Critical Alerts
Ultimate Member Plugin Vulnerability Allows Password Reset Link Disclosure
Patch Ultimate Member to version 2.12.0 immediately to close password reset link disclosure vulnerability.
Phishing Attack Exploits Open‑Source Project’s Cloud Signup Flow
Implement captcha, disposable‑email blocker, rate limits, workspace‑name filter, and revoke any compromised Resend keys.
CVE‑2026‑5426: Hard‑Coded ASP.NET Keys in KnowledgeDeliver Enable Godzilla Shell
Patch Digital Knowledge KnowledgeDeliver to fix hard‑coded ASP.NET machine keys and prevent Godzilla shell exploitation.
Critical Vulnerability in Funnel Builder Plugin Allows JS Injection into WooCommerce Checkout
Patch Funnel Builder immediately to stop malicious JavaScript injection into WooCommerce checkout pages.
SonicWall Announces Exploitation of Two Zero‑Day Vulnerabilities in Secure Mobile Access Appliances
Apply SonicWall patches for CVE‑2026‑15409 and CVE‑2026‑15410 to eliminate SSRF and arbitrary command execution.
GitHub Dependabot Adds Three‑Day Cooldown for Non‑Security Updates
Verify Dependabot uses the default 3‑day cooldown; no action needed unless you want to override.
Five Eyes Warns of AI Models Autonomously Hacking Systems
Enable AI‑driven vulnerability scanning and update incident response plans to counter autonomous attack patterns.
Squidbleed Vulnerability Exposes HTTP Requests in Squid 2.9 Proxy
Patch Squid to the latest stable release (≥3.5) immediately and audit proxy configurations.
xAI's Grok Build CLI Uploads Entire Git Repositories to External Cloud Bucket
Patch: configure Grok Build CLI to limit uploads to necessary files, revoke bucket access, and audit repository content.
Forg365 Phishing-as-a-Service Targets Microsoft 365 Accounts with AI-Driven Lure Creation
Block: disable device code flow, enable MFA, monitor for suspicious login attempts, and block Forg365 channels.
Threat Actor Uses PowerShell Script to Enumerate Active Directory
Block: prevent execution of the PowerShell enumeration script, audit AD logs, and enforce least privilege.
Python Web Server Left Exposed by Phishing Operation, Enabling Lateral Movement
Disable: stop the Python HTTP server, remove directory listing, delete .bash_history, and audit for other exposed services.
jscrambler npm Package Compromised – Infostealer in 8.14.0
Patch: uninstall jscrambler 8.14.0, install a verified version, and audit package-lock for malicious binaries.
SAP Releases Security Updates for NetWeaver ABAP, Fixing CVE‑2026‑44747
Patch: apply SAP NetWeaver ABAP update from July 2026 to fix CVE-2026-44747 before exploitation.
CISA Adds iCagenda and Balbooa Joomla Extensions to KEV Catalog for Zero‑Day Exploitation
Patch iCagenda and Balbooa Joomla extensions immediately to mitigate CVE‑2026‑48939 and related zero‑day vulnerabilities.
Zimbra Urges Customers to Patch Classic Web Client for Critical XSS Vulnerability
Patch Zimbra Classic Web Client immediately to mitigate XSS that could lead to arbitrary code execution.
Binarly Discovers Six New U‑Boot Flaws, Four of Which Can Crash Devices
Update U‑Boot firmware on all affected devices to mitigate crash and code execution risks.
ShinyHunters Exploit OAuth Trust to Penetrate Salesforce Without Platform Flaws
Audit OAuth connections in Salesforce and revoke unnecessary permissions.
Cybercrime Crew Leaves Server Open, Exposes 1.4 Million Target Sites
Review your own server exposure policies and ensure no public‑facing services are left unprotected.
Voice‑Based Phishing Targets Microsoft 365 Passkey Enrollment
Disable automatic passkey enrollment prompts and enforce MFA for Microsoft 365 accounts.
ModHeader Extension Removed After Hidden Browsing-History Collector Discovered
Uninstall ModHeader from all browsers and replace with a trusted alternative.
OpenClaw AI Assistant Vulnerabilities: Credential Theft, Privilege Escalation, and Code Execution
Apply the latest OpenClaw security patch to eliminate credential theft, privilege escalation, and code execution risks.
New GodDamn Ransomware Family Uses PoisonX Driver to Evade Security Software
Deploy updated anti‑malware signatures and monitor for PoisonX driver activity.
Microsoft Unveils Record‑Breaking Patch Tuesday, Fixes 622 CVEs and RoguePlanet Vulnerability
Apply the July 2026 Windows patches promptly, but first back up your systems.
Wordfence Intelligence Weekly Vulnerability Report: 250 New Vulnerabilities Disclosed
Patch all unpatched WordPress plugins and themes, and enable the new Wordfence firewall rules for Ninja Forms <=3.3.29, WAF‑RULE‑923, and WAF‑RULE‑924 immediately.
Post‑Quantum Migration: Cloudflare Deploys ML‑KEM Encryption and ML‑DSA Signatures
Patch TLS to use ML‑KEM encryption and ML‑DSA signatures for post‑quantum security and monitor for upcoming signature standards.
Albanian .AL TLD DNSSEC Rollover Failure Forces Cloudflare to Deploy NTA and EDE Codes
Patch DNSSEC validation to respect EDE codes and monitor for NTA usage to detect unvalidated responses.
Chrome’s WebMCP Security Guidance Highlights Attack Vectors for AI Agents
Patch your WebMCP tools by adding untrustedContentHint, readOnlyHint, and exposedTo annotations to mitigate malicious manifest and contaminated output attacks.
Claude AI Memory System Exfiltration Vulnerability Exposes User Data
Patch the web_fetch tool to reject arbitrary path encoding that can carry data.
Mandiant reveals how Cisco SD‑WAN zero‑day attacks gained root access
Patch Cisco SD‑WAN devices to the latest firmware that fixes CVE‑2026‑20245 and disable tenant‑upload feature until patch is applied.
Gravity SMTP Plugin CVE-2026-4020: Medium‑Severity Info Disclosure Flaw Exploited on 100,000 WordPress Sites
Patch Gravity SMTP to the latest version to fix CVE-2026-4020.
Wordfence Weekly Vulnerability Report: 146 Vulnerabilities in 127 Plugins and 1 Theme
Patch the 7 unpatched vulnerabilities, including the 7 critical ones, as soon as possible and run the Wordfence CLI scanner to verify all sites are secure.
