npm Adds 2FA-Gated Publishing and Package Install Controls Against Supply Chain Attacks
npm’s new security controls are a welcome step toward reducing the blast radius of open-source supply-chain attacks. GitHub has introduced staged publishing for npm, where a package tarball is first uploaded to a stagin…
May 24, 2026
LiteSpeed cPanel Plugin CVE-2026-48172 Exploited to Run Scripts as Root
The LiteSpeed User-End cPanel Plugin vulnerability is a serious reminder that hosting control panels and plugins are high-value targets because they sit close to websites, accounts, and server administration. The flaw, …
May 24, 2026
Ghost CMS SQL injection flaw exploited in large-scale ClickFix campaign
The Ghost CMS campaign is a clear reminder that a CMS vulnerability does not only put the website at risk. It can turn trusted websites into malware delivery infrastructure. In this case, attackers are exploiting CVE-20…
May 24, 2026
Laravel Lang packages hijacked to deploy credential-stealing malware
The Laravel Lang package hijack is another serious reminder that open-source supply-chain attacks are increasingly targeting developer trust, not just production applications. In this case, attackers abused GitHub versi…
May 24, 2026
Ubiquiti patches three max severity UniFi OS vulnerabilities
The Ubiquiti UniFi OS vulnerabilities are a serious reminder that network management platforms must be treated as critical infrastructure, not just convenient dashboards. Ubiquiti has patched three maximum-severity flaw…
May 23, 2026
Megalodon GitHub Attack Targets 5,561 Repos with Malicious CI/CD Workflows
The Megalodon GitHub attack shows how quickly CI/CD pipelines can become a mass credential-theft channel. According to the report, attackers pushed 5,718 malicious commits into 5,561 GitHub repositories within a six-hou…
May 23, 2026
Cisco Patches CVSS 10.0 Secure Workload REST API Flaw Enabling Data Access
Cisco’s disclosure of CVE-2026-20223 in Cisco Secure Workload is a serious reminder that security management platforms are themselves critical attack surfaces. The flaw has a CVSS score of 10.0 and affects Cisco Secure …
May 22, 2026
CISA Adds Exploited Langflow and Trend Micro Apex One Vulnerabilities to KEV
CISA adding the Langflow and Trend Micro Apex One vulnerabilities to its Known Exploited Vulnerabilities catalog is a clear signal that these are not theoretical risks anymore. KEV listing means there is evidence of act…
May 22, 2026
Microsoft warns of new Defender zero-days exploited in attacks
Microsoft’s warning about two actively exploited Defender zero-days is a reminder that security software is also software, and it must be patched with the same urgency as any exposed system component. The vulnerabilitie…
May 22, 2026
Google accidentally exposed details of unfixed Chromium flaw
Google’s accidental exposure of details about an unfixed Chromium vulnerability is a serious reminder that browser security issues can become large-scale risks very quickly. According to the report, the flaw allows Java…
May 22, 2026
Showboat Linux Malware Hits Middle East Telecom with SOCKS5 Proxy Backdoor
The Showboat Linux malware campaign is a clear reminder that Linux infrastructure, especially in telecom environments, is a strategic target for espionage groups. According to the report, Showboat has been used against …
May 22, 2026
ABB B&R Automation Studio
CISA’s ICSA-26-141-03 advisory is another reminder that industrial control system vulnerabilities must be handled with operational urgency, not treated like ordinary IT patch notes. ICS and OT systems often support crit…
May 22, 2026