📰 DAILY THREAT BRIEFING
Friday, May 8, 2026
12 News Items
THN · BleepingComputer · Krebs · Dark Reading · SANS

📰 Cybersecurity News Headlines

Top stories from leading cybersecurity publications as of May 8, 2026.

  1. Canvas login portals hacked in mass ShinyHunters extortion campaign
    — Bleeping Computer

    The ShinyHunters extortion gang has breached education technology giant Instructure again, this time exploiting another vulnerability to def…
  2. New TCLBanker malware self-spreads over WhatsApp and Outlook
    — Bleeping Computer

    A new trojan named TCLBanker, which targets 59 banking, fintech, and cryptocurrency platforms, uses a trojanized MSI installer for Logitech …
  3. After Replacing TeamPCP Malware, 'PCPJack' Steals Cloud Secrets
    — Dark Reading

    PCPJack makes innovative use of parquet files for stealthy, pre-validated target discovery as it canvasses multiple cloud environments.
  4. Has CISA Finally Found Its New Leader in Tom Parker?
    — Dark Reading

    Dark Reading investigates rumors that Tom Parker, a board room "operator" and longtime cyber exec, could be next in line to take over CISA.
  5. New PCPJack worm steals credentials, cleans TeamPCP infections
    — Bleeping Computer

    A new malware framework called PCPJack is stealing credentials from exposed cloud infrastructure while actively removing TeamPCP's access to…
  6. Australia warns of ClickFix attacks pushing Vidar Stealer malware
    — Bleeping Computer

    The Australian Cyber Security Center (ACSC) is warning organizations of an ongoing malware campaign using the ClickFix social engineering te…
  7. Ivanti EPMM CVE-2026-6973 RCE Under Active Exploitation Grants Admin-Level Access
    — The Hacker News

    Ivanti is warning that a new security flaw impacting Endpoint Manager Mobile (EPMM) has been explored in limited attacks in the wild. The hi…
  8. PCPJack Credential Stealer Exploits 5 CVEs to Spread Worm-Like Across Cloud Systems
    — The Hacker News

    Cybersecurity researchers have disclosed details of a new credential theft framework dubbed PCPJack that targets exposed cloud infrastructur…
  9. One Click, Total Shutdown: The "Patient Zero" Webinar on Killing Stealth Breaches
    — The Hacker News

    The hardest part of cybersecurity isn't the technology, it’s the people. Every major breach you’ve read about lately usually starts the …
  10. PAN-OS RCE Exploit Under Active Use Enabling Root Access and Espionage
    — The Hacker News

    Palo Alto Networks has disclosed that threat actors may have attempted to unsuccessfully exploit a recently disclosed critical security flaw…
  11. 'TrustFall' Convention Exposes Claude Code Execution Risk
    — Dark Reading

    Malicious repositories can trigger code execution in Claude Code, Cursor CLI, Gemini CLI, and CoPilot CLI with minimal or no user interactio…
  12. World's First AI-Driven Cyberattack Couldn't Breach OT Systems
    — Dark Reading

    The most sophisticated AI-integrated campaign to date hit a brick wall in the form of a SCADA login screen.

Generated by HiveNet.ai Threat Intelligence Platform · May 8, 2026 · Sources: The Hacker News, Bleeping Computer, Krebs on Security, Dark Reading, SANS ISC