Briefing

Critical Alerts

277 critical watches · last 7 days
urgent

Ultimate Member Plugin Vulnerability Allows Password Reset Link Disclosure

Patch Ultimate Member to version 2.12.0 immediately to close password reset link disclosure vulnerability.

security 10/10 Search Engine Journal
25 Jun 20:57
urgent

Phishing Attack Exploits Open‑Source Project’s Cloud Signup Flow

Implement captcha, disposable‑email blocker, rate limits, workspace‑name filter, and revoke any compromised Resend keys.

security 10/10 Hacker News (front page)
29 May 20:47
urgent

CVE‑2026‑5426: Hard‑Coded ASP.NET Keys in KnowledgeDeliver Enable Godzilla Shell

Patch Digital Knowledge KnowledgeDeliver to fix hard‑coded ASP.NET machine keys and prevent Godzilla shell exploitation.

security 10/10 The Hacker News
29 May 20:32
urgent

Critical Vulnerability in Funnel Builder Plugin Allows JS Injection into WooCommerce Checkout

Patch Funnel Builder immediately to stop malicious JavaScript injection into WooCommerce checkout pages.

security 10/10 The Hacker News
18 May 14:02
urgent

SonicWall Announces Exploitation of Two Zero‑Day Vulnerabilities in Secure Mobile Access Appliances

Apply SonicWall patches for CVE‑2026‑15409 and CVE‑2026‑15410 to eliminate SSRF and arbitrary command execution.

security 9/10 The Hacker News
15 Jul 12:21
urgent

GitHub Dependabot Adds Three‑Day Cooldown for Non‑Security Updates

Verify Dependabot uses the default 3‑day cooldown; no action needed unless you want to override.

security 9/10 Simon Willison
15 Jul 12:11
urgent

Five Eyes Warns of AI Models Autonomously Hacking Systems

Enable AI‑driven vulnerability scanning and update incident response plans to counter autonomous attack patterns.

security 9/10 Schneier on Security
15 Jul 12:09
urgent

Squidbleed Vulnerability Exposes HTTP Requests in Squid 2.9 Proxy

Patch Squid to the latest stable release (≥3.5) immediately and audit proxy configurations.

security 9/10 Schneier on Security
15 Jul 12:09
urgent

xAI's Grok Build CLI Uploads Entire Git Repositories to External Cloud Bucket

Patch: configure Grok Build CLI to limit uploads to necessary files, revoke bucket access, and audit repository content.

security 9/10 The Hacker News
15 Jul 12:08
urgent

Forg365 Phishing-as-a-Service Targets Microsoft 365 Accounts with AI-Driven Lure Creation

Block: disable device code flow, enable MFA, monitor for suspicious login attempts, and block Forg365 channels.

security 9/10 The Hacker News
15 Jul 12:08
urgent

Threat Actor Uses PowerShell Script to Enumerate Active Directory

Block: prevent execution of the PowerShell enumeration script, audit AD logs, and enforce least privilege.

security 9/10 The Hacker News
15 Jul 12:08
urgent

Python Web Server Left Exposed by Phishing Operation, Enabling Lateral Movement

Disable: stop the Python HTTP server, remove directory listing, delete .bash_history, and audit for other exposed services.

security 9/10 The Hacker News
15 Jul 12:08
urgent

jscrambler npm Package Compromised – Infostealer in 8.14.0

Patch: uninstall jscrambler 8.14.0, install a verified version, and audit package-lock for malicious binaries.

security 9/10 The Hacker News
15 Jul 12:08
urgent

SAP Releases Security Updates for NetWeaver ABAP, Fixing CVE‑2026‑44747

Patch: apply SAP NetWeaver ABAP update from July 2026 to fix CVE-2026-44747 before exploitation.

security 9/10 The Hacker News
15 Jul 12:08
urgent

CISA Adds iCagenda and Balbooa Joomla Extensions to KEV Catalog for Zero‑Day Exploitation

Patch iCagenda and Balbooa Joomla extensions immediately to mitigate CVE‑2026‑48939 and related zero‑day vulnerabilities.

security 9/10 The Hacker News
15 Jul 12:05
urgent

Zimbra Urges Customers to Patch Classic Web Client for Critical XSS Vulnerability

Patch Zimbra Classic Web Client immediately to mitigate XSS that could lead to arbitrary code execution.

security 9/10 The Hacker News
15 Jul 12:05
urgent

Binarly Discovers Six New U‑Boot Flaws, Four of Which Can Crash Devices

Update U‑Boot firmware on all affected devices to mitigate crash and code execution risks.

security 9/10 The Hacker News
15 Jul 12:03
urgent

ShinyHunters Exploit OAuth Trust to Penetrate Salesforce Without Platform Flaws

Audit OAuth connections in Salesforce and revoke unnecessary permissions.

security 9/10 The Hacker News
15 Jul 12:03
urgent

Cybercrime Crew Leaves Server Open, Exposes 1.4 Million Target Sites

Review your own server exposure policies and ensure no public‑facing services are left unprotected.

security 9/10 The Hacker News
15 Jul 12:03
urgent

Voice‑Based Phishing Targets Microsoft 365 Passkey Enrollment

Disable automatic passkey enrollment prompts and enforce MFA for Microsoft 365 accounts.

security 9/10 The Hacker News
15 Jul 12:03
urgent

ModHeader Extension Removed After Hidden Browsing-History Collector Discovered

Uninstall ModHeader from all browsers and replace with a trusted alternative.

security 9/10 The Hacker News
15 Jul 12:03
urgent

OpenClaw AI Assistant Vulnerabilities: Credential Theft, Privilege Escalation, and Code Execution

Apply the latest OpenClaw security patch to eliminate credential theft, privilege escalation, and code execution risks.

security 9/10 The Hacker News
15 Jul 12:03
urgent

New GodDamn Ransomware Family Uses PoisonX Driver to Evade Security Software

Deploy updated anti‑malware signatures and monitor for PoisonX driver activity.

security 9/10 The Hacker News
15 Jul 12:03
urgent

Microsoft Unveils Record‑Breaking Patch Tuesday, Fixes 622 CVEs and RoguePlanet Vulnerability

Apply the July 2026 Windows patches promptly, but first back up your systems.

security 9/10 Krebs on Security
15 Jul 12:02
urgent

Wordfence Intelligence Weekly Vulnerability Report: 250 New Vulnerabilities Disclosed

Patch all unpatched WordPress plugins and themes, and enable the new Wordfence firewall rules for Ninja Forms <=3.3.29, WAF‑RULE‑923, and WAF‑RULE‑924 immediately.

security 9/10 Wordfence Blog
15 Jul 12:00
urgent

Post‑Quantum Migration: Cloudflare Deploys ML‑KEM Encryption and ML‑DSA Signatures

Patch TLS to use ML‑KEM encryption and ML‑DSA signatures for post‑quantum security and monitor for upcoming signature standards.

security 9/10 Cloudflare Blog
15 Jul 12:00
urgent

Albanian .AL TLD DNSSEC Rollover Failure Forces Cloudflare to Deploy NTA and EDE Codes

Patch DNSSEC validation to respect EDE codes and monitor for NTA usage to detect unvalidated responses.

security 9/10 Cloudflare Blog
15 Jul 12:00
urgent

Chrome’s WebMCP Security Guidance Highlights Attack Vectors for AI Agents

Patch your WebMCP tools by adding untrustedContentHint, readOnlyHint, and exposedTo annotations to mitigate malicious manifest and contaminated output attacks.

security 9/10 Search Engine Journal
15 Jul 11:53
urgent

Claude AI Memory System Exfiltration Vulnerability Exposes User Data

Patch the web_fetch tool to reject arbitrary path encoding that can carry data.

security 9/10 Hacker News (front page)
15 Jul 11:52
urgent

Mandiant reveals how Cisco SD‑WAN zero‑day attacks gained root access

Patch Cisco SD‑WAN devices to the latest firmware that fixes CVE‑2026‑20245 and disable tenant‑upload feature until patch is applied.

security 9/10 Bleeping Computer
25 Jun 21:30
urgent

Gravity SMTP Plugin CVE-2026-4020: Medium‑Severity Info Disclosure Flaw Exploited on 100,000 WordPress Sites

Patch Gravity SMTP to the latest version to fix CVE-2026-4020.

security 9/10 The Hacker News
25 Jun 21:29
urgent

Wordfence Weekly Vulnerability Report: 146 Vulnerabilities in 127 Plugins and 1 Theme

Patch the 7 unpatched vulnerabilities, including the 7 critical ones, as soon as possible and run the Wordfence CLI scanner to verify all sites are secure.

security 9/10 Wordfence Blog
25 Jun 21:28
urgent

LastPass Warns Users of Data Breach via Partner Klue

Patch exposed API tokens and revoke partner access immediately.

