RubyGems Suspends New Signups After Hundreds of Malicious Packages Are Uploaded
RubyGems temporarily suspending new signups after hundreds of malicious packages were uploaded is a clear warning that open-source package repositories are now active attack surfaces, not just developer convenience plat…
May 12, 2026
Fuji Electric Tellus
The CISA advisory on Fuji Electric Tellus is another reminder that industrial software security must be treated beyond the application layer. A kernel driver granting broad read/write permissions to all users can create…
May 12, 2026
New TrickMo Variant Uses TON C2 and SOCKS5 to Create Android Network Pivots
https://thehackernews.com/2026/05/new-trickmo-variant-uses-ton-c2-and.html
May 12, 2026
Mini Shai-Hulud Worm Compromises TanStack, Mistral AI, Guardrails AI & More Packages
The Mini Shai-Hulud campaign shows how dangerous modern software supply-chain attacks have become when CI/CD, package registries, provenance, and developer tools are all abused together. The campaign reportedly compromi…
May 12, 2026
SAP fixes critical vulnerabilities in Commerce Cloud and S/4HANA
SAP’s May 2026 security updates should be treated with urgency because the affected products sit at the heart of business operations. The update addresses 15 vulnerabilities, including two critical issues in SAP Commerc…
May 12, 2026
iOS 26.5 Brings Default End-to-End Encrypted RCS Messaging Between iPhone and Android
Apple enabling default end-to-end encrypted RCS between iPhone and Android users is a major step forward because it finally improves privacy for cross-platform messaging that has historically fallen back to weaker SMS/M…
May 12, 2026
Official CheckMarx Jenkins package compromised with infostealer
The Checkmarx Jenkins AST plugin compromise is a serious supply-chain warning because Jenkins plugins run inside CI/CD environments where secrets, source code, build credentials, deployment keys, and release workflows o…
May 12, 2026
New GhostLock tool abuses Windows API to block file access
GhostLock is a useful reminder that availability attacks do not always need encryption, deletion, or ransomware-style payloads. By abusing legitimate Windows file-sharing behavior through the CreateFileW() API with excl…
May 12, 2026
Instructure confirms hackers used Canvas flaw to deface portals
The Canvas incident shows why XSS in trusted platforms should never be treated as a minor UI issue. Instructure confirmed that attackers exploited a vulnerability to modify Canvas login portals, while BleepingComputer r…
May 11, 2026
Google: Hackers used AI to develop zero-day exploit for web admin tool
Google’s finding is a major warning sign for defenders: AI is no longer just being used to write phishing emails or polish malware scripts, but may now be helping attackers discover and build working zero-day exploits. …
May 11, 2026
Ollama Out-of-Bounds Read Vulnerability Allows Remote Process Memory Leak
The Ollama vulnerability is a serious reminder that locally hosted AI does not automatically mean safely hosted AI. CVE-2026-7482, also called Bleeding Llama, reportedly allows a remote unauthenticated attacker to abuse…
May 11, 2026
Fake OpenAI repository on Hugging Face pushes infostealer malware
The fake OpenAI repository on Hugging Face shows how quickly attackers are adapting to the AI supply chain. By impersonating a legitimate OpenAI “Privacy Filter” project and reaching Hugging Face’s trending list, the ma…
May 10, 2026