Data Breach Cybersecurity Vendors Supply Chain

Trellix Source Code Breach: RansomHouse Claims April 17 Intrusion, Vendor Confirms Repo Access

Ransomware Web Hosting Threat Intelligence

Sorry Ransomware Sweeps cPanel Hosts: 7,135 Servers Encrypted, Censys Says cPanel Is 80% of New Malicious IPs Today

Data Breach Education Ransomware

ShinyHunters Sets May 12 Deadline for Canvas / Instructure: 8,809 Schools, 275M Records, Per-School Ransom Demands

File Transfer Vulnerability Disclosure Enterprise

MOVEit Automation CVE-2026-4670: Unauthenticated Auth Bypass on the MFT Engine 1,400+ Customers Run

Web Hosting Vulnerability Disclosure Supply Chain

cPanel CVE-2026-41940: 64-Day Zero-Day, 44,000 Compromised IPs, and a Targeted Run at Southeast Asian Defence and MSPs

Apache Web Servers Vulnerability Disclosure

Apache HTTP Server 2.4.66 HTTP/2 Double-Free (CVE-2026-23918): A Single-Version Bug With RCE Potential

LLM Security SQL Injection Vulnerability Disclosure

LiteLLM CVE-2026-42208: Pre-Auth SQL Injection in the AI Gateway, Targeted Exploitation Within 36 Hours

Machine Learning Robotics Vulnerability Disclosure

Hugging Face LeRobot CVE-2026-25874: Unauthenticated Pickle RCE Over gRPC, Still Unpatched

GitHub DevOps Vulnerability Disclosure

One git push, Full Server: CVE-2026-3854 Let Anyone with Push Access RCE GitHub.com and Enterprise Server

APT DevOps Security Supply Chain

Tropic Trooper Turns VS Code Tunnels and GitHub Issues into a Stealth C2, Plants Trojanized SumatraPDF on Devs

Windows Privilege Escalation Vulnerability Research

PhantomRPC: Architectural Flaw in Windows RPC Lets Any Service Account Reach SYSTEM, and Microsoft Will Not Patch It

WordPress Vulnerabilities File Upload

Ninja Forms File Upload CVE-2026-0740 (CVSS 9.8) — 50,000 WordPress Sites Under Active Webshell Attack

ICS OT Security Modbus

Global Modbus/TCP Scanning Campaign Hits 14,426 Internet-Exposed PLCs in 70 Countries — Including Active Write Attempts

Identity Vishing Okta

ADT Confirms Breach: One Vishing Call → Okta SSO → 10M Salesforce Records — The ShinyHunters Playbook in Action

APT China Mongolia

GopherWhisper: China-Aligned APT Uses Slack, Discord, and Microsoft 365 Outlook as Command-and-Control

CISA KEV Vulnerabilities SimpleHelp

CISA Adds 4 Actively Exploited Flaws to KEV: SimpleHelp, Samsung MagicINFO, D-Link DIR-823X — May 8 Federal Deadline

AI Security SSRF LLM

LMDeploy SSRF (CVE-2026-33626) Weaponized Within 13 Hours of Disclosure — Your AI Inference Box Is a Metadata-API Probe

Cisco APT Firewall

FIRESTARTER: APT Backdoor on Cisco ASA/Firepower Devices Survives Patching — Federal Agency Confirmed Compromised

CrowdStrike Tenable SIEM

Your Security Tools Are the Vulnerability: Critical CrowdStrike LogScale (CVE-2026-40050) and High-Severity Tenable Nessus (CVE-2026-33694) Patches

Microsoft Defender Zero-Day Privilege Escalation

Defender BlueHammer (CVE-2026-33825) Now Actively Exploited — CISA KEV Deadline May 6

Supply Chain npm Bitwarden

Bitwarden CLI Backdoored in Ongoing TeamPCP Campaign — Shai-Hulud: The Third Coming

Supply Chain Docker DevSecOps

Checkmarx KICS Docker Hub and VS Code Extensions Poisoned in Fresh Supply Chain Attack

Supply Chain npm Developer Security

CanisterWorm: A Self-Propagating npm Worm Is Stealing Developer Tokens and Spreading Autonomously

ASP.NET Core Microsoft Cryptography

ASP.NET Core CVE-2026-40372: Out-of-Band Patch for Critical Cookie Forgery Flaw — Rotate Your Data Protection Keys

AI Security Prompt Injection IDE Security

Google Antigravity IDE: Prompt Injection Through find_by_name Turns File Search Into Full RCE

