Quasar Linux RAT steals developer credentials in software supply chain compromise

Ravi LakshmananMay 8, 2026Linux/DevOps The previously undocumented Linux implant, codenamed Quasar Linux RAT (QLNX), targets developers’ systems to not only establish a silent foothold, but also facilitate a wide range of post-compromise functions, including credential harvesting, keylogging, file manipulation, clipboard monitoring, and network tunneling. “QLNX targets developers and DevOps credentials across the software supply chain,” […]

What 25 million alerts reveal about low-severity risks

The dark secret of corporate security operations is that defenders have quietly institutionalized the habit of not looking. This is not just an anecdote, but is backed up by a recent report that examined over 25 million security alerts, including informational and low-severity alerts, across real-world enterprise environments. The dataset behind these findings includes telemetry […]

New Linux PamDOORa backdoor uses PAM module to steal SSH credentials

Rabi LakshmananMay 8, 2026Malware/Threat Intelligence Cybersecurity researchers have revealed details of a new Linux backdoor named PamDOORa that is being advertised on the Rehub Russian cybercrime forum for $1,600 by a threat actor called “darkworm.” The backdoor is designed as a Pluggable Authentication Module (PAM)-based post-exploitation toolkit that allows persistent SSH access through a combination […]

Linux kernel dirty flag LPE exploit allows root access across major distributions

Rabi LakshmananMay 8, 2026Linux / Vulnerabilities Details have emerged about a new unpatched local privilege elevation (LPE) vulnerability affecting the Linux kernel. The vulnerability, known as Dirty Frag, is said to be a successor to Copy Fail (CVE-2026-31431, CVSS score: 7.8), a recently disclosed LPE flaw affecting the Linux kernel that has since been exploited […]

Ivanti EPMM CVE-2026-6973 Active exploit allows RCE to grant administrator-level access

Ravi LakshmananMay 7, 2026Vulnerability/Network Security Ivanti warns that a new security flaw affecting Endpoint Manager Mobile (EPMM) is being investigated in limited live attacks. High severity vulnerability CVE-2026-6973 (CVSS score: 7.2) is a case of improper input validation that affects EPMM versions prior to 12.6.1.1, 12.7.0.1, and 12.8.0.1. This allows “remote authenticated users with administrative […]

PCPJack Credential Stealer exploits five CVEs to spread like a worm across cloud systems

Rabi LakshmananMay 7, 2026Threat Intelligence/Cloud Security Cybersecurity researchers have revealed details of a new credential theft framework called PCPJack that targets exposed cloud infrastructure and expels any artifacts linked to TeamPCP from the environment. “This toolset collects credentials from cloud, container, developer, productivity, and financial services, steals data through attacker-controlled infrastructure, and attempts to spread […]

“Patient Zero” Webinar on Eliminating Stealth Breaches

hacker newsMay 7, 2026Artificial intelligence/threat detection The most difficult part of cybersecurity is not technology, but people. The big breaches we’ve read about lately usually start the same way: one employee, one well-crafted email, one “Patient Zero” infection. In 2026, hackers are using AI to make these “first clicks” nearly impossible to identify. Do you […]

PAN-OS RCE exploit is actively used to allow root access and espionage

Rabi LakshmananMay 7, 2026Vulnerabilities/Cyber ​​Espionage Palo Alto Networks has disclosed that attackers may have unsuccessfully attempted to exploit a recently disclosed critical security flaw as early as April 9, 2026. The vulnerability in question, CVE-2026-0300 (CVSS score: 9.3/8.7), is a buffer overflow vulnerability in the User Identity Authentication Portal service of Palo Alto Networks PAN-OS […]

Edge Plaintext Passwords, ICS 0-Days, Patch-or-Die Alerts and 25+ New Stories

Ravie LakshmananMay 07, 2026Hacking News / Cybersecurity News Bad week. Turns out the easiest way to get hacked in 2026 is still the same old garbage: shady packages, fake apps, forgotten DNS junk, scam ads, and stolen logins getting dumped into Discord channels like it’s normal. Some of these attack chains don’t even feel sophisticated […]

The Operational Gaps That Break Incident Response

Having an incident response retainer, or even a pre-approved external incident response firm, is not the same as being ready for an incident. A retainer means someone will answer the phone. Operational readiness determines whether that team can do meaningful work the moment they do.  That distinction matters far more than many organizations realize. In […]