security 9/10 Hacker News (front page)
25 Jun 21:21
urgent

Missing Content in AI News Articles Leaves Readers Uninformed

Disable Anthropic's Fable 5 and Mythos 5 models to comply with U.S. export‑control directive.

marketing 9/10 MarketingProfs
25 Jun 21:08
urgent

Apple Patches Beats Studio Buds Vulnerability CVE‑2025‑20701

Update Beats Studio Buds firmware to fix CVE‑2025‑20701.

security 9/10 The Hacker News
25 Jun 21:05
urgent

Cordyceps: New CI/CD Workflow Weakness Threatens Open-Source Supply Chains

Patch CI/CD workflows to mitigate Cordyceps.

security 9/10 The Hacker News
25 Jun 21:05
urgent

Microsoft AutoJack Exploit Turns AI Browsing Agent into RCE Vehicle

Patch AI browsing agents to prevent AutoJack exploitation.

security 9/10 The Hacker News
25 Jun 21:05
urgent

Squidbleed: Heap Over-Read Vulnerability Exposes Cleartext HTTP Requests

Patch Squid to a version that fixes the Squidbleed heap over‑read vulnerability.

security 9/10 The Hacker News
25 Jun 21:04
urgent

GitHub Updates actions/checkout to Block pull_request_target Attacks

Update actions/checkout to the latest version to block pull_request_target workflow attacks.

security 9/10 The Hacker News
25 Jun 21:04
urgent

ShapedPlugin Supply‑Chain Attack Injects Backdoor into Pro Plugins

Notify users of ShapedPlugin and roll back to a clean version before the compromised release.

security 9/10 The Hacker News
25 Jun 21:02
urgent

Cisco Unified Communications Manager Vulnerability CVE-2026-20230 Allows Remote Exploitation

Apply the Cisco Unified Communications Manager patch for CVE-2026-20230 immediately to close the remote exploitation vector.

security 9/10 The Hacker News
25 Jun 21:00
urgent

CISA Issues Patch Alert for Ubiquiti and Lantronix Vulnerabilities

Apply the Lantronix EDS5000 firmware patch before 26 June 2026 to mitigate the code injection flaw.

security 9/10 The Hacker News
25 Jun 21:00
urgent

Agentic Traps: Hidden Tokens and Dynamic Cloaking Threaten AI Agents

Audit web content for hidden tokens and dynamic cloaking that could trap AI agents and mitigate potential security risks.

security 9/10 Search Engine Journal
25 Jun 20:57
urgent

New Gogs zero-day flaw lets hackers get remote code execution

Patch Gogs to 0.14.2 or 0.15.0+dev to eliminate RCE.

security 9/10 Bleeping Computer
29 May 23:35
urgent

OpenAI ChatGPT Vulnerability Allows Prompt Injection via Trusted Markdown Links

Patch ChatGPT rendering to sanitize Markdown links and images to prevent prompt injection.

security 9/10 The Hacker News
29 May 20:55
urgent

Marimo Notebook Exploited via CVE‑2026‑39987, LLM Agent Drives Post‑Compromise Actions

Patch the Marimo environment to mitigate CVE‑2026‑39987 before attackers can use LLM agents.

security 9/10 The Hacker News
29 May 20:54
urgent

Critical Unauthenticated Administrator Account Creation Vulnerability in WP Maps Pro (CVE-2026-8732)

Patch WP Maps Pro to 6.1.1 immediately to eliminate the unauthenticated admin account creation flaw (CVE-2026-8732).

security 9/10 Wordfence Blog
29 May 20:52
urgent

Microsoft Copilot Cowork Vulnerability Allows Email Exfiltration

Patch Copilot Cowork to prevent unsanctioned email sending and image rendering.

security 9/10 Simon Willison
29 May 20:39
urgent

CVE-2026-27771: Gitea Vulnerability Allows Unauthenticated Pull of Private Container Images

Patch: Upgrade Gitea to version 1.26.2 or later to fix CVE‑2026‑27771 and prevent unauthenticated pull of private container images.

security 9/10 The Hacker News
29 May 20:33
urgent

CVE-2026-48172: LiteSpeed User‑End cPanel Plugin Privilege Escalation Under Active Exploitation

Patch: Update the LiteSpeed User‑End cPanel Plugin to the latest patched version to eliminate CVE‑2026‑48172 before exploitation.

security 9/10 The Hacker News
29 May 20:33
urgent

CERT‑IN Mandates 12‑Hour Patch Window for Critical Vulnerabilities

Patch critical internet‑exposed systems within 12 hours of detection to comply with CERT‑IN guidelines.

security 9/10 The Hacker News
29 May 20:32
urgent

Microsoft Releases Patch for CVE‑2026‑45659 Remote Code Execution in SharePoint

Patch SharePoint to the latest version to mitigate CVE‑2026‑45659.

security 9/10 The Hacker News
29 May 20:28
urgent

Yoast SEO Premium 27.6.1 Security Patch Addresses .htaccess Redirect Vulnerability

Patch Yoast SEO Premium to 27.6.1 immediately if using .htaccess redirects and edit_posts capability.

security 9/10 Yoast SEO Blog
29 May 20:27
urgent

Advanced Custom Fields 6.8.2 Security Release

Patch ACF to 6.8.2 immediately to fix frontend form security.

security 9/10 Advanced Custom Fields
29 May 20:22
urgent

NGINX Vulnerability CVE-2026-42945: Heap Buffer Overflow in Rewrite Module Exploited in Wild

Patch NGINX to the latest release (≥1.30.1) immediately to fix CVE-2026-42945, a heap buffer overflow in ngx_http_rewrite_module that is actively exploited.

security 9/10 The Hacker News
22 May 04:44
urgent

May 2026 Core Update Rolling Out, No Companion Blog Post

Wait one week after the core update completes, then review Search Console data against baseline.

seo 9/10 Search Engine Journal
22 May 02:08
urgent

Anthropic’s Mythos AI Helps Discover Kernel Memory Corruption Exploit on Apple M5

Patch Apple M5 devices immediately to mitigate the kernel memory corruption vulnerability discovered using Anthropic’s Mythos.

security 9/10 Schneier on Security
21 May 23:23
urgent

Google accidentally exposed details of unfixed Chromium flaw

Patch Chromium to the latest stable version and disable background Service Workers.

security 9/10 Bleeping Computer
21 May 23:22
urgent

Drupal Core Vulnerability CVE-2026-9082 Allows Remote Code Execution and Privilege Escalation

Apply the Drupal Core security patch for CVE-2026-9082 without delay.

security 9/10 The Hacker News
21 May 23:17
urgent

Forensic Breakdown: CyberPanel SnappyMail Log Exploited to Persist Webshell on WordPress

Patch the wp-config.php file to remove the malicious eval base64_decode payload, then audit server logs for root-level backdoor and apply CyberPanel security updates.

security 9/10 Wordfence Blog
21 May 23:12
urgent

Linux Kernel copy.fail Vulnerability Enables Local Privilege Escalation

Patch: Update to the latest kernel (≥6.5.0) immediately to fix copy.fail LPE.

security 9/10 Schneier on Security
18 May 13:50
urgent

Multiple Linux kernel exploits released after patching: PinTheft, DirtyDecrypt, and others

Update your kernel to the latest patched version, or apply the dirtyfrag mitigation script to block DirtyDecrypt exploitation.

security 9/10 Bleeping Computer
18 May 13:49
urgent

Popular node-ipc npm package compromised to steal credentials

Patch node‑ipc to a safe version, rotate exposed secrets, and audit lockfiles.

security 9/10 Bleeping Computer
18 May 13:48
urgent

Microsoft Exchange Server Vulnerability CVE-2026-42897: Spoofing Bug from XSS Exploited in Wild

Patch Exchange Server to fix CVE‑2026‑42897 immediately.

security 9/10 The Hacker News
18 May 13:46
urgent

Burst Statistics Authentication Bypass Vulnerability (CVE-2026-8181) – Critical Fix Released

Patch Burst Statistics to 3.4.2 immediately to eliminate the authentication bypass.

security 9/10 Wordfence Blog
18 May 13:45
urgent

Google Ads Offline Conversion Imports Ending – Migrate to Data Manager API

Migrate offline conversion imports to the Data Manager API before June 15 to avoid data loss.

ads 9/10 Search Engine Land
18 May 13:39
urgent

Funnel Builder WordPress plugin bug exploited to steal credit cards

Patch: Update Funnel Builder to 3.15.0.3 immediately and remove any injected scripts from External Scripts settings.

