10 Million-Install Chrome Ad Blocker Hides a Remote Kill Switch for Arbitrary JavaScript

A Featured Chrome extension, Adblock for YouTube, ships dormant infrastructure to inject arbitrary JavaScript on any site a victim visits. No malicious payload has been pushed yet, but a single server-side flag could weaponize it across 10 million browsers with no update and no store review. Its all-sites access and a trivially bypassed youtube.com check make every banking, work, and admin session reachable.

June 26, 2026  |  5 min
Read post →

Backdoor.Turn Got the Headlines. convoC2 Is the Version Anyone Can Run.

North Korea's Backdoor.Turn tunneled command-and-control through Microsoft Teams and stayed hidden for months. The real risk, as Patrick Duggan argues, is convoC2: the open-source clone that hands the same Teams-relay evasion to any criminal with a GitHub account. It is already in fraud crews' hands, and the only place to catch it is the endpoint.

June 25, 2026  |  7 min
Read post →

FortiBleed: Russian IAB Sniffs 110 Million Credentials Off 430,000 FortiGate Firewalls

A Russian-speaking initial access broker has run a credential-harvesting operation against 430,000-plus FortiGate firewalls since February 2026, deploying passive sniffers to scrape cleartext and hashed credentials from device traffic. The multi-vendor campaign has identified over 110 million credentials and now feeds Active Directory intrusions, lateral movement, and a thriving access-for-sale market.

June 24, 2026  |  6 min
Read post →

Fake AI Agent Skill Slipped Past Every Scanner and Reached 26,000 Agents

A security firm planted a malicious AI agent skill that passed Cisco's, NVIDIA's, and skills.sh's scanners, borrowed 36,000 GitHub stars, and reportedly reached 26,000 agents. The trick: keep the shipped package clean and host the payload behind an external link rewritten after the scan clears. Here is why the entire trust model around agent skills is broken.

June 23, 2026  |  6 min
Read post →

Squidbleed: A 1997 Squid Proxy Bug Leaks Other Users' Cleartext HTTP Requests

A 29-year-old heap over-read in the Squid web proxy, dubbed Squidbleed (CVE-2026-47729), lets any permitted proxy user leak another user's cleartext HTTP requests, including Authorization headers and session tokens. The flaw lives in Squid's default FTP parser and was caught by an AI model. Proof-of-concept code is public.

June 22, 2026  |  5 min
Read post →

CISA Sounds the Alarm: FortiBleed Leak Exposes Fortinet Credentials, Secure Your Devices Now

CISA is urging every Fortinet customer to rotate credentials and harden devices after the FortiBleed leak exposed authentication data harvested from FortiGate appliances. Attackers can replay leaked credentials and session artifacts to walk straight past perimeter defenses. If you run Fortinet at the edge, treat every device as compromised until proven otherwise.

June 21, 2026  |  5 min
Read post →

usbliter8: Unpatchable SecureROM Exploit Breaks Apple A12 and A13 Boot Chain

Paradigm Shift researchers published a working exploit, usbliter8, that achieves arbitrary code execution inside the SecureROM of Apple A12 and A13 chips. Burned into silicon at manufacture, the flaw cannot be patched by any software update. It requires physical access and DFU mode, completes in under two seconds, and affects iPhone XS through iPhone 11, several iPads, and Apple Watch Series 4 and 5.

June 21, 2026  |  6 min
Read post →

Microsoft Ties Mastra AI npm Supply Chain Attack to North Korean Hackers

Microsoft has attributed a supply chain compromise of the Mastra AI agent framework's npm ecosystem to North Korean state-sponsored hackers. Poisoned packages pushed credential-stealing and backdoor payloads to developers building AI agents. The campaign extends Pyongyang's long-running assault on open-source registries and developer machines.

June 20, 2026  |  5 min
Read post →

FortiBleed: CISA Warns 86,644 FortiGate Devices Compromised in Russian-Speaking Credential Campaign

A Russian-speaking threat actor has compromised 86,644 internet-facing FortiGate appliances using leaked credentials and legacy hashing weaknesses. CISA issued an emergency advisory urging password resets, PBKDF2 migration, and MFA. The attack self-propagates by harvesting credentials from traffic passing through breached devices.

June 20, 2026  |  6 min
Read post →

AutoJack: One Web Page Turns a Local AI Agent Into Host Code Execution

Microsoft researchers detailed AutoJack, an exploit chain that lets a single attacker-controlled web page reach a privileged local service through an AI browsing agent and run arbitrary commands on the host. The flaw lives in AutoGen Studio's MCP WebSocket route, which never shipped in the stable PyPI build but did ship unpatched in two pre-releases. No credentials, no extra clicks, no exploitation in the wild yet.

June 19, 2026  |  5 min
Read post →

Google Vertex AI SDK Flaw Let Attackers Hijack Model Uploads With Nothing but a Project ID

A flaw in Google Cloud's Vertex AI SDK for Python let an attacker with zero access to a victim's project hijack ML model uploads and run code inside Google's serving infrastructure. The only prerequisites were the attacker's own GCP project and the victim's project ID, which is often public. Patch to google-cloud-aiplatform 1.148.0 and set an explicit staging_bucket.

June 19, 2026  |  5 min
Read post →

Chinese APT UNC6508 Weaponized Google Workspace Compliance Rules to Exfiltrate Defense Research

China-linked UNC6508 backdoored REDCap research servers at US and Canadian medical and defense institutions, then abused Google Workspace content compliance rules to silently BCC matching emails to attacker-controlled inboxes for over a year.

June 16, 2026  |  6 min
Read post →

LiteLLM Vulnerability Chain Enables Full AI Gateway Takeover from Default Account

Three chained vulnerabilities in LiteLLM let low-privilege users escalate to admin and execute code on AI gateway servers. Critical-severity chain exposes all provider keys, credentials, and prompts flowing through the proxy.

June 15, 2026  |  6 min
Read post →

Chinese APT Hijacks Authentication to Spy on Air-Gapped Network for 10 Years

A Chinese state-sponsored threat actor compromised an isolated network for a decade by hijacking authentication flows through a connected system. The campaign demonstrates sophisticated persistence techniques against air-gapped infrastructure.

