SAP Ecosystem Targeted: The Mini Shai-Hulud Supply Chain Attack
SAP Ecosystem Targeted: The Mini Shai-Hulud Supply Chain Attack A sophisticated npm supply-chain compromise dubbed “Mini Shai-Hulud” has recently emerged, creating an urgent risk for SAP CAP developme...
CVE-2026-3854 Exposes a Critical Weak Point in GitHub’s Git Push Pipel...
CVE-2026-3854 Exposes a Critical Weak Point in GitHub’s Git Push Pipeline A newly disclosed GitHub vulnerability, CVE-2026-3854, has drawn attention because it turned a routine git push operation into...
Handala Hack Targets U.S. Troops with Doxxing Threats in Bahrain
Handala Hack Targets U.S. Troops with Doxxing Threats in Bahrain On Monday, U.S. service members stationed in Bahrain started getting WhatsApp messages on their personal phones telling them they were ...
Bitwarden CLI Hijacked in npm Supply Chain Attack Linked to TeamPCP & ...
Bitwarden CLI Hijacked in npm Supply Chain Attack Linked to TeamPCP & Checkmarx Breach A malicious version of the Bitwarden CLI circulated on npm for roughly 90 minutes on April 22, 2026, silently...
How AI Changed Vishing: Case of PlugValley
How AI Changed Vishing: Case of PlugValley Vishing or voice phishing is not a new attack. Fraudsters have been calling people and pretending to be banks, government agencies, and tech support for deca...
CVE-2026-38526 in Krayin CRM Enables RCE
CVE-2026-38526 in Krayin CRM Enables RCE CVE-2026-38526 is a critical authenticated remote code execution (RCE) vulnerability affecting Webkul Krayin CRM / Krayin Laravel CRM v2.2.x. The issue is in t...
Vercel Breach: Hacker Claims to Sell Stolen Data in Potential Global S...
Vercel Breach: Hacker Claims to Sell Stolen Data in Potential Global Supply Chain Attack On April 19, 2026, Vercel, the cloud development platform behind Next.js and Turbopack, disclosed a security in...
Public Elasticsearch Servers Expose 9.8 Billion Credential Records Acr...
Public Elasticsearch Servers Expose 9.8 Billion Credential Records Across Enterprise, Cloud, and AI Platforms Misconfigured Elasticsearch servers continue to expose massive volumes of sensitive data. ...
BlueHammer, RedSun, and UnDefend: Three Windows Defender Zero-Days Exp...
BlueHammer, RedSun, and UnDefend: Three Windows Defender Zero-Days Exploited in the Wild [Update] July 3, 2026: CISA Flags BlueHammer as Exploited in Ransomware Campaigns Three Windows Defender vulner...
April 2026 Patch Tuesday: 165 Vulnerabilities, Two Zero-Days Including...
April 2026 Patch Tuesday: 165 Vulnerabilities, Two Zero-Days Including One Actively Exploited Microsoft released its April 2026 Patch Tuesday security updates, resolving a total of 165 vulnerabilities...
CVE-2026-34486: Apache Tomcat Tribes Regression Creates Unauthenticate...
CVE-2026-34486: Apache Tomcat Tribes Regression Creates Unauthenticated RCE Path Apache Tomcat users running Tribes clustering should pay attention to CVE-2026-34486, an important-severity regression ...
Claude Code & ChatGPT Used to Steal Millions of Records in Mexican Gov...
Claude Code & ChatGPT Used to Steal Millions of Records in Mexican Government Breach A cyberattack spanning nine Mexican government organizations has become one of the clearest examples yet of how...
CVE-2026-34621: Adobe Acrobat Reader Zero-Day Enables Arbitrary Code E...
CVE-2026-34621: Adobe Acrobat Reader Zero-Day Enables Arbitrary Code Execution via Crafted PDF Adobe released an emergency update for Adobe Acrobat and Adobe Acrobat Reader on Windows and macOS to add...
Could XChat Become a Telegram Rival and a Future Hub for Threat Actors...
Could XChat Become a Telegram Rival and a Future Hub for Threat Actors? X’s upcoming messaging app, XChat, is being presented as more than a simple upgrade to direct messages. Public details point to ...
Claude Mythos Preview Signals a New Phase for AI in Vulnerability Rese...
Claude Mythos Preview Signals a New Phase for AI in Vulnerability Research Anthropic’s Claude Mythos Preview is drawing attention because it showed a much stronger ability to find and exploit software...
FBI IC3 2025 Internet Crime Report: 10 Important Takeaways
FBI IC3 2025 Internet Crime Report: 10 Important Takeaways The FBI’s Internet Crime Complaint Center (IC3) has just released its 2025 Annual Report, and it’s a record-breaker in the worst way. For the...
BlueHammer Windows Zero-Day: Privilege Escalation Risk
BlueHammer Windows Zero-Day: Privilege Escalation Risk A newly exposed Windows zero-day known as BlueHammer has become a serious concern because it can let an attacker move from a limited user account...
CVE-2026-35616: FortiClient EMS API Auth Bypass Enables Command Execut...
CVE-2026-35616: FortiClient EMS API Auth Bypass Enables Command Execution Fortinet disclosed a critical vulnerability in Fortinet FortiClient EMS (Enterprise Management Server) tracked as CVE-2026-356...
Progress ShareFile Flaws CVE-2026-2699 & CVE-2026-2701 RCE
Progress ShareFile Flaws CVE-2026-2699 & CVE-2026-2701 RCE A newly disclosed Progress ShareFile pre-auth RCE chain is drawing attention after researchers showed how CVE-2026-2699 and CVE-2026-2701...
CVE-2026-20093: Critical Cisco IMC Flaw Allows Unauthenticated Admin A...
CVE-2026-20093: Critical Cisco IMC Flaw Allows Unauthenticated Admin Access to UCS Servers CVE-2026-20093, is an authentication bypass flaw found in the change password functionality of Cisco Integrat...
