CISO Daily Digest: Foxconn Ransomware Attack & Microsoft Patch Tuesday 137 Vulns (20260513)
Nitrogen ransomware group breaches Foxconn, steals 8TB data; Microsoft Patch Tuesday fixes 137 vulns with 30 critical; Apple releases OS 26.5.
May 13 saw a massive ransomware attack against manufacturing giant Foxconn (Hon Hai), with the Nitrogen ransomware group claiming to have stolen 8TB of data encompassing tens of millions of files. Microsoftโs May Patch Tuesday addressed 137 vulnerabilities, including 30 rated critical, while Apple pushed OS 26.5 updates across its entire product line. New vulnerabilities in Ollama and the Claude browser extension raised fresh concerns about AI platform security.
Active Threats This Week
๐ Nitrogen Ransomware Group Breaches Foxconn, Steals 8TB Data
The Nitrogen ransomware group allegedly breached manufacturing giant Foxconn (Hon Hai), exfiltrating 8TB of data comprising tens of millions of files. The attack is one of the largest ransomware incidents targeting the manufacturing sector.
๐ Reference: iThome
๐ Microsoft Patch Tuesday Fixes 137 Vulnerabilities, 30 Critical
Microsoftโs May 2026 Patch Tuesday addressed 137 vulnerabilities, including 30 critical-rated flaws. The update covers Windows, Office, Exchange Server, and multiple other product families.
๐ Reference: Krebs on Security | Dark Reading
๐ Ollama Critical Vulnerability Leaks Prompts and API Keys
A critical vulnerability in Ollama allows attackers to craft malicious GGUF model files that, when loaded, leak prompts, API keys, and other sensitive data from self-hosted LLM deployments.
๐ Reference: iThome
๐ Claude Browser Extension Design Flaw Enables AI Hijacking
A design flaw in the Claude Chrome extension could allow attackers to hijack the AI assistant through malicious browser extensions, potentially executing privileged commands and stealing data from user interactions.
๐ Reference: iThome
๐ Taiwan Student Hacks High-Speed Rail System, Stops Trains
A Taiwanese student successfully hacked into the countryโs high-speed rail system, gaining the ability to stop trains. The incident highlighted critical security gaps in transportation operational technology.
๐ Reference: Xakep | Dark Reading
๐ Apple Releases OS 26.5 Updates Across All Platforms
Apple pushed security updates across iPhone, iPad, Mac, Apple Watch, and Apple TV, including patches for the notification service vulnerability and multiple memory corruption issues.
๐ Reference: iThome
This digest is auto-generated from curated cybersecurity news sources.