How OAuth consent bypasses MFA

In February 2026, a phishing-as-a-service (PhaaS) platform called EvilTokens went live. Within five weeks, more than 340 Microsoft 365 organizations in five countries were compromised. Platform targets received a message asking them to enter a short code at microsoft.com/devicelogin to complete a regular MFA challenge and left believing they had confirmed a routine sign-in. In […]
Drupal releases emergency core security update on May 20th, sites are told to prepare

Ravi LakshmananMay 19, 2026Vulnerabilities / Website Security Drupal has issued an alert stating that it plans to release a “Core Security Release” for all supported branches on May 20, 2026 from 5:00 PM to 9:00 PM (UTC). A maintainer of a PHP-based content management system (CMS) said, “The Drupal security team recommends that you allow […]
Vulnerability in SEPPMail Secure E-Mail Gateway allows RCE and email traffic access

Ravi LakshmananMay 19, 2026Vulnerabilities / Email Security A critical security vulnerability has been disclosed in SEPPMail Secure E-Mail Gateway, an enterprise-grade email security solution. This vulnerability could be exploited to cause remote code execution and allow an attacker to read arbitrary email from the virtual appliance. “These vulnerabilities could be exploited to read all email […]
Nx Console 18.95.0 compromised and VS Code developers targeted by Credential Stealer

Ravi LakshmananMay 19, 2026Supply chain attacks/developer security Cybersecurity researchers reported a compromised version of the Nx Console extension published to the Microsoft Visual Studio Code (VS Code) marketplace. The extension in question is rwl.angular-console (version 18.95.0), a popular user interface and plugin for code editors such as VS Code, Cursor, and JetBrains. Over 2.2 million […]
Popular GitHub action tag redirects to fraudsters stealing CI/CD credentials

Ravi LakshmananMay 19, 2026Software security/malware In yet another software supply chain attack, threat actors compromised the popular GitHub Actions workflow, actions-cool/issues-helper, collected sensitive credentials, and executed malicious code that was leaked to attacker-controlled servers. “All existing tags in the repository were moved to point to the impostor commit, which does not appear in the action’s […]
Mini Shai-Hulud pushes malicious AntV npm packages via compromised maintainer account

Cybersecurity researchers have discovered a new software supply chain attack campaign that compromises various npm packages associated with the @antv ecosystem as part of the ongoing Mini Shai-Hulud attack wave. “This attack affects packages associated with the npm maintainer account atool, including echarts-for-react, a widely used React wrapper for Apache ECharts that is downloaded approximately […]
Interpol’s Operation Ramz disrupts MENA cybercrime network, arrests 201 people

Interpol coordinated its first cybercrime crackdown across the Middle East and North Africa (MENA), resulting in 201 arrests and the identification of a further 382 suspects. The effort, which ran from October 2025 to February 2026, involved efforts from 13 countries in the region and aimed to investigate and neutralize malicious infrastructure, apprehend the perpetrators […]
Exchange 0-Day, npm Worm, Fake AI Repo, Cisco Exploit and More

Ravie LakshmananMay 18, 2026Cybersecurity / Hacking Monday opens with a trust problem. A mail server flaw is under active use. A network control system was targeted. Trusted packages were poisoned. A fake model page pushed a stealer. Then came the familiar ransom claim: the data was returned and deleted. The pattern is clear. One weak […]
How to reduce phishing exposure before it leads to business disruption

What if a phishing email seems safe enough to get past security, but is dangerous enough to expose your business with just one click? That’s the gap that many SOCs still have. The attack left the team unsure of what was exposed, who else was targeted, and how far the risk spread. Detecting phishing early […]
Developer workstations are now part of the software supply chain

Supply chain attackers aren’t just trying to sneak malicious code into trusted software. They seek to steal access that enables trusted software. Recently, three separate campaigns attacked npm, PyPI, and Docker Hub within 48 hours, targeting three secrets from developer environments and CI/CD pipelines, including API keys, cloud credentials, SSH keys, and tokens. This is […]