A curated dispatch from GajShield

The GajShield Gazette

Lead story
Also today
In brief

TP-Link patches Omada ZTP flaws allowing hackers to breach networks

TP-Link Omada ZTP Vulnerabilities Show How Automated Network Provisioning Can Become an Attack PathThe discovery of 15 vulnerabilities affe…

Aug 05, 2026

QuickFox Supply Chain Attack Delivers FDMTP Backdoor via Trojanized Windows Installer

QuickFox Supply-Chain Attack Delivered FDMTP Backdoor Through Official Windows InstallerThe discovery of a long-running supply-chain compro…

Aug 05, 2026

77 Open VSX extensions found harvesting developer info

Counterfeit Open VSX Extensions Harvest Developer and CI/CD Environment InformationThe discovery of 77 counterfeit extensions on the Open V…

Aug 05, 2026

New XCSSET variant targets macOS devs via compromised Xcode projects

New XCSSET Variant Turns Compromised Xcode Projects into a macOS Supply-Chain AttackThe emergence of XCSSET version 40 demonstrates how att…

Aug 05, 2026

CISA Adds Three Known Exploited Vulnerabilities to Catalog

CISA Adds Actively Exploited N-able, Apache Tomcat and Langflow Vulnerabilities to KEV CatalogThe addition of three vulnerabilities affecti…

Aug 05, 2026

Phishing service spoofs RingCentral to steal Microsoft 365 accounts

Greatness Phishing Service Exploits RingCentral Trust to Compromise Microsoft 365 AccountsA phishing campaign impersonating RingCentral dem…

Aug 05, 2026

Fake Adobe and Zoom Updates Install ScreenConnect for Persistent Remote Access

Fake Adobe and Zoom Updates Show How Attackers Abuse Trusted Software to Establish Persistent Remote AccessA series of phishing campaigns u…

Aug 04, 2026

Keyv-Linked npm Worm Poisons Hundreds of Packages, Plants Claude Code and VS Code Hooks

Keyv-Linked npm Worm Demonstrates How Developer Credentials Can Turn One Compromise into a Software Supply-Chain EpidemicThe discovery of a…

Aug 04, 2026

New DOUBLECUP ClickFix service hides malware in browser cache images

DOUBLECUP ClickFix Service Shows How Browser Caches Are Being Turned into Malware Delivery ChannelsThe newly identified DOUBLECUP loader-as…

Aug 04, 2026

New cPanel Critical Flaw Could Let Hosting Customers Run SQL as Database Root

Critical cPanel Flaw Could Allow Hosting Customers to Execute SQL with Database Root PrivilegesA newly disclosed critical vulnerability in …

Aug 04, 2026

18 Malicious npm Packages Deliver Cross-Platform RAT to Alibaba Tool Users

Malicious npm Packages Target Alibaba Developers with a Cross-Platform Remote-Access TrojanThe discovery of 18 malicious npm packages targe…

Aug 04, 2026