43AA 6E9A 54EE B550 D830 EF7A 36EE 72FB 8AD1 F5CC

Infosec bits for 2026 week 21

Anele Siwela | May 22, 2026, 2:36 p.m.

Cybersecurity News:

  • New Windows ‘MiniPlasma’ Zero-Day Let Attackers Gain SYSTEM Access – PoC Released [Abinaya, CyberSecurity News]
  • Cybersecurity News: Cisco’s 10.0 vulnerability, Microsoft email spammed, Chrome vulnerability surge [Steve Prentice, ciso series]
  • FBI Warns of Kali365 Attacking Microsoft 365 Users to Steal Logins and Bypass MFA [Abinaya, CyberSecurity News]
  • Expert urges businesses to adopt modern security systems against fraud [Sodiq Omolaoye, guardian]
  • CISA Adds Exploited Langflow and Trend Micro Apex One Vulnerabilities to KEV [Ravie Lakshmanan, Thehacker news]
  • CISA asks cybersecurity community to alert it to vulnerability exploitation [Eric Geller, Cybersecurity dive]
  • Vulnerabilities & Patches:

  • Critical Chrome Vulnerabilities Enable Remote Code Execution Attacks – Patch Now! [Abinaya, CyberSecurity News]
  • Anthropic’s Mythos set off a cybersecurity ‘hysteria.’ Experts say the threat was already here [Hugh Son , Samantha Subin, CNBC]
  • CVE-2026-31431: Copy Fail vulnerability enables Linux root privilege escalation across cloud environments [microsoft, microsoft]
  • Claw Chain' Vulnerabilities Threaten OpenClaw Deployments [Jai Vijayan, Darkreading]
  • Malware:

  • New TCLBanker malware self-spreads over WhatsApp and Outlook [Bill Toulas, Bleeping computer]
  • Disrupting Fox Tempest: A cybercrime service that turned “verified” software into a pathway for ransomware [Steven Masada, microsoft]
  • New Linux malware ‘Showboat’ targets Middle East telecom provider [scworld, Scworld]
  • Microsoft disrupts service selling fake certificates to ransomware gangs [Sam Sabin, axios]
  • Windows 11’s new SecureBoot folder isn’t malware. Here’s what it does [pcworld, Laura Pippig]
  • Microsoft Disrupts Fox Tempest Malware-Signing-as-a-Service Platform Tied to Ransomware Gangs [John Kevin Hao, securityboulevard]