<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[this week in security — may 24 2026 edition]]></title><description><![CDATA[

<div>~ ~</div>

<h3>
  THIS WEEK, TL;DR
</h3>

<p><a href="https://www.bleepingcomputer.com/news/security/github-confirms-breach-of-3-800-repos-via-malicious-vscode-extension/"><strong><u>GitHub says hackers stole data from thousands of internal repos after a staffer's plugin was compromised</u></strong></a><br /><strong>Bleeping Computer: </strong>GitHub was hacked and some 3,800 of its internal repos breached after hackers compromised an employee's VS Code extension that they used for writing and editing source code. The poisoned extension, <a href="https://github.com/nrwl/nx-console/security/advisories/GHSA-c9j4-9m59-847w"><u>Nx Console</u></a>, was itself hacked by an earlier attack on open source web stack Tanstack, allowing the hackers to steal sensitive private keys and tokens, and hop from one hacked company to another. Nx Console also has <a href="https://nx.dev/blog/nx-console-v18-95-0-postmortem"><u>indicators of compromise</u></a> for affected customers beyond GitHub. If this seems like a trend, it's because it is, per <a href="https://www.wired.com/story/teampcp-software-supply-chain-attack-spree-github/"><u>Wired ($)</u></a>. Lock down your developer pipelines, people! GitHub said no customer information was taken, but it's a bruising incident for an already degraded GitHub. TeamPCP <a href="https://www.wiz.io/blog/mini-shai-hulud-teampcp-hits-antv-supply-chain"><u>took credit</u></a> for this latest breach (as it did with Tanstack), saying it was selling the stolen data, rather than extorting GitHub. <em>Meanwhile: </em>Grafana's <a href="https://grafana.com/blog/grafana-labs-security-update-latest-on-tanstack-npm-supply-chain-ransomware-incident/"><u>post-breach report</u></a> is out, which blamed last week's hack on <em>one</em> token that wasn't rotated after Tanstack's breach. Grafana decided not to pay the hackers' ransom.<br /><strong>More: </strong><a href="https://therecord.media/github-confirms-teampcp-hack-customers-unaffected"><u>The Record</u></a> | <a href="https://www.threatlocker.com/blog/github-breach-likely-caused-by-nx-console-compromise"><u>ThreatLocker</u></a> | <a href="https://www.wiz.io/blog/mini-shai-hulud-teampcp-hits-antv-supply-chain"><u>Wiz</u></a> | <a href="https://discourse.ifin.network/t/github-internal-repositories-compromised-offered-for-sale/484"><u>IFIN</u></a> | <a href="https://github.com/nrwl/nx-console/security/advisories/GHSA-c9j4-9m59-847w"><u>Nx Console</u></a> | <a href="https://x.com/jeffbcross/status/2057236396658811020"><u>@jeffbcross</u></a> | <a href="https://grafana.com/blog/grafana-labs-security-update-latest-on-tanstack-npm-supply-chain-ransomware-incident/"><u>Grafana</u></a></p><p><a href="https://arstechnica.com/security/2026/05/google-publishes-exploit-code-threatening-millions-of-chromium-users/"><strong><u>Google publishes exploit code affecting millions of Chromium users</u></strong></a><br /><strong>Ars Technica: </strong>Come for the interesting Chromium bug writeup, stay for <a href="https://infosec.exchange/@rebane2001/116606836889483917"><u>the "oh f—k" moment</u></a> when the researcher realizes Google <em>thought </em>it fixed the bug but hadn't. As a result, Google released the proof-of-concept code that allowed anyone to use it. The code was subsequently pulled. The bug in Chromium browsers (think Chrome, Edge, Brave, and any other browser that relies on the core Chromium engine) meant attackers could create a persistent connection to the user's browser as a way to proxy