RubyGems suspends new signups after hundreds of malicious packages are uploaded

Ravi LakshmananMay 12, 2026Supply chain attacks/software security RubyGems, the standard package manager for the Ruby programming language, has suspended account sign-ups following what it describes as a “large-scale malicious attack.” “We are currently dealing with a large-scale malicious attack against Ruby Gems,” Maciej Mensfeld, senior product manager of software supply chain security at Mend.io, said […]
New TrickMo variant creates Android network pivot using TON C2 and SOCKS5

Ravi LakshmananMay 12, 2026Malware/Mobile Security Cybersecurity researchers have reported a new version of TrickMo, an Android banking Trojan that uses The Open Network (TON) for command and control (C2). This new variant was observed by ThreatFabric from January to February 2026 and was observed actively targeting users of banks and crypto wallets in France, Italy, […]
Webinar: What are the riskiest SOC alerts that go unanswered?

hacker newsMay 12, 2026Threat detection/AI security Why are my highest-risk SOC alerts not being responded to? Security operations teams are overwhelmed with alerts. But the real issue isn’t necessarily the volume of alerts. That’s a blind spot. The most dangerous alerts are those that no one investigates. A recent report from The Hacker News investigated […]
Mini Shai-Hulud worm compromises packages including TanStack, Mistral AI, Guardrails AI

TeamPCP, the threat actor behind recent supply chain attacks, has been implicated in compromising npm and PyPI packages for TanStack, UiPath, Mistral AI, OpenSearch, and Guardrails AI as part of a new Mini Shai-Hulud campaign. The affected npm packages have been modified to include an obfuscated JavaScript file (‘router_init.js’) designed to profile the execution environment […]
Why Agentic AI is the next security blind spot

Agentic AI is already running in production environments in many organizations today. It performs tasks, consumes data, and takes actions, perhaps without any meaningful involvement from your security team. The industry debate has largely framed this as a policy issue: to allow, restrict, or monitor. But that framework misses the point. The more pressing question […]
Instructor enters ransom agreement with ShinyHunters to stop 3.65TB canvas leak

Ravi LakshmananMay 12, 2026Vulnerability/Network Security Canvas’ parent company, American education technology company Instructor, announced it had reached an “agreement” with a decentralized cybercrime extortion group after the group infiltrated its network and threatened to divulge information stolen from thousands of schools and universities. In an update shared on Monday, the Utah-based company said it had […]
OpenAI launches Daybreak, an AI-powered vulnerability detection and patch verification service

Ravi LakshmananMay 12, 2026Vulnerability/AI Security OpenAI has launched Daybreak, a new cybersecurity initiative that integrates frontier artificial intelligence (AI) modeling capabilities with Codex Security. This allows organizations to identify and patch vulnerabilities before attackers find a way to exploit the same issue. “Daybreak combines the intelligence of OpenAI models, the scalability of Codex as an […]
iOS 26.5 brings default end-to-end encrypted RCS messaging between iPhone and Android

Ravi LakshmananMay 12, 2026Encryption/Mobile Security Apple on Monday officially released iOS 26.5 in beta with support for end-to-end encryption (E2EE) for Rich Communications Services (RCS) as part of a “cross-industry effort” to replace traditional SMS with more secure alternatives. To that end, E2EE RCS Messaging is rolling out to iPhone users running iOS 26.5 on […]
Weeks after KICS supply chain attack, TeamPCP compromises Checkmarx Jenkins AST plugin

Ravi LakshmananMay 11, 2026Supply chain attack / DevSecOps Checkmarx has confirmed that a fixed version of the Jenkins AST plugin has been published on the Jenkins Marketplace. “If you are using the Checkmarx Jenkins AST plugin, you should ensure that you are using version 2.0.13-829.vc72453fa_1c16 published on or before December 17, 2025,” the cybersecurity firm […]
cPanel CVE-2026-41940 Active exploitation to deploy Filemanager backdoor

Ravi LakshmananMay 11, 2026Vulnerability/Ransomware A threat actor named Mr_Rot13 is believed to have exploited a recently revealed critical flaw in cPanel to deploy a backdoor codenamed Filemanager into compromised environments. This attack exploits vulnerability CVE-2026-41940, which affects cPanel and WebHost Manager (WHM), resulting in an authentication bypass that could allow a remote attacker to gain […]