Marimo CVE-2026-39987 After exploitation, attacker uses LLM agent for post-exploitation purposes

Rabi LakshmananMay 29, 2026Vulnerability / Artificial Intelligence After exploiting the publicly accessible Marimo network using recently disclosed vulnerabilities and gaining initial access, unknown attackers have been observed using large-scale language model (LLM) agents to perform post-compromise actions. “The attacker compromised a Marimo notebook with internet access via CVE-2026-39987, extracted two cloud credentials from the compromised […]
New Russian-linked GREYVIBE targets Ukraine with AI-powered cyber attack

Rabi LakshmananMay 29, 2026Cyber espionage/artificial intelligence A previously undocumented threat actor known as GREYVIBE is believed to have been conducting sustained and persistent attacks targeting Ukraine and Ukrainian-affiliated entities since at least August 2025. According to WithSecure, GREYVIBE is assessed to be a Russian-speaking group widely active in the Russian time zone and whose activities […]
2,000 Vibe-encoded apps exposed, exposing the limitations of most security stacks

Shadow AI meant employees pasting things into ChatGPT that they shouldn’t. It now has a larger meaning, with employees building complete applications using AI, connecting them to production systems, and publishing them on the open internet. No need to involve security or IT. Artifacts have been moved from prompts to products. The risk profile has […]
Malicious Sicoob NuGet steals banking credentials as npm package targets cloud secrets

Cybersecurity researchers discovered a malicious NuGet package posing as a C# software development kit from Sicoob, one of Brazil’s largest cooperative financial systems, and siphoning client IDs and PFX certificates. According to Socket, versions 2.0.0 to 2.0.4 of Sicoob.Sdk include the ability to extract sensitive information such as PFX certificates used to authenticate businesses on […]
Kimsuky introduces HTTPSpy and expands his arsenal with HelloDoor and VS Code tunnels

A North Korean state-sponsored threat actor known as Kimsky (also known as Velvet Chorima) is believed to have been responsible for a new round of cyberattacks targeting South Korean military and businesses from March to April 2026. “Kimsuky employed a variety of customized social engineering tactics, including spoofing security software installation pages and creating fake […]
Critical vulnerability in Gogs RCE could allow authenticated users to execute arbitrary code

Rabi LakshmananMay 28, 2026Vulnerabilities / Open Source A critical security vulnerability has been disclosed in Gogs, a popular open source self-hosted Git service, that could allow authenticated users to execute arbitrary code under certain conditions. According to Rapid7, this security flaw is rated 9.4 on the CVSS scoring system. There is no CVE identifier. “This […]
Threat actors exploit critical flaw in FortiClient EMS to deploy credential stealer

Rabi LakshmananMay 28, 2026Vulnerabilities / Endpoint Security Attackers continue to exploit patched critical security flaws affecting FortiClient Endpoint Management Server (EMS) deployments to distribute credential-stealing malware. “This campaign exploited trusted endpoint management infrastructure to distribute malware across managed endpoints,” Arctic Wolf said. “Threat actors disguised the credential-stealing payload as a Fortinet endpoint update and silently […]
Microsoft condemns zero-day release while GitHub Researcher account deletion

Rabi LakshmananMay 28, 2026Zero-day/vulnerability disclosure Microsoft strongly supports Coordinated Vulnerability Disclosure (CVD) and urges the research community to share its findings and give affected vendors an opportunity to better understand the impact and take action before the information becomes public. The development comes after a researcher named Chaotic Eclipse (also known as Nightmare-Eclipse) disclosed details […]
Claude Security Plugin, Azure Priv-Esc, Kali365 MFA Bypass, FIFA Scams +15 More

Ravie LakshmananMay 28, 2026Hacking News / Cybersecurity News Every time you think the industry has finally stopped doing some reckless, low-effort crap, somebody spins up a fresh box full of sketchy loaders, fake installers, recycled social-engineering bait, and enough exposed infrastructure to make you wonder if prod is just a public beta now – meanwhile […]
Enterprise AI risks are concentrated in a small group of AI “power users”

LayerX Security’s AI Usage Report 2026 (full report here) reveals the extent of the enterprise AI visibility gap and why most organizations still don’t understand where their AI exposure is actually coming from. This research shows that enterprises’ AI risks are not evenly distributed across users or platforms. Instead, it concentrates on a small number […]