Security Affairs newsletter Round 578 by Pierluigi Paganini – INTERNATIONAL EDITION

Security Affairs newsletter Round 578 by Pierluigi Paganini – INTERNATIONAL EDITION

Security Affairs newsletter Round 578 by Pierluigi Paganini – INTERNATIONAL EDITION

https://securityaffairs.com/192586/hacking/security-affairs-newsletter-round-578-by-pierluigi-paganini-international-edition.html

Publish Date: 2026-05-24 08:00:00

Source Domain: securityaffairs.com

Security Affairs newsletter Round 578 by Pierluigi Paganini – INTERNATIONAL EDITION

Pierluigi Paganini
May 24, 2026

A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box.

Enjoy a new round of the weekly SecurityAffairs newsletter, including the international press.

International Press – Newsletter

Cybercrime

Tycoon 2FA Operators Adopt OAuth Device Code Phishing 

201 arrests in first-of-its-kind cybercrime operation in MENA region 18 May 2026  

Exposing Fox Tempest: A malware-signing service operation 

B1ack’s Stash Releases 4.6 Million Stolen Credit Cards for Free  

The App Store stopped over $2.2 billion in potentially fraudulent transactions in 2025  

Cybercriminal VPN used by ransomware actors dismantled in global crackdown  

Middle East Malicious Infrastructure Report: 1,350+ C2 Servers Mapped Across 98 Providers

Canadian man arrested by international authorities, charged with administrating KimWolf DDoS botnet    

Ransomware ditched encryption in May 2026 — here’s why     

Malware

Popular node-ipc npm Package Infected with Credential Stealer 

Void Botnet uses Ethereum smart contracts for seizure-resistant C2 

Kash Patel’s clothing brand website shut down after reports it was hacked 

Megalodon: Mass GitHub Repo Backdooring via CI Workflows  

Malicious Postinstall Hook Found Across 700+ GitHub Repositories, Including Packagist and Node.js Projects  

Hacking

NGINX CVE-2026-42945 Exploited in the Wild, Causing Worker Crashes and Possible RCE

Huawei zero-day attack behind last year’s crash of Luxembourg’s entire telecoms network  

DirtyDecrypt: Linux kernel LPE in the RxGK subsystem (CVE-2026-31635) with public PoC  

PinTheft  

First public macOS kernel memory corruption exploit…

Source