LastPass Warns Users of Data Breach via Partner Klue
Patch exposed API tokens and revoke partner access immediately.
Missing Content in AI News Articles Leaves Readers Uninformed
Disable Anthropic's Fable 5 and Mythos 5 models to comply with U.S. export‑control directive.
Apple Patches Beats Studio Buds Vulnerability CVE‑2025‑20701
Update Beats Studio Buds firmware to fix CVE‑2025‑20701.
Cordyceps: New CI/CD Workflow Weakness Threatens Open-Source Supply Chains
Patch CI/CD workflows to mitigate Cordyceps.
Microsoft AutoJack Exploit Turns AI Browsing Agent into RCE Vehicle
Patch AI browsing agents to prevent AutoJack exploitation.
Squidbleed: Heap Over-Read Vulnerability Exposes Cleartext HTTP Requests
Patch Squid to a version that fixes the Squidbleed heap over‑read vulnerability.
GitHub Updates actions/checkout to Block pull_request_target Attacks
Update actions/checkout to the latest version to block pull_request_target workflow attacks.
ShapedPlugin Supply‑Chain Attack Injects Backdoor into Pro Plugins
Notify users of ShapedPlugin and roll back to a clean version before the compromised release.
Cisco Unified Communications Manager Vulnerability CVE-2026-20230 Allows Remote Exploitation
Apply the Cisco Unified Communications Manager patch for CVE-2026-20230 immediately to close the remote exploitation vector.
CISA Issues Patch Alert for Ubiquiti and Lantronix Vulnerabilities
Apply the Lantronix EDS5000 firmware patch before 26 June 2026 to mitigate the code injection flaw.
Agentic Traps: Hidden Tokens and Dynamic Cloaking Threaten AI Agents
Audit web content for hidden tokens and dynamic cloaking that could trap AI agents and mitigate potential security risks.
New Gogs zero-day flaw lets hackers get remote code execution
Patch Gogs to 0.14.2 or 0.15.0+dev to eliminate RCE.
OpenAI ChatGPT Vulnerability Allows Prompt Injection via Trusted Markdown Links
Patch ChatGPT rendering to sanitize Markdown links and images to prevent prompt injection.
Marimo Notebook Exploited via CVE‑2026‑39987, LLM Agent Drives Post‑Compromise Actions
Patch the Marimo environment to mitigate CVE‑2026‑39987 before attackers can use LLM agents.
Critical Unauthenticated Administrator Account Creation Vulnerability in WP Maps Pro (CVE-2026-8732)
Patch WP Maps Pro to 6.1.1 immediately to eliminate the unauthenticated admin account creation flaw (CVE-2026-8732).
Microsoft Copilot Cowork Vulnerability Allows Email Exfiltration
Patch Copilot Cowork to prevent unsanctioned email sending and image rendering.
CVE-2026-27771: Gitea Vulnerability Allows Unauthenticated Pull of Private Container Images
Patch: Upgrade Gitea to version 1.26.2 or later to fix CVE‑2026‑27771 and prevent unauthenticated pull of private container images.
CVE-2026-48172: LiteSpeed User‑End cPanel Plugin Privilege Escalation Under Active Exploitation
Patch: Update the LiteSpeed User‑End cPanel Plugin to the latest patched version to eliminate CVE‑2026‑48172 before exploitation.
CERT‑IN Mandates 12‑Hour Patch Window for Critical Vulnerabilities
Patch critical internet‑exposed systems within 12 hours of detection to comply with CERT‑IN guidelines.
Microsoft Releases Patch for CVE‑2026‑45659 Remote Code Execution in SharePoint
Patch SharePoint to the latest version to mitigate CVE‑2026‑45659.
Yoast SEO Premium 27.6.1 Security Patch Addresses .htaccess Redirect Vulnerability
Patch Yoast SEO Premium to 27.6.1 immediately if using .htaccess redirects and edit_posts capability.
Advanced Custom Fields 6.8.2 Security Release
Patch ACF to 6.8.2 immediately to fix frontend form security.
NGINX Vulnerability CVE-2026-42945: Heap Buffer Overflow in Rewrite Module Exploited in Wild
Patch NGINX to the latest release (≥1.30.1) immediately to fix CVE-2026-42945, a heap buffer overflow in ngx_http_rewrite_module that is actively exploited.
May 2026 Core Update Rolling Out, No Companion Blog Post
Wait one week after the core update completes, then review Search Console data against baseline.
Anthropic’s Mythos AI Helps Discover Kernel Memory Corruption Exploit on Apple M5
Patch Apple M5 devices immediately to mitigate the kernel memory corruption vulnerability discovered using Anthropic’s Mythos.
Google accidentally exposed details of unfixed Chromium flaw
Patch Chromium to the latest stable version and disable background Service Workers.
Drupal Core Vulnerability CVE-2026-9082 Allows Remote Code Execution and Privilege Escalation
Apply the Drupal Core security patch for CVE-2026-9082 without delay.
Forensic Breakdown: CyberPanel SnappyMail Log Exploited to Persist Webshell on WordPress
Patch the wp-config.php file to remove the malicious eval base64_decode payload, then audit server logs for root-level backdoor and apply CyberPanel security updates.
Linux Kernel copy.fail Vulnerability Enables Local Privilege Escalation
Patch: Update to the latest kernel (≥6.5.0) immediately to fix copy.fail LPE.
Multiple Linux kernel exploits released after patching: PinTheft, DirtyDecrypt, and others
Update your kernel to the latest patched version, or apply the dirtyfrag mitigation script to block DirtyDecrypt exploitation.
Popular node-ipc npm package compromised to steal credentials
Patch node‑ipc to a safe version, rotate exposed secrets, and audit lockfiles.
Microsoft Exchange Server Vulnerability CVE-2026-42897: Spoofing Bug from XSS Exploited in Wild
Patch Exchange Server to fix CVE‑2026‑42897 immediately.
Burst Statistics Authentication Bypass Vulnerability (CVE-2026-8181) – Critical Fix Released
Patch Burst Statistics to 3.4.2 immediately to eliminate the authentication bypass.
Google Ads Offline Conversion Imports Ending – Migrate to Data Manager API
Migrate offline conversion imports to the Data Manager API before June 15 to avoid data loss.
Funnel Builder WordPress plugin bug exploited to steal credit cards
Patch: Update Funnel Builder to 3.15.0.3 immediately and remove any injected scripts from External Scripts settings.
