Stay informed about the latest cybersecurity threats, vulnerabilities, malware campaigns, phishing trends, supply-chain attacks, and security advisories. This section provides timely updates and practical insights to help organizations understand emerging risks and strengthen their security posture.
GitHub’s confirmation that its internal repositories were breached through a malicious Nx Console VS Code extension is another warning that developer tooling has become a prime supply-chain attack vector. In this case, the compromise reportedly originated from a poisoned exten…
The YellowKey Windows zero-day is a serious reminder that disk encryption is only as strong as the boot and recovery chain around it. According to the report, Microsoft is tracking the flaw as CVE-2026-45585, a BitLocker security feature bypass where a public proof-of-concept …
The Webworm campaign highlights how advanced threat actors are increasingly abusing legitimate cloud and collaboration platforms for command-and-control. According to the report, the China-aligned Webworm group deployed two new backdoors, EchoCreep and GraphWorm, using Discord…
The reported GitHub incident is a serious reminder that developer ecosystems are now one of the most attractive targets for cybercriminal groups. According to the report, GitHub is investigating claims by TeamPCP that it accessed around 4,000 internal repositories, with GitHub…
The ChromaDB vulnerability is a serious warning for organizations building AI applications: AI infrastructure is now part of the attack surface, not just an innovation layer. The reported flaw, CVE-2026-45829, affects the Python FastAPI version of ChromaDB and can allow unauth…
The disruption of the Fox Tempest malware-signing-as-a-service operation shows how attackers are abusing trust itself as an attack vector. According to the report, the group misused Microsoft’s Artifact Signing service to generate fraudulent code-signing certificates, allowing…
The FBI’s warning on crypto ATM scams highlights how cybercrime is not always about sophisticated malware or zero-day exploits. Sometimes it is simply about manipulating people into moving money through irreversible channels. According to the report, Americans lost over $388 m…
The Storm-2949 campaign shows how identity recovery workflows can become an attack path when social engineering is added to the mix. According to the report, attackers abused Microsoft Entra ID Self-Service Password Reset by initiating a reset for targeted employees and then i…
CISA’s advisory on Kieback & Peter DDC Building Controllers is another reminder that building automation systems are now part of the cyber-risk surface, not just facilities infrastructure. These controllers are used to regulate and monitor HVAC and building operations, and Kie…
The Hacker News article highlights an important shift in phishing: attackers are no longer always trying to steal passwords. They are increasingly trying to trick users into approving OAuth consent, which can give attackers long-lived access tokens to mailboxes, files, calenda…
The Drupal advisory is a clear reminder that CMS platforms remain high-value targets because they sit directly on the public internet and often power business-critical websites. Drupal has announced an urgent core security release for all supported branches on May 20, 2026, wa…
The SEPPMail Secure E-Mail Gateway vulnerabilities are a strong reminder that security gateways themselves must be treated as high-value attack surfaces. According to the report, multiple flaws could allow attackers to achieve remote code execution, read arbitrary mail, access…
The compromised Nx Console 18.95.0 incident is a serious reminder that developer tools have become a direct path into enterprise environments. According to the report, a malicious version of the Nx Console extension was published to the VS Code Marketplace and, once a develope…
The Trapdoor Android ad-fraud campaign shows how mobile threats are becoming more layered and harder to detect. Researchers found that the operation involved 455 malicious Android apps and 183 attacker-controlled C2 domains, generating up to 659 million bid requests per day. W…
The 7-Eleven data breach claimed by ShinyHunters is another reminder that large retail brands must secure not only customer-facing systems, but also franchisee, document-management, and SaaS environments. 7-Eleven confirmed that an unauthorized third party accessed certain sys…
CISA’s advisory on ZKTeco CCTV Cameras highlights why physical security devices must be managed with the same discipline as core IT infrastructure. The issue affects the SSC335-GC2063-Face-0b77 solution, where vulnerabilities may allow authentication bypass leading to full adm…
View CSAF Summary An update is available that resolves vulnerability in the product versions listed as affected in this advisory. A path traversal vulnerability in these products can allow unauthentic…
The GitHub Actions supply-chain attack against actions-cool/issues-helper is a serious reminder that CI/CD pipelines are now prime targets for credential theft. In this case, attackers reportedly moved existing GitHub Action tags to point to an imposter commit containing malic…
The SHub “Reaper” macOS infostealer campaign shows how attackers are rapidly adapting to platform security improvements. Instead of relying only on older ClickFix-style Terminal tricks, this variant abuses the applescript:// URL scheme to open Script Editor with malicious Appl…
The reported exposure of AWS GovCloud keys and internal CISA credentials on a public GitHub repository is a stark reminder that secret management failures can undermine even the most security-focused organizations. According to the report, the repository exposed highly privile…