Cyber Security
Application Security
Single-Letter Go Typosquat Backdoors Financial and Crypto Developers
Mitchell Langley
May 21, 2026
A Go module typosquatting shopspring/decimal deployed a DNS-based backdoor polling for OS commands every five minutes, targeting financial app developers.
Application Security
CVE-2026-46376: FreePBX Hard-Coded Credentials Open VoIP Portals
Mitchell Langley
May 21, 2026
CVE-2026-46376 in FreePBX hardcodes setup credentials in the User Control Panel, letting unauthenticated attackers access phone systems and commit toll fraud.
Cybersecurity
Pardus Linux CVSS 9.3 Flaw Exposes Turkish Government Systems to Root
Gabby Lee
May 21, 2026
A three-vulnerability chain in Pardus Linux's pardus-update package lets any local user gain root on Turkish government systems; no patch is available yet.
CVE Vulnerability Alerts
CVE-2026-46333: Linux Kernel Flaw Grants Root via ssh-keysign
Gabby Lee
May 21, 2026
Qualys disclosed CVE-2026-46333, a nine-year-old Linux privilege escalation flaw that gives local users a reliable path to root on Debian, Fedora, and Ubuntu.
CVE Vulnerability Alerts
CISA Adds Two Exploited Microsoft Defender Zero-Days to KEV
Andrew Doyle
May 21, 2026
Microsoft Defender is actively being exploited via two zero-days, CVE-2026-41091 and CVE-2026-45498, which CISA added to its KEV catalog on May 20, 2026.
Cybersecurity
Ukraine IDs 18-Year-Old Who Stole 28,000 Accounts, $721K
Gabby Lee
May 21, 2026
Ukrainian cyberpolice and U.S. law enforcement identified an 18-year-old from Odesa behind 28,000 stolen accounts and $721,000 in fraudulent purchases.
CVE Vulnerability Alerts
SonicWall Gen6 MFA Bypass CVE-2024-12802 Left Open by Incomplete Patch
Mitchell Langley
May 21, 2026
SonicWall's patch for CVE-2024-12802 needed a manual LDAP reconfiguration most admins skipped, leaving Gen6 VPN open to MFA bypass and ransomware access.
Cybersecurity
TeamPCP Claims Breach of 4,000 GitHub Private Repositories
Mitchell Langley
May 20, 2026
The hacker group TeamPCP claims unauthorized access to ~4,000 GitHub private repositories and is demanding a $50,000 ransom for the stolen source code.
CVE Vulnerability Alerts
CVE-2026-45585: Windows Zero-Day Bypasses BitLocker
Mitchell Langley
May 20, 2026
Microsoft disclosed CVE-2026-45585, a Windows zero-day that allows attackers with physical access to bypass BitLocker encryption without the decryption key.
Application Security
CVE-2026-45829: Max-Severity Flaw Lets Attackers Hijack ChromaDB
Andrew Doyle
May 20, 2026
CVE-2026-45829 is a maximum-severity pre-auth flaw in ChromaDB allowing server hijacking; about 73% of internet-exposed instances run a vulnerable version.
Cybersecurity
Microsoft Disrupts Fox Tempest Malware-Signing Service
Andrew Doyle
May 20, 2026
Microsoft seized Fox Tempest's signspace.cloud domain and revoked over 1,000 fraudulent code-signing certificates used by ransomware groups and infostealers.
Cybersecurity
B1ack’s Stash Releases 4.6M Stolen Credit Cards Free
Gabby Lee
May 20, 2026
B1ack's Stash dark-web marketplace released 4.6 million stolen card records for free, with 4.3 million actionable, after resellers violated its terms.
Cybersecurity
Trapdoor Android Ad Fraud Scheme Generated 659M Fake Bids
Mitchell Langley
May 20, 2026
HUMAN's Satori team disclosed Trapdoor, 455 malicious Android apps generating 659 million fake ad bids daily, with more than 24 million total downloads.
Application Security
Nx Console VS Code Extension Poisoned to Steal 1Password, AWS Keys
Andrew Doyle
May 20, 2026
Version 18.95.0 of the Nx Console VS Code extension was weaponized for 11 minutes to steal 1Password vaults, AWS credentials, and Claude Code secrets.
