Software Supply Chain Vulnerability3 Min Read June 19, 2026 AutoJack Attack Lets One Web Page Hijack AI Agent for Host Code Execution Microsoft researchers have detailed an exploit chain, named AutoJack, that turns an AI browsing agent into a delivery vehicle for remote…
Agentic AI SaaS Security4 Min Read June 19, 2026 Forget Data Leakage: Shadow AI's Real Threat Is Access Control The first wave of enterprise AI concern was straightforward. It was simply employees pasting sensitive data into public AI tools. Security…
Malware Social Engineering2 Min Read June 17, 2026 Crypto Clipper Campaign Abuses Fake Reviews, AI Narrators, and VirusTotal Comments An unknown threat actor has been observed leveraging paid or promoted posts on legitimate news websites to drum up buzz for their warez,…
Malware Mobile Security2 Min Read June 16, 2026 New Rokarolla Android Malware Steals PINs, SMS Codes, and Crypto Wallet Funds Security researchers at Zimperium's zLabs have documented a new Android banking trojan, Rokarolla, that targets 217 banking and…
Malware Supply Chain Attack7 Min Read June 15, 2026 North Korean Hackers Are Turning Developer Tools Into Malware Delivery Channels Cybersecurity researchers have flagged two malicious cyber campaigns that exhibit similarities with a persistent North Korean threat cluster…
Artificial Intelligence Vulnerability4 Min Read June 15, 2026 LiteLLM Vulnerability Chain Lets Low-Privilege Users Take Over AI Gateway Servers A default low-privilege account on a LiteLLM proxy can climb to full admin and run code on the server by chaining three vulnerabilities,…
Cybersecurity Hacking13 Min Read June 15, 2026 ⚡ Weekly Recap: Chrome 0-Day, UniFi Exploits, macOS Stealers, VPN Flaw and More Stuff broke again. Not in a movie way. An old tool was left exposed. An abandoned package was abused. A deprecated feature was still running…
Linux Supply Chain Attack5 Min Read June 12, 2026 Over 400 Arch Linux AUR Packages Hijacked to Deploy Infostealer and eBPF Rootkit Attackers took over more than 400 packages in the Arch User Repository (AUR) this week and rewrote their build scripts to install a credential…
Cybersecurity News Hacking News18 Min Read June 11, 2026 ThreatsDay Bulletin: Worm Code Leaked, AI Agent Phished, Claude Code Patch + 28 New Stories It's been one of those weeks. You expect the usual noise: recycled malware, sloppy attacks, another easy target getting hit. Instead, there's…
Developer Security Software Supply Chain2 Min Read June 11, 2026 GitHub to Disable npm Install Scripts by Default to Stop Supply Chain Attacks GitHub has announced what it said are "breaking changes" coming to npm version 12, one of which turns off install scripts by default to combat…
Vulnerability Zero-Day3 Min Read June 10, 2026 Microsoft Defender RoguePlanet Zero-Day Grants SYSTEM Access on Updated Windows The anonymous security researcher going by the name Chaotic Eclipse (aka Nightmare-Eclipse) has released a proof-of-concept (PoC) exploit for…
AI Security Software Supply Chain3 Min Read June 9, 2026 Microsoft Restores Some GitHub Repos, Keeps Others Offline as Miasma Probe Continues Microsoft on Monday confirmed that it temporarily removed some GitHub repositories in response to a recent security incident that led to 73 of…
Malware Supply Chain Attack4 Min Read June 9, 2026 Hades PyPI Attack: 19 Packages Poisoned to Auto-Run Bun Credential Stealer The Miasma supply chain campaign has sparked a fresh attack wave called Hades, this time involving 37 malicious wheel artifacts across 19…
Cybersecurity Hacking14 Min Read June 8, 2026 ⚡ Weekly Recap: Instagram Account Hacks, Android Zero-Day, GitHub Worm and More Monday again. The weekend was meant to be quiet. It wasn't. Last week had poisoned packages, a broken AI helper, and a worm tearing through…
