iOS 26.5 Brings Default End-to-End Encrypted RCS Messaging Between iPhone and Android
2026-05-12T07:24:09Z•aa82e2037090adb9db202bb3a5b880cf51399a39660de70846878f8fcd2dfc55
AI-assisted exploit developmentHugging FaceIoT botnetLinux kernel LPEPAM backdoorPyPIRCS E2EEactive exploitationbackdoorcredential theftmalicious packagesmemory disclosurepatchingprivilege escalationremote code executionsoftware supply chainsupply chain compromisethreat actorsvm2 sandbox escapezero-day
What happened
This collection highlights a wave of high-risk vulnerabilities, active exploitations, and supply-chain attacks across multiple platforms. Notable incidents include: active exploitation of cPanel CVE-2026-41940 to deploy a Filemanager backdoor (actor: Mr_Rot13); a compromised Checkmarx Jenkins AST plugin tied to TeamPCP; Ollama out-of-bounds read CVE-2026-7482 (Bleeding Llama) allowing full process memory leaks; PAN-OS buffer overflow CVE-2026-0300 under active use for unauthenticated RCE; Ivanti EPMM CVE-2026-6973 used for remote code execution; and a new Linux kernel local privilege-escaltion
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- aa82e2037090adb9db202bb3a5b880cf51399a39660de70846878f8fcd2dfc55
- Enrichment time
- 2026-05-12T07:24:09Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.