loader image
Dark-Web Brokers Sell Old Breaches as New

Dark-web brokers are creating havoc by recycling old breach data and passing it off as fresh corporate leaks. Operating primarily in Chinese-language cybercrime forums, these brokers are deceiving organizations into responding to incidents that are not genuine. This activity is causing significant alarm among global security teams as they struggle to differentiate real threats from […]

Zombie Account Let Hackers Control City Water

A security breach recently allowed hackers to seize control of a city’s water system due to an inactive account, often referred to as a “zombie account.” The incident highlights the critical oversight of not disabling accounts that belong to former employees. Such oversight can lead to severe risks for municipal infrastructure. In this case, the […]

EU Breaks With Big Tech After Trump Push

The EU is experiencing an unprecedented shift as it moves away from American tech giants, with “eu breaks” being evident in its strategic choices. France has already opted for locally-sourced communication solutions, opting out of widely-used platforms like Zoom and Microsoft Teams. This move reflects broader European sentiments, as other member countries swiftly reconsider their […]

GitHub Internal Repos Hit by Malicious Nx Console

GitHub has confirmed a breach of its internal repositories, caused by a compromised employee device due to a malicious version of the Nx Console Visual Studio Code extension. This breach marks a significant cybersecurity incident, raising concerns about the security protocols of widely-used platforms. The issue arose when unauthorized actors gained access to a developer’s […]

Mini Shai-Hulud Hijacks AntV Npm Packages

The mini Shai-Hulud hijacks have unveiled a new dimension in software supply chain attacks, as cybersecurity experts reveal a breach compromising assorted npm packages in the @antv ecosystem. This campaign exploits the npm maintainer account known as atool, notably affecting echarts-for-react. This specific React wrapper for Apache ECharts enjoys widespread usage, with about 1.1 million […]

Europol Removes 14,200 IRGC Propaganda Links

Europol removes a major online propaganda network linked to the Iranian Revolutionary Guard Corps (IRGC), taking down 14,200 extremist links spread across multiple digital platforms. In a concerted effort to combat misinformation, the European Union’s law enforcement agency worked alongside international partners to dismantle the network orchestrating these propaganda activities. The operation not only targeted […]

GitHub Actions Tags Redirected to Steal CI/CD Keys

In a concerning development, threat actors have targeted GitHub Actions tags, redirecting them to unauthorized commit points as part of a sophisticated software supply chain attack. This breach specifically involves the popular GitHub Actions workflow, actions-cool/issues-helper, which attackers have manipulated to execute malicious code. This code is designed to harvest sensitive CI/CD credentials and transmit […]

Microsoft Entra ID Used to Steal Azure, M365 Data

Microsoft Entra ID was recently exploited by hackers in a sophisticated cyberattack targeting Microsoft 365 and Azure data. This incident involved a compromised version of the Nx Console VS Code extension, which appeared on the Visual Studio Code Marketplace on May 18, 2026. The malware targeted developer credentials, cloud tokens, and CI/CD secrets, spreading across […]

Pwn2Own Berlin Pays $1.3 Million to Hackers

The recent Pwn2Own Berlin 2026 competition showcased the prowess of security researchers as they collectively earned $1,298,250 for discovering and exploiting 47 zero-day vulnerabilities. This esteemed contest, known for rewarding top-notch hacking skills, saw participants tackle a range of software and hardware challenges. Their success underscores the importance of public cybersecurity events in identifying flaws […]

Anthropic’s Claude Code Exposes RCE via Deeplinks

Anthropic’s Claude Code tool recently faced a significant security breach due to a remote code execution (RCE) flaw. Discovered by security researcher Joernchen of 0day.click, this vulnerability allowed attackers to execute arbitrary commands on a victim’s machine using malicious deeplinks. The issue originated from a naive command-line argument parser in the tool’s claude-cli:// deeplink handler. […]

Windows MiniPlasma Zero-Day Gives SYSTEM Access

A cybersecurity researcher has unveiled a proof-of-concept exploit for a Windows vulnerability known as ‘MiniPlasma’. This Windows Miniplasma zero-day allows attackers to gain SYSTEM privileges even on fully updated Windows systems. The exploit poses a serious threat, as it enables malicious actors to take over a system with elevated permissions, potentially leading to significant data […]

Burst Statistics Flaw Exposes 200K WordPress Sites

A critical vulnerability, known as the Burst Statistics flaw, has compromised over 200,000 websites by allowing attackers to bypass authentication and take control of accounts. The flaw, identified by Wordfence’s PRISM platform on May 8, 2026, impacts the Burst Statistics plugin used for privacy-focused analytics on WordPress sites. This vulnerability, tracked as CVE-2026-8181 with a […]