Cybersecurity
Storm-2949 Abuses Azure Password Reset to Seize Cloud Accounts
Gabby Lee
May 20, 2026
Microsoft tracks Storm-2949, a threat actor using SSPR social engineering to hijack Azure accounts without malware and extract Key Vault secrets and M365 data.
Application Security
Drupal Issues Highly Critical Patch, Exploits Expected Within Hours
Andrew Doyle
May 20, 2026
Drupal warned a highly critical vulnerability in versions 11.3.x through 10.5.x could be exploited within hours of its May 20, 2026 patch release date.
CVE Vulnerability Alerts
SEPPMail Gateway Hit with 7 CVEs, Including CVSS 10.0 RCE Flaw
Mitchell Langley
May 20, 2026
Seven vulnerabilities in SEPPMail Secure E-Mail Gateway, including a CVSS 10.0 pre-auth RCE, could let attackers intercept all protected mail traffic.
Cybersecurity
Grafana Breach Traced to TanStack npm Supply Chain Attack
Mitchell Langley
May 20, 2026
Grafana revealed the source code breach that exposed its GitHub repositories originated from a TanStack npm package poisoned by the TeamPCP threat actor.
CVE Vulnerability Alerts
CISA Orders Patch for Sixth Cisco SD-WAN Zero-Day of 2026
Andrew Doyle
May 19, 2026
Cisco confirmed active exploitation of CVE-2026-20182, a CVSS 10.0 authentication bypass in SD-WAN, as CISA gave federal agencies three days to patch.
Application Security
Exchange Server XSS CVE-2026-42897 Exploited via Crafted Email
Gabby Lee
May 19, 2026
Microsoft confirmed active exploitation of CVE-2026-42897, an XSS flaw in on-premises Exchange Server triggered when victims open malicious emails in OWA.
CVE Vulnerability Alerts
Critical FortiMail Zero-Day Exploited With No Patch Yet
Mitchell Langley
October 2, 2026
Cybersecurity
Ransomware Attack Disrupts Keio Corporation Business Systems
Mitchell Langley
September 29, 2026
TOP CYBERSECURITY HEADLINES
Application Security
Self-Healing WordPress Backdoor Defies Standard Removal
CVE Vulnerability Alerts
Cisco Patches Actively Exploited Catalyst SD-WAN Flaw
Cybersecurity
MetaMask Discloses Incident, Exits Ethereum Validators
CVE Vulnerability Alerts
TeamViewer Patches Critical Access-Control Bypass Flaw
This Week’s Security Spotlight
Cybersecurity
OpenAI Shelves GPT-6.1 Astra After Safety Failures and Rogue Actions
Mitchell Langley
September 29, 2026
Trending
Daily Briefing Newsletter
Subscribe to the Daily Security Review Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.
Featured Videos
Podcasts
Cyber Security News
- All
- Application Security
- Blog
- CVE Vulnerability Alerts
- Cybersecurity
- Cybersecurity Newsletter
- Data Security
- Endpoint Security
- Identity and Access Management
- Information Security
- Network Security
- News
- Phishing
- Podcasts
- Product Reviews
- Ransomware
- Ransomware Victims
- Resources
- Security Spotlight
- Sponsored
- Threat Actors
- Threat Actors
- Threat Detection Tools
CVE-2026-46333: Linux Kernel Flaw Grants Root via ssh-keysign
May 21, 2026
Qualys disclosed CVE-2026-46333, a nine-year-old Linux privilege escalation flaw that gives local users a reliable path to root on Debian, Fedora, and Ubuntu.
CISA Adds Two Exploited Microsoft Defender Zero-Days to KEV
May 21, 2026
Microsoft Defender is actively being exploited via two zero-days, CVE-2026-41091 and CVE-2026-45498, which CISA added to its KEV catalog on May 20, 2026.
Ukraine IDs 18-Year-Old Who Stole 28,000 Accounts, $721K
May 21, 2026
Ukrainian cyberpolice and U.S. law enforcement identified an 18-year-old from Odesa behind 28,000 stolen accounts and $721,000 in fraudulent purchases.
SonicWall Gen6 MFA Bypass CVE-2024-12802 Left Open by Incomplete Patch
May 21, 2026
SonicWall's patch for CVE-2024-12802 needed a manual LDAP reconfiguration most admins skipped, leaving Gen6 VPN open to MFA bypass and ransomware access.
