Critical PAN-OS Flaw & Consultant Extortion Sentence – Weekly News Roundup

https://gbhackers.com/sap-patch-day-fixes-critical-flaws/
Here is the most recent Cybersecurity news for the past week:

πŸ€–AI-Assisted Zero-Day Exploitation Detected in the Wild
Google researchers identified what is believed to be the first real-world case of threat actors using AI to help discover and weaponize a zero-day vulnerability. The flaw enabled a two-factor authentication bypass in a widely used open-source administration tool, highlighting how AI is accelerating offensive cyber capabilities.
https://thehackernews.com/2026/05/hackers-used-ai-to-develop-first-known.html

πŸ”₯Critical PAN-OS Firewall Vulnerability Under Active Exploitation
Palo Alto Networks disclosed a critical PAN-OS vulnerability (CVE-2026-0300) allowing unauthenticated remote code execution with root privileges. The flaw is actively exploited in the wild, impacting PA-Series and VM-Series firewalls.
https://www.sans.org/newsletters/newsbites/xxviii-35

πŸŽ“Canvas Breach Impacts Thousands of Schools Worldwide
The cyberattack against Canvas LMS continues to escalate, with attackers threatening to leak data tied to more than 8,800 educational institutions globally. The incident is considered one of the largest education-sector breaches on record, affecting millions of students and faculty.
https://cyberscoop.com/canvas-instructure-data-theft-extortion-the-com/

πŸ”—Supply Chain Attacks Continue Expanding Across Trusted Platforms
Security researchers continue warning about the growth of software supply chain attacks, with threat actors increasingly targeting trusted update mechanisms, GitHub workflows, and third-party providers to gain indirect access into organizations.
https://www.esecurityplanet.com/weekly-roundup/supply-chain-attacks-ai-security-and-major-breaches-define-this-week-in-cybersecurity-in-may-2026/

βš–οΈFormer Security Consultant Sentenced for Extortion and Unauthorized Access
A former cybersecurity consultant was sentenced this week after exploiting privileged access to client environments and attempting extortion. The case highlights the growing importance of governance, access oversight, and trust verification inside security programs.

newsletter signup

Our goal? To deliver the best cybersecurity insights you can read inΒ five minutes or lessΒ β€” straight to your inbox, once a week.

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

newsletter signup

Our goal? To deliver the best cybersecurity insights you can read inΒ five minutes or lessΒ β€” straight to your inbox, once a week.

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.