Phishing‑as‑a‑Service Platforms Hijack Hundreds of Microsoft 365 Accounts
Patch: Disable OAuth device‑code flow on Microsoft 365 accounts and enforce Continuous Access Evaluation to mitigate Tycoon2FA device‑code phishing.
Avada Builder WordPress plugin suffers critical flaws enabling credential theft and data breaches
Upgrade Avada Builder to 3.15.3 immediately to eliminate the file‑read and SQL injection vulnerabilities.
Linux Kernel Exposes Multiple Local Privilege Escalation Flaws, Prompting Urgent Patching
Apply the latest kernel patch to fix Fragnesia LPE (CVE‑2026‑46300) before local attackers can gain root.
Cisco Vulnerabilities Prompt CISA Urgent Patch for Federal Agencies
Remediate Cisco SD‑WAN Controller authentication bypass (CVE‑2026‑20182) by May 17 2026.
YellowKey Zero‑Day Bypasses Windows 11 BitLocker
Patch Microsoft Defender immediately to mitigate YellowKey and GreenPlasma zero‑days.
Critical NGINX Vulnerabilities Disclosed, Including 18‑Year‑Old Heap Buffer Overflow
Patch NGINX to the latest version immediately to fix the CVE‑2026‑42945 heap buffer overflow.
RubyGems Pauses Sign‑Ups Amid Major Malicious Attack
Disable new RubyGems account creation for your projects until the pause lifts and monitor security advisories.
Microsoft, Apple, Google, Mozilla, Oracle Release Major Security Patches—118 CVEs Fixed on Patch Tuesday
Patch all Windows Server 2012+ to fix CVE‑2026‑41089, CVE‑2026‑41096, CVE‑2026‑41103; update Chrome to the latest build to resolve 127 CVEs; back up data before applying any vendor patches.
Palo Alto Networks Discloses Critical PAN‑OS CVE‑2026‑0300 Exploitation Attempts
Patch PAN‑OS immediately to mitigate CVE‑2026‑0300.
cPanel and WHM Hit by CVE-2026-41940 Authentication Bypass, Threat Actor Mr_Rot13 Deploys Filemanager Backdoor
Patch cPanel to the latest release that addresses CVE‑2026‑41940 immediately.
TanStack Router npm Packages Compromised in Supply‑Chain Attack
Audit all TanStack router dependencies, update to the patched version, and remove any compromised packages from your build.
Canonical Suffers 20‑Hour DDoS Attack Using Cloudflare‑Busting Service
Configure Cloudflare to enforce ‘Under Attack Mode’ on all critical endpoints, block IP ranges associated with Beamed, and monitor certificate transparency logs for unexpected apex certificate issuance.
Google Thwarts AI‑Powered Attack, Uncovers Zero‑Day 2FA Bypass
Patch Google services to the latest security patch that mitigates the AI‑generated zero‑day exploit.
Critical Vulnerability in Ollama Could Leak Entire Process Memory (CVE-2026-7482)
Upgrade Ollama immediately to the patched version that resolves CVE‑2026‑7482.
cPanel Releases Emergency Patch After Authentication Bypass Ransomware Attack
Patch cPanel to the latest emergency security release to mitigate the authentication bypass vulnerability.
cPanel Releases Security Update for Three Vulnerabilities Including CVE-2026-29201
Patch cPanel to the latest security release to fix the feature::LOADFEATUREFILE input validation flaw (CVE-2026-29201).
Meta Releases Patch for React2Shell RCE Vulnerability (CVE‑2025‑55182)
Patch React to the latest version (≥18.2.0) immediately to eliminate the Flight protocol RCE.
JDownloader site hacked, installers replaced with malware
Patch the JDownloader website by fixing the unpatched ACL bug and restore legitimate download links.
Mozilla Unveils 271 AI‑Detected Security Fixes for Firefox 150
Patch the 271 bugs identified by Claude Mythos Preview in Firefox 150 and the 149.0.2, 150.0.1, and 150.0.2 releases immediately.
Dirty Frag Linux Kernel Vulnerability Forces Urgent Patch and Manual Mitigation
Patch the kernel or blacklist esp4, esp6, rxrpc modules to mitigate Dirty Frag before a vendor patch is released.
CVE-2024-3094: xz‑utils Backdoor Threatens OpenSSH via SystemD and IFUNC
Patch OpenSSH to the latest version that removes the SystemD dependency before the next maintenance window.
Open-OSS/privacy-filter Model Discovered as Malware – Security Alert
Delete the Open‑OSS/privacy‑filter model from your environment, report the malicious code to Hugging Face and Microsoft, and avoid using it.
Fake Claude AI Website Distributes Beagle Windows Malware
Patch: Delete any NOVupdate.exe, NOVupdate.exe.dat, and avk.dll from Startup, block license.claude‑pro.com, and run a full AV scan to remove the Beagle backdoor.
PyPI Packages Discovered Delivering New ZiChatBot Malware
Patch your Python environments by uninstalling the three malicious packages and monitor for ZiChatBot activity.
vm2 Node.js Library Suffers Dozen Critical Security Vulnerabilities
Patch vm2 to the latest release (v3.0.9) immediately
Hackers abuse Google ads for GoDaddy ManageWP login phishing
Block the malicious Google Ads result for the 'managewp' query and verify that your ManageWP login redirects to the official domain, preventing credential theft.
Slider Revolution 7.0.0-7.0.10 Vulnerability (CVE-2026-6692) – Authenticated Arbitrary File Upload and RCE
Patch Slider Revolution to 7.0.11 immediately to mitigate CVE-2026-6692 and prevent authenticated RCE.
New Cisco DoS flaw requires manual reboot to revive devices
Upgrade CNC to 7.2 or later and NSO to 6.5 or later to patch CVE‑2026‑20188 and eliminate the DoS risk.
Palo Alto Networks Warns of Firewall RCE Zero‑Day Exploited in Attacks
Check your firewall configuration and restrict or disable the User‑ID Authentication Portal until a patch is released.
CloudZ RAT and Undocumented Pheno Plugin Used in Credential Theft Intrusion
Patch or remove the Pheno plugin immediately and monitor for CloudZ RAT activity.
Disc Soft Limited Issues Malware‑Free DAEMON Tools Version After Supply‑Chain Breach
Remove the trojanized DAEMON Tools installers and run a full malware scan to eliminate the embedded backdoor.
Critical Arbitrary File Upload Vulnerability in Breeze Cache Plugin (CVE-2026-3844)
Patch Breeze Cache to 2.4.5 immediately to eliminate the arbitrary file upload flaw.
