A curated dispatch from GajShield

The GajShield Gazette

Lead story
Also today
May 12, 2026

Fuji Electric Tellus

The CISA advisory on Fuji Electric Tellus is another reminder that industrial software security must be treated beyond the application layer. A kernel driver granting br…

In brief

SAP fixes critical vulnerabilities in Commerce Cloud and S/4HANA

SAP’s May 2026 security updates should be treated with urgency because the affected products sit at the heart of business operations. The u…

May 12, 2026

iOS 26.5 Brings Default End-to-End Encrypted RCS Messaging Between iPhone and Android

Apple enabling default end-to-end encrypted RCS between iPhone and Android users is a major step forward because it finally improves privac…

May 12, 2026

Official CheckMarx Jenkins package compromised with infostealer

The Checkmarx Jenkins AST plugin compromise is a serious supply-chain warning because Jenkins plugins run inside CI/CD environments where s…

May 12, 2026

New GhostLock tool abuses Windows API to block file access

GhostLock is a useful reminder that availability attacks do not always need encryption, deletion, or ransomware-style payloads. By abusing …

May 12, 2026

Instructure confirms hackers used Canvas flaw to deface portals

The Canvas incident shows why XSS in trusted platforms should never be treated as a minor UI issue. Instructure confirmed that attackers ex…

May 11, 2026

Google: Hackers used AI to develop zero-day exploit for web admin tool

Google’s finding is a major warning sign for defenders: AI is no longer just being used to write phishing emails or polish malware scripts,…

May 11, 2026

Ollama Out-of-Bounds Read Vulnerability Allows Remote Process Memory Leak

The Ollama vulnerability is a serious reminder that locally hosted AI does not automatically mean safely hosted AI. CVE-2026-7482, also cal…

May 11, 2026

Fake OpenAI repository on Hugging Face pushes infostealer malware

The fake OpenAI repository on Hugging Face shows how quickly attackers are adapting to the AI supply chain. By impersonating a legitimate O…

May 10, 2026

JDownloader site hacked to replace installers with Python RAT malware

The JDownloader incident is another reminder that users can still be compromised even when they download software from the “official” websi…

May 10, 2026

cPanel, WHM Release Fixes for Three New Vulnerabilities — Patch Now

The latest cPanel and WHM vulnerabilities are a strong reminder that hosting control panels are high-value targets because they sit directl…

May 09, 2026

CISA Adds One Known Exploited Vulnerability to Catalog

CISA adding CVE-2026-6973 to the KEV catalog should be treated as a clear escalation signal, not just another vulnerability bulletin. The i…

May 09, 2026