data through their internet connection, or used for denial-of-service attacks. This is similar to how botnet hosts use residential home networks to funnel their malicious traffic, so while this Chromium bug won't let hackers read your emails or see what websites you're browsing, this is still <em>not good</em>. The bug has been unfixed for ~3.5 years. <br /><strong>More: </strong><a href="https://www.bleepingcomputer.com/news/security/google-accidentally-exposed-details-of-unfixed-chromium-flaw/"><u>Bleeping Computer</u></a> | <a href="https://infosec.exchange/@rebane2001/116606836889483917"><u>@rebane2001 thread</u></a> | <a href="https://x.com/lukOlejnik/status/2057805633718514120"><u>@lukOlejnik</u></a></p><figure><a href="https://infosec.exchange/@rebane2001/116606836889483917"><img src="https://storage.ghost.io/c/ed/a2/eda2c6f7-faef-48b4-9ed4-86a4fa4dca68/content/images/2026/05/rebane.jpeg" alt="Rebane post on Mastodon: &quot;OH NO I JUST REALIZED THIS IS NOT ACTUALLY PROPERLY FIXED AND STILL WORKS 💀💀,&quot; followed by a screenshot showing the attacker's view in their browser showing that the attack still functions." width="1000" height="695" srcset="https://storage.ghost.io/c/ed/a2/eda2c6f7-faef-48b4-9ed4-86a4fa4dca68/content/images/size/w600/2026/05/rebane.jpeg 600w, https://storage.ghost.io/c/ed/a2/eda2c6f7-faef-48b4-9ed4-86a4fa4dca68/content/images/2026/05/rebane.jpeg 1000w" /></a></figure><p><a href="https://krebsonsecurity.com/2026/05/cisa-admin-leaked-aws-govcloud-keys-on-github/"><strong><u>CISA admin exposed AWS GovCloud keys and credentials on GitHub</u></strong></a><br /><strong>Krebs on Security: </strong>Embarrassing moment for U.S. cyber agency CISA after a contractor admin with access to government cloud credentials left them exposed to the internet in a public GitHub repo — including spreadsheets full of passwords and one plaintext file that simply read: "Important AWS Tokens." While a rookie mistake, it's ultimately not a good look for the agency who's charged with …<em>*checks notes*...</em> <em>federal cybersecurity!</em> Krebs had the scoop, and by the end of the week, lawmakers were <a href="https://krebsonsecurity.com/2026/05/lawmakers-demand-answers-as-cisa-tries-to-contain-data-leak/"><u>clambering for answers</u></a>. CISA has faced cuts, furloughs, and layoffs throughout the past year-plus under Trump, and still doesn't have a permanent Senate-approved director leading the place. <br /><strong>More: </strong><a href="https://krebsonsecurity.com/2026/05/lawmakers-demand-answers-as-cisa-tries-to-contain-data-leak/"><u>Krebs on Security</u></a> | <a href="https://cyberscoop.com/cisa-credential-leak-congress-demands-answers/"><u>Cyberscoop</u></a> | <a href="https://techcrunch.com/2026/05/19/us-cyber-agency-cisa-exposed-reams-of-passwords-and-cloud-keys-to-the-open-web/"><u>TechCrunch ($)</u></a> | <a href="https://infosec.exchange/@briankrebs/116608340448629866"><u>@briankrebs</u></a> </p><figure><a href="https://krebsonsecurity.com/2026/05/cisa-admin-leaked-aws-govcloud-keys-on-github/"><img src="https://storage.ghost.io/c/ed/a2/eda2c6f7-faef-48b4-9ed4-86a4fa4dca68/content/images/2026/05/cisa-list.jpeg" alt="a screenshot showing several files, including &quot;AWS-Workspace&quot;-named files, containing passwords, tokens, and configuration files." width="1000" height="438" srcset="https://storage.ghost.io/c/ed/a2/eda2c6f7-faef-48b4-9ed4-86a4fa4dca68/content/images/size/w600/2026/05/cisa-list.jpeg 600w, https://storage.ghost.io/c/ed/a2/eda2c6f7-faef-48b4-9ed4-86a4fa4dca68/content/images/2026/05/cisa-list.jpeg 1000w" /></a></figure>
<div>
            