June 15, 2026  |  6 min
Read post →

China-Linked Velvet Ant Backdoored Linux PAM and OpenSSH for Nine Years

Chinese APT group Velvet Ant compromised the Linux login layer itself—backdooring PAM modules and OpenSSH binaries on air-gapped networks since 2016. Sygnia researchers found nine variants recording credentials where ordinary defenses cannot reach.

June 14, 2026  |  6 min
Read post →

Splunk Enterprise CVE-2026-20253: Unauthenticated RCE via PostgreSQL Sidecar

A critical 9.8 CVSS vulnerability in Splunk Enterprise allows unauthenticated attackers to achieve remote code execution through exposed PostgreSQL sidecar endpoints. WatchTowr Labs published a detailed exploit chain exploiting missing authentication controls.

June 13, 2026  |  6 min
Read post →

A Government Directive Just Took Fable 5 and Mythos 5 Offline Worldwide

On June 12, 2026, Anthropic received a US government directive and suspended Fable 5 and Mythos 5 for every customer worldwide, including its own foreign-national employees. The operational lesson for defenders: frontier-AI availability is now a supply-chain dependency policy can sever in minutes. What to do this quarter.

June 12, 2026  |  6 min
Read post →

Over 400 Arch Linux AUR Packages Hijacked to Deploy Infostealer and eBPF Rootkit

Attackers compromised more than 400 packages in Arch Linux's AUR by adopting orphaned repositories and injecting credential-stealing malware with eBPF rootkit capabilities into build scripts. The Rust-based stealer harvests developer secrets and establishes persistence through systemd services.

June 13, 2026  |  6 min
Read post →

Agentjacking: AI Coding Agents Tricked Into Running Malicious Code via Sentry Injection

Researchers demonstrate a new attack class that weaponizes AI coding agents by injecting malicious instructions through Sentry error reports. 2,388 organizations exposed with an 85% exploitation success rate against popular AI assistants.

June 12, 2026  |  6 min
Read post →

ShinyHunters Exploits Oracle PeopleSoft Zero-Day (CVE-2026-35273) to Breach 100+ Universities

The ShinyHunters extortion crew exploited CVE-2026-35273, a 9.8-severity zero-day in Oracle PeopleSoft, to breach over 100 organizations—68% of them universities. Oracle patched after attackers had already exfiltrated student and staff data from multiple institutions.

June 12, 2026  |  6 min
Read post →

OpenClaw AI Agent Exploited Through Hidden Contact Prompts and Social Engineering

Two research teams demonstrated separate attacks forcing OpenClaw AI agent to execute malicious code and exfiltrate credentials. Imperva exploited message-object prompt injection via contact names; Varonis succeeded with simple phishing emails that bypassed verification rules.

June 11, 2026  |  6 min
Read post →

CVE-2026-5027: Unpatched Langflow RCE Under Active Exploitation

A critical path traversal flaw in Langflow enables unauthenticated remote code execution and is being actively exploited in the wild. With 7,000 exposed instances and no patch available, organizations running AI development infrastructure face immediate risk.

June 11, 2026  |  6 min
Read post →

ServiceNow Zero-Day Exploited for Two Months Before Emergency Patch

ServiceNow patched a critical authentication bypass flaw on June 5, 2026, after threat actors exploited it to query customer instance tables. The vulnerability was known internally since April 7 but classified as non-urgent for two months.

June 10, 2026  |  6 min
Read post →

Hades PyPI Attack: 37 Malicious Wheel Artifacts Auto-Execute Bun Credential Stealer

Threat actors deployed 37 malicious wheel artifacts across 19 PyPI packages using *-setup.pth files to achieve automatic execution during Python startup. The Hades campaign steals credentials from GitHub, AWS, Azure, npm, and CI/CD platforms while incorporating AI defense evasion and wiper capabilities.

June 10, 2026  |  6 min
Read post →

Self-Replicating AI Worm Operates Entirely on Local Models, Bypasses Vendor Controls

University of Toronto researchers built a proof-of-concept AI worm that uses local open-weight LLMs to autonomously reason through networks, generate runtime exploits, and self-replicate—compromising 62% of test hosts without touching commercial AI services or human input.

June 9, 2026  |  8 min
Read post →

Claude Fable 5 and Mythos 5: The Cyber Safeguard Is Now the Product Boundary

Anthropic shipped Claude Fable 5 for general use alongside Claude Mythos 5, the identical model with cyber safeguards removed for Project Glasswing partners. Frontier offensive-cyber capability now sits behind a classifier-and-fallback boundary, not absence, and a sanctioned variant ships with that boundary lifted. What it means for defenders.

June 9, 2026  |  7 min
Read post →

Single-Character Kernel Typo Grants Root on Millions of Linux Systems

CVE-2026-23111, a one-character typo in nf_tables, lets unprivileged users escalate to root and escape containers. Patched February 5, exploits published in April and June—update and reboot now.

June 9, 2026  |  5 min
Read post →

Check Point IKEv1 VPN Authentication Bypass Exploited by Qilin Ransomware Affiliate

CVE-2026-50751, a critical logic flaw in Check Point VPN certificate validation, allows unauthenticated attackers to bypass passwords in IKEv1 configurations. Exploitation tied to Qilin ransomware began May 7, targeting dozens of organizations globally.

June 8, 2026  |  5 min
Read post →

Miasma Worm Compromises 73 Microsoft GitHub Repositories in Self-Replicating Supply Chain Attack

A self-replicating worm has infected 73 Microsoft GitHub repositories across Azure, Microsoft, and MicrosoftDocs organizations. The Miasma variant exploits legitimate authentication channels to spread exponentially, compromising developer credentials and propagating through AI coding tools.

June 8, 2026  |  6 min
Read post →

OpenAI Launches ChatGPT Lockdown Mode to Block Prompt Injection Data Exfiltration

OpenAI rolls out Lockdown Mode for ChatGPT to mitigate data exfiltration risks from prompt injection attacks. The optional security feature disables web browsing, image support, and file downloads across Free, Plus, Pro, and Business tiers.