security 9/10 Bleeping Computer
18 May 13:24
urgent

Phishing‑as‑a‑Service Platforms Hijack Hundreds of Microsoft 365 Accounts

Patch: Disable OAuth device‑code flow on Microsoft 365 accounts and enforce Continuous Access Evaluation to mitigate Tycoon2FA device‑code phishing.

security 9/10 Bleeping Computer
18 May 13:23
urgent

Avada Builder WordPress plugin suffers critical flaws enabling credential theft and data breaches

Upgrade Avada Builder to 3.15.3 immediately to eliminate the file‑read and SQL injection vulnerabilities.

wordpress 9/10 Bleeping Computer
18 May 13:22
urgent

Linux Kernel Exposes Multiple Local Privilege Escalation Flaws, Prompting Urgent Patching

Apply the latest kernel patch to fix Fragnesia LPE (CVE‑2026‑46300) before local attackers can gain root.

security 9/10 The Hacker News
18 May 13:20
urgent

Cisco Vulnerabilities Prompt CISA Urgent Patch for Federal Agencies

Remediate Cisco SD‑WAN Controller authentication bypass (CVE‑2026‑20182) by May 17 2026.

security 9/10 The Hacker News
18 May 13:20
urgent

YellowKey Zero‑Day Bypasses Windows 11 BitLocker

Patch Microsoft Defender immediately to mitigate YellowKey and GreenPlasma zero‑days.

security 9/10 The Hacker News
18 May 13:20
urgent

Critical NGINX Vulnerabilities Disclosed, Including 18‑Year‑Old Heap Buffer Overflow

Patch NGINX to the latest version immediately to fix the CVE‑2026‑42945 heap buffer overflow.

security 9/10 The Hacker News
18 May 13:19
urgent

RubyGems Pauses Sign‑Ups Amid Major Malicious Attack

Disable new RubyGems account creation for your projects until the pause lifts and monitor security advisories.

security 9/10 The Hacker News
18 May 13:19
urgent

Microsoft, Apple, Google, Mozilla, Oracle Release Major Security Patches—118 CVEs Fixed on Patch Tuesday

Patch all Windows Server 2012+ to fix CVE‑2026‑41089, CVE‑2026‑41096, CVE‑2026‑41103; update Chrome to the latest build to resolve 127 CVEs; back up data before applying any vendor patches.

security 9/10 Krebs on Security
18 May 13:17
urgent

Palo Alto Networks Discloses Critical PAN‑OS CVE‑2026‑0300 Exploitation Attempts

Patch PAN‑OS immediately to mitigate CVE‑2026‑0300.

security 9/10 The Hacker News
12 May 06:00
urgent

cPanel and WHM Hit by CVE-2026-41940 Authentication Bypass, Threat Actor Mr_Rot13 Deploys Filemanager Backdoor

Patch cPanel to the latest release that addresses CVE‑2026‑41940 immediately.

security 9/10 The Hacker News
12 May 05:41
urgent

TanStack Router npm Packages Compromised in Supply‑Chain Attack

Audit all TanStack router dependencies, update to the patched version, and remove any compromised packages from your build.

security 9/10 Hacker News (front page)
12 May 01:27
urgent

Canonical Suffers 20‑Hour DDoS Attack Using Cloudflare‑Busting Service

Configure Cloudflare to enforce ‘Under Attack Mode’ on all critical endpoints, block IP ranges associated with Beamed, and monitor certificate transparency logs for unexpected apex certificate issuance.

security 9/10 Hacker News (front page)
11 May 22:09
urgent

Google Thwarts AI‑Powered Attack, Uncovers Zero‑Day 2FA Bypass

Patch Google services to the latest security patch that mitigates the AI‑generated zero‑day exploit.

security 9/10 The Hacker News
11 May 20:16
urgent

Critical Vulnerability in Ollama Could Leak Entire Process Memory (CVE-2026-7482)

Upgrade Ollama immediately to the patched version that resolves CVE‑2026‑7482.

security 9/10 The Hacker News
11 May 19:11
urgent

cPanel Releases Emergency Patch After Authentication Bypass Ransomware Attack

Patch cPanel to the latest emergency security release to mitigate the authentication bypass vulnerability.

security 9/10 Hacker News (front page)
11 May 14:53
urgent

cPanel Releases Security Update for Three Vulnerabilities Including CVE-2026-29201

Patch cPanel to the latest security release to fix the feature::LOADFEATUREFILE input validation flaw (CVE-2026-29201).

security 9/10 The Hacker News
9 May 14:17
urgent

Meta Releases Patch for React2Shell RCE Vulnerability (CVE‑2025‑55182)

Patch React to the latest version (≥18.2.0) immediately to eliminate the Flight protocol RCE.

security 9/10 Hacker News (front page)
9 May 11:44
urgent

JDownloader site hacked, installers replaced with malware

Patch the JDownloader website by fixing the unpatched ACL bug and restore legitimate download links.

security 9/10 Hacker News (front page)
8 May 16:10
urgent

Mozilla Unveils 271 AI‑Detected Security Fixes for Firefox 150

Patch the 271 bugs identified by Claude Mythos Preview in Firefox 150 and the 149.0.2, 150.0.1, and 150.0.2 releases immediately.

security 9/10 Hacker News (front page)
8 May 15:28
urgent

Dirty Frag Linux Kernel Vulnerability Forces Urgent Patch and Manual Mitigation

Patch the kernel or blacklist esp4, esp6, rxrpc modules to mitigate Dirty Frag before a vendor patch is released.

security 9/10 Bleeping Computer
8 May 11:11
urgent

CVE-2024-3094: xz‑utils Backdoor Threatens OpenSSH via SystemD and IFUNC

Patch OpenSSH to the latest version that removes the SystemD dependency before the next maintenance window.

security 9/10 Hacker News (front page)
8 May 03:48
urgent

Open-OSS/privacy-filter Model Discovered as Malware – Security Alert

Delete the Open‑OSS/privacy‑filter model from your environment, report the malicious code to Hugging Face and Microsoft, and avoid using it.

security 9/10 Reddit r/LocalLLaMA
7 May 21:42
urgent

Fake Claude AI Website Distributes Beagle Windows Malware

Patch: Delete any NOVupdate.exe, NOVupdate.exe.dat, and avk.dll from Startup, block license.claude‑pro.com, and run a full AV scan to remove the Beagle backdoor.

security 9/10 Bleeping Computer
7 May 12:07
urgent

PyPI Packages Discovered Delivering New ZiChatBot Malware

Patch your Python environments by uninstalling the three malicious packages and monitor for ZiChatBot activity.

security 9/10 The Hacker News
7 May 11:32
urgent

vm2 Node.js Library Suffers Dozen Critical Security Vulnerabilities

Patch vm2 to the latest release (v3.0.9) immediately

security 9/10 The Hacker News
7 May 07:05
urgent

Hackers abuse Google ads for GoDaddy ManageWP login phishing

Block the malicious Google Ads result for the 'managewp' query and verify that your ManageWP login redirects to the official domain, preventing credential theft.

security 9/10 Bleeping Computer
6 May 23:41
urgent

Slider Revolution 7.0.0-7.0.10 Vulnerability (CVE-2026-6692) – Authenticated Arbitrary File Upload and RCE

Patch Slider Revolution to 7.0.11 immediately to mitigate CVE-2026-6692 and prevent authenticated RCE.

security 9/10 Wordfence Blog
6 May 20:29
urgent

New Cisco DoS flaw requires manual reboot to revive devices

Upgrade CNC to 7.2 or later and NSO to 6.5 or later to patch CVE‑2026‑20188 and eliminate the DoS risk.

security 9/10 Bleeping Computer
6 May 20:19
urgent

Palo Alto Networks Warns of Firewall RCE Zero‑Day Exploited in Attacks

Check your firewall configuration and restrict or disable the User‑ID Authentication Portal until a patch is released.

security 9/10 Bleeping Computer
6 May 12:55
urgent

CloudZ RAT and Undocumented Pheno Plugin Used in Credential Theft Intrusion

Patch or remove the Pheno plugin immediately and monitor for CloudZ RAT activity.

security 9/10 The Hacker News
6 May 12:00
urgent

Disc Soft Limited Issues Malware‑Free DAEMON Tools Version After Supply‑Chain Breach

Remove the trojanized DAEMON Tools installers and run a full malware scan to eliminate the embedded backdoor.

security 9/10 Bleeping Computer
5 May 22:57
urgent

Critical Arbitrary File Upload Vulnerability in Breeze Cache Plugin (CVE-2026-3844)

Patch Breeze Cache to 2.4.5 immediately to eliminate the arbitrary file upload flaw.

security 9/10 Wordfence Blog
5 May 20:16
urgent

AI Agent Deletes Production Database: A Wake‑Up Call for API Security

Patch: restrict any public API endpoints that allow destructive actions, enforce RBAC, add audit logging, and run security scans.

