AI-powered bug hunting tools are overwhelming security teams by generating duplicate vulnerability reports, forcing maintainers to spend time redirecting reports or explaining that bugs were already fixed, as Linus Torvalds noted regarding the Linux kernel security mailing list.
Deep Dive
Prerequisite Knowledge
- No data available.
Where to go next
- No data available.
Deep Dive
Linus Torvalds talks AI bug hunters, 7-Eleven ransom demand, MENA's new cybercrime opAdded:
From the CISO series, it's cybersecurity headlines.
These are the cybersecurity headlines for Tuesday, May 19th, [music] 2026. I'm Sarah Lane.
Linus Torvalds not into AI bug hunters.
Linus Torvalds says AI-powered bug hunting tools are overwhelming the Linux kernel security mailing list with duplicate reports, making it almost entirely unmanageable. He says multiple researchers are using the same AI tools to uncover the same vulnerabilities, forcing maintainers to spend time redirecting reports or explaining the bugs were already fixed. Torvalds said AI-generated findings are useful only when paired with meaningful contributions, like patches and technical analysis, criticizing drive-by reports that add little value beyond what automated tools already surface.
7-Eleven hit with ransom demands.
7-Eleven confirmed a data breach after the ShinyHunters Group claimed it stole more than 600,000 Salesforce records containing personal and corporate data.
The company said attackers accessed systems used to store application documents, though it hasn't disclosed the total number of affected individuals. ShinyHunters allegedly tried to extort the company before offering the stolen data for $250,000.
ShinyHunters has increasingly targeted Salesforce environments through phishing attacks, third-party integrations, and configuration weaknesses, rather than flaws in Salesforce itself.
MENA runs first-of-its-kind cybercrime op. Interpol said countries across the Middle East and North Africa, known as MENA, m e n a, carried out the region's first large-scale coordinated cybercrime crackdown, dubbed Operation RAMZ, R A M Z, between October of 2025 and February of 2026. The operation involved 13 countries targeting phishing campaigns, malware infrastructure, and online scams, resulting in 201 arrests, the identification of 3,867 victims, and the seizure of 53 servers.
Authorities also shared nearly 8,000 intelligence records during the operation.
TanStack weighs invitation-only pull requests. TanStack is considering making pull requests invitation-only after that supply chain attack from last week tied to the Shai Hulud worm compromised its GitHub Actions workflows. Attackers exploited a feature to run malicious code through automated CI pipelines, poisoning a shared cache across the repository. TanStack has removed the vulnerable workflow pattern, disabled shared caches, strengthened dependency and authentication protections, and adopted new safeguards in the Node.js package manager, pnpm.
>> [music] >> Huge thanks to our sponsor, >> [music] >> ThreatLocker. ThreatLocker is extending zero trust beyond endpoint control. With the recent release of zero trust network access and [music] zero trust cloud access, access isn't based on credentials alone. It requires [music] the right user, the right device, and the right conditions. Because, as we've seen in recent large-scale CRM breaches, stolen credentials >> [music] >> and misconfigurations can expose massive amounts of data. With [music] ThreatLocker, nothing is exposed and access is limited to exactly [music] what's needed. Learn more and start your free trial today at [music] threadlocker.com/c-sound.
New info stealer campaign gets bigger.
Researchers at OX Security say copies of that leaked Shy Halud malware are being used in various malicious NPM packages targeting developers. Noting four typo squatted or fake packages that stole credentials, cloud configuration files, crypto wallet data, and other sensitive information. With one package also adding infected systems to a DDoS botnets. The malware appears to be a largely unmodified copy of Shy Halud's leaked source code, which was previously linked to the Team PCP hacking group and recent supply chain attacks against node.js ecosystems. The infected packages were downloaded more than 2600 times and developers are urged to remove them and rotate compromised credentials and API keys.
US healthcare breaches continue. Several major healthcare data breaches affecting potentially millions of people were recently added to the US Department of Health and Human Services Breach Tracker. New York City Health and Hospitals Corporation reported the largest confirmed incidents with attackers accessing systems through a third-party vendor between late 2025 and early 2026 exposing sensitive personal, medical, insurance, biometric, and financial data tied to 1.8 million people. Other breaches include those at Erie Family Health Centers affecting 570,000 individuals and Florida Physician Specialists affecting 276,000.
Nginx Rift attackers target exposed servers. Researchers at Vulkan Check say attackers are already probing and exploiting the newly disclosed Nginx Rift vulnerability just days after patches and proof of concept code were released. The now 18-year-old flaw in Nginx was originally disclosed by researchers at Depth First and can let specially crafted HTTP requests crash worker processes and potentially enable remote code execution in rare cases where Linux memory protections like ASLR are disabled. Vulkan Check researcher Patrick Garrity said exploitation attempts were already hitting the company's canary systems. Security researcher Kevin Beaumont noted that modern Linux defaults make widespread real-world remote code execution attacks unlikely.
AI won't stop the slop. GitHub product security engineer Jerome Brown warns that many submissions lack reproducible proof-of-concept exploits or duplicate known issues requiring stricter validation standards. Cloudflare chief security officer Grant Borzikas says AI tools are worsening triage overload by producing large volumes of plausible but unverified findings that drain security team's time. Cloudflare testing of Anthropic's Methos showed some improvement in generating exploit chains and proof-of-concepts, but security researcher Daniel Stenberg, lead developer of curl, that's cURL, says most findings were false positives or low impact and argued the model's gains over earlier tools are modest despite the hype.
Remember to join us this Friday at 4:00 p.m. Eastern for our Department of No livestream. This week we're joined by Mike Lockhart, CISO at Eagle View, and Kathleen Mullen, the former CISO at MyKargerithm will be digging into how the news of the week applies to your security teams. What stories are more noise than signal and having some fun with our live chats. Be sure you're subscribed to the CISO series on YouTube and catch the stream at 4:00 p.m.
Eastern time this Friday. If you have some thoughts on the news from today or about our show in general, be sure to reach out feedback at CISOseries.com.
We'd love to hear from you. I am Sarah Lane reporting for the CISO series.
Thank you for listening and we will talk to you tomorrow.
Cybersecurity headlines are available every weekday. Head to CISOseries.com [music] for the full stories behind the headlines.
Related Videos
OpenHuman VS Hermes AI: Who Wins?
JulianGoldieSEO
285 views•2026-05-29
BREAKING: Microsoft’s New Image Generating Model Beat Out GPT 1.5 and Nano Banana 2
aimmediahouse
122 views•2026-06-03
Long-Running Agents — Build an Agent That Never Forgets with Google ADK
suryakunju
142 views•2026-05-30
This computer is made from real human brain cells. And you can buy it.
Talktmsmedia
3K views•2026-05-28
I Made the Same Anime Fight Scene in Every AI Video Generator
NobleGooseAnime
295 views•2026-05-30
Nvidia Bets Big On AI PCs | New Chip To Power Windows Laptops | Technology | AI Updates | N18S
cnnnews18
3K views•2026-06-01
I Tested NEW Opus 4.8 on Four Projects (Updated LLM Leaderboard)
AICodingDaily
298 views•2026-05-29
3D Platformer Update - NO CAPES
SolarLune
294 views•2026-05-30











