<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[🔒 Security News Digest - 2026-05-05]]></title><description><![CDATA[<p><img src="https://board.circlewithadot.net/assets/plugins/nodebb-plugin-emoji/emoji/android/1f512.png?v=28325c671da" class="not-responsive emoji emoji-android emoji--lock" style="height:23px;width:auto;vertical-align:middle" title="🔒" alt="🔒" /> Security News Digest - 2026-05-05</p><p><img src="https://board.circlewithadot.net/assets/plugins/nodebb-plugin-emoji/emoji/android/1f4ca.png?v=28325c671da" class="not-responsive emoji emoji-android emoji--bar_chart" style="height:23px;width:auto;vertical-align:middle" title="📊" alt="📊" /> 26 updates from 7 sources:</p><p><img src="https://board.circlewithadot.net/assets/plugins/nodebb-plugin-emoji/emoji/android/1f539.png?v=28325c671da" class="not-responsive emoji emoji-android emoji--small_blue_diamond" style="height:23px;width:auto;vertical-align:middle" title="🔹" alt="🔹" /> BleepingComputer: Karakurt extortion gang ‘cold case’ negotiator gets 8.5 years in prison<br />   <a href="https://www.bleepingcomputer.com/news/security/karakurt-extortion-gang-negotiator-sentenced-to-85-years-in-prison/" rel="nofollow noopener"><span>https://www.</span><span>bleepingcomputer.com/news/secu</span><span>rity/karakurt-extortion-gang-negotiator-sentenced-to-85-years-in-prison/</span></a></p><p><img src="https://board.circlewithadot.net/assets/plugins/nodebb-plugin-emoji/emoji/android/1f539.png?v=28325c671da" class="not-responsive emoji emoji-android emoji--small_blue_diamond" style="height:23px;width:auto;vertical-align:middle" title="🔹" alt="🔹" /> The Hacker News: We Scanned 1 Million Exposed AI Services. Here's How Bad the Security Actually Is<br />   <a href="https://thehackernews.com/2026/05/we-scanned-1-million-exposed-ai.html" rel="nofollow noopener"><span>https://</span><span>thehackernews.com/2026/05/we-s</span><span>canned-1-million-exposed-ai.html</span></a></p><p><img src="https://board.circlewithadot.net/assets/plugins/nodebb-plugin-emoji/emoji/android/1f539.png?v=28325c671da" class="not-responsive emoji emoji-android emoji--small_blue_diamond" style="height:23px;width:auto;vertical-align:middle" title="🔹" alt="🔹" /> SecurityWeek: Karakurt Ransomware Negotiator Sentenced to Prison<br />   <a href="https://www.securityweek.com/karakurt-ransomware-negotiator-sentenced-to-prison/" rel="nofollow noopener"><span>https://www.</span><span>securityweek.com/karakurt-rans</span><span>omware-negotiator-sentenced-to-prison/</span></a></p><p><img src="https://board.circlewithadot.net/assets/plugins/nodebb-plugin-emoji/emoji/android/1f539.png?v=28325c671da" class="not-responsive emoji emoji-android emoji--small_blue_diamond" style="height:23px;width:auto;vertical-align:middle" title="🔹" alt="🔹" /> SecurityWeek: Critical, High-Severity Vulnerabilities Patched in Apache MINA, HTTP Server<br />   <a href="https://www.securityweek.com/critical-high-severity-vulnerabilities-patched-in-apache-mina-http-server/" rel="nofollow noopener"><span>https://www.</span><span>securityweek.com/critical-high</span><span>-severity-vulnerabilities-patched-in-apache-mina-http-server/</span></a></p><p><img src="https://board.circlewithadot.net/assets/plugins/nodebb-plugin-emoji/emoji/android/1f539.png?v=28325c671da" class="not-responsive emoji emoji-android emoji--small_blue_diamond" style="height:23px;width:auto;vertical-align:middle" title="🔹" alt="🔹" /> BleepingComputer: Google now offers up to $1.5 million for some Android exploits<br />   <a href="https://www.bleepingcomputer.com/news/security/google-now-offers-up-to-15-million-for-some-android-exploits/" rel="nofollow noopener"><span>https://www.