📰 DAILY THREAT BRIEFING
Friday, May 15, 2026
12 News Items
THN · BleepingComputer · Krebs · Dark Reading · SANS

📰 Cybersecurity News Headlines

Top stories from leading cybersecurity publications as of May 15, 2026.

  1. TeamPCP hackers advertise Mistral AI code repos for sale
    — Bleeping Computer

    The TeamPCP hacker group is threatening to leak source code from the Mistral AI project unless a buyer is found for the data. […]
  2. Hackers exploit auth bypass flaw in Burst Statistics WordPress plugin
    — Bleeping Computer

    Hackers are leveraging a critical authentication bypass vulnerability in the WordPress plugin Burst Statistics to obtain admin-level access …
  3. SecurityScorecard Snags Driftnet to Level Up Threat Intelligence
    — Dark Reading

    The acquisition looks to boost visibility into third-party ecosystems, which are becoming a bigger concern as vectors for supply chain attac…
  4. Maximum Severity Cisco SD-WAN Bug Exploited in the Wild
    — Dark Reading

    This is the second time this year a threat actor has leveraged a CVSS 10.0 vulnerability in Cisco's network control system.
  5. Cisco warns of new critical SD-WAN flaw exploited in zero-day attacks
    — Bleeping Computer

    Cisco is warning that a critical Catalyst SD-WAN Controller authentication bypass flaw, tracked as CVE-2026-20182, was actively exploited in…
  6. OpenAI confirms security breach in TanStack supply chain attack
    — Bleeping Computer

    OpenAI says two employees' devices were breached in the recent TanStack supply chain attack that impacted hundreds of npm and PyPI packages,…
  7. Cisco Catalyst SD-WAN Controller Auth Bypass Actively Exploited to Gain Admin Access
    — The Hacker News

    Cisco has released updates to address a maximum-severity authentication bypass flaw in Catalyst SD-WAN Controller that it said has been expl…
  8. Stealer Backdoor Found in 3 Node-IPC Versions Targeting Developer Secrets
    — The Hacker News

    Cybersecurity researchers are sounding the alarm about what has been described as "malicious activity" in newly published versions of node-i…
  9. 'FrostyNeighbor' APT Carefully Targets Govt Orgs in Poland, Ukraine
    — Dark Reading

    Attackers uniquely fingerprint victims before delivering spear-phishing payloads aimed at espionage, in the latest campaign from the Belarus…
  10. ThreatsDay Bulletin: PAN-OS RCE, Mythos cURL Bug, AI Tokenizer Attacks, and 10+ Stories
    — The Hacker News

    Everything is still on fire. This week feels dumb in the worst way — bad links, weak checks, fake help desks, shady forum posts, and peopl…
  11. Ghostwriter Targets Ukrainian Government With Geofenced PDF Phishing, Cobalt Strike
    — The Hacker News

    The Belarus-aligned threat group known as Ghostwriter has been attributed to a fresh set of attacks targeting governmental organizations in …
  12. AI Drives Cybersecurity Investments, Widening 'Valley of Death'
    — Dark Reading

    In a role reversal, investment dollars in security startups exceeded the value of mergers and acquisitions in 1Q26 by more than $1 billion, …

Generated by HiveNet.ai Threat Intelligence Platform · May 15, 2026 · Sources: The Hacker News, Bleeping Computer, Krebs on Security, Dark Reading, SANS ISC