A curated dispatch from GajShield

The GajShield Gazette

Lead story
Also today
May 19, 2026

ZKTeco CCTV Cameras

CISA’s advisory on ZKTeco CCTV Cameras highlights why physical security devices must be managed with the same discipline as core IT infrastructure. The issue affects the…

In brief

ABB CoreSense HM and CoreSense M10

View CSAF Summary An update is available that resolves vulnerability in the product versions listed as affected in this advisory. A path tr…

May 19, 2026

GitHub Actions Supply Chain Attack Redirects Tags to Steal CI/CD Credentials

The GitHub Actions supply-chain attack against actions-cool/issues-helper is a serious reminder that CI/CD pipelines are now prime targets …

May 19, 2026

SHub macOS infostealer variant spoofs Apple security updates

The SHub “Reaper” macOS infostealer campaign shows how attackers are rapidly adapting to platform security improvements. Instead of relying…

May 19, 2026

CISA Admin Leaked AWS GovCloud Keys on Github

The reported exposure of AWS GovCloud keys and internal CISA credentials on a public GitHub repository is a stark reminder that secret mana…

May 19, 2026

Pre-Stuxnet Fast16 Malware Tampered with Nuclear Weapons Simulations

The analysis of Fast16 shows that cyber sabotage against industrial and scientific systems predates Stuxnet and has been far more specializ…

May 18, 2026

Exploit available for new DirtyDecrypt Linux root escalation flaw

The public exploit for DirtyDecrypt raises the urgency for Linux administrators because this is no longer just a theoretical kernel flaw. T…

May 18, 2026

New Windows 'MiniPlasma' zero-day exploit gives SYSTEM access, PoC released

The MiniPlasma Windows zero-day is a serious reminder that endpoint compromise does not end at initial access. Once an attacker gains a foo…

May 18, 2026

Tycoon2FA hijacks Microsoft 365 accounts via device-code phishing

Tycoon2FA’s use of Microsoft 365 device-code phishing shows how attackers are adapting to bypass traditional MFA expectations without needi…

May 17, 2026

NGINX CVE-2026-42945 Exploited in the Wild, Causing Worker Crashes and Possible RCE

The active exploitation of CVE-2026-42945 in NGINX should be treated as an urgent infrastructure risk, especially for internet-facing web s…

May 17, 2026

Grafana GitHub Token Breach Led to Codebase Download and Extortion Attempt

CISA adding CVE-2026-42897 to the Known Exploited Vulnerabilities catalog should be treated as an immediate priority signal for every organ…

May 17, 2026

Funnel Builder Flaw Under Active Exploitation Enables WooCommerce Checkout Skimming

The active exploitation of the Funnel Builder plugin is a serious warning for WooCommerce store owners because this flaw directly impacts c…

May 17, 2026