            <div>
                
                
                    <div>
                    
                        <div>
                            <p><span>~ ~</span></p>
                        </div>
                    
                    
                    </div>
                
            </div>
        </div>

<div>
            
                <div>
                    <div>
                        <span>PLEASE SUPPORT THIS NEWSLETTER!</span>
                    </div>
                </div>
            
            <div>
                
                
                    <div>
                    
                        <div>
                            <p><a href="/user/index%40this.weekinsecurity.com" rel="noreferrer"><b><strong>~this week in security~</strong></b></a><span> is my weekly cybersecurity newsletter supported by readers like you. Please consider signing up for a </span><a href="https://this.weekinsecurity.com/#/portal/signup" rel="noreferrer"><b><strong>paying subscription starting at $10/month</strong></b></a><span> for access to exclusive articles, analysis, and more.</span></p><p><span>Or, you can </span><a href="https://this.weekinsecurity.com/this-week-in-security-april-19-2026-edition/#/portal/support" rel="noreferrer"><b><strong>submit a one-time tip</strong></b></a><span> to show your support!</span></p>
                        </div>
                    
                    
                        <a href="https://this.weekinsecurity.com/#/portal/signup">
                            Subscribe to support this newsletter
                        </a>
                        
                    </div>
                
            </div>
        </div>
<div>
            
            <div>
                
                
                    <div>
                    
                        <div>
                            <p><span>~ ~</span></p>
                        </div>
                    