security 9/10 Hacker News (front page)
5 May 19:51
urgent

Instagram Encrypted Messaging Ends on Friday, May 8

Disable end‑to‑end encryption for Instagram DMs by May 8, 2026; update any integrations that rely on encrypted messages.

security 9/10 Hacker News (front page)
5 May 19:40
urgent

CVE‑2026‑31431 “Copy Fail” Lets Unprivileged Users Escalate to Root in Rootless Containers

Patch kernel to 6.19.12 or later to mitigate CVE-2026-31431.

security 9/10 Hacker News (front page)
5 May 15:01
urgent

Weaver E-cology 10.0 RCE Vulnerability (CVE-2026-22679) Actively Exploited

Patch Weaver E-cology to version 20260312 or later immediately to eliminate the unauthenticated RCE vulnerability (CVE-2026-22679).

security 9/10 The Hacker News
5 May 11:30
urgent

Critical Security Incident Misclassification Due to Scikit‑Learn 1.5 Update

Re‑train the incident classifier with balanced data and pin scikit‑learn 1.4 to avoid the KMeans n_init change.

security 9/10 Dev.to (top)
5 May 10:47
urgent

Chrome silently installs 4 GB Gemini Nano AI model without user consent

Disable the OnDeviceModelBackgroundDownload flag in Chrome to stop silent Gemini Nano downloads.

security 9/10 Hacker News (front page)
5 May 10:28
urgent

WannaCry Ransomware: EternalBlue Exploit and the Importance of Patching

Patch all Windows machines with MS17‑010, disable SMBv1, enable firewall, and monitor for the kill‑switch domain to block new infections.

security 9/10 Dev.to (top)
5 May 10:14
urgent

Automated Exfiltration Bot: RCE via Persistent Jupyter Kernel and Prompt Injection

Replace persistent Jupyter kernels with one‑shot Kamikaze kernels using Docker + gVisor to prevent RCE.

security 9/10 Dev.to (top)
5 May 02:40
urgent

Weaver E-cology 10.0 Suffers Critical Remote Code Execution Bug

Patch Weaver E‑Cology 10.0 to build 20260312 immediately to eliminate the exposed debug endpoint and stop RCE.

security 9/10 Bleeping Computer
5 May 00:16
urgent

Gravity SMTP Security Breach CVE‑2026‑4020 Exposes API Keys

Patch Gravity SMTP to version 2.1.5 or later immediately to fix CVE‑2026‑4020 and rotate any exposed API keys.

security 9/10 Reddit r/WordPress
4 May 23:03
urgent

Nix and Lix Buffer Overflow Vulnerabilities Allow Local Code Execution as Root

Patch Nix and Lix to fix buffer overflows in daemons and prevent local code execution as root.

security 9/10 Lobste.rs
4 May 23:02
urgent

Comprehensive CVE Analysis of Package Managers Reveals Path Traversal, Injection, and Credential Leakage Vulnerabilities

Patch package managers to enforce path sanitisation, use '--' separator, and verify signatures.

security 9/10 Lobste.rs
4 May 23:01
urgent

Prompt Injection Attacks Against OopsSec Store’s AI Assistant

Patch the AI assistant to remove regex blocklist and add output filtering to prevent secret leakage.

security 9/10 Dev.to (top)
4 May 21:05
urgent

Critical cPanel Vulnerability Exploited by Hackers, Prompting Urgent Patch

Patch cPanel immediately to stop exploitation.

security 9/10 The Hacker News
4 May 17:57
urgent

CISA Adds ConnectWise ScreenConnect and Microsoft Windows Vulnerabilities to KEV Catalog

Patch: update ConnectWise ScreenConnect to the latest version to fix CVE‑2024‑1708.

security 9/10 The Hacker News
4 May 17:50
urgent

Atos Threat Research Center Identifies Campaign Targeting High-Privilege Accounts

Patch: enforce MFA for all high‑privilege accounts to mitigate impersonation attacks.

security 9/10 The Hacker News
4 May 17:49
urgent

Google Ads API v20 Sunset – Upgrade Required

Upgrade to a newer Google Ads API version before June 10 2026 to avoid service disruption.

ads 9/10 Search Engine Land
4 May 17:38
urgent

Google Search Console Logging Error Resolved After 50‑Week Gap

Check Search Console performance reports for missing impressions between May 13 2025 and April 27 2026.

seo 9/10 Search Engine Land
4 May 17:38
urgent

Mozilla Uses Anthropic’s Claude Mythos to Patch 271 Firefox Vulnerabilities

Patch to Firefox 150, examine the 271 vulnerability fixes, and update your security tooling to detect similar AI‑generated vulnerabilities.

security 9/10 Schneier on Security
4 May 15:39
urgent

GitHub Vulnerability CVE-2026-3854 Enables Remote Code Execution via git push

Patch GitHub to the latest version or apply the security advisory immediately.

security 9/10 The Hacker News
4 May 15:31
urgent

Wordfence Reports 87 New WordPress Vulnerabilities in April 2026

Patch all WordPress core, plugins, and themes listed in the Sucuri roundup to mitigate CVEs.

security 9/10 Sucuri Blog
4 May 15:27
urgent

Injective Labs SDK Compromised: Malicious npm Package Steals Crypto Wallet Keys

Remove the compromised @injectivelabs/sdk‑[email protected] package and audit your npm dependencies for malicious code.

security 8/10 The Hacker News
15 Jul 12:22
urgent

XQUIC XRING Vulnerability Lets Remote Clients Crash Alibaba's QUIC Library with Legal Traffic

Avoid using XQUIC or apply a workaround to prevent remote crash via XRING until a patch is released.

security 8/10 The Hacker News
15 Jul 12:21
urgent

RabbitMQ Access Control Flaws Could Leak OAuth Secrets and Bypass Tenant Boundaries

Patch RabbitMQ to the latest version that fixes the OAuth client secret leakage and tenant boundary bypass.

security 8/10 The Hacker News
15 Jul 12:21
urgent

Tailscale Serves Two Critical Vulnerabilities Fixed in 1.98.9

Patch Tailscale to 1.98.9 or newer to fix CPU core denial of service and SSH root access.

security 8/10 Hacker News (front page)
15 Jul 12:17
urgent

LabubaRAT: Rust‑Based RAT Masquerading as NVIDIA Software

Run endpoint detection to identify LabubaRAT binaries, quarantine them, and enforce strict code signing and integrity checks.

security 8/10 The Hacker News
15 Jul 12:07
urgent

Free VPN Apps on Google Play Failing Basic Privacy Tests

Audit VPN integrations to ensure traffic is routed through the VPN tunnel and replace any apps that leak traffic.

security 8/10 The Hacker News
15 Jul 12:07
urgent

Friendly Fire: AI Coding Agents May Execute Attacker Code on Host Machine

Patch or disable autonomous mode in Claude Code and OpenAI Codex, and restrict code execution permissions for AI coding agents.

security 8/10 The Hacker News
15 Jul 12:07
urgent

Coinspect Exposes Ill Bloom Wallet Recovery Phrase Flaw

Update wallet software to use cryptographically secure random generators for recovery phrases and re‑generate phrases for affected users.

security 8/10 The Hacker News
15 Jul 12:07
urgent

Browser Extension Vulnerability Lets Rogue Scripts Trigger Claude for Chrome Tasks

Disable or remove any rogue browser extensions that can run scripts on claude.ai and update the Claude for Chrome extension to the latest patched version.

security 8/10 The Hacker News
15 Jul 12:07
urgent

Datadog Warns of GitHub Enumeration Campaigns Using API

Rotate all GitHub tokens, enforce least‑privilege scopes, enable audit logs, and monitor for automated scraping activity.

security 8/10 The Hacker News
15 Jul 12:07
urgent

OAuth Client ID Spoofing Used to Evade Telemetry in Microsoft Entra ID

Enforce strict client ID validation in Microsoft Entra ID to block OAuth client ID spoofing attacks.

security 8/10 The Hacker News
15 Jul 12:05
urgent

Progress Software Advises ShareFile Customers to Shut Down Storage Zone Controllers Amid Credible Threat

Shut down ShareFile Storage Zone Controller Windows servers immediately to mitigate the credible external threat.

security 8/10 The Hacker News
15 Jul 12:05
urgent

CISA Postmortem Reveals Six‑Month Leak of AWS GovCloud Credentials

Implement continuous secret scanning and improve reporting channels to reduce exposure time.

security 8/10 Krebs on Security
15 Jul 12:02
urgent

KrebsOnSecurity Exposes IRIS C2, a Startup Selling Zero‑Day Exploits to Governments

Notify your security team of the IRIS C2 threat and review zero‑day exposure risk.