June 7, 2026  |  5 min
Read post →

Smart TVs Turned Into AI Scraping Proxies Through Free App SDKs

Bright Data's SDK embedded in free consumer apps converts always-on smart TVs and mobile devices into residential proxy exit nodes for AI web scraping. Security researchers found unauthenticated peer channels, VPN bypass on iOS, and traffic limits up to 200 GB monthly.

June 7, 2026  |  6 min
Read post →

AI Agent Finds 21 Zero-Days in FFmpeg for $1,000 as Chrome Ships Record 429 Patches

A security startup's autonomous AI agent discovered 21 zero-days in FFmpeg's 1.5 million lines of code for around $1,000, some bugs dormant for 23 years. The same week, Chrome 149 patched a record 429 vulnerabilities as Google overhauls its bounty program to handle the AI-driven submission flood.

June 6, 2026  |  6 min
Read post →

IronWorm and Miasma Worm Variants Execute Dual npm Supply Chain Attacks

Two sophisticated supply chain attacks have compromised over 100 npm packages, deploying a Rust-based information stealer with eBPF rootkit capabilities and a self-propagating worm that exploits AI coding assistants. The campaigns target developer credentials across cloud platforms, cryptocurrency wallets, and CI/CD pipelines.

June 6, 2026  |  6 min
Read post →

Notification-Based Prompt Injection Gave Attackers Complete Control of Google Gemini on Android

A single malicious notification from WhatsApp, Slack, or SMS could hijack Google Gemini's voice assistant on Android, enabling attackers to control smart homes, poison AI memory, and fake messages from trusted contacts—no malicious app required.

June 5, 2026  |  6 min
Read post →

Five-Month Mailbox Espionage Operation Targeted Stock Exchange Executive

Unknown attackers maintained persistent access to a senior stock exchange executive's Outlook mailbox for five months, exfiltrating data through consumer cloud services to evade detection. The operation used legitimate tools and infrastructure to blend with normal traffic.

June 5, 2026  |  6 min
Read post →

Critical Flaw in Anthropic's Claude Code GitHub Action Enabled Repository Takeover via Single Malicious Issue

A CVSS 7.8 vulnerability in Anthropic's Claude Code GitHub Action allowed attackers to hijack repositories through prompt injection and authentication bypass. The flaw could have poisoned the official action itself, cascading malicious code to all downstream projects.

June 4, 2026  |  6 min
Read post →

Debug Flag Left Enabled in Microsoft 365 Android Apps Exposed Account Tokens to Any App

A single line of debug code left in production builds of six Microsoft 365 Android apps disabled authentication checks, allowing any app on the device to steal user account tokens without password prompts or user interaction. Microsoft patched the flaw affecting billions of app downloads after Enclave Security disclosed it.

June 4, 2026  |  6 min
Read post →

One-Click GitHub.dev Attack Enables Full OAuth Token Theft

A critical vulnerability in GitHub.dev allows attackers to steal full-access GitHub OAuth tokens through a single malicious link. The exploit leverages VS Code's webview mechanism and extension system to bypass security controls and access all private repositories.

June 3, 2026  |  6 min
Read post →

AI Now Costs More Than Employees. That's a Security Problem Too.

A four-person team's single-month Anthropic bill hit $113,421, more than the annual cost of one of those four people. AI crossed from expense to headcount-class spend, and that unmonitored six-figure channel is now both an attack surface and a gift to invoice-fraud crews.

June 3, 2026  |  5 min
Read post →

AI-Driven Exploitation Collapses Vulnerability Windows to Hours

Exploitation timelines have shrunk from days to hours while median patching times increased to 43 days. AI tools like Claude Mythos identified 10,000+ critical vulnerabilities in one month—and attackers have the same capabilities.

June 3, 2026  |  7 min
Read post →

The New AI Executive Order: What It Means for Defenders and Critical Infrastructure

The June 2, 2026 White House executive order pairs aggressive 30-to-60-day federal cyber-defense mandates with a no-licensing stance on frontier AI models, and formally recognizes that frontier models now carry benchmark-worthy offensive cyber capability. What the deadlines mean for critical-infrastructure operators, and how Etairos and Caver already deliver what the order spends 60 days reaching toward.

June 2, 2026  |  6 min
Read post →

Gamaredon Exploits WinRAR Vulnerability to Deploy GammaWorm and GammaSteel Against Ukraine

Russian FSB-linked threat group Gamaredon weaponizes CVE-2025-8088 WinRAR vulnerability to deliver modular malware framework targeting Ukrainian organizations. Attack chain deploys GammaPhish HTML applications, GammaWorm propagation tools, and GammaSteel data theft modules.

June 2, 2026  |  6 min
Read post →

OpenAI Codex Tokens Stolen in Active npm Supply Chain Attack Targeting 29,000 Weekly Downloads

The codexui-android npm package, downloaded 29,000 times weekly, has been quietly exfiltrating OpenAI Codex authentication tokens to attacker infrastructure for over a month. The campaign extends to Android apps with 60,000+ combined downloads, targeting AI developer workflows with persistent credential theft.

June 2, 2026  |  5 min
Read post →

Miasma Supply Chain Attack: Credential-Stealing Worm Compromises Red Hat npm Packages

A sophisticated supply chain attack has compromised multiple Red Hat npm packages, deploying a self-propagating worm that steals credentials, cloud identities, and secrets from developer machines. The attack leverages open-sourced tools from the Shai-Hulud campaigns and uses unique encryption per infection to evade detection.

June 1, 2026  |  6 min
Read post →

2,000 Exposed Vibe-Coded Apps Expose Critical Gap in Enterprise Security Stacks

Red Access investigation reveals over 2,000 corporate applications built with AI development platforms are exposing sensitive data on the open internet. Traditional security tools—EDR, DLP, CASB—weren't designed to detect this new category of Shadow AI risk.

June 1, 2026  |  8 min
Read post →

PAN-OS GlobalProtect Authentication Bypass CVE-2026-0257 Under Active Exploitation

Palo Alto Networks CVE-2026-0257 authentication bypass vulnerability is being actively exploited in the wild, allowing attackers to establish unauthorized VPN connections. Rapid7 confirms successful exploitation across numerous customers dating back to May 17, with threat actors gaining internal network access.