                    
                    </div>
                
            </div>
        </div>





<h3>THE STUFF YOU MIGHT'VE MISSED
</h3>

<p><a href="https://www.pcmag.com/news/kash-patels-apparel-site-is-trying-to-trick-visitors-into-installing-malware"><strong><u>Kash Patel's apparel website down after serving ClickFix attacks</u></strong></a><br /><strong>PCMag: </strong>FBI director Kash Patel has pulled down his side hustle clothing business (which, admittedly, I didn't know was a thing) after the website was served with a ClickFix attack. This is where websites are hacked and trick visitors into thinking they're facing a Captcha-style screen, but are prompted to copy and paste malicious code into their computer, which plants malware. <strong>For subscribers:</strong> My <a href="https://this.weekinsecurity.com/clickfix-attacks-are-increasingly-devious-dangerous-and-can-get-you-hacked-in-an-instant/"><u>deep-dive read on ClickFix</u></a>.</p><figure><a href="https://mastodon.social/@zackwhittaker/116618277274478200"><img src="https://storage.ghost.io/c/ed/a2/eda2c6f7-faef-48b4-9ed4-86a4fa4dca68/content/images/2026/05/based-1.jpeg" alt="a screenshot from Kash Patel's Based Apparel website, showing a Cloudflare-style captcha box, but actually presents users with a lure to install malware on their computers." width="778" height="648" srcset="https://storage.ghost.io/c/ed/a2/eda2c6f7-faef-48b4-9ed4-86a4fa4dca68/content/images/size/w600/2026/05/based-1.jpeg 600w, https://storage.ghost.io/c/ed/a2/eda2c6f7-faef-48b4-9ed4-86a4fa4dca68/content/images/2026/05/based-1.jpeg 778w" /></a></figure><p><a href="https://shostack.org/blog/hipaa-nprm-threat-modeling/"><strong><u>HIPAA security rule is expected to be overhauled</u></strong></a><br /><strong>Shostack + Associates: </strong>HIPAA, the decades-old complicated healthcare law that actually doesn't do half the things people think, is set to have its security rules overhauled. The Department of Health &amp; Human Services has until the end of May to finalize the rule, which will matter a great deal to HIPAA-covered entities. Shostack's team explores some of the changes, as does <a href="https://www.bankinfosecurity.com/whats-next-for-proposed-hipaa-security-rule-overhaul-a-31692"><u>BankInfoSecurity</u></a>. Expect more to come soon.</p><p><a href="https://www.reuters.com/business/fears-unfettered-hacking-spurred-by-anthropics-mythos-ai-model-overstated-2026-05-20/"><strong><u>Fears of unfettered hacking sprees 'looking overstated' after Mythos release</u></strong></a><br /><strong>Reuters ($): </strong>Good stuff here from <a href="https://bsky.app/profile/ajvicens.bsky.social"><u>@ajvicens</u></a><strong> </strong>examining the security fallout (or lack of, frankly) following last month's restricted release of Anthropic's Mythos. Cyber experts say the AI model's abilities are largely overstated, and the reactions were measured. This was an important read and a good leveler for anyone needing a splash of cold water to the face on all-things AI security. <em>Meanwhile: </em>The White House scrapped an anticipated AI executive order, slated to allow federal agencies to get pre-release access to frontier AI models to test for flaws and dangerous capabilities. But tech executives didn't like it, per the <a href="https://www.washingtonpost.com/politics/2026/05/22/last-minute-lobbying-by-tech-industry-officials-led-trump-cancel-ai-order/"><u>Washington Post ($)</u></a>, even though their invites had already gone out.</p><figure><a href="https://bsky.app/profile/ddimolfetta.bsky.social/post/3mmeqstkuxk2e"><img src="https://storage.ghost.io/c/ed/a2/eda2c6f7-faef-48b4-9ed4-86a4fa4dca68/content/images/2026/05/david.jpeg" alt="David DiMolfetta post on Bluesky: &quot;WH AI EO signing delayed, people familiar tell me. Appears that enough tech CEOs couldn't turn out for the signing.