Mobile Security Vulnerability2 Min Read June 3, 2026 Microsoft 365 Android Apps Let Any App Steal Account Tokens via Leftover Debug Flag A development flag left switched on in production builds of several Microsoft 365 Android apps disabled the check that limits account-token…
Software Development Vulnerability2 Min Read June 3, 2026 One-Click GitHub Dev Attack Lets Attackers Steal Full GitHub OAuth Tokens Cybersecurity researchers have disclosed a one-click attack via Microsoft Visual Studio Code (VS Code) that makes it possible to steal a…
Network Security Vulnerability2 Min Read June 3, 2026 Unpatched Windows Search URI Vulnerability Lets Attackers Steal NTLMv2 Hashes Cybersecurity researchers have disclosed details of an unpatched issue that could be exploited to disclose a user's NTLMv2 hash to the…
Malware Threat Intelligence2 Min Read June 2, 2026 Gamaredon Exploits WinRAR to Deliver GammaWorm and GammaSteel Against Ukraine The Russian hacking group known as Gamaredon has been attributed to the continued exploitation of a WinRAR vulnerability to deliver multiple…
Cyber Espionage Threat Intelligence2 Min Read June 2, 2026 Pakistan-Linked SideCopy Targets Afghanistan Finance Ministry with Xeno RAT Cybersecurity researchers have disclosed details of a spear-phishing campaign likely undertaken by the Pakistan-aligned SideCopy group…
Software Security Supply Chain Attack3 Min Read June 1, 2026 Miasma Supply Chain Attack Compromises Red Hat npm Packages with Credential-Stealing Worm A new Mini Shai-Hulud supply chain attack campaign, codenamed Miasma, has compromised @redhat-cloud-services packages to steal credentials and…
Cybersecurity Hacking11 Min Read June 1, 2026 ⚡ Weekly Recap: New Linux Flaw, PAN-OS Exploit, AI-Powered Attacks, OAuth Phishing and More Monday hit like a cron job with anger issues. A busted auth path here, a repo-side faceplant there, some "patched-ish" thing already getting…
Endpoint Security Threat Intelligence3 Min Read June 1, 2026 China-Aligned Groups Ramp Up Attacks: Dragon Weave Hits Czech Republic & Taiwan A new cyber espionage campaign codenamed Operation Dragon Weave has been observed targeting officials and citizens in the Czech Republic and…
Artificial Intelligence Vulnerability Research6 Min Read May 29, 2026 ChatGPhish Vulnerability Turns ChatGPT Web Summaries Into a Phishing Surface Cybersecurity researchers have disclosed details of a vulnerability in OpenAI ChatGPT that leverages the artificial intelligence (AI)…
Artificial Intelligence Cyber Espionage4 Min Read May 29, 2026 New Russia-Linked GREYVIBE Targets Ukraine with AI-Powered Cyberattacks A previously undocumented threat actor dubbed GREYVIBE has been attributed to ongoing and persistent attacks targeting Ukraine and…
Software Supply Chain Threat Intelligence4 Min Read May 29, 2026 Malicious Sicoob NuGet Steals Banking Credentials as npm Packages Target Cloud Secrets Cybersecurity researchers have discovered a malicious NuGet package that masquerades as a C# software development kit for Sicoob, one of…
Endpoint Security Threat Intelligence5 Min Read May 29, 2026 Kimsuky Deploys HTTPSpy, Expands Arsenal with HelloDoor and VS Code Tunnels The North Korean state-sponsored threat actor known as Kimsuky (aka Velvet Chollima) has been attributed to a fresh set of cyber attacks…
Vulnerability Disclosure Zero Day2 Min Read May 28, 2026 Microsoft Slams Public Zero-Day Disclosures Amid GitHub Researcher Account Removal Microsoft has come out strongly in favor of Coordinated Vulnerability Disclosure (CVD), urging the research community to share their findings…
Cybersecurity News Hacking News11 Min Read May 28, 2026 ThreatsDay Bulletin: Claude Security Plugin, Azure Priv-Esc, Kali365 MFA Bypass, FIFA Scams +15 More Every time you think the industry has finally stopped doing some reckless, low-effort crap, somebody spins up a fresh box full of sketchy…
