Microsoft patches SharePoint RCE flaw CVE-2026-45659 across server versions

Rabi LakshmananMay 26, 2026Vulnerabilities / Enterprise Security Microsoft has released an update that fixes a remote code execution vulnerability affecting SharePoint. This vulnerability could be exploited by a malicious attacker without any special conditions being met. This vulnerability is tracked as CVE-2026-45659 and has a CVSS score of 8.8. It has been assigned a severity […]

Why the second element won’t save you

Multi-factor authentication (MFA) was seen as filling a critical gap in identity security. This means that even if an attacker has the account credentials, they will not be able to log in without the second factor. This logic was good, but the attacker realized that he didn’t need to steal the second element, he just […]

CERT-In mandates 12-hour patching for internet-facing flaws during AI-assisted attacks

The Computer Emergency Response Team of India (CERT-In) has issued new guidelines requiring organizations to patch critical security vulnerabilities in internet-exposed systems within 12 hours of being flagged, in order to automate vulnerability discovery and exploitation and protect against potential threats arising from the misuse of artificial intelligence (AI) tools and large-scale language models (LLM) […]

Iranian hackers deploy MiniFast and MiniJunk V2 via phishing and SEO poisoning

The Iranian state-sponsored threat actor known as Nimbus Manticore (also known as Screening Serpens and UNC1549) is believed to have engaged in a new campaign using decoys impersonating aviation and software organizations across the United States, Europe, and the Middle East following the joint U.S.-Israeli military operation against the country in late February 2026. In […]

Exploiting flaws in KnowledgeDeliver LMS to deploy Godzilla and Cobalt Strike

Rabi LakshmananMay 26, 2026Vulnerability/Threat Intelligence A currently patched high-severity security flaw affecting Digital Knowledge KnowledgeDeliver, a popular learning management system (LMS) in Japan, was exploited as a zero-day to deliver the Godzilla web shell and ultimately facilitate the deployment of Cobalt Strike Beacon. The vulnerability, tracked as CVE-2026-5426 (CVSS score: 7.5), results from the use […]

Linux Flaws, Defender 0-Days, Router Botnets, and Supply Chain Chaos

Ravie LakshmananMay 25, 2026Cybersecurity / Hacking Monday recap. Same mess, new week. A sketchy dev tool got people pwned, old bugs came back from the dead, and security products somehow needed protecting from themselves. A bunch of companies spent the week checking old boxes and forgotten servers they should’ve patched years ago. Good times. Phishing […]

Ghost CMS CVE-2026-26980 exploited to hijack over 700 sites in ClickFix attack

Rabi LakshmananMay 25, 2026Vulnerabilities / Web Security Threat actors are exploiting recently revealed critical security flaws in Ghost CMS to inject malicious JavaScript code in order to facilitate ClickFix attacks. According to QiAnXin XLab, this activity involves the exploitation of CVE-2026-26980 (CVSS score: 9.4), a SQL injection vulnerability in Ghost’s Content API that could allow […]

Alert Firehose is finally here!

Ask cybersecurity experts about Network Detection and Response (NDR) and you may still hear that it’s too noisy and uses too much data. But if you ask teams running NDR that include agent AI capabilities, you’ll hear that they are actually using it to detect threats earlier, triage faster, and reduce false positives. The persistence […]

Lazarus Deploys RemotePE Memory-Only RAT for Financial and Crypto Companies

Rabi LakshmananMay 25, 2026Endpoint security/threat intelligence Cybersecurity researchers have uncovered a cross-platform malware called RemotePE used by the North Korean-linked Lazarus Group in attacks targeting financial institutions and cryptocurrency organizations. According to Fox-IT, a subsidiary of NCC Group, RemotePE is part of a multi-stage attack chain involving two loaders tracked as DPAPILoader and RemotePELoader. “DPAPILoader […]

TrapDoor supply chain attack spreads credential-stealing malware via npm, PyPI, CratesIO

A new coordinated cross-ecosystem software supply chain attack campaign targets npm, PyPI, and Crates.io and distributes credential-stealing malware. The campaign, codenamed “TrapDoor,” spans over 34 malicious packages across over 384 versions. The oldest activity was recorded on May 22, 2026 at 8:20 PM UTC, when new packages were published to the ecosystem from a cluster […]