Google fixes issue with CVSS 10 Gemini CLI CI RCE and cursor flaw that could allow code execution

Google has addressed a maximum severity security flaw in the Gemini CLI (the “@google/gemini-cli” npm package and the “google-github-actions/run-gemini-cli” GitHub Actions workflow). This flaw could allow an attacker to execute arbitrary commands on the host system. “This vulnerability could allow an unauthorized external attacker to force load their own malicious content as a Gemini configuration,” […]
SAP-related npm packages compromised in supply chain attack that steals credentials

Ravi LakshmananApril 29, 2026Supply chain attacks/malware Cybersecurity researchers are sounding the alarm about a new supply chain attack campaign targeting SAP-related npm packages that contain credential-stealing malware. According to reports from Aikido Security, SafeDep, Socket, StepSecurity, and Google-owned Wiz, the campaign, dubbed Mini Shai-Hulud, affected the following packages related to SAP’s JavaScript and cloud application […]
New wave of North Korean attacks using AI-embedded npm malware, fake companies, and RATs

Cybersecurity researchers discovered malicious code within an npm package following the malicious package as a dependency to a project by Anthropic’s Claude Opus Large-Scale Language Model (LLM). The package in question is “@validate-sdk/v2” and is listed on npm as a utility software development kit (SDK) for hashing, validation, encoding/decoding, and secure random generation. However, its […]
How to automate exposure verification at the speed of AI attacks

hacker newsApril 29, 2026Artificial intelligence/exposure verification In February 2026, researchers discovered a change that changed the situation forever. Attackers are using custom AI setups to automate attacks directly into the kill chain. We’re no longer just talking about AI creating better phishing emails. We’re talking about an autonomous agent that maps Active Directory and retrieves […]
What to look for in an exposure management platform (and what most of it is wrong with)

Every security team has a version of the same story. The quarter ends with hundreds of vulnerabilities resolved. The dashboard is full of green. Then someone in the leadership council asks, “So are we actually safer now?” Crickets. The room falls silent because honest answers require context. Patch counts and CVSS scores are not designed […]
A critical cPanel authentication vulnerability has been identified – please update your servers immediately

Ravi LakshmananApril 29, 2026Vulnerabilities / Web Hosting cPanel has released a security update to address security issues affecting various authentication paths that could allow an attacker to gain access to the control panel software. According to an alert released by cPanel on Tuesday, the issue affects all currently supported versions. This issue has been resolved […]
CISA adds actively exploited ConnectWise and Windows flaws to KEV

Ravi LakshmananApril 29, 2026Vulnerability/Network Security The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added two security flaws affecting ConnectWise ScreenConnect and Microsoft Windows to its Known Exploited Vulnerabilities (KEV) catalog based on evidence of active exploitation. The vulnerabilities are listed below. CVE-2024-1708 (CVSS Score: 8.4) – A path traversal vulnerability in ConnectWise ScreenConnect […]
LiteLLM CVE-2026-42208 SQL injection can be exploited within 36 hours of publication.

Ravi LakshmananApril 29, 2026Vulnerability / Cloud Security In yet another example of threat actors quickly jumping on the exploitation bandwagon, a newly disclosed critical security flaw in BerriAI’s LiteLLM Python package was actively exploited in the wild within 36 hours of the bug becoming public knowledge. This vulnerability, tracked as CVE-2026-42208 (CVSS score: 9.3), is […]
Researchers have discovered a critical GitHub CVE-2026-3854 RCE flaw that can be exploited via a single Git push

Ravi LakshmananApril 28, 2026Vulnerabilities/Software Security Cybersecurity researchers have detailed a critical security vulnerability affecting GitHub.com and GitHub Enterprise Server. This vulnerability could allow an authenticated user to execute remote code with a single “git push” command. This flaw, tracked as CVE-2026-3854 (CVSS score: 8.7), is a case of command injection that could allow an attacker […]
Brazil’s LofyGang resurfaces after 3 years with Minecraft LofyStealer campaign

A cybercrime group of Brazilian origin has resurfaced after more than three years and organized a campaign targeting Minecraft players using a new stealer called LofyStealer (also known as GrabBot). “This malware disguises itself as a Minecraft hack called ‘Slinky,’” Brazil-based cybersecurity firm ZenoX said in a technical report. “It exploits young users’ trust in […]