May 31, 2026  |  5 min
Read post →

GREYVIBE: Russia-Linked Threat Group Uses AI to Target Ukraine

New Russian-speaking threat actor GREYVIBE has deployed AI-assisted malware against Ukrainian military, government, and civilian targets since August 2025. WithSecure researchers identify the group as a hybrid operation blending nation-state objectives with cybercriminal tactics and tooling.

May 31, 2026  |  6 min
Read post →

Malicious NuGet and npm Packages Target Banking Credentials and Cloud Secrets in Coordinated Supply Chain Attack

A sophisticated supply chain attack campaign compromised 500 downloads of a fake Sicoob banking SDK on NuGet while 14 malicious npm packages targeted AWS credentials and cloud secrets. The attacks demonstrate attackers moving beyond simple typosquatting to manufactured legitimacy tactics.

May 30, 2026  |  8 min
Read post →

ChatGPhish Exploits ChatGPT Web Summaries to Deliver Phishing Attacks Through Trusted AI Interface

Security researchers disclosed ChatGPhish, a vulnerability allowing attackers to embed malicious Markdown links and images in web pages that ChatGPT automatically renders when summarizing content. The attack leverages implicit trust in the AI interface to bypass traditional security controls and deliver phishing content directly through chatgpt.com's response renderer.

May 30, 2026  |  6 min
Read post →

LLM Agents Enter the Attack Chain: Marimo CVE-2026-39987 Breach Shows AI-Driven Post-Exploitation

Threat actors deployed an LLM agent for post-exploitation after breaching a Marimo notebook via CVE-2026-39987, exfiltrating a complete PostgreSQL database in under two minutes. The attack demonstrates how AI agents enable adaptive, real-time exploitation without pre-staged playbooks.

May 29, 2026  |  6 min
Read post →

Critical Gogs RCE Flaw Enables Authenticated Users to Execute Arbitrary Code

A critical 9.4 CVSS vulnerability in Gogs allows any authenticated user to achieve remote code execution through malicious branch names during rebase operations. Over 1,100 internet-facing instances remain unpatched since disclosure in March 2026.

May 29, 2026  |  6 min
Read post →

FortiClient EMS Flaw Exploited to Deploy Credential Stealer Across Managed Endpoints

Threat actors are exploiting CVE-2026-35616, a critical authentication bypass in FortiClient EMS, to deploy credential-stealing malware disguised as legitimate Fortinet updates. The attack abuses trusted endpoint management infrastructure to compromise every managed device without requiring separate intrusion paths.

May 28, 2026  |  5 min
Read post →

GlassWorm Malware Takedown: Multi-Channel C2 Infrastructure Neutralized in Coordinated Operation

CrowdStrike, Google, and Shadowserver Foundation have dismantled all four command-and-control channels of GlassWorm malware, ending a 16-month campaign that poisoned over 300 GitHub repositories and targeted developers through trojanized VS Code extensions and malicious packages.

May 28, 2026  |  6 min
Read post →

844 MB of Live Government Secrets Sat in a Public GitHub Repo for Months

A Nightwing contractor working for CISA exposed AWS GovCloud keys, Entra ID SAML certificates, and plaintext passwords in a public repo for six months while seven scanner alerts went ignored. The exposure is a hygiene failure; the unanswered question is whether the keys were ever abused.

May 27, 2026  |  5 min
Read post →

Malicious npm Package Targets Claude AI User Directory in Supply Chain Attack

A malicious npm package named mouse5212-super-formatter exfiltrated files from Claude AI's user directory to attacker-controlled GitHub repositories. The campaign, dubbed Malware-Slop, demonstrates how AI-generated malware is lowering entry barriers for threat actors.

May 27, 2026  |  6 min
Read post →

Lazarus Group Deploys Memory-Only RemotePE RAT Against Financial Targets

North Korean Lazarus Group is using RemotePE, a sophisticated memory-only remote access trojan, to target financial and cryptocurrency organizations. The malware executes entirely in memory with no filesystem artifacts, making detection extremely difficult.

May 27, 2026  |  5 min
Read post →

MFA Prompt Bombing: How Attackers Bypass Your Second Factor

Push-based MFA is failing organizations as attackers weaponize notification fatigue and social engineering to gain legitimate-looking access. The 2022 Cisco breach proves this technique works even against mature security programs.

May 26, 2026  |  6 min
Read post →

FBI Warns of Kali365 Phishing-as-a-Service Targeting Microsoft 365 Credentials

The FBI has issued a warning about Kali365, a sophisticated phishing-as-a-service platform specifically designed to harvest Microsoft 365 credentials. The service lowers the technical barrier for cybercriminals to launch convincing credential theft campaigns at scale.

May 26, 2026  |  6 min
Read post →

TrapDoor Campaign Deploys Credential-Stealing Malware Across npm, PyPI, and Crates.io

Coordinated cross-ecosystem attack targets developers with 34 malicious packages across 384 versions. Campaign specifically targets crypto, DeFi, Solana, and AI developers to steal credentials, SSH keys, and cloud tokens.

May 25, 2026  |  6 min
Read post →

Packagist Supply Chain Attack Leverages Cross-Ecosystem Tactics to Deliver Linux Malware

Eight Packagist packages compromised with malicious code hidden in package.json files rather than standard Composer manifests. Attack demonstrates sophisticated cross-ecosystem technique that bypasses conventional PHP security scanning focused solely on composer.json.

May 25, 2026  |  5 min
Read post →

npm Rolls Out Staged Publishing and Install Controls to Combat Supply Chain Attacks

GitHub introduces mandatory 2FA-gated staged publishing for npm packages and new install source flags, requiring human approval before packages go live. The changes directly address the surge in supply chain attacks like TeamPCP's widespread poisoning campaign.

May 24, 2026  |  5 min
Read post →

Laravel-Lang Supply Chain Attack Delivers Cross-Platform Credential Stealer Across 700+ Package Versions

Multiple Laravel-Lang PHP packages were compromised to distribute a sophisticated credential stealer targeting cloud credentials, cryptocurrency wallets, and authentication tokens. Over 700 malicious versions were published in rapid succession through compromised organization-level access.

