A curated dispatch from GajShield

The GajShield Gazette

Lead story

Fake Paysafe, Skrill SDKs on NPM and PyPi steal credentials

The fake Paysafe, Skrill, and Neteller SDK campaign shows how attackers are abusing public package repositories to target developers working with payment integrations.At least 17 malicious npm and PyPI packages were published to impersonate legitimate payment SDKs. The pac…

Also today
In brief

Telco giant KDDI says data breach affects over 12 million people

The KDDI data breach highlights the serious risk created when email platforms used by telecom and internet service providers are compromise…

Jul 08, 2026

CISA Adds 4 Actively Exploited Adobe, Joomla, and Langflow Flaws to KEV

CISA’s addition of four actively exploited vulnerabilities to its Known Exploited Vulnerabilities catalogue shows how quickly attackers are…

Jul 08, 2026

New Januscape Linux flaw allows VM escape on Intel, AMD devices

The Januscape Linux kernel vulnerability highlights the risk of guest-to-host escape flaws in virtualization platforms.Tracked as CVE-2026-…

Jul 08, 2026

Rogue Agent Flaw Could Have Let Attackers Hijack Google Dialogflow CX Chatbots

The Rogue Agent flaw in Google Dialogflow CX shows how AI chatbot platforms can become risky when custom code runs inside shared, provider-…

Jul 08, 2026

Hidden backdoor in Tenda router firmware grants admin access

The discovery of a hidden authentication backdoor in multiple Tenda router firmware versions highlights the serious risk created when undoc…

Jul 08, 2026

Accenture confirms breach after hacker offers stolen data for sale

The Accenture breach shows how theft of source code and development secrets can create risk far beyond the immediate exposure of internal f…

Jul 08, 2026

Opera GX Flaw Let Malicious Sites Auto-Install Mods to Steal Data From Visited Pages

The Opera GX vulnerability shows how browser customization features can become an unexpected path for data theft when installation controls…

Jul 07, 2026

New Java-Based QuimaRAT MaaS Built to Run on Windows, Linux, and macOS

The emergence of QuimaRAT shows how malware-as-a-service is making cross-platform remote-access tools easier for criminals to obtain and op…

Jul 07, 2026

16-Year-Old Linux KVM Flaw Lets Guest VMs Escape to Host on Intel and AMD x86 Systems

The disclosure of Januscape, tracked as CVE-2026-53359, highlights the seriousness of vulnerabilities in virtualization layers that are exp…

Jul 07, 2026

Fake IT support calls on Microsoft Teams push EtherRAT malware

The fake IT-support campaign abusing Microsoft Teams shows how attackers are shifting from email phishing to direct social engineering thro…

Jul 07, 2026

Medtronic notifies customers impacted by ShinyHunters data breach

The Medtronic data breach highlights the serious and long-lasting consequences of exposing personal and health-related information.The inci…

Jul 03, 2026