security 8/10 Krebs on Security
15 Jul 12:02
urgent

Shop Order‑Tracking App Abuse Fuels Callback Phishing Attacks

Notify users to ignore any receipt they did not place and verify charges directly with their bank; do not call the phone number listed.

security 8/10 Bleeping Computer
25 Jun 21:51
urgent

Rust-based macOS Implant Gaslight Tricks AI Analysis Tools with Prompt Injection

Patch your AI analysis tools to detect prompt injection payloads in Rust-based macOS implants.

security 8/10 The Hacker News
25 Jun 21:29
urgent

Malicious Edge extension abuses Native Messaging as bridge to malware

Disable suspicious Edge extensions, block native messaging hosts, and monitor for malicious ZIP files.

security 8/10 Bleeping Computer
25 Jun 21:08
urgent

AryStinger Malware Turns Home Routers into Reconnaissance Network

Block AryStinger traffic from infected routers.

security 8/10 The Hacker News
25 Jun 21:05
urgent

Salesforce Disables Klue Battlecards Integration After Security Incident

Disable the Klue Battlecards integration until Salesforce resolves the security incident.

security 8/10 The Hacker News
25 Jun 21:04
urgent

Gentlemen RaaS Releases EDR-Killing Tools to Disable Security Defenses

Patch or disable EDR killers from Gentlemen RaaS to prevent system defense impairment.

security 8/10 The Hacker News
25 Jun 21:04
urgent

Malicious NPM Packages Deliver Windows RAT, Researchers Warn

Patch or remove the malicious npm packages aes-decode-runner-pro, postcss-minify-selector, and postcss-minify-selector-parser to prevent RAT delivery.

security 8/10 The Hacker News
25 Jun 21:04
urgent

New Stealthy Backdoor 'Mistic' Deployed in Financially Motivated Attacks

Patch any exposed systems that might have been compromised by the Mistic backdoor.

security 8/10 The Hacker News
25 Jun 21:04
urgent

Cisco Catalyst SD‑WAN Zero‑Day Exploited Before Public Disclosure

Patch Cisco Catalyst SD‑WAN firmware to the latest version that fixes CVE‑2026‑20245.

security 8/10 The Hacker News
25 Jun 21:02
urgent

Adblock for YouTube Chrome Extension Vulnerable to Arbitrary JavaScript Execution

Disable or uninstall the Adblock for YouTube extension and replace it with a vetted alternative to eliminate arbitrary JavaScript execution.

security 8/10 The Hacker News
25 Jun 21:00
urgent

TrapDoor Supply Chain Attack Distributes Credential-Stealing Malware Across Ecosystems

Audit all packages for TrapDoor malware and remove infected ones.

security 8/10 The Hacker News
29 May 20:54
urgent

Malicious npm Package Mouse5212-Super-Formatter Steals Claude AI Data

Remove mouse5212-super-formatter and audit dependencies for malicious code.

security 8/10 The Hacker News
29 May 20:54
urgent

Ghost CMS CVE-2026-26980 Allows SQL Injection and Malicious JS Injection

Patch Ghost CMS to fix CVE-2026-26980 immediately.

security 8/10 The Hacker News
29 May 20:54
urgent

Fortinet FortiClient EMS flaw used to push credential‑stealing malware

Patch FortiClient EMS immediately to stop credential-stealing attacks.

security 8/10 The Hacker News
29 May 20:54
urgent

Unpatched Gogs Vulnerability Lets Authenticated Users Execute Remote Code

Patch Gogs to the latest version to eliminate the RCE vulnerability.

security 8/10 The Hacker News
29 May 20:54
urgent

Microsoft Warns of AI-Driven Cryptojacking Campaign

Block AI chatbot interactions that trigger cryptojacking downloads.

security 8/10 The Hacker News
29 May 20:54
urgent

CISA Adds CVE-2026-9082 to KEV Catalog for Drupal Core

Patch Drupal Core immediately to the latest version that includes CVE-2026-9082 to stop active exploitation.

security 8/10 The Hacker News
29 May 20:54
urgent

California AG sues 23andMe over 2023 breach exposing health data

Patch Salesforce and other systems to prevent credential stuffing, enforce MFA, review code for errors, and monitor for suspicious activity.

security 8/10 Bleeping Computer
29 May 20:35
urgent

Packagist Supply‑Chain Attack Targets Eight Composer Packages with Malicious Linux Binary

Patch: Scan Composer packages for malicious package.json entries that download binaries from GitHub Releases, and replace or remove affected packages.

security 8/10 The Hacker News
29 May 20:33
urgent

Banking Trojan Campaigns Targeting Latin America and Europe with Grandoreiro and BTMOB

Patch: Update antivirus signatures to block Grandoreiro and BTMOB on Windows and Android endpoints, and monitor for banking trojan activity in Spain, Portugal, Mexico, and Brazil.

security 8/10 The Hacker News
29 May 20:33
urgent

MFA Security Gap: Attackers Exploit User Cooperation

Patch MFA workflows to enforce device‑based second factors and educate users to avoid phishing.

security 8/10 The Hacker News
29 May 20:32
urgent

CrowdStrike, Google, and Shadowserver Disrupt GlassWorm Command‑and‑Control Channels

Block GlassWorm C2 domains and monitor for related malware on your network.

security 8/10 The Hacker News
29 May 20:28
urgent

Malicious NuGet Package Sicoob.Sdk Exfiltrates Client IDs and PFX Certificates

Remove or replace the compromised Sicoob.Sdk package and revoke exposed PFX certificates.

security 8/10 The Hacker News
29 May 20:28
urgent

Supply Chain Attack Targets Multiple Laravel-Lang PHP Packages

Patch all laravel‑lang packages to the latest secure versions and audit dependencies for similar supply‑chain vulnerabilities.

security 8/10 The Hacker News
29 May 20:28
urgent

Dutch Authorities Arrest Hosting Company Co‑Owners Linked to Russia‑Backed Cyberattacks

Patch your hosting infrastructure to remove any connections to sanctioned entities and verify compliance with EU sanctions.

security 8/10 Krebs on Security
29 May 20:25
urgent

Google Announces May 2026 Core Update Rollout

Check your site's content relevance signals and update any low‑quality pages before the update fully rolls out.

seo 8/10 Search Engine Roundtable
22 May 03:39
urgent

Exploit released for new PinTheft Arch Linux root escalation flaw

Patch the kernel to the latest version or apply the rds module mitigation immediately.

security 8/10 Bleeping Computer
22 May 03:25
urgent

PoC Exploit Released for DirtyDecrypt Linux Kernel Vulnerability

Patch the kernel to the latest version that fixes DirtyDecrypt immediately to stop the PoC exploit.

security 8/10 The Hacker News
22 May 01:49
urgent

Microsoft Issues Patches for Two Exploited Defender Vulnerabilities

Patch Microsoft Defender to the latest update immediately.

security 8/10 The Hacker News
22 May 00:13
urgent

Max severity Cisco Secure Workload flaw gives Site Admin privileges

Upgrade Secure Workload to release 3.10.8.3 or 4.0.3.17 and confirm API authentication is enforced.

security 8/10 Bleeping Computer
22 May 00:00
urgent

GitHub Actions Workflow Compromised: actions-cool/issues-helper Harvests Credentials

Delete the compromised actions-cool/issues-helper workflow and replace it with a trusted version or custom action.

security 8/10 The Hacker News
21 May 23:58
urgent

Drupal Issues Urgent Core Security Update for May 20, Advises Immediate Action

Reserve time and apply the Drupal core security update on 20 May 2026 before 5‑9 UTC.

security 8/10 The Hacker News
21 May 23:56
urgent

Microsoft Disrupts Malware‑Signing‑as‑a‑Service Operation Using Artifact Signing

Verify the integrity of signed binaries and monitor for unauthorized signing certificates.

security 8/10 The Hacker News
21 May 23:54
urgent

Compromised Nx Console Extension v18.95.0 Flagged by Researchers

Patch or uninstall the rwl.angular-console v18.95.0 extension immediately to stop the malicious code from running.

security 8/10 The Hacker News
21 May 23:53
urgent

Google Launches May 2026 Core Update, Rolling Out Over Two Weeks

Monitor rankings and audit content quality during the May 2026 core update rollout, ensuring your pages remain helpful and people‑first.

seo 8/10 Search Engine Land
21 May 23:27
urgent

CISA Contractor’s GitHub Repo Exposes AWS GovCloud Credentials

Revoke all exposed AWS GovCloud credentials and enable GitHub secret scanning for all repositories.

security 8/10 Krebs on Security
21 May 23:13
urgent

OpenAI Reports Mini Shai-Hulud Impact on Employee Devices via TanStack

Patch your internal systems to detect and isolate any compromised TanStack packages and ensure employee devices are scanned for malware.