</span><span>bleepingcomputer.com/news/secu</span><span>rity/google-now-offers-up-to-15-million-for-some-android-exploits/</span></a></p><p>🦠 Malwarebytes: Update WhatsApp now: Two new flaws could expose you to malicious files<br />   <a href="https://www.malwarebytes.com/blog/news/2026/05/update-whatsapp-now-two-new-flaws-could-expose-you-to-malicious-files" rel="nofollow noopener"><span>https://www.</span><span>malwarebytes.com/blog/news/202</span><span>6/05/update-whatsapp-now-two-new-flaws-could-expose-you-to-malicious-files</span></a></p><p><img src="https://board.circlewithadot.net/assets/plugins/nodebb-plugin-emoji/emoji/android/1f539.png?v=28325c671da" class="not-responsive emoji emoji-android emoji--small_blue_diamond" style="height:23px;width:auto;vertical-align:middle" title="🔹" alt="🔹" /> The Hacker News: MetInfo CMS CVE-2026-29014 Exploited for Remote Code Execution Attacks<br />   <a href="https://thehackernews.com/2026/05/metinfo-cms-cve-2026-29014-exploited.html" rel="nofollow noopener"><span>https://</span><span>thehackernews.com/2026/05/meti</span><span>nfo-cms-cve-2026-29014-exploited.html</span></a></p><p><img src="https://board.circlewithadot.net/assets/plugins/nodebb-plugin-emoji/emoji/android/1f539.png?v=28325c671da" class="not-responsive emoji emoji-android emoji--small_blue_diamond" style="height:23px;width:auto;vertical-align:middle" title="🔹" alt="🔹" /> darkreading: How the Story of a USB Penetration Test Went Viral<br />   <a href="https://www.darkreading.com/cyberattacks-data-breaches/how-story-usb-penetration-test-went-viral" rel="nofollow noopener"><span>https://www.</span><span>darkreading.com/cyberattacks-d</span><span>ata-breaches/how-story-usb-penetration-test-went-viral</span></a></p><p><img src="https://board.circlewithadot.net/assets/plugins/nodebb-plugin-emoji/emoji/android/1f539.png?v=28325c671da" class="not-responsive emoji emoji-android emoji--small_blue_diamond" style="height:23px;width:auto;vertical-align:middle" title="🔹" alt="🔹" /> The Hacker News: The Back Door Attackers Know About — and Most Security Teams Still Haven’t Closed<br />   <a href="https://thehackernews.com/2026/05/the-back-door-attackers-know-about-and.html" rel="nofollow noopener"><span>https://</span><span>thehackernews.com/2026/05/the-</span><span>back-door-attackers-know-about-and.html</span></a></p><p><img src="https://board.circlewithadot.net/assets/plugins/nodebb-plugin-emoji/emoji/android/1f539.png?v=28325c671da" class="not-responsive emoji emoji-android emoji--small_blue_diamond" style="height:23px;width:auto;vertical-align:middle" title="🔹" alt="🔹" /> SecurityWeek: Critical Remote Code Execution Vulnerability Patched in Android<br />   <a href="https://www.securityweek.com/critical-remote-code-execution-vulnerability-patched-in-android-2/" rel="nofollow noopener"><span>https://www.</span><span>securityweek.com/critical-remo</span><span>te-code-execution-vulnerability-patched-in-android-2/</span></a></p><p><img src="https://board.circlewithadot.net/assets/plugins/nodebb-plugin-emoji/emoji/android/1f539.png?v=28325c671da" class="not-responsive emoji emoji-android emoji--small_blue_diamond" style="height:23px;width:auto;vertical-align:middle" title="🔹" alt="🔹" /> SecurityWeek: Critical Bug Could Expose 300,000 Ollama Deployments to Information Theft<br />   <a href="https://www.securityweek.com/critical-bug-could-expose-300000-ollama-deployments-to-information-theft/" rel="nofollow noopener"><span>https://www.