loader image
GitHub Actions Tags Redirected to Steal CI/CD Keys

In a concerning development, threat actors have targeted GitHub Actions tags, redirecting them to unauthorized commit points as part of a sophisticated software supply chain attack. This breach specifically involves the popular GitHub Actions workflow, actions-cool/issues-helper, which attackers have manipulated to execute malicious code. This code is designed to harvest sensitive CI/CD credentials and transmit […]

Microsoft Entra ID Used to Steal Azure, M365 Data

Microsoft Entra ID was recently exploited by hackers in a sophisticated cyberattack targeting Microsoft 365 and Azure data. This incident involved a compromised version of the Nx Console VS Code extension, which appeared on the Visual Studio Code Marketplace on May 18, 2026. The malware targeted developer credentials, cloud tokens, and CI/CD secrets, spreading across […]

Pwn2Own Berlin Pays $1.3 Million to Hackers

The recent Pwn2Own Berlin 2026 competition showcased the prowess of security researchers as they collectively earned $1,298,250 for discovering and exploiting 47 zero-day vulnerabilities. This esteemed contest, known for rewarding top-notch hacking skills, saw participants tackle a range of software and hardware challenges. Their success underscores the importance of public cybersecurity events in identifying flaws […]

Anthropic’s Claude Code Exposes RCE via Deeplinks

Anthropic’s Claude Code tool recently faced a significant security breach due to a remote code execution (RCE) flaw. Discovered by security researcher Joernchen of 0day.click, this vulnerability allowed attackers to execute arbitrary commands on a victim’s machine using malicious deeplinks. The issue originated from a naive command-line argument parser in the tool’s claude-cli:// deeplink handler. […]

Windows MiniPlasma Zero-Day Gives SYSTEM Access

A cybersecurity researcher has unveiled a proof-of-concept exploit for a Windows vulnerability known as ‘MiniPlasma’. This Windows Miniplasma zero-day allows attackers to gain SYSTEM privileges even on fully updated Windows systems. The exploit poses a serious threat, as it enables malicious actors to take over a system with elevated permissions, potentially leading to significant data […]

Burst Statistics Flaw Exposes 200K WordPress Sites

A critical vulnerability, known as the Burst Statistics flaw, has compromised over 200,000 websites by allowing attackers to bypass authentication and take control of accounts. The flaw, identified by Wordfence’s PRISM platform on May 8, 2026, impacts the Burst Statistics plugin used for privacy-focused analytics on WordPress sites. This vulnerability, tracked as CVE-2026-8181 with a […]

GitLab Issues Critical Patch for XSS, DoS Flaws

GitLab has issued a critical patch to address high-severity vulnerabilities impacting its self-managed instances. The update, available for both Community Edition (CE) and Enterprise Edition (EE), comprises versions 18.11.3, 18.10.6, and 18.9.7. These patches fix serious security flaws, including a cross-site scripting (XSS) vulnerability and an unauthenticated denial-of-service (DoS) flaw, which could potentially be exploited […]

OPNsense Flaw Enables Root RCE

The cybersecurity community is on high alert following the disclosure of critical security vulnerabilities within OPNsense firewalls. These vulnerabilities, identified as CVE-2026-44194 and CVE-2026-45158, allow attackers to execute remote code with root privileges. The OPNsense flaw enables root access, posing significant risks to these widely used open-source firewall systems. The exposure of full technical details […]

18-Year-Old NGINX Flaw Allows Unauthenticated RCE

An 18-year-old NGINX flaw has emerged as a significant cybersecurity threat. Depthfirst recently identified a critical vulnerability in both NGINX Plus and NGINX Open, which could have severe implications for server security. This flaw is a heap buffer overflow issue within the ngx_http_rewrite_module, tagged as CVE-2026-42945, with a CVSS v4 score of 9.2. Such a […]

Microsoft BitLocker Bypassed by YellowKey 0-Day

A newly surfaced security threat poses a significant risk to Microsoft users, as unpatched zero-day vulnerabilities allow the Microsoft BitLocker encryption to be bypassed. Dubbed “YellowKey,” this critical flaw grants attackers full access to locked system drives used in Windows 11, Server 2022, and Server 2025. Highlighted alongside is “GreenPlasma,” a vulnerability that exploits the […]

TrickMo Variant Hijacks Phones to Steal Wallets

A new TrickMo variant hijacks phones, posing a serious threat to Android users by targeting banking, wallet, and authenticator apps. Identified by analysts at ThreatFabric, this variant elevates the malware’s capabilities through improved stealth tactics. Once users install the deceptive malware via fake TikTok apps, it gains extensive control by exploiting accessibility permissions. TrickMo intercepts […]

M23-Held Rubaya Landslides Kill Hundreds

In the M23-held Rubaya landslides, which have occurred since early 2026, hundreds of lives have been lost along the Democratic Republic of Congo’s coltan-rich Rubaya mines. The mines, a crucial source for smartphone and e-vehicle components, operate under perilous conditions. Despite global attention, access remains restricted due to control by the Rwandan-backed M23 group. Bellingcat […]