Mon, 25 May 2026 19:43:27 +0530⚡ Weekly Recap: Linux Flaws, Defender 0-Days, Router Botnets, and Supply Chain Chaos
9.8/10 · Must read/watchThe Hacker Newssupply-chainai
Summary
Monday recap. Same mess, new week. A sketchy dev tool got people pwned, old bugs came back from the dead, and security products somehow needed protecting from themselves. A bunch of companies spent the week checking old boxes and forgotten servers they should'
Mon, 25 May 2026 17:32:46 +0530Ghost CMS CVE-2026-26980 Exploited to Hijack 700+ Sites for ClickFix Attacks
9.8/10 · Must read/watchThe Hacker Newsvulnai
Summary
Threat actors are exploiting a recently disclosed critical security flaw in Ghost CMS to inject malicious JavaScript code with an aim to fuel ClickFix attacks. According to QiAnXin XLab, the activity involves the exploitation of CVE-2026-26980 (CVSS score: 9.4
Mon, May 25 · 12:00 PM CDTFBI Warns 'Kali365' Phishing Kit Hijacks Microsoft 365 OAuth Tokens
9.0/10 · Must read/watchInfosecurity Magazineidentity
Summary
Collected from the Infosecurity Magazine news page during the latest run.
Mon, 25 May 2026 17:00:00 +0530The Alert Firehose Finally Meets Its Match
8.1/10 · Worth your timeThe Hacker Newsai
Summary
Ask a cybersecurity pro about Network Detection and Response (NDR) and you might still hear "Noisy," "Too much data." But ask the teams running NDR that includes agentic AI capabilities and you'll hear they're actually using it to catch threats earlier, triage
Mon, May 25 · 09:00 AM CDTNetherlands Seizes 800 Servers, Arrests 2 for Aiding Cyberattacks
8.1/10 · Worth your timeHacker Newsai
Summary
Surfaced from Hacker News front page during collection run. Freshness on HN: 3 hours ago.