Artificial Intelligence Enterprise Security6 Min Read May 28, 2026 New AI Usage Report: Enterprise AI Risk Is Heavily Concentrated Among a Small Group of AI "Power users" State of AI Usage Report 2026 (full report here) by LayerX Security reveals the extent of the enterprise AI visibility gap and why most…
Artificial Intelligence Enterprise Security6 Min Read May 27, 2026 5 Steps to Managing Shadow AI Tools Without Slowing Down Employees When an employee installs an AI writing assistant, connects a coding copilot to their IDE, or starts summarizing meetings with a new browser…
Malware Threat Intelligence3 Min Read May 27, 2026 GlassWorm Malware Takedown Disrupts Developer Supply Chain Attack Infrastructure CrowdStrike, in partnership with Google and the Shadowserver Foundation, has announced the simultaneous disruption of all command-and-control…
Artificial Intelligence Threat Intelligence4 Min Read May 27, 2026 AI Chatbot Recommendations Redirect Users to Cryptojacking Malware Sites Microsoft has warned of an active cryptojacking campaign that makes use of artificial intelligence (AI) chatbot interactions as a mechanism…
Enterprise Security Vulnerability1 Min Read May 26, 2026 Microsoft Patches SharePoint RCE Flaw CVE-2026-45659 Across Server Versions Microsoft has rolled out updates to fix a remote code execution vulnerability impacting SharePoint that could be exploited by bad actors in…
Password Security Social Engineering4 Min Read May 26, 2026 MFA Prompt Bombing: Why Your Second Factor Isn't Saving You Multi-factor authentication (MFA) was supposed to close a critical gap in identity security. It meant that, even if an attacker possessed the…
Threat Intelligence Vulnerability2 Min Read May 26, 2026 KnowledgeDeliver LMS Flaw Exploited to Deploy Godzilla and Cobalt Strike A now-patched high-severity security flaw affecting Digital Knowledge KnowledgeDeliver, a Learning Management System (LMS) popular in Japan,…
Cybersecurity Hacking14 Min Read May 25, 2026 ⚡ Weekly Recap: Linux Flaws, Defender 0-Days, Router Botnets, and Supply Chain Chaos Monday recap. Same mess, new week. A sketchy dev tool got people pwned, old bugs came back from the dead, and security products somehow needed…
DevSecOps Software Supply Chain2 Min Read May 23, 2026 npm Adds 2FA-Gated Publishing and Package Install Controls Against Supply Chain Attacks GitHub has rolled out new controls for npm to improve the security of the software supply chain, giving maintainers the ability to explicitly…
Artificial Intelligence Vulnerability3 Min Read May 23, 2026 Claude Mythos AI Finds 10,000 High-Severity Flaws in Widely Used Software Anthropic on Friday disclosed that Project Glasswing has helped uncover more than 10,000 high- or critical-severity vulnerabilities across…
Malware Supply Chain Attack3 Min Read May 23, 2026 Laravel-Lang PHP Packages Compromised to Deliver Cross-Platform Credential Stealer Cybersecurity researchers have flagged a fresh software supply chain attack campaign that has targeted multiple PHP packages belonging to…
Cloud Security Supply Chain Attack4 Min Read May 22, 2026 Megalodon GitHub Attack Targets 5,561 Repos with Malicious CI/CD Workflows Cybersecurity researchers have disclosed details of a new automated campaign called Megalodon that has pushed 5,718 malicious commits to 5,561…
Driver Security Vulnerability36 Min Read May 22, 2026 Making Vulnerable Drivers Exploitable Without Hardware – The BYOVD Perspective 1 Introduction This article provides a technical analysis of how many Windows kernel mode drivers can be interacted with from user mode…
Cyber Espionage Threat Intelligence3 Min Read May 21, 2026 Showboat Linux Malware Hits Middle East Telecom with SOCKS5 Proxy Backdoor Cybersecurity researchers have disclosed details of a new Linux malware dubbed Showboat that has been put to use in a campaign targeting a…