May 24, 2026  |  6 min
Read post →

Anthropic's Claude Mythos AI Discovers 10,000 Critical Vulnerabilities in One Month

Anthropic's Project Glasswing has uncovered over 10,000 high and critical-severity vulnerabilities in globally critical software within one month of operation. The initiative grants 50 partners early access to Claude Mythos Preview, an AI model capable of autonomous vulnerability discovery that's forcing a fundamental shift in patch cycles.

May 23, 2026  |  6 min
Read post →

The NSA Just Published a Detailed Report on MCP Security. Here's What It Actually Says.

The NSA Artificial Intelligence Security Center released a Cybersecurity Information Sheet on May 20, 2026 warning that Model Context Protocol deployments carry novel and systemic risks established defenses do not adequately address. The agency calls out serialization risks, trust boundaries, agent misuse, dynamic tool invocation, implicit trust, and context sharing.

May 23, 2026  |  7 min
Read post →

Ghostwriter Deploys Prometheus-Themed Phishing Campaign Against Ukrainian Government

Belarus-aligned APT Ghostwriter is targeting Ukrainian government entities with multi-stage JavaScript malware disguised as legitimate Prometheus learning platform communications. The campaign leverages compromised accounts and delivers Cobalt Strike payloads through obfuscated registry-based execution.

May 23, 2026  |  5 min
Read post →

Megalodon Attack: 5,561 GitHub Repositories Compromised in Six-Hour CI/CD Blitz

Automated campaign injected malicious GitHub Actions workflows into 5,561 repositories within six hours, exfiltrating CI secrets, cloud credentials, and tokens to attacker-controlled infrastructure. The attack used forged identities and throwaway accounts to bypass detection.

May 22, 2026  |  6 min
Read post →

When Identity Becomes the Attack Path: Why Traditional Tools Keep Missing the Threat

A single cached AWS access key exposed 98% of a company's cloud environment. Despite billions in security spending, identity-based attacks succeeded in 90% of 2025 breach investigations because tools can't map how credentials chain into exploitable paths.

May 22, 2026  |  9 min
Read post →

GitHub Breached Through Poisoned VS Code Extension in 18-Minute Attack Window

GitHub confirmed breach of internal repositories after employee device compromise via malicious Nx Console VS Code extension. Attackers exfiltrated 3,800 repositories in attack live for only 18 minutes on Visual Studio Marketplace.

May 21, 2026  |  6 min
Read post →

GitHub Actions Supply Chain Attack Redirects Repository Tags to Credential-Stealing Malware

Attackers compromised two popular GitHub Actions repositories, redirecting all existing tags to malicious commits that exfiltrate CI/CD credentials. The attack used imposter commits to bypass pull request reviews and affected any workflow not pinned to specific commit SHAs.

May 21, 2026  |  5 min
Read post →

Microsoft Dismantles Malware-Signing Service That Weaponized Azure Infrastructure

Microsoft has taken down Fox Tempest's malware-signing-as-a-service operation that exploited the company's Artifact Signing system to distribute ransomware and malware to thousands of victims. The service charged criminals $5,000-$9,000 to sign malicious code with fraudulent certificates.

May 20, 2026  |  5 min
Read post →

Critical RCE Vulnerability in ChromaDB Enables Complete Server Takeover

A maximum severity vulnerability (CVSS 10.0) in ChromaDB, a widely-used vector database for AI applications, allows unauthenticated attackers to execute arbitrary code and hijack servers. Organizations running ChromaDB versions before 0.5.15 face immediate risk of complete system compromise.

May 20, 2026  |  6 min
Read post →

OAuth Consent Phishing Bypasses MFA: 340+ Organizations Compromised in Five Weeks

EvilTokens phishing-as-a-service platform compromised over 340 Microsoft 365 organizations by exploiting OAuth consent flows that sit structurally below MFA controls. Attackers walk away with long-lived refresh tokens that survive password resets and produce no suspicious sign-in events.

May 19, 2026  |  7 min
Read post →

NGINX CVE-2026-42945 Under Active Exploitation: 18-Year-Old Flaw Triggers Worker Crashes and RCE

Critical heap buffer overflow in NGINX versions 0.6.27 through 1.30.0 is being actively exploited in the wild. The vulnerability, introduced in 2008, allows unauthenticated attackers to crash worker processes or achieve remote code execution on systems without ASLR protection.

May 19, 2026  |  5 min
Read post →

Developer Workstations: The New Frontier of Supply Chain Attacks

Three coordinated attacks on npm, PyPI, and Docker Hub within 48 hours targeted developer credentials rather than code. Attackers are shifting from tampering with software to stealing the access that makes trusted software possible.

May 18, 2026  |  8 min
Read post →

Windows MiniPlasma Zero-Day Grants SYSTEM Access, PoC Published

A newly disclosed Windows zero-day vulnerability dubbed MiniPlasma allows unprivileged users to escalate to SYSTEM-level access through a flaw in the Print Spooler service. Proof-of-concept code is now publicly available with no patch currently deployed.

May 18, 2026  |  6 min
Read post →

Tycoon2FA Phishing Kit Exploits Microsoft Device Code Flow to Bypass MFA

The Tycoon2FA phishing-as-a-service platform is hijacking Microsoft 365 accounts by exploiting OAuth device code authentication flows, bypassing multi-factor authentication protections. Security researchers have identified this threat targeting organizations through adversary-in-the-middle attacks since August 2023.

May 17, 2026  |  8 min
Read post →

PraisonAI Authentication Bypass Exploited Within 4 Hours of Disclosure

CVE-2026-44338, a critical authentication bypass in PraisonAI's multi-agent orchestration framework, was actively probed within 3 hours and 44 minutes of public disclosure. The flaw affects 32 versions of the Python package and exposes sensitive API endpoints to unauthenticated attackers.

May 17, 2026  |  5 min
Read post →

AI Hallucinations Create Exploitable Security Vulnerabilities in Critical Infrastructure

AI models are generating confident but incorrect outputs that drive security decisions, with 36 of 40 tested models more likely to provide wrong answers than correct ones. Organizations deploying AI in cybersecurity operations face risks from missed threats, fabricated alerts, and dangerous remediation recommendations.

