Ivanti, Fortinet, SAP, VMware, n8n Patch RCE, SQL injection, privilege escalation flaw

Ravi LakshmananMay 18, 2026Vulnerabilities/Software Security Ivanti, Fortinet, n8n, SAP, and VMware have released security fixes for various vulnerabilities that could be exploited by malicious parties to bypass authentication and execute arbitrary code. Topping the list is a critical flaw affecting Ivanti Xtraction (CVE-2026-8043, CVSS score: 9.6) that could be exploited for information disclosure or client-side […]
Four malicious npm packages deliver information theft and Phantom Bot DDoS malware

Ravi LakshmananMay 18, 2026Supply chain attack/botnet Cybersecurity researchers have discovered four new npm packages containing information-stealing malware. One of them is a clone of the Shai-Hulud worm that was open sourced by TeamPCP. The list of identified packages is below – chalk-tempalte (825 downloads) @deadcode09284814/axios-util (284 downloads) axois-utils (963 downloads) color-style-utils (934 downloads) “One of […]
Stuxnet Fast16 and earlier malware tampers with nuclear weapon simulation

Ravi LakshmananMay 18, 2026Industrial sabotage/malware New analysis of the Lua-based fast16 malware confirms that it is a cyber-jamming tool designed to tamper with nuclear weapons test simulations. The Broadcom-owned Symantec and Carbon Black teams say tools before Stuxnet were designed to subvert uranium compression simulations, which are central to nuclear weapons design. “Fast16’s hook engine […]
MiniPlasma Windows 0-Day enables SYSTEM privilege escalation on fully patched systems

Ravi LakshmananMay 18, 2026Zero-day/vulnerabilities Chaotic Eclipse, the security researchers behind the recently revealed Windows flaws YellowKey and GreenPlasma, has released a proof of concept (PoC) for a Windows privilege escalation zero-day flaw that grants an attacker SYSTEM privileges on a fully patched Windows system. Codenamed MiniPlasma, the vulnerability affects ‘cldflt.sys’, which refers to the Windows […]
NGINX CVE-2026-42945 can be exploited in the wild to cause worker crash and possible RCE

Ravi LakshmananMay 17, 2026Server security/vulnerabilities According to VulnCheck, a newly disclosed security flaw affecting NGINX Plus and NGINX Open has become exploitable in the wild just days after its publication. The vulnerability, tracked as CVE-2026-42945 (CVSS score: 9.2), is a heap buffer overflow in ngx_http_rewrite_module that affects NGINX versions 0.6.27 through 1.30.0. According to AI-native […]
Grafana GitHub token compromise led to codebase downloads and extortion attempts

Ravi LakshmananMay 17, 2026Data breach/cyber crime Grafana revealed that an “unauthorized party” obtained a token that gave them permission to access the company’s GitHub environment and download its codebase. “Our investigation has determined that no customer data or personal information was accessed in this incident, and we found no evidence of any impact on customer […]
Actively exploited funnel builder flaw allows WooCommerce checkout skimming

Ravi LakshmananMay 16, 2026Vulnerabilities / Website Security A critical security vulnerability affecting the Funnel Builder plugin for WordPress has been exploited to inject malicious JavaScript code into WooCommerce checkout pages with the purpose of stealing payment data. Details of the activities were announced by Sunsec this week. This vulnerability currently does not have a formal […]
Turla turns Kazuar backdoor into modular P2P botnet for persistent access

Ravi LakshmananMay 15, 2026Botnet/Threat Intelligence A Russian state-sponsored hacking group known as Turla transformed the custom backdoor Katar into a modular peer-to-peer (P2P) botnet designed for stealthy and persistent access to compromised hosts. According to the U.S. Cybersecurity and Infrastructure Security Agency (CISA), Turla has been assessed as belonging to Center 16 of Russia’s Federal […]
Four OpenClaw flaws allow data theft, privilege escalation, and persistence

Ravi LakshmananMay 15, 2026Vulnerability/AI Security Cybersecurity researchers have revealed a series of four security flaws in OpenClaw that can be chained together to achieve data theft, privilege escalation, and persistence. The vulnerabilities, collectively referred to as “Claw Chain” by Cyera, could allow attackers to establish a foothold, expose sensitive data, and install backdoors. A brief […]
What you can learn about your real attack surface by observing your tools for 45 days

hacker newsMay 15, 2026Endpoint security/threat detection In “The Biggest Security Risk Isn’t Malware — It’s What You Already Trust,” I made the simple argument that the most dangerous activity within most organizations no longer looks like an attack. It’s administrative-like. PowerShell, WMIC, netsh, Certutil, MSBuild — the same trusted utilities that IT teams use every […]