security 8/10 The Hacker News
18 May 14:09
urgent

Supply Chain Attackers Target Secrets in npm, PyPI, and Docker Hub

Patch your CI/CD pipelines to enforce secret scanning and rotate exposed credentials immediately.

security 8/10 The Hacker News
18 May 14:09
urgent

Ivanti Xtraction CVE-2026-8043 Vulnerability Fixed in Latest Security Patch

Patch Ivanti Xtraction to fix CVE-2026-8043 and other vendor fixes.

security 8/10 The Hacker News
18 May 13:47
urgent

Exim MTA Security Update Addresses CVE-2026-45185 Memory Corruption Vulnerability

Apply the Exim security patch to fix CVE-2026-45185.

security 8/10 The Hacker News
18 May 13:46
urgent

OpenAI Employee Devices Compromised in TanStack Supply‑Chain Attack

Patch OpenAI macOS apps to the latest version before June 12 to eliminate the supply‑chain vulnerability.

security 8/10 OpenAI Blog
18 May 13:31
urgent

Microsoft backpedals: Edge to stop loading passwords into memory

Patch: Upgrade all Edge installations to build 148 or newer to stop passwords from loading into memory at startup.

security 8/10 Bleeping Computer
18 May 13:24
urgent

MiniPlasma Windows Zero‑Day PoC Gives Attackers SYSTEM Access on Patched Systems

Patch Windows to the latest cumulative update and verify cldflt.sys is updated to close the MiniPlasma flaw.

security 8/10 Bleeping Computer
18 May 13:22
urgent

Windows 11 Update KB5089549 Fails to Install on Devices with Low ESP Space

Apply the Known Issue Rollback group policy to affected devices and restart to mitigate the ESP space issue.

security 8/10 Bleeping Computer
18 May 13:22
urgent

Node‑ipc Found to Contain Malicious Activity in Multiple Versions

Remove node‑ipc from your dependencies and replace it with a vetted alternative; run a security audit.

security 8/10 The Hacker News
18 May 13:19
urgent

Four npm Packages Discovered Containing Malware, Including a Shai‑Hulud Clone

Remove these malicious packages from your dependencies and replace them with vetted alternatives; run npm audit.

security 8/10 The Hacker News
18 May 13:19
urgent

Instructure settles with cyber‑extortion group after Canvas network breach

Patch Canvas to the latest release, disable Free‑for‑Teacher accounts, and audit for XSS.

security 8/10 Bleeping Computer
18 May 13:10
urgent

Hackers abuse Google ads, Claude.ai chats to push Mac malware

Block malicious Claude.ai shared chat links in Google Ads and monitor for terminal command instructions.

security 8/10 Bleeping Computer
11 May 20:19
urgent

Fake OpenAI “Privacy Filter” Repo on Hugging Face Distributes Malware, Hits 244 k Downloads

Remove the malicious Open‑OSS/privacy‑filter repository from your Hugging Face account and audit all imported models for malicious code.

security 8/10 The Hacker News
11 May 19:33
urgent

NVIDIA confirms GeForce NOW data breach affecting Armenian users

Notify affected users and review authentication logs for suspicious activity.

security 8/10 Bleeping Computer
9 May 00:01
urgent

Wordfence Weekly Vulnerability Report: 87 New Vulnerabilities in WordPress Plugins and Themes

Check the Wordfence Intelligence vulnerability feed for the 87 newly disclosed vulnerabilities and update any affected plugins or themes.

security 8/10 Wordfence Blog
8 May 23:55
urgent

QLNX: Undocumented Linux RAT Targets Developers and DevOps Credentials

Deploy updated antivirus signatures and monitor for QLNX activity; isolate affected systems immediately.

security 8/10 The Hacker News
8 May 15:17
urgent

Canvas Outage: ShinyHunters Threaten to Leak Data of 275 Million Students

Patch the Canvas login page to remove defacement and verify authentication flow.

security 8/10 Krebs on Security
8 May 06:53
urgent

Australia warns of ClickFix attacks pushing Vidar Stealer malware

Patch WordPress themes, plugins, and remove unused components; restrict PowerShell execution and enable application allow‑listing to stop ClickFix attacks.

security 8/10 Bleeping Computer
7 May 20:37
urgent

New Credential‑Theft Framework PCPJack Targets Exposed Cloud Infrastructure

Detect and block PCPJack activity by monitoring for credential harvesting patterns and exfiltration traffic.

security 8/10 The Hacker News
7 May 20:36
urgent

Ivanti EPMM Zero-Day RCE Exploited, Federal Agencies Urged to Patch

Patch Ivanti Endpoint Manager Mobile to version 12.6.1.1 or later to fix CVE‑2026‑6973.

security 8/10 The Hacker News
7 May 20:36
urgent

Cloudflare Responds to Linux "Copy Fail" CVE‑2026‑31431

Patch the kernel to the latest LTS (6.18) and deploy the bpf‑lsm mitigation immediately.

security 8/10 Hacker News (front page)
7 May 16:22
urgent

MuddyWater Linked to Ransomware Attack Using Microsoft Teams, Rapid7 Reports

Patch Microsoft Teams to block malicious links, enable MFA, and monitor Teams traffic for phishing.

security 8/10 The Hacker News
7 May 12:01
urgent

ADT says customer data stolen in cyber intrusion

Patch ADT's exposed endpoints and enforce MFA on admin accounts.

security 8/10 Hacker News (front page)
7 May 03:35
urgent

DAEMON Tools Supply‑Chain Breach: Trojans in Free Lite Version

Patch all installations of DAEMON Tools Lite 12.5.1 by uninstalling, scanning, and installing 12.6.0.2445 from the official site.

security 8/10 Bleeping Computer
6 May 23:11
urgent

Hunt.io Exposes Mirai‑Derived xlabs_v1 Botnet Targeting ADB‑Exposed Devices

Patch or secure Android Debug Bridge on all devices to prevent enlistment in the xlabs_v1 Mirai‑derived botnet.

security 8/10 The Hacker News
6 May 22:51
urgent

Critical vm2 Sandbox Bug Lets Attackers Execute Code on Hosts

Patch vm2 to 3.10.5 or later immediately to prevent arbitrary host code execution.

security 8/10 Bleeping Computer
6 May 20:49
urgent

DENIC DNSSEC Misconfiguration Causes .de SERVFAIL Outage, Cloudflare Mitigates with Override Rule

Configure your DNS resolver to treat .de as an insecure zone using an override rule to bypass DNSSEC validation during the outage.

security 8/10 Cloudflare Blog
6 May 20:46
urgent

WP Engine Blocks AI Crawlers, Causing 429 Errors for ClaudeBot and Others

Patch WP Engine firewall rules to whitelist current AI crawler UAs (ClaudeBot, GPTBot, Amazonbot) and remove outdated blocklist entries.

security 8/10 Search Engine Land
6 May 15:39
urgent

CVE-2026-31431 Public Notifications Vulnerability in theori-io Plugin

Patch the theori‑io plugin immediately by applying the latest release or the provided patch to enforce authentication on notification settings.

security 8/10 Hacker News (front page)
6 May 11:13
urgent

Palo Alto Vulnerability CVE-2026-0300 Exploited for a Month

Patch PAN‑OS to the latest version that fixes CVE‑2026‑0300 immediately.

security 8/10 The Hacker News
6 May 09:30
urgent

New Quasar Linux RAT Targets Developers with Stealthy Credential Theft

Patch: Immediately audit all development machines for LD_PRELOAD usage, remove unauthorized PAM modules, and apply security patches to kernel and userland libraries.

security 8/10 Bleeping Computer
6 May 00:08
urgent

Apache HTTP Server Security Update Addresses CVE-2026-23918 RCE Vulnerability

Patch Apache HTTP Server to the latest security release (2.5.70) immediately and verify HTTP/2 handling.

security 8/10 The Hacker News
5 May 19:29
urgent

ScarCruft Compromises Video Game Platform with BirdCallto Backdoor

Patch any compromised components and monitor for BirdCallto activity to mitigate the active supply‑chain threat.

security 8/10 The Hacker News
5 May 12:02
urgent

cPanel Patch Halts Mass Ransomware Attack on 44,000 Servers

Apply the WHM/cPanel emergency update immediately to fix CVE-2026-41940 and stop the Sorry ransomware spread.

security 8/10 Bleeping Computer
5 May 05:42
urgent

Fixing LangChain Serialization Regression with Automated Pytest

Upgrade LangChain to 0.1.0, adjust serialization logic, add pytest suite with FakeRedis to catch regressions.

