News

Cybersecurity
SideCopy APT Targets Afghan Finance Ministry with Xeno RAT
Pakistan-attributed SideCopy APT used Pashto-language LNK lures against Afghanistan's Finance Ministry, deploying Xeno RAT for full system access and exfil.
Application Security
Meta AI Chatbot Flaw Lets Attackers Hijack Instagram Accounts
A confused deputy flaw in Meta's AI support chatbot let attackers hijack Instagram accounts including @obamawhitehouse, Sephora, and U.S. Space Force.
Application Security
Red Hat npm Packages Backdoored with Miasma Credential Worm
Attackers backdoored 32 Red Hat npm packages with the Miasma worm, stealing CI/CD secrets, cloud keys, and SSH keys across roughly 80,000 weekly downloads.
CVE Vulnerability Alerts
Google Patches Android Zero-Day CVE-2025-48595 Under Active Exploit
Google confirmed CVE-2025-48595, a no-interaction privilege escalation flaw in Android 14–16, is under active targeted attack. Patches arrive June 5.
CVE Vulnerability Alerts
CVE-2026-41089 Exploited: Windows Netlogon RCE Under Active Attack
Belgium's CCB confirmed active exploitation of CVE-2026-41089, a CVSS 9.8 unauthenticated Windows Netlogon RCE affecting all supported Windows Server versions.
Application Security
Malicious npm Package codexui-android Steals OpenAI Tokens at Scale
A malicious npm package named codexui-android harvested OpenAI Codex authentication tokens from developers at roughly 29,000 weekly downloads before removal.
Application Security
WP Maps Pro Flaw Exploited to Create Unauthorized Admin Accounts
An unauthenticated privilege escalation flaw in WP Maps Pro, a WordPress plugin with 15,000 paid sites, is actively exploited to create unauthorized administrator accounts.
CVE Vulnerability Alerts
PAN-OS CVE-2026-0257 Exploited Just 4 Days After Public Disclosure
CVE-2026-0257, a PAN-OS GlobalProtect authentication bypass, saw active exploitation begin just four days after public disclosure, with attacks ongoing for weeks.
CVE Vulnerability Alerts
CIFSwitch Linux Kernel Flaw Gets Public PoC, Root Access Possible
CIFSwitch is a 19-year-old Linux kernel privilege escalation flaw with a public PoC that enables root access on Ubuntu, RHEL, Debian, and other distributions.
Application Security
Public Exploit Raises Flowise CVE-2026-40933 RCE to Immediate Risk
Public exploit code for CVE-2026-40933 now targets Flowise, a self-hosted AI chatflow builder, via a one-click malicious import that executes arbitrary code on the server.