{"id":215887,"date":"2026-05-18T13:43:00","date_gmt":"2026-05-18T17:43:00","guid":{"rendered":"https:\/\/testing.news-you-need.com\/index.php\/2026\/05\/18\/banks-race-to-patch-new-cyber-vulnerabilities-and-other-cybersecurity-news\/"},"modified":"2026-05-18T16:30:17","modified_gmt":"2026-05-18T20:30:17","slug":"banks-race-to-patch-new-cyber-vulnerabilities-and-other-cybersecurity-news","status":"publish","type":"post","link":"https:\/\/testing.news-you-need.com\/index.php\/2026\/05\/18\/banks-race-to-patch-new-cyber-vulnerabilities-and-other-cybersecurity-news\/","title":{"rendered":"Banks race to patch new cyber vulnerabilities, and other cybersecurity news"},"content":{"rendered":"<p><a href=\"https:\/\/www.weforum.org\/stories\/2026\/05\/banks-race-to-patch-cyber-vulnerabilities-and-other-cybersecurity-news\/\">Banks race to patch new cyber vulnerabilities, and other cybersecurity news<\/a><\/p>\n<p><a href=\"https:\/\/www.weforum.org\/stories\/2026\/05\/banks-race-to-patch-cyber-vulnerabilities-and-other-cybersecurity-news\/\">https:\/\/www.weforum.org\/stories\/2026\/05\/banks-race-to-patch-cyber-vulnerabilities-and-other-cybersecurity-news\/<\/a><\/p>\n<p>Publish Date: <a href=\"publish_date]\">2026-05-18 13:43:00<\/a><\/p>\n<p>Source Domain: <a href=\"www.weforum.org\">www.weforum.org<\/a><\/p>\n<p>Author: <a href=\"\"><\/a><\/p>\n<p> Using an unordered list, summarize the following article with between 4 and 8 key points. This regular round-up brings you key cybersecurity stories from the past month.Top cybersecurity news: Banks shoring up vulnerabilities exposed by new AI tool; Hackers who targeted student data strike deal; World Cup cyber risks revealed.The World Economic Forum\u2019s Centre for Cybersecurity provides an independent and impartial platform to reinforce the importance of cybersecurity as a strategic imperative and drive global public-private action to address systemic cybersecurity challenges.1. Banks rush to counter newly-revealed cyber threatsWhile the vulnerability-hunting AI model has only been made available to a limited number of institutions currently, firstly in the US, its impact is being felt worldwide. Banks are discovering previously unknown weaknesses, increasing pressure to accelerate remediation and upgrades, particularly in institutions with ageing legacy systems. Smaller banks are being warned through shared findings from larger peers, while the European Central Bank (ECB) is urging banks across the eurozone to urgently prepare for cyberattacks. \u201cLack of access [to Mythos] is no excuse for doing nothing. On the contrary, it makes it even more important for banks to act now,\u201d said ECB Executive Board member Frank Elderson. The International Monetary Fund has also weighed in, saying that \u201cfast-moving, AI-driven cyber risks could destabilize the financial system if not managed carefully&#8221;. A new World Economic Forum report, in collaboration with KPMG, lays out how that careful management can be achieved. Empowering Defenders: AI for Cybersecurity says that organizations must choose from four levels of AI autonomy, and that with each there is a trade-off: &#8220;machine-speed actions enable cybersecurity professionals to counter AI-driven threats, but reduce the human accountability and oversight needed to catch errors before they cause damage&#8221;.Organizations must work out how much autonomy to give AI when it comes to cybersecurity. Image: World Economic Forum\/KPMG2. Cyber criminals who targeted student data &#8216;reach agreement&#8217;The company behind Canvas, the widely used education platform, says it has &#8220;reached an agreement&#8221; with the hackers behind a major breach that disrupted thousands of universities and colleges across the US, Canada, Australia and the UK in early May. Instructure said the deal prevented the publication of 3.5 terabytes of stolen student and university data and included \u201cdigital confirmation\u201d that the material had been destroyed, although the BBC said the company stopped short of spelling out whether money changed hands.The deal is seen by many cybersecurity experts as a risky trade-off, because there is no guarantee that the stolen data is actually deleted and it may also set a precedent and encourage further attacks.A recent survey by a US cybersecurity company found that 58% of Chief Information Security Officers are willing to pay hackers to &#8220;minimize disruption&#8221;. But this approach can backfire, says Cybersecurity Insiders, with ransomware attacks now often involving a &#8216;double extortion&#8217; \u2013 in which data is first stolen and then organizations are locked out of their own networks.DiscoverHow the Forum helps leaders understand cyber risk and strengthen digital resilience Show moreThe Centre for Cybersecurity provides a trusted platform where leaders come together to make sense of evolving cyber risks and their systemic implications. It focuses on building understanding and trust in an increasingly interconnected digital world.By enabling cross-sector collaboration and insight sharing, the Centre helps partners strengthen cyber resilience and address challenges that require collective responses.3. News in brief: Top cybersecurity stories this monthWorld Cup build-up sparks cyber warnings: A UK cybersecurity expert has warned that the upcoming 2026 football tournament across the US, Canada and Mexico could be &#8220;a temporary single point of failure&#8221; because it is a large spectacle with global visibility. Dr Aybars Tuncdogan of King&#8217;s College London Business School cited AI and geopolitical