Kieback & Peter DDC Building Controllers
CISA’s advisory on Kieback & Peter DDC Building Controllers is another reminder that building automation systems are now part of the cyber-risk surface, not just facilities infrastructure. These controllers are used to …
May 20, 2026
The New Phishing Click: How OAuth Consent Bypasses MFA
The Hacker News article highlights an important shift in phishing: attackers are no longer always trying to steal passwords. They are increasingly trying to trick users into approving OAuth consent, which can give attac…
May 20, 2026
Drupal to Release Urgent Core Security Updates on May 20, Sites Told to Prepare
The Drupal advisory is a clear reminder that CMS platforms remain high-value targets because they sit directly on the public internet and often power business-critical websites. Drupal has announced an urgent core secur…
May 20, 2026
SEPPMail Secure E-Mail Gateway Vulnerabilities Enable RCE and Mail Traffic Access
The SEPPMail Secure E-Mail Gateway vulnerabilities are a strong reminder that security gateways themselves must be treated as high-value attack surfaces. According to the report, multiple flaws could allow attackers to …
May 20, 2026
Compromised Nx Console 18.95.0 Targeted VS Code Developers with Credential Stealer
The compromised Nx Console 18.95.0 incident is a serious reminder that developer tools have become a direct path into enterprise environments. According to the report, a malicious version of the Nx Console extension was…
May 20, 2026
Trapdoor Android Ad Fraud Scheme Hit 659 Million Daily Bid Requests Using 455 Apps
The Trapdoor Android ad-fraud campaign shows how mobile threats are becoming more layered and harder to detect. Researchers found that the operation involved 455 malicious Android apps and 183 attacker-controlled C2 dom…
May 19, 2026
7-Eleven confirms data breach claimed by the ShinyHunters gang
The 7-Eleven data breach claimed by ShinyHunters is another reminder that large retail brands must secure not only customer-facing systems, but also franchisee, document-management, and SaaS environments. 7-Eleven confi…
May 19, 2026
ZKTeco CCTV Cameras
CISA’s advisory on ZKTeco CCTV Cameras highlights why physical security devices must be managed with the same discipline as core IT infrastructure. The issue affects the SSC335-GC2063-Face-0b77 solution, where vulnerabi…
May 19, 2026
ABB CoreSense HM and CoreSense M10
View CSAF Summary An update is available that resolves vulnerability in the product versions listed as affected in this advisory. A path traversal vulnerability in these products can allow unauthentic…
May 19, 2026
GitHub Actions Supply Chain Attack Redirects Tags to Steal CI/CD Credentials
The GitHub Actions supply-chain attack against actions-cool/issues-helper is a serious reminder that CI/CD pipelines are now prime targets for credential theft. In this case, attackers reportedly moved existing GitHub A…
May 19, 2026
SHub macOS infostealer variant spoofs Apple security updates
The SHub “Reaper” macOS infostealer campaign shows how attackers are rapidly adapting to platform security improvements. Instead of relying only on older ClickFix-style Terminal tricks, this variant abuses the applescri…
May 19, 2026
CISA Admin Leaked AWS GovCloud Keys on Github
The reported exposure of AWS GovCloud keys and internal CISA credentials on a public GitHub repository is a stark reminder that secret management failures can undermine even the most security-focused organizations. Acco…
May 19, 2026