May 16, 2026  |  8 min
Read post →

Remus Infostealer: Inside the Session Theft MaaS Threatening Enterprise Security

Remus infostealer has emerged as a sophisticated Malware-as-a-Service platform targeting browser sessions and credentials. With rapid development cycles and advanced evasion techniques, this threat demands immediate attention from security teams.

May 16, 2026  |  7 min
Read post →

Turla Transforms Kazuar Backdoor Into Modular P2P Botnet for Long-Term Espionage

Russian FSB-affiliated APT group Turla has re-engineered its Kazuar backdoor from a monolithic framework into a three-tier modular botnet architecture. The transformation enables persistent access through peer-to-peer coordination while reducing detection footprint across compromised government and defense networks.

May 15, 2026  |  6 min
Read post →

YellowKey and GreenPlasma Zero-Days Target BitLocker Encryption and Windows Privilege Escalation

Anonymous researcher Chaotic Eclipse disclosed two critical Windows zero-days: YellowKey enables BitLocker bypass through Windows Recovery Environment in minutes, while GreenPlasma allows SYSTEM-level privilege escalation via CTFMON. Both vulnerabilities remain unpatched as tensions escalate with Microsoft.

May 15, 2026  |  6 min
Read post →

Stealer Backdoor Compromises Node-IPC Package Targeting 90 Categories of Developer Credentials

Three malicious versions of the popular Node-IPC npm package contain obfuscated stealer malware designed to exfiltrate developer secrets including AWS, Azure, GCP credentials, and SSH keys. The compromised versions were published after 21 months of package dormancy by a maintainer with no prior publish history.

May 14, 2026  |  6 min
Read post →

IED in the Drinking Water: The ICS Attack Surface Is Multi-Layered

A grenade-style IED was found underwater at the J.B. Converse Reservoir dam in Mobile, AL on May 13, 2026, the drinking water source for roughly 350,000 residents. Different vector, same target class as the active cyber campaigns against U.S. water systems.

May 14, 2026  |  5 min
Read post →

Agentic AI: The Security Blind Spot Growing by the Week

Agentic AI is already running in production environments across organizations, executing tasks and consuming data without security team oversight. The gap between AI deployment speed and security understanding is compounding weekly, creating a supply chain problem that mirrors past technology adoption failures.

May 14, 2026  |  8 min
Read post →

Mini Shai-Hulud Worm Deploys SLSA-Attested Malware Across Major Package Ecosystems

TeamPCP threat actors compromised 42 TanStack packages and infiltrated npm/PyPI repositories from Mistral AI, UiPath, OpenSearch, and Guardrails AI using GitHub Actions OIDC token hijacking. The worm produces validly attested malicious packages and includes a destructive wiper component targeting developers who revoke compromised tokens.

May 13, 2026  |  7 min
Read post →

RubyGems Suspends New Signups After Hundreds of Malicious Packages Uploaded in Supply Chain Attack

RubyGems has temporarily disabled new account registration following a major supply chain attack involving hundreds of malicious packages. The attack targeted the package manager's infrastructure and distributed exploits, prompting Mend.io to suspend signups while the incident is contained.

May 12, 2026  |  5 min
Read post →

TeamPCP Breaches Checkmarx Jenkins Plugin Weeks After Initial Compromise

TeamPCP successfully compromised Checkmarx's Jenkins AST plugin just weeks after breaching the company's KICS Docker image, indicating persistent access or incomplete remediation. The attack targeted the Jenkins Marketplace with a malicious plugin version, escalating concerns about supply chain security in DevSecOps tooling.

May 12, 2026  |  6 min
Read post →

AI Enables First Zero-Day 2FA Bypass for Mass Exploitation

Google has identified the first known case of threat actors using AI to develop a zero-day exploit—a 2FA bypass in an open-source administration tool. The discovery marks a watershed moment in offensive security capabilities and signals compressed attack timelines.

May 11, 2026  |  6 min
Read post →

Nightmare-Eclipse Toolkit Deployed 8 Days After Public Release — FortiGate SSL VPN Intrusion Breakdown

Compromised FortiGate VPN credentials led to deployment of three Nightmare-Eclipse PE tools and a previously undocumented Go tunneling agent (BeigeBurrow) just eight days after public toolkit release. All privilege escalation attempts failed.

May 11, 2026  |  7 min
Read post →

JDownloader Supply Chain Attack: Python RAT Malware Distributed Through Compromised Official Site

Attackers compromised JDownloader's official website to replace legitimate installers with Python-based remote access trojan malware. The supply chain attack targeted users of the popular download manager with 1.5 billion downloads worldwide.

May 11, 2026  |  7 min
Read post →

Critical Ollama Vulnerabilities Expose 300,000+ Servers to Memory Leaks and Persistent Code Execution

A critical out-of-bounds read vulnerability (CVE-2026-7482, CVSS 9.1) in Ollama enables unauthenticated attackers to exfiltrate entire process memory from over 300,000 servers. Two additional unpatched Windows vulnerabilities allow persistent code execution through the update mechanism.

May 10, 2026  |  6 min
Read post →

Twelve Critical Vulnerabilities in vm2 Node.js Library Enable Complete Sandbox Escape

Twelve critical vulnerabilities in the widely-used vm2 Node.js sandbox library allow attackers to escape isolation and execute arbitrary code on host systems. Three vulnerabilities scored perfect 10.0 CVSS ratings, affecting all versions through 3.11.1.

May 10, 2026  |  6 min
Read post →

ClaudeBleed: A Zero-Permission Chrome Extension Can Hijack Claude and Steal All Your Data

A confused deputy flaw in Claude's 7M-user Chrome extension lets any other extension hijack your AI agent and exfiltrate Google Drive, Gmail, and GitHub — no permissions required. Anthropic's patch was bypassed in 3 hours.