Malware Software Supply Chain2 Min Read June 8, 2026 VS Code Adds 2-Hour Extension Auto-Update Delay to Limit Supply Chain Attacks Microsoft has announced that Visual Studio Code (VS Code) will apply a two-hour delay before extensions for the integrated development…
Malware Supply Chain Attack3 Min Read June 6, 2026 Miasma Worm Hits 73 Microsoft GitHub Repositories in Major Supply Chain Attack Microsoft's GitHub repositories have become the latest to fall victim to the ongoing Miasma self-replicating supply chain attack campaign. The…
Malware Software Supply Chain5 Min Read June 5, 2026 IronWorm and New Miasma Worm Variant Hit npm in Supply Chain Attacks Multiple software supply chain attacks have hit the npm ecosystem, with threat actors using both malicious and poisoned versions of over 50…
AI Security Vulnerability4 Min Read June 4, 2026 Claude Code GitHub Action Flaw Let One Malicious Issue Hijack Repositories A security researcher found a flaw in Anthropic's Claude Code GitHub Action that let an attacker take over vulnerable public repositories…
Malware Open Source3 Min Read June 4, 2026 Fake Sites Mimicking Open-Source Tools Rank High on Google to Deliver Malware via TDS Cybersecurity researchers have flagged a large-scale operation that impersonates open-source and freeware projects to funnel unsuspecting…
Software Development Vulnerability2 Min Read June 3, 2026 One-Click GitHub Dev Attack Lets Attackers Steal Full GitHub OAuth Tokens Cybersecurity researchers have disclosed a one-click attack via Microsoft Visual Studio Code (VS Code) that makes it possible to steal a…
Software Security Supply Chain Attack3 Min Read June 1, 2026 Miasma Supply Chain Attack Compromises Red Hat npm Packages with Credential-Stealing Worm A new Mini Shai-Hulud supply chain attack campaign, codenamed Miasma, has compromised @redhat-cloud-services packages to steal credentials and…
Cybersecurity Hacking11 Min Read June 1, 2026 ⚡ Weekly Recap: New Linux Flaw, PAN-OS Exploit, AI-Powered Attacks, OAuth Phishing and More Monday hit like a cron job with anger issues. A busted auth path here, a repo-side faceplant there, some "patched-ish" thing already getting…
API Security Cloud Security4 Min Read June 1, 2026 OpenAI Codex Authentication Tokens Stolen in codexui-android npm Supply Chain Attack Cybersecurity researchers have disclosed details of a new malicious supply chain campaign that's targeting developers using OpenAI Codex…
Artificial Intelligence Vulnerability Research6 Min Read May 29, 2026 ChatGPhish Vulnerability Turns ChatGPT Web Summaries Into a Phishing Surface Cybersecurity researchers have disclosed details of a vulnerability in OpenAI ChatGPT that leverages the artificial intelligence (AI)…
Software Supply Chain Threat Intelligence4 Min Read May 29, 2026 Malicious Sicoob NuGet Steals Banking Credentials as npm Packages Target Cloud Secrets Cybersecurity researchers have discovered a malicious NuGet package that masquerades as a C# software development kit for Sicoob, one of…
Vulnerability Disclosure Zero Day2 Min Read May 28, 2026 Microsoft Slams Public Zero-Day Disclosures Amid GitHub Researcher Account Removal Microsoft has come out strongly in favor of Coordinated Vulnerability Disclosure (CVD), urging the research community to share their findings…
Cybersecurity News Hacking News11 Min Read May 28, 2026 ThreatsDay Bulletin: Claude Security Plugin, Azure Priv-Esc, Kali365 MFA Bypass, FIFA Scams +15 More Every time you think the industry has finally stopped doing some reckless, low-effort crap, somebody spins up a fresh box full of sketchy…
Artificial Intelligence Enterprise Security6 Min Read May 28, 2026 New AI Usage Report: Enterprise AI Risk Is Heavily Concentrated Among a Small Group of AI "Power users" State of AI Usage Report 2026 (full report here) by LayerX Security reveals the extent of the enterprise AI visibility gap and why most…