Supply Chain OAuth Data Breach

Vercel Breach Traced to Context.ai Supply Chain Compromise — Rotate Your Environment Variables Now

AI Security Remote Code Execution MLOps

SGLang CVE-2026-5760: A Malicious AI Model File Is Enough to Get RCE on Your Inference Server

ICS OT Security Healthcare

BRIDGE:BREAK — 20 New Vulnerabilities in Lantronix and Silex Serial-to-IP Converters Threaten OT and Hospital Networks

AI Security MCP Supply Chain

Anthropic's MCP Has a By-Design RCE Flaw Affecting 200,000 Servers — and Anthropic Won't Fix It

Patch Tuesday Microsoft Zero-Day

Microsoft's Massive April 2026 Patch Tuesday Fixes 167 Flaws Including Exploited SharePoint Zero-Day

ICS OT Security Patch Tuesday

ICS Patch Tuesday: Siemens, Schneider Electric, Rockwell and Five More Vendors Ship Critical Fixes

Active Exploitation Remote Code Execution Self-Hosted Tools

ShowDoc RCE Flaw CVE-2025-0520 Is Being Actively Exploited — Over 2,000 Servers Exposed

Supply Chain PHP Composer

PHP Composer Patches Two Command Injection Flaws in Perforce VCS Driver — Update to 2.9.6 Now

Supply Chain OpenAI Code Signing

OpenAI Revokes macOS Code Signing Certificate After North Korea-Linked Axios Supply Chain Attack

Android Malware RAT Residential Proxy

Mirax Android RAT Converts Infected Phones into Residential Proxies After Spreading via Meta Ads

CISA Vulnerability Patching

CISA Orders Federal Agencies to Patch 6 Actively Exploited Flaws in Fortinet, Microsoft, and Adobe

Browser Security Chrome Extensions Data Theft

108 Malicious Chrome Extensions Caught Stealing Google Tokens and Telegram Sessions

Chrome Session Security Cookie Theft

Google Chrome Now Makes Stolen Session Cookies Useless With Device Bound Session Credentials

Zero-Day Windows Privilege Escalation

Unpatched 'BlueHammer' Windows Zero-Day Lets Local Users Escalate to Admin — PoC Is Public

Supply Chain Malware Watering Hole

CPUID Website Breached — Trojanized CPU-Z and HWMonitor Downloads Delivered STX RAT for Six Hours

Zero-Day Adobe Reader Patching

Adobe Ships Emergency Patch for Acrobat Reader Zero-Day That Was Exploited for Five Months

WordPress Supply Chain Backdoor

Attackers Hijacked Smart Slider 3 Pro's Update Server to Push a Backdoor to 800,000 WordPress Sites

Vulnerability Python Remote Code Execution

Critical Marimo Python Notebook Flaw Exploited in Under 10 Hours After Public Disclosure

Patching Firewall Palo Alto Networks

Palo Alto Networks and SonicWall Release Patches for High-Severity Firewall and VPN Vulnerabilities

Zero-Day Adobe Reader Vulnerability

Adobe Reader Zero-Day Has Been Exploited Through Malicious PDFs Since Late 2025

OpenSSL Vulnerability Patching

OpenSSL Patches Seven Vulnerabilities Including a Data Leakage Flaw in RSASVE Key Encapsulation

Docker DevOps Vulnerability

Critical Docker Engine Flaw Lets Attackers Bypass Authorization Plugins and Access the Host

Phishing OAuth Microsoft 365

Device Code Phishing Attacks Have Surged 37x — Here's How to Stop Them

Linux Security PHP

How Attackers Are Hiding PHP Web Shells Inside HTTP Cookies on Linux Servers

Microsoft's Defender team uncovered a growing technique where attackers use HTTP cookies as a hidden command channel for PHP web shells — making them far harder to detect than traditional approaches.

Supply Chain DevOps AWS

How a Poisoned Trivy Update Gave Hackers the Keys to the European Commission's AWS

A supply chain attack against Trivy resulted in the European Commission losing 340 GB of data from its AWS environment — showing how dangerous a single compromised tool in a pipeline can be.

Vulnerability ShareFile Remote Code Execution

Critical ShareFile Vulnerabilities Allow Full RCE Without a Password — Patch Now

Two chained vulnerabilities in Progress ShareFile's Storage Zones Controller allow an unauthenticated attacker to go from zero access to full remote code execution on the server — no credentials needed.