Cybersecurity News Hacking News18 Min Read May 21, 2026 ThreatsDay Bulletin: Linux Rootkits, Router 0-Day, AI Intrusions, Scam Kits and 25 New Stories This week starts small. A token leaks. A bad package slips in. A login trick works. An old tool shows up again. At first, it feels like the…
Endpoint Security Vulnerability2 Min Read May 21, 2026 Microsoft Warns of Two Actively Exploited Defender Vulnerabilities Microsoft has disclosed that a privilege escalation and a denial-of-service flaw in Defender has come under active exploitation in the wild.…
Developer Tools Supply Chain Attack3 Min Read May 21, 2026 GitHub Internal Repositories Breached via Malicious Nx Console VS Code Extension GitHub on Wednesday officially confirmed that the breach of its internal repositories was the result of a compromise of an employee device…
Artificial Intelligence Security Testing2 Min Read May 20, 2026 Microsoft Open-Sources RAMPART and Clarity to Secure AI Agents During Development Microsoft has unveiled two new open-source tools called RAMPART and Clarity to assist developers in better testing the security of artificial…
Cybercrime Malware3 Min Read May 20, 2026 Microsoft Takes Down Malware-Signing Service Behind Ransomware Attacks Microsoft on Tuesday said it disrupted a malware-signing-as-a-service (MSaaS) operation that weaponized the company's Artifact Signing system…
Cybercrime Malware3 Min Read May 20, 2026 Webworm Deploys EchoCreep and GraphWorm Backdoors Using Discord and MS Graph API Cybersecurity researchers have flagged fresh activity from a China-aligned threat actor known as Webworm in 2025, deploying custom backdoors…
Encryption Vulnerability2 Min Read May 20, 2026 Microsoft Releases Mitigation for YellowKey BitLocker Bypass CVE-2026-45585 Exploit Microsoft on Tuesday released a mitigation for a BitLocker bypass vulnerability named YellowKey following its public disclosure last week. The…
Cloud Security Malware4 Min Read May 20, 2026 GitHub Breached — Employee Device Hack Led to Exfiltration of 3,800+ Internal Repos GitHub on Tuesday said it's investigating unauthorized access to its internal repositories after the notorious threat actor known as TeamPCP…
AI Security Identity Security5 Min Read May 19, 2026 The New Phishing Click: How OAuth Consent Bypasses MFA In February 2026, a phishing-as-a-service (PhaaS) platform called EvilTokens went live. Within five weeks, it had compromised more than 340…
Developer Security Supply Chain Attack4 Min Read May 19, 2026 Compromised Nx Console 18.95.0 Targeted VS Code Developers with Credential Stealer Cybersecurity researchers have flagged a compromised version of the Nx Console extension that was published to the Microsoft Visual Studio…
Malware Software Security2 Min Read May 19, 2026 Popular GitHub Action Tags Redirected to Imposter Commit to Steal CI/CD Credentials In yet another software supply chain attack, threat actors have compromised the popular GitHub Actions workflow, actions-cool/issues-helper,…
Malware Supply Chain Attack4 Min Read May 19, 2026 Mini Shai-Hulud Pushes Malicious AntV npm Packages via Compromised Maintainer Account Cybersecurity researchers have discovered a fresh software supply chain attack campaign that has compromised various npm packages associated…
Cybersecurity Hacking11 Min Read May 18, 2026 ⚡ Weekly Recap: Exchange 0-Day, npm Worm, Fake AI Repo, Cisco Exploit and More Monday opens with a trust problem. A mail server flaw is under active use. A network control system was targeted. Trusted packages were…
Software Security Vulnerability4 Min Read May 18, 2026 Ivanti, Fortinet, SAP, VMware, n8n Patch RCE, SQL Injection, Privilege Escalation Flaws Ivanti, Fortinet, n8n, SAP, and VMware have released security fixes for various vulnerabilities that could be exploited by bad actors to…