News

Drupal Issues Highly Critical Patch, Exploits Expected Within Hours
Application Security
Drupal Issues Highly Critical Patch, Exploits Expected Within Hours
Drupal warned a highly critical vulnerability in versions 11.3.x through 10.5.x could be exploited within hours of its May 20, 2026 patch release date.
SEPPMail Gateway Hit with 7 CVEs, Including CVSS 10.0 RCE Flaw
CVE Vulnerability Alerts
SEPPMail Gateway Hit with 7 CVEs, Including CVSS 10.0 RCE Flaw
Seven vulnerabilities in SEPPMail Secure E-Mail Gateway, including a CVSS 10.0 pre-auth RCE, could let attackers intercept all protected mail traffic.
Grafana Breach Traced to TanStack npm Supply Chain Attack
Cybersecurity
Grafana Breach Traced to TanStack npm Supply Chain Attack
Grafana revealed the source code breach that exposed its GitHub repositories originated from a TanStack npm package poisoned by the TeamPCP threat actor.
CVE Vulnerability Alerts
CISA Orders Patch for Sixth Cisco SD-WAN Zero-Day of 2026
Cisco confirmed active exploitation of CVE-2026-20182, a CVSS 10.0 authentication bypass in SD-WAN, as CISA gave federal agencies three days to patch.
Application Security
Exchange Server XSS CVE-2026-42897 Exploited via Crafted Email
Microsoft confirmed active exploitation of CVE-2026-42897, an XSS flaw in on-premises Exchange Server triggered when victims open malicious emails in OWA.
Cybersecurity
Ghostwriter APT Deploys Cobalt Strike in Geofenced Ukraine Campaign
ESET documented a Ghostwriter spear-phishing campaign using geofenced PDFs to deliver Cobalt Strike against Ukrainian and Polish government targets since March 2026.
Application Security
OpenAI Confirms Breach via Mini Shai-Hulud npm Supply Chain Attack
OpenAI confirmed two employee devices were compromised through a supply chain attack, exposing code-signing certificates for macOS, Windows, iOS, and Android apps.
Cybersecurity
KongTuke IAB Uses Microsoft Teams to Deploy ModeloRAT in 5 Minutes
ReliaQuest found KongTuke impersonating IT help desk staff via Microsoft Teams to trick employees into running PowerShell, deploying ModeloRAT and selling access to ransomware groups.
Application Security
node-ipc npm Package Hid Credential Stealer Across Three Versions
Socket and StepSecurity found stealer backdoors in three node-ipc npm versions targeting 90 cloud and developer credential categories via an unknown new publisher account.
Application Security
PraisonAI CVE-2026-44338 Exploited 3h44m After Public Disclosure
Attackers began exploiting a missing-authentication flaw in PraisonAI's Flask API server 3 hours and 44 minutes after the CVE-2026-44338 advisory was published on May 11.