</span><span>securityweek.com/critical-bug-</span><span>could-expose-300000-ollama-deployments-to-information-theft/</span></a></p><p><img src="https://board.circlewithadot.net/assets/plugins/nodebb-plugin-emoji/emoji/android/1f539.png?v=28325c671da" class="not-responsive emoji emoji-android emoji--small_blue_diamond" style="height:23px;width:auto;vertical-align:middle" title="🔹" alt="🔹" /> The Record from Recorded Future News: Australia launches cyber review board modeled on version disbanded in US<br />   <a href="https://therecord.media/australia-launches-cyber-review-board" rel="nofollow noopener"><span>https://</span><span>therecord.media/australia-laun</span><span>ches-cyber-review-board</span></a></p><p><img src="https://board.circlewithadot.net/assets/plugins/nodebb-plugin-emoji/emoji/android/1f539.png?v=28325c671da" class="not-responsive emoji emoji-android emoji--small_blue_diamond" style="height:23px;width:auto;vertical-align:middle" title="🔹" alt="🔹" /> BleepingComputer: Vimeo data breach exposes personal information of 119,000 people<br />   <a href="https://www.bleepingcomputer.com/news/security/vimeo-data-breach-exposes-personal-information-of-119-000-people/" rel="nofollow noopener"><span>https://www.</span><span>bleepingcomputer.com/news/secu</span><span>rity/vimeo-data-breach-exposes-personal-information-of-119-000-people/</span></a></p><p><img src="https://board.circlewithadot.net/assets/plugins/nodebb-plugin-emoji/emoji/android/1f539.png?v=28325c671da" class="not-responsive emoji emoji-android emoji--small_blue_diamond" style="height:23px;width:auto;vertical-align:middle" title="🔹" alt="🔹" /> SecurityWeek: Hacker Conversations: Joey Melo on Hacking AI<br />   <a href="https://www.securityweek.com/hacker-conversations-joey-melo-on-hacking-ai/" rel="nofollow noopener"><span>https://www.</span><span>securityweek.com/hacker-conver</span><span>sations-joey-melo-on-hacking-ai/</span></a></p><p><img src="https://board.circlewithadot.net/assets/plugins/nodebb-plugin-emoji/emoji/android/1f539.png?v=28325c671da" class="not-responsive emoji emoji-android emoji--small_blue_diamond" style="height:23px;width:auto;vertical-align:middle" title="🔹" alt="🔹" /> Security News | TechCrunch: 4 days left: Get 50% off a second TechCrunch Disrupt 2026 pass to make more deals faster<br />   <a href="https://techcrunch.com/2026/05/05/4-days-left-get-50-off-a-second-techcrunch-disrupt-2026-pass-to-make-more-deals-faster/" rel="nofollow noopener"><span>https://</span><span>techcrunch.com/2026/05/05/4-da</span><span>ys-left-get-50-off-a-second-techcrunch-disrupt-2026-pass-to-make-more-deals-faster/</span></a></p><p><img src="https://board.circlewithadot.net/assets/plugins/nodebb-plugin-emoji/emoji/android/1f539.png?v=28325c671da" class="not-responsive emoji emoji-android emoji--small_blue_diamond" style="height:23px;width:auto;vertical-align:middle" title="🔹" alt="🔹" /> BleepingComputer: The EOL Blind Spot in Your CVE Feed: What SCA Tools Don't Check.<br />   <a href="https://www.bleepingcomputer.com/news/security/the-eol-blind-spot-in-your-cve-feed-what-sca-tools-dont-check/" rel="nofollow noopener"><span>https://www.