ai-dev 8/10 Dev.to (top)
5 May 03:40
urgent

Invisible Newsletter Breach: Zero-Click Prompt Injection Exposes Email Assistant

Patch your email ingestion pipeline to sanitize incoming HTML and strip invisible text vectors before passing to the LLM.

security 8/10 Dev.to (top)
5 May 02:39
urgent

VeriSigil AI: SSL‑Like Cryptographic Identity for Autonomous Agents

Call the issue‑test endpoint to obtain a test passport and verify your agent with the verify endpoint.

security 8/10 Dev.to (top)
5 May 01:24
urgent

Progress warns of critical MOVEit Automation auth bypass flaw

Patch all MOVEit Automation instances to the latest version before the outage window.

security 8/10 Bleeping Computer
4 May 23:24
urgent

Microsoft Defender wrongly flags DigiCert certs as Trojan:Win32/Cerdigent.A!dha

Patch Microsoft Defender to Security Intelligence version 1.449.430.0 or later to restore removed DigiCert root certificates.

security 8/10 Bleeping Computer
4 May 23:06
urgent

Phishing Scam Targeting WordPress Agencies via Fake Google OAuth

Notify all agencies to avoid clicking the fake Google OAuth link and do not send credentials.

security 8/10 Reddit r/WordPress
4 May 23:03
urgent

Canonical Switch to uutils Coreutils and CVE Audit

Patch uutils coreutils to a fixed version or replace with GNU coreutils to avoid CVEs.

security 8/10 Lobste.rs
4 May 23:00
urgent

Accidental Exposure of Entire Website Source Code via Python HTTP Server

Patch: Immediately stop the accidental HTTP server, close port 80, apply firewall rules, verify no other services are exposed, and review server configuration.

security 8/10 Reddit r/webdev
4 May 21:44
urgent

Phishing Campaign Uses Legitimate RMM Software for Persistent Remote Access

Patch: Enable MFA on all RMM accounts, review access logs, isolate compromised hosts, update RMM software, and notify users of phishing.

security 8/10 The Hacker News
4 May 20:12
urgent

Progress Software Issues Critical MOVEit Authentication Bypass

Install the newest MOVEit Automation security patch to fix the authentication bypass and other critical flaws.

security 8/10 The Hacker News
4 May 19:31
urgent

PyTorch Lightning 2.6.3 Supply‑Chain Attack Steals Credentials

Uninstall malicious Lightning 2.6.2 and 2.6.3 and install the latest secure release.

security 8/10 The Hacker News
4 May 17:53
urgent

VECT 2.0 Acts as Wiper Due to Encryption Flaw

Patch: update antivirus signatures to detect VECT 2.0 and monitor for its activity.

security 8/10 The Hacker News
4 May 17:49
urgent

Malicious Code Found in @validate-sdk/v2 Used by Anthropic’s Claude Opus

Remove @validate-sdk/v2 from dependencies and audit all projects using it.

ai-dev 8/10 The Hacker News
4 May 17:49
urgent

Threat Actors Deploy Custom AI to Automate Active Directory Attacks

Patch your AD monitoring tools to detect rapid credential harvesting by AI agents.

security 8/10 The Hacker News
4 May 17:37
urgent

OpenFang Agent Vulnerability: curl Fetch Leads to Reverse Shell

Patch OpenFang to validate fetched content before execution.

security 8/10 Dev.to (top)
4 May 15:47
urgent

Fast16 State‑Sponsored Malware Targeting Iran

Check for Fast16 signatures, isolate affected networks, and patch any vulnerable software that could be targeted by silent manipulation of high‑precision calculations.

security 8/10 Schneier on Security
4 May 15:38
urgent

Mini Shai-Hulud Campaign Targets SAP-Related npm Packages with Credential-Stealing Malware

Patch affected npm packages, tighten dependency management, and monitor for credential theft.

security 8/10 The Hacker News
4 May 15:32
urgent

BufferZoneCorp Uses Sleeper Packages to Deploy Credential Theft and GitHub Actions Tampering

Patch vulnerable Ruby gems and Go modules, audit GitHub Actions, and monitor for SSH persistence.

security 8/10 The Hacker News
4 May 15:32
urgent

LeRobot Vulnerability CVE-2026-25874 Enables Remote Code Execution via Untrusted Deserialization

Patch LeRobot to the latest version or apply the security advisory immediately.

security 8/10 The Hacker News
4 May 15:31
urgent

Gemini CLI Security Flaw Allows Unprivileged Attacker to Execute Arbitrary Commands

Patch the @google/gemini-cli npm package to the latest version or apply the security advisory immediately.

security 8/10 The Hacker News
4 May 15:31
urgent

Microsoft Entra ID Agent ID Administrator Role Vulnerability Enables Privilege Escalation

Patch Microsoft Entra ID to the latest version or apply the security advisory immediately.

security 8/10 The Hacker News
4 May 15:31
urgent

BerriAI LiteLLM Python Package Vulnerability CVE-2026-42208 Enables SQL Injection

Patch LiteLLM to the latest version or apply the security advisory immediately.

security 8/10 The Hacker News
4 May 15:31
urgent

Wordfence Weekly Vulnerability Report: 157 Vulnerabilities Disclosed Across 122 Plugins and 27 Themes

Patch any affected plugins or themes immediately; check the Wordfence vulnerability database for the 157 disclosed issues.

security 8/10 Wordfence Blog
4 May 15:26
urgent

Researchers Find 11 Microsoft‑Signed UEFI Apps That Can Bypass Secure Boot

Patch or update firmware to remove the 11 vulnerable UEFI applications.

security 7/10 The Hacker News
15 Jul 12:22
urgent

CrashStealer: Native C++ macOS Information Stealer Validates Password Before Theft

Remove or quarantine CrashStealer from macOS systems and update security tools to detect native C++ stealers.

security 7/10 The Hacker News
15 Jul 12:22
urgent

Silver Fox Group Uses Rust‑Based MODBEACON RAR to Deploy Counterfeit Installers via SEO Poisoning

Block downloads from suspicious installers and monitor for MODBEACON signatures in your environment.

security 7/10 The Hacker News
15 Jul 12:21
urgent

148 npm Packages Turn Browsers into DDoS Botnet via Student Proxy Scam

Remove the compromised npm packages and audit your dependencies to prevent botnet infection.

security 7/10 The Hacker News
15 Jul 12:21
urgent

Sustained Cyber‑Espionage Against Pakistani Law Enforcement by China‑ and India‑Aligned Actors

Perform a comprehensive security assessment of all web applications, enforce least‑privilege access, enable MFA, and monitor logs for suspicious activity.

security 7/10 The Hacker News
15 Jul 12:07
urgent

Compromised @asyncapi npm Packages Distribute Multi‑Stage Botnet Loader

Patch all @asyncapi packages to the latest safe releases immediately and audit your dependency tree for other compromised packages.

security 7/10 The Hacker News
15 Jul 12:07
urgent

WordPress Org Hardens GitHub Actions Workflows Against Supply‑Chain Attacks

Patch all WordPress org repositories by merging the hardening PRs, enabling Actionlint and Zizmor, and reviewing workflow permissions.

security 7/10 Make WordPress Core
15 Jul 11:57
urgent

New macOS malware tricks AI scanners with fake error comments

Scan for Gaslight binaries, update macOS, monitor for fake error strings, and use AI analysis tools with caution.

security 7/10 Bleeping Computer
25 Jun 21:08
urgent

Bluekit phishing kit adopts browser-in-the-middle for login theft

Block rrweb scripts, monitor for BitM patterns, enforce MFA, and review phishing templates.

security 7/10 Bleeping Computer
25 Jun 21:08
urgent

Four Vulnerabilities in Dify Allow Unauthenticated Read of AI Conversions

Patch Dify to the latest release that resolves the DifyTap vulnerabilities.

security 7/10 The Hacker News
25 Jun 21:02
urgent

WhatsApp DM Campaign Distributes VBScript to Install Legitimate RMM Software

Block VBScript file downloads from WhatsApp and scan for installed RMM software to mitigate the campaign.

security 7/10 The Hacker News
25 Jun 21:00
urgent

New CastleStealer Campaign Uses OXLOADER Loader via Malicious Google Ads

Block malicious Google Ads and monitor for OXLOADER signatures to stop CastleStealer distribution.

security 7/10 The Hacker News
25 Jun 21:00
urgent

Recruitment‑Themed Phishing Targets Crypto Firms with Custom macOS Malware

Block recruitment‑themed phishing and harden macOS endpoints to defend against targeted cryptocurrency attacks.

security 7/10 The Hacker News
29 May 20:32
urgent

Linux Kernel CVE-2026-46333: 9-Year-Old Privilege Escalation Flaw Exposed

Patch the Linux kernel to the latest version that contains the CVE-2026-46333 fix.

