Checkmarx Jenkins Plugin Backdoored in New TeamPCP Supply Chain Attack
Checkmarx Jenkins Plugin Backdoored in New TeamPCP Supply Chain Attack It hasn’t been long since TeamPCP made headlines for compromising Checkmarx’s GitHub Actions and OpenVSX extensions as part of a ...
SOCRadar Recognized in the 2026 Gartner® Magic Quadrant™ for Cyberthre...
SOCRadar Recognized in the 2026 Gartner® Magic Quadrant™ for Cyberthreat Intelligence Technologies SOCRadar is positioned as a Visionary in the inaugural Magic Quadrant report for Threat Intelligence,...
CVE-2026-6973: Authenticated Admin RCE In Ivanti EPMM Added to CISA KE...
CVE-2026-6973: Authenticated Admin RCE In Ivanti EPMM Added to CISA KEV Ivanti has patched CVE-2026-6973, a high-severity remote code execution (RCE) vulnerability affecting Ivanti Endpoint Manager Mo...
CVE-2026-26956: vm2 Sandbox Escape Enables Host RCE in Node.js 25
CVE-2026-26956: vm2 Sandbox Escape Enables Host RCE in Node.js 25 CVE-2026-26956 is a critical sandbox escape affecting the Node.js sandbox library vm2. In vm2 3.10.4, attacker-controlled JavaScript e...
CVE-2026-23918: Apache HTTP Server HTTP/2 Double Free With Possible RC...
CVE-2026-23918: Apache HTTP Server HTTP/2 Double Free With Possible RCE CVE-2026-23918 is a vulnerability in Apache HTTP Server (httpd) that affects its HTTP/2 implementation and can lead to a double ...
CVE-2026-0300 Enables Root RCE in PAN-OS Captive Portal
CVE-2026-0300 Enables Root RCE in PAN-OS Captive Portal Palo Alto Networks disclosed CVE-2026-0300, a critical pre-authentication buffer overflow in the User-ID™ Authentication Portal (Captive Portal)...
Trellix Source Code Repository Incident: What Defenders Should Know
Trellix Source Code Repository Incident: What Defenders Should Know Trellix publicly disclosed that it identified unauthorized access to a portion of its internal source code repository. The company s...
ShinyHunters Breached Instructure: 275 Million Students, Teachers and ...
ShinyHunters Breached Instructure: 275 Million Students, Teachers and Staff Potentially Exposed If your school uses Canvas, your data may already be in the hands of one of the most active hacking grou...
CVE-2026-4670 & CVE-2026-5174: MOVEit Automation Flaws Enable Auth Byp...
CVE-2026-4670 & CVE-2026-5174: MOVEit Automation Flaws Enable Auth Bypass and Privilege Escalation Progress Software has disclosed and patched two vulnerabilities in MOVEit Automation, its managed...
March 2026: Wiper Attack Paralyzes Stryker as BPO Breaches & Data Thef...
March 2026: Wiper Attack Paralyzes Stryker as BPO Breaches & Data Thefts Sweep the Month March 2026 brought a heavy concentration of significant cyber incidents across healthcare, outsourcing, sof...
CVE-2026-31431: "Copy Fail," the Nine-Year-Old Linux Bug Introduced in...
CVE-2026-31431: “Copy Fail,” the Nine-Year-Old Linux Bug Introduced in 2017 A vulnerability hiding in plain sight for nearly a decade, capable of granting full root access to almost any Linux server w...
Chinese Cybercrime Infrastructure Detected: Automated Exploitation & H...
Chinese Cybercrime Infrastructure Detected: Automated Exploitation & Harvesting Infrastructure SOCRadar Threat Research Team identified automated Chinese cybercrime infrastructure that blends larg...
SAP Ecosystem Targeted: The Mini Shai-Hulud Supply Chain Attack
SAP Ecosystem Targeted: The Mini Shai-Hulud Supply Chain Attack A sophisticated npm supply-chain compromise dubbed “Mini Shai-Hulud” has recently emerged, creating an urgent risk for SAP CAP developme...
CVE-2026-3854 Exposes a Critical Weak Point in GitHub’s Git Push Pipel...
CVE-2026-3854 Exposes a Critical Weak Point in GitHub’s Git Push Pipeline A newly disclosed GitHub vulnerability, CVE-2026-3854, has drawn attention because it turned a routine git push operation into...
Handala Hack Targets U.S. Troops with Doxxing Threats in Bahrain
Handala Hack Targets U.S. Troops with Doxxing Threats in Bahrain On Monday, U.S. service members stationed in Bahrain started getting WhatsApp messages on their personal phones telling them they were ...
Bitwarden CLI Hijacked in npm Supply Chain Attack Linked to TeamPCP & ...
Bitwarden CLI Hijacked in npm Supply Chain Attack Linked to TeamPCP & Checkmarx Breach A malicious version of the Bitwarden CLI circulated on npm for roughly 90 minutes on April 22, 2026, silently...
How AI Changed Vishing: Case of PlugValley
How AI Changed Vishing: Case of PlugValley Vishing or voice phishing is not a new attack. Fraudsters have been calling people and pretending to be banks, government agencies, and tech support for deca...
CVE-2026-38526 in Krayin CRM Enables RCE
CVE-2026-38526 in Krayin CRM Enables RCE CVE-2026-38526 is a critical authenticated remote code execution (RCE) vulnerability affecting Webkul Krayin CRM / Krayin Laravel CRM v2.2.x. The issue is in t...
Vercel Breach: Hacker Claims to Sell Stolen Data in Potential Global S...
Vercel Breach: Hacker Claims to Sell Stolen Data in Potential Global Supply Chain Attack On April 19, 2026, Vercel, the cloud development platform behind Next.js and Turbopack, disclosed a security in...
Public Elasticsearch Servers Expose 9.8 Billion Credential Records Acr...
Public Elasticsearch Servers Expose 9.8 Billion Credential Records Across Enterprise, Cloud, and AI Platforms Misconfigured Elasticsearch servers continue to expose massive volumes of sensitive data. ...