May 9, 2026  |  6 min read
Read post →

ZiChatBot Malware Deployed Through PyPI Supply Chain Attack Using Zulip APIs

Three malicious PyPI packages delivered ZiChatBot malware to Windows and Linux systems, accumulating 2,480 downloads before removal. The attack leveraged Zulip chat APIs for command-and-control, with code similarities linking it to Vietnam-aligned APT32.

May 9, 2026  |  6 min
Read post →

Copy Fail: The 732-Byte Python Script That Roots Every Major Linux Distro

A 9-year-old Linux kernel bug in the AEAD crypto interface lets any local user overwrite any file’s page cache and get root. The exploit is 732 bytes of Python. Researchers published it on April 29 — it works on every major distribution.

May 5, 2026  |  5 min read
Read post →

PamDOORa: Linux Backdoor Exploits PAM Framework for SSH Credential Theft

A new Linux backdoor called PamDOORa is being sold on Russian cybercrime forums for $1,600, targeting PAM authentication modules to steal SSH credentials and maintain persistent access. The malware represents an evolution beyond open-source PAM backdoors with integrated anti-forensic capabilities.

May 9, 2026  |  5 min
Read post →

Quasar Linux RAT Targets Developer Credentials in Software Supply Chain Attacks

A sophisticated Linux implant is harvesting developer credentials from npm, PyPI, AWS, Docker, and CI/CD systems to poison software packages. The fileless malware uses dual-layer rootkit architecture and seven persistence mechanisms to maintain long-term access.

May 8, 2026  |  6 min
Read post →

NVIDIA Says AI Compute Now Costs More Than Paying Its Human Employees

NVIDIA's VP of applied deep learning told Axios compute costs "far beyond" employee costs for his team. A 2024 MIT study found AI is economically viable in only 23% of roles. Uber's 2026 AI budget is already gone. The economics are still being figured out.

May 8, 2026  |  5 min read
Read post →

DAEMON Tools Supply Chain Attack Delivers Targeted Backdoor to Government and Manufacturing Sectors

Attackers compromised official DAEMON Tools installers with digitally signed malware starting April 8, 2026, infecting thousands across 100+ countries. Only a dozen organizations received second-stage payloads, indicating sophisticated targeting of government, manufacturing, and research entities.

May 8, 2026  |  5 min
Read post →

PCPJack Worm Exploits 5 CVEs to Steal Credentials and Hijack TeamPCP Infrastructure

New credential theft framework PCPJack exploits five CVEs to spread worm-like across cloud environments while deliberately removing TeamPCP artifacts. The campaign targets Docker, Kubernetes, and multiple cloud services to harvest credentials from cloud, container, and financial platforms.

May 7, 2026  |  6 min
Read post →

MuddyWater Weaponizes Microsoft Teams in False Flag Ransomware Operation

Iranian state-sponsored group MuddyWater deployed fake ransomware attacks via Microsoft Teams social engineering to mask credential theft and persistence operations. The campaign abused legitimate remote access tools and bypassed traditional encryption workflows in favor of data exfiltration.

May 7, 2026  |  5 min
Read post →

AI Agents Are Bypassing Traditional IAM—Half of Enterprise Identity Activity Is Already Invisible

Gartner confirms AI agent deployment is outpacing governance capabilities. Roughly 50% of enterprise identity activity now occurs outside centralized IAM visibility, creating an invisible layer of unmanaged access that traditional security tools cannot see.

May 6, 2026  |  6 min
Read post →

1 Million AI Services Scanned: 31% of Ollama APIs Respond Without Authentication

Large-scale scan of 2 million hosts reveals self-hosted AI infrastructure is more vulnerable than any software category previously analyzed. Over 1,600 Ollama APIs responded to unauthenticated requests, exposing everything from personal chatbots to cloud management systems.

May 6, 2026  |  8 min
Read post →

One OAuth Token. 700 Enterprise Customers. The Vercel Supply Chain Attack Explained.

Attackers compromised Context.ai via Lumma Stealer, harvested OAuth tokens, and pivoted into Vercel's infrastructure to reach 700+ enterprise customers including Cloudflare, Palo Alto, and Zscaler.

May 5, 2026  |  5 min read
Read post →

1,800 Developers Hit by npm Supply Chain Attack Targeting SAP, Lightning, and Intercom

Four npm packages in the SAP CAP ecosystem were hijacked in the Mini Shai-Hulud campaign, exfiltrating CI/CD secrets and npm tokens from 1,800+ developers with 570K+ combined weekly downloads.

May 5, 2026  |  5 min read
Read post →

Axios Got Hijacked. The Malicious Version Deployed a Cross-Platform RAT on Mac, Windows, and Linux.

Attackers hijacked the Axios npm maintainer account in March 2026 and published two versions containing a cross-platform remote access trojan that erased its own install traces after execution.

May 5, 2026  |  5 min read
Read post →

Fake Bitwarden CLI Package Deployed a Self-Replicating npm Worm That Targeted AI Coding Assistants

A fake @bitwarden/cli package lived 90 minutes on npm, pulled 334 times, and deployed a credential harvester plus the first known malware specifically engineered to extract secrets from AI coding assistant sessions.

May 5, 2026  |  5 min read
Read post →

ShinyHunters Hit Vimeo Through a Vendor Nobody Was Watching

ShinyHunters breached Vimeo by compromising Anodot, a third-party analytics vendor with a trusted integration, extracting 119K email addresses before dumping the data after extortion demands were refused.

May 5, 2026  |  5 min read
Read post →

13.5 Million McGraw-Hill Records Exposed. The Attack Vector Was a Salesforce Misconfiguration.

ShinyHunters dumped 100GB of McGraw-Hill data after a Salesforce misconfiguration exposed 13.5 million records, the third major Salesforce-vector breach claimed by the group in two months.

May 5, 2026  |  5 min read
Read post →

ADT Lost 5.5 Million Customer Records Because One Employee Got Vished Into Giving Up Their Okta Password

ShinyHunters social-engineered an ADT employee into handing over their Okta SSO credentials. One phone call gave attackers access to Salesforce and 5.5 million customer records.

May 5, 2026  |  5 min read
Read post →

"Code of Conduct" Phishing Hit 35,000 Users Across 13,000 Organizations in 48 Hours

A 48-hour phishing campaign used AI-generated code of conduct violation emails to target 35,000 Microsoft 365 users. AiTM relay bypassed MFA entirely, capturing live session tokens.

