Scanning the Threat Landscape

AI-analyzed cybersecurity news with IFF classification and defender context.

Latest Stories

Election interlopers register 5K+ domains, hope to catch some voting phish

Malicious actors have registered over 5,000 new domains in an effort to impersonate election-related entities and conduct phishing attacks. These domains are designed to mimic legitimate election websites and organizations, aiming to trick voters into revealing personal information. This tactic highlights the shift from direct election system attacks to social engineering methods.

Oracle’s first monthly patch release fixes 35 flaws, including 11 rated ‘critical’

Oracle has released its first monthly Critical Security Patch Update (CSPU) for May 2026, addressing 35 vulnerabilities, including 11 rated as critical. Among these are several flaws with publicly available exploit code, some of which have been known for a considerable time, highlighting ongoing challenges with patching embedded open-source components.

Hackers Used Meta’s AI Support Bot to Seize Instagram Accounts

Hackers exploited Meta's AI support bot to gain unauthorized access to Instagram accounts, including those of the Obama White House and the U.S. Space Force Chief Master Sergeant. Instructions circulating on Telegram guided users on how to trick the AI into resetting account passwords, leading to the brief defacement of these accounts with pro-Iranian content.

Vulnerability Disclosure in the Age of AI

A new article by Melissa Hathaway argues that AI is dramatically accelerating vulnerability discovery, exposing decades of software development prioritizing speed over security. It calls for a coordinated national and international effort involving governments, vendors, and operators to accelerate remediation and invest in automated repair before adversaries exploit this opportunity.

Flowise’s MCP implementation can run ghost commands

A critical remote code execution (RCE) vulnerability, tracked as CVE-2026-40933, has been discovered in self-hosted Flowise deployments. The flaw exists within the implementation of Model Context Protocol (MCP) stdio servers, allowing attackers to trigger code execution with a single click via a malicious chatflow import. This vulnerability could grant attackers root-level access in containerized environments.

CISA Adds One Known Exploited Vulnerability to Catalog

CISA has added CVE-2024-21182, an unspecified vulnerability in Oracle WebLogic Server, to its Known Exploited Vulnerabilities (KEV) Catalog. This addition is based on evidence of active exploitation, posing significant risks to federal networks. Federal agencies are required to remediate this vulnerability, and CISA strongly encourages all organizations to prioritize its patching.

Microsoft fixes outage affecting MFA setup, MySignIn service

Microsoft has resolved an issue that was preventing customers from setting up multi-factor authentication (MFA) and accessing the My Sign-Ins service. The outage impacted users globally, causing difficulties in managing security settings. Services have now been restored, allowing normal access and MFA configuration.