A curated dispatch from GajShield

The GajShield Gazette

Lead story

FBI warns of Kali365 phishing service targeting Microsoft 365 accounts

The TrapDoor supply-chain campaign is another warning that attackers are no longer targeting only one package ecosystem at a time. According to the report, the campaign spans npm, PyPI, and Crates.io, with more than 34 malicious packages across 384+ versions, targeting develop…

Also today
In brief

Ghost CMS SQL injection flaw exploited in large-scale ClickFix campaign

The Ghost CMS campaign is a clear reminder that a CMS vulnerability does not only put the website at risk. It can turn trusted websites int…

May 24, 2026

Laravel Lang packages hijacked to deploy credential-stealing malware

The Laravel Lang package hijack is another serious reminder that open-source supply-chain attacks are increasingly targeting developer trus…

May 24, 2026

Ubiquiti patches three max severity UniFi OS vulnerabilities

The Ubiquiti UniFi OS vulnerabilities are a serious reminder that network management platforms must be treated as critical infrastructure, …

May 23, 2026

Megalodon GitHub Attack Targets 5,561 Repos with Malicious CI/CD Workflows

The Megalodon GitHub attack shows how quickly CI/CD pipelines can become a mass credential-theft channel. According to the report, attacker…

May 23, 2026

Cisco Patches CVSS 10.0 Secure Workload REST API Flaw Enabling Data Access

Cisco’s disclosure of CVE-2026-20223 in Cisco Secure Workload is a serious reminder that security management platforms are themselves criti…

May 22, 2026

CISA Adds Exploited Langflow and Trend Micro Apex One Vulnerabilities to KEV

CISA adding the Langflow and Trend Micro Apex One vulnerabilities to its Known Exploited Vulnerabilities catalog is a clear signal that the…

May 22, 2026

Microsoft warns of new Defender zero-days exploited in attacks

Microsoft’s warning about two actively exploited Defender zero-days is a reminder that security software is also software, and it must be p…

May 22, 2026

Google accidentally exposed details of unfixed Chromium flaw

Google’s accidental exposure of details about an unfixed Chromium vulnerability is a serious reminder that browser security issues can beco…

May 22, 2026

Showboat Linux Malware Hits Middle East Telecom with SOCKS5 Proxy Backdoor

The Showboat Linux malware campaign is a clear reminder that Linux infrastructure, especially in telecom environments, is a strategic targe…

May 22, 2026

ABB B&R Automation Studio

CISA’s ICSA-26-141-03 advisory is another reminder that industrial control system vulnerabilities must be handled with operational urgency,…

May 22, 2026

Police seize “First VPN” service used in ransomware, data theft attacks

The takedown of First VPN is an important reminder that cybercrime does not rely only on malware developers and ransomware operators. It al…

May 21, 2026