&quot;" width="1000" height="317" srcset="https://storage.ghost.io/c/ed/a2/eda2c6f7-faef-48b4-9ed4-86a4fa4dca68/content/images/size/w600/2026/05/david.jpeg 600w, https://storage.ghost.io/c/ed/a2/eda2c6f7-faef-48b4-9ed4-86a4fa4dca68/content/images/2026/05/david.jpeg 1000w" /></a></figure><p><a href="https://www.bleepingcomputer.com/news/security/microsoft-warns-of-new-defender-zero-days-exploited-in-attacks/"><strong><u>Microsoft fixes Defender zero-day</u></strong></a><strong>; </strong><a href="https://www.theregister.com/security/2026/05/21/cisco-serves-up-yet-another-perfect-10-bug-with-secure-workload-admin-flaw/5244012"><strong><u>Cisco fixes new 10/10 bug</u></strong></a><br /><strong>Bleeping Computer, The Register:</strong> Microsoft fixed two zero-day bugs under attack in its Defender anti-malware engine that allowed malware to gain system-level privileges on a target's computer. The company also said it's <a href="https://www.bleepingcomputer.com/news/microsoft/microsoft-shares-mitigation-for-yellowkey-windows-zero-day/"><u>released mitigations</u></a> for a BitLocker bug (<em>*cough* </em>backdoor <em>*cough*) </em>dubbed YellowKey, which was <a href="https://arstechnica.com/security/2026/05/zero-day-exploit-completely-defeats-default-windows-11-bitlocker-protections/"><u>published online</u></a> as a zero-day and allows access to data on protected drives. <em>Meanwhile: </em>Not to be outdone, Cisco struck yet another 10/10 max-severity bug, this time in <a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-csw-pnbsa-g8WEnuy"><u>Cisco Secure Workload</u></a>; though, on the bright side, no evidence of exploitation just yet… but give it time. Patch today! <em>Last up: </em>Trend Micro <a href="https://success.trendmicro.com/en-US/solution/KA-0023430"><u>warned</u></a> of a <a href="https://www.securityweek.com/trendai-patches-apex-one-zero-day-exploited-in-the-wild/"><u>zero-day under attack</u></a> in its Apex One product.</p><p><a href="https://cyberscoop.com/verizon-data-breach-investigations-report-2026/"><strong><u>Verizon reports surge of exploited security vulnerabilities</u></strong></a><br /><strong>Cyberscoop: </strong>Verizon's annual data breach report is out. According to the data, 31% of intrusions (up from 20%) exploited security flaws in software code, like zero day bugs. The issue was blamed on too many bugs and not enough time to patch. Financially motivated crims made up most of the attacks, and ransomware is still a big deal, so doing the <a href="https://this.weekinsecurity.com/ai-can-find-bugs-and-flaws-but-do-not-forget-the-cybersecurity-basics/"><u>security basics</u></a> will help you a lot.<em> </em>Verizon <em>always </em>deserves the flak that it gets, but I will say, props for not putting the report behind a paywall; the direct PDF is readable <a href="https://www.verizon.com/business/resources/T15a/reports/2026-dbir-data-breach-investigations-report.pdf"><u>here</u></a>.</p><p><a href="https://techcrunch.com/2026/05/21/scammers-are-abusing-an-internal-microsoft-account-to-send-spam/"><strong><u>Scammers are abusing an internal Microsoft email to send spam</u></strong></a><br /><strong>TechCrunch ($): </strong>An internal email address that Microsoft uses for sending <em>actual</em> account notifications to users, such as two-factor codes, is being abused to send spam emails. Microsoft said (belatedly) that it was aware of the issue, but anti-spam nonprofit <a href="https://infosec.exchange/@spamhaus/116601270466207765"><u>Spamhaus</u></a> said this has been going on for months already. <em>(Disclosure: I wrote this story!)</em></p><div>
            