AI Agent Deletes Production Database: A Wake‑Up Call for API Security
Patch: restrict any public API endpoints that allow destructive actions, enforce RBAC, add audit logging, and run security scans.
Instagram Encrypted Messaging Ends on Friday, May 8
Disable end‑to‑end encryption for Instagram DMs by May 8, 2026; update any integrations that rely on encrypted messages.
CVE‑2026‑31431 “Copy Fail” Lets Unprivileged Users Escalate to Root in Rootless Containers
Patch kernel to 6.19.12 or later to mitigate CVE-2026-31431.
Weaver E-cology 10.0 RCE Vulnerability (CVE-2026-22679) Actively Exploited
Patch Weaver E-cology to version 20260312 or later immediately to eliminate the unauthenticated RCE vulnerability (CVE-2026-22679).
Critical Security Incident Misclassification Due to Scikit‑Learn 1.5 Update
Re‑train the incident classifier with balanced data and pin scikit‑learn 1.4 to avoid the KMeans n_init change.
Chrome silently installs 4 GB Gemini Nano AI model without user consent
Disable the OnDeviceModelBackgroundDownload flag in Chrome to stop silent Gemini Nano downloads.
WannaCry Ransomware: EternalBlue Exploit and the Importance of Patching
Patch all Windows machines with MS17‑010, disable SMBv1, enable firewall, and monitor for the kill‑switch domain to block new infections.
Automated Exfiltration Bot: RCE via Persistent Jupyter Kernel and Prompt Injection
Replace persistent Jupyter kernels with one‑shot Kamikaze kernels using Docker + gVisor to prevent RCE.
Weaver E-cology 10.0 Suffers Critical Remote Code Execution Bug
Patch Weaver E‑Cology 10.0 to build 20260312 immediately to eliminate the exposed debug endpoint and stop RCE.
Gravity SMTP Security Breach CVE‑2026‑4020 Exposes API Keys
Patch Gravity SMTP to version 2.1.5 or later immediately to fix CVE‑2026‑4020 and rotate any exposed API keys.
Nix and Lix Buffer Overflow Vulnerabilities Allow Local Code Execution as Root
Patch Nix and Lix to fix buffer overflows in daemons and prevent local code execution as root.
Comprehensive CVE Analysis of Package Managers Reveals Path Traversal, Injection, and Credential Leakage Vulnerabilities
Patch package managers to enforce path sanitisation, use '--' separator, and verify signatures.
Prompt Injection Attacks Against OopsSec Store’s AI Assistant
Patch the AI assistant to remove regex blocklist and add output filtering to prevent secret leakage.
Critical cPanel Vulnerability Exploited by Hackers, Prompting Urgent Patch
Patch cPanel immediately to stop exploitation.
CISA Adds ConnectWise ScreenConnect and Microsoft Windows Vulnerabilities to KEV Catalog
Patch: update ConnectWise ScreenConnect to the latest version to fix CVE‑2024‑1708.
Atos Threat Research Center Identifies Campaign Targeting High-Privilege Accounts
Patch: enforce MFA for all high‑privilege accounts to mitigate impersonation attacks.
Google Ads API v20 Sunset – Upgrade Required
Upgrade to a newer Google Ads API version before June 10 2026 to avoid service disruption.
Google Search Console Logging Error Resolved After 50‑Week Gap
Check Search Console performance reports for missing impressions between May 13 2025 and April 27 2026.
Mozilla Uses Anthropic’s Claude Mythos to Patch 271 Firefox Vulnerabilities
Patch to Firefox 150, examine the 271 vulnerability fixes, and update your security tooling to detect similar AI‑generated vulnerabilities.
GitHub Vulnerability CVE-2026-3854 Enables Remote Code Execution via git push
Patch GitHub to the latest version or apply the security advisory immediately.
Wordfence Reports 87 New WordPress Vulnerabilities in April 2026
Patch all WordPress core, plugins, and themes listed in the Sucuri roundup to mitigate CVEs.
Injective Labs SDK Compromised: Malicious npm Package Steals Crypto Wallet Keys
Remove the compromised @injectivelabs/sdk‑[email protected] package and audit your npm dependencies for malicious code.
XQUIC XRING Vulnerability Lets Remote Clients Crash Alibaba's QUIC Library with Legal Traffic
Avoid using XQUIC or apply a workaround to prevent remote crash via XRING until a patch is released.
RabbitMQ Access Control Flaws Could Leak OAuth Secrets and Bypass Tenant Boundaries
Patch RabbitMQ to the latest version that fixes the OAuth client secret leakage and tenant boundary bypass.
Tailscale Serves Two Critical Vulnerabilities Fixed in 1.98.9
Patch Tailscale to 1.98.9 or newer to fix CPU core denial of service and SSH root access.
LabubaRAT: Rust‑Based RAT Masquerading as NVIDIA Software
Run endpoint detection to identify LabubaRAT binaries, quarantine them, and enforce strict code signing and integrity checks.
Free VPN Apps on Google Play Failing Basic Privacy Tests
Audit VPN integrations to ensure traffic is routed through the VPN tunnel and replace any apps that leak traffic.
Friendly Fire: AI Coding Agents May Execute Attacker Code on Host Machine
Patch or disable autonomous mode in Claude Code and OpenAI Codex, and restrict code execution permissions for AI coding agents.
Coinspect Exposes Ill Bloom Wallet Recovery Phrase Flaw
Update wallet software to use cryptographically secure random generators for recovery phrases and re‑generate phrases for affected users.
Browser Extension Vulnerability Lets Rogue Scripts Trigger Claude for Chrome Tasks
Disable or remove any rogue browser extensions that can run scripts on claude.ai and update the Claude for Chrome extension to the latest patched version.
Datadog Warns of GitHub Enumeration Campaigns Using API
Rotate all GitHub tokens, enforce least‑privilege scopes, enable audit logs, and monitor for automated scraping activity.
OAuth Client ID Spoofing Used to Evade Telemetry in Microsoft Entra ID
Enforce strict client ID validation in Microsoft Entra ID to block OAuth client ID spoofing attacks.
Progress Software Advises ShareFile Customers to Shut Down Storage Zone Controllers Amid Credible Threat
Shut down ShareFile Storage Zone Controller Windows servers immediately to mitigate the credible external threat.
CISA Postmortem Reveals Six‑Month Leak of AWS GovCloud Credentials
Implement continuous secret scanning and improve reporting channels to reduce exposure time.
