifa (2,722 feet); VirusTotal (2,645 feet); One World Trade Center (1,792 feet); the Eiffel Tower (1,083 feet); Zack Whittaker, who is 6 feet tall; and vx-underground's malware repository is about 2.5 feet worth of hard drives." width="1000" height="364" srcset="https://storage.ghost.io/c/ed/a2/eda2c6f7-faef-48b4-9ed4-86a4fa4dca68/content/images/size/w600/2026/05/hard-drives.jpg 600w, https://storage.ghost.io/c/ed/a2/eda2c6f7-faef-48b4-9ed4-86a4fa4dca68/content/images/2026/05/hard-drives.jpg 1000w" /></a></figure><p><em>Got good news to share? Get in touch! </em><a href="mailto:this@weekinsecurity.com?subject=Good%20news%20for%20your%20newsletter"><em>this@weekinsecurity.com</em></a><em>.</em></p><div>
            
            <div>
                
                
                    <div>
                    
                        <div>
                            <p><span>~ ~</span></p>
                        </div>
                    
                    
                    </div>
                
            </div>
        </div>

<h3>CYBER CATS &amp; FRIENDS</h3>

<p>This week's returning cyber cat is Murphy, basking in a beautiful stream of sunlight, knowing full well that his online accounts are protected with long, unique passphrases stored in his human's password manager and multi-factorered; or better yet, protected with passkeys. Many thanks again to Matt S. for sending in!</p><figure><img src="https://storage.ghost.io/c/ed/a2/eda2c6f7-faef-48b4-9ed4-86a4fa4dca68/content/images/2026/05/murphy.jpg" alt="Murphy is a very handsome brown and dark orange tabby who can be seen here resting and snoozing on a blue blanket, in a stream of sunlight." width="1000" height="933" srcset="https://storage.ghost.io/c/ed/a2/eda2c6f7-faef-48b4-9ed4-86a4fa4dca68/content/images/size/w600/2026/05/murphy.jpg 600w, https://storage.ghost.io/c/ed/a2/eda2c6f7-faef-48b4-9ed4-86a4fa4dca68/content/images/2026/05/murphy.jpg 1000w" /></figure><p><img src="https://board.circlewithadot.net/assets/plugins/nodebb-plugin-emoji/emoji/android/1f408.png?v=28325c671da" class="not-responsive emoji emoji-android emoji--cat2" style="height:23px;width:auto;vertical-align:middle" title="🐈" alt="🐈" /><strong> Send in your cyber cats!</strong> <img src="https://board.circlewithadot.net/assets/plugins/nodebb-plugin-emoji/emoji/android/1f408.png?v=28325c671da" class="not-responsive emoji emoji-android emoji--cat2" style="height:23px;width:auto;vertical-align:middle" title="🐈" alt="🐈" />‍<img src="https://board.circlewithadot.net/assets/plugins/nodebb-plugin-emoji/emoji/android/2b1b.png?v=28325c671da" class="not-responsive emoji emoji-android emoji--black_large_square" style="height:23px;width:auto;vertical-align:middle" title="⬛" alt="⬛" /> Got a cat or a non-feline friend? <a href="mailto:this@weekinsecurity.com?Subject=Cyber%20Cat%20%28%26%20Friends%29%20submission&amp;Body=Please%20include%20a%20JPG%20of%20your%20cyber%20cat%20%28or%20other%20non-feline%20friend%29%2C%20their%20name%2C%20and%20also%20your%20name%20and/or%20social%20media%20handle%20if%20you%20want%20credit." rel="noreferrer">Send me an email</a> with their photo and name and they will be featured in a later newsletter!</p><div>
            
            <div>
                
                
                    <div>
                    
                        <div>
                            <p><span>~ ~</span></p>
                        </div>
                    
                    
                    </div>
                
            </div>
        </div>

<h3>SUGGESTION BOX</h3>

<p>That's it for now! Thank you so much for reading. I won't keep you for another moment! I'm off to my local pottery studio to throw some clay. Cyber is important, but so is making stuff and being creative. Whether you're reading at home or doing something outdoors, coding for fun, or something even more adventurous, I hope you enjoy and that you have a great rest of your day, weekend, and your week. </p><p>I'll catch you next Sunday with everything you need to know from the world of cyber. Please <a href="mailto:this@weekinsecurity.com" rel="noreferrer">do get in touch</a> if you have anything to share!</p><p>Ta-ra!<br /><a href="http://mastodon.social/@zackwhittaker" rel="noreferrer">@zackwhittaker</a></p><div>
            
            <div>
                
                <div>
                    <h2><span>Reading this online? Get ~this week in security~ by email</span></h2>
                    <p><span>a weekly cybersecurity newsletter by Zack Whittaker, plus analysis and blogs.</span></p>
                    
        
            
            <div>
                
                
                    <span>Subscribe</span>
                    <span>
        
            
                
                
                
            
            
        
    </span>
                
            </div>
            <div>
                Email sent! Check your inbox to complete your signup.
            </div>
            <div></div>
        
        
                    <p><span>No spam. Unsubscribe anytime.</span></p>
                </div>
            </div>
        </div>]]></description><link>https://board.circlewithadot.net/topic/00852876-bf91-42a9-8c72-7e15e1ad8a67/this-week-in-security-may-17-2026-edition</link><generator>RSS for Node</generator><lastBuildDate>Mon, 25 May 2026 17:41:27 GMT</lastBuildDate><atom:link href="https://board.circlewithadot.net/topic/00852876-bf91-42a9-8c72-7e15e1ad8a67.rss" rel="self" type="application/rss+xml"/><pubDate>Sun, 17 May 2026 15:08:06 GMT</pubDate><ttl>60</ttl></channel></rss>