            <div>
                
                
                    <div>
                    
                        <div>
                            <p><span>~ ~</span></p>
                        </div>
                    
                    
                    </div>
                
            </div>
        </div>

<h3>OTHER NEWSY NUGGETS</h3>

<p><strong>Crypto 'wrench' attacks on the rise: </strong>Physical attacks on crypto holders are rising, with at least 72 confirmed incidents during 2025, allowing the theft of $41 million in crypto. These are called wrench attacks because bad people use violence (hence the wrench) to force crypto owners to give up their passwords. Many of the attacks have <a href="https://startupfortune.com/france-has-become-the-warning-sign-for-crypto-wrench-attacks/"><u>been in France</u></a>. <em>(via </em><a href="https://www.bloomberg.com/news/articles/2026-05-19/crypto-conferences-up-security-after-attacks-scams"><em><u>Bloomberg ($)</u></em></a><em>, </em><a href="https://cointelegraph.com/news/70-crypto-wrench-attacks-happen-france"><em><u>Cointelegraph</u></em></a><em>)</em></p><p><strong>How many government demands does Oura get? </strong>Health wearable gadget maker Oura says it receives government demands for users' data. The big question is <em>how many</em>. <em>(via </em><a href="https://this.weekinsecurity.com/oura-says-it-gets-government-demands-for-user-data-will-it-share-how-many/"><em><u>this week in security</u></em></a><em>)</em> </p><p><strong>KimWolf botnet boss busted: </strong>A Canadian man has been nicked and is set to be extradited across the border to the U.S. for allegedly running the notorious KimWolf botnet, used for launching DDoS-for-hire attacks. Some attacks were measured at 30 terabits per second, which the DOJ says was a "record" in known DDoS attacks at the time. <em>(via </em><a href="https://www.justice.gov/usao-ak/pr/canadian-man-arrested-international-authorities-charged-administrating-kimwolf-ddos"><em><u>Justice Department</u></em></a><em>, </em><a href="https://krebsonsecurity.com/2026/05/alleged-kimwolf-botmaster-dort-arrested-charged-in-u-s-and-canada/"><em><u>Krebs on Security</u></em></a><em>, </em><a href="https://www.govinfosecurity.com/23-year-old-canadian-charged-in-kimwolf-botnet-operation-a-31757"><em><u>GovInfoSecurity</u></em></a><em>)</em></p><p><strong>New gov app, who dis? </strong>The White House plans to auto-install its official app on all federal phones in the executive branch. Notwithstanding the <em>weirdness </em>of it all, the app is known to have <a href="https://www.notus.org/technology/trump-white-house-app-cybersecurity"><u>some security bugs</u></a>, but it's unclear if those bugs are fixed or if the app is the same version in the public app stores. <em>(via </em><a href="https://www.govexec.com/management/2026/05/white-house-ordering-agencies-place-its-new-app-all-employees-government-phones/413738/"><em><u>Government Executive</u></em></a><em>, </em><a href="https://nasawatch.com/trumpspace/new-app-coming-soon-to-nasa-phones/"><em><u>NASA Watch</u></em></a><em>)</em></p><p><strong>Trump Mobile exposed customer order details: </strong>Trump Mobile, the <a href="https://www.cnet.com/tech/mobile/trump-phone-t1-first-look-report/"><u>hilariously bad</u></a> Trump-themed cell provider and phone maker, exposed 10,000 unique customer order details. Two YouTubers disclosed the leak after hearing nothing from Trump Mobile, which later confirmed it had publicly spilled customers' data. <em>(via </em><a href="https://www.pcmag.com/news/trump-mobile-site-reportedly-exposing-customers-private-data"><em><u>PCMag</u></em></a><em>, </em><a href="https://techcrunch.com/2026/05/22/trump-mobile-confirms-it-exposed-customers-personal-data-including-phone-numbers-and-home-addresses/"><em><u>TechCrunch ($)</u></em></a><em>)</em></p><p><strong>SMS blaster at Eurovision: </strong>Incredible headline… a Chinese scammer was caught with an SMS blaster outside the Eurovision Song Contest in Vienna, and likely used to send several million SMS phishing text messages. <a href="https://commsrisk.com/chinese-sms-blaster-scammer-attacks-eurovision-in-vienna/"><u>Commsrisk</u></a> has high-resolution photos of the device for your viewing. Although, I will say, it's extremely <em>bad</em> form for this guy to have his 6-year-old son in the car. That's <em>far</em> too young to be handling cellular equipment.</p><p><strong>Hackers' favorite VPN is no more: </strong>Authorities have dismantled First VPN, a VPN provider that was allegedly used by ransomware gangs to hide their malicious traffic. French and Dutch authorities <a href="https://operation-saffron.eu/"><u>took down</u></a> dozens of servers, and <a href="https://www.politie.nl/en/news/2026/mei/21/first-vpn-criminal-vpn-service-taken-offline.html"><u>notified</u></a> those who used the service "who mistakenly believed themselves to be safe." <em>Savage</em>. <em>(via </em><a href="https://www.helpnetsecurity.com/2026/05/21/operation-saffron-first-vpn-takedown/"><em><u>Help Net Security</u></em></a><em>, </em><a href="https://operation-saffron.eu/"><em><u>Operation Saffron</u></em></a><em>, </em><a href="https://bsky.app/profile/ransomwaresommelier.com/post/3mmc7q4ynas2x"><em><u>@ransomwaresommelier</u></em></a><em>)</em></p><div>
            
            <div>
                
                
                    <div>
                    
                        <div>
                            <p><span>~ ~</span></p>
                        </div>
                    
