Latest Articles

Mini Shai-Hulud Supply-Chain Attack Hits SAP, Lightning, and Intercom Packages, Exposing Developer Secrets at Scale

Mini Shai-Hulud Supply-Chain Attack Hits SAP, Lightning, and Intercom Packages, Exposing Developer Secrets at Scale

The Mini Shai-Hulud campaign is a reminder that a poisoned package does not need months of persistence to create an enterprise incident. A few hours in the wrong dependency chain can be enough to...

European Commission Accuses Meta of Breaching Child Safety Rules Under Digital Services Act

European Commission Accuses Meta of Breaching Child Safety Rules Under Digital Services Act

The European Commission has issued preliminary findings accusing Meta Platforms Inc. of failing to adequately protect minors on its platforms, particularly Instagram and Facebook. The allegations...

Hackers Exploit Qinglong RCE Vulnerabilities (CVE-2026-3965 & CVE-2026-4047) to Deploy Cryptominers on Developer Servers

Hackers Exploit Qinglong RCE Vulnerabilities (CVE-2026-3965 & CVE-2026-4047) to Deploy Cryptominers on Developer Servers

A sophisticated cyberattack campaign has emerged targeting developers and DevOps environments by exploiting critical vulnerabilities in the Qinglong open-source task scheduler. Attackers leveraged...

Checkmarx KICS Supply Chain Compromise: Attackers Hijack Docker Images and VS Code Extensions to Steal Developer Secrets

Checkmarx KICS Supply Chain Compromise: Attackers Hijack Docker Images and VS Code Extensions to Steal Developer Secrets

On April 22, 2026, a sophisticated supply chain attack targeted Checkmarx's popular open source Infrastructure as Code (IaC) scanning tool KICS. Attackers gained access to official distribution...

Vimeo Data Breach via Anodot Exposes Emails and Metadata as ShinyHunters Escalates SaaS Extortion

Vimeo Data Breach via Anodot Exposes Emails and Metadata as ShinyHunters Escalates SaaS Extortion

Vimeo was not breached through a flashy exploit or a direct hit on its core video platform. The more important story is quieter: a trusted analytics integration became the path into downstream...

VECT 2.0 Ransomware: The Flawed Multi-Platform Threat That Destroys Critical Files Instead of Encrypting Them

VECT 2.0 Ransomware: The Flawed Multi-Platform Threat That Destroys Critical Files Instead of Encrypting Them

In the ever-evolving landscape of cyber threats, a new ransomware variant has emerged that challenges traditional assumptions about extortion-based attacks. VECT 2.0, a ransomware-as-a-service...

M3RX Claims Data Breach at Anvil Arts: Sensitive and Operational Information Accessed from Leading UK Performing Arts Organization

M3RX Claims Data Breach at Anvil Arts: Sensitive and Operational Information Accessed from Leading UK Performing Arts Organization

In a development that has sent ripples through the United Kingdom's cultural landscape, the hacker group known as M3RX has publicly claimed responsibility for a significant breach targeting Anvil...

GlassWorm Campaign Escalates: 73 Malicious Open VSX Sleeper Extensions Activate New Supply Chain Threats in 2026

GlassWorm Campaign Escalates: 73 Malicious Open VSX Sleeper Extensions Activate New Supply Chain Threats in 2026

April 2026 marks a significant escalation in the ongoing GlassWorm campaign, as security researchers from Socket have identified 73 malicious sleeper extensions on the Open VSX marketplace. These...

Litecoin Zero-Day Vulnerability Exploited in DoS Attack Disrupts Major Mining Pools: Technical Analysis, Impact, and Mitigation

Litecoin Zero-Day Vulnerability Exploited in DoS Attack Disrupts Major Mining Pools: Technical Analysis, Impact, and Mitigation

A critical zero-day vulnerability in the Litecoin network has recently been exploited to launch a large-scale denial-of-service (DoS) attack, temporarily disrupting operations across several major...