security 7/10 The Hacker News
22 May 01:56
urgent

GitHub links repo breach to TanStack npm supply‑chain attack

Patch all GitHub repositories by rotating secrets and monitoring for unauthorized access after the Nx Console 18.95.0 compromise.

security 7/10 Bleeping Computer
22 May 01:34
urgent

EvilTokens Phishing-as-a-Service Compromises 340 Microsoft 365 Organizations in Five Weeks

Patch your MFA flow to reject device login requests that contain short codes and verify the request source.

security 7/10 The Hacker News
22 May 01:33
urgent

Microsoft Issues Mitigation for YellowKey BitLocker Bypass Exploit

Apply the Microsoft BitLocker mitigation immediately.

security 7/10 The Hacker News
22 May 00:15
urgent

Hackers bypass SonicWall VPN MFA due to incomplete patching

Update Gen6 SonicWall firmware, delete LDAP config, reboot, and recreate LDAP without userPrincipalName to block MFA bypass.

security 7/10 Bleeping Computer
21 May 23:59
urgent

GitHub Investigates Unauthorized Access to Internal Repositories After TeamPCP Sale Listing

Audit internal repository permissions and enable two‑factor authentication for all users.

security 7/10 The Hacker News
21 May 23:53
urgent

Supply‑Chain Attacks Exploit Mail‑Server Flaw, Poison Packages, and Deliver Stealers

Audit all dependencies for known vulnerabilities and remove any that expose secrets.

security 7/10 The Hacker News
21 May 23:53
urgent

OpenClaw Vulnerabilities Form Claw Chain for Data Theft and Persistence

Patch OpenClaw to close the Claw Chain vulnerabilities.

security 7/10 The Hacker News
18 May 13:47
urgent

PraisonAI Vulnerability CVE-2026-44338 Exploited Within Hours of Disclosure

Patch PraisonAI to address CVE-2026-44338 and secure sensitive endpoints.

security 7/10 The Hacker News
18 May 13:46
urgent

Microsoft Claims Silent Fix for Azure Backup for AKS Vulnerability

Check Azure Backup for AKS logs for silent patch application and verify no unexpected changes.

security 7/10 Bleeping Computer
18 May 13:22
urgent

TrickMo Android banker adopts TON blockchain for covert comms

Ensure Android devices only install apps from Google Play, limit app count, enable Play Protect, and monitor for TrickMo.C signatures.

security 7/10 Bleeping Computer
11 May 20:20
urgent

Dirty Frag: Unpatched Local Privilege Escalation Vulnerability in Linux Kernel

Patch all Linux systems to the latest kernel version that addresses Dirty Frag before exploitation.

security 7/10 The Hacker News
8 May 15:38
urgent

Kaspersky Finds Supply‑Chain Attack on DAEMON Tools Installers

Patch: Verify installer signatures and update to the latest DAEMON Tools version to mitigate the supply chain attack.

security 7/10 The Hacker News
6 May 01:01
urgent

Persistent OAuth Tokens Without Expiration Pose Major Security Risk

Disable or rotate all long‑lived OAuth tokens and enforce expiration policies.

security 7/10 The Hacker News
5 May 14:55
urgent

MetInfo CMS Vulnerability CVE-2026-29014 Allows Arbitrary Code Execution

Patch MetInfo to the latest release (8.2+) immediately.

security 7/10 The Hacker News
5 May 14:54
urgent

CloudZ RAT exploits Microsoft Phone Link to steal SMS and OTPs

Disable Microsoft Phone Link on all Windows machines, enforce hardware‑based MFA, and block CloudZ RAT traffic.

security 7/10 Bleeping Computer
5 May 12:11
urgent

Backdoored PyTorch Lightning package drops credential stealer

Rotate all secrets, avoid importing PyTorch Lightning 2.6.3, and use version 2.6.1 until the audit completes.

security 7/10 Bleeping Computer
4 May 23:47
urgent

cPanel Security Crisis: Multiple Exploits Prompt Emergency Patches and Ransomware Attack

Apply the latest cPanel and WHM security update immediately.

security 7/10 The Hacker News
4 May 20:47
urgent

17-Year-Old Arrested for Extracting Personal Data of 7 Million Kaikatsu Club Users

Notify affected users and report the breach to authorities.

security 7/10 The Hacker News
4 May 17:49
urgent

Checkmarx Supply Chain Attack Leak Exposes GitHub Repository Data

Patch repository access controls, audit credentials, and notify stakeholders immediately.

security 7/10 The Hacker News
4 May 15:32
urgent

Microsoft Windows Shell Vulnerability CVE-2026-32202 Patched but Actively Exploited

Apply the latest Windows security patch that includes CVE-2026-32202.

security 7/10 The Hacker News
4 May 15:31
urgent

AI Assistant Memory Injection via Email Can Rewrite User Facts

Patch your AI assistant to prevent email-based memory injection that can rewrite user facts.

security 6/10 The Hacker News
15 Jul 12:21
urgent

Microsoft Zero-Day Saga: Six Windows Vulnerabilities, Three Exploited, July 14 Threat

Patch all Windows systems against the six zero‑days, prioritising the three actively exploited ones (BlueHammer, RedSun, UnDefend) and YellowKey (CVE‑2026‑45585), and audit your vulnerability management to ensure coordinated disclosure.

security 6/10 Hacker News (front page)
29 May 23:32
urgent

Grafana source‑code theft after stolen GitHub token and supply‑chain breach

Verify Grafana GitHub tokens and rotate them immediately.

security 6/10 The Hacker News
18 May 13:47
urgent

New Rowhammer Attacks Grant Full Control Over NVIDIA GPUs and Host CPUs

Enable IOMMU in BIOS and apply NVIDIA firmware patches to mitigate rowhammer vulnerabilities.

security 6/10 Schneier on Security
6 May 12:43
urgent

LinkedIn Faces GDPR Complaint Over Paid Profile‑Visitor Data

Notify your legal team to examine LinkedIn's data handling and prepare a compliance audit.

social 6/10 Hacker News (front page)
5 May 11:31
urgent

ScarCruft’s BirdCall Backdoor Targets Ethnic Koreans in China via Game Platform Supply‑Chain Attack

Block installation of apps from sqgame.net and enforce downloads only from official marketplaces.

security 6/10 Bleeping Computer
5 May 11:24
urgent

Instructure’s Canvas faces 275‑million‑record data breach and defacement by ShinyHunters

Investigate the Instructure incident, monitor Canvas Data 2 and Canvas Beta for API key issues, and keep clients informed of potential data exposure.

security 6/10 Bleeping Computer
4 May 23:06
urgent

AccountDumpling: Vietnamese-Linked Operation Uses Google AppSheet as Phishing Relay

Check for phishing emails sent via Google AppSheet and advise users to enable 2FA on Facebook.

security 6/10 The Hacker News
4 May 17:48
urgent

Linux kernel “Copy Fail” and “Dirty Frag” flaws give attackers root access to major distributions

Patch Linux systems against CVE‑2026‑31431 immediately.

security 5/10 The Hacker News
4 May 21:17
urgent

Linux Kernel Adds Killswitch Feature for Immediate Function Mitigation

Patch the kernel with CONFIG_KILLSWITCH and immediately engage the vulnerable function using the control interface to stop exploitation until a proper fix is available.

security 4/10 Hacker News (front page)
9 May 16:10
urgent

FTC Bans Kochava From Selling Americans’ Location Data Without Consent

Patch your data handling to ensure no sensitive location data is sold without consent.

security 4/10 AdExchanger
5 May 01:15
urgent

Student hacked Taiwan high‑speed rail to trigger emergency brakes

Patch your TETRA parameter rotation policy to enforce quarterly changes and audit verification layers.

security 3/10 Bleeping Computer
5 May 19:48
urgent

Vimeo Data Breach Exposes Personal Information of 119,000 People

Patch: Disable all Anodot credentials and remove the Anodot integration from your Vimeo environment immediately.

security 3/10 Bleeping Computer
5 May 15:09
urgent

Microsoft Uncovers Large-Scale Credential Theft Campaign Using Legitimate Email Services

Enable MFA on all Microsoft accounts and block the attacker domains listed in the report immediately.

security 3/10 The Hacker News
5 May 10:03
urgent

Brazilian DDoS Protection Firm Compromised, Botnet Targets Local ISPs

Patch all TP‑Link Archer AX21 routers to the latest firmware, rotate any compromised SSH keys, and audit for unauthorized access to prevent future botnet activity.

security 3/10 Krebs on Security
4 May 15:28
urgent

DarkSword iOS Malware Exploit Chain Targets Multiple Nations

Patch iOS devices to the latest version (18.8 or later) to mitigate DarkSword exploitation.

security Schneier on Security
5 May 12:52