Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    PSIRT | FortiGuard Labs

    May 13, 2026

    Windows BitLocker zero-day gives access to protected drives, PoC released

    May 13, 2026

    CVE-2026-44572 | THREATINT

    May 13, 2026
    Facebook X (Twitter) Instagram
    • Demos
    • Technology
    • Gaming
    • Buy Now
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Canadian Cyber WatchCanadian Cyber Watch
    • Home
    • News
    • Alerts
    • Tips
    • Tools
    • Industry
    • Incidents
    • Events
    • Education
    Subscribe
    Canadian Cyber WatchCanadian Cyber Watch
    Home»News»InfoSec News Nuggets 05/13/2026
    News

    InfoSec News Nuggets 05/13/2026

    adminBy adminMay 13, 2026No Comments3 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Share
    Facebook Twitter LinkedIn Pinterest Email


    Foxconn confirms cyberattack after ransomware crew claims it stole confidential Apple, Nvidia files

    Foxconn confirmed a cyberattack affecting some North American factories after the Nitrogen ransomware group claimed it stole 8 TB of data, including more than 11 million files tied to internal project documentation and technical drawings. Foxconn says affected factories are returning to normal production, but the claims still matter because Foxconn supports major hardware supply chains. Even if customer data theft isn’t confirmed, attacks against large manufacturers can create downstream risk for partners, production timelines, intellectual property, and third-party assurance.

     

    Microsoft Patches Critical Zero-Click Outlook Vulnerability Threatening Enterprises

    Microsoft patched CVE-2026-40361, a critical remote code execution vulnerability affecting Word components used by Outlook. A researcher warned the flaw could be triggered when a victim reads or previews a malicious email, which makes it higher risk for enterprise environments because users may not need to click a link or open an attachment. Teams should prioritize patching Outlook and Office systems, especially for executives, finance, legal, and other users who receive high volumes of external email.

     

    Fortinet warns of critical RCE flaws in FortiSandbox and FortiAuthenticator

    Fortinet released fixes for two critical vulnerabilities affecting FortiSandbox and FortiAuthenticator that could let unauthenticated attackers execute commands or arbitrary code on unpatched systems. Fortinet says the flaws aren’t known to be exploited in the wild, but Fortinet products are often targeted by ransomware and espionage actors once technical details become available. Organizations using either product should patch quickly, restrict management interfaces, and review logs for suspicious access attempts.

     

    RubyGems Suspends New Signups After Hundreds of Malicious Packages Are Uploaded

    RubyGems temporarily suspended new account signups after attackers uploaded more than 500 malicious packages during a coordinated spam-publishing campaign. The malicious packages were removed, and RubyGems is working with Fastly on WAF protection and tighter rate limiting for account creation. This is another reminder that public package registries remain a soft target for supply chain abuse, and teams should avoid pulling new dependencies blindly without version pinning, reputation checks, and dependency review.

     

    Hugging Face Packages Weaponized With a Single File Tweak

    Researchers showed that an attacker could manipulate a Hugging Face model’s tokenizer.json file to hijack model output and redirect tool-call arguments through attacker-controlled infrastructure. The attack affects locally run models using common formats such as SafeTensors, ONNX, and GGUF, and could expose URLs, API parameters, or credentials embedded in model-driven requests. This matters because AI models and their supporting files are becoming part of the software supply chain, and defenders need to validate more than just model weights before allowing local model execution.

    The post InfoSec News Nuggets 05/13/2026 appeared first on AboutDFIR – The Definitive Compendium Project.



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleFuji Electric Tellus | CISA
    Next Article ZDI-26-312: Apple Safari Web Inspector WebCore Style Resolver Use-After-Free Remote Code Execution Vulnerability
    admin
    • Website

    Related Posts

    News

    Windows BitLocker zero-day gives access to protected drives, PoC released

    May 13, 2026
    News

    War and Data Centers Are Driving Up the Cost of Fiber-Optic Cable

    May 13, 2026
    News

    InfoSec News Nuggets 05/12/2026

    May 13, 2026
    Add A Comment

    Comments are closed.

    Demo
    Top Posts

    Catchy & Intriguing

    March 17, 202674 Views

    Defending Canada’s Digital Frontier: Combating Phishing, Social Engineering, Ransomware, and Malware

    March 23, 202624 Views

    IP Address Investigations and Local OSINT

    March 20, 202624 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews
    85
    Featured

    Pico 4 Review: Should You Actually Buy One Instead Of Quest 2?

    January 15, 2021 Featured
    8.1
    Uncategorized

    A Review of the Venus Optics Argus 18mm f/0.95 MFT APO Lens

    January 15, 2021 Uncategorized
    8.9
    Editor's Picks

    DJI Avata Review: Immersive FPV Flying For Drone Enthusiasts

    January 15, 2021 Editor's Picks

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Demo
    Most Popular

    Catchy & Intriguing

    March 17, 202674 Views

    Defending Canada’s Digital Frontier: Combating Phishing, Social Engineering, Ransomware, and Malware

    March 23, 202624 Views

    IP Address Investigations and Local OSINT

    March 20, 202624 Views
    Our Picks

    PSIRT | FortiGuard Labs

    May 13, 2026

    Windows BitLocker zero-day gives access to protected drives, PoC released

    May 13, 2026

    CVE-2026-44572 | THREATINT

    May 13, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • Home
    • Technology
    • Gaming
    • Phones
    • Buy Now
    © 2026 ThemeSphere. Designed by ThemeSphere.

    Type above and press Enter to search. Press Esc to cancel.