Supply Chain Attack on Xinference PyPI Package Exposes AI Developers to Widespread Credential Theft

Supply Chain Attack on Xinference PyPI Package Exposes AI Developers to Widespread Credential Theft

p>In a concerning development for the artificial intelligence and machine learning community, three consecutive versions of the popular Xinference Python package on PyPI were compromised with...

SimpleHelp CVE-2024-57726: Critical API Key Flaw Enables Server Admin Takeover

SimpleHelp CVE-2024-57726: Critical API Key Flaw Enables Server Admin Takeover

A low-privilege technician account should not become the master key to a remote support server. In vulnerable SimpleHelp deployments, CVE-2024-57726 breaks that boundary. The flaw allows...

ShinyHunters Claims Udemy Breach, Threatens Leak of 1.4 Million User Records

ShinyHunters Claims Udemy Breach, Threatens Leak of 1.4 Million User Records

A claimed breach at Udemy is not just another “user records” headline. If ShinyHunters’ claim proves accurate, the exposed data could give attackers a useful map of learners, instructors, corporate...

ADT Data Breach: Home Security Giant Confirms Cyber Intrusion by ShinyHunters Extortion Group

ADT Data Breach: Home Security Giant Confirms Cyber Intrusion by ShinyHunters Extortion Group

On April 24, 2026, ADT Inc. confirmed that unauthorized actors accessed a limited set of customer and prospective customer data. The confirmation followed public threats from the extortion group...

Citizens Bank and Frost Bank Confirm Vendor Data Incident After Everest Ransomware Claims Millions of Records

Citizens Bank and Frost Bank Confirm Vendor Data Incident After Everest Ransomware Claims Millions of Records

Two major US banks are now dealing with the same uncomfortable question: how much customer risk can sit outside the bank, inside a vendor’s environment, before it becomes the bank’s incident...

Bluesky Hit by Sophisticated 24-Hour DDoS Attack: Pro-Iran Group 313 Team Claims Responsibility, Raising Questions on Platform Resilience

Bluesky Hit by Sophisticated 24-Hour DDoS Attack: Pro-Iran Group 313 Team Claims Responsibility, Raising Questions on Platform Resilience

Bluesky, the decentralized social media platform, faced a prolonged and sophisticated distributed denial-of-service attack that began late on April 15, 2026. The incident started around 11:40 PM...

Anthropic Investigates Vendor Breach of Claude Mythos as Discord Group Accessed Offensive Cyber AI While CISA Sits Locked Out

Anthropic Investigates Vendor Breach of Claude Mythos as Discord Group Accessed Offensive Cyber AI While CISA Sits Locked Out

The most capable offensive-security AI model Anthropic has ever built was compromised not by a novel exploit chain, but by a contractor login and an educated guess about a URL pattern. That single...

Venice Flood Control OT Breach Claim Puts Piazza San Marco Defenses Under Pressure

Venice Flood Control OT Breach Claim Puts Piazza San Marco Defenses Under Pressure

For most cities, a cyber intrusion is a data problem. For Venice, it can become a water problem. That is what makes the reported breach of the Piazza San Marco flood-control environment so...

Rituals Cosmetics Confirms Customer Data Stolen in Membership Database Breach

Rituals Cosmetics Confirms Customer Data Stolen in Membership Database Breach

Loyalty programs are breach goldmines. They aggregate exactly what attackers want — verified identities, physical addresses, purchase histories, and contact details - all in one database, all tied to...

CVE-2026-33825 BlueHammer Exploited as Defender Becomes Its Own Attack Vector

CVE-2026-33825 BlueHammer Exploited as Defender Becomes Its Own Attack Vector

All Windows endpoints running Microsoft Defender face active exploitation of three privilege escalation and defense-degradation zero-days; only one has a patch, and two remain open with no...

BravoX Ransomware Hits 1st Solution CTC in Latest Cyberattack on German Training and Auditing Firm

BravoX Ransomware Hits 1st Solution CTC in Latest Cyberattack on German Training and Auditing Firm

On April 22, 2026, the emerging ransomware group BravoX publicly listed 1st Solution CTC as a new victim on its data leak site. The claim quickly gained attention in cybersecurity monitoring...