<img src="https://secure.ruth8badb.com/159098.png" alt="" style="display:none;">

IT Security Newsletter - 05/19/26

SHARE

Breaches

Millions Impacted Across Several US Healthcare Data Breaches

Several major data breaches were added to the healthcare data breach tracker maintained by the US Department of Health and Human Services (HHS) in recent days. All of the breaches were disclosed in recent months, but the number of affected individuals has only been made public now on the HHS breach tracker. The largest incident affects the New York City Health and Hospitals Corporation, which in March disclosed a data breach detected on February 2, 2026. READ MORE...

Software Updates

Microsoft confirms patching issues in restricted Windows networks

Microsoft says customers in restricted network environments may encounter Windows Update failures after installing the January 2026 optional non-security preview updates. In Windows network-restricted environments, ranging from fully isolated, air-gapped systems to strictly firewalled networks, affected systems will display error code 0x80010002 when updating through Windows Update. READ MORE...

Malware

Do fear the Reaper - stealer swipes macOS users' passwords, wallets, then backdoors them

A new infostealer variant targets macOS users by spoofing Apple, Microsoft, and Google and then then gets to work searching for victims' password managers so it can steal all of their credentials and access cryptocurrency wallets such as MetaMask and Phantom. The updated SHub stealer variant is called Reaper, and it uses macOS Script Editor, pre-populated with the malicious payload to execute the malware, according to SentinelOne research engineer Phil Stokes, who documented the attack in a Monday blog. READ MORE...


201 Arrested in Crackdown on Cybercrime in Middle East, North Africa

A total of 201 individuals were arrested, and 382 additional suspects were identified in a law enforcement crackdown on phishing and malware threats in the Middle East and North Africa (MENA) region. Named Operation Ramz, the 13-country effort also resulted in the seizure of 53 servers and in the identification of 3,867 victims across participating jurisdictions. Law enforcement agencies in Algeria, Bahrain, Egypt, Iraq, Jordan, Lebanon, Libya, Morocco, Oman, Palestine, Qatar, Tunisia, and the UAE participated in the operation. READ MORE...

Information Security

B1ack's Stash Marketplace Gives Away 4.6 Million Stolen Credit Cards

The notorious B1ack's Stash dark web carding marketplace has announced the free download of 4.6 million stolen credit card records. The data, it says, was dumped after sellers were caught reselling card data purchased from B1ack's Stash on competing platforms, a violation of the marketplace's policies. B1ack's Stash allegedly suspended 8 million stolen CVV2 records in response to the sellers' misconduct, and decided to release the card data for free, instead of deleting it from its inventory. READ MORE...

Exploits/Vulnerabilities

Critical Vulnerability Exposes Industrial Robot Fleets to Hacking

Universal Robots, a Danish company specializing in collaborative industrial robots, or cobots, has patched a critical vulnerability affecting one of its operating systems. Advisories published last week by the cybersecurity agency CISA and Universal Robots revealed that PolyScope 5, an operating system and GUI designed to power and control the company's cobots, is affected by CVE-2026-8153, an OS command injection vulnerability in the Dashboard Server interface. READ MORE...


'Claw Chain' Vulnerabilities Threaten OpenClaw Deployments

The now-patched vulnerabilities in the rapidly growing AI agent framework allow attackers to steal credentials, escalate privileges, and maintain persistence. Security researchers have uncovered four new vulnerabilities in the OpenClaw open source framework that attackers can chain to gain initial access, steal credentials, escalate privileges, and establish persistent backdoor access on compromised systems. The maintainers of the framework have patched all four vulnerabilities after data security firm Cyera reported it to them last month. READ MORE...

On This Date

  • ...in 1749, King George II of England grants the Ohio Company a charter of several hundred thousand acres of land around the forks of the Ohio River.
  • ...in 1951, musician Jeffrey Ross Hyman AKA Joey Ramone, the lead singer of classic punk rock group the Ramones, is born in Queens, NY.
  • ...in 1963, the New York Post Sunday Magazine publishes Dr. Martin Luther King Jr.'s "Letter from Birmingham Jail".
  • ...in 1984, "Press Your Luck" contestant Michael Larson exploits a flaw in the game show's "random" prize board to win USD $110,000 in a single night.