                    
                    </div>
                
            </div>
        </div>

<h3>THE HAPPY CORNER</h3>

<p>Welcome to another happy corner, where everything is <em>~chill~</em>.</p><p>A new bipartisan(!) amendment, if passed, would effectively ban automatic license plate readers across the United States, per <a href="https://www.wired.com/story/a-bipartisan-amendment-would-end-police-license-plate-tracking-nationwide/"><u>Wired ($)</u></a>. This would be very good if it passes, and strikes at the heart of surveillance companies like Flock.</p><p>Congrats to those <s>kids</s> <em>young adults</em>, vx-underground, the world-renown group of friendly malware collectors, who marked their <a href="https://x.com/vxunderground/status/2057678768592839036"><u>7-year-anniversary this week</u></a>. If you're ever in the mood to research or rip apart some malware, vx has everything you need. Plus, their tweets always make me smile, and much like this newsletter, it also features cats. </p><p>Excellent news from Discord, which <a href="https://discord.com/blog/every-voice-and-video-call-on-discord-is-now-end-to-end-encrypted"><u>switched on end-to-end encryption</u></a> across its entire platform, meaning anyone who makes voice and video calls can now chat in privacy — not even Discord can access your content. No action is needed by users.</p><p>And lastly, <a href="https://x.com/avadanielsbf/status/2057641891835809828"><u>this week</u></a>: How many of us feel at the best of times:</p><figure><a href="https://x.com/avadanielsbf/status/2057641891835809828"><img src="https://storage.ghost.io/c/ed/a2/eda2c6f7-faef-48b4-9ed4-86a4fa4dca68/content/images/2026/05/no-ai.jpeg" alt="Mike tweet: &quot;NO AI!&quot; followed by two screenshots of Ava Daniels in 'Hacks', showing her speaking into her phone, saying: &quot;Siri, google, how to sink a superyacht — no AI!&quot;" width="1000" height="776" srcset="https://storage.ghost.io/c/ed/a2/eda2c6f7-faef-48b4-9ed4-86a4fa4dca68/content/images/size/w600/2026/05/no-ai.jpeg 600w, https://storage.ghost.io/c/ed/a2/eda2c6f7-faef-48b4-9ed4-86a4fa4dca68/content/images/2026/05/no-ai.jpeg 1000w" /></a></figure><p><em>Got good news to share? Get in touch! </em><a href="mailto:this@weekinsecurity.com?subject=Good%20news%20for%20your%20newsletter"><em>this@weekinsecurity.com</em></a><em>.</em></p><div>
            
            <div>
                
                
                    <div>
                    
                        <div>
                            <p><span>~ ~</span></p>
                        </div>
                    
                    
                    </div>
                
            </div>
        </div>

<h3>CYBER CATS &amp; FRIENDS</h3>

<p>This week's cyber pup is Ginger, who we're very fortunate to have <a href="https://this.weekinsecurity.com/this-week-in-security----august-11-edition-2/" rel="noreferrer">featured in a newsletter</a> a couple of years ago. Ginger recently passed over the rainbow bridge, and though I know we're all really sad to see her go, she was deeply loved, and lived a happy and wonderful life. Thanks to Jason T. for the photo, and we're sending all our love and support. </p><figure><img src="https://storage.ghost.io/c/ed/a2/eda2c6f7-faef-48b4-9ed4-86a4fa4dca68/content/images/2026/05/ginger.jpeg" alt="Ginger is a brown and dark-orange pupper who can be seen here looking beautiful and zen, laying cuddled up on a bedspread." width="1000" height="887" srcset="https://storage.ghost.io/c/ed/a2/eda2c6f7-faef-48b4-9ed4-86a4fa4dca68/content/images/size/w600/2026/05/ginger.jpeg 600w, https://storage.ghost.io/c/ed/a2/eda2c6f7-faef-48b4-9ed4-86a4fa4dca68/content/images/2026/05/ginger.jpeg 1000w" /></figure><p><img src="https://board.circlewithadot.net/assets/plugins/nodebb-plugin-emoji/emoji/android/1f408.png?v=28325c671da" class="not-responsive emoji emoji-android emoji--cat2" style="height:23px;width:auto;vertical-align:middle" title="🐈" alt="🐈" /><strong> Send in your cyber cats!</strong> <img src="https://board.circlewithadot.net/assets/plugins/nodebb-plugin-emoji/emoji/android/1f408.png?v=28325c671da" class="not-responsive emoji emoji-android emoji--cat2" style="height:23px;width:auto;vertical-align:middle" title="🐈" alt="🐈" />‍<img src="https://board.circlewithadot.net/assets/plugins/nodebb-plugin-emoji/emoji/android/2b1b.png?v=28325c671da" class="not-responsive emoji emoji-android emoji--black_large_square" style="height:23px;width:auto;vertical-align:middle" title="⬛" alt="⬛" /> Got a cat or a non-feline friend? <a href="mailto:this@weekinsecurity.com?Subject=Cyber%20Cat%20%28%26%20Friends%29%20submission&amp;Body=Please%20include%20a%20JPG%20of%20your%20cyber%20cat%20%28or%20other%20non-feline%20friend%29%2C%20their%20name%2C%20and%20also%20your%20name%20and/or%20social%20media%20handle%20if%20you%20want%20credit." rel="noreferrer">Send me an email</a> with their photo and name and they will be featured in a later newsletter!</p><div>
            