KrebsOnSecurity Exposes IRIS C2, a Startup Selling Zero‑Day Exploits to Governments
Notify your security team of the IRIS C2 threat and review zero‑day exposure risk.
Shop Order‑Tracking App Abuse Fuels Callback Phishing Attacks
Notify users to ignore any receipt they did not place and verify charges directly with their bank; do not call the phone number listed.
Rust-based macOS Implant Gaslight Tricks AI Analysis Tools with Prompt Injection
Patch your AI analysis tools to detect prompt injection payloads in Rust-based macOS implants.
Malicious Edge extension abuses Native Messaging as bridge to malware
Disable suspicious Edge extensions, block native messaging hosts, and monitor for malicious ZIP files.
AryStinger Malware Turns Home Routers into Reconnaissance Network
Block AryStinger traffic from infected routers.
Salesforce Disables Klue Battlecards Integration After Security Incident
Disable the Klue Battlecards integration until Salesforce resolves the security incident.
Gentlemen RaaS Releases EDR-Killing Tools to Disable Security Defenses
Patch or disable EDR killers from Gentlemen RaaS to prevent system defense impairment.
Malicious NPM Packages Deliver Windows RAT, Researchers Warn
Patch or remove the malicious npm packages aes-decode-runner-pro, postcss-minify-selector, and postcss-minify-selector-parser to prevent RAT delivery.
New Stealthy Backdoor 'Mistic' Deployed in Financially Motivated Attacks
Patch any exposed systems that might have been compromised by the Mistic backdoor.
Cisco Catalyst SD‑WAN Zero‑Day Exploited Before Public Disclosure
Patch Cisco Catalyst SD‑WAN firmware to the latest version that fixes CVE‑2026‑20245.
Adblock for YouTube Chrome Extension Vulnerable to Arbitrary JavaScript Execution
Disable or uninstall the Adblock for YouTube extension and replace it with a vetted alternative to eliminate arbitrary JavaScript execution.
TrapDoor Supply Chain Attack Distributes Credential-Stealing Malware Across Ecosystems
Audit all packages for TrapDoor malware and remove infected ones.
Malicious npm Package Mouse5212-Super-Formatter Steals Claude AI Data
Remove mouse5212-super-formatter and audit dependencies for malicious code.
Ghost CMS CVE-2026-26980 Allows SQL Injection and Malicious JS Injection
Patch Ghost CMS to fix CVE-2026-26980 immediately.
Fortinet FortiClient EMS flaw used to push credential‑stealing malware
Patch FortiClient EMS immediately to stop credential-stealing attacks.
Unpatched Gogs Vulnerability Lets Authenticated Users Execute Remote Code
Patch Gogs to the latest version to eliminate the RCE vulnerability.
Microsoft Warns of AI-Driven Cryptojacking Campaign
Block AI chatbot interactions that trigger cryptojacking downloads.
CISA Adds CVE-2026-9082 to KEV Catalog for Drupal Core
Patch Drupal Core immediately to the latest version that includes CVE-2026-9082 to stop active exploitation.
California AG sues 23andMe over 2023 breach exposing health data
Patch Salesforce and other systems to prevent credential stuffing, enforce MFA, review code for errors, and monitor for suspicious activity.
Packagist Supply‑Chain Attack Targets Eight Composer Packages with Malicious Linux Binary
Patch: Scan Composer packages for malicious package.json entries that download binaries from GitHub Releases, and replace or remove affected packages.
Banking Trojan Campaigns Targeting Latin America and Europe with Grandoreiro and BTMOB
Patch: Update antivirus signatures to block Grandoreiro and BTMOB on Windows and Android endpoints, and monitor for banking trojan activity in Spain, Portugal, Mexico, and Brazil.
MFA Security Gap: Attackers Exploit User Cooperation
Patch MFA workflows to enforce device‑based second factors and educate users to avoid phishing.
CrowdStrike, Google, and Shadowserver Disrupt GlassWorm Command‑and‑Control Channels
Block GlassWorm C2 domains and monitor for related malware on your network.
Malicious NuGet Package Sicoob.Sdk Exfiltrates Client IDs and PFX Certificates
Remove or replace the compromised Sicoob.Sdk package and revoke exposed PFX certificates.
Supply Chain Attack Targets Multiple Laravel-Lang PHP Packages
Patch all laravel‑lang packages to the latest secure versions and audit dependencies for similar supply‑chain vulnerabilities.
Dutch Authorities Arrest Hosting Company Co‑Owners Linked to Russia‑Backed Cyberattacks
Patch your hosting infrastructure to remove any connections to sanctioned entities and verify compliance with EU sanctions.
Google Announces May 2026 Core Update Rollout
Check your site's content relevance signals and update any low‑quality pages before the update fully rolls out.
Exploit released for new PinTheft Arch Linux root escalation flaw
Patch the kernel to the latest version or apply the rds module mitigation immediately.
PoC Exploit Released for DirtyDecrypt Linux Kernel Vulnerability
Patch the kernel to the latest version that fixes DirtyDecrypt immediately to stop the PoC exploit.
Microsoft Issues Patches for Two Exploited Defender Vulnerabilities
Patch Microsoft Defender to the latest update immediately.
Max severity Cisco Secure Workload flaw gives Site Admin privileges
Upgrade Secure Workload to release 3.10.8.3 or 4.0.3.17 and confirm API authentication is enforced.
GitHub Actions Workflow Compromised: actions-cool/issues-helper Harvests Credentials
Delete the compromised actions-cool/issues-helper workflow and replace it with a trusted version or custom action.
Drupal Issues Urgent Core Security Update for May 20, Advises Immediate Action
Reserve time and apply the Drupal core security update on 20 May 2026 before 5‑9 UTC.
Microsoft Disrupts Malware‑Signing‑as‑a‑Service Operation Using Artifact Signing
Verify the integrity of signed binaries and monitor for unauthorized signing certificates.
Compromised Nx Console Extension v18.95.0 Flagged by Researchers
Patch or uninstall the rwl.angular-console v18.95.0 extension immediately to stop the malicious code from running.
Google Launches May 2026 Core Update, Rolling Out Over Two Weeks
Monitor rankings and audit content quality during the May 2026 core update rollout, ensuring your pages remain helpful and people‑first.
CISA Contractor’s GitHub Repo Exposes AWS GovCloud Credentials
Revoke all exposed AWS GovCloud credentials and enable GitHub secret scanning for all repositories.
