Pre-Stuxnet Fast16 Malware Tampered with Nuclear Weapons Simulations
The analysis of Fast16 shows that cyber sabotage against industrial and scientific systems predates Stuxnet and has been far more specialized than many organizations assume. Unlike generic malware, Fast16 was reportedly…
May 18, 2026
Exploit available for new DirtyDecrypt Linux root escalation flaw
The public exploit for DirtyDecrypt raises the urgency for Linux administrators because this is no longer just a theoretical kernel flaw. The vulnerability is a local privilege escalation issue in the Linux kernel’s rxg…
May 18, 2026
New Windows 'MiniPlasma' zero-day exploit gives SYSTEM access, PoC released
The MiniPlasma Windows zero-day is a serious reminder that endpoint compromise does not end at initial access. Once an attacker gains a foothold on a Windows system, local privilege escalation flaws can turn limited acc…
May 18, 2026
Tycoon2FA hijacks Microsoft 365 accounts via device-code phishing
Tycoon2FA’s use of Microsoft 365 device-code phishing shows how attackers are adapting to bypass traditional MFA expectations without needing to steal passwords directly. By tricking users into entering an attacker-gene…
May 17, 2026
NGINX CVE-2026-42945 Exploited in the Wild, Causing Worker Crashes and Possible RCE
The active exploitation of CVE-2026-42945 in NGINX should be treated as an urgent infrastructure risk, especially for internet-facing web servers and reverse proxies. The flaw is a heap buffer overflow in ngx_http_rewri…
May 17, 2026
Grafana GitHub Token Breach Led to Codebase Download and Extortion Attempt
CISA adding CVE-2026-42897 to the Known Exploited Vulnerabilities catalog should be treated as an immediate priority signal for every organization running on-premises Microsoft Exchange. The vulnerability affects Exchan…
May 17, 2026
Funnel Builder Flaw Under Active Exploitation Enables WooCommerce Checkout Skimming
The active exploitation of the Funnel Builder plugin is a serious warning for WooCommerce store owners because this flaw directly impacts checkout security and customer payment data. The vulnerability affects Funnel Bui…
May 17, 2026
Funnel Builder WordPress plugin bug exploited to steal credit cards
The active exploitation of the Funnel Builder WordPress plugin is a serious warning for WooCommerce site owners because this is not just a website defacement risk, it directly targets payment data. The flaw affects plug…
May 16, 2026
CISA Adds One Known Exploited Vulnerability to Catalog
CISA adding CVE-2026-42897 to the Known Exploited Vulnerabilities catalog should be treated as an immediate priority signal for every organization running on-premises Microsoft Exchange. The vulnerability affects Exchan…
May 16, 2026
Four OpenClaw Flaws Enable Data Theft, Privilege Escalation, and Persistence
The four OpenClaw vulnerabilities, collectively called “Claw Chain,” show why AI agent platforms must be secured as high-privilege execution environments, not treated like ordinary productivity tools. The flaws can be c…
May 15, 2026
Popular node-ipc npm package compromised to steal credentials
The compromise of the popular node-ipc npm package is another serious reminder that software supply-chain attacks are now directly targeting developer workstations and CI/CD environments. The affected versions, includin…
May 15, 2026
Stealer Backdoor Found in 3 Node-IPC Versions Targeting Developer Secrets
The malicious Node-IPC versions are another sharp reminder that open-source package repositories are now part of the enterprise attack surface. Three newly published node-ipc versions, reportedly 9.1.6, 9.2.3, and 12.0.…
May 15, 2026