            <div>
                
                
                    <div>
                    
                        <div>
                            <p><span>~ ~</span></p>
                        </div>
                    
                    
                    </div>
                
            </div>
        </div>

<h3>SUGGESTION BOX</h3>

<p>That's all there is for this week's edition. Thank you so much for reading! I won't keep you for another moment. I hope you have a good rest of your long weekend (if you're here in the United States) and a great rest of your week wherever you are in the world.</p><p>Please <a href="mailto:this@weekinsecurity.com" rel="noreferrer">email me</a> if you want to see anything in next week's newsletter that you think would be a good fit. If you like what you read, please <a href="#/share" rel="noreferrer">share this newsletter</a>! </p><p>Peace, my friends,<br /><a href="http://mastodon.social/@zackwhittaker" rel="noreferrer">@zackwhittaker</a></p><div>
            
            <div>
                
                <div>
                    <h2><span>Reading this online? Get ~this week in security~ by email</span></h2>
                    <p><span>a weekly cybersecurity newsletter by Zack Whittaker, plus analysis and blogs.</span></p>
                    
        
            
            <div>
                
                
                    <span>Subscribe</span>
                    <span>
        
            
                
                
                
            
            
        
    </span>
                
            </div>
            <div>
                Email sent! Check your inbox to complete your signup.
            </div>
            <div></div>
        
        
                    <p><span>No spam. Unsubscribe anytime.</span></p>
                </div>
            </div>
        </div>]]></description><link>https://board.circlewithadot.net/topic/6c53bd4b-72c4-47f2-b28c-2738f91c071c/this-week-in-security-may-24-2026-edition</link><generator>RSS for Node</generator><lastBuildDate>Mon, 25 May 2026 17:41:27 GMT</lastBuildDate><atom:link href="https://board.circlewithadot.net/topic/6c53bd4b-72c4-47f2-b28c-2738f91c071c.rss" rel="self" type="application/rss+xml"/><pubDate>Sun, 24 May 2026 14:01:42 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to this week in security — may 24 2026 edition on Sun, 24 May 2026 14:18:57 GMT]]></title><description><![CDATA[<p><span><a href="/user/index%40this.weekinsecurity.com" rel="nofollow noopener">@<span>index</span></a></span> <span><a href="/user/zackwhittaker%40mastodon.social" rel="nofollow noopener">@<span>zackwhittaker</span></a></span> Zack, one thing wasn’t clear to me in the newsletter. Is that Chromium bug fixed now, or is it still outstanding?</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/scottwilson/statuses/116629984878001746</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/scottwilson/statuses/116629984878001746</guid><dc:creator><![CDATA[scottwilson@infosec.exchange]]></dc:creator><pubDate>Sun, 24 May 2026 14:18:57 GMT</pubDate></item></channel></rss>