tensions as extra risk factors. Separately, a cybersecurity firm has warned that criminals are taking advantage of fans&#8217; excitement, with a rise in fake tickets, websites and phishing campaigns.Fresh set of cyberattacks on Ukraine: The threat group known as Ghostwriter is believed to be behind a recent spate of cyberattacks targeting governmental organizations in Ukraine. The Hacker News reports that the attacks involved PDF decoy documents, with the phishing emails impersonating a local telecommunications company.First AI-generated zero-day exploit detected: Google has identified a zero-day exploit \u2013 a cyberattack that is unknown to the vendor, developers or the public -developed using an AI model, reports Security Week. Designed to bypass two-factor authentication, this is the first time AI has been used to develop such an exploit. Google has not named the hacker group, but says the discovery may have prevented &#8220;a mass exploitation event&#8221;. OpenAI victim of supply chain attack: ChatGPT developer OpenAI has disclosed that two of its employee devices have been impacted by the supply chain attack on TanStack. On a blog post about the incident, the organization said they &#8220;found no evidence that OpenAI user data was accessed, that our production systems or intellectual property were compromised, or that our software was altered&#8221;.Cyber-crime network taken down for second time: German police shut down the second iteration of Crimenetwork in early May, a criminal marketplace that was first stopped in December 2024, according to Security Week. Both versions allowed criminals to trade illegal goods and services, like stolen data, drugs and fake documents, with transactions made in cryptocurrency such as Bitcoin. Law enforcement evidence suggests Crimenetwork was making more than $4.2 million in revenue. 4. More about cybersecurity on Forum StoriesAnnual Meeting on Cybersecurity 2026: Cybersecurity has become a systemic, economic and strategic imperative in an AI-driven, fragmented world. This was not a gradual evolution; it was a fundamental shift. Against this backdrop, leaders convened at the World Economic Forum\u2019s Annual Meeting on Cybersecurity 2026 in Geneva to advance cooperation and shape a more resilient digital future.Cybercrime has evolved into a vast and complex ecosystem, comprised of diverse players that trade, collaborate, specialize and depend on each other across every phase of criminal operations. To combat such activity, greater transparency and shared information are required. The Forum\u2019s Cybercrime Atlas helps bridge these gaps by building a shared understanding of cybercriminal networks and enabling more coordinated action. Learn more about the initiative here. The transition to quantum-safe security is well underway, impacting every layer of the digital economy and providing the opportunity to build stronger cyber resilience. But it&#8217;s a complex process, explains this expert. Standards have to be embedded and then deployed across the infrastructure societies depend on every day. And that process only works when each layer moves with clarity and alignment. Nation-state bad actors now use cyber attacks to actively sabotage critical infrastructure like hospitals, power grids and transit networks, with the burden of defending such infrastructure falling on cash- and resource-strapped local authorities. Deploying AI for defence can close the gap between physical operational technology and digital IT networks by matching the speed of attackers, argues the CEO of a US cybersecurity company.<br \/><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Banks race to patch new cyber vulnerabilities, and other cybersecurity news https:\/\/www.weforum.org\/stories\/2026\/05\/banks-race-to-patch-cyber-vulnerabilities-and-other-cybersecurity-news\/ Publish Date: 2026-05-18&#8230;<\/p>\n","protected":false},"author":1,"featured_media":215888,"comment_status":"closed","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/assets.weforum.org\/editor\/kDO9Ouvazov-LDyXpKX4Ma0TO9yzjjhzp6GIOqmyFN0.png","fifu_image_alt":"","footnotes":""},"categories":[15],"tags":[26,30,24,31,35,25,27],"class_list":["post-215887","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-ai","tag-breach","tag-cybersecurity","tag-exploit","tag-hacker","tag-phishing","tag-vulnerability"],"_links":{"self":[{"href":"https:\/\/testing.news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/215887"}],"collection":[{"href":"https:\/\/testing.news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/testing.news-you-need.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/testing.news-you-need.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/testing.news-you-need.com\/index.php\/wp-json\/wp\/v2\/comments?post=215887"}],"version-history":[{"count":1,"href":"https:\/\/testing.news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/215887\/revisions"}],"predecessor-version":[{"id":215889,"href":"https:\/\/testing.news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/215887\/revisions\/215889"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/testing.news-you-need.com\/index.php\/wp-json\/wp\/v2\/media\/215888"}],"wp:attachment":[{"href":"https:\/\/testing.news-you-need.com\/index.php\/wp-json\/wp\/v2\/media?parent=215887"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/testing.news-you-need.com\/index.php\/wp-json\/wp\/v2\/categories?post=215887"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/testing.news-you-need.com\/index.php\/wp-json\/wp\/v2\/tags?post=215887"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}