TanStack supply chain attack attacks two OpenAI employee devices, forcing macOS updates

OpenAI disclosed that two of its employee devices in its corporate environment were affected by the Mini Shai-Hulud supply chain attack on TanStack, but said that no user data, production systems, or intellectual property was compromised or modified in an unauthorized manner. “Once we identified the malicious activity, we quickly took steps to investigate, contain, […]

On-premises Microsoft Exchange Server CVE-2026-42897 can be exploited via crafted email

Rabi LakshmananMay 15, 2026Microsoft / Vulnerability Microsoft has disclosed a new security vulnerability affecting the on-premises version of Exchange Server and announced that it is being exploited in the wild. The vulnerability is tracked as CVE-2026-42897 (CVSS score: 8.1) and is described as a spoofing bug due to a cross-site scripting flaw. An anonymous researcher […]

CISA adds Cisco SD-WAN CVE-2026-20182 to KEV after administrator access exploit

Rabi LakshmananMay 15, 2026Vulnerability/Credential Theft The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a newly disclosed vulnerability affecting Cisco Catalyst SD-WAN controllers to its Known Exploited Vulnerabilities (KEV) catalog and asked federal civilian executive branch (FCEB) agencies to fix the issue by May 17, 2026. This vulnerability is a critical authentication bypass […]

Cisco Catalyst SD-WAN Controller Authentication Bypass Is Actively Abused to Gain Administrative Access

Rabi LakshmananMay 14, 2026Vulnerability/Network Security Cisco has released an update that addresses a maximum severity authentication bypass flaw in Catalyst SD-WAN controllers that it announced was exploited in a limited attack. This vulnerability is tracked as CVE-2026-20182 and has a CVSS score of 10.0. “A vulnerability in peering authentication for Cisco Catalyst SD-WAN Controller (formerly […]

Stealer backdoor targeting developer secrets found in three node IPC versions

Ravi LakshmananMay 14, 2026Developer security/supply chain attacks Cybersecurity researchers are sounding the alarm over alleged “malicious activity” in a newly released version of node-ipc. According to Socket and StepSecurity, three different versions of npm packages have been confirmed as malicious. node-ipc@9.1.6 node-ipc@9.2.3 node-ipc@12.0.1 “Initial analysis indicates that node-ipc@9.1.6, node-ipc@9.2.3, and node-ipc@12.0.1 contain obfuscated stealer/backdoor behavior,” […]

PAN-OS RCE, Mythos cURL Bug, AI Tokenizer Attacks, and 10+ Stories

Ravie LakshmananMay 14, 2026Hacking News / Cybersecurity News Everything is still on fire. This week feels dumb in the worst way — bad links, weak checks, fake help desks, shady forum posts, and people turning supply chain attacks into some cursed little game for clout and cash. Half of it feels new. Half of it […]

Ghostwriter, geofenced PDF phishing, and Cobalt Strike target Ukrainian government

A Belarusian threat group known as Ghostwriter is believed to be behind new attacks targeting government agencies in Ukraine. Ghostwriter has been active since at least 2016 and is said to be involved in both cyber espionage and influence operations targeting neighboring countries, particularly Ukraine. It has also been tracked under the names FrostyNeighbor, PUSHCHA, […]

PraisonAI CVE-2026-44338 Authentication bypass targeted within hours of release

Rabi LakshmananMay 14, 2026Vulnerabilities/API Security Threat actors have been observed attempting to exploit recently disclosed security vulnerabilities in PraisonAI, an open source multi-agent orchestration framework, within four hours of publication. The vulnerability in question is CVE-2026-44338 (CVSS score: 7.3), which exposes sensitive endpoints when authentication is missing, allowing an attacker to call protected functions of […]

How AI illusions are creating real security risks

AI illusions are abusing human trust through reliable but inaccurate outputs, posing serious security risks to critical infrastructure decision-making. If an AI model lacks certainty, there is no mechanism to recognize it. Instead, it generates the most likely response based on patterns in the training data, even if that response is inaccurate. These outputs can […]

Windows zero-day exposes BitLocker bypass and CTFMON privilege escalation

The anonymous cybersecurity researcher who disclosed three vulnerabilities in Microsoft Defender is back with two more zero-days involving BitLocker bypass and privilege escalation affecting Windows Collaborative Translation Framework (CTFMON). The security flaws have been codenamed YellowKey and GreenPlasma by researchers operating under the online aliases Chaotic Eclipse and Nightmare-Eclipse, respectively. The researcher described YellowKey as […]