On-Prem Microsoft Exchange Server CVE-2026-42897 Exploited via Crafted Email
The active exploitation of CVE-2026-42897 in on-premises Microsoft Exchange Server is a serious reminder that email platforms remain one of the most targeted enterprise assets. Microsoft describes the issue as a spoofin…
May 15, 2026
OpenAI confirms security breach in TanStack supply chain attack
The OpenAI incident linked to the TanStack “Mini Shai-Hulud” supply-chain attack is another reminder that developer environments have become one of the most attractive targets for attackers. OpenAI stated that two emplo…
May 15, 2026
Cisco warns of new critical SD-WAN flaw exploited in zero-day attacks
Cisco is warning that a critical Catalyst SD-WAN Controller authentication bypass flaw, tracked as CVE-2026-20182, was actively exploited in zero-day attacks that allowed attackers to gain administrat…
May 15, 2026
TeamPCP hackers advertise Mistral AI code repos for sale
The TeamPCP claim around Mistral AI repositories shows how software supply-chain attacks are now moving beyond package poisoning into source-code theft, extortion, and exposure of internal development workflows. Mistral…
May 15, 2026
Hackers exploit auth bypass flaw in Burst Statistics WordPress plugin
The active exploitation of the Burst Statistics WordPress plugin vulnerability shows how quickly attackers weaponize flaws in widely deployed plugins. CVE-2026-8181 allows unauthenticated attackers to impersonate known …
May 15, 2026
Dell confirms its SupportAssist software causes Windows BSOD crashes
Dell confirming that SupportAssist Remediation version 5.5.16.0 is causing Windows BSOD crashes is a reminder that endpoint management and recovery tools must be tested as carefully as operating system patches. A utilit…
May 14, 2026
PraisonAI CVE-2026-44338 Auth Bypass Targeted Within Hours of Disclosure
The PraisonAI CVE-2026-44338 authentication bypass is a clear warning for the fast-growing AI agent ecosystem. The vulnerability affects PraisonAI Python package versions 2.5.6 through 4.6.33 and is caused by the legacy…
May 14, 2026
KongTuke hackers now use Microsoft Teams for corporate breaches
KongTuke’s shift to Microsoft Teams for corporate breaches shows how attackers are moving their social engineering directly into trusted business communication channels. According to the report, the group is abusing Tea…
May 14, 2026
18-Year-Old NGINX Rewrite Module Flaw Enables Unauthenticated RCE
The 18-year-old NGINX rewrite module vulnerability, tracked as CVE-2026-42945 and named “NGINX Rift,” is a serious reminder that even mature, widely deployed infrastructure can hide critical flaws for years. The issue a…
May 14, 2026
New Fragnesia Linux flaw lets attackers gain root privileges
The Fragnesia Linux kernel vulnerability, tracked as CVE-2026-46300, is another serious reminder that local privilege escalation flaws can be just as damaging as remote vulnerabilities once an attacker gains even limite…
May 14, 2026
West Pharmaceutical says hackers stole data, encrypted systems
The West Pharmaceutical cyberattack is a serious reminder that ransomware and data-theft incidents in the pharmaceutical supply chain can have consequences beyond IT disruption. West disclosed that unauthorized actors e…
May 14, 2026
Windows BitLocker zero-day gives access to protected drives, PoC released
The newly disclosed BitLocker bypass, known as YellowKey, is a serious reminder that disk encryption is only as strong as the full boot and recovery chain around it. The reported issue abuses Windows Recovery Environmen…
May 13, 2026