Security News

Curated cybersecurity news and emerging threats relevant to startups, SMBs, and growing teams.

Industry news, vulnerability disclosures, compliance updates, and threat intelligence—handpicked for relevance to your environment.

Each item includes our perspective on why it matters to your security posture.

US Offers $10M Reward for Info on Russian-Backed Phishing Groups UNC5792 and UNC4221

Threat Intelligence Identity & Access Regulations

The US State Department is offering up to $10 million for information on two Russian-linked threat groups that ran phishing campaigns stealing WhatsApp and Signal accounts from government officials.

Why it matters: Phishing campaigns targeting messaging apps like WhatsApp and Signal represent a direct threat to out-of-band communication channels that security teams often treat as safe. If your organization uses consumer messaging apps for any sensitive coordination, this is a reminder to enforce mobile device policies and monitor for account compromise signals.
Read source →

SharePoint Deserialization RCE (CVE-2026-45659) Added to CISA's KEV Catalog

Vulnerability Compliance

CISA confirmed active exploitation of a CVSS 8.8 deserialization flaw in on-prem SharePoint Server, exploitable by any authenticated user with minimal Site Member permissions.

Why it matters: Low privilege requirement plus low attack complexity is a bad combination — any authenticated Site Member is enough to trigger this. If you run on-prem SharePoint Server (Subscription Edition, 2019, or Enterprise 2016), confirm the May 2026 patch is actually installed, not just scheduled.
Read source →

Wiz AI Agent Finds Critical Airline API Vulnerability in 15 Minutes

Vulnerability Tools Threat Intelligence

Wiz's autonomous red-team agent discovered a BOLA flaw in an airline booking API, exposing customer data and write access to flights, refunds, and cancellations.

Why it matters: Autonomous AI agents are compressing the time from 'API exists' to 'API is fully compromised' down to minutes. If you expose customer-facing APIs, assume both attackers and automated red-teaming tools can now find authorization flaws faster than your manual review cycle catches them.
Read source →

Supply Chain Attack on Polymarket Results in $3M User Theft

Supply Chain Incident Response

Attackers planted malicious code on the Polymarket betting platform via a compromised third-party vendor, stealing approximately $3 million from users.

Why it matters: This is a textbook third-party supply chain attack — the platform itself wasn't breached directly, but a vendor it trusted was. If you don't have visibility into scripts and dependencies loaded from third parties, you won't see this kind of attack until users start losing money.
Read source →

River Holdings Reports Ransomware Attack on US Banking Operations

Incident Response Threat Intelligence

River Holdings, operator of River Bank in the US, disclosed a ransomware attack in an SEC filing, forcing the company to isolate systems and disable compromised admin accounts.

Why it matters: The detail that stands out here is the disabled admin accounts — that's a sign the attackers had already established persistence before the ransomware was deployed. By the time ransomware executes, the breach is usually well past its initial stage. If your detection coverage doesn't extend to admin account activity and lateral movement, you're only seeing the end of the attack.
Read source →

Attackers Impersonate Companies via Fake OpenAI Tenants to Harvest Corporate Conversations

Threat Intelligence Identity & Access

Push Security documents a campaign where attackers create OpenAI tenants mimicking target companies, trick employees into joining, then read their ChatGPT conversations.

Why it matters: Your employees are already sending sensitive information to AI tools — attackers know this and are now targeting the AI layer directly. This attack doesn't require any malware: just a convincing invite from a legitimate domain. Make sure employees know how to verify which OpenAI tenant they're working in, and consider whether your acceptable-use policy covers AI tools explicitly.
Read source →

Second Cyberattack in Two Weeks Disrupts Iran's Banking System

Incident Response Threat Intelligence Compliance

A new, separate cyberattack on Iran's banking IT provider Informatics Services Corporation knocked out card payment services nationwide.

Why it matters: Two distinct attacks on the same national banking infrastructure within two weeks point to either a persistent adversary or a systemic weakness that the first incident didn't fully address. If you depend on a shared infrastructure/IT provider across multiple institutions, make sure incident response and containment don't stop at 'patched the first attack' — verify the underlying access path is actually closed.
Read source →

LastPass Reports Customer Data Leak Following Klue Breach

Identity & Access Incident Response Vulnerability

LastPass says customer contact data leaked via a breach at third-party vendor Klue, but vault contents and passwords remain unaffected.

Why it matters: The vault stayed safe, but names, emails, and phone numbers leaking through a support-tooling vendor is exactly the kind of exposure that fuels targeted phishing. If your org integrates a vendor like Klue, review what customer data it can touch and treat your support-stack integrations as part of your attack surface, not just your product.
Read source →

8x8 Becomes Latest Victim of the Klue Supply-Chain Breach

Identity & Access Incident Response Vulnerability

8x8 reports a data leak after attackers exploited a third-party Klue integration to gain unauthorized access to its Salesforce instance.

Why it matters: This is the same Klue supply-chain compromise that hit LastPass — a third-party integration is turning into a multi-victim breach. Audit every third-party app connected to your CRM (Salesforce, HubSpot, etc.) and revoke or scope down integration permissions you no longer need, especially for sales-intelligence tools like Klue.
Read source →

Researchers Hijack 26,000 AI Agents With a 'Rug Pull' Malicious Skill

Threat Intelligence Supply Chain Tools

Air Security researchers built a trusted-looking AI agent skill, then flipped it malicious post-adoption, gaining control of 26,000 agents.

Why it matters: Treat agent skills exactly like any third-party dependency: pin them to a hash and version, block them from pulling additional instructions from external domains, restrict tool/file permissions to the minimum needed, and monitor their behavior continuously after install.
Read source →