Supply Chain Attack Threat Intelligence2 Min Read May 27, 2026 Malicious npm Package Stole Files From Claude AI User Directory via GitHub Cybersecurity researchers have discovered a new malicious package on the npm registry that comes with information stealing capabilities.…
Malware Threat Intelligence3 Min Read May 27, 2026 GlassWorm Malware Takedown Disrupts Developer Supply Chain Attack Infrastructure CrowdStrike, in partnership with Google and the Shadowserver Foundation, has announced the simultaneous disruption of all command-and-control…
Cybersecurity Hacking14 Min Read May 25, 2026 ⚡ Weekly Recap: Linux Flaws, Defender 0-Days, Router Botnets, and Supply Chain Chaos Monday recap. Same mess, new week. A sketchy dev tool got people pwned, old bugs came back from the dead, and security products somehow needed…
Malware Supply Chain Attack3 Min Read May 25, 2026 TrapDoor Supply Chain Attack Spreads Credential-Stealing Malware via npm, PyPI, and CratesIO A new coordinated cross-ecosystem software supply chain attack campaign has targeted npm, PyPI, and Crates.io to distribute…
DevSecOps Software Supply Chain2 Min Read May 23, 2026 npm Adds 2FA-Gated Publishing and Package Install Controls Against Supply Chain Attacks GitHub has rolled out new controls for npm to improve the security of the software supply chain, giving maintainers the ability to explicitly…
DevSecOps Malware2 Min Read May 23, 2026 Packagist Supply Chain Attack Infects 8 Packages Using GitHub-Hosted Linux Malware A new "coordinated" supply chain attack campaign has impacted eight packages on Packagist including malicious code designed to run a Linux…
Malware Supply Chain Attack3 Min Read May 23, 2026 Laravel-Lang PHP Packages Compromised to Deliver Cross-Platform Credential Stealer Cybersecurity researchers have flagged a fresh software supply chain attack campaign that has targeted multiple PHP packages belonging to…
Cloud Security Supply Chain Attack4 Min Read May 22, 2026 Megalodon GitHub Attack Targets 5,561 Repos with Malicious CI/CD Workflows Cybersecurity researchers have disclosed details of a new automated campaign called Megalodon that has pushed 5,718 malicious commits to 5,561…
Cybersecurity News Hacking News18 Min Read May 21, 2026 ThreatsDay Bulletin: Linux Rootkits, Router 0-Day, AI Intrusions, Scam Kits and 25 New Stories This week starts small. A token leaks. A bad package slips in. A login trick works. An old tool shows up again. At first, it feels like the…
Developer Tools Supply Chain Attack3 Min Read May 21, 2026 GitHub Internal Repositories Breached via Malicious Nx Console VS Code Extension GitHub on Wednesday officially confirmed that the breach of its internal repositories was the result of a compromise of an employee device…
Cybercrime Malware3 Min Read May 20, 2026 Webworm Deploys EchoCreep and GraphWorm Backdoors Using Discord and MS Graph API Cybersecurity researchers have flagged fresh activity from a China-aligned threat actor known as Webworm in 2025, deploying custom backdoors…
Browser Security Supply Chain Attack6 Min Read May 20, 2026 Typosquatting Is No Longer a User Problem. It's a Supply Chain Problem AI-generated lookalike domains are now embedded inside the third-party scripts running on your web properties. Here's why your current stack…
Encryption Vulnerability2 Min Read May 20, 2026 Microsoft Releases Mitigation for YellowKey BitLocker Bypass CVE-2026-45585 Exploit Microsoft on Tuesday released a mitigation for a BitLocker bypass vulnerability named YellowKey following its public disclosure last week. The…
Cloud Security Supply Chain Attack2 Min Read May 20, 2026 Grafana GitHub Breach Exposes Source Code via TanStack npm Attack Grafana Labs, on May 19, 2026, said an investigation into its recent breach found no evidence of customer production systems or operations…