How AI Hallucinations Are Creating Real Security Risks

14/05/2026 0 Comments 0 tags

AI hallucinations are introducing serious security risks into critical infrastructure decision-making by exploiting human trust through highly confident yet incorrect outputs. When an AI model lacks certainty, it doesn’t have

PraisonAI CVE-2026-44338 Auth Bypass Targeted Within Hours of Disclosure

14/05/2026 0 Comments 0 tags

Threat actors have been observed attempting to exploit a recently disclosed security vulnerability in PraisonAI, an open-source multi-agent orchestration framework, within four hours of public disclosure. The vulnerability in question

Windows Zero-Days Expose BitLocker Bypasses And CTFMON Privilege Escalation

14/05/2026 0 Comments 0 tags

An anonymous cybersecurity researcher who disclosed three Microsoft Defender vulnerabilities has returned with two more zero-days involving a BitLocker bypass and a privilege escalation impacting Windows Collaborative Translation Framework (CTFMON).

New Fragnesia Linux Kernel LPE Grants Root Access via Page Cache Corruption

14/05/2026 0 Comments 0 tags

Details have emerged about a new variant of the recent Dirty Frag Linux local privilege escalation (LPE) vulnerability that allows local attackers to gain root access, making it the third

18-Year-Old NGINX Rewrite Module Flaw Enables Unauthenticated RCE

14/05/2026 0 Comments 0 tags

Cybersecurity researchers have disclosed multiple security vulnerabilities impacting NGINX Plus and NGINX Open, including a critical flaw that remained undetected for 18 years. The vulnerability, discovered by depthfirst, is a

Azerbaijani Energy Firm Hit by Repeated Microsoft Exchange Exploitation

13/05/2026 0 Comments 0 tags

A threat actor with affiliations to China has been linked to a “multi-wave intrusion” targeting an unnamed Azerbaijani oil and gas company between late December 2025 and late February 2026,

Microsoft’s MDASH AI System Finds 16 Windows Flaws Fixed in Patch Tuesday

13/05/2026 0 Comments 0 tags

Microsoft has unveiled a new multi-model artificial intelligence (AI)-driven system called MDASH to facilitate vulnerability discovery and remediation at scale, adding that it’s being tested by some customers as part

Microsoft Patches 138 Vulnerabilities, Including DNS and Netlogon RCE Flaws

13/05/2026 0 Comments 0 tags

Microsoft on Tuesday released patches for 138 security vulnerabilities spanning its product portfolio, although none of them have been listed as publicly known or under active attack. Of the 138

Most Remediation Programs Never Confirm the Fix Actually Worked

13/05/2026 0 Comments 0 tags

Security teams have never had better visibility into their environments and never been worse at confirming what they fix stays fixed. Mandiant’s M-Trends 2026 report puts the mean time to

[Webinar] Why Your AppSec Tools Miss the “Lethal Path” (and How to Fix It)

13/05/2026 0 Comments 0 tags

TL;DR: Stop chasing thousands of “toast” alerts. Join experts from Wiz and Okta/GitLab to learn how hackers connect tiny flaws to build a “Lethal Chain” to your data—and how to