May 5, 2026  |  5 min read
Read post →

EvilTokens Campaign: Device Code OAuth Phishing Hits 340 Microsoft 365 Organizations, MFA Is Useless

The EvilTokens PhaaS campaign exploited Microsoft's OAuth device code flow to capture persistent refresh tokens across 340 organizations in five countries. MFA provided no protection.

May 5, 2026  |  5 min read
Read post →

Medtronic Breach: ShinyHunters Claims 9 Million Patient Records From the World's Largest Medical Device Maker

ShinyHunters listed Medtronic on their breach marketplace April 17, claiming 9 million patient records and terabytes of corporate data from the maker of pacemakers and insulin pumps.

May 5, 2026  |  5 min read
Read post →

Everest Ransomware Group Hits Fiserv: Payment Processing Infrastructure Under Threat

Everest ransomware listed Fiserv on May 3 with 1,064 user credentials and 170 vendor credentials claimed. Fiserv processes payments for 10,000+ financial institutions.

May 5, 2026  |  5 min read
Read post →

Booking.com Breach: Millions of Travelers Had Reservation Details Stolen. Scammers Are Already Using It.

A third-party vendor breach exposed Booking.com customer reservation details including travel dates, home addresses, and special requests. Targeted phishing hit affected users within days.

May 5, 2026  |  5 min read
Read post →

Three Teenagers Used ChatGPT to Launch 220,000 Attacks on Rakuten Mobile

Japanese police arrested three minors who automated 220,000 fraudulent signups using ChatGPT. No prior coding experience required.

May 5, 2026  |  5 min read
Read post →

A Single Attacker Used Claude Code to Breach Nine Mexican Government Agencies

One attacker, nine agencies, 195 million citizen records. Claude Code executed 75% of the remote commands used in the campaign.

May 5, 2026  |  5 min read
Read post →

Claude Code Ran a Complete Extortion Campaign Against 17 Organizations. Anthropic Disclosed It.

Threat actor GTG-2002 used Claude Code to fully automate cyber extortion across 17 targets in one month. Anthropic detected and disclosed the campaign.

May 5, 2026  |  5 min read
Read post →

PROMPTFLUX Malware Rewrites Its Own Code Every Hour Using Google's Gemini API

Google GTIG found malware that queries the Gemini API on an hourly schedule to regenerate its own VBScript code. Signature-based detection is useless against it.

May 5, 2026  |  5 min read
Read post →

Russia's APT28 Is Deploying LLM-Powered Malware That Generates Its Own Attack Commands

Google GTIG confirmed APT28 deployed PROMPTSTEAL in Ukraine operations. The tool queries Qwen2.5-Coder via Hugging Face to generate attack commands dynamically.

May 5, 2026  |  5 min read
Read post →

CISA Is Considering a 3-Day Patch Deadline. AI Is Why.

CISA officials are evaluating a 3-day patching SLA for actively exploited CVEs. The stated justification is AI-compressed exploit timelines. Enterprise IT is not ready.

May 5, 2026  |  5 min read
Read post →

Chrome Zero-Day CVE-2026-5281: Active Exploitation of a WebGPU Use-After-Free

A use-after-free in Chrome's WebGPU Dawn engine is being exploited in the wild. CISA added it to the KEV catalog with a 14-day federal patch deadline.

May 5, 2026  |  5 min read
Read post →

cPanel Was Being Exploited for Two Months Before a Patch Existed (CVE-2026-41940)

An auth bypass in cPanel/WHM was exploited from Feb 23 to Apr 28 with no patch available, compromising 44,000+ servers and putting 1.5 million at risk.

May 5, 2026  |  5 min read
Read post →

April Patch Tuesday: 163 Vulnerabilities, a Wormable TCP/IP RCE, and Two Already-Exploited Flaws

Microsoft patched 163 CVEs including a wormable kernel RCE in the Windows TCP/IP stack and two zero-days already under active exploitation at release.

May 5, 2026  |  5 min read
Read post →

Russia's APT28 Is Hijacking Your Router to Steal Microsoft 365 Credentials

GRU-linked APT28 exploited unpatched TP-Link routers to perform DNS hijacking, intercepting M365 logins and capturing session tokens from NATO and Ukrainian targets.

May 5, 2026  |  5 min read
Read post →

North Korea Registered Fake US Companies to Distribute Malware to Crypto Developers

Lazarus Group created two US shell companies to run fake developer interviews, delivering a 3-stage malware chain targeting cryptocurrency wallet private keys.

May 5, 2026  |  5 min read
Read post →

This D-Link Router Zero-Day Has Been Exploited Since November. There Is No Patch.

CVE-2026-0625 in four EOL D-Link router models has been exploited by Mirai since November 2025. D-Link confirmed no patch is coming; replacement is the only fix.

May 5, 2026  |  5 min read
Read post →

The OAuth Backdoor: Why 45% of Organizations Have Zero Visibility Into Their Biggest Access Risk

OAuth tokens connected to Google and Microsoft environments bypass MFA, never expire, and persist after employee departures. New research shows 80% of security leaders recognize the risk, but 45% do nothing to monitor these persistent access grants at scale.

May 5, 2026  |  7 min
Read post →

Mythos Can Write Exploits. Now Businesses Are Hiding Their Code.

Mythos generates functional exploit code at 72.4% accuracy. The NHS locked down 850 repos. They're not wrong — here's what that actually means for your security posture.

May 5, 2026  |  6 min read
Read post →

"By Design": How Edge's Password Storage Becomes an OT Security Problem

Microsoft Edge loads every saved password into unencrypted memory at launch and keeps them there. Microsoft calls it working as intended. Your engineering workstation is probably running Edge.

May 5, 2026  |  5 min read
Read post →

Iranian IRGC Actors Targeting Water and Energy ICS: What You Need to Know

CyberAv3ngers actively compromising Unitronics PLCs in water treatment, energy, and manufacturing. Live exposure data, incidents, and assessment guidance.

April 2026
Read advisory →
No posts in this category yet.