OpenAI Reports Mini Shai-Hulud Impact on Employee Devices via TanStack
Patch your internal systems to detect and isolate any compromised TanStack packages and ensure employee devices are scanned for malware.
Supply Chain Attackers Target Secrets in npm, PyPI, and Docker Hub
Patch your CI/CD pipelines to enforce secret scanning and rotate exposed credentials immediately.
Ivanti Xtraction CVE-2026-8043 Vulnerability Fixed in Latest Security Patch
Patch Ivanti Xtraction to fix CVE-2026-8043 and other vendor fixes.
Exim MTA Security Update Addresses CVE-2026-45185 Memory Corruption Vulnerability
Apply the Exim security patch to fix CVE-2026-45185.
OpenAI Employee Devices Compromised in TanStack Supply‑Chain Attack
Patch OpenAI macOS apps to the latest version before June 12 to eliminate the supply‑chain vulnerability.
Microsoft backpedals: Edge to stop loading passwords into memory
Patch: Upgrade all Edge installations to build 148 or newer to stop passwords from loading into memory at startup.
MiniPlasma Windows Zero‑Day PoC Gives Attackers SYSTEM Access on Patched Systems
Patch Windows to the latest cumulative update and verify cldflt.sys is updated to close the MiniPlasma flaw.
Windows 11 Update KB5089549 Fails to Install on Devices with Low ESP Space
Apply the Known Issue Rollback group policy to affected devices and restart to mitigate the ESP space issue.
Node‑ipc Found to Contain Malicious Activity in Multiple Versions
Remove node‑ipc from your dependencies and replace it with a vetted alternative; run a security audit.
Four npm Packages Discovered Containing Malware, Including a Shai‑Hulud Clone
Remove these malicious packages from your dependencies and replace them with vetted alternatives; run npm audit.
Instructure settles with cyber‑extortion group after Canvas network breach
Patch Canvas to the latest release, disable Free‑for‑Teacher accounts, and audit for XSS.
Hackers abuse Google ads, Claude.ai chats to push Mac malware
Block malicious Claude.ai shared chat links in Google Ads and monitor for terminal command instructions.
Fake OpenAI “Privacy Filter” Repo on Hugging Face Distributes Malware, Hits 244 k Downloads
Remove the malicious Open‑OSS/privacy‑filter repository from your Hugging Face account and audit all imported models for malicious code.
NVIDIA confirms GeForce NOW data breach affecting Armenian users
Notify affected users and review authentication logs for suspicious activity.
Wordfence Weekly Vulnerability Report: 87 New Vulnerabilities in WordPress Plugins and Themes
Check the Wordfence Intelligence vulnerability feed for the 87 newly disclosed vulnerabilities and update any affected plugins or themes.
QLNX: Undocumented Linux RAT Targets Developers and DevOps Credentials
Deploy updated antivirus signatures and monitor for QLNX activity; isolate affected systems immediately.
Canvas Outage: ShinyHunters Threaten to Leak Data of 275 Million Students
Patch the Canvas login page to remove defacement and verify authentication flow.
Australia warns of ClickFix attacks pushing Vidar Stealer malware
Patch WordPress themes, plugins, and remove unused components; restrict PowerShell execution and enable application allow‑listing to stop ClickFix attacks.
New Credential‑Theft Framework PCPJack Targets Exposed Cloud Infrastructure
Detect and block PCPJack activity by monitoring for credential harvesting patterns and exfiltration traffic.
Ivanti EPMM Zero-Day RCE Exploited, Federal Agencies Urged to Patch
Patch Ivanti Endpoint Manager Mobile to version 12.6.1.1 or later to fix CVE‑2026‑6973.
Cloudflare Responds to Linux "Copy Fail" CVE‑2026‑31431
Patch the kernel to the latest LTS (6.18) and deploy the bpf‑lsm mitigation immediately.
MuddyWater Linked to Ransomware Attack Using Microsoft Teams, Rapid7 Reports
Patch Microsoft Teams to block malicious links, enable MFA, and monitor Teams traffic for phishing.
ADT says customer data stolen in cyber intrusion
Patch ADT's exposed endpoints and enforce MFA on admin accounts.
DAEMON Tools Supply‑Chain Breach: Trojans in Free Lite Version
Patch all installations of DAEMON Tools Lite 12.5.1 by uninstalling, scanning, and installing 12.6.0.2445 from the official site.
Hunt.io Exposes Mirai‑Derived xlabs_v1 Botnet Targeting ADB‑Exposed Devices
Patch or secure Android Debug Bridge on all devices to prevent enlistment in the xlabs_v1 Mirai‑derived botnet.
Critical vm2 Sandbox Bug Lets Attackers Execute Code on Hosts
Patch vm2 to 3.10.5 or later immediately to prevent arbitrary host code execution.
DENIC DNSSEC Misconfiguration Causes .de SERVFAIL Outage, Cloudflare Mitigates with Override Rule
Configure your DNS resolver to treat .de as an insecure zone using an override rule to bypass DNSSEC validation during the outage.
WP Engine Blocks AI Crawlers, Causing 429 Errors for ClaudeBot and Others
Patch WP Engine firewall rules to whitelist current AI crawler UAs (ClaudeBot, GPTBot, Amazonbot) and remove outdated blocklist entries.
CVE-2026-31431 Public Notifications Vulnerability in theori-io Plugin
Patch the theori‑io plugin immediately by applying the latest release or the provided patch to enforce authentication on notification settings.
Palo Alto Vulnerability CVE-2026-0300 Exploited for a Month
Patch PAN‑OS to the latest version that fixes CVE‑2026‑0300 immediately.
New Quasar Linux RAT Targets Developers with Stealthy Credential Theft
Patch: Immediately audit all development machines for LD_PRELOAD usage, remove unauthorized PAM modules, and apply security patches to kernel and userland libraries.
Apache HTTP Server Security Update Addresses CVE-2026-23918 RCE Vulnerability
Patch Apache HTTP Server to the latest security release (2.5.70) immediately and verify HTTP/2 handling.
ScarCruft Compromises Video Game Platform with BirdCallto Backdoor
Patch any compromised components and monitor for BirdCallto activity to mitigate the active supply‑chain threat.
cPanel Patch Halts Mass Ransomware Attack on 44,000 Servers
Apply the WHM/cPanel emergency update immediately to fix CVE-2026-41940 and stop the Sorry ransomware spread.
Fixing LangChain Serialization Regression with Automated Pytest
Upgrade LangChain to 0.1.0, adjust serialization logic, add pytest suite with FakeRedis to catch regressions.