</span><span>bleepingcomputer.com/news/secu</span><span>rity/the-eol-blind-spot-in-your-cve-feed-what-sca-tools-dont-check/</span></a></p><p><img src="https://board.circlewithadot.net/assets/plugins/nodebb-plugin-emoji/emoji/android/1f539.png?v=28325c671da" class="not-responsive emoji emoji-android emoji--small_blue_diamond" style="height:23px;width:auto;vertical-align:middle" title="🔹" alt="🔹" /> The Hacker News: China-Linked UAT-8302 Targets Governments Using Shared APT Malware Across Regions<br />   <a href="https://thehackernews.com/2026/05/china-linked-uat-8302-targets.html" rel="nofollow noopener"><span>https://</span><span>thehackernews.com/2026/05/chin</span><span>a-linked-uat-8302-targets.html</span></a></p><p><img src="https://board.circlewithadot.net/assets/plugins/nodebb-plugin-emoji/emoji/android/1f539.png?v=28325c671da" class="not-responsive emoji emoji-android emoji--small_blue_diamond" style="height:23px;width:auto;vertical-align:middle" title="🔹" alt="🔹" /> Security News | TechCrunch: Hackers steal students’ data during breach at education tech giant Instructure<br />   <a href="https://techcrunch.com/2026/05/05/hackers-steal-students-data-during-breach-at-education-tech-giant-instructure/" rel="nofollow noopener"><span>https://</span><span>techcrunch.com/2026/05/05/hack</span><span>ers-steal-students-data-during-breach-at-education-tech-giant-instructure/</span></a></p><p><img src="https://board.circlewithadot.net/assets/plugins/nodebb-plugin-emoji/emoji/android/1f539.png?v=28325c671da" class="not-responsive emoji emoji-android emoji--small_blue_diamond" style="height:23px;width:auto;vertical-align:middle" title="🔹" alt="🔹" /> BleepingComputer: FTC to ban data broker Kochava from selling Americans’ location data<br />   <a href="https://www.bleepingcomputer.com/news/security/ftc-to-ban-data-broker-kochava-from-selling-americans-location-data/" rel="nofollow noopener"><span>https://www.</span><span>bleepingcomputer.com/news/secu</span><span>rity/ftc-to-ban-data-broker-kochava-from-selling-americans-location-data/</span></a></p><p><img src="https://board.circlewithadot.net/assets/plugins/nodebb-plugin-emoji/emoji/android/1f539.png?v=28325c671da" class="not-responsive emoji emoji-android emoji--small_blue_diamond" style="height:23px;width:auto;vertical-align:middle" title="🔹" alt="🔹" /> SecurityWeek: Microsoft Warns of Sophisticated Phishing Campaign Targeting US Organizations<br />   <a href="https://www.securityweek.com/microsoft-warns-of-sophisticated-phishing-campaign-targeting-us-organizations/" rel="nofollow noopener"><span>https://www.</span><span>securityweek.com/microsoft-war</span><span>ns-of-sophisticated-phishing-campaign-targeting-us-organizations/</span></a></p><p><img src="https://board.circlewithadot.net/assets/plugins/nodebb-plugin-emoji/emoji/android/1f539.png?v=28325c671da" class="not-responsive emoji emoji-android emoji--small_blue_diamond" style="height:23px;width:auto;vertical-align:middle" title="🔹" alt="🔹" /> darkreading: Microsoft Edge Stores Passwords in Process Memory, Posing Enterprise Risk<br />   <a href="https://www.darkreading.com/cyber-risk/microsoft-edge-passwords-enterprise-risk" rel="nofollow noopener"><span>https://www.