TeamPCP Claims Breach of 4,000 GitHub Private Repositories
May 20, 2026
The hacker group TeamPCP claims unauthorized access to ~4,000 GitHub private repositories and is demanding a $50,000 ransom for the stolen source code.
CVE-2026-45585: Windows Zero-Day Bypasses BitLocker
May 20, 2026
Microsoft disclosed CVE-2026-45585, a Windows zero-day that allows attackers with physical access to bypass BitLocker encryption without the decryption key.
CVE-2026-45829: Max-Severity Flaw Lets Attackers Hijack ChromaDB
May 20, 2026
CVE-2026-45829 is a maximum-severity pre-auth flaw in ChromaDB allowing server hijacking; about 73% of internet-exposed instances run a vulnerable version.
Microsoft Disrupts Fox Tempest Malware-Signing Service
May 20, 2026
Microsoft seized Fox Tempest's signspace.cloud domain and revoked over 1,000 fraudulent code-signing certificates used by ransomware groups and infostealers.
B1ack’s Stash Releases 4.6M Stolen Credit Cards Free
May 20, 2026
B1ack's Stash dark-web marketplace released 4.6 million stolen card records for free, with 4.3 million actionable, after resellers violated its terms.
Trapdoor Android Ad Fraud Scheme Generated 659M Fake Bids
May 20, 2026
HUMAN's Satori team disclosed Trapdoor, 455 malicious Android apps generating 659 million fake ad bids daily, with more than 24 million total downloads.
Nx Console VS Code Extension Poisoned to Steal 1Password, AWS Keys
May 20, 2026
Version 18.95.0 of the Nx Console VS Code extension was weaponized for 11 minutes to steal 1Password vaults, AWS credentials, and Claude Code secrets.
Storm-2949 Abuses Azure Password Reset to Seize Cloud Accounts
May 20, 2026
Microsoft tracks Storm-2949, a threat actor using SSPR social engineering to hijack Azure accounts without malware and extract Key Vault secrets and M365 data.
Drupal Issues Highly Critical Patch, Exploits Expected Within Hours
May 20, 2026
Drupal warned a highly critical vulnerability in versions 11.3.x through 10.5.x could be exploited within hours of its May 20, 2026 patch release date.
SEPPMail Gateway Hit with 7 CVEs, Including CVSS 10.0 RCE Flaw
May 20, 2026
Seven vulnerabilities in SEPPMail Secure E-Mail Gateway, including a CVSS 10.0 pre-auth RCE, could let attackers intercept all protected mail traffic.
Grafana Breach Traced to TanStack npm Supply Chain Attack
May 20, 2026
Grafana revealed the source code breach that exposed its GitHub repositories originated from a TanStack npm package poisoned by the TeamPCP threat actor.
CISA Orders Patch for Sixth Cisco SD-WAN Zero-Day of 2026
May 19, 2026
Cisco confirmed active exploitation of CVE-2026-20182, a CVSS 10.0 authentication bypass in SD-WAN, as CISA gave federal agencies three days to patch.
Exchange Server XSS CVE-2026-42897 Exploited via Crafted Email
May 19, 2026
Microsoft confirmed active exploitation of CVE-2026-42897, an XSS flaw in on-premises Exchange Server triggered when victims open malicious emails in OWA.
Ghostwriter APT Deploys Cobalt Strike in Geofenced Ukraine Campaign
May 19, 2026
ESET documented a Ghostwriter spear-phishing campaign using geofenced PDFs to deliver Cobalt Strike against Ukrainian and Polish government targets since March 2026.
OpenAI Confirms Breach via Mini Shai-Hulud npm Supply Chain Attack
May 19, 2026
OpenAI confirmed two employee devices were compromised through a supply chain attack, exposing code-signing certificates for macOS, Windows, iOS, and Android apps.
KongTuke IAB Uses Microsoft Teams to Deploy ModeloRAT in 5 Minutes
May 19, 2026
ReliaQuest found KongTuke impersonating IT help desk staff via Microsoft Teams to trick employees into running PowerShell, deploying ModeloRAT and selling access to ransomware groups.





