Invisible Newsletter Breach: Zero-Click Prompt Injection Exposes Email Assistant
Patch your email ingestion pipeline to sanitize incoming HTML and strip invisible text vectors before passing to the LLM.
VeriSigil AI: SSL‑Like Cryptographic Identity for Autonomous Agents
Call the issue‑test endpoint to obtain a test passport and verify your agent with the verify endpoint.
Progress warns of critical MOVEit Automation auth bypass flaw
Patch all MOVEit Automation instances to the latest version before the outage window.
Microsoft Defender wrongly flags DigiCert certs as Trojan:Win32/Cerdigent.A!dha
Patch Microsoft Defender to Security Intelligence version 1.449.430.0 or later to restore removed DigiCert root certificates.
Phishing Scam Targeting WordPress Agencies via Fake Google OAuth
Notify all agencies to avoid clicking the fake Google OAuth link and do not send credentials.
Canonical Switch to uutils Coreutils and CVE Audit
Patch uutils coreutils to a fixed version or replace with GNU coreutils to avoid CVEs.
Accidental Exposure of Entire Website Source Code via Python HTTP Server
Patch: Immediately stop the accidental HTTP server, close port 80, apply firewall rules, verify no other services are exposed, and review server configuration.
Phishing Campaign Uses Legitimate RMM Software for Persistent Remote Access
Patch: Enable MFA on all RMM accounts, review access logs, isolate compromised hosts, update RMM software, and notify users of phishing.
Progress Software Issues Critical MOVEit Authentication Bypass
Install the newest MOVEit Automation security patch to fix the authentication bypass and other critical flaws.
PyTorch Lightning 2.6.3 Supply‑Chain Attack Steals Credentials
Uninstall malicious Lightning 2.6.2 and 2.6.3 and install the latest secure release.
VECT 2.0 Acts as Wiper Due to Encryption Flaw
Patch: update antivirus signatures to detect VECT 2.0 and monitor for its activity.
Malicious Code Found in @validate-sdk/v2 Used by Anthropic’s Claude Opus
Remove @validate-sdk/v2 from dependencies and audit all projects using it.
Threat Actors Deploy Custom AI to Automate Active Directory Attacks
Patch your AD monitoring tools to detect rapid credential harvesting by AI agents.
OpenFang Agent Vulnerability: curl Fetch Leads to Reverse Shell
Patch OpenFang to validate fetched content before execution.
Fast16 State‑Sponsored Malware Targeting Iran
Check for Fast16 signatures, isolate affected networks, and patch any vulnerable software that could be targeted by silent manipulation of high‑precision calculations.
Mini Shai-Hulud Campaign Targets SAP-Related npm Packages with Credential-Stealing Malware
Patch affected npm packages, tighten dependency management, and monitor for credential theft.
BufferZoneCorp Uses Sleeper Packages to Deploy Credential Theft and GitHub Actions Tampering
Patch vulnerable Ruby gems and Go modules, audit GitHub Actions, and monitor for SSH persistence.
LeRobot Vulnerability CVE-2026-25874 Enables Remote Code Execution via Untrusted Deserialization
Patch LeRobot to the latest version or apply the security advisory immediately.
Gemini CLI Security Flaw Allows Unprivileged Attacker to Execute Arbitrary Commands
Patch the @google/gemini-cli npm package to the latest version or apply the security advisory immediately.
Microsoft Entra ID Agent ID Administrator Role Vulnerability Enables Privilege Escalation
Patch Microsoft Entra ID to the latest version or apply the security advisory immediately.
BerriAI LiteLLM Python Package Vulnerability CVE-2026-42208 Enables SQL Injection
Patch LiteLLM to the latest version or apply the security advisory immediately.
Wordfence Weekly Vulnerability Report: 157 Vulnerabilities Disclosed Across 122 Plugins and 27 Themes
Patch any affected plugins or themes immediately; check the Wordfence vulnerability database for the 157 disclosed issues.
Researchers Find 11 Microsoft‑Signed UEFI Apps That Can Bypass Secure Boot
Patch or update firmware to remove the 11 vulnerable UEFI applications.
CrashStealer: Native C++ macOS Information Stealer Validates Password Before Theft
Remove or quarantine CrashStealer from macOS systems and update security tools to detect native C++ stealers.
Silver Fox Group Uses Rust‑Based MODBEACON RAR to Deploy Counterfeit Installers via SEO Poisoning
Block downloads from suspicious installers and monitor for MODBEACON signatures in your environment.
148 npm Packages Turn Browsers into DDoS Botnet via Student Proxy Scam
Remove the compromised npm packages and audit your dependencies to prevent botnet infection.
Sustained Cyber‑Espionage Against Pakistani Law Enforcement by China‑ and India‑Aligned Actors
Perform a comprehensive security assessment of all web applications, enforce least‑privilege access, enable MFA, and monitor logs for suspicious activity.
Compromised @asyncapi npm Packages Distribute Multi‑Stage Botnet Loader
Patch all @asyncapi packages to the latest safe releases immediately and audit your dependency tree for other compromised packages.
WordPress Org Hardens GitHub Actions Workflows Against Supply‑Chain Attacks
Patch all WordPress org repositories by merging the hardening PRs, enabling Actionlint and Zizmor, and reviewing workflow permissions.
New macOS malware tricks AI scanners with fake error comments
Scan for Gaslight binaries, update macOS, monitor for fake error strings, and use AI analysis tools with caution.
Bluekit phishing kit adopts browser-in-the-middle for login theft
Block rrweb scripts, monitor for BitM patterns, enforce MFA, and review phishing templates.
Four Vulnerabilities in Dify Allow Unauthenticated Read of AI Conversions
Patch Dify to the latest release that resolves the DifyTap vulnerabilities.
WhatsApp DM Campaign Distributes VBScript to Install Legitimate RMM Software
Block VBScript file downloads from WhatsApp and scan for installed RMM software to mitigate the campaign.
New CastleStealer Campaign Uses OXLOADER Loader via Malicious Google Ads
Block malicious Google Ads and monitor for OXLOADER signatures to stop CastleStealer distribution.
Recruitment‑Themed Phishing Targets Crypto Firms with Custom macOS Malware
Block recruitment‑themed phishing and harden macOS endpoints to defend against targeted cryptocurrency attacks.
Linux Kernel CVE-2026-46333: 9-Year-Old Privilege Escalation Flaw Exposed
Patch the Linux kernel to the latest version that contains the CVE-2026-46333 fix.
