336 US Highway 46, Fairfield, NJ 07004  ·  (888) 711-4521 intelamation.com
Cyber Shield Weekly
Cybersecurity Intelligence  ·  Powered by AI
■  May 19, 2026 Weekly Cyber Situational Awareness
🌍
5
Global Threats
🇺🇸
5
National Alerts
📍
5
Regional Alerts
🎧  Audio Edition Available
Prefer to listen? An AI-generated audio overview of this edition is available — ideal for your commute or workday background.
▶  Watch & Listen
🎵  Audio Only
INTEL

Cyber Threat Intelligence

Organizations face an escalating and multi-vector threat environment, with active exploitation risks spanning critical infrastructure components including a newly released Linux kernel privilege escalation proof-of-concept, remote code execution vulnerabilities in secure email gateways, and an urgent Drupal core patch requiring immediate action. Threat actors are simultaneously targeting developer toolchains and identity controls through a compromised VS Code extension distributing credential stealers and sophisticated OAuth-based phishing techniques capable of bypassing multi-factor authentication, underscoring the need for heightened vigilance across both endpoint security and identity governance programs.

The Hacker News
DirtyDecrypt PoC Released for Linux Kernel CVE-2026-31635 LPE Vulnerability

Proof-of-concept (PoC) exploit code has now been released for a recently patched security flaw in the Linux kernel that could allow for local privilege escalation (LPE). Dubbed DirtyDecrypt (aka DirtyCBC), the vulnerability was discovered and reported by the Zellic and V12 security team on May 9, 2026, only to be informed by the maintainers that it...

Read Full Article →
The Hacker News
The New Phishing Click: How OAuth Consent Bypasses MFA

In February 2026, a phishing-as-a-service (PhaaS) platform called EvilTokens went live. Within five weeks, it had compromised more than 340 Microsoft 365 organizations across five countries. The targets of the platform received a message asking them to enter a short code at microsoft.com/devicelogin and complete their normal MFA challenge, then wal...

Read Full Article →
The Hacker News
Drupal to Release Urgent Core Security Updates on May 20, Sites Told to Prepare

Drupal has issued an alert stating that it intends to release a "core security release" for all supported branches on May 20, 2026, from 5-9 p.m. UTC. "The Drupal Security Team urges you to reserve time for core updates at that time because exploits might be developed within hours or days," the maintainers of the PHP-based content management system...

Read Full Article →
The Hacker News
SEPPMail Secure E-Mail Gateway Vulnerabilities Enable RCE and Mail Traffic Access

Critical security vulnerabilities have been disclosed in SEPPMail Secure E-Mail Gateway, an enterprise-grade email security solution, that could be exploited to achieve remote code execution and enable an attacker to read arbitrary mails from the virtual appliance. "These vulnerabilities could have been exploited to read all mail traffic or as an e...

Read Full Article →
The Hacker News
Compromised Nx Console 18.95.0 Targeted VS Code Developers with Credential Stealer

Cybersecurity researchers have flagged a compromised version of the Nx Console extension that was published to the Microsoft Visual Studio Code (VS Code) Marketplace. The extension in question is rwl.angular-console (version 18.95.0), a popular user interface and plugin for code editors like VS Code, Cursor, and JetBrains. The VS Code extension has...

Read Full Article →
INNOVATION

Cybersecurity Advancements

The latest in defensive technologies, AI-driven threat detection, security research, and industry developments shaping the future of cybersecurity.

Security Week
Legacy Windows Tool MSHTA Fuels Surge in Silent Malware Attacks

Attackers are increasingly abusing Microsoft’s decades-old MSHTA utility to stealthily deliver stealers, loaders, and persistent malware through phishing, fake software downloads, and LOLBIN-based attack chains. The post Legacy Windows Tool MSHTA Fuels Surge in Silent Malware Attacks appeared first on SecurityWeek .

Read Full Article →
Security Week
Unpatched ChromaDB Vulnerability Can Lead to Server Takeover

The security defect can be exploited remotely, without authentication, to execute arbitrary code and leak sensitive information. The post Unpatched ChromaDB Vulnerability Can Lead to Server Takeover appeared first on SecurityWeek .

Read Full Article →
Security Week
B1ack’s Stash Marketplace Gives Away 4.6 Million Stolen Credit Cards

The stolen credit card data was released as a free download, allegedly in response to seller misconduct. The post B1ack’s Stash Marketplace Gives Away 4.6 Million Stolen Credit Cards appeared first on SecurityWeek .

Read Full Article →
SMB SPOTLIGHT

Small Business Spotlight

Small businesses are navigating an increasingly complex cybersecurity landscape, from weighing the risks of agentic AI adoption to staying ahead of emerging vulnerability threats. This week's spotlight explores practical guidance — including key questions to ask when using AI for vulnerability detection and how to prepare for the next major patch wave — to help SMBs build smarter, more resilient defenses.

NCSC UK
Thinking carefully before adopting agentic AI

When it comes to using agentic AI, make sure you can walk before you run.

Read Full Article →
NCSC UK
10 questions to ask when using AI models to find vulnerabilities

Using Artificial Intelligence to find vulnerabilities can bring added security considerations.

Read Full Article →
NCSC UK
Preparing for a ‘vulnerability patch wave’

Organisations must act now to prepare for a wave of patches that will address decades of technical debt.

Read Full Article →
💡
From the CTO's Desk
Daniel Ramos  — CTO — Intelligent Automation  LinkedIn

Happy Tuesday, cyber-warriors! Grab your coffee, because this week's threat landscape is serving up a full buffet of "why can't we have nice things." Let's dig in.

First up, a proof-of-concept dropped for CVE-2026-31635, a Linux kernel local privilege escalation bug dubbed DirtyDecrypt — because apparently naming kernel exploits after household chores is still on-trend. If you manage Linux systems, patch now. Not "later today." Now. PoC code in the wild means script kiddies are already sharpening their pencils.

Meanwhile, attackers discovered that OAuth consent flows are basically MFA's kryptonite. Why brute-force a one-time code when you can just sweet-talk a user into granting your malicious app full account access? Train your users to scrutinize OAuth permission requests like they're reading a cell phone contract — because the devil is absolutely in the scopes.

Drupal is dropping urgent core security patches on May 20th — that's tomorrow, folks. Schedule that maintenance window tonight. Also, SEPPMail's secure email gateway has RCE vulnerabilities, which is cybersecurity irony at its finest — your "secure" mail system, now with bonus unauthorized access.

Finally, Nx Console 18.95.0 was compromised with a credential stealer targeting VS Code developers. Check your installed extensions, verify hashes, and remember: supply chain attacks are the Trojan Horse strategy of the 21st century — classic, effective, and deeply annoying.

Stay patched, stay skeptical, and never trust anything that asks for more permissions than it needs — including your teenagers.

— Daniel Ramos, CTO — Intelligent Automation

THREATS

Threat Landscape Overview

Top active threats across global, national, and Fairfield, New Jersey levels. Click any item to read the full advisory or source article.

Intelligent Automation, LLC

Your Managed Cybersecurity Services Provider
(888) 711-4521
+ Subscribe Unsubscribe

This newsletter is compiled weekly by the Intelligent Automation cybersecurity team using live feeds from CISA, The Hacker News, Krebs on Security, Bleeping Computer, Security Week, and other authoritative sources. All article links direct to original publishers.

© 2026 Intelligent Automation, LLC  ·  336 US Highway 46, Fairfield, NJ 07004  ·  https://intelamation.com
Newsletter generated automatically every Tuesday at 12:00 PM Eastern.