</span><span>darkreading.com/cyber-risk/mic</span><span>rosoft-edge-passwords-enterprise-risk</span></a></p><p><img src="https://board.circlewithadot.net/assets/plugins/nodebb-plugin-emoji/emoji/android/1f539.png?v=28325c671da" class="not-responsive emoji emoji-android emoji--small_blue_diamond" style="height:23px;width:auto;vertical-align:middle" title="🔹" alt="🔹" /> Security News | TechCrunch: Kaspersky suspects Chinese hackers planted a backdoor into Daemon Tools in ‘widespread’ attack<br />   <a href="https://techcrunch.com/2026/05/05/kaspersky-suspects-chinese-hackers-planted-a-backdoor-into-daemon-tools-in-widespread-attack/" rel="nofollow noopener"><span>https://</span><span>techcrunch.com/2026/05/05/kasp</span><span>ersky-suspects-chinese-hackers-planted-a-backdoor-into-daemon-tools-in-widespread-attack/</span></a></p><p><img src="https://board.circlewithadot.net/assets/plugins/nodebb-plugin-emoji/emoji/android/1f539.png?v=28325c671da" class="not-responsive emoji emoji-android emoji--small_blue_diamond" style="height:23px;width:auto;vertical-align:middle" title="🔹" alt="🔹" /> The Hacker News: DAEMON Tools Supply Chain Attack Compromises Official Installers with Malware<br />   <a href="https://thehackernews.com/2026/05/daemon-tools-supply-chain-attack.html" rel="nofollow noopener"><span>https://</span><span>thehackernews.com/2026/05/daem</span><span>on-tools-supply-chain-attack.html</span></a></p><p><img src="https://board.circlewithadot.net/assets/plugins/nodebb-plugin-emoji/emoji/android/1f539.png?v=28325c671da" class="not-responsive emoji emoji-android emoji--small_blue_diamond" style="height:23px;width:auto;vertical-align:middle" title="🔹" alt="🔹" /> The Hacker News: Critical Apache HTTP/2 Flaw (CVE-2026-23918) Enables DoS and Potential RCE<br />   <a href="https://thehackernews.com/2026/05/critical-apache-http2-flaw-cve-2026.html" rel="nofollow noopener"><span>https://</span><span>thehackernews.com/2026/05/crit</span><span>ical-apache-http2-flaw-cve-2026.html</span></a></p><p><img src="https://board.circlewithadot.net/assets/plugins/nodebb-plugin-emoji/emoji/android/1f539.png?v=28325c671da" class="not-responsive emoji emoji-android emoji--small_blue_diamond" style="height:23px;width:auto;vertical-align:middle" title="🔹" alt="🔹" /> The Record from Recorded Future News: Conti, Akira ransomware affiliate given 8-year sentence<br />   <a href="https://therecord.media/conti-akira-ransomware-affiliate-sentenced" rel="nofollow noopener"><span>https://</span><span>therecord.media/conti-akira-ra</span><span>nsomware-affiliate-sentenced</span></a></p><p><img src="https://board.circlewithadot.net/assets/plugins/nodebb-plugin-emoji/emoji/android/1f539.png?v=28325c671da" class="not-responsive emoji emoji-android emoji--small_blue_diamond" style="height:23px;width:auto;vertical-align:middle" title="🔹" alt="🔹" /> BleepingComputer: Student hacked Taiwan high-speed rail to trigger emergency brakes<br />   <a href="https://www.bleepingcomputer.com/news/security/student-hacked-taiwan-high-speed-rail-to-trigger-emergency-brakes/" rel="nofollow noopener"><span>https://www.</span><span>bleepingcomputer.com/news/secu</span><span>rity/student-hacked-taiwan-high-speed-rail-to-trigger-emergency-brakes/</span></a></p><p><a href="https://infosec.exchange/tags/InfoSec" rel="tag">#<span>InfoSec</span></a> <a href="https://infosec.exchange/tags/SecurityNews" rel="tag">#<span>SecurityNews</span></a></p>]]></description><link>https://board.circlewithadot.net/topic/fa9b2a65-7f5a-4394-96d5-4fcf4fc64536/security-news-digest-2026-05-05</link><generator>RSS for Node</generator><lastBuildDate>Fri, 15 May 2026 04:41:51 GMT</lastBuildDate><atom:link href="https://board.circlewithadot.net/topic/fa9b2a65-7f5a-4394-96d5-4fcf4fc64536.rss" rel="self" type="application/rss+xml"/><pubDate>Tue, 05 May 2026 17:42:52 GMT</pubDate><ttl>60</ttl></channel></rss>