GitHub links repo breach to TanStack npm supply‑chain attack
Patch all GitHub repositories by rotating secrets and monitoring for unauthorized access after the Nx Console 18.95.0 compromise.
EvilTokens Phishing-as-a-Service Compromises 340 Microsoft 365 Organizations in Five Weeks
Patch your MFA flow to reject device login requests that contain short codes and verify the request source.
Microsoft Issues Mitigation for YellowKey BitLocker Bypass Exploit
Apply the Microsoft BitLocker mitigation immediately.
Hackers bypass SonicWall VPN MFA due to incomplete patching
Update Gen6 SonicWall firmware, delete LDAP config, reboot, and recreate LDAP without userPrincipalName to block MFA bypass.
GitHub Investigates Unauthorized Access to Internal Repositories After TeamPCP Sale Listing
Audit internal repository permissions and enable two‑factor authentication for all users.
Supply‑Chain Attacks Exploit Mail‑Server Flaw, Poison Packages, and Deliver Stealers
Audit all dependencies for known vulnerabilities and remove any that expose secrets.
OpenClaw Vulnerabilities Form Claw Chain for Data Theft and Persistence
Patch OpenClaw to close the Claw Chain vulnerabilities.
PraisonAI Vulnerability CVE-2026-44338 Exploited Within Hours of Disclosure
Patch PraisonAI to address CVE-2026-44338 and secure sensitive endpoints.
Microsoft Claims Silent Fix for Azure Backup for AKS Vulnerability
Check Azure Backup for AKS logs for silent patch application and verify no unexpected changes.
TrickMo Android banker adopts TON blockchain for covert comms
Ensure Android devices only install apps from Google Play, limit app count, enable Play Protect, and monitor for TrickMo.C signatures.
Dirty Frag: Unpatched Local Privilege Escalation Vulnerability in Linux Kernel
Patch all Linux systems to the latest kernel version that addresses Dirty Frag before exploitation.
Kaspersky Finds Supply‑Chain Attack on DAEMON Tools Installers
Patch: Verify installer signatures and update to the latest DAEMON Tools version to mitigate the supply chain attack.
Persistent OAuth Tokens Without Expiration Pose Major Security Risk
Disable or rotate all long‑lived OAuth tokens and enforce expiration policies.
MetInfo CMS Vulnerability CVE-2026-29014 Allows Arbitrary Code Execution
Patch MetInfo to the latest release (8.2+) immediately.
CloudZ RAT exploits Microsoft Phone Link to steal SMS and OTPs
Disable Microsoft Phone Link on all Windows machines, enforce hardware‑based MFA, and block CloudZ RAT traffic.
Backdoored PyTorch Lightning package drops credential stealer
Rotate all secrets, avoid importing PyTorch Lightning 2.6.3, and use version 2.6.1 until the audit completes.
cPanel Security Crisis: Multiple Exploits Prompt Emergency Patches and Ransomware Attack
Apply the latest cPanel and WHM security update immediately.
17-Year-Old Arrested for Extracting Personal Data of 7 Million Kaikatsu Club Users
Notify affected users and report the breach to authorities.
Checkmarx Supply Chain Attack Leak Exposes GitHub Repository Data
Patch repository access controls, audit credentials, and notify stakeholders immediately.
Microsoft Windows Shell Vulnerability CVE-2026-32202 Patched but Actively Exploited
Apply the latest Windows security patch that includes CVE-2026-32202.
AI Assistant Memory Injection via Email Can Rewrite User Facts
Patch your AI assistant to prevent email-based memory injection that can rewrite user facts.
Microsoft Zero-Day Saga: Six Windows Vulnerabilities, Three Exploited, July 14 Threat
Patch all Windows systems against the six zero‑days, prioritising the three actively exploited ones (BlueHammer, RedSun, UnDefend) and YellowKey (CVE‑2026‑45585), and audit your vulnerability management to ensure coordinated disclosure.
Grafana source‑code theft after stolen GitHub token and supply‑chain breach
Verify Grafana GitHub tokens and rotate them immediately.
New Rowhammer Attacks Grant Full Control Over NVIDIA GPUs and Host CPUs
Enable IOMMU in BIOS and apply NVIDIA firmware patches to mitigate rowhammer vulnerabilities.
LinkedIn Faces GDPR Complaint Over Paid Profile‑Visitor Data
Notify your legal team to examine LinkedIn's data handling and prepare a compliance audit.
ScarCruft’s BirdCall Backdoor Targets Ethnic Koreans in China via Game Platform Supply‑Chain Attack
Block installation of apps from sqgame.net and enforce downloads only from official marketplaces.
Instructure’s Canvas faces 275‑million‑record data breach and defacement by ShinyHunters
Investigate the Instructure incident, monitor Canvas Data 2 and Canvas Beta for API key issues, and keep clients informed of potential data exposure.
AccountDumpling: Vietnamese-Linked Operation Uses Google AppSheet as Phishing Relay
Check for phishing emails sent via Google AppSheet and advise users to enable 2FA on Facebook.
Linux kernel “Copy Fail” and “Dirty Frag” flaws give attackers root access to major distributions
Patch Linux systems against CVE‑2026‑31431 immediately.
Linux Kernel Adds Killswitch Feature for Immediate Function Mitigation
Patch the kernel with CONFIG_KILLSWITCH and immediately engage the vulnerable function using the control interface to stop exploitation until a proper fix is available.
FTC Bans Kochava From Selling Americans’ Location Data Without Consent
Patch your data handling to ensure no sensitive location data is sold without consent.
Student hacked Taiwan high‑speed rail to trigger emergency brakes
Patch your TETRA parameter rotation policy to enforce quarterly changes and audit verification layers.
Vimeo Data Breach Exposes Personal Information of 119,000 People
Patch: Disable all Anodot credentials and remove the Anodot integration from your Vimeo environment immediately.
Microsoft Uncovers Large-Scale Credential Theft Campaign Using Legitimate Email Services
Enable MFA on all Microsoft accounts and block the attacker domains listed in the report immediately.
Brazilian DDoS Protection Firm Compromised, Botnet Targets Local ISPs
Patch all TP‑Link Archer AX21 routers to the latest firmware, rotate any compromised SSH keys, and audit for unauthorized access to prevent future botnet activity.
DarkSword iOS Malware Exploit Chain Targets Multiple Nations
Patch iOS devices to the latest version (18.8 or later) to mitigate DarkSword exploitation.